X-Git-Url: https://bearssl.org/gitweb//home/git/?p=BearSSL;a=blobdiff_plain;f=src%2Fint%2Fi15_mulacc.c;h=69f4696ba4fd324da013bf43a936d36b579ac475;hp=7bde395df7e96ec7a450321515109b050d69eace;hb=c1e540575c63e09e6ab25c0c7826601d77b18d97;hpb=2f454aad577ae53798935cc32438a2d3f02ba31f diff --git a/src/int/i15_mulacc.c b/src/int/i15_mulacc.c index 7bde395..69f4696 100644 --- a/src/int/i15_mulacc.c +++ b/src/int/i15_mulacc.c @@ -29,10 +29,19 @@ void br_i15_mulacc(uint16_t *d, const uint16_t *a, const uint16_t *b) { size_t alen, blen, u; + unsigned dl, dh; alen = (a[0] + 15) >> 4; blen = (b[0] + 15) >> 4; - d[0] = a[0] + b[0]; + + /* + * Announced bit length of d[] will be the sum of the announced + * bit lengths of a[] and b[]; but the lengths are encoded. + */ + dl = (a[0] & 15) + (d[0] & 15); + dh = (a[0] >> 4) + (b[0] >> 4); + d[0] = (dh << 4) + dl + (~(uint16_t)(dl - 15) >> 15); + for (u = 0; u < blen; u ++) { uint32_t f; size_t v;