Lines Matching refs:pad
410 unsigned int len = (i == (x4 - 1) ? last : frag), pad, j;
427 /* pad */
428 pad = 15 - len % 16;
429 for (j = 0; j <= pad; j++)
430 *(out++) = pad;
431 len += pad + 1;
516 /* pad the payload|hmac */
538 unsigned int res, maxpad, pad, bitlen;
577 pad = out[len - 1];
582 mask = constant_time_ge(maxpad, pad);
585 * If pad is invalid then we will fail the above test but we must
587 * we'll use the maxpad value instead of the supplied pad to make
590 pad = constant_time_select(mask, pad, maxpad);
592 inp_len = len - (SHA_DIGEST_LENGTH + pad + 1);
757 res |= (c ^ pad) & ~cmask; /* ... and padding */
774 pad = (pad & ~res) | (maxpad & res);
775 out = out + len - 1 - pad;
776 for (res = 0, i = 0; i < pad; i++)
777 res |= out[i] ^ pad;