ppc-mont.pl 48 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611161216131614161516161617161816191620162116221623162416251626162716281629163016311632163316341635163616371638163916401641164216431644164516461647164816491650165116521653165416551656165716581659166016611662166316641665166616671668166916701671167216731674167516761677167816791680168116821683168416851686168716881689169016911692169316941695169616971698169917001701170217031704170517061707170817091710171117121713171417151716171717181719172017211722172317241725172617271728172917301731173217331734173517361737173817391740174117421743174417451746174717481749175017511752175317541755175617571758175917601761176217631764176517661767176817691770177117721773177417751776177717781779178017811782178317841785178617871788178917901791179217931794179517961797179817991800180118021803180418051806180718081809181018111812181318141815181618171818181918201821182218231824182518261827182818291830183118321833183418351836183718381839184018411842184318441845184618471848184918501851185218531854185518561857185818591860186118621863186418651866186718681869187018711872187318741875187618771878187918801881188218831884188518861887188818891890189118921893189418951896189718981899190019011902190319041905190619071908190919101911191219131914191519161917191819191920192119221923192419251926192719281929193019311932193319341935193619371938193919401941194219431944194519461947194819491950195119521953195419551956195719581959196019611962196319641965196619671968196919701971197219731974197519761977197819791980198119821983198419851986198719881989
  1. #! /usr/bin/env perl
  2. # Copyright 2006-2016 The OpenSSL Project Authors. All Rights Reserved.
  3. #
  4. # Licensed under the OpenSSL license (the "License"). You may not use
  5. # this file except in compliance with the License. You can obtain a copy
  6. # in the file LICENSE in the source distribution or at
  7. # https://www.openssl.org/source/license.html
  8. # ====================================================================
  9. # Written by Andy Polyakov <appro@openssl.org> for the OpenSSL
  10. # project. The module is, however, dual licensed under OpenSSL and
  11. # CRYPTOGAMS licenses depending on where you obtain it. For further
  12. # details see http://www.openssl.org/~appro/cryptogams/.
  13. # ====================================================================
  14. # April 2006
  15. # "Teaser" Montgomery multiplication module for PowerPC. It's possible
  16. # to gain a bit more by modulo-scheduling outer loop, then dedicated
  17. # squaring procedure should give further 20% and code can be adapted
  18. # for 32-bit application running on 64-bit CPU. As for the latter.
  19. # It won't be able to achieve "native" 64-bit performance, because in
  20. # 32-bit application context every addc instruction will have to be
  21. # expanded as addc, twice right shift by 32 and finally adde, etc.
  22. # So far RSA *sign* performance improvement over pre-bn_mul_mont asm
  23. # for 64-bit application running on PPC970/G5 is:
  24. #
  25. # 512-bit +65%
  26. # 1024-bit +35%
  27. # 2048-bit +18%
  28. # 4096-bit +4%
  29. # September 2016
  30. #
  31. # Add multiplication procedure operating on lengths divisible by 4
  32. # and squaring procedure operating on lengths divisible by 8. Length
  33. # is expressed in number of limbs. RSA private key operations are
  34. # ~35-50% faster (more for longer keys) on contemporary high-end POWER
  35. # processors in 64-bit builds, [mysteriously enough] more in 32-bit
  36. # builds. On low-end 32-bit processors performance improvement turned
  37. # to be marginal...
  38. $flavour = shift;
  39. if ($flavour =~ /32/) {
  40. $BITS= 32;
  41. $BNSZ= $BITS/8;
  42. $SIZE_T=4;
  43. $RZONE= 224;
  44. $LD= "lwz"; # load
  45. $LDU= "lwzu"; # load and update
  46. $LDX= "lwzx"; # load indexed
  47. $ST= "stw"; # store
  48. $STU= "stwu"; # store and update
  49. $STX= "stwx"; # store indexed
  50. $STUX= "stwux"; # store indexed and update
  51. $UMULL= "mullw"; # unsigned multiply low
  52. $UMULH= "mulhwu"; # unsigned multiply high
  53. $UCMP= "cmplw"; # unsigned compare
  54. $SHRI= "srwi"; # unsigned shift right by immediate
  55. $SHLI= "slwi"; # unsigned shift left by immediate
  56. $PUSH= $ST;
  57. $POP= $LD;
  58. } elsif ($flavour =~ /64/) {
  59. $BITS= 64;
  60. $BNSZ= $BITS/8;
  61. $SIZE_T=8;
  62. $RZONE= 288;
  63. # same as above, but 64-bit mnemonics...
  64. $LD= "ld"; # load
  65. $LDU= "ldu"; # load and update
  66. $LDX= "ldx"; # load indexed
  67. $ST= "std"; # store
  68. $STU= "stdu"; # store and update
  69. $STX= "stdx"; # store indexed
  70. $STUX= "stdux"; # store indexed and update
  71. $UMULL= "mulld"; # unsigned multiply low
  72. $UMULH= "mulhdu"; # unsigned multiply high
  73. $UCMP= "cmpld"; # unsigned compare
  74. $SHRI= "srdi"; # unsigned shift right by immediate
  75. $SHLI= "sldi"; # unsigned shift left by immediate
  76. $PUSH= $ST;
  77. $POP= $LD;
  78. } else { die "nonsense $flavour"; }
  79. $FRAME=8*$SIZE_T+$RZONE;
  80. $LOCALS=8*$SIZE_T;
  81. $0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1;
  82. ( $xlate="${dir}ppc-xlate.pl" and -f $xlate ) or
  83. ( $xlate="${dir}../../perlasm/ppc-xlate.pl" and -f $xlate) or
  84. die "can't locate ppc-xlate.pl";
  85. open STDOUT,"| $^X $xlate $flavour ".shift || die "can't call $xlate: $!";
  86. $sp="r1";
  87. $toc="r2";
  88. $rp="r3";
  89. $ap="r4";
  90. $bp="r5";
  91. $np="r6";
  92. $n0="r7";
  93. $num="r8";
  94. {
  95. my $ovf=$rp;
  96. my $rp="r9"; # $rp is reassigned
  97. my $aj="r10";
  98. my $nj="r11";
  99. my $tj="r12";
  100. # non-volatile registers
  101. my $i="r20";
  102. my $j="r21";
  103. my $tp="r22";
  104. my $m0="r23";
  105. my $m1="r24";
  106. my $lo0="r25";
  107. my $hi0="r26";
  108. my $lo1="r27";
  109. my $hi1="r28";
  110. my $alo="r29";
  111. my $ahi="r30";
  112. my $nlo="r31";
  113. #
  114. my $nhi="r0";
  115. $code=<<___;
  116. .machine "any"
  117. .text
  118. .globl .bn_mul_mont_int
  119. .align 5
  120. .bn_mul_mont_int:
  121. mr $rp,r3 ; $rp is reassigned
  122. li r3,0
  123. ___
  124. $code.=<<___ if ($BNSZ==4);
  125. cmpwi $num,32 ; longer key performance is not better
  126. bgelr
  127. ___
  128. $code.=<<___;
  129. slwi $num,$num,`log($BNSZ)/log(2)`
  130. li $tj,-4096
  131. addi $ovf,$num,$FRAME
  132. subf $ovf,$ovf,$sp ; $sp-$ovf
  133. and $ovf,$ovf,$tj ; minimize TLB usage
  134. subf $ovf,$sp,$ovf ; $ovf-$sp
  135. mr $tj,$sp
  136. srwi $num,$num,`log($BNSZ)/log(2)`
  137. $STUX $sp,$sp,$ovf
  138. $PUSH r20,`-12*$SIZE_T`($tj)
  139. $PUSH r21,`-11*$SIZE_T`($tj)
  140. $PUSH r22,`-10*$SIZE_T`($tj)
  141. $PUSH r23,`-9*$SIZE_T`($tj)
  142. $PUSH r24,`-8*$SIZE_T`($tj)
  143. $PUSH r25,`-7*$SIZE_T`($tj)
  144. $PUSH r26,`-6*$SIZE_T`($tj)
  145. $PUSH r27,`-5*$SIZE_T`($tj)
  146. $PUSH r28,`-4*$SIZE_T`($tj)
  147. $PUSH r29,`-3*$SIZE_T`($tj)
  148. $PUSH r30,`-2*$SIZE_T`($tj)
  149. $PUSH r31,`-1*$SIZE_T`($tj)
  150. $LD $n0,0($n0) ; pull n0[0] value
  151. addi $num,$num,-2 ; adjust $num for counter register
  152. $LD $m0,0($bp) ; m0=bp[0]
  153. $LD $aj,0($ap) ; ap[0]
  154. addi $tp,$sp,$LOCALS
  155. $UMULL $lo0,$aj,$m0 ; ap[0]*bp[0]
  156. $UMULH $hi0,$aj,$m0
  157. $LD $aj,$BNSZ($ap) ; ap[1]
  158. $LD $nj,0($np) ; np[0]
  159. $UMULL $m1,$lo0,$n0 ; "tp[0]"*n0
  160. $UMULL $alo,$aj,$m0 ; ap[1]*bp[0]
  161. $UMULH $ahi,$aj,$m0
  162. $UMULL $lo1,$nj,$m1 ; np[0]*m1
  163. $UMULH $hi1,$nj,$m1
  164. $LD $nj,$BNSZ($np) ; np[1]
  165. addc $lo1,$lo1,$lo0
  166. addze $hi1,$hi1
  167. $UMULL $nlo,$nj,$m1 ; np[1]*m1
  168. $UMULH $nhi,$nj,$m1
  169. mtctr $num
  170. li $j,`2*$BNSZ`
  171. .align 4
  172. L1st:
  173. $LDX $aj,$ap,$j ; ap[j]
  174. addc $lo0,$alo,$hi0
  175. $LDX $nj,$np,$j ; np[j]
  176. addze $hi0,$ahi
  177. $UMULL $alo,$aj,$m0 ; ap[j]*bp[0]
  178. addc $lo1,$nlo,$hi1
  179. $UMULH $ahi,$aj,$m0
  180. addze $hi1,$nhi
  181. $UMULL $nlo,$nj,$m1 ; np[j]*m1
  182. addc $lo1,$lo1,$lo0 ; np[j]*m1+ap[j]*bp[0]
  183. $UMULH $nhi,$nj,$m1
  184. addze $hi1,$hi1
  185. $ST $lo1,0($tp) ; tp[j-1]
  186. addi $j,$j,$BNSZ ; j++
  187. addi $tp,$tp,$BNSZ ; tp++
  188. bdnz L1st
  189. ;L1st
  190. addc $lo0,$alo,$hi0
  191. addze $hi0,$ahi
  192. addc $lo1,$nlo,$hi1
  193. addze $hi1,$nhi
  194. addc $lo1,$lo1,$lo0 ; np[j]*m1+ap[j]*bp[0]
  195. addze $hi1,$hi1
  196. $ST $lo1,0($tp) ; tp[j-1]
  197. li $ovf,0
  198. addc $hi1,$hi1,$hi0
  199. addze $ovf,$ovf ; upmost overflow bit
  200. $ST $hi1,$BNSZ($tp)
  201. li $i,$BNSZ
  202. .align 4
  203. Louter:
  204. $LDX $m0,$bp,$i ; m0=bp[i]
  205. $LD $aj,0($ap) ; ap[0]
  206. addi $tp,$sp,$LOCALS
  207. $LD $tj,$LOCALS($sp); tp[0]
  208. $UMULL $lo0,$aj,$m0 ; ap[0]*bp[i]
  209. $UMULH $hi0,$aj,$m0
  210. $LD $aj,$BNSZ($ap) ; ap[1]
  211. $LD $nj,0($np) ; np[0]
  212. addc $lo0,$lo0,$tj ; ap[0]*bp[i]+tp[0]
  213. $UMULL $alo,$aj,$m0 ; ap[j]*bp[i]
  214. addze $hi0,$hi0
  215. $UMULL $m1,$lo0,$n0 ; tp[0]*n0
  216. $UMULH $ahi,$aj,$m0
  217. $UMULL $lo1,$nj,$m1 ; np[0]*m1
  218. $UMULH $hi1,$nj,$m1
  219. $LD $nj,$BNSZ($np) ; np[1]
  220. addc $lo1,$lo1,$lo0
  221. $UMULL $nlo,$nj,$m1 ; np[1]*m1
  222. addze $hi1,$hi1
  223. $UMULH $nhi,$nj,$m1
  224. mtctr $num
  225. li $j,`2*$BNSZ`
  226. .align 4
  227. Linner:
  228. $LDX $aj,$ap,$j ; ap[j]
  229. addc $lo0,$alo,$hi0
  230. $LD $tj,$BNSZ($tp) ; tp[j]
  231. addze $hi0,$ahi
  232. $LDX $nj,$np,$j ; np[j]
  233. addc $lo1,$nlo,$hi1
  234. $UMULL $alo,$aj,$m0 ; ap[j]*bp[i]
  235. addze $hi1,$nhi
  236. $UMULH $ahi,$aj,$m0
  237. addc $lo0,$lo0,$tj ; ap[j]*bp[i]+tp[j]
  238. $UMULL $nlo,$nj,$m1 ; np[j]*m1
  239. addze $hi0,$hi0
  240. $UMULH $nhi,$nj,$m1
  241. addc $lo1,$lo1,$lo0 ; np[j]*m1+ap[j]*bp[i]+tp[j]
  242. addi $j,$j,$BNSZ ; j++
  243. addze $hi1,$hi1
  244. $ST $lo1,0($tp) ; tp[j-1]
  245. addi $tp,$tp,$BNSZ ; tp++
  246. bdnz Linner
  247. ;Linner
  248. $LD $tj,$BNSZ($tp) ; tp[j]
  249. addc $lo0,$alo,$hi0
  250. addze $hi0,$ahi
  251. addc $lo0,$lo0,$tj ; ap[j]*bp[i]+tp[j]
  252. addze $hi0,$hi0
  253. addc $lo1,$nlo,$hi1
  254. addze $hi1,$nhi
  255. addc $lo1,$lo1,$lo0 ; np[j]*m1+ap[j]*bp[i]+tp[j]
  256. addze $hi1,$hi1
  257. $ST $lo1,0($tp) ; tp[j-1]
  258. addic $ovf,$ovf,-1 ; move upmost overflow to XER[CA]
  259. li $ovf,0
  260. adde $hi1,$hi1,$hi0
  261. addze $ovf,$ovf
  262. $ST $hi1,$BNSZ($tp)
  263. ;
  264. slwi $tj,$num,`log($BNSZ)/log(2)`
  265. $UCMP $i,$tj
  266. addi $i,$i,$BNSZ
  267. ble Louter
  268. addi $num,$num,2 ; restore $num
  269. subfc $j,$j,$j ; j=0 and "clear" XER[CA]
  270. addi $tp,$sp,$LOCALS
  271. mtctr $num
  272. .align 4
  273. Lsub: $LDX $tj,$tp,$j
  274. $LDX $nj,$np,$j
  275. subfe $aj,$nj,$tj ; tp[j]-np[j]
  276. $STX $aj,$rp,$j
  277. addi $j,$j,$BNSZ
  278. bdnz Lsub
  279. li $j,0
  280. mtctr $num
  281. subfe $ovf,$j,$ovf ; handle upmost overflow bit
  282. and $ap,$tp,$ovf
  283. andc $np,$rp,$ovf
  284. or $ap,$ap,$np ; ap=borrow?tp:rp
  285. .align 4
  286. Lcopy: ; copy or in-place refresh
  287. $LDX $tj,$ap,$j
  288. $STX $tj,$rp,$j
  289. $STX $j,$tp,$j ; zap at once
  290. addi $j,$j,$BNSZ
  291. bdnz Lcopy
  292. $POP $tj,0($sp)
  293. li r3,1
  294. $POP r20,`-12*$SIZE_T`($tj)
  295. $POP r21,`-11*$SIZE_T`($tj)
  296. $POP r22,`-10*$SIZE_T`($tj)
  297. $POP r23,`-9*$SIZE_T`($tj)
  298. $POP r24,`-8*$SIZE_T`($tj)
  299. $POP r25,`-7*$SIZE_T`($tj)
  300. $POP r26,`-6*$SIZE_T`($tj)
  301. $POP r27,`-5*$SIZE_T`($tj)
  302. $POP r28,`-4*$SIZE_T`($tj)
  303. $POP r29,`-3*$SIZE_T`($tj)
  304. $POP r30,`-2*$SIZE_T`($tj)
  305. $POP r31,`-1*$SIZE_T`($tj)
  306. mr $sp,$tj
  307. blr
  308. .long 0
  309. .byte 0,12,4,0,0x80,12,6,0
  310. .long 0
  311. .size .bn_mul_mont_int,.-.bn_mul_mont_int
  312. ___
  313. }
  314. if (1) {
  315. my ($a0,$a1,$a2,$a3,
  316. $t0,$t1,$t2,$t3,
  317. $m0,$m1,$m2,$m3,
  318. $acc0,$acc1,$acc2,$acc3,$acc4,
  319. $bi,$mi,$tp,$ap_end,$cnt) = map("r$_",(9..12,14..31));
  320. my ($carry,$zero) = ($rp,"r0");
  321. # sp----------->+-------------------------------+
  322. # | saved sp |
  323. # +-------------------------------+
  324. # . .
  325. # +8*size_t +-------------------------------+
  326. # | 4 "n0*t0" |
  327. # . .
  328. # . .
  329. # +12*size_t +-------------------------------+
  330. # | size_t tmp[num] |
  331. # . .
  332. # . .
  333. # . .
  334. # +-------------------------------+
  335. # | topmost carry |
  336. # . .
  337. # -18*size_t +-------------------------------+
  338. # | 18 saved gpr, r14-r31 |
  339. # . .
  340. # . .
  341. # +-------------------------------+
  342. $code.=<<___;
  343. .globl .bn_mul4x_mont_int
  344. .align 5
  345. .bn_mul4x_mont_int:
  346. andi. r0,$num,7
  347. bne .Lmul4x_do
  348. $UCMP $ap,$bp
  349. bne .Lmul4x_do
  350. b .Lsqr8x_do
  351. .Lmul4x_do:
  352. slwi $num,$num,`log($SIZE_T)/log(2)`
  353. mr $a0,$sp
  354. li $a1,-32*$SIZE_T
  355. sub $a1,$a1,$num
  356. $STUX $sp,$sp,$a1 # alloca
  357. $PUSH r14,-$SIZE_T*18($a0)
  358. $PUSH r15,-$SIZE_T*17($a0)
  359. $PUSH r16,-$SIZE_T*16($a0)
  360. $PUSH r17,-$SIZE_T*15($a0)
  361. $PUSH r18,-$SIZE_T*14($a0)
  362. $PUSH r19,-$SIZE_T*13($a0)
  363. $PUSH r20,-$SIZE_T*12($a0)
  364. $PUSH r21,-$SIZE_T*11($a0)
  365. $PUSH r22,-$SIZE_T*10($a0)
  366. $PUSH r23,-$SIZE_T*9($a0)
  367. $PUSH r24,-$SIZE_T*8($a0)
  368. $PUSH r25,-$SIZE_T*7($a0)
  369. $PUSH r26,-$SIZE_T*6($a0)
  370. $PUSH r27,-$SIZE_T*5($a0)
  371. $PUSH r28,-$SIZE_T*4($a0)
  372. $PUSH r29,-$SIZE_T*3($a0)
  373. $PUSH r30,-$SIZE_T*2($a0)
  374. $PUSH r31,-$SIZE_T*1($a0)
  375. subi $ap,$ap,$SIZE_T # bias by -1
  376. subi $np,$np,$SIZE_T # bias by -1
  377. subi $rp,$rp,$SIZE_T # bias by -1
  378. $LD $n0,0($n0) # *n0
  379. add $t0,$bp,$num
  380. add $ap_end,$ap,$num
  381. subi $t0,$t0,$SIZE_T*4 # &b[num-4]
  382. $LD $bi,$SIZE_T*0($bp) # b[0]
  383. li $acc0,0
  384. $LD $a0,$SIZE_T*1($ap) # a[0..3]
  385. li $acc1,0
  386. $LD $a1,$SIZE_T*2($ap)
  387. li $acc2,0
  388. $LD $a2,$SIZE_T*3($ap)
  389. li $acc3,0
  390. $LDU $a3,$SIZE_T*4($ap)
  391. $LD $m0,$SIZE_T*1($np) # n[0..3]
  392. $LD $m1,$SIZE_T*2($np)
  393. $LD $m2,$SIZE_T*3($np)
  394. $LDU $m3,$SIZE_T*4($np)
  395. $PUSH $rp,$SIZE_T*6($sp) # offload rp and &b[num-4]
  396. $PUSH $t0,$SIZE_T*7($sp)
  397. li $carry,0
  398. addic $tp,$sp,$SIZE_T*7 # &t[-1], clear carry bit
  399. li $cnt,0
  400. li $zero,0
  401. b .Loop_mul4x_1st_reduction
  402. .align 5
  403. .Loop_mul4x_1st_reduction:
  404. $UMULL $t0,$a0,$bi # lo(a[0..3]*b[0])
  405. addze $carry,$carry # modulo-scheduled
  406. $UMULL $t1,$a1,$bi
  407. addi $cnt,$cnt,$SIZE_T
  408. $UMULL $t2,$a2,$bi
  409. andi. $cnt,$cnt,$SIZE_T*4-1
  410. $UMULL $t3,$a3,$bi
  411. addc $acc0,$acc0,$t0
  412. $UMULH $t0,$a0,$bi # hi(a[0..3]*b[0])
  413. adde $acc1,$acc1,$t1
  414. $UMULH $t1,$a1,$bi
  415. adde $acc2,$acc2,$t2
  416. $UMULL $mi,$acc0,$n0 # t[0]*n0
  417. adde $acc3,$acc3,$t3
  418. $UMULH $t2,$a2,$bi
  419. addze $acc4,$zero
  420. $UMULH $t3,$a3,$bi
  421. $LDX $bi,$bp,$cnt # next b[i] (or b[0])
  422. addc $acc1,$acc1,$t0
  423. # (*) mul $t0,$m0,$mi # lo(n[0..3]*t[0]*n0)
  424. $STU $mi,$SIZE_T($tp) # put aside t[0]*n0 for tail processing
  425. adde $acc2,$acc2,$t1
  426. $UMULL $t1,$m1,$mi
  427. adde $acc3,$acc3,$t2
  428. $UMULL $t2,$m2,$mi
  429. adde $acc4,$acc4,$t3 # can't overflow
  430. $UMULL $t3,$m3,$mi
  431. # (*) addc $acc0,$acc0,$t0
  432. # (*) As for removal of first multiplication and addition
  433. # instructions. The outcome of first addition is
  434. # guaranteed to be zero, which leaves two computationally
  435. # significant outcomes: it either carries or not. Then
  436. # question is when does it carry? Is there alternative
  437. # way to deduce it? If you follow operations, you can
  438. # observe that condition for carry is quite simple:
  439. # $acc0 being non-zero. So that carry can be calculated
  440. # by adding -1 to $acc0. That's what next instruction does.
  441. addic $acc0,$acc0,-1 # (*), discarded
  442. $UMULH $t0,$m0,$mi # hi(n[0..3]*t[0]*n0)
  443. adde $acc0,$acc1,$t1
  444. $UMULH $t1,$m1,$mi
  445. adde $acc1,$acc2,$t2
  446. $UMULH $t2,$m2,$mi
  447. adde $acc2,$acc3,$t3
  448. $UMULH $t3,$m3,$mi
  449. adde $acc3,$acc4,$carry
  450. addze $carry,$zero
  451. addc $acc0,$acc0,$t0
  452. adde $acc1,$acc1,$t1
  453. adde $acc2,$acc2,$t2
  454. adde $acc3,$acc3,$t3
  455. #addze $carry,$carry
  456. bne .Loop_mul4x_1st_reduction
  457. $UCMP $ap_end,$ap
  458. beq .Lmul4x4_post_condition
  459. $LD $a0,$SIZE_T*1($ap) # a[4..7]
  460. $LD $a1,$SIZE_T*2($ap)
  461. $LD $a2,$SIZE_T*3($ap)
  462. $LDU $a3,$SIZE_T*4($ap)
  463. $LD $mi,$SIZE_T*8($sp) # a[0]*n0
  464. $LD $m0,$SIZE_T*1($np) # n[4..7]
  465. $LD $m1,$SIZE_T*2($np)
  466. $LD $m2,$SIZE_T*3($np)
  467. $LDU $m3,$SIZE_T*4($np)
  468. b .Loop_mul4x_1st_tail
  469. .align 5
  470. .Loop_mul4x_1st_tail:
  471. $UMULL $t0,$a0,$bi # lo(a[4..7]*b[i])
  472. addze $carry,$carry # modulo-scheduled
  473. $UMULL $t1,$a1,$bi
  474. addi $cnt,$cnt,$SIZE_T
  475. $UMULL $t2,$a2,$bi
  476. andi. $cnt,$cnt,$SIZE_T*4-1
  477. $UMULL $t3,$a3,$bi
  478. addc $acc0,$acc0,$t0
  479. $UMULH $t0,$a0,$bi # hi(a[4..7]*b[i])
  480. adde $acc1,$acc1,$t1
  481. $UMULH $t1,$a1,$bi
  482. adde $acc2,$acc2,$t2
  483. $UMULH $t2,$a2,$bi
  484. adde $acc3,$acc3,$t3
  485. $UMULH $t3,$a3,$bi
  486. addze $acc4,$zero
  487. $LDX $bi,$bp,$cnt # next b[i] (or b[0])
  488. addc $acc1,$acc1,$t0
  489. $UMULL $t0,$m0,$mi # lo(n[4..7]*a[0]*n0)
  490. adde $acc2,$acc2,$t1
  491. $UMULL $t1,$m1,$mi
  492. adde $acc3,$acc3,$t2
  493. $UMULL $t2,$m2,$mi
  494. adde $acc4,$acc4,$t3 # can't overflow
  495. $UMULL $t3,$m3,$mi
  496. addc $acc0,$acc0,$t0
  497. $UMULH $t0,$m0,$mi # hi(n[4..7]*a[0]*n0)
  498. adde $acc1,$acc1,$t1
  499. $UMULH $t1,$m1,$mi
  500. adde $acc2,$acc2,$t2
  501. $UMULH $t2,$m2,$mi
  502. adde $acc3,$acc3,$t3
  503. adde $acc4,$acc4,$carry
  504. $UMULH $t3,$m3,$mi
  505. addze $carry,$zero
  506. addi $mi,$sp,$SIZE_T*8
  507. $LDX $mi,$mi,$cnt # next t[0]*n0
  508. $STU $acc0,$SIZE_T($tp) # word of result
  509. addc $acc0,$acc1,$t0
  510. adde $acc1,$acc2,$t1
  511. adde $acc2,$acc3,$t2
  512. adde $acc3,$acc4,$t3
  513. #addze $carry,$carry
  514. bne .Loop_mul4x_1st_tail
  515. sub $t1,$ap_end,$num # rewinded $ap
  516. $UCMP $ap_end,$ap # done yet?
  517. beq .Lmul4x_proceed
  518. $LD $a0,$SIZE_T*1($ap)
  519. $LD $a1,$SIZE_T*2($ap)
  520. $LD $a2,$SIZE_T*3($ap)
  521. $LDU $a3,$SIZE_T*4($ap)
  522. $LD $m0,$SIZE_T*1($np)
  523. $LD $m1,$SIZE_T*2($np)
  524. $LD $m2,$SIZE_T*3($np)
  525. $LDU $m3,$SIZE_T*4($np)
  526. b .Loop_mul4x_1st_tail
  527. .align 5
  528. .Lmul4x_proceed:
  529. $LDU $bi,$SIZE_T*4($bp) # *++b
  530. addze $carry,$carry # topmost carry
  531. $LD $a0,$SIZE_T*1($t1)
  532. $LD $a1,$SIZE_T*2($t1)
  533. $LD $a2,$SIZE_T*3($t1)
  534. $LD $a3,$SIZE_T*4($t1)
  535. addi $ap,$t1,$SIZE_T*4
  536. sub $np,$np,$num # rewind np
  537. $ST $acc0,$SIZE_T*1($tp) # result
  538. $ST $acc1,$SIZE_T*2($tp)
  539. $ST $acc2,$SIZE_T*3($tp)
  540. $ST $acc3,$SIZE_T*4($tp)
  541. $ST $carry,$SIZE_T*5($tp) # save topmost carry
  542. $LD $acc0,$SIZE_T*12($sp) # t[0..3]
  543. $LD $acc1,$SIZE_T*13($sp)
  544. $LD $acc2,$SIZE_T*14($sp)
  545. $LD $acc3,$SIZE_T*15($sp)
  546. $LD $m0,$SIZE_T*1($np) # n[0..3]
  547. $LD $m1,$SIZE_T*2($np)
  548. $LD $m2,$SIZE_T*3($np)
  549. $LDU $m3,$SIZE_T*4($np)
  550. addic $tp,$sp,$SIZE_T*7 # &t[-1], clear carry bit
  551. li $carry,0
  552. b .Loop_mul4x_reduction
  553. .align 5
  554. .Loop_mul4x_reduction:
  555. $UMULL $t0,$a0,$bi # lo(a[0..3]*b[4])
  556. addze $carry,$carry # modulo-scheduled
  557. $UMULL $t1,$a1,$bi
  558. addi $cnt,$cnt,$SIZE_T
  559. $UMULL $t2,$a2,$bi
  560. andi. $cnt,$cnt,$SIZE_T*4-1
  561. $UMULL $t3,$a3,$bi
  562. addc $acc0,$acc0,$t0
  563. $UMULH $t0,$a0,$bi # hi(a[0..3]*b[4])
  564. adde $acc1,$acc1,$t1
  565. $UMULH $t1,$a1,$bi
  566. adde $acc2,$acc2,$t2
  567. $UMULL $mi,$acc0,$n0 # t[0]*n0
  568. adde $acc3,$acc3,$t3
  569. $UMULH $t2,$a2,$bi
  570. addze $acc4,$zero
  571. $UMULH $t3,$a3,$bi
  572. $LDX $bi,$bp,$cnt # next b[i]
  573. addc $acc1,$acc1,$t0
  574. # (*) mul $t0,$m0,$mi
  575. $STU $mi,$SIZE_T($tp) # put aside t[0]*n0 for tail processing
  576. adde $acc2,$acc2,$t1
  577. $UMULL $t1,$m1,$mi # lo(n[0..3]*t[0]*n0
  578. adde $acc3,$acc3,$t2
  579. $UMULL $t2,$m2,$mi
  580. adde $acc4,$acc4,$t3 # can't overflow
  581. $UMULL $t3,$m3,$mi
  582. # (*) addc $acc0,$acc0,$t0
  583. addic $acc0,$acc0,-1 # (*), discarded
  584. $UMULH $t0,$m0,$mi # hi(n[0..3]*t[0]*n0
  585. adde $acc0,$acc1,$t1
  586. $UMULH $t1,$m1,$mi
  587. adde $acc1,$acc2,$t2
  588. $UMULH $t2,$m2,$mi
  589. adde $acc2,$acc3,$t3
  590. $UMULH $t3,$m3,$mi
  591. adde $acc3,$acc4,$carry
  592. addze $carry,$zero
  593. addc $acc0,$acc0,$t0
  594. adde $acc1,$acc1,$t1
  595. adde $acc2,$acc2,$t2
  596. adde $acc3,$acc3,$t3
  597. #addze $carry,$carry
  598. bne .Loop_mul4x_reduction
  599. $LD $t0,$SIZE_T*5($tp) # t[4..7]
  600. addze $carry,$carry
  601. $LD $t1,$SIZE_T*6($tp)
  602. $LD $t2,$SIZE_T*7($tp)
  603. $LD $t3,$SIZE_T*8($tp)
  604. $LD $a0,$SIZE_T*1($ap) # a[4..7]
  605. $LD $a1,$SIZE_T*2($ap)
  606. $LD $a2,$SIZE_T*3($ap)
  607. $LDU $a3,$SIZE_T*4($ap)
  608. addc $acc0,$acc0,$t0
  609. adde $acc1,$acc1,$t1
  610. adde $acc2,$acc2,$t2
  611. adde $acc3,$acc3,$t3
  612. #addze $carry,$carry
  613. $LD $mi,$SIZE_T*8($sp) # t[0]*n0
  614. $LD $m0,$SIZE_T*1($np) # n[4..7]
  615. $LD $m1,$SIZE_T*2($np)
  616. $LD $m2,$SIZE_T*3($np)
  617. $LDU $m3,$SIZE_T*4($np)
  618. b .Loop_mul4x_tail
  619. .align 5
  620. .Loop_mul4x_tail:
  621. $UMULL $t0,$a0,$bi # lo(a[4..7]*b[4])
  622. addze $carry,$carry # modulo-scheduled
  623. $UMULL $t1,$a1,$bi
  624. addi $cnt,$cnt,$SIZE_T
  625. $UMULL $t2,$a2,$bi
  626. andi. $cnt,$cnt,$SIZE_T*4-1
  627. $UMULL $t3,$a3,$bi
  628. addc $acc0,$acc0,$t0
  629. $UMULH $t0,$a0,$bi # hi(a[4..7]*b[4])
  630. adde $acc1,$acc1,$t1
  631. $UMULH $t1,$a1,$bi
  632. adde $acc2,$acc2,$t2
  633. $UMULH $t2,$a2,$bi
  634. adde $acc3,$acc3,$t3
  635. $UMULH $t3,$a3,$bi
  636. addze $acc4,$zero
  637. $LDX $bi,$bp,$cnt # next b[i]
  638. addc $acc1,$acc1,$t0
  639. $UMULL $t0,$m0,$mi # lo(n[4..7]*t[0]*n0)
  640. adde $acc2,$acc2,$t1
  641. $UMULL $t1,$m1,$mi
  642. adde $acc3,$acc3,$t2
  643. $UMULL $t2,$m2,$mi
  644. adde $acc4,$acc4,$t3 # can't overflow
  645. $UMULL $t3,$m3,$mi
  646. addc $acc0,$acc0,$t0
  647. $UMULH $t0,$m0,$mi # hi(n[4..7]*t[0]*n0)
  648. adde $acc1,$acc1,$t1
  649. $UMULH $t1,$m1,$mi
  650. adde $acc2,$acc2,$t2
  651. $UMULH $t2,$m2,$mi
  652. adde $acc3,$acc3,$t3
  653. $UMULH $t3,$m3,$mi
  654. adde $acc4,$acc4,$carry
  655. addi $mi,$sp,$SIZE_T*8
  656. $LDX $mi,$mi,$cnt # next a[0]*n0
  657. addze $carry,$zero
  658. $STU $acc0,$SIZE_T($tp) # word of result
  659. addc $acc0,$acc1,$t0
  660. adde $acc1,$acc2,$t1
  661. adde $acc2,$acc3,$t2
  662. adde $acc3,$acc4,$t3
  663. #addze $carry,$carry
  664. bne .Loop_mul4x_tail
  665. $LD $t0,$SIZE_T*5($tp) # next t[i] or topmost carry
  666. sub $t1,$np,$num # rewinded np?
  667. addze $carry,$carry
  668. $UCMP $ap_end,$ap # done yet?
  669. beq .Loop_mul4x_break
  670. $LD $t1,$SIZE_T*6($tp)
  671. $LD $t2,$SIZE_T*7($tp)
  672. $LD $t3,$SIZE_T*8($tp)
  673. $LD $a0,$SIZE_T*1($ap)
  674. $LD $a1,$SIZE_T*2($ap)
  675. $LD $a2,$SIZE_T*3($ap)
  676. $LDU $a3,$SIZE_T*4($ap)
  677. addc $acc0,$acc0,$t0
  678. adde $acc1,$acc1,$t1
  679. adde $acc2,$acc2,$t2
  680. adde $acc3,$acc3,$t3
  681. #addze $carry,$carry
  682. $LD $m0,$SIZE_T*1($np) # n[4..7]
  683. $LD $m1,$SIZE_T*2($np)
  684. $LD $m2,$SIZE_T*3($np)
  685. $LDU $m3,$SIZE_T*4($np)
  686. b .Loop_mul4x_tail
  687. .align 5
  688. .Loop_mul4x_break:
  689. $POP $t2,$SIZE_T*6($sp) # pull rp and &b[num-4]
  690. $POP $t3,$SIZE_T*7($sp)
  691. addc $a0,$acc0,$t0 # accumulate topmost carry
  692. $LD $acc0,$SIZE_T*12($sp) # t[0..3]
  693. addze $a1,$acc1
  694. $LD $acc1,$SIZE_T*13($sp)
  695. addze $a2,$acc2
  696. $LD $acc2,$SIZE_T*14($sp)
  697. addze $a3,$acc3
  698. $LD $acc3,$SIZE_T*15($sp)
  699. addze $carry,$carry # topmost carry
  700. $ST $a0,$SIZE_T*1($tp) # result
  701. sub $ap,$ap_end,$num # rewind ap
  702. $ST $a1,$SIZE_T*2($tp)
  703. $ST $a2,$SIZE_T*3($tp)
  704. $ST $a3,$SIZE_T*4($tp)
  705. $ST $carry,$SIZE_T*5($tp) # store topmost carry
  706. $LD $m0,$SIZE_T*1($t1) # n[0..3]
  707. $LD $m1,$SIZE_T*2($t1)
  708. $LD $m2,$SIZE_T*3($t1)
  709. $LD $m3,$SIZE_T*4($t1)
  710. addi $np,$t1,$SIZE_T*4
  711. $UCMP $bp,$t3 # done yet?
  712. beq .Lmul4x_post
  713. $LDU $bi,$SIZE_T*4($bp)
  714. $LD $a0,$SIZE_T*1($ap) # a[0..3]
  715. $LD $a1,$SIZE_T*2($ap)
  716. $LD $a2,$SIZE_T*3($ap)
  717. $LDU $a3,$SIZE_T*4($ap)
  718. li $carry,0
  719. addic $tp,$sp,$SIZE_T*7 # &t[-1], clear carry bit
  720. b .Loop_mul4x_reduction
  721. .align 5
  722. .Lmul4x_post:
  723. # Final step. We see if result is larger than modulus, and
  724. # if it is, subtract the modulus. But comparison implies
  725. # subtraction. So we subtract modulus, see if it borrowed,
  726. # and conditionally copy original value.
  727. srwi $cnt,$num,`log($SIZE_T)/log(2)+2`
  728. mr $bp,$t2 # &rp[-1]
  729. subi $cnt,$cnt,1
  730. mr $ap_end,$t2 # &rp[-1] copy
  731. subfc $t0,$m0,$acc0
  732. addi $tp,$sp,$SIZE_T*15
  733. subfe $t1,$m1,$acc1
  734. mtctr $cnt
  735. .Lmul4x_sub:
  736. $LD $m0,$SIZE_T*1($np)
  737. $LD $acc0,$SIZE_T*1($tp)
  738. subfe $t2,$m2,$acc2
  739. $LD $m1,$SIZE_T*2($np)
  740. $LD $acc1,$SIZE_T*2($tp)
  741. subfe $t3,$m3,$acc3
  742. $LD $m2,$SIZE_T*3($np)
  743. $LD $acc2,$SIZE_T*3($tp)
  744. $LDU $m3,$SIZE_T*4($np)
  745. $LDU $acc3,$SIZE_T*4($tp)
  746. $ST $t0,$SIZE_T*1($bp)
  747. $ST $t1,$SIZE_T*2($bp)
  748. subfe $t0,$m0,$acc0
  749. $ST $t2,$SIZE_T*3($bp)
  750. $STU $t3,$SIZE_T*4($bp)
  751. subfe $t1,$m1,$acc1
  752. bdnz .Lmul4x_sub
  753. $LD $a0,$SIZE_T*1($ap_end)
  754. $ST $t0,$SIZE_T*1($bp)
  755. $LD $t0,$SIZE_T*12($sp)
  756. subfe $t2,$m2,$acc2
  757. $LD $a1,$SIZE_T*2($ap_end)
  758. $ST $t1,$SIZE_T*2($bp)
  759. $LD $t1,$SIZE_T*13($sp)
  760. subfe $t3,$m3,$acc3
  761. subfe $carry,$zero,$carry # did it borrow?
  762. addi $tp,$sp,$SIZE_T*12
  763. $LD $a2,$SIZE_T*3($ap_end)
  764. $ST $t2,$SIZE_T*3($bp)
  765. $LD $t2,$SIZE_T*14($sp)
  766. $LD $a3,$SIZE_T*4($ap_end)
  767. $ST $t3,$SIZE_T*4($bp)
  768. $LD $t3,$SIZE_T*15($sp)
  769. mtctr $cnt
  770. .Lmul4x_cond_copy:
  771. and $t0,$t0,$carry
  772. andc $a0,$a0,$carry
  773. $ST $zero,$SIZE_T*0($tp) # wipe stack clean
  774. and $t1,$t1,$carry
  775. andc $a1,$a1,$carry
  776. $ST $zero,$SIZE_T*1($tp)
  777. and $t2,$t2,$carry
  778. andc $a2,$a2,$carry
  779. $ST $zero,$SIZE_T*2($tp)
  780. and $t3,$t3,$carry
  781. andc $a3,$a3,$carry
  782. $ST $zero,$SIZE_T*3($tp)
  783. or $acc0,$t0,$a0
  784. $LD $a0,$SIZE_T*5($ap_end)
  785. $LD $t0,$SIZE_T*4($tp)
  786. or $acc1,$t1,$a1
  787. $LD $a1,$SIZE_T*6($ap_end)
  788. $LD $t1,$SIZE_T*5($tp)
  789. or $acc2,$t2,$a2
  790. $LD $a2,$SIZE_T*7($ap_end)
  791. $LD $t2,$SIZE_T*6($tp)
  792. or $acc3,$t3,$a3
  793. $LD $a3,$SIZE_T*8($ap_end)
  794. $LD $t3,$SIZE_T*7($tp)
  795. addi $tp,$tp,$SIZE_T*4
  796. $ST $acc0,$SIZE_T*1($ap_end)
  797. $ST $acc1,$SIZE_T*2($ap_end)
  798. $ST $acc2,$SIZE_T*3($ap_end)
  799. $STU $acc3,$SIZE_T*4($ap_end)
  800. bdnz .Lmul4x_cond_copy
  801. $POP $bp,0($sp) # pull saved sp
  802. and $t0,$t0,$carry
  803. andc $a0,$a0,$carry
  804. $ST $zero,$SIZE_T*0($tp)
  805. and $t1,$t1,$carry
  806. andc $a1,$a1,$carry
  807. $ST $zero,$SIZE_T*1($tp)
  808. and $t2,$t2,$carry
  809. andc $a2,$a2,$carry
  810. $ST $zero,$SIZE_T*2($tp)
  811. and $t3,$t3,$carry
  812. andc $a3,$a3,$carry
  813. $ST $zero,$SIZE_T*3($tp)
  814. or $acc0,$t0,$a0
  815. or $acc1,$t1,$a1
  816. $ST $zero,$SIZE_T*4($tp)
  817. or $acc2,$t2,$a2
  818. or $acc3,$t3,$a3
  819. $ST $acc0,$SIZE_T*1($ap_end)
  820. $ST $acc1,$SIZE_T*2($ap_end)
  821. $ST $acc2,$SIZE_T*3($ap_end)
  822. $ST $acc3,$SIZE_T*4($ap_end)
  823. b .Lmul4x_done
  824. .align 4
  825. .Lmul4x4_post_condition:
  826. $POP $ap,$SIZE_T*6($sp) # pull &rp[-1]
  827. $POP $bp,0($sp) # pull saved sp
  828. addze $carry,$carry # modulo-scheduled
  829. # $acc0-3,$carry hold result, $m0-3 hold modulus
  830. subfc $a0,$m0,$acc0
  831. subfe $a1,$m1,$acc1
  832. subfe $a2,$m2,$acc2
  833. subfe $a3,$m3,$acc3
  834. subfe $carry,$zero,$carry # did it borrow?
  835. and $m0,$m0,$carry
  836. and $m1,$m1,$carry
  837. addc $a0,$a0,$m0
  838. and $m2,$m2,$carry
  839. adde $a1,$a1,$m1
  840. and $m3,$m3,$carry
  841. adde $a2,$a2,$m2
  842. adde $a3,$a3,$m3
  843. $ST $a0,$SIZE_T*1($ap) # write result
  844. $ST $a1,$SIZE_T*2($ap)
  845. $ST $a2,$SIZE_T*3($ap)
  846. $ST $a3,$SIZE_T*4($ap)
  847. .Lmul4x_done:
  848. $ST $zero,$SIZE_T*8($sp) # wipe stack clean
  849. $ST $zero,$SIZE_T*9($sp)
  850. $ST $zero,$SIZE_T*10($sp)
  851. $ST $zero,$SIZE_T*11($sp)
  852. li r3,1 # signal "done"
  853. $POP r14,-$SIZE_T*18($bp)
  854. $POP r15,-$SIZE_T*17($bp)
  855. $POP r16,-$SIZE_T*16($bp)
  856. $POP r17,-$SIZE_T*15($bp)
  857. $POP r18,-$SIZE_T*14($bp)
  858. $POP r19,-$SIZE_T*13($bp)
  859. $POP r20,-$SIZE_T*12($bp)
  860. $POP r21,-$SIZE_T*11($bp)
  861. $POP r22,-$SIZE_T*10($bp)
  862. $POP r23,-$SIZE_T*9($bp)
  863. $POP r24,-$SIZE_T*8($bp)
  864. $POP r25,-$SIZE_T*7($bp)
  865. $POP r26,-$SIZE_T*6($bp)
  866. $POP r27,-$SIZE_T*5($bp)
  867. $POP r28,-$SIZE_T*4($bp)
  868. $POP r29,-$SIZE_T*3($bp)
  869. $POP r30,-$SIZE_T*2($bp)
  870. $POP r31,-$SIZE_T*1($bp)
  871. mr $sp,$bp
  872. blr
  873. .long 0
  874. .byte 0,12,4,0x20,0x80,18,6,0
  875. .long 0
  876. .size .bn_mul4x_mont_int,.-.bn_mul4x_mont_int
  877. ___
  878. }
  879. if (1) {
  880. ########################################################################
  881. # Following is PPC adaptation of sqrx8x_mont from x86_64-mont5 module.
  882. my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7)=map("r$_",(9..12,14..17));
  883. my ($t0,$t1,$t2,$t3)=map("r$_",(18..21));
  884. my ($acc0,$acc1,$acc2,$acc3,$acc4,$acc5,$acc6,$acc7)=map("r$_",(22..29));
  885. my ($cnt,$carry,$zero)=("r30","r31","r0");
  886. my ($tp,$ap_end,$na0)=($bp,$np,$carry);
  887. # sp----------->+-------------------------------+
  888. # | saved sp |
  889. # +-------------------------------+
  890. # . .
  891. # +12*size_t +-------------------------------+
  892. # | size_t tmp[2*num] |
  893. # . .
  894. # . .
  895. # . .
  896. # +-------------------------------+
  897. # . .
  898. # -18*size_t +-------------------------------+
  899. # | 18 saved gpr, r14-r31 |
  900. # . .
  901. # . .
  902. # +-------------------------------+
  903. $code.=<<___;
  904. .align 5
  905. __bn_sqr8x_mont:
  906. .Lsqr8x_do:
  907. mr $a0,$sp
  908. slwi $a1,$num,`log($SIZE_T)/log(2)+1`
  909. li $a2,-32*$SIZE_T
  910. sub $a1,$a2,$a1
  911. slwi $num,$num,`log($SIZE_T)/log(2)`
  912. $STUX $sp,$sp,$a1 # alloca
  913. $PUSH r14,-$SIZE_T*18($a0)
  914. $PUSH r15,-$SIZE_T*17($a0)
  915. $PUSH r16,-$SIZE_T*16($a0)
  916. $PUSH r17,-$SIZE_T*15($a0)
  917. $PUSH r18,-$SIZE_T*14($a0)
  918. $PUSH r19,-$SIZE_T*13($a0)
  919. $PUSH r20,-$SIZE_T*12($a0)
  920. $PUSH r21,-$SIZE_T*11($a0)
  921. $PUSH r22,-$SIZE_T*10($a0)
  922. $PUSH r23,-$SIZE_T*9($a0)
  923. $PUSH r24,-$SIZE_T*8($a0)
  924. $PUSH r25,-$SIZE_T*7($a0)
  925. $PUSH r26,-$SIZE_T*6($a0)
  926. $PUSH r27,-$SIZE_T*5($a0)
  927. $PUSH r28,-$SIZE_T*4($a0)
  928. $PUSH r29,-$SIZE_T*3($a0)
  929. $PUSH r30,-$SIZE_T*2($a0)
  930. $PUSH r31,-$SIZE_T*1($a0)
  931. subi $ap,$ap,$SIZE_T # bias by -1
  932. subi $t0,$np,$SIZE_T # bias by -1
  933. subi $rp,$rp,$SIZE_T # bias by -1
  934. $LD $n0,0($n0) # *n0
  935. li $zero,0
  936. add $ap_end,$ap,$num
  937. $LD $a0,$SIZE_T*1($ap)
  938. #li $acc0,0
  939. $LD $a1,$SIZE_T*2($ap)
  940. li $acc1,0
  941. $LD $a2,$SIZE_T*3($ap)
  942. li $acc2,0
  943. $LD $a3,$SIZE_T*4($ap)
  944. li $acc3,0
  945. $LD $a4,$SIZE_T*5($ap)
  946. li $acc4,0
  947. $LD $a5,$SIZE_T*6($ap)
  948. li $acc5,0
  949. $LD $a6,$SIZE_T*7($ap)
  950. li $acc6,0
  951. $LDU $a7,$SIZE_T*8($ap)
  952. li $acc7,0
  953. addi $tp,$sp,$SIZE_T*11 # &tp[-1]
  954. subic. $cnt,$num,$SIZE_T*8
  955. b .Lsqr8x_zero_start
  956. .align 5
  957. .Lsqr8x_zero:
  958. subic. $cnt,$cnt,$SIZE_T*8
  959. $ST $zero,$SIZE_T*1($tp)
  960. $ST $zero,$SIZE_T*2($tp)
  961. $ST $zero,$SIZE_T*3($tp)
  962. $ST $zero,$SIZE_T*4($tp)
  963. $ST $zero,$SIZE_T*5($tp)
  964. $ST $zero,$SIZE_T*6($tp)
  965. $ST $zero,$SIZE_T*7($tp)
  966. $ST $zero,$SIZE_T*8($tp)
  967. .Lsqr8x_zero_start:
  968. $ST $zero,$SIZE_T*9($tp)
  969. $ST $zero,$SIZE_T*10($tp)
  970. $ST $zero,$SIZE_T*11($tp)
  971. $ST $zero,$SIZE_T*12($tp)
  972. $ST $zero,$SIZE_T*13($tp)
  973. $ST $zero,$SIZE_T*14($tp)
  974. $ST $zero,$SIZE_T*15($tp)
  975. $STU $zero,$SIZE_T*16($tp)
  976. bne .Lsqr8x_zero
  977. $PUSH $rp,$SIZE_T*6($sp) # offload &rp[-1]
  978. $PUSH $t0,$SIZE_T*7($sp) # offload &np[-1]
  979. $PUSH $n0,$SIZE_T*8($sp) # offload n0
  980. $PUSH $tp,$SIZE_T*9($sp) # &tp[2*num-1]
  981. $PUSH $zero,$SIZE_T*10($sp) # initial top-most carry
  982. addi $tp,$sp,$SIZE_T*11 # &tp[-1]
  983. # Multiply everything but a[i]*a[i]
  984. .align 5
  985. .Lsqr8x_outer_loop:
  986. # a[1]a[0] (i)
  987. # a[2]a[0]
  988. # a[3]a[0]
  989. # a[4]a[0]
  990. # a[5]a[0]
  991. # a[6]a[0]
  992. # a[7]a[0]
  993. # a[2]a[1] (ii)
  994. # a[3]a[1]
  995. # a[4]a[1]
  996. # a[5]a[1]
  997. # a[6]a[1]
  998. # a[7]a[1]
  999. # a[3]a[2] (iii)
  1000. # a[4]a[2]
  1001. # a[5]a[2]
  1002. # a[6]a[2]
  1003. # a[7]a[2]
  1004. # a[4]a[3] (iv)
  1005. # a[5]a[3]
  1006. # a[6]a[3]
  1007. # a[7]a[3]
  1008. # a[5]a[4] (v)
  1009. # a[6]a[4]
  1010. # a[7]a[4]
  1011. # a[6]a[5] (vi)
  1012. # a[7]a[5]
  1013. # a[7]a[6] (vii)
  1014. $UMULL $t0,$a1,$a0 # lo(a[1..7]*a[0]) (i)
  1015. $UMULL $t1,$a2,$a0
  1016. $UMULL $t2,$a3,$a0
  1017. $UMULL $t3,$a4,$a0
  1018. addc $acc1,$acc1,$t0 # t[1]+lo(a[1]*a[0])
  1019. $UMULL $t0,$a5,$a0
  1020. adde $acc2,$acc2,$t1
  1021. $UMULL $t1,$a6,$a0
  1022. adde $acc3,$acc3,$t2
  1023. $UMULL $t2,$a7,$a0
  1024. adde $acc4,$acc4,$t3
  1025. $UMULH $t3,$a1,$a0 # hi(a[1..7]*a[0])
  1026. adde $acc5,$acc5,$t0
  1027. $UMULH $t0,$a2,$a0
  1028. adde $acc6,$acc6,$t1
  1029. $UMULH $t1,$a3,$a0
  1030. adde $acc7,$acc7,$t2
  1031. $UMULH $t2,$a4,$a0
  1032. $ST $acc0,$SIZE_T*1($tp) # t[0]
  1033. addze $acc0,$zero # t[8]
  1034. $ST $acc1,$SIZE_T*2($tp) # t[1]
  1035. addc $acc2,$acc2,$t3 # t[2]+lo(a[1]*a[0])
  1036. $UMULH $t3,$a5,$a0
  1037. adde $acc3,$acc3,$t0
  1038. $UMULH $t0,$a6,$a0
  1039. adde $acc4,$acc4,$t1
  1040. $UMULH $t1,$a7,$a0
  1041. adde $acc5,$acc5,$t2
  1042. $UMULL $t2,$a2,$a1 # lo(a[2..7]*a[1]) (ii)
  1043. adde $acc6,$acc6,$t3
  1044. $UMULL $t3,$a3,$a1
  1045. adde $acc7,$acc7,$t0
  1046. $UMULL $t0,$a4,$a1
  1047. adde $acc0,$acc0,$t1
  1048. $UMULL $t1,$a5,$a1
  1049. addc $acc3,$acc3,$t2
  1050. $UMULL $t2,$a6,$a1
  1051. adde $acc4,$acc4,$t3
  1052. $UMULL $t3,$a7,$a1
  1053. adde $acc5,$acc5,$t0
  1054. $UMULH $t0,$a2,$a1 # hi(a[2..7]*a[1])
  1055. adde $acc6,$acc6,$t1
  1056. $UMULH $t1,$a3,$a1
  1057. adde $acc7,$acc7,$t2
  1058. $UMULH $t2,$a4,$a1
  1059. adde $acc0,$acc0,$t3
  1060. $UMULH $t3,$a5,$a1
  1061. $ST $acc2,$SIZE_T*3($tp) # t[2]
  1062. addze $acc1,$zero # t[9]
  1063. $ST $acc3,$SIZE_T*4($tp) # t[3]
  1064. addc $acc4,$acc4,$t0
  1065. $UMULH $t0,$a6,$a1
  1066. adde $acc5,$acc5,$t1
  1067. $UMULH $t1,$a7,$a1
  1068. adde $acc6,$acc6,$t2
  1069. $UMULL $t2,$a3,$a2 # lo(a[3..7]*a[2]) (iii)
  1070. adde $acc7,$acc7,$t3
  1071. $UMULL $t3,$a4,$a2
  1072. adde $acc0,$acc0,$t0
  1073. $UMULL $t0,$a5,$a2
  1074. adde $acc1,$acc1,$t1
  1075. $UMULL $t1,$a6,$a2
  1076. addc $acc5,$acc5,$t2
  1077. $UMULL $t2,$a7,$a2
  1078. adde $acc6,$acc6,$t3
  1079. $UMULH $t3,$a3,$a2 # hi(a[3..7]*a[2])
  1080. adde $acc7,$acc7,$t0
  1081. $UMULH $t0,$a4,$a2
  1082. adde $acc0,$acc0,$t1
  1083. $UMULH $t1,$a5,$a2
  1084. adde $acc1,$acc1,$t2
  1085. $UMULH $t2,$a6,$a2
  1086. $ST $acc4,$SIZE_T*5($tp) # t[4]
  1087. addze $acc2,$zero # t[10]
  1088. $ST $acc5,$SIZE_T*6($tp) # t[5]
  1089. addc $acc6,$acc6,$t3
  1090. $UMULH $t3,$a7,$a2
  1091. adde $acc7,$acc7,$t0
  1092. $UMULL $t0,$a4,$a3 # lo(a[4..7]*a[3]) (iv)
  1093. adde $acc0,$acc0,$t1
  1094. $UMULL $t1,$a5,$a3
  1095. adde $acc1,$acc1,$t2
  1096. $UMULL $t2,$a6,$a3
  1097. adde $acc2,$acc2,$t3
  1098. $UMULL $t3,$a7,$a3
  1099. addc $acc7,$acc7,$t0
  1100. $UMULH $t0,$a4,$a3 # hi(a[4..7]*a[3])
  1101. adde $acc0,$acc0,$t1
  1102. $UMULH $t1,$a5,$a3
  1103. adde $acc1,$acc1,$t2
  1104. $UMULH $t2,$a6,$a3
  1105. adde $acc2,$acc2,$t3
  1106. $UMULH $t3,$a7,$a3
  1107. $ST $acc6,$SIZE_T*7($tp) # t[6]
  1108. addze $acc3,$zero # t[11]
  1109. $STU $acc7,$SIZE_T*8($tp) # t[7]
  1110. addc $acc0,$acc0,$t0
  1111. $UMULL $t0,$a5,$a4 # lo(a[5..7]*a[4]) (v)
  1112. adde $acc1,$acc1,$t1
  1113. $UMULL $t1,$a6,$a4
  1114. adde $acc2,$acc2,$t2
  1115. $UMULL $t2,$a7,$a4
  1116. adde $acc3,$acc3,$t3
  1117. $UMULH $t3,$a5,$a4 # hi(a[5..7]*a[4])
  1118. addc $acc1,$acc1,$t0
  1119. $UMULH $t0,$a6,$a4
  1120. adde $acc2,$acc2,$t1
  1121. $UMULH $t1,$a7,$a4
  1122. adde $acc3,$acc3,$t2
  1123. $UMULL $t2,$a6,$a5 # lo(a[6..7]*a[5]) (vi)
  1124. addze $acc4,$zero # t[12]
  1125. addc $acc2,$acc2,$t3
  1126. $UMULL $t3,$a7,$a5
  1127. adde $acc3,$acc3,$t0
  1128. $UMULH $t0,$a6,$a5 # hi(a[6..7]*a[5])
  1129. adde $acc4,$acc4,$t1
  1130. $UMULH $t1,$a7,$a5
  1131. addc $acc3,$acc3,$t2
  1132. $UMULL $t2,$a7,$a6 # lo(a[7]*a[6]) (vii)
  1133. adde $acc4,$acc4,$t3
  1134. $UMULH $t3,$a7,$a6 # hi(a[7]*a[6])
  1135. addze $acc5,$zero # t[13]
  1136. addc $acc4,$acc4,$t0
  1137. $UCMP $ap_end,$ap # done yet?
  1138. adde $acc5,$acc5,$t1
  1139. addc $acc5,$acc5,$t2
  1140. sub $t0,$ap_end,$num # rewinded ap
  1141. addze $acc6,$zero # t[14]
  1142. add $acc6,$acc6,$t3
  1143. beq .Lsqr8x_outer_break
  1144. mr $n0,$a0
  1145. $LD $a0,$SIZE_T*1($tp)
  1146. $LD $a1,$SIZE_T*2($tp)
  1147. $LD $a2,$SIZE_T*3($tp)
  1148. $LD $a3,$SIZE_T*4($tp)
  1149. $LD $a4,$SIZE_T*5($tp)
  1150. $LD $a5,$SIZE_T*6($tp)
  1151. $LD $a6,$SIZE_T*7($tp)
  1152. $LD $a7,$SIZE_T*8($tp)
  1153. addc $acc0,$acc0,$a0
  1154. $LD $a0,$SIZE_T*1($ap)
  1155. adde $acc1,$acc1,$a1
  1156. $LD $a1,$SIZE_T*2($ap)
  1157. adde $acc2,$acc2,$a2
  1158. $LD $a2,$SIZE_T*3($ap)
  1159. adde $acc3,$acc3,$a3
  1160. $LD $a3,$SIZE_T*4($ap)
  1161. adde $acc4,$acc4,$a4
  1162. $LD $a4,$SIZE_T*5($ap)
  1163. adde $acc5,$acc5,$a5
  1164. $LD $a5,$SIZE_T*6($ap)
  1165. adde $acc6,$acc6,$a6
  1166. $LD $a6,$SIZE_T*7($ap)
  1167. subi $rp,$ap,$SIZE_T*7
  1168. addze $acc7,$a7
  1169. $LDU $a7,$SIZE_T*8($ap)
  1170. #addze $carry,$zero # moved below
  1171. li $cnt,0
  1172. b .Lsqr8x_mul
  1173. # a[8]a[0]
  1174. # a[9]a[0]
  1175. # a[a]a[0]
  1176. # a[b]a[0]
  1177. # a[c]a[0]
  1178. # a[d]a[0]
  1179. # a[e]a[0]
  1180. # a[f]a[0]
  1181. # a[8]a[1]
  1182. # a[f]a[1]........................
  1183. # a[8]a[2]
  1184. # a[f]a[2]........................
  1185. # a[8]a[3]
  1186. # a[f]a[3]........................
  1187. # a[8]a[4]
  1188. # a[f]a[4]........................
  1189. # a[8]a[5]
  1190. # a[f]a[5]........................
  1191. # a[8]a[6]
  1192. # a[f]a[6]........................
  1193. # a[8]a[7]
  1194. # a[f]a[7]........................
  1195. .align 5
  1196. .Lsqr8x_mul:
  1197. $UMULL $t0,$a0,$n0
  1198. addze $carry,$zero # carry bit, modulo-scheduled
  1199. $UMULL $t1,$a1,$n0
  1200. addi $cnt,$cnt,$SIZE_T
  1201. $UMULL $t2,$a2,$n0
  1202. andi. $cnt,$cnt,$SIZE_T*8-1
  1203. $UMULL $t3,$a3,$n0
  1204. addc $acc0,$acc0,$t0
  1205. $UMULL $t0,$a4,$n0
  1206. adde $acc1,$acc1,$t1
  1207. $UMULL $t1,$a5,$n0
  1208. adde $acc2,$acc2,$t2
  1209. $UMULL $t2,$a6,$n0
  1210. adde $acc3,$acc3,$t3
  1211. $UMULL $t3,$a7,$n0
  1212. adde $acc4,$acc4,$t0
  1213. $UMULH $t0,$a0,$n0
  1214. adde $acc5,$acc5,$t1
  1215. $UMULH $t1,$a1,$n0
  1216. adde $acc6,$acc6,$t2
  1217. $UMULH $t2,$a2,$n0
  1218. adde $acc7,$acc7,$t3
  1219. $UMULH $t3,$a3,$n0
  1220. addze $carry,$carry
  1221. $STU $acc0,$SIZE_T($tp)
  1222. addc $acc0,$acc1,$t0
  1223. $UMULH $t0,$a4,$n0
  1224. adde $acc1,$acc2,$t1
  1225. $UMULH $t1,$a5,$n0
  1226. adde $acc2,$acc3,$t2
  1227. $UMULH $t2,$a6,$n0
  1228. adde $acc3,$acc4,$t3
  1229. $UMULH $t3,$a7,$n0
  1230. $LDX $n0,$rp,$cnt
  1231. adde $acc4,$acc5,$t0
  1232. adde $acc5,$acc6,$t1
  1233. adde $acc6,$acc7,$t2
  1234. adde $acc7,$carry,$t3
  1235. #addze $carry,$zero # moved above
  1236. bne .Lsqr8x_mul
  1237. # note that carry flag is guaranteed
  1238. # to be zero at this point
  1239. $UCMP $ap,$ap_end # done yet?
  1240. beq .Lsqr8x_break
  1241. $LD $a0,$SIZE_T*1($tp)
  1242. $LD $a1,$SIZE_T*2($tp)
  1243. $LD $a2,$SIZE_T*3($tp)
  1244. $LD $a3,$SIZE_T*4($tp)
  1245. $LD $a4,$SIZE_T*5($tp)
  1246. $LD $a5,$SIZE_T*6($tp)
  1247. $LD $a6,$SIZE_T*7($tp)
  1248. $LD $a7,$SIZE_T*8($tp)
  1249. addc $acc0,$acc0,$a0
  1250. $LD $a0,$SIZE_T*1($ap)
  1251. adde $acc1,$acc1,$a1
  1252. $LD $a1,$SIZE_T*2($ap)
  1253. adde $acc2,$acc2,$a2
  1254. $LD $a2,$SIZE_T*3($ap)
  1255. adde $acc3,$acc3,$a3
  1256. $LD $a3,$SIZE_T*4($ap)
  1257. adde $acc4,$acc4,$a4
  1258. $LD $a4,$SIZE_T*5($ap)
  1259. adde $acc5,$acc5,$a5
  1260. $LD $a5,$SIZE_T*6($ap)
  1261. adde $acc6,$acc6,$a6
  1262. $LD $a6,$SIZE_T*7($ap)
  1263. adde $acc7,$acc7,$a7
  1264. $LDU $a7,$SIZE_T*8($ap)
  1265. #addze $carry,$zero # moved above
  1266. b .Lsqr8x_mul
  1267. .align 5
  1268. .Lsqr8x_break:
  1269. $LD $a0,$SIZE_T*8($rp)
  1270. addi $ap,$rp,$SIZE_T*15
  1271. $LD $a1,$SIZE_T*9($rp)
  1272. sub. $t0,$ap_end,$ap # is it last iteration?
  1273. $LD $a2,$SIZE_T*10($rp)
  1274. sub $t1,$tp,$t0
  1275. $LD $a3,$SIZE_T*11($rp)
  1276. $LD $a4,$SIZE_T*12($rp)
  1277. $LD $a5,$SIZE_T*13($rp)
  1278. $LD $a6,$SIZE_T*14($rp)
  1279. $LD $a7,$SIZE_T*15($rp)
  1280. beq .Lsqr8x_outer_loop
  1281. $ST $acc0,$SIZE_T*1($tp)
  1282. $LD $acc0,$SIZE_T*1($t1)
  1283. $ST $acc1,$SIZE_T*2($tp)
  1284. $LD $acc1,$SIZE_T*2($t1)
  1285. $ST $acc2,$SIZE_T*3($tp)
  1286. $LD $acc2,$SIZE_T*3($t1)
  1287. $ST $acc3,$SIZE_T*4($tp)
  1288. $LD $acc3,$SIZE_T*4($t1)
  1289. $ST $acc4,$SIZE_T*5($tp)
  1290. $LD $acc4,$SIZE_T*5($t1)
  1291. $ST $acc5,$SIZE_T*6($tp)
  1292. $LD $acc5,$SIZE_T*6($t1)
  1293. $ST $acc6,$SIZE_T*7($tp)
  1294. $LD $acc6,$SIZE_T*7($t1)
  1295. $ST $acc7,$SIZE_T*8($tp)
  1296. $LD $acc7,$SIZE_T*8($t1)
  1297. mr $tp,$t1
  1298. b .Lsqr8x_outer_loop
  1299. .align 5
  1300. .Lsqr8x_outer_break:
  1301. ####################################################################
  1302. # Now multiply above result by 2 and add a[n-1]*a[n-1]|...|a[0]*a[0]
  1303. $LD $a1,$SIZE_T*1($t0) # recall that $t0 is &a[-1]
  1304. $LD $a3,$SIZE_T*2($t0)
  1305. $LD $a5,$SIZE_T*3($t0)
  1306. $LD $a7,$SIZE_T*4($t0)
  1307. addi $ap,$t0,$SIZE_T*4
  1308. # "tp[x]" comments are for num==8 case
  1309. $LD $t1,$SIZE_T*13($sp) # =tp[1], t[0] is not interesting
  1310. $LD $t2,$SIZE_T*14($sp)
  1311. $LD $t3,$SIZE_T*15($sp)
  1312. $LD $t0,$SIZE_T*16($sp)
  1313. $ST $acc0,$SIZE_T*1($tp) # tp[8]=
  1314. srwi $cnt,$num,`log($SIZE_T)/log(2)+2`
  1315. $ST $acc1,$SIZE_T*2($tp)
  1316. subi $cnt,$cnt,1
  1317. $ST $acc2,$SIZE_T*3($tp)
  1318. $ST $acc3,$SIZE_T*4($tp)
  1319. $ST $acc4,$SIZE_T*5($tp)
  1320. $ST $acc5,$SIZE_T*6($tp)
  1321. $ST $acc6,$SIZE_T*7($tp)
  1322. #$ST $acc7,$SIZE_T*8($tp) # tp[15] is not interesting
  1323. addi $tp,$sp,$SIZE_T*11 # &tp[-1]
  1324. $UMULL $acc0,$a1,$a1
  1325. $UMULH $a1,$a1,$a1
  1326. add $acc1,$t1,$t1 # <<1
  1327. $SHRI $t1,$t1,$BITS-1
  1328. $UMULL $a2,$a3,$a3
  1329. $UMULH $a3,$a3,$a3
  1330. addc $acc1,$acc1,$a1
  1331. add $acc2,$t2,$t2
  1332. $SHRI $t2,$t2,$BITS-1
  1333. add $acc3,$t3,$t3
  1334. $SHRI $t3,$t3,$BITS-1
  1335. or $acc2,$acc2,$t1
  1336. mtctr $cnt
  1337. .Lsqr4x_shift_n_add:
  1338. $UMULL $a4,$a5,$a5
  1339. $UMULH $a5,$a5,$a5
  1340. $LD $t1,$SIZE_T*6($tp) # =tp[5]
  1341. $LD $a1,$SIZE_T*1($ap)
  1342. adde $acc2,$acc2,$a2
  1343. add $acc4,$t0,$t0
  1344. $SHRI $t0,$t0,$BITS-1
  1345. or $acc3,$acc3,$t2
  1346. $LD $t2,$SIZE_T*7($tp) # =tp[6]
  1347. adde $acc3,$acc3,$a3
  1348. $LD $a3,$SIZE_T*2($ap)
  1349. add $acc5,$t1,$t1
  1350. $SHRI $t1,$t1,$BITS-1
  1351. or $acc4,$acc4,$t3
  1352. $LD $t3,$SIZE_T*8($tp) # =tp[7]
  1353. $UMULL $a6,$a7,$a7
  1354. $UMULH $a7,$a7,$a7
  1355. adde $acc4,$acc4,$a4
  1356. add $acc6,$t2,$t2
  1357. $SHRI $t2,$t2,$BITS-1
  1358. or $acc5,$acc5,$t0
  1359. $LD $t0,$SIZE_T*9($tp) # =tp[8]
  1360. adde $acc5,$acc5,$a5
  1361. $LD $a5,$SIZE_T*3($ap)
  1362. add $acc7,$t3,$t3
  1363. $SHRI $t3,$t3,$BITS-1
  1364. or $acc6,$acc6,$t1
  1365. $LD $t1,$SIZE_T*10($tp) # =tp[9]
  1366. $UMULL $a0,$a1,$a1
  1367. $UMULH $a1,$a1,$a1
  1368. adde $acc6,$acc6,$a6
  1369. $ST $acc0,$SIZE_T*1($tp) # tp[0]=
  1370. add $acc0,$t0,$t0
  1371. $SHRI $t0,$t0,$BITS-1
  1372. or $acc7,$acc7,$t2
  1373. $LD $t2,$SIZE_T*11($tp) # =tp[10]
  1374. adde $acc7,$acc7,$a7
  1375. $LDU $a7,$SIZE_T*4($ap)
  1376. $ST $acc1,$SIZE_T*2($tp) # tp[1]=
  1377. add $acc1,$t1,$t1
  1378. $SHRI $t1,$t1,$BITS-1
  1379. or $acc0,$acc0,$t3
  1380. $LD $t3,$SIZE_T*12($tp) # =tp[11]
  1381. $UMULL $a2,$a3,$a3
  1382. $UMULH $a3,$a3,$a3
  1383. adde $acc0,$acc0,$a0
  1384. $ST $acc2,$SIZE_T*3($tp) # tp[2]=
  1385. add $acc2,$t2,$t2
  1386. $SHRI $t2,$t2,$BITS-1
  1387. or $acc1,$acc1,$t0
  1388. $LD $t0,$SIZE_T*13($tp) # =tp[12]
  1389. adde $acc1,$acc1,$a1
  1390. $ST $acc3,$SIZE_T*4($tp) # tp[3]=
  1391. $ST $acc4,$SIZE_T*5($tp) # tp[4]=
  1392. $ST $acc5,$SIZE_T*6($tp) # tp[5]=
  1393. $ST $acc6,$SIZE_T*7($tp) # tp[6]=
  1394. $STU $acc7,$SIZE_T*8($tp) # tp[7]=
  1395. add $acc3,$t3,$t3
  1396. $SHRI $t3,$t3,$BITS-1
  1397. or $acc2,$acc2,$t1
  1398. bdnz .Lsqr4x_shift_n_add
  1399. ___
  1400. my ($np,$np_end)=($ap,$ap_end);
  1401. $code.=<<___;
  1402. $POP $np,$SIZE_T*7($sp) # pull &np[-1] and n0
  1403. $POP $n0,$SIZE_T*8($sp)
  1404. $UMULL $a4,$a5,$a5
  1405. $UMULH $a5,$a5,$a5
  1406. $ST $acc0,$SIZE_T*1($tp) # tp[8]=
  1407. $LD $acc0,$SIZE_T*12($sp) # =tp[0]
  1408. $LD $t1,$SIZE_T*6($tp) # =tp[13]
  1409. adde $acc2,$acc2,$a2
  1410. add $acc4,$t0,$t0
  1411. $SHRI $t0,$t0,$BITS-1
  1412. or $acc3,$acc3,$t2
  1413. $LD $t2,$SIZE_T*7($tp) # =tp[14]
  1414. adde $acc3,$acc3,$a3
  1415. add $acc5,$t1,$t1
  1416. $SHRI $t1,$t1,$BITS-1
  1417. or $acc4,$acc4,$t3
  1418. $UMULL $a6,$a7,$a7
  1419. $UMULH $a7,$a7,$a7
  1420. adde $acc4,$acc4,$a4
  1421. add $acc6,$t2,$t2
  1422. $SHRI $t2,$t2,$BITS-1
  1423. or $acc5,$acc5,$t0
  1424. $ST $acc1,$SIZE_T*2($tp) # tp[9]=
  1425. $LD $acc1,$SIZE_T*13($sp) # =tp[1]
  1426. adde $acc5,$acc5,$a5
  1427. or $acc6,$acc6,$t1
  1428. $LD $a0,$SIZE_T*1($np)
  1429. $LD $a1,$SIZE_T*2($np)
  1430. adde $acc6,$acc6,$a6
  1431. $LD $a2,$SIZE_T*3($np)
  1432. $LD $a3,$SIZE_T*4($np)
  1433. adde $acc7,$a7,$t2
  1434. $LD $a4,$SIZE_T*5($np)
  1435. $LD $a5,$SIZE_T*6($np)
  1436. ################################################################
  1437. # Reduce by 8 limbs per iteration
  1438. $UMULL $na0,$n0,$acc0 # t[0]*n0
  1439. li $cnt,8
  1440. $LD $a6,$SIZE_T*7($np)
  1441. add $np_end,$np,$num
  1442. $LDU $a7,$SIZE_T*8($np)
  1443. $ST $acc2,$SIZE_T*3($tp) # tp[10]=
  1444. $LD $acc2,$SIZE_T*14($sp)
  1445. $ST $acc3,$SIZE_T*4($tp) # tp[11]=
  1446. $LD $acc3,$SIZE_T*15($sp)
  1447. $ST $acc4,$SIZE_T*5($tp) # tp[12]=
  1448. $LD $acc4,$SIZE_T*16($sp)
  1449. $ST $acc5,$SIZE_T*6($tp) # tp[13]=
  1450. $LD $acc5,$SIZE_T*17($sp)
  1451. $ST $acc6,$SIZE_T*7($tp) # tp[14]=
  1452. $LD $acc6,$SIZE_T*18($sp)
  1453. $ST $acc7,$SIZE_T*8($tp) # tp[15]=
  1454. $LD $acc7,$SIZE_T*19($sp)
  1455. addi $tp,$sp,$SIZE_T*11 # &tp[-1]
  1456. mtctr $cnt
  1457. b .Lsqr8x_reduction
  1458. .align 5
  1459. .Lsqr8x_reduction:
  1460. # (*) $UMULL $t0,$a0,$na0 # lo(n[0-7])*lo(t[0]*n0)
  1461. $UMULL $t1,$a1,$na0
  1462. $UMULL $t2,$a2,$na0
  1463. $STU $na0,$SIZE_T($tp) # put aside t[0]*n0 for tail processing
  1464. $UMULL $t3,$a3,$na0
  1465. # (*) addc $acc0,$acc0,$t0
  1466. addic $acc0,$acc0,-1 # (*)
  1467. $UMULL $t0,$a4,$na0
  1468. adde $acc0,$acc1,$t1
  1469. $UMULL $t1,$a5,$na0
  1470. adde $acc1,$acc2,$t2
  1471. $UMULL $t2,$a6,$na0
  1472. adde $acc2,$acc3,$t3
  1473. $UMULL $t3,$a7,$na0
  1474. adde $acc3,$acc4,$t0
  1475. $UMULH $t0,$a0,$na0 # hi(n[0-7])*lo(t[0]*n0)
  1476. adde $acc4,$acc5,$t1
  1477. $UMULH $t1,$a1,$na0
  1478. adde $acc5,$acc6,$t2
  1479. $UMULH $t2,$a2,$na0
  1480. adde $acc6,$acc7,$t3
  1481. $UMULH $t3,$a3,$na0
  1482. addze $acc7,$zero
  1483. addc $acc0,$acc0,$t0
  1484. $UMULH $t0,$a4,$na0
  1485. adde $acc1,$acc1,$t1
  1486. $UMULH $t1,$a5,$na0
  1487. adde $acc2,$acc2,$t2
  1488. $UMULH $t2,$a6,$na0
  1489. adde $acc3,$acc3,$t3
  1490. $UMULH $t3,$a7,$na0
  1491. $UMULL $na0,$n0,$acc0 # next t[0]*n0
  1492. adde $acc4,$acc4,$t0
  1493. adde $acc5,$acc5,$t1
  1494. adde $acc6,$acc6,$t2
  1495. adde $acc7,$acc7,$t3
  1496. bdnz .Lsqr8x_reduction
  1497. $LD $t0,$SIZE_T*1($tp)
  1498. $LD $t1,$SIZE_T*2($tp)
  1499. $LD $t2,$SIZE_T*3($tp)
  1500. $LD $t3,$SIZE_T*4($tp)
  1501. subi $rp,$tp,$SIZE_T*7
  1502. $UCMP $np_end,$np # done yet?
  1503. addc $acc0,$acc0,$t0
  1504. $LD $t0,$SIZE_T*5($tp)
  1505. adde $acc1,$acc1,$t1
  1506. $LD $t1,$SIZE_T*6($tp)
  1507. adde $acc2,$acc2,$t2
  1508. $LD $t2,$SIZE_T*7($tp)
  1509. adde $acc3,$acc3,$t3
  1510. $LD $t3,$SIZE_T*8($tp)
  1511. adde $acc4,$acc4,$t0
  1512. adde $acc5,$acc5,$t1
  1513. adde $acc6,$acc6,$t2
  1514. adde $acc7,$acc7,$t3
  1515. #addze $carry,$zero # moved below
  1516. beq .Lsqr8x8_post_condition
  1517. $LD $n0,$SIZE_T*0($rp)
  1518. $LD $a0,$SIZE_T*1($np)
  1519. $LD $a1,$SIZE_T*2($np)
  1520. $LD $a2,$SIZE_T*3($np)
  1521. $LD $a3,$SIZE_T*4($np)
  1522. $LD $a4,$SIZE_T*5($np)
  1523. $LD $a5,$SIZE_T*6($np)
  1524. $LD $a6,$SIZE_T*7($np)
  1525. $LDU $a7,$SIZE_T*8($np)
  1526. li $cnt,0
  1527. .align 5
  1528. .Lsqr8x_tail:
  1529. $UMULL $t0,$a0,$n0
  1530. addze $carry,$zero # carry bit, modulo-scheduled
  1531. $UMULL $t1,$a1,$n0
  1532. addi $cnt,$cnt,$SIZE_T
  1533. $UMULL $t2,$a2,$n0
  1534. andi. $cnt,$cnt,$SIZE_T*8-1
  1535. $UMULL $t3,$a3,$n0
  1536. addc $acc0,$acc0,$t0
  1537. $UMULL $t0,$a4,$n0
  1538. adde $acc1,$acc1,$t1
  1539. $UMULL $t1,$a5,$n0
  1540. adde $acc2,$acc2,$t2
  1541. $UMULL $t2,$a6,$n0
  1542. adde $acc3,$acc3,$t3
  1543. $UMULL $t3,$a7,$n0
  1544. adde $acc4,$acc4,$t0
  1545. $UMULH $t0,$a0,$n0
  1546. adde $acc5,$acc5,$t1
  1547. $UMULH $t1,$a1,$n0
  1548. adde $acc6,$acc6,$t2
  1549. $UMULH $t2,$a2,$n0
  1550. adde $acc7,$acc7,$t3
  1551. $UMULH $t3,$a3,$n0
  1552. addze $carry,$carry
  1553. $STU $acc0,$SIZE_T($tp)
  1554. addc $acc0,$acc1,$t0
  1555. $UMULH $t0,$a4,$n0
  1556. adde $acc1,$acc2,$t1
  1557. $UMULH $t1,$a5,$n0
  1558. adde $acc2,$acc3,$t2
  1559. $UMULH $t2,$a6,$n0
  1560. adde $acc3,$acc4,$t3
  1561. $UMULH $t3,$a7,$n0
  1562. $LDX $n0,$rp,$cnt
  1563. adde $acc4,$acc5,$t0
  1564. adde $acc5,$acc6,$t1
  1565. adde $acc6,$acc7,$t2
  1566. adde $acc7,$carry,$t3
  1567. #addze $carry,$zero # moved above
  1568. bne .Lsqr8x_tail
  1569. # note that carry flag is guaranteed
  1570. # to be zero at this point
  1571. $LD $a0,$SIZE_T*1($tp)
  1572. $POP $carry,$SIZE_T*10($sp) # pull top-most carry in case we break
  1573. $UCMP $np_end,$np # done yet?
  1574. $LD $a1,$SIZE_T*2($tp)
  1575. sub $t2,$np_end,$num # rewinded np
  1576. $LD $a2,$SIZE_T*3($tp)
  1577. $LD $a3,$SIZE_T*4($tp)
  1578. $LD $a4,$SIZE_T*5($tp)
  1579. $LD $a5,$SIZE_T*6($tp)
  1580. $LD $a6,$SIZE_T*7($tp)
  1581. $LD $a7,$SIZE_T*8($tp)
  1582. beq .Lsqr8x_tail_break
  1583. addc $acc0,$acc0,$a0
  1584. $LD $a0,$SIZE_T*1($np)
  1585. adde $acc1,$acc1,$a1
  1586. $LD $a1,$SIZE_T*2($np)
  1587. adde $acc2,$acc2,$a2
  1588. $LD $a2,$SIZE_T*3($np)
  1589. adde $acc3,$acc3,$a3
  1590. $LD $a3,$SIZE_T*4($np)
  1591. adde $acc4,$acc4,$a4
  1592. $LD $a4,$SIZE_T*5($np)
  1593. adde $acc5,$acc5,$a5
  1594. $LD $a5,$SIZE_T*6($np)
  1595. adde $acc6,$acc6,$a6
  1596. $LD $a6,$SIZE_T*7($np)
  1597. adde $acc7,$acc7,$a7
  1598. $LDU $a7,$SIZE_T*8($np)
  1599. #addze $carry,$zero # moved above
  1600. b .Lsqr8x_tail
  1601. .align 5
  1602. .Lsqr8x_tail_break:
  1603. $POP $n0,$SIZE_T*8($sp) # pull n0
  1604. $POP $t3,$SIZE_T*9($sp) # &tp[2*num-1]
  1605. addi $cnt,$tp,$SIZE_T*8 # end of current t[num] window
  1606. addic $carry,$carry,-1 # "move" top-most carry to carry bit
  1607. adde $t0,$acc0,$a0
  1608. $LD $acc0,$SIZE_T*8($rp)
  1609. $LD $a0,$SIZE_T*1($t2) # recall that $t2 is &n[-1]
  1610. adde $t1,$acc1,$a1
  1611. $LD $acc1,$SIZE_T*9($rp)
  1612. $LD $a1,$SIZE_T*2($t2)
  1613. adde $acc2,$acc2,$a2
  1614. $LD $a2,$SIZE_T*3($t2)
  1615. adde $acc3,$acc3,$a3
  1616. $LD $a3,$SIZE_T*4($t2)
  1617. adde $acc4,$acc4,$a4
  1618. $LD $a4,$SIZE_T*5($t2)
  1619. adde $acc5,$acc5,$a5
  1620. $LD $a5,$SIZE_T*6($t2)
  1621. adde $acc6,$acc6,$a6
  1622. $LD $a6,$SIZE_T*7($t2)
  1623. adde $acc7,$acc7,$a7
  1624. $LD $a7,$SIZE_T*8($t2)
  1625. addi $np,$t2,$SIZE_T*8
  1626. addze $t2,$zero # top-most carry
  1627. $UMULL $na0,$n0,$acc0
  1628. $ST $t0,$SIZE_T*1($tp)
  1629. $UCMP $cnt,$t3 # did we hit the bottom?
  1630. $ST $t1,$SIZE_T*2($tp)
  1631. li $cnt,8
  1632. $ST $acc2,$SIZE_T*3($tp)
  1633. $LD $acc2,$SIZE_T*10($rp)
  1634. $ST $acc3,$SIZE_T*4($tp)
  1635. $LD $acc3,$SIZE_T*11($rp)
  1636. $ST $acc4,$SIZE_T*5($tp)
  1637. $LD $acc4,$SIZE_T*12($rp)
  1638. $ST $acc5,$SIZE_T*6($tp)
  1639. $LD $acc5,$SIZE_T*13($rp)
  1640. $ST $acc6,$SIZE_T*7($tp)
  1641. $LD $acc6,$SIZE_T*14($rp)
  1642. $ST $acc7,$SIZE_T*8($tp)
  1643. $LD $acc7,$SIZE_T*15($rp)
  1644. $PUSH $t2,$SIZE_T*10($sp) # off-load top-most carry
  1645. addi $tp,$rp,$SIZE_T*7 # slide the window
  1646. mtctr $cnt
  1647. bne .Lsqr8x_reduction
  1648. ################################################################
  1649. # Final step. We see if result is larger than modulus, and
  1650. # if it is, subtract the modulus. But comparison implies
  1651. # subtraction. So we subtract modulus, see if it borrowed,
  1652. # and conditionally copy original value.
  1653. $POP $rp,$SIZE_T*6($sp) # pull &rp[-1]
  1654. srwi $cnt,$num,`log($SIZE_T)/log(2)+3`
  1655. mr $n0,$tp # put tp aside
  1656. addi $tp,$tp,$SIZE_T*8
  1657. subi $cnt,$cnt,1
  1658. subfc $t0,$a0,$acc0
  1659. subfe $t1,$a1,$acc1
  1660. mr $carry,$t2
  1661. mr $ap_end,$rp # $rp copy
  1662. mtctr $cnt
  1663. b .Lsqr8x_sub
  1664. .align 5
  1665. .Lsqr8x_sub:
  1666. $LD $a0,$SIZE_T*1($np)
  1667. $LD $acc0,$SIZE_T*1($tp)
  1668. $LD $a1,$SIZE_T*2($np)
  1669. $LD $acc1,$SIZE_T*2($tp)
  1670. subfe $t2,$a2,$acc2
  1671. $LD $a2,$SIZE_T*3($np)
  1672. $LD $acc2,$SIZE_T*3($tp)
  1673. subfe $t3,$a3,$acc3
  1674. $LD $a3,$SIZE_T*4($np)
  1675. $LD $acc3,$SIZE_T*4($tp)
  1676. $ST $t0,$SIZE_T*1($rp)
  1677. subfe $t0,$a4,$acc4
  1678. $LD $a4,$SIZE_T*5($np)
  1679. $LD $acc4,$SIZE_T*5($tp)
  1680. $ST $t1,$SIZE_T*2($rp)
  1681. subfe $t1,$a5,$acc5
  1682. $LD $a5,$SIZE_T*6($np)
  1683. $LD $acc5,$SIZE_T*6($tp)
  1684. $ST $t2,$SIZE_T*3($rp)
  1685. subfe $t2,$a6,$acc6
  1686. $LD $a6,$SIZE_T*7($np)
  1687. $LD $acc6,$SIZE_T*7($tp)
  1688. $ST $t3,$SIZE_T*4($rp)
  1689. subfe $t3,$a7,$acc7
  1690. $LDU $a7,$SIZE_T*8($np)
  1691. $LDU $acc7,$SIZE_T*8($tp)
  1692. $ST $t0,$SIZE_T*5($rp)
  1693. subfe $t0,$a0,$acc0
  1694. $ST $t1,$SIZE_T*6($rp)
  1695. subfe $t1,$a1,$acc1
  1696. $ST $t2,$SIZE_T*7($rp)
  1697. $STU $t3,$SIZE_T*8($rp)
  1698. bdnz .Lsqr8x_sub
  1699. srwi $cnt,$num,`log($SIZE_T)/log(2)+2`
  1700. $LD $a0,$SIZE_T*1($ap_end) # original $rp
  1701. $LD $acc0,$SIZE_T*1($n0) # original $tp
  1702. subi $cnt,$cnt,1
  1703. $LD $a1,$SIZE_T*2($ap_end)
  1704. $LD $acc1,$SIZE_T*2($n0)
  1705. subfe $t2,$a2,$acc2
  1706. $LD $a2,$SIZE_T*3($ap_end)
  1707. $LD $acc2,$SIZE_T*3($n0)
  1708. subfe $t3,$a3,$acc3
  1709. $LD $a3,$SIZE_T*4($ap_end)
  1710. $LDU $acc3,$SIZE_T*4($n0)
  1711. $ST $t0,$SIZE_T*1($rp)
  1712. subfe $t0,$a4,$acc4
  1713. $ST $t1,$SIZE_T*2($rp)
  1714. subfe $t1,$a5,$acc5
  1715. $ST $t2,$SIZE_T*3($rp)
  1716. subfe $t2,$a6,$acc6
  1717. $ST $t3,$SIZE_T*4($rp)
  1718. subfe $t3,$a7,$acc7
  1719. $ST $t0,$SIZE_T*5($rp)
  1720. subfe $carry,$zero,$carry # did it borrow?
  1721. $ST $t1,$SIZE_T*6($rp)
  1722. $ST $t2,$SIZE_T*7($rp)
  1723. $ST $t3,$SIZE_T*8($rp)
  1724. addi $tp,$sp,$SIZE_T*11
  1725. mtctr $cnt
  1726. .Lsqr4x_cond_copy:
  1727. andc $a0,$a0,$carry
  1728. $ST $zero,-$SIZE_T*3($n0) # wipe stack clean
  1729. and $acc0,$acc0,$carry
  1730. $ST $zero,-$SIZE_T*2($n0)
  1731. andc $a1,$a1,$carry
  1732. $ST $zero,-$SIZE_T*1($n0)
  1733. and $acc1,$acc1,$carry
  1734. $ST $zero,-$SIZE_T*0($n0)
  1735. andc $a2,$a2,$carry
  1736. $ST $zero,$SIZE_T*1($tp)
  1737. and $acc2,$acc2,$carry
  1738. $ST $zero,$SIZE_T*2($tp)
  1739. andc $a3,$a3,$carry
  1740. $ST $zero,$SIZE_T*3($tp)
  1741. and $acc3,$acc3,$carry
  1742. $STU $zero,$SIZE_T*4($tp)
  1743. or $t0,$a0,$acc0
  1744. $LD $a0,$SIZE_T*5($ap_end)
  1745. $LD $acc0,$SIZE_T*1($n0)
  1746. or $t1,$a1,$acc1
  1747. $LD $a1,$SIZE_T*6($ap_end)
  1748. $LD $acc1,$SIZE_T*2($n0)
  1749. or $t2,$a2,$acc2
  1750. $LD $a2,$SIZE_T*7($ap_end)
  1751. $LD $acc2,$SIZE_T*3($n0)
  1752. or $t3,$a3,$acc3
  1753. $LD $a3,$SIZE_T*8($ap_end)
  1754. $LDU $acc3,$SIZE_T*4($n0)
  1755. $ST $t0,$SIZE_T*1($ap_end)
  1756. $ST $t1,$SIZE_T*2($ap_end)
  1757. $ST $t2,$SIZE_T*3($ap_end)
  1758. $STU $t3,$SIZE_T*4($ap_end)
  1759. bdnz .Lsqr4x_cond_copy
  1760. $POP $ap,0($sp) # pull saved sp
  1761. andc $a0,$a0,$carry
  1762. and $acc0,$acc0,$carry
  1763. andc $a1,$a1,$carry
  1764. and $acc1,$acc1,$carry
  1765. andc $a2,$a2,$carry
  1766. and $acc2,$acc2,$carry
  1767. andc $a3,$a3,$carry
  1768. and $acc3,$acc3,$carry
  1769. or $t0,$a0,$acc0
  1770. or $t1,$a1,$acc1
  1771. or $t2,$a2,$acc2
  1772. or $t3,$a3,$acc3
  1773. $ST $t0,$SIZE_T*1($ap_end)
  1774. $ST $t1,$SIZE_T*2($ap_end)
  1775. $ST $t2,$SIZE_T*3($ap_end)
  1776. $ST $t3,$SIZE_T*4($ap_end)
  1777. b .Lsqr8x_done
  1778. .align 5
  1779. .Lsqr8x8_post_condition:
  1780. $POP $rp,$SIZE_T*6($sp) # pull rp
  1781. $POP $ap,0($sp) # pull saved sp
  1782. addze $carry,$zero
  1783. # $acc0-7,$carry hold result, $a0-7 hold modulus
  1784. subfc $acc0,$a0,$acc0
  1785. subfe $acc1,$a1,$acc1
  1786. $ST $zero,$SIZE_T*12($sp) # wipe stack clean
  1787. $ST $zero,$SIZE_T*13($sp)
  1788. subfe $acc2,$a2,$acc2
  1789. $ST $zero,$SIZE_T*14($sp)
  1790. $ST $zero,$SIZE_T*15($sp)
  1791. subfe $acc3,$a3,$acc3
  1792. $ST $zero,$SIZE_T*16($sp)
  1793. $ST $zero,$SIZE_T*17($sp)
  1794. subfe $acc4,$a4,$acc4
  1795. $ST $zero,$SIZE_T*18($sp)
  1796. $ST $zero,$SIZE_T*19($sp)
  1797. subfe $acc5,$a5,$acc5
  1798. $ST $zero,$SIZE_T*20($sp)
  1799. $ST $zero,$SIZE_T*21($sp)
  1800. subfe $acc6,$a6,$acc6
  1801. $ST $zero,$SIZE_T*22($sp)
  1802. $ST $zero,$SIZE_T*23($sp)
  1803. subfe $acc7,$a7,$acc7
  1804. $ST $zero,$SIZE_T*24($sp)
  1805. $ST $zero,$SIZE_T*25($sp)
  1806. subfe $carry,$zero,$carry # did it borrow?
  1807. $ST $zero,$SIZE_T*26($sp)
  1808. $ST $zero,$SIZE_T*27($sp)
  1809. and $a0,$a0,$carry
  1810. and $a1,$a1,$carry
  1811. addc $acc0,$acc0,$a0 # add modulus back if borrowed
  1812. and $a2,$a2,$carry
  1813. adde $acc1,$acc1,$a1
  1814. and $a3,$a3,$carry
  1815. adde $acc2,$acc2,$a2
  1816. and $a4,$a4,$carry
  1817. adde $acc3,$acc3,$a3
  1818. and $a5,$a5,$carry
  1819. adde $acc4,$acc4,$a4
  1820. and $a6,$a6,$carry
  1821. adde $acc5,$acc5,$a5
  1822. and $a7,$a7,$carry
  1823. adde $acc6,$acc6,$a6
  1824. adde $acc7,$acc7,$a7
  1825. $ST $acc0,$SIZE_T*1($rp)
  1826. $ST $acc1,$SIZE_T*2($rp)
  1827. $ST $acc2,$SIZE_T*3($rp)
  1828. $ST $acc3,$SIZE_T*4($rp)
  1829. $ST $acc4,$SIZE_T*5($rp)
  1830. $ST $acc5,$SIZE_T*6($rp)
  1831. $ST $acc6,$SIZE_T*7($rp)
  1832. $ST $acc7,$SIZE_T*8($rp)
  1833. .Lsqr8x_done:
  1834. $PUSH $zero,$SIZE_T*8($sp)
  1835. $PUSH $zero,$SIZE_T*10($sp)
  1836. $POP r14,-$SIZE_T*18($ap)
  1837. li r3,1 # signal "done"
  1838. $POP r15,-$SIZE_T*17($ap)
  1839. $POP r16,-$SIZE_T*16($ap)
  1840. $POP r17,-$SIZE_T*15($ap)
  1841. $POP r18,-$SIZE_T*14($ap)
  1842. $POP r19,-$SIZE_T*13($ap)
  1843. $POP r20,-$SIZE_T*12($ap)
  1844. $POP r21,-$SIZE_T*11($ap)
  1845. $POP r22,-$SIZE_T*10($ap)
  1846. $POP r23,-$SIZE_T*9($ap)
  1847. $POP r24,-$SIZE_T*8($ap)
  1848. $POP r25,-$SIZE_T*7($ap)
  1849. $POP r26,-$SIZE_T*6($ap)
  1850. $POP r27,-$SIZE_T*5($ap)
  1851. $POP r28,-$SIZE_T*4($ap)
  1852. $POP r29,-$SIZE_T*3($ap)
  1853. $POP r30,-$SIZE_T*2($ap)
  1854. $POP r31,-$SIZE_T*1($ap)
  1855. mr $sp,$ap
  1856. blr
  1857. .long 0
  1858. .byte 0,12,4,0x20,0x80,18,6,0
  1859. .long 0
  1860. .size __bn_sqr8x_mont,.-__bn_sqr8x_mont
  1861. ___
  1862. }
  1863. $code.=<<___;
  1864. .asciz "Montgomery Multiplication for PPC, CRYPTOGAMS by <appro\@openssl.org>"
  1865. ___
  1866. $code =~ s/\`([^\`]*)\`/eval $1/gem;
  1867. print $code;
  1868. close STDOUT;