Files
wolfssl/wolfcrypt
Daniele Lacamera 4acfa9984f sp_int: remove tautological err check in sp_todecimal
Premise:  sp_int.c:18887 `if (err == MP_OKAY) {` opens the block that dominates
          the claimed condition. The last thing that can set err is
          ALLOC_SP_INT_SIZE at :18883, above that guard.
Claim:    sp_int.c:18909, a second `if (err == MP_OKAY)` nested directly inside
          the first.
Proof:    control reaches :18909 only through the taken branch of :18887, so
          err == MP_OKAY there. Between the two, err is neither assigned nor
          passed by address: the span holds character stores into str and
          `(void)sp_div_d(t, 10, t, &d)`, whose return value is explicitly
          discarded. The inner test is therefore a tautology and its false
          branch is unreachable.
Scope:    the only preprocessor construct in the span is the
          WOLFSSL_SP_INT_NEGATIVE sign-character block (:18888-18895); neither
          arm writes err.
Evidence: llvm-cov MC/DC records this decision as never taking its false
          branch; it is one of the two structural residuals noted for sp_int.c
          in the sp-math baseline.

The remaining err checks in the function are live: ALLOC_SP_INT_SIZE writes err
(MP_VAL when the size exceeds SP_INT_DIGITS, MP_MEM in the malloc form) in both
its small-stack and static-stack expansions.

Compiler cross-check: gcc -O2 emits byte-identical code for this file before
and after this commit -- the optimiser had already folded the removed
condition, independently confirming it was dead.
2026-07-31 17:13:56 +02:00
..