blob: 4066f00d08f4c29d43d90e7ede2921fc8ef381c2 [file] [log] [blame]
Paul Bakker5121ce52009-01-03 21:22:43 +00001/**
2 * \file bn_mul.h
Paul Bakkere0ccd0a2009-01-04 16:27:10 +00003 *
Darryl Greena40a1012018-01-05 15:33:17 +00004 * \brief Multi-precision integer library
5 */
6/*
Bence Szépkúti1e148272020-08-07 13:07:28 +02007 * Copyright The Mbed TLS Contributors
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02008 * SPDX-License-Identifier: Apache-2.0
9 *
10 * Licensed under the Apache License, Version 2.0 (the "License"); you may
11 * not use this file except in compliance with the License.
12 * You may obtain a copy of the License at
13 *
14 * http://www.apache.org/licenses/LICENSE-2.0
15 *
16 * Unless required by applicable law or agreed to in writing, software
17 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
18 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
19 * See the License for the specific language governing permissions and
20 * limitations under the License.
Paul Bakker5121ce52009-01-03 21:22:43 +000021 */
22/*
23 * Multiply source vector [s] with b, add result
24 * to destination vector [d] and set carry c.
25 *
26 * Currently supports:
27 *
28 * . IA-32 (386+) . AMD64 / EM64T
29 * . IA-32 (SSE2) . Motorola 68000
30 * . PowerPC, 32-bit . MicroBlaze
31 * . PowerPC, 64-bit . TriCore
32 * . SPARC v8 . ARM v3+
33 * . Alpha . MIPS32
34 * . C, longlong . C, generic
35 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020036#ifndef MBEDTLS_BN_MUL_H
37#define MBEDTLS_BN_MUL_H
Paul Bakker5121ce52009-01-03 21:22:43 +000038
Bence Szépkútic662b362021-05-27 11:25:03 +020039#include "mbedtls/build_info.h"
Ron Eldor8b0cf2e2018-02-14 16:02:41 +020040
Jaeden Ameroc49fbbf2019-07-04 20:01:14 +010041#include "mbedtls/bignum.h"
Paul Bakker5121ce52009-01-03 21:22:43 +000042
Janos Follath8c70e812021-06-24 14:48:38 +010043
44/*
45 * Conversion macros for embedded constants:
46 * build lists of mbedtls_mpi_uint's from lists of unsigned char's grouped by 8, 4 or 2
47 */
48#if defined(MBEDTLS_HAVE_INT32)
49
Janos Follath1107ee42021-06-25 12:43:26 +010050#define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
Janos Follath8c70e812021-06-24 14:48:38 +010051 ( (mbedtls_mpi_uint) (a) << 0 ) | \
52 ( (mbedtls_mpi_uint) (b) << 8 ) | \
53 ( (mbedtls_mpi_uint) (c) << 16 ) | \
54 ( (mbedtls_mpi_uint) (d) << 24 )
55
Janos Follath1107ee42021-06-25 12:43:26 +010056#define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
57 MBEDTLS_BYTES_TO_T_UINT_4( a, b, 0, 0 )
Janos Follath8c70e812021-06-24 14:48:38 +010058
Janos Follath1107ee42021-06-25 12:43:26 +010059#define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
60 MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ), \
61 MBEDTLS_BYTES_TO_T_UINT_4( e, f, g, h )
Janos Follath8c70e812021-06-24 14:48:38 +010062
63#else /* 64-bits */
64
Janos Follath1107ee42021-06-25 12:43:26 +010065#define MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, e, f, g, h ) \
Janos Follath8c70e812021-06-24 14:48:38 +010066 ( (mbedtls_mpi_uint) (a) << 0 ) | \
67 ( (mbedtls_mpi_uint) (b) << 8 ) | \
68 ( (mbedtls_mpi_uint) (c) << 16 ) | \
69 ( (mbedtls_mpi_uint) (d) << 24 ) | \
70 ( (mbedtls_mpi_uint) (e) << 32 ) | \
71 ( (mbedtls_mpi_uint) (f) << 40 ) | \
72 ( (mbedtls_mpi_uint) (g) << 48 ) | \
73 ( (mbedtls_mpi_uint) (h) << 56 )
74
Janos Follath1107ee42021-06-25 12:43:26 +010075#define MBEDTLS_BYTES_TO_T_UINT_4( a, b, c, d ) \
76 MBEDTLS_BYTES_TO_T_UINT_8( a, b, c, d, 0, 0, 0, 0 )
Janos Follath8c70e812021-06-24 14:48:38 +010077
Janos Follath1107ee42021-06-25 12:43:26 +010078#define MBEDTLS_BYTES_TO_T_UINT_2( a, b ) \
79 MBEDTLS_BYTES_TO_T_UINT_8( a, b, 0, 0, 0, 0, 0, 0 )
Janos Follath8c70e812021-06-24 14:48:38 +010080
81#endif /* bits in mbedtls_mpi_uint */
82
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020083#if defined(MBEDTLS_HAVE_ASM)
Paul Bakker5121ce52009-01-03 21:22:43 +000084
Manuel Pégourié-Gonnardba194322015-05-29 09:47:57 +020085#ifndef asm
86#define asm __asm
87#endif
88
Manuel Pégourié-Gonnard854dab92015-08-10 12:08:34 +020089/* armcc5 --gnu defines __GNUC__ but doesn't support GNU's extended asm */
90#if defined(__GNUC__) && \
91 ( !defined(__ARMCC_VERSION) || __ARMCC_VERSION >= 6000000 )
Simon Butcher4b9a3ad2018-07-10 20:18:29 +010092
93/*
94 * Disable use of the i386 assembly code below if option -O0, to disable all
95 * compiler optimisations, is passed, detected with __OPTIMIZE__
96 * This is done as the number of registers used in the assembly code doesn't
97 * work with the -O0 option.
98 */
Simon Butchere459f072018-07-23 09:44:42 +010099#if defined(__i386__) && defined(__OPTIMIZE__)
Paul Bakker5121ce52009-01-03 21:22:43 +0000100
Hanno Beckereacf3b92022-04-06 11:25:22 +0100101#define MULADDC_X1_INIT \
Hanno Beckerefdc5192022-04-11 10:44:02 +0100102 { mbedtls_mpi_uint t; \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200103 asm( \
104 "movl %%ebx, %0 \n\t" \
105 "movl %5, %%esi \n\t" \
106 "movl %6, %%edi \n\t" \
107 "movl %7, %%ecx \n\t" \
108 "movl %8, %%ebx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000109
Hanno Beckereacf3b92022-04-06 11:25:22 +0100110#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200111 "lodsl \n\t" \
112 "mull %%ebx \n\t" \
113 "addl %%ecx, %%eax \n\t" \
114 "adcl $0, %%edx \n\t" \
115 "addl (%%edi), %%eax \n\t" \
116 "adcl $0, %%edx \n\t" \
117 "movl %%edx, %%ecx \n\t" \
118 "stosl \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000119
Hanno Beckereacf3b92022-04-06 11:25:22 +0100120#define MULADDC_X1_STOP \
121 "movl %4, %%ebx \n\t" \
122 "movl %%ecx, %1 \n\t" \
123 "movl %%edi, %2 \n\t" \
124 "movl %%esi, %3 \n\t" \
125 : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
126 : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
127 : "eax", "ebx", "ecx", "edx", "esi", "edi" \
128 ); }
129
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200130#if defined(MBEDTLS_HAVE_SSE2)
Paul Bakker5121ce52009-01-03 21:22:43 +0000131
Hanno Beckereacf3b92022-04-06 11:25:22 +0100132#define MULADDC_X8_INIT MULADDC_X1_INIT
133
134#define MULADDC_X8_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200135 "movd %%ecx, %%mm1 \n\t" \
136 "movd %%ebx, %%mm0 \n\t" \
137 "movd (%%edi), %%mm3 \n\t" \
138 "paddq %%mm3, %%mm1 \n\t" \
139 "movd (%%esi), %%mm2 \n\t" \
140 "pmuludq %%mm0, %%mm2 \n\t" \
141 "movd 4(%%esi), %%mm4 \n\t" \
142 "pmuludq %%mm0, %%mm4 \n\t" \
143 "movd 8(%%esi), %%mm6 \n\t" \
144 "pmuludq %%mm0, %%mm6 \n\t" \
145 "movd 12(%%esi), %%mm7 \n\t" \
146 "pmuludq %%mm0, %%mm7 \n\t" \
147 "paddq %%mm2, %%mm1 \n\t" \
148 "movd 4(%%edi), %%mm3 \n\t" \
149 "paddq %%mm4, %%mm3 \n\t" \
150 "movd 8(%%edi), %%mm5 \n\t" \
151 "paddq %%mm6, %%mm5 \n\t" \
152 "movd 12(%%edi), %%mm4 \n\t" \
153 "paddq %%mm4, %%mm7 \n\t" \
154 "movd %%mm1, (%%edi) \n\t" \
155 "movd 16(%%esi), %%mm2 \n\t" \
156 "pmuludq %%mm0, %%mm2 \n\t" \
157 "psrlq $32, %%mm1 \n\t" \
158 "movd 20(%%esi), %%mm4 \n\t" \
159 "pmuludq %%mm0, %%mm4 \n\t" \
160 "paddq %%mm3, %%mm1 \n\t" \
161 "movd 24(%%esi), %%mm6 \n\t" \
162 "pmuludq %%mm0, %%mm6 \n\t" \
163 "movd %%mm1, 4(%%edi) \n\t" \
164 "psrlq $32, %%mm1 \n\t" \
165 "movd 28(%%esi), %%mm3 \n\t" \
166 "pmuludq %%mm0, %%mm3 \n\t" \
167 "paddq %%mm5, %%mm1 \n\t" \
168 "movd 16(%%edi), %%mm5 \n\t" \
169 "paddq %%mm5, %%mm2 \n\t" \
170 "movd %%mm1, 8(%%edi) \n\t" \
171 "psrlq $32, %%mm1 \n\t" \
172 "paddq %%mm7, %%mm1 \n\t" \
173 "movd 20(%%edi), %%mm5 \n\t" \
174 "paddq %%mm5, %%mm4 \n\t" \
175 "movd %%mm1, 12(%%edi) \n\t" \
176 "psrlq $32, %%mm1 \n\t" \
177 "paddq %%mm2, %%mm1 \n\t" \
178 "movd 24(%%edi), %%mm5 \n\t" \
179 "paddq %%mm5, %%mm6 \n\t" \
180 "movd %%mm1, 16(%%edi) \n\t" \
181 "psrlq $32, %%mm1 \n\t" \
182 "paddq %%mm4, %%mm1 \n\t" \
183 "movd 28(%%edi), %%mm5 \n\t" \
184 "paddq %%mm5, %%mm3 \n\t" \
185 "movd %%mm1, 20(%%edi) \n\t" \
186 "psrlq $32, %%mm1 \n\t" \
187 "paddq %%mm6, %%mm1 \n\t" \
188 "movd %%mm1, 24(%%edi) \n\t" \
189 "psrlq $32, %%mm1 \n\t" \
190 "paddq %%mm3, %%mm1 \n\t" \
191 "movd %%mm1, 28(%%edi) \n\t" \
192 "addl $32, %%edi \n\t" \
193 "addl $32, %%esi \n\t" \
194 "psrlq $32, %%mm1 \n\t" \
195 "movd %%mm1, %%ecx \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000196
Hanno Beckereacf3b92022-04-06 11:25:22 +0100197#define MULADDC_X8_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200198 "emms \n\t" \
199 "movl %4, %%ebx \n\t" \
200 "movl %%ecx, %1 \n\t" \
201 "movl %%edi, %2 \n\t" \
202 "movl %%esi, %3 \n\t" \
Paul Bakkerc89cf7c2009-07-19 21:37:39 +0000203 : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
204 : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
Simon Butcher53571642018-06-24 12:58:31 +0100205 : "eax", "ebx", "ecx", "edx", "esi", "edi" \
Hanno Beckerefdc5192022-04-11 10:44:02 +0100206 ); } \
207
Paul Bakker5121ce52009-01-03 21:22:43 +0000208#endif /* SSE2 */
Hanno Beckereacf3b92022-04-06 11:25:22 +0100209
Paul Bakker5121ce52009-01-03 21:22:43 +0000210#endif /* i386 */
211
212#if defined(__amd64__) || defined (__x86_64__)
213
Hanno Beckereacf3b92022-04-06 11:25:22 +0100214#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200215 asm( \
Simon Butchera86de142018-09-30 12:09:47 +0100216 "xorq %%r8, %%r8\n"
Paul Bakker5121ce52009-01-03 21:22:43 +0000217
Hanno Beckereacf3b92022-04-06 11:25:22 +0100218#define MULADDC_X1_CORE \
Simon Butchera86de142018-09-30 12:09:47 +0100219 "movq (%%rsi), %%rax\n" \
220 "mulq %%rbx\n" \
221 "addq $8, %%rsi\n" \
222 "addq %%rcx, %%rax\n" \
223 "movq %%r8, %%rcx\n" \
224 "adcq $0, %%rdx\n" \
225 "nop \n" \
226 "addq %%rax, (%%rdi)\n" \
227 "adcq %%rdx, %%rcx\n" \
228 "addq $8, %%rdi\n"
Paul Bakker5121ce52009-01-03 21:22:43 +0000229
Hanno Beckereacf3b92022-04-06 11:25:22 +0100230#define MULADDC_X1_STOP \
Gilles Peskined337fbc2021-09-14 00:13:05 +0200231 : "+c" (c), "+D" (d), "+S" (s), "+m" (*(uint64_t (*)[16]) d) \
232 : "b" (b), "m" (*(const uint64_t (*)[16]) s) \
233 : "rax", "rdx", "r8" \
Manuel Pégourié-Gonnarddef018d2014-01-07 17:50:46 +0100234 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000235
236#endif /* AMD64 */
237
Ko-cc1871e2018-08-16 02:01:57 -0700238#if defined(__aarch64__)
239
Hanno Beckereacf3b92022-04-06 11:25:22 +0100240#define MULADDC_X1_INIT \
Ko-cc1871e2018-08-16 02:01:57 -0700241 asm(
242
Hanno Beckereacf3b92022-04-06 11:25:22 +0100243#define MULADDC_X1_CORE \
Ko-cb260bb2018-08-20 13:59:53 +0100244 "ldr x4, [%2], #8 \n\t" \
245 "ldr x5, [%1] \n\t" \
David Horstmann11c81df2021-09-22 18:15:51 +0100246 "mul x6, x4, %4 \n\t" \
247 "umulh x7, x4, %4 \n\t" \
Ko-cc1871e2018-08-16 02:01:57 -0700248 "adds x5, x5, x6 \n\t" \
249 "adc x7, x7, xzr \n\t" \
Ko-cb260bb2018-08-20 13:59:53 +0100250 "adds x5, x5, %0 \n\t" \
Ko-cc1871e2018-08-16 02:01:57 -0700251 "adc %0, x7, xzr \n\t" \
252 "str x5, [%1], #8 \n\t"
253
Hanno Beckereacf3b92022-04-06 11:25:22 +0100254#define MULADDC_X1_STOP \
David Horstmann11c81df2021-09-22 18:15:51 +0100255 : "+r" (c), "+r" (d), "+r" (s), "+m" (*(uint64_t (*)[16]) d) \
256 : "r" (b), "m" (*(const uint64_t (*)[16]) s) \
257 : "x4", "x5", "x6", "x7", "cc" \
Ko-cc1871e2018-08-16 02:01:57 -0700258 );
259
260#endif /* Aarch64 */
261
Paul Bakker5121ce52009-01-03 21:22:43 +0000262#if defined(__mc68020__) || defined(__mcpu32__)
263
Hanno Beckereacf3b92022-04-06 11:25:22 +0100264#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200265 asm( \
266 "movl %3, %%a2 \n\t" \
267 "movl %4, %%a3 \n\t" \
268 "movl %5, %%d3 \n\t" \
269 "movl %6, %%d2 \n\t" \
270 "moveq #0, %%d0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000271
Hanno Beckereacf3b92022-04-06 11:25:22 +0100272#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200273 "movel %%a2@+, %%d1 \n\t" \
274 "mulul %%d2, %%d4:%%d1 \n\t" \
275 "addl %%d3, %%d1 \n\t" \
276 "addxl %%d0, %%d4 \n\t" \
277 "moveq #0, %%d3 \n\t" \
278 "addl %%d1, %%a3@+ \n\t" \
279 "addxl %%d4, %%d3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000280
Hanno Beckereacf3b92022-04-06 11:25:22 +0100281#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200282 "movl %%d3, %0 \n\t" \
283 "movl %%a3, %1 \n\t" \
284 "movl %%a2, %2 \n\t" \
Manuel Pégourié-Gonnard3b05e4c2014-01-10 15:30:23 +0100285 : "=m" (c), "=m" (d), "=m" (s) \
286 : "m" (s), "m" (d), "m" (c), "m" (b) \
287 : "d0", "d1", "d2", "d3", "d4", "a2", "a3" \
288 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000289
Hanno Beckereacf3b92022-04-06 11:25:22 +0100290#define MULADDC_X8_INIT MULADDC_X1_INIT
291
292#define MULADDC_X8_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200293 "movel %%a2@+, %%d1 \n\t" \
294 "mulul %%d2, %%d4:%%d1 \n\t" \
295 "addxl %%d3, %%d1 \n\t" \
296 "addxl %%d0, %%d4 \n\t" \
297 "addl %%d1, %%a3@+ \n\t" \
298 "movel %%a2@+, %%d1 \n\t" \
299 "mulul %%d2, %%d3:%%d1 \n\t" \
300 "addxl %%d4, %%d1 \n\t" \
301 "addxl %%d0, %%d3 \n\t" \
302 "addl %%d1, %%a3@+ \n\t" \
303 "movel %%a2@+, %%d1 \n\t" \
304 "mulul %%d2, %%d4:%%d1 \n\t" \
305 "addxl %%d3, %%d1 \n\t" \
306 "addxl %%d0, %%d4 \n\t" \
307 "addl %%d1, %%a3@+ \n\t" \
308 "movel %%a2@+, %%d1 \n\t" \
309 "mulul %%d2, %%d3:%%d1 \n\t" \
310 "addxl %%d4, %%d1 \n\t" \
311 "addxl %%d0, %%d3 \n\t" \
312 "addl %%d1, %%a3@+ \n\t" \
313 "movel %%a2@+, %%d1 \n\t" \
314 "mulul %%d2, %%d4:%%d1 \n\t" \
315 "addxl %%d3, %%d1 \n\t" \
316 "addxl %%d0, %%d4 \n\t" \
317 "addl %%d1, %%a3@+ \n\t" \
318 "movel %%a2@+, %%d1 \n\t" \
319 "mulul %%d2, %%d3:%%d1 \n\t" \
320 "addxl %%d4, %%d1 \n\t" \
321 "addxl %%d0, %%d3 \n\t" \
322 "addl %%d1, %%a3@+ \n\t" \
323 "movel %%a2@+, %%d1 \n\t" \
324 "mulul %%d2, %%d4:%%d1 \n\t" \
325 "addxl %%d3, %%d1 \n\t" \
326 "addxl %%d0, %%d4 \n\t" \
327 "addl %%d1, %%a3@+ \n\t" \
328 "movel %%a2@+, %%d1 \n\t" \
329 "mulul %%d2, %%d3:%%d1 \n\t" \
330 "addxl %%d4, %%d1 \n\t" \
331 "addxl %%d0, %%d3 \n\t" \
332 "addl %%d1, %%a3@+ \n\t" \
333 "addxl %%d0, %%d3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000334
Hanno Beckereacf3b92022-04-06 11:25:22 +0100335#define MULADDC_X8_STOP MULADDC_X1_STOP
336
Paul Bakker5121ce52009-01-03 21:22:43 +0000337#endif /* MC68000 */
338
Paul Bakker5121ce52009-01-03 21:22:43 +0000339#if defined(__powerpc64__) || defined(__ppc64__)
340
341#if defined(__MACH__) && defined(__APPLE__)
342
Hanno Beckereacf3b92022-04-06 11:25:22 +0100343#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200344 asm( \
345 "ld r3, %3 \n\t" \
346 "ld r4, %4 \n\t" \
347 "ld r5, %5 \n\t" \
348 "ld r6, %6 \n\t" \
349 "addi r3, r3, -8 \n\t" \
350 "addi r4, r4, -8 \n\t" \
351 "addic r5, r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000352
Hanno Beckereacf3b92022-04-06 11:25:22 +0100353#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200354 "ldu r7, 8(r3) \n\t" \
355 "mulld r8, r7, r6 \n\t" \
356 "mulhdu r9, r7, r6 \n\t" \
357 "adde r8, r8, r5 \n\t" \
358 "ld r7, 8(r4) \n\t" \
359 "addze r5, r9 \n\t" \
360 "addc r8, r8, r7 \n\t" \
361 "stdu r8, 8(r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000362
Hanno Beckereacf3b92022-04-06 11:25:22 +0100363#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200364 "addze r5, r5 \n\t" \
365 "addi r4, r4, 8 \n\t" \
366 "addi r3, r3, 8 \n\t" \
367 "std r5, %0 \n\t" \
368 "std r4, %1 \n\t" \
369 "std r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100370 : "=m" (c), "=m" (d), "=m" (s) \
371 : "m" (s), "m" (d), "m" (c), "m" (b) \
372 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
373 );
374
Paul Bakker5121ce52009-01-03 21:22:43 +0000375
Paul Bakker9af723c2014-05-01 13:03:14 +0200376#else /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000377
Hanno Beckereacf3b92022-04-06 11:25:22 +0100378#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200379 asm( \
380 "ld %%r3, %3 \n\t" \
381 "ld %%r4, %4 \n\t" \
382 "ld %%r5, %5 \n\t" \
383 "ld %%r6, %6 \n\t" \
384 "addi %%r3, %%r3, -8 \n\t" \
385 "addi %%r4, %%r4, -8 \n\t" \
386 "addic %%r5, %%r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000387
Hanno Beckereacf3b92022-04-06 11:25:22 +0100388#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200389 "ldu %%r7, 8(%%r3) \n\t" \
390 "mulld %%r8, %%r7, %%r6 \n\t" \
391 "mulhdu %%r9, %%r7, %%r6 \n\t" \
392 "adde %%r8, %%r8, %%r5 \n\t" \
393 "ld %%r7, 8(%%r4) \n\t" \
394 "addze %%r5, %%r9 \n\t" \
395 "addc %%r8, %%r8, %%r7 \n\t" \
396 "stdu %%r8, 8(%%r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000397
Hanno Beckereacf3b92022-04-06 11:25:22 +0100398#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200399 "addze %%r5, %%r5 \n\t" \
400 "addi %%r4, %%r4, 8 \n\t" \
401 "addi %%r3, %%r3, 8 \n\t" \
402 "std %%r5, %0 \n\t" \
403 "std %%r4, %1 \n\t" \
404 "std %%r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100405 : "=m" (c), "=m" (d), "=m" (s) \
406 : "m" (s), "m" (d), "m" (c), "m" (b) \
407 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
408 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000409
Paul Bakker9af723c2014-05-01 13:03:14 +0200410#endif /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000411
Barry K. Nathan35e7cb92014-05-05 23:26:13 -0700412#elif defined(__powerpc__) || defined(__ppc__) /* end PPC64/begin PPC32 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000413
414#if defined(__MACH__) && defined(__APPLE__)
415
Hanno Beckereacf3b92022-04-06 11:25:22 +0100416#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200417 asm( \
418 "lwz r3, %3 \n\t" \
419 "lwz r4, %4 \n\t" \
420 "lwz r5, %5 \n\t" \
421 "lwz r6, %6 \n\t" \
422 "addi r3, r3, -4 \n\t" \
423 "addi r4, r4, -4 \n\t" \
424 "addic r5, r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000425
Hanno Beckereacf3b92022-04-06 11:25:22 +0100426#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200427 "lwzu r7, 4(r3) \n\t" \
428 "mullw r8, r7, r6 \n\t" \
429 "mulhwu r9, r7, r6 \n\t" \
430 "adde r8, r8, r5 \n\t" \
431 "lwz r7, 4(r4) \n\t" \
432 "addze r5, r9 \n\t" \
433 "addc r8, r8, r7 \n\t" \
434 "stwu r8, 4(r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000435
Hanno Beckereacf3b92022-04-06 11:25:22 +0100436#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200437 "addze r5, r5 \n\t" \
438 "addi r4, r4, 4 \n\t" \
439 "addi r3, r3, 4 \n\t" \
440 "stw r5, %0 \n\t" \
441 "stw r4, %1 \n\t" \
442 "stw r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100443 : "=m" (c), "=m" (d), "=m" (s) \
444 : "m" (s), "m" (d), "m" (c), "m" (b) \
445 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
446 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000447
Paul Bakker9af723c2014-05-01 13:03:14 +0200448#else /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000449
Hanno Beckereacf3b92022-04-06 11:25:22 +0100450#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200451 asm( \
452 "lwz %%r3, %3 \n\t" \
453 "lwz %%r4, %4 \n\t" \
454 "lwz %%r5, %5 \n\t" \
455 "lwz %%r6, %6 \n\t" \
456 "addi %%r3, %%r3, -4 \n\t" \
457 "addi %%r4, %%r4, -4 \n\t" \
458 "addic %%r5, %%r5, 0 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000459
Hanno Beckereacf3b92022-04-06 11:25:22 +0100460#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200461 "lwzu %%r7, 4(%%r3) \n\t" \
462 "mullw %%r8, %%r7, %%r6 \n\t" \
463 "mulhwu %%r9, %%r7, %%r6 \n\t" \
464 "adde %%r8, %%r8, %%r5 \n\t" \
465 "lwz %%r7, 4(%%r4) \n\t" \
466 "addze %%r5, %%r9 \n\t" \
467 "addc %%r8, %%r8, %%r7 \n\t" \
468 "stwu %%r8, 4(%%r4) \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000469
Hanno Beckereacf3b92022-04-06 11:25:22 +0100470#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200471 "addze %%r5, %%r5 \n\t" \
472 "addi %%r4, %%r4, 4 \n\t" \
473 "addi %%r3, %%r3, 4 \n\t" \
474 "stw %%r5, %0 \n\t" \
475 "stw %%r4, %1 \n\t" \
476 "stw %%r3, %2 \n\t" \
Manuel Pégourié-Gonnard02d800c2014-01-07 19:16:48 +0100477 : "=m" (c), "=m" (d), "=m" (s) \
478 : "m" (s), "m" (d), "m" (c), "m" (b) \
479 : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
480 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000481
Paul Bakker9af723c2014-05-01 13:03:14 +0200482#endif /* __MACH__ && __APPLE__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000483
484#endif /* PPC32 */
Paul Bakker5121ce52009-01-03 21:22:43 +0000485
Manuel Pégourié-Gonnard31357252014-06-24 17:57:57 +0200486/*
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200487 * The Sparc(64) assembly is reported to be broken.
Manuel Pégourié-Gonnard31357252014-06-24 17:57:57 +0200488 * Disable it for now, until we're able to fix it.
489 */
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200490#if 0 && defined(__sparc__)
491#if defined(__sparc64__)
Paul Bakker5121ce52009-01-03 21:22:43 +0000492
Hanno Beckereacf3b92022-04-06 11:25:22 +0100493#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200494 asm( \
495 "ldx %3, %%o0 \n\t" \
496 "ldx %4, %%o1 \n\t" \
497 "ld %5, %%o2 \n\t" \
498 "ld %6, %%o3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000499
Hanno Beckereacf3b92022-04-06 11:25:22 +0100500#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200501 "ld [%%o0], %%o4 \n\t" \
502 "inc 4, %%o0 \n\t" \
503 "ld [%%o1], %%o5 \n\t" \
504 "umul %%o3, %%o4, %%o4 \n\t" \
505 "addcc %%o4, %%o2, %%o4 \n\t" \
506 "rd %%y, %%g1 \n\t" \
507 "addx %%g1, 0, %%g1 \n\t" \
508 "addcc %%o4, %%o5, %%o4 \n\t" \
509 "st %%o4, [%%o1] \n\t" \
510 "addx %%g1, 0, %%o2 \n\t" \
511 "inc 4, %%o1 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000512
Hanno Beckereacf3b92022-04-06 11:25:22 +0100513#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200514 "st %%o2, %0 \n\t" \
515 "stx %%o1, %1 \n\t" \
516 "stx %%o0, %2 \n\t" \
Paul Bakker4f024b72012-10-30 07:29:57 +0000517 : "=m" (c), "=m" (d), "=m" (s) \
518 : "m" (s), "m" (d), "m" (c), "m" (b) \
519 : "g1", "o0", "o1", "o2", "o3", "o4", \
520 "o5" \
521 );
Paul Bakker4f024b72012-10-30 07:29:57 +0000522
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200523#else /* __sparc64__ */
Paul Bakker4f024b72012-10-30 07:29:57 +0000524
Hanno Beckereacf3b92022-04-06 11:25:22 +0100525#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200526 asm( \
527 "ld %3, %%o0 \n\t" \
528 "ld %4, %%o1 \n\t" \
529 "ld %5, %%o2 \n\t" \
530 "ld %6, %%o3 \n\t"
Paul Bakker4f024b72012-10-30 07:29:57 +0000531
Hanno Beckereacf3b92022-04-06 11:25:22 +0100532#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200533 "ld [%%o0], %%o4 \n\t" \
534 "inc 4, %%o0 \n\t" \
535 "ld [%%o1], %%o5 \n\t" \
536 "umul %%o3, %%o4, %%o4 \n\t" \
537 "addcc %%o4, %%o2, %%o4 \n\t" \
538 "rd %%y, %%g1 \n\t" \
539 "addx %%g1, 0, %%g1 \n\t" \
540 "addcc %%o4, %%o5, %%o4 \n\t" \
541 "st %%o4, [%%o1] \n\t" \
542 "addx %%g1, 0, %%o2 \n\t" \
543 "inc 4, %%o1 \n\t"
Paul Bakker4f024b72012-10-30 07:29:57 +0000544
Hanno Beckereacf3b92022-04-06 11:25:22 +0100545#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200546 "st %%o2, %0 \n\t" \
547 "st %%o1, %1 \n\t" \
548 "st %%o0, %2 \n\t" \
Paul Bakker4f024b72012-10-30 07:29:57 +0000549 : "=m" (c), "=m" (d), "=m" (s) \
550 : "m" (s), "m" (d), "m" (c), "m" (b) \
551 : "g1", "o0", "o1", "o2", "o3", "o4", \
552 "o5" \
553 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000554
Manuel Pégourié-Gonnard7c5fcdc2015-10-21 14:52:24 +0200555#endif /* __sparc64__ */
556#endif /* __sparc__ */
Paul Bakker5121ce52009-01-03 21:22:43 +0000557
558#if defined(__microblaze__) || defined(microblaze)
559
Hanno Beckereacf3b92022-04-06 11:25:22 +0100560#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200561 asm( \
562 "lwi r3, %3 \n\t" \
563 "lwi r4, %4 \n\t" \
564 "lwi r5, %5 \n\t" \
565 "lwi r6, %6 \n\t" \
566 "andi r7, r6, 0xffff \n\t" \
567 "bsrli r6, r6, 16 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000568
Kazuyuki Kimurab88dbdd2021-05-31 17:07:28 +0900569#if(__BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__)
570#define MULADDC_LHUI \
571 "lhui r9, r3, 0 \n\t" \
572 "addi r3, r3, 2 \n\t" \
573 "lhui r8, r3, 0 \n\t"
574#else
575#define MULADDC_LHUI \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200576 "lhui r8, r3, 0 \n\t" \
577 "addi r3, r3, 2 \n\t" \
Kazuyuki Kimurab88dbdd2021-05-31 17:07:28 +0900578 "lhui r9, r3, 0 \n\t"
579#endif
580
581#define MULADDC_X1_CORE \
582 MULADDC_LHUI \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200583 "addi r3, r3, 2 \n\t" \
584 "mul r10, r9, r6 \n\t" \
585 "mul r11, r8, r7 \n\t" \
586 "mul r12, r9, r7 \n\t" \
587 "mul r13, r8, r6 \n\t" \
588 "bsrli r8, r10, 16 \n\t" \
589 "bsrli r9, r11, 16 \n\t" \
590 "add r13, r13, r8 \n\t" \
591 "add r13, r13, r9 \n\t" \
592 "bslli r10, r10, 16 \n\t" \
593 "bslli r11, r11, 16 \n\t" \
594 "add r12, r12, r10 \n\t" \
595 "addc r13, r13, r0 \n\t" \
596 "add r12, r12, r11 \n\t" \
597 "addc r13, r13, r0 \n\t" \
598 "lwi r10, r4, 0 \n\t" \
599 "add r12, r12, r10 \n\t" \
600 "addc r13, r13, r0 \n\t" \
601 "add r12, r12, r5 \n\t" \
602 "addc r5, r13, r0 \n\t" \
603 "swi r12, r4, 0 \n\t" \
604 "addi r4, r4, 4 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000605
Hanno Beckereacf3b92022-04-06 11:25:22 +0100606#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200607 "swi r5, %0 \n\t" \
608 "swi r4, %1 \n\t" \
609 "swi r3, %2 \n\t" \
Manuel Pégourié-Gonnard1753e2f2014-01-10 15:35:41 +0100610 : "=m" (c), "=m" (d), "=m" (s) \
611 : "m" (s), "m" (d), "m" (c), "m" (b) \
Zach van Rijne7d3f8e2018-05-21 10:52:34 -0400612 : "r3", "r4", "r5", "r6", "r7", "r8", \
Manuel Pégourié-Gonnard1753e2f2014-01-10 15:35:41 +0100613 "r9", "r10", "r11", "r12", "r13" \
614 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000615
616#endif /* MicroBlaze */
617
618#if defined(__tricore__)
619
Hanno Beckereacf3b92022-04-06 11:25:22 +0100620#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200621 asm( \
622 "ld.a %%a2, %3 \n\t" \
623 "ld.a %%a3, %4 \n\t" \
624 "ld.w %%d4, %5 \n\t" \
625 "ld.w %%d1, %6 \n\t" \
626 "xor %%d5, %%d5 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000627
Hanno Beckereacf3b92022-04-06 11:25:22 +0100628#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200629 "ld.w %%d0, [%%a2+] \n\t" \
630 "madd.u %%e2, %%e4, %%d0, %%d1 \n\t" \
631 "ld.w %%d0, [%%a3] \n\t" \
632 "addx %%d2, %%d2, %%d0 \n\t" \
633 "addc %%d3, %%d3, 0 \n\t" \
634 "mov %%d4, %%d3 \n\t" \
635 "st.w [%%a3+], %%d2 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000636
Hanno Beckereacf3b92022-04-06 11:25:22 +0100637#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200638 "st.w %0, %%d4 \n\t" \
639 "st.a %1, %%a3 \n\t" \
640 "st.a %2, %%a2 \n\t" \
Manuel Pégourié-Gonnard3f687ad2014-01-10 15:47:50 +0100641 : "=m" (c), "=m" (d), "=m" (s) \
642 : "m" (s), "m" (d), "m" (c), "m" (b) \
643 : "d0", "d1", "e2", "d4", "a2", "a3" \
644 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000645
646#endif /* TriCore */
647
Manuel Pégourié-Gonnard25caaf32016-01-08 14:29:11 +0100648/*
Simon Butcher3ad2efd2018-05-02 14:49:38 +0100649 * Note, gcc -O0 by default uses r7 for the frame pointer, so it complains about
650 * our use of r7 below, unless -fomit-frame-pointer is passed.
Manuel Pégourié-Gonnard25caaf32016-01-08 14:29:11 +0100651 *
652 * On the other hand, -fomit-frame-pointer is implied by any -Ox options with
653 * x !=0, which we can detect using __OPTIMIZE__ (which is also defined by
654 * clang and armcc5 under the same conditions).
655 *
656 * So, only use the optimized assembly below for optimized build, which avoids
657 * the build error and is pretty reasonable anyway.
658 */
659#if defined(__GNUC__) && !defined(__OPTIMIZE__)
Manuel Pégourié-Gonnard365f3252016-01-08 14:58:45 +0100660#define MULADDC_CANNOT_USE_R7
Manuel Pégourié-Gonnard25caaf32016-01-08 14:29:11 +0100661#endif
662
Manuel Pégourié-Gonnard365f3252016-01-08 14:58:45 +0100663#if defined(__arm__) && !defined(MULADDC_CANNOT_USE_R7)
Paul Bakker5121ce52009-01-03 21:22:43 +0000664
Paul Bakkerfc4f46f2013-06-24 19:23:56 +0200665#if defined(__thumb__) && !defined(__thumb2__)
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000666
Hanno Beckereacf3b92022-04-06 11:25:22 +0100667#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200668 asm( \
669 "ldr r0, %3 \n\t" \
670 "ldr r1, %4 \n\t" \
671 "ldr r2, %5 \n\t" \
672 "ldr r3, %6 \n\t" \
673 "lsr r7, r3, #16 \n\t" \
674 "mov r9, r7 \n\t" \
675 "lsl r7, r3, #16 \n\t" \
676 "lsr r7, r7, #16 \n\t" \
677 "mov r8, r7 \n\t"
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000678
Hanno Beckereacf3b92022-04-06 11:25:22 +0100679#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200680 "ldmia r0!, {r6} \n\t" \
681 "lsr r7, r6, #16 \n\t" \
682 "lsl r6, r6, #16 \n\t" \
683 "lsr r6, r6, #16 \n\t" \
684 "mov r4, r8 \n\t" \
685 "mul r4, r6 \n\t" \
686 "mov r3, r9 \n\t" \
687 "mul r6, r3 \n\t" \
688 "mov r5, r9 \n\t" \
689 "mul r5, r7 \n\t" \
690 "mov r3, r8 \n\t" \
691 "mul r7, r3 \n\t" \
692 "lsr r3, r6, #16 \n\t" \
693 "add r5, r5, r3 \n\t" \
694 "lsr r3, r7, #16 \n\t" \
695 "add r5, r5, r3 \n\t" \
696 "add r4, r4, r2 \n\t" \
697 "mov r2, #0 \n\t" \
698 "adc r5, r2 \n\t" \
699 "lsl r3, r6, #16 \n\t" \
700 "add r4, r4, r3 \n\t" \
701 "adc r5, r2 \n\t" \
702 "lsl r3, r7, #16 \n\t" \
703 "add r4, r4, r3 \n\t" \
704 "adc r5, r2 \n\t" \
705 "ldr r3, [r1] \n\t" \
706 "add r4, r4, r3 \n\t" \
707 "adc r2, r5 \n\t" \
708 "stmia r1!, {r4} \n\t"
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000709
Hanno Beckereacf3b92022-04-06 11:25:22 +0100710#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200711 "str r2, %0 \n\t" \
712 "str r1, %1 \n\t" \
713 "str r0, %2 \n\t" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100714 : "=m" (c), "=m" (d), "=m" (s) \
715 : "m" (s), "m" (d), "m" (c), "m" (b) \
716 : "r0", "r1", "r2", "r3", "r4", "r5", \
Paul Bakkereff2e6d2013-04-11 17:13:22 +0200717 "r6", "r7", "r8", "r9", "cc" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100718 );
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000719
Aurelien Jarno5daa34f2018-11-03 00:46:06 +0100720#elif (__ARM_ARCH >= 6) && \
721 defined (__ARM_FEATURE_DSP) && (__ARM_FEATURE_DSP == 1)
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200722
Hanno Beckereacf3b92022-04-06 11:25:22 +0100723#define MULADDC_X1_INIT \
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100724 { \
725 mbedtls_mpi_uint tmp_a, tmp_b; \
726 asm volatile (
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200727
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100728#define MULADDC_X1_CORE \
729 ".p2align 2 \n\t" \
730 "ldr.w %[a], [%[in]], #4 \n\t" \
731 "ldr.w %[b], [%[acc]] \n\t" \
732 "umaal %[b], %[carry], %[scalar], %[a] \n\t" \
733 "str.w %[b], [%[acc]], #4 \n\t"
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200734
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100735#define MULADDC_X1_STOP \
736 : [a] "=&r" (tmp_a), \
737 [b] "=&r" (tmp_b), \
738 [in] "+r" (s), \
739 [acc] "+r" (d), \
740 [carry] "+l" (c) \
741 : [scalar] "r" (b) \
742 : "memory" \
743 ); \
744 }
745
746#define MULADDC_X2_INIT \
747 { \
748 mbedtls_mpi_uint tmp_a0, tmp_b0; \
749 mbedtls_mpi_uint tmp_a1, tmp_b1; \
750 asm volatile (
751
Hanno Becker606cb162022-04-17 06:57:34 +0100752 /* - Make sure loop is 4-byte aligned to avoid stalls
753 * upon repeated non-word aligned instructions in
754 * some microarchitectures.
755 * - Don't use ldm with post-increment or back-to-back
756 * loads with post-increment and same address register
757 * to avoid stalls on some microarchitectures.
758 * - Bunch loads and stores to reduce latency on some
759 * microarchitectures. E.g., on Cortex-M4, the first
760 * in a series of load/store operations has latency
761 * 2 cycles, while subsequent loads/stores are single-cycle. */
Hanno Beckerd46d96c2022-04-06 11:38:48 +0100762#define MULADDC_X2_CORE \
763 ".p2align 2 \n\t" \
764 "ldr.w %[a0], [%[in]], #+8 \n\t" \
765 "ldr.w %[b0], [%[acc]], #+8 \n\t" \
766 "ldr.w %[a1], [%[in], #-4] \n\t" \
767 "ldr.w %[b1], [%[acc], #-4] \n\t" \
768 "umaal %[b0], %[carry], %[scalar], %[a0] \n\t" \
769 "umaal %[b1], %[carry], %[scalar], %[a1] \n\t" \
770 "str.w %[b0], [%[acc], #-8] \n\t" \
771 "str.w %[b1], [%[acc], #-4] \n\t"
772
773#define MULADDC_X2_STOP \
774 : [a0] "=&r" (tmp_a0), \
775 [b0] "=&r" (tmp_b0), \
776 [a1] "=&r" (tmp_a1), \
777 [b1] "=&r" (tmp_b1), \
778 [in] "+r" (s), \
779 [acc] "+r" (d), \
780 [carry] "+l" (c) \
781 : [scalar] "r" (b) \
782 : "memory" \
783 ); \
784 }
Aurelien Jarno16b1bd82018-05-21 22:01:21 +0200785
Paul Bakker4f9a7bb2012-07-02 08:36:36 +0000786#else
Paul Bakkera2713a32011-11-18 12:47:23 +0000787
Hanno Beckereacf3b92022-04-06 11:25:22 +0100788#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200789 asm( \
790 "ldr r0, %3 \n\t" \
791 "ldr r1, %4 \n\t" \
792 "ldr r2, %5 \n\t" \
793 "ldr r3, %6 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000794
Hanno Beckereacf3b92022-04-06 11:25:22 +0100795#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200796 "ldr r4, [r0], #4 \n\t" \
797 "mov r5, #0 \n\t" \
798 "ldr r6, [r1] \n\t" \
799 "umlal r2, r5, r3, r4 \n\t" \
800 "adds r7, r6, r2 \n\t" \
801 "adc r2, r5, #0 \n\t" \
802 "str r7, [r1], #4 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000803
Hanno Beckereacf3b92022-04-06 11:25:22 +0100804#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200805 "str r2, %0 \n\t" \
806 "str r1, %1 \n\t" \
807 "str r0, %2 \n\t" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100808 : "=m" (c), "=m" (d), "=m" (s) \
809 : "m" (s), "m" (d), "m" (c), "m" (b) \
810 : "r0", "r1", "r2", "r3", "r4", "r5", \
Paul Bakkereff2e6d2013-04-11 17:13:22 +0200811 "r6", "r7", "cc" \
Paul Bakkerfb1cbd32013-03-06 18:14:52 +0100812 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000813
Paul Bakkera2713a32011-11-18 12:47:23 +0000814#endif /* Thumb */
815
Paul Bakker5121ce52009-01-03 21:22:43 +0000816#endif /* ARMv3 */
817
818#if defined(__alpha__)
819
Hanno Beckereacf3b92022-04-06 11:25:22 +0100820#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200821 asm( \
822 "ldq $1, %3 \n\t" \
823 "ldq $2, %4 \n\t" \
824 "ldq $3, %5 \n\t" \
825 "ldq $4, %6 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000826
Hanno Beckereacf3b92022-04-06 11:25:22 +0100827#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200828 "ldq $6, 0($1) \n\t" \
829 "addq $1, 8, $1 \n\t" \
830 "mulq $6, $4, $7 \n\t" \
831 "umulh $6, $4, $6 \n\t" \
832 "addq $7, $3, $7 \n\t" \
833 "cmpult $7, $3, $3 \n\t" \
834 "ldq $5, 0($2) \n\t" \
835 "addq $7, $5, $7 \n\t" \
836 "cmpult $7, $5, $5 \n\t" \
837 "stq $7, 0($2) \n\t" \
838 "addq $2, 8, $2 \n\t" \
839 "addq $6, $3, $3 \n\t" \
840 "addq $5, $3, $3 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000841
Hanno Beckereacf3b92022-04-06 11:25:22 +0100842#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200843 "stq $3, %0 \n\t" \
844 "stq $2, %1 \n\t" \
845 "stq $1, %2 \n\t" \
Manuel Pégourié-Gonnard5af8e642014-01-10 15:53:41 +0100846 : "=m" (c), "=m" (d), "=m" (s) \
847 : "m" (s), "m" (d), "m" (c), "m" (b) \
848 : "$1", "$2", "$3", "$4", "$5", "$6", "$7" \
849 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000850#endif /* Alpha */
851
James Cowgilld1e7e8b2014-12-16 15:24:06 +0000852#if defined(__mips__) && !defined(__mips64)
Paul Bakker5121ce52009-01-03 21:22:43 +0000853
Hanno Beckereacf3b92022-04-06 11:25:22 +0100854#define MULADDC_X1_INIT \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200855 asm( \
856 "lw $10, %3 \n\t" \
857 "lw $11, %4 \n\t" \
858 "lw $12, %5 \n\t" \
859 "lw $13, %6 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000860
Hanno Beckereacf3b92022-04-06 11:25:22 +0100861#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200862 "lw $14, 0($10) \n\t" \
863 "multu $13, $14 \n\t" \
864 "addi $10, $10, 4 \n\t" \
865 "mflo $14 \n\t" \
866 "mfhi $9 \n\t" \
867 "addu $14, $12, $14 \n\t" \
868 "lw $15, 0($11) \n\t" \
869 "sltu $12, $14, $12 \n\t" \
870 "addu $15, $14, $15 \n\t" \
871 "sltu $14, $15, $14 \n\t" \
872 "addu $12, $12, $9 \n\t" \
873 "sw $15, 0($11) \n\t" \
874 "addu $12, $12, $14 \n\t" \
875 "addi $11, $11, 4 \n\t"
Paul Bakker5121ce52009-01-03 21:22:43 +0000876
Hanno Beckereacf3b92022-04-06 11:25:22 +0100877#define MULADDC_X1_STOP \
Manuel Pégourié-Gonnardacbcbba2014-06-19 17:20:43 +0200878 "sw $12, %0 \n\t" \
879 "sw $11, %1 \n\t" \
880 "sw $10, %2 \n\t" \
Manuel Pégourié-Gonnard8b1b1032014-01-07 18:31:06 +0100881 : "=m" (c), "=m" (d), "=m" (s) \
882 : "m" (s), "m" (d), "m" (c), "m" (b) \
Jeffrey Martind25fd8d2019-01-14 18:01:40 -0600883 : "$9", "$10", "$11", "$12", "$13", "$14", "$15", "lo", "hi" \
Manuel Pégourié-Gonnard8b1b1032014-01-07 18:31:06 +0100884 );
Paul Bakker5121ce52009-01-03 21:22:43 +0000885
886#endif /* MIPS */
887#endif /* GNUC */
888
889#if (defined(_MSC_VER) && defined(_M_IX86)) || defined(__WATCOMC__)
890
Hanno Beckereacf3b92022-04-06 11:25:22 +0100891#define MULADDC_X1_INIT \
Paul Bakker5121ce52009-01-03 21:22:43 +0000892 __asm mov esi, s \
893 __asm mov edi, d \
894 __asm mov ecx, c \
895 __asm mov ebx, b
896
Hanno Beckereacf3b92022-04-06 11:25:22 +0100897#define MULADDC_X1_CORE \
Paul Bakker5121ce52009-01-03 21:22:43 +0000898 __asm lodsd \
899 __asm mul ebx \
900 __asm add eax, ecx \
901 __asm adc edx, 0 \
902 __asm add eax, [edi] \
903 __asm adc edx, 0 \
904 __asm mov ecx, edx \
905 __asm stosd
906
Hanno Beckereacf3b92022-04-06 11:25:22 +0100907#define MULADDC_X1_STOP \
908 __asm mov c, ecx \
909 __asm mov d, edi \
910 __asm mov s, esi
911
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200912#if defined(MBEDTLS_HAVE_SSE2)
Paul Bakker5121ce52009-01-03 21:22:43 +0000913
914#define EMIT __asm _emit
915
Hanno Beckereacf3b92022-04-06 11:25:22 +0100916#define MULADDC_X8_INIT MULADDC_X1_INIT
917
918#define MULADDC_X8_CORE \
Paul Bakker5121ce52009-01-03 21:22:43 +0000919 EMIT 0x0F EMIT 0x6E EMIT 0xC9 \
920 EMIT 0x0F EMIT 0x6E EMIT 0xC3 \
921 EMIT 0x0F EMIT 0x6E EMIT 0x1F \
922 EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
923 EMIT 0x0F EMIT 0x6E EMIT 0x16 \
924 EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
925 EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x04 \
926 EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
927 EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x08 \
928 EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
929 EMIT 0x0F EMIT 0x6E EMIT 0x7E EMIT 0x0C \
930 EMIT 0x0F EMIT 0xF4 EMIT 0xF8 \
931 EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
932 EMIT 0x0F EMIT 0x6E EMIT 0x5F EMIT 0x04 \
933 EMIT 0x0F EMIT 0xD4 EMIT 0xDC \
934 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x08 \
935 EMIT 0x0F EMIT 0xD4 EMIT 0xEE \
936 EMIT 0x0F EMIT 0x6E EMIT 0x67 EMIT 0x0C \
937 EMIT 0x0F EMIT 0xD4 EMIT 0xFC \
938 EMIT 0x0F EMIT 0x7E EMIT 0x0F \
939 EMIT 0x0F EMIT 0x6E EMIT 0x56 EMIT 0x10 \
940 EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
941 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
942 EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x14 \
943 EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
944 EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
945 EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x18 \
946 EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
947 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x04 \
948 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
949 EMIT 0x0F EMIT 0x6E EMIT 0x5E EMIT 0x1C \
950 EMIT 0x0F EMIT 0xF4 EMIT 0xD8 \
951 EMIT 0x0F EMIT 0xD4 EMIT 0xCD \
952 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x10 \
953 EMIT 0x0F EMIT 0xD4 EMIT 0xD5 \
954 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x08 \
955 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
956 EMIT 0x0F EMIT 0xD4 EMIT 0xCF \
957 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x14 \
958 EMIT 0x0F EMIT 0xD4 EMIT 0xE5 \
959 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x0C \
960 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
961 EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
962 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x18 \
963 EMIT 0x0F EMIT 0xD4 EMIT 0xF5 \
964 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x10 \
965 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
966 EMIT 0x0F EMIT 0xD4 EMIT 0xCC \
967 EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x1C \
968 EMIT 0x0F EMIT 0xD4 EMIT 0xDD \
969 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x14 \
970 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
971 EMIT 0x0F EMIT 0xD4 EMIT 0xCE \
972 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x18 \
973 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
974 EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
975 EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x1C \
976 EMIT 0x83 EMIT 0xC7 EMIT 0x20 \
977 EMIT 0x83 EMIT 0xC6 EMIT 0x20 \
978 EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
979 EMIT 0x0F EMIT 0x7E EMIT 0xC9
980
Hanno Beckereacf3b92022-04-06 11:25:22 +0100981#define MULADDC_X8_STOP \
Paul Bakker5121ce52009-01-03 21:22:43 +0000982 EMIT 0x0F EMIT 0x77 \
983 __asm mov c, ecx \
984 __asm mov d, edi \
Hanno Beckereacf3b92022-04-06 11:25:22 +0100985 __asm mov s, esi
Paul Bakker5121ce52009-01-03 21:22:43 +0000986
987#endif /* SSE2 */
988#endif /* MSVC */
989
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200990#endif /* MBEDTLS_HAVE_ASM */
Paul Bakker5121ce52009-01-03 21:22:43 +0000991
Hanno Beckereacf3b92022-04-06 11:25:22 +0100992#if !defined(MULADDC_X1_CORE)
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200993#if defined(MBEDTLS_HAVE_UDBL)
Paul Bakker5121ce52009-01-03 21:22:43 +0000994
Hanno Beckereacf3b92022-04-06 11:25:22 +0100995#define MULADDC_X1_INIT \
Paul Bakker5121ce52009-01-03 21:22:43 +0000996{ \
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200997 mbedtls_t_udbl r; \
998 mbedtls_mpi_uint r0, r1;
Paul Bakker5121ce52009-01-03 21:22:43 +0000999
Hanno Beckereacf3b92022-04-06 11:25:22 +01001000#define MULADDC_X1_CORE \
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001001 r = *(s++) * (mbedtls_t_udbl) b; \
1002 r0 = (mbedtls_mpi_uint) r; \
1003 r1 = (mbedtls_mpi_uint)( r >> biL ); \
Paul Bakker5121ce52009-01-03 21:22:43 +00001004 r0 += c; r1 += (r0 < c); \
1005 r0 += *d; r1 += (r0 < *d); \
1006 c = r1; *(d++) = r0;
1007
Hanno Beckereacf3b92022-04-06 11:25:22 +01001008#define MULADDC_X1_STOP \
Paul Bakker5121ce52009-01-03 21:22:43 +00001009}
1010
Hanno Beckereacf3b92022-04-06 11:25:22 +01001011#else /* MBEDTLS_HAVE_UDBL */
1012
1013#define MULADDC_X1_INIT \
Paul Bakker5121ce52009-01-03 21:22:43 +00001014{ \
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02001015 mbedtls_mpi_uint s0, s1, b0, b1; \
1016 mbedtls_mpi_uint r0, r1, rx, ry; \
Paul Bakker5121ce52009-01-03 21:22:43 +00001017 b0 = ( b << biH ) >> biH; \
1018 b1 = ( b >> biH );
1019
Hanno Beckereacf3b92022-04-06 11:25:22 +01001020#define MULADDC_X1_CORE \
Paul Bakker5121ce52009-01-03 21:22:43 +00001021 s0 = ( *s << biH ) >> biH; \
1022 s1 = ( *s >> biH ); s++; \
1023 rx = s0 * b1; r0 = s0 * b0; \
1024 ry = s1 * b0; r1 = s1 * b1; \
1025 r1 += ( rx >> biH ); \
1026 r1 += ( ry >> biH ); \
1027 rx <<= biH; ry <<= biH; \
1028 r0 += rx; r1 += (r0 < rx); \
1029 r0 += ry; r1 += (r0 < ry); \
1030 r0 += c; r1 += (r0 < c); \
1031 r0 += *d; r1 += (r0 < *d); \
1032 c = r1; *(d++) = r0;
1033
Hanno Beckereacf3b92022-04-06 11:25:22 +01001034#define MULADDC_X1_STOP \
Paul Bakker5121ce52009-01-03 21:22:43 +00001035}
1036
Paul Bakker5121ce52009-01-03 21:22:43 +00001037#endif /* C (longlong) */
Hanno Beckereacf3b92022-04-06 11:25:22 +01001038#endif /* C (generic) */
1039
1040#if !defined(MULADDC_X2_CORE)
1041#define MULADDC_X2_INIT MULADDC_X1_INIT
1042#define MULADDC_X2_STOP MULADDC_X1_STOP
1043#define MULADDC_X2_CORE MULADDC_X1_CORE MULADDC_X1_CORE
1044#endif /* MULADDC_X2_CORE */
1045
1046#if !defined(MULADDC_X4_CORE)
1047#define MULADDC_X4_INIT MULADDC_X2_INIT
1048#define MULADDC_X4_STOP MULADDC_X2_STOP
1049#define MULADDC_X4_CORE MULADDC_X2_CORE MULADDC_X2_CORE
1050#endif /* MULADDC_X4_CORE */
1051
1052#if !defined(MULADDC_X8_CORE)
1053#define MULADDC_X8_INIT MULADDC_X4_INIT
1054#define MULADDC_X8_STOP MULADDC_X4_STOP
1055#define MULADDC_X8_CORE MULADDC_X4_CORE MULADDC_X4_CORE
1056#endif /* MULADDC_X8_CORE */
Paul Bakker5121ce52009-01-03 21:22:43 +00001057
1058#endif /* bn_mul.h */