bn_mul.h 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974
  1. /**
  2. * \file bn_mul.h
  3. *
  4. * \brief Multi-precision integer library
  5. */
  6. /*
  7. * Copyright The Mbed TLS Contributors
  8. * SPDX-License-Identifier: Apache-2.0
  9. *
  10. * Licensed under the Apache License, Version 2.0 (the "License"); you may
  11. * not use this file except in compliance with the License.
  12. * You may obtain a copy of the License at
  13. *
  14. * http://www.apache.org/licenses/LICENSE-2.0
  15. *
  16. * Unless required by applicable law or agreed to in writing, software
  17. * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
  18. * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  19. * See the License for the specific language governing permissions and
  20. * limitations under the License.
  21. */
  22. /*
  23. * Multiply source vector [s] with b, add result
  24. * to destination vector [d] and set carry c.
  25. *
  26. * Currently supports:
  27. *
  28. * . IA-32 (386+) . AMD64 / EM64T
  29. * . IA-32 (SSE2) . Motorola 68000
  30. * . PowerPC, 32-bit . MicroBlaze
  31. * . PowerPC, 64-bit . TriCore
  32. * . SPARC v8 . ARM v3+
  33. * . Alpha . MIPS32
  34. * . C, longlong . C, generic
  35. */
  36. #ifndef MBEDTLS_BN_MUL_H
  37. #define MBEDTLS_BN_MUL_H
  38. #include "mbedtls/build_info.h"
  39. #include "mbedtls/bignum.h"
  40. /*
  41. * Conversion macros for embedded constants:
  42. * build lists of mbedtls_mpi_uint's from lists of unsigned char's grouped by 8, 4 or 2
  43. */
  44. #if defined(MBEDTLS_HAVE_INT32)
  45. #define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
  46. ( (mbedtls_mpi_uint) (a) << 0 ) | \
  47. ( (mbedtls_mpi_uint) (b) << 8 ) | \
  48. ( (mbedtls_mpi_uint) (c) << 16 ) | \
  49. ( (mbedtls_mpi_uint) (d) << 24 )
  50. #define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
  51. MBEDTLS_BYTES_TO_T_UINT_4( a, b, 0, 0 )
  52. #define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
  53. MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ), \
  54. MBEDTLS_BYTES_TO_T_UINT_4( e, f, g, h )
  55. #else /* 64-bits */
  56. #define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
  57. ( (mbedtls_mpi_uint) (a) << 0 ) | \
  58. ( (mbedtls_mpi_uint) (b) << 8 ) | \
  59. ( (mbedtls_mpi_uint) (c) << 16 ) | \
  60. ( (mbedtls_mpi_uint) (d) << 24 ) | \
  61. ( (mbedtls_mpi_uint) (e) << 32 ) | \
  62. ( (mbedtls_mpi_uint) (f) << 40 ) | \
  63. ( (mbedtls_mpi_uint) (g) << 48 ) | \
  64. ( (mbedtls_mpi_uint) (h) << 56 )
  65. #define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
  66. MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, 0, 0, 0, 0 )
  67. #define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
  68. MBEDTLS_BYTES_TO_T_UINT_8( a, b, 0, 0, 0, 0, 0, 0 )
  69. #endif /* bits in mbedtls_mpi_uint */
  70. #if defined(MBEDTLS_HAVE_ASM)
  71. #ifndef asm
  72. #define asm __asm
  73. #endif
  74. /* armcc5 --gnu defines __GNUC__ but doesn't support GNU's extended asm */
  75. #if defined(__GNUC__) && \
  76. ( !defined(__ARMCC_VERSION) || __ARMCC_VERSION >= 6000000 )
  77. /*
  78. * Disable use of the i386 assembly code below if option -O0, to disable all
  79. * compiler optimisations, is passed, detected with __OPTIMIZE__
  80. * This is done as the number of registers used in the assembly code doesn't
  81. * work with the -O0 option.
  82. */
  83. #if defined(__i386__) && defined(__OPTIMIZE__)
  84. #define MULADDC_INIT \
  85. asm( \
  86. "movl %%ebx, %0 \n\t" \
  87. "movl %5, %%esi \n\t" \
  88. "movl %6, %%edi \n\t" \
  89. "movl %7, %%ecx \n\t" \
  90. "movl %8, %%ebx \n\t"
  91. #define MULADDC_CORE \
  92. "lodsl \n\t" \
  93. "mull %%ebx \n\t" \
  94. "addl %%ecx, %%eax \n\t" \
  95. "adcl $0, %%edx \n\t" \
  96. "addl (%%edi), %%eax \n\t" \
  97. "adcl $0, %%edx \n\t" \
  98. "movl %%edx, %%ecx \n\t" \
  99. "stosl \n\t"
  100. #if defined(MBEDTLS_HAVE_SSE2)
  101. #define MULADDC_HUIT \
  102. "movd %%ecx, %%mm1 \n\t" \
  103. "movd %%ebx, %%mm0 \n\t" \
  104. "movd (%%edi), %%mm3 \n\t" \
  105. "paddq %%mm3, %%mm1 \n\t" \
  106. "movd (%%esi), %%mm2 \n\t" \
  107. "pmuludq %%mm0, %%mm2 \n\t" \
  108. "movd 4(%%esi), %%mm4 \n\t" \
  109. "pmuludq %%mm0, %%mm4 \n\t" \
  110. "movd 8(%%esi), %%mm6 \n\t" \
  111. "pmuludq %%mm0, %%mm6 \n\t" \
  112. "movd 12(%%esi), %%mm7 \n\t" \
  113. "pmuludq %%mm0, %%mm7 \n\t" \
  114. "paddq %%mm2, %%mm1 \n\t" \
  115. "movd 4(%%edi), %%mm3 \n\t" \
  116. "paddq %%mm4, %%mm3 \n\t" \
  117. "movd 8(%%edi), %%mm5 \n\t" \
  118. "paddq %%mm6, %%mm5 \n\t" \
  119. "movd 12(%%edi), %%mm4 \n\t" \
  120. "paddq %%mm4, %%mm7 \n\t" \
  121. "movd %%mm1, (%%edi) \n\t" \
  122. "movd 16(%%esi), %%mm2 \n\t" \
  123. "pmuludq %%mm0, %%mm2 \n\t" \
  124. "psrlq $32, %%mm1 \n\t" \
  125. "movd 20(%%esi), %%mm4 \n\t" \
  126. "pmuludq %%mm0, %%mm4 \n\t" \
  127. "paddq %%mm3, %%mm1 \n\t" \
  128. "movd 24(%%esi), %%mm6 \n\t" \
  129. "pmuludq %%mm0, %%mm6 \n\t" \
  130. "movd %%mm1, 4(%%edi) \n\t" \
  131. "psrlq $32, %%mm1 \n\t" \
  132. "movd 28(%%esi), %%mm3 \n\t" \
  133. "pmuludq %%mm0, %%mm3 \n\t" \
  134. "paddq %%mm5, %%mm1 \n\t" \
  135. "movd 16(%%edi), %%mm5 \n\t" \
  136. "paddq %%mm5, %%mm2 \n\t" \
  137. "movd %%mm1, 8(%%edi) \n\t" \
  138. "psrlq $32, %%mm1 \n\t" \
  139. "paddq %%mm7, %%mm1 \n\t" \
  140. "movd 20(%%edi), %%mm5 \n\t" \
  141. "paddq %%mm5, %%mm4 \n\t" \
  142. "movd %%mm1, 12(%%edi) \n\t" \
  143. "psrlq $32, %%mm1 \n\t" \
  144. "paddq %%mm2, %%mm1 \n\t" \
  145. "movd 24(%%edi), %%mm5 \n\t" \
  146. "paddq %%mm5, %%mm6 \n\t" \
  147. "movd %%mm1, 16(%%edi) \n\t" \
  148. "psrlq $32, %%mm1 \n\t" \
  149. "paddq %%mm4, %%mm1 \n\t" \
  150. "movd 28(%%edi), %%mm5 \n\t" \
  151. "paddq %%mm5, %%mm3 \n\t" \
  152. "movd %%mm1, 20(%%edi) \n\t" \
  153. "psrlq $32, %%mm1 \n\t" \
  154. "paddq %%mm6, %%mm1 \n\t" \
  155. "movd %%mm1, 24(%%edi) \n\t" \
  156. "psrlq $32, %%mm1 \n\t" \
  157. "paddq %%mm3, %%mm1 \n\t" \
  158. "movd %%mm1, 28(%%edi) \n\t" \
  159. "addl $32, %%edi \n\t" \
  160. "addl $32, %%esi \n\t" \
  161. "psrlq $32, %%mm1 \n\t" \
  162. "movd %%mm1, %%ecx \n\t"
  163. #define MULADDC_STOP \
  164. "emms \n\t" \
  165. "movl %4, %%ebx \n\t" \
  166. "movl %%ecx, %1 \n\t" \
  167. "movl %%edi, %2 \n\t" \
  168. "movl %%esi, %3 \n\t" \
  169. : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
  170. : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
  171. : "eax", "ebx", "ecx", "edx", "esi", "edi" \
  172. );
  173. #else
  174. #define MULADDC_STOP \
  175. "movl %4, %%ebx \n\t" \
  176. "movl %%ecx, %1 \n\t" \
  177. "movl %%edi, %2 \n\t" \
  178. "movl %%esi, %3 \n\t" \
  179. : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
  180. : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
  181. : "eax", "ebx", "ecx", "edx", "esi", "edi" \
  182. );
  183. #endif /* SSE2 */
  184. #endif /* i386 */
  185. #if defined(__amd64__) || defined (__x86_64__)
  186. #define MULADDC_INIT \
  187. asm( \
  188. "xorq %%r8, %%r8\n"
  189. #define MULADDC_CORE \
  190. "movq (%%rsi), %%rax\n" \
  191. "mulq %%rbx\n" \
  192. "addq $8, %%rsi\n" \
  193. "addq %%rcx, %%rax\n" \
  194. "movq %%r8, %%rcx\n" \
  195. "adcq $0, %%rdx\n" \
  196. "nop \n" \
  197. "addq %%rax, (%%rdi)\n" \
  198. "adcq %%rdx, %%rcx\n" \
  199. "addq $8, %%rdi\n"
  200. #define MULADDC_STOP \
  201. : "+c" (c), "+D" (d), "+S" (s), "+m" (*(uint64_t (*)[16]) d) \
  202. : "b" (b), "m" (*(const uint64_t (*)[16]) s) \
  203. : "rax", "rdx", "r8" \
  204. );
  205. #endif /* AMD64 */
  206. #if defined(__aarch64__)
  207. #define MULADDC_INIT \
  208. asm(
  209. #define MULADDC_CORE \
  210. "ldr x4, [%2], #8 \n\t" \
  211. "ldr x5, [%1] \n\t" \
  212. "mul x6, x4, %4 \n\t" \
  213. "umulh x7, x4, %4 \n\t" \
  214. "adds x5, x5, x6 \n\t" \
  215. "adc x7, x7, xzr \n\t" \
  216. "adds x5, x5, %0 \n\t" \
  217. "adc %0, x7, xzr \n\t" \
  218. "str x5, [%1], #8 \n\t"
  219. #define MULADDC_STOP \
  220. : "+r" (c), "+r" (d), "+r" (s), "+m" (*(uint64_t (*)[16]) d) \
  221. : "r" (b), "m" (*(const uint64_t (*)[16]) s) \
  222. : "x4", "x5", "x6", "x7", "cc" \
  223. );
  224. #endif /* Aarch64 */
  225. #if defined(__mc68020__) || defined(__mcpu32__)
  226. #define MULADDC_INIT \
  227. asm( \
  228. "movl %3, %%a2 \n\t" \
  229. "movl %4, %%a3 \n\t" \
  230. "movl %5, %%d3 \n\t" \
  231. "movl %6, %%d2 \n\t" \
  232. "moveq #0, %%d0 \n\t"
  233. #define MULADDC_CORE \
  234. "movel %%a2@+, %%d1 \n\t" \
  235. "mulul %%d2, %%d4:%%d1 \n\t" \
  236. "addl %%d3, %%d1 \n\t" \
  237. "addxl %%d0, %%d4 \n\t" \
  238. "moveq #0, %%d3 \n\t" \
  239. "addl %%d1, %%a3@+ \n\t" \
  240. "addxl %%d4, %%d3 \n\t"
  241. #define MULADDC_STOP \
  242. "movl %%d3, %0 \n\t" \
  243. "movl %%a3, %1 \n\t" \
  244. "movl %%a2, %2 \n\t" \
  245. : "=m" (c), "=m" (d), "=m" (s) \
  246. : "m" (s), "m" (d), "m" (c), "m" (b) \
  247. : "d0", "d1", "d2", "d3", "d4", "a2", "a3" \
  248. );
  249. #define MULADDC_HUIT \
  250. "movel %%a2@+, %%d1 \n\t" \
  251. "mulul %%d2, %%d4:%%d1 \n\t" \
  252. "addxl %%d3, %%d1 \n\t" \
  253. "addxl %%d0, %%d4 \n\t" \
  254. "addl %%d1, %%a3@+ \n\t" \
  255. "movel %%a2@+, %%d1 \n\t" \
  256. "mulul %%d2, %%d3:%%d1 \n\t" \
  257. "addxl %%d4, %%d1 \n\t" \
  258. "addxl %%d0, %%d3 \n\t" \
  259. "addl %%d1, %%a3@+ \n\t" \
  260. "movel %%a2@+, %%d1 \n\t" \
  261. "mulul %%d2, %%d4:%%d1 \n\t" \
  262. "addxl %%d3, %%d1 \n\t" \
  263. "addxl %%d0, %%d4 \n\t" \
  264. "addl %%d1, %%a3@+ \n\t" \
  265. "movel %%a2@+, %%d1 \n\t" \
  266. "mulul %%d2, %%d3:%%d1 \n\t" \
  267. "addxl %%d4, %%d1 \n\t" \
  268. "addxl %%d0, %%d3 \n\t" \
  269. "addl %%d1, %%a3@+ \n\t" \
  270. "movel %%a2@+, %%d1 \n\t" \
  271. "mulul %%d2, %%d4:%%d1 \n\t" \
  272. "addxl %%d3, %%d1 \n\t" \
  273. "addxl %%d0, %%d4 \n\t" \
  274. "addl %%d1, %%a3@+ \n\t" \
  275. "movel %%a2@+, %%d1 \n\t" \
  276. "mulul %%d2, %%d3:%%d1 \n\t" \
  277. "addxl %%d4, %%d1 \n\t" \
  278. "addxl %%d0, %%d3 \n\t" \
  279. "addl %%d1, %%a3@+ \n\t" \
  280. "movel %%a2@+, %%d1 \n\t" \
  281. "mulul %%d2, %%d4:%%d1 \n\t" \
  282. "addxl %%d3, %%d1 \n\t" \
  283. "addxl %%d0, %%d4 \n\t" \
  284. "addl %%d1, %%a3@+ \n\t" \
  285. "movel %%a2@+, %%d1 \n\t" \
  286. "mulul %%d2, %%d3:%%d1 \n\t" \
  287. "addxl %%d4, %%d1 \n\t" \
  288. "addxl %%d0, %%d3 \n\t" \
  289. "addl %%d1, %%a3@+ \n\t" \
  290. "addxl %%d0, %%d3 \n\t"
  291. #endif /* MC68000 */
  292. #if defined(__powerpc64__) || defined(__ppc64__)
  293. #if defined(__MACH__) && defined(__APPLE__)
  294. #define MULADDC_INIT \
  295. asm( \
  296. "ld r3, %3 \n\t" \
  297. "ld r4, %4 \n\t" \
  298. "ld r5, %5 \n\t" \
  299. "ld r6, %6 \n\t" \
  300. "addi r3, r3, -8 \n\t" \
  301. "addi r4, r4, -8 \n\t" \
  302. "addic r5, r5, 0 \n\t"
  303. #define MULADDC_CORE \
  304. "ldu r7, 8(r3) \n\t" \
  305. "mulld r8, r7, r6 \n\t" \
  306. "mulhdu r9, r7, r6 \n\t" \
  307. "adde r8, r8, r5 \n\t" \
  308. "ld r7, 8(r4) \n\t" \
  309. "addze r5, r9 \n\t" \
  310. "addc r8, r8, r7 \n\t" \
  311. "stdu r8, 8(r4) \n\t"
  312. #define MULADDC_STOP \
  313. "addze r5, r5 \n\t" \
  314. "addi r4, r4, 8 \n\t" \
  315. "addi r3, r3, 8 \n\t" \
  316. "std r5, %0 \n\t" \
  317. "std r4, %1 \n\t" \
  318. "std r3, %2 \n\t" \
  319. : "=m" (c), "=m" (d), "=m" (s) \
  320. : "m" (s), "m" (d), "m" (c), "m" (b) \
  321. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  322. );
  323. #else /* __MACH__ && __APPLE__ */
  324. #define MULADDC_INIT \
  325. asm( \
  326. "ld %%r3, %3 \n\t" \
  327. "ld %%r4, %4 \n\t" \
  328. "ld %%r5, %5 \n\t" \
  329. "ld %%r6, %6 \n\t" \
  330. "addi %%r3, %%r3, -8 \n\t" \
  331. "addi %%r4, %%r4, -8 \n\t" \
  332. "addic %%r5, %%r5, 0 \n\t"
  333. #define MULADDC_CORE \
  334. "ldu %%r7, 8(%%r3) \n\t" \
  335. "mulld %%r8, %%r7, %%r6 \n\t" \
  336. "mulhdu %%r9, %%r7, %%r6 \n\t" \
  337. "adde %%r8, %%r8, %%r5 \n\t" \
  338. "ld %%r7, 8(%%r4) \n\t" \
  339. "addze %%r5, %%r9 \n\t" \
  340. "addc %%r8, %%r8, %%r7 \n\t" \
  341. "stdu %%r8, 8(%%r4) \n\t"
  342. #define MULADDC_STOP \
  343. "addze %%r5, %%r5 \n\t" \
  344. "addi %%r4, %%r4, 8 \n\t" \
  345. "addi %%r3, %%r3, 8 \n\t" \
  346. "std %%r5, %0 \n\t" \
  347. "std %%r4, %1 \n\t" \
  348. "std %%r3, %2 \n\t" \
  349. : "=m" (c), "=m" (d), "=m" (s) \
  350. : "m" (s), "m" (d), "m" (c), "m" (b) \
  351. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  352. );
  353. #endif /* __MACH__ && __APPLE__ */
  354. #elif defined(__powerpc__) || defined(__ppc__) /* end PPC64/begin PPC32 */
  355. #if defined(__MACH__) && defined(__APPLE__)
  356. #define MULADDC_INIT \
  357. asm( \
  358. "lwz r3, %3 \n\t" \
  359. "lwz r4, %4 \n\t" \
  360. "lwz r5, %5 \n\t" \
  361. "lwz r6, %6 \n\t" \
  362. "addi r3, r3, -4 \n\t" \
  363. "addi r4, r4, -4 \n\t" \
  364. "addic r5, r5, 0 \n\t"
  365. #define MULADDC_CORE \
  366. "lwzu r7, 4(r3) \n\t" \
  367. "mullw r8, r7, r6 \n\t" \
  368. "mulhwu r9, r7, r6 \n\t" \
  369. "adde r8, r8, r5 \n\t" \
  370. "lwz r7, 4(r4) \n\t" \
  371. "addze r5, r9 \n\t" \
  372. "addc r8, r8, r7 \n\t" \
  373. "stwu r8, 4(r4) \n\t"
  374. #define MULADDC_STOP \
  375. "addze r5, r5 \n\t" \
  376. "addi r4, r4, 4 \n\t" \
  377. "addi r3, r3, 4 \n\t" \
  378. "stw r5, %0 \n\t" \
  379. "stw r4, %1 \n\t" \
  380. "stw r3, %2 \n\t" \
  381. : "=m" (c), "=m" (d), "=m" (s) \
  382. : "m" (s), "m" (d), "m" (c), "m" (b) \
  383. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  384. );
  385. #else /* __MACH__ && __APPLE__ */
  386. #define MULADDC_INIT \
  387. asm( \
  388. "lwz %%r3, %3 \n\t" \
  389. "lwz %%r4, %4 \n\t" \
  390. "lwz %%r5, %5 \n\t" \
  391. "lwz %%r6, %6 \n\t" \
  392. "addi %%r3, %%r3, -4 \n\t" \
  393. "addi %%r4, %%r4, -4 \n\t" \
  394. "addic %%r5, %%r5, 0 \n\t"
  395. #define MULADDC_CORE \
  396. "lwzu %%r7, 4(%%r3) \n\t" \
  397. "mullw %%r8, %%r7, %%r6 \n\t" \
  398. "mulhwu %%r9, %%r7, %%r6 \n\t" \
  399. "adde %%r8, %%r8, %%r5 \n\t" \
  400. "lwz %%r7, 4(%%r4) \n\t" \
  401. "addze %%r5, %%r9 \n\t" \
  402. "addc %%r8, %%r8, %%r7 \n\t" \
  403. "stwu %%r8, 4(%%r4) \n\t"
  404. #define MULADDC_STOP \
  405. "addze %%r5, %%r5 \n\t" \
  406. "addi %%r4, %%r4, 4 \n\t" \
  407. "addi %%r3, %%r3, 4 \n\t" \
  408. "stw %%r5, %0 \n\t" \
  409. "stw %%r4, %1 \n\t" \
  410. "stw %%r3, %2 \n\t" \
  411. : "=m" (c), "=m" (d), "=m" (s) \
  412. : "m" (s), "m" (d), "m" (c), "m" (b) \
  413. : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
  414. );
  415. #endif /* __MACH__ && __APPLE__ */
  416. #endif /* PPC32 */
  417. /*
  418. * The Sparc(64) assembly is reported to be broken.
  419. * Disable it for now, until we're able to fix it.
  420. */
  421. #if 0 && defined(__sparc__)
  422. #if defined(__sparc64__)
  423. #define MULADDC_INIT \
  424. asm( \
  425. "ldx %3, %%o0 \n\t" \
  426. "ldx %4, %%o1 \n\t" \
  427. "ld %5, %%o2 \n\t" \
  428. "ld %6, %%o3 \n\t"
  429. #define MULADDC_CORE \
  430. "ld [%%o0], %%o4 \n\t" \
  431. "inc 4, %%o0 \n\t" \
  432. "ld [%%o1], %%o5 \n\t" \
  433. "umul %%o3, %%o4, %%o4 \n\t" \
  434. "addcc %%o4, %%o2, %%o4 \n\t" \
  435. "rd %%y, %%g1 \n\t" \
  436. "addx %%g1, 0, %%g1 \n\t" \
  437. "addcc %%o4, %%o5, %%o4 \n\t" \
  438. "st %%o4, [%%o1] \n\t" \
  439. "addx %%g1, 0, %%o2 \n\t" \
  440. "inc 4, %%o1 \n\t"
  441. #define MULADDC_STOP \
  442. "st %%o2, %0 \n\t" \
  443. "stx %%o1, %1 \n\t" \
  444. "stx %%o0, %2 \n\t" \
  445. : "=m" (c), "=m" (d), "=m" (s) \
  446. : "m" (s), "m" (d), "m" (c), "m" (b) \
  447. : "g1", "o0", "o1", "o2", "o3", "o4", \
  448. "o5" \
  449. );
  450. #else /* __sparc64__ */
  451. #define MULADDC_INIT \
  452. asm( \
  453. "ld %3, %%o0 \n\t" \
  454. "ld %4, %%o1 \n\t" \
  455. "ld %5, %%o2 \n\t" \
  456. "ld %6, %%o3 \n\t"
  457. #define MULADDC_CORE \
  458. "ld [%%o0], %%o4 \n\t" \
  459. "inc 4, %%o0 \n\t" \
  460. "ld [%%o1], %%o5 \n\t" \
  461. "umul %%o3, %%o4, %%o4 \n\t" \
  462. "addcc %%o4, %%o2, %%o4 \n\t" \
  463. "rd %%y, %%g1 \n\t" \
  464. "addx %%g1, 0, %%g1 \n\t" \
  465. "addcc %%o4, %%o5, %%o4 \n\t" \
  466. "st %%o4, [%%o1] \n\t" \
  467. "addx %%g1, 0, %%o2 \n\t" \
  468. "inc 4, %%o1 \n\t"
  469. #define MULADDC_STOP \
  470. "st %%o2, %0 \n\t" \
  471. "st %%o1, %1 \n\t" \
  472. "st %%o0, %2 \n\t" \
  473. : "=m" (c), "=m" (d), "=m" (s) \
  474. : "m" (s), "m" (d), "m" (c), "m" (b) \
  475. : "g1", "o0", "o1", "o2", "o3", "o4", \
  476. "o5" \
  477. );
  478. #endif /* __sparc64__ */
  479. #endif /* __sparc__ */
  480. #if defined(__microblaze__) || defined(microblaze)
  481. #define MULADDC_INIT \
  482. asm( \
  483. "lwi r3, %3 \n\t" \
  484. "lwi r4, %4 \n\t" \
  485. "lwi r5, %5 \n\t" \
  486. "lwi r6, %6 \n\t" \
  487. "andi r7, r6, 0xffff \n\t" \
  488. "bsrli r6, r6, 16 \n\t"
  489. #define MULADDC_CORE \
  490. "lhui r8, r3, 0 \n\t" \
  491. "addi r3, r3, 2 \n\t" \
  492. "lhui r9, r3, 0 \n\t" \
  493. "addi r3, r3, 2 \n\t" \
  494. "mul r10, r9, r6 \n\t" \
  495. "mul r11, r8, r7 \n\t" \
  496. "mul r12, r9, r7 \n\t" \
  497. "mul r13, r8, r6 \n\t" \
  498. "bsrli r8, r10, 16 \n\t" \
  499. "bsrli r9, r11, 16 \n\t" \
  500. "add r13, r13, r8 \n\t" \
  501. "add r13, r13, r9 \n\t" \
  502. "bslli r10, r10, 16 \n\t" \
  503. "bslli r11, r11, 16 \n\t" \
  504. "add r12, r12, r10 \n\t" \
  505. "addc r13, r13, r0 \n\t" \
  506. "add r12, r12, r11 \n\t" \
  507. "addc r13, r13, r0 \n\t" \
  508. "lwi r10, r4, 0 \n\t" \
  509. "add r12, r12, r10 \n\t" \
  510. "addc r13, r13, r0 \n\t" \
  511. "add r12, r12, r5 \n\t" \
  512. "addc r5, r13, r0 \n\t" \
  513. "swi r12, r4, 0 \n\t" \
  514. "addi r4, r4, 4 \n\t"
  515. #define MULADDC_STOP \
  516. "swi r5, %0 \n\t" \
  517. "swi r4, %1 \n\t" \
  518. "swi r3, %2 \n\t" \
  519. : "=m" (c), "=m" (d), "=m" (s) \
  520. : "m" (s), "m" (d), "m" (c), "m" (b) \
  521. : "r3", "r4", "r5", "r6", "r7", "r8", \
  522. "r9", "r10", "r11", "r12", "r13" \
  523. );
  524. #endif /* MicroBlaze */
  525. #if defined(__tricore__)
  526. #define MULADDC_INIT \
  527. asm( \
  528. "ld.a %%a2, %3 \n\t" \
  529. "ld.a %%a3, %4 \n\t" \
  530. "ld.w %%d4, %5 \n\t" \
  531. "ld.w %%d1, %6 \n\t" \
  532. "xor %%d5, %%d5 \n\t"
  533. #define MULADDC_CORE \
  534. "ld.w %%d0, [%%a2+] \n\t" \
  535. "madd.u %%e2, %%e4, %%d0, %%d1 \n\t" \
  536. "ld.w %%d0, [%%a3] \n\t" \
  537. "addx %%d2, %%d2, %%d0 \n\t" \
  538. "addc %%d3, %%d3, 0 \n\t" \
  539. "mov %%d4, %%d3 \n\t" \
  540. "st.w [%%a3+], %%d2 \n\t"
  541. #define MULADDC_STOP \
  542. "st.w %0, %%d4 \n\t" \
  543. "st.a %1, %%a3 \n\t" \
  544. "st.a %2, %%a2 \n\t" \
  545. : "=m" (c), "=m" (d), "=m" (s) \
  546. : "m" (s), "m" (d), "m" (c), "m" (b) \
  547. : "d0", "d1", "e2", "d4", "a2", "a3" \
  548. );
  549. #endif /* TriCore */
  550. /*
  551. * Note, gcc -O0 by default uses r7 for the frame pointer, so it complains about
  552. * our use of r7 below, unless -fomit-frame-pointer is passed.
  553. *
  554. * On the other hand, -fomit-frame-pointer is implied by any -Ox options with
  555. * x !=0, which we can detect using __OPTIMIZE__ (which is also defined by
  556. * clang and armcc5 under the same conditions).
  557. *
  558. * So, only use the optimized assembly below for optimized build, which avoids
  559. * the build error and is pretty reasonable anyway.
  560. */
  561. #if defined(__GNUC__) && !defined(__OPTIMIZE__)
  562. #define MULADDC_CANNOT_USE_R7
  563. #endif
  564. #if defined(__arm__) && !defined(MULADDC_CANNOT_USE_R7)
  565. #if defined(__thumb__) && !defined(__thumb2__)
  566. #define MULADDC_INIT \
  567. asm( \
  568. "ldr r0, %3 \n\t" \
  569. "ldr r1, %4 \n\t" \
  570. "ldr r2, %5 \n\t" \
  571. "ldr r3, %6 \n\t" \
  572. "lsr r7, r3, #16 \n\t" \
  573. "mov r9, r7 \n\t" \
  574. "lsl r7, r3, #16 \n\t" \
  575. "lsr r7, r7, #16 \n\t" \
  576. "mov r8, r7 \n\t"
  577. #define MULADDC_CORE \
  578. "ldmia r0!, {r6} \n\t" \
  579. "lsr r7, r6, #16 \n\t" \
  580. "lsl r6, r6, #16 \n\t" \
  581. "lsr r6, r6, #16 \n\t" \
  582. "mov r4, r8 \n\t" \
  583. "mul r4, r6 \n\t" \
  584. "mov r3, r9 \n\t" \
  585. "mul r6, r3 \n\t" \
  586. "mov r5, r9 \n\t" \
  587. "mul r5, r7 \n\t" \
  588. "mov r3, r8 \n\t" \
  589. "mul r7, r3 \n\t" \
  590. "lsr r3, r6, #16 \n\t" \
  591. "add r5, r5, r3 \n\t" \
  592. "lsr r3, r7, #16 \n\t" \
  593. "add r5, r5, r3 \n\t" \
  594. "add r4, r4, r2 \n\t" \
  595. "mov r2, #0 \n\t" \
  596. "adc r5, r2 \n\t" \
  597. "lsl r3, r6, #16 \n\t" \
  598. "add r4, r4, r3 \n\t" \
  599. "adc r5, r2 \n\t" \
  600. "lsl r3, r7, #16 \n\t" \
  601. "add r4, r4, r3 \n\t" \
  602. "adc r5, r2 \n\t" \
  603. "ldr r3, [r1] \n\t" \
  604. "add r4, r4, r3 \n\t" \
  605. "adc r2, r5 \n\t" \
  606. "stmia r1!, {r4} \n\t"
  607. #define MULADDC_STOP \
  608. "str r2, %0 \n\t" \
  609. "str r1, %1 \n\t" \
  610. "str r0, %2 \n\t" \
  611. : "=m" (c), "=m" (d), "=m" (s) \
  612. : "m" (s), "m" (d), "m" (c), "m" (b) \
  613. : "r0", "r1", "r2", "r3", "r4", "r5", \
  614. "r6", "r7", "r8", "r9", "cc" \
  615. );
  616. #elif (__ARM_ARCH >= 6) && \
  617. defined (__ARM_FEATURE_DSP) && (__ARM_FEATURE_DSP == 1)
  618. #define MULADDC_INIT \
  619. asm(
  620. #define MULADDC_CORE \
  621. "ldr r0, [%0], #4 \n\t" \
  622. "ldr r1, [%1] \n\t" \
  623. "umaal r1, %2, %3, r0 \n\t" \
  624. "str r1, [%1], #4 \n\t"
  625. #define MULADDC_STOP \
  626. : "=r" (s), "=r" (d), "=r" (c) \
  627. : "r" (b), "0" (s), "1" (d), "2" (c) \
  628. : "r0", "r1", "memory" \
  629. );
  630. #else
  631. #define MULADDC_INIT \
  632. asm( \
  633. "ldr r0, %3 \n\t" \
  634. "ldr r1, %4 \n\t" \
  635. "ldr r2, %5 \n\t" \
  636. "ldr r3, %6 \n\t"
  637. #define MULADDC_CORE \
  638. "ldr r4, [r0], #4 \n\t" \
  639. "mov r5, #0 \n\t" \
  640. "ldr r6, [r1] \n\t" \
  641. "umlal r2, r5, r3, r4 \n\t" \
  642. "adds r7, r6, r2 \n\t" \
  643. "adc r2, r5, #0 \n\t" \
  644. "str r7, [r1], #4 \n\t"
  645. #define MULADDC_STOP \
  646. "str r2, %0 \n\t" \
  647. "str r1, %1 \n\t" \
  648. "str r0, %2 \n\t" \
  649. : "=m" (c), "=m" (d), "=m" (s) \
  650. : "m" (s), "m" (d), "m" (c), "m" (b) \
  651. : "r0", "r1", "r2", "r3", "r4", "r5", \
  652. "r6", "r7", "cc" \
  653. );
  654. #endif /* Thumb */
  655. #endif /* ARMv3 */
  656. #if defined(__alpha__)
  657. #define MULADDC_INIT \
  658. asm( \
  659. "ldq $1, %3 \n\t" \
  660. "ldq $2, %4 \n\t" \
  661. "ldq $3, %5 \n\t" \
  662. "ldq $4, %6 \n\t"
  663. #define MULADDC_CORE \
  664. "ldq $6, 0($1) \n\t" \
  665. "addq $1, 8, $1 \n\t" \
  666. "mulq $6, $4, $7 \n\t" \
  667. "umulh $6, $4, $6 \n\t" \
  668. "addq $7, $3, $7 \n\t" \
  669. "cmpult $7, $3, $3 \n\t" \
  670. "ldq $5, 0($2) \n\t" \
  671. "addq $7, $5, $7 \n\t" \
  672. "cmpult $7, $5, $5 \n\t" \
  673. "stq $7, 0($2) \n\t" \
  674. "addq $2, 8, $2 \n\t" \
  675. "addq $6, $3, $3 \n\t" \
  676. "addq $5, $3, $3 \n\t"
  677. #define MULADDC_STOP \
  678. "stq $3, %0 \n\t" \
  679. "stq $2, %1 \n\t" \
  680. "stq $1, %2 \n\t" \
  681. : "=m" (c), "=m" (d), "=m" (s) \
  682. : "m" (s), "m" (d), "m" (c), "m" (b) \
  683. : "$1", "$2", "$3", "$4", "$5", "$6", "$7" \
  684. );
  685. #endif /* Alpha */
  686. #if defined(__mips__) && !defined(__mips64)
  687. #define MULADDC_INIT \
  688. asm( \
  689. "lw $10, %3 \n\t" \
  690. "lw $11, %4 \n\t" \
  691. "lw $12, %5 \n\t" \
  692. "lw $13, %6 \n\t"
  693. #define MULADDC_CORE \
  694. "lw $14, 0($10) \n\t" \
  695. "multu $13, $14 \n\t" \
  696. "addi $10, $10, 4 \n\t" \
  697. "mflo $14 \n\t" \
  698. "mfhi $9 \n\t" \
  699. "addu $14, $12, $14 \n\t" \
  700. "lw $15, 0($11) \n\t" \
  701. "sltu $12, $14, $12 \n\t" \
  702. "addu $15, $14, $15 \n\t" \
  703. "sltu $14, $15, $14 \n\t" \
  704. "addu $12, $12, $9 \n\t" \
  705. "sw $15, 0($11) \n\t" \
  706. "addu $12, $12, $14 \n\t" \
  707. "addi $11, $11, 4 \n\t"
  708. #define MULADDC_STOP \
  709. "sw $12, %0 \n\t" \
  710. "sw $11, %1 \n\t" \
  711. "sw $10, %2 \n\t" \
  712. : "=m" (c), "=m" (d), "=m" (s) \
  713. : "m" (s), "m" (d), "m" (c), "m" (b) \
  714. : "$9", "$10", "$11", "$12", "$13", "$14", "$15", "lo", "hi" \
  715. );
  716. #endif /* MIPS */
  717. #endif /* GNUC */
  718. #if (defined(_MSC_VER) && defined(_M_IX86)) || defined(__WATCOMC__)
  719. #define MULADDC_INIT \
  720. __asm mov esi, s \
  721. __asm mov edi, d \
  722. __asm mov ecx, c \
  723. __asm mov ebx, b
  724. #define MULADDC_CORE \
  725. __asm lodsd \
  726. __asm mul ebx \
  727. __asm add eax, ecx \
  728. __asm adc edx, 0 \
  729. __asm add eax, [edi] \
  730. __asm adc edx, 0 \
  731. __asm mov ecx, edx \
  732. __asm stosd
  733. #if defined(MBEDTLS_HAVE_SSE2)
  734. #define EMIT __asm _emit
  735. #define MULADDC_HUIT \
  736. EMIT 0x0F EMIT 0x6E EMIT 0xC9 \
  737. EMIT 0x0F EMIT 0x6E EMIT 0xC3 \
  738. EMIT 0x0F EMIT 0x6E EMIT 0x1F \
  739. EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
  740. EMIT 0x0F EMIT 0x6E EMIT 0x16 \
  741. EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
  742. EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x04 \
  743. EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
  744. EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x08 \
  745. EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
  746. EMIT 0x0F EMIT 0x6E EMIT 0x7E EMIT 0x0C \
  747. EMIT 0x0F EMIT 0xF4 EMIT 0xF8 \
  748. EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
  749. EMIT 0x0F EMIT 0x6E EMIT 0x5F EMIT 0x04 \
  750. EMIT 0x0F EMIT 0xD4 EMIT 0xDC \
  751. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x08 \
  752. EMIT 0x0F EMIT 0xD4 EMIT 0xEE \
  753. EMIT 0x0F EMIT 0x6E EMIT 0x67 EMIT 0x0C \
  754. EMIT 0x0F EMIT 0xD4 EMIT 0xFC \
  755. EMIT 0x0F EMIT 0x7E EMIT 0x0F \
  756. EMIT 0x0F EMIT 0x6E EMIT 0x56 EMIT 0x10 \
  757. EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
  758. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  759. EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x14 \
  760. EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
  761. EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
  762. EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x18 \
  763. EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
  764. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x04 \
  765. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  766. EMIT 0x0F EMIT 0x6E EMIT 0x5E EMIT 0x1C \
  767. EMIT 0x0F EMIT 0xF4 EMIT 0xD8 \
  768. EMIT 0x0F EMIT 0xD4 EMIT 0xCD \
  769. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x10 \
  770. EMIT 0x0F EMIT 0xD4 EMIT 0xD5 \
  771. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x08 \
  772. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  773. EMIT 0x0F EMIT 0xD4 EMIT 0xCF \
  774. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x14 \
  775. EMIT 0x0F EMIT 0xD4 EMIT 0xE5 \
  776. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x0C \
  777. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  778. EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
  779. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x18 \
  780. EMIT 0x0F EMIT 0xD4 EMIT 0xF5 \
  781. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x10 \
  782. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  783. EMIT 0x0F EMIT 0xD4 EMIT 0xCC \
  784. EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x1C \
  785. EMIT 0x0F EMIT 0xD4 EMIT 0xDD \
  786. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x14 \
  787. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  788. EMIT 0x0F EMIT 0xD4 EMIT 0xCE \
  789. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x18 \
  790. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  791. EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
  792. EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x1C \
  793. EMIT 0x83 EMIT 0xC7 EMIT 0x20 \
  794. EMIT 0x83 EMIT 0xC6 EMIT 0x20 \
  795. EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
  796. EMIT 0x0F EMIT 0x7E EMIT 0xC9
  797. #define MULADDC_STOP \
  798. EMIT 0x0F EMIT 0x77 \
  799. __asm mov c, ecx \
  800. __asm mov d, edi \
  801. __asm mov s, esi \
  802. #else
  803. #define MULADDC_STOP \
  804. __asm mov c, ecx \
  805. __asm mov d, edi \
  806. __asm mov s, esi \
  807. #endif /* SSE2 */
  808. #endif /* MSVC */
  809. #endif /* MBEDTLS_HAVE_ASM */
  810. #if !defined(MULADDC_CORE)
  811. #if defined(MBEDTLS_HAVE_UDBL)
  812. #define MULADDC_INIT \
  813. { \
  814. mbedtls_t_udbl r; \
  815. mbedtls_mpi_uint r0, r1;
  816. #define MULADDC_CORE \
  817. r = *(s++) * (mbedtls_t_udbl) b; \
  818. r0 = (mbedtls_mpi_uint) r; \
  819. r1 = (mbedtls_mpi_uint)( r >> biL ); \
  820. r0 += c; r1 += (r0 < c); \
  821. r0 += *d; r1 += (r0 < *d); \
  822. c = r1; *(d++) = r0;
  823. #define MULADDC_STOP \
  824. }
  825. #else
  826. #define MULADDC_INIT \
  827. { \
  828. mbedtls_mpi_uint s0, s1, b0, b1; \
  829. mbedtls_mpi_uint r0, r1, rx, ry; \
  830. b0 = ( b << biH ) >> biH; \
  831. b1 = ( b >> biH );
  832. #define MULADDC_CORE \
  833. s0 = ( *s << biH ) >> biH; \
  834. s1 = ( *s >> biH ); s++; \
  835. rx = s0 * b1; r0 = s0 * b0; \
  836. ry = s1 * b0; r1 = s1 * b1; \
  837. r1 += ( rx >> biH ); \
  838. r1 += ( ry >> biH ); \
  839. rx <<= biH; ry <<= biH; \
  840. r0 += rx; r1 += (r0 < rx); \
  841. r0 += ry; r1 += (r0 < ry); \
  842. r0 += c; r1 += (r0 < c); \
  843. r0 += *d; r1 += (r0 < *d); \
  844. c = r1; *(d++) = r0;
  845. #define MULADDC_STOP \
  846. }
  847. #endif /* C (generic) */
  848. #endif /* C (longlong) */
  849. #endif /* bn_mul.h */