forked from floodyberry/poly1305-opt
-
Notifications
You must be signed in to change notification settings - Fork 0
/
poly1305_x86-32.inc
632 lines (624 loc) · 10.7 KB
/
poly1305_x86-32.inc
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
/* cannibalized from the public domain x86 implementation in supercop by djb */
SECTION_TEXT
GLOBAL_HIDDEN_FN poly1305_block_size_x86
movl $16, %eax
ret
FN_END poly1305_block_size_x86
GLOBAL_HIDDEN_FN poly1305_init_ext_x86
poly1305_init_ext_x86_local:
pushl %ebx
pushl %esi
pushl %edi
pushl %eax
pushl %eax
movl 24(%esp), %eax
movl 28(%esp), %edx
movl $0x137f, %ecx
movl %ecx, 0(%esp)
fstcw 4(%esp)
fldcw 0(%esp)
movl 16(%edx), %ecx
movl 20(%edx), %ebx
movl 24(%edx), %esi
movl 28(%edx), %edi
movl %ecx, 104(%eax)
movl %ebx, 108(%eax)
movl %esi, 112(%eax)
movl %edi, 116(%eax)
movl 0(%edx), %ecx
movl 4(%edx), %ebx
movl 8(%edx), %esi
movl 12(%edx), %edi
andl $0x0fffffff, %ecx
andl $0x0ffffffc, %ebx
andl $0x0ffffffc, %esi
andl $0x0ffffffc, %edi
movl %ecx, 0(%eax)
movl $0x43300000, 4(%eax)
movl %ebx, 8(%eax)
movl $0x45300000, 12(%eax)
movl %esi, 16(%eax)
movl $0x47300000, 20(%eax)
movl %edi, 24(%eax)
movl $0x49300000, 28(%eax)
LOAD_VAR_PIC poly1305_constants_x86, %edx
fldl 0(%eax)
fsubl 64(%edx)
fldl 8(%eax)
fsubl 72(%edx)
fldl 16(%eax)
fsubl 80(%edx)
fldl 24(%eax)
fsubl 88(%edx)
fxch %st(3)
fstpl 0(%eax)
fxch %st(1)
fstl 8(%eax)
fmull 0(%edx)
fstpl 16(%eax)
fstl 24(%eax)
fmull 0(%edx)
fstpl 32(%eax)
fstl 40(%eax)
fmull 0(%edx)
fstpl 48(%eax)
fldz
fstl 56(%eax)
fstl 64(%eax)
fstl 72(%eax)
fstl 80(%eax)
fstl 88(%eax)
fstpl 96(%eax)
fldcw 4(%esp)
popl %eax
popl %eax
popl %edi
popl %esi
popl %ebx
ret
FN_END poly1305_init_ext_x86
GLOBAL_HIDDEN_FN poly1305_blocks_x86
poly1305_blocks_x86_local:
movl %esp,%eax
andl $63,%eax
addl $192,%eax
subl %eax,%esp
movl %eax,0(%esp)
movl %ebx,4(%esp)
movl %esi,8(%esp)
movl %edi,12(%esp)
movl %ebp,16(%esp)
movl $0x137f, %ecx
movl %ecx, 188(%esp)
fstcw 184(%esp)
fldcw 188(%esp)
movl $0x43300000,100(%esp)
movl $0x45300000,108(%esp)
movl $0x47300000,116(%esp)
movl $0x49300000,124(%esp)
movl 4(%esp,%eax),%ebp
movl 8(%esp,%eax),%esi
movl 12(%esp,%eax),%ecx
LOAD_VAR_PIC poly1305_constants_x86, %edx
cmp $16,%ecx
jb poly1305_blocks_x86_nomorebytes
fldt 92(%ebp)
fldt 80(%ebp)
fldt 68(%ebp)
fldt 56(%ebp)
add $16,%esi
sub $16,%ecx
movl %ecx, 20(%esp)
movl -4(%esi),%eax
movl -8(%esi),%ecx
movl -12(%esi),%ebx
movl -16(%esi),%edi
movl %eax,120(%esp)
movl %ecx,112(%esp)
movl %ebx,104(%esp)
movl %edi,96(%esp)
fxch %st(3)
faddl 120(%esp)
fsubl 96(%edx)
fxch %st(1)
faddl 104(%esp)
fsubl 72(%edx)
fxch %st(2)
faddl 112(%esp)
fsubl 80(%edx)
fxch %st(3)
faddl 96(%esp)
fsubl 64(%edx)
movl 20(%esp), %ecx
cmp $16, %ecx
jb poly1305_blocks_x86_lastmultiply
poly1305_blocks_x86_multiplyaddatleast16bytes:
add $16,%esi
sub $16,%ecx
movl %ecx, 20(%esp)
movl -4(%esi),%eax
movl -8(%esi),%ecx
movl -12(%esi),%ebx
movl -16(%esi),%edi
movl %eax,120(%esp)
movl %ecx,112(%esp)
movl %ebx,104(%esp)
movl %edi,96(%esp)
fldl 56(%edx)
fadd %st(2),%st(0)
fsubl 56(%edx)
fsubr %st(0),%st(2)
fmull 0(%edx)
fldl 32(%edx)
fadd %st(2),%st(0)
fsubl 32(%edx)
fsubr %st(0),%st(2)
fxch %st(2)
faddp %st(0),%st(1)
fldl 40(%edx)
fadd %st(4),%st(0)
fsubl 40(%edx)
fsubr %st(0),%st(4)
fldl 48(%edx)
fadd %st(6),%st(0)
fsubl 48(%edx)
fsubr %st(0),%st(6)
fxch %st(6)
faddp %st(0),%st(1)
fxch %st(3)
faddp %st(0),%st(5)
fxch %st(3)
faddp %st(0),%st(1)
fldl 40(%ebp)
fmul %st(3),%st(0)
fldl 24(%ebp)
fmul %st(4),%st(0)
fldl 8(%ebp)
fmul %st(5),%st(0)
fldl 0(%ebp)
fmulp %st(0),%st(6)
fldl 24(%ebp)
fmul %st(4),%st(0)
faddp %st(0),%st(3)
fldl 8(%ebp)
fmul %st(4),%st(0)
faddp %st(0),%st(2)
fldl 0(%ebp)
fmul %st(4),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebp)
fmulp %st(0),%st(4)
fxch %st(3)
faddp %st(0),%st(5)
fldl 8(%ebp)
fmul %st(4),%st(0)
faddp %st(0),%st(2)
fldl 0(%ebp)
fmul %st(4),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebp)
fmul %st(4),%st(0)
faddp %st(0),%st(3)
fldl 32(%ebp)
fmulp %st(0),%st(4)
fxch %st(3)
faddp %st(0),%st(4)
fldl 0(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(1)
fxch %st(3)
fldl 48(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(3)
fxch %st(1)
fldl 32(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(1)
fldl 16(%ebp)
fmulp %st(0),%st(5)
fxch %st(4)
faddp %st(0),%st(1)
movl 20(%esp), %ecx
fxch %st(2)
fldl 120(%esp)
fsubl 96(%edx)
faddp %st(0),%st(1)
fxch %st(1)
fldl 112(%esp)
fsubl 80(%edx)
cmp $16,%ecx
faddp %st(0),%st(1)
fxch %st(3)
fldl 104(%esp)
fsubl 72(%edx)
faddp %st(0),%st(1)
fxch %st(2)
fldl 96(%esp)
fsubl 64(%edx)
faddp %st(0),%st(1)
jae poly1305_blocks_x86_multiplyaddatleast16bytes
poly1305_blocks_x86_lastmultiply:
fldl 56(%edx)
fadd %st(2),%st(0)
fsubl 56(%edx)
fsubr %st(0),%st(2)
fmull 0(%edx)
fldl 32(%edx)
fadd %st(2),%st(0)
fsubl 32(%edx)
fsubr %st(0),%st(2)
fldl 40(%edx)
fadd %st(5),%st(0)
fsubl 40(%edx)
fsubr %st(0),%st(5)
fldl 48(%edx)
fadd %st(7),%st(0)
fsubl 48(%edx)
fsubr %st(0),%st(7)
fxch %st(7)
faddp %st(0),%st(1)
fxch %st(5)
faddp %st(0),%st(1)
fxch %st(3)
faddp %st(0),%st(5)
faddp %st(0),%st(1)
fldl 40(%ebp)
fmul %st(1),%st(0)
fldl 24(%ebp)
fmul %st(2),%st(0)
fldl 8(%ebp)
fmul %st(3),%st(0)
fldl 0(%ebp)
fmulp %st(0),%st(4)
fldl 24(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(3)
fldl 8(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(2)
fldl 0(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebp)
fmulp %st(0),%st(5)
fxch %st(4)
faddp %st(0),%st(3)
fldl 8(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(2)
fldl 0(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(4)
fldl 32(%ebp)
fmulp %st(0),%st(5)
fxch %st(4)
faddp %st(0),%st(2)
fldl 0(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(4)
fldl 32(%ebp)
fmul %st(5),%st(0)
faddp %st(0),%st(3)
fldl 16(%ebp)
fmulp %st(0),%st(5)
fxch %st(4)
faddp %st(0),%st(1)
fstpt 56(%ebp)
fstpt 68(%ebp)
fstpt 80(%ebp)
fstpt 92(%ebp)
poly1305_blocks_x86_nomorebytes:
fldcw 184(%esp)
movl 0(%esp), %eax
movl 4(%esp), %ebx
movl 8(%esp), %esi
movl 12(%esp), %edi
movl 16(%esp), %ebp
addl %eax, %esp
ret
FN_END poly1305_blocks_x86
GLOBAL_HIDDEN_FN poly1305_finish_ext_x86
poly1305_finish_ext_x86_local:
pushl %ebx
pushl %esi
pushl %edi
pushl %ebp
mov %esp, %ebp
andl $~63, %esp
subl $256, %esp
movl $0x137f, %ecx
movl %ecx, 0(%esp)
fstcw 4(%esp)
fldcw 0(%esp)
mov 20(%ebp), %ebx
mov 24(%ebp), %esi
mov 28(%ebp), %ecx
mov 32(%ebp), %eax
movl %ebp, 0(%esp)
movl %ebx, 4(%esp)
movl %eax, 8(%esp)
fldt 92(%ebx)
fldt 80(%ebx)
fldt 68(%ebx)
fldt 56(%ebx)
andl %ecx, %ecx
jz poly1305_finish_x86_nomorebytes
movl $0x43300000,100(%esp)
movl $0x45300000,108(%esp)
movl $0x47300000,116(%esp)
movl $0x49300000,124(%esp)
movl $0,64(%esp)
movl $0,4+64(%esp)
movl $0,8+64(%esp)
movl $0,12+64(%esp)
leal 64(%esp),%edi
rep movsb
movb $1,0(%edi)
movl 12+64(%esp),%eax
movl 8+64(%esp),%ecx
movl 4+64(%esp),%edx
movl 64(%esp),%esi
movl %eax,120(%esp)
movl %ecx,112(%esp)
movl %edx,104(%esp)
movl %esi,96(%esp)
LOAD_VAR_PIC poly1305_constants_x86, %edx
fxch %st(3)
faddl 120(%esp)
fsubl 88(%edx)
fxch %st(2)
faddl 112(%esp)
fsubl 80(%edx)
fxch %st(1)
faddl 104(%esp)
fsubl 72(%edx)
fxch %st(3)
faddl 96(%esp)
fsubl 64(%edx)
fldl 56(%edx)
fadd %st(3),%st(0)
fsubl 56(%edx)
fsubr %st(0),%st(3)
fmull 0(%edx)
fldl 32(%edx)
fadd %st(2),%st(0)
fsubl 32(%edx)
fsubr %st(0),%st(2)
fldl 40(%edx)
fadd %st(6),%st(0)
fsubl 40(%edx)
fsubr %st(0),%st(6)
fldl 48(%edx)
fadd %st(5),%st(0)
fsubl 48(%edx)
fsubr %st(0),%st(5)
fxch %st(4)
faddp %st(0),%st(3)
fxch %st(6)
faddp %st(0),%st(1)
fxch %st(3)
faddp %st(0),%st(5)
fxch %st(3)
faddp %st(0),%st(1)
fldl 40(%ebx)
fmul %st(3),%st(0)
fldl 24(%ebx)
fmul %st(4),%st(0)
fldl 8(%ebx)
fmul %st(5),%st(0)
fldl 0(%ebx)
fmulp %st(0),%st(6)
fldl 24(%ebx)
fmul %st(5),%st(0)
faddp %st(0),%st(3)
fldl 8(%ebx)
fmul %st(5),%st(0)
faddp %st(0),%st(2)
fldl 0(%ebx)
fmul %st(5),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebx)
fmulp %st(0),%st(5)
fxch %st(4)
faddp %st(0),%st(5)
fldl 8(%ebx)
fmul %st(6),%st(0)
faddp %st(0),%st(2)
fldl 0(%ebx)
fmul %st(6),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebx)
fmul %st(6),%st(0)
faddp %st(0),%st(4)
fldl 32(%ebx)
fmulp %st(0),%st(6)
fxch %st(5)
faddp %st(0),%st(4)
fldl 0(%ebx)
fmul %st(2),%st(0)
faddp %st(0),%st(1)
fldl 48(%ebx)
fmul %st(2),%st(0)
faddp %st(0),%st(5)
fldl 32(%ebx)
fmul %st(2),%st(0)
faddp %st(0),%st(3)
fldl 16(%ebx)
fmulp %st(0),%st(2)
fxch %st(1)
faddp %st(0),%st(3)
fxch %st(3)
fxch %st(2)
poly1305_finish_x86_nomorebytes:
LOAD_VAR_PIC poly1305_constants_x86, %edx
fldl 56(%edx)
fadd %st(4),%st(0)
fsubl 56(%edx)
fsubr %st(0),%st(4)
fmull 0(%edx)
fldl 32(%edx)
fadd %st(2),%st(0)
fsubl 32(%edx)
fsubr %st(0),%st(2)
fldl 40(%edx)
fadd %st(4),%st(0)
fsubl 40(%edx)
fsubr %st(0),%st(4)
fldl 48(%edx)
fadd %st(6),%st(0)
fsubl 48(%edx)
fxch %st(6)
fsub %st(6),%st(0)
fxch %st(4)
faddp %st(0),%st(3)
fxch %st(4)
faddp %st(0),%st(1)
fxch %st(2)
faddp %st(0),%st(3)
fxch %st(4)
faddp %st(0),%st(3)
fxch %st(3)
faddl 104(%edx)
fxch %st(3)
faddl 112(%edx)
fxch %st(1)
faddl 120(%edx)
fxch %st(2)
faddl 128(%edx)
fxch %st(3)
fstpl 96(%esp)
fstpl 104(%esp)
fstpl 112(%esp)
fstpl 120(%esp)
movl 100(%esp),%eax
and $63,%eax
movl 108(%esp),%ecx
and $63,%ecx
movl 116(%esp),%edx
and $63,%edx
movl 124(%esp),%ebx
and $63,%ebx
movl 104(%esp),%esi
addl %eax,%esi
movl %esi,28(%esp)
movl 112(%esp),%eax
adcl %ecx,%eax
movl %eax,32(%esp)
movl 120(%esp),%eax
adcl %edx,%eax
movl %eax,36(%esp)
mov $0,%eax
adcl %ebx,%eax
movl %eax,40(%esp)
mov $5,%eax
movl 96(%esp),%ecx
addl %ecx,%eax
movl %eax,44(%esp)
mov $0,%eax
movl 28(%esp),%edx
adcl %edx,%eax
movl %eax,28(%esp)
mov $0,%eax
movl 32(%esp),%ebx
adcl %ebx,%eax
movl %eax,32(%esp)
mov $0,%eax
movl 36(%esp),%esi
adcl %esi,%eax
movl %eax,36(%esp)
mov $0xfffffffc,%eax
movl 40(%esp),%edi
adcl %edi,%eax
sar $16,%eax
mov %eax,%edi
xor $0xffffffff,%edi
andl %eax,%ecx
movl 44(%esp),%ebp
andl %edi,%ebp
orl %ebp,%ecx
andl %eax,%edx
movl 28(%esp),%ebp
andl %edi,%ebp
orl %ebp,%edx
andl %eax,%ebx
movl 32(%esp),%ebp
andl %edi,%ebp
orl %ebp,%ebx
andl %eax,%esi
movl 36(%esp),%eax
andl %edi,%eax
orl %eax,%esi
movl 4(%esp),%eax
addl 104(%eax),%ecx
adcl 108(%eax),%edx
adcl 112(%eax),%ebx
adcl 116(%eax),%esi
movl 8(%esp),%eax
movl %ecx,0(%eax)
movl %edx,4(%eax)
movl %ebx,8(%eax)
movl %esi,12(%eax)
xorl %eax, %eax
movl 4(%esp),%edi
fldz
fstl 0(%edi)
fstl 8(%edi)
fstl 16(%edi)
fstl 24(%edi)
fstl 32(%edi)
fstl 40(%edi)
fstl 48(%edi)
fstl 56(%edi)
fstl 64(%edi)
fstl 72(%edi)
fstl 80(%edi)
fstl 88(%edi)
fstl 96(%edi)
fstl 104(%edi)
fstpl 112(%edi)
movl 0(%esp), %esp
popl %ebp
popl %edi
popl %esi
popl %ebx
ret
FN_END poly1305_finish_ext_x86
GLOBAL_HIDDEN_FN poly1305_auth_x86
poly1305_auth_x86_local:
pushl %ebp
pushl %edi
movl %esp, %ebp
subl $128, %esp
andl $~63, %esp
movl %esp, %edi
pushl 24(%ebp)
pushl %edi
calll poly1305_init_ext_x86_local
movl 20(%ebp), %ecx
andl $~15, %ecx
jz poly1305_auth_x86_no_data
pushl %ecx
pushl 16(%ebp)
addl %ecx, 16(%ebp)
pushl %edi
calll poly1305_blocks_x86_local
poly1305_auth_x86_no_data:
pushl 12(%ebp)
movl 20(%ebp), %ecx
andl $15, %ecx
pushl %ecx
pushl 16(%ebp)
pushl %edi
calll poly1305_finish_ext_x86_local
movl %ebp, %esp
popl %edi
popl %ebp
ret
FN_END poly1305_auth_x86
INCLUDE_VAR_FILE "poly1305/poly1305_constants_x86.inc", poly1305_constants_x86