field: correct fe_equal's b magnitude bound
`secp256k1_fe_equal` negates `a` before adding `b`. That gives the temporary value magnitude 2, and the following field addition requires the input magnitudes to sum to at most 32. So the largest `b` magnitude the implementation can accept is 30, not 31. Lower the documented and checked bound for `b` to 30. Adjust the focused test to use random field elements with randomized magnitudes within the accepted `a <= 1` and `b <= 30` bounds. Co-authored-by: Sebastian Falbesoner <sebastian.falbesoner@gmail.com> Co-authored-by: Tim Ruffing <me@real-or-random.org>
This commit is contained in:
@@ -166,7 +166,7 @@ static int secp256k1_fe_is_odd(const secp256k1_fe *a);
|
||||
/** Determine whether two field elements are equal.
|
||||
*
|
||||
* On input, a and b must be valid field elements with magnitudes not exceeding
|
||||
* 1 and 31, respectively.
|
||||
* 1 and 30, respectively.
|
||||
* Returns a = b (mod p).
|
||||
*/
|
||||
static int secp256k1_fe_equal(const secp256k1_fe *a, const secp256k1_fe *b);
|
||||
|
||||
Reference in New Issue
Block a user