blob: ab1a66ae55156f915b9cc15696b3747779b70071 [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/**
2 * \file bn_mul.h
Paul Bakkere0ccd0a2009-01-04 16:27:10 +00003 *
Darryl Greena40a1012018-01-05 15:33:17 +00004 * \brief Multi-precision integer library
5 */
6/*
Bence Szépkúti1e148272020-08-07 13:07:28 +02007 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02008 * SPDX-License-Identifier: Apache-2.0
9 *
10 * Licensed under the Apache License, Version 2.0 (the "License"); you may
11 * not use this file except in compliance with the License.
12 * You may obtain a copy of the License at
13 *
14 * http://www.apache.org/licenses/LICENSE-2.0
15 *
16 * Unless required by applicable law or agreed to in writing, software
17 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
18 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
19 * See the License for the specific language governing permissions and
20 * limitations under the License.
Paul Bakker5121ce52009-01-03 21:22:43 +000021 */
22/*
23 * Multiply source vector [s] with b, add result
24 * to destination vector [d] and set carry c.
25 *
26 * Currently supports:
27 *
28 * . IA-32 (386+) . AMD64 / EM64T
29 * . IA-32 (SSE2) . Motorola 68000
30 * . PowerPC, 32-bit . MicroBlaze
31 * . PowerPC, 64-bit . TriCore
32 * . SPARC v8 . ARM v3+
33 * . Alpha . MIPS32
34 * . C, longlong . C, generic
35 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020036#ifndef MBEDTLS_BN_MUL_H
37#define MBEDTLS_BN_MUL_H
Paul Bakker5121ce52009-01-03 21:22:43 +000038
Bence Szépkútic662b362021-05-27 11:25:03 +020039#include "mbedtls/build_info.h"
Ron Eldor8b0cf2e2018-02-14 16:02:41 +020040
Jaeden Ameroc49fbbf2019-07-04 20:01:14 +010041#include "mbedtls/bignum.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000042
Janos Follath8c70e812021-06-24 14:48:38 +010043
44/*
45 * Conversion macros for embedded constants:
46 * build lists of mbedtls_mpi_uint's from lists of unsigned char's grouped by 8, 4 or 2
47 */
48#if defined(MBEDTLS_HAVE_INT32)
49
Gilles Peskine449bd832023-01-11 14:50:10 +010050#define MBEDTLS_BYTES_TO_T_UINT_4(a, b, c, d) \
51 ((mbedtls_mpi_uint) (a) << 0) | \
52 ((mbedtls_mpi_uint) (b) << 8) | \
53 ((mbedtls_mpi_uint) (c) << 16) | \
54 ((mbedtls_mpi_uint) (d) << 24)
Janos Follath8c70e812021-06-24 14:48:38 +010055
Gilles Peskine449bd832023-01-11 14:50:10 +010056#define MBEDTLS_BYTES_TO_T_UINT_2(a, b) \
57 MBEDTLS_BYTES_TO_T_UINT_4(a, b, 0, 0)
Janos Follath8c70e812021-06-24 14:48:38 +010058
Gilles Peskine449bd832023-01-11 14:50:10 +010059#define MBEDTLS_BYTES_TO_T_UINT_8(a, b, c, d, e, f, g, h) \
60 MBEDTLS_BYTES_TO_T_UINT_4(a, b, c, d), \
61 MBEDTLS_BYTES_TO_T_UINT_4(e, f, g, h)
Janos Follath8c70e812021-06-24 14:48:38 +010062
63#else /* 64-bits */
64
Gilles Peskine449bd832023-01-11 14:50:10 +010065#define MBEDTLS_BYTES_TO_T_UINT_8(a, b, c, d, e, f, g, h) \
66 ((mbedtls_mpi_uint) (a) << 0) | \
67 ((mbedtls_mpi_uint) (b) << 8) | \
68 ((mbedtls_mpi_uint) (c) << 16) | \
69 ((mbedtls_mpi_uint) (d) << 24) | \
70 ((mbedtls_mpi_uint) (e) << 32) | \
71 ((mbedtls_mpi_uint) (f) << 40) | \
72 ((mbedtls_mpi_uint) (g) << 48) | \
73 ((mbedtls_mpi_uint) (h) << 56)
Janos Follath8c70e812021-06-24 14:48:38 +010074
Gilles Peskine449bd832023-01-11 14:50:10 +010075#define MBEDTLS_BYTES_TO_T_UINT_4(a, b, c, d) \
76 MBEDTLS_BYTES_TO_T_UINT_8(a, b, c, d, 0, 0, 0, 0)
Janos Follath8c70e812021-06-24 14:48:38 +010077
Gilles Peskine449bd832023-01-11 14:50:10 +010078#define MBEDTLS_BYTES_TO_T_UINT_2(a, b) \
79 MBEDTLS_BYTES_TO_T_UINT_8(a, b, 0, 0, 0, 0, 0, 0)
Janos Follath8c70e812021-06-24 14:48:38 +010080
81#endif /* bits in mbedtls_mpi_uint */
82
David Horstmanncb3b6ae2023-01-04 17:50:08 +000083/* *INDENT-OFF* */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020084#if defined(MBEDTLS_HAVE_ASM)
Paul Bakker5121ce52009-01-03 21:22:43 +000085
Manuel Pégourié-Gonnard854dab92015-08-10 12:08:34 +020086/* armcc5 --gnu defines __GNUC__ but doesn't support GNU's extended asm */
87#if defined(__GNUC__) && \
88 ( !defined(__ARMCC_VERSION) || __ARMCC_VERSION >= 6000000 )
Simon Butcher4b9a3ad2018-07-10 20:18:29 +010089
90/*
Peter Korsgaardc0546e32018-08-27 22:50:57 +020091 * GCC < 5.0 treated the x86 ebx (which is used for the GOT) as a
92 * fixed reserved register when building as PIC, leading to errors
93 * like: bn_mul.h:46:13: error: PIC register clobbered by 'ebx' in 'asm'
94 *
95 * This is fixed by an improved register allocator in GCC 5+. From the
96 * release notes:
97 * Register allocation improvements: Reuse of the PIC hard register,
98 * instead of using a fixed register, was implemented on x86/x86-64
99 * targets. This improves generated PIC code performance as more hard
100 * registers can be used.
101 */
102#if defined(__GNUC__) && __GNUC__ < 5 && defined(__PIC__)
103#define MULADDC_CANNOT_USE_EBX
104#endif
105
106/*
Simon Butcher4b9a3ad2018-07-10 20:18:29 +0100107 * Disable use of the i386 assembly code below if option -O0, to disable all
108 * compiler optimisations, is passed, detected with __OPTIMIZE__
109 * This is done as the number of registers used in the assembly code doesn't
110 * work with the -O0 option.
111 */
Peter Korsgaardc0546e32018-08-27 22:50:57 +0200112#if defined(__i386__) && defined(__OPTIMIZE__) && !defined(MULADDC_CANNOT_USE_EBX)
Paul Bakker5121ce52009-01-03 21:22:43 +0000113
Hanno Beckereacf3b92022-04-06 11:25:22 +0100114#define MULADDC_X1_INIT \
Hanno Beckerefdc5192022-04-11 10:44:02 +0100115 { mbedtls_mpi_uint t; \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200116 asm( \
117 "movl %%ebx, %0 \n\t" \
118 "movl %5, %%esi \n\t" \
119 "movl %6, %%edi \n\t" \
120 "movl %7, %%ecx \n\t" \
121 "movl %8, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000122
Hanno Beckereacf3b92022-04-06 11:25:22 +0100123#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200124 "lodsl \n\t" \
125 "mull %%ebx \n\t" \
126 "addl %%ecx, %%eax \n\t" \
127 "adcl $0, %%edx \n\t" \
128 "addl (%%edi), %%eax \n\t" \
129 "adcl $0, %%edx \n\t" \
130 "movl %%edx, %%ecx \n\t" \
131 "stosl \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000132
Hanno Beckereacf3b92022-04-06 11:25:22 +0100133#define MULADDC_X1_STOP \
134 "movl %4, %%ebx \n\t" \
135 "movl %%ecx, %1 \n\t" \
136 "movl %%edi, %2 \n\t" \
137 "movl %%esi, %3 \n\t" \
138 : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
139 : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
140 : "eax", "ebx", "ecx", "edx", "esi", "edi" \
141 ); }
142
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200143#if defined(MBEDTLS_HAVE_SSE2)
Paul Bakker5121ce52009-01-03 21:22:43 +0000144
Hanno Beckereacf3b92022-04-06 11:25:22 +0100145#define MULADDC_X8_INIT MULADDC_X1_INIT
146
147#define MULADDC_X8_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200148 "movd %%ecx, %%mm1 \n\t" \
149 "movd %%ebx, %%mm0 \n\t" \
150 "movd (%%edi), %%mm3 \n\t" \
151 "paddq %%mm3, %%mm1 \n\t" \
152 "movd (%%esi), %%mm2 \n\t" \
153 "pmuludq %%mm0, %%mm2 \n\t" \
154 "movd 4(%%esi), %%mm4 \n\t" \
155 "pmuludq %%mm0, %%mm4 \n\t" \
156 "movd 8(%%esi), %%mm6 \n\t" \
157 "pmuludq %%mm0, %%mm6 \n\t" \
158 "movd 12(%%esi), %%mm7 \n\t" \
159 "pmuludq %%mm0, %%mm7 \n\t" \
160 "paddq %%mm2, %%mm1 \n\t" \
161 "movd 4(%%edi), %%mm3 \n\t" \
162 "paddq %%mm4, %%mm3 \n\t" \
163 "movd 8(%%edi), %%mm5 \n\t" \
164 "paddq %%mm6, %%mm5 \n\t" \
165 "movd 12(%%edi), %%mm4 \n\t" \
166 "paddq %%mm4, %%mm7 \n\t" \
167 "movd %%mm1, (%%edi) \n\t" \
168 "movd 16(%%esi), %%mm2 \n\t" \
169 "pmuludq %%mm0, %%mm2 \n\t" \
170 "psrlq $32, %%mm1 \n\t" \
171 "movd 20(%%esi), %%mm4 \n\t" \
172 "pmuludq %%mm0, %%mm4 \n\t" \
173 "paddq %%mm3, %%mm1 \n\t" \
174 "movd 24(%%esi), %%mm6 \n\t" \
175 "pmuludq %%mm0, %%mm6 \n\t" \
176 "movd %%mm1, 4(%%edi) \n\t" \
177 "psrlq $32, %%mm1 \n\t" \
178 "movd 28(%%esi), %%mm3 \n\t" \
179 "pmuludq %%mm0, %%mm3 \n\t" \
180 "paddq %%mm5, %%mm1 \n\t" \
181 "movd 16(%%edi), %%mm5 \n\t" \
182 "paddq %%mm5, %%mm2 \n\t" \
183 "movd %%mm1, 8(%%edi) \n\t" \
184 "psrlq $32, %%mm1 \n\t" \
185 "paddq %%mm7, %%mm1 \n\t" \
186 "movd 20(%%edi), %%mm5 \n\t" \
187 "paddq %%mm5, %%mm4 \n\t" \
188 "movd %%mm1, 12(%%edi) \n\t" \
189 "psrlq $32, %%mm1 \n\t" \
190 "paddq %%mm2, %%mm1 \n\t" \
191 "movd 24(%%edi), %%mm5 \n\t" \
192 "paddq %%mm5, %%mm6 \n\t" \
193 "movd %%mm1, 16(%%edi) \n\t" \
194 "psrlq $32, %%mm1 \n\t" \
195 "paddq %%mm4, %%mm1 \n\t" \
196 "movd 28(%%edi), %%mm5 \n\t" \
197 "paddq %%mm5, %%mm3 \n\t" \
198 "movd %%mm1, 20(%%edi) \n\t" \
199 "psrlq $32, %%mm1 \n\t" \
200 "paddq %%mm6, %%mm1 \n\t" \
201 "movd %%mm1, 24(%%edi) \n\t" \
202 "psrlq $32, %%mm1 \n\t" \
203 "paddq %%mm3, %%mm1 \n\t" \
204 "movd %%mm1, 28(%%edi) \n\t" \
205 "addl $32, %%edi \n\t" \
206 "addl $32, %%esi \n\t" \
207 "psrlq $32, %%mm1 \n\t" \
208 "movd %%mm1, %%ecx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000209
Hanno Beckereacf3b92022-04-06 11:25:22 +0100210#define MULADDC_X8_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200211 "emms \n\t" \
212 "movl %4, %%ebx \n\t" \
213 "movl %%ecx, %1 \n\t" \
214 "movl %%edi, %2 \n\t" \
215 "movl %%esi, %3 \n\t" \
Paul Bakkerc89cf7c2009-07-19 21:37:39 +0000216 : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
217 : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
Simon Butcher53571642018-06-24 12:58:31 +0100218 : "eax", "ebx", "ecx", "edx", "esi", "edi" \
Hanno Beckerefdc5192022-04-11 10:44:02 +0100219 ); } \
220
Paul Bakker5121ce52009-01-03 21:22:43 +0000221#endif /* SSE2 */
Hanno Beckereacf3b92022-04-06 11:25:22 +0100222
Paul Bakker5121ce52009-01-03 21:22:43 +0000223#endif /* i386 */
224
225#if defined(__amd64__) || defined (__x86_64__)
226
Hanno Beckereacf3b92022-04-06 11:25:22 +0100227#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200228 asm( \
Simon Butchera86de142018-09-30 12:09:47 +0100229 "xorq %%r8, %%r8\n"
Paul Bakker5121ce52009-01-03 21:22:43 +0000230
Hanno Beckereacf3b92022-04-06 11:25:22 +0100231#define MULADDC_X1_CORE \
Simon Butchera86de142018-09-30 12:09:47 +0100232 "movq (%%rsi), %%rax\n" \
233 "mulq %%rbx\n" \
234 "addq $8, %%rsi\n" \
235 "addq %%rcx, %%rax\n" \
236 "movq %%r8, %%rcx\n" \
237 "adcq $0, %%rdx\n" \
238 "nop \n" \
239 "addq %%rax, (%%rdi)\n" \
240 "adcq %%rdx, %%rcx\n" \
241 "addq $8, %%rdi\n"
Paul Bakker5121ce52009-01-03 21:22:43 +0000242
Hanno Beckereacf3b92022-04-06 11:25:22 +0100243#define MULADDC_X1_STOP \
Gilles Peskined337fbc2021-09-14 00:13:05 +0200244 : "+c" (c), "+D" (d), "+S" (s), "+m" (*(uint64_t (*)[16]) d) \
245 : "b" (b), "m" (*(const uint64_t (*)[16]) s) \
246 : "rax", "rdx", "r8" \
Manuel Pégourié-Gonnarddef018d2014-01-07 17:50:46 +0100247 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000248
249#endif /* AMD64 */
250
Dave Rodgman4e5c63d2023-06-23 15:17:37 +0100251// The following assembly code assumes that a pointer will fit in a 64-bit register
252// (including ILP32 __aarch64__ ABIs such as on watchOS, hence the 2^32 - 1)
Dave Rodgmane6c99962023-06-21 21:16:23 +0100253#if defined(__aarch64__) && (UINTPTR_MAX == 0xfffffffful || UINTPTR_MAX == 0xfffffffffffffffful)
Ko-cc1871e2018-08-16 02:01:57 -0700254
Dave Rodgman8c5fae22023-06-27 09:43:55 +0100255/*
256 * There are some issues around different compilers requiring different constraint
257 * syntax for updating pointers from assembly code (see notes for
258 * MBEDTLS_ASM_AARCH64_PTR_CONSTRAINT in common.h), especially on aarch64_32 (aka ILP32).
259 *
260 * For this reason we cast the pointers to/from uintptr_t here.
261 */
Hanno Beckereacf3b92022-04-06 11:25:22 +0100262#define MULADDC_X1_INIT \
Dave Rodgmane6c99962023-06-21 21:16:23 +0100263 do { uintptr_t muladdc_d = (uintptr_t) d, muladdc_s = (uintptr_t) s; asm(
Ko-cc1871e2018-08-16 02:01:57 -0700264
Hanno Beckereacf3b92022-04-06 11:25:22 +0100265#define MULADDC_X1_CORE \
Dave Rodgman9e868be2023-06-27 09:27:27 +0100266 "ldr x4, [%x2], #8 \n\t" \
267 "ldr x5, [%x1] \n\t" \
David Horstmann11c81df2021-09-22 18:15:51 +0100268 "mul x6, x4, %4 \n\t" \
269 "umulh x7, x4, %4 \n\t" \
Ko-cc1871e2018-08-16 02:01:57 -0700270 "adds x5, x5, x6 \n\t" \
271 "adc x7, x7, xzr \n\t" \
Ko-cb260bb2018-08-20 13:59:53 +0100272 "adds x5, x5, %0 \n\t" \
Ko-cc1871e2018-08-16 02:01:57 -0700273 "adc %0, x7, xzr \n\t" \
Dave Rodgman9e868be2023-06-27 09:27:27 +0100274 "str x5, [%x1], #8 \n\t"
Ko-cc1871e2018-08-16 02:01:57 -0700275
Hanno Beckereacf3b92022-04-06 11:25:22 +0100276#define MULADDC_X1_STOP \
Dave Rodgman0400ae22023-06-21 16:14:46 +0100277 : "+r" (c), \
Dave Rodgmane6c99962023-06-21 21:16:23 +0100278 "+r" (muladdc_d), \
279 "+r" (muladdc_s), \
Dave Rodgman0400ae22023-06-21 16:14:46 +0100280 "+m" (*(uint64_t (*)[16]) d) \
David Horstmann11c81df2021-09-22 18:15:51 +0100281 : "r" (b), "m" (*(const uint64_t (*)[16]) s) \
282 : "x4", "x5", "x6", "x7", "cc" \
Dave Rodgmane6c99962023-06-21 21:16:23 +0100283 ); d = (mbedtls_mpi_uint *)muladdc_d; s = (mbedtls_mpi_uint *)muladdc_s; } while (0);
Ko-cc1871e2018-08-16 02:01:57 -0700284
285#endif /* Aarch64 */
286
Paul Bakker5121ce52009-01-03 21:22:43 +0000287#if defined(__mc68020__) || defined(__mcpu32__)
288
Hanno Beckereacf3b92022-04-06 11:25:22 +0100289#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200290 asm( \
291 "movl %3, %%a2 \n\t" \
292 "movl %4, %%a3 \n\t" \
293 "movl %5, %%d3 \n\t" \
294 "movl %6, %%d2 \n\t" \
295 "moveq #0, %%d0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000296
Hanno Beckereacf3b92022-04-06 11:25:22 +0100297#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200298 "movel %%a2@+, %%d1 \n\t" \
299 "mulul %%d2, %%d4:%%d1 \n\t" \
300 "addl %%d3, %%d1 \n\t" \
301 "addxl %%d0, %%d4 \n\t" \
302 "moveq #0, %%d3 \n\t" \
303 "addl %%d1, %%a3@+ \n\t" \
304 "addxl %%d4, %%d3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000305
Hanno Beckereacf3b92022-04-06 11:25:22 +0100306#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200307 "movl %%d3, %0 \n\t" \
308 "movl %%a3, %1 \n\t" \
309 "movl %%a2, %2 \n\t" \
Manuel Pégourié-Gonnard3b05e4c2014-01-10 15:30:23 +0100310 : "=m" (c), "=m" (d), "=m" (s) \
311 : "m" (s), "m" (d), "m" (c), "m" (b) \
312 : "d0", "d1", "d2", "d3", "d4", "a2", "a3" \
313 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000314
Hanno Beckereacf3b92022-04-06 11:25:22 +0100315#define MULADDC_X8_INIT MULADDC_X1_INIT
316
317#define MULADDC_X8_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200318 "movel %%a2@+, %%d1 \n\t" \
319 "mulul %%d2, %%d4:%%d1 \n\t" \
320 "addxl %%d3, %%d1 \n\t" \
321 "addxl %%d0, %%d4 \n\t" \
322 "addl %%d1, %%a3@+ \n\t" \
323 "movel %%a2@+, %%d1 \n\t" \
324 "mulul %%d2, %%d3:%%d1 \n\t" \
325 "addxl %%d4, %%d1 \n\t" \
326 "addxl %%d0, %%d3 \n\t" \
327 "addl %%d1, %%a3@+ \n\t" \
328 "movel %%a2@+, %%d1 \n\t" \
329 "mulul %%d2, %%d4:%%d1 \n\t" \
330 "addxl %%d3, %%d1 \n\t" \
331 "addxl %%d0, %%d4 \n\t" \
332 "addl %%d1, %%a3@+ \n\t" \
333 "movel %%a2@+, %%d1 \n\t" \
334 "mulul %%d2, %%d3:%%d1 \n\t" \
335 "addxl %%d4, %%d1 \n\t" \
336 "addxl %%d0, %%d3 \n\t" \
337 "addl %%d1, %%a3@+ \n\t" \
338 "movel %%a2@+, %%d1 \n\t" \
339 "mulul %%d2, %%d4:%%d1 \n\t" \
340 "addxl %%d3, %%d1 \n\t" \
341 "addxl %%d0, %%d4 \n\t" \
342 "addl %%d1, %%a3@+ \n\t" \
343 "movel %%a2@+, %%d1 \n\t" \
344 "mulul %%d2, %%d3:%%d1 \n\t" \
345 "addxl %%d4, %%d1 \n\t" \
346 "addxl %%d0, %%d3 \n\t" \
347 "addl %%d1, %%a3@+ \n\t" \
348 "movel %%a2@+, %%d1 \n\t" \
349 "mulul %%d2, %%d4:%%d1 \n\t" \
350 "addxl %%d3, %%d1 \n\t" \
351 "addxl %%d0, %%d4 \n\t" \
352 "addl %%d1, %%a3@+ \n\t" \
353 "movel %%a2@+, %%d1 \n\t" \
354 "mulul %%d2, %%d3:%%d1 \n\t" \
355 "addxl %%d4, %%d1 \n\t" \
356 "addxl %%d0, %%d3 \n\t" \
357 "addl %%d1, %%a3@+ \n\t" \
358 "addxl %%d0, %%d3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000359
Hanno Beckereacf3b92022-04-06 11:25:22 +0100360#define MULADDC_X8_STOP MULADDC_X1_STOP
361
Paul Bakker5121ce52009-01-03 21:22:43 +0000362#endif /* MC68000 */
363
Paul Bakker5121ce52009-01-03 21:22:43 +0000364#if defined(__powerpc64__) || defined(__ppc64__)
365
366#if defined(__MACH__) && defined(__APPLE__)
367
Hanno Beckereacf3b92022-04-06 11:25:22 +0100368#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200369 asm( \
370 "ld r3, %3 \n\t" \
371 "ld r4, %4 \n\t" \
372 "ld r5, %5 \n\t" \
373 "ld r6, %6 \n\t" \
374 "addi r3, r3, -8 \n\t" \
375 "addi r4, r4, -8 \n\t" \
376 "addic r5, r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000377
Hanno Beckereacf3b92022-04-06 11:25:22 +0100378#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200379 "ldu r7, 8(r3) \n\t" \
380 "mulld r8, r7, r6 \n\t" \
381 "mulhdu r9, r7, r6 \n\t" \
382 "adde r8, r8, r5 \n\t" \
383 "ld r7, 8(r4) \n\t" \
384 "addze r5, r9 \n\t" \
385 "addc r8, r8, r7 \n\t" \
386 "stdu r8, 8(r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000387
Hanno Beckereacf3b92022-04-06 11:25:22 +0100388#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200389 "addze r5, r5 \n\t" \
390 "addi r4, r4, 8 \n\t" \
391 "addi r3, r3, 8 \n\t" \
392 "std r5, %0 \n\t" \
393 "std r4, %1 \n\t" \
394 "std r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100395 : "=m" (c), "=m" (d), "=m" (s) \
396 : "m" (s), "m" (d), "m" (c), "m" (b) \
397 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
398 );
399
Paul Bakker5121ce52009-01-03 21:22:43 +0000400
Paul Bakker9af723c2014-05-01 13:03:14 +0200401#else /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000402
Hanno Beckereacf3b92022-04-06 11:25:22 +0100403#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200404 asm( \
405 "ld %%r3, %3 \n\t" \
406 "ld %%r4, %4 \n\t" \
407 "ld %%r5, %5 \n\t" \
408 "ld %%r6, %6 \n\t" \
409 "addi %%r3, %%r3, -8 \n\t" \
410 "addi %%r4, %%r4, -8 \n\t" \
411 "addic %%r5, %%r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000412
Hanno Beckereacf3b92022-04-06 11:25:22 +0100413#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200414 "ldu %%r7, 8(%%r3) \n\t" \
415 "mulld %%r8, %%r7, %%r6 \n\t" \
416 "mulhdu %%r9, %%r7, %%r6 \n\t" \
417 "adde %%r8, %%r8, %%r5 \n\t" \
418 "ld %%r7, 8(%%r4) \n\t" \
419 "addze %%r5, %%r9 \n\t" \
420 "addc %%r8, %%r8, %%r7 \n\t" \
421 "stdu %%r8, 8(%%r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000422
Hanno Beckereacf3b92022-04-06 11:25:22 +0100423#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200424 "addze %%r5, %%r5 \n\t" \
425 "addi %%r4, %%r4, 8 \n\t" \
426 "addi %%r3, %%r3, 8 \n\t" \
427 "std %%r5, %0 \n\t" \
428 "std %%r4, %1 \n\t" \
429 "std %%r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100430 : "=m" (c), "=m" (d), "=m" (s) \
431 : "m" (s), "m" (d), "m" (c), "m" (b) \
432 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
433 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000434
Paul Bakker9af723c2014-05-01 13:03:14 +0200435#endif /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000436
Barry K. Nathan35e7cb92014-05-05 23:26:13 -0700437#elif defined(__powerpc__) || defined(__ppc__) /* end PPC64/begin PPC32 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000438
439#if defined(__MACH__) && defined(__APPLE__)
440
Hanno Beckereacf3b92022-04-06 11:25:22 +0100441#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200442 asm( \
443 "lwz r3, %3 \n\t" \
444 "lwz r4, %4 \n\t" \
445 "lwz r5, %5 \n\t" \
446 "lwz r6, %6 \n\t" \
447 "addi r3, r3, -4 \n\t" \
448 "addi r4, r4, -4 \n\t" \
449 "addic r5, r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000450
Hanno Beckereacf3b92022-04-06 11:25:22 +0100451#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200452 "lwzu r7, 4(r3) \n\t" \
453 "mullw r8, r7, r6 \n\t" \
454 "mulhwu r9, r7, r6 \n\t" \
455 "adde r8, r8, r5 \n\t" \
456 "lwz r7, 4(r4) \n\t" \
457 "addze r5, r9 \n\t" \
458 "addc r8, r8, r7 \n\t" \
459 "stwu r8, 4(r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000460
Hanno Beckereacf3b92022-04-06 11:25:22 +0100461#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200462 "addze r5, r5 \n\t" \
463 "addi r4, r4, 4 \n\t" \
464 "addi r3, r3, 4 \n\t" \
465 "stw r5, %0 \n\t" \
466 "stw r4, %1 \n\t" \
467 "stw r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100468 : "=m" (c), "=m" (d), "=m" (s) \
469 : "m" (s), "m" (d), "m" (c), "m" (b) \
470 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
471 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000472
Paul Bakker9af723c2014-05-01 13:03:14 +0200473#else /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000474
Hanno Beckereacf3b92022-04-06 11:25:22 +0100475#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200476 asm( \
477 "lwz %%r3, %3 \n\t" \
478 "lwz %%r4, %4 \n\t" \
479 "lwz %%r5, %5 \n\t" \
480 "lwz %%r6, %6 \n\t" \
481 "addi %%r3, %%r3, -4 \n\t" \
482 "addi %%r4, %%r4, -4 \n\t" \
483 "addic %%r5, %%r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000484
Hanno Beckereacf3b92022-04-06 11:25:22 +0100485#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200486 "lwzu %%r7, 4(%%r3) \n\t" \
487 "mullw %%r8, %%r7, %%r6 \n\t" \
488 "mulhwu %%r9, %%r7, %%r6 \n\t" \
489 "adde %%r8, %%r8, %%r5 \n\t" \
490 "lwz %%r7, 4(%%r4) \n\t" \
491 "addze %%r5, %%r9 \n\t" \
492 "addc %%r8, %%r8, %%r7 \n\t" \
493 "stwu %%r8, 4(%%r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000494
Hanno Beckereacf3b92022-04-06 11:25:22 +0100495#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200496 "addze %%r5, %%r5 \n\t" \
497 "addi %%r4, %%r4, 4 \n\t" \
498 "addi %%r3, %%r3, 4 \n\t" \
499 "stw %%r5, %0 \n\t" \
500 "stw %%r4, %1 \n\t" \
501 "stw %%r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100502 : "=m" (c), "=m" (d), "=m" (s) \
503 : "m" (s), "m" (d), "m" (c), "m" (b) \
504 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
505 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000506
Paul Bakker9af723c2014-05-01 13:03:14 +0200507#endif /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000508
509#endif /* PPC32 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000510
Manuel Pégourié-Gonnard31357252014-06-24 17:57:57 +0200511/*
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200512 * The Sparc(64) assembly is reported to be broken.
Manuel Pégourié-Gonnard31357252014-06-24 17:57:57 +0200513 * Disable it for now, until we're able to fix it.
514 */
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200515#if 0 && defined(__sparc__)
516#if defined(__sparc64__)
Paul Bakker5121ce52009-01-03 21:22:43 +0000517
Hanno Beckereacf3b92022-04-06 11:25:22 +0100518#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200519 asm( \
520 "ldx %3, %%o0 \n\t" \
521 "ldx %4, %%o1 \n\t" \
522 "ld %5, %%o2 \n\t" \
523 "ld %6, %%o3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000524
Hanno Beckereacf3b92022-04-06 11:25:22 +0100525#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200526 "ld [%%o0], %%o4 \n\t" \
527 "inc 4, %%o0 \n\t" \
528 "ld [%%o1], %%o5 \n\t" \
529 "umul %%o3, %%o4, %%o4 \n\t" \
530 "addcc %%o4, %%o2, %%o4 \n\t" \
531 "rd %%y, %%g1 \n\t" \
532 "addx %%g1, 0, %%g1 \n\t" \
533 "addcc %%o4, %%o5, %%o4 \n\t" \
534 "st %%o4, [%%o1] \n\t" \
535 "addx %%g1, 0, %%o2 \n\t" \
536 "inc 4, %%o1 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000537
Hanno Beckereacf3b92022-04-06 11:25:22 +0100538#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200539 "st %%o2, %0 \n\t" \
540 "stx %%o1, %1 \n\t" \
541 "stx %%o0, %2 \n\t" \
Paul Bakker4f024b72012-10-30 07:29:57 +0000542 : "=m" (c), "=m" (d), "=m" (s) \
543 : "m" (s), "m" (d), "m" (c), "m" (b) \
544 : "g1", "o0", "o1", "o2", "o3", "o4", \
545 "o5" \
546 );
Paul Bakker4f024b72012-10-30 07:29:57 +0000547
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200548#else /* __sparc64__ */
Paul Bakker4f024b72012-10-30 07:29:57 +0000549
Hanno Beckereacf3b92022-04-06 11:25:22 +0100550#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200551 asm( \
552 "ld %3, %%o0 \n\t" \
553 "ld %4, %%o1 \n\t" \
554 "ld %5, %%o2 \n\t" \
555 "ld %6, %%o3 \n\t"
Paul Bakker4f024b72012-10-30 07:29:57 +0000556
Hanno Beckereacf3b92022-04-06 11:25:22 +0100557#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200558 "ld [%%o0], %%o4 \n\t" \
559 "inc 4, %%o0 \n\t" \
560 "ld [%%o1], %%o5 \n\t" \
561 "umul %%o3, %%o4, %%o4 \n\t" \
562 "addcc %%o4, %%o2, %%o4 \n\t" \
563 "rd %%y, %%g1 \n\t" \
564 "addx %%g1, 0, %%g1 \n\t" \
565 "addcc %%o4, %%o5, %%o4 \n\t" \
566 "st %%o4, [%%o1] \n\t" \
567 "addx %%g1, 0, %%o2 \n\t" \
568 "inc 4, %%o1 \n\t"
Paul Bakker4f024b72012-10-30 07:29:57 +0000569
Hanno Beckereacf3b92022-04-06 11:25:22 +0100570#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200571 "st %%o2, %0 \n\t" \
572 "st %%o1, %1 \n\t" \
573 "st %%o0, %2 \n\t" \
Paul Bakker4f024b72012-10-30 07:29:57 +0000574 : "=m" (c), "=m" (d), "=m" (s) \
575 : "m" (s), "m" (d), "m" (c), "m" (b) \
576 : "g1", "o0", "o1", "o2", "o3", "o4", \
577 "o5" \
578 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000579
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200580#endif /* __sparc64__ */
581#endif /* __sparc__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000582
583#if defined(__microblaze__) || defined(microblaze)
584
Hanno Beckereacf3b92022-04-06 11:25:22 +0100585#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200586 asm( \
587 "lwi r3, %3 \n\t" \
588 "lwi r4, %4 \n\t" \
589 "lwi r5, %5 \n\t" \
590 "lwi r6, %6 \n\t" \
591 "andi r7, r6, 0xffff \n\t" \
592 "bsrli r6, r6, 16 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000593
Kazuyuki Kimurab88dbdd2021-05-31 17:07:28 +0900594#if(__BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__)
595#define MULADDC_LHUI \
596 "lhui r9, r3, 0 \n\t" \
597 "addi r3, r3, 2 \n\t" \
598 "lhui r8, r3, 0 \n\t"
599#else
600#define MULADDC_LHUI \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200601 "lhui r8, r3, 0 \n\t" \
602 "addi r3, r3, 2 \n\t" \
Kazuyuki Kimurab88dbdd2021-05-31 17:07:28 +0900603 "lhui r9, r3, 0 \n\t"
604#endif
605
606#define MULADDC_X1_CORE \
607 MULADDC_LHUI \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200608 "addi r3, r3, 2 \n\t" \
609 "mul r10, r9, r6 \n\t" \
610 "mul r11, r8, r7 \n\t" \
611 "mul r12, r9, r7 \n\t" \
612 "mul r13, r8, r6 \n\t" \
613 "bsrli r8, r10, 16 \n\t" \
614 "bsrli r9, r11, 16 \n\t" \
615 "add r13, r13, r8 \n\t" \
616 "add r13, r13, r9 \n\t" \
617 "bslli r10, r10, 16 \n\t" \
618 "bslli r11, r11, 16 \n\t" \
619 "add r12, r12, r10 \n\t" \
620 "addc r13, r13, r0 \n\t" \
621 "add r12, r12, r11 \n\t" \
622 "addc r13, r13, r0 \n\t" \
623 "lwi r10, r4, 0 \n\t" \
624 "add r12, r12, r10 \n\t" \
625 "addc r13, r13, r0 \n\t" \
626 "add r12, r12, r5 \n\t" \
627 "addc r5, r13, r0 \n\t" \
628 "swi r12, r4, 0 \n\t" \
629 "addi r4, r4, 4 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000630
Hanno Beckereacf3b92022-04-06 11:25:22 +0100631#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200632 "swi r5, %0 \n\t" \
633 "swi r4, %1 \n\t" \
634 "swi r3, %2 \n\t" \
Manuel Pégourié-Gonnard1753e2f2014-01-10 15:35:41 +0100635 : "=m" (c), "=m" (d), "=m" (s) \
636 : "m" (s), "m" (d), "m" (c), "m" (b) \
Zach van Rijne7d3f8e2018-05-21 10:52:34 -0400637 : "r3", "r4", "r5", "r6", "r7", "r8", \
Manuel Pégourié-Gonnard1753e2f2014-01-10 15:35:41 +0100638 "r9", "r10", "r11", "r12", "r13" \
639 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000640
641#endif /* MicroBlaze */
642
643#if defined(__tricore__)
644
Hanno Beckereacf3b92022-04-06 11:25:22 +0100645#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200646 asm( \
647 "ld.a %%a2, %3 \n\t" \
648 "ld.a %%a3, %4 \n\t" \
649 "ld.w %%d4, %5 \n\t" \
650 "ld.w %%d1, %6 \n\t" \
651 "xor %%d5, %%d5 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000652
Hanno Beckereacf3b92022-04-06 11:25:22 +0100653#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200654 "ld.w %%d0, [%%a2+] \n\t" \
655 "madd.u %%e2, %%e4, %%d0, %%d1 \n\t" \
656 "ld.w %%d0, [%%a3] \n\t" \
657 "addx %%d2, %%d2, %%d0 \n\t" \
658 "addc %%d3, %%d3, 0 \n\t" \
659 "mov %%d4, %%d3 \n\t" \
660 "st.w [%%a3+], %%d2 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000661
Hanno Beckereacf3b92022-04-06 11:25:22 +0100662#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200663 "st.w %0, %%d4 \n\t" \
664 "st.a %1, %%a3 \n\t" \
665 "st.a %2, %%a2 \n\t" \
Manuel Pégourié-Gonnard3f687ad2014-01-10 15:47:50 +0100666 : "=m" (c), "=m" (d), "=m" (s) \
667 : "m" (s), "m" (d), "m" (c), "m" (b) \
668 : "d0", "d1", "e2", "d4", "a2", "a3" \
669 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000670
671#endif /* TriCore */
672
Dave Rodgman12b14b22023-05-25 12:53:41 +0100673#if defined(__arm__)
674
Dave Rodgman3964fe02023-05-25 18:53:57 +0100675#if defined(__thumb__) && !defined(__thumb2__)
Dave Rodgman7fdfd702023-06-15 18:42:25 +0100676#if defined(MBEDTLS_COMPILER_IS_GCC)
Manuel Pégourié-Gonnard25caaf32016-01-08 14:29:11 +0100677/*
Dave Rodgmanf89e3c52023-06-04 20:41:52 -0400678 * Thumb 1 ISA. This code path has only been tested successfully on gcc;
679 * it does not compile on clang or armclang.
Manuel Pégourié-Gonnard25caaf32016-01-08 14:29:11 +0100680 */
Dave Rodgmanffbb7c52023-05-24 18:28:46 +0100681
Dave Rodgman12b14b22023-05-25 12:53:41 +0100682#if !defined(__OPTIMIZE__) && defined(__GNUC__)
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100683/*
684 * Note, gcc -O0 by default uses r7 for the frame pointer, so it complains about
685 * our use of r7 below, unless -fomit-frame-pointer is passed.
686 *
687 * On the other hand, -fomit-frame-pointer is implied by any -Ox options with
688 * x !=0, which we can detect using __OPTIMIZE__ (which is also defined by
689 * clang and armcc5 under the same conditions).
690 *
691 * If gcc needs to use r7, we use r1 as a scratch register and have a few extra
692 * instructions to preserve/restore it; otherwise, we can use r7 and avoid
693 * the preserve/restore overhead.
694 */
Dave Rodgmanb6e06542023-06-04 20:42:17 -0400695#define MULADDC_SCRATCH "RS .req r1 \n\t"
696#define MULADDC_PRESERVE_SCRATCH "mov r10, r1 \n\t"
697#define MULADDC_RESTORE_SCRATCH "mov r1, r10 \n\t"
698#define MULADDC_SCRATCH_CLOBBER "r10"
Dave Rodgman12b14b22023-05-25 12:53:41 +0100699#else /* !defined(__OPTIMIZE__) && defined(__GNUC__) */
Dave Rodgmanb6e06542023-06-04 20:42:17 -0400700#define MULADDC_SCRATCH "RS .req r7 \n\t"
701#define MULADDC_PRESERVE_SCRATCH ""
702#define MULADDC_RESTORE_SCRATCH ""
703#define MULADDC_SCRATCH_CLOBBER "r7"
Dave Rodgman12b14b22023-05-25 12:53:41 +0100704#endif /* !defined(__OPTIMIZE__) && defined(__GNUC__) */
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100705
Hanno Beckereacf3b92022-04-06 11:25:22 +0100706#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200707 asm( \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100708 MULADDC_SCRATCH \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200709 "ldr r0, %3 \n\t" \
710 "ldr r1, %4 \n\t" \
711 "ldr r2, %5 \n\t" \
712 "ldr r3, %6 \n\t" \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100713 "lsr r4, r3, #16 \n\t" \
714 "mov r9, r4 \n\t" \
715 "lsl r4, r3, #16 \n\t" \
716 "lsr r4, r4, #16 \n\t" \
717 "mov r8, r4 \n\t" \
718
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000719
Hanno Beckereacf3b92022-04-06 11:25:22 +0100720#define MULADDC_X1_CORE \
Dave Rodgman9a676a72023-06-04 20:42:28 -0400721 MULADDC_PRESERVE_SCRATCH \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200722 "ldmia r0!, {r6} \n\t" \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100723 "lsr RS, r6, #16 \n\t" \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200724 "lsl r6, r6, #16 \n\t" \
725 "lsr r6, r6, #16 \n\t" \
726 "mov r4, r8 \n\t" \
727 "mul r4, r6 \n\t" \
728 "mov r3, r9 \n\t" \
729 "mul r6, r3 \n\t" \
730 "mov r5, r9 \n\t" \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100731 "mul r5, RS \n\t" \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200732 "mov r3, r8 \n\t" \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100733 "mul RS, r3 \n\t" \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200734 "lsr r3, r6, #16 \n\t" \
735 "add r5, r5, r3 \n\t" \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100736 "lsr r3, RS, #16 \n\t" \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200737 "add r5, r5, r3 \n\t" \
738 "add r4, r4, r2 \n\t" \
739 "mov r2, #0 \n\t" \
740 "adc r5, r2 \n\t" \
741 "lsl r3, r6, #16 \n\t" \
742 "add r4, r4, r3 \n\t" \
743 "adc r5, r2 \n\t" \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100744 "lsl r3, RS, #16 \n\t" \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200745 "add r4, r4, r3 \n\t" \
746 "adc r5, r2 \n\t" \
Dave Rodgman9a676a72023-06-04 20:42:28 -0400747 MULADDC_RESTORE_SCRATCH \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200748 "ldr r3, [r1] \n\t" \
749 "add r4, r4, r3 \n\t" \
750 "adc r2, r5 \n\t" \
751 "stmia r1!, {r4} \n\t"
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000752
Hanno Beckereacf3b92022-04-06 11:25:22 +0100753#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200754 "str r2, %0 \n\t" \
755 "str r1, %1 \n\t" \
756 "str r0, %2 \n\t" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100757 : "=m" (c), "=m" (d), "=m" (s) \
758 : "m" (s), "m" (d), "m" (c), "m" (b) \
759 : "r0", "r1", "r2", "r3", "r4", "r5", \
Dave Rodgmanb047bf62023-05-25 11:01:41 +0100760 "r6", MULADDC_SCRATCH_CLOBBER, "r8", "r9", "cc" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100761 );
Dave Rodgman6df1e542023-06-02 10:27:13 -0400762#endif /* !defined(__ARMCC_VERSION) && !defined(__clang__) */
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000763
Dave Rodgman12b14b22023-05-25 12:53:41 +0100764#elif (__ARM_ARCH >= 6) && \
765 defined (__ARM_FEATURE_DSP) && (__ARM_FEATURE_DSP == 1)
Dave Rodgman3964fe02023-05-25 18:53:57 +0100766/* Armv6-M (or later) with DSP Instruction Set Extensions.
767 * Requires support for either Thumb 2 or Arm ISA.
768 */
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200769
Hanno Beckereacf3b92022-04-06 11:25:22 +0100770#define MULADDC_X1_INIT \
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100771 { \
772 mbedtls_mpi_uint tmp_a, tmp_b; \
773 asm volatile (
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200774
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100775#define MULADDC_X1_CORE \
776 ".p2align 2 \n\t" \
Hanno Becker907a3672022-07-15 12:00:58 +0100777 "ldr %[a], [%[in]], #4 \n\t" \
778 "ldr %[b], [%[acc]] \n\t" \
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100779 "umaal %[b], %[carry], %[scalar], %[a] \n\t" \
Hanno Becker907a3672022-07-15 12:00:58 +0100780 "str %[b], [%[acc]], #4 \n\t"
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200781
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100782#define MULADDC_X1_STOP \
783 : [a] "=&r" (tmp_a), \
784 [b] "=&r" (tmp_b), \
785 [in] "+r" (s), \
786 [acc] "+r" (d), \
787 [carry] "+l" (c) \
788 : [scalar] "r" (b) \
789 : "memory" \
790 ); \
791 }
792
793#define MULADDC_X2_INIT \
794 { \
795 mbedtls_mpi_uint tmp_a0, tmp_b0; \
796 mbedtls_mpi_uint tmp_a1, tmp_b1; \
797 asm volatile (
798
Hanno Becker606cb162022-04-17 06:57:34 +0100799 /* - Make sure loop is 4-byte aligned to avoid stalls
800 * upon repeated non-word aligned instructions in
801 * some microarchitectures.
802 * - Don't use ldm with post-increment or back-to-back
803 * loads with post-increment and same address register
804 * to avoid stalls on some microarchitectures.
805 * - Bunch loads and stores to reduce latency on some
806 * microarchitectures. E.g., on Cortex-M4, the first
807 * in a series of load/store operations has latency
808 * 2 cycles, while subsequent loads/stores are single-cycle. */
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100809#define MULADDC_X2_CORE \
810 ".p2align 2 \n\t" \
Hanno Becker907a3672022-07-15 12:00:58 +0100811 "ldr %[a0], [%[in]], #+8 \n\t" \
812 "ldr %[b0], [%[acc]], #+8 \n\t" \
813 "ldr %[a1], [%[in], #-4] \n\t" \
814 "ldr %[b1], [%[acc], #-4] \n\t" \
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100815 "umaal %[b0], %[carry], %[scalar], %[a0] \n\t" \
816 "umaal %[b1], %[carry], %[scalar], %[a1] \n\t" \
Hanno Becker907a3672022-07-15 12:00:58 +0100817 "str %[b0], [%[acc], #-8] \n\t" \
818 "str %[b1], [%[acc], #-4] \n\t"
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100819
820#define MULADDC_X2_STOP \
821 : [a0] "=&r" (tmp_a0), \
822 [b0] "=&r" (tmp_b0), \
823 [a1] "=&r" (tmp_a1), \
824 [b1] "=&r" (tmp_b1), \
825 [in] "+r" (s), \
826 [acc] "+r" (d), \
827 [carry] "+l" (c) \
828 : [scalar] "r" (b) \
829 : "memory" \
830 ); \
831 }
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200832
Dave Rodgman9a676a72023-06-04 20:42:28 -0400833#else /* Thumb 2 or Arm ISA, without DSP extensions */
Paul Bakkera2713a32011-11-18 12:47:23 +0000834
Hanno Beckereacf3b92022-04-06 11:25:22 +0100835#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200836 asm( \
837 "ldr r0, %3 \n\t" \
838 "ldr r1, %4 \n\t" \
839 "ldr r2, %5 \n\t" \
840 "ldr r3, %6 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000841
Hanno Beckereacf3b92022-04-06 11:25:22 +0100842#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200843 "ldr r4, [r0], #4 \n\t" \
844 "mov r5, #0 \n\t" \
845 "ldr r6, [r1] \n\t" \
846 "umlal r2, r5, r3, r4 \n\t" \
Dave Rodgmancee166e2023-05-25 11:00:05 +0100847 "adds r4, r6, r2 \n\t" \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200848 "adc r2, r5, #0 \n\t" \
Dave Rodgmancee166e2023-05-25 11:00:05 +0100849 "str r4, [r1], #4 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000850
Hanno Beckereacf3b92022-04-06 11:25:22 +0100851#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200852 "str r2, %0 \n\t" \
853 "str r1, %1 \n\t" \
854 "str r0, %2 \n\t" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100855 : "=m" (c), "=m" (d), "=m" (s) \
856 : "m" (s), "m" (d), "m" (c), "m" (b) \
857 : "r0", "r1", "r2", "r3", "r4", "r5", \
Dave Rodgmancee166e2023-05-25 11:00:05 +0100858 "r6", "cc" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100859 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000860
Dave Rodgman12b14b22023-05-25 12:53:41 +0100861#endif /* ISA codepath selection */
862
863#endif /* defined(__arm__) */
Paul Bakker5121ce52009-01-03 21:22:43 +0000864
865#if defined(__alpha__)
866
Hanno Beckereacf3b92022-04-06 11:25:22 +0100867#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200868 asm( \
869 "ldq $1, %3 \n\t" \
870 "ldq $2, %4 \n\t" \
871 "ldq $3, %5 \n\t" \
872 "ldq $4, %6 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000873
Hanno Beckereacf3b92022-04-06 11:25:22 +0100874#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200875 "ldq $6, 0($1) \n\t" \
876 "addq $1, 8, $1 \n\t" \
877 "mulq $6, $4, $7 \n\t" \
878 "umulh $6, $4, $6 \n\t" \
879 "addq $7, $3, $7 \n\t" \
880 "cmpult $7, $3, $3 \n\t" \
881 "ldq $5, 0($2) \n\t" \
882 "addq $7, $5, $7 \n\t" \
883 "cmpult $7, $5, $5 \n\t" \
884 "stq $7, 0($2) \n\t" \
885 "addq $2, 8, $2 \n\t" \
886 "addq $6, $3, $3 \n\t" \
887 "addq $5, $3, $3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000888
Hanno Beckereacf3b92022-04-06 11:25:22 +0100889#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200890 "stq $3, %0 \n\t" \
891 "stq $2, %1 \n\t" \
892 "stq $1, %2 \n\t" \
Manuel Pégourié-Gonnard5af8e642014-01-10 15:53:41 +0100893 : "=m" (c), "=m" (d), "=m" (s) \
894 : "m" (s), "m" (d), "m" (c), "m" (b) \
895 : "$1", "$2", "$3", "$4", "$5", "$6", "$7" \
896 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000897#endif /* Alpha */
898
James Cowgilld1e7e8b2014-12-16 15:24:06 +0000899#if defined(__mips__) && !defined(__mips64)
Paul Bakker5121ce52009-01-03 21:22:43 +0000900
Hanno Beckereacf3b92022-04-06 11:25:22 +0100901#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200902 asm( \
903 "lw $10, %3 \n\t" \
904 "lw $11, %4 \n\t" \
905 "lw $12, %5 \n\t" \
906 "lw $13, %6 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000907
Hanno Beckereacf3b92022-04-06 11:25:22 +0100908#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200909 "lw $14, 0($10) \n\t" \
910 "multu $13, $14 \n\t" \
911 "addi $10, $10, 4 \n\t" \
912 "mflo $14 \n\t" \
913 "mfhi $9 \n\t" \
914 "addu $14, $12, $14 \n\t" \
915 "lw $15, 0($11) \n\t" \
916 "sltu $12, $14, $12 \n\t" \
917 "addu $15, $14, $15 \n\t" \
918 "sltu $14, $15, $14 \n\t" \
919 "addu $12, $12, $9 \n\t" \
920 "sw $15, 0($11) \n\t" \
921 "addu $12, $12, $14 \n\t" \
922 "addi $11, $11, 4 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000923
Hanno Beckereacf3b92022-04-06 11:25:22 +0100924#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200925 "sw $12, %0 \n\t" \
926 "sw $11, %1 \n\t" \
927 "sw $10, %2 \n\t" \
Manuel Pégourié-Gonnard8b1b1032014-01-07 18:31:06 +0100928 : "=m" (c), "=m" (d), "=m" (s) \
929 : "m" (s), "m" (d), "m" (c), "m" (b) \
Jeffrey Martind25fd8d2019-01-14 18:01:40 -0600930 : "$9", "$10", "$11", "$12", "$13", "$14", "$15", "lo", "hi" \
Manuel Pégourié-Gonnard8b1b1032014-01-07 18:31:06 +0100931 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000932
933#endif /* MIPS */
934#endif /* GNUC */
935
936#if (defined(_MSC_VER) && defined(_M_IX86)) || defined(__WATCOMC__)
937
Hanno Beckereacf3b92022-04-06 11:25:22 +0100938#define MULADDC_X1_INIT \
Paul Bakker5121ce52009-01-03 21:22:43 +0000939 __asm mov esi, s \
940 __asm mov edi, d \
941 __asm mov ecx, c \
942 __asm mov ebx, b
943
Hanno Beckereacf3b92022-04-06 11:25:22 +0100944#define MULADDC_X1_CORE \
Paul Bakker5121ce52009-01-03 21:22:43 +0000945 __asm lodsd \
946 __asm mul ebx \
947 __asm add eax, ecx \
948 __asm adc edx, 0 \
949 __asm add eax, [edi] \
950 __asm adc edx, 0 \
951 __asm mov ecx, edx \
952 __asm stosd
953
Hanno Beckereacf3b92022-04-06 11:25:22 +0100954#define MULADDC_X1_STOP \
955 __asm mov c, ecx \
956 __asm mov d, edi \
957 __asm mov s, esi
958
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200959#if defined(MBEDTLS_HAVE_SSE2)
Paul Bakker5121ce52009-01-03 21:22:43 +0000960
961#define EMIT __asm _emit
962
Hanno Beckereacf3b92022-04-06 11:25:22 +0100963#define MULADDC_X8_INIT MULADDC_X1_INIT
964
965#define MULADDC_X8_CORE \
Paul Bakker5121ce52009-01-03 21:22:43 +0000966 EMIT 0x0F EMIT 0x6E EMIT 0xC9 \
967 EMIT 0x0F EMIT 0x6E EMIT 0xC3 \
968 EMIT 0x0F EMIT 0x6E EMIT 0x1F \
969 EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
970 EMIT 0x0F EMIT 0x6E EMIT 0x16 \
971 EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
972 EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x04 \
973 EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
974 EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x08 \
975 EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
976 EMIT 0x0F EMIT 0x6E EMIT 0x7E EMIT 0x0C \
977 EMIT 0x0F EMIT 0xF4 EMIT 0xF8 \
978 EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
979 EMIT 0x0F EMIT 0x6E EMIT 0x5F EMIT 0x04 \
980 EMIT 0x0F EMIT 0xD4 EMIT 0xDC \
981 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x08 \
982 EMIT 0x0F EMIT 0xD4 EMIT 0xEE \
983 EMIT 0x0F EMIT 0x6E EMIT 0x67 EMIT 0x0C \
984 EMIT 0x0F EMIT 0xD4 EMIT 0xFC \
985 EMIT 0x0F EMIT 0x7E EMIT 0x0F \
986 EMIT 0x0F EMIT 0x6E EMIT 0x56 EMIT 0x10 \
987 EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
988 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
989 EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x14 \
990 EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
991 EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
992 EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x18 \
993 EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
994 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x04 \
995 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
996 EMIT 0x0F EMIT 0x6E EMIT 0x5E EMIT 0x1C \
997 EMIT 0x0F EMIT 0xF4 EMIT 0xD8 \
998 EMIT 0x0F EMIT 0xD4 EMIT 0xCD \
999 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x10 \
1000 EMIT 0x0F EMIT 0xD4 EMIT 0xD5 \
1001 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x08 \
1002 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
1003 EMIT 0x0F EMIT 0xD4 EMIT 0xCF \
1004 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x14 \
1005 EMIT 0x0F EMIT 0xD4 EMIT 0xE5 \
1006 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x0C \
1007 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
1008 EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
1009 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x18 \
1010 EMIT 0x0F EMIT 0xD4 EMIT 0xF5 \
1011 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x10 \
1012 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
1013 EMIT 0x0F EMIT 0xD4 EMIT 0xCC \
1014 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x1C \
1015 EMIT 0x0F EMIT 0xD4 EMIT 0xDD \
1016 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x14 \
1017 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
1018 EMIT 0x0F EMIT 0xD4 EMIT 0xCE \
1019 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x18 \
1020 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
1021 EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
1022 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x1C \
1023 EMIT 0x83 EMIT 0xC7 EMIT 0x20 \
1024 EMIT 0x83 EMIT 0xC6 EMIT 0x20 \
1025 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
1026 EMIT 0x0F EMIT 0x7E EMIT 0xC9
1027
Hanno Beckereacf3b92022-04-06 11:25:22 +01001028#define MULADDC_X8_STOP \
Paul Bakker5121ce52009-01-03 21:22:43 +00001029 EMIT 0x0F EMIT 0x77 \
1030 __asm mov c, ecx \
1031 __asm mov d, edi \
Hanno Beckereacf3b92022-04-06 11:25:22 +01001032 __asm mov s, esi
Paul Bakker5121ce52009-01-03 21:22:43 +00001033
1034#endif /* SSE2 */
1035#endif /* MSVC */
1036
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001037#endif /* MBEDTLS_HAVE_ASM */
Paul Bakker5121ce52009-01-03 21:22:43 +00001038
Hanno Beckereacf3b92022-04-06 11:25:22 +01001039#if !defined(MULADDC_X1_CORE)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001040#if defined(MBEDTLS_HAVE_UDBL)
Paul Bakker5121ce52009-01-03 21:22:43 +00001041
Hanno Beckereacf3b92022-04-06 11:25:22 +01001042#define MULADDC_X1_INIT \
Paul Bakker5121ce52009-01-03 21:22:43 +00001043{ \
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001044 mbedtls_t_udbl r; \
1045 mbedtls_mpi_uint r0, r1;
Paul Bakker5121ce52009-01-03 21:22:43 +00001046
Hanno Beckereacf3b92022-04-06 11:25:22 +01001047#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001048 r = *(s++) * (mbedtls_t_udbl) b; \
1049 r0 = (mbedtls_mpi_uint) r; \
1050 r1 = (mbedtls_mpi_uint)( r >> biL ); \
Paul Bakker5121ce52009-01-03 21:22:43 +00001051 r0 += c; r1 += (r0 < c); \
1052 r0 += *d; r1 += (r0 < *d); \
1053 c = r1; *(d++) = r0;
1054
Hanno Beckereacf3b92022-04-06 11:25:22 +01001055#define MULADDC_X1_STOP \
Paul Bakker5121ce52009-01-03 21:22:43 +00001056}
1057
Hanno Beckereacf3b92022-04-06 11:25:22 +01001058#else /* MBEDTLS_HAVE_UDBL */
1059
1060#define MULADDC_X1_INIT \
Paul Bakker5121ce52009-01-03 21:22:43 +00001061{ \
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001062 mbedtls_mpi_uint s0, s1, b0, b1; \
1063 mbedtls_mpi_uint r0, r1, rx, ry; \
Paul Bakker5121ce52009-01-03 21:22:43 +00001064 b0 = ( b << biH ) >> biH; \
1065 b1 = ( b >> biH );
1066
Hanno Beckereacf3b92022-04-06 11:25:22 +01001067#define MULADDC_X1_CORE \
Paul Bakker5121ce52009-01-03 21:22:43 +00001068 s0 = ( *s << biH ) >> biH; \
1069 s1 = ( *s >> biH ); s++; \
1070 rx = s0 * b1; r0 = s0 * b0; \
1071 ry = s1 * b0; r1 = s1 * b1; \
1072 r1 += ( rx >> biH ); \
1073 r1 += ( ry >> biH ); \
1074 rx <<= biH; ry <<= biH; \
1075 r0 += rx; r1 += (r0 < rx); \
1076 r0 += ry; r1 += (r0 < ry); \
1077 r0 += c; r1 += (r0 < c); \
1078 r0 += *d; r1 += (r0 < *d); \
1079 c = r1; *(d++) = r0;
1080
Hanno Beckereacf3b92022-04-06 11:25:22 +01001081#define MULADDC_X1_STOP \
Paul Bakker5121ce52009-01-03 21:22:43 +00001082}
1083
Paul Bakker5121ce52009-01-03 21:22:43 +00001084#endif /* C (longlong) */
Hanno Beckereacf3b92022-04-06 11:25:22 +01001085#endif /* C (generic) */
1086
1087#if !defined(MULADDC_X2_CORE)
1088#define MULADDC_X2_INIT MULADDC_X1_INIT
1089#define MULADDC_X2_STOP MULADDC_X1_STOP
1090#define MULADDC_X2_CORE MULADDC_X1_CORE MULADDC_X1_CORE
1091#endif /* MULADDC_X2_CORE */
1092
1093#if !defined(MULADDC_X4_CORE)
1094#define MULADDC_X4_INIT MULADDC_X2_INIT
1095#define MULADDC_X4_STOP MULADDC_X2_STOP
1096#define MULADDC_X4_CORE MULADDC_X2_CORE MULADDC_X2_CORE
1097#endif /* MULADDC_X4_CORE */
1098
1099#if !defined(MULADDC_X8_CORE)
1100#define MULADDC_X8_INIT MULADDC_X4_INIT
1101#define MULADDC_X8_STOP MULADDC_X4_STOP
1102#define MULADDC_X8_CORE MULADDC_X4_CORE MULADDC_X4_CORE
1103#endif /* MULADDC_X8_CORE */
Paul Bakker5121ce52009-01-03 21:22:43 +00001104
David Horstmannbec95322023-01-05 09:50:47 +00001105/* *INDENT-ON* */
Paul Bakker5121ce52009-01-03 21:22:43 +00001106#endif /* bn_mul.h */