OPTIGA Trust M  1.1.0
C++ library for Optiga Trust M Chip Security Controller
bn_mul.h
Go to the documentation of this file.
1 
6 /*
7  * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
8  * SPDX-License-Identifier: Apache-2.0
9  *
10  * Licensed under the Apache License, Version 2.0 (the "License"); you may
11  * not use this file except in compliance with the License.
12  * You may obtain a copy of the License at
13  *
14  * http://www.apache.org/licenses/LICENSE-2.0
15  *
16  * Unless required by applicable law or agreed to in writing, software
17  * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
18  * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
19  * See the License for the specific language governing permissions and
20  * limitations under the License.
21  *
22  * This file is part of mbed TLS (https://tls.mbed.org)
23  */
24 /*
25  * Multiply source vector [s] with b, add result
26  * to destination vector [d] and set carry c.
27  *
28  * Currently supports:
29  *
30  * . IA-32 (386+) . AMD64 / EM64T
31  * . IA-32 (SSE2) . Motorola 68000
32  * . PowerPC, 32-bit . MicroBlaze
33  * . PowerPC, 64-bit . TriCore
34  * . SPARC v8 . ARM v3+
35  * . Alpha . MIPS32
36  * . C, longlong . C, generic
37  */
38 #ifndef MBEDTLS_BN_MUL_H
39 #define MBEDTLS_BN_MUL_H
40 
41 #include "bignum.h"
42 
43 #if defined(MBEDTLS_HAVE_ASM)
44 
45 #ifndef asm
46 #define asm __asm
47 #endif
48 
49 /* armcc5 --gnu defines __GNUC__ but doesn't support GNU's extended asm */
50 #if defined(__GNUC__) && \
51  ( !defined(__ARMCC_VERSION) || __ARMCC_VERSION >= 6000000 )
52 
53 /*
54  * Disable use of the i386 assembly code below if option -O0, to disable all
55  * compiler optimisations, is passed, detected with __OPTIMIZE__
56  * This is done as the number of registers used in the assembly code doesn't
57  * work with the -O0 option.
58  */
59 #if defined(__i386__) && defined(__OPTIMIZE__)
60 
61 #define MULADDC_INIT \
62  asm( \
63  "movl %%ebx, %0 \n\t" \
64  "movl %5, %%esi \n\t" \
65  "movl %6, %%edi \n\t" \
66  "movl %7, %%ecx \n\t" \
67  "movl %8, %%ebx \n\t"
68 
69 #define MULADDC_CORE \
70  "lodsl \n\t" \
71  "mull %%ebx \n\t" \
72  "addl %%ecx, %%eax \n\t" \
73  "adcl $0, %%edx \n\t" \
74  "addl (%%edi), %%eax \n\t" \
75  "adcl $0, %%edx \n\t" \
76  "movl %%edx, %%ecx \n\t" \
77  "stosl \n\t"
78 
79 #if defined(MBEDTLS_HAVE_SSE2)
80 
81 #define MULADDC_HUIT \
82  "movd %%ecx, %%mm1 \n\t" \
83  "movd %%ebx, %%mm0 \n\t" \
84  "movd (%%edi), %%mm3 \n\t" \
85  "paddq %%mm3, %%mm1 \n\t" \
86  "movd (%%esi), %%mm2 \n\t" \
87  "pmuludq %%mm0, %%mm2 \n\t" \
88  "movd 4(%%esi), %%mm4 \n\t" \
89  "pmuludq %%mm0, %%mm4 \n\t" \
90  "movd 8(%%esi), %%mm6 \n\t" \
91  "pmuludq %%mm0, %%mm6 \n\t" \
92  "movd 12(%%esi), %%mm7 \n\t" \
93  "pmuludq %%mm0, %%mm7 \n\t" \
94  "paddq %%mm2, %%mm1 \n\t" \
95  "movd 4(%%edi), %%mm3 \n\t" \
96  "paddq %%mm4, %%mm3 \n\t" \
97  "movd 8(%%edi), %%mm5 \n\t" \
98  "paddq %%mm6, %%mm5 \n\t" \
99  "movd 12(%%edi), %%mm4 \n\t" \
100  "paddq %%mm4, %%mm7 \n\t" \
101  "movd %%mm1, (%%edi) \n\t" \
102  "movd 16(%%esi), %%mm2 \n\t" \
103  "pmuludq %%mm0, %%mm2 \n\t" \
104  "psrlq $32, %%mm1 \n\t" \
105  "movd 20(%%esi), %%mm4 \n\t" \
106  "pmuludq %%mm0, %%mm4 \n\t" \
107  "paddq %%mm3, %%mm1 \n\t" \
108  "movd 24(%%esi), %%mm6 \n\t" \
109  "pmuludq %%mm0, %%mm6 \n\t" \
110  "movd %%mm1, 4(%%edi) \n\t" \
111  "psrlq $32, %%mm1 \n\t" \
112  "movd 28(%%esi), %%mm3 \n\t" \
113  "pmuludq %%mm0, %%mm3 \n\t" \
114  "paddq %%mm5, %%mm1 \n\t" \
115  "movd 16(%%edi), %%mm5 \n\t" \
116  "paddq %%mm5, %%mm2 \n\t" \
117  "movd %%mm1, 8(%%edi) \n\t" \
118  "psrlq $32, %%mm1 \n\t" \
119  "paddq %%mm7, %%mm1 \n\t" \
120  "movd 20(%%edi), %%mm5 \n\t" \
121  "paddq %%mm5, %%mm4 \n\t" \
122  "movd %%mm1, 12(%%edi) \n\t" \
123  "psrlq $32, %%mm1 \n\t" \
124  "paddq %%mm2, %%mm1 \n\t" \
125  "movd 24(%%edi), %%mm5 \n\t" \
126  "paddq %%mm5, %%mm6 \n\t" \
127  "movd %%mm1, 16(%%edi) \n\t" \
128  "psrlq $32, %%mm1 \n\t" \
129  "paddq %%mm4, %%mm1 \n\t" \
130  "movd 28(%%edi), %%mm5 \n\t" \
131  "paddq %%mm5, %%mm3 \n\t" \
132  "movd %%mm1, 20(%%edi) \n\t" \
133  "psrlq $32, %%mm1 \n\t" \
134  "paddq %%mm6, %%mm1 \n\t" \
135  "movd %%mm1, 24(%%edi) \n\t" \
136  "psrlq $32, %%mm1 \n\t" \
137  "paddq %%mm3, %%mm1 \n\t" \
138  "movd %%mm1, 28(%%edi) \n\t" \
139  "addl $32, %%edi \n\t" \
140  "addl $32, %%esi \n\t" \
141  "psrlq $32, %%mm1 \n\t" \
142  "movd %%mm1, %%ecx \n\t"
143 
144 #define MULADDC_STOP \
145  "emms \n\t" \
146  "movl %4, %%ebx \n\t" \
147  "movl %%ecx, %1 \n\t" \
148  "movl %%edi, %2 \n\t" \
149  "movl %%esi, %3 \n\t" \
150  : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
151  : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
152  : "eax", "ebx", "ecx", "edx", "esi", "edi" \
153  );
154 
155 #else
156 
157 #define MULADDC_STOP \
158  "movl %4, %%ebx \n\t" \
159  "movl %%ecx, %1 \n\t" \
160  "movl %%edi, %2 \n\t" \
161  "movl %%esi, %3 \n\t" \
162  : "=m" (t), "=m" (c), "=m" (d), "=m" (s) \
163  : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b) \
164  : "eax", "ebx", "ecx", "edx", "esi", "edi" \
165  );
166 #endif /* SSE2 */
167 #endif /* i386 */
168 
169 #if defined(__amd64__) || defined (__x86_64__)
170 
171 #define MULADDC_INIT \
172  asm( \
173  "xorq %%r8, %%r8\n"
174 
175 #define MULADDC_CORE \
176  "movq (%%rsi), %%rax\n" \
177  "mulq %%rbx\n" \
178  "addq $8, %%rsi\n" \
179  "addq %%rcx, %%rax\n" \
180  "movq %%r8, %%rcx\n" \
181  "adcq $0, %%rdx\n" \
182  "nop \n" \
183  "addq %%rax, (%%rdi)\n" \
184  "adcq %%rdx, %%rcx\n" \
185  "addq $8, %%rdi\n"
186 
187 #define MULADDC_STOP \
188  : "+c" (c), "+D" (d), "+S" (s) \
189  : "b" (b) \
190  : "rax", "rdx", "r8" \
191  );
192 
193 #endif /* AMD64 */
194 
195 #if defined(__mc68020__) || defined(__mcpu32__)
196 
197 #define MULADDC_INIT \
198  asm( \
199  "movl %3, %%a2 \n\t" \
200  "movl %4, %%a3 \n\t" \
201  "movl %5, %%d3 \n\t" \
202  "movl %6, %%d2 \n\t" \
203  "moveq #0, %%d0 \n\t"
204 
205 #define MULADDC_CORE \
206  "movel %%a2@+, %%d1 \n\t" \
207  "mulul %%d2, %%d4:%%d1 \n\t" \
208  "addl %%d3, %%d1 \n\t" \
209  "addxl %%d0, %%d4 \n\t" \
210  "moveq #0, %%d3 \n\t" \
211  "addl %%d1, %%a3@+ \n\t" \
212  "addxl %%d4, %%d3 \n\t"
213 
214 #define MULADDC_STOP \
215  "movl %%d3, %0 \n\t" \
216  "movl %%a3, %1 \n\t" \
217  "movl %%a2, %2 \n\t" \
218  : "=m" (c), "=m" (d), "=m" (s) \
219  : "m" (s), "m" (d), "m" (c), "m" (b) \
220  : "d0", "d1", "d2", "d3", "d4", "a2", "a3" \
221  );
222 
223 #define MULADDC_HUIT \
224  "movel %%a2@+, %%d1 \n\t" \
225  "mulul %%d2, %%d4:%%d1 \n\t" \
226  "addxl %%d3, %%d1 \n\t" \
227  "addxl %%d0, %%d4 \n\t" \
228  "addl %%d1, %%a3@+ \n\t" \
229  "movel %%a2@+, %%d1 \n\t" \
230  "mulul %%d2, %%d3:%%d1 \n\t" \
231  "addxl %%d4, %%d1 \n\t" \
232  "addxl %%d0, %%d3 \n\t" \
233  "addl %%d1, %%a3@+ \n\t" \
234  "movel %%a2@+, %%d1 \n\t" \
235  "mulul %%d2, %%d4:%%d1 \n\t" \
236  "addxl %%d3, %%d1 \n\t" \
237  "addxl %%d0, %%d4 \n\t" \
238  "addl %%d1, %%a3@+ \n\t" \
239  "movel %%a2@+, %%d1 \n\t" \
240  "mulul %%d2, %%d3:%%d1 \n\t" \
241  "addxl %%d4, %%d1 \n\t" \
242  "addxl %%d0, %%d3 \n\t" \
243  "addl %%d1, %%a3@+ \n\t" \
244  "movel %%a2@+, %%d1 \n\t" \
245  "mulul %%d2, %%d4:%%d1 \n\t" \
246  "addxl %%d3, %%d1 \n\t" \
247  "addxl %%d0, %%d4 \n\t" \
248  "addl %%d1, %%a3@+ \n\t" \
249  "movel %%a2@+, %%d1 \n\t" \
250  "mulul %%d2, %%d3:%%d1 \n\t" \
251  "addxl %%d4, %%d1 \n\t" \
252  "addxl %%d0, %%d3 \n\t" \
253  "addl %%d1, %%a3@+ \n\t" \
254  "movel %%a2@+, %%d1 \n\t" \
255  "mulul %%d2, %%d4:%%d1 \n\t" \
256  "addxl %%d3, %%d1 \n\t" \
257  "addxl %%d0, %%d4 \n\t" \
258  "addl %%d1, %%a3@+ \n\t" \
259  "movel %%a2@+, %%d1 \n\t" \
260  "mulul %%d2, %%d3:%%d1 \n\t" \
261  "addxl %%d4, %%d1 \n\t" \
262  "addxl %%d0, %%d3 \n\t" \
263  "addl %%d1, %%a3@+ \n\t" \
264  "addxl %%d0, %%d3 \n\t"
265 
266 #endif /* MC68000 */
267 
268 #if defined(__powerpc64__) || defined(__ppc64__)
269 
270 #if defined(__MACH__) && defined(__APPLE__)
271 
272 #define MULADDC_INIT \
273  asm( \
274  "ld r3, %3 \n\t" \
275  "ld r4, %4 \n\t" \
276  "ld r5, %5 \n\t" \
277  "ld r6, %6 \n\t" \
278  "addi r3, r3, -8 \n\t" \
279  "addi r4, r4, -8 \n\t" \
280  "addic r5, r5, 0 \n\t"
281 
282 #define MULADDC_CORE \
283  "ldu r7, 8(r3) \n\t" \
284  "mulld r8, r7, r6 \n\t" \
285  "mulhdu r9, r7, r6 \n\t" \
286  "adde r8, r8, r5 \n\t" \
287  "ld r7, 8(r4) \n\t" \
288  "addze r5, r9 \n\t" \
289  "addc r8, r8, r7 \n\t" \
290  "stdu r8, 8(r4) \n\t"
291 
292 #define MULADDC_STOP \
293  "addze r5, r5 \n\t" \
294  "addi r4, r4, 8 \n\t" \
295  "addi r3, r3, 8 \n\t" \
296  "std r5, %0 \n\t" \
297  "std r4, %1 \n\t" \
298  "std r3, %2 \n\t" \
299  : "=m" (c), "=m" (d), "=m" (s) \
300  : "m" (s), "m" (d), "m" (c), "m" (b) \
301  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
302  );
303 
304 
305 #else /* __MACH__ && __APPLE__ */
306 
307 #define MULADDC_INIT \
308  asm( \
309  "ld %%r3, %3 \n\t" \
310  "ld %%r4, %4 \n\t" \
311  "ld %%r5, %5 \n\t" \
312  "ld %%r6, %6 \n\t" \
313  "addi %%r3, %%r3, -8 \n\t" \
314  "addi %%r4, %%r4, -8 \n\t" \
315  "addic %%r5, %%r5, 0 \n\t"
316 
317 #define MULADDC_CORE \
318  "ldu %%r7, 8(%%r3) \n\t" \
319  "mulld %%r8, %%r7, %%r6 \n\t" \
320  "mulhdu %%r9, %%r7, %%r6 \n\t" \
321  "adde %%r8, %%r8, %%r5 \n\t" \
322  "ld %%r7, 8(%%r4) \n\t" \
323  "addze %%r5, %%r9 \n\t" \
324  "addc %%r8, %%r8, %%r7 \n\t" \
325  "stdu %%r8, 8(%%r4) \n\t"
326 
327 #define MULADDC_STOP \
328  "addze %%r5, %%r5 \n\t" \
329  "addi %%r4, %%r4, 8 \n\t" \
330  "addi %%r3, %%r3, 8 \n\t" \
331  "std %%r5, %0 \n\t" \
332  "std %%r4, %1 \n\t" \
333  "std %%r3, %2 \n\t" \
334  : "=m" (c), "=m" (d), "=m" (s) \
335  : "m" (s), "m" (d), "m" (c), "m" (b) \
336  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
337  );
338 
339 #endif /* __MACH__ && __APPLE__ */
340 
341 #elif defined(__powerpc__) || defined(__ppc__) /* end PPC64/begin PPC32 */
342 
343 #if defined(__MACH__) && defined(__APPLE__)
344 
345 #define MULADDC_INIT \
346  asm( \
347  "lwz r3, %3 \n\t" \
348  "lwz r4, %4 \n\t" \
349  "lwz r5, %5 \n\t" \
350  "lwz r6, %6 \n\t" \
351  "addi r3, r3, -4 \n\t" \
352  "addi r4, r4, -4 \n\t" \
353  "addic r5, r5, 0 \n\t"
354 
355 #define MULADDC_CORE \
356  "lwzu r7, 4(r3) \n\t" \
357  "mullw r8, r7, r6 \n\t" \
358  "mulhwu r9, r7, r6 \n\t" \
359  "adde r8, r8, r5 \n\t" \
360  "lwz r7, 4(r4) \n\t" \
361  "addze r5, r9 \n\t" \
362  "addc r8, r8, r7 \n\t" \
363  "stwu r8, 4(r4) \n\t"
364 
365 #define MULADDC_STOP \
366  "addze r5, r5 \n\t" \
367  "addi r4, r4, 4 \n\t" \
368  "addi r3, r3, 4 \n\t" \
369  "stw r5, %0 \n\t" \
370  "stw r4, %1 \n\t" \
371  "stw r3, %2 \n\t" \
372  : "=m" (c), "=m" (d), "=m" (s) \
373  : "m" (s), "m" (d), "m" (c), "m" (b) \
374  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
375  );
376 
377 #else /* __MACH__ && __APPLE__ */
378 
379 #define MULADDC_INIT \
380  asm( \
381  "lwz %%r3, %3 \n\t" \
382  "lwz %%r4, %4 \n\t" \
383  "lwz %%r5, %5 \n\t" \
384  "lwz %%r6, %6 \n\t" \
385  "addi %%r3, %%r3, -4 \n\t" \
386  "addi %%r4, %%r4, -4 \n\t" \
387  "addic %%r5, %%r5, 0 \n\t"
388 
389 #define MULADDC_CORE \
390  "lwzu %%r7, 4(%%r3) \n\t" \
391  "mullw %%r8, %%r7, %%r6 \n\t" \
392  "mulhwu %%r9, %%r7, %%r6 \n\t" \
393  "adde %%r8, %%r8, %%r5 \n\t" \
394  "lwz %%r7, 4(%%r4) \n\t" \
395  "addze %%r5, %%r9 \n\t" \
396  "addc %%r8, %%r8, %%r7 \n\t" \
397  "stwu %%r8, 4(%%r4) \n\t"
398 
399 #define MULADDC_STOP \
400  "addze %%r5, %%r5 \n\t" \
401  "addi %%r4, %%r4, 4 \n\t" \
402  "addi %%r3, %%r3, 4 \n\t" \
403  "stw %%r5, %0 \n\t" \
404  "stw %%r4, %1 \n\t" \
405  "stw %%r3, %2 \n\t" \
406  : "=m" (c), "=m" (d), "=m" (s) \
407  : "m" (s), "m" (d), "m" (c), "m" (b) \
408  : "r3", "r4", "r5", "r6", "r7", "r8", "r9" \
409  );
410 
411 #endif /* __MACH__ && __APPLE__ */
412 
413 #endif /* PPC32 */
414 
415 /*
416  * The Sparc(64) assembly is reported to be broken.
417  * Disable it for now, until we're able to fix it.
418  */
419 #if 0 && defined(__sparc__)
420 #if defined(__sparc64__)
421 
422 #define MULADDC_INIT \
423  asm( \
424  "ldx %3, %%o0 \n\t" \
425  "ldx %4, %%o1 \n\t" \
426  "ld %5, %%o2 \n\t" \
427  "ld %6, %%o3 \n\t"
428 
429 #define MULADDC_CORE \
430  "ld [%%o0], %%o4 \n\t" \
431  "inc 4, %%o0 \n\t" \
432  "ld [%%o1], %%o5 \n\t" \
433  "umul %%o3, %%o4, %%o4 \n\t" \
434  "addcc %%o4, %%o2, %%o4 \n\t" \
435  "rd %%y, %%g1 \n\t" \
436  "addx %%g1, 0, %%g1 \n\t" \
437  "addcc %%o4, %%o5, %%o4 \n\t" \
438  "st %%o4, [%%o1] \n\t" \
439  "addx %%g1, 0, %%o2 \n\t" \
440  "inc 4, %%o1 \n\t"
441 
442  #define MULADDC_STOP \
443  "st %%o2, %0 \n\t" \
444  "stx %%o1, %1 \n\t" \
445  "stx %%o0, %2 \n\t" \
446  : "=m" (c), "=m" (d), "=m" (s) \
447  : "m" (s), "m" (d), "m" (c), "m" (b) \
448  : "g1", "o0", "o1", "o2", "o3", "o4", \
449  "o5" \
450  );
451 
452 #else /* __sparc64__ */
453 
454 #define MULADDC_INIT \
455  asm( \
456  "ld %3, %%o0 \n\t" \
457  "ld %4, %%o1 \n\t" \
458  "ld %5, %%o2 \n\t" \
459  "ld %6, %%o3 \n\t"
460 
461 #define MULADDC_CORE \
462  "ld [%%o0], %%o4 \n\t" \
463  "inc 4, %%o0 \n\t" \
464  "ld [%%o1], %%o5 \n\t" \
465  "umul %%o3, %%o4, %%o4 \n\t" \
466  "addcc %%o4, %%o2, %%o4 \n\t" \
467  "rd %%y, %%g1 \n\t" \
468  "addx %%g1, 0, %%g1 \n\t" \
469  "addcc %%o4, %%o5, %%o4 \n\t" \
470  "st %%o4, [%%o1] \n\t" \
471  "addx %%g1, 0, %%o2 \n\t" \
472  "inc 4, %%o1 \n\t"
473 
474 #define MULADDC_STOP \
475  "st %%o2, %0 \n\t" \
476  "st %%o1, %1 \n\t" \
477  "st %%o0, %2 \n\t" \
478  : "=m" (c), "=m" (d), "=m" (s) \
479  : "m" (s), "m" (d), "m" (c), "m" (b) \
480  : "g1", "o0", "o1", "o2", "o3", "o4", \
481  "o5" \
482  );
483 
484 #endif /* __sparc64__ */
485 #endif /* __sparc__ */
486 
487 #if defined(__microblaze__) || defined(microblaze)
488 
489 #define MULADDC_INIT \
490  asm( \
491  "lwi r3, %3 \n\t" \
492  "lwi r4, %4 \n\t" \
493  "lwi r5, %5 \n\t" \
494  "lwi r6, %6 \n\t" \
495  "andi r7, r6, 0xffff \n\t" \
496  "bsrli r6, r6, 16 \n\t"
497 
498 #define MULADDC_CORE \
499  "lhui r8, r3, 0 \n\t" \
500  "addi r3, r3, 2 \n\t" \
501  "lhui r9, r3, 0 \n\t" \
502  "addi r3, r3, 2 \n\t" \
503  "mul r10, r9, r6 \n\t" \
504  "mul r11, r8, r7 \n\t" \
505  "mul r12, r9, r7 \n\t" \
506  "mul r13, r8, r6 \n\t" \
507  "bsrli r8, r10, 16 \n\t" \
508  "bsrli r9, r11, 16 \n\t" \
509  "add r13, r13, r8 \n\t" \
510  "add r13, r13, r9 \n\t" \
511  "bslli r10, r10, 16 \n\t" \
512  "bslli r11, r11, 16 \n\t" \
513  "add r12, r12, r10 \n\t" \
514  "addc r13, r13, r0 \n\t" \
515  "add r12, r12, r11 \n\t" \
516  "addc r13, r13, r0 \n\t" \
517  "lwi r10, r4, 0 \n\t" \
518  "add r12, r12, r10 \n\t" \
519  "addc r13, r13, r0 \n\t" \
520  "add r12, r12, r5 \n\t" \
521  "addc r5, r13, r0 \n\t" \
522  "swi r12, r4, 0 \n\t" \
523  "addi r4, r4, 4 \n\t"
524 
525 #define MULADDC_STOP \
526  "swi r5, %0 \n\t" \
527  "swi r4, %1 \n\t" \
528  "swi r3, %2 \n\t" \
529  : "=m" (c), "=m" (d), "=m" (s) \
530  : "m" (s), "m" (d), "m" (c), "m" (b) \
531  : "r3", "r4", "r5", "r6", "r7", "r8", \
532  "r9", "r10", "r11", "r12", "r13" \
533  );
534 
535 #endif /* MicroBlaze */
536 
537 #if defined(__tricore__)
538 
539 #define MULADDC_INIT \
540  asm( \
541  "ld.a %%a2, %3 \n\t" \
542  "ld.a %%a3, %4 \n\t" \
543  "ld.w %%d4, %5 \n\t" \
544  "ld.w %%d1, %6 \n\t" \
545  "xor %%d5, %%d5 \n\t"
546 
547 #define MULADDC_CORE \
548  "ld.w %%d0, [%%a2+] \n\t" \
549  "madd.u %%e2, %%e4, %%d0, %%d1 \n\t" \
550  "ld.w %%d0, [%%a3] \n\t" \
551  "addx %%d2, %%d2, %%d0 \n\t" \
552  "addc %%d3, %%d3, 0 \n\t" \
553  "mov %%d4, %%d3 \n\t" \
554  "st.w [%%a3+], %%d2 \n\t"
555 
556 #define MULADDC_STOP \
557  "st.w %0, %%d4 \n\t" \
558  "st.a %1, %%a3 \n\t" \
559  "st.a %2, %%a2 \n\t" \
560  : "=m" (c), "=m" (d), "=m" (s) \
561  : "m" (s), "m" (d), "m" (c), "m" (b) \
562  : "d0", "d1", "e2", "d4", "a2", "a3" \
563  );
564 
565 #endif /* TriCore */
566 
567 /*
568  * Note, gcc -O0 by default uses r7 for the frame pointer, so it complains about
569  * our use of r7 below, unless -fomit-frame-pointer is passed.
570  *
571  * On the other hand, -fomit-frame-pointer is implied by any -Ox options with
572  * x !=0, which we can detect using __OPTIMIZE__ (which is also defined by
573  * clang and armcc5 under the same conditions).
574  *
575  * So, only use the optimized assembly below for optimized build, which avoids
576  * the build error and is pretty reasonable anyway.
577  */
578 #if defined(__GNUC__) && !defined(__OPTIMIZE__)
579 #define MULADDC_CANNOT_USE_R7
580 #endif
581 
582 #if defined(__arm__) && !defined(MULADDC_CANNOT_USE_R7)
583 
584 #if defined(__thumb__) && !defined(__thumb2__)
585 
586 #define MULADDC_INIT \
587  asm( \
588  "ldr r0, %3 \n\t" \
589  "ldr r1, %4 \n\t" \
590  "ldr r2, %5 \n\t" \
591  "ldr r3, %6 \n\t" \
592  "lsr r7, r3, #16 \n\t" \
593  "mov r9, r7 \n\t" \
594  "lsl r7, r3, #16 \n\t" \
595  "lsr r7, r7, #16 \n\t" \
596  "mov r8, r7 \n\t"
597 
598 #define MULADDC_CORE \
599  "ldmia r0!, {r6} \n\t" \
600  "lsr r7, r6, #16 \n\t" \
601  "lsl r6, r6, #16 \n\t" \
602  "lsr r6, r6, #16 \n\t" \
603  "mov r4, r8 \n\t" \
604  "mul r4, r6 \n\t" \
605  "mov r3, r9 \n\t" \
606  "mul r6, r3 \n\t" \
607  "mov r5, r9 \n\t" \
608  "mul r5, r7 \n\t" \
609  "mov r3, r8 \n\t" \
610  "mul r7, r3 \n\t" \
611  "lsr r3, r6, #16 \n\t" \
612  "add r5, r5, r3 \n\t" \
613  "lsr r3, r7, #16 \n\t" \
614  "add r5, r5, r3 \n\t" \
615  "add r4, r4, r2 \n\t" \
616  "mov r2, #0 \n\t" \
617  "adc r5, r2 \n\t" \
618  "lsl r3, r6, #16 \n\t" \
619  "add r4, r4, r3 \n\t" \
620  "adc r5, r2 \n\t" \
621  "lsl r3, r7, #16 \n\t" \
622  "add r4, r4, r3 \n\t" \
623  "adc r5, r2 \n\t" \
624  "ldr r3, [r1] \n\t" \
625  "add r4, r4, r3 \n\t" \
626  "adc r2, r5 \n\t" \
627  "stmia r1!, {r4} \n\t"
628 
629 #define MULADDC_STOP \
630  "str r2, %0 \n\t" \
631  "str r1, %1 \n\t" \
632  "str r0, %2 \n\t" \
633  : "=m" (c), "=m" (d), "=m" (s) \
634  : "m" (s), "m" (d), "m" (c), "m" (b) \
635  : "r0", "r1", "r2", "r3", "r4", "r5", \
636  "r6", "r7", "r8", "r9", "cc" \
637  );
638 
639 #elif defined (__ARM_FEATURE_DSP) && (__ARM_FEATURE_DSP == 1)
640 
641 #define MULADDC_INIT \
642  asm(
643 
644 #define MULADDC_CORE \
645  "ldr r0, [%0], #4 \n\t" \
646  "ldr r1, [%1] \n\t" \
647  "umaal r1, %2, %3, r0 \n\t" \
648  "str r1, [%1], #4 \n\t"
649 
650 #define MULADDC_STOP \
651  : "=r" (s), "=r" (d), "=r" (c) \
652  : "r" (b), "0" (s), "1" (d), "2" (c) \
653  : "r0", "r1", "memory" \
654  );
655 
656 #else
657 
658 #define MULADDC_INIT \
659  asm( \
660  "ldr r0, %3 \n\t" \
661  "ldr r1, %4 \n\t" \
662  "ldr r2, %5 \n\t" \
663  "ldr r3, %6 \n\t"
664 
665 #define MULADDC_CORE \
666  "ldr r4, [r0], #4 \n\t" \
667  "mov r5, #0 \n\t" \
668  "ldr r6, [r1] \n\t" \
669  "umlal r2, r5, r3, r4 \n\t" \
670  "adds r7, r6, r2 \n\t" \
671  "adc r2, r5, #0 \n\t" \
672  "str r7, [r1], #4 \n\t"
673 
674 #define MULADDC_STOP \
675  "str r2, %0 \n\t" \
676  "str r1, %1 \n\t" \
677  "str r0, %2 \n\t" \
678  : "=m" (c), "=m" (d), "=m" (s) \
679  : "m" (s), "m" (d), "m" (c), "m" (b) \
680  : "r0", "r1", "r2", "r3", "r4", "r5", \
681  "r6", "r7", "cc" \
682  );
683 
684 #endif /* Thumb */
685 
686 #endif /* ARMv3 */
687 
688 #if defined(__alpha__)
689 
690 #define MULADDC_INIT \
691  asm( \
692  "ldq $1, %3 \n\t" \
693  "ldq $2, %4 \n\t" \
694  "ldq $3, %5 \n\t" \
695  "ldq $4, %6 \n\t"
696 
697 #define MULADDC_CORE \
698  "ldq $6, 0($1) \n\t" \
699  "addq $1, 8, $1 \n\t" \
700  "mulq $6, $4, $7 \n\t" \
701  "umulh $6, $4, $6 \n\t" \
702  "addq $7, $3, $7 \n\t" \
703  "cmpult $7, $3, $3 \n\t" \
704  "ldq $5, 0($2) \n\t" \
705  "addq $7, $5, $7 \n\t" \
706  "cmpult $7, $5, $5 \n\t" \
707  "stq $7, 0($2) \n\t" \
708  "addq $2, 8, $2 \n\t" \
709  "addq $6, $3, $3 \n\t" \
710  "addq $5, $3, $3 \n\t"
711 
712 #define MULADDC_STOP \
713  "stq $3, %0 \n\t" \
714  "stq $2, %1 \n\t" \
715  "stq $1, %2 \n\t" \
716  : "=m" (c), "=m" (d), "=m" (s) \
717  : "m" (s), "m" (d), "m" (c), "m" (b) \
718  : "$1", "$2", "$3", "$4", "$5", "$6", "$7" \
719  );
720 #endif /* Alpha */
721 
722 #if defined(__mips__) && !defined(__mips64)
723 
724 #define MULADDC_INIT \
725  asm( \
726  "lw $10, %3 \n\t" \
727  "lw $11, %4 \n\t" \
728  "lw $12, %5 \n\t" \
729  "lw $13, %6 \n\t"
730 
731 #define MULADDC_CORE \
732  "lw $14, 0($10) \n\t" \
733  "multu $13, $14 \n\t" \
734  "addi $10, $10, 4 \n\t" \
735  "mflo $14 \n\t" \
736  "mfhi $9 \n\t" \
737  "addu $14, $12, $14 \n\t" \
738  "lw $15, 0($11) \n\t" \
739  "sltu $12, $14, $12 \n\t" \
740  "addu $15, $14, $15 \n\t" \
741  "sltu $14, $15, $14 \n\t" \
742  "addu $12, $12, $9 \n\t" \
743  "sw $15, 0($11) \n\t" \
744  "addu $12, $12, $14 \n\t" \
745  "addi $11, $11, 4 \n\t"
746 
747 #define MULADDC_STOP \
748  "sw $12, %0 \n\t" \
749  "sw $11, %1 \n\t" \
750  "sw $10, %2 \n\t" \
751  : "=m" (c), "=m" (d), "=m" (s) \
752  : "m" (s), "m" (d), "m" (c), "m" (b) \
753  : "$9", "$10", "$11", "$12", "$13", "$14", "$15" \
754  );
755 
756 #endif /* MIPS */
757 #endif /* GNUC */
758 
759 #if (defined(_MSC_VER) && defined(_M_IX86)) || defined(__WATCOMC__)
760 
761 #define MULADDC_INIT \
762  __asm mov esi, s \
763  __asm mov edi, d \
764  __asm mov ecx, c \
765  __asm mov ebx, b
766 
767 #define MULADDC_CORE \
768  __asm lodsd \
769  __asm mul ebx \
770  __asm add eax, ecx \
771  __asm adc edx, 0 \
772  __asm add eax, [edi] \
773  __asm adc edx, 0 \
774  __asm mov ecx, edx \
775  __asm stosd
776 
777 #if defined(MBEDTLS_HAVE_SSE2)
778 
779 #define EMIT __asm _emit
780 
781 #define MULADDC_HUIT \
782  EMIT 0x0F EMIT 0x6E EMIT 0xC9 \
783  EMIT 0x0F EMIT 0x6E EMIT 0xC3 \
784  EMIT 0x0F EMIT 0x6E EMIT 0x1F \
785  EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
786  EMIT 0x0F EMIT 0x6E EMIT 0x16 \
787  EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
788  EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x04 \
789  EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
790  EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x08 \
791  EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
792  EMIT 0x0F EMIT 0x6E EMIT 0x7E EMIT 0x0C \
793  EMIT 0x0F EMIT 0xF4 EMIT 0xF8 \
794  EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
795  EMIT 0x0F EMIT 0x6E EMIT 0x5F EMIT 0x04 \
796  EMIT 0x0F EMIT 0xD4 EMIT 0xDC \
797  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x08 \
798  EMIT 0x0F EMIT 0xD4 EMIT 0xEE \
799  EMIT 0x0F EMIT 0x6E EMIT 0x67 EMIT 0x0C \
800  EMIT 0x0F EMIT 0xD4 EMIT 0xFC \
801  EMIT 0x0F EMIT 0x7E EMIT 0x0F \
802  EMIT 0x0F EMIT 0x6E EMIT 0x56 EMIT 0x10 \
803  EMIT 0x0F EMIT 0xF4 EMIT 0xD0 \
804  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
805  EMIT 0x0F EMIT 0x6E EMIT 0x66 EMIT 0x14 \
806  EMIT 0x0F EMIT 0xF4 EMIT 0xE0 \
807  EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
808  EMIT 0x0F EMIT 0x6E EMIT 0x76 EMIT 0x18 \
809  EMIT 0x0F EMIT 0xF4 EMIT 0xF0 \
810  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x04 \
811  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
812  EMIT 0x0F EMIT 0x6E EMIT 0x5E EMIT 0x1C \
813  EMIT 0x0F EMIT 0xF4 EMIT 0xD8 \
814  EMIT 0x0F EMIT 0xD4 EMIT 0xCD \
815  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x10 \
816  EMIT 0x0F EMIT 0xD4 EMIT 0xD5 \
817  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x08 \
818  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
819  EMIT 0x0F EMIT 0xD4 EMIT 0xCF \
820  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x14 \
821  EMIT 0x0F EMIT 0xD4 EMIT 0xE5 \
822  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x0C \
823  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
824  EMIT 0x0F EMIT 0xD4 EMIT 0xCA \
825  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x18 \
826  EMIT 0x0F EMIT 0xD4 EMIT 0xF5 \
827  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x10 \
828  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
829  EMIT 0x0F EMIT 0xD4 EMIT 0xCC \
830  EMIT 0x0F EMIT 0x6E EMIT 0x6F EMIT 0x1C \
831  EMIT 0x0F EMIT 0xD4 EMIT 0xDD \
832  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x14 \
833  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
834  EMIT 0x0F EMIT 0xD4 EMIT 0xCE \
835  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x18 \
836  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
837  EMIT 0x0F EMIT 0xD4 EMIT 0xCB \
838  EMIT 0x0F EMIT 0x7E EMIT 0x4F EMIT 0x1C \
839  EMIT 0x83 EMIT 0xC7 EMIT 0x20 \
840  EMIT 0x83 EMIT 0xC6 EMIT 0x20 \
841  EMIT 0x0F EMIT 0x73 EMIT 0xD1 EMIT 0x20 \
842  EMIT 0x0F EMIT 0x7E EMIT 0xC9
843 
844 #define MULADDC_STOP \
845  EMIT 0x0F EMIT 0x77 \
846  __asm mov c, ecx \
847  __asm mov d, edi \
848  __asm mov s, esi \
849 
850 #else
851 
852 #define MULADDC_STOP \
853  __asm mov c, ecx \
854  __asm mov d, edi \
855  __asm mov s, esi \
856 
857 #endif /* SSE2 */
858 #endif /* MSVC */
859 
860 #endif /* MBEDTLS_HAVE_ASM */
861 
862 #if !defined(MULADDC_CORE)
863 #if defined(MBEDTLS_HAVE_UDBL)
864 
865 #define MULADDC_INIT \
866 { \
867  mbedtls_t_udbl r; \
868  mbedtls_mpi_uint r0, r1;
869 
870 #define MULADDC_CORE \
871  r = *(s++) * (mbedtls_t_udbl) b; \
872  r0 = (mbedtls_mpi_uint) r; \
873  r1 = (mbedtls_mpi_uint)( r >> biL ); \
874  r0 += c; r1 += (r0 < c); \
875  r0 += *d; r1 += (r0 < *d); \
876  c = r1; *(d++) = r0;
877 
878 #define MULADDC_STOP \
879 }
880 
881 #else
882 #define MULADDC_INIT \
883 { \
884  mbedtls_mpi_uint s0, s1, b0, b1; \
885  mbedtls_mpi_uint r0, r1, rx, ry; \
886  b0 = ( b << biH ) >> biH; \
887  b1 = ( b >> biH );
888 
889 #define MULADDC_CORE \
890  s0 = ( *s << biH ) >> biH; \
891  s1 = ( *s >> biH ); s++; \
892  rx = s0 * b1; r0 = s0 * b0; \
893  ry = s1 * b0; r1 = s1 * b1; \
894  r1 += ( rx >> biH ); \
895  r1 += ( ry >> biH ); \
896  rx <<= biH; ry <<= biH; \
897  r0 += rx; r1 += (r0 < rx); \
898  r0 += ry; r1 += (r0 < ry); \
899  r0 += c; r1 += (r0 < c); \
900  r0 += *d; r1 += (r0 < *d); \
901  c = r1; *(d++) = r0;
902 
903 #define MULADDC_STOP \
904 }
905 
906 #endif /* C (generic) */
907 #endif /* C (longlong) */
908 
909 #endif /* bn_mul.h */
Multi-precision integer library.