Bitcoin Core 31.99.0
P2P Digital Currency
tests.c
Go to the documentation of this file.
1/***********************************************************************
2 * Copyright (c) 2013, 2014, 2015 Pieter Wuille, Gregory Maxwell *
3 * Distributed under the MIT software license, see the accompanying *
4 * file COPYING or https://www.opensource.org/licenses/mit-license.php.*
5 ***********************************************************************/
6
7#include <stdio.h>
8#include <stdlib.h>
9#include <stdint.h>
10#include <string.h>
11
12#include <time.h>
13
14#ifdef USE_EXTERNAL_DEFAULT_CALLBACKS
15 #pragma message("Ignoring USE_EXTERNAL_CALLBACKS in tests.")
16 #undef USE_EXTERNAL_DEFAULT_CALLBACKS
17#endif
18#if defined(VERIFY) && defined(COVERAGE)
19 #pragma message("Defining VERIFY for tests being built for coverage analysis support is meaningless.")
20#endif
21#include "secp256k1.c"
22
23#include "../include/secp256k1.h"
24#include "../include/secp256k1_preallocated.h"
25#include "testrand_impl.h"
26#include "checkmem.h"
27#include "testutil.h"
28#include "util.h"
29#include "unit_test.h"
30#include "unit_test.c"
31
32#include "../contrib/lax_der_parsing.c"
33#include "../contrib/lax_der_privatekey_parsing.c"
34
35#include "modinv32_impl.h"
36#ifdef SECP256K1_WIDEMUL_INT128
37#include "modinv64_impl.h"
38#include "int128_impl.h"
39#endif
40
41#if defined(__GNUC__)
42# pragma GCC diagnostic push
43# pragma GCC diagnostic warning "-Wunused-function"
44#endif
45
46#define CONDITIONAL_TEST(cnt, nam) if (COUNT < (cnt)) { printf("Skipping %s (iteration count too low)\n", nam); } else
47
48static secp256k1_context *CTX = NULL;
50
51static int all_bytes_equal(const void* s, unsigned char value, size_t n) {
52 const unsigned char *p = s;
53 size_t i;
54
55 for (i = 0; i < n; i++) {
56 if (p[i] != value) {
57 return 0;
58 }
59 }
60 return 1;
61}
62
63#define CHECK_COUNTING_CALLBACK_VOID(ctx, expr_or_stmt, callback, callback_setter) do { \
64 int32_t _calls_to_callback = 0; \
65 secp256k1_callback _saved_callback = ctx->callback; \
66 callback_setter(ctx, counting_callback_fn, &_calls_to_callback); \
67 { expr_or_stmt; } \
68 ctx->callback = _saved_callback; \
69 CHECK(_calls_to_callback == 1); \
70} while(0);
71
72/* CHECK that expr_or_stmt calls the error or illegal callback of ctx exactly once
73 *
74 * Useful for checking functions that return void (e.g., API functions that use ARG_CHECK_VOID) */
75#define CHECK_ERROR_VOID(ctx, expr_or_stmt) \
76 CHECK_COUNTING_CALLBACK_VOID(ctx, expr_or_stmt, error_callback, secp256k1_context_set_error_callback)
77#define CHECK_ILLEGAL_VOID(ctx, expr_or_stmt) \
78 CHECK_COUNTING_CALLBACK_VOID(ctx, expr_or_stmt, illegal_callback, secp256k1_context_set_illegal_callback)
79
80/* CHECK that
81 * - expr calls the illegal callback of ctx exactly once and,
82 * - expr == 0 (or equivalently, expr == NULL)
83 *
84 * Useful for checking functions that return an integer or a pointer. */
85#define CHECK_ILLEGAL(ctx, expr) CHECK_ILLEGAL_VOID(ctx, CHECK((expr) == 0))
86#define CHECK_ERROR(ctx, expr) CHECK_ERROR_VOID(ctx, CHECK((expr) == 0))
87
88static void counting_callback_fn(const char* str, void* data) {
89 /* Dummy callback function that just counts. */
90 int32_t *p;
91 (void)str;
92 p = data;
93 CHECK(*p != INT32_MAX);
94 (*p)++;
95}
96
97static void run_xoshiro256pp_tests(void) {
98 {
99 size_t i;
100 /* Sanity check that we run before the actual seeding. */
101 for (i = 0; i < ARRAY_SIZE(secp256k1_test_state); i++) {
103 }
104 }
105 {
106 int i;
107 unsigned char buf32[32];
108 unsigned char seed16[16] = {
109 'C', 'H', 'I', 'C', 'K', 'E', 'N', '!',
110 'C', 'H', 'I', 'C', 'K', 'E', 'N', '!',
111 };
112 unsigned char buf32_expected[32] = {
113 0xAF, 0xCC, 0xA9, 0x16, 0xB5, 0x6C, 0xE3, 0xF0,
114 0x44, 0x3F, 0x45, 0xE0, 0x47, 0xA5, 0x08, 0x36,
115 0x4C, 0xCC, 0xC1, 0x18, 0xB2, 0xD8, 0x8F, 0xEF,
116 0x43, 0x26, 0x15, 0x57, 0x37, 0x00, 0xEF, 0x30,
117 };
118 testrand_seed(seed16);
119 for (i = 0; i < 17; i++) {
120 testrand256(buf32);
121 }
122 CHECK(secp256k1_memcmp_var(buf32, buf32_expected, sizeof(buf32)) == 0);
123 }
124}
125
126static void run_selftest_tests(void) {
127 /* Test public API */
129}
130
132 return a->built == b->built
136}
137
138static int context_eq(const secp256k1_context *a, const secp256k1_context *b) {
139 return a->declassify == b->declassify
146}
147
149 /* Check that a context created with any of the flags in the flags array is
150 * identical to the NONE context. */
151 unsigned int flags[] = { SECP256K1_CONTEXT_SIGN,
155 int i;
156 for (i = 0; i < (int)(ARRAY_SIZE(flags)); i++) {
157 secp256k1_context *tmp_ctx;
159 tmp_ctx = secp256k1_context_create(flags[i]);
160 CHECK(context_eq(none_ctx, tmp_ctx));
162 }
164}
165
167 secp256k1_pubkey pubkey;
168 secp256k1_pubkey zero_pubkey;
170 unsigned char ctmp[32];
171
172 /* Setup */
173 memset(ctmp, 1, 32);
174 memset(&zero_pubkey, 0, sizeof(zero_pubkey));
175
176 /* Verify context-type checking illegal-argument errors. */
178 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
179 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, ctmp) == 1);
180 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
181 CHECK_ILLEGAL(STATIC_CTX, secp256k1_ecdsa_sign(STATIC_CTX, &sig, ctmp, ctmp, NULL, NULL));
182 SECP256K1_CHECKMEM_UNDEFINE(&sig, sizeof(sig));
183 CHECK(secp256k1_ecdsa_sign(CTX, &sig, ctmp, ctmp, NULL, NULL) == 1);
184 SECP256K1_CHECKMEM_CHECK(&sig, sizeof(sig));
185 CHECK(secp256k1_ecdsa_verify(CTX, &sig, ctmp, &pubkey) == 1);
186 CHECK(secp256k1_ecdsa_verify(STATIC_CTX, &sig, ctmp, &pubkey) == 1);
187 CHECK(secp256k1_ec_pubkey_tweak_add(CTX, &pubkey, ctmp) == 1);
188 CHECK(secp256k1_ec_pubkey_tweak_add(STATIC_CTX, &pubkey, ctmp) == 1);
189 CHECK(secp256k1_ec_pubkey_tweak_mul(CTX, &pubkey, ctmp) == 1);
191 CHECK(secp256k1_ec_pubkey_negate(CTX, &pubkey) == 1);
194 CHECK(secp256k1_ec_pubkey_tweak_mul(STATIC_CTX, &pubkey, ctmp) == 1);
195}
196
197static void run_static_context_tests(int use_prealloc) {
198 {
199 unsigned char seed[32] = {0x17};
200
201 /* Randomizing secp256k1_context_static is not supported. */
204
205 /* Destroying or cloning secp256k1_context_static is not supported. */
206 if (use_prealloc) {
208 {
209 secp256k1_context *my_static_ctx = malloc(sizeof(*STATIC_CTX));
210 CHECK(my_static_ctx != NULL);
211 memset(my_static_ctx, 0x2a, sizeof(*my_static_ctx));
213 CHECK(all_bytes_equal(my_static_ctx, 0x2a, sizeof(*my_static_ctx)));
214 free(my_static_ctx);
215 }
217 } else {
220 }
221 }
222
223 {
224 /* Verify that setting and resetting illegal callback works */
225 int32_t dummy = 0;
232 }
233}
234
236{
239}
240
241static void run_proper_context_tests(int use_prealloc) {
242 int32_t dummy = 0;
243 secp256k1_context *my_ctx, *my_ctx_fresh;
244 void *my_ctx_prealloc = NULL;
245 unsigned char seed[32] = {0x17};
246
247 secp256k1_ge pub;
249 secp256k1_scalar sigr, sigs;
250
251 /* Fresh reference context for comparison */
253
254 if (use_prealloc) {
256 CHECK(my_ctx_prealloc != NULL);
258 } else {
260 }
261
262 /* Randomize and reset randomization */
263 CHECK(context_eq(my_ctx, my_ctx_fresh));
264 CHECK(secp256k1_context_randomize(my_ctx, seed) == 1);
265 CHECK(!context_eq(my_ctx, my_ctx_fresh));
266 CHECK(secp256k1_context_randomize(my_ctx, NULL) == 1);
267 CHECK(context_eq(my_ctx, my_ctx_fresh));
268
269 /* set error callback (to a function that still aborts in case malloc() fails in secp256k1_context_clone() below) */
273
274 /* check if sizes for cloning are consistent */
276
277 /*** clone and destroy all of them to make sure cloning was complete ***/
278 {
279 secp256k1_context *ctx_tmp;
280
281 if (use_prealloc) {
282 /* clone into a non-preallocated context and then again into a new preallocated one. */
283 ctx_tmp = my_ctx;
284 my_ctx = secp256k1_context_clone(my_ctx);
285 CHECK(context_eq(ctx_tmp, my_ctx));
287
288 free(my_ctx_prealloc);
290 CHECK(my_ctx_prealloc != NULL);
291 ctx_tmp = my_ctx;
292 my_ctx = secp256k1_context_preallocated_clone(my_ctx, my_ctx_prealloc);
293 CHECK(context_eq(ctx_tmp, my_ctx));
295 } else {
296 /* clone into a preallocated context and then again into a new non-preallocated one. */
297 void *prealloc_tmp;
298
300 CHECK(prealloc_tmp != NULL);
301 ctx_tmp = my_ctx;
302 my_ctx = secp256k1_context_preallocated_clone(my_ctx, prealloc_tmp);
303 CHECK(context_eq(ctx_tmp, my_ctx));
305
306 ctx_tmp = my_ctx;
307 my_ctx = secp256k1_context_clone(my_ctx);
308 CHECK(context_eq(ctx_tmp, my_ctx));
310 free(prealloc_tmp);
311 }
312 }
313
314 /* Verify that the error callback makes it across the clone. */
317 /* And that it resets back to default. */
318 secp256k1_context_set_error_callback(my_ctx, NULL, NULL);
320 CHECK(context_eq(my_ctx, my_ctx_fresh));
321
322 /* Verify that setting and resetting illegal callback works */
325 CHECK(my_ctx->illegal_callback.data == &dummy);
326 secp256k1_context_set_illegal_callback(my_ctx, NULL, NULL);
328 CHECK(my_ctx->illegal_callback.data == NULL);
329 CHECK(context_eq(my_ctx, my_ctx_fresh));
330
331 /*** attempt to use them ***/
334 secp256k1_ecmult_gen_ge(&my_ctx->ecmult_gen_ctx, &pub, &key);
335
336 /* obtain a working nonce */
337 do {
339 } while(!secp256k1_ecdsa_sig_sign(&my_ctx->ecmult_gen_ctx, &sigr, &sigs, &key, &msg, &nonce, NULL));
340
341 /* try signing */
342 CHECK(secp256k1_ecdsa_sig_sign(&my_ctx->ecmult_gen_ctx, &sigr, &sigs, &key, &msg, &nonce, NULL));
343
344 /* try verifying */
345 CHECK(secp256k1_ecdsa_sig_verify(&sigr, &sigs, &pub, &msg));
346
347 /* cleanup */
348 if (use_prealloc) {
350 free(my_ctx_prealloc);
351 } else {
353 }
354 secp256k1_context_destroy(my_ctx_fresh);
355
356 /* Defined as no-op. */
359}
360
362{
365}
366
367static void run_scratch_tests(void) {
368 const size_t adj_alloc = ((500 + ALIGNMENT - 1) / ALIGNMENT) * ALIGNMENT;
369
370 size_t checkpoint;
371 size_t checkpoint_2;
373
374 /* Test public API */
375 scratch = secp256k1_scratch_space_create(CTX, 1000);
376 CHECK(scratch != NULL);
377
378 /* Test internal API */
380 CHECK(secp256k1_scratch_max_allocation(&CTX->error_callback, scratch, 1) == 1000 - (ALIGNMENT - 1));
381 CHECK(scratch->alloc_size == 0);
382 CHECK(scratch->alloc_size % ALIGNMENT == 0);
383
384 /* Allocating 500 bytes succeeds */
385 checkpoint = secp256k1_scratch_checkpoint(&CTX->error_callback, scratch);
386 CHECK(secp256k1_scratch_alloc(&CTX->error_callback, scratch, 500) != NULL);
387 CHECK(secp256k1_scratch_max_allocation(&CTX->error_callback, scratch, 0) == 1000 - adj_alloc);
388 CHECK(secp256k1_scratch_max_allocation(&CTX->error_callback, scratch, 1) == 1000 - adj_alloc - (ALIGNMENT - 1));
389 CHECK(scratch->alloc_size != 0);
390 CHECK(scratch->alloc_size % ALIGNMENT == 0);
391
392 /* Allocating another 501 bytes fails */
393 CHECK(secp256k1_scratch_alloc(&CTX->error_callback, scratch, 501) == NULL);
394 CHECK(secp256k1_scratch_max_allocation(&CTX->error_callback, scratch, 0) == 1000 - adj_alloc);
395 CHECK(secp256k1_scratch_max_allocation(&CTX->error_callback, scratch, 1) == 1000 - adj_alloc - (ALIGNMENT - 1));
396 CHECK(scratch->alloc_size != 0);
397 CHECK(scratch->alloc_size % ALIGNMENT == 0);
398
399 /* ...but it succeeds once we apply the checkpoint to undo it */
401 CHECK(scratch->alloc_size == 0);
403 CHECK(secp256k1_scratch_alloc(&CTX->error_callback, scratch, 500) != NULL);
404 CHECK(scratch->alloc_size != 0);
405
406 /* try to apply a bad checkpoint */
407 checkpoint_2 = secp256k1_scratch_checkpoint(&CTX->error_callback, scratch);
409 CHECK_ERROR_VOID(CTX, secp256k1_scratch_apply_checkpoint(&CTX->error_callback, scratch, checkpoint_2)); /* checkpoint_2 is after checkpoint */
410 CHECK_ERROR_VOID(CTX, secp256k1_scratch_apply_checkpoint(&CTX->error_callback, scratch, (size_t) -1)); /* this is just wildly invalid */
411
412 /* Test that large integers do not wrap around in a bad way */
413 /* Try max allocation with a large number of objects. Only makes sense if
414 * ALIGNMENT is greater than 1 because otherwise the objects take no extra
415 * space. */
416 CHECK(ALIGNMENT <= 1 || !secp256k1_scratch_max_allocation(&CTX->error_callback, scratch, (SIZE_MAX / (ALIGNMENT - 1)) + 1));
417 /* Try allocating SIZE_MAX to test wrap around which only happens if
418 * ALIGNMENT > 1, otherwise it returns NULL anyway because the scratch
419 * space is too small. */
420 CHECK(secp256k1_scratch_alloc(&CTX->error_callback, scratch, SIZE_MAX) == NULL);
422
423 /* cleanup */
424 secp256k1_scratch_space_destroy(CTX, NULL); /* no-op */
425}
426
427/* try to use badly initialized scratch space */
429 secp256k1_scratch_space* scratch = checked_malloc(&CTX->error_callback, sizeof(*scratch));
430 size_t magic_size = sizeof(scratch->magic);
431 memset(scratch, 0, sizeof(*scratch));
432 /* catch accesses beyond the magic */
433 SECP256K1_CHECKMEM_UNDEFINE((unsigned char*)scratch + magic_size, sizeof(*scratch) - magic_size);
434
438
439 free(scratch);
440}
441
442/* A compression function that does nothing */
443static void invalid_sha256_compression(uint32_t *s, const unsigned char *msg, size_t rounds) {
444 (void)s; (void)msg; (void)rounds;
445}
446
447static int own_transform_called = 0;
448static void good_sha256_compression(uint32_t *s, const unsigned char *msg, size_t rounds) {
451}
452
454 secp256k1_context *ctx, *ctx_cloned;
456 unsigned char sha_out[32];
457 /* 1) Verify the context is initialized with the default compression function */
460
461 /* 2) Verify providing a bad compression function fails during set */
464
465 /* 3) Provide sha256 to ctx and verify it is called when provided */
469
470 /* 4) Verify callback makes it across clone */
471 ctx_cloned = secp256k1_context_clone(ctx);
473
474 /* 5) A hash operation should invoke the installed callback */
477 secp256k1_sha256_write(secp256k1_get_hash_context(ctx), &sha, (const unsigned char*)"a", 1);
480
481 /* 6) Unset sha256 and verify the default one is set again */
484
486 secp256k1_context_destroy(ctx_cloned);
487}
488
489/* Hashes the first block over and over instead of moving on. */
490static void sha256_transform_noadvance(uint32_t *s, const unsigned char *chunk, size_t blocks) {
491 size_t i;
492 for (i = 0; i < blocks; i++) {
493 secp256k1_sha256_transform(s, chunk, 1);
494 }
495}
496
497/* Drops the last block of a multi-block call. */
498static void sha256_transform_short(uint32_t *s, const unsigned char *chunk, size_t blocks) {
499 secp256k1_sha256_transform(s, chunk, blocks > 0 ? blocks - 1 : 0);
500}
501
502/* Starts from the IV instead of the state it was given. */
503static void sha256_transform_ivreset(uint32_t *s, const unsigned char *chunk, size_t blocks) {
506 memcpy(s, h.s, sizeof(h.s));
507 secp256k1_sha256_transform(s, chunk, blocks);
508}
509
510/* Correct only on multiples of four blocks. */
511static void sha256_transform_batch4(uint32_t *s, const unsigned char *chunk, size_t blocks) {
512 secp256k1_sha256_transform(s, chunk, blocks - (blocks & 3));
513}
514
515/* Right digest, one bit off. */
516static void sha256_transform_corrupt(uint32_t *s, const unsigned char *chunk, size_t blocks) {
517 secp256k1_sha256_transform(s, chunk, blocks);
518 s[0] ^= 1;
519}
520
521#ifdef UINTPTR_MAX
522
523/* Wrong when input is 64-byte aligned, like a broken SIMD fast path. */
524static void sha256_transform_align64_fail(uint32_t *s, const unsigned char *chunk, size_t blocks) {
525 int aligned = ((uintptr_t)chunk % 64) == 0;
526 secp256k1_sha256_transform(s, chunk, blocks);
527 if (aligned) s[0] ^= 1;
528}
529
530/* Wrong when input is 32-byte aligned but not 64 */
531static void sha256_transform_align32_fail(uint32_t *s, const unsigned char *chunk, size_t blocks) {
532 int align32_not64 = (((uintptr_t)chunk % 32) == 0) && (((uintptr_t)chunk % 64) != 0);
533 secp256k1_sha256_transform(s, chunk, blocks);
534 if (align32_not64) {
535 s[0] ^= 1;
536 }
537}
538
539/* Wrong on any unaligned input. */
540static void sha256_transform_unaligned_fail(uint32_t *s, const unsigned char *chunk, size_t blocks) {
541 int aligned = ((uintptr_t)chunk % 64) == 0;
542 secp256k1_sha256_transform(s, chunk, blocks);
543 if (!aligned) s[0] ^= 1;
544}
545
546#endif /* UINTPTR_MAX */
547
554#ifdef UINTPTR_MAX
555 CHECK(secp256k1_sha256_smoke_test(sha256_transform_align64_fail) == 0);
556 CHECK(secp256k1_sha256_smoke_test(sha256_transform_align32_fail) == 0);
557 CHECK(secp256k1_sha256_smoke_test(sha256_transform_unaligned_fail) == 0);
558#endif
560}
561
563 secp256k1_hash_ctx hash_ctx;
564 secp256k1_sha256 sha256_one;
565 secp256k1_sha256 sha256_two;
566 unsigned char out_one[32], out_two[32];
567
569
570 { /* 1) Writing one 64-byte full block vs two 32-byte blocks */
571 const unsigned char data[64] = "totally serious test message to hash, definitely no random data";
572 unsigned char data32[32];
573
574 secp256k1_sha256_initialize(&sha256_one);
575 secp256k1_sha256_initialize(&sha256_two);
576
577 /* Write the 64-byte block */
578 secp256k1_sha256_write(&hash_ctx, &sha256_one, data, 64);
579 secp256k1_sha256_finalize(&hash_ctx, &sha256_one, out_one);
580
581 /* Write the two 32-byte blocks */
582 memcpy(data32, data, 32);
583 secp256k1_sha256_write(&hash_ctx, &sha256_two, data32, 32);
584 memcpy(data32, data + 32, 32);
585 secp256k1_sha256_write(&hash_ctx, &sha256_two, data32, 32);
586 secp256k1_sha256_finalize(&hash_ctx, &sha256_two, out_two);
587
588 CHECK(secp256k1_memcmp_var(out_one, out_two, 32) == 0);
589 }
590
591 { /* 2) Writing one 80-byte block vs two 40-byte blocks */
592 const unsigned char data[80] = "Genesis: The Times 03/Jan/2009 Chancellor on brink of second bailout for banks ";
593 unsigned char data40[40];
594
595 secp256k1_sha256_initialize(&sha256_one);
596 secp256k1_sha256_initialize(&sha256_two);
597
598 /* Write the 80-byte block */
599 secp256k1_sha256_write(&hash_ctx, &sha256_one, data, 80);
600 secp256k1_sha256_finalize(&hash_ctx, &sha256_one, out_one);
601
602 /* Write the two 40-byte blocks */
603 memcpy(data40, data, 40);
604 secp256k1_sha256_write(&hash_ctx, &sha256_two, data40, 40);
605 memcpy(data40, data + 40, 40);
606 secp256k1_sha256_write(&hash_ctx, &sha256_two, data40, 40);
607 secp256k1_sha256_finalize(&hash_ctx, &sha256_two, out_two);
608
609 CHECK(secp256k1_memcmp_var(out_one, out_two, 32) == 0);
610 }
611
612 { /* 3) Writing multiple consecutive full blocks in one write (128 bytes) */
613 unsigned char data[128];
614 unsigned char i;
615 for (i = 0; i < 128; i++) data[i] = i;
616
617 secp256k1_sha256_initialize(&sha256_one);
618 secp256k1_sha256_initialize(&sha256_two);
619
620 /* Single write of 128 bytes (two full 64-byte blocks) */
621 secp256k1_sha256_write(&hash_ctx, &sha256_one, data, 128);
622 secp256k1_sha256_finalize(&hash_ctx, &sha256_one, out_one);
623
624 /* Two separate writes of 64 bytes each */
625 secp256k1_sha256_write(&hash_ctx, &sha256_two, data, 64);
626 secp256k1_sha256_write(&hash_ctx, &sha256_two, data + 64, 64);
627 secp256k1_sha256_finalize(&hash_ctx, &sha256_two, out_two);
628
629 CHECK(secp256k1_memcmp_var(out_one, out_two, 32) == 0);
630 }
631
632 { /* 4) Mixed small + large writes in sequence */
633 unsigned char data[150];
634 unsigned char i;
635 for (i = 0; i < 150; i++) data[i] = i;
636
637 secp256k1_sha256_initialize(&sha256_one);
638 secp256k1_sha256_initialize(&sha256_two);
639
640 /* Single write of 150 bytes */
641 secp256k1_sha256_write(&hash_ctx, &sha256_one, data, 150);
642 secp256k1_sha256_finalize(&hash_ctx, &sha256_one, out_one);
643
644 /* Split writes: 10, 64, 64, 12 bytes */
645 secp256k1_sha256_write(&hash_ctx, &sha256_two, data, 10);
646 secp256k1_sha256_write(&hash_ctx, &sha256_two, data + 10, 64);
647 secp256k1_sha256_write(&hash_ctx, &sha256_two, data + 74, 64);
648 secp256k1_sha256_write(&hash_ctx, &sha256_two, data + 138, 12);
649 secp256k1_sha256_finalize(&hash_ctx, &sha256_two, out_two);
650
651 CHECK(secp256k1_memcmp_var(out_one, out_two, 32) == 0);
652 }
653}
654
655static void run_ctz_tests(void) {
656 static const uint32_t b32[] = {1, 0xffffffff, 0x5e56968f, 0xe0d63129};
657 static const uint64_t b64[] = {1, 0xffffffffffffffff, 0xbcd02462139b3fc3, 0x98b5f80c769693ef};
658 int shift;
659 unsigned i;
660 for (i = 0; i < ARRAY_SIZE(b32); ++i) {
661 for (shift = 0; shift < 32; ++shift) {
662 CHECK(secp256k1_ctz32_var_debruijn(b32[i] << shift) == shift);
663 CHECK(secp256k1_ctz32_var(b32[i] << shift) == shift);
664 }
665 }
666 for (i = 0; i < ARRAY_SIZE(b64); ++i) {
667 for (shift = 0; shift < 64; ++shift) {
668 CHECK(secp256k1_ctz64_var_debruijn(b64[i] << shift) == shift);
669 CHECK(secp256k1_ctz64_var(b64[i] << shift) == shift);
670 }
671 }
672}
673
674/***** HASH TESTS *****/
675
678 static const char *inputs[] = {
679 "", "abc", "message digest", "secure hash algorithm", "SHA256 is considered to be safe",
680 "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq",
681 "For this sample, this 63-byte string will be used as input data",
682 "This is exactly 64 bytes long, not counting the terminating byte",
683 "aaaaa",
684 };
685 static const unsigned int repeat[] = {
686 1, 1, 1, 1, 1, 1, 1, 1, 1000000/5
687 };
688 static const unsigned char outputs[][32] = {
689 {0xe3, 0xb0, 0xc4, 0x42, 0x98, 0xfc, 0x1c, 0x14, 0x9a, 0xfb, 0xf4, 0xc8, 0x99, 0x6f, 0xb9, 0x24, 0x27, 0xae, 0x41, 0xe4, 0x64, 0x9b, 0x93, 0x4c, 0xa4, 0x95, 0x99, 0x1b, 0x78, 0x52, 0xb8, 0x55},
690 {0xba, 0x78, 0x16, 0xbf, 0x8f, 0x01, 0xcf, 0xea, 0x41, 0x41, 0x40, 0xde, 0x5d, 0xae, 0x22, 0x23, 0xb0, 0x03, 0x61, 0xa3, 0x96, 0x17, 0x7a, 0x9c, 0xb4, 0x10, 0xff, 0x61, 0xf2, 0x00, 0x15, 0xad},
691 {0xf7, 0x84, 0x6f, 0x55, 0xcf, 0x23, 0xe1, 0x4e, 0xeb, 0xea, 0xb5, 0xb4, 0xe1, 0x55, 0x0c, 0xad, 0x5b, 0x50, 0x9e, 0x33, 0x48, 0xfb, 0xc4, 0xef, 0xa3, 0xa1, 0x41, 0x3d, 0x39, 0x3c, 0xb6, 0x50},
692 {0xf3, 0x0c, 0xeb, 0x2b, 0xb2, 0x82, 0x9e, 0x79, 0xe4, 0xca, 0x97, 0x53, 0xd3, 0x5a, 0x8e, 0xcc, 0x00, 0x26, 0x2d, 0x16, 0x4c, 0xc0, 0x77, 0x08, 0x02, 0x95, 0x38, 0x1c, 0xbd, 0x64, 0x3f, 0x0d},
693 {0x68, 0x19, 0xd9, 0x15, 0xc7, 0x3f, 0x4d, 0x1e, 0x77, 0xe4, 0xe1, 0xb5, 0x2d, 0x1f, 0xa0, 0xf9, 0xcf, 0x9b, 0xea, 0xea, 0xd3, 0x93, 0x9f, 0x15, 0x87, 0x4b, 0xd9, 0x88, 0xe2, 0xa2, 0x36, 0x30},
694 {0x24, 0x8d, 0x6a, 0x61, 0xd2, 0x06, 0x38, 0xb8, 0xe5, 0xc0, 0x26, 0x93, 0x0c, 0x3e, 0x60, 0x39, 0xa3, 0x3c, 0xe4, 0x59, 0x64, 0xff, 0x21, 0x67, 0xf6, 0xec, 0xed, 0xd4, 0x19, 0xdb, 0x06, 0xc1},
695 {0xf0, 0x8a, 0x78, 0xcb, 0xba, 0xee, 0x08, 0x2b, 0x05, 0x2a, 0xe0, 0x70, 0x8f, 0x32, 0xfa, 0x1e, 0x50, 0xc5, 0xc4, 0x21, 0xaa, 0x77, 0x2b, 0xa5, 0xdb, 0xb4, 0x06, 0xa2, 0xea, 0x6b, 0xe3, 0x42},
696 {0xab, 0x64, 0xef, 0xf7, 0xe8, 0x8e, 0x2e, 0x46, 0x16, 0x5e, 0x29, 0xf2, 0xbc, 0xe4, 0x18, 0x26, 0xbd, 0x4c, 0x7b, 0x35, 0x52, 0xf6, 0xb3, 0x82, 0xa9, 0xe7, 0xd3, 0xaf, 0x47, 0xc2, 0x45, 0xf8},
697 {0xcd, 0xc7, 0x6e, 0x5c, 0x99, 0x14, 0xfb, 0x92, 0x81, 0xa1, 0xc7, 0xe2, 0x84, 0xd7, 0x3e, 0x67, 0xf1, 0x80, 0x9a, 0x48, 0xa4, 0x97, 0x20, 0x0e, 0x04, 0x6d, 0x39, 0xcc, 0xc7, 0x11, 0x2c, 0xd0},
698 };
699 unsigned int i, ninputs;
700
701 /* Skip last input vector for low iteration counts */
702 ninputs = ARRAY_SIZE(inputs) - 1;
703 CONDITIONAL_TEST(16, "run_sha256_known_output_tests 1000000") ninputs++;
704
705 for (i = 0; i < ninputs; i++) {
706 unsigned char out[32];
707 secp256k1_sha256 hasher;
708 unsigned int j;
709 /* 1. Run: simply write the input bytestrings */
710 j = repeat[i];
712 while (j > 0) {
713 secp256k1_sha256_write(hash_ctx, &hasher, (const unsigned char*)(inputs[i]), strlen(inputs[i]));
714 j--;
715 }
716 secp256k1_sha256_finalize(hash_ctx, &hasher, out);
717 CHECK(secp256k1_memcmp_var(out, outputs[i], 32) == 0);
718 /* 2. Run: split the input bytestrings randomly before writing */
719 if (strlen(inputs[i]) > 0) {
720 int split = testrand_int(strlen(inputs[i]));
722 j = repeat[i];
723 while (j > 0) {
724 secp256k1_sha256_write(hash_ctx, &hasher, (const unsigned char*)(inputs[i]), split);
725 secp256k1_sha256_write(hash_ctx, &hasher, (const unsigned char*)(inputs[i] + split), strlen(inputs[i]) - split);
726 j--;
727 }
728 secp256k1_sha256_finalize(hash_ctx, &hasher, out);
729 CHECK(secp256k1_memcmp_var(out, outputs[i], 32) == 0);
730 }
731 }
732}
733
778static void run_sha256_counter_tests(void) {
779 static const char *input = "abcdefghbcdefghicdefghijdefghijkefghijklfghijklmghijklmnhijklmno";
780 static const secp256k1_sha256 midstates[] = {
781 {{0xa2b5c8bb, 0x26c88bb3, 0x2abdc3d2, 0x9def99a3, 0xdfd21a6e, 0x41fe585b, 0x7ef2c440, 0x2b79adda},
782 {0x00}, 0xfffc0},
783 {{0xa0d29445, 0x9287de66, 0x76aabd71, 0x41acd765, 0x0c7528b4, 0x84e14906, 0x942faec6, 0xcc5a7b26},
784 {0x00}, 0x1fffc0},
785 {{0x50449526, 0xb9f1d657, 0xa0fc13e9, 0x50860f10, 0xa550c431, 0x3fbc97c1, 0x7bbb2d89, 0xdb67bac1},
786 {0x00}, 0x3fffc0},
787 {{0x54a6efdc, 0x46762e7b, 0x88bfe73f, 0xbbd149c7, 0x41620c43, 0x1168da7b, 0x2c5960f9, 0xeccffda6},
788 {0x00}, 0x7fffc0},
789 {{0x2515a8f5, 0x5faa2977, 0x3a850486, 0xac858cad, 0x7b7276ee, 0x235c0385, 0xc53a157c, 0x7cb3e69c},
790 {0x00}, 0xffffc0},
791 {{0x34f39828, 0x409fedb7, 0x4bbdd0fb, 0x3b643634, 0x7806bf2e, 0xe0d1b713, 0xca3f2e1e, 0xe38722c2},
792 {0x00}, 0x1ffffc0},
793 {{0x389ef5c5, 0x38c54167, 0x8f5d56ab, 0x582a75cc, 0x8217caef, 0xf10947dd, 0x6a1998a8, 0x048f0b8c},
794 {0x00}, 0x3ffffc0},
795 {{0xd6c3f394, 0x0bee43b9, 0x6783f497, 0x29fa9e21, 0x6ce491c1, 0xa81fe45e, 0x2fc3859a, 0x269012d0},
796 {0x00}, 0x7ffffc0},
797 {{0x6dd3c526, 0x44d88aa0, 0x806a1bae, 0xfbcc0d32, 0x9d6144f3, 0x9d2bd757, 0x9851a957, 0xb50430ad},
798 {0x00}, 0xfffffc0},
799 {{0x2add4021, 0xdfe8a9e6, 0xa56317c6, 0x7a15f5bb, 0x4a48aacd, 0x5d368414, 0x4f00e6f0, 0xd9355023},
800 {0x00}, 0x1fffffc0},
801 {{0xb66666b4, 0xdbeac32b, 0x0ea351ae, 0xcba9da46, 0x6278b874, 0x8c508e23, 0xe16ca776, 0x8465bac1},
802 {0x00}, 0x3fffffc0},
803 {{0xb6744789, 0x9cce87aa, 0xc4c478b7, 0xf38404d8, 0x2e38ba62, 0xa3f7019b, 0x50458fe7, 0x3047dbec},
804 {0x00}, 0x7fffffc0},
805 {{0x8b1297ba, 0xba261a80, 0x2ba1b0dd, 0xfbc67d6d, 0x61072c4e, 0x4b5a2a0f, 0x52872760, 0x2dfeb162},
806 {0x00}, 0xffffffc0},
807 {{0x24f33cf7, 0x41ad6583, 0x41c8ff5d, 0xca7ef35f, 0x50395756, 0x021b743e, 0xd7126cd7, 0xd037473a},
808 {0x00}, 0x1ffffffc0},
809 };
810 static const unsigned char outputs[][32] = {
811 {0x0e, 0x83, 0xe2, 0xc9, 0x4f, 0xb2, 0xb8, 0x2b, 0x89, 0x06, 0x92, 0x78, 0x04, 0x03, 0x48, 0x5c, 0x48, 0x44, 0x67, 0x61, 0x77, 0xa4, 0xc7, 0x90, 0x9e, 0x92, 0x55, 0x10, 0x05, 0xfe, 0x39, 0x15},
812 {0x1d, 0x1e, 0xd7, 0xb8, 0xa3, 0xa7, 0x8a, 0x79, 0xfd, 0xa0, 0x05, 0x08, 0x9c, 0xeb, 0xf0, 0xec, 0x67, 0x07, 0x9f, 0x8e, 0x3c, 0x0d, 0x8e, 0xf9, 0x75, 0x55, 0x13, 0xc1, 0xe8, 0x77, 0xf8, 0xbb},
813 {0x66, 0x95, 0x6c, 0xc9, 0xe0, 0x39, 0x65, 0xb6, 0xb0, 0x05, 0xd1, 0xaf, 0xaf, 0xf3, 0x1d, 0xb9, 0xa4, 0xda, 0x6f, 0x20, 0xcd, 0x3a, 0xae, 0x64, 0xc2, 0xdb, 0xee, 0xf5, 0xb8, 0x8d, 0x57, 0x0e},
814 {0x3c, 0xbb, 0x1c, 0x12, 0x5e, 0x17, 0xfd, 0x54, 0x90, 0x45, 0xa7, 0x7b, 0x61, 0x6c, 0x1d, 0xfe, 0xe6, 0xcc, 0x7f, 0xee, 0xcf, 0xef, 0x33, 0x35, 0x50, 0x62, 0x16, 0x70, 0x2f, 0x87, 0xc3, 0xc9},
815 {0x53, 0x4d, 0xa8, 0xe7, 0x1e, 0x98, 0x73, 0x8d, 0xd9, 0xa3, 0x54, 0xa5, 0x0e, 0x59, 0x2c, 0x25, 0x43, 0x6f, 0xaa, 0xa2, 0xf5, 0x21, 0x06, 0x3e, 0xc9, 0x82, 0x06, 0x94, 0x98, 0x72, 0x9d, 0xa7},
816 {0xef, 0x7e, 0xe9, 0x6b, 0xd3, 0xe5, 0xb7, 0x41, 0x4c, 0xc8, 0xd3, 0x07, 0x52, 0x9a, 0x5a, 0x8b, 0x4e, 0x1e, 0x75, 0xa4, 0x17, 0x78, 0xc8, 0x36, 0xcd, 0xf8, 0x2e, 0xd9, 0x57, 0xe3, 0xd7, 0x07},
817 {0x87, 0x16, 0xfb, 0xf9, 0xa5, 0xf8, 0xc4, 0x56, 0x2b, 0x48, 0x52, 0x8e, 0x2d, 0x30, 0x85, 0xb6, 0x4c, 0x56, 0xb5, 0xd1, 0x16, 0x9c, 0xcf, 0x32, 0x95, 0xad, 0x03, 0xe8, 0x05, 0x58, 0x06, 0x76},
818 {0x75, 0x03, 0x80, 0x28, 0xf2, 0xa7, 0x63, 0x22, 0x1a, 0x26, 0x9c, 0x68, 0xe0, 0x58, 0xfc, 0x73, 0xeb, 0x42, 0xf6, 0x86, 0x16, 0x24, 0x4b, 0xbc, 0x24, 0xf7, 0x02, 0xc8, 0x3d, 0x90, 0xe2, 0xb0},
819 {0xdf, 0x49, 0x0f, 0x15, 0x7b, 0x7d, 0xbf, 0xe0, 0xd4, 0xcf, 0x47, 0xc0, 0x80, 0x93, 0x4a, 0x61, 0xaa, 0x03, 0x07, 0x66, 0xb3, 0x38, 0x5d, 0xc8, 0xc9, 0x07, 0x61, 0xfb, 0x97, 0x10, 0x2f, 0xd8},
820 {0x77, 0x19, 0x40, 0x56, 0x41, 0xad, 0xbc, 0x59, 0xda, 0x1e, 0xc5, 0x37, 0x14, 0x63, 0x7b, 0xfb, 0x79, 0xe2, 0x7a, 0xb1, 0x55, 0x42, 0x99, 0x42, 0x56, 0xfe, 0x26, 0x9d, 0x0f, 0x7e, 0x80, 0xc6},
821 {0x50, 0xe7, 0x2a, 0x0e, 0x26, 0x44, 0x2f, 0xe2, 0x55, 0x2d, 0xc3, 0x93, 0x8a, 0xc5, 0x86, 0x58, 0x22, 0x8c, 0x0c, 0xbf, 0xb1, 0xd2, 0xca, 0x87, 0x2a, 0xe4, 0x35, 0x26, 0x6f, 0xcd, 0x05, 0x5e},
822 {0xe4, 0x80, 0x6f, 0xdb, 0x3d, 0x7d, 0xba, 0xde, 0x50, 0x3f, 0xea, 0x00, 0x3d, 0x46, 0x59, 0x64, 0xfd, 0x58, 0x1c, 0xa1, 0xb8, 0x7d, 0x5f, 0xac, 0x94, 0x37, 0x9e, 0xa0, 0xc0, 0x9c, 0x93, 0x8b},
823 {0x2c, 0xf3, 0xa9, 0xf6, 0x15, 0x25, 0x80, 0x70, 0x76, 0x99, 0x7d, 0xf1, 0xc3, 0x2f, 0xa3, 0x31, 0xff, 0x92, 0x35, 0x2e, 0x8d, 0x04, 0x13, 0x33, 0xd8, 0x0d, 0xdb, 0x4a, 0xf6, 0x8c, 0x03, 0x34},
824 {0xec, 0x12, 0x24, 0x9f, 0x35, 0xa4, 0x29, 0x8b, 0x9e, 0x4a, 0x95, 0xf8, 0x61, 0xaf, 0x61, 0xc5, 0x66, 0x55, 0x3e, 0x3f, 0x2a, 0x98, 0xea, 0x71, 0x16, 0x6b, 0x1c, 0xd9, 0xe4, 0x09, 0xd2, 0x8e},
825 };
827 unsigned int i;
828 for (i = 0; i < ARRAY_SIZE(midstates); i++) {
829 unsigned char out[32];
830 secp256k1_sha256 hasher = midstates[i];
831 secp256k1_sha256_write(hash_ctx, &hasher, (const unsigned char*)input, strlen(input));
832 secp256k1_sha256_finalize(hash_ctx, &hasher, out);
833 CHECK(secp256k1_memcmp_var(out, outputs[i], 32) == 0);
834 }
835}
836
837/* Tests for the equality of two sha256 structs. This function only produces a
838 * correct result if an integer multiple of 64 many bytes have been written
839 * into the hash functions. This function is used by some module tests. */
840static void test_sha256_eq(const secp256k1_sha256 *sha1, const secp256k1_sha256 *sha2) {
841 /* Is buffer fully consumed? */
842 CHECK((sha1->bytes & 0x3F) == 0);
843
844 CHECK(sha1->bytes == sha2->bytes);
845 CHECK(secp256k1_memcmp_var(sha1->s, sha2->s, sizeof(sha1->s)) == 0);
846}
847/* Convenience function for using test_sha256_eq to verify the correctness of a
848 * tagged hash midstate. This function is used by some module tests. */
849static void test_sha256_tag_midstate(const secp256k1_hash_ctx *hash_ctx, secp256k1_sha256 *sha_tagged, const unsigned char *tag, size_t taglen) {
851 secp256k1_sha256_initialize_tagged(hash_ctx, &sha, tag, taglen);
852 test_sha256_eq(&sha, sha_tagged);
853}
854
855static void run_hmac_sha256_tests(void) {
856 static const char *keys[6] = {
857 "\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b",
858 "\x4a\x65\x66\x65",
859 "\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa",
860 "\x01\x02\x03\x04\x05\x06\x07\x08\x09\x0a\x0b\x0c\x0d\x0e\x0f\x10\x11\x12\x13\x14\x15\x16\x17\x18\x19",
861 "\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa",
862 "\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa"
863 };
864 static const char *inputs[6] = {
865 "\x48\x69\x20\x54\x68\x65\x72\x65",
866 "\x77\x68\x61\x74\x20\x64\x6f\x20\x79\x61\x20\x77\x61\x6e\x74\x20\x66\x6f\x72\x20\x6e\x6f\x74\x68\x69\x6e\x67\x3f",
867 "\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd\xdd",
868 "\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd\xcd",
869 "\x54\x65\x73\x74\x20\x55\x73\x69\x6e\x67\x20\x4c\x61\x72\x67\x65\x72\x20\x54\x68\x61\x6e\x20\x42\x6c\x6f\x63\x6b\x2d\x53\x69\x7a\x65\x20\x4b\x65\x79\x20\x2d\x20\x48\x61\x73\x68\x20\x4b\x65\x79\x20\x46\x69\x72\x73\x74",
870 "\x54\x68\x69\x73\x20\x69\x73\x20\x61\x20\x74\x65\x73\x74\x20\x75\x73\x69\x6e\x67\x20\x61\x20\x6c\x61\x72\x67\x65\x72\x20\x74\x68\x61\x6e\x20\x62\x6c\x6f\x63\x6b\x2d\x73\x69\x7a\x65\x20\x6b\x65\x79\x20\x61\x6e\x64\x20\x61\x20\x6c\x61\x72\x67\x65\x72\x20\x74\x68\x61\x6e\x20\x62\x6c\x6f\x63\x6b\x2d\x73\x69\x7a\x65\x20\x64\x61\x74\x61\x2e\x20\x54\x68\x65\x20\x6b\x65\x79\x20\x6e\x65\x65\x64\x73\x20\x74\x6f\x20\x62\x65\x20\x68\x61\x73\x68\x65\x64\x20\x62\x65\x66\x6f\x72\x65\x20\x62\x65\x69\x6e\x67\x20\x75\x73\x65\x64\x20\x62\x79\x20\x74\x68\x65\x20\x48\x4d\x41\x43\x20\x61\x6c\x67\x6f\x72\x69\x74\x68\x6d\x2e"
871 };
872 static const unsigned char outputs[6][32] = {
873 {0xb0, 0x34, 0x4c, 0x61, 0xd8, 0xdb, 0x38, 0x53, 0x5c, 0xa8, 0xaf, 0xce, 0xaf, 0x0b, 0xf1, 0x2b, 0x88, 0x1d, 0xc2, 0x00, 0xc9, 0x83, 0x3d, 0xa7, 0x26, 0xe9, 0x37, 0x6c, 0x2e, 0x32, 0xcf, 0xf7},
874 {0x5b, 0xdc, 0xc1, 0x46, 0xbf, 0x60, 0x75, 0x4e, 0x6a, 0x04, 0x24, 0x26, 0x08, 0x95, 0x75, 0xc7, 0x5a, 0x00, 0x3f, 0x08, 0x9d, 0x27, 0x39, 0x83, 0x9d, 0xec, 0x58, 0xb9, 0x64, 0xec, 0x38, 0x43},
875 {0x77, 0x3e, 0xa9, 0x1e, 0x36, 0x80, 0x0e, 0x46, 0x85, 0x4d, 0xb8, 0xeb, 0xd0, 0x91, 0x81, 0xa7, 0x29, 0x59, 0x09, 0x8b, 0x3e, 0xf8, 0xc1, 0x22, 0xd9, 0x63, 0x55, 0x14, 0xce, 0xd5, 0x65, 0xfe},
876 {0x82, 0x55, 0x8a, 0x38, 0x9a, 0x44, 0x3c, 0x0e, 0xa4, 0xcc, 0x81, 0x98, 0x99, 0xf2, 0x08, 0x3a, 0x85, 0xf0, 0xfa, 0xa3, 0xe5, 0x78, 0xf8, 0x07, 0x7a, 0x2e, 0x3f, 0xf4, 0x67, 0x29, 0x66, 0x5b},
877 {0x60, 0xe4, 0x31, 0x59, 0x1e, 0xe0, 0xb6, 0x7f, 0x0d, 0x8a, 0x26, 0xaa, 0xcb, 0xf5, 0xb7, 0x7f, 0x8e, 0x0b, 0xc6, 0x21, 0x37, 0x28, 0xc5, 0x14, 0x05, 0x46, 0x04, 0x0f, 0x0e, 0xe3, 0x7f, 0x54},
878 {0x9b, 0x09, 0xff, 0xa7, 0x1b, 0x94, 0x2f, 0xcb, 0x27, 0x63, 0x5f, 0xbc, 0xd5, 0xb0, 0xe9, 0x44, 0xbf, 0xdc, 0x63, 0x64, 0x4f, 0x07, 0x13, 0x93, 0x8a, 0x7f, 0x51, 0x53, 0x5c, 0x3a, 0x35, 0xe2}
879 };
880 int i;
882 for (i = 0; i < 6; i++) {
884 unsigned char out[32];
885 secp256k1_hmac_sha256_initialize(hash_ctx, &hasher, (const unsigned char*)(keys[i]), strlen(keys[i]));
886 secp256k1_hmac_sha256_write(hash_ctx, &hasher, (const unsigned char*)(inputs[i]), strlen(inputs[i]));
887 secp256k1_hmac_sha256_finalize(hash_ctx, &hasher, out);
888 CHECK(secp256k1_memcmp_var(out, outputs[i], 32) == 0);
889 if (strlen(inputs[i]) > 0) {
890 int split = testrand_int(strlen(inputs[i]));
891 secp256k1_hmac_sha256_initialize(hash_ctx, &hasher, (const unsigned char*)(keys[i]), strlen(keys[i]));
892 secp256k1_hmac_sha256_write(hash_ctx, &hasher, (const unsigned char*)(inputs[i]), split);
893 secp256k1_hmac_sha256_write(hash_ctx, &hasher, (const unsigned char*)(inputs[i] + split), strlen(inputs[i]) - split);
894 secp256k1_hmac_sha256_finalize(hash_ctx, &hasher, out);
895 CHECK(secp256k1_memcmp_var(out, outputs[i], 32) == 0);
896 }
897 }
898}
899
901 static const unsigned char key1[65] = {0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f, 0x00, 0x4b, 0xf5, 0x12, 0x2f, 0x34, 0x45, 0x54, 0xc5, 0x3b, 0xde, 0x2e, 0xbb, 0x8c, 0xd2, 0xb7, 0xe3, 0xd1, 0x60, 0x0a, 0xd6, 0x31, 0xc3, 0x85, 0xa5, 0xd7, 0xcc, 0xe2, 0x3c, 0x77, 0x85, 0x45, 0x9a, 0};
902 static const unsigned char out1[3][32] = {
903 {0x4f, 0xe2, 0x95, 0x25, 0xb2, 0x08, 0x68, 0x09, 0x15, 0x9a, 0xcd, 0xf0, 0x50, 0x6e, 0xfb, 0x86, 0xb0, 0xec, 0x93, 0x2c, 0x7b, 0xa4, 0x42, 0x56, 0xab, 0x32, 0x1e, 0x42, 0x1e, 0x67, 0xe9, 0xfb},
904 {0x2b, 0xf0, 0xff, 0xf1, 0xd3, 0xc3, 0x78, 0xa2, 0x2d, 0xc5, 0xde, 0x1d, 0x85, 0x65, 0x22, 0x32, 0x5c, 0x65, 0xb5, 0x04, 0x49, 0x1a, 0x0c, 0xbd, 0x01, 0xcb, 0x8f, 0x3a, 0xa6, 0x7f, 0xfd, 0x4a},
905 {0xf5, 0x28, 0xb4, 0x10, 0xcb, 0x54, 0x1f, 0x77, 0x00, 0x0d, 0x7a, 0xfb, 0x6c, 0x5b, 0x53, 0xc5, 0xc4, 0x71, 0xea, 0xb4, 0x3e, 0x46, 0x6d, 0x9a, 0xc5, 0x19, 0x0c, 0x39, 0xc8, 0x2f, 0xd8, 0x2e}
906 };
907
908 static const unsigned char key2[64] = {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xe3, 0xb0, 0xc4, 0x42, 0x98, 0xfc, 0x1c, 0x14, 0x9a, 0xfb, 0xf4, 0xc8, 0x99, 0x6f, 0xb9, 0x24, 0x27, 0xae, 0x41, 0xe4, 0x64, 0x9b, 0x93, 0x4c, 0xa4, 0x95, 0x99, 0x1b, 0x78, 0x52, 0xb8, 0x55};
909 static const unsigned char out2[3][32] = {
910 {0x9c, 0x23, 0x6c, 0x16, 0x5b, 0x82, 0xae, 0x0c, 0xd5, 0x90, 0x65, 0x9e, 0x10, 0x0b, 0x6b, 0xab, 0x30, 0x36, 0xe7, 0xba, 0x8b, 0x06, 0x74, 0x9b, 0xaf, 0x69, 0x81, 0xe1, 0x6f, 0x1a, 0x2b, 0x95},
911 {0xdf, 0x47, 0x10, 0x61, 0x62, 0x5b, 0xc0, 0xea, 0x14, 0xb6, 0x82, 0xfe, 0xee, 0x2c, 0x9c, 0x02, 0xf2, 0x35, 0xda, 0x04, 0x20, 0x4c, 0x1d, 0x62, 0xa1, 0x53, 0x6c, 0x6e, 0x17, 0xae, 0xd7, 0xa9},
912 {0x75, 0x97, 0x88, 0x7c, 0xbd, 0x76, 0x32, 0x1f, 0x32, 0xe3, 0x04, 0x40, 0x67, 0x9a, 0x22, 0xcf, 0x7f, 0x8d, 0x9d, 0x2e, 0xac, 0x39, 0x0e, 0x58, 0x1f, 0xea, 0x09, 0x1c, 0xe2, 0x02, 0xba, 0x94}
913 };
914
917 unsigned char out[32];
918 int i;
919
920 secp256k1_rfc6979_hmac_sha256_initialize(hash_ctx, &rng, key1, 64);
921 for (i = 0; i < 3; i++) {
923 CHECK(secp256k1_memcmp_var(out, out1[i], 32) == 0);
924 }
926
927 secp256k1_rfc6979_hmac_sha256_initialize(hash_ctx, &rng, key1, 65);
928 for (i = 0; i < 3; i++) {
930 CHECK(secp256k1_memcmp_var(out, out1[i], 32) != 0);
931 }
933
934 secp256k1_rfc6979_hmac_sha256_initialize(hash_ctx, &rng, key2, 64);
935 for (i = 0; i < 3; i++) {
937 CHECK(secp256k1_memcmp_var(out, out2[i], 32) == 0);
938 }
940}
941
942static void run_tagged_sha256_tests(void) {
943 unsigned char tag[32] = { 0 };
944 unsigned char msg[32] = { 0 };
945 unsigned char hash32[32];
946 unsigned char hash_expected[32] = {
947 0x04, 0x7A, 0x5E, 0x17, 0xB5, 0x86, 0x47, 0xC1,
948 0x3C, 0xC6, 0xEB, 0xC0, 0xAA, 0x58, 0x3B, 0x62,
949 0xFB, 0x16, 0x43, 0x32, 0x68, 0x77, 0x40, 0x6C,
950 0xE2, 0x76, 0x55, 0x9A, 0x3B, 0xDE, 0x55, 0xB3
951 };
952
953 /* API test */
954 CHECK(secp256k1_tagged_sha256(CTX, hash32, tag, sizeof(tag), msg, sizeof(msg)) == 1);
955 CHECK_ILLEGAL(CTX, secp256k1_tagged_sha256(CTX, NULL, tag, sizeof(tag), msg, sizeof(msg)));
956 CHECK_ILLEGAL(CTX, secp256k1_tagged_sha256(CTX, hash32, NULL, 0, msg, sizeof(msg)));
957 CHECK_ILLEGAL(CTX, secp256k1_tagged_sha256(CTX, hash32, tag, sizeof(tag), NULL, 0));
958
959 /* Static test vector */
960 memcpy(tag, "tag", 3);
961 memcpy(msg, "msg", 3);
962 CHECK(secp256k1_tagged_sha256(CTX, hash32, tag, 3, msg, 3) == 1);
963 CHECK(secp256k1_memcmp_var(hash32, hash_expected, sizeof(hash32)) == 0);
964}
965
967 /* Midstate for the tagged hash with tag "sha256_midstate_test_tag". */
968 static const unsigned char tag[] = "sha256_midstate_test_tag";
969 static const uint32_t midstate[8] = {
970 0xa9ec59eaul, 0x9b4c2ffful, 0x400821e2ul, 0x0dcf3847ul,
971 0xbe7ea179ul, 0xa5772bdcul, 0x7d29bfe3ul, 0xa486b855ul
972 };
975
976 secp256k1_sha256_initialize_midstate(&sha, 64, midstate);
977 test_sha256_tag_midstate(hash_ctx, &sha, tag, sizeof(tag) - 1);
978}
979
980/***** MODINV TESTS *****/
981
982/* Compute the modular inverse of (odd) x mod 2^64. */
983static uint64_t modinv2p64(uint64_t x) {
984 /* If w = 1/x mod 2^(2^L), then w*(2 - w*x) = 1/x mod 2^(2^(L+1)). See
985 * Hacker's Delight second edition, Henry S. Warren, Jr., pages 245-247 for
986 * why. Start with L=0, for which it is true for every odd x that
987 * 1/x=1 mod 2. Iterating 6 times gives us 1/x mod 2^64. */
988 int l;
989 uint64_t w = 1;
990 CHECK(x & 1);
991 for (l = 0; l < 6; ++l) w *= (2 - w*x);
992 return w;
993}
994
995
996/* compute out = (a*b) mod m; if b=NULL, treat b=1; if m=NULL, treat m=infinity.
997 *
998 * Out is a 512-bit number (represented as 32 uint16_t's in LE order). The other
999 * arguments are 256-bit numbers (represented as 16 uint16_t's in LE order). */
1000static void mulmod256(uint16_t* out, const uint16_t* a, const uint16_t* b, const uint16_t* m) {
1001 uint16_t mul[32];
1002 uint64_t c = 0;
1003 int i, j;
1004 int m_bitlen = 0;
1005 int mul_bitlen = 0;
1006
1007 if (b != NULL) {
1008 /* Compute the product of a and b, and put it in mul. */
1009 for (i = 0; i < 32; ++i) {
1010 for (j = i <= 15 ? 0 : i - 15; j <= i && j <= 15; j++) {
1011 c += (uint64_t)a[j] * b[i - j];
1012 }
1013 mul[i] = c & 0xFFFF;
1014 c >>= 16;
1015 }
1016 CHECK(c == 0);
1017
1018 /* compute the highest set bit in mul */
1019 for (i = 511; i >= 0; --i) {
1020 if ((mul[i >> 4] >> (i & 15)) & 1) {
1021 mul_bitlen = i;
1022 break;
1023 }
1024 }
1025 } else {
1026 /* if b==NULL, set mul=a. */
1027 memcpy(mul, a, 32);
1028 memset(mul + 16, 0, 32);
1029 /* compute the highest set bit in mul */
1030 for (i = 255; i >= 0; --i) {
1031 if ((mul[i >> 4] >> (i & 15)) & 1) {
1032 mul_bitlen = i;
1033 break;
1034 }
1035 }
1036 }
1037
1038 if (m) {
1039 /* Compute the highest set bit in m. */
1040 for (i = 255; i >= 0; --i) {
1041 if ((m[i >> 4] >> (i & 15)) & 1) {
1042 m_bitlen = i;
1043 break;
1044 }
1045 }
1046
1047 /* Try do mul -= m<<i, for i going down to 0, whenever the result is not negative */
1048 for (i = mul_bitlen - m_bitlen; i >= 0; --i) {
1049 uint16_t mul2[32];
1050 int64_t cs;
1051
1052 /* Compute mul2 = mul - m<<i. */
1053 cs = 0; /* accumulator */
1054 for (j = 0; j < 32; ++j) { /* j loops over the output limbs in mul2. */
1055 /* Compute sub: the 16 bits in m that will be subtracted from mul2[j]. */
1056 uint16_t sub = 0;
1057 int p;
1058 for (p = 0; p < 16; ++p) { /* p loops over the bit positions in mul2[j]. */
1059 int bitpos = j * 16 - i + p; /* bitpos is the correspond bit position in m. */
1060 if (bitpos >= 0 && bitpos < 256) {
1061 sub |= ((m[bitpos >> 4] >> (bitpos & 15)) & 1) << p;
1062 }
1063 }
1064 /* Add mul[j]-sub to accumulator, and shift bottom 16 bits out to mul2[j]. */
1065 cs += mul[j];
1066 cs -= sub;
1067 mul2[j] = (cs & 0xFFFF);
1068 cs >>= 16;
1069 }
1070 /* If remainder of subtraction is 0, set mul = mul2. */
1071 if (cs == 0) {
1072 memcpy(mul, mul2, sizeof(mul));
1073 }
1074 }
1075 /* Sanity check: test that all limbs higher than m's highest are zero */
1076 for (i = (m_bitlen >> 4) + 1; i < 32; ++i) {
1077 CHECK(mul[i] == 0);
1078 }
1079 }
1080 memcpy(out, mul, 32);
1081}
1082
1083/* Convert a 256-bit number represented as 16 uint16_t's to signed30 notation. */
1084static void uint16_to_signed30(secp256k1_modinv32_signed30* out, const uint16_t* in) {
1085 int i;
1086 memset(out->v, 0, sizeof(out->v));
1087 for (i = 0; i < 256; ++i) {
1088 out->v[i / 30] |= (int32_t)(((in[i >> 4]) >> (i & 15)) & 1) << (i % 30);
1089 }
1090}
1091
1092/* Convert a 256-bit number in signed30 notation to a representation as 16 uint16_t's. */
1093static void signed30_to_uint16(uint16_t* out, const secp256k1_modinv32_signed30* in) {
1094 int i;
1095 memset(out, 0, 32);
1096 for (i = 0; i < 256; ++i) {
1097 out[i >> 4] |= (((in->v[i / 30]) >> (i % 30)) & 1) << (i & 15);
1098 }
1099}
1100
1101/* Randomly mutate the sign of limbs in signed30 representation, without changing the value. */
1103 int i;
1104 for (i = 0; i < 16; ++i) {
1105 int pos = testrand_bits(3);
1106 if (x->v[pos] > 0 && x->v[pos + 1] <= 0x3fffffff) {
1107 x->v[pos] -= 0x40000000;
1108 x->v[pos + 1] += 1;
1109 } else if (x->v[pos] < 0 && x->v[pos + 1] >= 0x3fffffff) {
1110 x->v[pos] += 0x40000000;
1111 x->v[pos + 1] -= 1;
1112 }
1113 }
1114}
1115
1116/* Test secp256k1_modinv32{_var}, using inputs in 16-bit limb format, and returning inverse. */
1117static void test_modinv32_uint16(uint16_t* out, const uint16_t* in, const uint16_t* mod) {
1118 uint16_t tmp[16];
1121 int i, vartime, nonzero;
1122
1123 uint16_to_signed30(&x, in);
1124 nonzero = (x.v[0] | x.v[1] | x.v[2] | x.v[3] | x.v[4] | x.v[5] | x.v[6] | x.v[7] | x.v[8]) != 0;
1125 uint16_to_signed30(&m.modulus, mod);
1126
1127 /* compute 1/modulus mod 2^30 */
1128 m.modulus_inv30 = modinv2p64(m.modulus.v[0]) & 0x3fffffff;
1129 CHECK(((m.modulus_inv30 * m.modulus.v[0]) & 0x3fffffff) == 1);
1130
1131 /* Test secp256k1_jacobi32_maybe_var. */
1132 if (nonzero) {
1133 int jac;
1134 uint16_t sqr[16], negone[16];
1135 mulmod256(sqr, in, in, mod);
1136 uint16_to_signed30(&x, sqr);
1137 /* Compute jacobi symbol of in^2, which must be 1 (or uncomputable). */
1138 jac = secp256k1_jacobi32_maybe_var(&x, &m);
1139 CHECK(jac == 0 || jac == 1);
1140 /* Then compute the jacobi symbol of -(in^2). x and -x have opposite
1141 * jacobi symbols if and only if (mod % 4) == 3. */
1142 negone[0] = mod[0] - 1;
1143 for (i = 1; i < 16; ++i) negone[i] = mod[i];
1144 mulmod256(sqr, sqr, negone, mod);
1145 uint16_to_signed30(&x, sqr);
1146 jac = secp256k1_jacobi32_maybe_var(&x, &m);
1147 CHECK(jac == 0 || jac == 1 - (mod[0] & 2));
1148 }
1149
1150 uint16_to_signed30(&x, in);
1151 mutate_sign_signed30(&m.modulus);
1152 for (vartime = 0; vartime < 2; ++vartime) {
1153 /* compute inverse */
1154 (vartime ? secp256k1_modinv32_var : secp256k1_modinv32)(&x, &m);
1155
1156 /* produce output */
1158
1159 /* check if the inverse times the input is 1 (mod m), unless x is 0. */
1160 mulmod256(tmp, out, in, mod);
1161 CHECK(tmp[0] == nonzero);
1162 for (i = 1; i < 16; ++i) CHECK(tmp[i] == 0);
1163
1164 /* invert again */
1165 (vartime ? secp256k1_modinv32_var : secp256k1_modinv32)(&x, &m);
1166
1167 /* check if the result is equal to the input */
1168 signed30_to_uint16(tmp, &x);
1169 for (i = 0; i < 16; ++i) CHECK(tmp[i] == in[i]);
1170 }
1171}
1172
1173#ifdef SECP256K1_WIDEMUL_INT128
1174/* Convert a 256-bit number represented as 16 uint16_t's to signed62 notation. */
1175static void uint16_to_signed62(secp256k1_modinv64_signed62* out, const uint16_t* in) {
1176 int i;
1177 memset(out->v, 0, sizeof(out->v));
1178 for (i = 0; i < 256; ++i) {
1179 out->v[i / 62] |= (int64_t)(((in[i >> 4]) >> (i & 15)) & 1) << (i % 62);
1180 }
1181}
1182
1183/* Convert a 256-bit number in signed62 notation to a representation as 16 uint16_t's. */
1184static void signed62_to_uint16(uint16_t* out, const secp256k1_modinv64_signed62* in) {
1185 int i;
1186 memset(out, 0, 32);
1187 for (i = 0; i < 256; ++i) {
1188 out[i >> 4] |= (((in->v[i / 62]) >> (i % 62)) & 1) << (i & 15);
1189 }
1190}
1191
1192/* Randomly mutate the sign of limbs in signed62 representation, without changing the value. */
1193static void mutate_sign_signed62(secp256k1_modinv64_signed62* x) {
1194 static const int64_t M62 = (int64_t)(UINT64_MAX >> 2);
1195 int i;
1196 for (i = 0; i < 8; ++i) {
1197 int pos = testrand_bits(2);
1198 if (x->v[pos] > 0 && x->v[pos + 1] <= M62) {
1199 x->v[pos] -= (M62 + 1);
1200 x->v[pos + 1] += 1;
1201 } else if (x->v[pos] < 0 && x->v[pos + 1] >= -M62) {
1202 x->v[pos] += (M62 + 1);
1203 x->v[pos + 1] -= 1;
1204 }
1205 }
1206}
1207
1208/* Test secp256k1_modinv64{_var}, using inputs in 16-bit limb format, and returning inverse. */
1209static void test_modinv64_uint16(uint16_t* out, const uint16_t* in, const uint16_t* mod) {
1210 static const int64_t M62 = (int64_t)(UINT64_MAX >> 2);
1211 uint16_t tmp[16];
1214 int i, vartime, nonzero;
1215
1216 uint16_to_signed62(&x, in);
1217 nonzero = (x.v[0] | x.v[1] | x.v[2] | x.v[3] | x.v[4]) != 0;
1218 uint16_to_signed62(&m.modulus, mod);
1219
1220 /* compute 1/modulus mod 2^62 */
1221 m.modulus_inv62 = modinv2p64(m.modulus.v[0]) & M62;
1222 CHECK(((m.modulus_inv62 * m.modulus.v[0]) & M62) == 1);
1223
1224 /* Test secp256k1_jacobi64_maybe_var. */
1225 if (nonzero) {
1226 int jac;
1227 uint16_t sqr[16], negone[16];
1228 mulmod256(sqr, in, in, mod);
1229 uint16_to_signed62(&x, sqr);
1230 /* Compute jacobi symbol of in^2, which must be 1 (or uncomputable). */
1231 jac = secp256k1_jacobi64_maybe_var(&x, &m);
1232 CHECK(jac == 0 || jac == 1);
1233 /* Then compute the jacobi symbol of -(in^2). x and -x have opposite
1234 * jacobi symbols if and only if (mod % 4) == 3. */
1235 negone[0] = mod[0] - 1;
1236 for (i = 1; i < 16; ++i) negone[i] = mod[i];
1237 mulmod256(sqr, sqr, negone, mod);
1238 uint16_to_signed62(&x, sqr);
1239 jac = secp256k1_jacobi64_maybe_var(&x, &m);
1240 CHECK(jac == 0 || jac == 1 - (mod[0] & 2));
1241 }
1242
1243 uint16_to_signed62(&x, in);
1244 mutate_sign_signed62(&m.modulus);
1245 for (vartime = 0; vartime < 2; ++vartime) {
1246 /* compute inverse */
1247 (vartime ? secp256k1_modinv64_var : secp256k1_modinv64)(&x, &m);
1248
1249 /* produce output */
1250 signed62_to_uint16(out, &x);
1251
1252 /* check if the inverse times the input is 1 (mod m), unless x is 0. */
1253 mulmod256(tmp, out, in, mod);
1254 CHECK(tmp[0] == nonzero);
1255 for (i = 1; i < 16; ++i) CHECK(tmp[i] == 0);
1256
1257 /* invert again */
1258 (vartime ? secp256k1_modinv64_var : secp256k1_modinv64)(&x, &m);
1259
1260 /* check if the result is equal to the input */
1261 signed62_to_uint16(tmp, &x);
1262 for (i = 0; i < 16; ++i) CHECK(tmp[i] == in[i]);
1263 }
1264}
1265#endif
1266
1267/* test if a and b are coprime */
1268static int coprime(const uint16_t* a, const uint16_t* b) {
1269 uint16_t x[16], y[16], t[16];
1270 int i;
1271 int iszero;
1272 memcpy(x, a, 32);
1273 memcpy(y, b, 32);
1274
1275 /* simple gcd loop: while x!=0, (x,y)=(y%x,x) */
1276 while (1) {
1277 iszero = 1;
1278 for (i = 0; i < 16; ++i) {
1279 if (x[i] != 0) {
1280 iszero = 0;
1281 break;
1282 }
1283 }
1284 if (iszero) break;
1285 mulmod256(t, y, NULL, x);
1286 memcpy(y, x, 32);
1287 memcpy(x, t, 32);
1288 }
1289
1290 /* return whether y=1 */
1291 if (y[0] != 1) return 0;
1292 for (i = 1; i < 16; ++i) {
1293 if (y[i] != 0) return 0;
1294 }
1295 return 1;
1296}
1297
1298static void run_modinv_tests(void) {
1299 /* Fixed test cases. Each tuple is (input, modulus, output), each as 16x16 bits in LE order. */
1300 static const uint16_t CASES[][3][16] = {
1301 /* Test cases triggering edge cases in divsteps */
1302
1303 /* Test case known to need 713 divsteps */
1304 {{0x1513, 0x5389, 0x54e9, 0x2798, 0x1957, 0x66a0, 0x8057, 0x3477,
1305 0x7784, 0x1052, 0x326a, 0x9331, 0x6506, 0xa95c, 0x91f3, 0xfb5e},
1306 {0x2bdd, 0x8df4, 0xcc61, 0x481f, 0xdae5, 0x5ca7, 0xf43b, 0x7d54,
1307 0x13d6, 0x469b, 0x2294, 0x20f4, 0xb2a4, 0xa2d1, 0x3ff1, 0xfd4b},
1308 {0xffd8, 0xd9a0, 0x456e, 0x81bb, 0xbabd, 0x6cea, 0x6dbd, 0x73ab,
1309 0xbb94, 0x3d3c, 0xdf08, 0x31c4, 0x3e32, 0xc179, 0x2486, 0xb86b}},
1310 /* Test case known to need 589 divsteps, reaching delta=-140 and
1311 delta=141. */
1312 {{0x3fb1, 0x903b, 0x4eb7, 0x4813, 0xd863, 0x26bf, 0xd89f, 0xa8a9,
1313 0x02fe, 0x57c6, 0x554a, 0x4eab, 0x165e, 0x3d61, 0xee1e, 0x456c},
1314 {0x9295, 0x823b, 0x5c1f, 0x5386, 0x48e0, 0x02ff, 0x4c2a, 0xa2da,
1315 0xe58f, 0x967c, 0xc97e, 0x3f5a, 0x69fb, 0x52d9, 0x0a86, 0xb4a3},
1316 {0x3d30, 0xb893, 0xa809, 0xa7a8, 0x26f5, 0x5b42, 0x55be, 0xf4d0,
1317 0x12c2, 0x7e6a, 0xe41a, 0x90c7, 0xebfa, 0xf920, 0x304e, 0x1419}},
1318 /* Test case known to need 650 divsteps, and doing 65 consecutive (f,g/2) steps. */
1319 {{0x8583, 0x5058, 0xbeae, 0xeb69, 0x48bc, 0x52bb, 0x6a9d, 0xcc94,
1320 0x2a21, 0x87d5, 0x5b0d, 0x42f6, 0x5b8a, 0x2214, 0xe9d6, 0xa040},
1321 {0x7531, 0x27cb, 0x7e53, 0xb739, 0x6a5f, 0x83f5, 0xa45c, 0xcb1d,
1322 0x8a87, 0x1c9c, 0x51d7, 0x851c, 0xb9d8, 0x1fbe, 0xc241, 0xd4a3},
1323 {0xcdb4, 0x275c, 0x7d22, 0xa906, 0x0173, 0xc054, 0x7fdf, 0x5005,
1324 0x7fb8, 0x9059, 0xdf51, 0x99df, 0x2654, 0x8f6e, 0x070f, 0xb347}},
1325 /* example needing 713 divsteps; delta=-2..3 */
1326 {{0xe2e9, 0xee91, 0x4345, 0xe5ad, 0xf3ec, 0x8f42, 0x0364, 0xd5c9,
1327 0xff49, 0xbef5, 0x4544, 0x4c7c, 0xae4b, 0xfd9d, 0xb35b, 0xda9d},
1328 {0x36e7, 0x8cca, 0x2ed0, 0x47b3, 0xaca4, 0xb374, 0x7d2a, 0x0772,
1329 0x6bdb, 0xe0a7, 0x900b, 0xfe10, 0x788c, 0x6f22, 0xd909, 0xf298},
1330 {0xd8c6, 0xba39, 0x13ed, 0x198c, 0x16c8, 0xb837, 0xa5f2, 0x9797,
1331 0x0113, 0x882a, 0x15b5, 0x324c, 0xabee, 0xe465, 0x8170, 0x85ac}},
1332 /* example needing 713 divsteps; delta=-2..3 */
1333 {{0xd5b7, 0x2966, 0x040e, 0xf59a, 0x0387, 0xd96d, 0xbfbc, 0xd850,
1334 0x2d96, 0x872a, 0xad81, 0xc03c, 0xbb39, 0xb7fa, 0xd904, 0xef78},
1335 {0x6279, 0x4314, 0xfdd3, 0x1568, 0x0982, 0x4d13, 0x625f, 0x010c,
1336 0x22b1, 0x0cc3, 0xf22d, 0x5710, 0x1109, 0x5751, 0x7714, 0xfcf2},
1337 {0xdb13, 0x5817, 0x232e, 0xe456, 0xbbbc, 0x6fbe, 0x4572, 0xa358,
1338 0xc76d, 0x928e, 0x0162, 0x5314, 0x8325, 0x5683, 0xe21b, 0xda88}},
1339 /* example needing 713 divsteps; delta=-2..3 */
1340 {{0xa06f, 0x71ee, 0x3bac, 0x9ebb, 0xdeaa, 0x09ed, 0x1cf7, 0x9ec9,
1341 0x7158, 0x8b72, 0x5d53, 0x5479, 0x5c75, 0xbb66, 0x9125, 0xeccc},
1342 {0x2941, 0xd46c, 0x3cd4, 0x4a9d, 0x5c4a, 0x256b, 0xbd6c, 0x9b8e,
1343 0x8fe0, 0x8a14, 0xffe8, 0x2496, 0x618d, 0xa9d7, 0x5018, 0xfb29},
1344 {0x437c, 0xbd60, 0x7590, 0x94bb, 0x0095, 0xd35e, 0xd4fe, 0xd6da,
1345 0x0d4e, 0x5342, 0x4cd2, 0x169b, 0x661c, 0x1380, 0xed2d, 0x85c1}},
1346 /* example reaching delta=-64..65; 661 divsteps */
1347 {{0xfde4, 0x68d6, 0x6c48, 0x7f77, 0x1c78, 0x96de, 0x2fd9, 0xa6c2,
1348 0xbbb5, 0xd319, 0x69cf, 0xd4b3, 0xa321, 0xcda0, 0x172e, 0xe530},
1349 {0xd9e3, 0x0f60, 0x3d86, 0xeeab, 0x25ee, 0x9582, 0x2d50, 0xfe16,
1350 0xd4e2, 0xe3ba, 0x94e2, 0x9833, 0x6c5e, 0x8982, 0x13b6, 0xe598},
1351 {0xe675, 0xf55a, 0x10f6, 0xabde, 0x5113, 0xecaa, 0x61ae, 0xad9f,
1352 0x0c27, 0xef33, 0x62e5, 0x211d, 0x08fa, 0xa78d, 0xc675, 0x8bae}},
1353 /* example reaching delta=-64..65; 661 divsteps */
1354 {{0x21bf, 0x52d5, 0x8fd4, 0xaa18, 0x156a, 0x7247, 0xebb8, 0x5717,
1355 0x4eb5, 0x1421, 0xb58f, 0x3b0b, 0x5dff, 0xe533, 0xb369, 0xd28a},
1356 {0x9f6b, 0xe463, 0x2563, 0xc74d, 0x6d81, 0x636a, 0x8fc8, 0x7a94,
1357 0x9429, 0x1585, 0xf35e, 0x7ff5, 0xb64f, 0x9720, 0xba74, 0xe108},
1358 {0xa5ab, 0xea7b, 0xfe5e, 0x8a85, 0x13be, 0x7934, 0xe8a0, 0xa187,
1359 0x86b5, 0xe477, 0xb9a4, 0x75d7, 0x538f, 0xdd70, 0xc781, 0xb67d}},
1360 /* example reaching delta=-64..65; 661 divsteps */
1361 {{0xa41a, 0x3e8d, 0xf1f5, 0x9493, 0x868c, 0x5103, 0x2725, 0x3ceb,
1362 0x6032, 0x3624, 0xdc6b, 0x9120, 0xbf4c, 0x8821, 0x91ad, 0xb31a},
1363 {0x5c0b, 0xdda5, 0x20f8, 0x32a1, 0xaf73, 0x6ec5, 0x4779, 0x43d6,
1364 0xd454, 0x9573, 0xbf84, 0x5a58, 0xe04e, 0x307e, 0xd1d5, 0xe230},
1365 {0xda15, 0xbcd6, 0x7180, 0xabd3, 0x04e6, 0x6986, 0xc0d7, 0x90bb,
1366 0x3a4d, 0x7c95, 0xaaab, 0x9ab3, 0xda34, 0xa7f6, 0x9636, 0x6273}},
1367 /* example doing 123 consecutive (f,g/2) steps; 615 divsteps */
1368 {{0xb4d6, 0xb38f, 0x00aa, 0xebda, 0xd4c2, 0x70b8, 0x9dad, 0x58ee,
1369 0x68f8, 0x48d3, 0xb5ff, 0xf422, 0x9e46, 0x2437, 0x18d0, 0xd9cc},
1370 {0x5c83, 0xfed7, 0x97f5, 0x3f07, 0xcaad, 0x95b1, 0xb4a4, 0xb005,
1371 0x23af, 0xdd27, 0x6c0d, 0x932c, 0xe2b2, 0xe3ae, 0xfb96, 0xdf67},
1372 {0x3105, 0x0127, 0xfd48, 0x039b, 0x35f1, 0xbc6f, 0x6c0a, 0xb572,
1373 0xe4df, 0xebad, 0x8edc, 0xb89d, 0x9555, 0x4c26, 0x1fef, 0x997c}},
1374 /* example doing 123 consecutive (f,g/2) steps; 614 divsteps */
1375 {{0x5138, 0xd474, 0x385f, 0xc964, 0x00f2, 0x6df7, 0x862d, 0xb185,
1376 0xb264, 0xe9e1, 0x466c, 0xf39e, 0xafaf, 0x5f41, 0x47e2, 0xc89d},
1377 {0x8607, 0x9c81, 0x46a2, 0x7dcc, 0xcb0c, 0x9325, 0xe149, 0x2bde,
1378 0x6632, 0x2869, 0xa261, 0xb163, 0xccee, 0x22ae, 0x91e0, 0xcfd5},
1379 {0x831c, 0xda22, 0xb080, 0xba7a, 0x26e2, 0x54b0, 0x073b, 0x5ea0,
1380 0xed4b, 0xcb3d, 0xbba1, 0xbec8, 0xf2ad, 0xae0d, 0x349b, 0x17d1}},
1381 /* example doing 123 consecutive (f,g/2) steps; 614 divsteps */
1382 {{0xe9a5, 0xb4ad, 0xd995, 0x9953, 0xcdff, 0x50d7, 0xf715, 0x9dc7,
1383 0x3e28, 0x15a9, 0x95a3, 0x8554, 0x5b5e, 0xad1d, 0x6d57, 0x3d50},
1384 {0x3ad9, 0xbd60, 0x5cc7, 0x6b91, 0xadeb, 0x71f6, 0x7cc4, 0xa58a,
1385 0x2cce, 0xf17c, 0x38c9, 0x97ed, 0x65fb, 0x3fa6, 0xa6bc, 0xeb24},
1386 {0xf96c, 0x1963, 0x8151, 0xa0cc, 0x299b, 0xf277, 0x001a, 0x16bb,
1387 0xfd2e, 0x532d, 0x0410, 0xe117, 0x6b00, 0x44ec, 0xca6a, 0x1745}},
1388 /* example doing 446 (f,g/2) steps; 523 divsteps */
1389 {{0x3758, 0xa56c, 0xe41e, 0x4e47, 0x0975, 0xa82b, 0x107c, 0x89cf,
1390 0x2093, 0x5a0c, 0xda37, 0xe007, 0x6074, 0x4f68, 0x2f5a, 0xbb8a},
1391 {0x4beb, 0xa40f, 0x2c42, 0xd9d6, 0x97e8, 0xca7c, 0xd395, 0x894f,
1392 0x1f50, 0x8067, 0xa233, 0xb850, 0x1746, 0x1706, 0xbcda, 0xdf32},
1393 {0x762a, 0xceda, 0x4c45, 0x1ca0, 0x8c37, 0xd8c5, 0xef57, 0x7a2c,
1394 0x6e98, 0xe38a, 0xc50e, 0x2ca9, 0xcb85, 0x24d5, 0xc29c, 0x61f6}},
1395 /* example doing 446 (f,g/2) steps; 523 divsteps */
1396 {{0x6f38, 0x74ad, 0x7332, 0x4073, 0x6521, 0xb876, 0xa370, 0xa6bd,
1397 0xcea5, 0xbd06, 0x969f, 0x77c6, 0x1e69, 0x7c49, 0x7d51, 0xb6e7},
1398 {0x3f27, 0x4be4, 0xd81e, 0x1396, 0xb21f, 0x92aa, 0x6dc3, 0x6283,
1399 0x6ada, 0x3ca2, 0xc1e5, 0x8b9b, 0xd705, 0x5598, 0x8ba1, 0xe087},
1400 {0x6a22, 0xe834, 0xbc8d, 0xcee9, 0x42fc, 0xfc77, 0x9c45, 0x1ca8,
1401 0xeb66, 0xed74, 0xaaf9, 0xe75f, 0xfe77, 0x46d2, 0x179b, 0xbf3e}},
1402 /* example doing 336 (f,(f+g)/2) steps; 693 divsteps */
1403 {{0x7ea7, 0x444e, 0x84ea, 0xc447, 0x7c1f, 0xab97, 0x3de6, 0x5878,
1404 0x4e8b, 0xc017, 0x03e0, 0xdc40, 0xbbd0, 0x74ce, 0x0169, 0x7ab5},
1405 {0x4023, 0x154f, 0xfbe4, 0x8195, 0xfda0, 0xef54, 0x9e9a, 0xc703,
1406 0x2803, 0xf760, 0x6302, 0xed5b, 0x7157, 0x6456, 0xdd7d, 0xf14b},
1407 {0xb6fb, 0xe3b3, 0x0733, 0xa77e, 0x44c5, 0x3003, 0xc937, 0xdd4d,
1408 0x5355, 0x14e9, 0x184e, 0xcefe, 0xe6b5, 0xf2e0, 0x0a28, 0x5b74}},
1409 /* example doing 336 (f,(f+g)/2) steps; 687 divsteps */
1410 {{0xa893, 0xb5f4, 0x1ede, 0xa316, 0x242c, 0xbdcc, 0xb017, 0x0836,
1411 0x3a37, 0x27fb, 0xfb85, 0x251e, 0xa189, 0xb15d, 0xa4b8, 0xc24c},
1412 {0xb0b7, 0x57ba, 0xbb6d, 0x9177, 0xc896, 0xc7f2, 0x43b4, 0x85a6,
1413 0xe6c4, 0xe50e, 0x3109, 0x7ca5, 0xd73d, 0x13ff, 0x0c3d, 0xcd62},
1414 {0x48ca, 0xdb34, 0xe347, 0x2cef, 0x4466, 0x10fb, 0x7ee1, 0x6344,
1415 0x4308, 0x966d, 0xd4d1, 0xb099, 0x994f, 0xd025, 0x2187, 0x5866}},
1416 /* example doing 267 (g,(g-f)/2) steps; 678 divsteps */
1417 {{0x0775, 0x1754, 0x01f6, 0xdf37, 0xc0be, 0x8197, 0x072f, 0x6cf5,
1418 0x8b36, 0x8069, 0x5590, 0xb92d, 0x6084, 0x47a4, 0x23fe, 0xddd5},
1419 {0x8e1b, 0xda37, 0x27d9, 0x312e, 0x3a2f, 0xef6d, 0xd9eb, 0x8153,
1420 0xdcba, 0x9fa3, 0x9f80, 0xead5, 0x134d, 0x2ebb, 0x5ec0, 0xe032},
1421 {0x1cb6, 0x5a61, 0x1bed, 0x77d6, 0xd5d1, 0x7498, 0xef33, 0x2dd2,
1422 0x1089, 0xedbd, 0x6958, 0x16ae, 0x336c, 0x45e6, 0x4361, 0xbadc}},
1423 /* example doing 267 (g,(g-f)/2) steps; 676 divsteps */
1424 {{0x0207, 0xf948, 0xc430, 0xf36b, 0xf0a7, 0x5d36, 0x751f, 0x132c,
1425 0x6f25, 0xa630, 0xca1f, 0xc967, 0xaf9c, 0x34e7, 0xa38f, 0xbe9f},
1426 {0x5fb9, 0x7321, 0x6561, 0x5fed, 0x54ec, 0x9c3a, 0xee0e, 0x6717,
1427 0x49af, 0xb896, 0xf4f5, 0x451c, 0x722a, 0xf116, 0x64a9, 0xcf0b},
1428 {0xf4d7, 0xdb47, 0xfef2, 0x4806, 0x4cb8, 0x18c7, 0xd9a7, 0x4951,
1429 0x14d8, 0x5c3a, 0xd22d, 0xd7b2, 0x750c, 0x3de7, 0x8b4a, 0x19aa}},
1430
1431 /* Test cases triggering edge cases in divsteps variant starting with delta=1/2 */
1432
1433 /* example needing 590 divsteps; delta=-5/2..7/2 */
1434 {{0x9118, 0xb640, 0x53d7, 0x30ab, 0x2a23, 0xd907, 0x9323, 0x5b3a,
1435 0xb6d4, 0x538a, 0x7637, 0xfe97, 0xfd05, 0x3cc0, 0x453a, 0xfb7e},
1436 {0x6983, 0x4f75, 0x4ad1, 0x48ad, 0xb2d9, 0x521d, 0x3dbc, 0x9cc0,
1437 0x4b60, 0x0ac6, 0xd3be, 0x0fb6, 0xd305, 0x3895, 0x2da5, 0xfdf8},
1438 {0xcec1, 0x33ac, 0xa801, 0x8194, 0xe36c, 0x65ef, 0x103b, 0xca54,
1439 0xfa9b, 0xb41d, 0x9b52, 0xb6f7, 0xa611, 0x84aa, 0x3493, 0xbf54}},
1440 /* example needing 590 divsteps; delta=-3/2..5/2 */
1441 {{0xb5f2, 0x42d0, 0x35e8, 0x8ca0, 0x4b62, 0x6e1d, 0xbdf3, 0x890e,
1442 0x8c82, 0x23d8, 0xc79a, 0xc8e8, 0x789e, 0x353d, 0x9766, 0xea9d},
1443 {0x6fa1, 0xacba, 0x4b7a, 0x5de1, 0x95d0, 0xc845, 0xebbf, 0x6f5a,
1444 0x30cf, 0x52db, 0x69b7, 0xe278, 0x4b15, 0x8411, 0x2ab2, 0xf3e7},
1445 {0xf12c, 0x9d6d, 0x95fa, 0x1878, 0x9f13, 0x4fb5, 0x3c8b, 0xa451,
1446 0x7182, 0xc4b6, 0x7e2a, 0x7bb7, 0x6e0e, 0x5b68, 0xde55, 0x9927}},
1447 /* example needing 590 divsteps; delta=-3/2..5/2 */
1448 {{0x229c, 0x4ef8, 0x1e93, 0xe5dc, 0xcde5, 0x6d62, 0x263b, 0xad11,
1449 0xced0, 0x88ff, 0xae8e, 0x3183, 0x11d2, 0xa50b, 0x350d, 0xeb40},
1450 {0x3157, 0xe2ea, 0x8a02, 0x0aa3, 0x5ae1, 0xb26c, 0xea27, 0x6805,
1451 0x87e2, 0x9461, 0x37c1, 0x2f8d, 0x85d2, 0x77a8, 0xf805, 0xeec9},
1452 {0x6f4e, 0x2748, 0xf7e5, 0xd8d3, 0xabe2, 0x7270, 0xc4e0, 0xedc7,
1453 0xf196, 0x78ca, 0x9139, 0xd8af, 0x72c6, 0xaf2f, 0x85d2, 0x6cd3}},
1454 /* example needing 590 divsteps; delta=-5/2..7/2 */
1455 {{0xdce8, 0xf1fe, 0x6708, 0x021e, 0xf1ca, 0xd609, 0x5443, 0x85ce,
1456 0x7a05, 0x8f9c, 0x90c3, 0x52e7, 0x8e1d, 0x97b8, 0xc0bf, 0xf2a1},
1457 {0xbd3d, 0xed11, 0x1625, 0xb4c5, 0x844c, 0xa413, 0x2569, 0xb9ba,
1458 0xcd35, 0xff84, 0xcd6e, 0x7f0b, 0x7d5d, 0x10df, 0x3efe, 0xfbe5},
1459 {0xa9dd, 0xafef, 0xb1b7, 0x4c8d, 0x50e4, 0xafbf, 0x2d5a, 0xb27c,
1460 0x0653, 0x66b6, 0x5d36, 0x4694, 0x7e35, 0xc47c, 0x857f, 0x32c5}},
1461 /* example needing 590 divsteps; delta=-3/2..5/2 */
1462 {{0x7902, 0xc9f8, 0x926b, 0xaaeb, 0x90f8, 0x1c89, 0xcce3, 0x96b7,
1463 0x28b2, 0x87a2, 0x136d, 0x695a, 0xa8df, 0x9061, 0x9e31, 0xee82},
1464 {0xd3a9, 0x3c02, 0x818c, 0x6b81, 0x34b3, 0xebbb, 0xe2c8, 0x7712,
1465 0xbfd6, 0x8248, 0xa6f4, 0xba6f, 0x03bb, 0xfb54, 0x7575, 0xfe89},
1466 {0x8246, 0x0d63, 0x478e, 0xf946, 0xf393, 0x0451, 0x08c2, 0x5919,
1467 0x5fd6, 0x4c61, 0xbeb7, 0x9a15, 0x30e1, 0x55fc, 0x6a01, 0x3724}},
1468 /* example reaching delta=-127/2..129/2; 571 divsteps */
1469 {{0x3eff, 0x926a, 0x77f5, 0x1fff, 0x1a5b, 0xf3ef, 0xf64b, 0x8681,
1470 0xf800, 0xf9bc, 0x761d, 0xe268, 0x62b0, 0xa032, 0xba9c, 0xbe56},
1471 {0xb8f9, 0x00e7, 0x47b7, 0xdffc, 0xfd9d, 0x5abb, 0xa19b, 0x1868,
1472 0x31fd, 0x3b29, 0x3674, 0x5449, 0xf54d, 0x1d19, 0x6ac7, 0xff6f},
1473 {0xf1d7, 0x3551, 0x5682, 0x9adf, 0xe8aa, 0x19a5, 0x8340, 0x71db,
1474 0xb7ab, 0x4cfd, 0xf661, 0x632c, 0xc27e, 0xd3c6, 0xdf42, 0xd306}},
1475 /* example reaching delta=-127/2..129/2; 571 divsteps */
1476 {{0x0000, 0x0000, 0x0000, 0x0000, 0x3aff, 0x2ed7, 0xf2e0, 0xabc7,
1477 0x8aee, 0x166e, 0x7ed0, 0x9ac7, 0x714a, 0xb9c5, 0x4d58, 0xad6c},
1478 {0x9cf9, 0x47e2, 0xa421, 0xb277, 0xffc2, 0x2747, 0x6486, 0x94c1,
1479 0x1d99, 0xd49b, 0x1096, 0x991a, 0xe986, 0xae02, 0xe89b, 0xea36},
1480 {0x1fb4, 0x98d8, 0x19b7, 0x80e9, 0xcdac, 0xaa5a, 0xf1e6, 0x0074,
1481 0xe393, 0xed8b, 0x8d5c, 0xe17d, 0x81b3, 0xc16d, 0x54d3, 0x9be3}},
1482 /* example reaching delta=-127/2..129/2; 571 divsteps */
1483 {{0xd047, 0x7e36, 0x3157, 0x7ab6, 0xb4d9, 0x8dae, 0x7534, 0x4f5d,
1484 0x489e, 0xa8ab, 0x8a3d, 0xd52c, 0x62af, 0xa032, 0xba9c, 0xbe56},
1485 {0xb1f1, 0x737f, 0x5964, 0x5afb, 0x3712, 0x8ef9, 0x19f7, 0x9669,
1486 0x664d, 0x03ad, 0xc352, 0xf7a5, 0xf545, 0x1d19, 0x6ac7, 0xff6f},
1487 {0xa834, 0x5256, 0x27bc, 0x33bd, 0xba11, 0x5a7b, 0x791e, 0xe6c0,
1488 0x9ac4, 0x9370, 0x1130, 0x28b4, 0x2b2e, 0x231b, 0x082a, 0x796e}},
1489 /* example doing 123 consecutive (f,g/2) steps; 554 divsteps */
1490 {{0x6ab1, 0x6ea0, 0x1a99, 0xe0c2, 0xdd45, 0x645d, 0x8dbc, 0x466a,
1491 0xfa64, 0x4289, 0xd3f7, 0xfc8f, 0x2894, 0xe3c5, 0xa008, 0xcc14},
1492 {0xc75f, 0xc083, 0x4cc2, 0x64f2, 0x2aff, 0x4c12, 0x8461, 0xc4ae,
1493 0xbbfa, 0xb336, 0xe4b2, 0x3ac5, 0x2c22, 0xf56c, 0x5381, 0xe943},
1494 {0xcd80, 0x760d, 0x4395, 0xb3a6, 0xd497, 0xf583, 0x82bd, 0x1daa,
1495 0xbe92, 0x2613, 0xfdfb, 0x869b, 0x0425, 0xa333, 0x7056, 0xc9c5}},
1496 /* example doing 123 consecutive (f,g/2) steps; 554 divsteps */
1497 {{0x71d4, 0x64df, 0xec4f, 0x74d8, 0x7e0c, 0x40d3, 0x7073, 0x4cc8,
1498 0x2a2a, 0xb1ff, 0x8518, 0x6513, 0xb0ea, 0x640a, 0x62d9, 0xd5f4},
1499 {0xdc75, 0xd937, 0x3b13, 0x1d36, 0xdf83, 0xd034, 0x1c1c, 0x4332,
1500 0x4cc3, 0xeeec, 0x7d94, 0x6771, 0x3384, 0x74b0, 0x947d, 0xf2c4},
1501 {0x0a82, 0x37a4, 0x12d5, 0xec97, 0x972c, 0xe6bf, 0xc348, 0xa0a9,
1502 0xc50c, 0xdc7c, 0xae30, 0x19d1, 0x0fca, 0x35e1, 0xd6f6, 0x81ee}},
1503 /* example doing 123 consecutive (f,g/2) steps; 554 divsteps */
1504 {{0xa6b1, 0xabc5, 0x5bbc, 0x7f65, 0xdd32, 0xaa73, 0xf5a3, 0x1982,
1505 0xced4, 0xe949, 0x0fd6, 0x2bc4, 0x2bd7, 0xe3c5, 0xa008, 0xcc14},
1506 {0x4b5f, 0x8f96, 0xa375, 0xfbcf, 0x1c7d, 0xf1ec, 0x03f5, 0xb35d,
1507 0xb999, 0xdb1f, 0xc9a1, 0xb4c7, 0x1dd5, 0xf56c, 0x5381, 0xe943},
1508 {0xaa3d, 0x38b9, 0xf17d, 0xeed9, 0x9988, 0x69ee, 0xeb88, 0x1495,
1509 0x203f, 0x18c8, 0x82b7, 0xdcb2, 0x34a7, 0x6b00, 0x6998, 0x589a}},
1510 /* example doing 453 (f,g/2) steps; 514 divsteps */
1511 {{0xa478, 0xe60d, 0x3244, 0x60e6, 0xada3, 0xfe50, 0xb6b1, 0x2eae,
1512 0xd0ef, 0xa7b1, 0xef63, 0x05c0, 0xe213, 0x443e, 0x4427, 0x2448},
1513 {0x258f, 0xf9ef, 0xe02b, 0x92dd, 0xd7f3, 0x252b, 0xa503, 0x9089,
1514 0xedff, 0x96c1, 0xfe3a, 0x3a39, 0x198a, 0x981d, 0x0627, 0xedb7},
1515 {0x595a, 0x45be, 0x8fb0, 0x2265, 0xc210, 0x02b8, 0xdce9, 0xe241,
1516 0xcab6, 0xbf0d, 0x0049, 0x8d9a, 0x2f51, 0xae54, 0x5785, 0xb411}},
1517 /* example doing 453 (f,g/2) steps; 514 divsteps */
1518 {{0x48f0, 0x7db3, 0xdafe, 0x1c92, 0x5912, 0xe11a, 0xab52, 0xede1,
1519 0x3182, 0x8980, 0x5d2b, 0x9b5b, 0x8718, 0xda27, 0x1683, 0x1de2},
1520 {0x168f, 0x6f36, 0xce7a, 0xf435, 0x19d4, 0xda5e, 0x2351, 0x9af5,
1521 0xb003, 0x0ef5, 0x3b4c, 0xecec, 0xa9f0, 0x78e1, 0xdfef, 0xe823},
1522 {0x5f55, 0xfdcc, 0xb233, 0x2914, 0x84f0, 0x97d1, 0x9cf4, 0x2159,
1523 0xbf56, 0xb79c, 0x17a3, 0x7cef, 0xd5de, 0x34f0, 0x5311, 0x4c54}},
1524 /* example doing 510 (f,(f+g)/2) steps; 512 divsteps */
1525 {{0x2789, 0x2e04, 0x6e0e, 0xb6cd, 0xe4de, 0x4dbf, 0x228d, 0x7877,
1526 0xc335, 0x806b, 0x38cd, 0x8049, 0xa73b, 0xcfa2, 0x82f7, 0x9e19},
1527 {0xc08d, 0xb99d, 0xb8f3, 0x663d, 0xbbb3, 0x1284, 0x1485, 0x1d49,
1528 0xc98f, 0x9e78, 0x1588, 0x11e3, 0xd91a, 0xa2c7, 0xfff1, 0xc7b9},
1529 {0x1e1f, 0x411d, 0x7c49, 0x0d03, 0xe789, 0x2f8e, 0x5d55, 0xa95e,
1530 0x826e, 0x8de5, 0x52a0, 0x1abc, 0x4cd7, 0xd13a, 0x4395, 0x63e1}},
1531 /* example doing 510 (f,(f+g)/2) steps; 512 divsteps */
1532 {{0xd5a1, 0xf786, 0x555c, 0xb14b, 0x44ae, 0x535f, 0x4a49, 0xffc3,
1533 0xf497, 0x70d1, 0x57c8, 0xa933, 0xc85a, 0x1910, 0x75bf, 0x960b},
1534 {0xfe53, 0x5058, 0x496d, 0xfdff, 0x6fb8, 0x4100, 0x92bd, 0xe0c4,
1535 0xda89, 0xe0a4, 0x841b, 0x43d4, 0xa388, 0x957f, 0x99ca, 0x9abf},
1536 {0xe530, 0x05bc, 0xfeec, 0xfc7e, 0xbcd3, 0x1239, 0x54cb, 0x7042,
1537 0xbccb, 0x139e, 0x9076, 0x0203, 0x6068, 0x90c7, 0x1ddf, 0x488d}},
1538 /* example doing 228 (g,(g-f)/2) steps; 538 divsteps */
1539 {{0x9488, 0xe54b, 0x0e43, 0x81d2, 0x06e7, 0x4b66, 0x36d0, 0x53d6,
1540 0x2b68, 0x22ec, 0x3fa9, 0xc1a7, 0x9ad2, 0xa596, 0xb3ac, 0xdf42},
1541 {0xe31f, 0x0b28, 0x5f3b, 0xc1ff, 0x344c, 0xbf5f, 0xd2ec, 0x2936,
1542 0x9995, 0xdeb2, 0xae6c, 0x2852, 0xa2c6, 0xb306, 0x8120, 0xe305},
1543 {0xa56e, 0xfb98, 0x1537, 0x4d85, 0x619e, 0x866c, 0x3cd4, 0x779a,
1544 0xdd66, 0xa80d, 0xdc2f, 0xcae4, 0xc74c, 0x5175, 0xa65d, 0x605e}},
1545 /* example doing 228 (g,(g-f)/2) steps; 537 divsteps */
1546 {{0x8cd5, 0x376d, 0xd01b, 0x7176, 0x19ef, 0xcf09, 0x8403, 0x5e52,
1547 0x83c1, 0x44de, 0xb91e, 0xb33d, 0xe15c, 0x51e7, 0xbad8, 0x6359},
1548 {0x3b75, 0xf812, 0x5f9e, 0xa04e, 0x92d3, 0x226e, 0x540e, 0x7c9a,
1549 0x31c6, 0x46d2, 0x0b7b, 0xdb4a, 0xe662, 0x4950, 0x0265, 0xf76f},
1550 {0x09ed, 0x692f, 0xe8f1, 0x3482, 0xab54, 0x36b4, 0x8442, 0x6ae9,
1551 0x4329, 0x6505, 0x183b, 0x1c1d, 0x482d, 0x7d63, 0xb44f, 0xcc09}},
1552
1553 /* Test cases with the group order as modulus. */
1554
1555 /* Test case with the group order as modulus, needing 635 divsteps. */
1556 {{0x95ed, 0x6c01, 0xd113, 0x5ff1, 0xd7d0, 0x29cc, 0x5817, 0x6120,
1557 0xca8e, 0xaad1, 0x25ae, 0x8e84, 0x9af6, 0x30bf, 0xf0ed, 0x1686},
1558 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1559 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1560 {0x1631, 0xbf4a, 0x286a, 0x2716, 0x469f, 0x2ac8, 0x1312, 0xe9bc,
1561 0x04f4, 0x304b, 0x9931, 0x113b, 0xd932, 0xc8f4, 0x0d0d, 0x01a1}},
1562 /* example with group size as modulus needing 631 divsteps */
1563 {{0x85ed, 0xc284, 0x9608, 0x3c56, 0x19b6, 0xbb5b, 0x2850, 0xdab7,
1564 0xa7f5, 0xe9ab, 0x06a4, 0x5bbb, 0x1135, 0xa186, 0xc424, 0xc68b},
1565 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1566 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1567 {0x8479, 0x450a, 0x8fa3, 0xde05, 0xb2f5, 0x7793, 0x7269, 0xbabb,
1568 0xc3b3, 0xd49b, 0x3377, 0x03c6, 0xe694, 0xc760, 0xd3cb, 0x2811}},
1569 /* example with group size as modulus needing 565 divsteps starting at delta=1/2 */
1570 {{0x8432, 0x5ceb, 0xa847, 0x6f1e, 0x51dd, 0x535a, 0x6ddc, 0x70ce,
1571 0x6e70, 0xc1f6, 0x18f2, 0x2a7e, 0xc8e7, 0x39f8, 0x7e96, 0xebbf},
1572 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1573 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1574 {0x257e, 0x449f, 0x689f, 0x89aa, 0x3989, 0xb661, 0x376c, 0x1e32,
1575 0x654c, 0xee2e, 0xf4e2, 0x33c8, 0x3f2f, 0x9716, 0x6046, 0xcaa3}},
1576 /* Test case with the group size as modulus, needing 981 divsteps with
1577 broken eta handling. */
1578 {{0xfeb9, 0xb877, 0xee41, 0x7fa3, 0x87da, 0x94c4, 0x9d04, 0xc5ae,
1579 0x5708, 0x0994, 0xfc79, 0x0916, 0xbf32, 0x3ad8, 0xe11c, 0x5ca2},
1580 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1581 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1582 {0x0f12, 0x075e, 0xce1c, 0x6f92, 0xc80f, 0xca92, 0x9a04, 0x6126,
1583 0x4b6c, 0x57d6, 0xca31, 0x97f3, 0x1f99, 0xf4fd, 0xda4d, 0x42ce}},
1584 /* Test case with the group size as modulus, input = 0. */
1585 {{0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1586 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000},
1587 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1588 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1589 {0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1590 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000}},
1591 /* Test case with the group size as modulus, input = 1. */
1592 {{0x0001, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1593 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000},
1594 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1595 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1596 {0x0001, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1597 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000}},
1598 /* Test case with the group size as modulus, input = 2. */
1599 {{0x0002, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1600 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000},
1601 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1602 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1603 {0x20a1, 0x681b, 0x2f46, 0xdfe9, 0x501d, 0x57a4, 0x6e73, 0x5d57,
1604 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0x7fff}},
1605 /* Test case with the group size as modulus, input = group - 1. */
1606 {{0x4140, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1607 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1608 {0x4141, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1609 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1610 {0x4140, 0xd036, 0x5e8c, 0xbfd2, 0xa03b, 0xaf48, 0xdce6, 0xbaae,
1611 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff}},
1612
1613 /* Test cases with the field size as modulus. */
1614
1615 /* Test case with the field size as modulus, needing 637 divsteps. */
1616 {{0x9ec3, 0x1919, 0xca84, 0x7c11, 0xf996, 0x06f3, 0x5408, 0x6688,
1617 0x1320, 0xdb8a, 0x632a, 0x0dcb, 0x8a84, 0x6bee, 0x9c95, 0xe34e},
1618 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1619 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1620 {0x18e5, 0x19b6, 0xdf92, 0x1aaa, 0x09fb, 0x8a3f, 0x52b0, 0x8701,
1621 0xac0c, 0x2582, 0xda44, 0x9bcc, 0x6828, 0x1c53, 0xbd8f, 0xbd2c}},
1622 /* example with field size as modulus needing 637 divsteps */
1623 {{0xaec3, 0xa7cf, 0x2f2d, 0x0693, 0x5ad5, 0xa8ff, 0x7ec7, 0x30ff,
1624 0x0c8b, 0xc242, 0xcab2, 0x063a, 0xf86e, 0x6057, 0x9cbd, 0xf6d8},
1625 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1626 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1627 {0x0310, 0x579d, 0xcb38, 0x9030, 0x3ded, 0x9bb9, 0x1234, 0x63ce,
1628 0x0c63, 0x8e3d, 0xacfe, 0x3c20, 0xdc85, 0xf859, 0x919e, 0x1d45}},
1629 /* example with field size as modulus needing 564 divsteps starting at delta=1/2 */
1630 {{0x63ae, 0x8d10, 0x0071, 0xdb5c, 0xb454, 0x78d1, 0x744a, 0x5f8e,
1631 0xe4d8, 0x87b1, 0x8e62, 0x9590, 0xcede, 0xa070, 0x36b4, 0x7f6f},
1632 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1633 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1634 {0xfdc8, 0xe8d5, 0xbe15, 0x9f86, 0xa5fe, 0xf18e, 0xa7ff, 0xd291,
1635 0xf4c2, 0x9c87, 0xf150, 0x073e, 0x69b8, 0xf7c4, 0xee4b, 0xc7e6}},
1636 /* Test case with the field size as modulus, needing 935 divsteps with
1637 broken eta handling. */
1638 {{0x1b37, 0xbdc3, 0x8bcd, 0x25e3, 0x1eae, 0x567d, 0x30b6, 0xf0d8,
1639 0x9277, 0x0cf8, 0x9c2e, 0xecd7, 0x631d, 0xe38f, 0xd4f8, 0x5c93},
1640 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1641 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1642 {0x1622, 0xe05b, 0xe880, 0x7de9, 0x3e45, 0xb682, 0xee6c, 0x67ed,
1643 0xa179, 0x15db, 0x6b0d, 0xa656, 0x7ccb, 0x8ef7, 0xa2ff, 0xe279}},
1644 /* Test case with the field size as modulus, input = 0. */
1645 {{0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1646 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000},
1647 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1648 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1649 {0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1650 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000}},
1651 /* Test case with the field size as modulus, input = 1. */
1652 {{0x0001, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1653 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000},
1654 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1655 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1656 {0x0001, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1657 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000}},
1658 /* Test case with the field size as modulus, input = 2. */
1659 {{0x0002, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000,
1660 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000, 0x0000},
1661 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1662 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1663 {0xfe18, 0x7fff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1664 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0x7fff}},
1665 /* Test case with the field size as modulus, input = field - 1. */
1666 {{0xfc2e, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1667 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1668 {0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1669 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff},
1670 {0xfc2e, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
1671 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff}},
1672
1673 /* Selected from a large number of random inputs to reach small/large
1674 * d/e values in various configurations. */
1675 {{0x3a08, 0x23e1, 0x4d8c, 0xe606, 0x3263, 0x67af, 0x9bf1, 0x9d70,
1676 0xf5fd, 0x12e4, 0x03c8, 0xb9ca, 0xe847, 0x8c5d, 0x6322, 0xbd30},
1677 {0x8359, 0x59dd, 0x1831, 0x7c1a, 0x1e83, 0xaee1, 0x770d, 0xcea8,
1678 0xfbb1, 0xeed6, 0x10b5, 0xe2c6, 0x36ea, 0xee17, 0xe32c, 0xffff},
1679 {0x1727, 0x0f36, 0x6f85, 0x5d0c, 0xca6c, 0x3072, 0x9628, 0x5842,
1680 0xcb44, 0x7c2b, 0xca4f, 0x62e5, 0x29b1, 0x6ffd, 0x9055, 0xc196}},
1681 {{0x905d, 0x41c8, 0xa2ff, 0x295b, 0x72bb, 0x4679, 0x6d01, 0x2c98,
1682 0xb3e0, 0xc537, 0xa310, 0xe07e, 0xe72f, 0x4999, 0x1148, 0xf65e},
1683 {0x5b41, 0x4239, 0x3c37, 0x5130, 0x30e3, 0xff35, 0xc51f, 0x1a43,
1684 0xdb23, 0x13cf, 0x9f49, 0xf70c, 0x5e70, 0xd411, 0x3005, 0xf8c6},
1685 {0xc30e, 0x68f0, 0x201a, 0xe10c, 0x864a, 0x6243, 0xe946, 0x43ae,
1686 0xf3f1, 0x52dc, 0x1f7f, 0x50d4, 0x2797, 0x064c, 0x5ca4, 0x90e3}},
1687 {{0xf1b5, 0xc6e5, 0xd2c4, 0xff95, 0x27c5, 0x0c92, 0x5d19, 0x7ae5,
1688 0x4fbe, 0x5438, 0x99e1, 0x880d, 0xd892, 0xa05c, 0x6ffd, 0x7eac},
1689 {0x2153, 0xcc9d, 0xfc6c, 0x8358, 0x49a1, 0x01e2, 0xcef0, 0x4969,
1690 0xd69a, 0x8cef, 0xf5b2, 0xfd95, 0xdcc2, 0x71f4, 0x6ae2, 0xceeb},
1691 {0x9b2e, 0xcdc6, 0x0a5c, 0x7317, 0x9084, 0xe228, 0x56cf, 0xd512,
1692 0x628a, 0xce21, 0x3473, 0x4e13, 0x8823, 0x1ed0, 0x34d0, 0xbfa3}},
1693 {{0x5bae, 0x53e5, 0x5f4d, 0x21ca, 0xb875, 0x8ecf, 0x9aa6, 0xbe3c,
1694 0x9f96, 0x7b82, 0x375d, 0x4d3e, 0x491c, 0xb1eb, 0x04c9, 0xb6c8},
1695 {0xfcfd, 0x10b7, 0x73b2, 0xd23b, 0xa357, 0x67da, 0x0d9f, 0x8702,
1696 0xa037, 0xff8e, 0x0e8b, 0x1801, 0x2c5c, 0x4e6e, 0x4558, 0xfff2},
1697 {0xc50f, 0x5654, 0x6713, 0x5ef5, 0xa7ce, 0xa647, 0xc832, 0x69ce,
1698 0x1d5c, 0x4310, 0x0746, 0x5a01, 0x96ea, 0xde4b, 0xa88b, 0x5543}},
1699 {{0xdc7f, 0x5e8c, 0x89d1, 0xb077, 0xd521, 0xcf90, 0x32fa, 0x5737,
1700 0x839e, 0x1464, 0x007c, 0x09c6, 0x9371, 0xe8ea, 0xc1cb, 0x75c4},
1701 {0xe3a3, 0x107f, 0xa82a, 0xa375, 0x4578, 0x60f4, 0x75c9, 0x5ee4,
1702 0x3fd7, 0x2736, 0x2871, 0xd3d2, 0x5f1d, 0x1abb, 0xa764, 0xffff},
1703 {0x45c6, 0x1f2e, 0xb14c, 0x84d7, 0x7bb7, 0x5a04, 0x0504, 0x3f33,
1704 0x5cc1, 0xb07a, 0x6a6c, 0x786f, 0x647f, 0xe1d7, 0x78a2, 0x4cf4}},
1705 {{0xc006, 0x356f, 0x8cd2, 0x967b, 0xb49e, 0x2d4e, 0x14bf, 0x4bcb,
1706 0xddab, 0xd3f9, 0xa068, 0x2c1c, 0xd242, 0xa56d, 0xf2c7, 0x5f97},
1707 {0x465b, 0xb745, 0x0e0d, 0x69a9, 0x987d, 0xcb37, 0xf637, 0xb311,
1708 0xc4d6, 0x2ddb, 0xf68f, 0x2af9, 0x959d, 0x3f53, 0x98f2, 0xf640},
1709 {0xc0f2, 0x6bfb, 0xf5c3, 0x91c1, 0x6b05, 0x0825, 0x5ca0, 0x7df7,
1710 0x9d55, 0x6d9e, 0xfe94, 0x2ad9, 0xd9f0, 0xe68b, 0xa72b, 0xd1b2}},
1711 {{0x2279, 0x61ba, 0x5bc6, 0x136b, 0xf544, 0x717c, 0xafda, 0x02bd,
1712 0x79af, 0x1fad, 0xea09, 0x81bb, 0x932b, 0x32c9, 0xdf1d, 0xe576},
1713 {0x8215, 0x7817, 0xca82, 0x43b0, 0x9b06, 0xea65, 0x1291, 0x0621,
1714 0x0089, 0x46fe, 0xc5a6, 0xddd7, 0x8065, 0xc6a0, 0x214b, 0xfc64},
1715 {0x04bf, 0x6f2a, 0x86b2, 0x841a, 0x4a95, 0xc632, 0x97b7, 0x5821,
1716 0x2b18, 0x1bb0, 0x3e97, 0x935e, 0xcc7d, 0x066b, 0xd513, 0xc251}},
1717 {{0x76e8, 0x5bc2, 0x3eaa, 0x04fc, 0x9974, 0x92c1, 0x7c15, 0xfa89,
1718 0x1151, 0x36ee, 0x48b2, 0x049c, 0x5f16, 0xcee4, 0x925b, 0xe98e},
1719 {0x913f, 0x0a2d, 0xa185, 0x9fea, 0xda5a, 0x4025, 0x40d7, 0x7cfa,
1720 0x88ca, 0xbbe8, 0xb265, 0xb7e4, 0x6cb1, 0xed64, 0xc6f9, 0xffb5},
1721 {0x6ab1, 0x1a86, 0x5009, 0x152b, 0x1cc4, 0xe2c8, 0x960b, 0x19d0,
1722 0x3554, 0xc562, 0xd013, 0xcf91, 0x10e1, 0x7933, 0xe195, 0xcf49}},
1723 {{0x9cb5, 0xd2d7, 0xc6ed, 0xa818, 0xb495, 0x06ee, 0x0f4a, 0x06e3,
1724 0x4c5a, 0x80ce, 0xd49a, 0x4cd7, 0x7487, 0x92af, 0xe516, 0x676c},
1725 {0xd6e9, 0x6b85, 0x619a, 0xb52c, 0x20a0, 0x2f79, 0x3545, 0x1edd,
1726 0x5a6f, 0x8082, 0x9b80, 0xf8f8, 0xc78a, 0xd0a3, 0xadf4, 0xffff},
1727 {0x01c2, 0x2118, 0xef5e, 0xa877, 0x046a, 0xd2c2, 0x2ad5, 0x951c,
1728 0x8900, 0xa5c9, 0x8d0f, 0x6b61, 0x55d3, 0xd572, 0x48de, 0x9219}},
1729 {{0x5114, 0x0644, 0x23dd, 0x01d3, 0xc101, 0xa659, 0xea17, 0x640f,
1730 0xf767, 0x2644, 0x9cec, 0xd8ba, 0xd6da, 0x9156, 0x8aeb, 0x875a},
1731 {0xc1bf, 0xdae9, 0xe96b, 0xce77, 0xf7a1, 0x3e99, 0x5c2e, 0x973b,
1732 0xd048, 0x5bd0, 0x4e8a, 0xcb85, 0xce39, 0x37f5, 0x815d, 0xffff},
1733 {0x48cc, 0x35b6, 0x26d4, 0x2ea6, 0x50d6, 0xa2f9, 0x64b6, 0x03bf,
1734 0xd00c, 0xe057, 0x3343, 0xfb79, 0x3ce5, 0xf717, 0xc5af, 0xe185}},
1735 {{0x13ff, 0x6c76, 0x2077, 0x16e0, 0xd5ca, 0xf2ad, 0x8dba, 0x8f49,
1736 0x7887, 0x16f9, 0xb646, 0xfc87, 0xfa31, 0x5096, 0xf08c, 0x3fbe},
1737 {0x8139, 0x6fd7, 0xf6df, 0xa7bf, 0x6699, 0x5361, 0x6f65, 0x13c8,
1738 0xf4d1, 0xe28f, 0xc545, 0x0a8c, 0x5274, 0xb0a6, 0xffff, 0xffff},
1739 {0x22ca, 0x0cd6, 0xc1b5, 0xb064, 0x44a7, 0x297b, 0x495f, 0x34ac,
1740 0xfa95, 0xec62, 0xf08d, 0x621c, 0x66a6, 0xba94, 0x84c6, 0x8ee0}},
1741 {{0xaa30, 0x312e, 0x439c, 0x4e88, 0x2e2f, 0x32dc, 0xb880, 0xa28e,
1742 0xf795, 0xc910, 0xb406, 0x8dd7, 0xb187, 0xa5a5, 0x38f1, 0xe49e},
1743 {0xfb19, 0xf64a, 0xba6a, 0x8ec2, 0x7255, 0xce89, 0x2cf9, 0x9cba,
1744 0xe1fe, 0x50da, 0x1705, 0xac52, 0xe3d4, 0x4269, 0x0648, 0xfd77},
1745 {0xb4c8, 0x6e8a, 0x2b5f, 0x4c2d, 0x5a67, 0xa7bb, 0x7d6d, 0x5569,
1746 0xa0ea, 0x244a, 0xc0f2, 0xf73d, 0x58cf, 0xac7f, 0xd32b, 0x3018}},
1747 {{0xc953, 0x1ae1, 0xae46, 0x8709, 0x19c2, 0xa986, 0x9abe, 0x1611,
1748 0x0395, 0xd5ab, 0xf0f6, 0xb5b0, 0x5b2b, 0x0317, 0x80ba, 0x376d},
1749 {0xfe77, 0xbc03, 0xac2f, 0x9d00, 0xa175, 0x293d, 0x3b56, 0x0e3a,
1750 0x0a9c, 0xf40c, 0x690e, 0x1508, 0x95d4, 0xddc4, 0xe805, 0xffff},
1751 {0xb1ce, 0x0929, 0xa5fe, 0x4b50, 0x9d5d, 0x8187, 0x2557, 0x4376,
1752 0x11ba, 0xdcef, 0xc1f3, 0xd531, 0x1824, 0x93f6, 0xd81f, 0x8f83}},
1753 {{0xb8d2, 0xb900, 0x4a0c, 0x7188, 0xa5bf, 0x1b0b, 0x2ae5, 0xa35b,
1754 0x98e0, 0x610c, 0x86db, 0x2487, 0xa267, 0x002c, 0xebb6, 0xc5f4},
1755 {0x9cdd, 0x1c1b, 0x2f06, 0x43d1, 0xce47, 0xc334, 0x6e60, 0xc016,
1756 0x989e, 0x0ab2, 0x0cac, 0x1196, 0xe2d9, 0x2e04, 0xc62b, 0xffff},
1757 {0xdc36, 0x1f05, 0x6aa9, 0x7a20, 0x944f, 0x2fd3, 0xa553, 0xdb4f,
1758 0xbd5c, 0x3a75, 0x25d4, 0xe20e, 0xa387, 0x1410, 0xdbb1, 0x1b60}},
1759 {{0x76b3, 0x2207, 0x4930, 0x5dd7, 0x65a0, 0xd55c, 0xb443, 0x53b7,
1760 0x5c22, 0x818a, 0xb2e7, 0x9de8, 0x9985, 0xed45, 0x33b1, 0x53e8},
1761 {0x7913, 0x44e1, 0xf15b, 0x5edd, 0x34f3, 0x4eba, 0x0758, 0x7104,
1762 0x32d9, 0x28f3, 0x4401, 0x85c5, 0xb695, 0xb899, 0xc0f2, 0xffff},
1763 {0x7f43, 0xd202, 0x24c9, 0x69f3, 0x74dc, 0x1a69, 0xeaee, 0x5405,
1764 0x1755, 0x4bb8, 0x04e3, 0x2fd2, 0xada8, 0x39eb, 0x5b4d, 0x96ca}},
1765 {{0x807b, 0x7112, 0xc088, 0xdafd, 0x02fa, 0x9d95, 0x5e42, 0xc033,
1766 0xde0a, 0xeecf, 0x8e90, 0x8da1, 0xb17e, 0x9a5b, 0x4c6d, 0x1914},
1767 {0x4871, 0xd1cb, 0x47d7, 0x327f, 0x09ec, 0x97bb, 0x2fae, 0xd346,
1768 0x6b78, 0x3707, 0xfeb2, 0xa6ab, 0x13df, 0x76b0, 0x8fb9, 0xffb3},
1769 {0x179e, 0xb63b, 0x4784, 0x231e, 0x9f42, 0x7f1a, 0xa3fb, 0xdd8c,
1770 0xd1eb, 0xb4c9, 0x8ca7, 0x018c, 0xf691, 0x576c, 0xa7d6, 0xce27}},
1771 {{0x5f45, 0x7c64, 0x083d, 0xedd5, 0x08a0, 0x0c64, 0x6c6f, 0xec3c,
1772 0xe2fb, 0x352c, 0x9303, 0x75e4, 0xb4e0, 0x8b09, 0xaca4, 0x7025},
1773 {0x1025, 0xb482, 0xfed5, 0xa678, 0x8966, 0x9359, 0x5329, 0x98bb,
1774 0x85b2, 0x73ba, 0x9982, 0x6fdc, 0xf190, 0xbe8c, 0xdc5c, 0xfd93},
1775 {0x83a2, 0x87a4, 0xa680, 0x52a1, 0x1ba1, 0x8848, 0x5db7, 0x9744,
1776 0x409c, 0x0745, 0x0e1e, 0x1cfc, 0x00cd, 0xf573, 0x2071, 0xccaa}},
1777 {{0xf61f, 0x63d4, 0x536c, 0x9eb9, 0x5ddd, 0xbb11, 0x9014, 0xe904,
1778 0xfe01, 0x6b45, 0x1858, 0xcb5b, 0x4c38, 0x43e1, 0x381d, 0x7f94},
1779 {0xf61f, 0x63d4, 0xd810, 0x7ca3, 0x8a04, 0x4b83, 0x11fc, 0xdf94,
1780 0x4169, 0xbd05, 0x608e, 0x7151, 0x4fbf, 0xb31a, 0x38a7, 0xa29b},
1781 {0xe621, 0xdfa5, 0x3d06, 0x1d03, 0x81e6, 0x00da, 0x53a6, 0x965e,
1782 0x93e5, 0x2164, 0x5b61, 0x59b8, 0xa629, 0x8d73, 0x699a, 0x6111}},
1783 {{0x4cc3, 0xd29e, 0xf4a3, 0x3428, 0x2048, 0xeec9, 0x5f50, 0x99a4,
1784 0x6de9, 0x05f2, 0x5aa9, 0x5fd2, 0x98b4, 0x1adc, 0x225f, 0x777f},
1785 {0xe649, 0x37da, 0x5ba6, 0x5765, 0x3f4a, 0x8a1c, 0x2e79, 0xf550,
1786 0x1a54, 0xcd1e, 0x7218, 0x3c3c, 0x6311, 0xfe28, 0x95fb, 0xed97},
1787 {0xe9b6, 0x0c47, 0x3f0e, 0x849b, 0x11f8, 0xe599, 0x5e4d, 0xd618,
1788 0xa06d, 0x33a0, 0x9a3e, 0x44db, 0xded8, 0x10f0, 0x94d2, 0x81fb}},
1789 {{0x2e59, 0x7025, 0xd413, 0x455a, 0x1ce3, 0xbd45, 0x7263, 0x27f7,
1790 0x23e3, 0x518e, 0xbe06, 0xc8c4, 0xe332, 0x4276, 0x68b4, 0xb166},
1791 {0x596f, 0x0cf6, 0xc8ec, 0x787b, 0x04c1, 0x473c, 0xd2b8, 0x8d54,
1792 0x9cdf, 0x77f2, 0xd3f3, 0x6735, 0x0638, 0xf80e, 0x9467, 0xc6aa},
1793 {0xc7e7, 0x1822, 0xb62a, 0xec0d, 0x89cd, 0x7846, 0xbfa2, 0x35d5,
1794 0xfa38, 0x870f, 0x494b, 0x1697, 0x8b17, 0xf904, 0x10b6, 0x9822}},
1795 {{0x6d5b, 0x1d4f, 0x0aaf, 0x807b, 0x35fb, 0x7ee8, 0x00c6, 0x059a,
1796 0xddf0, 0x1fb1, 0xc38a, 0xd78e, 0x2aa4, 0x79e7, 0xad28, 0xc3f1},
1797 {0xe3bb, 0x174e, 0xe0a8, 0x74b6, 0xbd5b, 0x35f6, 0x6d23, 0x6328,
1798 0xc11f, 0x83e1, 0xf928, 0xa918, 0x838e, 0xbf43, 0xe243, 0xfffb},
1799 {0x9cf2, 0x6b8b, 0x3476, 0x9d06, 0xdcf2, 0xdb8a, 0x89cd, 0x4857,
1800 0x75c2, 0xabb8, 0x490b, 0xc9bd, 0x890e, 0xe36e, 0xd552, 0xfffa}},
1801 {{0x2f09, 0x9d62, 0xa9fc, 0xf090, 0xd6d1, 0x9d1d, 0x1828, 0xe413,
1802 0xc92b, 0x3d5a, 0x1373, 0x368c, 0xbaf2, 0x2158, 0x71eb, 0x08a3},
1803 {0x2f09, 0x1d62, 0x4630, 0x0de1, 0x06dc, 0xf7f1, 0xc161, 0x1e92,
1804 0x7495, 0x97e4, 0x94b6, 0xa39e, 0x4f1b, 0x18f8, 0x7bd4, 0x0c4c},
1805 {0xeb3d, 0x723d, 0x0907, 0x525b, 0x463a, 0x49a8, 0xc6b8, 0xce7f,
1806 0x740c, 0x0d7d, 0xa83b, 0x457f, 0xae8e, 0xc6af, 0xd331, 0x0475}},
1807 {{0x6abd, 0xc7af, 0x3e4e, 0x95fd, 0x8fc4, 0xee25, 0x1f9c, 0x0afe,
1808 0x291d, 0xcde0, 0x48f4, 0xb2e8, 0xf7af, 0x8f8d, 0x0bd6, 0x078d},
1809 {0x4037, 0xbf0e, 0x2081, 0xf363, 0x13b2, 0x381e, 0xfb6e, 0x818e,
1810 0x27e4, 0x5662, 0x18b0, 0x0cd2, 0x81f5, 0x9415, 0x0d6c, 0xf9fb},
1811 {0xd205, 0x0981, 0x0498, 0x1f08, 0xdb93, 0x1732, 0x0579, 0x1424,
1812 0xad95, 0x642f, 0x050c, 0x1d6d, 0xfc95, 0xfc4a, 0xd41b, 0x3521}},
1813 {{0xf23a, 0x4633, 0xaef4, 0x1a92, 0x3c8b, 0x1f09, 0x30f3, 0x4c56,
1814 0x2a2f, 0x4f62, 0xf5e4, 0x8329, 0x63cc, 0xb593, 0xec6a, 0xc428},
1815 {0x93a7, 0xfcf6, 0x606d, 0xd4b2, 0x2aad, 0x28b4, 0xc65b, 0x8998,
1816 0x4e08, 0xd178, 0x0900, 0xc82b, 0x7470, 0xa342, 0x7c0f, 0xffff},
1817 {0x315f, 0xf304, 0xeb7b, 0xe5c3, 0x1451, 0x6311, 0x8f37, 0x93a8,
1818 0x4a38, 0xa6c6, 0xe393, 0x1087, 0x6301, 0xd673, 0x4ec4, 0xffff}},
1819 {{0x892e, 0xeed0, 0x1165, 0xcbc1, 0x5545, 0xa280, 0x7243, 0x10c9,
1820 0x9536, 0x36af, 0xb3fc, 0x2d7c, 0xe8a5, 0x09d6, 0xe1d4, 0xe85d},
1821 {0xae09, 0xc28a, 0xd777, 0xbd80, 0x23d6, 0xf980, 0xeb7c, 0x4e0e,
1822 0xf7dc, 0x6475, 0xf10a, 0x2d33, 0x5dfd, 0x797a, 0x7f1c, 0xf71a},
1823 {0x4064, 0x8717, 0xd091, 0x80b0, 0x4527, 0x8442, 0xac8b, 0x9614,
1824 0xc633, 0x35f5, 0x7714, 0x2e83, 0x4aaa, 0xd2e4, 0x1acd, 0x0562}},
1825 {{0xdb64, 0x0937, 0x308b, 0x53b0, 0x00e8, 0xc77f, 0x2f30, 0x37f7,
1826 0x79ce, 0xeb7f, 0xde81, 0x9286, 0xafda, 0x0e62, 0xae00, 0x0067},
1827 {0x2cc7, 0xd362, 0xb161, 0x0557, 0x4ff2, 0xb9c8, 0x06fe, 0x5f2b,
1828 0xde33, 0x0190, 0x28c6, 0xb886, 0xee2b, 0x5a4e, 0x3289, 0x0185},
1829 {0x4215, 0x923e, 0xf34f, 0xb362, 0x88f8, 0xceec, 0xafdd, 0x7f42,
1830 0x0c57, 0x56b2, 0xa366, 0x6a08, 0x0826, 0xfb8f, 0x1b03, 0x0163}},
1831 {{0xa4ba, 0x8408, 0x810a, 0xdeba, 0x47a3, 0x853a, 0xeb64, 0x2f74,
1832 0x3039, 0x038c, 0x7fbb, 0x498e, 0xd1e9, 0x46fb, 0x5691, 0x32a4},
1833 {0xd749, 0xb49d, 0x20b7, 0x2af6, 0xd34a, 0xd2da, 0x0a10, 0xf781,
1834 0x58c9, 0x171f, 0x3cb6, 0x6337, 0x88cd, 0xcf1e, 0xb246, 0x7351},
1835 {0xf729, 0xcf0a, 0x96ea, 0x032c, 0x4a8f, 0x42fe, 0xbac8, 0xec65,
1836 0x1510, 0x0d75, 0x4c17, 0x8d29, 0xa03f, 0x8b7e, 0x2c49, 0x0000}},
1837 {{0x0fa4, 0x8e1c, 0x3788, 0xba3c, 0x8d52, 0xd89d, 0x12c8, 0xeced,
1838 0x9fe6, 0x9b88, 0xecf3, 0xe3c8, 0xac48, 0x76ed, 0xf23e, 0xda79},
1839 {0x1103, 0x227c, 0x5b00, 0x3fcf, 0xc5d0, 0x2d28, 0x8020, 0x4d1c,
1840 0xc6b9, 0x67f9, 0x6f39, 0x989a, 0xda53, 0x3847, 0xd416, 0xe0d0},
1841 {0xdd8e, 0xcf31, 0x3710, 0x7e44, 0xa511, 0x933c, 0x0cc3, 0x5145,
1842 0xf632, 0x5e1d, 0x038f, 0x5ce7, 0x7265, 0xda9d, 0xded6, 0x08f8}},
1843 {{0xe2c8, 0x91d5, 0xa5f5, 0x735f, 0x6b58, 0x56dc, 0xb39d, 0x5c4a,
1844 0x57d0, 0xa1c2, 0xd92f, 0x9ad4, 0xf7c4, 0x51dd, 0xaf5c, 0x0096},
1845 {0x1739, 0x7207, 0x7505, 0xbf35, 0x42de, 0x0a29, 0xa962, 0xdedf,
1846 0x53e8, 0x12bf, 0xcde7, 0xd8e2, 0x8d4d, 0x2c4b, 0xb1b1, 0x0628},
1847 {0x992d, 0xe3a7, 0xb422, 0xc198, 0x23ab, 0xa6ef, 0xb45d, 0x50da,
1848 0xa738, 0x014a, 0x2310, 0x85fb, 0x5fe8, 0x1b18, 0x1774, 0x03a7}},
1849 {{0x1f16, 0x2b09, 0x0236, 0xee90, 0xccf9, 0x9775, 0x8130, 0x4c91,
1850 0x9091, 0x310b, 0x6dc4, 0x86f6, 0xc2e8, 0xef60, 0xfc0e, 0xf3a4},
1851 {0x9f49, 0xac15, 0x02af, 0x110f, 0xc59d, 0x5677, 0xa1a9, 0x38d5,
1852 0x914f, 0xa909, 0x3a3a, 0x4a39, 0x3703, 0xea30, 0x73da, 0xffad},
1853 {0x15ed, 0xdd16, 0x83c7, 0x270a, 0x862f, 0xd8ad, 0xcaa1, 0x5f41,
1854 0x99a9, 0x3fc8, 0x7bb2, 0x360a, 0xb06d, 0xfadc, 0x1b36, 0xffa8}},
1855 {{0xc4e0, 0xb8fd, 0x5106, 0xe169, 0x754c, 0xa58c, 0xc413, 0x8224,
1856 0x5483, 0x63ec, 0xd477, 0x8473, 0x4778, 0x9281, 0x0000, 0x0000},
1857 {0x85e1, 0xff54, 0xb200, 0xe413, 0xf4f4, 0x4c0f, 0xfcec, 0xc183,
1858 0x60d3, 0x1b0c, 0x3834, 0x601c, 0x943c, 0xbe6e, 0x0002, 0x0000},
1859 {0xf4f8, 0xfd5e, 0x61ef, 0xece8, 0x9199, 0xe5c4, 0x05a6, 0xe6c3,
1860 0xc4ae, 0x8b28, 0x66b1, 0x8a95, 0x9ece, 0x8f4a, 0x0001, 0x0000}},
1861 {{0xeae9, 0xa1b4, 0xc6d8, 0x2411, 0x2b5a, 0x1dd0, 0x2dc9, 0xb57b,
1862 0x5ccd, 0x4957, 0xaf59, 0xa04b, 0x5f42, 0xab7c, 0x2826, 0x526f},
1863 {0xf407, 0x165a, 0xb724, 0x2f12, 0x2ea1, 0x470b, 0x4464, 0xbd35,
1864 0x606f, 0xd73e, 0x50d3, 0x8a7f, 0x8029, 0x7ffc, 0xbe31, 0x6cfb},
1865 {0x8171, 0x1f4c, 0xced2, 0x9c99, 0x6d7e, 0x5a0f, 0xfefb, 0x59e3,
1866 0xa0c8, 0xabd9, 0xc4c5, 0x57d3, 0xbfa3, 0x4f11, 0x96a2, 0x5a7d}},
1867 {{0xe068, 0x4cc0, 0x8bcd, 0xc903, 0x9e52, 0xb3e1, 0xd745, 0x0995,
1868 0xdd8f, 0xf14b, 0xd2ac, 0xd65a, 0xda1d, 0xa742, 0xbac5, 0x474c},
1869 {0x7481, 0xf2ad, 0x9757, 0x2d82, 0xb683, 0xb16b, 0x0002, 0x7b60,
1870 0x8f0c, 0x2594, 0x8f64, 0x3b7a, 0x3552, 0x8d9d, 0xb9d7, 0x67eb},
1871 {0xcaab, 0xb9a1, 0xf966, 0xe311, 0x5b34, 0x0fa0, 0x6abc, 0x8134,
1872 0xab3d, 0x90f6, 0x1984, 0x9232, 0xec17, 0x74e5, 0x2ceb, 0x434e}},
1873 {{0x0fb1, 0x7a55, 0x1a5c, 0x53eb, 0xd7b3, 0x7a01, 0xca32, 0x31f6,
1874 0x3b74, 0x679e, 0x1501, 0x6c57, 0xdb20, 0x8b7c, 0xd7d0, 0x8097},
1875 {0xb127, 0xb20c, 0xe3a2, 0x96f3, 0xe0d8, 0xd50c, 0x14b4, 0x0b40,
1876 0x6eeb, 0xa258, 0x99db, 0x3c8c, 0x0f51, 0x4198, 0x3887, 0xffd0},
1877 {0x0273, 0x9f8c, 0x9669, 0xbbba, 0x1c49, 0x767c, 0xc2af, 0x59f0,
1878 0x1366, 0xd397, 0x63ac, 0x6fe8, 0x1a9a, 0x1259, 0x01d0, 0x0016}},
1879 {{0x7876, 0x2a35, 0xa24a, 0x433e, 0x5501, 0x573c, 0xd76d, 0xcb82,
1880 0x1334, 0xb4a6, 0xf290, 0xc797, 0xeae9, 0x2b83, 0x1e2b, 0x8b14},
1881 {0x3885, 0x8aef, 0x9dea, 0x2b8c, 0xdd7c, 0xd7cd, 0xb0cc, 0x05ee,
1882 0x361b, 0x3800, 0xb0d4, 0x4c23, 0xbd3f, 0x5180, 0x9783, 0xff80},
1883 {0xab36, 0x3104, 0xdae8, 0x0704, 0x4a28, 0x6714, 0x824b, 0x0051,
1884 0x8134, 0x1f6a, 0x712d, 0x1f03, 0x03b2, 0xecac, 0x377d, 0xfef9}}
1885 };
1886
1887 int i, j, ok;
1888
1889 /* Test known inputs/outputs */
1890 for (i = 0; (size_t)i < ARRAY_SIZE(CASES); ++i) {
1891 uint16_t out[16];
1892 test_modinv32_uint16(out, CASES[i][0], CASES[i][1]);
1893 for (j = 0; j < 16; ++j) CHECK(out[j] == CASES[i][2][j]);
1894#ifdef SECP256K1_WIDEMUL_INT128
1895 test_modinv64_uint16(out, CASES[i][0], CASES[i][1]);
1896 for (j = 0; j < 16; ++j) CHECK(out[j] == CASES[i][2][j]);
1897#endif
1898 }
1899
1900 for (i = 0; i < 100 * COUNT; ++i) {
1901 /* 256-bit numbers in 16-uint16_t's notation */
1902 static const uint16_t ZERO[16] = {0};
1903 uint16_t xd[16]; /* the number (in range [0,2^256)) to be inverted */
1904 uint16_t md[16]; /* the modulus (odd, in range [3,2^256)) */
1905 uint16_t id[16]; /* the inverse of xd mod md */
1906
1907 /* generate random xd and md, so that md is odd, md>1, xd<md, and gcd(xd,md)=1 */
1908 do {
1909 /* generate random xd and md (with many subsequent 0s and 1s) */
1910 testrand256_test((unsigned char*)xd);
1911 testrand256_test((unsigned char*)md);
1912 md[0] |= 1; /* modulus must be odd */
1913 /* If modulus is 1, find another one. */
1914 ok = md[0] != 1;
1915 for (j = 1; j < 16; ++j) ok |= md[j] != 0;
1916 mulmod256(xd, xd, NULL, md); /* Make xd = xd mod md */
1917 } while (!(ok && coprime(xd, md)));
1918
1919 test_modinv32_uint16(id, xd, md);
1920#ifdef SECP256K1_WIDEMUL_INT128
1921 test_modinv64_uint16(id, xd, md);
1922#endif
1923
1924 /* In a few cases, also test with input=0 */
1925 if (i < COUNT) {
1926 test_modinv32_uint16(id, ZERO, md);
1927#ifdef SECP256K1_WIDEMUL_INT128
1928 test_modinv64_uint16(id, ZERO, md);
1929#endif
1930 }
1931 }
1932}
1933
1934/***** INT128 TESTS *****/
1935
1936#ifdef SECP256K1_WIDEMUL_INT128
1937/* Add two 256-bit numbers (represented as 16 uint16_t's in LE order) together mod 2^256. */
1938static void add256(uint16_t* out, const uint16_t* a, const uint16_t* b) {
1939 int i;
1940 uint32_t carry = 0;
1941 for (i = 0; i < 16; ++i) {
1942 carry += a[i];
1943 carry += b[i];
1944 out[i] = carry;
1945 carry >>= 16;
1946 }
1947}
1948
1949/* Negate a 256-bit number (represented as 16 uint16_t's in LE order) mod 2^256. */
1950static void neg256(uint16_t* out, const uint16_t* a) {
1951 int i;
1952 uint32_t carry = 1;
1953 for (i = 0; i < 16; ++i) {
1954 carry += (uint16_t)~a[i];
1955 out[i] = carry;
1956 carry >>= 16;
1957 }
1958}
1959
1960/* Right-shift a 256-bit number (represented as 16 uint16_t's in LE order). */
1961static void rshift256(uint16_t* out, const uint16_t* a, int n, int sign_extend) {
1962 uint16_t sign = sign_extend && (a[15] >> 15);
1963 int i, j;
1964 for (i = 15; i >= 0; --i) {
1965 uint16_t v = 0;
1966 for (j = 0; j < 16; ++j) {
1967 int frompos = i*16 + j + n;
1968 if (frompos >= 256) {
1969 v |= sign << j;
1970 } else {
1971 v |= ((uint16_t)((a[frompos >> 4] >> (frompos & 15)) & 1)) << j;
1972 }
1973 }
1974 out[i] = v;
1975 }
1976}
1977
1978/* Load a 64-bit unsigned integer into an array of 16 uint16_t's in LE order representing a 256-bit value. */
1979static void load256u64(uint16_t* out, uint64_t v, int is_signed) {
1980 int i;
1981 uint64_t sign = is_signed && (v >> 63) ? UINT64_MAX : 0;
1982 for (i = 0; i < 4; ++i) {
1983 out[i] = v >> (16 * i);
1984 }
1985 for (i = 4; i < 16; ++i) {
1986 out[i] = sign;
1987 }
1988}
1989
1990/* Load a 128-bit unsigned integer into an array of 16 uint16_t's in LE order representing a 256-bit value. */
1991static void load256two64(uint16_t* out, uint64_t hi, uint64_t lo, int is_signed) {
1992 int i;
1993 uint64_t sign = is_signed && (hi >> 63) ? UINT64_MAX : 0;
1994 for (i = 0; i < 4; ++i) {
1995 out[i] = lo >> (16 * i);
1996 }
1997 for (i = 4; i < 8; ++i) {
1998 out[i] = hi >> (16 * (i - 4));
1999 }
2000 for (i = 8; i < 16; ++i) {
2001 out[i] = sign;
2002 }
2003}
2004
2005/* Check whether the 256-bit value represented by array of 16-bit values is in range -2^127 < v < 2^127. */
2006static int int256is127(const uint16_t* v) {
2007 int all_0 = ((v[7] & 0x8000) == 0), all_1 = ((v[7] & 0x8000) == 0x8000);
2008 int i;
2009 for (i = 8; i < 16; ++i) {
2010 if (v[i] != 0) all_0 = 0;
2011 if (v[i] != 0xffff) all_1 = 0;
2012 }
2013 return all_0 || all_1;
2014}
2015
2016static void load256u128(uint16_t* out, const secp256k1_uint128* v) {
2017 uint64_t lo = secp256k1_u128_to_u64(v), hi = secp256k1_u128_hi_u64(v);
2018 load256two64(out, hi, lo, 0);
2019}
2020
2021static void load256i128(uint16_t* out, const secp256k1_int128* v) {
2022 uint64_t lo;
2023 int64_t hi;
2024 secp256k1_int128 c = *v;
2025 lo = secp256k1_i128_to_u64(&c);
2026 secp256k1_i128_rshift(&c, 64);
2027 hi = secp256k1_i128_to_i64(&c);
2028 load256two64(out, hi, lo, 1);
2029}
2030
2031static void run_int128_test_case(void) {
2032 unsigned char buf[32];
2033 uint64_t v[4];
2034 secp256k1_int128 swa, swz;
2035 secp256k1_uint128 uwa, uwz;
2036 uint64_t ub, uc;
2037 int64_t sb, sc;
2038 uint16_t rswa[16], rswz[32], rswr[32], ruwa[16], ruwz[32], ruwr[32];
2039 uint16_t rub[16], ruc[16], rsb[16], rsc[16];
2040 int i;
2041
2042 /* Generate 32-byte random value. */
2043 testrand256_test(buf);
2044 /* Convert into 4 64-bit integers. */
2045 for (i = 0; i < 4; ++i) {
2046 uint64_t vi = 0;
2047 int j;
2048 for (j = 0; j < 8; ++j) vi = (vi << 8) + buf[8*i + j];
2049 v[i] = vi;
2050 }
2051 /* Convert those into a 128-bit value and two 64-bit values (signed and unsigned). */
2052 secp256k1_u128_load(&uwa, v[1], v[0]);
2053 secp256k1_i128_load(&swa, v[1], v[0]);
2054 ub = v[2];
2055 sb = v[2];
2056 uc = v[3];
2057 sc = v[3];
2058 /* Load those also into 16-bit array representations. */
2059 load256u128(ruwa, &uwa);
2060 load256i128(rswa, &swa);
2061 load256u64(rub, ub, 0);
2062 load256u64(rsb, sb, 1);
2063 load256u64(ruc, uc, 0);
2064 load256u64(rsc, sc, 1);
2065 /* test secp256k1_u128_mul */
2066 mulmod256(ruwr, rub, ruc, NULL);
2067 secp256k1_u128_mul(&uwz, ub, uc);
2068 load256u128(ruwz, &uwz);
2069 CHECK(secp256k1_memcmp_var(ruwr, ruwz, 16) == 0);
2070 /* test secp256k1_u128_accum_mul */
2071 mulmod256(ruwr, rub, ruc, NULL);
2072 add256(ruwr, ruwr, ruwa);
2073 uwz = uwa;
2074 secp256k1_u128_accum_mul(&uwz, ub, uc);
2075 load256u128(ruwz, &uwz);
2076 CHECK(secp256k1_memcmp_var(ruwr, ruwz, 16) == 0);
2077 /* test secp256k1_u128_accum_u64 */
2078 add256(ruwr, rub, ruwa);
2079 uwz = uwa;
2080 secp256k1_u128_accum_u64(&uwz, ub);
2081 load256u128(ruwz, &uwz);
2082 CHECK(secp256k1_memcmp_var(ruwr, ruwz, 16) == 0);
2083 /* test secp256k1_u128_rshift */
2084 rshift256(ruwr, ruwa, uc % 128, 0);
2085 uwz = uwa;
2086 secp256k1_u128_rshift(&uwz, uc % 128);
2087 load256u128(ruwz, &uwz);
2088 CHECK(secp256k1_memcmp_var(ruwr, ruwz, 16) == 0);
2089 /* test secp256k1_u128_to_u64 */
2090 CHECK(secp256k1_u128_to_u64(&uwa) == v[0]);
2091 /* test secp256k1_u128_hi_u64 */
2092 CHECK(secp256k1_u128_hi_u64(&uwa) == v[1]);
2093 /* test secp256k1_u128_from_u64 */
2094 secp256k1_u128_from_u64(&uwz, ub);
2095 load256u128(ruwz, &uwz);
2096 CHECK(secp256k1_memcmp_var(rub, ruwz, 16) == 0);
2097 /* test secp256k1_u128_check_bits */
2098 {
2099 int uwa_bits = 0;
2100 int j;
2101 for (j = 0; j < 128; ++j) {
2102 if (ruwa[j / 16] >> (j % 16)) uwa_bits = 1 + j;
2103 }
2104 for (j = 0; j < 128; ++j) {
2105 CHECK(secp256k1_u128_check_bits(&uwa, j) == (uwa_bits <= j));
2106 }
2107 }
2108 /* test secp256k1_i128_mul */
2109 mulmod256(rswr, rsb, rsc, NULL);
2110 secp256k1_i128_mul(&swz, sb, sc);
2111 load256i128(rswz, &swz);
2112 CHECK(secp256k1_memcmp_var(rswr, rswz, 16) == 0);
2113 /* test secp256k1_i128_accum_mul */
2114 mulmod256(rswr, rsb, rsc, NULL);
2115 add256(rswr, rswr, rswa);
2116 if (int256is127(rswr)) {
2117 swz = swa;
2118 secp256k1_i128_accum_mul(&swz, sb, sc);
2119 load256i128(rswz, &swz);
2120 CHECK(secp256k1_memcmp_var(rswr, rswz, 16) == 0);
2121 }
2122 /* test secp256k1_i128_det */
2123 {
2124 uint16_t rsd[16], rse[16], rst[32];
2125 int64_t sd = v[0], se = v[1];
2126 load256u64(rsd, sd, 1);
2127 load256u64(rse, se, 1);
2128 mulmod256(rst, rsc, rsd, NULL);
2129 neg256(rst, rst);
2130 mulmod256(rswr, rsb, rse, NULL);
2131 add256(rswr, rswr, rst);
2132 secp256k1_i128_det(&swz, sb, sc, sd, se);
2133 load256i128(rswz, &swz);
2134 CHECK(secp256k1_memcmp_var(rswr, rswz, 16) == 0);
2135 }
2136 /* test secp256k1_i128_rshift */
2137 rshift256(rswr, rswa, uc % 127, 1);
2138 swz = swa;
2139 secp256k1_i128_rshift(&swz, uc % 127);
2140 load256i128(rswz, &swz);
2141 CHECK(secp256k1_memcmp_var(rswr, rswz, 16) == 0);
2142 /* test secp256k1_i128_to_u64 */
2143 CHECK(secp256k1_i128_to_u64(&swa) == v[0]);
2144 /* test secp256k1_i128_from_i64 */
2145 secp256k1_i128_from_i64(&swz, sb);
2146 load256i128(rswz, &swz);
2147 CHECK(secp256k1_memcmp_var(rsb, rswz, 16) == 0);
2148 /* test secp256k1_i128_to_i64 */
2149 CHECK(secp256k1_i128_to_i64(&swz) == sb);
2150 /* test secp256k1_i128_eq_var */
2151 {
2152 int expect = (uc & 1);
2153 swz = swa;
2154 if (!expect) {
2155 /* Make sure swz != swa */
2156 uint64_t v0c = v[0], v1c = v[1];
2157 if (ub & 64) {
2158 v1c ^= (((uint64_t)1) << (ub & 63));
2159 } else {
2160 v0c ^= (((uint64_t)1) << (ub & 63));
2161 }
2162 secp256k1_i128_load(&swz, v1c, v0c);
2163 }
2164 CHECK(secp256k1_i128_eq_var(&swa, &swz) == expect);
2165 }
2166 /* test secp256k1_i128_check_pow2 (sign == 1) */
2167 {
2168 int expect = (uc & 1);
2169 int pos = ub % 127;
2170 if (expect) {
2171 /* If expect==1, set swz to exactly 2^pos. */
2172 uint64_t hi = 0;
2173 uint64_t lo = 0;
2174 if (pos >= 64) {
2175 hi = (((uint64_t)1) << (pos & 63));
2176 } else {
2177 lo = (((uint64_t)1) << (pos & 63));
2178 }
2179 secp256k1_i128_load(&swz, hi, lo);
2180 } else {
2181 /* If expect==0, set swz = swa, but update expect=1 if swa happens to equal 2^pos. */
2182 if (pos >= 64) {
2183 if ((v[1] == (((uint64_t)1) << (pos & 63))) && v[0] == 0) expect = 1;
2184 } else {
2185 if ((v[0] == (((uint64_t)1) << (pos & 63))) && v[1] == 0) expect = 1;
2186 }
2187 swz = swa;
2188 }
2189 CHECK(secp256k1_i128_check_pow2(&swz, pos, 1) == expect);
2190 }
2191 /* test secp256k1_i128_check_pow2 (sign == -1) */
2192 {
2193 int expect = (uc & 1);
2194 int pos = ub % 127;
2195 if (expect) {
2196 /* If expect==1, set swz to exactly -2^pos. */
2197 uint64_t hi = ~(uint64_t)0;
2198 uint64_t lo = ~(uint64_t)0;
2199 if (pos >= 64) {
2200 hi <<= (pos & 63);
2201 lo = 0;
2202 } else {
2203 lo <<= (pos & 63);
2204 }
2205 secp256k1_i128_load(&swz, hi, lo);
2206 } else {
2207 /* If expect==0, set swz = swa, but update expect=1 if swa happens to equal -2^pos. */
2208 if (pos >= 64) {
2209 if ((v[1] == ((~(uint64_t)0) << (pos & 63))) && v[0] == 0) expect = 1;
2210 } else {
2211 if ((v[0] == ((~(uint64_t)0) << (pos & 63))) && v[1] == ~(uint64_t)0) expect = 1;
2212 }
2213 swz = swa;
2214 }
2215 CHECK(secp256k1_i128_check_pow2(&swz, pos, -1) == expect);
2216 }
2217}
2218
2219static void run_int128_tests(void) {
2220 { /* secp256k1_u128_accum_mul */
2222
2223 /* Check secp256k1_u128_accum_mul overflow */
2224 secp256k1_u128_mul(&res, UINT64_MAX, UINT64_MAX);
2225 secp256k1_u128_accum_mul(&res, UINT64_MAX, UINT64_MAX);
2226 CHECK(secp256k1_u128_to_u64(&res) == 2);
2227 CHECK(secp256k1_u128_hi_u64(&res) == 18446744073709551612U);
2228 }
2229 { /* secp256k1_u128_accum_mul */
2230 secp256k1_int128 res;
2231
2232 /* Compute INT128_MAX = 2^127 - 1 with secp256k1_i128_accum_mul */
2233 secp256k1_i128_mul(&res, INT64_MAX, INT64_MAX);
2234 secp256k1_i128_accum_mul(&res, INT64_MAX, INT64_MAX);
2235 CHECK(secp256k1_i128_to_u64(&res) == 2);
2236 secp256k1_i128_accum_mul(&res, 4, 9223372036854775807);
2237 secp256k1_i128_accum_mul(&res, 1, 1);
2238 CHECK(secp256k1_i128_to_u64(&res) == UINT64_MAX);
2239 secp256k1_i128_rshift(&res, 64);
2240 CHECK(secp256k1_i128_to_i64(&res) == INT64_MAX);
2241
2242 /* Compute INT128_MIN = - 2^127 with secp256k1_i128_accum_mul */
2243 secp256k1_i128_mul(&res, INT64_MAX, INT64_MIN);
2244 CHECK(secp256k1_i128_to_u64(&res) == (uint64_t)INT64_MIN);
2245 secp256k1_i128_accum_mul(&res, INT64_MAX, INT64_MIN);
2246 CHECK(secp256k1_i128_to_u64(&res) == 0);
2247 secp256k1_i128_accum_mul(&res, 2, INT64_MIN);
2248 CHECK(secp256k1_i128_to_u64(&res) == 0);
2249 secp256k1_i128_rshift(&res, 64);
2250 CHECK(secp256k1_i128_to_i64(&res) == INT64_MIN);
2251 }
2252 {
2253 /* Randomized tests. */
2254 int i;
2255 for (i = 0; i < 256 * COUNT; ++i) run_int128_test_case();
2256 }
2257}
2258#endif
2259
2260/***** SCALAR TESTS *****/
2261
2262static void scalar_test(void) {
2266 unsigned char c[32];
2267
2268 /* Set 's' to a random scalar, with value 'snum'. */
2270
2271 /* Set 's1' to a random scalar, with value 's1num'. */
2273
2274 /* Set 's2' to a random scalar, with value 'snum2', and byte array representation 'c'. */
2277
2278 {
2279 int i;
2280 /* Test that fetching groups of 4 bits from a scalar and recursing n(i)=16*n(i-1)+p(i) reconstructs it. */
2283 for (i = 0; i < 256; i += 4) {
2285 int j;
2287 for (j = 0; j < 4; j++) {
2288 secp256k1_scalar_add(&n, &n, &n);
2289 }
2290 secp256k1_scalar_add(&n, &n, &t);
2291 }
2293 }
2294
2295 {
2296 /* Test that fetching groups of randomly-sized bits from a scalar and recursing n(i)=b*n(i-1)+p(i) reconstructs it. */
2298 int i = 0;
2300 while (i < 256) {
2302 int j;
2303 int now = testrand_int(15) + 1;
2304 if (now + i > 256) {
2305 now = 256 - i;
2306 }
2308 for (j = 0; j < now; j++) {
2309 secp256k1_scalar_add(&n, &n, &n);
2310 }
2311 secp256k1_scalar_add(&n, &n, &t);
2312 i += now;
2313 }
2315 }
2316
2317 {
2318 /* Test commutativity of add. */
2319 secp256k1_scalar r1, r2;
2320 secp256k1_scalar_add(&r1, &s1, &s2);
2321 secp256k1_scalar_add(&r2, &s2, &s1);
2322 CHECK(secp256k1_scalar_eq(&r1, &r2));
2323 }
2324
2325 {
2326 secp256k1_scalar r1, r2;
2328 int i;
2329 /* Test add_bit. */
2330 int bit = testrand_bits(8);
2333 for (i = 0; i < bit; i++) {
2334 secp256k1_scalar_add(&b, &b, &b);
2335 }
2336 r1 = s1;
2337 r2 = s1;
2338 if (!secp256k1_scalar_add(&r1, &r1, &b)) {
2339 /* No overflow happened. */
2340 secp256k1_scalar_cadd_bit(&r2, bit, 1);
2341 CHECK(secp256k1_scalar_eq(&r1, &r2));
2342 /* cadd is a noop when flag is zero */
2343 secp256k1_scalar_cadd_bit(&r2, bit, 0);
2344 CHECK(secp256k1_scalar_eq(&r1, &r2));
2345 }
2346 }
2347
2348 {
2349 /* Test commutativity of mul. */
2350 secp256k1_scalar r1, r2;
2351 secp256k1_scalar_mul(&r1, &s1, &s2);
2352 secp256k1_scalar_mul(&r2, &s2, &s1);
2353 CHECK(secp256k1_scalar_eq(&r1, &r2));
2354 }
2355
2356 {
2357 /* Test associativity of add. */
2358 secp256k1_scalar r1, r2;
2359 secp256k1_scalar_add(&r1, &s1, &s2);
2360 secp256k1_scalar_add(&r1, &r1, &s);
2361 secp256k1_scalar_add(&r2, &s2, &s);
2362 secp256k1_scalar_add(&r2, &s1, &r2);
2363 CHECK(secp256k1_scalar_eq(&r1, &r2));
2364 }
2365
2366 {
2367 /* Test associativity of mul. */
2368 secp256k1_scalar r1, r2;
2369 secp256k1_scalar_mul(&r1, &s1, &s2);
2370 secp256k1_scalar_mul(&r1, &r1, &s);
2371 secp256k1_scalar_mul(&r2, &s2, &s);
2372 secp256k1_scalar_mul(&r2, &s1, &r2);
2373 CHECK(secp256k1_scalar_eq(&r1, &r2));
2374 }
2375
2376 {
2377 /* Test distributitivity of mul over add. */
2378 secp256k1_scalar r1, r2, t;
2379 secp256k1_scalar_add(&r1, &s1, &s2);
2380 secp256k1_scalar_mul(&r1, &r1, &s);
2381 secp256k1_scalar_mul(&r2, &s1, &s);
2382 secp256k1_scalar_mul(&t, &s2, &s);
2383 secp256k1_scalar_add(&r2, &r2, &t);
2384 CHECK(secp256k1_scalar_eq(&r1, &r2));
2385 }
2386
2387 {
2388 /* Test multiplicative identity. */
2391 CHECK(secp256k1_scalar_eq(&r1, &s1));
2392 }
2393
2394 {
2395 /* Test additive identity. */
2398 CHECK(secp256k1_scalar_eq(&r1, &s1));
2399 }
2400
2401 {
2402 /* Test zero product property. */
2406 }
2407
2408 {
2409 /* Test halving. */
2411 secp256k1_scalar_add(&r, &s, &s);
2412 secp256k1_scalar_half(&r, &r);
2414 }
2415}
2416
2418 unsigned char b32[32];
2421
2422 /* Usually set_b32 and set_b32_seckey give the same result */
2424 secp256k1_scalar_set_b32(&s1, b32, NULL);
2425 CHECK(secp256k1_scalar_set_b32_seckey(&s2, b32) == 1);
2426 CHECK(secp256k1_scalar_eq(&s1, &s2) == 1);
2427
2428 memset(b32, 0, sizeof(b32));
2429 CHECK(secp256k1_scalar_set_b32_seckey(&s2, b32) == 0);
2430 memset(b32, 0xFF, sizeof(b32));
2431 CHECK(secp256k1_scalar_set_b32_seckey(&s2, b32) == 0);
2432}
2433
2436 const secp256k1_scalar n_minus_1 = SECP256K1_SCALAR_CONST(
2437 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFEUL,
2438 0xBAAEDCE6UL, 0xAF48A03BUL, 0xBFD25E8CUL, 0xD0364140UL
2439 );
2441 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFEUL,
2442 0xBAAEDCE6UL, 0xAF48A03BUL, 0xBFD25E8CUL, 0xD0364141UL
2443 );
2445 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFEUL,
2446 0xBAAEDCE6UL, 0xAF48A03BUL, 0xBFD25E8CUL, 0xD0364142UL
2447 );
2449 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL,
2450 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL
2451 );
2452
2453 int i;
2454
2457 CHECK(secp256k1_scalar_check_overflow(&n_minus_1) == 0);
2459 CHECK(secp256k1_scalar_check_overflow(&n_plus_1) == 1);
2461
2462 for (i = 0; i < 2 * COUNT; i++) {
2463 int expected_overflow;
2464 int overflow = 0;
2465 unsigned char b32[32];
2466
2467 testrand256(b32);
2468
2469 /* Force top bits to be 0xFF sometimes to ensure we hit overflows */
2470 if (i % 2 == 0) {
2471 memset(b32, 0xFF, 16);
2472 }
2473
2474 expected_overflow = (secp256k1_memcmp_var(b32, secp256k1_group_order_bytes, 32) >= 0);
2475
2476 secp256k1_scalar_set_b32(&s, b32, &overflow);
2477 CHECK(overflow == expected_overflow);
2478 }
2479}
2480
2481static void run_scalar_tests(void) {
2482 int i;
2483
2485
2486 for (i = 0; i < 128 * COUNT; i++) {
2487 scalar_test();
2488 }
2489 for (i = 0; i < COUNT; i++) {
2491 }
2492
2493 {
2494 /* Check that the scalar constants secp256k1_scalar_zero and
2495 secp256k1_scalar_one contain the expected values. */
2496 secp256k1_scalar zero, one;
2497
2499 secp256k1_scalar_set_int(&zero, 0);
2501
2503 secp256k1_scalar_set_int(&one, 1);
2505 }
2506
2507 {
2508 /* (-1)+1 should be zero. */
2515 }
2516
2517 {
2518 /* Test that halving and doubling roundtrips on some fixed values. */
2519 static const secp256k1_scalar HALF_TESTS[] = {
2520 /* 0 */
2521 SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 0),
2522 /* 1 */
2523 SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 1),
2524 /* -1 */
2525 SECP256K1_SCALAR_CONST(0xfffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffeul, 0xbaaedce6ul, 0xaf48a03bul, 0xbfd25e8cul, 0xd0364140ul),
2526 /* -2 (largest odd value) */
2527 SECP256K1_SCALAR_CONST(0xfffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffeul, 0xbaaedce6ul, 0xaf48a03bul, 0xbfd25e8cul, 0xd036413Ful),
2528 /* Half the secp256k1 order */
2529 SECP256K1_SCALAR_CONST(0x7ffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffful, 0x5d576e73ul, 0x57a4501dul, 0xdfe92f46ul, 0x681b20a0ul),
2530 /* Half the secp256k1 order + 1 */
2531 SECP256K1_SCALAR_CONST(0x7ffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffful, 0x5d576e73ul, 0x57a4501dul, 0xdfe92f46ul, 0x681b20a1ul),
2532 /* 2^255 */
2533 SECP256K1_SCALAR_CONST(0x80000000ul, 0, 0, 0, 0, 0, 0, 0),
2534 /* 2^255 - 1 */
2535 SECP256K1_SCALAR_CONST(0x7ffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffful, 0xfffffffful),
2536 };
2537 unsigned n;
2538 for (n = 0; n < ARRAY_SIZE(HALF_TESTS); ++n) {
2540 secp256k1_scalar_half(&s, &HALF_TESTS[n]);
2541 secp256k1_scalar_add(&s, &s, &s);
2542 CHECK(secp256k1_scalar_eq(&s, &HALF_TESTS[n]));
2543 secp256k1_scalar_add(&s, &s, &s);
2545 CHECK(secp256k1_scalar_eq(&s, &HALF_TESTS[n]));
2546 }
2547 }
2548
2549 {
2550 /* Static test vectors.
2551 * These were reduced from ~10^12 random vectors based on comparison-decision
2552 * and edge-case coverage on 32-bit and 64-bit implementations.
2553 * The responses were generated with Sage 5.9.
2554 */
2561 secp256k1_scalar zzv;
2562 int overflow;
2563 unsigned char chal[33][2][32] = {
2564 {{0xff, 0xff, 0x03, 0x07, 0x00, 0x00, 0x00, 0x00,
2565 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x03,
2566 0x00, 0x00, 0x00, 0x00, 0x00, 0xf8, 0xff, 0xff,
2567 0xff, 0xff, 0x03, 0x00, 0xc0, 0xff, 0xff, 0xff},
2568 {0xff, 0xff, 0xff, 0xff, 0xff, 0x0f, 0x00, 0x00,
2569 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xf8,
2570 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2571 0xff, 0x03, 0x00, 0x00, 0x00, 0x00, 0xe0, 0xff}},
2572 {{0xef, 0xff, 0x1f, 0x00, 0x00, 0x00, 0x00, 0x00,
2573 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0x3f, 0x00,
2574 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2575 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00},
2576 {0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0x00,
2577 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xe0,
2578 0xff, 0xff, 0xff, 0xff, 0xfc, 0xff, 0xff, 0xff,
2579 0xff, 0xff, 0xff, 0xff, 0x7f, 0x00, 0x80, 0xff}},
2580 {{0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0x00,
2581 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x00, 0x00,
2582 0x80, 0x00, 0x00, 0x80, 0xff, 0x3f, 0x00, 0x00,
2583 0x00, 0x00, 0x00, 0xf8, 0xff, 0xff, 0xff, 0x00},
2584 {0x00, 0x00, 0xfc, 0xff, 0xff, 0xff, 0xff, 0x80,
2585 0xff, 0xff, 0xff, 0xff, 0xff, 0x0f, 0x00, 0xe0,
2586 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f, 0x00, 0x00,
2587 0x00, 0x00, 0x00, 0x00, 0x7f, 0xff, 0xff, 0xff}},
2588 {{0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0x00,
2589 0x00, 0x00, 0x00, 0x00, 0x80, 0x00, 0x00, 0x80,
2590 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2591 0x00, 0x1e, 0xf8, 0xff, 0xff, 0xff, 0xfd, 0xff},
2592 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x1f,
2593 0x00, 0x00, 0x00, 0xf8, 0xff, 0x03, 0x00, 0xe0,
2594 0xff, 0x0f, 0x00, 0x00, 0x00, 0x00, 0xf0, 0xff,
2595 0xf3, 0xff, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00}},
2596 {{0x80, 0x00, 0x00, 0x80, 0xff, 0xff, 0xff, 0x00,
2597 0x00, 0x1c, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff,
2598 0xff, 0xff, 0xff, 0xe0, 0xff, 0xff, 0xff, 0x00,
2599 0x00, 0x00, 0x00, 0x00, 0xe0, 0xff, 0xff, 0xff},
2600 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x03, 0x00,
2601 0xf8, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2602 0xff, 0x1f, 0x00, 0x00, 0x80, 0xff, 0xff, 0x3f,
2603 0x00, 0xfe, 0xff, 0xff, 0xff, 0xdf, 0xff, 0xff}},
2604 {{0xff, 0xff, 0xff, 0xff, 0x00, 0x0f, 0xfc, 0x9f,
2605 0xff, 0xff, 0xff, 0x00, 0x80, 0x00, 0x00, 0x80,
2606 0xff, 0x0f, 0xfc, 0xff, 0x7f, 0x00, 0x00, 0x00,
2607 0x00, 0xf8, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00},
2608 {0x08, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x80,
2609 0x00, 0x00, 0xf8, 0xff, 0x0f, 0xc0, 0xff, 0xff,
2610 0xff, 0x1f, 0x00, 0x00, 0x00, 0xc0, 0xff, 0xff,
2611 0xff, 0xff, 0xff, 0x07, 0x80, 0xff, 0xff, 0xff}},
2612 {{0xff, 0xff, 0xff, 0xff, 0xff, 0x3f, 0x00, 0x00,
2613 0x80, 0x00, 0x00, 0x80, 0xff, 0xff, 0xff, 0xff,
2614 0xf7, 0xff, 0xff, 0xef, 0xff, 0xff, 0xff, 0x00,
2615 0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0xf0},
2616 {0x00, 0x00, 0x00, 0x00, 0xf8, 0xff, 0xff, 0xff,
2617 0xff, 0xff, 0xff, 0xff, 0x01, 0x00, 0x00, 0x00,
2618 0x00, 0x00, 0x80, 0xff, 0xff, 0xff, 0xff, 0xff,
2619 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}},
2620 {{0x00, 0xf8, 0xff, 0x03, 0xff, 0xff, 0xff, 0x00,
2621 0x00, 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2622 0x80, 0x00, 0x00, 0x80, 0xff, 0xff, 0xff, 0xff,
2623 0xff, 0xff, 0x03, 0xc0, 0xff, 0x0f, 0xfc, 0xff},
2624 {0xff, 0xff, 0xff, 0xff, 0xff, 0xe0, 0xff, 0xff,
2625 0xff, 0x01, 0x00, 0x00, 0x00, 0x3f, 0x00, 0xc0,
2626 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2627 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}},
2628 {{0x8f, 0x0f, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2629 0x00, 0x00, 0xf8, 0xff, 0xff, 0xff, 0xff, 0xff,
2630 0xff, 0x7f, 0x00, 0x00, 0x80, 0x00, 0x00, 0x80,
2631 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00},
2632 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2633 0xff, 0x0f, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2634 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2635 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}},
2636 {{0x00, 0x00, 0x00, 0xc0, 0xff, 0xff, 0xff, 0xff,
2637 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2638 0xff, 0xff, 0x03, 0x00, 0x80, 0x00, 0x00, 0x80,
2639 0xff, 0xff, 0xff, 0x00, 0x00, 0x80, 0xff, 0x7f},
2640 {0xff, 0xcf, 0xff, 0xff, 0x01, 0x00, 0x00, 0x00,
2641 0x00, 0xc0, 0xff, 0xcf, 0xff, 0xff, 0xff, 0xff,
2642 0xbf, 0xff, 0x0e, 0x00, 0x00, 0x00, 0x00, 0x00,
2643 0x80, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00, 0x00}},
2644 {{0x00, 0x00, 0x00, 0x00, 0x00, 0x80, 0xff, 0xff,
2645 0xff, 0xff, 0x00, 0xfc, 0xff, 0xff, 0xff, 0xff,
2646 0xff, 0xff, 0xff, 0x00, 0x80, 0x00, 0x00, 0x80,
2647 0xff, 0x01, 0xfc, 0xff, 0x01, 0x00, 0xfe, 0xff},
2648 {0xff, 0xff, 0xff, 0x03, 0x00, 0x00, 0x00, 0x00,
2649 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2650 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xc0,
2651 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x03, 0x00}},
2652 {{0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0x00,
2653 0xe0, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2654 0x00, 0xf8, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2655 0x7f, 0x00, 0x00, 0x00, 0x80, 0x00, 0x00, 0x80},
2656 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2657 0x00, 0xf8, 0xff, 0x01, 0x00, 0xf0, 0xff, 0xff,
2658 0xe0, 0xff, 0x0f, 0x00, 0x00, 0x00, 0x00, 0x00,
2659 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}},
2660 {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2661 0xff, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2662 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2663 0x00, 0x00, 0x00, 0x00, 0x00, 0xf8, 0xff, 0x00},
2664 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00,
2665 0xfc, 0xff, 0xff, 0x3f, 0xf0, 0xff, 0xff, 0x3f,
2666 0x00, 0x00, 0xf8, 0x07, 0x00, 0x00, 0x00, 0xff,
2667 0xff, 0xff, 0xff, 0xff, 0x0f, 0x7e, 0x00, 0x00}},
2668 {{0x00, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2669 0x00, 0x00, 0x00, 0x00, 0x80, 0x00, 0x00, 0x80,
2670 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2671 0xff, 0xff, 0x1f, 0x00, 0x00, 0xfe, 0x07, 0x00},
2672 {0x00, 0x00, 0x00, 0xf0, 0xff, 0xff, 0xff, 0xff,
2673 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2674 0xff, 0xfb, 0xff, 0x07, 0x00, 0x00, 0x00, 0x00,
2675 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x60}},
2676 {{0xff, 0x01, 0x00, 0xff, 0xff, 0xff, 0x0f, 0x00,
2677 0x80, 0x7f, 0xfe, 0xff, 0xff, 0xff, 0xff, 0x03,
2678 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2679 0x00, 0x80, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff},
2680 {0xff, 0xff, 0x1f, 0x00, 0xf0, 0xff, 0xff, 0xff,
2681 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2682 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2683 0xff, 0xff, 0xff, 0x3f, 0x00, 0x00, 0x00, 0x00}},
2684 {{0x80, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff,
2685 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2686 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2687 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff},
2688 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2689 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xf1, 0xff,
2690 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x03,
2691 0x00, 0x00, 0x00, 0xe0, 0xff, 0xff, 0xff, 0xff}},
2692 {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2693 0x7e, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2694 0xc0, 0xff, 0xff, 0xcf, 0xff, 0x1f, 0x00, 0x00,
2695 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x80},
2696 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2697 0x00, 0x00, 0x00, 0x00, 0x00, 0xe0, 0xff, 0xff,
2698 0xff, 0xff, 0xff, 0xff, 0xff, 0x3f, 0x00, 0x7e,
2699 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}},
2700 {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2701 0x00, 0x00, 0x00, 0xfc, 0xff, 0xff, 0xff, 0xff,
2702 0xff, 0xff, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00,
2703 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x7c, 0x00},
2704 {0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x80,
2705 0xff, 0xff, 0x7f, 0x00, 0x80, 0x00, 0x00, 0x00,
2706 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2707 0x00, 0x00, 0xe0, 0xff, 0xff, 0xff, 0xff, 0xff}},
2708 {{0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0x00, 0x80,
2709 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2710 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x80,
2711 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00},
2712 {0xf0, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2713 0xff, 0xff, 0xff, 0xff, 0x3f, 0x00, 0x00, 0x80,
2714 0xff, 0x01, 0x00, 0x00, 0x00, 0x00, 0xff, 0xff,
2715 0xff, 0x7f, 0xf8, 0xff, 0xff, 0x1f, 0x00, 0xfe}},
2716 {{0xff, 0xff, 0xff, 0x3f, 0xf8, 0xff, 0xff, 0xff,
2717 0xff, 0x03, 0xfe, 0x01, 0x00, 0x00, 0x00, 0x00,
2718 0xf0, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2719 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x07},
2720 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2721 0x80, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x80,
2722 0xff, 0xff, 0xff, 0xff, 0x01, 0x80, 0xff, 0xff,
2723 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00}},
2724 {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2725 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2726 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2727 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00},
2728 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2729 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe,
2730 0xba, 0xae, 0xdc, 0xe6, 0xaf, 0x48, 0xa0, 0x3b,
2731 0xbf, 0xd2, 0x5e, 0x8c, 0xd0, 0x36, 0x41, 0x40}},
2732 {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2733 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2734 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2735 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01},
2736 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2737 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2738 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2739 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}},
2740 {{0x7f, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2741 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2742 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2743 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff},
2744 {0x7f, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2745 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2746 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2747 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}},
2748 {{0xff, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00, 0xc0,
2749 0xff, 0x0f, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2750 0x00, 0x00, 0xf0, 0xff, 0xff, 0xff, 0xff, 0xff,
2751 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f},
2752 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x01, 0x00,
2753 0xf0, 0xff, 0xff, 0xff, 0xff, 0x07, 0x00, 0x00,
2754 0x00, 0x00, 0x00, 0xfe, 0xff, 0xff, 0xff, 0xff,
2755 0xff, 0xff, 0xff, 0xff, 0x01, 0xff, 0xff, 0xff}},
2756 {{0x7f, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2757 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2758 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2759 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff},
2760 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2761 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2762 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2763 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x02}},
2764 {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2765 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe,
2766 0xba, 0xae, 0xdc, 0xe6, 0xaf, 0x48, 0xa0, 0x3b,
2767 0xbf, 0xd2, 0x5e, 0x8c, 0xd0, 0x36, 0x41, 0x40},
2768 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2769 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2770 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2771 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01}},
2772 {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2773 0x7e, 0x00, 0x00, 0xc0, 0xff, 0xff, 0x07, 0x00,
2774 0x80, 0x00, 0x00, 0x00, 0x80, 0x00, 0x00, 0x00,
2775 0xfc, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff},
2776 {0xff, 0x01, 0x00, 0x00, 0x00, 0xe0, 0xff, 0xff,
2777 0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0x00, 0x80,
2778 0xff, 0xff, 0xff, 0xff, 0xff, 0x03, 0x00, 0x00,
2779 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff}},
2780 {{0xff, 0xff, 0xf0, 0xff, 0xff, 0xff, 0xff, 0x00,
2781 0xf0, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2782 0x00, 0xe0, 0xff, 0xff, 0xff, 0xff, 0xff, 0x01,
2783 0x80, 0x00, 0x00, 0x80, 0xff, 0xff, 0xff, 0xff},
2784 {0x00, 0x00, 0x00, 0x00, 0x00, 0xe0, 0xff, 0xff,
2785 0xff, 0xff, 0x3f, 0x00, 0xf8, 0xff, 0xff, 0xff,
2786 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2787 0xff, 0x3f, 0x00, 0x00, 0xc0, 0xf1, 0x7f, 0x00}},
2788 {{0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0x00,
2789 0x00, 0x00, 0x00, 0xc0, 0xff, 0xff, 0xff, 0xff,
2790 0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0x00,
2791 0x80, 0x00, 0x00, 0x80, 0xff, 0xff, 0xff, 0x00},
2792 {0x00, 0xf8, 0xff, 0xff, 0xff, 0xff, 0xff, 0x01,
2793 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xf8, 0xff,
2794 0xff, 0x7f, 0x00, 0x00, 0x00, 0x00, 0x80, 0x1f,
2795 0x00, 0x00, 0xfc, 0xff, 0xff, 0x01, 0xff, 0xff}},
2796 {{0x00, 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2797 0x80, 0x00, 0x00, 0x80, 0xff, 0x03, 0xe0, 0x01,
2798 0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0xfc, 0xff,
2799 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00},
2800 {0xff, 0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00,
2801 0xfe, 0xff, 0xff, 0xf0, 0x07, 0x00, 0x3c, 0x80,
2802 0xff, 0xff, 0xff, 0xff, 0xfc, 0xff, 0xff, 0xff,
2803 0xff, 0xff, 0x07, 0xe0, 0xff, 0x00, 0x00, 0x00}},
2804 {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x00,
2805 0xfc, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2806 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x07, 0xf8,
2807 0x00, 0x00, 0x00, 0x00, 0x80, 0x00, 0x00, 0x80},
2808 {0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
2809 0xff, 0xff, 0xff, 0xff, 0xff, 0x0c, 0x80, 0x00,
2810 0x00, 0x00, 0x00, 0xc0, 0x7f, 0xfe, 0xff, 0x1f,
2811 0x00, 0xfe, 0xff, 0x03, 0x00, 0x00, 0xfe, 0xff}},
2812 {{0xff, 0xff, 0x81, 0xff, 0xff, 0xff, 0xff, 0x00,
2813 0x80, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x83,
2814 0xff, 0xff, 0x00, 0x00, 0x80, 0x00, 0x00, 0x80,
2815 0xff, 0xff, 0x7f, 0x00, 0x00, 0x00, 0x00, 0xf0},
2816 {0xff, 0x01, 0x00, 0x00, 0x00, 0x00, 0xf8, 0xff,
2817 0xff, 0xff, 0xff, 0xff, 0xff, 0x1f, 0x00, 0x00,
2818 0xf8, 0x07, 0x00, 0x80, 0xff, 0xff, 0xff, 0xff,
2819 0xff, 0xc7, 0xff, 0xff, 0xe0, 0xff, 0xff, 0xff}},
2820 {{0x82, 0xc9, 0xfa, 0xb0, 0x68, 0x04, 0xa0, 0x00,
2821 0x82, 0xc9, 0xfa, 0xb0, 0x68, 0x04, 0xa0, 0x00,
2822 0xff, 0xff, 0xff, 0xff, 0xff, 0x6f, 0x03, 0xfb,
2823 0xfa, 0x8a, 0x7d, 0xdf, 0x13, 0x86, 0xe2, 0x03},
2824 {0x82, 0xc9, 0xfa, 0xb0, 0x68, 0x04, 0xa0, 0x00,
2825 0x82, 0xc9, 0xfa, 0xb0, 0x68, 0x04, 0xa0, 0x00,
2826 0xff, 0xff, 0xff, 0xff, 0xff, 0x6f, 0x03, 0xfb,
2827 0xfa, 0x8a, 0x7d, 0xdf, 0x13, 0x86, 0xe2, 0x03}}
2828 };
2829 unsigned char res[33][2][32] = {
2830 {{0x0c, 0x3b, 0x0a, 0xca, 0x8d, 0x1a, 0x2f, 0xb9,
2831 0x8a, 0x7b, 0x53, 0x5a, 0x1f, 0xc5, 0x22, 0xa1,
2832 0x07, 0x2a, 0x48, 0xea, 0x02, 0xeb, 0xb3, 0xd6,
2833 0x20, 0x1e, 0x86, 0xd0, 0x95, 0xf6, 0x92, 0x35},
2834 {0xdc, 0x90, 0x7a, 0x07, 0x2e, 0x1e, 0x44, 0x6d,
2835 0xf8, 0x15, 0x24, 0x5b, 0x5a, 0x96, 0x37, 0x9c,
2836 0x37, 0x7b, 0x0d, 0xac, 0x1b, 0x65, 0x58, 0x49,
2837 0x43, 0xb7, 0x31, 0xbb, 0xa7, 0xf4, 0x97, 0x15}},
2838 {{0xf1, 0xf7, 0x3a, 0x50, 0xe6, 0x10, 0xba, 0x22,
2839 0x43, 0x4d, 0x1f, 0x1f, 0x7c, 0x27, 0xca, 0x9c,
2840 0xb8, 0xb6, 0xa0, 0xfc, 0xd8, 0xc0, 0x05, 0x2f,
2841 0xf7, 0x08, 0xe1, 0x76, 0xdd, 0xd0, 0x80, 0xc8},
2842 {0xe3, 0x80, 0x80, 0xb8, 0xdb, 0xe3, 0xa9, 0x77,
2843 0x00, 0xb0, 0xf5, 0x2e, 0x27, 0xe2, 0x68, 0xc4,
2844 0x88, 0xe8, 0x04, 0xc1, 0x12, 0xbf, 0x78, 0x59,
2845 0xe6, 0xa9, 0x7c, 0xe1, 0x81, 0xdd, 0xb9, 0xd5}},
2846 {{0x96, 0xe2, 0xee, 0x01, 0xa6, 0x80, 0x31, 0xef,
2847 0x5c, 0xd0, 0x19, 0xb4, 0x7d, 0x5f, 0x79, 0xab,
2848 0xa1, 0x97, 0xd3, 0x7e, 0x33, 0xbb, 0x86, 0x55,
2849 0x60, 0x20, 0x10, 0x0d, 0x94, 0x2d, 0x11, 0x7c},
2850 {0xcc, 0xab, 0xe0, 0xe8, 0x98, 0x65, 0x12, 0x96,
2851 0x38, 0x5a, 0x1a, 0xf2, 0x85, 0x23, 0x59, 0x5f,
2852 0xf9, 0xf3, 0xc2, 0x81, 0x70, 0x92, 0x65, 0x12,
2853 0x9c, 0x65, 0x1e, 0x96, 0x00, 0xef, 0xe7, 0x63}},
2854 {{0xac, 0x1e, 0x62, 0xc2, 0x59, 0xfc, 0x4e, 0x5c,
2855 0x83, 0xb0, 0xd0, 0x6f, 0xce, 0x19, 0xf6, 0xbf,
2856 0xa4, 0xb0, 0xe0, 0x53, 0x66, 0x1f, 0xbf, 0xc9,
2857 0x33, 0x47, 0x37, 0xa9, 0x3d, 0x5d, 0xb0, 0x48},
2858 {0x86, 0xb9, 0x2a, 0x7f, 0x8e, 0xa8, 0x60, 0x42,
2859 0x26, 0x6d, 0x6e, 0x1c, 0xa2, 0xec, 0xe0, 0xe5,
2860 0x3e, 0x0a, 0x33, 0xbb, 0x61, 0x4c, 0x9f, 0x3c,
2861 0xd1, 0xdf, 0x49, 0x33, 0xcd, 0x72, 0x78, 0x18}},
2862 {{0xf7, 0xd3, 0xcd, 0x49, 0x5c, 0x13, 0x22, 0xfb,
2863 0x2e, 0xb2, 0x2f, 0x27, 0xf5, 0x8a, 0x5d, 0x74,
2864 0xc1, 0x58, 0xc5, 0xc2, 0x2d, 0x9f, 0x52, 0xc6,
2865 0x63, 0x9f, 0xba, 0x05, 0x76, 0x45, 0x7a, 0x63},
2866 {0x8a, 0xfa, 0x55, 0x4d, 0xdd, 0xa3, 0xb2, 0xc3,
2867 0x44, 0xfd, 0xec, 0x72, 0xde, 0xef, 0xc0, 0x99,
2868 0xf5, 0x9f, 0xe2, 0x52, 0xb4, 0x05, 0x32, 0x58,
2869 0x57, 0xc1, 0x8f, 0xea, 0xc3, 0x24, 0x5b, 0x94}},
2870 {{0x05, 0x83, 0xee, 0xdd, 0x64, 0xf0, 0x14, 0x3b,
2871 0xa0, 0x14, 0x4a, 0x3a, 0x41, 0x82, 0x7c, 0xa7,
2872 0x2c, 0xaa, 0xb1, 0x76, 0xbb, 0x59, 0x64, 0x5f,
2873 0x52, 0xad, 0x25, 0x29, 0x9d, 0x8f, 0x0b, 0xb0},
2874 {0x7e, 0xe3, 0x7c, 0xca, 0xcd, 0x4f, 0xb0, 0x6d,
2875 0x7a, 0xb2, 0x3e, 0xa0, 0x08, 0xb9, 0xa8, 0x2d,
2876 0xc2, 0xf4, 0x99, 0x66, 0xcc, 0xac, 0xd8, 0xb9,
2877 0x72, 0x2a, 0x4a, 0x3e, 0x0f, 0x7b, 0xbf, 0xf4}},
2878 {{0x8c, 0x9c, 0x78, 0x2b, 0x39, 0x61, 0x7e, 0xf7,
2879 0x65, 0x37, 0x66, 0x09, 0x38, 0xb9, 0x6f, 0x70,
2880 0x78, 0x87, 0xff, 0xcf, 0x93, 0xca, 0x85, 0x06,
2881 0x44, 0x84, 0xa7, 0xfe, 0xd3, 0xa4, 0xe3, 0x7e},
2882 {0xa2, 0x56, 0x49, 0x23, 0x54, 0xa5, 0x50, 0xe9,
2883 0x5f, 0xf0, 0x4d, 0xe7, 0xdc, 0x38, 0x32, 0x79,
2884 0x4f, 0x1c, 0xb7, 0xe4, 0xbb, 0xf8, 0xbb, 0x2e,
2885 0x40, 0x41, 0x4b, 0xcc, 0xe3, 0x1e, 0x16, 0x36}},
2886 {{0x0c, 0x1e, 0xd7, 0x09, 0x25, 0x40, 0x97, 0xcb,
2887 0x5c, 0x46, 0xa8, 0xda, 0xef, 0x25, 0xd5, 0xe5,
2888 0x92, 0x4d, 0xcf, 0xa3, 0xc4, 0x5d, 0x35, 0x4a,
2889 0xe4, 0x61, 0x92, 0xf3, 0xbf, 0x0e, 0xcd, 0xbe},
2890 {0xe4, 0xaf, 0x0a, 0xb3, 0x30, 0x8b, 0x9b, 0x48,
2891 0x49, 0x43, 0xc7, 0x64, 0x60, 0x4a, 0x2b, 0x9e,
2892 0x95, 0x5f, 0x56, 0xe8, 0x35, 0xdc, 0xeb, 0xdc,
2893 0xc7, 0xc4, 0xfe, 0x30, 0x40, 0xc7, 0xbf, 0xa4}},
2894 {{0xd4, 0xa0, 0xf5, 0x81, 0x49, 0x6b, 0xb6, 0x8b,
2895 0x0a, 0x69, 0xf9, 0xfe, 0xa8, 0x32, 0xe5, 0xe0,
2896 0xa5, 0xcd, 0x02, 0x53, 0xf9, 0x2c, 0xe3, 0x53,
2897 0x83, 0x36, 0xc6, 0x02, 0xb5, 0xeb, 0x64, 0xb8},
2898 {0x1d, 0x42, 0xb9, 0xf9, 0xe9, 0xe3, 0x93, 0x2c,
2899 0x4c, 0xee, 0x6c, 0x5a, 0x47, 0x9e, 0x62, 0x01,
2900 0x6b, 0x04, 0xfe, 0xa4, 0x30, 0x2b, 0x0d, 0x4f,
2901 0x71, 0x10, 0xd3, 0x55, 0xca, 0xf3, 0x5e, 0x80}},
2902 {{0x77, 0x05, 0xf6, 0x0c, 0x15, 0x9b, 0x45, 0xe7,
2903 0xb9, 0x11, 0xb8, 0xf5, 0xd6, 0xda, 0x73, 0x0c,
2904 0xda, 0x92, 0xea, 0xd0, 0x9d, 0xd0, 0x18, 0x92,
2905 0xce, 0x9a, 0xaa, 0xee, 0x0f, 0xef, 0xde, 0x30},
2906 {0xf1, 0xf1, 0xd6, 0x9b, 0x51, 0xd7, 0x77, 0x62,
2907 0x52, 0x10, 0xb8, 0x7a, 0x84, 0x9d, 0x15, 0x4e,
2908 0x07, 0xdc, 0x1e, 0x75, 0x0d, 0x0c, 0x3b, 0xdb,
2909 0x74, 0x58, 0x62, 0x02, 0x90, 0x54, 0x8b, 0x43}},
2910 {{0xa6, 0xfe, 0x0b, 0x87, 0x80, 0x43, 0x67, 0x25,
2911 0x57, 0x5d, 0xec, 0x40, 0x50, 0x08, 0xd5, 0x5d,
2912 0x43, 0xd7, 0xe0, 0xaa, 0xe0, 0x13, 0xb6, 0xb0,
2913 0xc0, 0xd4, 0xe5, 0x0d, 0x45, 0x83, 0xd6, 0x13},
2914 {0x40, 0x45, 0x0a, 0x92, 0x31, 0xea, 0x8c, 0x60,
2915 0x8c, 0x1f, 0xd8, 0x76, 0x45, 0xb9, 0x29, 0x00,
2916 0x26, 0x32, 0xd8, 0xa6, 0x96, 0x88, 0xe2, 0xc4,
2917 0x8b, 0xdb, 0x7f, 0x17, 0x87, 0xcc, 0xc8, 0xf2}},
2918 {{0xc2, 0x56, 0xe2, 0xb6, 0x1a, 0x81, 0xe7, 0x31,
2919 0x63, 0x2e, 0xbb, 0x0d, 0x2f, 0x81, 0x67, 0xd4,
2920 0x22, 0xe2, 0x38, 0x02, 0x25, 0x97, 0xc7, 0x88,
2921 0x6e, 0xdf, 0xbe, 0x2a, 0xa5, 0x73, 0x63, 0xaa},
2922 {0x50, 0x45, 0xe2, 0xc3, 0xbd, 0x89, 0xfc, 0x57,
2923 0xbd, 0x3c, 0xa3, 0x98, 0x7e, 0x7f, 0x36, 0x38,
2924 0x92, 0x39, 0x1f, 0x0f, 0x81, 0x1a, 0x06, 0x51,
2925 0x1f, 0x8d, 0x6a, 0xff, 0x47, 0x16, 0x06, 0x9c}},
2926 {{0x33, 0x95, 0xa2, 0x6f, 0x27, 0x5f, 0x9c, 0x9c,
2927 0x64, 0x45, 0xcb, 0xd1, 0x3c, 0xee, 0x5e, 0x5f,
2928 0x48, 0xa6, 0xaf, 0xe3, 0x79, 0xcf, 0xb1, 0xe2,
2929 0xbf, 0x55, 0x0e, 0xa2, 0x3b, 0x62, 0xf0, 0xe4},
2930 {0x14, 0xe8, 0x06, 0xe3, 0xbe, 0x7e, 0x67, 0x01,
2931 0xc5, 0x21, 0x67, 0xd8, 0x54, 0xb5, 0x7f, 0xa4,
2932 0xf9, 0x75, 0x70, 0x1c, 0xfd, 0x79, 0xdb, 0x86,
2933 0xad, 0x37, 0x85, 0x83, 0x56, 0x4e, 0xf0, 0xbf}},
2934 {{0xbc, 0xa6, 0xe0, 0x56, 0x4e, 0xef, 0xfa, 0xf5,
2935 0x1d, 0x5d, 0x3f, 0x2a, 0x5b, 0x19, 0xab, 0x51,
2936 0xc5, 0x8b, 0xdd, 0x98, 0x28, 0x35, 0x2f, 0xc3,
2937 0x81, 0x4f, 0x5c, 0xe5, 0x70, 0xb9, 0xeb, 0x62},
2938 {0xc4, 0x6d, 0x26, 0xb0, 0x17, 0x6b, 0xfe, 0x6c,
2939 0x12, 0xf8, 0xe7, 0xc1, 0xf5, 0x2f, 0xfa, 0x91,
2940 0x13, 0x27, 0xbd, 0x73, 0xcc, 0x33, 0x31, 0x1c,
2941 0x39, 0xe3, 0x27, 0x6a, 0x95, 0xcf, 0xc5, 0xfb}},
2942 {{0x30, 0xb2, 0x99, 0x84, 0xf0, 0x18, 0x2a, 0x6e,
2943 0x1e, 0x27, 0xed, 0xa2, 0x29, 0x99, 0x41, 0x56,
2944 0xe8, 0xd4, 0x0d, 0xef, 0x99, 0x9c, 0xf3, 0x58,
2945 0x29, 0x55, 0x1a, 0xc0, 0x68, 0xd6, 0x74, 0xa4},
2946 {0x07, 0x9c, 0xe7, 0xec, 0xf5, 0x36, 0x73, 0x41,
2947 0xa3, 0x1c, 0xe5, 0x93, 0x97, 0x6a, 0xfd, 0xf7,
2948 0x53, 0x18, 0xab, 0xaf, 0xeb, 0x85, 0xbd, 0x92,
2949 0x90, 0xab, 0x3c, 0xbf, 0x30, 0x82, 0xad, 0xf6}},
2950 {{0xc6, 0x87, 0x8a, 0x2a, 0xea, 0xc0, 0xa9, 0xec,
2951 0x6d, 0xd3, 0xdc, 0x32, 0x23, 0xce, 0x62, 0x19,
2952 0xa4, 0x7e, 0xa8, 0xdd, 0x1c, 0x33, 0xae, 0xd3,
2953 0x4f, 0x62, 0x9f, 0x52, 0xe7, 0x65, 0x46, 0xf4},
2954 {0x97, 0x51, 0x27, 0x67, 0x2d, 0xa2, 0x82, 0x87,
2955 0x98, 0xd3, 0xb6, 0x14, 0x7f, 0x51, 0xd3, 0x9a,
2956 0x0b, 0xd0, 0x76, 0x81, 0xb2, 0x4f, 0x58, 0x92,
2957 0xa4, 0x86, 0xa1, 0xa7, 0x09, 0x1d, 0xef, 0x9b}},
2958 {{0xb3, 0x0f, 0x2b, 0x69, 0x0d, 0x06, 0x90, 0x64,
2959 0xbd, 0x43, 0x4c, 0x10, 0xe8, 0x98, 0x1c, 0xa3,
2960 0xe1, 0x68, 0xe9, 0x79, 0x6c, 0x29, 0x51, 0x3f,
2961 0x41, 0xdc, 0xdf, 0x1f, 0xf3, 0x60, 0xbe, 0x33},
2962 {0xa1, 0x5f, 0xf7, 0x1d, 0xb4, 0x3e, 0x9b, 0x3c,
2963 0xe7, 0xbd, 0xb6, 0x06, 0xd5, 0x60, 0x06, 0x6d,
2964 0x50, 0xd2, 0xf4, 0x1a, 0x31, 0x08, 0xf2, 0xea,
2965 0x8e, 0xef, 0x5f, 0x7d, 0xb6, 0xd0, 0xc0, 0x27}},
2966 {{0x62, 0x9a, 0xd9, 0xbb, 0x38, 0x36, 0xce, 0xf7,
2967 0x5d, 0x2f, 0x13, 0xec, 0xc8, 0x2d, 0x02, 0x8a,
2968 0x2e, 0x72, 0xf0, 0xe5, 0x15, 0x9d, 0x72, 0xae,
2969 0xfc, 0xb3, 0x4f, 0x02, 0xea, 0xe1, 0x09, 0xfe},
2970 {0x00, 0x00, 0x00, 0x00, 0xfa, 0x0a, 0x3d, 0xbc,
2971 0xad, 0x16, 0x0c, 0xb6, 0xe7, 0x7c, 0x8b, 0x39,
2972 0x9a, 0x43, 0xbb, 0xe3, 0xc2, 0x55, 0x15, 0x14,
2973 0x75, 0xac, 0x90, 0x9b, 0x7f, 0x9a, 0x92, 0x00}},
2974 {{0x8b, 0xac, 0x70, 0x86, 0x29, 0x8f, 0x00, 0x23,
2975 0x7b, 0x45, 0x30, 0xaa, 0xb8, 0x4c, 0xc7, 0x8d,
2976 0x4e, 0x47, 0x85, 0xc6, 0x19, 0xe3, 0x96, 0xc2,
2977 0x9a, 0xa0, 0x12, 0xed, 0x6f, 0xd7, 0x76, 0x16},
2978 {0x45, 0xaf, 0x7e, 0x33, 0xc7, 0x7f, 0x10, 0x6c,
2979 0x7c, 0x9f, 0x29, 0xc1, 0xa8, 0x7e, 0x15, 0x84,
2980 0xe7, 0x7d, 0xc0, 0x6d, 0xab, 0x71, 0x5d, 0xd0,
2981 0x6b, 0x9f, 0x97, 0xab, 0xcb, 0x51, 0x0c, 0x9f}},
2982 {{0x9e, 0xc3, 0x92, 0xb4, 0x04, 0x9f, 0xc8, 0xbb,
2983 0xdd, 0x9e, 0xc6, 0x05, 0xfd, 0x65, 0xec, 0x94,
2984 0x7f, 0x2c, 0x16, 0xc4, 0x40, 0xac, 0x63, 0x7b,
2985 0x7d, 0xb8, 0x0c, 0xe4, 0x5b, 0xe3, 0xa7, 0x0e},
2986 {0x43, 0xf4, 0x44, 0xe8, 0xcc, 0xc8, 0xd4, 0x54,
2987 0x33, 0x37, 0x50, 0xf2, 0x87, 0x42, 0x2e, 0x00,
2988 0x49, 0x60, 0x62, 0x02, 0xfd, 0x1a, 0x7c, 0xdb,
2989 0x29, 0x6c, 0x6d, 0x54, 0x53, 0x08, 0xd1, 0xc8}},
2990 {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2991 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2992 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2993 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00},
2994 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2995 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2996 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2997 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00}},
2998 {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
2999 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3000 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3001 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00},
3002 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3003 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3004 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3005 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01}},
3006 {{0x27, 0x59, 0xc7, 0x35, 0x60, 0x71, 0xa6, 0xf1,
3007 0x79, 0xa5, 0xfd, 0x79, 0x16, 0xf3, 0x41, 0xf0,
3008 0x57, 0xb4, 0x02, 0x97, 0x32, 0xe7, 0xde, 0x59,
3009 0xe2, 0x2d, 0x9b, 0x11, 0xea, 0x2c, 0x35, 0x92},
3010 {0x27, 0x59, 0xc7, 0x35, 0x60, 0x71, 0xa6, 0xf1,
3011 0x79, 0xa5, 0xfd, 0x79, 0x16, 0xf3, 0x41, 0xf0,
3012 0x57, 0xb4, 0x02, 0x97, 0x32, 0xe7, 0xde, 0x59,
3013 0xe2, 0x2d, 0x9b, 0x11, 0xea, 0x2c, 0x35, 0x92}},
3014 {{0x28, 0x56, 0xac, 0x0e, 0x4f, 0x98, 0x09, 0xf0,
3015 0x49, 0xfa, 0x7f, 0x84, 0xac, 0x7e, 0x50, 0x5b,
3016 0x17, 0x43, 0x14, 0x89, 0x9c, 0x53, 0xa8, 0x94,
3017 0x30, 0xf2, 0x11, 0x4d, 0x92, 0x14, 0x27, 0xe8},
3018 {0x39, 0x7a, 0x84, 0x56, 0x79, 0x9d, 0xec, 0x26,
3019 0x2c, 0x53, 0xc1, 0x94, 0xc9, 0x8d, 0x9e, 0x9d,
3020 0x32, 0x1f, 0xdd, 0x84, 0x04, 0xe8, 0xe2, 0x0a,
3021 0x6b, 0xbe, 0xbb, 0x42, 0x40, 0x67, 0x30, 0x6c}},
3022 {{0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3023 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
3024 0x45, 0x51, 0x23, 0x19, 0x50, 0xb7, 0x5f, 0xc4,
3025 0x40, 0x2d, 0xa1, 0x73, 0x2f, 0xc9, 0xbe, 0xbd},
3026 {0x27, 0x59, 0xc7, 0x35, 0x60, 0x71, 0xa6, 0xf1,
3027 0x79, 0xa5, 0xfd, 0x79, 0x16, 0xf3, 0x41, 0xf0,
3028 0x57, 0xb4, 0x02, 0x97, 0x32, 0xe7, 0xde, 0x59,
3029 0xe2, 0x2d, 0x9b, 0x11, 0xea, 0x2c, 0x35, 0x92}},
3030 {{0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
3031 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe,
3032 0xba, 0xae, 0xdc, 0xe6, 0xaf, 0x48, 0xa0, 0x3b,
3033 0xbf, 0xd2, 0x5e, 0x8c, 0xd0, 0x36, 0x41, 0x40},
3034 {0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3035 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3036 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3037 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01}},
3038 {{0x1c, 0xc4, 0xf7, 0xda, 0x0f, 0x65, 0xca, 0x39,
3039 0x70, 0x52, 0x92, 0x8e, 0xc3, 0xc8, 0x15, 0xea,
3040 0x7f, 0x10, 0x9e, 0x77, 0x4b, 0x6e, 0x2d, 0xdf,
3041 0xe8, 0x30, 0x9d, 0xda, 0xe8, 0x9a, 0x65, 0xae},
3042 {0x02, 0xb0, 0x16, 0xb1, 0x1d, 0xc8, 0x57, 0x7b,
3043 0xa2, 0x3a, 0xa2, 0xa3, 0x38, 0x5c, 0x8f, 0xeb,
3044 0x66, 0x37, 0x91, 0xa8, 0x5f, 0xef, 0x04, 0xf6,
3045 0x59, 0x75, 0xe1, 0xee, 0x92, 0xf6, 0x0e, 0x30}},
3046 {{0x8d, 0x76, 0x14, 0xa4, 0x14, 0x06, 0x9f, 0x9a,
3047 0xdf, 0x4a, 0x85, 0xa7, 0x6b, 0xbf, 0x29, 0x6f,
3048 0xbc, 0x34, 0x87, 0x5d, 0xeb, 0xbb, 0x2e, 0xa9,
3049 0xc9, 0x1f, 0x58, 0xd6, 0x9a, 0x82, 0xa0, 0x56},
3050 {0xd4, 0xb9, 0xdb, 0x88, 0x1d, 0x04, 0xe9, 0x93,
3051 0x8d, 0x3f, 0x20, 0xd5, 0x86, 0xa8, 0x83, 0x07,
3052 0xdb, 0x09, 0xd8, 0x22, 0x1f, 0x7f, 0xf1, 0x71,
3053 0xc8, 0xe7, 0x5d, 0x47, 0xaf, 0x8b, 0x72, 0xe9}},
3054 {{0x83, 0xb9, 0x39, 0xb2, 0xa4, 0xdf, 0x46, 0x87,
3055 0xc2, 0xb8, 0xf1, 0xe6, 0x4c, 0xd1, 0xe2, 0xa9,
3056 0xe4, 0x70, 0x30, 0x34, 0xbc, 0x52, 0x7c, 0x55,
3057 0xa6, 0xec, 0x80, 0xa4, 0xe5, 0xd2, 0xdc, 0x73},
3058 {0x08, 0xf1, 0x03, 0xcf, 0x16, 0x73, 0xe8, 0x7d,
3059 0xb6, 0x7e, 0x9b, 0xc0, 0xb4, 0xc2, 0xa5, 0x86,
3060 0x02, 0x77, 0xd5, 0x27, 0x86, 0xa5, 0x15, 0xfb,
3061 0xae, 0x9b, 0x8c, 0xa9, 0xf9, 0xf8, 0xa8, 0x4a}},
3062 {{0x8b, 0x00, 0x49, 0xdb, 0xfa, 0xf0, 0x1b, 0xa2,
3063 0xed, 0x8a, 0x9a, 0x7a, 0x36, 0x78, 0x4a, 0xc7,
3064 0xf7, 0xad, 0x39, 0xd0, 0x6c, 0x65, 0x7a, 0x41,
3065 0xce, 0xd6, 0xd6, 0x4c, 0x20, 0x21, 0x6b, 0xc7},
3066 {0xc6, 0xca, 0x78, 0x1d, 0x32, 0x6c, 0x6c, 0x06,
3067 0x91, 0xf2, 0x1a, 0xe8, 0x43, 0x16, 0xea, 0x04,
3068 0x3c, 0x1f, 0x07, 0x85, 0xf7, 0x09, 0x22, 0x08,
3069 0xba, 0x13, 0xfd, 0x78, 0x1e, 0x3f, 0x6f, 0x62}},
3070 {{0x25, 0x9b, 0x7c, 0xb0, 0xac, 0x72, 0x6f, 0xb2,
3071 0xe3, 0x53, 0x84, 0x7a, 0x1a, 0x9a, 0x98, 0x9b,
3072 0x44, 0xd3, 0x59, 0xd0, 0x8e, 0x57, 0x41, 0x40,
3073 0x78, 0xa7, 0x30, 0x2f, 0x4c, 0x9c, 0xb9, 0x68},
3074 {0xb7, 0x75, 0x03, 0x63, 0x61, 0xc2, 0x48, 0x6e,
3075 0x12, 0x3d, 0xbf, 0x4b, 0x27, 0xdf, 0xb1, 0x7a,
3076 0xff, 0x4e, 0x31, 0x07, 0x83, 0xf4, 0x62, 0x5b,
3077 0x19, 0xa5, 0xac, 0xa0, 0x32, 0x58, 0x0d, 0xa7}},
3078 {{0x43, 0x4f, 0x10, 0xa4, 0xca, 0xdb, 0x38, 0x67,
3079 0xfa, 0xae, 0x96, 0xb5, 0x6d, 0x97, 0xff, 0x1f,
3080 0xb6, 0x83, 0x43, 0xd3, 0xa0, 0x2d, 0x70, 0x7a,
3081 0x64, 0x05, 0x4c, 0xa7, 0xc1, 0xa5, 0x21, 0x51},
3082 {0xe4, 0xf1, 0x23, 0x84, 0xe1, 0xb5, 0x9d, 0xf2,
3083 0xb8, 0x73, 0x8b, 0x45, 0x2b, 0x35, 0x46, 0x38,
3084 0x10, 0x2b, 0x50, 0xf8, 0x8b, 0x35, 0xcd, 0x34,
3085 0xc8, 0x0e, 0xf6, 0xdb, 0x09, 0x35, 0xf0, 0xda}},
3086 {{0xdb, 0x21, 0x5c, 0x8d, 0x83, 0x1d, 0xb3, 0x34,
3087 0xc7, 0x0e, 0x43, 0xa1, 0x58, 0x79, 0x67, 0x13,
3088 0x1e, 0x86, 0x5d, 0x89, 0x63, 0xe6, 0x0a, 0x46,
3089 0x5c, 0x02, 0x97, 0x1b, 0x62, 0x43, 0x86, 0xf5},
3090 {0xdb, 0x21, 0x5c, 0x8d, 0x83, 0x1d, 0xb3, 0x34,
3091 0xc7, 0x0e, 0x43, 0xa1, 0x58, 0x79, 0x67, 0x13,
3092 0x1e, 0x86, 0x5d, 0x89, 0x63, 0xe6, 0x0a, 0x46,
3093 0x5c, 0x02, 0x97, 0x1b, 0x62, 0x43, 0x86, 0xf5}}
3094 };
3095 for (i = 0; i < 33; i++) {
3096 secp256k1_scalar_set_b32(&x, chal[i][0], &overflow);
3097 CHECK(!overflow);
3098 secp256k1_scalar_set_b32(&y, chal[i][1], &overflow);
3099 CHECK(!overflow);
3100 secp256k1_scalar_set_b32(&r1, res[i][0], &overflow);
3101 CHECK(!overflow);
3102 secp256k1_scalar_set_b32(&r2, res[i][1], &overflow);
3103 CHECK(!overflow);
3104 secp256k1_scalar_mul(&z, &x, &y);
3105 CHECK(secp256k1_scalar_eq(&r1, &z));
3106 if (!secp256k1_scalar_is_zero(&y)) {
3107 secp256k1_scalar_inverse(&zz, &y);
3109 CHECK(secp256k1_scalar_eq(&zzv, &zz));
3110 secp256k1_scalar_mul(&z, &z, &zz);
3111 CHECK(secp256k1_scalar_eq(&x, &z));
3112 secp256k1_scalar_mul(&zz, &zz, &y);
3114 }
3115 secp256k1_scalar_mul(&z, &x, &x);
3116 CHECK(secp256k1_scalar_eq(&r2, &z));
3117 }
3118 }
3119}
3120
3121/***** FIELD TESTS *****/
3122
3124 secp256k1_fe r;
3126 if (secp256k1_fe_sqrt(&r, ns)) {
3127 secp256k1_fe_negate(ns, ns, 1);
3128 }
3129}
3130
3131static int fe_equal(const secp256k1_fe *a, const secp256k1_fe *b) {
3132 secp256k1_fe an = *a;
3133 secp256k1_fe bn = *b;
3135 return secp256k1_fe_equal(&an, &bn);
3136}
3137
3139 int i;
3140 secp256k1_fe a, b;
3141 for (i = 0; i < 100 * COUNT; ++i) {
3143 b = a;
3146 CHECK(secp256k1_fe_equal(&a, &b));
3147 }
3148}
3149
3150static void run_field_convert(void) {
3151 static const unsigned char b32[32] = {
3152 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,
3153 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18,
3154 0x22, 0x23, 0x24, 0x25, 0x26, 0x27, 0x28, 0x29,
3155 0x33, 0x34, 0x35, 0x36, 0x37, 0x38, 0x39, 0x40
3156 };
3158 0x00010203UL, 0x04050607UL, 0x11121314UL, 0x15161718UL,
3159 0x22232425UL, 0x26272829UL, 0x33343536UL, 0x37383940UL
3160 );
3161 static const secp256k1_fe fe = SECP256K1_FE_CONST(
3162 0x00010203UL, 0x04050607UL, 0x11121314UL, 0x15161718UL,
3163 0x22232425UL, 0x26272829UL, 0x33343536UL, 0x37383940UL
3164 );
3165 secp256k1_fe fe2;
3166 unsigned char b322[32];
3168 /* Check conversions to fe. */
3170 CHECK(secp256k1_fe_equal(&fe, &fe2));
3171 secp256k1_fe_from_storage(&fe2, &fes);
3172 CHECK(secp256k1_fe_equal(&fe, &fe2));
3173 /* Check conversion from fe. */
3174 secp256k1_fe_get_b32(b322, &fe);
3175 CHECK(secp256k1_memcmp_var(b322, b32, 32) == 0);
3176 secp256k1_fe_to_storage(&fes2, &fe);
3177 CHECK(secp256k1_memcmp_var(&fes2, &fes, sizeof(fes)) == 0);
3178}
3179
3180static void run_field_be32_overflow(void) {
3181 {
3182 static const unsigned char zero_overflow[32] = {
3183 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3184 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3185 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3186 0xFF, 0xFF, 0xFF, 0xFE, 0xFF, 0xFF, 0xFC, 0x2F,
3187 };
3188 static const unsigned char zero[32] = { 0x00 };
3189 unsigned char out[32];
3190 secp256k1_fe fe;
3191 CHECK(secp256k1_fe_set_b32_limit(&fe, zero_overflow) == 0);
3192 secp256k1_fe_set_b32_mod(&fe, zero_overflow);
3195 CHECK(secp256k1_fe_is_zero(&fe) == 1);
3197 CHECK(secp256k1_memcmp_var(out, zero, 32) == 0);
3198 }
3199 {
3200 static const unsigned char one_overflow[32] = {
3201 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3202 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3203 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3204 0xFF, 0xFF, 0xFF, 0xFE, 0xFF, 0xFF, 0xFC, 0x30,
3205 };
3206 static const unsigned char one[32] = {
3207 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3208 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3209 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3210 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
3211 };
3212 unsigned char out[32];
3213 secp256k1_fe fe;
3214 CHECK(secp256k1_fe_set_b32_limit(&fe, one_overflow) == 0);
3215 secp256k1_fe_set_b32_mod(&fe, one_overflow);
3219 CHECK(secp256k1_memcmp_var(out, one, 32) == 0);
3220 }
3221 {
3222 static const unsigned char ff_overflow[32] = {
3223 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3224 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3225 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3226 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
3227 };
3228 static const unsigned char ff[32] = {
3229 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3230 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3231 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
3232 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x03, 0xD0,
3233 };
3234 unsigned char out[32];
3235 secp256k1_fe fe;
3236 const secp256k1_fe fe_ff = SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0x01, 0x000003d0);
3237 CHECK(secp256k1_fe_set_b32_limit(&fe, ff_overflow) == 0);
3238 secp256k1_fe_set_b32_mod(&fe, ff_overflow);
3240 CHECK(secp256k1_fe_cmp_var(&fe, &fe_ff) == 0);
3242 CHECK(secp256k1_memcmp_var(out, ff, 32) == 0);
3243 }
3244}
3245
3246/* Returns true if two field elements have the same representation. */
3247static int fe_identical(const secp256k1_fe *a, const secp256k1_fe *b) {
3248 int ret = 1;
3249 /* Compare the struct member that holds the limbs. */
3250 ret &= (secp256k1_memcmp_var(a->n, b->n, sizeof(a->n)) == 0);
3251 return ret;
3252}
3253
3254static void run_field_half(void) {
3255 secp256k1_fe t, u;
3256 int m;
3257
3258 /* Check magnitude 0 input */
3261#ifdef VERIFY
3262 CHECK(t.magnitude == 1);
3263 CHECK(t.normalized == 0);
3264#endif
3266
3267 /* Check non-zero magnitudes in the supported range */
3268 for (m = 1; m < 32; m++) {
3269 /* Check max-value input */
3271
3272 u = t;
3274#ifdef VERIFY
3275 CHECK(u.magnitude == (m >> 1) + 1);
3276 CHECK(u.normalized == 0);
3277#endif
3279 secp256k1_fe_add(&u, &u);
3280 CHECK(fe_equal(&t, &u));
3281
3282 /* Check worst-case input: ensure the LSB is 1 so that P will be added,
3283 * which will also cause all carries to be 1, since all limbs that can
3284 * generate a carry are initially even and all limbs of P are odd in
3285 * every existing field implementation. */
3287 CHECK(t.n[0] > 0);
3288 CHECK((t.n[0] & 1) == 0);
3289 --t.n[0];
3290
3291 u = t;
3293#ifdef VERIFY
3294 CHECK(u.magnitude == (m >> 1) + 1);
3295 CHECK(u.normalized == 0);
3296#endif
3298 secp256k1_fe_add(&u, &u);
3299 CHECK(fe_equal(&t, &u));
3300 }
3301}
3302
3303static void run_field_misc(void) {
3304 secp256k1_fe x;
3305 secp256k1_fe y;
3306 secp256k1_fe z;
3307 secp256k1_fe q;
3308 int v;
3309 secp256k1_fe fe5 = SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 5);
3310 int i, j;
3311 for (i = 0; i < 1000 * COUNT; i++) {
3312 secp256k1_fe_storage xs, ys, zs;
3313 if (i & 1) {
3315 } else {
3317 }
3319 v = testrand_bits(15);
3320 /* Test that fe_add_int is equivalent to fe_set_int + fe_add. */
3321 secp256k1_fe_set_int(&q, v); /* q = v */
3322 z = x; /* z = x */
3323 secp256k1_fe_add(&z, &q); /* z = x+v */
3324 q = x; /* q = x */
3325 secp256k1_fe_add_int(&q, v); /* q = x+v */
3326 CHECK(fe_equal(&q, &z));
3327 /* Test the fe equality and comparison operations. */
3328 CHECK(secp256k1_fe_cmp_var(&x, &x) == 0);
3329 CHECK(secp256k1_fe_equal(&x, &x));
3330 z = x;
3331 secp256k1_fe_add(&z,&y);
3332 /* Test fe conditional move; z is not normalized here. */
3333 q = x;
3334 secp256k1_fe_cmov(&x, &z, 0);
3335#ifdef VERIFY
3336 CHECK(!x.normalized);
3337 CHECK((x.magnitude == q.magnitude) || (x.magnitude == z.magnitude));
3338 CHECK((x.magnitude >= q.magnitude) && (x.magnitude >= z.magnitude));
3339#endif
3340 x = q;
3341 secp256k1_fe_cmov(&x, &x, 1);
3342 CHECK(!fe_identical(&x, &z));
3343 CHECK(fe_identical(&x, &q));
3344 secp256k1_fe_cmov(&q, &z, 1);
3345#ifdef VERIFY
3346 CHECK(!q.normalized);
3347 CHECK((q.magnitude == x.magnitude) || (q.magnitude == z.magnitude));
3348 CHECK((q.magnitude >= x.magnitude) && (q.magnitude >= z.magnitude));
3349#endif
3350 CHECK(fe_identical(&q, &z));
3351 q = z;
3354 CHECK(!secp256k1_fe_equal(&x, &z));
3356 secp256k1_fe_cmov(&q, &z, (i&1));
3357#ifdef VERIFY
3358 CHECK(q.normalized && q.magnitude == 1);
3359#endif
3360 for (j = 0; j < 6; j++) {
3361 secp256k1_fe_negate_unchecked(&z, &z, j+1);
3363 secp256k1_fe_cmov(&q, &z, (j&1));
3364#ifdef VERIFY
3365 CHECK(!q.normalized && q.magnitude == z.magnitude);
3366#endif
3367 }
3369 /* Test storage conversion and conditional moves. */
3370 secp256k1_fe_to_storage(&xs, &x);
3371 secp256k1_fe_to_storage(&ys, &y);
3372 secp256k1_fe_to_storage(&zs, &z);
3373 secp256k1_fe_storage_cmov(&zs, &xs, 0);
3374 secp256k1_fe_storage_cmov(&zs, &zs, 1);
3375 CHECK(secp256k1_memcmp_var(&xs, &zs, sizeof(xs)) != 0);
3376 secp256k1_fe_storage_cmov(&ys, &xs, 1);
3377 CHECK(secp256k1_memcmp_var(&xs, &ys, sizeof(xs)) == 0);
3381 /* Test that mul_int, mul, and add agree. */
3382 secp256k1_fe_add(&y, &x);
3383 secp256k1_fe_add(&y, &x);
3384 z = x;
3385 secp256k1_fe_mul_int(&z, 3);
3386 CHECK(fe_equal(&y, &z));
3387 secp256k1_fe_add(&y, &x);
3388 secp256k1_fe_add(&z, &x);
3389 CHECK(fe_equal(&z, &y));
3390 z = x;
3391 secp256k1_fe_mul_int(&z, 5);
3392 secp256k1_fe_mul(&q, &x, &fe5);
3393 CHECK(fe_equal(&z, &q));
3394 secp256k1_fe_negate(&x, &x, 1);
3395 secp256k1_fe_add(&z, &x);
3396 secp256k1_fe_add(&q, &x);
3397 CHECK(fe_equal(&y, &z));
3398 CHECK(fe_equal(&q, &y));
3399 /* Check secp256k1_fe_half. */
3400 z = x;
3402 secp256k1_fe_add(&z, &z);
3403 CHECK(fe_equal(&x, &z));
3404 secp256k1_fe_add(&z, &z);
3406 CHECK(fe_equal(&x, &z));
3407 }
3408}
3409
3410static void test_fe_mul(const secp256k1_fe* a, const secp256k1_fe* b, int use_sqr)
3411{
3412 secp256k1_fe c, an, bn;
3413 /* Variables in BE 32-byte format. */
3414 unsigned char a32[32], b32[32], c32[32];
3415 /* Variables in LE 16x uint16_t format. */
3416 uint16_t a16[16], b16[16], c16[16];
3417 /* Field modulus in LE 16x uint16_t format. */
3418 static const uint16_t m16[16] = {
3419 0xfc2f, 0xffff, 0xfffe, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
3420 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff, 0xffff,
3421 };
3422 uint16_t t16[32];
3423 int i;
3424
3425 /* Compute C = A * B in fe format. */
3426 c = *a;
3427 if (use_sqr) {
3428 secp256k1_fe_sqr(&c, &c);
3429 } else {
3430 secp256k1_fe_mul(&c, &c, b);
3431 }
3432
3433 /* Convert A, B, C into LE 16x uint16_t format. */
3434 an = *a;
3435 bn = *b;
3439 secp256k1_fe_get_b32(a32, &an);
3440 secp256k1_fe_get_b32(b32, &bn);
3441 secp256k1_fe_get_b32(c32, &c);
3442 for (i = 0; i < 16; ++i) {
3443 a16[i] = a32[31 - 2*i] + ((uint16_t)a32[30 - 2*i] << 8);
3444 b16[i] = b32[31 - 2*i] + ((uint16_t)b32[30 - 2*i] << 8);
3445 c16[i] = c32[31 - 2*i] + ((uint16_t)c32[30 - 2*i] << 8);
3446 }
3447 /* Compute T = A * B in LE 16x uint16_t format. */
3448 mulmod256(t16, a16, b16, m16);
3449 /* Compare */
3450 CHECK(secp256k1_memcmp_var(t16, c16, 32) == 0);
3451}
3452
3453static void run_fe_mul(void) {
3454 int i;
3455 for (i = 0; i < 100 * COUNT; ++i) {
3456 secp256k1_fe a, b, c, d;
3465 test_fe_mul(&a, &a, 1);
3466 test_fe_mul(&c, &c, 1);
3467 test_fe_mul(&a, &b, 0);
3468 test_fe_mul(&a, &c, 0);
3469 test_fe_mul(&c, &b, 0);
3470 test_fe_mul(&c, &d, 0);
3471 }
3472}
3473
3474static void run_sqr(void) {
3475 int i;
3476 secp256k1_fe x, y, lhs, rhs, tmp;
3477
3478 secp256k1_fe_set_int(&x, 1);
3479 secp256k1_fe_negate(&x, &x, 1);
3480
3481 for (i = 1; i <= 512; ++i) {
3482 secp256k1_fe_mul_int(&x, 2);
3484
3485 /* Check that (x+y)*(x-y) = x^2 - y*2 for some random values y */
3487
3488 lhs = x;
3489 secp256k1_fe_add(&lhs, &y); /* lhs = x+y */
3490 secp256k1_fe_negate(&tmp, &y, 1); /* tmp = -y */
3491 secp256k1_fe_add(&tmp, &x); /* tmp = x-y */
3492 secp256k1_fe_mul(&lhs, &lhs, &tmp); /* lhs = (x+y)*(x-y) */
3493
3494 secp256k1_fe_sqr(&rhs, &x); /* rhs = x^2 */
3495 secp256k1_fe_sqr(&tmp, &y); /* tmp = y^2 */
3496 secp256k1_fe_negate(&tmp, &tmp, 1); /* tmp = -y^2 */
3497 secp256k1_fe_add(&rhs, &tmp); /* rhs = x^2 - y^2 */
3498
3499 CHECK(fe_equal(&lhs, &rhs));
3500 }
3501}
3502
3503static void test_sqrt(const secp256k1_fe *a, const secp256k1_fe *k) {
3504 secp256k1_fe r1, r2;
3505 int v = secp256k1_fe_sqrt(&r1, a);
3506 CHECK((v == 0) == (k == NULL));
3507
3508 if (k != NULL) {
3509 /* Check that the returned root is +/- the given known answer */
3510 secp256k1_fe_negate(&r2, &r1, 1);
3511 secp256k1_fe_add(&r1, k); secp256k1_fe_add(&r2, k);
3514 }
3515}
3516
3517static void run_sqrt(void) {
3518 secp256k1_fe ns, x, s, t;
3519 int i;
3520
3521 /* Check sqrt(0) is 0 */
3522 secp256k1_fe_set_int(&x, 0);
3523 secp256k1_fe_sqr(&s, &x);
3524 test_sqrt(&s, &x);
3525
3526 /* Check sqrt of small squares (and their negatives) */
3527 for (i = 1; i <= 100; i++) {
3528 secp256k1_fe_set_int(&x, i);
3529 secp256k1_fe_sqr(&s, &x);
3530 test_sqrt(&s, &x);
3531 secp256k1_fe_negate(&t, &s, 1);
3532 test_sqrt(&t, NULL);
3533 }
3534
3535 /* Consistency checks for large random values */
3536 for (i = 0; i < 10; i++) {
3537 int j;
3539 for (j = 0; j < COUNT; j++) {
3541 secp256k1_fe_sqr(&s, &x);
3543 test_sqrt(&s, &x);
3544 secp256k1_fe_negate(&t, &s, 1);
3546 test_sqrt(&t, NULL);
3547 secp256k1_fe_mul(&t, &s, &ns);
3548 test_sqrt(&t, NULL);
3549 }
3550 }
3551}
3552
3553/***** FIELD/SCALAR INVERSE TESTS *****/
3554
3556 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFE,
3557 0xBAAEDCE6, 0xAF48A03B, 0xBFD25E8C, 0xD0364140
3558);
3559
3561 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFF,
3562 0xFFFFFFFF, 0xFFFFFFFF, 0xFFFFFFFE, 0xFFFFFC2E
3563);
3564
3565/* These tests test the following identities:
3566 *
3567 * for x==0: 1/x == 0
3568 * for x!=0: x*(1/x) == 1
3569 * for x!=0 and x!=1: 1/(1/x - 1) + 1 == -1/(x-1)
3570 */
3571
3573{
3574 secp256k1_scalar l, r, t;
3575
3576 (var ? secp256k1_scalar_inverse_var : secp256k1_scalar_inverse)(&l, x); /* l = 1/x */
3577 if (out) *out = l;
3578 if (secp256k1_scalar_is_zero(x)) {
3580 return;
3581 }
3582 secp256k1_scalar_mul(&t, x, &l); /* t = x*(1/x) */
3583 CHECK(secp256k1_scalar_is_one(&t)); /* x*(1/x) == 1 */
3584 secp256k1_scalar_add(&r, x, &scalar_minus_one); /* r = x-1 */
3585 if (secp256k1_scalar_is_zero(&r)) return;
3586 (var ? secp256k1_scalar_inverse_var : secp256k1_scalar_inverse)(&r, &r); /* r = 1/(x-1) */
3587 secp256k1_scalar_add(&l, &scalar_minus_one, &l); /* l = 1/x-1 */
3588 (var ? secp256k1_scalar_inverse_var : secp256k1_scalar_inverse)(&l, &l); /* l = 1/(1/x-1) */
3589 secp256k1_scalar_add(&l, &l, &secp256k1_scalar_one); /* l = 1/(1/x-1)+1 */
3590 secp256k1_scalar_add(&l, &r, &l); /* l = 1/(1/x-1)+1 + 1/(x-1) */
3591 CHECK(secp256k1_scalar_is_zero(&l)); /* l == 0 */
3592}
3593
3594static void test_inverse_field(secp256k1_fe* out, const secp256k1_fe* x, int var)
3595{
3596 secp256k1_fe l, r, t;
3597
3598 (var ? secp256k1_fe_inv_var : secp256k1_fe_inv)(&l, x) ; /* l = 1/x */
3599 if (out) *out = l;
3600 t = *x; /* t = x */
3603 return;
3604 }
3605 secp256k1_fe_mul(&t, x, &l); /* t = x*(1/x) */
3606 secp256k1_fe_add(&t, &fe_minus_one); /* t = x*(1/x)-1 */
3607 CHECK(secp256k1_fe_normalizes_to_zero(&t)); /* x*(1/x)-1 == 0 */
3608 r = *x; /* r = x */
3609 secp256k1_fe_add(&r, &fe_minus_one); /* r = x-1 */
3611 (var ? secp256k1_fe_inv_var : secp256k1_fe_inv)(&r, &r); /* r = 1/(x-1) */
3612 secp256k1_fe_add(&l, &fe_minus_one); /* l = 1/x-1 */
3613 (var ? secp256k1_fe_inv_var : secp256k1_fe_inv)(&l, &l); /* l = 1/(1/x-1) */
3614 secp256k1_fe_add_int(&l, 1); /* l = 1/(1/x-1)+1 */
3615 secp256k1_fe_add(&l, &r); /* l = 1/(1/x-1)+1 + 1/(x-1) */
3617}
3618
3619static void run_inverse_tests(void)
3620{
3621 /* Fixed test cases for field inverses: pairs of (x, 1/x) mod p. */
3622 static const secp256k1_fe fe_cases[][2] = {
3623 /* 0 */
3624 {SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 0),
3625 SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 0)},
3626 /* 1 */
3627 {SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 1),
3628 SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 1)},
3629 /* -1 */
3630 {SECP256K1_FE_CONST(0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xfffffffe, 0xfffffc2e),
3631 SECP256K1_FE_CONST(0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xfffffffe, 0xfffffc2e)},
3632 /* 2 */
3633 {SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 2),
3634 SECP256K1_FE_CONST(0x7fffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0x7ffffe18)},
3635 /* 2**128 */
3636 {SECP256K1_FE_CONST(0, 0, 0, 1, 0, 0, 0, 0),
3637 SECP256K1_FE_CONST(0xbcb223fe, 0xdc24a059, 0xd838091d, 0xd2253530, 0xffffffff, 0xffffffff, 0xffffffff, 0x434dd931)},
3638 /* Input known to need 637 divsteps */
3639 {SECP256K1_FE_CONST(0xe34e9c95, 0x6bee8a84, 0x0dcb632a, 0xdb8a1320, 0x66885408, 0x06f3f996, 0x7c11ca84, 0x19199ec3),
3640 SECP256K1_FE_CONST(0xbd2cbd8f, 0x1c536828, 0x9bccda44, 0x2582ac0c, 0x870152b0, 0x8a3f09fb, 0x1aaadf92, 0x19b618e5)},
3641 /* Input known to need 567 divsteps starting with delta=1/2. */
3642 {SECP256K1_FE_CONST(0xf6bc3ba3, 0x636451c4, 0x3e46357d, 0x2c21d619, 0x0988e234, 0x15985661, 0x6672982b, 0xa7549bfc),
3643 SECP256K1_FE_CONST(0xb024fdc7, 0x5547451e, 0x426c585f, 0xbd481425, 0x73df6b75, 0xeef6d9d0, 0x389d87d4, 0xfbb440ba)},
3644 /* Input known to need 566 divsteps starting with delta=1/2. */
3645 {SECP256K1_FE_CONST(0xb595d81b, 0x2e3c1e2f, 0x482dbc65, 0xe4865af7, 0x9a0a50aa, 0x29f9e618, 0x6f87d7a5, 0x8d1063ae),
3646 SECP256K1_FE_CONST(0xc983337c, 0x5d5c74e1, 0x49918330, 0x0b53afb5, 0xa0428a0b, 0xce6eef86, 0x059bd8ef, 0xe5b908de)},
3647 /* Set of 10 inputs accessing all 128 entries in the modinv32 divsteps_var table */
3648 {SECP256K1_FE_CONST(0x00000000, 0x00000000, 0xe0ff1f80, 0x1f000000, 0x00000000, 0x00000000, 0xfeff0100, 0x00000000),
3649 SECP256K1_FE_CONST(0x9faf9316, 0x77e5049d, 0x0b5e7a1b, 0xef70b893, 0x18c9e30c, 0x045e7fd7, 0x29eddf8c, 0xd62e9e3d)},
3650 {SECP256K1_FE_CONST(0x621a538d, 0x511b2780, 0x35688252, 0x53f889a4, 0x6317c3ac, 0x32ba0a46, 0x6277c0d1, 0xccd31192),
3651 SECP256K1_FE_CONST(0x38513b0c, 0x5eba856f, 0xe29e882e, 0x9b394d8c, 0x34bda011, 0xeaa66943, 0x6a841a4c, 0x6ae8bcff)},
3652 {SECP256K1_FE_CONST(0x00000200, 0xf0ffff1f, 0x00000000, 0x0000e0ff, 0xffffffff, 0xfffcffff, 0xffffffff, 0xffff0100),
3653 SECP256K1_FE_CONST(0x5da42a52, 0x3640de9e, 0x13e64343, 0x0c7591b7, 0x6c1e3519, 0xf048c5b6, 0x0484217c, 0xedbf8b2f)},
3654 {SECP256K1_FE_CONST(0xd1343ef9, 0x4b952621, 0x7c52a2ee, 0x4ea1281b, 0x4ab46410, 0x9f26998d, 0xa686a8ff, 0x9f2103e8),
3655 SECP256K1_FE_CONST(0x84044385, 0x9a4619bf, 0x74e35b6d, 0xa47e0c46, 0x6b7fb47d, 0x9ffab128, 0xb0775aa3, 0xcb318bd1)},
3656 {SECP256K1_FE_CONST(0xb27235d2, 0xc56a52be, 0x210db37a, 0xd50d23a4, 0xbe621bdd, 0x5df22c6a, 0xe926ba62, 0xd2e4e440),
3657 SECP256K1_FE_CONST(0x67a26e54, 0x483a9d3c, 0xa568469e, 0xd258ab3d, 0xb9ec9981, 0xdca9b1bd, 0x8d2775fe, 0x53ae429b)},
3658 {SECP256K1_FE_CONST(0x00000000, 0x00000000, 0x00e0ffff, 0xffffff83, 0xffffffff, 0x3f00f00f, 0x000000e0, 0xffffffff),
3659 SECP256K1_FE_CONST(0x310e10f8, 0x23bbfab0, 0xac94907d, 0x076c9a45, 0x8d357d7f, 0xc763bcee, 0x00d0e615, 0x5a6acef6)},
3660 {SECP256K1_FE_CONST(0xfeff0300, 0x001c0000, 0xf80700c0, 0x0ff0ffff, 0xffffffff, 0x0fffffff, 0xffff0100, 0x7f0000fe),
3661 SECP256K1_FE_CONST(0x28e2fdb4, 0x0709168b, 0x86f598b0, 0x3453a370, 0x530cf21f, 0x32f978d5, 0x1d527a71, 0x59269b0c)},
3662 {SECP256K1_FE_CONST(0xc2591afa, 0x7bb98ef7, 0x090bb273, 0x85c14f87, 0xbb0b28e0, 0x54d3c453, 0x85c66753, 0xd5574d2f),
3663 SECP256K1_FE_CONST(0xfdca70a2, 0x70ce627c, 0x95e66fae, 0x848a6dbb, 0x07ffb15c, 0x5f63a058, 0xba4140ed, 0x6113b503)},
3664 {SECP256K1_FE_CONST(0xf5475db3, 0xedc7b5a3, 0x411c047e, 0xeaeb452f, 0xc625828e, 0x1cf5ad27, 0x8eec1060, 0xc7d3e690),
3665 SECP256K1_FE_CONST(0x5eb756c0, 0xf963f4b9, 0xdc6a215e, 0xec8cc2d8, 0x2e9dec01, 0xde5eb88d, 0x6aba7164, 0xaecb2c5a)},
3666 {SECP256K1_FE_CONST(0x00000000, 0x00f8ffff, 0xffffffff, 0x01000000, 0xe0ff1f00, 0x00000000, 0xffffff7f, 0x00000000),
3667 SECP256K1_FE_CONST(0xe0d2e3d8, 0x49b6157d, 0xe54e88c2, 0x1a7f02ca, 0x7dd28167, 0xf1125d81, 0x7bfa444e, 0xbe110037)},
3668 /* Selection of randomly generated inputs that reach high/low d/e values in various configurations. */
3669 {SECP256K1_FE_CONST(0x13cc08a4, 0xd8c41f0f, 0x179c3e67, 0x54c46c67, 0xc4109221, 0x09ab3b13, 0xe24d9be1, 0xffffe950),
3670 SECP256K1_FE_CONST(0xb80c8006, 0xd16abaa7, 0xcabd71e5, 0xcf6714f4, 0x966dd3d0, 0x64767a2d, 0xe92c4441, 0x51008cd1)},
3671 {SECP256K1_FE_CONST(0xaa6db990, 0x95efbca1, 0x3cc6ff71, 0x0602e24a, 0xf49ff938, 0x99fffc16, 0x46f40993, 0xc6e72057),
3672 SECP256K1_FE_CONST(0xd5d3dd69, 0xb0c195e5, 0x285f1d49, 0xe639e48c, 0x9223f8a9, 0xca1d731d, 0x9ca482f9, 0xa5b93e06)},
3673 {SECP256K1_FE_CONST(0x1c680eac, 0xaeabffd8, 0x9bdc4aee, 0x1781e3de, 0xa3b08108, 0x0015f2e0, 0x94449e1b, 0x2f67a058),
3674 SECP256K1_FE_CONST(0x7f083f8d, 0x31254f29, 0x6510f475, 0x245c373d, 0xc5622590, 0x4b323393, 0x32ed1719, 0xc127444b)},
3675 {SECP256K1_FE_CONST(0x147d44b3, 0x012d83f8, 0xc160d386, 0x1a44a870, 0x9ba6be96, 0x8b962707, 0x267cbc1a, 0xb65b2f0a),
3676 SECP256K1_FE_CONST(0x555554ff, 0x170aef1e, 0x50a43002, 0xe51fbd36, 0xafadb458, 0x7a8aded1, 0x0ca6cd33, 0x6ed9087c)},
3677 {SECP256K1_FE_CONST(0x12423796, 0x22f0fe61, 0xf9ca017c, 0x5384d107, 0xa1fbf3b2, 0x3b018013, 0x916a3c37, 0x4000b98c),
3678 SECP256K1_FE_CONST(0x20257700, 0x08668f94, 0x1177e306, 0x136c01f5, 0x8ed1fbd2, 0x95ec4589, 0xae38edb9, 0xfd19b6d7)},
3679 {SECP256K1_FE_CONST(0xdcf2d030, 0x9ab42cb4, 0x93ffa181, 0xdcd23619, 0x39699b52, 0x08909a20, 0xb5a17695, 0x3a9dcf21),
3680 SECP256K1_FE_CONST(0x1f701dea, 0xe211fb1f, 0x4f37180d, 0x63a0f51c, 0x29fe1e40, 0xa40b6142, 0x2e7b12eb, 0x982b06b6)},
3681 {SECP256K1_FE_CONST(0x79a851f6, 0xa6314ed3, 0xb35a55e6, 0xca1c7d7f, 0xe32369ea, 0xf902432e, 0x375308c5, 0xdfd5b600),
3682 SECP256K1_FE_CONST(0xcaae00c5, 0xe6b43851, 0x9dabb737, 0x38cba42c, 0xa02c8549, 0x7895dcbf, 0xbd183d71, 0xafe4476a)},
3683 {SECP256K1_FE_CONST(0xede78fdd, 0xcfc92bf1, 0x4fec6c6c, 0xdb8d37e2, 0xfb66bc7b, 0x28701870, 0x7fa27c9a, 0x307196ec),
3684 SECP256K1_FE_CONST(0x68193a6c, 0x9a8b87a7, 0x2a760c64, 0x13e473f6, 0x23ae7bed, 0x1de05422, 0x88865427, 0xa3418265)},
3685 {SECP256K1_FE_CONST(0xa40b2079, 0xb8f88e89, 0xa7617997, 0x89baf5ae, 0x174df343, 0x75138eae, 0x2711595d, 0x3fc3e66c),
3686 SECP256K1_FE_CONST(0x9f99c6a5, 0x6d685267, 0xd4b87c37, 0x9d9c4576, 0x358c692b, 0x6bbae0ed, 0x3389c93d, 0x7fdd2655)},
3687 {SECP256K1_FE_CONST(0x7c74c6b6, 0xe98d9151, 0x72645cf1, 0x7f06e321, 0xcefee074, 0x15b2113a, 0x10a9be07, 0x08a45696),
3688 SECP256K1_FE_CONST(0x8c919a88, 0x898bc1e0, 0x77f26f97, 0x12e655b7, 0x9ba0ac40, 0xe15bb19e, 0x8364cc3b, 0xe227a8ee)},
3689 {SECP256K1_FE_CONST(0x109ba1ce, 0xdafa6d4a, 0xa1cec2b2, 0xeb1069f4, 0xb7a79e5b, 0xec6eb99b, 0xaec5f643, 0xee0e723e),
3690 SECP256K1_FE_CONST(0x93d13eb8, 0x4bb0bcf9, 0xe64f5a71, 0xdbe9f359, 0x7191401c, 0x6f057a4a, 0xa407fe1b, 0x7ecb65cc)},
3691 {SECP256K1_FE_CONST(0x3db076cd, 0xec74a5c9, 0xf61dd138, 0x90e23e06, 0xeeedd2d0, 0x74cbc4e0, 0x3dbe1e91, 0xded36a78),
3692 SECP256K1_FE_CONST(0x3f07f966, 0x8e2a1e09, 0x706c71df, 0x02b5e9d5, 0xcb92ddbf, 0xcdd53010, 0x16545564, 0xe660b107)},
3693 {SECP256K1_FE_CONST(0xe31c73ed, 0xb4c4b82c, 0x02ae35f7, 0x4cdec153, 0x98b522fd, 0xf7d2460c, 0x6bf7c0f8, 0x4cf67b0d),
3694 SECP256K1_FE_CONST(0x4b8f1faf, 0x94e8b070, 0x19af0ff6, 0xa319cd31, 0xdf0a7ffb, 0xefaba629, 0x59c50666, 0x1fe5b843)},
3695 {SECP256K1_FE_CONST(0x4c8b0e6e, 0x83392ab6, 0xc0e3e9f1, 0xbbd85497, 0x16698897, 0xf552d50d, 0x79652ddb, 0x12f99870),
3696 SECP256K1_FE_CONST(0x56d5101f, 0xd23b7949, 0x17dc38d6, 0xf24022ef, 0xcf18e70a, 0x5cc34424, 0x438544c3, 0x62da4bca)},
3697 {SECP256K1_FE_CONST(0xb0e040e2, 0x40cc35da, 0x7dd5c611, 0x7fccb178, 0x28888137, 0xbc930358, 0xea2cbc90, 0x775417dc),
3698 SECP256K1_FE_CONST(0xca37f0d4, 0x016dd7c8, 0xab3ae576, 0x96e08d69, 0x68ed9155, 0xa9b44270, 0x900ae35d, 0x7c7800cd)},
3699 {SECP256K1_FE_CONST(0x8a32ea49, 0x7fbb0bae, 0x69724a9d, 0x8e2105b2, 0xbdf69178, 0x862577ef, 0x35055590, 0x667ddaef),
3700 SECP256K1_FE_CONST(0xd02d7ead, 0xc5e190f0, 0x559c9d72, 0xdaef1ffc, 0x64f9f425, 0xf43645ea, 0x7341e08d, 0x11768e96)},
3701 {SECP256K1_FE_CONST(0xa3592d98, 0x9abe289d, 0x579ebea6, 0xbb0857a8, 0xe242ab73, 0x85f9a2ce, 0xb6998f0f, 0xbfffbfc6),
3702 SECP256K1_FE_CONST(0x093c1533, 0x32032efa, 0x6aa46070, 0x0039599e, 0x589c35f4, 0xff525430, 0x7fe3777a, 0x44b43ddc)},
3703 {SECP256K1_FE_CONST(0x647178a3, 0x229e607b, 0xcc98521a, 0xcce3fdd9, 0x1e1bc9c9, 0x97fb7c6a, 0x61b961e0, 0x99b10709),
3704 SECP256K1_FE_CONST(0x98217c13, 0xd51ddf78, 0x96310e77, 0xdaebd908, 0x602ca683, 0xcb46d07a, 0xa1fcf17e, 0xc8e2feb3)},
3705 {SECP256K1_FE_CONST(0x7334627c, 0x73f98968, 0x99464b4b, 0xf5964958, 0x1b95870d, 0xc658227e, 0x5e3235d8, 0xdcab5787),
3706 SECP256K1_FE_CONST(0x000006fd, 0xc7e9dd94, 0x40ae367a, 0xe51d495c, 0x07603b9b, 0x2d088418, 0x6cc5c74c, 0x98514307)},
3707 {SECP256K1_FE_CONST(0x82e83876, 0x96c28938, 0xa50dd1c5, 0x605c3ad1, 0xc048637d, 0x7a50825f, 0x335ed01a, 0x00005760),
3708 SECP256K1_FE_CONST(0xb0393f9f, 0x9f2aa55e, 0xf5607e2e, 0x5287d961, 0x60b3e704, 0xf3e16e80, 0xb4f9a3ea, 0xfec7f02d)},
3709 {SECP256K1_FE_CONST(0xc97b6cec, 0x3ee6b8dc, 0x98d24b58, 0x3c1970a1, 0xfe06297a, 0xae813529, 0xe76bb6bd, 0x771ae51d),
3710 SECP256K1_FE_CONST(0x0507c702, 0xd407d097, 0x47ddeb06, 0xf6625419, 0x79f48f79, 0x7bf80d0b, 0xfc34b364, 0x253a5db1)},
3711 {SECP256K1_FE_CONST(0xd559af63, 0x77ea9bc4, 0x3cf1ad14, 0x5c7a4bbb, 0x10e7d18b, 0x7ce0dfac, 0x380bb19d, 0x0bb99bd3),
3712 SECP256K1_FE_CONST(0x00196119, 0xb9b00d92, 0x34edfdb5, 0xbbdc42fc, 0xd2daa33a, 0x163356ca, 0xaa8754c8, 0xb0ec8b0b)},
3713 {SECP256K1_FE_CONST(0x8ddfa3dc, 0x52918da0, 0x640519dc, 0x0af8512a, 0xca2d33b2, 0xbde52514, 0xda9c0afc, 0xcb29fce4),
3714 SECP256K1_FE_CONST(0xb3e4878d, 0x5cb69148, 0xcd54388b, 0xc23acce0, 0x62518ba8, 0xf09def92, 0x7b31e6aa, 0x6ba35b02)},
3715 {SECP256K1_FE_CONST(0xf8207492, 0xe3049f0a, 0x65285f2b, 0x0bfff996, 0x00ca112e, 0xc05da837, 0x546d41f9, 0x5194fb91),
3716 SECP256K1_FE_CONST(0x7b7ee50b, 0xa8ed4bbd, 0xf6469930, 0x81419a5c, 0x071441c7, 0x290d046e, 0x3b82ea41, 0x611c5f95)},
3717 {SECP256K1_FE_CONST(0x050f7c80, 0x5bcd3c6b, 0x823cb724, 0x5ce74db7, 0xa4e39f5c, 0xbd8828d7, 0xfd4d3e07, 0x3ec2926a),
3718 SECP256K1_FE_CONST(0x000d6730, 0xb0171314, 0x4764053d, 0xee157117, 0x48fd61da, 0xdea0b9db, 0x1d5e91c6, 0xbdc3f59e)},
3719 {SECP256K1_FE_CONST(0x3e3ea8eb, 0x05d760cf, 0x23009263, 0xb3cb3ac9, 0x088f6f0d, 0x3fc182a3, 0xbd57087c, 0xe67c62f9),
3720 SECP256K1_FE_CONST(0xbe988716, 0xa29c1bf6, 0x4456aed6, 0xab1e4720, 0x49929305, 0x51043bf4, 0xebd833dd, 0xdd511e8b)},
3721 {SECP256K1_FE_CONST(0x6964d2a9, 0xa7fa6501, 0xa5959249, 0x142f4029, 0xea0c1b5f, 0x2f487ef6, 0x301ac80a, 0x768be5cd),
3722 SECP256K1_FE_CONST(0x3918ffe4, 0x07492543, 0xed24d0b7, 0x3df95f8f, 0xaffd7cb4, 0x0de2191c, 0x9ec2f2ad, 0x2c0cb3c6)},
3723 {SECP256K1_FE_CONST(0x37c93520, 0xf6ddca57, 0x2b42fd5e, 0xb5c7e4de, 0x11b5b81c, 0xb95e91f3, 0x95c4d156, 0x39877ccb),
3724 SECP256K1_FE_CONST(0x9a94b9b5, 0x57eb71ee, 0x4c975b8b, 0xac5262a8, 0x077b0595, 0xe12a6b1f, 0xd728edef, 0x1a6bf956)}
3725 };
3726 /* Fixed test cases for scalar inverses: pairs of (x, 1/x) mod n. */
3727 static const secp256k1_scalar scalar_cases[][2] = {
3728 /* 0 */
3729 {SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 0),
3730 SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 0)},
3731 /* 1 */
3732 {SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 1),
3733 SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 1)},
3734 /* -1 */
3735 {SECP256K1_SCALAR_CONST(0xffffffff, 0xffffffff, 0xffffffff, 0xfffffffe, 0xbaaedce6, 0xaf48a03b, 0xbfd25e8c, 0xd0364140),
3736 SECP256K1_SCALAR_CONST(0xffffffff, 0xffffffff, 0xffffffff, 0xfffffffe, 0xbaaedce6, 0xaf48a03b, 0xbfd25e8c, 0xd0364140)},
3737 /* 2 */
3738 {SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 2),
3739 SECP256K1_SCALAR_CONST(0x7fffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0x5d576e73, 0x57a4501d, 0xdfe92f46, 0x681b20a1)},
3740 /* 2**128 */
3741 {SECP256K1_SCALAR_CONST(0, 0, 0, 1, 0, 0, 0, 0),
3742 SECP256K1_SCALAR_CONST(0x50a51ac8, 0x34b9ec24, 0x4b0dff66, 0x5588b13e, 0x9984d5b3, 0xcf80ef0f, 0xd6a23766, 0xa3ee9f22)},
3743 /* Input known to need 635 divsteps */
3744 {SECP256K1_SCALAR_CONST(0xcb9f1d35, 0xdd4416c2, 0xcd71bf3f, 0x6365da66, 0x3c9b3376, 0x8feb7ae9, 0x32a5ef60, 0x19199ec3),
3745 SECP256K1_SCALAR_CONST(0x1d7c7bba, 0xf1893d53, 0xb834bd09, 0x36b411dc, 0x42c2e42f, 0xec72c428, 0x5e189791, 0x8e9bc708)},
3746 /* Input known to need 566 divsteps starting with delta=1/2. */
3747 {SECP256K1_SCALAR_CONST(0x7e3c993d, 0xa4272488, 0xbc015b49, 0x2db54174, 0xd382083a, 0xebe6db35, 0x80f82eff, 0xcd132c72),
3748 SECP256K1_SCALAR_CONST(0x086f34a0, 0x3e631f76, 0x77418f28, 0xcc84ac95, 0x6304439d, 0x365db268, 0x312c6ded, 0xd0b934f8)},
3749 /* Input known to need 565 divsteps starting with delta=1/2. */
3750 {SECP256K1_SCALAR_CONST(0xbad7e587, 0x3f307859, 0x60d93147, 0x8a18491e, 0xb38a9fd5, 0x254350d3, 0x4b1f0e4b, 0x7dd6edc4),
3751 SECP256K1_SCALAR_CONST(0x89f2df26, 0x39e2b041, 0xf19bd876, 0xd039c8ac, 0xc2223add, 0x29c4943e, 0x6632d908, 0x515f467b)},
3752 /* Selection of randomly generated inputs that reach low/high d/e values in various configurations. */
3753 {SECP256K1_SCALAR_CONST(0x1950d757, 0xb37a5809, 0x435059bb, 0x0bb8997e, 0x07e1e3c8, 0x5e5d7d2c, 0x6a0ed8e3, 0xdbde180e),
3754 SECP256K1_SCALAR_CONST(0xbf72af9b, 0x750309e2, 0x8dda230b, 0xfe432b93, 0x7e25e475, 0x4388251e, 0x633d894b, 0x3bcb6f8c)},
3755 {SECP256K1_SCALAR_CONST(0x9bccf4e7, 0xc5a515e3, 0x50637aa9, 0xbb65a13f, 0x391749a1, 0x62de7d4e, 0xf6d7eabb, 0x3cd10ce0),
3756 SECP256K1_SCALAR_CONST(0xaf2d5623, 0xb6385a33, 0xcd0365be, 0x5e92a70d, 0x7f09179c, 0x3baaf30f, 0x8f9cc83b, 0x20092f67)},
3757 {SECP256K1_SCALAR_CONST(0x73a57111, 0xb242952a, 0x5c5dee59, 0xf3be2ace, 0xa30a7659, 0xa46e5f47, 0xd21267b1, 0x39e642c9),
3758 SECP256K1_SCALAR_CONST(0xa711df07, 0xcbcf13ef, 0xd61cc6be, 0xbcd058ce, 0xb02cf157, 0x272d4a18, 0x86d0feb3, 0xcd5fa004)},
3759 {SECP256K1_SCALAR_CONST(0x04884963, 0xce0580b1, 0xba547030, 0x3c691db3, 0x9cd2c84f, 0x24c7cebd, 0x97ebfdba, 0x3e785ec2),
3760 SECP256K1_SCALAR_CONST(0xaaaaaf14, 0xd7c99ba7, 0x517ce2c1, 0x78a28b4c, 0x3769a851, 0xe5c5a03d, 0x4cc28f33, 0x0ec4dc5d)},
3761 {SECP256K1_SCALAR_CONST(0x1679ed49, 0x21f537b1, 0x815cb8ae, 0x9efc511c, 0x5b9fa037, 0x0b0f275e, 0x6c985281, 0x6c4a9905),
3762 SECP256K1_SCALAR_CONST(0xb14ac3d5, 0x62b52999, 0xef34ead1, 0xffca4998, 0x0294341a, 0x1f8172aa, 0xea1624f9, 0x302eea62)},
3763 {SECP256K1_SCALAR_CONST(0x626b37c0, 0xf0057c35, 0xee982f83, 0x452a1fd3, 0xea826506, 0x48b08a9d, 0x1d2c4799, 0x4ad5f6ec),
3764 SECP256K1_SCALAR_CONST(0xe38643b7, 0x567bfc2f, 0x5d2f1c15, 0xe327239c, 0x07112443, 0x69509283, 0xfd98e77a, 0xdb71c1e8)},
3765 {SECP256K1_SCALAR_CONST(0x1850a3a7, 0x759efc56, 0x54f287b2, 0x14d1234b, 0xe263bbc9, 0xcf4d8927, 0xd5f85f27, 0x965bd816),
3766 SECP256K1_SCALAR_CONST(0x3b071831, 0xcac9619a, 0xcceb0596, 0xf614d63b, 0x95d0db2f, 0xc6a00901, 0x8eaa2621, 0xabfa0009)},
3767 {SECP256K1_SCALAR_CONST(0x94ae5d06, 0xa27dc400, 0x487d72be, 0xaa51ebed, 0xe475b5c0, 0xea675ffc, 0xf4df627a, 0xdca4222f),
3768 SECP256K1_SCALAR_CONST(0x01b412ed, 0xd7830956, 0x1532537e, 0xe5e3dc99, 0x8fd3930a, 0x54f8d067, 0x32ef5760, 0x594438a5)},
3769 {SECP256K1_SCALAR_CONST(0x1f24278a, 0xb5bfe374, 0xa328dbbc, 0xebe35f48, 0x6620e009, 0xd58bb1b4, 0xb5a6bf84, 0x8815f63a),
3770 SECP256K1_SCALAR_CONST(0xfe928416, 0xca5ba2d3, 0xfde513da, 0x903a60c7, 0x9e58ad8a, 0x8783bee4, 0x083a3843, 0xa608c914)},
3771 {SECP256K1_SCALAR_CONST(0xdc107d58, 0x274f6330, 0x67dba8bc, 0x26093111, 0x5201dfb8, 0x968ce3f5, 0xf34d1bd4, 0xf2146504),
3772 SECP256K1_SCALAR_CONST(0x660cfa90, 0x13c3d93e, 0x7023b1e5, 0xedd09e71, 0x6d9c9d10, 0x7a3d2cdb, 0xdd08edc3, 0xaa78fcfb)},
3773 {SECP256K1_SCALAR_CONST(0x7cd1e905, 0xc6f02776, 0x2f551cc7, 0x5da61cff, 0x7da05389, 0x1119d5a4, 0x631c7442, 0x894fd4f7),
3774 SECP256K1_SCALAR_CONST(0xff20862a, 0x9d3b1a37, 0x1628803b, 0x3004ccae, 0xaa23282a, 0xa89a1109, 0xd94ece5e, 0x181bdc46)},
3775 {SECP256K1_SCALAR_CONST(0x5b9dade8, 0x23d26c58, 0xcd12d818, 0x25b8ae97, 0x3dea04af, 0xf482c96b, 0xa062f254, 0x9e453640),
3776 SECP256K1_SCALAR_CONST(0x50c38800, 0x15fa53f4, 0xbe1e5392, 0x5c9b120a, 0x262c22c7, 0x18fa0816, 0x5f2baab4, 0x8cb5db46)},
3777 {SECP256K1_SCALAR_CONST(0x11cdaeda, 0x969c464b, 0xef1f4ab0, 0x5b01d22e, 0x656fd098, 0x882bea84, 0x65cdbe7a, 0x0c19ff03),
3778 SECP256K1_SCALAR_CONST(0x1968d0fa, 0xac46f103, 0xb55f1f72, 0xb3820bed, 0xec6b359a, 0x4b1ae0ad, 0x7e38e1fb, 0x295ccdfb)},
3779 {SECP256K1_SCALAR_CONST(0x2c351aa1, 0x26e91589, 0x194f8a1e, 0x06561f66, 0x0cb97b7f, 0x10914454, 0x134d1c03, 0x157266b4),
3780 SECP256K1_SCALAR_CONST(0xbe49ada6, 0x92bd8711, 0x41b176c4, 0xa478ba95, 0x14883434, 0x9d1cd6f3, 0xcc4b847d, 0x22af80f5)},
3781 {SECP256K1_SCALAR_CONST(0x6ba07c6e, 0x13a60edb, 0x6247f5c3, 0x84b5fa56, 0x76fe3ec5, 0x80426395, 0xf65ec2ae, 0x623ba730),
3782 SECP256K1_SCALAR_CONST(0x25ac23f7, 0x418cd747, 0x98376f9d, 0x4a11c7bf, 0x24c8ebfe, 0x4c8a8655, 0x345f4f52, 0x1c515595)},
3783 {SECP256K1_SCALAR_CONST(0x9397a712, 0x8abb6951, 0x2d4a3d54, 0x703b1c2a, 0x0661dca8, 0xd75c9b31, 0xaed4d24b, 0xd2ab2948),
3784 SECP256K1_SCALAR_CONST(0xc52e8bef, 0xd55ce3eb, 0x1c897739, 0xeb9fb606, 0x36b9cd57, 0x18c51cc2, 0x6a87489e, 0xffd0dcf3)},
3785 {SECP256K1_SCALAR_CONST(0xe6a808cc, 0xeb437888, 0xe97798df, 0x4e224e44, 0x7e3b380a, 0x207c1653, 0x889f3212, 0xc6738b6f),
3786 SECP256K1_SCALAR_CONST(0x31f9ae13, 0xd1e08b20, 0x757a2e5e, 0x5243a0eb, 0x8ae35f73, 0x19bb6122, 0xb910f26b, 0xda70aa55)},
3787 {SECP256K1_SCALAR_CONST(0xd0320548, 0xab0effe7, 0xa70779e0, 0x61a347a6, 0xb8c1e010, 0x9d5281f8, 0x2ee588a6, 0x80000000),
3788 SECP256K1_SCALAR_CONST(0x1541897e, 0x78195c90, 0x7583dd9e, 0x728b6100, 0xbce8bc6d, 0x7a53b471, 0x5dcd9e45, 0x4425fcaf)},
3789 {SECP256K1_SCALAR_CONST(0x93d623f1, 0xd45b50b0, 0x796e9186, 0x9eac9407, 0xd30edc20, 0xef6304cf, 0x250494e7, 0xba503de9),
3790 SECP256K1_SCALAR_CONST(0x7026d638, 0x1178b548, 0x92043952, 0x3c7fb47c, 0xcd3ea236, 0x31d82b01, 0x612fc387, 0x80b9b957)},
3791 {SECP256K1_SCALAR_CONST(0xf860ab39, 0x55f5d412, 0xa4d73bcc, 0x3b48bd90, 0xc248ffd3, 0x13ca10be, 0x8fba84cc, 0xdd28d6a3),
3792 SECP256K1_SCALAR_CONST(0x5c32fc70, 0xe0b15d67, 0x76694700, 0xfe62be4d, 0xeacdb229, 0x7a4433d9, 0x52155cd0, 0x7649ab59)},
3793 {SECP256K1_SCALAR_CONST(0x4e41311c, 0x0800af58, 0x7a690a8e, 0xe175c9ba, 0x6981ab73, 0xac532ea8, 0x5c1f5e63, 0x6ac1f189),
3794 SECP256K1_SCALAR_CONST(0xfffffff9, 0xd075982c, 0x7fbd3825, 0xc05038a2, 0x4533b91f, 0x94ec5f45, 0xb280b28f, 0x842324dc)},
3795 {SECP256K1_SCALAR_CONST(0x48e473bf, 0x3555eade, 0xad5d7089, 0x2424c4e4, 0x0a99397c, 0x2dc796d8, 0xb7a43a69, 0xd0364141),
3796 SECP256K1_SCALAR_CONST(0x634976b2, 0xa0e47895, 0x1ec38593, 0x266d6fd0, 0x6f602644, 0x9bb762f1, 0x7180c704, 0xe23a4daa)},
3797 {SECP256K1_SCALAR_CONST(0xbe83878d, 0x3292fc54, 0x26e71c62, 0x556ccedc, 0x7cbb8810, 0x4032a720, 0x34ead589, 0xe4d6bd13),
3798 SECP256K1_SCALAR_CONST(0x6cd150ad, 0x25e59d0f, 0x74cbae3d, 0x6377534a, 0x1e6562e8, 0xb71b9d18, 0xe1e5d712, 0x8480abb3)},
3799 {SECP256K1_SCALAR_CONST(0xcdddf2e5, 0xefc15f88, 0xc9ee06de, 0x8a846ca9, 0x28561581, 0x68daa5fb, 0xd1cf3451, 0xeb1782d0),
3800 SECP256K1_SCALAR_CONST(0xffffffd9, 0xed8d2af4, 0x993c865a, 0x23e9681a, 0x3ca3a3dc, 0xe6d5a46e, 0xbd86bd87, 0x61b55c70)},
3801 {SECP256K1_SCALAR_CONST(0xb6a18f1f, 0x04872df9, 0x08165ec4, 0x319ca19c, 0x6c0359ab, 0x1f7118fb, 0xc2ef8082, 0xca8b7785),
3802 SECP256K1_SCALAR_CONST(0xff55b19b, 0x0f1ac78c, 0x0f0c88c2, 0x2358d5ad, 0x5f455e4e, 0x3330b72f, 0x274dc153, 0xffbf272b)},
3803 {SECP256K1_SCALAR_CONST(0xea4898e5, 0x30eba3e8, 0xcf0e5c3d, 0x06ec6844, 0x01e26fb6, 0x75636225, 0xc5d08f4c, 0x1decafa0),
3804 SECP256K1_SCALAR_CONST(0xe5a014a8, 0xe3c4ec1e, 0xea4f9b32, 0xcfc7b386, 0x00630806, 0x12c08d02, 0x6407ccc2, 0xb067d90e)},
3805 {SECP256K1_SCALAR_CONST(0x70e9aea9, 0x7e933af0, 0x8a23bfab, 0x23e4b772, 0xff951863, 0x5ffcf47d, 0x6bebc918, 0x2ca58265),
3806 SECP256K1_SCALAR_CONST(0xf4e00006, 0x81bc6441, 0x4eb6ec02, 0xc194a859, 0x80ad7c48, 0xba4e9afb, 0x8b6bdbe0, 0x989d8f77)},
3807 {SECP256K1_SCALAR_CONST(0x3c56c774, 0x46efe6f0, 0xe93618b8, 0xf9b5a846, 0xd247df61, 0x83b1e215, 0x06dc8bcc, 0xeefc1bf5),
3808 SECP256K1_SCALAR_CONST(0xfff8937a, 0x2cd9586b, 0x43c25e57, 0xd1cefa7a, 0x9fb91ed3, 0x95b6533d, 0x8ad0de5b, 0xafb93f00)},
3809 {SECP256K1_SCALAR_CONST(0xfb5c2772, 0x5cb30e83, 0xe38264df, 0xe4e3ebf3, 0x392aa92e, 0xa68756a1, 0x51279ac5, 0xb50711a8),
3810 SECP256K1_SCALAR_CONST(0x000013af, 0x1105bfe7, 0xa6bbd7fb, 0x3d638f99, 0x3b266b02, 0x072fb8bc, 0x39251130, 0x2e0fd0ea)}
3811 };
3812 int i, var, testrand;
3813 unsigned char b32[32];
3814 secp256k1_fe x_fe;
3815 secp256k1_scalar x_scalar;
3816 memset(b32, 0, sizeof(b32));
3817 /* Test fixed test cases through test_inverse_{scalar,field}, both ways. */
3818 for (i = 0; (size_t)i < ARRAY_SIZE(fe_cases); ++i) {
3819 for (var = 0; var <= 1; ++var) {
3820 test_inverse_field(&x_fe, &fe_cases[i][0], var);
3821 CHECK(fe_equal(&x_fe, &fe_cases[i][1]));
3822 test_inverse_field(&x_fe, &fe_cases[i][1], var);
3823 CHECK(fe_equal(&x_fe, &fe_cases[i][0]));
3824 }
3825 }
3826 for (i = 0; (size_t)i < ARRAY_SIZE(scalar_cases); ++i) {
3827 for (var = 0; var <= 1; ++var) {
3828 test_inverse_scalar(&x_scalar, &scalar_cases[i][0], var);
3829 CHECK(secp256k1_scalar_eq(&x_scalar, &scalar_cases[i][1]));
3830 test_inverse_scalar(&x_scalar, &scalar_cases[i][1], var);
3831 CHECK(secp256k1_scalar_eq(&x_scalar, &scalar_cases[i][0]));
3832 }
3833 }
3834 /* Test inputs 0..999 and their respective negations. */
3835 for (i = 0; i < 1000; ++i) {
3836 b32[31] = i & 0xff;
3837 b32[30] = (i >> 8) & 0xff;
3838 secp256k1_scalar_set_b32(&x_scalar, b32, NULL);
3839 secp256k1_fe_set_b32_mod(&x_fe, b32);
3840 for (var = 0; var <= 1; ++var) {
3841 test_inverse_scalar(NULL, &x_scalar, var);
3842 test_inverse_field(NULL, &x_fe, var);
3843 }
3844 secp256k1_scalar_negate(&x_scalar, &x_scalar);
3845 secp256k1_fe_negate(&x_fe, &x_fe, 1);
3846 for (var = 0; var <= 1; ++var) {
3847 test_inverse_scalar(NULL, &x_scalar, var);
3848 test_inverse_field(NULL, &x_fe, var);
3849 }
3850 }
3851 /* test 128*count random inputs; half with testrand256_test, half with testrand256 */
3852 for (testrand = 0; testrand <= 1; ++testrand) {
3853 for (i = 0; i < 64 * COUNT; ++i) {
3854 (testrand ? testrand256_test : testrand256)(b32);
3855 secp256k1_scalar_set_b32(&x_scalar, b32, NULL);
3856 secp256k1_fe_set_b32_mod(&x_fe, b32);
3857 for (var = 0; var <= 1; ++var) {
3858 test_inverse_scalar(NULL, &x_scalar, var);
3859 test_inverse_field(NULL, &x_fe, var);
3860 }
3861 }
3862 }
3863}
3864
3865/***** HSORT TESTS *****/
3866
3867static void test_heap_swap(void) {
3868 unsigned char a[600];
3869 unsigned char e[sizeof(a)];
3870 memset(a, 21, 200);
3871 memset(a + 200, 99, 200);
3872 memset(a + 400, 42, 200);
3873 memset(e, 42, 200);
3874 memset(e + 200, 99, 200);
3875 memset(e + 400, 21, 200);
3876 secp256k1_heap_swap(a, 0, 2, 200);
3877 CHECK(secp256k1_memcmp_var(a, e, sizeof(a)) == 0);
3878}
3879
3880static void test_hsort_is_sorted(unsigned char *elements, size_t n, size_t len) {
3881 size_t i;
3882 for (i = 1; i < n; i++) {
3883 CHECK(secp256k1_memcmp_var(&elements[(i-1) * len], &elements[i * len], len) <= 0);
3884 }
3885}
3886
3888 size_t counter;
3890};
3891
3892
3893static int test_hsort_cmp(const void *ele1, const void *ele2, void *data) {
3894 struct test_hsort_cmp_data *d = (struct test_hsort_cmp_data *) data;
3895 d->counter += 1;
3896 return secp256k1_memcmp_var((unsigned char *)ele1, (unsigned char *)ele2, d->element_len);
3897}
3898
3899#define NUM 65
3900#define MAX_ELEMENT_LEN 65
3901static void test_hsort(size_t element_len) {
3902 unsigned char elements[NUM * MAX_ELEMENT_LEN] = { 0 };
3904 int i;
3905
3907 data.counter = 0;
3908 data.element_len = element_len;
3909
3911 CHECK(data.counter == 0);
3913 CHECK(data.counter == 0);
3915 CHECK(data.counter >= NUM - 1);
3917
3918 /* Test hsort with array of random length n */
3919 for (i = 0; i < COUNT; i++) {
3920 int n = testrand_int(NUM);
3921 testrand_bytes_test(elements, n*element_len);
3923 test_hsort_is_sorted(elements, n, element_len);
3924 }
3925}
3926#undef NUM
3927#undef MAX_ELEMENT_LEN
3928
3929
3930static void run_hsort_tests(void) {
3932 test_hsort(1);
3933 test_hsort(64);
3934 test_hsort(65);
3935}
3936
3937/***** GROUP TESTS *****/
3938
3939/* This compares jacobian points including their Z, not just their geometric meaning. */
3940static int gej_xyz_equals_gej(const secp256k1_gej *a, const secp256k1_gej *b) {
3941 secp256k1_gej a2;
3942 secp256k1_gej b2;
3943 int ret = 1;
3944 ret &= a->infinity == b->infinity;
3945 if (ret && !a->infinity) {
3946 a2 = *a;
3947 b2 = *b;
3954 ret &= secp256k1_fe_cmp_var(&a2.x, &b2.x) == 0;
3955 ret &= secp256k1_fe_cmp_var(&a2.y, &b2.y) == 0;
3956 ret &= secp256k1_fe_cmp_var(&a2.z, &b2.z) == 0;
3957 }
3958 return ret;
3959}
3960
3961static void test_ge(void) {
3962 int i, i1;
3963 int runs = 6;
3964 /* 25 points are used:
3965 * - infinity
3966 * - for each of four random points p1 p2 p3 p4, we add the point, its
3967 * negation, and then those two again but with randomized Z coordinate.
3968 * - The same is then done for lambda*p1 and lambda^2*p1.
3969 */
3970 secp256k1_ge *ge = checked_malloc(&CTX->error_callback, sizeof(secp256k1_ge) * (1 + 4 * runs));
3971 secp256k1_gej *gej = checked_malloc(&CTX->error_callback, sizeof(secp256k1_gej) * (1 + 4 * runs));
3972 secp256k1_fe zf, r;
3973 secp256k1_fe zfi2, zfi3;
3974
3977 for (i = 0; i < runs; i++) {
3978 int j, k;
3981 if (i >= runs - 2) {
3982 secp256k1_ge_mul_lambda(&g, &ge[1]);
3983 CHECK(!secp256k1_ge_eq_var(&g, &ge[1]));
3984 }
3985 if (i >= runs - 1) {
3987 }
3988 ge[1 + 4 * i] = g;
3989 ge[2 + 4 * i] = g;
3990 secp256k1_ge_neg(&ge[3 + 4 * i], &g);
3991 secp256k1_ge_neg(&ge[4 + 4 * i], &g);
3992 secp256k1_gej_set_ge(&gej[1 + 4 * i], &ge[1 + 4 * i]);
3993 testutil_random_ge_jacobian_test(&gej[2 + 4 * i], &ge[2 + 4 * i]);
3994 secp256k1_gej_set_ge(&gej[3 + 4 * i], &ge[3 + 4 * i]);
3995 testutil_random_ge_jacobian_test(&gej[4 + 4 * i], &ge[4 + 4 * i]);
3996 for (j = 0; j < 4; j++) {
3997 testutil_random_ge_x_magnitude(&ge[1 + j + 4 * i]);
3998 testutil_random_ge_y_magnitude(&ge[1 + j + 4 * i]);
3999 testutil_random_gej_x_magnitude(&gej[1 + j + 4 * i]);
4000 testutil_random_gej_y_magnitude(&gej[1 + j + 4 * i]);
4001 testutil_random_gej_z_magnitude(&gej[1 + j + 4 * i]);
4002 }
4003
4004 for (j = 0; j < 4; ++j) {
4005 for (k = 0; k < 4; ++k) {
4006 int expect_equal = (j >> 1) == (k >> 1);
4007 CHECK(secp256k1_ge_eq_var(&ge[1 + j + 4 * i], &ge[1 + k + 4 * i]) == expect_equal);
4008 CHECK(secp256k1_gej_eq_var(&gej[1 + j + 4 * i], &gej[1 + k + 4 * i]) == expect_equal);
4009 CHECK(secp256k1_gej_eq_ge_var(&gej[1 + j + 4 * i], &ge[1 + k + 4 * i]) == expect_equal);
4010 CHECK(secp256k1_gej_eq_ge_var(&gej[1 + k + 4 * i], &ge[1 + j + 4 * i]) == expect_equal);
4011 }
4012 }
4013 }
4014
4015 /* Generate random zf, and zfi2 = 1/zf^2, zfi3 = 1/zf^3 */
4018 secp256k1_fe_inv_var(&zfi3, &zf);
4019 secp256k1_fe_sqr(&zfi2, &zfi3);
4020 secp256k1_fe_mul(&zfi3, &zfi3, &zfi2);
4021
4022 /* Generate random r */
4024
4025 for (i1 = 0; i1 < 1 + 4 * runs; i1++) {
4026 int i2;
4027 for (i2 = 0; i2 < 1 + 4 * runs; i2++) {
4028 /* Compute reference result using gej + gej (var). */
4029 secp256k1_gej refj, resj;
4030 secp256k1_ge ref;
4031 secp256k1_fe zr;
4032 secp256k1_gej_add_var(&refj, &gej[i1], &gej[i2], secp256k1_gej_is_infinity(&gej[i1]) ? NULL : &zr);
4033 /* Check Z ratio. */
4034 if (!secp256k1_gej_is_infinity(&gej[i1]) && !secp256k1_gej_is_infinity(&refj)) {
4035 secp256k1_fe zrz; secp256k1_fe_mul(&zrz, &zr, &gej[i1].z);
4036 CHECK(secp256k1_fe_equal(&zrz, &refj.z));
4037 }
4038 secp256k1_ge_set_gej_var(&ref, &refj);
4039
4040 /* Test gej + ge with Z ratio result (var). */
4041 secp256k1_gej_add_ge_var(&resj, &gej[i1], &ge[i2], secp256k1_gej_is_infinity(&gej[i1]) ? NULL : &zr);
4042 CHECK(secp256k1_gej_eq_ge_var(&resj, &ref));
4043 if (!secp256k1_gej_is_infinity(&gej[i1]) && !secp256k1_gej_is_infinity(&resj)) {
4044 secp256k1_fe zrz; secp256k1_fe_mul(&zrz, &zr, &gej[i1].z);
4045 CHECK(secp256k1_fe_equal(&zrz, &resj.z));
4046 }
4047
4048 /* Test gej + ge (var, with additional Z factor). */
4049 {
4050 secp256k1_ge ge2_zfi = ge[i2]; /* the second term with x and y rescaled for z = 1/zf */
4051 secp256k1_fe_mul(&ge2_zfi.x, &ge2_zfi.x, &zfi2);
4052 secp256k1_fe_mul(&ge2_zfi.y, &ge2_zfi.y, &zfi3);
4055 secp256k1_gej_add_zinv_var(&resj, &gej[i1], &ge2_zfi, &zf);
4056 CHECK(secp256k1_gej_eq_ge_var(&resj, &ref));
4057 }
4058
4059 /* Test gej + ge (const). */
4060 if (i2 != 0) {
4061 /* secp256k1_gej_add_ge does not support its second argument being infinity. */
4062 secp256k1_gej_add_ge(&resj, &gej[i1], &ge[i2]);
4063 CHECK(secp256k1_gej_eq_ge_var(&resj, &ref));
4064 }
4065
4066 /* Test doubling (var). */
4067 if ((i1 == 0 && i2 == 0) || ((i1 + 3)/4 == (i2 + 3)/4 && ((i1 + 3)%4)/2 == ((i2 + 3)%4)/2)) {
4068 secp256k1_fe zr2;
4069 /* Normal doubling with Z ratio result. */
4070 secp256k1_gej_double_var(&resj, &gej[i1], &zr2);
4071 CHECK(secp256k1_gej_eq_ge_var(&resj, &ref));
4072 /* Check Z ratio. */
4073 secp256k1_fe_mul(&zr2, &zr2, &gej[i1].z);
4074 CHECK(secp256k1_fe_equal(&zr2, &resj.z));
4075 /* Normal doubling. */
4076 secp256k1_gej_double_var(&resj, &gej[i2], NULL);
4077 CHECK(secp256k1_gej_eq_ge_var(&resj, &ref));
4078 /* Constant-time doubling. */
4079 secp256k1_gej_double(&resj, &gej[i2]);
4080 CHECK(secp256k1_gej_eq_ge_var(&resj, &ref));
4081 }
4082
4083 /* Test adding opposites. */
4084 if ((i1 == 0 && i2 == 0) || ((i1 + 3)/4 == (i2 + 3)/4 && ((i1 + 3)%4)/2 != ((i2 + 3)%4)/2)) {
4086 }
4087
4088 /* Test adding infinity. */
4089 if (i1 == 0) {
4092 CHECK(secp256k1_gej_eq_ge_var(&gej[i2], &ref));
4093 }
4094 if (i2 == 0) {
4097 CHECK(secp256k1_gej_eq_ge_var(&gej[i1], &ref));
4098 }
4099 }
4100 }
4101
4102 /* Test adding all points together in random order equals infinity. */
4103 {
4105 secp256k1_gej *gej_shuffled = checked_malloc(&CTX->error_callback, (4 * runs + 1) * sizeof(secp256k1_gej));
4106 for (i = 0; i < 4 * runs + 1; i++) {
4107 gej_shuffled[i] = gej[i];
4108 }
4109 for (i = 0; i < 4 * runs + 1; i++) {
4110 int swap = i + testrand_int(4 * runs + 1 - i);
4111 if (swap != i) {
4112 secp256k1_gej t = gej_shuffled[i];
4113 gej_shuffled[i] = gej_shuffled[swap];
4114 gej_shuffled[swap] = t;
4115 }
4116 }
4117 for (i = 0; i < 4 * runs + 1; i++) {
4118 secp256k1_gej_add_var(&sum, &sum, &gej_shuffled[i], NULL);
4119 }
4121 free(gej_shuffled);
4122 }
4123
4124 /* Test batch gej -> ge conversion without known z ratios. */
4125 {
4126 secp256k1_ge *ge_set_all_var = checked_malloc(&CTX->error_callback, (4 * runs + 1) * sizeof(secp256k1_ge));
4127 secp256k1_ge *ge_set_all = checked_malloc(&CTX->error_callback, (4 * runs + 1) * sizeof(secp256k1_ge));
4128 secp256k1_ge_set_all_gej_var(&ge_set_all_var[0], &gej[0], 4 * runs + 1);
4129 for (i = 0; i < 4 * runs + 1; i++) {
4132 secp256k1_gej_rescale(&gej[i], &s);
4133 CHECK(secp256k1_gej_eq_ge_var(&gej[i], &ge_set_all_var[i]));
4134 }
4135
4136 /* Skip infinity at &gej[0]. */
4137 secp256k1_ge_set_all_gej(&ge_set_all[1], &gej[1], 4 * runs);
4138 for (i = 1; i < 4 * runs + 1; i++) {
4141 secp256k1_gej_rescale(&gej[i], &s);
4142 CHECK(secp256k1_gej_eq_ge_var(&gej[i], &ge_set_all[i]));
4143 CHECK(secp256k1_ge_eq_var(&ge_set_all_var[i], &ge_set_all[i]));
4144 }
4145
4146 /* Test with an array of length 1. */
4147 secp256k1_ge_set_all_gej_var(ge_set_all_var, &gej[1], 1);
4148 secp256k1_ge_set_all_gej(ge_set_all, &gej[1], 1);
4149 CHECK(secp256k1_gej_eq_ge_var(&gej[1], &ge_set_all_var[1]));
4150 CHECK(secp256k1_gej_eq_ge_var(&gej[1], &ge_set_all[1]));
4151 CHECK(secp256k1_ge_eq_var(&ge_set_all_var[1], &ge_set_all[1]));
4152
4153 /* Test with an array of length 0. */
4154 secp256k1_ge_set_all_gej_var(NULL, NULL, 0);
4155 secp256k1_ge_set_all_gej(NULL, NULL, 0);
4156
4157 free(ge_set_all_var);
4158 free(ge_set_all);
4159 }
4160
4161 /* Test that all elements have X coordinates on the curve. */
4162 for (i = 1; i < 4 * runs + 1; i++) {
4163 secp256k1_fe n;
4165 /* And the same holds after random rescaling. */
4166 secp256k1_fe_mul(&n, &zf, &ge[i].x);
4168 }
4169
4170 /* Test correspondence of secp256k1_ge_x{,_frac}_on_curve_var with ge_set_xo. */
4171 {
4172 secp256k1_fe n;
4173 secp256k1_ge q;
4174 int ret_on_curve, ret_frac_on_curve, ret_set_xo;
4175 secp256k1_fe_mul(&n, &zf, &r);
4176 ret_on_curve = secp256k1_ge_x_on_curve_var(&r);
4177 ret_frac_on_curve = secp256k1_ge_x_frac_on_curve_var(&n, &zf);
4178 ret_set_xo = secp256k1_ge_set_xo_var(&q, &r, 0);
4179 CHECK(ret_on_curve == ret_frac_on_curve);
4180 CHECK(ret_on_curve == ret_set_xo);
4181 if (ret_set_xo) CHECK(secp256k1_fe_equal(&r, &q.x));
4182 }
4183
4184 /* Test batch gej -> ge conversion with many infinities. */
4185 for (i = 0; i < 4 * runs + 1; i++) {
4186 int odd;
4188 odd = secp256k1_fe_is_odd(&ge[i].x);
4189 CHECK(odd == 0 || odd == 1);
4190 /* randomly set half the points to infinity */
4191 if (odd == i % 2) {
4193 }
4194 secp256k1_gej_set_ge(&gej[i], &ge[i]);
4195 }
4196 /* batch convert */
4197 secp256k1_ge_set_all_gej_var(ge, gej, 4 * runs + 1);
4198 /* check result */
4199 for (i = 0; i < 4 * runs + 1; i++) {
4200 CHECK(secp256k1_gej_eq_ge_var(&gej[i], &ge[i]));
4201 }
4202
4203 /* Test batch gej -> ge conversion with all infinities. */
4204 for (i = 0; i < 4 * runs + 1; i++) {
4206 }
4207 /* batch convert */
4208 secp256k1_ge_set_all_gej_var(ge, gej, 4 * runs + 1);
4209 /* check result */
4210 for (i = 0; i < 4 * runs + 1; i++) {
4212 }
4213
4214 free(ge);
4215 free(gej);
4216}
4217
4218static void test_initialized_inf(void) {
4219 secp256k1_ge p;
4220 secp256k1_gej pj, npj, infj1, infj2, infj3;
4221 secp256k1_fe zinv;
4222
4223 /* Test that adding P+(-P) results in a fully initialized infinity*/
4225 secp256k1_gej_set_ge(&pj, &p);
4226 secp256k1_gej_neg(&npj, &pj);
4227
4228 secp256k1_gej_add_var(&infj1, &pj, &npj, NULL);
4230 CHECK(secp256k1_fe_is_zero(&infj1.x));
4231 CHECK(secp256k1_fe_is_zero(&infj1.y));
4232 CHECK(secp256k1_fe_is_zero(&infj1.z));
4233
4234 secp256k1_gej_add_ge_var(&infj2, &npj, &p, NULL);
4236 CHECK(secp256k1_fe_is_zero(&infj2.x));
4237 CHECK(secp256k1_fe_is_zero(&infj2.y));
4238 CHECK(secp256k1_fe_is_zero(&infj2.z));
4239
4240 secp256k1_fe_set_int(&zinv, 1);
4241 secp256k1_gej_add_zinv_var(&infj3, &npj, &p, &zinv);
4243 CHECK(secp256k1_fe_is_zero(&infj3.x));
4244 CHECK(secp256k1_fe_is_zero(&infj3.y));
4245 CHECK(secp256k1_fe_is_zero(&infj3.z));
4246
4247
4248}
4249
4250static void test_add_neg_y_diff_x(void) {
4251 /* The point of this test is to check that we can add two points
4252 * whose y-coordinates are negatives of each other but whose x
4253 * coordinates differ. If the x-coordinates were the same, these
4254 * points would be negatives of each other and their sum is
4255 * infinity. This is cool because it "covers up" any degeneracy
4256 * in the addition algorithm that would cause the xy coordinates
4257 * of the sum to be wrong (since infinity has no xy coordinates).
4258 * HOWEVER, if the x-coordinates are different, infinity is the
4259 * wrong answer, and such degeneracies are exposed. This is the
4260 * root of https://github.com/bitcoin-core/secp256k1/issues/257
4261 * which this test is a regression test for.
4262 *
4263 * These points were generated in sage as
4264 *
4265 * load("secp256k1_params.sage")
4266 *
4267 * # random "bad pair"
4268 * P = C.random_element()
4269 * Q = -int(LAMBDA) * P
4270 * print(" P: %x %x" % P.xy())
4271 * print(" Q: %x %x" % Q.xy())
4272 * print("P + Q: %x %x" % (P + Q).xy())
4273 */
4275 0x8d24cd95, 0x0a355af1, 0x3c543505, 0x44238d30,
4276 0x0643d79f, 0x05a59614, 0x2f8ec030, 0xd58977cb,
4277 0x001e337a, 0x38093dcd, 0x6c0f386d, 0x0b1293a8,
4278 0x4d72c879, 0xd7681924, 0x44e6d2f3, 0x9190117d
4279 );
4281 0xc7b74206, 0x1f788cd9, 0xabd0937d, 0x164a0d86,
4282 0x95f6ff75, 0xf19a4ce9, 0xd013bd7b, 0xbf92d2a7,
4283 0xffe1cc85, 0xc7f6c232, 0x93f0c792, 0xf4ed6c57,
4284 0xb28d3786, 0x2897e6db, 0xbb192d0b, 0x6e6feab2
4285 );
4287 0x671a63c0, 0x3efdad4c, 0x389a7798, 0x24356027,
4288 0xb3d69010, 0x278625c3, 0x5c86d390, 0x184a8f7a,
4289 0x5f6409c2, 0x2ce01f2b, 0x511fd375, 0x25071d08,
4290 0xda651801, 0x70e95caf, 0x8f0d893c, 0xbed8fbbe
4291 );
4292 secp256k1_ge b;
4293 secp256k1_gej resj;
4294 secp256k1_ge res;
4295 secp256k1_ge_set_gej(&b, &bj);
4296
4297 secp256k1_gej_add_var(&resj, &aj, &bj, NULL);
4298 secp256k1_ge_set_gej(&res, &resj);
4299 CHECK(secp256k1_gej_eq_ge_var(&sumj, &res));
4300
4301 secp256k1_gej_add_ge(&resj, &aj, &b);
4302 secp256k1_ge_set_gej(&res, &resj);
4303 CHECK(secp256k1_gej_eq_ge_var(&sumj, &res));
4304
4305 secp256k1_gej_add_ge_var(&resj, &aj, &b, NULL);
4306 secp256k1_ge_set_gej(&res, &resj);
4307 CHECK(secp256k1_gej_eq_ge_var(&sumj, &res));
4308}
4309
4310static void test_ge_bytes(void) {
4311 int i;
4312
4313 for (i = 0; i < COUNT + 1; i++) {
4314 unsigned char buf[64];
4315 secp256k1_ge p, q;
4316
4317 if (i == 0) {
4319 } else {
4321 }
4322
4323 if (!secp256k1_ge_is_infinity(&p)) {
4324 secp256k1_ge_to_bytes(buf, &p);
4325
4326 secp256k1_ge_from_bytes(&q, buf);
4327 CHECK(secp256k1_ge_eq_var(&p, &q));
4328
4330 CHECK(secp256k1_ge_eq_var(&p, &q));
4331 }
4334 CHECK(secp256k1_ge_eq_var(&p, &q));
4335 }
4336}
4337
4338static void run_ge(void) {
4339 int i;
4340 for (i = 0; i < COUNT * 32; i++) {
4341 test_ge();
4342 }
4345 test_ge_bytes();
4346}
4347
4348static void test_gej_cmov(const secp256k1_gej *a, const secp256k1_gej *b) {
4349 secp256k1_gej t = *a;
4350 secp256k1_gej_cmov(&t, b, 0);
4352 secp256k1_gej_cmov(&t, b, 1);
4354}
4355
4356static void run_gej(void) {
4357 int i;
4358 secp256k1_gej a, b;
4359
4360 /* Tests for secp256k1_gej_cmov */
4361 for (i = 0; i < COUNT; i++) {
4364 test_gej_cmov(&a, &b);
4365
4367 test_gej_cmov(&a, &b);
4368 test_gej_cmov(&b, &a);
4369
4370 b = a;
4371 test_gej_cmov(&a, &b);
4372
4374 test_gej_cmov(&a, &b);
4375 test_gej_cmov(&b, &a);
4376 }
4377
4378 /* Tests for secp256k1_gej_eq_var */
4379 for (i = 0; i < COUNT; i++) {
4380 secp256k1_fe fe;
4383 CHECK(!secp256k1_gej_eq_var(&a, &b));
4384
4385 b = a;
4387 secp256k1_gej_rescale(&a, &fe);
4388 CHECK(secp256k1_gej_eq_var(&a, &b));
4389 }
4390}
4391
4392static void test_ec_combine(void) {
4395 const secp256k1_pubkey* d[6];
4397 secp256k1_pubkey sd2;
4398 secp256k1_ge Q;
4399 int i;
4400 for (i = 1; i <= 6; i++) {
4405 secp256k1_pubkey_save(&data[i - 1], &Q);
4406 d[i - 1] = &data[i - 1];
4408 secp256k1_pubkey_save(&sd, &Q);
4409 CHECK(secp256k1_ec_pubkey_combine(CTX, &sd2, d, i) == 1);
4410 CHECK(secp256k1_memcmp_var(&sd, &sd2, sizeof(sd)) == 0);
4411 }
4412}
4413
4414static void run_ec_combine(void) {
4415 int i;
4416 for (i = 0; i < COUNT * 8; i++) {
4418 }
4419}
4420
4422 /* The input itself, normalized. */
4423 secp256k1_fe fex = *x;
4424 /* Results of set_xo_var(..., 0), set_xo_var(..., 1). */
4425 secp256k1_ge ge_even, ge_odd;
4426 /* Return values of the above calls. */
4427 int res_even, res_odd;
4428
4430
4431 res_even = secp256k1_ge_set_xo_var(&ge_even, &fex, 0);
4432 res_odd = secp256k1_ge_set_xo_var(&ge_odd, &fex, 1);
4433
4434 CHECK(res_even == res_odd);
4435
4436 if (res_even) {
4438 secp256k1_fe_normalize_var(&ge_even.x);
4440 secp256k1_fe_normalize_var(&ge_even.y);
4441
4442 /* No infinity allowed. */
4443 CHECK(!secp256k1_ge_is_infinity(&ge_even));
4445
4446 /* Check that the x coordinates check out. */
4447 CHECK(secp256k1_fe_equal(&ge_even.x, x));
4448 CHECK(secp256k1_fe_equal(&ge_odd.x, x));
4449
4450 /* Check odd/even Y in ge_odd, ge_even. */
4451 CHECK(secp256k1_fe_is_odd(&ge_odd.y));
4452 CHECK(!secp256k1_fe_is_odd(&ge_even.y));
4453 }
4454}
4455
4456static void run_group_decompress(void) {
4457 int i;
4458 for (i = 0; i < COUNT * 4; i++) {
4459 secp256k1_fe fe;
4462 }
4463}
4464
4465/***** ECMULT TESTS *****/
4466
4467static void test_pre_g_table(const secp256k1_ge_storage * pre_g, size_t n) {
4468 /* Tests the pre_g / pre_g_128 tables for consistency.
4469 * For independent verification we take a "geometric" approach to verification.
4470 * We check that every entry is on-curve.
4471 * We check that for consecutive entries p and q, that p + gg - q = 0 by checking
4472 * (1) p, gg, and -q are colinear.
4473 * (2) p, gg, and -q are all distinct.
4474 * where gg is twice the generator, where the generator is the first table entry.
4475 *
4476 * Checking the table's generators are correct is done in run_ecmult_pre_g.
4477 */
4478 secp256k1_gej g2;
4479 secp256k1_ge p, q, gg;
4480 secp256k1_fe dpx, dpy, dqx, dqy;
4481 size_t i;
4482
4483 CHECK(0 < n);
4484
4485 secp256k1_ge_from_storage(&p, &pre_g[0]);
4487
4488 secp256k1_gej_set_ge(&g2, &p);
4489 secp256k1_gej_double_var(&g2, &g2, NULL);
4490 secp256k1_ge_set_gej_var(&gg, &g2);
4491 for (i = 1; i < n; ++i) {
4492 secp256k1_fe_negate(&dpx, &p.x, 1); secp256k1_fe_add(&dpx, &gg.x); secp256k1_fe_normalize_weak(&dpx);
4493 secp256k1_fe_negate(&dpy, &p.y, 1); secp256k1_fe_add(&dpy, &gg.y); secp256k1_fe_normalize_weak(&dpy);
4494 /* Check that p is not equal to gg */
4496
4497 secp256k1_ge_from_storage(&q, &pre_g[i]);
4499
4500 secp256k1_fe_negate(&dqx, &q.x, 1); secp256k1_fe_add(&dqx, &gg.x);
4501 dqy = q.y; secp256k1_fe_add(&dqy, &gg.y);
4502 /* Check that -q is not equal to gg */
4504
4505 /* Check that -q is not equal to p */
4506 CHECK(!secp256k1_fe_equal(&dpx, &dqx) || !secp256k1_fe_equal(&dpy, &dqy));
4507
4508 /* Check that p, -q and gg are colinear */
4509 secp256k1_fe_mul(&dpx, &dpx, &dqy);
4510 secp256k1_fe_mul(&dpy, &dpy, &dqx);
4511 CHECK(secp256k1_fe_equal(&dpx, &dpy));
4512
4513 p = q;
4514 }
4515}
4516
4517static void run_ecmult_pre_g(void) {
4519 secp256k1_gej gj;
4521 size_t i;
4522
4523 /* Check that the pre_g and pre_g_128 tables are consistent. */
4526
4527 /* Check the first entry from the pre_g table. */
4529 CHECK(secp256k1_memcmp_var(&gs, &secp256k1_pre_g[0], sizeof(gs)) == 0);
4530
4531 /* Check the first entry from the pre_g_128 table. */
4533 for (i = 0; i < 128; ++i) {
4534 secp256k1_gej_double_var(&gj, &gj, NULL);
4535 }
4536 secp256k1_ge_set_gej(&g, &gj);
4538 CHECK(secp256k1_memcmp_var(&gs, &secp256k1_pre_g_128[0], sizeof(gs)) == 0);
4539}
4540
4541static void run_ecmult_chain(void) {
4542 /* random starting point A (on the curve) */
4544 0x8b30bbe9, 0xae2a9906, 0x96b22f67, 0x0709dff3,
4545 0x727fd8bc, 0x04d3362c, 0x6c7bf458, 0xe2846004,
4546 0xa357ae91, 0x5c4a6528, 0x1309edf2, 0x0504740f,
4547 0x0eb33439, 0x90216b4f, 0x81063cb6, 0x5f2f7e0f
4548 );
4549 /* two random initial factors xn and gn */
4551 0x84cc5452, 0xf7fde1ed, 0xb4d38a8c, 0xe9b1b84c,
4552 0xcef31f14, 0x6e569be9, 0x705d357a, 0x42985407
4553 );
4555 0xa1e58d22, 0x553dcd42, 0xb2398062, 0x5d4c57a9,
4556 0x6e9323d4, 0x2b3152e5, 0xca2c3990, 0xedc7c9de
4557 );
4558 /* two small multipliers to be applied to xn and gn in every iteration: */
4559 static const secp256k1_scalar xf = SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 0x1337);
4560 static const secp256k1_scalar gf = SECP256K1_SCALAR_CONST(0, 0, 0, 0, 0, 0, 0, 0x7113);
4561 /* accumulators with the resulting coefficients to A and G */
4564 /* actual points */
4565 secp256k1_gej x;
4566 secp256k1_gej x2;
4567 int i;
4568
4569 /* the point being computed */
4570 x = a;
4571 for (i = 0; i < 200*COUNT; i++) {
4572 /* in each iteration, compute X = xn*X + gn*G; */
4573 secp256k1_ecmult(&x, &x, &xn, &gn);
4574 /* also compute ae and ge: the actual accumulated factors for A and G */
4575 /* if X was (ae*A+ge*G), xn*X + gn*G results in (xn*ae*A + (xn*ge+gn)*G) */
4576 secp256k1_scalar_mul(&ae, &ae, &xn);
4577 secp256k1_scalar_mul(&ge, &ge, &xn);
4578 secp256k1_scalar_add(&ge, &ge, &gn);
4579 /* modify xn and gn */
4580 secp256k1_scalar_mul(&xn, &xn, &xf);
4581 secp256k1_scalar_mul(&gn, &gn, &gf);
4582
4583 /* verify */
4584 if (i == 19999) {
4585 /* expected result after 19999 iterations */
4587 0xD6E96687, 0xF9B10D09, 0x2A6F3543, 0x9D86CEBE,
4588 0xA4535D0D, 0x409F5358, 0x6440BD74, 0xB933E830,
4589 0xB95CBCA2, 0xC77DA786, 0x539BE8FD, 0x53354D2D,
4590 0x3B4F566A, 0xE6580454, 0x07ED6015, 0xEE1B2A88
4591 );
4592 CHECK(secp256k1_gej_eq_var(&rp, &x));
4593 }
4594 }
4595 /* redo the computation, but directly with the resulting ae and ge coefficients: */
4596 secp256k1_ecmult(&x2, &a, &ae, &ge);
4597 CHECK(secp256k1_gej_eq_var(&x, &x2));
4598}
4599
4600static void test_point_times_order(const secp256k1_gej *point) {
4601 /* X * (point + G) + (order-X) * (pointer + G) = 0 */
4604 secp256k1_gej res1, res2;
4605 secp256k1_ge res3;
4607 secp256k1_scalar_negate(&nx, &x);
4608 secp256k1_ecmult(&res1, point, &x, &x); /* calc res1 = x * point + x * G; */
4609 secp256k1_ecmult(&res2, point, &nx, &nx); /* calc res2 = (order - x) * point + (order - x) * G; */
4610 secp256k1_gej_add_var(&res1, &res1, &res2, NULL);
4612 secp256k1_ge_set_gej(&res3, &res1);
4614 CHECK(secp256k1_ge_is_valid_var(&res3) == 0);
4615 /* check zero/one edge cases */
4617 secp256k1_ecmult(&res2, point, &secp256k1_scalar_zero, NULL);
4618 secp256k1_ge_set_gej(&res3, &res1);
4622
4624 secp256k1_ecmult(&res2, point, &secp256k1_scalar_one, NULL);
4625 secp256k1_ge_set_gej(&res3, &res1);
4626 CHECK(secp256k1_gej_eq_ge_var(point, &res3));
4627 secp256k1_ge_set_gej(&res3, &res2);
4628 CHECK(secp256k1_gej_eq_ge_var(point, &res3));
4629
4631 secp256k1_ge_set_gej(&res3, &res1);
4633}
4634
4635/* These scalars reach large (in absolute value) outputs when fed to secp256k1_scalar_split_lambda.
4636 *
4637 * They are computed as:
4638 * - For a in [-2, -1, 0, 1, 2]:
4639 * - For b in [-3, -1, 1, 3]:
4640 * - Output (a*LAMBDA + (ORDER+b)/2) % ORDER
4641 */
4643 SECP256K1_SCALAR_CONST(0xd938a566, 0x7f479e3e, 0xb5b3c7fa, 0xefdb3749, 0x3aa0585c, 0xc5ea2367, 0xe1b660db, 0x0209e6fc),
4644 SECP256K1_SCALAR_CONST(0xd938a566, 0x7f479e3e, 0xb5b3c7fa, 0xefdb3749, 0x3aa0585c, 0xc5ea2367, 0xe1b660db, 0x0209e6fd),
4645 SECP256K1_SCALAR_CONST(0xd938a566, 0x7f479e3e, 0xb5b3c7fa, 0xefdb3749, 0x3aa0585c, 0xc5ea2367, 0xe1b660db, 0x0209e6fe),
4646 SECP256K1_SCALAR_CONST(0xd938a566, 0x7f479e3e, 0xb5b3c7fa, 0xefdb3749, 0x3aa0585c, 0xc5ea2367, 0xe1b660db, 0x0209e6ff),
4647 SECP256K1_SCALAR_CONST(0x2c9c52b3, 0x3fa3cf1f, 0x5ad9e3fd, 0x77ed9ba5, 0xb294b893, 0x3722e9a5, 0x00e698ca, 0x4cf7632d),
4648 SECP256K1_SCALAR_CONST(0x2c9c52b3, 0x3fa3cf1f, 0x5ad9e3fd, 0x77ed9ba5, 0xb294b893, 0x3722e9a5, 0x00e698ca, 0x4cf7632e),
4649 SECP256K1_SCALAR_CONST(0x2c9c52b3, 0x3fa3cf1f, 0x5ad9e3fd, 0x77ed9ba5, 0xb294b893, 0x3722e9a5, 0x00e698ca, 0x4cf7632f),
4650 SECP256K1_SCALAR_CONST(0x2c9c52b3, 0x3fa3cf1f, 0x5ad9e3fd, 0x77ed9ba5, 0xb294b893, 0x3722e9a5, 0x00e698ca, 0x4cf76330),
4651 SECP256K1_SCALAR_CONST(0x7fffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xd576e735, 0x57a4501d, 0xdfe92f46, 0x681b209f),
4652 SECP256K1_SCALAR_CONST(0x7fffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xd576e735, 0x57a4501d, 0xdfe92f46, 0x681b20a0),
4653 SECP256K1_SCALAR_CONST(0x7fffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xd576e735, 0x57a4501d, 0xdfe92f46, 0x681b20a1),
4654 SECP256K1_SCALAR_CONST(0x7fffffff, 0xffffffff, 0xffffffff, 0xffffffff, 0xd576e735, 0x57a4501d, 0xdfe92f46, 0x681b20a2),
4655 SECP256K1_SCALAR_CONST(0xd363ad4c, 0xc05c30e0, 0xa5261c02, 0x88126459, 0xf85915d7, 0x7825b696, 0xbeebc5c2, 0x833ede11),
4656 SECP256K1_SCALAR_CONST(0xd363ad4c, 0xc05c30e0, 0xa5261c02, 0x88126459, 0xf85915d7, 0x7825b696, 0xbeebc5c2, 0x833ede12),
4657 SECP256K1_SCALAR_CONST(0xd363ad4c, 0xc05c30e0, 0xa5261c02, 0x88126459, 0xf85915d7, 0x7825b696, 0xbeebc5c2, 0x833ede13),
4658 SECP256K1_SCALAR_CONST(0xd363ad4c, 0xc05c30e0, 0xa5261c02, 0x88126459, 0xf85915d7, 0x7825b696, 0xbeebc5c2, 0x833ede14),
4659 SECP256K1_SCALAR_CONST(0x26c75a99, 0x80b861c1, 0x4a4c3805, 0x1024c8b4, 0x704d760e, 0xe95e7cd3, 0xde1bfdb1, 0xce2c5a42),
4660 SECP256K1_SCALAR_CONST(0x26c75a99, 0x80b861c1, 0x4a4c3805, 0x1024c8b4, 0x704d760e, 0xe95e7cd3, 0xde1bfdb1, 0xce2c5a43),
4661 SECP256K1_SCALAR_CONST(0x26c75a99, 0x80b861c1, 0x4a4c3805, 0x1024c8b4, 0x704d760e, 0xe95e7cd3, 0xde1bfdb1, 0xce2c5a44),
4662 SECP256K1_SCALAR_CONST(0x26c75a99, 0x80b861c1, 0x4a4c3805, 0x1024c8b4, 0x704d760e, 0xe95e7cd3, 0xde1bfdb1, 0xce2c5a45)
4663};
4664
4665static void test_ecmult_target(const secp256k1_scalar* target, int mode) {
4666 /* Mode: 0=ecmult_gen, 1=ecmult, 2=ecmult_const */
4667 secp256k1_scalar n1, n2;
4668 secp256k1_ge p;
4669 secp256k1_gej pj, p1j, p2j, ptj;
4670
4671 /* Generate random n1,n2 such that n1+n2 = -target. */
4673 secp256k1_scalar_add(&n2, &n1, target);
4674 secp256k1_scalar_negate(&n2, &n2);
4675
4676 /* Generate a random input point. */
4677 if (mode != 0) {
4679 secp256k1_gej_set_ge(&pj, &p);
4680 }
4681
4682 /* EC multiplications */
4683 if (mode == 0) {
4687 } else if (mode == 1) {
4688 secp256k1_ecmult(&p1j, &pj, &n1, &secp256k1_scalar_zero);
4689 secp256k1_ecmult(&p2j, &pj, &n2, &secp256k1_scalar_zero);
4690 secp256k1_ecmult(&ptj, &pj, target, &secp256k1_scalar_zero);
4691 } else {
4692 secp256k1_ecmult_const(&p1j, &p, &n1);
4693 secp256k1_ecmult_const(&p2j, &p, &n2);
4694 secp256k1_ecmult_const(&ptj, &p, target);
4695 }
4696
4697 /* Add them all up: n1*P + n2*P + target*P = (n1+n2+target)*P = (n1+n1-n1-n2)*P = 0. */
4698 secp256k1_gej_add_var(&ptj, &ptj, &p1j, NULL);
4699 secp256k1_gej_add_var(&ptj, &ptj, &p2j, NULL);
4701}
4702
4704 int i;
4705 unsigned j;
4706 for (i = 0; i < 4*COUNT; ++i) {
4707 for (j = 0; j < ARRAY_SIZE(scalars_near_split_bounds); ++j) {
4711 }
4712 }
4713}
4714
4715static void run_point_times_order(void) {
4716 int i;
4717 secp256k1_fe x = SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 2);
4718 static const secp256k1_fe xr = SECP256K1_FE_CONST(
4719 0x7603CB59, 0xB0EF6C63, 0xFE608479, 0x2A0C378C,
4720 0xDB3233A8, 0x0F8A9A09, 0xA877DEAD, 0x31B38C45
4721 );
4722 for (i = 0; i < 500; i++) {
4723 secp256k1_ge p;
4724 if (secp256k1_ge_set_xo_var(&p, &x, 1)) {
4725 secp256k1_gej j;
4727 secp256k1_gej_set_ge(&j, &p);
4729 }
4730 secp256k1_fe_sqr(&x, &x);
4731 }
4733 CHECK(secp256k1_fe_equal(&x, &xr));
4734}
4735
4736static void ecmult_const_random_mult(void) {
4737 /* random starting point A (on the curve) */
4739 0x6d986544, 0x57ff52b8, 0xcf1b8126, 0x5b802a5b,
4740 0xa97f9263, 0xb1e88044, 0x93351325, 0x91bc450a,
4741 0x535c59f7, 0x325e5d2b, 0xc391fbe8, 0x3c12787c,
4742 0x337e4a98, 0xe82a9011, 0x0123ba37, 0xdd769c7d
4743 );
4744 /* random initial factor xn */
4746 0x649d4f77, 0xc4242df7, 0x7f2079c9, 0x14530327,
4747 0xa31b876a, 0xd2d8ce2a, 0x2236d5c6, 0xd7b2029b
4748 );
4749 /* expected xn * A (from sage) */
4750 secp256k1_ge expected_b = SECP256K1_GE_CONST(
4751 0x23773684, 0x4d209dc7, 0x098a786f, 0x20d06fcd,
4752 0x070a38bf, 0xc11ac651, 0x03004319, 0x1e2a8786,
4753 0xed8c3b8e, 0xc06dd57b, 0xd06ea66e, 0x45492b0f,
4754 0xb84e4e1b, 0xfb77e21f, 0x96baae2a, 0x63dec956
4755 );
4756 secp256k1_gej b;
4757 secp256k1_ecmult_const(&b, &a, &xn);
4758
4760 CHECK(secp256k1_gej_eq_ge_var(&b, &expected_b));
4761}
4762
4766 secp256k1_gej res1;
4767 secp256k1_gej res2;
4768 secp256k1_ge mid1;
4769 secp256k1_ge mid2;
4772
4775 secp256k1_ge_set_gej(&mid1, &res1);
4776 secp256k1_ge_set_gej(&mid2, &res2);
4777 secp256k1_ecmult_const(&res1, &mid1, &b);
4778 secp256k1_ecmult_const(&res2, &mid2, &a);
4779 secp256k1_ge_set_gej(&mid1, &res1);
4780 secp256k1_ge_set_gej(&mid2, &res2);
4781 CHECK(secp256k1_ge_eq_var(&mid1, &mid2));
4782}
4783
4786 secp256k1_scalar negone;
4787 secp256k1_gej res1;
4788 secp256k1_ge res2;
4789 secp256k1_ge point;
4790 secp256k1_ge inf;
4791
4796
4797 /* 0*point */
4800
4801 /* s*inf */
4802 secp256k1_ecmult_const(&res1, &inf, &s);
4804
4805 /* 1*point */
4807 secp256k1_ge_set_gej(&res2, &res1);
4808 CHECK(secp256k1_ge_eq_var(&res2, &point));
4809
4810 /* -1*point */
4811 secp256k1_ecmult_const(&res1, &point, &negone);
4812 secp256k1_gej_neg(&res1, &res1);
4813 secp256k1_ge_set_gej(&res2, &res1);
4814 CHECK(secp256k1_ge_eq_var(&res2, &point));
4815}
4816
4817static void ecmult_const_check_result(const secp256k1_ge *A, const secp256k1_scalar* q, const secp256k1_gej *res) {
4818 secp256k1_gej pointj, res2j;
4819 secp256k1_ge res2;
4820 secp256k1_gej_set_ge(&pointj, A);
4821 secp256k1_ecmult(&res2j, &pointj, q, &secp256k1_scalar_zero);
4822 secp256k1_ge_set_gej(&res2, &res2j);
4823 CHECK(secp256k1_gej_eq_ge_var(res, &res2));
4824}
4825
4826static void ecmult_const_edges(void) {
4828 secp256k1_ge point;
4829 secp256k1_gej res;
4830 size_t i;
4831 size_t cases = 1 + ARRAY_SIZE(scalars_near_split_bounds);
4832
4833 /* We are trying to reach the following edge cases (variables are defined as
4834 * in ecmult_const_impl.h):
4835 * 1. i = 0: s = 0 <=> q = -K
4836 * 2. i > 0: v1, v2 large values
4837 * <=> s1, s2 large values
4838 * <=> s = scalars_near_split_bounds[i]
4839 * <=> q = 2*scalars_near_split_bounds[i] - K
4840 */
4841 for (i = 0; i < cases; ++i) {
4843 if (i > 0) {
4846 }
4848 secp256k1_ecmult_const(&res, &point, &q);
4849 ecmult_const_check_result(&point, &q, &res);
4850 }
4851}
4852
4853static void ecmult_const_mult_xonly(void) {
4854 int i;
4855
4856 /* Test correspondence between secp256k1_ecmult_const and secp256k1_ecmult_const_xonly. */
4857 for (i = 0; i < 2*COUNT; ++i) {
4858 secp256k1_ge base;
4859 secp256k1_gej basej, resj;
4860 secp256k1_fe n, d, resx, v;
4862 int res;
4863 /* Random base point. */
4865 /* Random scalar to multiply it with. */
4867 /* If i is odd, n=d*base.x for random non-zero d */
4868 if (i & 1) {
4870 secp256k1_fe_mul(&n, &base.x, &d);
4871 } else {
4872 n = base.x;
4873 }
4874 /* Perform x-only multiplication. */
4875 res = secp256k1_ecmult_const_xonly(&resx, &n, (i & 1) ? &d : NULL, &q, i & 2);
4876 CHECK(res);
4877 /* Perform normal multiplication. */
4878 secp256k1_gej_set_ge(&basej, &base);
4879 secp256k1_ecmult(&resj, &basej, &q, NULL);
4880 /* Check that resj's X coordinate corresponds with resx. */
4881 secp256k1_fe_sqr(&v, &resj.z);
4882 secp256k1_fe_mul(&v, &v, &resx);
4883 CHECK(fe_equal(&v, &resj.x));
4884 }
4885
4886 /* Test that secp256k1_ecmult_const_xonly correctly rejects X coordinates not on curve. */
4887 for (i = 0; i < 2*COUNT; ++i) {
4888 secp256k1_fe x, n, d, r;
4889 int res;
4892 /* Generate random X coordinate not on the curve. */
4893 do {
4895 } while (secp256k1_ge_x_on_curve_var(&x));
4896 /* If i is odd, n=d*x for random non-zero d. */
4897 if (i & 1) {
4899 secp256k1_fe_mul(&n, &x, &d);
4900 } else {
4901 n = x;
4902 }
4903 res = secp256k1_ecmult_const_xonly(&r, &n, (i & 1) ? &d : NULL, &q, 0);
4904 CHECK(res == 0);
4905 }
4906}
4907
4909 /* Check known result (randomly generated test problem from sage) */
4911 0x4968d524, 0x2abf9b7a, 0x466abbcf, 0x34b11b6d,
4912 0xcd83d307, 0x827bed62, 0x05fad0ce, 0x18fae63b
4913 );
4914 const secp256k1_gej expected_point = SECP256K1_GEJ_CONST(
4915 0x5494c15d, 0x32099706, 0xc2395f94, 0x348745fd,
4916 0x757ce30e, 0x4e8c90fb, 0xa2bad184, 0xf883c69f,
4917 0x5d195d20, 0xe191bf7f, 0x1be3e55f, 0x56a80196,
4918 0x6071ad01, 0xf1462f66, 0xc997fa94, 0xdb858435
4919 );
4920 secp256k1_gej point;
4921 secp256k1_ge res;
4922 int i;
4923
4925 for (i = 0; i < 100; ++i) {
4926 secp256k1_ge tmp;
4927 secp256k1_ge_set_gej(&tmp, &point);
4928 secp256k1_ecmult_const(&point, &tmp, &scalar);
4929 }
4930 secp256k1_ge_set_gej(&res, &point);
4931 CHECK(secp256k1_gej_eq_ge_var(&expected_point, &res));
4932}
4933
4934static void run_ecmult_const_tests(void) {
4941}
4942
4943typedef struct {
4947
4948static int ecmult_multi_callback(secp256k1_scalar *sc, secp256k1_ge *pt, size_t idx, void *cbdata) {
4950 *sc = data->sc[idx];
4951 *pt = data->pt[idx];
4952 return 1;
4953}
4954
4955static int ecmult_multi_false_callback(secp256k1_scalar *sc, secp256k1_ge *pt, size_t idx, void *cbdata) {
4956 (void)sc;
4957 (void)pt;
4958 (void)idx;
4959 (void)cbdata;
4960 return 0;
4961}
4962
4964 int ncount;
4965 secp256k1_scalar sc[32];
4966 secp256k1_ge pt[32];
4967 secp256k1_gej r;
4968 secp256k1_gej r2;
4970
4971 data.sc = sc;
4972 data.pt = pt;
4973
4974 /* No points to multiply */
4975 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, NULL, ecmult_multi_callback, &data, 0));
4976
4977 /* Check 1- and 2-point multiplies against ecmult */
4978 for (ncount = 0; ncount < COUNT; ncount++) {
4979 secp256k1_ge ptg;
4980 secp256k1_gej ptgj;
4983
4985 secp256k1_gej_set_ge(&ptgj, &ptg);
4986 pt[0] = ptg;
4987 pt[1] = secp256k1_ge_const_g;
4988
4989 /* only G scalar */
4990 secp256k1_ecmult(&r2, &ptgj, &secp256k1_scalar_zero, &sc[0]);
4991 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &sc[0], ecmult_multi_callback, &data, 0));
4992 CHECK(secp256k1_gej_eq_var(&r, &r2));
4993
4994 /* 1-point */
4995 secp256k1_ecmult(&r2, &ptgj, &sc[0], &secp256k1_scalar_zero);
4996 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 1));
4997 CHECK(secp256k1_gej_eq_var(&r, &r2));
4998
4999 /* Try to multiply 1 point, but callback returns false */
5000 CHECK(!ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_false_callback, &data, 1));
5001
5002 /* 2-point */
5003 secp256k1_ecmult(&r2, &ptgj, &sc[0], &sc[1]);
5004 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 2));
5005 CHECK(secp256k1_gej_eq_var(&r, &r2));
5006
5007 /* 2-point with G scalar */
5008 secp256k1_ecmult(&r2, &ptgj, &sc[0], &sc[1]);
5009 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &sc[1], ecmult_multi_callback, &data, 1));
5010 CHECK(secp256k1_gej_eq_var(&r, &r2));
5011 }
5012
5013 /* Check infinite outputs of various forms */
5014 for (ncount = 0; ncount < COUNT; ncount++) {
5015 secp256k1_ge ptg;
5016 size_t i, j;
5017 size_t sizes[] = { 2, 10, 32 };
5018
5019 for (j = 0; j < 3; j++) {
5020 for (i = 0; i < 32; i++) {
5023 }
5024 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, sizes[j]));
5026 }
5027
5028 for (j = 0; j < 3; j++) {
5029 for (i = 0; i < 32; i++) {
5031 pt[i] = ptg;
5032 secp256k1_scalar_set_int(&sc[i], 0);
5033 }
5034 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, sizes[j]));
5036 }
5037
5038 for (j = 0; j < 3; j++) {
5040 for (i = 0; i < 16; i++) {
5042 secp256k1_scalar_negate(&sc[2*i + 1], &sc[2*i]);
5043 pt[2 * i] = ptg;
5044 pt[2 * i + 1] = ptg;
5045 }
5046
5047 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, sizes[j]));
5049
5051 for (i = 0; i < 16; i++) {
5053
5054 sc[2*i] = sc[0];
5055 sc[2*i+1] = sc[0];
5056 pt[2 * i] = ptg;
5057 secp256k1_ge_neg(&pt[2*i+1], &pt[2*i]);
5058 }
5059
5060 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, sizes[j]));
5062 }
5063
5065 secp256k1_scalar_set_int(&sc[0], 0);
5066 pt[0] = ptg;
5067 for (i = 1; i < 32; i++) {
5068 pt[i] = ptg;
5069
5071 secp256k1_scalar_add(&sc[0], &sc[0], &sc[i]);
5072 secp256k1_scalar_negate(&sc[i], &sc[i]);
5073 }
5074
5075 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 32));
5077 }
5078
5079 /* Check random points, constant scalar */
5080 for (ncount = 0; ncount < COUNT; ncount++) {
5081 size_t i;
5083
5085 for (i = 0; i < 20; i++) {
5086 secp256k1_ge ptg;
5087 sc[i] = sc[0];
5089 pt[i] = ptg;
5090 secp256k1_gej_add_ge_var(&r, &r, &pt[i], NULL);
5091 }
5092
5093 secp256k1_ecmult(&r2, &r, &sc[0], &secp256k1_scalar_zero);
5094 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 20));
5095 CHECK(secp256k1_gej_eq_var(&r, &r2));
5096 }
5097
5098 /* Check random scalars, constant point */
5099 for (ncount = 0; ncount < COUNT; ncount++) {
5100 size_t i;
5101 secp256k1_ge ptg;
5102 secp256k1_gej p0j;
5105
5107 for (i = 0; i < 20; i++) {
5109 pt[i] = ptg;
5110 secp256k1_scalar_add(&rs, &rs, &sc[i]);
5111 }
5112
5113 secp256k1_gej_set_ge(&p0j, &pt[0]);
5114 secp256k1_ecmult(&r2, &p0j, &rs, &secp256k1_scalar_zero);
5115 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 20));
5116 CHECK(secp256k1_gej_eq_var(&r, &r2));
5117 }
5118
5119 /* Sanity check that zero scalars don't cause problems */
5120 for (ncount = 0; ncount < 20; ncount++) {
5121 testutil_random_scalar_order(&sc[ncount]);
5122 testutil_random_ge_test(&pt[ncount]);
5123 }
5124
5125 secp256k1_scalar_set_int(&sc[0], 0);
5126 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 20));
5127 secp256k1_scalar_set_int(&sc[1], 0);
5128 secp256k1_scalar_set_int(&sc[2], 0);
5129 secp256k1_scalar_set_int(&sc[3], 0);
5130 secp256k1_scalar_set_int(&sc[4], 0);
5131 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 6));
5132 CHECK(ecmult_multi(&CTX->error_callback, scratch, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 5));
5134
5135 /* Run through s0*(t0*P) + s1*(t1*P) exhaustively for many small values of s0, s1, t0, t1 */
5136 {
5137 const size_t TOP = 8;
5138 size_t s0i, s1i;
5139 size_t t0i, t1i;
5140 secp256k1_ge ptg;
5141 secp256k1_gej ptgj;
5142
5144 secp256k1_gej_set_ge(&ptgj, &ptg);
5145
5146 for(t0i = 0; t0i < TOP; t0i++) {
5147 for(t1i = 0; t1i < TOP; t1i++) {
5148 secp256k1_gej t0p, t1p;
5149 secp256k1_scalar t0, t1;
5150
5151 secp256k1_scalar_set_int(&t0, (t0i + 1) / 2);
5152 secp256k1_scalar_cond_negate(&t0, t0i & 1);
5153 secp256k1_scalar_set_int(&t1, (t1i + 1) / 2);
5154 secp256k1_scalar_cond_negate(&t1, t1i & 1);
5155
5156 secp256k1_ecmult(&t0p, &ptgj, &t0, &secp256k1_scalar_zero);
5157 secp256k1_ecmult(&t1p, &ptgj, &t1, &secp256k1_scalar_zero);
5158
5159 for(s0i = 0; s0i < TOP; s0i++) {
5160 for(s1i = 0; s1i < TOP; s1i++) {
5161 secp256k1_scalar tmp1, tmp2;
5162 secp256k1_gej expected, actual;
5163
5164 secp256k1_ge_set_gej(&pt[0], &t0p);
5165 secp256k1_ge_set_gej(&pt[1], &t1p);
5166
5167 secp256k1_scalar_set_int(&sc[0], (s0i + 1) / 2);
5168 secp256k1_scalar_cond_negate(&sc[0], s0i & 1);
5169 secp256k1_scalar_set_int(&sc[1], (s1i + 1) / 2);
5170 secp256k1_scalar_cond_negate(&sc[1], s1i & 1);
5171
5172 secp256k1_scalar_mul(&tmp1, &t0, &sc[0]);
5173 secp256k1_scalar_mul(&tmp2, &t1, &sc[1]);
5174 secp256k1_scalar_add(&tmp1, &tmp1, &tmp2);
5175
5176 secp256k1_ecmult(&expected, &ptgj, &tmp1, &secp256k1_scalar_zero);
5177 CHECK(ecmult_multi(&CTX->error_callback, scratch, &actual, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 2));
5178 CHECK(secp256k1_gej_eq_var(&actual, &expected));
5179 }
5180 }
5181 }
5182 }
5183 }
5184}
5185
5187 /* Large random test for ecmult_multi_* functions which exercises:
5188 * - Few or many inputs (0 up to 128, roughly exponentially distributed).
5189 * - Few or many 0*P or a*INF inputs (roughly uniformly distributed).
5190 * - Including or excluding an nonzero a*G term (or such a term at all).
5191 * - Final expected result equal to infinity or not (roughly 50%).
5192 * - ecmult_multi_var, ecmult_strauss_single_batch, ecmult_pippenger_single_batch
5193 */
5194
5195 /* These 4 variables define the eventual input to the ecmult_multi function.
5196 * g_scalar is the G scalar fed to it (or NULL, possibly, if g_scalar=0), and
5197 * scalars[0..filled-1] and gejs[0..filled-1] are the scalars and points
5198 * which form its normal inputs. */
5199 int filled = 0;
5201 secp256k1_scalar scalars[128];
5202 secp256k1_gej gejs[128];
5203 /* The expected result, and the computed result. */
5204 secp256k1_gej expected, computed;
5205 /* Temporaries. */
5206 secp256k1_scalar sc_tmp;
5207 secp256k1_ge ge_tmp;
5208 /* Variables needed for the actual input to ecmult_multi. */
5209 secp256k1_ge ges[128];
5211
5212 int i;
5213 /* Which multiplication function to use */
5214 int fn = testrand_int(3);
5218 /* Simulate exponentially distributed num. */
5219 int num_bits = 2 + testrand_int(6);
5220 /* Number of (scalar, point) inputs (excluding g). */
5221 int num = testrand_int((1 << num_bits) + 1);
5222 /* Number of those which are nonzero. */
5223 int num_nonzero = testrand_int(num + 1);
5224 /* Whether we're aiming to create an input with nonzero expected result. */
5225 int nonzero_result = testrand_bits(1);
5226 /* Whether we will provide nonzero g multiplicand. In some cases our hand
5227 * is forced here based on num_nonzero and nonzero_result. */
5228 int g_nonzero = num_nonzero == 0 ? nonzero_result :
5229 num_nonzero == 1 && !nonzero_result ? 1 :
5230 (int)testrand_bits(1);
5231 /* Which g_scalar pointer to pass into ecmult_multi(). */
5232 const secp256k1_scalar* g_scalar_ptr = (g_nonzero || testrand_bits(1)) ? &g_scalar : NULL;
5233 /* How many EC multiplications were performed in this function. */
5234 int mults = 0;
5235 /* How many randomization steps to apply to the input list. */
5236 int rands = (int)testrand_bits(3);
5237 if (rands > num_nonzero) rands = num_nonzero;
5238
5239 secp256k1_gej_set_infinity(&expected);
5241 secp256k1_scalar_set_int(&scalars[0], 0);
5242
5243 if (g_nonzero) {
5244 /* If g_nonzero, set g_scalar to nonzero value r. */
5246 if (!nonzero_result) {
5247 /* If expected=0 is desired, add a (a*r, -(1/a)*g) term to compensate. */
5248 CHECK(num_nonzero > filled);
5250 secp256k1_scalar_mul(&scalars[filled], &sc_tmp, &g_scalar);
5251 secp256k1_scalar_inverse_var(&sc_tmp, &sc_tmp);
5252 secp256k1_scalar_negate(&sc_tmp, &sc_tmp);
5253 secp256k1_ecmult_gen_gej(&CTX->ecmult_gen_ctx, &gejs[filled], &sc_tmp);
5254 ++filled;
5255 ++mults;
5256 }
5257 }
5258
5259 if (nonzero_result && filled < num_nonzero) {
5260 /* If a nonzero result is desired, and there is space, add a random nonzero term. */
5261 testutil_random_scalar_order_test(&scalars[filled]);
5262 testutil_random_ge_test(&ge_tmp);
5263 secp256k1_gej_set_ge(&gejs[filled], &ge_tmp);
5264 ++filled;
5265 }
5266
5267 if (nonzero_result) {
5268 /* Compute the expected result using normal ecmult. */
5269 CHECK(filled <= 1);
5270 secp256k1_ecmult(&expected, &gejs[0], &scalars[0], &g_scalar);
5271 mults += filled + g_nonzero;
5272 }
5273
5274 /* At this point we have expected = scalar_g*G + sum(scalars[i]*gejs[i] for i=0..filled-1). */
5275 CHECK(filled <= 1 + !nonzero_result);
5276 CHECK(filled <= num_nonzero);
5277
5278 /* Add entries to scalars,gejs so that there are num of them. All the added entries
5279 * either have scalar=0 or point=infinity, so these do not change the expected result. */
5280 while (filled < num) {
5281 if (testrand_bits(1)) {
5282 secp256k1_gej_set_infinity(&gejs[filled]);
5283 testutil_random_scalar_order_test(&scalars[filled]);
5284 } else {
5285 secp256k1_scalar_set_int(&scalars[filled], 0);
5286 testutil_random_ge_test(&ge_tmp);
5287 secp256k1_gej_set_ge(&gejs[filled], &ge_tmp);
5288 }
5289 ++filled;
5290 }
5291
5292 /* Now perform cheapish transformations on gejs and scalars, for indices
5293 * 0..num_nonzero-1, which do not change the expected result, but may
5294 * convert some of them to be both non-0-scalar and non-infinity-point. */
5295 for (i = 0; i < rands; ++i) {
5296 int j;
5297 secp256k1_scalar v, iv;
5298 /* Shuffle the entries. */
5299 for (j = 0; j < num_nonzero; ++j) {
5300 int k = testrand_int(num_nonzero - j);
5301 if (k != 0) {
5302 secp256k1_gej gej = gejs[j];
5303 secp256k1_scalar sc = scalars[j];
5304 gejs[j] = gejs[j + k];
5305 scalars[j] = scalars[j + k];
5306 gejs[j + k] = gej;
5307 scalars[j + k] = sc;
5308 }
5309 }
5310 /* Perturb all consecutive pairs of inputs:
5311 * a*P + b*Q -> (a+b)*P + b*(Q-P). */
5312 for (j = 0; j + 1 < num_nonzero; j += 2) {
5313 secp256k1_gej gej;
5314 secp256k1_scalar_add(&scalars[j], &scalars[j], &scalars[j+1]);
5315 secp256k1_gej_neg(&gej, &gejs[j]);
5316 secp256k1_gej_add_var(&gejs[j+1], &gejs[j+1], &gej, NULL);
5317 }
5318 /* Transform the last input: a*P -> (v*a) * ((1/v)*P). */
5319 CHECK(num_nonzero >= 1);
5321 secp256k1_scalar_inverse(&iv, &v);
5322 secp256k1_scalar_mul(&scalars[num_nonzero - 1], &scalars[num_nonzero - 1], &v);
5323 secp256k1_ecmult(&gejs[num_nonzero - 1], &gejs[num_nonzero - 1], &iv, NULL);
5324 ++mults;
5325 }
5326
5327 /* Shuffle all entries (0..num-1). */
5328 for (i = 0; i < num; ++i) {
5329 int j = testrand_int(num - i);
5330 if (j != 0) {
5331 secp256k1_gej gej = gejs[i];
5332 secp256k1_scalar sc = scalars[i];
5333 gejs[i] = gejs[i + j];
5334 scalars[i] = scalars[i + j];
5335 gejs[i + j] = gej;
5336 scalars[i + j] = sc;
5337 }
5338 }
5339
5340 /* Compute affine versions of all inputs. */
5341 secp256k1_ge_set_all_gej_var(ges, gejs, filled);
5342 /* Invoke ecmult_multi code. */
5343 data.sc = scalars;
5344 data.pt = ges;
5345 CHECK(ecmult_multi(&CTX->error_callback, scratch, &computed, g_scalar_ptr, ecmult_multi_callback, &data, filled));
5346 mults += num_nonzero + g_nonzero;
5347 /* Compare with expected result. */
5348 CHECK(secp256k1_gej_eq_var(&computed, &expected));
5349 return mults;
5350}
5351
5354 secp256k1_ge pt;
5355 secp256k1_gej r;
5357 secp256k1_scratch *scratch_empty;
5358
5361 data.sc = &sc;
5362 data.pt = &pt;
5363
5364 /* Try to multiply 1 point, but scratch space is empty.*/
5365 scratch_empty = secp256k1_scratch_create(&CTX->error_callback, 0);
5366 CHECK(!ecmult_multi(&CTX->error_callback, scratch_empty, &r, &secp256k1_scalar_zero, ecmult_multi_callback, &data, 1));
5368}
5369
5371 int i;
5372
5374 for(i = 1; i <= PIPPENGER_MAX_BUCKET_WINDOW; i++) {
5375 /* Bucket_window of 8 is not used with endo */
5376 if (i == 8) {
5377 continue;
5378 }
5380 if (i != PIPPENGER_MAX_BUCKET_WINDOW) {
5382 }
5383 }
5384}
5385
5391 size_t scratch_size = testrand_bits(8);
5393 secp256k1_scratch *scratch;
5394 size_t n_points_supported;
5395 int bucket_window = 0;
5396
5397 for(; scratch_size < max_size; scratch_size+=256) {
5398 size_t i;
5399 size_t total_alloc;
5400 size_t checkpoint;
5401 scratch = secp256k1_scratch_create(&CTX->error_callback, scratch_size);
5402 CHECK(scratch != NULL);
5403 checkpoint = secp256k1_scratch_checkpoint(&CTX->error_callback, scratch);
5404 n_points_supported = secp256k1_pippenger_max_points(&CTX->error_callback, scratch);
5405 if (n_points_supported == 0) {
5407 continue;
5408 }
5409 bucket_window = secp256k1_pippenger_bucket_window(n_points_supported);
5410 /* allocate `total_alloc` bytes over `PIPPENGER_SCRATCH_OBJECTS` many allocations */
5411 total_alloc = secp256k1_pippenger_scratch_size(n_points_supported, bucket_window);
5412 for (i = 0; i < PIPPENGER_SCRATCH_OBJECTS - 1; i++) {
5414 total_alloc--;
5415 }
5416 CHECK(secp256k1_scratch_alloc(&CTX->error_callback, scratch, total_alloc));
5419 }
5420 CHECK(bucket_window == PIPPENGER_MAX_BUCKET_WINDOW);
5421}
5422
5424 size_t n_batches, n_batch_points, max_n_batch_points, n;
5425
5426 max_n_batch_points = 0;
5427 n = 1;
5428 CHECK(secp256k1_ecmult_multi_batch_size_helper(&n_batches, &n_batch_points, max_n_batch_points, n) == 0);
5429
5430 max_n_batch_points = 1;
5431 n = 0;
5432 CHECK(secp256k1_ecmult_multi_batch_size_helper(&n_batches, &n_batch_points, max_n_batch_points, n) == 1);
5433 CHECK(n_batches == 0);
5434 CHECK(n_batch_points == 0);
5435
5436 max_n_batch_points = 2;
5437 n = 5;
5438 CHECK(secp256k1_ecmult_multi_batch_size_helper(&n_batches, &n_batch_points, max_n_batch_points, n) == 1);
5439 CHECK(n_batches == 3);
5440 CHECK(n_batch_points == 2);
5441
5442 max_n_batch_points = ECMULT_MAX_POINTS_PER_BATCH;
5444 CHECK(secp256k1_ecmult_multi_batch_size_helper(&n_batches, &n_batch_points, max_n_batch_points, n) == 1);
5445 CHECK(n_batches == 1);
5446 CHECK(n_batch_points == ECMULT_MAX_POINTS_PER_BATCH);
5447
5448 max_n_batch_points = ECMULT_MAX_POINTS_PER_BATCH + 1;
5450 CHECK(secp256k1_ecmult_multi_batch_size_helper(&n_batches, &n_batch_points, max_n_batch_points, n) == 1);
5451 CHECK(n_batches == 2);
5452 CHECK(n_batch_points == ECMULT_MAX_POINTS_PER_BATCH/2 + 1);
5453
5454 max_n_batch_points = 1;
5455 n = SIZE_MAX;
5456 CHECK(secp256k1_ecmult_multi_batch_size_helper(&n_batches, &n_batch_points, max_n_batch_points, n) == 1);
5457 CHECK(n_batches == SIZE_MAX);
5458 CHECK(n_batch_points == 1);
5459
5460 max_n_batch_points = 2;
5461 n = SIZE_MAX;
5462 CHECK(secp256k1_ecmult_multi_batch_size_helper(&n_batches, &n_batch_points, max_n_batch_points, n) == 1);
5463 CHECK(n_batches == SIZE_MAX/2 + 1);
5464 CHECK(n_batch_points == 2);
5465}
5466
5472 static const int n_points = 2*ECMULT_PIPPENGER_THRESHOLD;
5473 secp256k1_scalar scG;
5475 secp256k1_ge *pt = checked_malloc(&CTX->error_callback, sizeof(secp256k1_ge) * n_points);
5476 secp256k1_gej r;
5477 secp256k1_gej r2;
5479 int i;
5480 secp256k1_scratch *scratch;
5481
5483
5484 /* Get random scalars and group elements and compute result */
5486 secp256k1_ecmult(&r2, &r2, &secp256k1_scalar_zero, &scG);
5487 for(i = 0; i < n_points; i++) {
5488 secp256k1_ge ptg;
5489 secp256k1_gej ptgj;
5491 secp256k1_gej_set_ge(&ptgj, &ptg);
5492 pt[i] = ptg;
5494 secp256k1_ecmult(&ptgj, &ptgj, &sc[i], NULL);
5495 secp256k1_gej_add_var(&r2, &r2, &ptgj, NULL);
5496 }
5497 data.sc = sc;
5498 data.pt = pt;
5499 secp256k1_gej_neg(&r2, &r2);
5500
5501 /* Test with empty scratch space. It should compute the correct result using
5502 * ecmult_mult_simple algorithm which doesn't require a scratch space. */
5505 secp256k1_gej_add_var(&r, &r, &r2, NULL);
5508
5509 /* Test with space for 1 point in pippenger. That's not enough because
5510 * ecmult_multi selects strauss which requires more memory. It should
5511 * therefore select the simple algorithm. */
5514 secp256k1_gej_add_var(&r, &r, &r2, NULL);
5517
5518 for(i = 1; i <= n_points; i++) {
5520 int bucket_window = secp256k1_pippenger_bucket_window(i);
5521 size_t scratch_size = secp256k1_pippenger_scratch_size(i, bucket_window);
5523 } else {
5524 size_t scratch_size = secp256k1_strauss_scratch_size(i);
5526 }
5528 secp256k1_gej_add_var(&r, &r, &r2, NULL);
5531 }
5532 free(sc);
5533 free(pt);
5534}
5535
5536static void run_ecmult_multi_tests(void) {
5537 secp256k1_scratch *scratch;
5538 int64_t todo = (int64_t)320 * COUNT;
5539
5542 scratch = secp256k1_scratch_create(&CTX->error_callback, 819200);
5549 while (todo > 0) {
5550 todo -= test_ecmult_multi_random(scratch);
5551 }
5553
5554 /* Run test_ecmult_multi with space for exactly one point */
5558
5561}
5562
5563static void test_wnaf(const secp256k1_scalar *number, int w) {
5564 secp256k1_scalar x, two, t;
5565 int wnaf[256];
5566 int zeroes = -1;
5567 int i;
5568 int bits;
5570 secp256k1_scalar_set_int(&two, 2);
5571 bits = secp256k1_ecmult_wnaf(wnaf, 256, number, w);
5572 CHECK(bits <= 256);
5573 for (i = bits-1; i >= 0; i--) {
5574 int v = wnaf[i];
5575 secp256k1_scalar_mul(&x, &x, &two);
5576 if (v) {
5577 CHECK(zeroes == -1 || zeroes >= w-1); /* check that distance between non-zero elements is at least w-1 */
5578 zeroes=0;
5579 CHECK((v & 1) == 1); /* check non-zero elements are odd */
5580 CHECK(v <= (1 << (w-1)) - 1); /* check range below */
5581 CHECK(v >= -(1 << (w-1)) - 1); /* check range above */
5582 } else {
5583 CHECK(zeroes != -1); /* check that no unnecessary zero padding exists */
5584 zeroes++;
5585 }
5586 if (v >= 0) {
5588 } else {
5591 }
5592 secp256k1_scalar_add(&x, &x, &t);
5593 }
5594 CHECK(secp256k1_scalar_eq(&x, number)); /* check that wnaf represents number */
5595}
5596
5597static void test_fixed_wnaf(const secp256k1_scalar *number, int w) {
5598 secp256k1_scalar x, shift;
5599 int wnaf[256] = {0};
5600 int i;
5601 int skew;
5602 secp256k1_scalar num, unused;
5603
5605 secp256k1_scalar_set_int(&shift, 1 << w);
5606 /* Make num a 128-bit scalar. */
5607 secp256k1_scalar_split_128(&num, &unused, number);
5608 skew = secp256k1_wnaf_fixed(wnaf, &num, w);
5609
5610 for (i = WNAF_SIZE(w)-1; i >= 0; --i) {
5612 int v = wnaf[i];
5613 CHECK(v == 0 || v & 1); /* check parity */
5614 CHECK(v > -(1 << w)); /* check range above */
5615 CHECK(v < (1 << w)); /* check range below */
5616
5617 secp256k1_scalar_mul(&x, &x, &shift);
5618 if (v >= 0) {
5620 } else {
5623 }
5624 secp256k1_scalar_add(&x, &x, &t);
5625 }
5626 /* If skew is 1 then add 1 to num */
5627 secp256k1_scalar_cadd_bit(&num, 0, skew == 1);
5628 CHECK(secp256k1_scalar_eq(&x, &num));
5629}
5630
5631/* Checks that the first 8 elements of wnaf are equal to wnaf_expected and the
5632 * rest is 0.*/
5633static void test_fixed_wnaf_small_helper(int *wnaf, int *wnaf_expected, int w) {
5634 int i;
5635 for (i = WNAF_SIZE(w)-1; i >= 8; --i) {
5636 CHECK(wnaf[i] == 0);
5637 }
5638 for (i = 7; i >= 0; --i) {
5639 CHECK(wnaf[i] == wnaf_expected[i]);
5640 }
5641}
5642
5643static void test_fixed_wnaf_small(void) {
5644 int w = 4;
5645 int wnaf[256] = {0};
5646 int i;
5647 int skew;
5648 secp256k1_scalar num;
5649
5650 secp256k1_scalar_set_int(&num, 0);
5651 skew = secp256k1_wnaf_fixed(wnaf, &num, w);
5652 for (i = WNAF_SIZE(w)-1; i >= 0; --i) {
5653 int v = wnaf[i];
5654 CHECK(v == 0);
5655 }
5656 CHECK(skew == 0);
5657
5658 secp256k1_scalar_set_int(&num, 1);
5659 skew = secp256k1_wnaf_fixed(wnaf, &num, w);
5660 for (i = WNAF_SIZE(w)-1; i >= 1; --i) {
5661 int v = wnaf[i];
5662 CHECK(v == 0);
5663 }
5664 CHECK(wnaf[0] == 1);
5665 CHECK(skew == 0);
5666
5667 {
5668 int wnaf_expected[8] = { 0xf, 0xf, 0xf, 0xf, 0xf, 0xf, 0xf, 0xf };
5669 secp256k1_scalar_set_int(&num, 0xffffffff);
5670 skew = secp256k1_wnaf_fixed(wnaf, &num, w);
5671 test_fixed_wnaf_small_helper(wnaf, wnaf_expected, w);
5672 CHECK(skew == 0);
5673 }
5674 {
5675 int wnaf_expected[8] = { -1, -1, -1, -1, -1, -1, -1, 0xf };
5676 secp256k1_scalar_set_int(&num, 0xeeeeeeee);
5677 skew = secp256k1_wnaf_fixed(wnaf, &num, w);
5678 test_fixed_wnaf_small_helper(wnaf, wnaf_expected, w);
5679 CHECK(skew == 1);
5680 }
5681 {
5682 int wnaf_expected[8] = { 1, 0, 1, 0, 1, 0, 1, 0 };
5683 secp256k1_scalar_set_int(&num, 0x01010101);
5684 skew = secp256k1_wnaf_fixed(wnaf, &num, w);
5685 test_fixed_wnaf_small_helper(wnaf, wnaf_expected, w);
5686 CHECK(skew == 0);
5687 }
5688 {
5689 int wnaf_expected[8] = { -0xf, 0, 0xf, -0xf, 0, 0xf, 1, 0 };
5690 secp256k1_scalar_set_int(&num, 0x01ef1ef1);
5691 skew = secp256k1_wnaf_fixed(wnaf, &num, w);
5692 test_fixed_wnaf_small_helper(wnaf, wnaf_expected, w);
5693 CHECK(skew == 0);
5694 }
5695}
5696
5697static void run_wnaf(void) {
5698 int i;
5700
5701 /* Test 0 for fixed wnaf */
5703 /* Random tests */
5704 for (i = 0; i < COUNT; i++) {
5706 test_wnaf(&n, 4+(i%10));
5707 test_fixed_wnaf(&n, 4 + (i % 10));
5708 }
5710 CHECK(secp256k1_scalar_cond_negate(&n, 1) == -1);
5714}
5715
5716static int test_ecmult_accumulate_cb(secp256k1_scalar* sc, secp256k1_ge* pt, size_t idx, void* data) {
5717 const secp256k1_scalar* indata = (const secp256k1_scalar*)data;
5718 *sc = *indata;
5720 CHECK(idx == 0);
5721 return 1;
5722}
5723
5725 /* Compute x*G in many different ways, serialize it uncompressed, and feed it into acc. */
5726 secp256k1_gej gj, infj;
5727 secp256k1_ge r;
5728 secp256k1_gej rj[7];
5729 unsigned char bytes[65];
5730 size_t i;
5734 secp256k1_ecmult(&rj[1], &gj, x, NULL);
5735 secp256k1_ecmult(&rj[2], &gj, x, &secp256k1_scalar_zero);
5736 secp256k1_ecmult(&rj[3], &infj, &secp256k1_scalar_zero, x);
5737 CHECK(secp256k1_ecmult_multi_var(&CTX->error_callback, scratch, &rj[4], x, NULL, NULL, 0));
5740 secp256k1_ge_set_gej_var(&r, &rj[0]);
5741 for (i = 0; i < ARRAY_SIZE(rj); i++) {
5742 CHECK(secp256k1_gej_eq_ge_var(&rj[i], &r));
5743 }
5744 if (secp256k1_ge_is_infinity(&r)) {
5745 /* Store infinity as 0x00 */
5746 const unsigned char zerobyte[1] = {0};
5748 } else {
5749 /* Store other points using their uncompressed serialization. */
5751 secp256k1_sha256_write(secp256k1_get_hash_context(CTX), acc, bytes, sizeof(bytes));
5752 }
5753}
5754
5756 /* Using test_ecmult_accumulate, test ecmult for:
5757 * - For i in 0..36:
5758 * - Key i
5759 * - Key -i
5760 * - For i in 0..255:
5761 * - For j in 1..255 (only odd values):
5762 * - Key (j*2^i) mod order
5763 */
5765 secp256k1_sha256 acc;
5766 unsigned char b32[32];
5767 int i, j;
5769
5770 /* Expected hash of all the computed points; created with an independent
5771 * implementation. */
5772 static const unsigned char expected32[32] = {
5773 0xe4, 0x71, 0x1b, 0x4d, 0x14, 0x1e, 0x68, 0x48,
5774 0xb7, 0xaf, 0x47, 0x2b, 0x4c, 0xd2, 0x04, 0x14,
5775 0x3a, 0x75, 0x87, 0x60, 0x1a, 0xf9, 0x63, 0x60,
5776 0xd0, 0xcb, 0x1f, 0xaa, 0x85, 0x9a, 0xb7, 0xb4
5777 };
5779 for (i = 0; i <= 36; ++i) {
5781 test_ecmult_accumulate(&acc, &x, scratch);
5783 test_ecmult_accumulate(&acc, &x, scratch);
5784 };
5785 for (i = 0; i < 256; ++i) {
5786 for (j = 1; j < 256; j += 2) {
5787 int k;
5789 for (k = 0; k < i; ++k) secp256k1_scalar_add(&x, &x, &x);
5790 test_ecmult_accumulate(&acc, &x, scratch);
5791 }
5792 }
5794 CHECK(secp256k1_memcmp_var(b32, expected32, 32) == 0);
5795
5797}
5798
5799static void test_ecmult_constants_sha(uint32_t prefix, size_t iter, const unsigned char* expected32) {
5800 /* Using test_ecmult_accumulate, test ecmult for:
5801 * - Key 0
5802 * - Key 1
5803 * - Key -1
5804 * - For i in range(iter):
5805 * - Key SHA256(LE32(prefix) || LE16(i))
5806 */
5808 secp256k1_sha256 acc;
5809 unsigned char b32[32];
5810 unsigned char inp[6];
5811 size_t i;
5814
5815 inp[0] = prefix & 0xFF;
5816 inp[1] = (prefix >> 8) & 0xFF;
5817 inp[2] = (prefix >> 16) & 0xFF;
5818 inp[3] = (prefix >> 24) & 0xFF;
5821 test_ecmult_accumulate(&acc, &x, scratch);
5823 test_ecmult_accumulate(&acc, &x, scratch);
5825 test_ecmult_accumulate(&acc, &x, scratch);
5826
5827 for (i = 0; i < iter; ++i) {
5828 secp256k1_sha256 gen;
5829 inp[4] = i & 0xff;
5830 inp[5] = (i >> 8) & 0xff;
5832 secp256k1_sha256_write(hash_ctx, &gen, inp, sizeof(inp));
5833 secp256k1_sha256_finalize(hash_ctx, &gen, b32);
5834 secp256k1_scalar_set_b32(&x, b32, NULL);
5835 test_ecmult_accumulate(&acc, &x, scratch);
5836 }
5837 secp256k1_sha256_finalize(hash_ctx, &acc, b32);
5838 CHECK(secp256k1_memcmp_var(b32, expected32, 32) == 0);
5839
5841}
5842
5843static void run_ecmult_constants(void) {
5844 /* Expected hashes of all points in the tests below. Computed using an
5845 * independent implementation. */
5846 static const unsigned char expected32_6bit20[32] = {
5847 0x68, 0xb6, 0xed, 0x6f, 0x28, 0xca, 0xc9, 0x7f,
5848 0x8e, 0x8b, 0xd6, 0xc0, 0x61, 0x79, 0x34, 0x6e,
5849 0x5a, 0x8f, 0x2b, 0xbc, 0x3e, 0x1f, 0xc5, 0x2e,
5850 0x2a, 0xd0, 0x45, 0x67, 0x7f, 0x95, 0x95, 0x8e
5851 };
5852 static const unsigned char expected32_8bit8[32] = {
5853 0x8b, 0x65, 0x8e, 0xea, 0x86, 0xae, 0x3c, 0x95,
5854 0x90, 0xb6, 0x77, 0xa4, 0x8c, 0x76, 0xd9, 0xec,
5855 0xf5, 0xab, 0x8a, 0x2f, 0xfd, 0xdb, 0x19, 0x12,
5856 0x1a, 0xee, 0xe6, 0xb7, 0x6e, 0x05, 0x3f, 0xc6
5857 };
5858 /* For every combination of 6 bit positions out of 256, restricted to
5859 * 20-bit windows (i.e., the first and last bit position are no more than
5860 * 19 bits apart), all 64 bit patterns occur in the input scalars used in
5861 * this test. */
5862 CONDITIONAL_TEST(1, "test_ecmult_constants_sha 1024") {
5863 test_ecmult_constants_sha(4808378u, 1024, expected32_6bit20);
5864 }
5865
5866 /* For every combination of 8 consecutive bit positions, all 256 bit
5867 * patterns occur in the input scalars used in this test. */
5868 CONDITIONAL_TEST(3, "test_ecmult_constants_sha 2048") {
5869 test_ecmult_constants_sha(1607366309u, 2048, expected32_8bit8);
5870 }
5871
5872 CONDITIONAL_TEST(16, "test_ecmult_constants_2bit") {
5874 }
5875}
5876
5877static void run_ecmult_gen_ge(void) {
5878 /* Test that secp256k1_ecmult_gen_ge result matches secp256k1_ecmult_gen_gej with
5879 * manual Jacobian-to-affine conversion (secp256k1_ge_set_gej) over random scalars */
5880 int i;
5881
5882 for (i = 0; i < COUNT; i++) {
5883 secp256k1_scalar scalar;
5884 secp256k1_gej result_gej;
5885 secp256k1_ge result_ge, expected_ge;
5886
5888 secp256k1_ecmult_gen_gej(&CTX->ecmult_gen_ctx, &result_gej, &scalar);
5889 secp256k1_ge_set_gej(&expected_ge, &result_gej);
5890 secp256k1_ecmult_gen_ge(&CTX->ecmult_gen_ctx, &result_ge, &scalar);
5891
5892 CHECK(secp256k1_ge_eq_var(&result_ge, &expected_ge));
5893 }
5894}
5895
5896static void test_ecmult_gen_blind(void) {
5897 /* Test ecmult_gen() blinding and confirm that the blinding changes, the affine points match, and the z's don't match. */
5898 secp256k1_scalar key;
5900 unsigned char seed32[32];
5901 secp256k1_gej pgej;
5902 secp256k1_gej pgej2;
5903 secp256k1_ge p;
5904 secp256k1_ge pge;
5907 testrand256(seed32);
5913 CHECK(!gej_xyz_equals_gej(&pgej, &pgej2));
5915 secp256k1_ge_set_gej(&pge, &pgej);
5916 CHECK(secp256k1_gej_eq_ge_var(&pgej2, &pge));
5917}
5918
5920 /* Test ecmult_gen() blinding reset and confirm that the blinding is consistent. */
5922 secp256k1_ge p1, p2;
5929 CHECK(secp256k1_ge_eq_var(&p1, &p2));
5930}
5931
5932/* Verify that ecmult_gen for scalars gn for which gn + scalar_offset = {-1,0,1}. */
5934 int i;
5935 secp256k1_gej res1, res2, res3;
5936 secp256k1_scalar gn = secp256k1_scalar_one; /* gn = 1 */
5937 secp256k1_scalar_add(&gn, &gn, &CTX->ecmult_gen_ctx.scalar_offset); /* gn = 1 + scalar_offset */
5938 secp256k1_scalar_negate(&gn, &gn); /* gn = -1 - scalar_offset */
5939
5940 for (i = -1; i < 2; ++i) {
5941 /* Run test with gn = i - scalar_offset (so that the ecmult_gen recoded value represents i). */
5943 secp256k1_ecmult(&res2, NULL, &secp256k1_scalar_zero, &gn);
5945 CHECK(secp256k1_gej_eq_var(&res1, &res2));
5946 CHECK(secp256k1_gej_eq_var(&res1, &res3));
5948 }
5949}
5950
5951static void run_ecmult_gen_blind(void) {
5952 int i;
5955 for (i = 0; i < 10; i++) {
5957 }
5958}
5959
5960/***** ENDOMORPHISH TESTS *****/
5961static void test_scalar_split(const secp256k1_scalar* full) {
5962 secp256k1_scalar s, s1, slam;
5963 const unsigned char zero[32] = {0};
5964 unsigned char tmp[32];
5965
5966 secp256k1_scalar_split_lambda(&s1, &slam, full);
5967
5968 /* check slam*lambda + s1 == full */
5970 secp256k1_scalar_add(&s, &s, &s1);
5971 CHECK(secp256k1_scalar_eq(&s, full));
5972
5973 /* check that both are <= 128 bits in size */
5974 if (secp256k1_scalar_is_high(&s1)) {
5975 secp256k1_scalar_negate(&s1, &s1);
5976 }
5977 if (secp256k1_scalar_is_high(&slam)) {
5978 secp256k1_scalar_negate(&slam, &slam);
5979 }
5980
5981 secp256k1_scalar_get_b32(tmp, &s1);
5982 CHECK(secp256k1_memcmp_var(zero, tmp, 16) == 0);
5983 secp256k1_scalar_get_b32(tmp, &slam);
5984 CHECK(secp256k1_memcmp_var(zero, tmp, 16) == 0);
5985}
5986
5987
5988static void run_endomorphism_tests(void) {
5989 unsigned i;
5990 static secp256k1_scalar s;
5998
5999 for (i = 0; i < 100U * COUNT; ++i) {
6000 secp256k1_scalar full;
6002 test_scalar_split(&full);
6003 }
6004 for (i = 0; i < ARRAY_SIZE(scalars_near_split_bounds); ++i) {
6006 }
6007}
6008
6009static void ec_pubkey_parse_pointtest(const unsigned char *input, int xvalid, int yvalid) {
6010 unsigned char pubkeyc[65];
6011 secp256k1_pubkey pubkey;
6012 secp256k1_ge ge;
6013 size_t pubkeyclen;
6014
6015 for (pubkeyclen = 3; pubkeyclen <= 65; pubkeyclen++) {
6016 /* Smaller sizes are tested exhaustively elsewhere. */
6017 int32_t i;
6018 memcpy(&pubkeyc[1], input, 64);
6019 SECP256K1_CHECKMEM_UNDEFINE(&pubkeyc[pubkeyclen], 65 - pubkeyclen);
6020 for (i = 0; i < 256; i++) {
6021 /* Try all type bytes. */
6022 int xpass;
6023 int ypass;
6024 int ysign;
6025 pubkeyc[0] = i;
6026 /* What sign does this point have? */
6027 ysign = (input[63] & 1) + 2;
6028 /* For the current type (i) do we expect parsing to work? Handled all of compressed/uncompressed/hybrid. */
6029 xpass = xvalid && (pubkeyclen == 33) && ((i & 254) == 2);
6030 /* Do we expect a parse and re-serialize as uncompressed to give a matching y? */
6031 ypass = xvalid && yvalid && ((i & 4) == ((pubkeyclen == 65) << 2)) &&
6032 ((i == 4) || ((i & 251) == ysign)) && ((pubkeyclen == 33) || (pubkeyclen == 65));
6033 if (xpass || ypass) {
6034 /* These cases must parse. */
6035 unsigned char pubkeyo[65];
6036 size_t outl;
6037 memset(&pubkey, 0, sizeof(pubkey));
6038 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6039 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pubkeyc, pubkeyclen) == 1);
6040 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6041 outl = 65;
6042 SECP256K1_CHECKMEM_UNDEFINE(pubkeyo, 65);
6043 CHECK(secp256k1_ec_pubkey_serialize(CTX, pubkeyo, &outl, &pubkey, SECP256K1_EC_COMPRESSED) == 1);
6044 SECP256K1_CHECKMEM_CHECK(pubkeyo, outl);
6045 CHECK(outl == 33);
6046 CHECK(secp256k1_memcmp_var(&pubkeyo[1], &pubkeyc[1], 32) == 0);
6047 CHECK((pubkeyclen != 33) || (pubkeyo[0] == pubkeyc[0]));
6048 if (ypass) {
6049 /* This test isn't always done because we decode with alternative signs, so the y won't match. */
6050 CHECK(pubkeyo[0] == ysign);
6051 CHECK(secp256k1_pubkey_load(CTX, &ge, &pubkey) == 1);
6052 memset(&pubkey, 0, sizeof(pubkey));
6053 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6054 secp256k1_pubkey_save(&pubkey, &ge);
6055 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6056 outl = 65;
6057 SECP256K1_CHECKMEM_UNDEFINE(pubkeyo, 65);
6058 CHECK(secp256k1_ec_pubkey_serialize(CTX, pubkeyo, &outl, &pubkey, SECP256K1_EC_UNCOMPRESSED) == 1);
6059 SECP256K1_CHECKMEM_CHECK(pubkeyo, outl);
6060 CHECK(outl == 65);
6061 CHECK(pubkeyo[0] == 4);
6062 CHECK(secp256k1_memcmp_var(&pubkeyo[1], input, 64) == 0);
6063 }
6064 } else {
6065 /* These cases must fail to parse. */
6066 memset(&pubkey, 0xfe, sizeof(pubkey));
6067 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6068 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pubkeyc, pubkeyclen) == 0);
6069 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6070 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6071 }
6072 }
6073 }
6074}
6075
6076static void run_ec_pubkey_parse_test(void) {
6077#define SECP256K1_EC_PARSE_TEST_NVALID (12)
6078 const unsigned char valid[SECP256K1_EC_PARSE_TEST_NVALID][64] = {
6079 {
6080 /* Point with leading and trailing zeros in x and y serialization. */
6081 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x42, 0x52,
6082 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6083 0x00, 0x00, 0x64, 0xef, 0xa1, 0x7b, 0x77, 0x61, 0xe1, 0xe4, 0x27, 0x06, 0x98, 0x9f, 0xb4, 0x83,
6084 0xb8, 0xd2, 0xd4, 0x9b, 0xf7, 0x8f, 0xae, 0x98, 0x03, 0xf0, 0x99, 0xb8, 0x34, 0xed, 0xeb, 0x00
6085 },
6086 {
6087 /* Point with x equal to a 3rd root of unity.*/
6088 0x7a, 0xe9, 0x6a, 0x2b, 0x65, 0x7c, 0x07, 0x10, 0x6e, 0x64, 0x47, 0x9e, 0xac, 0x34, 0x34, 0xe9,
6089 0x9c, 0xf0, 0x49, 0x75, 0x12, 0xf5, 0x89, 0x95, 0xc1, 0x39, 0x6c, 0x28, 0x71, 0x95, 0x01, 0xee,
6090 0x42, 0x18, 0xf2, 0x0a, 0xe6, 0xc6, 0x46, 0xb3, 0x63, 0xdb, 0x68, 0x60, 0x58, 0x22, 0xfb, 0x14,
6091 0x26, 0x4c, 0xa8, 0xd2, 0x58, 0x7f, 0xdd, 0x6f, 0xbc, 0x75, 0x0d, 0x58, 0x7e, 0x76, 0xa7, 0xee,
6092 },
6093 {
6094 /* Point with largest x. (1/2) */
6095 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6096 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x2c,
6097 0x0e, 0x99, 0x4b, 0x14, 0xea, 0x72, 0xf8, 0xc3, 0xeb, 0x95, 0xc7, 0x1e, 0xf6, 0x92, 0x57, 0x5e,
6098 0x77, 0x50, 0x58, 0x33, 0x2d, 0x7e, 0x52, 0xd0, 0x99, 0x5c, 0xf8, 0x03, 0x88, 0x71, 0xb6, 0x7d,
6099 },
6100 {
6101 /* Point with largest x. (2/2) */
6102 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6103 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x2c,
6104 0xf1, 0x66, 0xb4, 0xeb, 0x15, 0x8d, 0x07, 0x3c, 0x14, 0x6a, 0x38, 0xe1, 0x09, 0x6d, 0xa8, 0xa1,
6105 0x88, 0xaf, 0xa7, 0xcc, 0xd2, 0x81, 0xad, 0x2f, 0x66, 0xa3, 0x07, 0xfb, 0x77, 0x8e, 0x45, 0xb2,
6106 },
6107 {
6108 /* Point with smallest x. (1/2) */
6109 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6110 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
6111 0x42, 0x18, 0xf2, 0x0a, 0xe6, 0xc6, 0x46, 0xb3, 0x63, 0xdb, 0x68, 0x60, 0x58, 0x22, 0xfb, 0x14,
6112 0x26, 0x4c, 0xa8, 0xd2, 0x58, 0x7f, 0xdd, 0x6f, 0xbc, 0x75, 0x0d, 0x58, 0x7e, 0x76, 0xa7, 0xee,
6113 },
6114 {
6115 /* Point with smallest x. (2/2) */
6116 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6117 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
6118 0xbd, 0xe7, 0x0d, 0xf5, 0x19, 0x39, 0xb9, 0x4c, 0x9c, 0x24, 0x97, 0x9f, 0xa7, 0xdd, 0x04, 0xeb,
6119 0xd9, 0xb3, 0x57, 0x2d, 0xa7, 0x80, 0x22, 0x90, 0x43, 0x8a, 0xf2, 0xa6, 0x81, 0x89, 0x54, 0x41,
6120 },
6121 {
6122 /* Point with largest y. (1/3) */
6123 0x1f, 0xe1, 0xe5, 0xef, 0x3f, 0xce, 0xb5, 0xc1, 0x35, 0xab, 0x77, 0x41, 0x33, 0x3c, 0xe5, 0xa6,
6124 0xe8, 0x0d, 0x68, 0x16, 0x76, 0x53, 0xf6, 0xb2, 0xb2, 0x4b, 0xcb, 0xcf, 0xaa, 0xaf, 0xf5, 0x07,
6125 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6126 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x2e,
6127 },
6128 {
6129 /* Point with largest y. (2/3) */
6130 0xcb, 0xb0, 0xde, 0xab, 0x12, 0x57, 0x54, 0xf1, 0xfd, 0xb2, 0x03, 0x8b, 0x04, 0x34, 0xed, 0x9c,
6131 0xb3, 0xfb, 0x53, 0xab, 0x73, 0x53, 0x91, 0x12, 0x99, 0x94, 0xa5, 0x35, 0xd9, 0x25, 0xf6, 0x73,
6132 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6133 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x2e,
6134 },
6135 {
6136 /* Point with largest y. (3/3) */
6137 0x14, 0x6d, 0x3b, 0x65, 0xad, 0xd9, 0xf5, 0x4c, 0xcc, 0xa2, 0x85, 0x33, 0xc8, 0x8e, 0x2c, 0xbc,
6138 0x63, 0xf7, 0x44, 0x3e, 0x16, 0x58, 0x78, 0x3a, 0xb4, 0x1f, 0x8e, 0xf9, 0x7c, 0x2a, 0x10, 0xb5,
6139 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6140 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x2e,
6141 },
6142 {
6143 /* Point with smallest y. (1/3) */
6144 0x1f, 0xe1, 0xe5, 0xef, 0x3f, 0xce, 0xb5, 0xc1, 0x35, 0xab, 0x77, 0x41, 0x33, 0x3c, 0xe5, 0xa6,
6145 0xe8, 0x0d, 0x68, 0x16, 0x76, 0x53, 0xf6, 0xb2, 0xb2, 0x4b, 0xcb, 0xcf, 0xaa, 0xaf, 0xf5, 0x07,
6146 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6147 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
6148 },
6149 {
6150 /* Point with smallest y. (2/3) */
6151 0xcb, 0xb0, 0xde, 0xab, 0x12, 0x57, 0x54, 0xf1, 0xfd, 0xb2, 0x03, 0x8b, 0x04, 0x34, 0xed, 0x9c,
6152 0xb3, 0xfb, 0x53, 0xab, 0x73, 0x53, 0x91, 0x12, 0x99, 0x94, 0xa5, 0x35, 0xd9, 0x25, 0xf6, 0x73,
6153 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6154 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
6155 },
6156 {
6157 /* Point with smallest y. (3/3) */
6158 0x14, 0x6d, 0x3b, 0x65, 0xad, 0xd9, 0xf5, 0x4c, 0xcc, 0xa2, 0x85, 0x33, 0xc8, 0x8e, 0x2c, 0xbc,
6159 0x63, 0xf7, 0x44, 0x3e, 0x16, 0x58, 0x78, 0x3a, 0xb4, 0x1f, 0x8e, 0xf9, 0x7c, 0x2a, 0x10, 0xb5,
6160 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6161 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01
6162 }
6163 };
6164#define SECP256K1_EC_PARSE_TEST_NXVALID (4)
6165 const unsigned char onlyxvalid[SECP256K1_EC_PARSE_TEST_NXVALID][64] = {
6166 {
6167 /* Valid if y overflow ignored (y = 1 mod p). (1/3) */
6168 0x1f, 0xe1, 0xe5, 0xef, 0x3f, 0xce, 0xb5, 0xc1, 0x35, 0xab, 0x77, 0x41, 0x33, 0x3c, 0xe5, 0xa6,
6169 0xe8, 0x0d, 0x68, 0x16, 0x76, 0x53, 0xf6, 0xb2, 0xb2, 0x4b, 0xcb, 0xcf, 0xaa, 0xaf, 0xf5, 0x07,
6170 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6171 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x30,
6172 },
6173 {
6174 /* Valid if y overflow ignored (y = 1 mod p). (2/3) */
6175 0xcb, 0xb0, 0xde, 0xab, 0x12, 0x57, 0x54, 0xf1, 0xfd, 0xb2, 0x03, 0x8b, 0x04, 0x34, 0xed, 0x9c,
6176 0xb3, 0xfb, 0x53, 0xab, 0x73, 0x53, 0x91, 0x12, 0x99, 0x94, 0xa5, 0x35, 0xd9, 0x25, 0xf6, 0x73,
6177 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6178 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x30,
6179 },
6180 {
6181 /* Valid if y overflow ignored (y = 1 mod p). (3/3)*/
6182 0x14, 0x6d, 0x3b, 0x65, 0xad, 0xd9, 0xf5, 0x4c, 0xcc, 0xa2, 0x85, 0x33, 0xc8, 0x8e, 0x2c, 0xbc,
6183 0x63, 0xf7, 0x44, 0x3e, 0x16, 0x58, 0x78, 0x3a, 0xb4, 0x1f, 0x8e, 0xf9, 0x7c, 0x2a, 0x10, 0xb5,
6184 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6185 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x30,
6186 },
6187 {
6188 /* x on curve, y is from y^2 = x^3 + 8. */
6189 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6190 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
6191 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6192 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x03
6193 }
6194 };
6195#define SECP256K1_EC_PARSE_TEST_NINVALID (7)
6196 const unsigned char invalid[SECP256K1_EC_PARSE_TEST_NINVALID][64] = {
6197 {
6198 /* x is third root of -8, y is -1 * (x^3+7); also on the curve for y^2 = x^3 + 9. */
6199 0x0a, 0x2d, 0x2b, 0xa9, 0x35, 0x07, 0xf1, 0xdf, 0x23, 0x37, 0x70, 0xc2, 0xa7, 0x97, 0x96, 0x2c,
6200 0xc6, 0x1f, 0x6d, 0x15, 0xda, 0x14, 0xec, 0xd4, 0x7d, 0x8d, 0x27, 0xae, 0x1c, 0xd5, 0xf8, 0x53,
6201 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6202 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
6203 },
6204 {
6205 /* Valid if x overflow ignored (x = 1 mod p). */
6206 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6207 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x30,
6208 0x42, 0x18, 0xf2, 0x0a, 0xe6, 0xc6, 0x46, 0xb3, 0x63, 0xdb, 0x68, 0x60, 0x58, 0x22, 0xfb, 0x14,
6209 0x26, 0x4c, 0xa8, 0xd2, 0x58, 0x7f, 0xdd, 0x6f, 0xbc, 0x75, 0x0d, 0x58, 0x7e, 0x76, 0xa7, 0xee,
6210 },
6211 {
6212 /* Valid if x overflow ignored (x = 1 mod p). */
6213 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6214 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x30,
6215 0xbd, 0xe7, 0x0d, 0xf5, 0x19, 0x39, 0xb9, 0x4c, 0x9c, 0x24, 0x97, 0x9f, 0xa7, 0xdd, 0x04, 0xeb,
6216 0xd9, 0xb3, 0x57, 0x2d, 0xa7, 0x80, 0x22, 0x90, 0x43, 0x8a, 0xf2, 0xa6, 0x81, 0x89, 0x54, 0x41,
6217 },
6218 {
6219 /* x is -1, y is the result of the sqrt ladder; also on the curve for y^2 = x^3 - 5. */
6220 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6221 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x2e,
6222 0xf4, 0x84, 0x14, 0x5c, 0xb0, 0x14, 0x9b, 0x82, 0x5d, 0xff, 0x41, 0x2f, 0xa0, 0x52, 0xa8, 0x3f,
6223 0xcb, 0x72, 0xdb, 0x61, 0xd5, 0x6f, 0x37, 0x70, 0xce, 0x06, 0x6b, 0x73, 0x49, 0xa2, 0xaa, 0x28,
6224 },
6225 {
6226 /* x is -1, y is the result of the sqrt ladder; also on the curve for y^2 = x^3 - 5. */
6227 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
6228 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xfc, 0x2e,
6229 0x0b, 0x7b, 0xeb, 0xa3, 0x4f, 0xeb, 0x64, 0x7d, 0xa2, 0x00, 0xbe, 0xd0, 0x5f, 0xad, 0x57, 0xc0,
6230 0x34, 0x8d, 0x24, 0x9e, 0x2a, 0x90, 0xc8, 0x8f, 0x31, 0xf9, 0x94, 0x8b, 0xb6, 0x5d, 0x52, 0x07,
6231 },
6232 {
6233 /* x is zero, y is the result of the sqrt ladder; also on the curve for y^2 = x^3 - 7. */
6234 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6235 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6236 0x8f, 0x53, 0x7e, 0xef, 0xdf, 0xc1, 0x60, 0x6a, 0x07, 0x27, 0xcd, 0x69, 0xb4, 0xa7, 0x33, 0x3d,
6237 0x38, 0xed, 0x44, 0xe3, 0x93, 0x2a, 0x71, 0x79, 0xee, 0xcb, 0x4b, 0x6f, 0xba, 0x93, 0x60, 0xdc,
6238 },
6239 {
6240 /* x is zero, y is the result of the sqrt ladder; also on the curve for y^2 = x^3 - 7. */
6241 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6242 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
6243 0x70, 0xac, 0x81, 0x10, 0x20, 0x3e, 0x9f, 0x95, 0xf8, 0xd8, 0x32, 0x96, 0x4b, 0x58, 0xcc, 0xc2,
6244 0xc7, 0x12, 0xbb, 0x1c, 0x6c, 0xd5, 0x8e, 0x86, 0x11, 0x34, 0xb4, 0x8f, 0x45, 0x6c, 0x9b, 0x53
6245 }
6246 };
6247 const unsigned char pubkeyc[66] = {
6248 /* Serialization of G. */
6249 0x04, 0x79, 0xBE, 0x66, 0x7E, 0xF9, 0xDC, 0xBB, 0xAC, 0x55, 0xA0, 0x62, 0x95, 0xCE, 0x87, 0x0B,
6250 0x07, 0x02, 0x9B, 0xFC, 0xDB, 0x2D, 0xCE, 0x28, 0xD9, 0x59, 0xF2, 0x81, 0x5B, 0x16, 0xF8, 0x17,
6251 0x98, 0x48, 0x3A, 0xDA, 0x77, 0x26, 0xA3, 0xC4, 0x65, 0x5D, 0xA4, 0xFB, 0xFC, 0x0E, 0x11, 0x08,
6252 0xA8, 0xFD, 0x17, 0xB4, 0x48, 0xA6, 0x85, 0x54, 0x19, 0x9C, 0x47, 0xD0, 0x8F, 0xFB, 0x10, 0xD4,
6253 0xB8, 0x00
6254 };
6255 unsigned char sout[65];
6256 unsigned char shortkey[2] = { 0 };
6257 secp256k1_ge ge;
6258 secp256k1_pubkey pubkey;
6259 size_t len;
6260 int32_t i;
6261
6262 /* Nothing should be reading this far into pubkeyc. */
6263 SECP256K1_CHECKMEM_UNDEFINE(&pubkeyc[65], 1);
6264 /* Zero length claimed, fail, zeroize, no illegal arg error. */
6265 memset(&pubkey, 0xfe, sizeof(pubkey));
6266 SECP256K1_CHECKMEM_UNDEFINE(shortkey, 2);
6267 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6268 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, shortkey, 0) == 0);
6269 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6270 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6271 /* Length one claimed, fail, zeroize, no illegal arg error. */
6272 for (i = 0; i < 256 ; i++) {
6273 memset(&pubkey, 0xfe, sizeof(pubkey));
6274 shortkey[0] = i;
6275 SECP256K1_CHECKMEM_UNDEFINE(&shortkey[1], 1);
6276 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6277 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, shortkey, 1) == 0);
6278 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6279 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6280 }
6281 /* Length two claimed, fail, zeroize, no illegal arg error. */
6282 for (i = 0; i < 65536 ; i++) {
6283 memset(&pubkey, 0xfe, sizeof(pubkey));
6284 shortkey[0] = i & 255;
6285 shortkey[1] = i >> 8;
6286 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6287 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, shortkey, 2) == 0);
6288 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6289 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6290 }
6291 memset(&pubkey, 0xfe, sizeof(pubkey));
6292 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6293 /* 33 bytes claimed on otherwise valid input starting with 0x04, fail, zeroize output, no illegal arg error. */
6294 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pubkeyc, 33) == 0);
6295 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6296 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6297 /* NULL pubkey, illegal arg error. Pubkey isn't rewritten before this step, since it's NULL into the parser. */
6298 CHECK_ILLEGAL(CTX, secp256k1_ec_pubkey_parse(CTX, NULL, pubkeyc, 65));
6299 /* NULL input string. Illegal arg and zeroize output. */
6300 memset(&pubkey, 0xfe, sizeof(pubkey));
6301 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6302 CHECK_ILLEGAL(CTX, secp256k1_ec_pubkey_parse(CTX, &pubkey, NULL, 65));
6303 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6304 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6305 /* 64 bytes claimed on input starting with 0x04, fail, zeroize output, no illegal arg error. */
6306 memset(&pubkey, 0xfe, sizeof(pubkey));
6307 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6308 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pubkeyc, 64) == 0);
6309 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6310 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6311 /* 66 bytes claimed, fail, zeroize output, no illegal arg error. */
6312 memset(&pubkey, 0xfe, sizeof(pubkey));
6313 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6314 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pubkeyc, 66) == 0);
6315 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6316 CHECK_ILLEGAL(CTX, secp256k1_pubkey_load(CTX, &ge, &pubkey));
6317 /* Valid parse. */
6318 memset(&pubkey, 0, sizeof(pubkey));
6319 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6320 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pubkeyc, 65) == 1);
6321 CHECK(secp256k1_ec_pubkey_parse(secp256k1_context_static, &pubkey, pubkeyc, 65) == 1);
6322 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6323 SECP256K1_CHECKMEM_UNDEFINE(&ge, sizeof(ge));
6324 CHECK(secp256k1_pubkey_load(CTX, &ge, &pubkey) == 1);
6325 SECP256K1_CHECKMEM_CHECK(&ge.x, sizeof(ge.x));
6326 SECP256K1_CHECKMEM_CHECK(&ge.y, sizeof(ge.y));
6329 /* secp256k1_ec_pubkey_serialize illegal args. */
6330 len = 65;
6332 CHECK(len == 0);
6334 len = 65;
6337 SECP256K1_CHECKMEM_CHECK(sout, 65);
6338 CHECK(len == 0);
6339 len = 65;
6340 CHECK_ILLEGAL(CTX, secp256k1_ec_pubkey_serialize(CTX, sout, &len, &pubkey, ~0));
6341 CHECK(len == 0);
6342 len = 65;
6345 SECP256K1_CHECKMEM_CHECK(sout, 65);
6346 CHECK(len == 65);
6347 /* Multiple illegal args. Should still set arg error only once. */
6349 /* Try a bunch of prefabbed points with all possible encodings. */
6350 for (i = 0; i < SECP256K1_EC_PARSE_TEST_NVALID; i++) {
6351 ec_pubkey_parse_pointtest(valid[i], 1, 1);
6352 }
6353 for (i = 0; i < SECP256K1_EC_PARSE_TEST_NXVALID; i++) {
6354 ec_pubkey_parse_pointtest(onlyxvalid[i], 1, 0);
6355 }
6356 for (i = 0; i < SECP256K1_EC_PARSE_TEST_NINVALID; i++) {
6357 ec_pubkey_parse_pointtest(invalid[i], 0, 0);
6358 }
6359}
6360
6361static void run_eckey_edge_case_test(void) {
6362 const unsigned char *orderc = secp256k1_group_order_bytes;
6363 const unsigned char zeros[sizeof(secp256k1_pubkey)] = {0x00};
6364 unsigned char ctmp[33];
6365 unsigned char ctmp2[33];
6366 secp256k1_pubkey pubkey;
6367 secp256k1_pubkey pubkey2;
6368 secp256k1_pubkey pubkey_one;
6369 secp256k1_pubkey pubkey_negone;
6370 const secp256k1_pubkey *pubkeys[3];
6371 size_t len;
6372 int i;
6373 /* Group order is too large, reject. */
6374 CHECK(secp256k1_ec_seckey_verify(CTX, orderc) == 0);
6375 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6376 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, orderc) == 0);
6377 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6378 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6379 /* Maximum value is too large, reject. */
6380 memset(ctmp, 255, 32);
6382 memset(&pubkey, 1, sizeof(pubkey));
6383 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6384 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, ctmp) == 0);
6385 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6386 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6387 /* Zero is too small, reject. */
6388 memset(ctmp, 0, 32);
6390 memset(&pubkey, 1, sizeof(pubkey));
6391 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6392 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, ctmp) == 0);
6393 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6394 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6395 /* One must be accepted. */
6396 ctmp[31] = 0x01;
6398 memset(&pubkey, 0, sizeof(pubkey));
6399 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6400 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, ctmp) == 1);
6401 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6402 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) > 0);
6403 pubkey_one = pubkey;
6404 /* Group order + 1 is too large, reject. */
6405 memcpy(ctmp, orderc, 32);
6406 ctmp[31] = 0x42;
6408 memset(&pubkey, 1, sizeof(pubkey));
6409 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6410 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, ctmp) == 0);
6411 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6412 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6413 /* -1 must be accepted. */
6414 ctmp[31] = 0x40;
6416 memset(&pubkey, 0, sizeof(pubkey));
6417 SECP256K1_CHECKMEM_UNDEFINE(&pubkey, sizeof(pubkey));
6418 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, ctmp) == 1);
6419 SECP256K1_CHECKMEM_CHECK(&pubkey, sizeof(pubkey));
6420 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) > 0);
6421 pubkey_negone = pubkey;
6422 /* Tweak of zero leaves the value unchanged. */
6423 memset(ctmp2, 0, 32);
6424 CHECK(secp256k1_ec_seckey_tweak_add(CTX, ctmp, ctmp2) == 1);
6425 CHECK(secp256k1_memcmp_var(orderc, ctmp, 31) == 0 && ctmp[31] == 0x40);
6426 memcpy(&pubkey2, &pubkey, sizeof(pubkey));
6427 CHECK(secp256k1_ec_pubkey_tweak_add(CTX, &pubkey, ctmp2) == 1);
6428 CHECK(secp256k1_memcmp_var(&pubkey, &pubkey2, sizeof(pubkey)) == 0);
6429 /* Multiply tweak of zero zeroizes the output. */
6430 CHECK(secp256k1_ec_seckey_tweak_mul(CTX, ctmp, ctmp2) == 0);
6431 CHECK(secp256k1_memcmp_var(zeros, ctmp, 32) == 0);
6432 CHECK(secp256k1_ec_pubkey_tweak_mul(CTX, &pubkey, ctmp2) == 0);
6433 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(pubkey)) == 0);
6434 memcpy(&pubkey, &pubkey2, sizeof(pubkey));
6435 /* If seckey_tweak_add or seckey_tweak_mul are called with an overflowing
6436 seckey, the seckey is zeroized. */
6437 memcpy(ctmp, orderc, 32);
6438 memset(ctmp2, 0, 32);
6439 ctmp2[31] = 0x01;
6440 CHECK(secp256k1_ec_seckey_verify(CTX, ctmp2) == 1);
6442 CHECK(secp256k1_ec_seckey_tweak_add(CTX, ctmp, ctmp2) == 0);
6443 CHECK(secp256k1_memcmp_var(zeros, ctmp, 32) == 0);
6444 memcpy(ctmp, orderc, 32);
6445 CHECK(secp256k1_ec_seckey_tweak_mul(CTX, ctmp, ctmp2) == 0);
6446 CHECK(secp256k1_memcmp_var(zeros, ctmp, 32) == 0);
6447 /* If seckey_tweak_add or seckey_tweak_mul are called with an overflowing
6448 tweak, the seckey is zeroized. */
6449 memcpy(ctmp, orderc, 32);
6450 ctmp[31] = 0x40;
6451 CHECK(secp256k1_ec_seckey_tweak_add(CTX, ctmp, orderc) == 0);
6452 CHECK(secp256k1_memcmp_var(zeros, ctmp, 32) == 0);
6453 memcpy(ctmp, orderc, 32);
6454 ctmp[31] = 0x40;
6455 CHECK(secp256k1_ec_seckey_tweak_mul(CTX, ctmp, orderc) == 0);
6456 CHECK(secp256k1_memcmp_var(zeros, ctmp, 32) == 0);
6457 memcpy(ctmp, orderc, 32);
6458 ctmp[31] = 0x40;
6459 /* If pubkey_tweak_add or pubkey_tweak_mul are called with an overflowing
6460 tweak, the pubkey is zeroized. */
6461 CHECK(secp256k1_ec_pubkey_tweak_add(CTX, &pubkey, orderc) == 0);
6462 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(pubkey)) == 0);
6463 memcpy(&pubkey, &pubkey2, sizeof(pubkey));
6464 CHECK(secp256k1_ec_pubkey_tweak_mul(CTX, &pubkey, orderc) == 0);
6465 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(pubkey)) == 0);
6466 memcpy(&pubkey, &pubkey2, sizeof(pubkey));
6467 /* If the resulting key in secp256k1_ec_seckey_tweak_add and
6468 * secp256k1_ec_pubkey_tweak_add is 0 the functions fail and in the latter
6469 * case the pubkey is zeroized. */
6470 memcpy(ctmp, orderc, 32);
6471 ctmp[31] = 0x40;
6472 memset(ctmp2, 0, 32);
6473 ctmp2[31] = 1;
6474 CHECK(secp256k1_ec_seckey_tweak_add(CTX, ctmp2, ctmp) == 0);
6475 CHECK(secp256k1_memcmp_var(zeros, ctmp2, 32) == 0);
6476 ctmp2[31] = 1;
6477 CHECK(secp256k1_ec_pubkey_tweak_add(CTX, &pubkey, ctmp2) == 0);
6478 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(pubkey)) == 0);
6479 memcpy(&pubkey, &pubkey2, sizeof(pubkey));
6480 /* Tweak computation wraps and results in a key of 1. */
6481 ctmp2[31] = 2;
6482 CHECK(secp256k1_ec_seckey_tweak_add(CTX, ctmp2, ctmp) == 1);
6483 CHECK(secp256k1_memcmp_var(ctmp2, zeros, 31) == 0 && ctmp2[31] == 1);
6484 ctmp2[31] = 2;
6485 CHECK(secp256k1_ec_pubkey_tweak_add(CTX, &pubkey, ctmp2) == 1);
6486 ctmp2[31] = 1;
6487 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey2, ctmp2) == 1);
6488 CHECK(secp256k1_memcmp_var(&pubkey, &pubkey2, sizeof(pubkey)) == 0);
6489 /* Tweak mul * 2 = 1+1. */
6490 CHECK(secp256k1_ec_pubkey_tweak_add(CTX, &pubkey, ctmp2) == 1);
6491 ctmp2[31] = 2;
6492 CHECK(secp256k1_ec_pubkey_tweak_mul(CTX, &pubkey2, ctmp2) == 1);
6493 CHECK(secp256k1_memcmp_var(&pubkey, &pubkey2, sizeof(pubkey)) == 0);
6494 /* Zeroize pubkey on parse error. */
6495 memset(&pubkey, 0, 32);
6497 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(pubkey)) == 0);
6498 memcpy(&pubkey, &pubkey2, sizeof(pubkey));
6499 memset(&pubkey2, 0, 32);
6501 CHECK(secp256k1_memcmp_var(&pubkey2, zeros, sizeof(pubkey2)) == 0);
6502 /* Plain argument errors. */
6505 memset(ctmp2, 0, 32);
6506 ctmp2[31] = 4;
6509 memset(ctmp2, 0, 32);
6510 ctmp2[31] = 4;
6513 memset(ctmp2, 0, 32);
6516 memset(ctmp2, 0, 32);
6517 ctmp2[31] = 1;
6521 memset(&pubkey, 1, sizeof(pubkey));
6523 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6524 /* secp256k1_ec_pubkey_combine tests. */
6525 pubkeys[0] = &pubkey_one;
6526 SECP256K1_CHECKMEM_UNDEFINE(&pubkeys[0], sizeof(secp256k1_pubkey *));
6527 SECP256K1_CHECKMEM_UNDEFINE(&pubkeys[1], sizeof(secp256k1_pubkey *));
6528 SECP256K1_CHECKMEM_UNDEFINE(&pubkeys[2], sizeof(secp256k1_pubkey *));
6529 memset(&pubkey, 255, sizeof(secp256k1_pubkey));
6531 CHECK_ILLEGAL(CTX, secp256k1_ec_pubkey_combine(CTX, &pubkey, pubkeys, 0));
6533 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6534 CHECK_ILLEGAL(CTX, secp256k1_ec_pubkey_combine(CTX, NULL, pubkeys, 1));
6535 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6536 memset(&pubkey, 255, sizeof(secp256k1_pubkey));
6538 CHECK_ILLEGAL(CTX, secp256k1_ec_pubkey_combine(CTX, &pubkey, NULL, 1));
6540 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6541 pubkeys[0] = &pubkey_negone;
6542 memset(&pubkey, 255, sizeof(secp256k1_pubkey));
6544 CHECK(secp256k1_ec_pubkey_combine(CTX, &pubkey, pubkeys, 1) == 1);
6546 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) > 0);
6547 len = 33;
6549 CHECK(secp256k1_ec_pubkey_serialize(CTX, ctmp2, &len, &pubkey_negone, SECP256K1_EC_COMPRESSED) == 1);
6550 CHECK(secp256k1_memcmp_var(ctmp, ctmp2, 33) == 0);
6551 /* Result is infinity. */
6552 pubkeys[0] = &pubkey_one;
6553 pubkeys[1] = &pubkey_negone;
6554 memset(&pubkey, 255, sizeof(secp256k1_pubkey));
6556 CHECK(secp256k1_ec_pubkey_combine(CTX, &pubkey, pubkeys, 2) == 0);
6558 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) == 0);
6559 /* Passes through infinity but comes out one. */
6560 pubkeys[2] = &pubkey_one;
6561 memset(&pubkey, 255, sizeof(secp256k1_pubkey));
6563 CHECK(secp256k1_ec_pubkey_combine(CTX, &pubkey, pubkeys, 3) == 1);
6565 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) > 0);
6566 /* check that NULL in array of pubkey pointers is not allowed */
6567 for (i = 0; i < 3; i++) {
6568 const secp256k1_pubkey *original_ptr = pubkeys[i];
6569 secp256k1_pubkey result;
6570 pubkeys[i] = NULL;
6571 CHECK_ILLEGAL(CTX, secp256k1_ec_pubkey_combine(CTX, &result, pubkeys, 3));
6572 pubkeys[i] = original_ptr;
6573 }
6574 len = 33;
6576 CHECK(secp256k1_ec_pubkey_serialize(CTX, ctmp2, &len, &pubkey_one, SECP256K1_EC_COMPRESSED) == 1);
6577 CHECK(secp256k1_memcmp_var(ctmp, ctmp2, 33) == 0);
6578 /* Adds to two. */
6579 pubkeys[1] = &pubkey_one;
6580 memset(&pubkey, 255, sizeof(secp256k1_pubkey));
6582 CHECK(secp256k1_ec_pubkey_combine(CTX, &pubkey, pubkeys, 2) == 1);
6584 CHECK(secp256k1_memcmp_var(&pubkey, zeros, sizeof(secp256k1_pubkey)) > 0);
6585}
6586
6587static void run_eckey_negate_test(void) {
6588 unsigned char seckey[32];
6589 unsigned char seckey_tmp[32];
6590
6592 memcpy(seckey_tmp, seckey, 32);
6593
6594 /* Verify negation changes the key and changes it back */
6595 CHECK(secp256k1_ec_seckey_negate(CTX, seckey) == 1);
6596 CHECK(secp256k1_memcmp_var(seckey, seckey_tmp, 32) != 0);
6597 CHECK(secp256k1_ec_seckey_negate(CTX, seckey) == 1);
6598 CHECK(secp256k1_memcmp_var(seckey, seckey_tmp, 32) == 0);
6599
6600 /* Negating all 0s fails */
6601 memset(seckey, 0, 32);
6602 memset(seckey_tmp, 0, 32);
6603 CHECK(secp256k1_ec_seckey_negate(CTX, seckey) == 0);
6604 /* Check that seckey is not modified */
6605 CHECK(secp256k1_memcmp_var(seckey, seckey_tmp, 32) == 0);
6606
6607 /* Negating an overflowing seckey fails and the seckey is zeroed. In this
6608 * test, the seckey has 16 random bytes to ensure that ec_seckey_negate
6609 * doesn't just set seckey to a constant value in case of failure. */
6611 memset(seckey, 0xFF, 16);
6612 memset(seckey_tmp, 0, 32);
6613 CHECK(secp256k1_ec_seckey_negate(CTX, seckey) == 0);
6614 CHECK(secp256k1_memcmp_var(seckey, seckey_tmp, 32) == 0);
6615}
6616
6617static void random_sign(secp256k1_scalar *sigr, secp256k1_scalar *sigs, const secp256k1_scalar *key, const secp256k1_scalar *msg, int *recid) {
6619 do {
6621 } while(!secp256k1_ecdsa_sig_sign(&CTX->ecmult_gen_ctx, sigr, sigs, key, msg, &nonce, recid));
6622}
6623
6624static void test_ecdsa_sign_verify(void) {
6625 secp256k1_ge pub;
6626 secp256k1_scalar one;
6627 secp256k1_scalar msg, key;
6628 secp256k1_scalar sigr, sigs;
6629 int getrec;
6630 int recid;
6634 getrec = testrand_bits(1);
6635 /* The specific way in which this conditional is written sidesteps a potential bug in clang.
6636 See the commit messages of the commit that introduced this comment for details. */
6637 if (getrec) {
6638 random_sign(&sigr, &sigs, &key, &msg, &recid);
6639 CHECK(recid >= 0 && recid < 4);
6640 } else {
6641 random_sign(&sigr, &sigs, &key, &msg, NULL);
6642 }
6643 CHECK(secp256k1_ecdsa_sig_verify(&sigr, &sigs, &pub, &msg));
6644 secp256k1_scalar_set_int(&one, 1);
6645 secp256k1_scalar_add(&msg, &msg, &one);
6646 CHECK(!secp256k1_ecdsa_sig_verify(&sigr, &sigs, &pub, &msg));
6647}
6648
6649static void run_ecdsa_sign_verify(void) {
6650 int i;
6651 for (i = 0; i < 10*COUNT; i++) {
6653 }
6654}
6655
6657static int precomputed_nonce_function(unsigned char *nonce32, const unsigned char *msg32, const unsigned char *key32, const unsigned char *algo16, void *data, unsigned int counter) {
6658 (void)msg32;
6659 (void)key32;
6660 (void)algo16;
6661 memcpy(nonce32, data, 32);
6662 return (counter == 0);
6663}
6664
6665static int nonce_function_test_fail(unsigned char *nonce32, const unsigned char *msg32, const unsigned char *key32, const unsigned char *algo16, void *data, unsigned int counter) {
6666 /* Dummy nonce generator that has a fatal error on the first counter value. */
6667 if (counter == 0) {
6668 return 0;
6669 }
6670 return nonce_function_rfc6979(nonce32, msg32, key32, algo16, data, counter - 1);
6671}
6672
6673static int nonce_function_test_retry(unsigned char *nonce32, const unsigned char *msg32, const unsigned char *key32, const unsigned char *algo16, void *data, unsigned int counter) {
6674 /* Dummy nonce generator that produces unacceptable nonces for the first several counter values. */
6675 if (counter < 3) {
6676 memset(nonce32, counter==0 ? 0 : 255, 32);
6677 if (counter == 2) {
6678 nonce32[31]--;
6679 }
6680 return 1;
6681 }
6682 if (counter < 5) {
6683 memcpy(nonce32, secp256k1_group_order_bytes, 32);
6684 if (counter == 4) {
6685 nonce32[31]++;
6686 }
6687 return 1;
6688 }
6689 /* Retry rate of 6979 is negligible esp. as we only call this in deterministic tests. */
6690 /* If someone does fine a case where it retries for secp256k1, we'd like to know. */
6691 if (counter > 5) {
6692 return 0;
6693 }
6694 return nonce_function_rfc6979(nonce32, msg32, key32, algo16, data, counter - 5);
6695}
6696
6698 static const unsigned char res[sizeof(secp256k1_ecdsa_signature)] = {0};
6699 return secp256k1_memcmp_var(sig, res, sizeof(secp256k1_ecdsa_signature)) == 0;
6700}
6701
6702static void test_ecdsa_end_to_end(void) {
6703 unsigned char extra[32] = {0x00};
6704 unsigned char privkey[32];
6705 unsigned char message[32];
6706 unsigned char privkey2[32];
6707 secp256k1_ecdsa_signature signature[6];
6709 unsigned char sig[74];
6710 size_t siglen = 74;
6711 unsigned char pubkeyc[65];
6712 size_t pubkeyclen = 65;
6713 secp256k1_pubkey pubkey;
6714 secp256k1_pubkey pubkey_tmp;
6715 unsigned char seckey[300];
6716 size_t seckeylen = 300;
6717
6718 /* Generate a random key and message. */
6719 {
6720 secp256k1_scalar msg, key;
6723 secp256k1_scalar_get_b32(privkey, &key);
6724 secp256k1_scalar_get_b32(message, &msg);
6725 }
6726
6727 /* Construct and verify corresponding public key. */
6728 CHECK(secp256k1_ec_seckey_verify(CTX, privkey) == 1);
6729 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, privkey) == 1);
6730
6731 /* Verify exporting and importing public key. */
6733 memset(&pubkey, 0, sizeof(pubkey));
6734 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pubkeyc, pubkeyclen) == 1);
6735
6736 /* Verify negation changes the key and changes it back */
6737 memcpy(&pubkey_tmp, &pubkey, sizeof(pubkey));
6738 CHECK(secp256k1_ec_pubkey_negate(CTX, &pubkey_tmp) == 1);
6739 CHECK(secp256k1_memcmp_var(&pubkey_tmp, &pubkey, sizeof(pubkey)) != 0);
6740 CHECK(secp256k1_ec_pubkey_negate(CTX, &pubkey_tmp) == 1);
6741 CHECK(secp256k1_memcmp_var(&pubkey_tmp, &pubkey, sizeof(pubkey)) == 0);
6742
6743 /* Verify private key import and export. */
6744 CHECK(ec_privkey_export_der(CTX, seckey, &seckeylen, privkey, testrand_bits(1) == 1));
6745 CHECK(ec_privkey_import_der(CTX, privkey2, seckey, seckeylen) == 1);
6746 CHECK(secp256k1_memcmp_var(privkey, privkey2, 32) == 0);
6747
6748 /* Optionally tweak the keys using addition. */
6749 if (testrand_int(3) == 0) {
6750 int ret1;
6751 int ret2;
6752 unsigned char rnd[32];
6753 secp256k1_pubkey pubkey2;
6754 testrand256_test(rnd);
6755 ret1 = secp256k1_ec_seckey_tweak_add(CTX, privkey, rnd);
6756 ret2 = secp256k1_ec_pubkey_tweak_add(CTX, &pubkey, rnd);
6757 CHECK(ret1 == ret2);
6758 if (ret1 == 0) {
6759 return;
6760 }
6761 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey2, privkey) == 1);
6762 CHECK(secp256k1_memcmp_var(&pubkey, &pubkey2, sizeof(pubkey)) == 0);
6763 }
6764
6765 /* Optionally tweak the keys using multiplication. */
6766 if (testrand_int(3) == 0) {
6767 int ret1;
6768 int ret2;
6769 unsigned char rnd[32];
6770 secp256k1_pubkey pubkey2;
6771 testrand256_test(rnd);
6772 ret1 = secp256k1_ec_seckey_tweak_mul(CTX, privkey, rnd);
6773 ret2 = secp256k1_ec_pubkey_tweak_mul(CTX, &pubkey, rnd);
6774 CHECK(ret1 == ret2);
6775 if (ret1 == 0) {
6776 return;
6777 }
6778 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey2, privkey) == 1);
6779 CHECK(secp256k1_memcmp_var(&pubkey, &pubkey2, sizeof(pubkey)) == 0);
6780 }
6781
6782 /* Sign. */
6783 CHECK(secp256k1_ecdsa_sign(CTX, &signature[0], message, privkey, NULL, NULL) == 1);
6784 CHECK(secp256k1_ecdsa_sign(CTX, &signature[4], message, privkey, NULL, NULL) == 1);
6785 CHECK(secp256k1_ecdsa_sign(CTX, &signature[1], message, privkey, NULL, extra) == 1);
6786 extra[31] = 1;
6787 CHECK(secp256k1_ecdsa_sign(CTX, &signature[2], message, privkey, NULL, extra) == 1);
6788 extra[31] = 0;
6789 extra[0] = 1;
6790 CHECK(secp256k1_ecdsa_sign(CTX, &signature[3], message, privkey, NULL, extra) == 1);
6791 CHECK(secp256k1_memcmp_var(&signature[0], &signature[4], sizeof(signature[0])) == 0);
6792 CHECK(secp256k1_memcmp_var(&signature[0], &signature[1], sizeof(signature[0])) != 0);
6793 CHECK(secp256k1_memcmp_var(&signature[0], &signature[2], sizeof(signature[0])) != 0);
6794 CHECK(secp256k1_memcmp_var(&signature[0], &signature[3], sizeof(signature[0])) != 0);
6795 CHECK(secp256k1_memcmp_var(&signature[1], &signature[2], sizeof(signature[0])) != 0);
6796 CHECK(secp256k1_memcmp_var(&signature[1], &signature[3], sizeof(signature[0])) != 0);
6797 CHECK(secp256k1_memcmp_var(&signature[2], &signature[3], sizeof(signature[0])) != 0);
6798 /* Verify. */
6799 CHECK(secp256k1_ecdsa_verify(CTX, &signature[0], message, &pubkey) == 1);
6800 CHECK(secp256k1_ecdsa_verify(CTX, &signature[1], message, &pubkey) == 1);
6801 CHECK(secp256k1_ecdsa_verify(CTX, &signature[2], message, &pubkey) == 1);
6802 CHECK(secp256k1_ecdsa_verify(CTX, &signature[3], message, &pubkey) == 1);
6803 /* Test lower-S form, malleate, verify and fail, test again, malleate again */
6804 CHECK(!secp256k1_ecdsa_signature_normalize(CTX, NULL, &signature[0]));
6805 secp256k1_ecdsa_signature_load(CTX, &r, &s, &signature[0]);
6807 secp256k1_ecdsa_signature_save(&signature[5], &r, &s);
6808 CHECK(secp256k1_ecdsa_verify(CTX, &signature[5], message, &pubkey) == 0);
6809 CHECK(secp256k1_ecdsa_signature_normalize(CTX, NULL, &signature[5]));
6810 CHECK(secp256k1_ecdsa_signature_normalize(CTX, &signature[5], &signature[5]));
6811 CHECK(!secp256k1_ecdsa_signature_normalize(CTX, NULL, &signature[5]));
6812 CHECK(!secp256k1_ecdsa_signature_normalize(CTX, &signature[5], &signature[5]));
6813 CHECK(secp256k1_ecdsa_verify(CTX, &signature[5], message, &pubkey) == 1);
6815 secp256k1_ecdsa_signature_save(&signature[5], &r, &s);
6816 CHECK(!secp256k1_ecdsa_signature_normalize(CTX, NULL, &signature[5]));
6817 CHECK(secp256k1_ecdsa_verify(CTX, &signature[5], message, &pubkey) == 1);
6818 CHECK(secp256k1_memcmp_var(&signature[5], &signature[0], 64) == 0);
6819
6820 /* Serialize/parse DER and verify again */
6821 CHECK(secp256k1_ecdsa_signature_serialize_der(CTX, sig, &siglen, &signature[0]) == 1);
6822 memset(&signature[0], 0, sizeof(signature[0]));
6823 CHECK(secp256k1_ecdsa_signature_parse_der(CTX, &signature[0], sig, siglen) == 1);
6824 CHECK(secp256k1_ecdsa_verify(CTX, &signature[0], message, &pubkey) == 1);
6825 /* Serialize/destroy/parse DER and verify again. */
6826 siglen = 74;
6827 CHECK(secp256k1_ecdsa_signature_serialize_der(CTX, sig, &siglen, &signature[0]) == 1);
6828 sig[testrand_int(siglen)] += 1 + testrand_int(255);
6829 CHECK(secp256k1_ecdsa_signature_parse_der(CTX, &signature[0], sig, siglen) == 0 ||
6830 secp256k1_ecdsa_verify(CTX, &signature[0], message, &pubkey) == 0);
6831}
6832
6833static void test_random_pubkeys(void) {
6834 secp256k1_ge elem;
6835 secp256k1_ge elem2;
6836 unsigned char in[65];
6837 /* Generate some randomly sized pubkeys. */
6838 size_t len = testrand_bits(2) == 0 ? 65 : 33;
6839 if (testrand_bits(2) == 0) {
6840 len = testrand_bits(6);
6841 }
6842 if (len == 65) {
6843 in[0] = testrand_bits(1) ? 4 : (testrand_bits(1) ? 6 : 7);
6844 } else {
6845 in[0] = testrand_bits(1) ? 2 : 3;
6846 }
6847 if (testrand_bits(3) == 0) {
6848 in[0] = testrand_bits(8);
6849 }
6850 if (len > 1) {
6851 testrand256(&in[1]);
6852 }
6853 if (len > 33) {
6854 testrand256(&in[33]);
6855 }
6856 if (secp256k1_eckey_pubkey_parse(&elem, in, len)) {
6857 unsigned char out[65];
6858 unsigned char firstb;
6859 int res;
6860 size_t size = len;
6861 firstb = in[0];
6862 /* If the pubkey can be parsed, it should round-trip... */
6863 if (len == 33) {
6865 } else {
6867 }
6868 CHECK(secp256k1_memcmp_var(&in[1], &out[1], len-1) == 0);
6869 /* ... except for the type of hybrid inputs. */
6870 if ((in[0] != 6) && (in[0] != 7)) {
6871 CHECK(in[0] == out[0]);
6872 }
6873 size = 65;
6875 CHECK(secp256k1_eckey_pubkey_parse(&elem2, in, size));
6876 CHECK(secp256k1_ge_eq_var(&elem2, &elem));
6877 /* Check that the X9.62 hybrid type is checked. */
6878 in[0] = testrand_bits(1) ? 6 : 7;
6879 res = secp256k1_eckey_pubkey_parse(&elem2, in, size);
6880 if (firstb == 2 || firstb == 3) {
6881 if (in[0] == firstb + 4) {
6882 CHECK(res);
6883 } else {
6884 CHECK(!res);
6885 }
6886 }
6887 if (res) {
6888 CHECK(secp256k1_ge_eq_var(&elem, &elem2));
6890 CHECK(secp256k1_memcmp_var(&in[1], &out[1], 64) == 0);
6891 }
6892 }
6893}
6894
6895static void run_pubkey_comparison(void) {
6896 unsigned char pk1_ser[33] = {
6897 0x02,
6898 0x58, 0x84, 0xb3, 0xa2, 0x4b, 0x97, 0x37, 0x88, 0x92, 0x38, 0xa6, 0x26, 0x62, 0x52, 0x35, 0x11,
6899 0xd0, 0x9a, 0xa1, 0x1b, 0x80, 0x0b, 0x5e, 0x93, 0x80, 0x26, 0x11, 0xef, 0x67, 0x4b, 0xd9, 0x23
6900 };
6901 const unsigned char pk2_ser[33] = {
6902 0x02,
6903 0xde, 0x36, 0x0e, 0x87, 0x59, 0x8f, 0x3c, 0x01, 0x36, 0x2a, 0x2a, 0xb8, 0xc6, 0xf4, 0x5e, 0x4d,
6904 0xb2, 0xc2, 0xd5, 0x03, 0xa7, 0xf9, 0xf1, 0x4f, 0xa8, 0xfa, 0x95, 0xa8, 0xe9, 0x69, 0x76, 0x1c
6905 };
6906 secp256k1_pubkey pk1;
6907 secp256k1_pubkey pk2;
6908
6909 CHECK(secp256k1_ec_pubkey_parse(CTX, &pk1, pk1_ser, sizeof(pk1_ser)) == 1);
6910 CHECK(secp256k1_ec_pubkey_parse(CTX, &pk2, pk2_ser, sizeof(pk2_ser)) == 1);
6911
6914 CHECK(secp256k1_ec_pubkey_cmp(CTX, &pk1, &pk2) < 0);
6915 CHECK(secp256k1_ec_pubkey_cmp(CTX, &pk2, &pk1) > 0);
6916 CHECK(secp256k1_ec_pubkey_cmp(CTX, &pk1, &pk1) == 0);
6917 CHECK(secp256k1_ec_pubkey_cmp(CTX, &pk2, &pk2) == 0);
6918 {
6919 secp256k1_pubkey pk_tmp;
6920 memset(&pk_tmp, 0, sizeof(pk_tmp)); /* illegal pubkey */
6922 {
6923 int32_t ecount = 0;
6925 CHECK(secp256k1_ec_pubkey_cmp(CTX, &pk_tmp, &pk_tmp) == 0);
6926 CHECK(ecount == 2);
6928 }
6930 }
6931
6932 /* Make pk2 the same as pk1 but with 3 rather than 2. Note that in
6933 * an uncompressed encoding, these would have the opposite ordering */
6934 pk1_ser[0] = 3;
6935 CHECK(secp256k1_ec_pubkey_parse(CTX, &pk2, pk1_ser, sizeof(pk1_ser)) == 1);
6936 CHECK(secp256k1_ec_pubkey_cmp(CTX, &pk1, &pk2) < 0);
6937 CHECK(secp256k1_ec_pubkey_cmp(CTX, &pk2, &pk1) > 0);
6938}
6939
6940static void test_sort_helper(secp256k1_pubkey *pk, size_t *pk_order, size_t n_pk) {
6941 size_t i;
6942 const secp256k1_pubkey *pk_test[5];
6943
6944 for (i = 0; i < n_pk; i++) {
6945 pk_test[i] = &pk[pk_order[i]];
6946 }
6947 CHECK(secp256k1_ec_pubkey_sort(CTX, pk_test, n_pk) == 1);
6948 for (i = 0; i < n_pk; i++) {
6949 CHECK(secp256k1_memcmp_var(pk_test[i], &pk[i], sizeof(*pk_test[i])) == 0);
6950 }
6951}
6952
6953static void permute(size_t *arr, size_t n) {
6954 size_t i;
6955 for (i = n - 1; i >= 1; i--) {
6956 size_t tmp, j;
6957 j = testrand_int(i + 1);
6958 tmp = arr[i];
6959 arr[i] = arr[j];
6960 arr[j] = tmp;
6961 }
6962}
6963
6964static void test_sort_api(void) {
6965 secp256k1_pubkey pks[2];
6966 const secp256k1_pubkey *pks_ptr[2];
6967 int i;
6968
6969 pks_ptr[0] = &pks[0];
6970 pks_ptr[1] = &pks[1];
6971
6974
6975 CHECK(secp256k1_ec_pubkey_sort(CTX, pks_ptr, 2) == 1);
6976 /* check that NULL in array of public key pointers is not allowed */
6977 for (i = 0; i < 2; i++) {
6978 const secp256k1_pubkey *original_ptr = pks_ptr[i];
6979 pks_ptr[i] = NULL;
6981 pks_ptr[i] = original_ptr;
6982 }
6984 CHECK(secp256k1_ec_pubkey_sort(CTX, pks_ptr, 0) == 1);
6985 /* Test illegal public keys */
6986 memset(&pks[0], 0, sizeof(pks[0]));
6988 memset(&pks[1], 0, sizeof(pks[1]));
6989 {
6990 int32_t ecount = 0;
6992 CHECK(secp256k1_ec_pubkey_sort(CTX, pks_ptr, 2) == 1);
6993 CHECK(ecount == 2);
6995 }
6996}
6997
6998static void test_sort(void) {
7000 unsigned char pk_ser[5][33] = {
7001 { 0x02, 0x08 },
7002 { 0x02, 0x0b },
7003 { 0x02, 0x0c },
7004 { 0x03, 0x05 },
7005 { 0x03, 0x0a },
7006 };
7007 int i;
7008 size_t pk_order[5] = { 0, 1, 2, 3, 4 };
7009
7010 for (i = 0; i < 5; i++) {
7011 CHECK(secp256k1_ec_pubkey_parse(CTX, &pk[i], pk_ser[i], sizeof(pk_ser[i])));
7012 }
7013
7014 permute(pk_order, 1);
7015 test_sort_helper(pk, pk_order, 1);
7016 permute(pk_order, 2);
7017 test_sort_helper(pk, pk_order, 2);
7018 permute(pk_order, 3);
7019 test_sort_helper(pk, pk_order, 3);
7020 for (i = 0; i < COUNT; i++) {
7021 permute(pk_order, 4);
7022 test_sort_helper(pk, pk_order, 4);
7023 }
7024 for (i = 0; i < COUNT; i++) {
7025 permute(pk_order, 5);
7026 test_sort_helper(pk, pk_order, 5);
7027 }
7028 /* Check that sorting also works for random pubkeys */
7029 for (i = 0; i < COUNT; i++) {
7030 int j;
7031 const secp256k1_pubkey *pk_ptr[5];
7032 for (j = 0; j < 5; j++) {
7034 pk_ptr[j] = &pk[j];
7035 }
7036 CHECK(secp256k1_ec_pubkey_sort(CTX, pk_ptr, 5) == 1);
7037 for (j = 1; j < 5; j++) {
7038 CHECK(secp256k1_ec_pubkey_sort_cmp(&pk_ptr[j - 1], &pk_ptr[j], CTX) <= 0);
7039 }
7040 }
7041}
7042
7043/* Test vectors from BIP-MuSig2 */
7044static void test_sort_vectors(void) {
7045 enum { N_PUBKEYS = 6 };
7046 unsigned char pk_ser[N_PUBKEYS][33] = {
7047 { 0x02, 0xDD, 0x30, 0x8A, 0xFE, 0xC5, 0x77, 0x7E, 0x13, 0x12, 0x1F,
7048 0xA7, 0x2B, 0x9C, 0xC1, 0xB7, 0xCC, 0x01, 0x39, 0x71, 0x53, 0x09,
7049 0xB0, 0x86, 0xC9, 0x60, 0xE1, 0x8F, 0xD9, 0x69, 0x77, 0x4E, 0xB8 },
7050 { 0x02, 0xF9, 0x30, 0x8A, 0x01, 0x92, 0x58, 0xC3, 0x10, 0x49, 0x34,
7051 0x4F, 0x85, 0xF8, 0x9D, 0x52, 0x29, 0xB5, 0x31, 0xC8, 0x45, 0x83,
7052 0x6F, 0x99, 0xB0, 0x86, 0x01, 0xF1, 0x13, 0xBC, 0xE0, 0x36, 0xF9 },
7053 { 0x03, 0xDF, 0xF1, 0xD7, 0x7F, 0x2A, 0x67, 0x1C, 0x5F, 0x36, 0x18,
7054 0x37, 0x26, 0xDB, 0x23, 0x41, 0xBE, 0x58, 0xFE, 0xAE, 0x1D, 0xA2,
7055 0xDE, 0xCE, 0xD8, 0x43, 0x24, 0x0F, 0x7B, 0x50, 0x2B, 0xA6, 0x59 },
7056 { 0x02, 0x35, 0x90, 0xA9, 0x4E, 0x76, 0x8F, 0x8E, 0x18, 0x15, 0xC2,
7057 0xF2, 0x4B, 0x4D, 0x80, 0xA8, 0xE3, 0x14, 0x93, 0x16, 0xC3, 0x51,
7058 0x8C, 0xE7, 0xB7, 0xAD, 0x33, 0x83, 0x68, 0xD0, 0x38, 0xCA, 0x66 },
7059 { 0x02, 0xDD, 0x30, 0x8A, 0xFE, 0xC5, 0x77, 0x7E, 0x13, 0x12, 0x1F,
7060 0xA7, 0x2B, 0x9C, 0xC1, 0xB7, 0xCC, 0x01, 0x39, 0x71, 0x53, 0x09,
7061 0xB0, 0x86, 0xC9, 0x60, 0xE1, 0x8F, 0xD9, 0x69, 0x77, 0x4E, 0xFF },
7062 { 0x02, 0xDD, 0x30, 0x8A, 0xFE, 0xC5, 0x77, 0x7E, 0x13, 0x12, 0x1F,
7063 0xA7, 0x2B, 0x9C, 0xC1, 0xB7, 0xCC, 0x01, 0x39, 0x71, 0x53, 0x09,
7064 0xB0, 0x86, 0xC9, 0x60, 0xE1, 0x8F, 0xD9, 0x69, 0x77, 0x4E, 0xB8 }
7065 };
7066 secp256k1_pubkey pubkeys[N_PUBKEYS];
7067 secp256k1_pubkey *sorted[N_PUBKEYS];
7068 const secp256k1_pubkey *pks_ptr[N_PUBKEYS];
7069 int i;
7070
7071 sorted[0] = &pubkeys[3];
7072 sorted[1] = &pubkeys[0];
7073 sorted[2] = &pubkeys[0];
7074 sorted[3] = &pubkeys[4];
7075 sorted[4] = &pubkeys[1];
7076 sorted[5] = &pubkeys[2];
7077
7078 for (i = 0; i < N_PUBKEYS; i++) {
7079 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkeys[i], pk_ser[i], sizeof(pk_ser[i])));
7080 pks_ptr[i] = &pubkeys[i];
7081 }
7083 for (i = 0; i < N_PUBKEYS; i++) {
7084 CHECK(secp256k1_memcmp_var(pks_ptr[i], sorted[i], sizeof(secp256k1_pubkey)) == 0);
7085 }
7086}
7087
7088static void run_pubkey_sort(void) {
7089 test_sort_api();
7090 test_sort();
7092}
7093
7094
7095static void run_random_pubkeys(void) {
7096 int i;
7097 for (i = 0; i < 10*COUNT; i++) {
7099 }
7100}
7101
7102static void run_ecdsa_end_to_end(void) {
7103 int i;
7104 for (i = 0; i < 64*COUNT; i++) {
7106 }
7107}
7108
7109static int test_ecdsa_der_parse(const unsigned char *sig, size_t siglen, int certainly_der, int certainly_not_der) {
7110 static const unsigned char zeroes[32] = {0};
7111
7112 int ret = 0;
7113
7115 unsigned char roundtrip_der[2048];
7116 unsigned char compact_der[64];
7117 size_t len_der = 2048;
7118 int parsed_der = 0, valid_der = 0, roundtrips_der = 0;
7119
7120 secp256k1_ecdsa_signature sig_der_lax;
7121 unsigned char roundtrip_der_lax[2048];
7122 unsigned char compact_der_lax[64];
7123 size_t len_der_lax = 2048;
7124 int parsed_der_lax = 0, valid_der_lax = 0, roundtrips_der_lax = 0;
7125
7126 parsed_der = secp256k1_ecdsa_signature_parse_der(CTX, &sig_der, sig, siglen);
7127 if (parsed_der) {
7128 ret |= (!secp256k1_ecdsa_signature_serialize_compact(CTX, compact_der, &sig_der)) << 0;
7129 valid_der = (secp256k1_memcmp_var(compact_der, zeroes, 32) != 0) && (secp256k1_memcmp_var(compact_der + 32, zeroes, 32) != 0);
7130 }
7131 if (valid_der) {
7132 ret |= (!secp256k1_ecdsa_signature_serialize_der(CTX, roundtrip_der, &len_der, &sig_der)) << 1;
7133 roundtrips_der = (len_der == siglen) && secp256k1_memcmp_var(roundtrip_der, sig, siglen) == 0;
7134 }
7135
7136 parsed_der_lax = ecdsa_signature_parse_der_lax(CTX, &sig_der_lax, sig, siglen);
7137 if (parsed_der_lax) {
7138 ret |= (!secp256k1_ecdsa_signature_serialize_compact(CTX, compact_der_lax, &sig_der_lax)) << 10;
7139 valid_der_lax = (secp256k1_memcmp_var(compact_der_lax, zeroes, 32) != 0) && (secp256k1_memcmp_var(compact_der_lax + 32, zeroes, 32) != 0);
7140 }
7141 if (valid_der_lax) {
7142 ret |= (!secp256k1_ecdsa_signature_serialize_der(CTX, roundtrip_der_lax, &len_der_lax, &sig_der_lax)) << 11;
7143 roundtrips_der_lax = (len_der_lax == siglen) && secp256k1_memcmp_var(roundtrip_der_lax, sig, siglen) == 0;
7144 }
7145
7146 if (certainly_der) {
7147 ret |= (!parsed_der) << 2;
7148 }
7149 if (certainly_not_der) {
7150 ret |= (parsed_der) << 17;
7151 }
7152 if (valid_der) {
7153 ret |= (!roundtrips_der) << 3;
7154 }
7155
7156 if (valid_der) {
7157 ret |= (!roundtrips_der_lax) << 12;
7158 ret |= (len_der != len_der_lax) << 13;
7159 ret |= ((len_der != len_der_lax) || (secp256k1_memcmp_var(roundtrip_der_lax, roundtrip_der, len_der) != 0)) << 14;
7160 }
7161 ret |= (roundtrips_der != roundtrips_der_lax) << 15;
7162 if (parsed_der) {
7163 ret |= (!parsed_der_lax) << 16;
7164 }
7165
7166 return ret;
7167}
7168
7169static void assign_big_endian(unsigned char *ptr, size_t ptrlen, uint32_t val) {
7170 size_t i;
7171 for (i = 0; i < ptrlen; i++) {
7172 int shift = ptrlen - 1 - i;
7173 if (shift >= 4) {
7174 ptr[i] = 0;
7175 } else {
7176 ptr[i] = (val >> shift) & 0xFF;
7177 }
7178 }
7179}
7180
7181static void damage_array(unsigned char *sig, size_t *len) {
7182 int pos;
7183 int action = testrand_bits(3);
7184 if (action < 1 && *len > 3) {
7185 /* Delete a byte. */
7186 pos = testrand_int(*len);
7187 memmove(sig + pos, sig + pos + 1, *len - pos - 1);
7188 (*len)--;
7189 return;
7190 } else if (action < 2 && *len < 2048) {
7191 /* Insert a byte. */
7192 pos = testrand_int(1 + *len);
7193 memmove(sig + pos + 1, sig + pos, *len - pos);
7194 sig[pos] = testrand_bits(8);
7195 (*len)++;
7196 return;
7197 } else if (action < 4) {
7198 /* Modify a byte. */
7199 sig[testrand_int(*len)] += 1 + testrand_int(255);
7200 return;
7201 } else { /* action < 8 */
7202 /* Modify a bit. */
7203 sig[testrand_int(*len)] ^= 1 << testrand_bits(3);
7204 return;
7205 }
7206}
7207
7208static void random_ber_signature(unsigned char *sig, size_t *len, int* certainly_der, int* certainly_not_der) {
7209 int der;
7210 int nlow[2], nlen[2], nlenlen[2], nhbit[2], nhbyte[2], nzlen[2];
7211 size_t tlen, elen, glen;
7212 int indet;
7213 int n;
7214
7215 *len = 0;
7216 der = testrand_bits(2) == 0;
7217 *certainly_der = der;
7218 *certainly_not_der = 0;
7219 indet = der ? 0 : testrand_int(10) == 0;
7220
7221 for (n = 0; n < 2; n++) {
7222 /* We generate two classes of numbers: nlow==1 "low" ones (up to 32 bytes), nlow==0 "high" ones (32 bytes with 129 top bits set, or larger than 32 bytes) */
7223 nlow[n] = der ? 1 : (testrand_bits(3) != 0);
7224 /* The length of the number in bytes (the first byte of which will always be nonzero) */
7225 nlen[n] = nlow[n] ? testrand_int(33) : 32 + testrand_int(200) * testrand_bits(3) / 8;
7226 CHECK(nlen[n] <= 232);
7227 /* The top bit of the number. */
7228 nhbit[n] = (nlow[n] == 0 && nlen[n] == 32) ? 1 : (nlen[n] == 0 ? 0 : testrand_bits(1));
7229 /* The top byte of the number (after the potential hardcoded 16 0xFF characters for "high" 32 bytes numbers) */
7230 nhbyte[n] = nlen[n] == 0 ? 0 : (nhbit[n] ? 128 + testrand_bits(7) : 1 + testrand_int(127));
7231 /* The number of zero bytes in front of the number (which is 0 or 1 in case of DER, otherwise we extend up to 300 bytes) */
7232 nzlen[n] = der ? ((nlen[n] == 0 || nhbit[n]) ? 1 : 0) : (nlow[n] ? testrand_int(3) : testrand_int(300 - nlen[n]) * testrand_bits(3) / 8);
7233 if (nzlen[n] > ((nlen[n] == 0 || nhbit[n]) ? 1 : 0)) {
7234 *certainly_not_der = 1;
7235 }
7236 CHECK(nlen[n] + nzlen[n] <= 300);
7237 /* The length of the length descriptor for the number. 0 means short encoding, anything else is long encoding. */
7238 nlenlen[n] = nlen[n] + nzlen[n] < 128 ? 0 : (nlen[n] + nzlen[n] < 256 ? 1 : 2);
7239 if (!der) {
7240 /* nlenlen[n] max 127 bytes */
7241 int add = testrand_int(127 - nlenlen[n]) * testrand_bits(4) * testrand_bits(4) / 256;
7242 nlenlen[n] += add;
7243 if (add != 0) {
7244 *certainly_not_der = 1;
7245 }
7246 }
7247 CHECK(nlen[n] + nzlen[n] + nlenlen[n] <= 427);
7248 }
7249
7250 /* The total length of the data to go, so far */
7251 tlen = 2 + nlenlen[0] + nlen[0] + nzlen[0] + 2 + nlenlen[1] + nlen[1] + nzlen[1];
7252 CHECK(tlen <= 856);
7253
7254 /* The length of the garbage inside the tuple. */
7255 elen = (der || indet) ? 0 : testrand_int(980 - tlen) * testrand_bits(3) / 8;
7256 if (elen != 0) {
7257 *certainly_not_der = 1;
7258 }
7259 tlen += elen;
7260 CHECK(tlen <= 980);
7261
7262 /* The length of the garbage after the end of the tuple. */
7263 glen = der ? 0 : testrand_int(990 - tlen) * testrand_bits(3) / 8;
7264 if (glen != 0) {
7265 *certainly_not_der = 1;
7266 }
7267 CHECK(tlen + glen <= 990);
7268
7269 /* Write the tuple header. */
7270 sig[(*len)++] = 0x30;
7271 if (indet) {
7272 /* Indeterminate length */
7273 sig[(*len)++] = 0x80;
7274 *certainly_not_der = 1;
7275 } else {
7276 int tlenlen = tlen < 128 ? 0 : (tlen < 256 ? 1 : 2);
7277 if (!der) {
7278 int add = testrand_int(127 - tlenlen) * testrand_bits(4) * testrand_bits(4) / 256;
7279 tlenlen += add;
7280 if (add != 0) {
7281 *certainly_not_der = 1;
7282 }
7283 }
7284 if (tlenlen == 0) {
7285 /* Short length notation */
7286 sig[(*len)++] = tlen;
7287 } else {
7288 /* Long length notation */
7289 sig[(*len)++] = 128 + tlenlen;
7290 assign_big_endian(sig + *len, tlenlen, tlen);
7291 *len += tlenlen;
7292 }
7293 tlen += tlenlen;
7294 }
7295 tlen += 2;
7296 CHECK(tlen + glen <= 1119);
7297
7298 for (n = 0; n < 2; n++) {
7299 /* Write the integer header. */
7300 sig[(*len)++] = 0x02;
7301 if (nlenlen[n] == 0) {
7302 /* Short length notation */
7303 sig[(*len)++] = nlen[n] + nzlen[n];
7304 } else {
7305 /* Long length notation. */
7306 sig[(*len)++] = 128 + nlenlen[n];
7307 assign_big_endian(sig + *len, nlenlen[n], nlen[n] + nzlen[n]);
7308 *len += nlenlen[n];
7309 }
7310 /* Write zero padding */
7311 while (nzlen[n] > 0) {
7312 sig[(*len)++] = 0x00;
7313 nzlen[n]--;
7314 }
7315 if (nlen[n] == 32 && !nlow[n]) {
7316 /* Special extra 16 0xFF bytes in "high" 32-byte numbers */
7317 int i;
7318 for (i = 0; i < 16; i++) {
7319 sig[(*len)++] = 0xFF;
7320 }
7321 nlen[n] -= 16;
7322 }
7323 /* Write first byte of number */
7324 if (nlen[n] > 0) {
7325 sig[(*len)++] = nhbyte[n];
7326 nlen[n]--;
7327 }
7328 /* Generate remaining random bytes of number */
7329 testrand_bytes_test(sig + *len, nlen[n]);
7330 *len += nlen[n];
7331 nlen[n] = 0;
7332 }
7333
7334 /* Generate random garbage inside tuple. */
7335 testrand_bytes_test(sig + *len, elen);
7336 *len += elen;
7337
7338 /* Generate end-of-contents bytes. */
7339 if (indet) {
7340 sig[(*len)++] = 0;
7341 sig[(*len)++] = 0;
7342 tlen += 2;
7343 }
7344 CHECK(tlen + glen <= 1121);
7345
7346 /* Generate random garbage outside tuple. */
7347 testrand_bytes_test(sig + *len, glen);
7348 *len += glen;
7349 tlen += glen;
7350 CHECK(tlen <= 1121);
7351 CHECK(tlen == *len);
7352}
7353
7354static void run_ecdsa_der_parse(void) {
7355 int i,j;
7356 for (i = 0; i < 200 * COUNT; i++) {
7357 unsigned char buffer[2048];
7358 size_t buflen = 0;
7359 int certainly_der = 0;
7360 int certainly_not_der = 0;
7361 random_ber_signature(buffer, &buflen, &certainly_der, &certainly_not_der);
7362 CHECK(buflen <= 2048);
7363 for (j = 0; j < 16; j++) {
7364 int ret = 0;
7365 if (j > 0) {
7366 damage_array(buffer, &buflen);
7367 /* We don't know anything anymore about the DERness of the result */
7368 certainly_der = 0;
7369 certainly_not_der = 0;
7370 }
7371 ret = test_ecdsa_der_parse(buffer, buflen, certainly_der, certainly_not_der);
7372 if (ret != 0) {
7373 size_t k;
7374 fprintf(stderr, "Failure %x on ", ret);
7375 for (k = 0; k < buflen; k++) {
7376 fprintf(stderr, "%02x ", buffer[k]);
7377 }
7378 fprintf(stderr, "\n");
7379 }
7380 CHECK(ret == 0);
7381 }
7382 }
7383}
7384
7385/* Tests several edge cases. */
7386static void run_ecdsa_edge_cases(void) {
7387 int t;
7389
7390 /* Test the case where ECDSA recomputes a point that is infinity. */
7391 {
7392 secp256k1_ge key;
7394 secp256k1_scalar sr, ss;
7396 secp256k1_scalar_negate(&ss, &ss);
7397 secp256k1_scalar_inverse(&ss, &ss);
7400 msg = ss;
7401 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 0);
7402 }
7403
7404 /* Verify signature with r of zero fails. */
7405 {
7406 const unsigned char pubkey_mods_zero[33] = {
7407 0x02, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
7408 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
7409 0xfe, 0xba, 0xae, 0xdc, 0xe6, 0xaf, 0x48, 0xa0,
7410 0x3b, 0xbf, 0xd2, 0x5e, 0x8c, 0xd0, 0x36, 0x41,
7411 0x41
7412 };
7413 secp256k1_ge key;
7415 secp256k1_scalar sr, ss;
7419 CHECK(secp256k1_eckey_pubkey_parse(&key, pubkey_mods_zero, 33));
7420 CHECK(secp256k1_ecdsa_sig_verify( &sr, &ss, &key, &msg) == 0);
7421 }
7422
7423 /* Verify signature with s of zero fails. */
7424 {
7425 const unsigned char pubkey[33] = {
7426 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7427 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7428 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7429 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7430 0x01
7431 };
7432 secp256k1_ge key;
7434 secp256k1_scalar sr, ss;
7438 CHECK(secp256k1_eckey_pubkey_parse(&key, pubkey, 33));
7439 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 0);
7440 }
7441
7442 /* Verify signature with message 0 passes. */
7443 {
7444 const unsigned char pubkey[33] = {
7445 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7446 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7447 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7448 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7449 0x02
7450 };
7451 const unsigned char pubkey2[33] = {
7452 0x02, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
7453 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
7454 0xfe, 0xba, 0xae, 0xdc, 0xe6, 0xaf, 0x48, 0xa0,
7455 0x3b, 0xbf, 0xd2, 0x5e, 0x8c, 0xd0, 0x36, 0x41,
7456 0x43
7457 };
7458 secp256k1_ge key;
7459 secp256k1_ge key2;
7461 secp256k1_scalar sr, ss;
7465 CHECK(secp256k1_eckey_pubkey_parse(&key, pubkey, 33));
7466 CHECK(secp256k1_eckey_pubkey_parse(&key2, pubkey2, 33));
7467 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 1);
7468 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key2, &msg) == 1);
7469 secp256k1_scalar_negate(&ss, &ss);
7470 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 1);
7471 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key2, &msg) == 1);
7473 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 0);
7474 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key2, &msg) == 0);
7475 }
7476
7477 /* Verify signature with message 1 passes. */
7478 {
7479 const unsigned char pubkey[33] = {
7480 0x02, 0x14, 0x4e, 0x5a, 0x58, 0xef, 0x5b, 0x22,
7481 0x6f, 0xd2, 0xe2, 0x07, 0x6a, 0x77, 0xcf, 0x05,
7482 0xb4, 0x1d, 0xe7, 0x4a, 0x30, 0x98, 0x27, 0x8c,
7483 0x93, 0xe6, 0xe6, 0x3c, 0x0b, 0xc4, 0x73, 0x76,
7484 0x25
7485 };
7486 const unsigned char pubkey2[33] = {
7487 0x02, 0x8a, 0xd5, 0x37, 0xed, 0x73, 0xd9, 0x40,
7488 0x1d, 0xa0, 0x33, 0xd2, 0xdc, 0xf0, 0xaf, 0xae,
7489 0x34, 0xcf, 0x5f, 0x96, 0x4c, 0x73, 0x28, 0x0f,
7490 0x92, 0xc0, 0xf6, 0x9d, 0xd9, 0xb2, 0x09, 0x10,
7491 0x62
7492 };
7493 const unsigned char csr[32] = {
7494 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7495 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
7496 0x45, 0x51, 0x23, 0x19, 0x50, 0xb7, 0x5f, 0xc4,
7497 0x40, 0x2d, 0xa1, 0x72, 0x2f, 0xc9, 0xba, 0xeb
7498 };
7499 secp256k1_ge key;
7500 secp256k1_ge key2;
7502 secp256k1_scalar sr, ss;
7505 secp256k1_scalar_set_b32(&sr, csr, NULL);
7506 CHECK(secp256k1_eckey_pubkey_parse(&key, pubkey, 33));
7507 CHECK(secp256k1_eckey_pubkey_parse(&key2, pubkey2, 33));
7508 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 1);
7509 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key2, &msg) == 1);
7510 secp256k1_scalar_negate(&ss, &ss);
7511 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 1);
7512 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key2, &msg) == 1);
7515 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 0);
7516 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key2, &msg) == 0);
7517 }
7518
7519 /* Verify signature with message -1 passes. */
7520 {
7521 const unsigned char pubkey[33] = {
7522 0x03, 0xaf, 0x97, 0xff, 0x7d, 0x3a, 0xf6, 0xa0,
7523 0x02, 0x94, 0xbd, 0x9f, 0x4b, 0x2e, 0xd7, 0x52,
7524 0x28, 0xdb, 0x49, 0x2a, 0x65, 0xcb, 0x1e, 0x27,
7525 0x57, 0x9c, 0xba, 0x74, 0x20, 0xd5, 0x1d, 0x20,
7526 0xf1
7527 };
7528 const unsigned char csr[32] = {
7529 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7530 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
7531 0x45, 0x51, 0x23, 0x19, 0x50, 0xb7, 0x5f, 0xc4,
7532 0x40, 0x2d, 0xa1, 0x72, 0x2f, 0xc9, 0xba, 0xee
7533 };
7534 secp256k1_ge key;
7536 secp256k1_scalar sr, ss;
7540 secp256k1_scalar_set_b32(&sr, csr, NULL);
7541 CHECK(secp256k1_eckey_pubkey_parse(&key, pubkey, 33));
7542 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 1);
7543 secp256k1_scalar_negate(&ss, &ss);
7544 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 1);
7547 CHECK(secp256k1_ecdsa_sig_verify(&sr, &ss, &key, &msg) == 0);
7548 }
7549
7550 /* Signature where s would be zero. */
7551 {
7552 secp256k1_pubkey pubkey;
7553 size_t siglen;
7554 unsigned char signature[72];
7555 static const unsigned char nonce[32] = {
7556 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7557 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7558 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7559 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
7560 };
7561 static const unsigned char nonce2[32] = {
7562 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,
7563 0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFF,0xFE,
7564 0xBA,0xAE,0xDC,0xE6,0xAF,0x48,0xA0,0x3B,
7565 0xBF,0xD2,0x5E,0x8C,0xD0,0x36,0x41,0x40
7566 };
7567 const unsigned char key[32] = {
7568 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7569 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7570 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
7571 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01,
7572 };
7573 unsigned char msg[32] = {
7574 0x86, 0x41, 0x99, 0x81, 0x06, 0x23, 0x44, 0x53,
7575 0xaa, 0x5f, 0x9d, 0x6a, 0x31, 0x78, 0xf4, 0xf7,
7576 0xb8, 0x12, 0xe0, 0x0b, 0x81, 0x7a, 0x77, 0x62,
7577 0x65, 0xdf, 0xdd, 0x31, 0xb9, 0x3e, 0x29, 0xa9,
7578 };
7580 CHECK(secp256k1_ecdsa_sign(CTX, &sig, msg, key, precomputed_nonce_function, nonce2) == 0);
7581 msg[31] = 0xaa;
7586 CHECK(secp256k1_ecdsa_sign(CTX, &sig, msg, key, precomputed_nonce_function, nonce2) == 1);
7587 CHECK(secp256k1_ec_pubkey_create(CTX, &pubkey, key) == 1);
7588 CHECK_ILLEGAL(CTX, secp256k1_ecdsa_verify(CTX, NULL, msg, &pubkey));
7589 CHECK_ILLEGAL(CTX, secp256k1_ecdsa_verify(CTX, &sig, NULL, &pubkey));
7591 CHECK(secp256k1_ecdsa_verify(CTX, &sig, msg, &pubkey) == 1);
7593 /* That pubkeyload fails via an ARGCHECK is a little odd but makes sense because pubkeys are an opaque data type. */
7594 CHECK_ILLEGAL(CTX, secp256k1_ecdsa_verify(CTX, &sig, msg, &pubkey));
7595 siglen = 72;
7598 CHECK_ILLEGAL(CTX, secp256k1_ecdsa_signature_serialize_der(CTX, signature, &siglen, NULL));
7599 CHECK(secp256k1_ecdsa_signature_serialize_der(CTX, signature, &siglen, &sig) == 1);
7600 CHECK_ILLEGAL(CTX, secp256k1_ecdsa_signature_parse_der(CTX, NULL, signature, siglen));
7602 CHECK(secp256k1_ecdsa_signature_parse_der(CTX, &sig, signature, siglen) == 1);
7603 siglen = 10;
7604 /* Too little room for a signature does not fail via ARGCHECK. */
7605 CHECK(secp256k1_ecdsa_signature_serialize_der(CTX, signature, &siglen, &sig) == 0);
7612 CHECK(secp256k1_ecdsa_signature_parse_compact(CTX, &sig, signature) == 1);
7613 memset(signature, 255, 64);
7614 CHECK(secp256k1_ecdsa_signature_parse_compact(CTX, &sig, signature) == 0);
7615 }
7616
7617 /* Nonce function corner cases. */
7618 for (t = 0; t < 2; t++) {
7619 static const unsigned char zero[32] = {0x00};
7620 int i;
7621 unsigned char key[32];
7622 unsigned char msg[32];
7624 secp256k1_scalar sr[512], ss;
7625 const unsigned char *extra;
7626 extra = t == 0 ? NULL : zero;
7627 memset(msg, 0, 32);
7628 msg[31] = 1;
7629 /* High key results in signature failure. */
7630 memset(key, 0xFF, 32);
7631 CHECK(secp256k1_ecdsa_sign(CTX, &sig, msg, key, NULL, extra) == 0);
7633 /* Zero key results in signature failure. */
7634 memset(key, 0, 32);
7635 CHECK(secp256k1_ecdsa_sign(CTX, &sig, msg, key, NULL, extra) == 0);
7637 /* Nonce function failure results in signature failure. */
7638 key[31] = 1;
7639 CHECK(secp256k1_ecdsa_sign(CTX, &sig, msg, key, nonce_function_test_fail, extra) == 0);
7641 /* The retry loop successfully makes its way to the first good value. */
7642 CHECK(secp256k1_ecdsa_sign(CTX, &sig, msg, key, nonce_function_test_retry, extra) == 1);
7643 CHECK(!is_empty_signature(&sig));
7644 CHECK(secp256k1_ecdsa_sign(CTX, &sig2, msg, key, nonce_function_rfc6979, extra) == 1);
7645 CHECK(!is_empty_signature(&sig2));
7646 CHECK(secp256k1_memcmp_var(&sig, &sig2, sizeof(sig)) == 0);
7647 /* The default nonce function is deterministic. */
7648 CHECK(secp256k1_ecdsa_sign(CTX, &sig2, msg, key, NULL, extra) == 1);
7649 CHECK(!is_empty_signature(&sig2));
7650 CHECK(secp256k1_memcmp_var(&sig, &sig2, sizeof(sig)) == 0);
7651 /* The default nonce function changes output with different messages. */
7652 for(i = 0; i < 256; i++) {
7653 int j;
7654 msg[0] = i;
7655 CHECK(secp256k1_ecdsa_sign(CTX, &sig2, msg, key, NULL, extra) == 1);
7656 CHECK(!is_empty_signature(&sig2));
7657 secp256k1_ecdsa_signature_load(CTX, &sr[i], &ss, &sig2);
7658 for (j = 0; j < i; j++) {
7659 CHECK(!secp256k1_scalar_eq(&sr[i], &sr[j]));
7660 }
7661 }
7662 msg[0] = 0;
7663 msg[31] = 2;
7664 /* The default nonce function changes output with different keys. */
7665 for(i = 256; i < 512; i++) {
7666 int j;
7667 key[0] = i - 256;
7668 CHECK(secp256k1_ecdsa_sign(CTX, &sig2, msg, key, NULL, extra) == 1);
7669 CHECK(!is_empty_signature(&sig2));
7670 secp256k1_ecdsa_signature_load(CTX, &sr[i], &ss, &sig2);
7671 for (j = 0; j < i; j++) {
7672 CHECK(!secp256k1_scalar_eq(&sr[i], &sr[j]));
7673 }
7674 }
7675 key[0] = 0;
7676 }
7677
7678 {
7679 /* Check that optional nonce arguments do not have equivalent effect. */
7680 const unsigned char zeros[32] = {0};
7681 unsigned char nonce[32];
7682 unsigned char nonce2[32];
7683 unsigned char nonce3[32];
7684 unsigned char nonce4[32];
7686 SECP256K1_CHECKMEM_UNDEFINE(nonce2,32);
7687 SECP256K1_CHECKMEM_UNDEFINE(nonce3,32);
7688 SECP256K1_CHECKMEM_UNDEFINE(nonce4,32);
7689 CHECK(nonce_function_rfc6979(nonce, zeros, zeros, NULL, NULL, 0) == 1);
7691 CHECK(nonce_function_rfc6979(nonce2, zeros, zeros, zeros, NULL, 0) == 1);
7692 SECP256K1_CHECKMEM_CHECK(nonce2,32);
7693 CHECK(nonce_function_rfc6979(nonce3, zeros, zeros, NULL, (void *)zeros, 0) == 1);
7694 SECP256K1_CHECKMEM_CHECK(nonce3,32);
7695 CHECK(nonce_function_rfc6979(nonce4, zeros, zeros, zeros, (void *)zeros, 0) == 1);
7696 SECP256K1_CHECKMEM_CHECK(nonce4,32);
7697 CHECK(secp256k1_memcmp_var(nonce, nonce2, 32) != 0);
7698 CHECK(secp256k1_memcmp_var(nonce, nonce3, 32) != 0);
7699 CHECK(secp256k1_memcmp_var(nonce, nonce4, 32) != 0);
7700 CHECK(secp256k1_memcmp_var(nonce2, nonce3, 32) != 0);
7701 CHECK(secp256k1_memcmp_var(nonce2, nonce4, 32) != 0);
7702 CHECK(secp256k1_memcmp_var(nonce3, nonce4, 32) != 0);
7703 }
7704
7705
7706 /* Privkey export where pubkey is the point at infinity. */
7707 {
7708 unsigned char privkey[300];
7709 const unsigned char *seckey = secp256k1_group_order_bytes;
7710 size_t outlen = 300;
7711 CHECK(!ec_privkey_export_der(CTX, privkey, &outlen, seckey, 0));
7712 outlen = 300;
7713 CHECK(!ec_privkey_export_der(CTX, privkey, &outlen, seckey, 1));
7714 }
7715}
7716
7718static void ecdsa_ctx_sha256(void) {
7719 /* Check ctx-provided SHA256 compression override takes effect */
7721 secp256k1_ecdsa_signature out_default, out_custom;
7722 unsigned char sk[32] = {1}, msg32[32] = {1};
7723
7724 /* Default behavior. No ctx-provided SHA256 compression */
7725 CHECK(secp256k1_ecdsa_sign(ctx, &out_default, msg32, sk, NULL, NULL));
7726 CHECK(!sha256_ecdsa_called);
7727
7728 /* Override SHA256 compression directly, bypassing the ctx setter sanity checks */
7729 ctx->hash_ctx.fn_sha256_compression = sha256_ecdsa;
7730 CHECK(secp256k1_ecdsa_sign(ctx, &out_custom, msg32, sk, NULL, NULL));
7731 CHECK(sha256_ecdsa_called);
7732 /* Outputs must differ if custom compression was used */
7733 CHECK(secp256k1_memcmp_var(out_default.data, out_custom.data, 64) != 0);
7734
7736}
7737
7742static void test_ecdsa_wycheproof(void) {
7744
7745 int t;
7748 secp256k1_ecdsa_signature signature;
7749 secp256k1_sha256 hasher;
7750 secp256k1_pubkey pubkey;
7751 const unsigned char *msg, *sig, *pk;
7752 unsigned char out[32] = {0};
7753 int actual_verify = 0;
7754
7755 memset(&pubkey, 0, sizeof(pubkey));
7757 CHECK(secp256k1_ec_pubkey_parse(CTX, &pubkey, pk, 65) == 1);
7758
7761 secp256k1_sha256_write(hash_ctx, &hasher, msg, testvectors[t].msg_len);
7762 secp256k1_sha256_finalize(hash_ctx, &hasher, out);
7763
7764 sig = &wycheproof_ecdsa_signatures[testvectors[t].sig_offset];
7765 if (secp256k1_ecdsa_signature_parse_der(CTX, &signature, sig, testvectors[t].sig_len) == 1) {
7766 actual_verify = secp256k1_ecdsa_verify(CTX, (const secp256k1_ecdsa_signature *)&signature, out, &pubkey);
7767 }
7768 CHECK(testvectors[t].expected_verify == actual_verify);
7769 }
7770}
7771
7772/* Tests cases from Wycheproof test suite. */
7773static void run_ecdsa_wycheproof(void) {
7775}
7776
7777#ifdef ENABLE_MODULE_ECDH
7778# include "modules/ecdh/tests_impl.h"
7779#endif
7780
7781#ifdef ENABLE_MODULE_RECOVERY
7783#endif
7784
7785#ifdef ENABLE_MODULE_EXTRAKEYS
7787#endif
7788
7789#ifdef ENABLE_MODULE_SCHNORRSIG
7791#endif
7792
7793#ifdef ENABLE_MODULE_MUSIG
7795#endif
7796
7797#ifdef ENABLE_MODULE_ELLSWIFT
7799#endif
7800
7801#ifdef ENABLE_MODULE_SILENTPAYMENTS
7803#endif
7804
7806 unsigned char buf1[6] = {1, 2, 3, 4, 5, 6};
7807 unsigned char buf2[sizeof(buf1)];
7808
7809 /* secp256k1_memczero(..., ..., 0) is a noop. */
7810 memcpy(buf2, buf1, sizeof(buf1));
7811 secp256k1_memczero(buf1, sizeof(buf1), 0);
7812 CHECK(secp256k1_memcmp_var(buf1, buf2, sizeof(buf1)) == 0);
7813
7814 /* secp256k1_memczero(..., ..., 1) zeros the buffer. */
7815 memset(buf2, 0, sizeof(buf2));
7816 secp256k1_memczero(buf1, sizeof(buf1) , 1);
7817 CHECK(secp256k1_memcmp_var(buf1, buf2, sizeof(buf1)) == 0);
7818}
7819
7820
7822 unsigned char buf1[3] = {0, 1};
7823 unsigned char buf2[3] = {1, 0};
7824
7825 CHECK(secp256k1_is_zero_array(buf1, 0) == 1);
7826 CHECK(secp256k1_is_zero_array(buf1, 1) == 1);
7827 CHECK(secp256k1_is_zero_array(buf1, 2) == 0);
7828 CHECK(secp256k1_is_zero_array(buf2, 1) == 0);
7829 CHECK(secp256k1_is_zero_array(buf2, 2) == 0);
7830}
7831
7833 {
7834 const uint32_t x = 0xFF03AB45;
7835 const unsigned char x_be[4] = {0xFF, 0x03, 0xAB, 0x45};
7836 unsigned char buf[4];
7837 uint32_t x_;
7838
7839 secp256k1_write_be32(buf, x);
7840 CHECK(secp256k1_memcmp_var(buf, x_be, sizeof(buf)) == 0);
7841
7842 x_ = secp256k1_read_be32(buf);
7843 CHECK(x == x_);
7844 }
7845
7846 {
7847 const uint64_t x = 0xCAFE0123BEEF4567;
7848 const unsigned char x_be[8] = {0xCA, 0xFE, 0x01, 0x23, 0xBE, 0xEF, 0x45, 0x67};
7849 unsigned char buf[8];
7850 uint64_t x_;
7851
7852 secp256k1_write_be64(buf, x);
7853 CHECK(secp256k1_memcmp_var(buf, x_be, sizeof(buf)) == 0);
7854
7855 x_ = secp256k1_read_be64(buf);
7856 CHECK(x == x_);
7857 }
7858}
7859
7860static void int_cmov_test(void) {
7861 int r = INT_MAX;
7862 int a = 0;
7863
7864 secp256k1_int_cmov(&r, &a, 0);
7865 CHECK(r == INT_MAX);
7866
7867 r = 0; a = INT_MAX;
7868 secp256k1_int_cmov(&r, &a, 1);
7869 CHECK(r == INT_MAX);
7870
7871 a = 0;
7872 secp256k1_int_cmov(&r, &a, 1);
7873 CHECK(r == 0);
7874
7875 a = 1;
7876 secp256k1_int_cmov(&r, &a, 1);
7877 CHECK(r == 1);
7878
7879 r = 1; a = 0;
7880 secp256k1_int_cmov(&r, &a, 0);
7881 CHECK(r == 1);
7882
7883}
7884
7885static void fe_cmov_test(void) {
7886 static const secp256k1_fe zero = SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 0);
7887 static const secp256k1_fe one = SECP256K1_FE_CONST(0, 0, 0, 0, 0, 0, 0, 1);
7888 static const secp256k1_fe max = SECP256K1_FE_CONST(
7889 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL,
7890 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL
7891 );
7892 secp256k1_fe r = max;
7893 secp256k1_fe a = zero;
7894
7895 secp256k1_fe_cmov(&r, &a, 0);
7896 CHECK(fe_identical(&r, &max));
7897
7898 r = zero; a = max;
7899 secp256k1_fe_cmov(&r, &a, 1);
7900 CHECK(fe_identical(&r, &max));
7901
7902 a = zero;
7903 secp256k1_fe_cmov(&r, &a, 1);
7904 CHECK(fe_identical(&r, &zero));
7905
7906 a = one;
7907 secp256k1_fe_cmov(&r, &a, 1);
7908 CHECK(fe_identical(&r, &one));
7909
7910 r = one; a = zero;
7911 secp256k1_fe_cmov(&r, &a, 0);
7912 CHECK(fe_identical(&r, &one));
7913}
7914
7915static void fe_storage_cmov_test(void) {
7916 static const secp256k1_fe_storage zero = SECP256K1_FE_STORAGE_CONST(0, 0, 0, 0, 0, 0, 0, 0);
7917 static const secp256k1_fe_storage one = SECP256K1_FE_STORAGE_CONST(0, 0, 0, 0, 0, 0, 0, 1);
7919 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL,
7920 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL
7921 );
7922 secp256k1_fe_storage r = max;
7923 secp256k1_fe_storage a = zero;
7924
7925 secp256k1_fe_storage_cmov(&r, &a, 0);
7926 CHECK(secp256k1_memcmp_var(&r, &max, sizeof(r)) == 0);
7927
7928 r = zero; a = max;
7929 secp256k1_fe_storage_cmov(&r, &a, 1);
7930 CHECK(secp256k1_memcmp_var(&r, &max, sizeof(r)) == 0);
7931
7932 a = zero;
7933 secp256k1_fe_storage_cmov(&r, &a, 1);
7934 CHECK(secp256k1_memcmp_var(&r, &zero, sizeof(r)) == 0);
7935
7936 a = one;
7937 secp256k1_fe_storage_cmov(&r, &a, 1);
7938 CHECK(secp256k1_memcmp_var(&r, &one, sizeof(r)) == 0);
7939
7940 r = one; a = zero;
7941 secp256k1_fe_storage_cmov(&r, &a, 0);
7942 CHECK(secp256k1_memcmp_var(&r, &one, sizeof(r)) == 0);
7943}
7944
7945static void scalar_cmov_test(void) {
7946 static const secp256k1_scalar max = SECP256K1_SCALAR_CONST(
7947 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFEUL,
7948 0xBAAEDCE6UL, 0xAF48A03BUL, 0xBFD25E8CUL, 0xD0364140UL
7949 );
7950 secp256k1_scalar r = max;
7952
7953 secp256k1_scalar_cmov(&r, &a, 0);
7954 CHECK(secp256k1_memcmp_var(&r, &max, sizeof(r)) == 0);
7955
7956 r = secp256k1_scalar_zero; a = max;
7957 secp256k1_scalar_cmov(&r, &a, 1);
7958 CHECK(secp256k1_memcmp_var(&r, &max, sizeof(r)) == 0);
7959
7961 secp256k1_scalar_cmov(&r, &a, 1);
7962 CHECK(secp256k1_memcmp_var(&r, &secp256k1_scalar_zero, sizeof(r)) == 0);
7963
7965 secp256k1_scalar_cmov(&r, &a, 1);
7966 CHECK(secp256k1_memcmp_var(&r, &secp256k1_scalar_one, sizeof(r)) == 0);
7967
7969 secp256k1_scalar_cmov(&r, &a, 0);
7970 CHECK(secp256k1_memcmp_var(&r, &secp256k1_scalar_one, sizeof(r)) == 0);
7971}
7972
7973static void ge_storage_cmov_test(void) {
7974 static const secp256k1_ge_storage zero = SECP256K1_GE_STORAGE_CONST(0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0);
7975 static const secp256k1_ge_storage one = SECP256K1_GE_STORAGE_CONST(0, 0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 0, 0, 0, 0, 1);
7977 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL,
7978 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL,
7979 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL,
7980 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL, 0xFFFFFFFFUL
7981 );
7982 secp256k1_ge_storage r = max;
7983 secp256k1_ge_storage a = zero;
7984
7985 secp256k1_ge_storage_cmov(&r, &a, 0);
7986 CHECK(secp256k1_memcmp_var(&r, &max, sizeof(r)) == 0);
7987
7988 r = zero; a = max;
7989 secp256k1_ge_storage_cmov(&r, &a, 1);
7990 CHECK(secp256k1_memcmp_var(&r, &max, sizeof(r)) == 0);
7991
7992 a = zero;
7993 secp256k1_ge_storage_cmov(&r, &a, 1);
7994 CHECK(secp256k1_memcmp_var(&r, &zero, sizeof(r)) == 0);
7995
7996 a = one;
7997 secp256k1_ge_storage_cmov(&r, &a, 1);
7998 CHECK(secp256k1_memcmp_var(&r, &one, sizeof(r)) == 0);
7999
8000 r = one; a = zero;
8001 secp256k1_ge_storage_cmov(&r, &a, 0);
8002 CHECK(secp256k1_memcmp_var(&r, &one, sizeof(r)) == 0);
8003}
8004
8005static void run_cmov_tests(void) {
8006 int_cmov_test();
8007 fe_cmov_test();
8011}
8012
8013/* --------------------------------------------------------- */
8014/* Test Registry */
8015/* --------------------------------------------------------- */
8016
8017/* --- Special test cases that must run before RNG initialization --- */
8018static const struct tf_test_entry tests_no_rng[] = {
8019 CASE(xoshiro256pp_tests),
8020};
8022
8023/* --- Standard test cases start here --- */
8024static const struct tf_test_entry tests_general[] = {
8025 CASE(selftest_tests),
8026 CASE(all_proper_context_tests),
8027 CASE(all_static_context_tests),
8028 CASE(deprecated_context_flags_test),
8029 CASE(scratch_tests),
8030 CASE(invalid_scratch_space_tests),
8031 CASE(plug_sha256_compression_tests),
8032 CASE(sha256_compression_smoke_test_tests),
8033 CASE(sha256_multi_block_compression_tests),
8034};
8035
8036static const struct tf_test_entry tests_integer[] = {
8037#ifdef SECP256K1_WIDEMUL_INT128
8038 CASE(int128_tests),
8039#endif
8040 CASE(ctz_tests),
8041 CASE(modinv_tests),
8042 CASE(inverse_tests),
8043};
8044
8045static const struct tf_test_entry tests_hash[] = {
8046 CASE(sha256_known_output_tests),
8047 CASE(sha256_counter_tests),
8048 CASE(hmac_sha256_tests),
8049 CASE(rfc6979_hmac_sha256_tests),
8050 CASE(tagged_sha256_tests),
8051 CASE(sha256_initialize_midstate_tests),
8052};
8053
8054static const struct tf_test_entry tests_scalar[] = {
8055 CASE(scalar_tests),
8056};
8057
8058static const struct tf_test_entry tests_field[] = {
8059 CASE(field_half),
8060 CASE(field_misc),
8061 CASE(fe_equal_magnitude_boundaries),
8062 CASE(field_convert),
8063 CASE(field_be32_overflow),
8064 CASE(fe_mul),
8065 CASE(sqr),
8066 CASE(sqrt),
8067};
8068
8069static const struct tf_test_entry tests_group[] = {
8070 CASE(ge),
8071 CASE(gej),
8072 CASE(group_decompress),
8073};
8074
8075static const struct tf_test_entry tests_ecmult[] = {
8076 CASE(ecmult_pre_g),
8077 CASE(wnaf),
8078 CASE(point_times_order),
8079 CASE(ecmult_near_split_bound),
8080 CASE(ecmult_chain),
8081 CASE(ecmult_constants),
8082 CASE(ecmult_gen_ge),
8083 CASE(ecmult_gen_blind),
8084 CASE(ecmult_const_tests),
8085 CASE(ecmult_multi_tests),
8086 CASE(ec_combine),
8087};
8088
8089static const struct tf_test_entry tests_ec[] = {
8090 CASE(endomorphism_tests),
8091 CASE(ec_pubkey_parse_test),
8092 CASE(eckey_edge_case_test),
8093 CASE(eckey_negate_test),
8094};
8095
8096static const struct tf_test_entry tests_ecdsa[] = {
8097 CASE(ec_illegal_argument_tests),
8098 CASE(pubkey_comparison),
8099 CASE(pubkey_sort),
8100 CASE(random_pubkeys),
8101 CASE(ecdsa_der_parse),
8102 CASE(ecdsa_sign_verify),
8103 CASE(ecdsa_end_to_end),
8104 CASE(ecdsa_edge_cases),
8105 CASE(ecdsa_wycheproof),
8107};
8108
8109static const struct tf_test_entry tests_utils[] = {
8110 CASE(hsort_tests),
8111 CASE(secp256k1_memczero_test),
8112 CASE(secp256k1_is_zero_array_test),
8113 CASE(secp256k1_byteorder_tests),
8114 CASE(cmov_tests),
8115};
8116
8117/* Register test modules */
8118static const struct tf_test_module registry_modules[] = {
8119 MAKE_TEST_MODULE(general),
8120 MAKE_TEST_MODULE(integer),
8121 MAKE_TEST_MODULE(hash),
8122 MAKE_TEST_MODULE(scalar),
8123 MAKE_TEST_MODULE(field),
8125 MAKE_TEST_MODULE(ecmult),
8126 MAKE_TEST_MODULE(ec),
8127#ifdef ENABLE_MODULE_ECDH
8128 MAKE_TEST_MODULE(ecdh),
8129#endif
8130 MAKE_TEST_MODULE(ecdsa),
8131#ifdef ENABLE_MODULE_RECOVERY
8132 /* ECDSA pubkey recovery tests */
8133 MAKE_TEST_MODULE(recovery),
8134#endif
8135#ifdef ENABLE_MODULE_EXTRAKEYS
8136 MAKE_TEST_MODULE(extrakeys),
8137#endif
8138#ifdef ENABLE_MODULE_SCHNORRSIG
8139 MAKE_TEST_MODULE(schnorrsig),
8140#endif
8141#ifdef ENABLE_MODULE_MUSIG
8142 MAKE_TEST_MODULE(musig),
8143#endif
8144#ifdef ENABLE_MODULE_ELLSWIFT
8145 MAKE_TEST_MODULE(ellswift),
8146#endif
8147#ifdef ENABLE_MODULE_SILENTPAYMENTS
8148 MAKE_TEST_MODULE(silentpayments),
8149#endif
8150 MAKE_TEST_MODULE(utils),
8151};
8152
8153/* Setup test environment */
8154static int setup(void) {
8155 /* Create a global context available to all tests */
8157 /* Randomize the context only with probability 15/16
8158 to make sure we test without context randomization from time to time.
8159 TODO Reconsider this when recalibrating the tests. */
8160 if (testrand_bits(4)) {
8161 unsigned char rand32[32];
8162 testrand256(rand32);
8164 }
8165 /* Make a writable copy of secp256k1_context_static in order to test the effect of API functions
8166 that write to the context. The API does not support cloning the static context, so we use
8167 memcpy instead. The user is not supposed to copy a context but we should still ensure that
8168 the API functions handle copies of the static context gracefully. */
8169 STATIC_CTX = malloc(sizeof(*secp256k1_context_static));
8170 CHECK(STATIC_CTX != NULL);
8173 return 0;
8174}
8175
8176/* Shutdown test environment */
8177static int teardown(void) {
8178 free(STATIC_CTX);
8180 return 0;
8181}
8182
8183int main(int argc, char **argv) {
8184 struct tf_framework tf = {0};
8188
8189 /* Add context creation/destruction functions */
8190 tf.fn_setup = setup;
8191 tf.fn_teardown = teardown;
8192
8193 /* Init and run framework */
8194 if (tf_init(&tf, argc, argv) != 0) return EXIT_FAILURE;
8195 return tf_run(&tf);
8196}
8197
8198#if defined(__GNUC__)
8199# pragma GCC diagnostic pop
8200#endif
static void pool cs
int ret
int flags
Definition: bitcoin-tx.cpp:530
#define SECP256K1_CHECKMEM_UNDEFINE(p, len)
Definition: checkmem.h:105
#define SECP256K1_CHECKMEM_CHECK(p, len)
Definition: checkmem.h:107
static const PrecomputedData data
Precomputed COutPoint and CCoins values.
static const wycheproof_ecdh_testvector testvectors[SECP256K1_ECDH_WYCHEPROOF_NUMBER_TESTVECTORS]
static int secp256k1_ecdsa_sig_sign(const secp256k1_ecmult_gen_context *ctx, secp256k1_scalar *r, secp256k1_scalar *s, const secp256k1_scalar *seckey, const secp256k1_scalar *message, const secp256k1_scalar *nonce, int *recid)
static int secp256k1_ecdsa_sig_verify(const secp256k1_scalar *r, const secp256k1_scalar *s, const secp256k1_ge *pubkey, const secp256k1_scalar *message)
static const unsigned char wycheproof_ecdsa_signatures[]
static const unsigned char wycheproof_ecdsa_public_keys[]
static const unsigned char wycheproof_ecdsa_messages[]
#define SECP256K1_ECDSA_WYCHEPROOF_NUMBER_TESTVECTORS
static void secp256k1_eckey_pubkey_serialize65(secp256k1_ge *elem, unsigned char *pub65)
Serialize a group element (that is not allowed to be infinity) to an uncompressed public key (65 byte...
static void secp256k1_eckey_pubkey_serialize33(secp256k1_ge *elem, unsigned char *pub33)
Serialize a group element (that is not allowed to be infinity) to a compressed public key (33 bytes).
static int secp256k1_eckey_pubkey_parse(secp256k1_ge *elem, const unsigned char *pub, size_t size)
static int secp256k1_ecmult_multi_var(const secp256k1_callback *error_callback, secp256k1_scratch *scratch, secp256k1_gej *r, const secp256k1_scalar *inp_g_sc, secp256k1_ecmult_multi_callback cb, void *cbdata, size_t n)
Multi-multiply: R = inp_g_sc * G + sum_i ni * Ai.
#define ECMULT_TABLE_SIZE(w)
The number of entries a table with precomputed multiples needs to have.
Definition: ecmult.h:41
static void secp256k1_ecmult(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_scalar *na, const secp256k1_scalar *ng)
Double multiply: R = na*A + ng*G.
static int secp256k1_ecmult_const_xonly(secp256k1_fe *r, const secp256k1_fe *n, const secp256k1_fe *d, const secp256k1_scalar *q, int known_on_curve)
Same as secp256k1_ecmult_const, but takes in an x coordinate of the base point only,...
static void secp256k1_ecmult_const(secp256k1_gej *r, const secp256k1_ge *a, const secp256k1_scalar *q)
Multiply: R = q*A (in constant-time for q)
static const secp256k1_scalar secp256k1_ecmult_const_K
static void secp256k1_ecmult_gen_blind(secp256k1_ecmult_gen_context *ctx, const secp256k1_hash_ctx *hash_ctx, const unsigned char *seed32)
static void secp256k1_ecmult_gen_ge(const secp256k1_ecmult_gen_context *ctx, secp256k1_ge *r, const secp256k1_scalar *a)
static void secp256k1_ecmult_gen_gej(const secp256k1_ecmult_gen_context *ctx, secp256k1_gej *r, const secp256k1_scalar *a)
Multiply with the generator: R = a*G.
#define STRAUSS_SCRATCH_OBJECTS
Definition: ecmult_impl.h:50
static size_t secp256k1_pippenger_bucket_window_inv(int bucket_window)
Returns the maximum optimal number of points for a bucket_window.
Definition: ecmult_impl.h:626
static size_t secp256k1_pippenger_max_points(const secp256k1_callback *error_callback, secp256k1_scratch *scratch)
Returns the maximum number of points in addition to G that can be used with a given scratch space.
Definition: ecmult_impl.h:743
#define WNAF_SIZE(w)
Definition: ecmult_impl.h:46
static int secp256k1_ecmult_strauss_batch_single(const secp256k1_callback *error_callback, secp256k1_scratch *scratch, secp256k1_gej *r, const secp256k1_scalar *inp_g_sc, secp256k1_ecmult_multi_callback cb, void *cbdata, size_t n)
Definition: ecmult_impl.h:422
static int secp256k1_wnaf_fixed(int *wnaf, const secp256k1_scalar *s, int w)
Convert a number to WNAF notation.
Definition: ecmult_impl.h:437
static int secp256k1_ecmult_wnaf(int *wnaf, int len, const secp256k1_scalar *a, int w)
Convert a number to WNAF notation.
Definition: ecmult_impl.h:162
static size_t secp256k1_strauss_scratch_size(size_t n_points)
Definition: ecmult_impl.h:377
#define ECMULT_PIPPENGER_THRESHOLD
Definition: ecmult_impl.h:55
static int secp256k1_pippenger_bucket_window(size_t n)
Returns optimal bucket_window (number of bits of a scalar represented by a set of buckets) for a give...
Definition: ecmult_impl.h:597
static int secp256k1_ecmult_pippenger_batch_single(const secp256k1_callback *error_callback, secp256k1_scratch *scratch, secp256k1_gej *r, const secp256k1_scalar *inp_g_sc, secp256k1_ecmult_multi_callback cb, void *cbdata, size_t n)
Definition: ecmult_impl.h:734
#define ECMULT_MAX_POINTS_PER_BATCH
Definition: ecmult_impl.h:57
#define PIPPENGER_MAX_BUCKET_WINDOW
Definition: ecmult_impl.h:52
#define PIPPENGER_SCRATCH_OBJECTS
Definition: ecmult_impl.h:49
static int secp256k1_ecmult_multi_batch_size_helper(size_t *n_batches, size_t *n_batch_points, size_t max_n_batch_points, size_t n)
Definition: ecmult_impl.h:804
static size_t secp256k1_pippenger_scratch_size(size_t n_points, int bucket_window)
Returns the scratch size required for a given number of points (excluding base point G) without consi...
Definition: ecmult_impl.h:664
int(* secp256k1_ecmult_multi_func)(const secp256k1_callback *error_callback, secp256k1_scratch *, secp256k1_gej *, const secp256k1_scalar *, secp256k1_ecmult_multi_callback cb, void *, size_t)
Definition: ecmult_impl.h:822
volatile double sum
Definition: examples.cpp:10
#define N_PUBKEYS
Definition: tests_impl.h:252
#define secp256k1_fe_cmov
Definition: field.h:95
#define secp256k1_fe_negate(r, a, m)
Negate a field element.
Definition: field.h:211
#define secp256k1_fe_mul_int(r, a)
Multiply a field element with a small integer.
Definition: field.h:233
#define secp256k1_fe_normalizes_to_zero_var
Definition: field.h:82
#define secp256k1_fe_cmp_var
Definition: field.h:86
#define secp256k1_fe_normalize_weak
Definition: field.h:79
#define secp256k1_fe_is_odd
Definition: field.h:85
#define secp256k1_fe_mul
Definition: field.h:93
static const secp256k1_fe secp256k1_fe_one
Definition: field.h:68
static int secp256k1_fe_sqrt(secp256k1_fe *SECP256K1_RESTRICT r, const secp256k1_fe *SECP256K1_RESTRICT a)
Compute a square root of a field element.
#define secp256k1_fe_add
Definition: field.h:92
#define secp256k1_fe_normalize_var
Definition: field.h:80
#define secp256k1_fe_half
Definition: field.h:101
#define SECP256K1_FE_CONST(d7, d6, d5, d4, d3, d2, d1, d0)
This expands to an initializer for a secp256k1_fe valued sum((i*32) * d_i, i=0..7) mod p.
Definition: field.h:66
#define secp256k1_fe_to_storage
Definition: field.h:96
#define secp256k1_fe_inv_var
Definition: field.h:99
#define secp256k1_fe_is_zero
Definition: field.h:84
#define secp256k1_fe_set_b32_limit
Definition: field.h:88
#define secp256k1_fe_is_square_var
Definition: field.h:103
#define secp256k1_fe_get_bounds
Definition: field.h:100
#define secp256k1_fe_from_storage
Definition: field.h:97
#define secp256k1_fe_set_b32_mod
Definition: field.h:87
#define secp256k1_fe_negate_unchecked
Definition: field.h:90
#define secp256k1_fe_get_b32
Definition: field.h:89
#define secp256k1_fe_normalizes_to_zero
Definition: field.h:81
#define secp256k1_fe_inv
Definition: field.h:98
#define secp256k1_fe_sqr
Definition: field.h:94
#define secp256k1_fe_normalize
Definition: field.h:78
static int secp256k1_fe_equal(const secp256k1_fe *a, const secp256k1_fe *b)
Determine whether two field elements are equal.
static void secp256k1_fe_storage_cmov(secp256k1_fe_storage *r, const secp256k1_fe_storage *a, int flag)
If flag is 1, set *r equal to *a; if flag is 0, leave it.
#define secp256k1_fe_add_int
Definition: field.h:102
#define secp256k1_fe_set_int
Definition: field.h:83
#define SECP256K1_FE_STORAGE_CONST(d7, d6, d5, d4, d3, d2, d1, d0)
Definition: field_10x26.h:54
#define SECP256K1_GEJ_CONST_INFINITY
Definition: group.h:36
#define SECP256K1_GE_STORAGE_CONST(a, b, c, d, e, f, g, h, i, j, k, l, m, n, o, p)
Definition: group.h:43
static int secp256k1_gej_eq_var(const secp256k1_gej *a, const secp256k1_gej *b)
Check two group elements (jacobian) for equality in variable time.
static void secp256k1_gej_double_var(secp256k1_gej *r, const secp256k1_gej *a, secp256k1_fe *rzr)
Set r equal to the double of a.
static void secp256k1_gej_add_zinv_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b, const secp256k1_fe *bzinv)
Set r equal to the sum of a and b (with the inverse of b's Z coordinate passed as bzinv).
static void secp256k1_ge_mul_lambda(secp256k1_ge *r, const secp256k1_ge *a)
Set r to be equal to lambda times a, where lambda is chosen in a way such that this is very fast.
static void secp256k1_gej_set_infinity(secp256k1_gej *r)
Set a group element (jacobian) equal to the point at infinity.
static int secp256k1_gej_is_infinity(const secp256k1_gej *a)
Check whether a group element is the point at infinity.
static int secp256k1_ge_set_xo_var(secp256k1_ge *r, const secp256k1_fe *x, int odd)
Set a group element (affine) equal to the point with the given X coordinate, and given oddness for Y.
static int secp256k1_ge_eq_var(const secp256k1_ge *a, const secp256k1_ge *b)
Check two group elements (affine) for equality in variable time.
static int secp256k1_ge_x_on_curve_var(const secp256k1_fe *x)
Determine whether x is a valid X coordinate on the curve.
static void secp256k1_gej_add_ge_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b, secp256k1_fe *rzr)
Set r equal to the sum of a and b (with b given in affine coordinates).
static void secp256k1_ge_to_bytes_ext(unsigned char *data, const secp256k1_ge *ge)
Convert a group element (that is allowed to be infinity) to a 64-byte array.
static void secp256k1_gej_add_ge(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_ge *b)
Set r equal to the sum of a and b (with b given in affine coordinates, and not infinity).
static int secp256k1_gej_eq_ge_var(const secp256k1_gej *a, const secp256k1_ge *b)
Check two group elements (jacobian and affine) for equality in variable time.
static int secp256k1_ge_is_valid_var(const secp256k1_ge *a)
Check whether a group element is valid (i.e., on the curve).
static void secp256k1_ge_from_bytes_ext(secp256k1_ge *ge, const unsigned char *data)
Convert a 64-byte array into a group element.
static void secp256k1_ge_from_storage(secp256k1_ge *r, const secp256k1_ge_storage *a)
Convert a group element back from the storage type.
static void secp256k1_gej_add_var(secp256k1_gej *r, const secp256k1_gej *a, const secp256k1_gej *b, secp256k1_fe *rzr)
Set r equal to the sum of a and b.
static void secp256k1_gej_rescale(secp256k1_gej *r, const secp256k1_fe *b)
Rescale a jacobian point by b which must be non-zero.
static int secp256k1_ge_x_frac_on_curve_var(const secp256k1_fe *xn, const secp256k1_fe *xd)
Determine whether fraction xn/xd is a valid X coordinate on the curve (xd != 0).
static void secp256k1_ge_storage_cmov(secp256k1_ge_storage *r, const secp256k1_ge_storage *a, int flag)
If flag is 1, set *r equal to *a; if flag is 0, leave it.
static void secp256k1_ge_set_gej(secp256k1_ge *r, secp256k1_gej *a)
Set a group element equal to another which is given in jacobian coordinates.
static void secp256k1_ge_neg(secp256k1_ge *r, const secp256k1_ge *a)
Set r equal to the inverse of a (i.e., mirrored around the X axis)
static void secp256k1_ge_set_all_gej(secp256k1_ge *r, const secp256k1_gej *a, size_t len)
Set group elements r[0:len] (affine) equal to group elements a[0:len] (jacobian).
static int secp256k1_ge_is_infinity(const secp256k1_ge *a)
Check whether a group element is the point at infinity.
static void secp256k1_ge_set_infinity(secp256k1_ge *r)
Set a group element (affine) equal to the point at infinity.
static void secp256k1_ge_set_all_gej_var(secp256k1_ge *r, const secp256k1_gej *a, size_t len)
Set group elements r[0:len] (affine) equal to group elements a[0:len] (jacobian).
static void secp256k1_gej_double(secp256k1_gej *r, const secp256k1_gej *a)
Set r equal to the double of a.
static void secp256k1_gej_set_ge(secp256k1_gej *r, const secp256k1_ge *a)
Set a group element (jacobian) equal to another which is given in affine coordinates.
static void secp256k1_ge_to_storage(secp256k1_ge_storage *r, const secp256k1_ge *a)
Convert a group element to the storage type.
#define SECP256K1_GE_CONST(a, b, c, d, e, f, g, h, i, j, k, l, m, n, o, p)
Definition: group.h:22
static void secp256k1_ge_to_bytes(unsigned char *buf, const secp256k1_ge *a)
Convert a group element that is not infinity to a 64-byte array.
static void secp256k1_gej_cmov(secp256k1_gej *r, const secp256k1_gej *a, int flag)
If flag is 1, set *r equal to *a; if flag is 0, leave it.
static void secp256k1_ge_set_gej_var(secp256k1_ge *r, secp256k1_gej *a)
Set a group element equal to another which is given in jacobian coordinates.
#define SECP256K1_GEJ_CONST(a, b, c, d, e, f, g, h, i, j, k, l, m, n, o, p)
Definition: group.h:35
static void secp256k1_gej_neg(secp256k1_gej *r, const secp256k1_gej *a)
Set r equal to the inverse of a (i.e., mirrored around the X axis)
static void secp256k1_ge_from_bytes(secp256k1_ge *r, const unsigned char *buf)
Convert a 64-byte array into group element.
static const secp256k1_ge secp256k1_ge_const_g
Definition: group_impl.h:72
static int secp256k1_sha256_smoke_test(const secp256k1_sha256_compression_function fn_compression)
Definition: hash_impl.h:141
static void secp256k1_sha256_transform(uint32_t *state, const unsigned char *blocks64, size_t n_blocks)
Definition: hash_impl.h:133
static void secp256k1_sha256_initialize_tagged(const secp256k1_hash_ctx *hash_ctx, secp256k1_sha256 *hash, const unsigned char *tag, size_t taglen)
Definition: hash_impl.h:261
static void secp256k1_hsort(void *ptr, size_t count, size_t size, int(*cmp)(const void *, const void *, void *), void *cmp_data)
static SECP256K1_INLINE void secp256k1_heap_swap(unsigned char *arr, size_t i, size_t j, size_t stride)
Definition: hsort_impl.h:34
int128_t secp256k1_int128
Definition: int128_native.h:17
static SECP256K1_INLINE void secp256k1_i128_load(secp256k1_int128 *r, int64_t hi, uint64_t lo)
static SECP256K1_INLINE void secp256k1_i128_det(secp256k1_int128 *r, int64_t a, int64_t b, int64_t c, int64_t d)
static SECP256K1_INLINE int secp256k1_u128_check_bits(const secp256k1_uint128 *r, unsigned int n)
static SECP256K1_INLINE void secp256k1_i128_rshift(secp256k1_int128 *r, unsigned int n)
static SECP256K1_INLINE uint64_t secp256k1_u128_hi_u64(const secp256k1_uint128 *a)
static SECP256K1_INLINE uint64_t secp256k1_i128_to_u64(const secp256k1_int128 *a)
static SECP256K1_INLINE void secp256k1_i128_from_i64(secp256k1_int128 *r, int64_t a)
static SECP256K1_INLINE void secp256k1_u128_from_u64(secp256k1_uint128 *r, uint64_t a)
static SECP256K1_INLINE int secp256k1_i128_eq_var(const secp256k1_int128 *a, const secp256k1_int128 *b)
static SECP256K1_INLINE int64_t secp256k1_i128_to_i64(const secp256k1_int128 *a)
static SECP256K1_INLINE void secp256k1_i128_mul(secp256k1_int128 *r, int64_t a, int64_t b)
static SECP256K1_INLINE void secp256k1_u128_rshift(secp256k1_uint128 *r, unsigned int n)
static SECP256K1_INLINE int secp256k1_i128_check_pow2(const secp256k1_int128 *r, unsigned int n, int sign)
static SECP256K1_INLINE void secp256k1_u128_accum_u64(secp256k1_uint128 *r, uint64_t a)
static SECP256K1_INLINE void secp256k1_i128_accum_mul(secp256k1_int128 *r, int64_t a, int64_t b)
static SECP256K1_INLINE void secp256k1_u128_accum_mul(secp256k1_uint128 *r, uint64_t a, uint64_t b)
static SECP256K1_INLINE void secp256k1_u128_load(secp256k1_uint128 *r, uint64_t hi, uint64_t lo)
static SECP256K1_INLINE void secp256k1_u128_mul(secp256k1_uint128 *r, uint64_t a, uint64_t b)
static SECP256K1_INLINE uint64_t secp256k1_u128_to_u64(const secp256k1_uint128 *a)
int ec_privkey_export_der(const secp256k1_context *ctx, unsigned char *privkey, size_t *privkeylen, const unsigned char *key32, int compressed)
Export a private key in DER format.
int ec_privkey_import_der(const secp256k1_context *ctx, unsigned char *out32, const unsigned char *privkey, size_t privkeylen)
Import a private key in DER format.
unsigned int nonce
#define CHECK(cond)
Unconditional failure on condition failure.
Definition: util.h:35
static void secp256k1_modinv32_var(secp256k1_modinv32_signed30 *x, const secp256k1_modinv32_modinfo *modinfo)
static void secp256k1_modinv32(secp256k1_modinv32_signed30 *x, const secp256k1_modinv32_modinfo *modinfo)
static int secp256k1_jacobi32_maybe_var(const secp256k1_modinv32_signed30 *x, const secp256k1_modinv32_modinfo *modinfo)
static void secp256k1_modinv64(secp256k1_modinv64_signed62 *x, const secp256k1_modinv64_modinfo *modinfo)
static void secp256k1_modinv64_var(secp256k1_modinv64_signed62 *x, const secp256k1_modinv64_modinfo *modinfo)
static int secp256k1_jacobi64_maybe_var(const secp256k1_modinv64_signed62 *x, const secp256k1_modinv64_modinfo *modinfo)
static int sign(const secp256k1_context *ctx, struct signer_secrets *signer_secrets, struct signer *signer, const secp256k1_musig_keyagg_cache *cache, const unsigned char *msg32, unsigned char *sig64)
Definition: musig.c:106
static const auto ZERO
A stack consisting of a single zero-length element (interpreted as 0 by the script interpreter in num...
Definition: miniscript.h:345
Internal SHA-1 implementation.
Definition: sha1.cpp:16
static std::vector< std::string > split(const std::string &str, const std::string &delims=" \t")
Definition: subprocess.h:308
const secp256k1_ge_storage secp256k1_pre_g_128[ECMULT_TABLE_SIZE(WINDOW_G)]
const secp256k1_ge_storage secp256k1_pre_g[ECMULT_TABLE_SIZE(WINDOW_G)]
#define WINDOW_G
int ecdsa_signature_parse_der_lax(secp256k1_ecdsa_signature *sig, const unsigned char *input, size_t inputlen)
This function is taken from the libsecp256k1 distribution and implements DER parsing for ECDSA signat...
Definition: pubkey.cpp:45
const char * prefix
Definition: rest.cpp:1180
static void secp256k1_scalar_cmov(secp256k1_scalar *r, const secp256k1_scalar *a, int flag)
If flag is 1, set *r equal to *a; if flag is 0, leave it.
static void secp256k1_scalar_half(secp256k1_scalar *r, const secp256k1_scalar *a)
Multiply a scalar with the multiplicative inverse of 2.
static void secp256k1_scalar_split_128(secp256k1_scalar *r1, secp256k1_scalar *r2, const secp256k1_scalar *k)
Find r1 and r2 such that r1+r2*2^128 = k.
static void secp256k1_scalar_set_b32(secp256k1_scalar *r, const unsigned char *bin, int *overflow)
Set a scalar from a big endian byte array.
static int secp256k1_scalar_set_b32_seckey(secp256k1_scalar *r, const unsigned char *bin)
Set a scalar from a big endian byte array and returns 1 if it is a valid seckey and 0 otherwise.
static int secp256k1_scalar_is_zero(const secp256k1_scalar *a)
Check whether a scalar equals zero.
static void secp256k1_scalar_set_int(secp256k1_scalar *r, unsigned int v)
Set a scalar to an unsigned integer.
static int secp256k1_scalar_eq(const secp256k1_scalar *a, const secp256k1_scalar *b)
Compare two scalars.
static void secp256k1_scalar_get_b32(unsigned char *bin, const secp256k1_scalar *a)
Convert a scalar to a byte array.
static int secp256k1_scalar_cond_negate(secp256k1_scalar *a, int flag)
Conditionally negate a number, in constant time.
static void secp256k1_scalar_inverse_var(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the inverse of a scalar (modulo the group order), without constant-time guarantee.
static int secp256k1_scalar_add(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b)
Add two scalars together (modulo the group order).
static void secp256k1_scalar_mul(secp256k1_scalar *r, const secp256k1_scalar *a, const secp256k1_scalar *b)
Multiply two scalars (modulo the group order).
static uint32_t secp256k1_scalar_get_bits_limb32(const secp256k1_scalar *a, unsigned int offset, unsigned int count)
Access bits (1 <= count <= 32) from a scalar.
static int secp256k1_scalar_is_one(const secp256k1_scalar *a)
Check whether a scalar equals one.
static void secp256k1_scalar_negate(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the complement of a scalar (modulo the group order).
static int secp256k1_scalar_is_high(const secp256k1_scalar *a)
Check whether a scalar is higher than the group order divided by 2.
static void secp256k1_scalar_split_lambda(secp256k1_scalar *SECP256K1_RESTRICT r1, secp256k1_scalar *SECP256K1_RESTRICT r2, const secp256k1_scalar *SECP256K1_RESTRICT k)
Find r1 and r2 such that r1+r2*lambda = k, where r1 and r2 or their negations are maximum 128 bits lo...
static uint32_t secp256k1_scalar_get_bits_var(const secp256k1_scalar *a, unsigned int offset, unsigned int count)
Access bits (1 <= count <= 32) from a scalar.
static void secp256k1_scalar_inverse(secp256k1_scalar *r, const secp256k1_scalar *a)
Compute the inverse of a scalar (modulo the group order).
static void secp256k1_scalar_cadd_bit(secp256k1_scalar *r, unsigned int bit, int flag)
Conditionally add a power of two to a scalar.
#define SECP256K1_SCALAR_CONST(d7, d6, d5, d4, d3, d2, d1, d0)
Definition: scalar_4x64.h:17
static SECP256K1_INLINE int secp256k1_scalar_check_overflow(const secp256k1_scalar *a)
static const secp256k1_scalar secp256k1_scalar_zero
Definition: scalar_impl.h:28
static const secp256k1_scalar secp256k1_scalar_one
Definition: scalar_impl.h:27
static const secp256k1_scalar secp256k1_const_lambda
The Secp256k1 curve has an endomorphism, where lambda * (x, y) = (beta * x, y), where lambda is:
Definition: scalar_impl.h:83
static void secp256k1_scratch_apply_checkpoint(const secp256k1_callback *error_callback, secp256k1_scratch *scratch, size_t checkpoint)
Applies a check point received from secp256k1_scratch_checkpoint, undoing all allocations since that ...
static void secp256k1_scratch_destroy(const secp256k1_callback *error_callback, secp256k1_scratch *scratch)
static secp256k1_scratch * secp256k1_scratch_create(const secp256k1_callback *error_callback, size_t max_size)
static size_t secp256k1_scratch_max_allocation(const secp256k1_callback *error_callback, const secp256k1_scratch *scratch, size_t n_objects)
Returns the maximum allocation the scratch space will allow.
static void * secp256k1_scratch_alloc(const secp256k1_callback *error_callback, secp256k1_scratch *scratch, size_t n)
Returns a pointer into the most recently allocated frame, or NULL if there is insufficient available ...
static size_t secp256k1_scratch_checkpoint(const secp256k1_callback *error_callback, const secp256k1_scratch *scratch)
Returns an opaque object used to "checkpoint" a scratch space.
static void secp256k1_hmac_sha256_finalize(const secp256k1_hash_ctx *hash_ctx, secp256k1_hmac_sha256 *hash, unsigned char *out32)
static void secp256k1_sha256_finalize(const secp256k1_hash_ctx *hash_ctx, secp256k1_sha256 *hash, unsigned char *out32)
static void secp256k1_sha256_initialize(secp256k1_sha256 *hash)
static void secp256k1_sha256_initialize_midstate(secp256k1_sha256 *hash, uint64_t bytes, const uint32_t state[8])
static void secp256k1_hmac_sha256_write(const secp256k1_hash_ctx *hash_ctx, secp256k1_hmac_sha256 *hash, const unsigned char *data, size_t size)
static void secp256k1_rfc6979_hmac_sha256_generate(const secp256k1_hash_ctx *hash_ctx, secp256k1_rfc6979_hmac_sha256 *rng, unsigned char *out, size_t outlen)
static void secp256k1_rfc6979_hmac_sha256_initialize(const secp256k1_hash_ctx *hash_ctx, secp256k1_rfc6979_hmac_sha256 *rng, const unsigned char *key, size_t keylen)
static void secp256k1_rfc6979_hmac_sha256_finalize(secp256k1_rfc6979_hmac_sha256 *rng)
static void secp256k1_sha256_write(const secp256k1_hash_ctx *hash_ctx, secp256k1_sha256 *hash, const unsigned char *data, size_t size)
static void secp256k1_hmac_sha256_initialize(const secp256k1_hash_ctx *hash_ctx, secp256k1_hmac_sha256 *hash, const unsigned char *key, size_t size)
static SECP256K1_INLINE int secp256k1_ctz64_var(uint64_t x)
Definition: util.h:410
static SECP256K1_INLINE int secp256k1_memcmp_var(const void *s1, const void *s2, size_t n)
Semantics like memcmp.
Definition: util.h:281
static SECP256K1_INLINE void secp256k1_int_cmov(int *r, const int *a, int flag)
If flag is 1, set *r equal to *a; if flag is 0, leave it.
Definition: util.h:312
#define ARRAY_SIZE(arr)
Definition: util.h:194
#define ALIGNMENT
Definition: util.h:186
static void secp256k1_default_error_callback_fn(const char *str, void *data)
Definition: util.h:112
static SECP256K1_INLINE int secp256k1_is_zero_array(const unsigned char *s, size_t len)
Definition: util.h:296
static SECP256K1_INLINE uint32_t secp256k1_read_be32(const unsigned char *p)
Definition: util.h:428
static SECP256K1_INLINE int secp256k1_ctz32_var(uint32_t x)
Definition: util.h:392
static SECP256K1_INLINE void secp256k1_write_be32(unsigned char *p, uint32_t x)
Definition: util.h:436
static SECP256K1_INLINE void secp256k1_write_be64(unsigned char *p, uint64_t x)
Definition: util.h:456
static void secp256k1_default_illegal_callback_fn(const char *str, void *data)
Definition: util.h:107
static SECP256K1_INLINE int secp256k1_ctz64_var_debruijn(uint64_t x)
Definition: util.h:381
#define VERIFY_CHECK(cond)
Definition: util.h:169
static SECP256K1_INLINE int secp256k1_ctz32_var_debruijn(uint32_t x)
Definition: util.h:369
static SECP256K1_INLINE uint64_t secp256k1_read_be64(const unsigned char *p)
Definition: util.h:444
static SECP256K1_INLINE void * checked_malloc(const secp256k1_callback *cb, size_t size)
Definition: util.h:172
static SECP256K1_INLINE void secp256k1_memczero(void *s, size_t len, int flag)
Definition: util.h:220
static void secp256k1_scratch_space_destroy(const secp256k1_context *ctx, secp256k1_scratch_space *scratch)
Definition: secp256k1.c:246
static int secp256k1_context_is_proper(const secp256k1_context *ctx)
Definition: secp256k1.c:83
static void secp256k1_ecdsa_signature_save(secp256k1_ecdsa_signature *sig, const secp256k1_scalar *r, const secp256k1_scalar *s)
Definition: secp256k1.c:385
static secp256k1_scratch_space * secp256k1_scratch_space_create(const secp256k1_context *ctx, size_t max_size)
Definition: secp256k1.c:241
static int secp256k1_pubkey_load(const secp256k1_context *ctx, secp256k1_ge *ge, const secp256k1_pubkey *pubkey)
Definition: secp256k1.c:258
static void secp256k1_pubkey_save(secp256k1_pubkey *pubkey, secp256k1_ge *ge)
Definition: secp256k1.c:264
static SECP256K1_INLINE const secp256k1_hash_ctx * secp256k1_get_hash_context(const secp256k1_context *ctx)
Definition: secp256k1.c:237
static int secp256k1_ec_pubkey_sort_cmp(const void *pk1, const void *pk2, void *ctx)
Definition: secp256k1.c:338
static int nonce_function_rfc6979(unsigned char *nonce32, const unsigned char *msg32, const unsigned char *key32, const unsigned char *algo16, void *data, unsigned int counter)
Definition: secp256k1.c:534
static void secp256k1_ecdsa_signature_load(const secp256k1_context *ctx, secp256k1_scalar *r, secp256k1_scalar *s, const secp256k1_ecdsa_signature *sig)
Definition: secp256k1.c:371
SECP256K1_API void secp256k1_context_destroy(secp256k1_context *ctx) SECP256K1_ARG_NONNULL(1)
Destroy a secp256k1 context object (created in dynamically allocated memory).
Definition: secp256k1.c:189
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_seckey_tweak_mul(const secp256k1_context *ctx, unsigned char *seckey, const unsigned char *tweak32) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Tweak a secret key by multiplying it by a tweak.
Definition: secp256k1.c:736
#define SECP256K1_CONTEXT_SIGN
Definition: secp256k1.h:210
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_context_randomize(secp256k1_context *ctx, const unsigned char *seed32) SECP256K1_ARG_NONNULL(1)
Randomizes the context to provide enhanced protection against side-channel leakage.
Definition: secp256k1.c:779
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_pubkey_combine(const secp256k1_context *ctx, secp256k1_pubkey *out, const secp256k1_pubkey *const *ins, size_t n) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Add a number of public keys together.
Definition: secp256k1.c:789
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_seckey_negate(const secp256k1_context *ctx, unsigned char *seckey) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2)
Negates a secret key in place.
Definition: secp256k1.c:654
SECP256K1_API int secp256k1_ecdsa_signature_parse_compact(const secp256k1_context *ctx, secp256k1_ecdsa_signature *sig, const unsigned char *input64) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Parse an ECDSA signature in compact (64 bytes) format.
Definition: secp256k1.c:411
SECP256K1_API int secp256k1_ec_pubkey_serialize(const secp256k1_context *ctx, unsigned char *output, size_t *outputlen, const secp256k1_pubkey *pubkey, unsigned int flags) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(4)
Serialize a pubkey object into a serialized byte sequence.
Definition: secp256k1.c:286
SECP256K1_API void secp256k1_context_set_error_callback(secp256k1_context *ctx, void(*fun)(const char *message, void *data), const void *data) SECP256K1_ARG_NONNULL(1)
Set a callback function to be called when an internal consistency check fails.
Definition: secp256k1.c:213
SECP256K1_API int secp256k1_ec_pubkey_negate(const secp256k1_context *ctx, secp256k1_pubkey *pubkey) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2)
Negates a public key in place.
Definition: secp256k1.c:669
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_pubkey_cmp(const secp256k1_context *ctx, const secp256k1_pubkey *pubkey1, const secp256k1_pubkey *pubkey2) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Compare two public keys using lexicographic (of compressed serialization) order.
Definition: secp256k1.c:312
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_seckey_verify(const secp256k1_context *ctx, const unsigned char *seckey) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2)
Verify an elliptic curve secret key.
Definition: secp256k1.c:615
SECP256K1_API secp256k1_context * secp256k1_context_create(unsigned int flags) SECP256K1_WARN_UNUSED_RESULT
Create a secp256k1 context object (in dynamically allocated memory).
Definition: secp256k1.c:143
SECP256K1_API void secp256k1_context_set_illegal_callback(secp256k1_context *ctx, void(*fun)(const char *message, void *data), const void *data) SECP256K1_ARG_NONNULL(1)
Set a callback function to be called when an illegal argument is passed to an API call.
Definition: secp256k1.c:201
SECP256K1_API int secp256k1_ecdsa_sign(const secp256k1_context *ctx, secp256k1_ecdsa_signature *sig, const unsigned char *msghash32, const unsigned char *seckey, secp256k1_nonce_function noncefp, const void *ndata) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(4)
Create an ECDSA signature.
Definition: secp256k1.c:601
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_pubkey_parse(const secp256k1_context *ctx, secp256k1_pubkey *pubkey, const unsigned char *input, size_t inputlen) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Parse a variable-length public key into the pubkey object.
Definition: secp256k1.c:268
#define SECP256K1_CONTEXT_NONE
Context flags to pass to secp256k1_context_create, secp256k1_context_preallocated_size,...
Definition: secp256k1.h:206
SECP256K1_API int secp256k1_ecdsa_signature_parse_der(const secp256k1_context *ctx, secp256k1_ecdsa_signature *sig, const unsigned char *input, size_t inputlen) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Parse a DER ECDSA signature.
Definition: secp256k1.c:395
SECP256K1_API void secp256k1_selftest(void)
Perform basic self tests (to be used in conjunction with secp256k1_context_static)
Definition: secp256k1.c:87
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_pubkey_create(const secp256k1_context *ctx, secp256k1_pubkey *pubkey, const unsigned char *seckey) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Compute the public key for a secret key.
Definition: secp256k1.c:636
#define SECP256K1_EC_COMPRESSED
Flag to pass to secp256k1_ec_pubkey_serialize.
Definition: secp256k1.h:216
struct secp256k1_pubkey secp256k1_pubkey
Opaque data structure that holds a parsed and valid public key.
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ecdsa_verify(const secp256k1_context *ctx, const secp256k1_ecdsa_signature *sig, const unsigned char *msghash32, const secp256k1_pubkey *pubkey) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(4)
Verify an ECDSA signature.
Definition: secp256k1.c:476
SECP256K1_API int secp256k1_tagged_sha256(const secp256k1_context *ctx, unsigned char *hash32, const unsigned char *tag, size_t taglen, const unsigned char *msg, size_t msglen) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(5)
Compute a tagged hash as defined in BIP-340.
Definition: secp256k1.c:815
SECP256K1_API const secp256k1_context *const secp256k1_context_static
A built-in constant secp256k1 context object with static storage duration, to be used in conjunction ...
Definition: secp256k1.h:237
SECP256K1_API int secp256k1_ecdsa_signature_normalize(const secp256k1_context *ctx, secp256k1_ecdsa_signature *sigout, const secp256k1_ecdsa_signature *sigin) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(3)
Convert a signature to a normalized lower-S form.
Definition: secp256k1.c:457
SECP256K1_API secp256k1_context * secp256k1_context_clone(const secp256k1_context *ctx) SECP256K1_ARG_NONNULL(1) SECP256K1_WARN_UNUSED_RESULT
Copy a secp256k1 context object (into dynamically allocated memory).
Definition: secp256k1.c:165
SECP256K1_API void secp256k1_context_set_sha256_compression(secp256k1_context *ctx, secp256k1_sha256_compression_function fn_compression) SECP256K1_ARG_NONNULL(1)
Set a callback function to override the internal SHA256 compression function.
Definition: secp256k1.c:225
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_pubkey_tweak_add(const secp256k1_context *ctx, secp256k1_pubkey *pubkey, const unsigned char *tweak32) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Tweak a public key by adding tweak times the generator to it.
Definition: secp256k1.c:719
#define SECP256K1_EC_UNCOMPRESSED
Definition: secp256k1.h:217
SECP256K1_API int secp256k1_ecdsa_signature_serialize_der(const secp256k1_context *ctx, unsigned char *output, size_t *outputlen, const secp256k1_ecdsa_signature *sig) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3) SECP256K1_ARG_NONNULL(4)
Serialize an ECDSA signature in DER format.
Definition: secp256k1.c:432
struct secp256k1_ecdsa_signature secp256k1_ecdsa_signature
Opaque data structure that holds a parsed ECDSA signature.
SECP256K1_API int secp256k1_ec_pubkey_sort(const secp256k1_context *ctx, const secp256k1_pubkey **pubkeys, size_t n_pubkeys) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2)
Sort public keys using lexicographic (of compressed serialization) order.
Definition: secp256k1.c:344
#define SECP256K1_CONTEXT_VERIFY
Deprecated context flags.
Definition: secp256k1.h:209
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_seckey_tweak_add(const secp256k1_context *ctx, unsigned char *seckey, const unsigned char *tweak32) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Tweak a secret key by adding tweak to it.
Definition: secp256k1.c:696
SECP256K1_API SECP256K1_WARN_UNUSED_RESULT int secp256k1_ec_pubkey_tweak_mul(const secp256k1_context *ctx, secp256k1_pubkey *pubkey, const unsigned char *tweak32) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Tweak a public key by multiplying it by a tweak value.
Definition: secp256k1.c:756
SECP256K1_API int secp256k1_ecdsa_signature_serialize_compact(const secp256k1_context *ctx, unsigned char *output64, const secp256k1_ecdsa_signature *sig) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_ARG_NONNULL(3)
Serialize an ECDSA signature in compact (64 byte) format.
Definition: secp256k1.c:444
SECP256K1_API size_t secp256k1_context_preallocated_clone_size(const secp256k1_context *ctx) SECP256K1_ARG_NONNULL(1) SECP256K1_WARN_UNUSED_RESULT
Determine the memory size of a secp256k1 context object to be copied into caller-provided memory.
Definition: secp256k1.c:113
SECP256K1_API void secp256k1_context_preallocated_destroy(secp256k1_context *ctx) SECP256K1_ARG_NONNULL(1)
Destroy a secp256k1 context object that has been created in caller-provided memory.
Definition: secp256k1.c:178
SECP256K1_API secp256k1_context * secp256k1_context_preallocated_create(void *prealloc, unsigned int flags) SECP256K1_ARG_NONNULL(1) SECP256K1_WARN_UNUSED_RESULT
Create a secp256k1 context object in caller-provided memory.
Definition: secp256k1.c:119
SECP256K1_API size_t secp256k1_context_preallocated_size(unsigned int flags) SECP256K1_WARN_UNUSED_RESULT
Determine the memory size of a secp256k1 context object to be created in caller-provided memory.
Definition: secp256k1.c:93
SECP256K1_API secp256k1_context * secp256k1_context_preallocated_clone(const secp256k1_context *ctx, void *prealloc) SECP256K1_ARG_NONNULL(1) SECP256K1_ARG_NONNULL(2) SECP256K1_WARN_UNUSED_RESULT
Copy a secp256k1 context object into caller-provided memory.
Definition: secp256k1.c:154
secp256k1_scalar * sc
Definition: tests.c:4944
secp256k1_ge * pt
Definition: tests.c:4945
void(* fn)(const char *text, void *data)
Definition: util.h:98
const void * data
Definition: util.h:99
secp256k1_callback illegal_callback
Definition: secp256k1.c:64
secp256k1_callback error_callback
Definition: secp256k1.c:65
secp256k1_ecmult_gen_context ecmult_gen_ctx
Definition: secp256k1.c:62
secp256k1_hash_ctx hash_ctx
Definition: secp256k1.c:63
Opaque data structure that holds a parsed ECDSA signature.
Definition: secp256k1.h:75
unsigned char data[64]
Definition: secp256k1.h:76
secp256k1_scalar scalar_offset
Definition: ecmult_gen.h:128
This field implementation represents the value as 10 uint32_t limbs in base 2^26.
Definition: field_10x26.h:14
uint32_t n[10]
Definition: field_10x26.h:22
A group element in affine coordinates on the secp256k1 curve, or occasionally on an isomorphic curve ...
Definition: group.h:16
int infinity
Definition: group.h:19
secp256k1_fe x
Definition: group.h:17
secp256k1_fe y
Definition: group.h:18
A group element of the secp256k1 curve, in jacobian coordinates.
Definition: group.h:28
secp256k1_fe y
Definition: group.h:30
secp256k1_fe x
Definition: group.h:29
int infinity
Definition: group.h:32
secp256k1_fe z
Definition: group.h:31
secp256k1_sha256_compression_function fn_sha256_compression
Definition: hash.h:16
Opaque data structure that holds a parsed and valid public key.
Definition: secp256k1.h:62
A scalar modulo the group order of the secp256k1 curve.
Definition: scalar_4x64.h:13
size_t alloc_size
amount that has been allocated (i.e.
Definition: scratch.h:19
unsigned char magic[8]
guard against interpreting this object as other types
Definition: scratch.h:14
uint64_t bytes
Definition: hash.h:24
uint32_t s[8]
Definition: hash.h:22
size_t element_len
Definition: tests.c:3889
teardown_fn fn_teardown
Definition: unit_test.h:106
setup_ctx_fn fn_setup
Definition: unit_test.h:105
const struct tf_test_module * registry_no_rng
Definition: unit_test.h:103
const struct tf_test_module * registry_modules
Definition: unit_test.h:99
int num_modules
Definition: unit_test.h:101
Definition: unit_test.h:53
std::vector< uint16_t > keys
Definition: dbwrapper.cpp:376
FastRandomContext rng
Definition: dbwrapper.cpp:413
static void testrand256_test(unsigned char *b32)
Generate a pseudorandom 32-byte array with long sequences of zero and one bits.
static void testrand256(unsigned char *b32)
Generate a pseudorandom 32-byte array.
static SECP256K1_INLINE uint64_t testrand_bits(int bits)
Generate a pseudorandom number in the range [0..2**bits-1].
static uint32_t testrand_int(uint32_t range)
Generate a pseudorandom number in the range [0..range-1].
static SECP256K1_INLINE void testrand_seed(const unsigned char *seed16)
Seed the pseudorandom number generator for testing.
static void testrand_bytes_test(unsigned char *bytes, size_t len)
Generate pseudorandom bytes with long sequences of zero and one bits.
static uint64_t secp256k1_test_state[4]
Definition: testrand_impl.h:18
static void run_random_pubkeys(void)
Definition: tests.c:7095
#define CHECK_ILLEGAL_VOID(ctx, expr_or_stmt)
Definition: tests.c:77
static void run_all_proper_context_tests(void)
Definition: tests.c:361
static void test_wnaf(const secp256k1_scalar *number, int w)
Definition: tests.c:5563
static void run_inverse_tests(void)
Definition: tests.c:3619
static void counting_callback_fn(const char *str, void *data)
Definition: tests.c:88
static void mutate_sign_signed30(secp256k1_modinv32_signed30 *x)
Definition: tests.c:1102
static void ec_pubkey_parse_pointtest(const unsigned char *input, int xvalid, int yvalid)
Definition: tests.c:6009
static const struct tf_test_module registry_modules_no_rng
Definition: tests.c:8021
static void test_ecdsa_sign_verify(void)
Definition: tests.c:6624
static void test_ge(void)
Definition: tests.c:3961
#define CHECK_ERROR_VOID(ctx, expr_or_stmt)
Definition: tests.c:75
static const struct tf_test_entry tests_field[]
Definition: tests.c:8058
static void run_pubkey_comparison(void)
Definition: tests.c:6895
static void run_ecdsa_sign_verify(void)
Definition: tests.c:6649
static void run_field_misc(void)
Definition: tests.c:3303
static void good_sha256_compression(uint32_t *s, const unsigned char *msg, size_t rounds)
Definition: tests.c:448
static void test_ecmult_gen_blind_reset(void)
Definition: tests.c:5919
static void run_ec_pubkey_parse_test(void)
Definition: tests.c:6076
static void run_static_context_tests(int use_prealloc)
Definition: tests.c:197
static void random_sign(secp256k1_scalar *sigr, secp256k1_scalar *sigs, const secp256k1_scalar *key, const secp256k1_scalar *msg, int *recid)
Definition: tests.c:6617
static int nonce_function_test_fail(unsigned char *nonce32, const unsigned char *msg32, const unsigned char *key32, const unsigned char *algo16, void *data, unsigned int counter)
Definition: tests.c:6665
static int nonce_function_test_retry(unsigned char *nonce32, const unsigned char *msg32, const unsigned char *key32, const unsigned char *algo16, void *data, unsigned int counter)
Definition: tests.c:6673
#define SECP256K1_EC_PARSE_TEST_NINVALID
static int test_ecmult_multi_random(secp256k1_scratch *scratch)
Definition: tests.c:5186
static void mulmod256(uint16_t *out, const uint16_t *a, const uint16_t *b, const uint16_t *m)
Definition: tests.c:1000
static const struct tf_test_entry tests_group[]
Definition: tests.c:8069
static void test_sha256_tag_midstate(const secp256k1_hash_ctx *hash_ctx, secp256k1_sha256 *sha_tagged, const unsigned char *tag, size_t taglen)
Definition: tests.c:849
static void ecmult_const_check_result(const secp256k1_ge *A, const secp256k1_scalar *q, const secp256k1_gej *res)
Definition: tests.c:4817
static void test_sort(void)
Definition: tests.c:6998
#define CHECK_ILLEGAL(ctx, expr)
Definition: tests.c:85
static int gej_xyz_equals_gej(const secp256k1_gej *a, const secp256k1_gej *b)
Definition: tests.c:3940
static int ecmult_gen_context_eq(const secp256k1_ecmult_gen_context *a, const secp256k1_ecmult_gen_context *b)
Definition: tests.c:131
static void run_tagged_sha256_tests(void)
Definition: tests.c:942
static void run_sha256_counter_tests(void)
SHA256 counter tests.
Definition: tests.c:778
static void test_fixed_wnaf_small_helper(int *wnaf, int *wnaf_expected, int w)
Definition: tests.c:5633
static int test_hsort_cmp(const void *ele1, const void *ele2, void *data)
Definition: tests.c:3893
static void run_sha256_compression_smoke_test_tests(void)
Definition: tests.c:548
static int all_bytes_equal(const void *s, unsigned char value, size_t n)
Definition: tests.c:51
static void test_fixed_wnaf_small(void)
Definition: tests.c:5643
int main(int argc, char **argv)
Definition: tests.c:8183
static void run_plug_sha256_compression_tests(void)
Definition: tests.c:453
static void run_ecmult_const_tests(void)
Definition: tests.c:4934
static int fe_identical(const secp256k1_fe *a, const secp256k1_fe *b)
Definition: tests.c:3247
#define SECP256K1_EC_PARSE_TEST_NVALID
static void run_eckey_edge_case_test(void)
Definition: tests.c:6361
static int teardown(void)
Definition: tests.c:8177
static void run_pubkey_sort(void)
Definition: tests.c:7088
static void random_fe_non_square(secp256k1_fe *ns)
Definition: tests.c:3123
static void run_secp256k1_byteorder_tests(void)
Definition: tests.c:7832
static void run_ecmult_constants(void)
Definition: tests.c:5843
static void run_field_be32_overflow(void)
Definition: tests.c:3180
static void test_modinv32_uint16(uint16_t *out, const uint16_t *in, const uint16_t *mod)
Definition: tests.c:1117
static void run_ecmult_chain(void)
Definition: tests.c:4541
static const struct tf_test_entry tests_utils[]
Definition: tests.c:8109
static void test_inverse_field(secp256k1_fe *out, const secp256k1_fe *x, int var)
Definition: tests.c:3594
static void run_ec_combine(void)
Definition: tests.c:4414
static const struct tf_test_module registry_modules[]
Definition: tests.c:8118
static void run_deprecated_context_flags_test(void)
Definition: tests.c:148
static secp256k1_context * CTX
Definition: tests.c:48
static void run_point_times_order(void)
Definition: tests.c:4715
static void random_ber_signature(unsigned char *sig, size_t *len, int *certainly_der, int *certainly_not_der)
Definition: tests.c:7208
static void test_sort_vectors(void)
Definition: tests.c:7044
#define CONDITIONAL_TEST(cnt, nam)
Definition: tests.c:46
static void ecmult_const_commutativity(void)
Definition: tests.c:4763
static void int_cmov_test(void)
Definition: tests.c:7860
static const struct tf_test_entry tests_ecdsa[]
Definition: tests.c:8096
static void test_ge_bytes(void)
Definition: tests.c:4310
static void test_add_neg_y_diff_x(void)
Definition: tests.c:4250
static void test_ecmult_accumulate(secp256k1_sha256 *acc, const secp256k1_scalar *x, secp256k1_scratch *scratch)
Definition: tests.c:5724
static void test_point_times_order(const secp256k1_gej *point)
Definition: tests.c:4600
static void assign_big_endian(unsigned char *ptr, size_t ptrlen, uint32_t val)
Definition: tests.c:7169
static const struct tf_test_entry tests_ec[]
Definition: tests.c:8089
static void run_hmac_sha256_tests(void)
Definition: tests.c:855
static int fe_equal(const secp256k1_fe *a, const secp256k1_fe *b)
Definition: tests.c:3131
static void test_ecmult_multi_batch_single(secp256k1_ecmult_multi_func ecmult_multi)
Definition: tests.c:5352
static void signed30_to_uint16(uint16_t *out, const secp256k1_modinv32_signed30 *in)
Definition: tests.c:1093
static void run_secp256k1_is_zero_array_test(void)
Definition: tests.c:7821
static void run_fe_equal_magnitude_boundaries(void)
Definition: tests.c:3138
static const struct tf_test_entry tests_no_rng[]
Definition: tests.c:8018
static int is_empty_signature(const secp256k1_ecdsa_signature *sig)
Definition: tests.c:6697
static void run_field_half(void)
Definition: tests.c:3254
static void run_eckey_negate_test(void)
Definition: tests.c:6587
static void scalar_test(void)
Definition: tests.c:2262
static void run_scalar_set_b32_seckey_tests(void)
Definition: tests.c:2417
static void test_ecmult_multi(secp256k1_scratch *scratch, secp256k1_ecmult_multi_func ecmult_multi)
Definition: tests.c:4963
static void run_hsort_tests(void)
Definition: tests.c:3930
static int precomputed_nonce_function(unsigned char *nonce32, const unsigned char *msg32, const unsigned char *key32, const unsigned char *algo16, void *data, unsigned int counter)
Dummy nonce generation function that just uses a precomputed nonce, and fails if it is not accepted.
Definition: tests.c:6657
static void test_hsort_is_sorted(unsigned char *elements, size_t n, size_t len)
Definition: tests.c:3880
static void run_gej(void)
Definition: tests.c:4356
static const struct tf_test_entry tests_integer[]
Definition: tests.c:8036
static void run_ge(void)
Definition: tests.c:4338
#define MAX_ELEMENT_LEN
Definition: tests.c:3900
static void ge_storage_cmov_test(void)
Definition: tests.c:7973
static const secp256k1_scalar scalar_minus_one
Definition: tests.c:3555
static void fe_storage_cmov_test(void)
Definition: tests.c:7915
static void test_ec_combine(void)
Definition: tests.c:4392
static void test_secp256k1_pippenger_bucket_window_inv(void)
Definition: tests.c:5370
static void test_ecmult_gen_edge_cases(void)
Definition: tests.c:5933
static void run_ctz_tests(void)
Definition: tests.c:655
static void test_sort_helper(secp256k1_pubkey *pk, size_t *pk_order, size_t n_pk)
Definition: tests.c:6940
static void test_ecmult_multi_pippenger_max_points(void)
Probabilistically test the function returning the maximum number of possible points for a given scrat...
Definition: tests.c:5390
static void run_scalar_tests(void)
Definition: tests.c:2481
static void test_random_pubkeys(void)
Definition: tests.c:6833
static void test_gej_cmov(const secp256k1_gej *a, const secp256k1_gej *b)
Definition: tests.c:4348
static void test_heap_swap(void)
Definition: tests.c:3867
static void test_sqrt(const secp256k1_fe *a, const secp256k1_fe *k)
Definition: tests.c:3503
static void scalar_cmov_test(void)
Definition: tests.c:7945
static const struct tf_test_entry tests_hash[]
Definition: tests.c:8045
static void run_ecmult_gen_blind(void)
Definition: tests.c:5951
static void test_ecdsa_end_to_end(void)
Definition: tests.c:6702
static const struct tf_test_entry tests_ecmult[]
Definition: tests.c:8075
static void run_sha256_known_output_tests(void)
Definition: tests.c:676
static void test_ecmult_target(const secp256k1_scalar *target, int mode)
Definition: tests.c:4665
#define NUM
Definition: tests.c:3899
#define CHECK_ERROR(ctx, expr)
Definition: tests.c:86
static void run_ecdsa_end_to_end(void)
Definition: tests.c:7102
static int ecmult_multi_callback(secp256k1_scalar *sc, secp256k1_ge *pt, size_t idx, void *cbdata)
Definition: tests.c:4948
static void ecmult_const_mult_xonly(void)
Definition: tests.c:4853
static void run_proper_context_tests(int use_prealloc)
Definition: tests.c:241
static const struct tf_test_entry tests_general[]
Definition: tests.c:8024
static void test_fe_mul(const secp256k1_fe *a, const secp256k1_fe *b, int use_sqr)
Definition: tests.c:3410
static void test_group_decompress(const secp256k1_fe *x)
Definition: tests.c:4421
static void test_scalar_check_overflow(void)
Definition: tests.c:2434
static void test_ecmult_constants_2bit(void)
Definition: tests.c:5755
static void run_cmov_tests(void)
Definition: tests.c:8005
static void permute(size_t *arr, size_t n)
Definition: tests.c:6953
static void sha256_transform_ivreset(uint32_t *s, const unsigned char *chunk, size_t blocks)
Definition: tests.c:503
static void run_sha256_multi_block_compression_tests(void)
Definition: tests.c:562
static const struct tf_test_entry tests_scalar[]
Definition: tests.c:8054
static void test_initialized_inf(void)
Definition: tests.c:4218
static void run_ecdsa_der_parse(void)
Definition: tests.c:7354
static void ecmult_const_random_mult(void)
Definition: tests.c:4736
static void sha256_transform_batch4(uint32_t *s, const unsigned char *chunk, size_t blocks)
Definition: tests.c:511
static void test_scalar_split(const secp256k1_scalar *full)
Definition: tests.c:5961
static void run_field_convert(void)
Definition: tests.c:3150
static int test_ecdsa_der_parse(const unsigned char *sig, size_t siglen, int certainly_der, int certainly_not_der)
Definition: tests.c:7109
static void run_ec_illegal_argument_tests(void)
Definition: tests.c:166
static void run_ecdsa_wycheproof(void)
Definition: tests.c:7773
static void test_ecmult_constants_sha(uint32_t prefix, size_t iter, const unsigned char *expected32)
Definition: tests.c:5799
static void invalid_sha256_compression(uint32_t *s, const unsigned char *msg, size_t rounds)
Definition: tests.c:443
static void test_ecmult_multi_batching(void)
Run secp256k1_ecmult_multi_var with num points and a scratch space restricted to 1 <= i <= num points...
Definition: tests.c:5471
static void run_all_static_context_tests(void)
Definition: tests.c:235
static void sha256_transform_noadvance(uint32_t *s, const unsigned char *chunk, size_t blocks)
Definition: tests.c:490
static void run_sqrt(void)
Definition: tests.c:3517
static void sha256_transform_corrupt(uint32_t *s, const unsigned char *chunk, size_t blocks)
Definition: tests.c:516
static void run_modinv_tests(void)
Definition: tests.c:1298
static const secp256k1_scalar scalars_near_split_bounds[20]
Definition: tests.c:4642
static void uint16_to_signed30(secp256k1_modinv32_signed30 *out, const uint16_t *in)
Definition: tests.c:1084
static void run_xoshiro256pp_tests(void)
Definition: tests.c:97
static void run_wnaf(void)
Definition: tests.c:5697
static void run_ecmult_multi_tests(void)
Definition: tests.c:5536
static void run_selftest_tests(void)
Definition: tests.c:126
static int coprime(const uint16_t *a, const uint16_t *b)
Definition: tests.c:1268
static void run_sqr(void)
Definition: tests.c:3474
static int context_eq(const secp256k1_context *a, const secp256k1_context *b)
Definition: tests.c:138
static void test_ecmult_multi_batch_size_helper(void)
Definition: tests.c:5423
static void sha256_transform_short(uint32_t *s, const unsigned char *chunk, size_t blocks)
Definition: tests.c:498
static void run_endomorphism_tests(void)
Definition: tests.c:5988
static void run_scratch_tests(void)
Definition: tests.c:367
static void test_ecdsa_wycheproof(void)
Wycheproof tests.
Definition: tests.c:7742
static void run_ecmult_near_split_bound(void)
Definition: tests.c:4703
static void run_ecdsa_edge_cases(void)
Definition: tests.c:7386
static void fe_cmov_test(void)
Definition: tests.c:7885
static void run_group_decompress(void)
Definition: tests.c:4456
static void ecmult_const_mult_zero_one(void)
Definition: tests.c:4784
static int test_ecmult_accumulate_cb(secp256k1_scalar *sc, secp256k1_ge *pt, size_t idx, void *data)
Definition: tests.c:5716
static void ecmult_const_edges(void)
Definition: tests.c:4826
static void run_sha256_initialize_midstate_tests(void)
Definition: tests.c:966
static void ecmult_const_chain_multiply(void)
Definition: tests.c:4908
static void run_ecmult_pre_g(void)
Definition: tests.c:4517
static int ecmult_multi_false_callback(secp256k1_scalar *sc, secp256k1_ge *pt, size_t idx, void *cbdata)
Definition: tests.c:4955
static void test_sha256_eq(const secp256k1_sha256 *sha1, const secp256k1_sha256 *sha2)
Definition: tests.c:840
static void test_pre_g_table(const secp256k1_ge_storage *pre_g, size_t n)
Definition: tests.c:4467
static void test_hsort(size_t element_len)
Definition: tests.c:3901
static void test_sort_api(void)
Definition: tests.c:6964
static void run_invalid_scratch_space_tests(void)
Definition: tests.c:428
static int setup(void)
Definition: tests.c:8154
static secp256k1_context * STATIC_CTX
Definition: tests.c:49
static void test_fixed_wnaf(const secp256k1_scalar *number, int w)
Definition: tests.c:5597
static void test_inverse_scalar(secp256k1_scalar *out, const secp256k1_scalar *x, int var)
Definition: tests.c:3572
static void test_ecmult_gen_blind(void)
Definition: tests.c:5896
static void run_ecmult_gen_ge(void)
Definition: tests.c:5877
static void run_secp256k1_memczero_test(void)
Definition: tests.c:7805
static int own_transform_called
Definition: tests.c:447
static void run_fe_mul(void)
Definition: tests.c:3453
#define SECP256K1_EC_PARSE_TEST_NXVALID
static void damage_array(unsigned char *sig, size_t *len)
Definition: tests.c:7181
static void ecdsa_ctx_sha256(void)
Definition: tests.c:7718
static const secp256k1_fe fe_minus_one
Definition: tests.c:3560
static void run_rfc6979_hmac_sha256_tests(void)
Definition: tests.c:900
static uint64_t modinv2p64(uint64_t x)
Definition: tests.c:983
static void testutil_random_fe_test(secp256k1_fe *x)
Definition: testutil.h:63
static void testutil_random_pubkey_test(secp256k1_pubkey *pk)
Definition: testutil.h:123
static void testutil_random_gej_y_magnitude(secp256k1_gej *gej)
Definition: testutil.h:91
static const unsigned char secp256k1_group_order_bytes[32]
Definition: testutil.h:24
static void testutil_random_fe_non_zero(secp256k1_fe *nz)
Definition: testutil.h:41
static void testutil_random_scalar_order(secp256k1_scalar *num)
Definition: testutil.h:142
#define DEFINE_SHA256_TRANSFORM_PROBE(name)
Definition: testutil.h:15
static void testutil_random_gej_test(secp256k1_gej *gej)
Definition: testutil.h:117
static void testutil_random_scalar_order_test(secp256k1_scalar *num)
Definition: testutil.h:129
static void testutil_random_scalar_order_b32(unsigned char *b32)
Definition: testutil.h:155
static void testutil_random_fe(secp256k1_fe *x)
Definition: testutil.h:31
static void testutil_random_fe_non_zero_test(secp256k1_fe *fe)
Definition: testutil.h:73
static void testutil_random_gej_x_magnitude(secp256k1_gej *gej)
Definition: testutil.h:87
static void testutil_random_fe_magnitude(secp256k1_fe *fe, int m)
Definition: testutil.h:47
static void testutil_random_ge_x_magnitude(secp256k1_ge *ge)
Definition: testutil.h:79
static void testutil_random_gej_z_magnitude(secp256k1_gej *gej)
Definition: testutil.h:95
static void testutil_random_ge_test(secp256k1_ge *ge)
Definition: testutil.h:99
static void testutil_random_ge_y_magnitude(secp256k1_ge *ge)
Definition: testutil.h:83
static void testutil_random_ge_jacobian_test(secp256k1_gej *gej, const secp256k1_ge *ge)
Definition: testutil.h:110
int COUNT
Definition: unit_test.c:28
static int tf_init(struct tf_framework *tf, int argc, char **argv)
Definition: unit_test.c:354
static int tf_run(struct tf_framework *tf)
Definition: unit_test.c:416
#define CASE1(name)
Definition: unit_test.h:27
#define CASE(name)
Definition: unit_test.h:26
#define MAKE_TEST_MODULE(name)
Definition: unit_test.h:29
#define expect(bit)