mbed TLS v2.28.1
bn_mul.h
Go to the documentation of this file.
1 
6 /*
7  * Copyright The Mbed TLS Contributors
8  * SPDX-License-Identifier: Apache-2.0
9  *
10  * Licensed under the Apache License, Version 2.0 (the "License"); you may
11  * not use this file except in compliance with the License.
12  * You may obtain a copy of the License at
13  *
14  * http://www.apache.org/licenses/LICENSE-2.0
15  *
16  * Unless required by applicable law or agreed to in writing, software
17  * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
18  * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
19  * See the License for the specific language governing permissions and
20  * limitations under the License.
21  */
22 /*
23  * Multiply source vector [s] with b, add result
24  * to destination vector [d] and set carry c.
25  *
26  * Currently supports:
27  *
28  * . IA-32 (386+) . AMD64 / EM64T
29  * . IA-32 (SSE2) . Motorola 68000
30  * . PowerPC, 32-bit . MicroBlaze
31  * . PowerPC, 64-bit . TriCore
32  * . SPARC v8 . ARM v3+
33  * . Alpha . MIPS32
34  * . C, longlong . C, generic
35  */
36 #ifndef MBEDTLS_BN_MUL_H
37 #define MBEDTLS_BN_MUL_H
38 
39 #if !defined(MBEDTLS_CONFIG_FILE)
40 #include "mbedtls/config.h"
41 #else
42 #include MBEDTLS_CONFIG_FILE
43 #endif
44 
45 #include "mbedtls/bignum.h"
46 
47 
48 /*
49  * Conversion macros for embedded constants:
50  * build lists of mbedtls_mpi_uint's from lists of unsigned char's grouped by 8, 4 or 2
51  */
52 #if defined(MBEDTLS_HAVE_INT32)
53 
54 #define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
55  ( (mbedtls_mpi_uint) (a) << 0 ) | \
56  ( (mbedtls_mpi_uint) (b) << 8 ) | \
57  ( (mbedtls_mpi_uint) (c) << 16 ) | \
58  ( (mbedtls_mpi_uint) (d) << 24 )
59 
60 #define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
61  MBEDTLS_BYTES_TO_T_UINT_4( a, b, 0, 0 )
62 
63 #define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
64  MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ), \
65  MBEDTLS_BYTES_TO_T_UINT_4( e, f, g, h )
66 
67 #else /* 64-bits */
68 
69 #define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
70  ( (mbedtls_mpi_uint) (a) << 0 ) | \
71  ( (mbedtls_mpi_uint) (b) << 8 ) | \
72  ( (mbedtls_mpi_uint) (c) << 16 ) | \
73  ( (mbedtls_mpi_uint) (d) << 24 ) | \
74  ( (mbedtls_mpi_uint) (e) << 32 ) | \
75  ( (mbedtls_mpi_uint) (f) << 40 ) | \
76  ( (mbedtls_mpi_uint) (g) << 48 ) | \
77  ( (mbedtls_mpi_uint) (h) << 56 )
78 
79 #define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
80  MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, 0, 0, 0, 0 )
81 
82 #define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
83  MBEDTLS_BYTES_TO_T_UINT_8( a, b, 0, 0, 0, 0, 0, 0 )
84 
85 #endif /* bits in mbedtls_mpi_uint */
86 
87 #if defined(MBEDTLS_HAVE_ASM)
88 
89 #ifndef asm
90 #define asm __asm
91 #endif
92 
93 /* armcc5 --gnu defines __GNUC__ but doesn't support GNU's extended asm */
94 #if defined(__GNUC__) && \
95  ( !defined(__ARMCC_VERSION) || __ARMCC_VERSION >= 6000000 )
96 
97 /*
98  * Disable use of the i386 assembly code below if option -O0, to disable all
99  * compiler optimisations, is passed, detected with __OPTIMIZE__
100  * This is done as the number of registers used in the assembly code doesn't
101  * work with the -O0 option.
102  */
103 #if defined(__i386__) && defined(__OPTIMIZE__)
104 
105 #define MULADDC_INIT \
106  asm( \
107  "movl %%ebx, %0 \n\t" \
108  "movl %5, %%esi \n\t" \
109  "movl %6, %%edi \n\t" \
110  "movl %7, %%ecx \n\t" \
111  "movl %8, %%ebx \n\t"
112 
113 #define MULADDC_CORE \
114  "lodsl \n\t" \
115  "mull %%ebx \n\t" \
116  "addl %%ecx, %%eax \n\t" \
117  "adcl $0, %%edx \n\t" \
118  "addl (%%edi), %%eax \n\t" \
119  "adcl $0, %%edx \n\t" \
120  "movl %%edx, %%ecx \n\t" \
121  "stosl \n\t"
122 
123 #if defined(MBEDTLS_HAVE_SSE2)
124 
125 #define MULADDC_HUIT \
126  "movd %%ecx, %%mm1 \n\t" \
127  "movd %%ebx, %%mm0 \n\t" \
128  "movd (%%edi), %%mm3 \n\t" \
129  "paddq %%mm3, %%mm1 \n\t" \
130  "movd (%%esi), %%mm2 \n\t" \
131  "pmuludq %%mm0, %%mm2 \n\t" \
132  "movd 4(%%esi), %%mm4 \n\t" \
133  "pmuludq %%mm0, %%mm4 \n\t" \
134  "movd 8(%%esi), %%mm6 \n\t" \
135  "pmuludq %%mm0, %%mm6 \n\t" \
136  "movd 12(%%esi), %%mm7 \n\t" \
137  "pmuludq %%mm0, %%mm7 \n\t" \
138  "paddq %%mm2, %%mm1 \n\t" \
139  "movd 4(%%edi), %%mm3 \n\t" \
140  "paddq %%mm4, %%mm3 \n\t" \
141  "movd 8(%%edi), %%mm5 \n\t" \
142  "paddq %%mm6, %%mm5 \n\t" \
143  "movd 12(%%edi), %%mm4 \n\t" \
144  "paddq %%mm4, %%mm7 \n\t" \
145  "movd %%mm1, (%%edi) \n\t" \
146  "movd 16(%%esi), %%mm2 \n\t" \
147  "pmuludq %%mm0, %%mm2 \n\t" \
148  "psrlq $32, %%mm1 \n\t" \
149  "movd 20(%%esi), %%mm4 \n\t" \
150  "pmuludq %%mm0, %%mm4 \n\t" \
151  "paddq %%mm3, %%mm1 \n\t" \
152  "movd 24(%%esi), %%mm6 \n\t" \
153  "pmuludq %%mm0, %%mm6 \n\t" \
154  "movd %%mm1, 4(%%edi) \n\t" \
155  "psrlq $32, %%mm1 \n\t" \
156  "movd 28(%%esi), %%mm3 \n\t" \
157  "pmuludq %%mm0, %%mm3 \n\t" \
158  "paddq %%mm5, %%mm1 \n\t" \
159  "movd 16(%%edi), %%mm5 \n\t" \
160  "paddq %%mm5, %%mm2 \n\t" \
161  "movd %%mm1, 8(%%edi) \n\t" \
162  "psrlq $32, %%mm1 \n\t" \
163  "paddq %%mm7, %%mm1 \n\t" \
164  "movd 20(%%edi), %%mm5 \n\t" \
165  "paddq %%mm5, %%mm4 \n\t" \
166  "movd %%mm1, 12(%%edi) \n\t" \
167  "psrlq $32, %%mm1 \n\t" \
168  "paddq %%mm2, %%mm1 \n\t" \
169  "movd 24(%%edi), %%mm5 \n\t" \
170  "paddq %%mm5, %%mm6 \n\t" \
171  "movd %%mm1, 16(%%edi) \n\t" \
172  "psrlq $32, %%mm1 \n\t" \
173  "paddq %%mm4, %%mm1 \n\t" \
174  "movd 28(%%edi), %%mm5 \n\t" \
175  "paddq %%mm5, %%mm3 \n\t" \
176  "movd %%mm1, 20(%%edi) \n\t" \
177  "psrlq $32, %%mm1 \n\t" \
178  "paddq %%mm6, %%mm1 \n\t" \
179  "movd %%mm1, 24(%%edi) \n\t" \
180  "psrlq $32, %%mm1 \n\t" \
181  "paddq %%mm3, %%mm1 \n\t" \
182  "movd %%mm1, 28(%%edi) \n\t" \
183  "addl $32, %%edi \n\t" \
184  "addl $32, %%esi \n\t" \
185  "psrlq $32, %%mm1 \n\t" \
186  "movd %%mm1, %%ecx \n\t"
187 
188 #define MULADDC_STOP \
189  "emms \n\t" \
190  "movl %4, %%ebx \n\t" \
191  "movl %%ecx, %1 \n\t" \
192  "movl %%edi, %2 \n\t" \
193  "movl %%esi, %3 \n\t" \
194  : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
195  : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
196  : "eax", "ebx", "ecx", "edx", "esi", "edi" \
197  );
198 
199 #else
200 
201 #define MULADDC_STOP \
202  "movl %4, %%ebx \n\t" \
203  "movl %%ecx, %1 \n\t" \
204  "movl %%edi, %2 \n\t" \
205  "movl %%esi, %3 \n\t" \
206  : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
207  : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
208  : "eax", "ebx", "ecx", "edx", "esi", "edi" \
209  );
210 #endif /* SSE2 */
211 #endif /* i386 */
212 
213 #if defined(__amd64__) || defined (__x86_64__)
214 
215 #define MULADDC_INIT \
216  asm( \
217  "xorq %%r8, %%r8\n"
218 
219 #define MULADDC_CORE \
220  "movq (%%rsi), %%rax\n" \
221  "mulq %%rbx\n" \
222  "addq $8, %%rsi\n" \
223  "addq %%rcx, %%rax\n" \
224  "movq %%r8, %%rcx\n" \
225  "adcq $0, %%rdx\n" \
226  "nop \n" \
227  "addq %%rax, (%%rdi)\n" \
228  "adcq %%rdx, %%rcx\n" \
229  "addq $8, %%rdi\n"
230 
231 #define MULADDC_STOP \
232  : "+c" (c), "+D" (d), "+S" (s), "+m" (*(uint64_t (*)[16]) d) \
233  : "b" (b), "m" (*(const uint64_t (*)[16]) s) \
234  : "rax", "rdx", "r8" \
235  );
236 
237 #endif /* AMD64 */
238 
239 #if defined(__aarch64__)
240 
241 #define MULADDC_INIT \
242  asm(
243 
244 #define MULADDC_CORE \
245  "ldr x4, [%2], #8 \n\t" \
246  "ldr x5, [%1] \n\t" \
247  "mul x6, x4, %4 \n\t" \
248  "umulh x7, x4, %4 \n\t" \
249  "adds x5, x5, x6 \n\t" \
250  "adc x7, x7, xzr \n\t" \
251  "adds x5, x5, %0 \n\t" \
252  "adc %0, x7, xzr \n\t" \
253  "str x5, [%1], #8 \n\t"
254 
255 #define MULADDC_STOP \
256  : "+r" (c), "+r" (d), "+r" (s), "+m" (*(uint64_t (*)[16]) d) \
257  : "r" (b), "m" (*(const uint64_t (*)[16]) s) \
258  : "x4", "x5", "x6", "x7", "cc" \
259  );
260 
261 #endif /* Aarch64 */
262 
263 #if defined(__mc68020__) || defined(__mcpu32__)
264 
265 #define MULADDC_INIT \
266  asm( \
267  "movl %3, %%a2 \n\t" \
268  "movl %4, %%a3 \n\t" \
269  "movl %5, %%d3 \n\t" \
270  "movl %6, %%d2 \n\t" \
271  "moveq #0, %%d0 \n\t"
272 
273 #define MULADDC_CORE \
274  "movel %%a2@+, %%d1 \n\t" \
275  "mulul %%d2, %%d4:%%d1 \n\t" \
276  "addl %%d3, %%d1 \n\t" \
277  "addxl %%d0, %%d4 \n\t" \
278  "moveq #0, %%d3 \n\t" \
279  "addl %%d1, %%a3@+ \n\t" \
280  "addxl %%d4, %%d3 \n\t"
281 
282 #define MULADDC_STOP \
283  "movl %%d3, %0 \n\t" \
284  "movl %%a3, %1 \n\t" \
285  "movl %%a2, %2 \n\t" \
286  : "=m" (c), "=m" (d), "=m" (s) \
287  : "m" (s), "m" (d), "m" (c), "m" (b) \
288  : "d0", "d1", "d2", "d3", "d4", "a2", "a3" \
289  );
290 
291 #define MULADDC_HUIT \
292  "movel %%a2@+, %%d1 \n\t" \
293  "mulul %%d2, %%d4:%%d1 \n\t" \
294  "addxl %%d3, %%d1 \n\t" \
295  "addxl %%d0, %%d4 \n\t" \
296  "addl %%d1, %%a3@+ \n\t" \
297  "movel %%a2@+, %%d1 \n\t" \
298  "mulul %%d2, %%d3:%%d1 \n\t" \
299  "addxl %%d4, %%d1 \n\t" \
300  "addxl %%d0, %%d3 \n\t" \
301  "addl %%d1, %%a3@+ \n\t" \
302  "movel %%a2@+, %%d1 \n\t" \
303  "mulul %%d2, %%d4:%%d1 \n\t" \
304  "addxl %%d3, %%d1 \n\t" \
305  "addxl %%d0, %%d4 \n\t" \
306  "addl %%d1, %%a3@+ \n\t" \
307  "movel %%a2@+, %%d1 \n\t" \
308  "mulul %%d2, %%d3:%%d1 \n\t" \
309  "addxl %%d4, %%d1 \n\t" \
310  "addxl %%d0, %%d3 \n\t" \
311  "addl %%d1, %%a3@+ \n\t" \
312  "movel %%a2@+, %%d1 \n\t" \
313  "mulul %%d2, %%d4:%%d1 \n\t" \
314  "addxl %%d3, %%d1 \n\t" \
315  "addxl %%d0, %%d4 \n\t" \
316  "addl %%d1, %%a3@+ \n\t" \
317  "movel %%a2@+, %%d1 \n\t" \
318  "mulul %%d2, %%d3:%%d1 \n\t" \
319  "addxl %%d4, %%d1 \n\t" \
320  "addxl %%d0, %%d3 \n\t" \
321  "addl %%d1, %%a3@+ \n\t" \
322  "movel %%a2@+, %%d1 \n\t" \
323  "mulul %%d2, %%d4:%%d1 \n\t" \
324  "addxl %%d3, %%d1 \n\t" \
325  "addxl %%d0, %%d4 \n\t" \
326  "addl %%d1, %%a3@+ \n\t" \
327  "movel %%a2@+, %%d1 \n\t" \
328  "mulul %%d2, %%d3:%%d1 \n\t" \
329  "addxl %%d4, %%d1 \n\t" \
330  "addxl %%d0, %%d3 \n\t" \
331  "addl %%d1, %%a3@+ \n\t" \
332  "addxl %%d0, %%d3 \n\t"
333 
334 #endif /* MC68000 */
335 
336 #if defined(__powerpc64__) || defined(__ppc64__)
337 
338 #if defined(__MACH__) && defined(__APPLE__)
339 
340 #define MULADDC_INIT \
341  asm( \
342  "ld r3, %3 \n\t" \
343  "ld r4, %4 \n\t" \
344  "ld r5, %5 \n\t" \
345  "ld r6, %6 \n\t" \
346  "addi r3, r3, -8 \n\t" \
347  "addi r4, r4, -8 \n\t" \
348  "addic r5, r5, 0 \n\t"
349 
350 #define MULADDC_CORE \
351  "ldu r7, 8(r3) \n\t" \
352  "mulld r8, r7, r6 \n\t" \
353  "mulhdu r9, r7, r6 \n\t" \
354  "adde r8, r8, r5 \n\t" \
355  "ld r7, 8(r4) \n\t" \
356  "addze r5, r9 \n\t" \
357  "addc r8, r8, r7 \n\t" \
358  "stdu r8, 8(r4) \n\t"
359 
360 #define MULADDC_STOP \
361  "addze r5, r5 \n\t" \
362  "addi r4, r4, 8 \n\t" \
363  "addi r3, r3, 8 \n\t" \
364  "std r5, %0 \n\t" \
365  "std r4, %1 \n\t" \
366  "std r3, %2 \n\t" \
367  : "=m" (c), "=m" (d), "=m" (s) \
368  : "m" (s), "m" (d), "m" (c), "m" (b) \
369  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
370  );
371 
372 
373 #else /* __MACH__ && __APPLE__ */
374 
375 #define MULADDC_INIT \
376  asm( \
377  "ld %%r3, %3 \n\t" \
378  "ld %%r4, %4 \n\t" \
379  "ld %%r5, %5 \n\t" \
380  "ld %%r6, %6 \n\t" \
381  "addi %%r3, %%r3, -8 \n\t" \
382  "addi %%r4, %%r4, -8 \n\t" \
383  "addic %%r5, %%r5, 0 \n\t"
384 
385 #define MULADDC_CORE \
386  "ldu %%r7, 8(%%r3) \n\t" \
387  "mulld %%r8, %%r7, %%r6 \n\t" \
388  "mulhdu %%r9, %%r7, %%r6 \n\t" \
389  "adde %%r8, %%r8, %%r5 \n\t" \
390  "ld %%r7, 8(%%r4) \n\t" \
391  "addze %%r5, %%r9 \n\t" \
392  "addc %%r8, %%r8, %%r7 \n\t" \
393  "stdu %%r8, 8(%%r4) \n\t"
394 
395 #define MULADDC_STOP \
396  "addze %%r5, %%r5 \n\t" \
397  "addi %%r4, %%r4, 8 \n\t" \
398  "addi %%r3, %%r3, 8 \n\t" \
399  "std %%r5, %0 \n\t" \
400  "std %%r4, %1 \n\t" \
401  "std %%r3, %2 \n\t" \
402  : "=m" (c), "=m" (d), "=m" (s) \
403  : "m" (s), "m" (d), "m" (c), "m" (b) \
404  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
405  );
406 
407 #endif /* __MACH__ && __APPLE__ */
408 
409 #elif defined(__powerpc__) || defined(__ppc__) /* end PPC64/begin PPC32 */
410 
411 #if defined(__MACH__) && defined(__APPLE__)
412 
413 #define MULADDC_INIT \
414  asm( \
415  "lwz r3, %3 \n\t" \
416  "lwz r4, %4 \n\t" \
417  "lwz r5, %5 \n\t" \
418  "lwz r6, %6 \n\t" \
419  "addi r3, r3, -4 \n\t" \
420  "addi r4, r4, -4 \n\t" \
421  "addic r5, r5, 0 \n\t"
422 
423 #define MULADDC_CORE \
424  "lwzu r7, 4(r3) \n\t" \
425  "mullw r8, r7, r6 \n\t" \
426  "mulhwu r9, r7, r6 \n\t" \
427  "adde r8, r8, r5 \n\t" \
428  "lwz r7, 4(r4) \n\t" \
429  "addze r5, r9 \n\t" \
430  "addc r8, r8, r7 \n\t" \
431  "stwu r8, 4(r4) \n\t"
432 
433 #define MULADDC_STOP \
434  "addze r5, r5 \n\t" \
435  "addi r4, r4, 4 \n\t" \
436  "addi r3, r3, 4 \n\t" \
437  "stw r5, %0 \n\t" \
438  "stw r4, %1 \n\t" \
439  "stw r3, %2 \n\t" \
440  : "=m" (c), "=m" (d), "=m" (s) \
441  : "m" (s), "m" (d), "m" (c), "m" (b) \
442  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
443  );
444 
445 #else /* __MACH__ && __APPLE__ */
446 
447 #define MULADDC_INIT \
448  asm( \
449  "lwz %%r3, %3 \n\t" \
450  "lwz %%r4, %4 \n\t" \
451  "lwz %%r5, %5 \n\t" \
452  "lwz %%r6, %6 \n\t" \
453  "addi %%r3, %%r3, -4 \n\t" \
454  "addi %%r4, %%r4, -4 \n\t" \
455  "addic %%r5, %%r5, 0 \n\t"
456 
457 #define MULADDC_CORE \
458  "lwzu %%r7, 4(%%r3) \n\t" \
459  "mullw %%r8, %%r7, %%r6 \n\t" \
460  "mulhwu %%r9, %%r7, %%r6 \n\t" \
461  "adde %%r8, %%r8, %%r5 \n\t" \
462  "lwz %%r7, 4(%%r4) \n\t" \
463  "addze %%r5, %%r9 \n\t" \
464  "addc %%r8, %%r8, %%r7 \n\t" \
465  "stwu %%r8, 4(%%r4) \n\t"
466 
467 #define MULADDC_STOP \
468  "addze %%r5, %%r5 \n\t" \
469  "addi %%r4, %%r4, 4 \n\t" \
470  "addi %%r3, %%r3, 4 \n\t" \
471  "stw %%r5, %0 \n\t" \
472  "stw %%r4, %1 \n\t" \
473  "stw %%r3, %2 \n\t" \
474  : "=m" (c), "=m" (d), "=m" (s) \
475  : "m" (s), "m" (d), "m" (c), "m" (b) \
476  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
477  );
478 
479 #endif /* __MACH__ && __APPLE__ */
480 
481 #endif /* PPC32 */
482 
483 /*
484  * The Sparc(64) assembly is reported to be broken.
485  * Disable it for now, until we're able to fix it.
486  */
487 #if 0 && defined(__sparc__)
488 #if defined(__sparc64__)
489 
490 #define MULADDC_INIT \
491  asm( \
492  "ldx %3, %%o0 \n\t" \
493  "ldx %4, %%o1 \n\t" \
494  "ld %5, %%o2 \n\t" \
495  "ld %6, %%o3 \n\t"
496 
497 #define MULADDC_CORE \
498  "ld [%%o0], %%o4 \n\t" \
499  "inc 4, %%o0 \n\t" \
500  "ld [%%o1], %%o5 \n\t" \
501  "umul %%o3, %%o4, %%o4 \n\t" \
502  "addcc %%o4, %%o2, %%o4 \n\t" \
503  "rd %%y, %%g1 \n\t" \
504  "addx %%g1, 0, %%g1 \n\t" \
505  "addcc %%o4, %%o5, %%o4 \n\t" \
506  "st %%o4, [%%o1] \n\t" \
507  "addx %%g1, 0, %%o2 \n\t" \
508  "inc 4, %%o1 \n\t"
509 
510  #define MULADDC_STOP \
511  "st %%o2, %0 \n\t" \
512  "stx %%o1, %1 \n\t" \
513  "stx %%o0, %2 \n\t" \
514  : "=m" (c), "=m" (d), "=m" (s) \
515  : "m" (s), "m" (d), "m" (c), "m" (b) \
516  : "g1", "o0", "o1", "o2", "o3", "o4", \
517  "o5" \
518  );
519 
520 #else /* __sparc64__ */
521 
522 #define MULADDC_INIT \
523  asm( \
524  "ld %3, %%o0 \n\t" \
525  "ld %4, %%o1 \n\t" \
526  "ld %5, %%o2 \n\t" \
527  "ld %6, %%o3 \n\t"
528 
529 #define MULADDC_CORE \
530  "ld [%%o0], %%o4 \n\t" \
531  "inc 4, %%o0 \n\t" \
532  "ld [%%o1], %%o5 \n\t" \
533  "umul %%o3, %%o4, %%o4 \n\t" \
534  "addcc %%o4, %%o2, %%o4 \n\t" \
535  "rd %%y, %%g1 \n\t" \
536  "addx %%g1, 0, %%g1 \n\t" \
537  "addcc %%o4, %%o5, %%o4 \n\t" \
538  "st %%o4, [%%o1] \n\t" \
539  "addx %%g1, 0, %%o2 \n\t" \
540  "inc 4, %%o1 \n\t"
541 
542 #define MULADDC_STOP \
543  "st %%o2, %0 \n\t" \
544  "st %%o1, %1 \n\t" \
545  "st %%o0, %2 \n\t" \
546  : "=m" (c), "=m" (d), "=m" (s) \
547  : "m" (s), "m" (d), "m" (c), "m" (b) \
548  : "g1", "o0", "o1", "o2", "o3", "o4", \
549  "o5" \
550  );
551 
552 #endif /* __sparc64__ */
553 #endif /* __sparc__ */
554 
555 #if defined(__microblaze__) || defined(microblaze)
556 
557 #define MULADDC_INIT \
558  asm( \
559  "lwi r3, %3 \n\t" \
560  "lwi r4, %4 \n\t" \
561  "lwi r5, %5 \n\t" \
562  "lwi r6, %6 \n\t" \
563  "andi r7, r6, 0xffff \n\t" \
564  "bsrli r6, r6, 16 \n\t"
565 
566 #define MULADDC_CORE \
567  "lhui r8, r3, 0 \n\t" \
568  "addi r3, r3, 2 \n\t" \
569  "lhui r9, r3, 0 \n\t" \
570  "addi r3, r3, 2 \n\t" \
571  "mul r10, r9, r6 \n\t" \
572  "mul r11, r8, r7 \n\t" \
573  "mul r12, r9, r7 \n\t" \
574  "mul r13, r8, r6 \n\t" \
575  "bsrli r8, r10, 16 \n\t" \
576  "bsrli r9, r11, 16 \n\t" \
577  "add r13, r13, r8 \n\t" \
578  "add r13, r13, r9 \n\t" \
579  "bslli r10, r10, 16 \n\t" \
580  "bslli r11, r11, 16 \n\t" \
581  "add r12, r12, r10 \n\t" \
582  "addc r13, r13, r0 \n\t" \
583  "add r12, r12, r11 \n\t" \
584  "addc r13, r13, r0 \n\t" \
585  "lwi r10, r4, 0 \n\t" \
586  "add r12, r12, r10 \n\t" \
587  "addc r13, r13, r0 \n\t" \
588  "add r12, r12, r5 \n\t" \
589  "addc r5, r13, r0 \n\t" \
590  "swi r12, r4, 0 \n\t" \
591  "addi r4, r4, 4 \n\t"
592 
593 #define MULADDC_STOP \
594  "swi r5, %0 \n\t" \
595  "swi r4, %1 \n\t" \
596  "swi r3, %2 \n\t" \
597  : "=m" (c), "=m" (d), "=m" (s) \
598  : "m" (s), "m" (d), "m" (c), "m" (b) \
599  : "r3", "r4", "r5", "r6", "r7", "r8", \
600  "r9", "r10", "r11", "r12", "r13" \
601  );
602 
603 #endif /* MicroBlaze */
604 
605 #if defined(__tricore__)
606 
607 #define MULADDC_INIT \
608  asm( \
609  "ld.a %%a2, %3 \n\t" \
610  "ld.a %%a3, %4 \n\t" \
611  "ld.w %%d4, %5 \n\t" \
612  "ld.w %%d1, %6 \n\t" \
613  "xor %%d5, %%d5 \n\t"
614 
615 #define MULADDC_CORE \
616  "ld.w %%d0, [%%a2+] \n\t" \
617  "madd.u %%e2, %%e4, %%d0, %%d1 \n\t" \
618  "ld.w %%d0, [%%a3] \n\t" \
619  "addx %%d2, %%d2, %%d0 \n\t" \
620  "addc %%d3, %%d3, 0 \n\t" \
621  "mov %%d4, %%d3 \n\t" \
622  "st.w [%%a3+], %%d2 \n\t"
623 
624 #define MULADDC_STOP \
625  "st.w %0, %%d4 \n\t" \
626  "st.a %1, %%a3 \n\t" \
627  "st.a %2, %%a2 \n\t" \
628  : "=m" (c), "=m" (d), "=m" (s) \
629  : "m" (s), "m" (d), "m" (c), "m" (b) \
630  : "d0", "d1", "e2", "d4", "a2", "a3" \
631  );
632 
633 #endif /* TriCore */
634 
635 /*
636  * Note, gcc -O0 by default uses r7 for the frame pointer, so it complains about
637  * our use of r7 below, unless -fomit-frame-pointer is passed.
638  *
639  * On the other hand, -fomit-frame-pointer is implied by any -Ox options with
640  * x !=0, which we can detect using __OPTIMIZE__ (which is also defined by
641  * clang and armcc5 under the same conditions).
642  *
643  * So, only use the optimized assembly below for optimized build, which avoids
644  * the build error and is pretty reasonable anyway.
645  */
646 #if defined(__GNUC__) && !defined(__OPTIMIZE__)
647 #define MULADDC_CANNOT_USE_R7
648 #endif
649 
650 #if defined(__arm__) && !defined(MULADDC_CANNOT_USE_R7)
651 
652 #if defined(__thumb__) && !defined(__thumb2__)
653 
654 #define MULADDC_INIT \
655  asm( \
656  "ldr r0, %3 \n\t" \
657  "ldr r1, %4 \n\t" \
658  "ldr r2, %5 \n\t" \
659  "ldr r3, %6 \n\t" \
660  "lsr r7, r3, #16 \n\t" \
661  "mov r9, r7 \n\t" \
662  "lsl r7, r3, #16 \n\t" \
663  "lsr r7, r7, #16 \n\t" \
664  "mov r8, r7 \n\t"
665 
666 #define MULADDC_CORE \
667  "ldmia r0!, {r6} \n\t" \
668  "lsr r7, r6, #16 \n\t" \
669  "lsl r6, r6, #16 \n\t" \
670  "lsr r6, r6, #16 \n\t" \
671  "mov r4, r8 \n\t" \
672  "mul r4, r6 \n\t" \
673  "mov r3, r9 \n\t" \
674  "mul r6, r3 \n\t" \
675  "mov r5, r9 \n\t" \
676  "mul r5, r7 \n\t" \
677  "mov r3, r8 \n\t" \
678  "mul r7, r3 \n\t" \
679  "lsr r3, r6, #16 \n\t" \
680  "add r5, r5, r3 \n\t" \
681  "lsr r3, r7, #16 \n\t" \
682  "add r5, r5, r3 \n\t" \
683  "add r4, r4, r2 \n\t" \
684  "mov r2, #0 \n\t" \
685  "adc r5, r2 \n\t" \
686  "lsl r3, r6, #16 \n\t" \
687  "add r4, r4, r3 \n\t" \
688  "adc r5, r2 \n\t" \
689  "lsl r3, r7, #16 \n\t" \
690  "add r4, r4, r3 \n\t" \
691  "adc r5, r2 \n\t" \
692  "ldr r3, [r1] \n\t" \
693  "add r4, r4, r3 \n\t" \
694  "adc r2, r5 \n\t" \
695  "stmia r1!, {r4} \n\t"
696 
697 #define MULADDC_STOP \
698  "str r2, %0 \n\t" \
699  "str r1, %1 \n\t" \
700  "str r0, %2 \n\t" \
701  : "=m" (c), "=m" (d), "=m" (s) \
702  : "m" (s), "m" (d), "m" (c), "m" (b) \
703  : "r0", "r1", "r2", "r3", "r4", "r5", \
704  "r6", "r7", "r8", "r9", "cc" \
705  );
706 
707 #elif (__ARM_ARCH >= 6) && \
708  defined (__ARM_FEATURE_DSP) && (__ARM_FEATURE_DSP == 1)
709 
710 #define MULADDC_INIT \
711  asm(
712 
713 #define MULADDC_CORE \
714  "ldr r0, [%0], #4 \n\t" \
715  "ldr r1, [%1] \n\t" \
716  "umaal r1, %2, %3, r0 \n\t" \
717  "str r1, [%1], #4 \n\t"
718 
719 #define MULADDC_STOP \
720  : "=r" (s), "=r" (d), "=r" (c) \
721  : "r" (b), "0" (s), "1" (d), "2" (c) \
722  : "r0", "r1", "memory" \
723  );
724 
725 #else
726 
727 #define MULADDC_INIT \
728  asm( \
729  "ldr r0, %3 \n\t" \
730  "ldr r1, %4 \n\t" \
731  "ldr r2, %5 \n\t" \
732  "ldr r3, %6 \n\t"
733 
734 #define MULADDC_CORE \
735  "ldr r4, [r0], #4 \n\t" \
736  "mov r5, #0 \n\t" \
737  "ldr r6, [r1] \n\t" \
738  "umlal r2, r5, r3, r4 \n\t" \
739  "adds r7, r6, r2 \n\t" \
740  "adc r2, r5, #0 \n\t" \
741  "str r7, [r1], #4 \n\t"
742 
743 #define MULADDC_STOP \
744  "str r2, %0 \n\t" \
745  "str r1, %1 \n\t" \
746  "str r0, %2 \n\t" \
747  : "=m" (c), "=m" (d), "=m" (s) \
748  : "m" (s), "m" (d), "m" (c), "m" (b) \
749  : "r0", "r1", "r2", "r3", "r4", "r5", \
750  "r6", "r7", "cc" \
751  );
752 
753 #endif /* Thumb */
754 
755 #endif /* ARMv3 */
756 
757 #if defined(__alpha__)
758 
759 #define MULADDC_INIT \
760  asm( \
761  "ldq $1, %3 \n\t" \
762  "ldq $2, %4 \n\t" \
763  "ldq $3, %5 \n\t" \
764  "ldq $4, %6 \n\t"
765 
766 #define MULADDC_CORE \
767  "ldq $6, 0($1) \n\t" \
768  "addq $1, 8, $1 \n\t" \
769  "mulq $6, $4, $7 \n\t" \
770  "umulh $6, $4, $6 \n\t" \
771  "addq $7, $3, $7 \n\t" \
772  "cmpult $7, $3, $3 \n\t" \
773  "ldq $5, 0($2) \n\t" \
774  "addq $7, $5, $7 \n\t" \
775  "cmpult $7, $5, $5 \n\t" \
776  "stq $7, 0($2) \n\t" \
777  "addq $2, 8, $2 \n\t" \
778  "addq $6, $3, $3 \n\t" \
779  "addq $5, $3, $3 \n\t"
780 
781 #define MULADDC_STOP \
782  "stq $3, %0 \n\t" \
783  "stq $2, %1 \n\t" \
784  "stq $1, %2 \n\t" \
785  : "=m" (c), "=m" (d), "=m" (s) \
786  : "m" (s), "m" (d), "m" (c), "m" (b) \
787  : "$1", "$2", "$3", "$4", "$5", "$6", "$7" \
788  );
789 #endif /* Alpha */
790 
791 #if defined(__mips__) && !defined(__mips64)
792 
793 #define MULADDC_INIT \
794  asm( \
795  "lw $10, %3 \n\t" \
796  "lw $11, %4 \n\t" \
797  "lw $12, %5 \n\t" \
798  "lw $13, %6 \n\t"
799 
800 #define MULADDC_CORE \
801  "lw $14, 0($10) \n\t" \
802  "multu $13, $14 \n\t" \
803  "addi $10, $10, 4 \n\t" \
804  "mflo $14 \n\t" \
805  "mfhi $9 \n\t" \
806  "addu $14, $12, $14 \n\t" \
807  "lw $15, 0($11) \n\t" \
808  "sltu $12, $14, $12 \n\t" \
809  "addu $15, $14, $15 \n\t" \
810  "sltu $14, $15, $14 \n\t" \
811  "addu $12, $12, $9 \n\t" \
812  "sw $15, 0($11) \n\t" \
813  "addu $12, $12, $14 \n\t" \
814  "addi $11, $11, 4 \n\t"
815 
816 #define MULADDC_STOP \
817  "sw $12, %0 \n\t" \
818  "sw $11, %1 \n\t" \
819  "sw $10, %2 \n\t" \
820  : "=m" (c), "=m" (d), "=m" (s) \
821  : "m" (s), "m" (d), "m" (c), "m" (b) \
822  : "$9", "$10", "$11", "$12", "$13", "$14", "$15", "lo", "hi" \
823  );
824 
825 #endif /* MIPS */
826 #endif /* GNUC */
827 
828 #if (defined(_MSC_VER) && defined(_M_IX86)) || defined(__WATCOMC__)
829 
830 #define MULADDC_INIT \
831  __asm mov esi, s \
832  __asm mov edi, d \
833  __asm mov ecx, c \
834  __asm mov ebx, b
835 
836 #define MULADDC_CORE \
837  __asm lodsd \
838  __asm mul ebx \
839  __asm add eax, ecx \
840  __asm adc edx, 0 \
841  __asm add eax, [edi] \
842  __asm adc edx, 0 \
843  __asm mov ecx, edx \
844  __asm stosd
845 
846 #if defined(MBEDTLS_HAVE_SSE2)
847 
848 #define EMIT __asm _emit
849 
850 #define MULADDC_HUIT \
851  EMIT 0x0F EMIT 0x6E EMIT 0xC9 \
852  EMIT 0x0F EMIT 0x6E EMIT 0xC3 \
853  EMIT 0x0F EMIT 0x6E EMIT 0x1F \
854  EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
855  EMIT 0x0F EMIT 0x6E EMIT 0x16 \
856  EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
857  EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x04 \
858  EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
859  EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x08 \
860  EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
861  EMIT 0x0F EMIT 0x6E EMIT 0x7E EMIT 0x0C \
862  EMIT 0x0F EMIT 0xF4 EMIT 0xF8 \
863  EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
864  EMIT 0x0F EMIT 0x6E EMIT 0x5F EMIT 0x04 \
865  EMIT 0x0F EMIT 0xD4 EMIT 0xDC \
866  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x08 \
867  EMIT 0x0F EMIT 0xD4 EMIT 0xEE \
868  EMIT 0x0F EMIT 0x6E EMIT 0x67 EMIT 0x0C \
869  EMIT 0x0F EMIT 0xD4 EMIT 0xFC \
870  EMIT 0x0F EMIT 0x7E EMIT 0x0F \
871  EMIT 0x0F EMIT 0x6E EMIT 0x56 EMIT 0x10 \
872  EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
873  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
874  EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x14 \
875  EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
876  EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
877  EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x18 \
878  EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
879  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x04 \
880  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
881  EMIT 0x0F EMIT 0x6E EMIT 0x5E EMIT 0x1C \
882  EMIT 0x0F EMIT 0xF4 EMIT 0xD8 \
883  EMIT 0x0F EMIT 0xD4 EMIT 0xCD \
884  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x10 \
885  EMIT 0x0F EMIT 0xD4 EMIT 0xD5 \
886  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x08 \
887  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
888  EMIT 0x0F EMIT 0xD4 EMIT 0xCF \
889  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x14 \
890  EMIT 0x0F EMIT 0xD4 EMIT 0xE5 \
891  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x0C \
892  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
893  EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
894  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x18 \
895  EMIT 0x0F EMIT 0xD4 EMIT 0xF5 \
896  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x10 \
897  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
898  EMIT 0x0F EMIT 0xD4 EMIT 0xCC \
899  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x1C \
900  EMIT 0x0F EMIT 0xD4 EMIT 0xDD \
901  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x14 \
902  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
903  EMIT 0x0F EMIT 0xD4 EMIT 0xCE \
904  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x18 \
905  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
906  EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
907  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x1C \
908  EMIT 0x83 EMIT 0xC7 EMIT 0x20 \
909  EMIT 0x83 EMIT 0xC6 EMIT 0x20 \
910  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
911  EMIT 0x0F EMIT 0x7E EMIT 0xC9
912 
913 #define MULADDC_STOP \
914  EMIT 0x0F EMIT 0x77 \
915  __asm mov c, ecx \
916  __asm mov d, edi \
917  __asm mov s, esi \
918 
919 #else
920 
921 #define MULADDC_STOP \
922  __asm mov c, ecx \
923  __asm mov d, edi \
924  __asm mov s, esi \
925 
926 #endif /* SSE2 */
927 #endif /* MSVC */
928 
929 #endif /* MBEDTLS_HAVE_ASM */
930 
931 #if !defined(MULADDC_CORE)
932 #if defined(MBEDTLS_HAVE_UDBL)
933 
934 #define MULADDC_INIT \
935 { \
936  mbedtls_t_udbl r; \
937  mbedtls_mpi_uint r0, r1;
938 
939 #define MULADDC_CORE \
940  r = *(s++) * (mbedtls_t_udbl) b; \
941  r0 = (mbedtls_mpi_uint) r; \
942  r1 = (mbedtls_mpi_uint)( r >> biL ); \
943  r0 += c; r1 += (r0 < c); \
944  r0 += *d; r1 += (r0 < *d); \
945  c = r1; *(d++) = r0;
946 
947 #define MULADDC_STOP \
948 }
949 
950 #else
951 #define MULADDC_INIT \
952 { \
953  mbedtls_mpi_uint s0, s1, b0, b1; \
954  mbedtls_mpi_uint r0, r1, rx, ry; \
955  b0 = ( b << biH ) >> biH; \
956  b1 = ( b >> biH );
957 
958 #define MULADDC_CORE \
959  s0 = ( *s << biH ) >> biH; \
960  s1 = ( *s >> biH ); s++; \
961  rx = s0 * b1; r0 = s0 * b0; \
962  ry = s1 * b0; r1 = s1 * b1; \
963  r1 += ( rx >> biH ); \
964  r1 += ( ry >> biH ); \
965  rx <<= biH; ry <<= biH; \
966  r0 += rx; r1 += (r0 < rx); \
967  r0 += ry; r1 += (r0 < ry); \
968  r0 += c; r1 += (r0 < c); \
969  r0 += *d; r1 += (r0 < *d); \
970  c = r1; *(d++) = r0;
971 
972 #define MULADDC_STOP \
973 }
974 
975 #endif /* C (generic) */
976 #endif /* C (longlong) */
977 
978 #endif /* bn_mul.h */
Multi-precision integer library.
Configuration options (set of defines)