Currently no test checks that ECDSA verify rejects a signature where r + n ≥ p and (r + n) mod p equals x(R), so the following mutant lives:
diff --git a/src/ecdsa_impl.h b/src/ecdsa_impl.h
index 5963877..5301eaa 100644
--- a/src/ecdsa_impl.h
+++ b/src/ecdsa_impl.h
@@ -258,10 +258,6 @@ static int secp256k1_ecdsa_sig_verify(const secp256k1_scalar *sigr, const secp25
/* xr * pr.z^2 mod p == pr.x, so the signature is valid. */
return 1;
}
- if (secp256k1_fe_cmp_var(&xr, &secp256k1_ecdsa_const_p_minus_order) >= 0) {
- /* xr + n >= p, so we can skip testing the second case. */
- return 0;
- }
secp256k1_fe_add(&xr, &secp256k1_ecdsa_const_order_as_fe);
if (secp256k1_gej_eq_x_var(&xr, &pr)) {
/* (xr + n) * pr.z^2 mod p == pr.x, so the signature is valid. */
This adds a case with r = p - n + 1, so that (r + n) mod p = 1, and a pubkey chosen so that x(R) = 1, covering this gap.