{"id":2224489,"url":"http://patchwork.ozlabs.org/api/patches/2224489/?format=json","web_url":"http://patchwork.ozlabs.org/project/uboot/patch/20260417130204.49896-3-philippe.reynes@softathome.com/","project":{"id":18,"url":"http://patchwork.ozlabs.org/api/projects/18/?format=json","name":"U-Boot","link_name":"uboot","list_id":"u-boot.lists.denx.de","list_email":"u-boot@lists.denx.de","web_url":null,"scm_url":null,"webscm_url":null,"list_archive_url":"","list_archive_url_format":"","commit_url_format":""},"msgid":"<20260417130204.49896-3-philippe.reynes@softathome.com>","list_archive_url":null,"date":"2026-04-17T13:01:52","name":"[v4,02/14] ecdsa: initial support of ecdsa using mbedtls","commit_ref":null,"pull_url":null,"state":"superseded","archived":false,"hash":"dd5d61c71fd773bf8ae6a00c9d74ab588b6d2cff","submitter":{"id":74351,"url":"http://patchwork.ozlabs.org/api/people/74351/?format=json","name":"Philippe Reynes","email":"philippe.reynes@softathome.com"},"delegate":{"id":161313,"url":"http://patchwork.ozlabs.org/api/users/161313/?format=json","username":"raymo200915","first_name":"Raymond","last_name":"Mao","email":"raymondmaoca@gmail.com"},"mbox":"http://patchwork.ozlabs.org/project/uboot/patch/20260417130204.49896-3-philippe.reynes@softathome.com/mbox/","series":[{"id":500332,"url":"http://patchwork.ozlabs.org/api/series/500332/?format=json","web_url":"http://patchwork.ozlabs.org/project/uboot/list/?series=500332","date":"2026-04-17T13:02:04","name":"add software ecdsa support","version":4,"mbox":"http://patchwork.ozlabs.org/series/500332/mbox/"}],"comments":"http://patchwork.ozlabs.org/api/patches/2224489/comments/","check":"pending","checks":"http://patchwork.ozlabs.org/api/patches/2224489/checks/","tags":{},"related":[],"headers":{"Return-Path":"<u-boot-bounces@lists.denx.de>","X-Original-To":"incoming@patchwork.ozlabs.org","Delivered-To":"patchwork-incoming@legolas.ozlabs.org","Authentication-Results":["legolas.ozlabs.org;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=softathome1.onmicrosoft.com header.i=@softathome1.onmicrosoft.com\n header.a=rsa-sha256 header.s=selector1-softathome1-onmicrosoft-com\n header.b=Oe5vKxHw;\n\tdkim-atps=neutral","legolas.ozlabs.org;\n spf=pass (sender SPF authorized) smtp.mailfrom=lists.denx.de\n (client-ip=2a01:238:438b:c500:173d:9f52:ddab:ee01; helo=phobos.denx.de;\n envelope-from=u-boot-bounces@lists.denx.de; receiver=patchwork.ozlabs.org)","phobos.denx.de;\n dmarc=none (p=none dis=none) header.from=softathome.com","phobos.denx.de;\n spf=pass smtp.mailfrom=u-boot-bounces@lists.denx.de","phobos.denx.de;\n\tdkim=pass (2048-bit key;\n unprotected) header.d=softathome1.onmicrosoft.com header.i=@softathome1.onmicrosoft.com\n header.b=\"Oe5vKxHw\";\n\tdkim-atps=neutral","phobos.denx.de; dmarc=none (p=none dis=none)\n header.from=softathome.com","phobos.denx.de;\n spf=pass smtp.mailfrom=philippe.reynes@softathome.com"],"Received":["from phobos.denx.de (phobos.denx.de\n [IPv6:2a01:238:438b:c500:173d:9f52:ddab:ee01])\n\t(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)\n\t key-exchange x25519)\n\t(No client certificate requested)\n\tby legolas.ozlabs.org (Postfix) with ESMTPS id 4fxw7w1VLxz1yCv\n\tfor <incoming@patchwork.ozlabs.org>; Fri, 17 Apr 2026 23:04:28 +1000 (AEST)","from h2850616.stratoserver.net (localhost [IPv6:::1])\n\tby phobos.denx.de (Postfix) with ESMTP id D4763843C3;\n\tFri, 17 Apr 2026 15:02:23 +0200 (CEST)","by phobos.denx.de (Postfix, from userid 109)\n id 5F8C384320; Fri, 17 Apr 2026 15:02:21 +0200 (CEST)","from PR0P264CU014.outbound.protection.outlook.com\n (mail-francecentralazlp170120004.outbound.protection.outlook.com\n [IPv6:2a01:111:f403:c20a::4])\n (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits))\n (No client certificate requested)\n by phobos.denx.de (Postfix) with ESMTPS id 6DF2684326\n for <u-boot@lists.denx.de>; Fri, 17 Apr 2026 15:02:18 +0200 (CEST)","from PR1P264CA0180.FRAP264.PROD.OUTLOOK.COM (2603:10a6:102:344::9)\n by MR1PPF5FEA73388.FRAP264.PROD.OUTLOOK.COM (2603:10a6:508:1::64b) with\n Microsoft SMTP Server (version=TLS1_2,\n cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9769.48; Fri, 17 Apr\n 2026 13:02:10 +0000","from PA2PEPF00019231.FRAP264.PROD.OUTLOOK.COM\n (2603:10a6:102:344:cafe::a7) by PR1P264CA0180.outlook.office365.com\n (2603:10a6:102:344::9) with Microsoft SMTP Server (version=TLS1_3,\n cipher=TLS_AES_256_GCM_SHA384) id 15.20.9769.52 via Frontend Transport; Fri,\n 17 Apr 2026 13:02:10 +0000","from proxy.softathome.com (149.6.166.170) by\n PA2PEPF00019231.mail.protection.outlook.com (10.167.242.37) with Microsoft\n SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.20.9769.17\n via Frontend Transport; Fri, 17 Apr 2026 13:02:09 +0000","from sah1lpt726.home (unknown [192.168.72.39])\n by proxy.softathome.com (Postfix) with ESMTPSA id AD52720C30;\n Fri, 17 Apr 2026 15:02:09 +0200 (CEST)"],"X-Spam-Checker-Version":"SpamAssassin 3.4.2 (2018-09-13) on phobos.denx.de","X-Spam-Level":"","X-Spam-Status":"No, score=-1.9 required=5.0 tests=BAYES_00,DKIM_SIGNED,\n DKIM_VALID,RCVD_IN_DNSWL_BLOCKED,SPF_HELO_PASS,SPF_PASS autolearn=ham\n autolearn_force=no version=3.4.2","ARC-Seal":"i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;\n b=zNqXOan3JCFcxAuoqb/oUd6GC1+2/A7a2GSjVonCbrdDlemxXDnauEVrJkBUSNVWxGD11XvoahP46iUEI0zrAr73a7dddRDUG5YJde/6u7/TdLQEgJsW0xilaaNK5X1qZzIB/fIqSiS51cTuy5MkvRnDDB1AkLbodFOo5LJL+enbOoobWw0qZlUu2mwob9Kt4xXjO+Fm95dCmJDx6IophcKtQOCwLPdBzsfcwpQaJ6ZjUcW4/S2LEQkxkxcw0x6qDnUYxy3z6rP+XXxaF3lPx5k0oE8/nGby9WrB5WQdEt9ByGAvY5H6wvaub+5luBfEeoEoUjuj6LeNGn79LXYsjA==","ARC-Message-Signature":"i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;\n s=arcselector10001;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;\n bh=ri0B6qHd1MC0/vpR1HnihbjRsZs9sZYbjoAhZ9itX0o=;\n b=P1hRbPkn78t3AdH0gtrr4kULnyVpCR9jpJFA70+qXvW0KsFUT1+7i5MVbEQcalyes+k9p3zTG3HxjnruxSS1iCrNsFZI4AT4HldqZaYa8sX1pI++QSVsCGXeBY4YYyP8NvVh/XiSKCE3Dp3t6fNfwWn+hvc3x/NkLoiTZ1uP17Q9K1zcK10aAiYESmfQOrqxZT6s9v5Q7ZsTBbh1QzIEM7ue2t05lAbyGrP9HSmhb8bAGwVoz5SKj/gXuezsGnZLODTo+CYxruURi0nYidZAKHz/RvgT6mEXgrag0vlry/8dX2i65YPAS2R+SiRwxdZzSTt6CHDl/pHPAnf7kTGsQw==","ARC-Authentication-Results":"i=1; mx.microsoft.com 1; spf=pass (sender ip is\n 149.6.166.170) smtp.rcpttodomain=canonical.com smtp.mailfrom=softathome.com;\n dmarc=bestguesspass action=none header.from=softathome.com; dkim=none\n (message not signed); arc=none (0)","DKIM-Signature":"v=1; a=rsa-sha256; c=relaxed/relaxed;\n d=softathome1.onmicrosoft.com; s=selector1-softathome1-onmicrosoft-com;\n h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;\n bh=ri0B6qHd1MC0/vpR1HnihbjRsZs9sZYbjoAhZ9itX0o=;\n b=Oe5vKxHwE2nLpAOfxjb99gHLUwElyoZCoHT3khwAfXhbPFyGj7HoA/iqKK+cRBAyvUHXlRqcfFnmfe9hHX/GEotqmLTf9wb5k7ZJAk7MANMtzVBJyp7LrrJzd/+ljlEdUkXWdvziHQ2XAgxcg5kMOQDXrnR/rqVRFAE326JXsyzLplTWIngnUPDLakK7TIGs7W2aM5AKdk7Fwm9ZUBxdzxGUaSNGUUN5cZ/+NBcJ+9KnWfOLcQVmjy87lyxiehdFBcOJkM6lGgRgQZqB6l6ZmMdZNRiKs+tSIMLLaAIgRpZR7D78lMYBEbkZzpASgczaXSaepwAwPhryzuEQTPGxKA==","X-MS-Exchange-Authentication-Results":"spf=pass (sender IP is 149.6.166.170)\n smtp.mailfrom=softathome.com; dkim=none (message not signed)\n header.d=none;dmarc=bestguesspass action=none header.from=softathome.com;","Received-SPF":"Pass (protection.outlook.com: domain of softathome.com\n designates 149.6.166.170 as permitted sender)\n receiver=protection.outlook.com; client-ip=149.6.166.170;\n helo=proxy.softathome.com; pr=C","From":"Philippe Reynes <philippe.reynes@softathome.com>","To":"marko.makela@iki.fi, jonny.green@keytechinc.com, raymondmaoca@gmail.com,\n trini@konsulko.com, simon.glass@canonical.com","Cc":"u-boot@lists.denx.de,\n\tPhilippe Reynes <philippe.reynes@softathome.com>","Subject":"[PATCH v4 02/14] ecdsa: initial support of ecdsa using mbedtls","Date":"Fri, 17 Apr 2026 15:01:52 +0200","Message-ID":"<20260417130204.49896-3-philippe.reynes@softathome.com>","X-Mailer":"git-send-email 2.43.0","In-Reply-To":"<20260417130204.49896-1-philippe.reynes@softathome.com>","References":"<20260417130204.49896-1-philippe.reynes@softathome.com>","MIME-Version":"1.0","Content-Transfer-Encoding":"8bit","X-EOPAttributedMessage":"0","X-MS-PublicTrafficType":"Email","X-MS-TrafficTypeDiagnostic":"PA2PEPF00019231:EE_|MR1PPF5FEA73388:EE_","Content-Type":"text/plain","X-MS-Office365-Filtering-Correlation-Id":"e0d456a0-d948-4818-fd29-08de9c81891e","X-MS-Exchange-SenderADCheck":"1","X-MS-Exchange-AntiSpam-Relay":"0","X-Microsoft-Antispam":"BCL:0;\n ARA:13230040|36860700016|376014|1800799024|82310400026|22082099003|18002099003|56012099003;","X-Microsoft-Antispam-Message-Info":"\n qC63BeXUKPI4UtJJVbdo1EkkAbNRNEyxirm6ehra+088ErcOA8wGlBmvlpeQ63zS2Ab9EokQYdV/VLeNZdD7kMFdse7KnAPDc60Fq2vIJuAQGz7Vktd0KCue/h/00MKz1aVCTa/PiOyfZCkYslfPwgGgWlGH6ZnsNsE2r+kQc1qj3auBfaPfo3oxbduB8a6IRawoLnMc+GZUbWGgj3OhWqCrm7ubT2MSlSIcH3AeUWydn1LaI+8HyQJVo3AdjBaCL/M0Ims+VLWqxaVZOa44WnWBD0uuS+CjUZACtcE4Mm8XPxuuGAjB7/mXq/yx7kkCOZgQS1+AVmBZ+00kKTb8dLa/Ub7iC7FrWszu+YW1RAn6Oe5QJDYTTEUy8Rga7sASXWozzbKxFTFi+d24B/u2dVTbXwCp7rRmJGx+2+KCoUiCXRvAVEFIymzAJCBnmTQ/ZbtIjcGg7pwRi8Dlh35TabCDeJh2kKoNj5+iNUqlGPMOCu4OydCvXbXea2HvXAGGn8ucM0GSCDDdbJTCAHDRhGqTPlsYbST6vEmoDV+M+2Nl6ARrKZGpU5jwYCbBRH1lJaH4Ou2oEV96XDzV0kg0Qs6/yeEW2n5HD6fno5zQMhD3Q2zwpQM3V/3okeXHl9c0tDlPl6RYaSh+ObWB74oZpro7QRtMKJ1EJmEzQmVC/lK8r5YNVhsf5LpKHf0NpCcmrcgmllIVZ6GEkzMBgY0QO6Hd+N1LJ0vWfkY+MYbHY3W2Sfaf8xrRZ6wgFhMFD9Wwcykm/FkovVIefCAO1UVo5g==","X-Forefront-Antispam-Report":"CIP:149.6.166.170; CTRY:FR; LANG:en; SCL:1; SRV:;\n IPV:CAL; SFV:NSPM; H:proxy.softathome.com; PTR:InfoDomainNonexistent;\n CAT:NONE;\n SFS:(13230040)(36860700016)(376014)(1800799024)(82310400026)(22082099003)(18002099003)(56012099003);\n DIR:OUT; SFP:1101;","X-MS-Exchange-AntiSpam-MessageData-ChunkCount":"1","X-MS-Exchange-AntiSpam-MessageData-0":"\n x4B/HbeeXtpw8zpicH6tlTcNkBchJvxsil44s5Xj6fuusmgk0YE5R7Q++I7qECxVVBj/I/t6ZiA7E375dYYbR/7NZOXlmiT2rn/wsqkQUZMcEavPNA0qtu4kUW5c0MPndn5dZPa9KoaXAAba+bhWoXVYmBh00BXbDxJ9giSi+DXCkNDewXIktO+TZoyYz4b7s9e0g51j47/Vkp6iEhghV8zC3S0whW4qyqdSAAQLgDY8I/UF9DSiNOElSipS/dKkrv5jRE4YWsOi5I1VE2en4pcJ1tz2z6bAMf+mBIOPKY99PnCcZkvTOLwb5sz+IZu2wyq99WtaqeDySHcFErkkvGgfuzPymXCXRhaYW+Ys4+BiMdcWhnJnmOCuFBdkExfaOZBdpifHfs+xkInchSqjHPboDZ0nqYqnz29/+g+4Vtfeb6p8Aj5x/zyFYmRWpH7n","X-OriginatorOrg":"softathome.com","X-MS-Exchange-CrossTenant-OriginalArrivalTime":"17 Apr 2026 13:02:09.8324 (UTC)","X-MS-Exchange-CrossTenant-Network-Message-Id":"\n e0d456a0-d948-4818-fd29-08de9c81891e","X-MS-Exchange-CrossTenant-Id":"aa10e044-e405-4c10-8353-36b4d0cce511","X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp":"\n TenantId=aa10e044-e405-4c10-8353-36b4d0cce511; Ip=[149.6.166.170];\n Helo=[proxy.softathome.com]","X-MS-Exchange-CrossTenant-AuthSource":"PA2PEPF00019231.FRAP264.PROD.OUTLOOK.COM","X-MS-Exchange-CrossTenant-AuthAs":"Anonymous","X-MS-Exchange-CrossTenant-FromEntityHeader":"HybridOnPrem","X-MS-Exchange-Transport-CrossTenantHeadersStamped":"MR1PPF5FEA73388","X-BeenThere":"u-boot@lists.denx.de","X-Mailman-Version":"2.1.39","Precedence":"list","List-Id":"U-Boot discussion <u-boot.lists.denx.de>","List-Unsubscribe":"<https://lists.denx.de/options/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=unsubscribe>","List-Archive":"<https://lists.denx.de/pipermail/u-boot/>","List-Post":"<mailto:u-boot@lists.denx.de>","List-Help":"<mailto:u-boot-request@lists.denx.de?subject=help>","List-Subscribe":"<https://lists.denx.de/listinfo/u-boot>,\n <mailto:u-boot-request@lists.denx.de?subject=subscribe>","Errors-To":"u-boot-bounces@lists.denx.de","Sender":"\"U-Boot\" <u-boot-bounces@lists.denx.de>","X-Virus-Scanned":"clamav-milter 0.103.8 at phobos.denx.de","X-Virus-Status":"Clean"},"content":"Adds an initial support of ecdsa verify using mbedtls.\n\nSigned-off-by: Philippe Reynes <philippe.reynes@softathome.com>\n---\nv2:\n- rename sw_ecdsa.c to ecdsa.c\nv3:\n- rename sw_ecdsa_verify to ecdsa_hash_verify\n- stop on first group found\n- check signature len\n- use debug instead of printf\n- check function returns\n- fix memleaks in ecdsa_hash_verify\nv4:\n- move struct ecdsa_public_key from ecdsa-u-class.h to internal/ecdsa.h\n- use DIV_ROUND_UP\n- some code cleanup\n\n include/crypto/ecdsa-uclass.h   |  15 +---\n include/crypto/internal/ecdsa.h |  28 ++++++\n lib/mbedtls/Makefile            |   3 +\n lib/mbedtls/ecdsa.c             | 146 ++++++++++++++++++++++++++++++++\n 4 files changed, 178 insertions(+), 14 deletions(-)\n create mode 100644 include/crypto/internal/ecdsa.h\n create mode 100644 lib/mbedtls/ecdsa.c","diff":"diff --git a/include/crypto/ecdsa-uclass.h b/include/crypto/ecdsa-uclass.h\nindex 189843820a0..047a5eda2fc 100644\n--- a/include/crypto/ecdsa-uclass.h\n+++ b/include/crypto/ecdsa-uclass.h\n@@ -4,20 +4,7 @@\n  */\n \n #include <dm/device.h>\n-\n-/**\n- * struct ecdsa_public_key - ECDSA public key properties\n- *\n- * The struct has pointers to the (x, y) curve coordinates to an ECDSA public\n- * key, as well as the name of the ECDSA curve. The size of the key is inferred\n- * from the 'curve_name'\n- */\n-struct ecdsa_public_key {\n-\tconst char *curve_name;\t/* Name of curve, e.g. \"prime256v1\" */\n-\tconst void *x;\t\t/* x coordinate of public key */\n-\tconst void *y;\t\t/* y coordinate of public key */\n-\tunsigned int size_bits;\t/* key size in bits, derived from curve name */\n-};\n+#include <crypto/internal/ecdsa.h>\n \n struct ecdsa_ops {\n \t/**\ndiff --git a/include/crypto/internal/ecdsa.h b/include/crypto/internal/ecdsa.h\nnew file mode 100644\nindex 00000000000..bfdc137091e\n--- /dev/null\n+++ b/include/crypto/internal/ecdsa.h\n@@ -0,0 +1,28 @@\n+/* SPDX-License-Identifier: GPL-2.0+ */\n+/*\n+ * Copyright (c) 2026, Philippe Reynes <philippe.reynes@softathome.com>\n+ */\n+#ifndef _ECDSA_HELPER_\n+#define _ECDSA_HELPER_\n+\n+#include <linux/types.h>\n+\n+/**\n+ * struct ecdsa_public_key - ECDSA public key properties\n+ *\n+ * The struct has pointers to the (x, y) curve coordinates to an ECDSA public\n+ * key, as well as the name of the ECDSA curve. The size of the key is inferred\n+ * from the 'curve_name'\n+ */\n+struct ecdsa_public_key {\n+\tconst char *curve_name;\t/* Name of curve, e.g. \"prime256v1\" */\n+\tconst void *x;\t\t/* x coordinate of public key */\n+\tconst void *y;\t\t/* y coordinate of public key */\n+\tunsigned int size_bits;\t/* key size in bits, derived from curve name */\n+};\n+\n+int ecdsa_hash_verify(const struct ecdsa_public_key *pubkey,\n+\t\t      const void *hash, size_t hash_len,\n+\t\t      const void *signature, size_t sig_len);\n+\n+#endif\ndiff --git a/lib/mbedtls/Makefile b/lib/mbedtls/Makefile\nindex aa1ca6d196b..d872c0eb788 100644\n--- a/lib/mbedtls/Makefile\n+++ b/lib/mbedtls/Makefile\n@@ -11,6 +11,9 @@ obj-$(CONFIG_$(PHASE_)SHA1_MBEDTLS) += sha1.o\n obj-$(CONFIG_$(PHASE_)SHA256_MBEDTLS) += sha256.o\n obj-$(CONFIG_$(PHASE_)SHA512_MBEDTLS) += sha512.o\n \n+# shim layer for ecdsa\n+obj-$(CONFIG_$(PHASE_)ECDSA_MBEDTLS) += ecdsa.o\n+\n # x509 libraries\n obj-$(CONFIG_$(PHASE_)ASYMMETRIC_PUBLIC_KEY_MBEDTLS) += \\\n \tpublic_key.o\ndiff --git a/lib/mbedtls/ecdsa.c b/lib/mbedtls/ecdsa.c\nnew file mode 100644\nindex 00000000000..a87b0d0e17f\n--- /dev/null\n+++ b/lib/mbedtls/ecdsa.c\n@@ -0,0 +1,146 @@\n+// SPDX-License-Identifier: GPL-2.0+\n+/*\n+ * Copyright (C) 2026 Philippe Reynes <philippe.reynes@softathome.com>\n+ */\n+\n+#include <log.h>\n+#include <linux/errno.h>\n+#include <linux/string.h>\n+#include <linux/types.h>\n+\n+#include <crypto/internal/ecdsa.h>\n+\n+#include \"mbedtls_options.h\" /* required to access private fields */\n+#include <mbedtls/ecdsa.h>\n+#include <mbedtls/ecp.h>\n+\n+static mbedtls_ecp_group_id ecdsa_search_group_id(const char *curve_name)\n+{\n+\tmbedtls_ecp_group_id grp_id = MBEDTLS_ECP_DP_NONE;\n+\tconst mbedtls_ecp_curve_info *info;\n+\n+\tif (!curve_name)\n+\t\tgoto out;\n+\n+\tif (!strcmp(curve_name, \"prime256v1\"))\n+\t\treturn MBEDTLS_ECP_DP_SECP256R1;\n+\n+\tinfo = mbedtls_ecp_curve_list();\n+\twhile (info && info->name) {\n+\t\tif (!strcmp(curve_name, info->name)) {\n+\t\t\tgrp_id = info->grp_id;\n+\t\t\tbreak;\n+\t\t}\n+\t\tinfo++;\n+\t}\n+\n+ out:\n+\treturn grp_id;\n+}\n+\n+int ecdsa_hash_verify(const struct ecdsa_public_key *pubkey,\n+\t\t      const void *hash, size_t hash_len,\n+\t\t      const void *signature, size_t sig_len)\n+{\n+\tmbedtls_ecp_group_id grp_id;\n+\tmbedtls_ecp_group grp;\n+\tmbedtls_ecp_point Q;\n+\tmbedtls_mpi r, s;\n+\tint key_len;\n+\tint err = -1;\n+\n+\tkey_len = DIV_ROUND_UP(pubkey->size_bits, 8);\n+\n+\t/* check the signature len */\n+\tif (sig_len != 2 * key_len) {\n+\t\tlog_debug(\"sig len should be twice the key len (sig len = %zu, key len = %d)\\n\",\n+\t\t\t  sig_len, key_len);\n+\t\terr = -EINVAL;\n+\t\tgoto out;\n+\t}\n+\n+\t/* search the group */\n+\tgrp_id = ecdsa_search_group_id(pubkey->curve_name);\n+\tif (grp_id == MBEDTLS_ECP_DP_NONE) {\n+\t\tlog_debug(\"curve name %s not found\\n\", pubkey->curve_name);\n+\t\terr = -EINVAL;\n+\t\tgoto out;\n+\t}\n+\n+\t/* init and load the group */\n+\tmbedtls_ecp_group_init(&grp);\n+\terr = mbedtls_ecp_group_load(&grp, grp_id);\n+\tif (err) {\n+\t\terr = -EINVAL;\n+\t\tgoto out1;\n+\t}\n+\n+\t/* prepare the pubkey */\n+\tmbedtls_ecp_point_init(&Q);\n+\terr = mbedtls_mpi_read_binary(&Q.X, pubkey->x, key_len);\n+\tif (err) {\n+\t\tlog_debug(\"could not read value x of the public key (err = %d)\\n\",\n+\t\t\t  err);\n+\t\terr = -EINVAL;\n+\t\tgoto out2;\n+\t}\n+\terr = mbedtls_mpi_read_binary(&Q.Y, pubkey->y, key_len);\n+\tif (err) {\n+\t\tlog_debug(\"could not read value y of the public key (err = %d)\\n\",\n+\t\t\t  err);\n+\t\terr = -EINVAL;\n+\t\tgoto out2;\n+\t}\n+\tmbedtls_mpi_lset(&Q.Z, 1);\n+\tif (err) {\n+\t\tlog_debug(\"could not set value z of the public key (err = %d)\\n\",\n+\t\t\t  err);\n+\t\terr = -EINVAL;\n+\t\tgoto out2;\n+\t}\n+\n+\t/* check if the pubkey is valid */\n+\terr = mbedtls_ecp_check_pubkey(&grp, &Q);\n+\tif (err) {\n+\t\tlog_debug(\"public key is invalid (err = %d)\\n\", err);\n+\t\terr = -EKEYREJECTED;\n+\t\tgoto out2;\n+\t}\n+\n+\t/* compute r */\n+\tmbedtls_mpi_init(&r);\n+\terr = mbedtls_mpi_read_binary(&r, signature, key_len);\n+\tif (err) {\n+\t\tlog_debug(\"could not read value r of the signature (err = %d)\\n\",\n+\t\t\t  err);\n+\t\terr = -EINVAL;\n+\t\tgoto out3;\n+\t}\n+\n+\t/* compute s */\n+\tmbedtls_mpi_init(&s);\n+\terr = mbedtls_mpi_read_binary(&s, signature + key_len, key_len);\n+\tif (err) {\n+\t\tlog_debug(\"could not read value s of the signature (err = %d)\\n\",\n+\t\t\t  err);\n+\t\terr = -EINVAL;\n+\t\tgoto out4;\n+\t}\n+\n+\t/* check the signature */\n+\terr = mbedtls_ecdsa_verify(&grp, hash, hash_len, &Q, &r, &s);\n+\tif (err)\n+\t\terr = -EINVAL;\n+\n+ out4:\n+\tmbedtls_mpi_free(&s);\n+ out3:\n+\tmbedtls_mpi_free(&r);\n+ out2:\n+\tmbedtls_ecp_point_free(&Q);\n+ out1:\n+\tmbedtls_ecp_group_free(&grp);\n+ out:\n+\n+\treturn err;\n+}\n","prefixes":["v4","02/14"]}