Lines Matching refs:pad
422 unsigned int len = (i == (x4 - 1) ? last : frag), pad, j;
442 /* pad */
443 pad = 15 - len % 16;
444 for (j = 0; j <= pad; j++)
445 *(out++) = pad;
446 len += pad + 1;
546 /* pad the payload|hmac */
571 unsigned int res, maxpad, pad, bitlen;
590 pad = out[len - 1];
595 mask = constant_time_ge(maxpad, pad);
598 * If pad is invalid then we will fail the above test but we must
600 * we'll use the maxpad value instead of the supplied pad to make
603 pad = constant_time_select(mask, pad, maxpad);
605 inp_len = len - (SHA256_DIGEST_LENGTH + pad + 1);
763 res |= (c ^ pad) & ~cmask; /* ... and padding */
780 pad = (pad & ~res) | (maxpad & res);
781 out = out + len - 1 - pad;
782 for (res = 0, i = 0; i < pad; i++)
783 res |= out[i] ^ pad;