aesni-x86.pl 100 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415
  1. #! /usr/bin/env perl
  2. # Copyright 2009-2016 The OpenSSL Project Authors. All Rights Reserved.
  3. #
  4. # Licensed under the OpenSSL license (the "License"). You may not use
  5. # this file except in compliance with the License. You can obtain a copy
  6. # in the file LICENSE in the source distribution or at
  7. # https://www.openssl.org/source/license.html
  8. # ====================================================================
  9. # Written by Andy Polyakov <appro@openssl.org> for the OpenSSL
  10. # project. The module is, however, dual licensed under OpenSSL and
  11. # CRYPTOGAMS licenses depending on where you obtain it. For further
  12. # details see http://www.openssl.org/~appro/cryptogams/.
  13. # ====================================================================
  14. #
  15. # This module implements support for Intel AES-NI extension. In
  16. # OpenSSL context it's used with Intel engine, but can also be used as
  17. # drop-in replacement for crypto/aes/asm/aes-586.pl [see below for
  18. # details].
  19. #
  20. # Performance.
  21. #
  22. # To start with see corresponding paragraph in aesni-x86_64.pl...
  23. # Instead of filling table similar to one found there I've chosen to
  24. # summarize *comparison* results for raw ECB, CTR and CBC benchmarks.
  25. # The simplified table below represents 32-bit performance relative
  26. # to 64-bit one in every given point. Ratios vary for different
  27. # encryption modes, therefore interval values.
  28. #
  29. # 16-byte 64-byte 256-byte 1-KB 8-KB
  30. # 53-67% 67-84% 91-94% 95-98% 97-99.5%
  31. #
  32. # Lower ratios for smaller block sizes are perfectly understandable,
  33. # because function call overhead is higher in 32-bit mode. Largest
  34. # 8-KB block performance is virtually same: 32-bit code is less than
  35. # 1% slower for ECB, CBC and CCM, and ~3% slower otherwise.
  36. # January 2011
  37. #
  38. # See aesni-x86_64.pl for details. Unlike x86_64 version this module
  39. # interleaves at most 6 aes[enc|dec] instructions, because there are
  40. # not enough registers for 8x interleave [which should be optimal for
  41. # Sandy Bridge]. Actually, performance results for 6x interleave
  42. # factor presented in aesni-x86_64.pl (except for CTR) are for this
  43. # module.
  44. # April 2011
  45. #
  46. # Add aesni_xts_[en|de]crypt. Westmere spends 1.50 cycles processing
  47. # one byte out of 8KB with 128-bit key, Sandy Bridge - 1.09.
  48. # November 2015
  49. #
  50. # Add aesni_ocb_[en|de]crypt.
  51. ######################################################################
  52. # Current large-block performance in cycles per byte processed with
  53. # 128-bit key (less is better).
  54. #
  55. # CBC en-/decrypt CTR XTS ECB OCB
  56. # Westmere 3.77/1.37 1.37 1.52 1.27
  57. # * Bridge 5.07/0.98 0.99 1.09 0.91 1.10
  58. # Haswell 4.44/0.80 0.97 1.03 0.72 0.76
  59. # Skylake 2.68/0.65 0.65 0.66 0.64 0.66
  60. # Silvermont 5.77/3.56 3.67 4.03 3.46 4.03
  61. # Goldmont 3.84/1.39 1.39 1.63 1.31 1.70
  62. # Bulldozer 5.80/0.98 1.05 1.24 0.93 1.23
  63. $PREFIX="aesni"; # if $PREFIX is set to "AES", the script
  64. # generates drop-in replacement for
  65. # crypto/aes/asm/aes-586.pl:-)
  66. $inline=1; # inline _aesni_[en|de]crypt
  67. $0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1;
  68. push(@INC,"${dir}","${dir}../../perlasm");
  69. require "x86asm.pl";
  70. $output = pop;
  71. open OUT,">$output";
  72. *STDOUT=*OUT;
  73. &asm_init($ARGV[0]);
  74. &external_label("OPENSSL_ia32cap_P");
  75. &static_label("key_const");
  76. if ($PREFIX eq "aesni") { $movekey=\&movups; }
  77. else { $movekey=\&movups; }
  78. $len="eax";
  79. $rounds="ecx";
  80. $key="edx";
  81. $inp="esi";
  82. $out="edi";
  83. $rounds_="ebx"; # backup copy for $rounds
  84. $key_="ebp"; # backup copy for $key
  85. $rndkey0="xmm0";
  86. $rndkey1="xmm1";
  87. $inout0="xmm2";
  88. $inout1="xmm3";
  89. $inout2="xmm4";
  90. $inout3="xmm5"; $in1="xmm5";
  91. $inout4="xmm6"; $in0="xmm6";
  92. $inout5="xmm7"; $ivec="xmm7";
  93. # AESNI extension
  94. sub aeskeygenassist
  95. { my($dst,$src,$imm)=@_;
  96. if ("$dst:$src" =~ /xmm([0-7]):xmm([0-7])/)
  97. { &data_byte(0x66,0x0f,0x3a,0xdf,0xc0|($1<<3)|$2,$imm); }
  98. }
  99. sub aescommon
  100. { my($opcodelet,$dst,$src)=@_;
  101. if ("$dst:$src" =~ /xmm([0-7]):xmm([0-7])/)
  102. { &data_byte(0x66,0x0f,0x38,$opcodelet,0xc0|($1<<3)|$2);}
  103. }
  104. sub aesimc { aescommon(0xdb,@_); }
  105. sub aesenc { aescommon(0xdc,@_); }
  106. sub aesenclast { aescommon(0xdd,@_); }
  107. sub aesdec { aescommon(0xde,@_); }
  108. sub aesdeclast { aescommon(0xdf,@_); }
  109. # Inline version of internal aesni_[en|de]crypt1
  110. { my $sn;
  111. sub aesni_inline_generate1
  112. { my ($p,$inout,$ivec)=@_; $inout=$inout0 if (!defined($inout));
  113. $sn++;
  114. &$movekey ($rndkey0,&QWP(0,$key));
  115. &$movekey ($rndkey1,&QWP(16,$key));
  116. &xorps ($ivec,$rndkey0) if (defined($ivec));
  117. &lea ($key,&DWP(32,$key));
  118. &xorps ($inout,$ivec) if (defined($ivec));
  119. &xorps ($inout,$rndkey0) if (!defined($ivec));
  120. &set_label("${p}1_loop_$sn");
  121. eval"&aes${p} ($inout,$rndkey1)";
  122. &dec ($rounds);
  123. &$movekey ($rndkey1,&QWP(0,$key));
  124. &lea ($key,&DWP(16,$key));
  125. &jnz (&label("${p}1_loop_$sn"));
  126. eval"&aes${p}last ($inout,$rndkey1)";
  127. }}
  128. sub aesni_generate1 # fully unrolled loop
  129. { my ($p,$inout)=@_; $inout=$inout0 if (!defined($inout));
  130. &function_begin_B("_aesni_${p}rypt1");
  131. &movups ($rndkey0,&QWP(0,$key));
  132. &$movekey ($rndkey1,&QWP(0x10,$key));
  133. &xorps ($inout,$rndkey0);
  134. &$movekey ($rndkey0,&QWP(0x20,$key));
  135. &lea ($key,&DWP(0x30,$key));
  136. &cmp ($rounds,11);
  137. &jb (&label("${p}128"));
  138. &lea ($key,&DWP(0x20,$key));
  139. &je (&label("${p}192"));
  140. &lea ($key,&DWP(0x20,$key));
  141. eval"&aes${p} ($inout,$rndkey1)";
  142. &$movekey ($rndkey1,&QWP(-0x40,$key));
  143. eval"&aes${p} ($inout,$rndkey0)";
  144. &$movekey ($rndkey0,&QWP(-0x30,$key));
  145. &set_label("${p}192");
  146. eval"&aes${p} ($inout,$rndkey1)";
  147. &$movekey ($rndkey1,&QWP(-0x20,$key));
  148. eval"&aes${p} ($inout,$rndkey0)";
  149. &$movekey ($rndkey0,&QWP(-0x10,$key));
  150. &set_label("${p}128");
  151. eval"&aes${p} ($inout,$rndkey1)";
  152. &$movekey ($rndkey1,&QWP(0,$key));
  153. eval"&aes${p} ($inout,$rndkey0)";
  154. &$movekey ($rndkey0,&QWP(0x10,$key));
  155. eval"&aes${p} ($inout,$rndkey1)";
  156. &$movekey ($rndkey1,&QWP(0x20,$key));
  157. eval"&aes${p} ($inout,$rndkey0)";
  158. &$movekey ($rndkey0,&QWP(0x30,$key));
  159. eval"&aes${p} ($inout,$rndkey1)";
  160. &$movekey ($rndkey1,&QWP(0x40,$key));
  161. eval"&aes${p} ($inout,$rndkey0)";
  162. &$movekey ($rndkey0,&QWP(0x50,$key));
  163. eval"&aes${p} ($inout,$rndkey1)";
  164. &$movekey ($rndkey1,&QWP(0x60,$key));
  165. eval"&aes${p} ($inout,$rndkey0)";
  166. &$movekey ($rndkey0,&QWP(0x70,$key));
  167. eval"&aes${p} ($inout,$rndkey1)";
  168. eval"&aes${p}last ($inout,$rndkey0)";
  169. &ret();
  170. &function_end_B("_aesni_${p}rypt1");
  171. }
  172. # void $PREFIX_encrypt (const void *inp,void *out,const AES_KEY *key);
  173. &aesni_generate1("enc") if (!$inline);
  174. &function_begin_B("${PREFIX}_encrypt");
  175. &mov ("eax",&wparam(0));
  176. &mov ($key,&wparam(2));
  177. &movups ($inout0,&QWP(0,"eax"));
  178. &mov ($rounds,&DWP(240,$key));
  179. &mov ("eax",&wparam(1));
  180. if ($inline)
  181. { &aesni_inline_generate1("enc"); }
  182. else
  183. { &call ("_aesni_encrypt1"); }
  184. &pxor ($rndkey0,$rndkey0); # clear register bank
  185. &pxor ($rndkey1,$rndkey1);
  186. &movups (&QWP(0,"eax"),$inout0);
  187. &pxor ($inout0,$inout0);
  188. &ret ();
  189. &function_end_B("${PREFIX}_encrypt");
  190. # void $PREFIX_decrypt (const void *inp,void *out,const AES_KEY *key);
  191. &aesni_generate1("dec") if(!$inline);
  192. &function_begin_B("${PREFIX}_decrypt");
  193. &mov ("eax",&wparam(0));
  194. &mov ($key,&wparam(2));
  195. &movups ($inout0,&QWP(0,"eax"));
  196. &mov ($rounds,&DWP(240,$key));
  197. &mov ("eax",&wparam(1));
  198. if ($inline)
  199. { &aesni_inline_generate1("dec"); }
  200. else
  201. { &call ("_aesni_decrypt1"); }
  202. &pxor ($rndkey0,$rndkey0); # clear register bank
  203. &pxor ($rndkey1,$rndkey1);
  204. &movups (&QWP(0,"eax"),$inout0);
  205. &pxor ($inout0,$inout0);
  206. &ret ();
  207. &function_end_B("${PREFIX}_decrypt");
  208. # _aesni_[en|de]cryptN are private interfaces, N denotes interleave
  209. # factor. Why 3x subroutine were originally used in loops? Even though
  210. # aes[enc|dec] latency was originally 6, it could be scheduled only
  211. # every *2nd* cycle. Thus 3x interleave was the one providing optimal
  212. # utilization, i.e. when subroutine's throughput is virtually same as
  213. # of non-interleaved subroutine [for number of input blocks up to 3].
  214. # This is why it originally made no sense to implement 2x subroutine.
  215. # But times change and it became appropriate to spend extra 192 bytes
  216. # on 2x subroutine on Atom Silvermont account. For processors that
  217. # can schedule aes[enc|dec] every cycle optimal interleave factor
  218. # equals to corresponding instructions latency. 8x is optimal for
  219. # * Bridge, but it's unfeasible to accommodate such implementation
  220. # in XMM registers addressable in 32-bit mode and therefore maximum
  221. # of 6x is used instead...
  222. sub aesni_generate2
  223. { my $p=shift;
  224. &function_begin_B("_aesni_${p}rypt2");
  225. &$movekey ($rndkey0,&QWP(0,$key));
  226. &shl ($rounds,4);
  227. &$movekey ($rndkey1,&QWP(16,$key));
  228. &xorps ($inout0,$rndkey0);
  229. &pxor ($inout1,$rndkey0);
  230. &$movekey ($rndkey0,&QWP(32,$key));
  231. &lea ($key,&DWP(32,$key,$rounds));
  232. &neg ($rounds);
  233. &add ($rounds,16);
  234. &set_label("${p}2_loop");
  235. eval"&aes${p} ($inout0,$rndkey1)";
  236. eval"&aes${p} ($inout1,$rndkey1)";
  237. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  238. &add ($rounds,32);
  239. eval"&aes${p} ($inout0,$rndkey0)";
  240. eval"&aes${p} ($inout1,$rndkey0)";
  241. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  242. &jnz (&label("${p}2_loop"));
  243. eval"&aes${p} ($inout0,$rndkey1)";
  244. eval"&aes${p} ($inout1,$rndkey1)";
  245. eval"&aes${p}last ($inout0,$rndkey0)";
  246. eval"&aes${p}last ($inout1,$rndkey0)";
  247. &ret();
  248. &function_end_B("_aesni_${p}rypt2");
  249. }
  250. sub aesni_generate3
  251. { my $p=shift;
  252. &function_begin_B("_aesni_${p}rypt3");
  253. &$movekey ($rndkey0,&QWP(0,$key));
  254. &shl ($rounds,4);
  255. &$movekey ($rndkey1,&QWP(16,$key));
  256. &xorps ($inout0,$rndkey0);
  257. &pxor ($inout1,$rndkey0);
  258. &pxor ($inout2,$rndkey0);
  259. &$movekey ($rndkey0,&QWP(32,$key));
  260. &lea ($key,&DWP(32,$key,$rounds));
  261. &neg ($rounds);
  262. &add ($rounds,16);
  263. &set_label("${p}3_loop");
  264. eval"&aes${p} ($inout0,$rndkey1)";
  265. eval"&aes${p} ($inout1,$rndkey1)";
  266. eval"&aes${p} ($inout2,$rndkey1)";
  267. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  268. &add ($rounds,32);
  269. eval"&aes${p} ($inout0,$rndkey0)";
  270. eval"&aes${p} ($inout1,$rndkey0)";
  271. eval"&aes${p} ($inout2,$rndkey0)";
  272. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  273. &jnz (&label("${p}3_loop"));
  274. eval"&aes${p} ($inout0,$rndkey1)";
  275. eval"&aes${p} ($inout1,$rndkey1)";
  276. eval"&aes${p} ($inout2,$rndkey1)";
  277. eval"&aes${p}last ($inout0,$rndkey0)";
  278. eval"&aes${p}last ($inout1,$rndkey0)";
  279. eval"&aes${p}last ($inout2,$rndkey0)";
  280. &ret();
  281. &function_end_B("_aesni_${p}rypt3");
  282. }
  283. # 4x interleave is implemented to improve small block performance,
  284. # most notably [and naturally] 4 block by ~30%. One can argue that one
  285. # should have implemented 5x as well, but improvement would be <20%,
  286. # so it's not worth it...
  287. sub aesni_generate4
  288. { my $p=shift;
  289. &function_begin_B("_aesni_${p}rypt4");
  290. &$movekey ($rndkey0,&QWP(0,$key));
  291. &$movekey ($rndkey1,&QWP(16,$key));
  292. &shl ($rounds,4);
  293. &xorps ($inout0,$rndkey0);
  294. &pxor ($inout1,$rndkey0);
  295. &pxor ($inout2,$rndkey0);
  296. &pxor ($inout3,$rndkey0);
  297. &$movekey ($rndkey0,&QWP(32,$key));
  298. &lea ($key,&DWP(32,$key,$rounds));
  299. &neg ($rounds);
  300. &data_byte (0x0f,0x1f,0x40,0x00);
  301. &add ($rounds,16);
  302. &set_label("${p}4_loop");
  303. eval"&aes${p} ($inout0,$rndkey1)";
  304. eval"&aes${p} ($inout1,$rndkey1)";
  305. eval"&aes${p} ($inout2,$rndkey1)";
  306. eval"&aes${p} ($inout3,$rndkey1)";
  307. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  308. &add ($rounds,32);
  309. eval"&aes${p} ($inout0,$rndkey0)";
  310. eval"&aes${p} ($inout1,$rndkey0)";
  311. eval"&aes${p} ($inout2,$rndkey0)";
  312. eval"&aes${p} ($inout3,$rndkey0)";
  313. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  314. &jnz (&label("${p}4_loop"));
  315. eval"&aes${p} ($inout0,$rndkey1)";
  316. eval"&aes${p} ($inout1,$rndkey1)";
  317. eval"&aes${p} ($inout2,$rndkey1)";
  318. eval"&aes${p} ($inout3,$rndkey1)";
  319. eval"&aes${p}last ($inout0,$rndkey0)";
  320. eval"&aes${p}last ($inout1,$rndkey0)";
  321. eval"&aes${p}last ($inout2,$rndkey0)";
  322. eval"&aes${p}last ($inout3,$rndkey0)";
  323. &ret();
  324. &function_end_B("_aesni_${p}rypt4");
  325. }
  326. sub aesni_generate6
  327. { my $p=shift;
  328. &function_begin_B("_aesni_${p}rypt6");
  329. &static_label("_aesni_${p}rypt6_enter");
  330. &$movekey ($rndkey0,&QWP(0,$key));
  331. &shl ($rounds,4);
  332. &$movekey ($rndkey1,&QWP(16,$key));
  333. &xorps ($inout0,$rndkey0);
  334. &pxor ($inout1,$rndkey0); # pxor does better here
  335. &pxor ($inout2,$rndkey0);
  336. eval"&aes${p} ($inout0,$rndkey1)";
  337. &pxor ($inout3,$rndkey0);
  338. &pxor ($inout4,$rndkey0);
  339. eval"&aes${p} ($inout1,$rndkey1)";
  340. &lea ($key,&DWP(32,$key,$rounds));
  341. &neg ($rounds);
  342. eval"&aes${p} ($inout2,$rndkey1)";
  343. &pxor ($inout5,$rndkey0);
  344. &$movekey ($rndkey0,&QWP(0,$key,$rounds));
  345. &add ($rounds,16);
  346. &jmp (&label("_aesni_${p}rypt6_inner"));
  347. &set_label("${p}6_loop",16);
  348. eval"&aes${p} ($inout0,$rndkey1)";
  349. eval"&aes${p} ($inout1,$rndkey1)";
  350. eval"&aes${p} ($inout2,$rndkey1)";
  351. &set_label("_aesni_${p}rypt6_inner");
  352. eval"&aes${p} ($inout3,$rndkey1)";
  353. eval"&aes${p} ($inout4,$rndkey1)";
  354. eval"&aes${p} ($inout5,$rndkey1)";
  355. &set_label("_aesni_${p}rypt6_enter");
  356. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  357. &add ($rounds,32);
  358. eval"&aes${p} ($inout0,$rndkey0)";
  359. eval"&aes${p} ($inout1,$rndkey0)";
  360. eval"&aes${p} ($inout2,$rndkey0)";
  361. eval"&aes${p} ($inout3,$rndkey0)";
  362. eval"&aes${p} ($inout4,$rndkey0)";
  363. eval"&aes${p} ($inout5,$rndkey0)";
  364. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  365. &jnz (&label("${p}6_loop"));
  366. eval"&aes${p} ($inout0,$rndkey1)";
  367. eval"&aes${p} ($inout1,$rndkey1)";
  368. eval"&aes${p} ($inout2,$rndkey1)";
  369. eval"&aes${p} ($inout3,$rndkey1)";
  370. eval"&aes${p} ($inout4,$rndkey1)";
  371. eval"&aes${p} ($inout5,$rndkey1)";
  372. eval"&aes${p}last ($inout0,$rndkey0)";
  373. eval"&aes${p}last ($inout1,$rndkey0)";
  374. eval"&aes${p}last ($inout2,$rndkey0)";
  375. eval"&aes${p}last ($inout3,$rndkey0)";
  376. eval"&aes${p}last ($inout4,$rndkey0)";
  377. eval"&aes${p}last ($inout5,$rndkey0)";
  378. &ret();
  379. &function_end_B("_aesni_${p}rypt6");
  380. }
  381. &aesni_generate2("enc") if ($PREFIX eq "aesni");
  382. &aesni_generate2("dec");
  383. &aesni_generate3("enc") if ($PREFIX eq "aesni");
  384. &aesni_generate3("dec");
  385. &aesni_generate4("enc") if ($PREFIX eq "aesni");
  386. &aesni_generate4("dec");
  387. &aesni_generate6("enc") if ($PREFIX eq "aesni");
  388. &aesni_generate6("dec");
  389. if ($PREFIX eq "aesni") {
  390. ######################################################################
  391. # void aesni_ecb_encrypt (const void *in, void *out,
  392. # size_t length, const AES_KEY *key,
  393. # int enc);
  394. &function_begin("aesni_ecb_encrypt");
  395. &mov ($inp,&wparam(0));
  396. &mov ($out,&wparam(1));
  397. &mov ($len,&wparam(2));
  398. &mov ($key,&wparam(3));
  399. &mov ($rounds_,&wparam(4));
  400. &and ($len,-16);
  401. &jz (&label("ecb_ret"));
  402. &mov ($rounds,&DWP(240,$key));
  403. &test ($rounds_,$rounds_);
  404. &jz (&label("ecb_decrypt"));
  405. &mov ($key_,$key); # backup $key
  406. &mov ($rounds_,$rounds); # backup $rounds
  407. &cmp ($len,0x60);
  408. &jb (&label("ecb_enc_tail"));
  409. &movdqu ($inout0,&QWP(0,$inp));
  410. &movdqu ($inout1,&QWP(0x10,$inp));
  411. &movdqu ($inout2,&QWP(0x20,$inp));
  412. &movdqu ($inout3,&QWP(0x30,$inp));
  413. &movdqu ($inout4,&QWP(0x40,$inp));
  414. &movdqu ($inout5,&QWP(0x50,$inp));
  415. &lea ($inp,&DWP(0x60,$inp));
  416. &sub ($len,0x60);
  417. &jmp (&label("ecb_enc_loop6_enter"));
  418. &set_label("ecb_enc_loop6",16);
  419. &movups (&QWP(0,$out),$inout0);
  420. &movdqu ($inout0,&QWP(0,$inp));
  421. &movups (&QWP(0x10,$out),$inout1);
  422. &movdqu ($inout1,&QWP(0x10,$inp));
  423. &movups (&QWP(0x20,$out),$inout2);
  424. &movdqu ($inout2,&QWP(0x20,$inp));
  425. &movups (&QWP(0x30,$out),$inout3);
  426. &movdqu ($inout3,&QWP(0x30,$inp));
  427. &movups (&QWP(0x40,$out),$inout4);
  428. &movdqu ($inout4,&QWP(0x40,$inp));
  429. &movups (&QWP(0x50,$out),$inout5);
  430. &lea ($out,&DWP(0x60,$out));
  431. &movdqu ($inout5,&QWP(0x50,$inp));
  432. &lea ($inp,&DWP(0x60,$inp));
  433. &set_label("ecb_enc_loop6_enter");
  434. &call ("_aesni_encrypt6");
  435. &mov ($key,$key_); # restore $key
  436. &mov ($rounds,$rounds_); # restore $rounds
  437. &sub ($len,0x60);
  438. &jnc (&label("ecb_enc_loop6"));
  439. &movups (&QWP(0,$out),$inout0);
  440. &movups (&QWP(0x10,$out),$inout1);
  441. &movups (&QWP(0x20,$out),$inout2);
  442. &movups (&QWP(0x30,$out),$inout3);
  443. &movups (&QWP(0x40,$out),$inout4);
  444. &movups (&QWP(0x50,$out),$inout5);
  445. &lea ($out,&DWP(0x60,$out));
  446. &add ($len,0x60);
  447. &jz (&label("ecb_ret"));
  448. &set_label("ecb_enc_tail");
  449. &movups ($inout0,&QWP(0,$inp));
  450. &cmp ($len,0x20);
  451. &jb (&label("ecb_enc_one"));
  452. &movups ($inout1,&QWP(0x10,$inp));
  453. &je (&label("ecb_enc_two"));
  454. &movups ($inout2,&QWP(0x20,$inp));
  455. &cmp ($len,0x40);
  456. &jb (&label("ecb_enc_three"));
  457. &movups ($inout3,&QWP(0x30,$inp));
  458. &je (&label("ecb_enc_four"));
  459. &movups ($inout4,&QWP(0x40,$inp));
  460. &xorps ($inout5,$inout5);
  461. &call ("_aesni_encrypt6");
  462. &movups (&QWP(0,$out),$inout0);
  463. &movups (&QWP(0x10,$out),$inout1);
  464. &movups (&QWP(0x20,$out),$inout2);
  465. &movups (&QWP(0x30,$out),$inout3);
  466. &movups (&QWP(0x40,$out),$inout4);
  467. jmp (&label("ecb_ret"));
  468. &set_label("ecb_enc_one",16);
  469. if ($inline)
  470. { &aesni_inline_generate1("enc"); }
  471. else
  472. { &call ("_aesni_encrypt1"); }
  473. &movups (&QWP(0,$out),$inout0);
  474. &jmp (&label("ecb_ret"));
  475. &set_label("ecb_enc_two",16);
  476. &call ("_aesni_encrypt2");
  477. &movups (&QWP(0,$out),$inout0);
  478. &movups (&QWP(0x10,$out),$inout1);
  479. &jmp (&label("ecb_ret"));
  480. &set_label("ecb_enc_three",16);
  481. &call ("_aesni_encrypt3");
  482. &movups (&QWP(0,$out),$inout0);
  483. &movups (&QWP(0x10,$out),$inout1);
  484. &movups (&QWP(0x20,$out),$inout2);
  485. &jmp (&label("ecb_ret"));
  486. &set_label("ecb_enc_four",16);
  487. &call ("_aesni_encrypt4");
  488. &movups (&QWP(0,$out),$inout0);
  489. &movups (&QWP(0x10,$out),$inout1);
  490. &movups (&QWP(0x20,$out),$inout2);
  491. &movups (&QWP(0x30,$out),$inout3);
  492. &jmp (&label("ecb_ret"));
  493. ######################################################################
  494. &set_label("ecb_decrypt",16);
  495. &mov ($key_,$key); # backup $key
  496. &mov ($rounds_,$rounds); # backup $rounds
  497. &cmp ($len,0x60);
  498. &jb (&label("ecb_dec_tail"));
  499. &movdqu ($inout0,&QWP(0,$inp));
  500. &movdqu ($inout1,&QWP(0x10,$inp));
  501. &movdqu ($inout2,&QWP(0x20,$inp));
  502. &movdqu ($inout3,&QWP(0x30,$inp));
  503. &movdqu ($inout4,&QWP(0x40,$inp));
  504. &movdqu ($inout5,&QWP(0x50,$inp));
  505. &lea ($inp,&DWP(0x60,$inp));
  506. &sub ($len,0x60);
  507. &jmp (&label("ecb_dec_loop6_enter"));
  508. &set_label("ecb_dec_loop6",16);
  509. &movups (&QWP(0,$out),$inout0);
  510. &movdqu ($inout0,&QWP(0,$inp));
  511. &movups (&QWP(0x10,$out),$inout1);
  512. &movdqu ($inout1,&QWP(0x10,$inp));
  513. &movups (&QWP(0x20,$out),$inout2);
  514. &movdqu ($inout2,&QWP(0x20,$inp));
  515. &movups (&QWP(0x30,$out),$inout3);
  516. &movdqu ($inout3,&QWP(0x30,$inp));
  517. &movups (&QWP(0x40,$out),$inout4);
  518. &movdqu ($inout4,&QWP(0x40,$inp));
  519. &movups (&QWP(0x50,$out),$inout5);
  520. &lea ($out,&DWP(0x60,$out));
  521. &movdqu ($inout5,&QWP(0x50,$inp));
  522. &lea ($inp,&DWP(0x60,$inp));
  523. &set_label("ecb_dec_loop6_enter");
  524. &call ("_aesni_decrypt6");
  525. &mov ($key,$key_); # restore $key
  526. &mov ($rounds,$rounds_); # restore $rounds
  527. &sub ($len,0x60);
  528. &jnc (&label("ecb_dec_loop6"));
  529. &movups (&QWP(0,$out),$inout0);
  530. &movups (&QWP(0x10,$out),$inout1);
  531. &movups (&QWP(0x20,$out),$inout2);
  532. &movups (&QWP(0x30,$out),$inout3);
  533. &movups (&QWP(0x40,$out),$inout4);
  534. &movups (&QWP(0x50,$out),$inout5);
  535. &lea ($out,&DWP(0x60,$out));
  536. &add ($len,0x60);
  537. &jz (&label("ecb_ret"));
  538. &set_label("ecb_dec_tail");
  539. &movups ($inout0,&QWP(0,$inp));
  540. &cmp ($len,0x20);
  541. &jb (&label("ecb_dec_one"));
  542. &movups ($inout1,&QWP(0x10,$inp));
  543. &je (&label("ecb_dec_two"));
  544. &movups ($inout2,&QWP(0x20,$inp));
  545. &cmp ($len,0x40);
  546. &jb (&label("ecb_dec_three"));
  547. &movups ($inout3,&QWP(0x30,$inp));
  548. &je (&label("ecb_dec_four"));
  549. &movups ($inout4,&QWP(0x40,$inp));
  550. &xorps ($inout5,$inout5);
  551. &call ("_aesni_decrypt6");
  552. &movups (&QWP(0,$out),$inout0);
  553. &movups (&QWP(0x10,$out),$inout1);
  554. &movups (&QWP(0x20,$out),$inout2);
  555. &movups (&QWP(0x30,$out),$inout3);
  556. &movups (&QWP(0x40,$out),$inout4);
  557. &jmp (&label("ecb_ret"));
  558. &set_label("ecb_dec_one",16);
  559. if ($inline)
  560. { &aesni_inline_generate1("dec"); }
  561. else
  562. { &call ("_aesni_decrypt1"); }
  563. &movups (&QWP(0,$out),$inout0);
  564. &jmp (&label("ecb_ret"));
  565. &set_label("ecb_dec_two",16);
  566. &call ("_aesni_decrypt2");
  567. &movups (&QWP(0,$out),$inout0);
  568. &movups (&QWP(0x10,$out),$inout1);
  569. &jmp (&label("ecb_ret"));
  570. &set_label("ecb_dec_three",16);
  571. &call ("_aesni_decrypt3");
  572. &movups (&QWP(0,$out),$inout0);
  573. &movups (&QWP(0x10,$out),$inout1);
  574. &movups (&QWP(0x20,$out),$inout2);
  575. &jmp (&label("ecb_ret"));
  576. &set_label("ecb_dec_four",16);
  577. &call ("_aesni_decrypt4");
  578. &movups (&QWP(0,$out),$inout0);
  579. &movups (&QWP(0x10,$out),$inout1);
  580. &movups (&QWP(0x20,$out),$inout2);
  581. &movups (&QWP(0x30,$out),$inout3);
  582. &set_label("ecb_ret");
  583. &pxor ("xmm0","xmm0"); # clear register bank
  584. &pxor ("xmm1","xmm1");
  585. &pxor ("xmm2","xmm2");
  586. &pxor ("xmm3","xmm3");
  587. &pxor ("xmm4","xmm4");
  588. &pxor ("xmm5","xmm5");
  589. &pxor ("xmm6","xmm6");
  590. &pxor ("xmm7","xmm7");
  591. &function_end("aesni_ecb_encrypt");
  592. ######################################################################
  593. # void aesni_ccm64_[en|de]crypt_blocks (const void *in, void *out,
  594. # size_t blocks, const AES_KEY *key,
  595. # const char *ivec,char *cmac);
  596. #
  597. # Handles only complete blocks, operates on 64-bit counter and
  598. # does not update *ivec! Nor does it finalize CMAC value
  599. # (see engine/eng_aesni.c for details)
  600. #
  601. { my $cmac=$inout1;
  602. &function_begin("aesni_ccm64_encrypt_blocks");
  603. &mov ($inp,&wparam(0));
  604. &mov ($out,&wparam(1));
  605. &mov ($len,&wparam(2));
  606. &mov ($key,&wparam(3));
  607. &mov ($rounds_,&wparam(4));
  608. &mov ($rounds,&wparam(5));
  609. &mov ($key_,"esp");
  610. &sub ("esp",60);
  611. &and ("esp",-16); # align stack
  612. &mov (&DWP(48,"esp"),$key_);
  613. &movdqu ($ivec,&QWP(0,$rounds_)); # load ivec
  614. &movdqu ($cmac,&QWP(0,$rounds)); # load cmac
  615. &mov ($rounds,&DWP(240,$key));
  616. # compose byte-swap control mask for pshufb on stack
  617. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  618. &mov (&DWP(4,"esp"),0x08090a0b);
  619. &mov (&DWP(8,"esp"),0x04050607);
  620. &mov (&DWP(12,"esp"),0x00010203);
  621. # compose counter increment vector on stack
  622. &mov ($rounds_,1);
  623. &xor ($key_,$key_);
  624. &mov (&DWP(16,"esp"),$rounds_);
  625. &mov (&DWP(20,"esp"),$key_);
  626. &mov (&DWP(24,"esp"),$key_);
  627. &mov (&DWP(28,"esp"),$key_);
  628. &shl ($rounds,4);
  629. &mov ($rounds_,16);
  630. &lea ($key_,&DWP(0,$key));
  631. &movdqa ($inout3,&QWP(0,"esp"));
  632. &movdqa ($inout0,$ivec);
  633. &lea ($key,&DWP(32,$key,$rounds));
  634. &sub ($rounds_,$rounds);
  635. &pshufb ($ivec,$inout3);
  636. &set_label("ccm64_enc_outer");
  637. &$movekey ($rndkey0,&QWP(0,$key_));
  638. &mov ($rounds,$rounds_);
  639. &movups ($in0,&QWP(0,$inp));
  640. &xorps ($inout0,$rndkey0);
  641. &$movekey ($rndkey1,&QWP(16,$key_));
  642. &xorps ($rndkey0,$in0);
  643. &xorps ($cmac,$rndkey0); # cmac^=inp
  644. &$movekey ($rndkey0,&QWP(32,$key_));
  645. &set_label("ccm64_enc2_loop");
  646. &aesenc ($inout0,$rndkey1);
  647. &aesenc ($cmac,$rndkey1);
  648. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  649. &add ($rounds,32);
  650. &aesenc ($inout0,$rndkey0);
  651. &aesenc ($cmac,$rndkey0);
  652. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  653. &jnz (&label("ccm64_enc2_loop"));
  654. &aesenc ($inout0,$rndkey1);
  655. &aesenc ($cmac,$rndkey1);
  656. &paddq ($ivec,&QWP(16,"esp"));
  657. &dec ($len);
  658. &aesenclast ($inout0,$rndkey0);
  659. &aesenclast ($cmac,$rndkey0);
  660. &lea ($inp,&DWP(16,$inp));
  661. &xorps ($in0,$inout0); # inp^=E(ivec)
  662. &movdqa ($inout0,$ivec);
  663. &movups (&QWP(0,$out),$in0); # save output
  664. &pshufb ($inout0,$inout3);
  665. &lea ($out,&DWP(16,$out));
  666. &jnz (&label("ccm64_enc_outer"));
  667. &mov ("esp",&DWP(48,"esp"));
  668. &mov ($out,&wparam(5));
  669. &movups (&QWP(0,$out),$cmac);
  670. &pxor ("xmm0","xmm0"); # clear register bank
  671. &pxor ("xmm1","xmm1");
  672. &pxor ("xmm2","xmm2");
  673. &pxor ("xmm3","xmm3");
  674. &pxor ("xmm4","xmm4");
  675. &pxor ("xmm5","xmm5");
  676. &pxor ("xmm6","xmm6");
  677. &pxor ("xmm7","xmm7");
  678. &function_end("aesni_ccm64_encrypt_blocks");
  679. &function_begin("aesni_ccm64_decrypt_blocks");
  680. &mov ($inp,&wparam(0));
  681. &mov ($out,&wparam(1));
  682. &mov ($len,&wparam(2));
  683. &mov ($key,&wparam(3));
  684. &mov ($rounds_,&wparam(4));
  685. &mov ($rounds,&wparam(5));
  686. &mov ($key_,"esp");
  687. &sub ("esp",60);
  688. &and ("esp",-16); # align stack
  689. &mov (&DWP(48,"esp"),$key_);
  690. &movdqu ($ivec,&QWP(0,$rounds_)); # load ivec
  691. &movdqu ($cmac,&QWP(0,$rounds)); # load cmac
  692. &mov ($rounds,&DWP(240,$key));
  693. # compose byte-swap control mask for pshufb on stack
  694. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  695. &mov (&DWP(4,"esp"),0x08090a0b);
  696. &mov (&DWP(8,"esp"),0x04050607);
  697. &mov (&DWP(12,"esp"),0x00010203);
  698. # compose counter increment vector on stack
  699. &mov ($rounds_,1);
  700. &xor ($key_,$key_);
  701. &mov (&DWP(16,"esp"),$rounds_);
  702. &mov (&DWP(20,"esp"),$key_);
  703. &mov (&DWP(24,"esp"),$key_);
  704. &mov (&DWP(28,"esp"),$key_);
  705. &movdqa ($inout3,&QWP(0,"esp")); # bswap mask
  706. &movdqa ($inout0,$ivec);
  707. &mov ($key_,$key);
  708. &mov ($rounds_,$rounds);
  709. &pshufb ($ivec,$inout3);
  710. if ($inline)
  711. { &aesni_inline_generate1("enc"); }
  712. else
  713. { &call ("_aesni_encrypt1"); }
  714. &shl ($rounds_,4);
  715. &mov ($rounds,16);
  716. &movups ($in0,&QWP(0,$inp)); # load inp
  717. &paddq ($ivec,&QWP(16,"esp"));
  718. &lea ($inp,&QWP(16,$inp));
  719. &sub ($rounds,$rounds_);
  720. &lea ($key,&DWP(32,$key_,$rounds_));
  721. &mov ($rounds_,$rounds);
  722. &jmp (&label("ccm64_dec_outer"));
  723. &set_label("ccm64_dec_outer",16);
  724. &xorps ($in0,$inout0); # inp ^= E(ivec)
  725. &movdqa ($inout0,$ivec);
  726. &movups (&QWP(0,$out),$in0); # save output
  727. &lea ($out,&DWP(16,$out));
  728. &pshufb ($inout0,$inout3);
  729. &sub ($len,1);
  730. &jz (&label("ccm64_dec_break"));
  731. &$movekey ($rndkey0,&QWP(0,$key_));
  732. &mov ($rounds,$rounds_);
  733. &$movekey ($rndkey1,&QWP(16,$key_));
  734. &xorps ($in0,$rndkey0);
  735. &xorps ($inout0,$rndkey0);
  736. &xorps ($cmac,$in0); # cmac^=out
  737. &$movekey ($rndkey0,&QWP(32,$key_));
  738. &set_label("ccm64_dec2_loop");
  739. &aesenc ($inout0,$rndkey1);
  740. &aesenc ($cmac,$rndkey1);
  741. &$movekey ($rndkey1,&QWP(0,$key,$rounds));
  742. &add ($rounds,32);
  743. &aesenc ($inout0,$rndkey0);
  744. &aesenc ($cmac,$rndkey0);
  745. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  746. &jnz (&label("ccm64_dec2_loop"));
  747. &movups ($in0,&QWP(0,$inp)); # load inp
  748. &paddq ($ivec,&QWP(16,"esp"));
  749. &aesenc ($inout0,$rndkey1);
  750. &aesenc ($cmac,$rndkey1);
  751. &aesenclast ($inout0,$rndkey0);
  752. &aesenclast ($cmac,$rndkey0);
  753. &lea ($inp,&QWP(16,$inp));
  754. &jmp (&label("ccm64_dec_outer"));
  755. &set_label("ccm64_dec_break",16);
  756. &mov ($rounds,&DWP(240,$key_));
  757. &mov ($key,$key_);
  758. if ($inline)
  759. { &aesni_inline_generate1("enc",$cmac,$in0); }
  760. else
  761. { &call ("_aesni_encrypt1",$cmac); }
  762. &mov ("esp",&DWP(48,"esp"));
  763. &mov ($out,&wparam(5));
  764. &movups (&QWP(0,$out),$cmac);
  765. &pxor ("xmm0","xmm0"); # clear register bank
  766. &pxor ("xmm1","xmm1");
  767. &pxor ("xmm2","xmm2");
  768. &pxor ("xmm3","xmm3");
  769. &pxor ("xmm4","xmm4");
  770. &pxor ("xmm5","xmm5");
  771. &pxor ("xmm6","xmm6");
  772. &pxor ("xmm7","xmm7");
  773. &function_end("aesni_ccm64_decrypt_blocks");
  774. }
  775. ######################################################################
  776. # void aesni_ctr32_encrypt_blocks (const void *in, void *out,
  777. # size_t blocks, const AES_KEY *key,
  778. # const char *ivec);
  779. #
  780. # Handles only complete blocks, operates on 32-bit counter and
  781. # does not update *ivec! (see crypto/modes/ctr128.c for details)
  782. #
  783. # stack layout:
  784. # 0 pshufb mask
  785. # 16 vector addend: 0,6,6,6
  786. # 32 counter-less ivec
  787. # 48 1st triplet of counter vector
  788. # 64 2nd triplet of counter vector
  789. # 80 saved %esp
  790. &function_begin("aesni_ctr32_encrypt_blocks");
  791. &mov ($inp,&wparam(0));
  792. &mov ($out,&wparam(1));
  793. &mov ($len,&wparam(2));
  794. &mov ($key,&wparam(3));
  795. &mov ($rounds_,&wparam(4));
  796. &mov ($key_,"esp");
  797. &sub ("esp",88);
  798. &and ("esp",-16); # align stack
  799. &mov (&DWP(80,"esp"),$key_);
  800. &cmp ($len,1);
  801. &je (&label("ctr32_one_shortcut"));
  802. &movdqu ($inout5,&QWP(0,$rounds_)); # load ivec
  803. # compose byte-swap control mask for pshufb on stack
  804. &mov (&DWP(0,"esp"),0x0c0d0e0f);
  805. &mov (&DWP(4,"esp"),0x08090a0b);
  806. &mov (&DWP(8,"esp"),0x04050607);
  807. &mov (&DWP(12,"esp"),0x00010203);
  808. # compose counter increment vector on stack
  809. &mov ($rounds,6);
  810. &xor ($key_,$key_);
  811. &mov (&DWP(16,"esp"),$rounds);
  812. &mov (&DWP(20,"esp"),$rounds);
  813. &mov (&DWP(24,"esp"),$rounds);
  814. &mov (&DWP(28,"esp"),$key_);
  815. &pextrd ($rounds_,$inout5,3); # pull 32-bit counter
  816. &pinsrd ($inout5,$key_,3); # wipe 32-bit counter
  817. &mov ($rounds,&DWP(240,$key)); # key->rounds
  818. # compose 2 vectors of 3x32-bit counters
  819. &bswap ($rounds_);
  820. &pxor ($rndkey0,$rndkey0);
  821. &pxor ($rndkey1,$rndkey1);
  822. &movdqa ($inout0,&QWP(0,"esp")); # load byte-swap mask
  823. &pinsrd ($rndkey0,$rounds_,0);
  824. &lea ($key_,&DWP(3,$rounds_));
  825. &pinsrd ($rndkey1,$key_,0);
  826. &inc ($rounds_);
  827. &pinsrd ($rndkey0,$rounds_,1);
  828. &inc ($key_);
  829. &pinsrd ($rndkey1,$key_,1);
  830. &inc ($rounds_);
  831. &pinsrd ($rndkey0,$rounds_,2);
  832. &inc ($key_);
  833. &pinsrd ($rndkey1,$key_,2);
  834. &movdqa (&QWP(48,"esp"),$rndkey0); # save 1st triplet
  835. &pshufb ($rndkey0,$inout0); # byte swap
  836. &movdqu ($inout4,&QWP(0,$key)); # key[0]
  837. &movdqa (&QWP(64,"esp"),$rndkey1); # save 2nd triplet
  838. &pshufb ($rndkey1,$inout0); # byte swap
  839. &pshufd ($inout0,$rndkey0,3<<6); # place counter to upper dword
  840. &pshufd ($inout1,$rndkey0,2<<6);
  841. &cmp ($len,6);
  842. &jb (&label("ctr32_tail"));
  843. &pxor ($inout5,$inout4); # counter-less ivec^key[0]
  844. &shl ($rounds,4);
  845. &mov ($rounds_,16);
  846. &movdqa (&QWP(32,"esp"),$inout5); # save counter-less ivec^key[0]
  847. &mov ($key_,$key); # backup $key
  848. &sub ($rounds_,$rounds); # backup twisted $rounds
  849. &lea ($key,&DWP(32,$key,$rounds));
  850. &sub ($len,6);
  851. &jmp (&label("ctr32_loop6"));
  852. &set_label("ctr32_loop6",16);
  853. # inlining _aesni_encrypt6's prologue gives ~6% improvement...
  854. &pshufd ($inout2,$rndkey0,1<<6);
  855. &movdqa ($rndkey0,&QWP(32,"esp")); # pull counter-less ivec
  856. &pshufd ($inout3,$rndkey1,3<<6);
  857. &pxor ($inout0,$rndkey0); # merge counter-less ivec
  858. &pshufd ($inout4,$rndkey1,2<<6);
  859. &pxor ($inout1,$rndkey0);
  860. &pshufd ($inout5,$rndkey1,1<<6);
  861. &$movekey ($rndkey1,&QWP(16,$key_));
  862. &pxor ($inout2,$rndkey0);
  863. &pxor ($inout3,$rndkey0);
  864. &aesenc ($inout0,$rndkey1);
  865. &pxor ($inout4,$rndkey0);
  866. &pxor ($inout5,$rndkey0);
  867. &aesenc ($inout1,$rndkey1);
  868. &$movekey ($rndkey0,&QWP(32,$key_));
  869. &mov ($rounds,$rounds_);
  870. &aesenc ($inout2,$rndkey1);
  871. &aesenc ($inout3,$rndkey1);
  872. &aesenc ($inout4,$rndkey1);
  873. &aesenc ($inout5,$rndkey1);
  874. &call (&label("_aesni_encrypt6_enter"));
  875. &movups ($rndkey1,&QWP(0,$inp));
  876. &movups ($rndkey0,&QWP(0x10,$inp));
  877. &xorps ($inout0,$rndkey1);
  878. &movups ($rndkey1,&QWP(0x20,$inp));
  879. &xorps ($inout1,$rndkey0);
  880. &movups (&QWP(0,$out),$inout0);
  881. &movdqa ($rndkey0,&QWP(16,"esp")); # load increment
  882. &xorps ($inout2,$rndkey1);
  883. &movdqa ($rndkey1,&QWP(64,"esp")); # load 2nd triplet
  884. &movups (&QWP(0x10,$out),$inout1);
  885. &movups (&QWP(0x20,$out),$inout2);
  886. &paddd ($rndkey1,$rndkey0); # 2nd triplet increment
  887. &paddd ($rndkey0,&QWP(48,"esp")); # 1st triplet increment
  888. &movdqa ($inout0,&QWP(0,"esp")); # load byte swap mask
  889. &movups ($inout1,&QWP(0x30,$inp));
  890. &movups ($inout2,&QWP(0x40,$inp));
  891. &xorps ($inout3,$inout1);
  892. &movups ($inout1,&QWP(0x50,$inp));
  893. &lea ($inp,&DWP(0x60,$inp));
  894. &movdqa (&QWP(48,"esp"),$rndkey0); # save 1st triplet
  895. &pshufb ($rndkey0,$inout0); # byte swap
  896. &xorps ($inout4,$inout2);
  897. &movups (&QWP(0x30,$out),$inout3);
  898. &xorps ($inout5,$inout1);
  899. &movdqa (&QWP(64,"esp"),$rndkey1); # save 2nd triplet
  900. &pshufb ($rndkey1,$inout0); # byte swap
  901. &movups (&QWP(0x40,$out),$inout4);
  902. &pshufd ($inout0,$rndkey0,3<<6);
  903. &movups (&QWP(0x50,$out),$inout5);
  904. &lea ($out,&DWP(0x60,$out));
  905. &pshufd ($inout1,$rndkey0,2<<6);
  906. &sub ($len,6);
  907. &jnc (&label("ctr32_loop6"));
  908. &add ($len,6);
  909. &jz (&label("ctr32_ret"));
  910. &movdqu ($inout5,&QWP(0,$key_));
  911. &mov ($key,$key_);
  912. &pxor ($inout5,&QWP(32,"esp")); # restore count-less ivec
  913. &mov ($rounds,&DWP(240,$key_)); # restore $rounds
  914. &set_label("ctr32_tail");
  915. &por ($inout0,$inout5);
  916. &cmp ($len,2);
  917. &jb (&label("ctr32_one"));
  918. &pshufd ($inout2,$rndkey0,1<<6);
  919. &por ($inout1,$inout5);
  920. &je (&label("ctr32_two"));
  921. &pshufd ($inout3,$rndkey1,3<<6);
  922. &por ($inout2,$inout5);
  923. &cmp ($len,4);
  924. &jb (&label("ctr32_three"));
  925. &pshufd ($inout4,$rndkey1,2<<6);
  926. &por ($inout3,$inout5);
  927. &je (&label("ctr32_four"));
  928. &por ($inout4,$inout5);
  929. &call ("_aesni_encrypt6");
  930. &movups ($rndkey1,&QWP(0,$inp));
  931. &movups ($rndkey0,&QWP(0x10,$inp));
  932. &xorps ($inout0,$rndkey1);
  933. &movups ($rndkey1,&QWP(0x20,$inp));
  934. &xorps ($inout1,$rndkey0);
  935. &movups ($rndkey0,&QWP(0x30,$inp));
  936. &xorps ($inout2,$rndkey1);
  937. &movups ($rndkey1,&QWP(0x40,$inp));
  938. &xorps ($inout3,$rndkey0);
  939. &movups (&QWP(0,$out),$inout0);
  940. &xorps ($inout4,$rndkey1);
  941. &movups (&QWP(0x10,$out),$inout1);
  942. &movups (&QWP(0x20,$out),$inout2);
  943. &movups (&QWP(0x30,$out),$inout3);
  944. &movups (&QWP(0x40,$out),$inout4);
  945. &jmp (&label("ctr32_ret"));
  946. &set_label("ctr32_one_shortcut",16);
  947. &movups ($inout0,&QWP(0,$rounds_)); # load ivec
  948. &mov ($rounds,&DWP(240,$key));
  949. &set_label("ctr32_one");
  950. if ($inline)
  951. { &aesni_inline_generate1("enc"); }
  952. else
  953. { &call ("_aesni_encrypt1"); }
  954. &movups ($in0,&QWP(0,$inp));
  955. &xorps ($in0,$inout0);
  956. &movups (&QWP(0,$out),$in0);
  957. &jmp (&label("ctr32_ret"));
  958. &set_label("ctr32_two",16);
  959. &call ("_aesni_encrypt2");
  960. &movups ($inout3,&QWP(0,$inp));
  961. &movups ($inout4,&QWP(0x10,$inp));
  962. &xorps ($inout0,$inout3);
  963. &xorps ($inout1,$inout4);
  964. &movups (&QWP(0,$out),$inout0);
  965. &movups (&QWP(0x10,$out),$inout1);
  966. &jmp (&label("ctr32_ret"));
  967. &set_label("ctr32_three",16);
  968. &call ("_aesni_encrypt3");
  969. &movups ($inout3,&QWP(0,$inp));
  970. &movups ($inout4,&QWP(0x10,$inp));
  971. &xorps ($inout0,$inout3);
  972. &movups ($inout5,&QWP(0x20,$inp));
  973. &xorps ($inout1,$inout4);
  974. &movups (&QWP(0,$out),$inout0);
  975. &xorps ($inout2,$inout5);
  976. &movups (&QWP(0x10,$out),$inout1);
  977. &movups (&QWP(0x20,$out),$inout2);
  978. &jmp (&label("ctr32_ret"));
  979. &set_label("ctr32_four",16);
  980. &call ("_aesni_encrypt4");
  981. &movups ($inout4,&QWP(0,$inp));
  982. &movups ($inout5,&QWP(0x10,$inp));
  983. &movups ($rndkey1,&QWP(0x20,$inp));
  984. &xorps ($inout0,$inout4);
  985. &movups ($rndkey0,&QWP(0x30,$inp));
  986. &xorps ($inout1,$inout5);
  987. &movups (&QWP(0,$out),$inout0);
  988. &xorps ($inout2,$rndkey1);
  989. &movups (&QWP(0x10,$out),$inout1);
  990. &xorps ($inout3,$rndkey0);
  991. &movups (&QWP(0x20,$out),$inout2);
  992. &movups (&QWP(0x30,$out),$inout3);
  993. &set_label("ctr32_ret");
  994. &pxor ("xmm0","xmm0"); # clear register bank
  995. &pxor ("xmm1","xmm1");
  996. &pxor ("xmm2","xmm2");
  997. &pxor ("xmm3","xmm3");
  998. &pxor ("xmm4","xmm4");
  999. &movdqa (&QWP(32,"esp"),"xmm0"); # clear stack
  1000. &pxor ("xmm5","xmm5");
  1001. &movdqa (&QWP(48,"esp"),"xmm0");
  1002. &pxor ("xmm6","xmm6");
  1003. &movdqa (&QWP(64,"esp"),"xmm0");
  1004. &pxor ("xmm7","xmm7");
  1005. &mov ("esp",&DWP(80,"esp"));
  1006. &function_end("aesni_ctr32_encrypt_blocks");
  1007. ######################################################################
  1008. # void aesni_xts_[en|de]crypt(const char *inp,char *out,size_t len,
  1009. # const AES_KEY *key1, const AES_KEY *key2
  1010. # const unsigned char iv[16]);
  1011. #
  1012. { my ($tweak,$twtmp,$twres,$twmask)=($rndkey1,$rndkey0,$inout0,$inout1);
  1013. &function_begin("aesni_xts_encrypt");
  1014. &mov ($key,&wparam(4)); # key2
  1015. &mov ($inp,&wparam(5)); # clear-text tweak
  1016. &mov ($rounds,&DWP(240,$key)); # key2->rounds
  1017. &movups ($inout0,&QWP(0,$inp));
  1018. if ($inline)
  1019. { &aesni_inline_generate1("enc"); }
  1020. else
  1021. { &call ("_aesni_encrypt1"); }
  1022. &mov ($inp,&wparam(0));
  1023. &mov ($out,&wparam(1));
  1024. &mov ($len,&wparam(2));
  1025. &mov ($key,&wparam(3)); # key1
  1026. &mov ($key_,"esp");
  1027. &sub ("esp",16*7+8);
  1028. &mov ($rounds,&DWP(240,$key)); # key1->rounds
  1029. &and ("esp",-16); # align stack
  1030. &mov (&DWP(16*6+0,"esp"),0x87); # compose the magic constant
  1031. &mov (&DWP(16*6+4,"esp"),0);
  1032. &mov (&DWP(16*6+8,"esp"),1);
  1033. &mov (&DWP(16*6+12,"esp"),0);
  1034. &mov (&DWP(16*7+0,"esp"),$len); # save original $len
  1035. &mov (&DWP(16*7+4,"esp"),$key_); # save original %esp
  1036. &movdqa ($tweak,$inout0);
  1037. &pxor ($twtmp,$twtmp);
  1038. &movdqa ($twmask,&QWP(6*16,"esp")); # 0x0...010...87
  1039. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1040. &and ($len,-16);
  1041. &mov ($key_,$key); # backup $key
  1042. &mov ($rounds_,$rounds); # backup $rounds
  1043. &sub ($len,16*6);
  1044. &jc (&label("xts_enc_short"));
  1045. &shl ($rounds,4);
  1046. &mov ($rounds_,16);
  1047. &sub ($rounds_,$rounds);
  1048. &lea ($key,&DWP(32,$key,$rounds));
  1049. &jmp (&label("xts_enc_loop6"));
  1050. &set_label("xts_enc_loop6",16);
  1051. for ($i=0;$i<4;$i++) {
  1052. &pshufd ($twres,$twtmp,0x13);
  1053. &pxor ($twtmp,$twtmp);
  1054. &movdqa (&QWP(16*$i,"esp"),$tweak);
  1055. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1056. &pand ($twres,$twmask); # isolate carry and residue
  1057. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1058. &pxor ($tweak,$twres);
  1059. }
  1060. &pshufd ($inout5,$twtmp,0x13);
  1061. &movdqa (&QWP(16*$i++,"esp"),$tweak);
  1062. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1063. &$movekey ($rndkey0,&QWP(0,$key_));
  1064. &pand ($inout5,$twmask); # isolate carry and residue
  1065. &movups ($inout0,&QWP(0,$inp)); # load input
  1066. &pxor ($inout5,$tweak);
  1067. # inline _aesni_encrypt6 prologue and flip xor with tweak and key[0]
  1068. &mov ($rounds,$rounds_); # restore $rounds
  1069. &movdqu ($inout1,&QWP(16*1,$inp));
  1070. &xorps ($inout0,$rndkey0); # input^=rndkey[0]
  1071. &movdqu ($inout2,&QWP(16*2,$inp));
  1072. &pxor ($inout1,$rndkey0);
  1073. &movdqu ($inout3,&QWP(16*3,$inp));
  1074. &pxor ($inout2,$rndkey0);
  1075. &movdqu ($inout4,&QWP(16*4,$inp));
  1076. &pxor ($inout3,$rndkey0);
  1077. &movdqu ($rndkey1,&QWP(16*5,$inp));
  1078. &pxor ($inout4,$rndkey0);
  1079. &lea ($inp,&DWP(16*6,$inp));
  1080. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1081. &movdqa (&QWP(16*$i,"esp"),$inout5); # save last tweak
  1082. &pxor ($inout5,$rndkey1);
  1083. &$movekey ($rndkey1,&QWP(16,$key_));
  1084. &pxor ($inout1,&QWP(16*1,"esp"));
  1085. &pxor ($inout2,&QWP(16*2,"esp"));
  1086. &aesenc ($inout0,$rndkey1);
  1087. &pxor ($inout3,&QWP(16*3,"esp"));
  1088. &pxor ($inout4,&QWP(16*4,"esp"));
  1089. &aesenc ($inout1,$rndkey1);
  1090. &pxor ($inout5,$rndkey0);
  1091. &$movekey ($rndkey0,&QWP(32,$key_));
  1092. &aesenc ($inout2,$rndkey1);
  1093. &aesenc ($inout3,$rndkey1);
  1094. &aesenc ($inout4,$rndkey1);
  1095. &aesenc ($inout5,$rndkey1);
  1096. &call (&label("_aesni_encrypt6_enter"));
  1097. &movdqa ($tweak,&QWP(16*5,"esp")); # last tweak
  1098. &pxor ($twtmp,$twtmp);
  1099. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1100. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1101. &xorps ($inout1,&QWP(16*1,"esp"));
  1102. &movups (&QWP(16*0,$out),$inout0); # write output
  1103. &xorps ($inout2,&QWP(16*2,"esp"));
  1104. &movups (&QWP(16*1,$out),$inout1);
  1105. &xorps ($inout3,&QWP(16*3,"esp"));
  1106. &movups (&QWP(16*2,$out),$inout2);
  1107. &xorps ($inout4,&QWP(16*4,"esp"));
  1108. &movups (&QWP(16*3,$out),$inout3);
  1109. &xorps ($inout5,$tweak);
  1110. &movups (&QWP(16*4,$out),$inout4);
  1111. &pshufd ($twres,$twtmp,0x13);
  1112. &movups (&QWP(16*5,$out),$inout5);
  1113. &lea ($out,&DWP(16*6,$out));
  1114. &movdqa ($twmask,&QWP(16*6,"esp")); # 0x0...010...87
  1115. &pxor ($twtmp,$twtmp);
  1116. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1117. &pand ($twres,$twmask); # isolate carry and residue
  1118. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1119. &pxor ($tweak,$twres);
  1120. &sub ($len,16*6);
  1121. &jnc (&label("xts_enc_loop6"));
  1122. &mov ($rounds,&DWP(240,$key_)); # restore $rounds
  1123. &mov ($key,$key_); # restore $key
  1124. &mov ($rounds_,$rounds);
  1125. &set_label("xts_enc_short");
  1126. &add ($len,16*6);
  1127. &jz (&label("xts_enc_done6x"));
  1128. &movdqa ($inout3,$tweak); # put aside previous tweak
  1129. &cmp ($len,0x20);
  1130. &jb (&label("xts_enc_one"));
  1131. &pshufd ($twres,$twtmp,0x13);
  1132. &pxor ($twtmp,$twtmp);
  1133. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1134. &pand ($twres,$twmask); # isolate carry and residue
  1135. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1136. &pxor ($tweak,$twres);
  1137. &je (&label("xts_enc_two"));
  1138. &pshufd ($twres,$twtmp,0x13);
  1139. &pxor ($twtmp,$twtmp);
  1140. &movdqa ($inout4,$tweak); # put aside previous tweak
  1141. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1142. &pand ($twres,$twmask); # isolate carry and residue
  1143. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1144. &pxor ($tweak,$twres);
  1145. &cmp ($len,0x40);
  1146. &jb (&label("xts_enc_three"));
  1147. &pshufd ($twres,$twtmp,0x13);
  1148. &pxor ($twtmp,$twtmp);
  1149. &movdqa ($inout5,$tweak); # put aside previous tweak
  1150. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1151. &pand ($twres,$twmask); # isolate carry and residue
  1152. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1153. &pxor ($tweak,$twres);
  1154. &movdqa (&QWP(16*0,"esp"),$inout3);
  1155. &movdqa (&QWP(16*1,"esp"),$inout4);
  1156. &je (&label("xts_enc_four"));
  1157. &movdqa (&QWP(16*2,"esp"),$inout5);
  1158. &pshufd ($inout5,$twtmp,0x13);
  1159. &movdqa (&QWP(16*3,"esp"),$tweak);
  1160. &paddq ($tweak,$tweak); # &psllq($inout0,1);
  1161. &pand ($inout5,$twmask); # isolate carry and residue
  1162. &pxor ($inout5,$tweak);
  1163. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1164. &movdqu ($inout1,&QWP(16*1,$inp));
  1165. &movdqu ($inout2,&QWP(16*2,$inp));
  1166. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1167. &movdqu ($inout3,&QWP(16*3,$inp));
  1168. &pxor ($inout1,&QWP(16*1,"esp"));
  1169. &movdqu ($inout4,&QWP(16*4,$inp));
  1170. &pxor ($inout2,&QWP(16*2,"esp"));
  1171. &lea ($inp,&DWP(16*5,$inp));
  1172. &pxor ($inout3,&QWP(16*3,"esp"));
  1173. &movdqa (&QWP(16*4,"esp"),$inout5); # save last tweak
  1174. &pxor ($inout4,$inout5);
  1175. &call ("_aesni_encrypt6");
  1176. &movaps ($tweak,&QWP(16*4,"esp")); # last tweak
  1177. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1178. &xorps ($inout1,&QWP(16*1,"esp"));
  1179. &xorps ($inout2,&QWP(16*2,"esp"));
  1180. &movups (&QWP(16*0,$out),$inout0); # write output
  1181. &xorps ($inout3,&QWP(16*3,"esp"));
  1182. &movups (&QWP(16*1,$out),$inout1);
  1183. &xorps ($inout4,$tweak);
  1184. &movups (&QWP(16*2,$out),$inout2);
  1185. &movups (&QWP(16*3,$out),$inout3);
  1186. &movups (&QWP(16*4,$out),$inout4);
  1187. &lea ($out,&DWP(16*5,$out));
  1188. &jmp (&label("xts_enc_done"));
  1189. &set_label("xts_enc_one",16);
  1190. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1191. &lea ($inp,&DWP(16*1,$inp));
  1192. &xorps ($inout0,$inout3); # input^=tweak
  1193. if ($inline)
  1194. { &aesni_inline_generate1("enc"); }
  1195. else
  1196. { &call ("_aesni_encrypt1"); }
  1197. &xorps ($inout0,$inout3); # output^=tweak
  1198. &movups (&QWP(16*0,$out),$inout0); # write output
  1199. &lea ($out,&DWP(16*1,$out));
  1200. &movdqa ($tweak,$inout3); # last tweak
  1201. &jmp (&label("xts_enc_done"));
  1202. &set_label("xts_enc_two",16);
  1203. &movaps ($inout4,$tweak); # put aside last tweak
  1204. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1205. &movups ($inout1,&QWP(16*1,$inp));
  1206. &lea ($inp,&DWP(16*2,$inp));
  1207. &xorps ($inout0,$inout3); # input^=tweak
  1208. &xorps ($inout1,$inout4);
  1209. &call ("_aesni_encrypt2");
  1210. &xorps ($inout0,$inout3); # output^=tweak
  1211. &xorps ($inout1,$inout4);
  1212. &movups (&QWP(16*0,$out),$inout0); # write output
  1213. &movups (&QWP(16*1,$out),$inout1);
  1214. &lea ($out,&DWP(16*2,$out));
  1215. &movdqa ($tweak,$inout4); # last tweak
  1216. &jmp (&label("xts_enc_done"));
  1217. &set_label("xts_enc_three",16);
  1218. &movaps ($inout5,$tweak); # put aside last tweak
  1219. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1220. &movups ($inout1,&QWP(16*1,$inp));
  1221. &movups ($inout2,&QWP(16*2,$inp));
  1222. &lea ($inp,&DWP(16*3,$inp));
  1223. &xorps ($inout0,$inout3); # input^=tweak
  1224. &xorps ($inout1,$inout4);
  1225. &xorps ($inout2,$inout5);
  1226. &call ("_aesni_encrypt3");
  1227. &xorps ($inout0,$inout3); # output^=tweak
  1228. &xorps ($inout1,$inout4);
  1229. &xorps ($inout2,$inout5);
  1230. &movups (&QWP(16*0,$out),$inout0); # write output
  1231. &movups (&QWP(16*1,$out),$inout1);
  1232. &movups (&QWP(16*2,$out),$inout2);
  1233. &lea ($out,&DWP(16*3,$out));
  1234. &movdqa ($tweak,$inout5); # last tweak
  1235. &jmp (&label("xts_enc_done"));
  1236. &set_label("xts_enc_four",16);
  1237. &movaps ($inout4,$tweak); # put aside last tweak
  1238. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1239. &movups ($inout1,&QWP(16*1,$inp));
  1240. &movups ($inout2,&QWP(16*2,$inp));
  1241. &xorps ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1242. &movups ($inout3,&QWP(16*3,$inp));
  1243. &lea ($inp,&DWP(16*4,$inp));
  1244. &xorps ($inout1,&QWP(16*1,"esp"));
  1245. &xorps ($inout2,$inout5);
  1246. &xorps ($inout3,$inout4);
  1247. &call ("_aesni_encrypt4");
  1248. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1249. &xorps ($inout1,&QWP(16*1,"esp"));
  1250. &xorps ($inout2,$inout5);
  1251. &movups (&QWP(16*0,$out),$inout0); # write output
  1252. &xorps ($inout3,$inout4);
  1253. &movups (&QWP(16*1,$out),$inout1);
  1254. &movups (&QWP(16*2,$out),$inout2);
  1255. &movups (&QWP(16*3,$out),$inout3);
  1256. &lea ($out,&DWP(16*4,$out));
  1257. &movdqa ($tweak,$inout4); # last tweak
  1258. &jmp (&label("xts_enc_done"));
  1259. &set_label("xts_enc_done6x",16); # $tweak is pre-calculated
  1260. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1261. &and ($len,15);
  1262. &jz (&label("xts_enc_ret"));
  1263. &movdqa ($inout3,$tweak);
  1264. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1265. &jmp (&label("xts_enc_steal"));
  1266. &set_label("xts_enc_done",16);
  1267. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1268. &pxor ($twtmp,$twtmp);
  1269. &and ($len,15);
  1270. &jz (&label("xts_enc_ret"));
  1271. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1272. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1273. &pshufd ($inout3,$twtmp,0x13);
  1274. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1275. &pand ($inout3,&QWP(16*6,"esp")); # isolate carry and residue
  1276. &pxor ($inout3,$tweak);
  1277. &set_label("xts_enc_steal");
  1278. &movz ($rounds,&BP(0,$inp));
  1279. &movz ($key,&BP(-16,$out));
  1280. &lea ($inp,&DWP(1,$inp));
  1281. &mov (&BP(-16,$out),&LB($rounds));
  1282. &mov (&BP(0,$out),&LB($key));
  1283. &lea ($out,&DWP(1,$out));
  1284. &sub ($len,1);
  1285. &jnz (&label("xts_enc_steal"));
  1286. &sub ($out,&DWP(16*7+0,"esp")); # rewind $out
  1287. &mov ($key,$key_); # restore $key
  1288. &mov ($rounds,$rounds_); # restore $rounds
  1289. &movups ($inout0,&QWP(-16,$out)); # load input
  1290. &xorps ($inout0,$inout3); # input^=tweak
  1291. if ($inline)
  1292. { &aesni_inline_generate1("enc"); }
  1293. else
  1294. { &call ("_aesni_encrypt1"); }
  1295. &xorps ($inout0,$inout3); # output^=tweak
  1296. &movups (&QWP(-16,$out),$inout0); # write output
  1297. &set_label("xts_enc_ret");
  1298. &pxor ("xmm0","xmm0"); # clear register bank
  1299. &pxor ("xmm1","xmm1");
  1300. &pxor ("xmm2","xmm2");
  1301. &movdqa (&QWP(16*0,"esp"),"xmm0"); # clear stack
  1302. &pxor ("xmm3","xmm3");
  1303. &movdqa (&QWP(16*1,"esp"),"xmm0");
  1304. &pxor ("xmm4","xmm4");
  1305. &movdqa (&QWP(16*2,"esp"),"xmm0");
  1306. &pxor ("xmm5","xmm5");
  1307. &movdqa (&QWP(16*3,"esp"),"xmm0");
  1308. &pxor ("xmm6","xmm6");
  1309. &movdqa (&QWP(16*4,"esp"),"xmm0");
  1310. &pxor ("xmm7","xmm7");
  1311. &movdqa (&QWP(16*5,"esp"),"xmm0");
  1312. &mov ("esp",&DWP(16*7+4,"esp")); # restore %esp
  1313. &function_end("aesni_xts_encrypt");
  1314. &function_begin("aesni_xts_decrypt");
  1315. &mov ($key,&wparam(4)); # key2
  1316. &mov ($inp,&wparam(5)); # clear-text tweak
  1317. &mov ($rounds,&DWP(240,$key)); # key2->rounds
  1318. &movups ($inout0,&QWP(0,$inp));
  1319. if ($inline)
  1320. { &aesni_inline_generate1("enc"); }
  1321. else
  1322. { &call ("_aesni_encrypt1"); }
  1323. &mov ($inp,&wparam(0));
  1324. &mov ($out,&wparam(1));
  1325. &mov ($len,&wparam(2));
  1326. &mov ($key,&wparam(3)); # key1
  1327. &mov ($key_,"esp");
  1328. &sub ("esp",16*7+8);
  1329. &and ("esp",-16); # align stack
  1330. &xor ($rounds_,$rounds_); # if(len%16) len-=16;
  1331. &test ($len,15);
  1332. &setnz (&LB($rounds_));
  1333. &shl ($rounds_,4);
  1334. &sub ($len,$rounds_);
  1335. &mov (&DWP(16*6+0,"esp"),0x87); # compose the magic constant
  1336. &mov (&DWP(16*6+4,"esp"),0);
  1337. &mov (&DWP(16*6+8,"esp"),1);
  1338. &mov (&DWP(16*6+12,"esp"),0);
  1339. &mov (&DWP(16*7+0,"esp"),$len); # save original $len
  1340. &mov (&DWP(16*7+4,"esp"),$key_); # save original %esp
  1341. &mov ($rounds,&DWP(240,$key)); # key1->rounds
  1342. &mov ($key_,$key); # backup $key
  1343. &mov ($rounds_,$rounds); # backup $rounds
  1344. &movdqa ($tweak,$inout0);
  1345. &pxor ($twtmp,$twtmp);
  1346. &movdqa ($twmask,&QWP(6*16,"esp")); # 0x0...010...87
  1347. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1348. &and ($len,-16);
  1349. &sub ($len,16*6);
  1350. &jc (&label("xts_dec_short"));
  1351. &shl ($rounds,4);
  1352. &mov ($rounds_,16);
  1353. &sub ($rounds_,$rounds);
  1354. &lea ($key,&DWP(32,$key,$rounds));
  1355. &jmp (&label("xts_dec_loop6"));
  1356. &set_label("xts_dec_loop6",16);
  1357. for ($i=0;$i<4;$i++) {
  1358. &pshufd ($twres,$twtmp,0x13);
  1359. &pxor ($twtmp,$twtmp);
  1360. &movdqa (&QWP(16*$i,"esp"),$tweak);
  1361. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1362. &pand ($twres,$twmask); # isolate carry and residue
  1363. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1364. &pxor ($tweak,$twres);
  1365. }
  1366. &pshufd ($inout5,$twtmp,0x13);
  1367. &movdqa (&QWP(16*$i++,"esp"),$tweak);
  1368. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1369. &$movekey ($rndkey0,&QWP(0,$key_));
  1370. &pand ($inout5,$twmask); # isolate carry and residue
  1371. &movups ($inout0,&QWP(0,$inp)); # load input
  1372. &pxor ($inout5,$tweak);
  1373. # inline _aesni_encrypt6 prologue and flip xor with tweak and key[0]
  1374. &mov ($rounds,$rounds_);
  1375. &movdqu ($inout1,&QWP(16*1,$inp));
  1376. &xorps ($inout0,$rndkey0); # input^=rndkey[0]
  1377. &movdqu ($inout2,&QWP(16*2,$inp));
  1378. &pxor ($inout1,$rndkey0);
  1379. &movdqu ($inout3,&QWP(16*3,$inp));
  1380. &pxor ($inout2,$rndkey0);
  1381. &movdqu ($inout4,&QWP(16*4,$inp));
  1382. &pxor ($inout3,$rndkey0);
  1383. &movdqu ($rndkey1,&QWP(16*5,$inp));
  1384. &pxor ($inout4,$rndkey0);
  1385. &lea ($inp,&DWP(16*6,$inp));
  1386. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1387. &movdqa (&QWP(16*$i,"esp"),$inout5); # save last tweak
  1388. &pxor ($inout5,$rndkey1);
  1389. &$movekey ($rndkey1,&QWP(16,$key_));
  1390. &pxor ($inout1,&QWP(16*1,"esp"));
  1391. &pxor ($inout2,&QWP(16*2,"esp"));
  1392. &aesdec ($inout0,$rndkey1);
  1393. &pxor ($inout3,&QWP(16*3,"esp"));
  1394. &pxor ($inout4,&QWP(16*4,"esp"));
  1395. &aesdec ($inout1,$rndkey1);
  1396. &pxor ($inout5,$rndkey0);
  1397. &$movekey ($rndkey0,&QWP(32,$key_));
  1398. &aesdec ($inout2,$rndkey1);
  1399. &aesdec ($inout3,$rndkey1);
  1400. &aesdec ($inout4,$rndkey1);
  1401. &aesdec ($inout5,$rndkey1);
  1402. &call (&label("_aesni_decrypt6_enter"));
  1403. &movdqa ($tweak,&QWP(16*5,"esp")); # last tweak
  1404. &pxor ($twtmp,$twtmp);
  1405. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1406. &pcmpgtd ($twtmp,$tweak); # broadcast upper bits
  1407. &xorps ($inout1,&QWP(16*1,"esp"));
  1408. &movups (&QWP(16*0,$out),$inout0); # write output
  1409. &xorps ($inout2,&QWP(16*2,"esp"));
  1410. &movups (&QWP(16*1,$out),$inout1);
  1411. &xorps ($inout3,&QWP(16*3,"esp"));
  1412. &movups (&QWP(16*2,$out),$inout2);
  1413. &xorps ($inout4,&QWP(16*4,"esp"));
  1414. &movups (&QWP(16*3,$out),$inout3);
  1415. &xorps ($inout5,$tweak);
  1416. &movups (&QWP(16*4,$out),$inout4);
  1417. &pshufd ($twres,$twtmp,0x13);
  1418. &movups (&QWP(16*5,$out),$inout5);
  1419. &lea ($out,&DWP(16*6,$out));
  1420. &movdqa ($twmask,&QWP(16*6,"esp")); # 0x0...010...87
  1421. &pxor ($twtmp,$twtmp);
  1422. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1423. &pand ($twres,$twmask); # isolate carry and residue
  1424. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1425. &pxor ($tweak,$twres);
  1426. &sub ($len,16*6);
  1427. &jnc (&label("xts_dec_loop6"));
  1428. &mov ($rounds,&DWP(240,$key_)); # restore $rounds
  1429. &mov ($key,$key_); # restore $key
  1430. &mov ($rounds_,$rounds);
  1431. &set_label("xts_dec_short");
  1432. &add ($len,16*6);
  1433. &jz (&label("xts_dec_done6x"));
  1434. &movdqa ($inout3,$tweak); # put aside previous tweak
  1435. &cmp ($len,0x20);
  1436. &jb (&label("xts_dec_one"));
  1437. &pshufd ($twres,$twtmp,0x13);
  1438. &pxor ($twtmp,$twtmp);
  1439. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1440. &pand ($twres,$twmask); # isolate carry and residue
  1441. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1442. &pxor ($tweak,$twres);
  1443. &je (&label("xts_dec_two"));
  1444. &pshufd ($twres,$twtmp,0x13);
  1445. &pxor ($twtmp,$twtmp);
  1446. &movdqa ($inout4,$tweak); # put aside previous tweak
  1447. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1448. &pand ($twres,$twmask); # isolate carry and residue
  1449. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1450. &pxor ($tweak,$twres);
  1451. &cmp ($len,0x40);
  1452. &jb (&label("xts_dec_three"));
  1453. &pshufd ($twres,$twtmp,0x13);
  1454. &pxor ($twtmp,$twtmp);
  1455. &movdqa ($inout5,$tweak); # put aside previous tweak
  1456. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1457. &pand ($twres,$twmask); # isolate carry and residue
  1458. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1459. &pxor ($tweak,$twres);
  1460. &movdqa (&QWP(16*0,"esp"),$inout3);
  1461. &movdqa (&QWP(16*1,"esp"),$inout4);
  1462. &je (&label("xts_dec_four"));
  1463. &movdqa (&QWP(16*2,"esp"),$inout5);
  1464. &pshufd ($inout5,$twtmp,0x13);
  1465. &movdqa (&QWP(16*3,"esp"),$tweak);
  1466. &paddq ($tweak,$tweak); # &psllq($inout0,1);
  1467. &pand ($inout5,$twmask); # isolate carry and residue
  1468. &pxor ($inout5,$tweak);
  1469. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1470. &movdqu ($inout1,&QWP(16*1,$inp));
  1471. &movdqu ($inout2,&QWP(16*2,$inp));
  1472. &pxor ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1473. &movdqu ($inout3,&QWP(16*3,$inp));
  1474. &pxor ($inout1,&QWP(16*1,"esp"));
  1475. &movdqu ($inout4,&QWP(16*4,$inp));
  1476. &pxor ($inout2,&QWP(16*2,"esp"));
  1477. &lea ($inp,&DWP(16*5,$inp));
  1478. &pxor ($inout3,&QWP(16*3,"esp"));
  1479. &movdqa (&QWP(16*4,"esp"),$inout5); # save last tweak
  1480. &pxor ($inout4,$inout5);
  1481. &call ("_aesni_decrypt6");
  1482. &movaps ($tweak,&QWP(16*4,"esp")); # last tweak
  1483. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1484. &xorps ($inout1,&QWP(16*1,"esp"));
  1485. &xorps ($inout2,&QWP(16*2,"esp"));
  1486. &movups (&QWP(16*0,$out),$inout0); # write output
  1487. &xorps ($inout3,&QWP(16*3,"esp"));
  1488. &movups (&QWP(16*1,$out),$inout1);
  1489. &xorps ($inout4,$tweak);
  1490. &movups (&QWP(16*2,$out),$inout2);
  1491. &movups (&QWP(16*3,$out),$inout3);
  1492. &movups (&QWP(16*4,$out),$inout4);
  1493. &lea ($out,&DWP(16*5,$out));
  1494. &jmp (&label("xts_dec_done"));
  1495. &set_label("xts_dec_one",16);
  1496. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1497. &lea ($inp,&DWP(16*1,$inp));
  1498. &xorps ($inout0,$inout3); # input^=tweak
  1499. if ($inline)
  1500. { &aesni_inline_generate1("dec"); }
  1501. else
  1502. { &call ("_aesni_decrypt1"); }
  1503. &xorps ($inout0,$inout3); # output^=tweak
  1504. &movups (&QWP(16*0,$out),$inout0); # write output
  1505. &lea ($out,&DWP(16*1,$out));
  1506. &movdqa ($tweak,$inout3); # last tweak
  1507. &jmp (&label("xts_dec_done"));
  1508. &set_label("xts_dec_two",16);
  1509. &movaps ($inout4,$tweak); # put aside last tweak
  1510. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1511. &movups ($inout1,&QWP(16*1,$inp));
  1512. &lea ($inp,&DWP(16*2,$inp));
  1513. &xorps ($inout0,$inout3); # input^=tweak
  1514. &xorps ($inout1,$inout4);
  1515. &call ("_aesni_decrypt2");
  1516. &xorps ($inout0,$inout3); # output^=tweak
  1517. &xorps ($inout1,$inout4);
  1518. &movups (&QWP(16*0,$out),$inout0); # write output
  1519. &movups (&QWP(16*1,$out),$inout1);
  1520. &lea ($out,&DWP(16*2,$out));
  1521. &movdqa ($tweak,$inout4); # last tweak
  1522. &jmp (&label("xts_dec_done"));
  1523. &set_label("xts_dec_three",16);
  1524. &movaps ($inout5,$tweak); # put aside last tweak
  1525. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1526. &movups ($inout1,&QWP(16*1,$inp));
  1527. &movups ($inout2,&QWP(16*2,$inp));
  1528. &lea ($inp,&DWP(16*3,$inp));
  1529. &xorps ($inout0,$inout3); # input^=tweak
  1530. &xorps ($inout1,$inout4);
  1531. &xorps ($inout2,$inout5);
  1532. &call ("_aesni_decrypt3");
  1533. &xorps ($inout0,$inout3); # output^=tweak
  1534. &xorps ($inout1,$inout4);
  1535. &xorps ($inout2,$inout5);
  1536. &movups (&QWP(16*0,$out),$inout0); # write output
  1537. &movups (&QWP(16*1,$out),$inout1);
  1538. &movups (&QWP(16*2,$out),$inout2);
  1539. &lea ($out,&DWP(16*3,$out));
  1540. &movdqa ($tweak,$inout5); # last tweak
  1541. &jmp (&label("xts_dec_done"));
  1542. &set_label("xts_dec_four",16);
  1543. &movaps ($inout4,$tweak); # put aside last tweak
  1544. &movups ($inout0,&QWP(16*0,$inp)); # load input
  1545. &movups ($inout1,&QWP(16*1,$inp));
  1546. &movups ($inout2,&QWP(16*2,$inp));
  1547. &xorps ($inout0,&QWP(16*0,"esp")); # input^=tweak
  1548. &movups ($inout3,&QWP(16*3,$inp));
  1549. &lea ($inp,&DWP(16*4,$inp));
  1550. &xorps ($inout1,&QWP(16*1,"esp"));
  1551. &xorps ($inout2,$inout5);
  1552. &xorps ($inout3,$inout4);
  1553. &call ("_aesni_decrypt4");
  1554. &xorps ($inout0,&QWP(16*0,"esp")); # output^=tweak
  1555. &xorps ($inout1,&QWP(16*1,"esp"));
  1556. &xorps ($inout2,$inout5);
  1557. &movups (&QWP(16*0,$out),$inout0); # write output
  1558. &xorps ($inout3,$inout4);
  1559. &movups (&QWP(16*1,$out),$inout1);
  1560. &movups (&QWP(16*2,$out),$inout2);
  1561. &movups (&QWP(16*3,$out),$inout3);
  1562. &lea ($out,&DWP(16*4,$out));
  1563. &movdqa ($tweak,$inout4); # last tweak
  1564. &jmp (&label("xts_dec_done"));
  1565. &set_label("xts_dec_done6x",16); # $tweak is pre-calculated
  1566. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1567. &and ($len,15);
  1568. &jz (&label("xts_dec_ret"));
  1569. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1570. &jmp (&label("xts_dec_only_one_more"));
  1571. &set_label("xts_dec_done",16);
  1572. &mov ($len,&DWP(16*7+0,"esp")); # restore original $len
  1573. &pxor ($twtmp,$twtmp);
  1574. &and ($len,15);
  1575. &jz (&label("xts_dec_ret"));
  1576. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1577. &mov (&DWP(16*7+0,"esp"),$len); # save $len%16
  1578. &pshufd ($twres,$twtmp,0x13);
  1579. &pxor ($twtmp,$twtmp);
  1580. &movdqa ($twmask,&QWP(16*6,"esp"));
  1581. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1582. &pand ($twres,$twmask); # isolate carry and residue
  1583. &pcmpgtd($twtmp,$tweak); # broadcast upper bits
  1584. &pxor ($tweak,$twres);
  1585. &set_label("xts_dec_only_one_more");
  1586. &pshufd ($inout3,$twtmp,0x13);
  1587. &movdqa ($inout4,$tweak); # put aside previous tweak
  1588. &paddq ($tweak,$tweak); # &psllq($tweak,1);
  1589. &pand ($inout3,$twmask); # isolate carry and residue
  1590. &pxor ($inout3,$tweak);
  1591. &mov ($key,$key_); # restore $key
  1592. &mov ($rounds,$rounds_); # restore $rounds
  1593. &movups ($inout0,&QWP(0,$inp)); # load input
  1594. &xorps ($inout0,$inout3); # input^=tweak
  1595. if ($inline)
  1596. { &aesni_inline_generate1("dec"); }
  1597. else
  1598. { &call ("_aesni_decrypt1"); }
  1599. &xorps ($inout0,$inout3); # output^=tweak
  1600. &movups (&QWP(0,$out),$inout0); # write output
  1601. &set_label("xts_dec_steal");
  1602. &movz ($rounds,&BP(16,$inp));
  1603. &movz ($key,&BP(0,$out));
  1604. &lea ($inp,&DWP(1,$inp));
  1605. &mov (&BP(0,$out),&LB($rounds));
  1606. &mov (&BP(16,$out),&LB($key));
  1607. &lea ($out,&DWP(1,$out));
  1608. &sub ($len,1);
  1609. &jnz (&label("xts_dec_steal"));
  1610. &sub ($out,&DWP(16*7+0,"esp")); # rewind $out
  1611. &mov ($key,$key_); # restore $key
  1612. &mov ($rounds,$rounds_); # restore $rounds
  1613. &movups ($inout0,&QWP(0,$out)); # load input
  1614. &xorps ($inout0,$inout4); # input^=tweak
  1615. if ($inline)
  1616. { &aesni_inline_generate1("dec"); }
  1617. else
  1618. { &call ("_aesni_decrypt1"); }
  1619. &xorps ($inout0,$inout4); # output^=tweak
  1620. &movups (&QWP(0,$out),$inout0); # write output
  1621. &set_label("xts_dec_ret");
  1622. &pxor ("xmm0","xmm0"); # clear register bank
  1623. &pxor ("xmm1","xmm1");
  1624. &pxor ("xmm2","xmm2");
  1625. &movdqa (&QWP(16*0,"esp"),"xmm0"); # clear stack
  1626. &pxor ("xmm3","xmm3");
  1627. &movdqa (&QWP(16*1,"esp"),"xmm0");
  1628. &pxor ("xmm4","xmm4");
  1629. &movdqa (&QWP(16*2,"esp"),"xmm0");
  1630. &pxor ("xmm5","xmm5");
  1631. &movdqa (&QWP(16*3,"esp"),"xmm0");
  1632. &pxor ("xmm6","xmm6");
  1633. &movdqa (&QWP(16*4,"esp"),"xmm0");
  1634. &pxor ("xmm7","xmm7");
  1635. &movdqa (&QWP(16*5,"esp"),"xmm0");
  1636. &mov ("esp",&DWP(16*7+4,"esp")); # restore %esp
  1637. &function_end("aesni_xts_decrypt");
  1638. }
  1639. ######################################################################
  1640. # void aesni_ocb_[en|de]crypt(const char *inp, char *out, size_t blocks,
  1641. # const AES_KEY *key, unsigned int start_block_num,
  1642. # unsigned char offset_i[16], const unsigned char L_[][16],
  1643. # unsigned char checksum[16]);
  1644. #
  1645. {
  1646. # offsets within stack frame
  1647. my $checksum = 16*6;
  1648. my ($key_off,$rounds_off,$out_off,$end_off,$esp_off)=map(16*7+4*$_,(0..4));
  1649. # reassigned registers
  1650. my ($l_,$block,$i1,$i3,$i5) = ($rounds_,$key_,$rounds,$len,$out);
  1651. # $l_, $blocks, $inp, $key are permanently allocated in registers;
  1652. # remaining non-volatile ones are offloaded to stack, which even
  1653. # stay invariant after written to stack.
  1654. &function_begin("aesni_ocb_encrypt");
  1655. &mov ($rounds,&wparam(5)); # &offset_i
  1656. &mov ($rounds_,&wparam(7)); # &checksum
  1657. &mov ($inp,&wparam(0));
  1658. &mov ($out,&wparam(1));
  1659. &mov ($len,&wparam(2));
  1660. &mov ($key,&wparam(3));
  1661. &movdqu ($rndkey0,&QWP(0,$rounds)); # load offset_i
  1662. &mov ($block,&wparam(4)); # start_block_num
  1663. &movdqu ($rndkey1,&QWP(0,$rounds_)); # load checksum
  1664. &mov ($l_,&wparam(6)); # L_
  1665. &mov ($rounds,"esp");
  1666. &sub ("esp",$esp_off+4); # alloca
  1667. &and ("esp",-16); # align stack
  1668. &sub ($out,$inp);
  1669. &shl ($len,4);
  1670. &lea ($len,&DWP(-16*6,$inp,$len)); # end of input - 16*6
  1671. &mov (&DWP($out_off,"esp"),$out);
  1672. &mov (&DWP($end_off,"esp"),$len);
  1673. &mov (&DWP($esp_off,"esp"),$rounds);
  1674. &mov ($rounds,&DWP(240,$key));
  1675. &test ($block,1);
  1676. &jnz (&label("odd"));
  1677. &bsf ($i3,$block);
  1678. &add ($block,1);
  1679. &shl ($i3,4);
  1680. &movdqu ($inout5,&QWP(0,$l_,$i3));
  1681. &mov ($i3,$key); # put aside key
  1682. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1683. &lea ($inp,&DWP(16,$inp));
  1684. &pxor ($inout5,$rndkey0); # ^ last offset_i
  1685. &pxor ($rndkey1,$inout0); # checksum
  1686. &pxor ($inout0,$inout5); # ^ offset_i
  1687. &movdqa ($inout4,$rndkey1);
  1688. if ($inline)
  1689. { &aesni_inline_generate1("enc"); }
  1690. else
  1691. { &call ("_aesni_encrypt1"); }
  1692. &xorps ($inout0,$inout5); # ^ offset_i
  1693. &movdqa ($rndkey0,$inout5); # pass last offset_i
  1694. &movdqa ($rndkey1,$inout4); # pass the checksum
  1695. &movups (&QWP(-16,$out,$inp),$inout0); # store output
  1696. &mov ($rounds,&DWP(240,$i3));
  1697. &mov ($key,$i3); # restore key
  1698. &mov ($len,&DWP($end_off,"esp"));
  1699. &set_label("odd");
  1700. &shl ($rounds,4);
  1701. &mov ($out,16);
  1702. &sub ($out,$rounds); # twisted rounds
  1703. &mov (&DWP($key_off,"esp"),$key);
  1704. &lea ($key,&DWP(32,$key,$rounds)); # end of key schedule
  1705. &mov (&DWP($rounds_off,"esp"),$out);
  1706. &cmp ($inp,$len);
  1707. &ja (&label("short"));
  1708. &jmp (&label("grandloop"));
  1709. &set_label("grandloop",32);
  1710. &lea ($i1,&DWP(1,$block));
  1711. &lea ($i3,&DWP(3,$block));
  1712. &lea ($i5,&DWP(5,$block));
  1713. &add ($block,6);
  1714. &bsf ($i1,$i1);
  1715. &bsf ($i3,$i3);
  1716. &bsf ($i5,$i5);
  1717. &shl ($i1,4);
  1718. &shl ($i3,4);
  1719. &shl ($i5,4);
  1720. &movdqu ($inout0,&QWP(0,$l_));
  1721. &movdqu ($inout1,&QWP(0,$l_,$i1));
  1722. &mov ($rounds,&DWP($rounds_off,"esp"));
  1723. &movdqa ($inout2,$inout0);
  1724. &movdqu ($inout3,&QWP(0,$l_,$i3));
  1725. &movdqa ($inout4,$inout0);
  1726. &movdqu ($inout5,&QWP(0,$l_,$i5));
  1727. &pxor ($inout0,$rndkey0); # ^ last offset_i
  1728. &pxor ($inout1,$inout0);
  1729. &movdqa (&QWP(16*0,"esp"),$inout0);
  1730. &pxor ($inout2,$inout1);
  1731. &movdqa (&QWP(16*1,"esp"),$inout1);
  1732. &pxor ($inout3,$inout2);
  1733. &movdqa (&QWP(16*2,"esp"),$inout2);
  1734. &pxor ($inout4,$inout3);
  1735. &movdqa (&QWP(16*3,"esp"),$inout3);
  1736. &pxor ($inout5,$inout4);
  1737. &movdqa (&QWP(16*4,"esp"),$inout4);
  1738. &movdqa (&QWP(16*5,"esp"),$inout5);
  1739. &$movekey ($rndkey0,&QWP(-48,$key,$rounds));
  1740. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1741. &movdqu ($inout1,&QWP(16*1,$inp));
  1742. &movdqu ($inout2,&QWP(16*2,$inp));
  1743. &movdqu ($inout3,&QWP(16*3,$inp));
  1744. &movdqu ($inout4,&QWP(16*4,$inp));
  1745. &movdqu ($inout5,&QWP(16*5,$inp));
  1746. &lea ($inp,&DWP(16*6,$inp));
  1747. &pxor ($rndkey1,$inout0); # checksum
  1748. &pxor ($inout0,$rndkey0); # ^ roundkey[0]
  1749. &pxor ($rndkey1,$inout1);
  1750. &pxor ($inout1,$rndkey0);
  1751. &pxor ($rndkey1,$inout2);
  1752. &pxor ($inout2,$rndkey0);
  1753. &pxor ($rndkey1,$inout3);
  1754. &pxor ($inout3,$rndkey0);
  1755. &pxor ($rndkey1,$inout4);
  1756. &pxor ($inout4,$rndkey0);
  1757. &pxor ($rndkey1,$inout5);
  1758. &pxor ($inout5,$rndkey0);
  1759. &movdqa (&QWP($checksum,"esp"),$rndkey1);
  1760. &$movekey ($rndkey1,&QWP(-32,$key,$rounds));
  1761. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  1762. &pxor ($inout1,&QWP(16*1,"esp"));
  1763. &pxor ($inout2,&QWP(16*2,"esp"));
  1764. &pxor ($inout3,&QWP(16*3,"esp"));
  1765. &pxor ($inout4,&QWP(16*4,"esp"));
  1766. &pxor ($inout5,&QWP(16*5,"esp"));
  1767. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  1768. &aesenc ($inout0,$rndkey1);
  1769. &aesenc ($inout1,$rndkey1);
  1770. &aesenc ($inout2,$rndkey1);
  1771. &aesenc ($inout3,$rndkey1);
  1772. &aesenc ($inout4,$rndkey1);
  1773. &aesenc ($inout5,$rndkey1);
  1774. &mov ($out,&DWP($out_off,"esp"));
  1775. &mov ($len,&DWP($end_off,"esp"));
  1776. &call ("_aesni_encrypt6_enter");
  1777. &movdqa ($rndkey0,&QWP(16*5,"esp")); # pass last offset_i
  1778. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  1779. &pxor ($inout1,&QWP(16*1,"esp"));
  1780. &pxor ($inout2,&QWP(16*2,"esp"));
  1781. &pxor ($inout3,&QWP(16*3,"esp"));
  1782. &pxor ($inout4,&QWP(16*4,"esp"));
  1783. &pxor ($inout5,$rndkey0);
  1784. &movdqa ($rndkey1,&QWP($checksum,"esp"));# pass the checksum
  1785. &movdqu (&QWP(-16*6,$out,$inp),$inout0);# store output
  1786. &movdqu (&QWP(-16*5,$out,$inp),$inout1);
  1787. &movdqu (&QWP(-16*4,$out,$inp),$inout2);
  1788. &movdqu (&QWP(-16*3,$out,$inp),$inout3);
  1789. &movdqu (&QWP(-16*2,$out,$inp),$inout4);
  1790. &movdqu (&QWP(-16*1,$out,$inp),$inout5);
  1791. &cmp ($inp,$len); # done yet?
  1792. &jb (&label("grandloop"));
  1793. &set_label("short");
  1794. &add ($len,16*6);
  1795. &sub ($len,$inp);
  1796. &jz (&label("done"));
  1797. &cmp ($len,16*2);
  1798. &jb (&label("one"));
  1799. &je (&label("two"));
  1800. &cmp ($len,16*4);
  1801. &jb (&label("three"));
  1802. &je (&label("four"));
  1803. &lea ($i1,&DWP(1,$block));
  1804. &lea ($i3,&DWP(3,$block));
  1805. &bsf ($i1,$i1);
  1806. &bsf ($i3,$i3);
  1807. &shl ($i1,4);
  1808. &shl ($i3,4);
  1809. &movdqu ($inout0,&QWP(0,$l_));
  1810. &movdqu ($inout1,&QWP(0,$l_,$i1));
  1811. &mov ($rounds,&DWP($rounds_off,"esp"));
  1812. &movdqa ($inout2,$inout0);
  1813. &movdqu ($inout3,&QWP(0,$l_,$i3));
  1814. &movdqa ($inout4,$inout0);
  1815. &pxor ($inout0,$rndkey0); # ^ last offset_i
  1816. &pxor ($inout1,$inout0);
  1817. &movdqa (&QWP(16*0,"esp"),$inout0);
  1818. &pxor ($inout2,$inout1);
  1819. &movdqa (&QWP(16*1,"esp"),$inout1);
  1820. &pxor ($inout3,$inout2);
  1821. &movdqa (&QWP(16*2,"esp"),$inout2);
  1822. &pxor ($inout4,$inout3);
  1823. &movdqa (&QWP(16*3,"esp"),$inout3);
  1824. &pxor ($inout5,$inout4);
  1825. &movdqa (&QWP(16*4,"esp"),$inout4);
  1826. &$movekey ($rndkey0,&QWP(-48,$key,$rounds));
  1827. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1828. &movdqu ($inout1,&QWP(16*1,$inp));
  1829. &movdqu ($inout2,&QWP(16*2,$inp));
  1830. &movdqu ($inout3,&QWP(16*3,$inp));
  1831. &movdqu ($inout4,&QWP(16*4,$inp));
  1832. &pxor ($inout5,$inout5);
  1833. &pxor ($rndkey1,$inout0); # checksum
  1834. &pxor ($inout0,$rndkey0); # ^ roundkey[0]
  1835. &pxor ($rndkey1,$inout1);
  1836. &pxor ($inout1,$rndkey0);
  1837. &pxor ($rndkey1,$inout2);
  1838. &pxor ($inout2,$rndkey0);
  1839. &pxor ($rndkey1,$inout3);
  1840. &pxor ($inout3,$rndkey0);
  1841. &pxor ($rndkey1,$inout4);
  1842. &pxor ($inout4,$rndkey0);
  1843. &movdqa (&QWP($checksum,"esp"),$rndkey1);
  1844. &$movekey ($rndkey1,&QWP(-32,$key,$rounds));
  1845. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  1846. &pxor ($inout1,&QWP(16*1,"esp"));
  1847. &pxor ($inout2,&QWP(16*2,"esp"));
  1848. &pxor ($inout3,&QWP(16*3,"esp"));
  1849. &pxor ($inout4,&QWP(16*4,"esp"));
  1850. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  1851. &aesenc ($inout0,$rndkey1);
  1852. &aesenc ($inout1,$rndkey1);
  1853. &aesenc ($inout2,$rndkey1);
  1854. &aesenc ($inout3,$rndkey1);
  1855. &aesenc ($inout4,$rndkey1);
  1856. &aesenc ($inout5,$rndkey1);
  1857. &mov ($out,&DWP($out_off,"esp"));
  1858. &call ("_aesni_encrypt6_enter");
  1859. &movdqa ($rndkey0,&QWP(16*4,"esp")); # pass last offset_i
  1860. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  1861. &pxor ($inout1,&QWP(16*1,"esp"));
  1862. &pxor ($inout2,&QWP(16*2,"esp"));
  1863. &pxor ($inout3,&QWP(16*3,"esp"));
  1864. &pxor ($inout4,$rndkey0);
  1865. &movdqa ($rndkey1,&QWP($checksum,"esp"));# pass the checksum
  1866. &movdqu (&QWP(16*0,$out,$inp),$inout0); # store output
  1867. &movdqu (&QWP(16*1,$out,$inp),$inout1);
  1868. &movdqu (&QWP(16*2,$out,$inp),$inout2);
  1869. &movdqu (&QWP(16*3,$out,$inp),$inout3);
  1870. &movdqu (&QWP(16*4,$out,$inp),$inout4);
  1871. &jmp (&label("done"));
  1872. &set_label("one",16);
  1873. &movdqu ($inout5,&QWP(0,$l_));
  1874. &mov ($key,&DWP($key_off,"esp")); # restore key
  1875. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1876. &mov ($rounds,&DWP(240,$key));
  1877. &pxor ($inout5,$rndkey0); # ^ last offset_i
  1878. &pxor ($rndkey1,$inout0); # checksum
  1879. &pxor ($inout0,$inout5); # ^ offset_i
  1880. &movdqa ($inout4,$rndkey1);
  1881. &mov ($out,&DWP($out_off,"esp"));
  1882. if ($inline)
  1883. { &aesni_inline_generate1("enc"); }
  1884. else
  1885. { &call ("_aesni_encrypt1"); }
  1886. &xorps ($inout0,$inout5); # ^ offset_i
  1887. &movdqa ($rndkey0,$inout5); # pass last offset_i
  1888. &movdqa ($rndkey1,$inout4); # pass the checksum
  1889. &movups (&QWP(0,$out,$inp),$inout0);
  1890. &jmp (&label("done"));
  1891. &set_label("two",16);
  1892. &lea ($i1,&DWP(1,$block));
  1893. &mov ($key,&DWP($key_off,"esp")); # restore key
  1894. &bsf ($i1,$i1);
  1895. &shl ($i1,4);
  1896. &movdqu ($inout4,&QWP(0,$l_));
  1897. &movdqu ($inout5,&QWP(0,$l_,$i1));
  1898. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1899. &movdqu ($inout1,&QWP(16*1,$inp));
  1900. &mov ($rounds,&DWP(240,$key));
  1901. &pxor ($inout4,$rndkey0); # ^ last offset_i
  1902. &pxor ($inout5,$inout4);
  1903. &pxor ($rndkey1,$inout0); # checksum
  1904. &pxor ($inout0,$inout4); # ^ offset_i
  1905. &pxor ($rndkey1,$inout1);
  1906. &pxor ($inout1,$inout5);
  1907. &movdqa ($inout3,$rndkey1)
  1908. &mov ($out,&DWP($out_off,"esp"));
  1909. &call ("_aesni_encrypt2");
  1910. &xorps ($inout0,$inout4); # ^ offset_i
  1911. &xorps ($inout1,$inout5);
  1912. &movdqa ($rndkey0,$inout5); # pass last offset_i
  1913. &movdqa ($rndkey1,$inout3); # pass the checksum
  1914. &movups (&QWP(16*0,$out,$inp),$inout0); # store output
  1915. &movups (&QWP(16*1,$out,$inp),$inout1);
  1916. &jmp (&label("done"));
  1917. &set_label("three",16);
  1918. &lea ($i1,&DWP(1,$block));
  1919. &mov ($key,&DWP($key_off,"esp")); # restore key
  1920. &bsf ($i1,$i1);
  1921. &shl ($i1,4);
  1922. &movdqu ($inout3,&QWP(0,$l_));
  1923. &movdqu ($inout4,&QWP(0,$l_,$i1));
  1924. &movdqa ($inout5,$inout3);
  1925. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1926. &movdqu ($inout1,&QWP(16*1,$inp));
  1927. &movdqu ($inout2,&QWP(16*2,$inp));
  1928. &mov ($rounds,&DWP(240,$key));
  1929. &pxor ($inout3,$rndkey0); # ^ last offset_i
  1930. &pxor ($inout4,$inout3);
  1931. &pxor ($inout5,$inout4);
  1932. &pxor ($rndkey1,$inout0); # checksum
  1933. &pxor ($inout0,$inout3); # ^ offset_i
  1934. &pxor ($rndkey1,$inout1);
  1935. &pxor ($inout1,$inout4);
  1936. &pxor ($rndkey1,$inout2);
  1937. &pxor ($inout2,$inout5);
  1938. &movdqa (&QWP($checksum,"esp"),$rndkey1);
  1939. &mov ($out,&DWP($out_off,"esp"));
  1940. &call ("_aesni_encrypt3");
  1941. &xorps ($inout0,$inout3); # ^ offset_i
  1942. &xorps ($inout1,$inout4);
  1943. &xorps ($inout2,$inout5);
  1944. &movdqa ($rndkey0,$inout5); # pass last offset_i
  1945. &movdqa ($rndkey1,&QWP($checksum,"esp"));# pass the checksum
  1946. &movups (&QWP(16*0,$out,$inp),$inout0); # store output
  1947. &movups (&QWP(16*1,$out,$inp),$inout1);
  1948. &movups (&QWP(16*2,$out,$inp),$inout2);
  1949. &jmp (&label("done"));
  1950. &set_label("four",16);
  1951. &lea ($i1,&DWP(1,$block));
  1952. &lea ($i3,&DWP(3,$block));
  1953. &bsf ($i1,$i1);
  1954. &bsf ($i3,$i3);
  1955. &mov ($key,&DWP($key_off,"esp")); # restore key
  1956. &shl ($i1,4);
  1957. &shl ($i3,4);
  1958. &movdqu ($inout2,&QWP(0,$l_));
  1959. &movdqu ($inout3,&QWP(0,$l_,$i1));
  1960. &movdqa ($inout4,$inout2);
  1961. &movdqu ($inout5,&QWP(0,$l_,$i3));
  1962. &pxor ($inout2,$rndkey0); # ^ last offset_i
  1963. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  1964. &pxor ($inout3,$inout2);
  1965. &movdqu ($inout1,&QWP(16*1,$inp));
  1966. &pxor ($inout4,$inout3);
  1967. &movdqa (&QWP(16*0,"esp"),$inout2);
  1968. &pxor ($inout5,$inout4);
  1969. &movdqa (&QWP(16*1,"esp"),$inout3);
  1970. &movdqu ($inout2,&QWP(16*2,$inp));
  1971. &movdqu ($inout3,&QWP(16*3,$inp));
  1972. &mov ($rounds,&DWP(240,$key));
  1973. &pxor ($rndkey1,$inout0); # checksum
  1974. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  1975. &pxor ($rndkey1,$inout1);
  1976. &pxor ($inout1,&QWP(16*1,"esp"));
  1977. &pxor ($rndkey1,$inout2);
  1978. &pxor ($inout2,$inout4);
  1979. &pxor ($rndkey1,$inout3);
  1980. &pxor ($inout3,$inout5);
  1981. &movdqa (&QWP($checksum,"esp"),$rndkey1)
  1982. &mov ($out,&DWP($out_off,"esp"));
  1983. &call ("_aesni_encrypt4");
  1984. &xorps ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  1985. &xorps ($inout1,&QWP(16*1,"esp"));
  1986. &xorps ($inout2,$inout4);
  1987. &movups (&QWP(16*0,$out,$inp),$inout0); # store output
  1988. &xorps ($inout3,$inout5);
  1989. &movups (&QWP(16*1,$out,$inp),$inout1);
  1990. &movdqa ($rndkey0,$inout5); # pass last offset_i
  1991. &movups (&QWP(16*2,$out,$inp),$inout2);
  1992. &movdqa ($rndkey1,&QWP($checksum,"esp"));# pass the checksum
  1993. &movups (&QWP(16*3,$out,$inp),$inout3);
  1994. &set_label("done");
  1995. &mov ($key,&DWP($esp_off,"esp"));
  1996. &pxor ($inout0,$inout0); # clear register bank
  1997. &pxor ($inout1,$inout1);
  1998. &movdqa (&QWP(16*0,"esp"),$inout0); # clear stack
  1999. &pxor ($inout2,$inout2);
  2000. &movdqa (&QWP(16*1,"esp"),$inout0);
  2001. &pxor ($inout3,$inout3);
  2002. &movdqa (&QWP(16*2,"esp"),$inout0);
  2003. &pxor ($inout4,$inout4);
  2004. &movdqa (&QWP(16*3,"esp"),$inout0);
  2005. &pxor ($inout5,$inout5);
  2006. &movdqa (&QWP(16*4,"esp"),$inout0);
  2007. &movdqa (&QWP(16*5,"esp"),$inout0);
  2008. &movdqa (&QWP(16*6,"esp"),$inout0);
  2009. &lea ("esp",&DWP(0,$key));
  2010. &mov ($rounds,&wparam(5)); # &offset_i
  2011. &mov ($rounds_,&wparam(7)); # &checksum
  2012. &movdqu (&QWP(0,$rounds),$rndkey0);
  2013. &pxor ($rndkey0,$rndkey0);
  2014. &movdqu (&QWP(0,$rounds_),$rndkey1);
  2015. &pxor ($rndkey1,$rndkey1);
  2016. &function_end("aesni_ocb_encrypt");
  2017. &function_begin("aesni_ocb_decrypt");
  2018. &mov ($rounds,&wparam(5)); # &offset_i
  2019. &mov ($rounds_,&wparam(7)); # &checksum
  2020. &mov ($inp,&wparam(0));
  2021. &mov ($out,&wparam(1));
  2022. &mov ($len,&wparam(2));
  2023. &mov ($key,&wparam(3));
  2024. &movdqu ($rndkey0,&QWP(0,$rounds)); # load offset_i
  2025. &mov ($block,&wparam(4)); # start_block_num
  2026. &movdqu ($rndkey1,&QWP(0,$rounds_)); # load checksum
  2027. &mov ($l_,&wparam(6)); # L_
  2028. &mov ($rounds,"esp");
  2029. &sub ("esp",$esp_off+4); # alloca
  2030. &and ("esp",-16); # align stack
  2031. &sub ($out,$inp);
  2032. &shl ($len,4);
  2033. &lea ($len,&DWP(-16*6,$inp,$len)); # end of input - 16*6
  2034. &mov (&DWP($out_off,"esp"),$out);
  2035. &mov (&DWP($end_off,"esp"),$len);
  2036. &mov (&DWP($esp_off,"esp"),$rounds);
  2037. &mov ($rounds,&DWP(240,$key));
  2038. &test ($block,1);
  2039. &jnz (&label("odd"));
  2040. &bsf ($i3,$block);
  2041. &add ($block,1);
  2042. &shl ($i3,4);
  2043. &movdqu ($inout5,&QWP(0,$l_,$i3));
  2044. &mov ($i3,$key); # put aside key
  2045. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  2046. &lea ($inp,&DWP(16,$inp));
  2047. &pxor ($inout5,$rndkey0); # ^ last offset_i
  2048. &pxor ($inout0,$inout5); # ^ offset_i
  2049. &movdqa ($inout4,$rndkey1);
  2050. if ($inline)
  2051. { &aesni_inline_generate1("dec"); }
  2052. else
  2053. { &call ("_aesni_decrypt1"); }
  2054. &xorps ($inout0,$inout5); # ^ offset_i
  2055. &movaps ($rndkey1,$inout4); # pass the checksum
  2056. &movdqa ($rndkey0,$inout5); # pass last offset_i
  2057. &xorps ($rndkey1,$inout0); # checksum
  2058. &movups (&QWP(-16,$out,$inp),$inout0); # store output
  2059. &mov ($rounds,&DWP(240,$i3));
  2060. &mov ($key,$i3); # restore key
  2061. &mov ($len,&DWP($end_off,"esp"));
  2062. &set_label("odd");
  2063. &shl ($rounds,4);
  2064. &mov ($out,16);
  2065. &sub ($out,$rounds); # twisted rounds
  2066. &mov (&DWP($key_off,"esp"),$key);
  2067. &lea ($key,&DWP(32,$key,$rounds)); # end of key schedule
  2068. &mov (&DWP($rounds_off,"esp"),$out);
  2069. &cmp ($inp,$len);
  2070. &ja (&label("short"));
  2071. &jmp (&label("grandloop"));
  2072. &set_label("grandloop",32);
  2073. &lea ($i1,&DWP(1,$block));
  2074. &lea ($i3,&DWP(3,$block));
  2075. &lea ($i5,&DWP(5,$block));
  2076. &add ($block,6);
  2077. &bsf ($i1,$i1);
  2078. &bsf ($i3,$i3);
  2079. &bsf ($i5,$i5);
  2080. &shl ($i1,4);
  2081. &shl ($i3,4);
  2082. &shl ($i5,4);
  2083. &movdqu ($inout0,&QWP(0,$l_));
  2084. &movdqu ($inout1,&QWP(0,$l_,$i1));
  2085. &mov ($rounds,&DWP($rounds_off,"esp"));
  2086. &movdqa ($inout2,$inout0);
  2087. &movdqu ($inout3,&QWP(0,$l_,$i3));
  2088. &movdqa ($inout4,$inout0);
  2089. &movdqu ($inout5,&QWP(0,$l_,$i5));
  2090. &pxor ($inout0,$rndkey0); # ^ last offset_i
  2091. &pxor ($inout1,$inout0);
  2092. &movdqa (&QWP(16*0,"esp"),$inout0);
  2093. &pxor ($inout2,$inout1);
  2094. &movdqa (&QWP(16*1,"esp"),$inout1);
  2095. &pxor ($inout3,$inout2);
  2096. &movdqa (&QWP(16*2,"esp"),$inout2);
  2097. &pxor ($inout4,$inout3);
  2098. &movdqa (&QWP(16*3,"esp"),$inout3);
  2099. &pxor ($inout5,$inout4);
  2100. &movdqa (&QWP(16*4,"esp"),$inout4);
  2101. &movdqa (&QWP(16*5,"esp"),$inout5);
  2102. &$movekey ($rndkey0,&QWP(-48,$key,$rounds));
  2103. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  2104. &movdqu ($inout1,&QWP(16*1,$inp));
  2105. &movdqu ($inout2,&QWP(16*2,$inp));
  2106. &movdqu ($inout3,&QWP(16*3,$inp));
  2107. &movdqu ($inout4,&QWP(16*4,$inp));
  2108. &movdqu ($inout5,&QWP(16*5,$inp));
  2109. &lea ($inp,&DWP(16*6,$inp));
  2110. &movdqa (&QWP($checksum,"esp"),$rndkey1);
  2111. &pxor ($inout0,$rndkey0); # ^ roundkey[0]
  2112. &pxor ($inout1,$rndkey0);
  2113. &pxor ($inout2,$rndkey0);
  2114. &pxor ($inout3,$rndkey0);
  2115. &pxor ($inout4,$rndkey0);
  2116. &pxor ($inout5,$rndkey0);
  2117. &$movekey ($rndkey1,&QWP(-32,$key,$rounds));
  2118. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  2119. &pxor ($inout1,&QWP(16*1,"esp"));
  2120. &pxor ($inout2,&QWP(16*2,"esp"));
  2121. &pxor ($inout3,&QWP(16*3,"esp"));
  2122. &pxor ($inout4,&QWP(16*4,"esp"));
  2123. &pxor ($inout5,&QWP(16*5,"esp"));
  2124. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  2125. &aesdec ($inout0,$rndkey1);
  2126. &aesdec ($inout1,$rndkey1);
  2127. &aesdec ($inout2,$rndkey1);
  2128. &aesdec ($inout3,$rndkey1);
  2129. &aesdec ($inout4,$rndkey1);
  2130. &aesdec ($inout5,$rndkey1);
  2131. &mov ($out,&DWP($out_off,"esp"));
  2132. &mov ($len,&DWP($end_off,"esp"));
  2133. &call ("_aesni_decrypt6_enter");
  2134. &movdqa ($rndkey0,&QWP(16*5,"esp")); # pass last offset_i
  2135. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  2136. &movdqa ($rndkey1,&QWP($checksum,"esp"));
  2137. &pxor ($inout1,&QWP(16*1,"esp"));
  2138. &pxor ($inout2,&QWP(16*2,"esp"));
  2139. &pxor ($inout3,&QWP(16*3,"esp"));
  2140. &pxor ($inout4,&QWP(16*4,"esp"));
  2141. &pxor ($inout5,$rndkey0);
  2142. &pxor ($rndkey1,$inout0); # checksum
  2143. &movdqu (&QWP(-16*6,$out,$inp),$inout0);# store output
  2144. &pxor ($rndkey1,$inout1);
  2145. &movdqu (&QWP(-16*5,$out,$inp),$inout1);
  2146. &pxor ($rndkey1,$inout2);
  2147. &movdqu (&QWP(-16*4,$out,$inp),$inout2);
  2148. &pxor ($rndkey1,$inout3);
  2149. &movdqu (&QWP(-16*3,$out,$inp),$inout3);
  2150. &pxor ($rndkey1,$inout4);
  2151. &movdqu (&QWP(-16*2,$out,$inp),$inout4);
  2152. &pxor ($rndkey1,$inout5);
  2153. &movdqu (&QWP(-16*1,$out,$inp),$inout5);
  2154. &cmp ($inp,$len); # done yet?
  2155. &jb (&label("grandloop"));
  2156. &set_label("short");
  2157. &add ($len,16*6);
  2158. &sub ($len,$inp);
  2159. &jz (&label("done"));
  2160. &cmp ($len,16*2);
  2161. &jb (&label("one"));
  2162. &je (&label("two"));
  2163. &cmp ($len,16*4);
  2164. &jb (&label("three"));
  2165. &je (&label("four"));
  2166. &lea ($i1,&DWP(1,$block));
  2167. &lea ($i3,&DWP(3,$block));
  2168. &bsf ($i1,$i1);
  2169. &bsf ($i3,$i3);
  2170. &shl ($i1,4);
  2171. &shl ($i3,4);
  2172. &movdqu ($inout0,&QWP(0,$l_));
  2173. &movdqu ($inout1,&QWP(0,$l_,$i1));
  2174. &mov ($rounds,&DWP($rounds_off,"esp"));
  2175. &movdqa ($inout2,$inout0);
  2176. &movdqu ($inout3,&QWP(0,$l_,$i3));
  2177. &movdqa ($inout4,$inout0);
  2178. &pxor ($inout0,$rndkey0); # ^ last offset_i
  2179. &pxor ($inout1,$inout0);
  2180. &movdqa (&QWP(16*0,"esp"),$inout0);
  2181. &pxor ($inout2,$inout1);
  2182. &movdqa (&QWP(16*1,"esp"),$inout1);
  2183. &pxor ($inout3,$inout2);
  2184. &movdqa (&QWP(16*2,"esp"),$inout2);
  2185. &pxor ($inout4,$inout3);
  2186. &movdqa (&QWP(16*3,"esp"),$inout3);
  2187. &pxor ($inout5,$inout4);
  2188. &movdqa (&QWP(16*4,"esp"),$inout4);
  2189. &$movekey ($rndkey0,&QWP(-48,$key,$rounds));
  2190. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  2191. &movdqu ($inout1,&QWP(16*1,$inp));
  2192. &movdqu ($inout2,&QWP(16*2,$inp));
  2193. &movdqu ($inout3,&QWP(16*3,$inp));
  2194. &movdqu ($inout4,&QWP(16*4,$inp));
  2195. &pxor ($inout5,$inout5);
  2196. &movdqa (&QWP($checksum,"esp"),$rndkey1);
  2197. &pxor ($inout0,$rndkey0); # ^ roundkey[0]
  2198. &pxor ($inout1,$rndkey0);
  2199. &pxor ($inout2,$rndkey0);
  2200. &pxor ($inout3,$rndkey0);
  2201. &pxor ($inout4,$rndkey0);
  2202. &$movekey ($rndkey1,&QWP(-32,$key,$rounds));
  2203. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  2204. &pxor ($inout1,&QWP(16*1,"esp"));
  2205. &pxor ($inout2,&QWP(16*2,"esp"));
  2206. &pxor ($inout3,&QWP(16*3,"esp"));
  2207. &pxor ($inout4,&QWP(16*4,"esp"));
  2208. &$movekey ($rndkey0,&QWP(-16,$key,$rounds));
  2209. &aesdec ($inout0,$rndkey1);
  2210. &aesdec ($inout1,$rndkey1);
  2211. &aesdec ($inout2,$rndkey1);
  2212. &aesdec ($inout3,$rndkey1);
  2213. &aesdec ($inout4,$rndkey1);
  2214. &aesdec ($inout5,$rndkey1);
  2215. &mov ($out,&DWP($out_off,"esp"));
  2216. &call ("_aesni_decrypt6_enter");
  2217. &movdqa ($rndkey0,&QWP(16*4,"esp")); # pass last offset_i
  2218. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  2219. &movdqa ($rndkey1,&QWP($checksum,"esp"));
  2220. &pxor ($inout1,&QWP(16*1,"esp"));
  2221. &pxor ($inout2,&QWP(16*2,"esp"));
  2222. &pxor ($inout3,&QWP(16*3,"esp"));
  2223. &pxor ($inout4,$rndkey0);
  2224. &pxor ($rndkey1,$inout0); # checksum
  2225. &movdqu (&QWP(16*0,$out,$inp),$inout0); # store output
  2226. &pxor ($rndkey1,$inout1);
  2227. &movdqu (&QWP(16*1,$out,$inp),$inout1);
  2228. &pxor ($rndkey1,$inout2);
  2229. &movdqu (&QWP(16*2,$out,$inp),$inout2);
  2230. &pxor ($rndkey1,$inout3);
  2231. &movdqu (&QWP(16*3,$out,$inp),$inout3);
  2232. &pxor ($rndkey1,$inout4);
  2233. &movdqu (&QWP(16*4,$out,$inp),$inout4);
  2234. &jmp (&label("done"));
  2235. &set_label("one",16);
  2236. &movdqu ($inout5,&QWP(0,$l_));
  2237. &mov ($key,&DWP($key_off,"esp")); # restore key
  2238. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  2239. &mov ($rounds,&DWP(240,$key));
  2240. &pxor ($inout5,$rndkey0); # ^ last offset_i
  2241. &pxor ($inout0,$inout5); # ^ offset_i
  2242. &movdqa ($inout4,$rndkey1);
  2243. &mov ($out,&DWP($out_off,"esp"));
  2244. if ($inline)
  2245. { &aesni_inline_generate1("dec"); }
  2246. else
  2247. { &call ("_aesni_decrypt1"); }
  2248. &xorps ($inout0,$inout5); # ^ offset_i
  2249. &movaps ($rndkey1,$inout4); # pass the checksum
  2250. &movdqa ($rndkey0,$inout5); # pass last offset_i
  2251. &xorps ($rndkey1,$inout0); # checksum
  2252. &movups (&QWP(0,$out,$inp),$inout0);
  2253. &jmp (&label("done"));
  2254. &set_label("two",16);
  2255. &lea ($i1,&DWP(1,$block));
  2256. &mov ($key,&DWP($key_off,"esp")); # restore key
  2257. &bsf ($i1,$i1);
  2258. &shl ($i1,4);
  2259. &movdqu ($inout4,&QWP(0,$l_));
  2260. &movdqu ($inout5,&QWP(0,$l_,$i1));
  2261. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  2262. &movdqu ($inout1,&QWP(16*1,$inp));
  2263. &mov ($rounds,&DWP(240,$key));
  2264. &movdqa ($inout3,$rndkey1);
  2265. &pxor ($inout4,$rndkey0); # ^ last offset_i
  2266. &pxor ($inout5,$inout4);
  2267. &pxor ($inout0,$inout4); # ^ offset_i
  2268. &pxor ($inout1,$inout5);
  2269. &mov ($out,&DWP($out_off,"esp"));
  2270. &call ("_aesni_decrypt2");
  2271. &xorps ($inout0,$inout4); # ^ offset_i
  2272. &xorps ($inout1,$inout5);
  2273. &movdqa ($rndkey0,$inout5); # pass last offset_i
  2274. &xorps ($inout3,$inout0); # checksum
  2275. &movups (&QWP(16*0,$out,$inp),$inout0); # store output
  2276. &xorps ($inout3,$inout1);
  2277. &movups (&QWP(16*1,$out,$inp),$inout1);
  2278. &movaps ($rndkey1,$inout3); # pass the checksum
  2279. &jmp (&label("done"));
  2280. &set_label("three",16);
  2281. &lea ($i1,&DWP(1,$block));
  2282. &mov ($key,&DWP($key_off,"esp")); # restore key
  2283. &bsf ($i1,$i1);
  2284. &shl ($i1,4);
  2285. &movdqu ($inout3,&QWP(0,$l_));
  2286. &movdqu ($inout4,&QWP(0,$l_,$i1));
  2287. &movdqa ($inout5,$inout3);
  2288. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  2289. &movdqu ($inout1,&QWP(16*1,$inp));
  2290. &movdqu ($inout2,&QWP(16*2,$inp));
  2291. &mov ($rounds,&DWP(240,$key));
  2292. &movdqa (&QWP($checksum,"esp"),$rndkey1);
  2293. &pxor ($inout3,$rndkey0); # ^ last offset_i
  2294. &pxor ($inout4,$inout3);
  2295. &pxor ($inout5,$inout4);
  2296. &pxor ($inout0,$inout3); # ^ offset_i
  2297. &pxor ($inout1,$inout4);
  2298. &pxor ($inout2,$inout5);
  2299. &mov ($out,&DWP($out_off,"esp"));
  2300. &call ("_aesni_decrypt3");
  2301. &movdqa ($rndkey1,&QWP($checksum,"esp"));# pass the checksum
  2302. &xorps ($inout0,$inout3); # ^ offset_i
  2303. &xorps ($inout1,$inout4);
  2304. &xorps ($inout2,$inout5);
  2305. &movups (&QWP(16*0,$out,$inp),$inout0); # store output
  2306. &pxor ($rndkey1,$inout0); # checksum
  2307. &movdqa ($rndkey0,$inout5); # pass last offset_i
  2308. &movups (&QWP(16*1,$out,$inp),$inout1);
  2309. &pxor ($rndkey1,$inout1);
  2310. &movups (&QWP(16*2,$out,$inp),$inout2);
  2311. &pxor ($rndkey1,$inout2);
  2312. &jmp (&label("done"));
  2313. &set_label("four",16);
  2314. &lea ($i1,&DWP(1,$block));
  2315. &lea ($i3,&DWP(3,$block));
  2316. &bsf ($i1,$i1);
  2317. &bsf ($i3,$i3);
  2318. &mov ($key,&DWP($key_off,"esp")); # restore key
  2319. &shl ($i1,4);
  2320. &shl ($i3,4);
  2321. &movdqu ($inout2,&QWP(0,$l_));
  2322. &movdqu ($inout3,&QWP(0,$l_,$i1));
  2323. &movdqa ($inout4,$inout2);
  2324. &movdqu ($inout5,&QWP(0,$l_,$i3));
  2325. &pxor ($inout2,$rndkey0); # ^ last offset_i
  2326. &movdqu ($inout0,&QWP(16*0,$inp)); # load input
  2327. &pxor ($inout3,$inout2);
  2328. &movdqu ($inout1,&QWP(16*1,$inp));
  2329. &pxor ($inout4,$inout3);
  2330. &movdqa (&QWP(16*0,"esp"),$inout2);
  2331. &pxor ($inout5,$inout4);
  2332. &movdqa (&QWP(16*1,"esp"),$inout3);
  2333. &movdqu ($inout2,&QWP(16*2,$inp));
  2334. &movdqu ($inout3,&QWP(16*3,$inp));
  2335. &mov ($rounds,&DWP(240,$key));
  2336. &movdqa (&QWP($checksum,"esp"),$rndkey1);
  2337. &pxor ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  2338. &pxor ($inout1,&QWP(16*1,"esp"));
  2339. &pxor ($inout2,$inout4);
  2340. &pxor ($inout3,$inout5);
  2341. &mov ($out,&DWP($out_off,"esp"));
  2342. &call ("_aesni_decrypt4");
  2343. &movdqa ($rndkey1,&QWP($checksum,"esp"));# pass the checksum
  2344. &xorps ($inout0,&QWP(16*0,"esp")); # ^ offset_i
  2345. &xorps ($inout1,&QWP(16*1,"esp"));
  2346. &xorps ($inout2,$inout4);
  2347. &movups (&QWP(16*0,$out,$inp),$inout0); # store output
  2348. &pxor ($rndkey1,$inout0); # checksum
  2349. &xorps ($inout3,$inout5);
  2350. &movups (&QWP(16*1,$out,$inp),$inout1);
  2351. &pxor ($rndkey1,$inout1);
  2352. &movdqa ($rndkey0,$inout5); # pass last offset_i
  2353. &movups (&QWP(16*2,$out,$inp),$inout2);
  2354. &pxor ($rndkey1,$inout2);
  2355. &movups (&QWP(16*3,$out,$inp),$inout3);
  2356. &pxor ($rndkey1,$inout3);
  2357. &set_label("done");
  2358. &mov ($key,&DWP($esp_off,"esp"));
  2359. &pxor ($inout0,$inout0); # clear register bank
  2360. &pxor ($inout1,$inout1);
  2361. &movdqa (&QWP(16*0,"esp"),$inout0); # clear stack
  2362. &pxor ($inout2,$inout2);
  2363. &movdqa (&QWP(16*1,"esp"),$inout0);
  2364. &pxor ($inout3,$inout3);
  2365. &movdqa (&QWP(16*2,"esp"),$inout0);
  2366. &pxor ($inout4,$inout4);
  2367. &movdqa (&QWP(16*3,"esp"),$inout0);
  2368. &pxor ($inout5,$inout5);
  2369. &movdqa (&QWP(16*4,"esp"),$inout0);
  2370. &movdqa (&QWP(16*5,"esp"),$inout0);
  2371. &movdqa (&QWP(16*6,"esp"),$inout0);
  2372. &lea ("esp",&DWP(0,$key));
  2373. &mov ($rounds,&wparam(5)); # &offset_i
  2374. &mov ($rounds_,&wparam(7)); # &checksum
  2375. &movdqu (&QWP(0,$rounds),$rndkey0);
  2376. &pxor ($rndkey0,$rndkey0);
  2377. &movdqu (&QWP(0,$rounds_),$rndkey1);
  2378. &pxor ($rndkey1,$rndkey1);
  2379. &function_end("aesni_ocb_decrypt");
  2380. }
  2381. }
  2382. ######################################################################
  2383. # void $PREFIX_cbc_encrypt (const void *inp, void *out,
  2384. # size_t length, const AES_KEY *key,
  2385. # unsigned char *ivp,const int enc);
  2386. &function_begin("${PREFIX}_cbc_encrypt");
  2387. &mov ($inp,&wparam(0));
  2388. &mov ($rounds_,"esp");
  2389. &mov ($out,&wparam(1));
  2390. &sub ($rounds_,24);
  2391. &mov ($len,&wparam(2));
  2392. &and ($rounds_,-16);
  2393. &mov ($key,&wparam(3));
  2394. &mov ($key_,&wparam(4));
  2395. &test ($len,$len);
  2396. &jz (&label("cbc_abort"));
  2397. &cmp (&wparam(5),0);
  2398. &xchg ($rounds_,"esp"); # alloca
  2399. &movups ($ivec,&QWP(0,$key_)); # load IV
  2400. &mov ($rounds,&DWP(240,$key));
  2401. &mov ($key_,$key); # backup $key
  2402. &mov (&DWP(16,"esp"),$rounds_); # save original %esp
  2403. &mov ($rounds_,$rounds); # backup $rounds
  2404. &je (&label("cbc_decrypt"));
  2405. &movaps ($inout0,$ivec);
  2406. &cmp ($len,16);
  2407. &jb (&label("cbc_enc_tail"));
  2408. &sub ($len,16);
  2409. &jmp (&label("cbc_enc_loop"));
  2410. &set_label("cbc_enc_loop",16);
  2411. &movups ($ivec,&QWP(0,$inp)); # input actually
  2412. &lea ($inp,&DWP(16,$inp));
  2413. if ($inline)
  2414. { &aesni_inline_generate1("enc",$inout0,$ivec); }
  2415. else
  2416. { &xorps($inout0,$ivec); &call("_aesni_encrypt1"); }
  2417. &mov ($rounds,$rounds_); # restore $rounds
  2418. &mov ($key,$key_); # restore $key
  2419. &movups (&QWP(0,$out),$inout0); # store output
  2420. &lea ($out,&DWP(16,$out));
  2421. &sub ($len,16);
  2422. &jnc (&label("cbc_enc_loop"));
  2423. &add ($len,16);
  2424. &jnz (&label("cbc_enc_tail"));
  2425. &movaps ($ivec,$inout0);
  2426. &pxor ($inout0,$inout0);
  2427. &jmp (&label("cbc_ret"));
  2428. &set_label("cbc_enc_tail");
  2429. &mov ("ecx",$len); # zaps $rounds
  2430. &data_word(0xA4F3F689); # rep movsb
  2431. &mov ("ecx",16); # zero tail
  2432. &sub ("ecx",$len);
  2433. &xor ("eax","eax"); # zaps $len
  2434. &data_word(0xAAF3F689); # rep stosb
  2435. &lea ($out,&DWP(-16,$out)); # rewind $out by 1 block
  2436. &mov ($rounds,$rounds_); # restore $rounds
  2437. &mov ($inp,$out); # $inp and $out are the same
  2438. &mov ($key,$key_); # restore $key
  2439. &jmp (&label("cbc_enc_loop"));
  2440. ######################################################################
  2441. &set_label("cbc_decrypt",16);
  2442. &cmp ($len,0x50);
  2443. &jbe (&label("cbc_dec_tail"));
  2444. &movaps (&QWP(0,"esp"),$ivec); # save IV
  2445. &sub ($len,0x50);
  2446. &jmp (&label("cbc_dec_loop6_enter"));
  2447. &set_label("cbc_dec_loop6",16);
  2448. &movaps (&QWP(0,"esp"),$rndkey0); # save IV
  2449. &movups (&QWP(0,$out),$inout5);
  2450. &lea ($out,&DWP(0x10,$out));
  2451. &set_label("cbc_dec_loop6_enter");
  2452. &movdqu ($inout0,&QWP(0,$inp));
  2453. &movdqu ($inout1,&QWP(0x10,$inp));
  2454. &movdqu ($inout2,&QWP(0x20,$inp));
  2455. &movdqu ($inout3,&QWP(0x30,$inp));
  2456. &movdqu ($inout4,&QWP(0x40,$inp));
  2457. &movdqu ($inout5,&QWP(0x50,$inp));
  2458. &call ("_aesni_decrypt6");
  2459. &movups ($rndkey1,&QWP(0,$inp));
  2460. &movups ($rndkey0,&QWP(0x10,$inp));
  2461. &xorps ($inout0,&QWP(0,"esp")); # ^=IV
  2462. &xorps ($inout1,$rndkey1);
  2463. &movups ($rndkey1,&QWP(0x20,$inp));
  2464. &xorps ($inout2,$rndkey0);
  2465. &movups ($rndkey0,&QWP(0x30,$inp));
  2466. &xorps ($inout3,$rndkey1);
  2467. &movups ($rndkey1,&QWP(0x40,$inp));
  2468. &xorps ($inout4,$rndkey0);
  2469. &movups ($rndkey0,&QWP(0x50,$inp)); # IV
  2470. &xorps ($inout5,$rndkey1);
  2471. &movups (&QWP(0,$out),$inout0);
  2472. &movups (&QWP(0x10,$out),$inout1);
  2473. &lea ($inp,&DWP(0x60,$inp));
  2474. &movups (&QWP(0x20,$out),$inout2);
  2475. &mov ($rounds,$rounds_); # restore $rounds
  2476. &movups (&QWP(0x30,$out),$inout3);
  2477. &mov ($key,$key_); # restore $key
  2478. &movups (&QWP(0x40,$out),$inout4);
  2479. &lea ($out,&DWP(0x50,$out));
  2480. &sub ($len,0x60);
  2481. &ja (&label("cbc_dec_loop6"));
  2482. &movaps ($inout0,$inout5);
  2483. &movaps ($ivec,$rndkey0);
  2484. &add ($len,0x50);
  2485. &jle (&label("cbc_dec_clear_tail_collected"));
  2486. &movups (&QWP(0,$out),$inout0);
  2487. &lea ($out,&DWP(0x10,$out));
  2488. &set_label("cbc_dec_tail");
  2489. &movups ($inout0,&QWP(0,$inp));
  2490. &movaps ($in0,$inout0);
  2491. &cmp ($len,0x10);
  2492. &jbe (&label("cbc_dec_one"));
  2493. &movups ($inout1,&QWP(0x10,$inp));
  2494. &movaps ($in1,$inout1);
  2495. &cmp ($len,0x20);
  2496. &jbe (&label("cbc_dec_two"));
  2497. &movups ($inout2,&QWP(0x20,$inp));
  2498. &cmp ($len,0x30);
  2499. &jbe (&label("cbc_dec_three"));
  2500. &movups ($inout3,&QWP(0x30,$inp));
  2501. &cmp ($len,0x40);
  2502. &jbe (&label("cbc_dec_four"));
  2503. &movups ($inout4,&QWP(0x40,$inp));
  2504. &movaps (&QWP(0,"esp"),$ivec); # save IV
  2505. &movups ($inout0,&QWP(0,$inp));
  2506. &xorps ($inout5,$inout5);
  2507. &call ("_aesni_decrypt6");
  2508. &movups ($rndkey1,&QWP(0,$inp));
  2509. &movups ($rndkey0,&QWP(0x10,$inp));
  2510. &xorps ($inout0,&QWP(0,"esp")); # ^= IV
  2511. &xorps ($inout1,$rndkey1);
  2512. &movups ($rndkey1,&QWP(0x20,$inp));
  2513. &xorps ($inout2,$rndkey0);
  2514. &movups ($rndkey0,&QWP(0x30,$inp));
  2515. &xorps ($inout3,$rndkey1);
  2516. &movups ($ivec,&QWP(0x40,$inp)); # IV
  2517. &xorps ($inout4,$rndkey0);
  2518. &movups (&QWP(0,$out),$inout0);
  2519. &movups (&QWP(0x10,$out),$inout1);
  2520. &pxor ($inout1,$inout1);
  2521. &movups (&QWP(0x20,$out),$inout2);
  2522. &pxor ($inout2,$inout2);
  2523. &movups (&QWP(0x30,$out),$inout3);
  2524. &pxor ($inout3,$inout3);
  2525. &lea ($out,&DWP(0x40,$out));
  2526. &movaps ($inout0,$inout4);
  2527. &pxor ($inout4,$inout4);
  2528. &sub ($len,0x50);
  2529. &jmp (&label("cbc_dec_tail_collected"));
  2530. &set_label("cbc_dec_one",16);
  2531. if ($inline)
  2532. { &aesni_inline_generate1("dec"); }
  2533. else
  2534. { &call ("_aesni_decrypt1"); }
  2535. &xorps ($inout0,$ivec);
  2536. &movaps ($ivec,$in0);
  2537. &sub ($len,0x10);
  2538. &jmp (&label("cbc_dec_tail_collected"));
  2539. &set_label("cbc_dec_two",16);
  2540. &call ("_aesni_decrypt2");
  2541. &xorps ($inout0,$ivec);
  2542. &xorps ($inout1,$in0);
  2543. &movups (&QWP(0,$out),$inout0);
  2544. &movaps ($inout0,$inout1);
  2545. &pxor ($inout1,$inout1);
  2546. &lea ($out,&DWP(0x10,$out));
  2547. &movaps ($ivec,$in1);
  2548. &sub ($len,0x20);
  2549. &jmp (&label("cbc_dec_tail_collected"));
  2550. &set_label("cbc_dec_three",16);
  2551. &call ("_aesni_decrypt3");
  2552. &xorps ($inout0,$ivec);
  2553. &xorps ($inout1,$in0);
  2554. &xorps ($inout2,$in1);
  2555. &movups (&QWP(0,$out),$inout0);
  2556. &movaps ($inout0,$inout2);
  2557. &pxor ($inout2,$inout2);
  2558. &movups (&QWP(0x10,$out),$inout1);
  2559. &pxor ($inout1,$inout1);
  2560. &lea ($out,&DWP(0x20,$out));
  2561. &movups ($ivec,&QWP(0x20,$inp));
  2562. &sub ($len,0x30);
  2563. &jmp (&label("cbc_dec_tail_collected"));
  2564. &set_label("cbc_dec_four",16);
  2565. &call ("_aesni_decrypt4");
  2566. &movups ($rndkey1,&QWP(0x10,$inp));
  2567. &movups ($rndkey0,&QWP(0x20,$inp));
  2568. &xorps ($inout0,$ivec);
  2569. &movups ($ivec,&QWP(0x30,$inp));
  2570. &xorps ($inout1,$in0);
  2571. &movups (&QWP(0,$out),$inout0);
  2572. &xorps ($inout2,$rndkey1);
  2573. &movups (&QWP(0x10,$out),$inout1);
  2574. &pxor ($inout1,$inout1);
  2575. &xorps ($inout3,$rndkey0);
  2576. &movups (&QWP(0x20,$out),$inout2);
  2577. &pxor ($inout2,$inout2);
  2578. &lea ($out,&DWP(0x30,$out));
  2579. &movaps ($inout0,$inout3);
  2580. &pxor ($inout3,$inout3);
  2581. &sub ($len,0x40);
  2582. &jmp (&label("cbc_dec_tail_collected"));
  2583. &set_label("cbc_dec_clear_tail_collected",16);
  2584. &pxor ($inout1,$inout1);
  2585. &pxor ($inout2,$inout2);
  2586. &pxor ($inout3,$inout3);
  2587. &pxor ($inout4,$inout4);
  2588. &set_label("cbc_dec_tail_collected");
  2589. &and ($len,15);
  2590. &jnz (&label("cbc_dec_tail_partial"));
  2591. &movups (&QWP(0,$out),$inout0);
  2592. &pxor ($rndkey0,$rndkey0);
  2593. &jmp (&label("cbc_ret"));
  2594. &set_label("cbc_dec_tail_partial",16);
  2595. &movaps (&QWP(0,"esp"),$inout0);
  2596. &pxor ($rndkey0,$rndkey0);
  2597. &mov ("ecx",16);
  2598. &mov ($inp,"esp");
  2599. &sub ("ecx",$len);
  2600. &data_word(0xA4F3F689); # rep movsb
  2601. &movdqa (&QWP(0,"esp"),$inout0);
  2602. &set_label("cbc_ret");
  2603. &mov ("esp",&DWP(16,"esp")); # pull original %esp
  2604. &mov ($key_,&wparam(4));
  2605. &pxor ($inout0,$inout0);
  2606. &pxor ($rndkey1,$rndkey1);
  2607. &movups (&QWP(0,$key_),$ivec); # output IV
  2608. &pxor ($ivec,$ivec);
  2609. &set_label("cbc_abort");
  2610. &function_end("${PREFIX}_cbc_encrypt");
  2611. ######################################################################
  2612. # Mechanical port from aesni-x86_64.pl.
  2613. #
  2614. # _aesni_set_encrypt_key is private interface,
  2615. # input:
  2616. # "eax" const unsigned char *userKey
  2617. # $rounds int bits
  2618. # $key AES_KEY *key
  2619. # output:
  2620. # "eax" return code
  2621. # $round rounds
  2622. &function_begin_B("_aesni_set_encrypt_key");
  2623. &push ("ebp");
  2624. &push ("ebx");
  2625. &test ("eax","eax");
  2626. &jz (&label("bad_pointer"));
  2627. &test ($key,$key);
  2628. &jz (&label("bad_pointer"));
  2629. &call (&label("pic"));
  2630. &set_label("pic");
  2631. &blindpop("ebx");
  2632. &lea ("ebx",&DWP(&label("key_const")."-".&label("pic"),"ebx"));
  2633. &picmeup("ebp","OPENSSL_ia32cap_P","ebx",&label("key_const"));
  2634. &movups ("xmm0",&QWP(0,"eax")); # pull first 128 bits of *userKey
  2635. &xorps ("xmm4","xmm4"); # low dword of xmm4 is assumed 0
  2636. &mov ("ebp",&DWP(4,"ebp"));
  2637. &lea ($key,&DWP(16,$key));
  2638. &and ("ebp",1<<28|1<<11); # AVX and XOP bits
  2639. &cmp ($rounds,256);
  2640. &je (&label("14rounds"));
  2641. &cmp ($rounds,192);
  2642. &je (&label("12rounds"));
  2643. &cmp ($rounds,128);
  2644. &jne (&label("bad_keybits"));
  2645. &set_label("10rounds",16);
  2646. &cmp ("ebp",1<<28);
  2647. &je (&label("10rounds_alt"));
  2648. &mov ($rounds,9);
  2649. &$movekey (&QWP(-16,$key),"xmm0"); # round 0
  2650. &aeskeygenassist("xmm1","xmm0",0x01); # round 1
  2651. &call (&label("key_128_cold"));
  2652. &aeskeygenassist("xmm1","xmm0",0x2); # round 2
  2653. &call (&label("key_128"));
  2654. &aeskeygenassist("xmm1","xmm0",0x04); # round 3
  2655. &call (&label("key_128"));
  2656. &aeskeygenassist("xmm1","xmm0",0x08); # round 4
  2657. &call (&label("key_128"));
  2658. &aeskeygenassist("xmm1","xmm0",0x10); # round 5
  2659. &call (&label("key_128"));
  2660. &aeskeygenassist("xmm1","xmm0",0x20); # round 6
  2661. &call (&label("key_128"));
  2662. &aeskeygenassist("xmm1","xmm0",0x40); # round 7
  2663. &call (&label("key_128"));
  2664. &aeskeygenassist("xmm1","xmm0",0x80); # round 8
  2665. &call (&label("key_128"));
  2666. &aeskeygenassist("xmm1","xmm0",0x1b); # round 9
  2667. &call (&label("key_128"));
  2668. &aeskeygenassist("xmm1","xmm0",0x36); # round 10
  2669. &call (&label("key_128"));
  2670. &$movekey (&QWP(0,$key),"xmm0");
  2671. &mov (&DWP(80,$key),$rounds);
  2672. &jmp (&label("good_key"));
  2673. &set_label("key_128",16);
  2674. &$movekey (&QWP(0,$key),"xmm0");
  2675. &lea ($key,&DWP(16,$key));
  2676. &set_label("key_128_cold");
  2677. &shufps ("xmm4","xmm0",0b00010000);
  2678. &xorps ("xmm0","xmm4");
  2679. &shufps ("xmm4","xmm0",0b10001100);
  2680. &xorps ("xmm0","xmm4");
  2681. &shufps ("xmm1","xmm1",0b11111111); # critical path
  2682. &xorps ("xmm0","xmm1");
  2683. &ret();
  2684. &set_label("10rounds_alt",16);
  2685. &movdqa ("xmm5",&QWP(0x00,"ebx"));
  2686. &mov ($rounds,8);
  2687. &movdqa ("xmm4",&QWP(0x20,"ebx"));
  2688. &movdqa ("xmm2","xmm0");
  2689. &movdqu (&QWP(-16,$key),"xmm0");
  2690. &set_label("loop_key128");
  2691. &pshufb ("xmm0","xmm5");
  2692. &aesenclast ("xmm0","xmm4");
  2693. &pslld ("xmm4",1);
  2694. &lea ($key,&DWP(16,$key));
  2695. &movdqa ("xmm3","xmm2");
  2696. &pslldq ("xmm2",4);
  2697. &pxor ("xmm3","xmm2");
  2698. &pslldq ("xmm2",4);
  2699. &pxor ("xmm3","xmm2");
  2700. &pslldq ("xmm2",4);
  2701. &pxor ("xmm2","xmm3");
  2702. &pxor ("xmm0","xmm2");
  2703. &movdqu (&QWP(-16,$key),"xmm0");
  2704. &movdqa ("xmm2","xmm0");
  2705. &dec ($rounds);
  2706. &jnz (&label("loop_key128"));
  2707. &movdqa ("xmm4",&QWP(0x30,"ebx"));
  2708. &pshufb ("xmm0","xmm5");
  2709. &aesenclast ("xmm0","xmm4");
  2710. &pslld ("xmm4",1);
  2711. &movdqa ("xmm3","xmm2");
  2712. &pslldq ("xmm2",4);
  2713. &pxor ("xmm3","xmm2");
  2714. &pslldq ("xmm2",4);
  2715. &pxor ("xmm3","xmm2");
  2716. &pslldq ("xmm2",4);
  2717. &pxor ("xmm2","xmm3");
  2718. &pxor ("xmm0","xmm2");
  2719. &movdqu (&QWP(0,$key),"xmm0");
  2720. &movdqa ("xmm2","xmm0");
  2721. &pshufb ("xmm0","xmm5");
  2722. &aesenclast ("xmm0","xmm4");
  2723. &movdqa ("xmm3","xmm2");
  2724. &pslldq ("xmm2",4);
  2725. &pxor ("xmm3","xmm2");
  2726. &pslldq ("xmm2",4);
  2727. &pxor ("xmm3","xmm2");
  2728. &pslldq ("xmm2",4);
  2729. &pxor ("xmm2","xmm3");
  2730. &pxor ("xmm0","xmm2");
  2731. &movdqu (&QWP(16,$key),"xmm0");
  2732. &mov ($rounds,9);
  2733. &mov (&DWP(96,$key),$rounds);
  2734. &jmp (&label("good_key"));
  2735. &set_label("12rounds",16);
  2736. &movq ("xmm2",&QWP(16,"eax")); # remaining 1/3 of *userKey
  2737. &cmp ("ebp",1<<28);
  2738. &je (&label("12rounds_alt"));
  2739. &mov ($rounds,11);
  2740. &$movekey (&QWP(-16,$key),"xmm0"); # round 0
  2741. &aeskeygenassist("xmm1","xmm2",0x01); # round 1,2
  2742. &call (&label("key_192a_cold"));
  2743. &aeskeygenassist("xmm1","xmm2",0x02); # round 2,3
  2744. &call (&label("key_192b"));
  2745. &aeskeygenassist("xmm1","xmm2",0x04); # round 4,5
  2746. &call (&label("key_192a"));
  2747. &aeskeygenassist("xmm1","xmm2",0x08); # round 5,6
  2748. &call (&label("key_192b"));
  2749. &aeskeygenassist("xmm1","xmm2",0x10); # round 7,8
  2750. &call (&label("key_192a"));
  2751. &aeskeygenassist("xmm1","xmm2",0x20); # round 8,9
  2752. &call (&label("key_192b"));
  2753. &aeskeygenassist("xmm1","xmm2",0x40); # round 10,11
  2754. &call (&label("key_192a"));
  2755. &aeskeygenassist("xmm1","xmm2",0x80); # round 11,12
  2756. &call (&label("key_192b"));
  2757. &$movekey (&QWP(0,$key),"xmm0");
  2758. &mov (&DWP(48,$key),$rounds);
  2759. &jmp (&label("good_key"));
  2760. &set_label("key_192a",16);
  2761. &$movekey (&QWP(0,$key),"xmm0");
  2762. &lea ($key,&DWP(16,$key));
  2763. &set_label("key_192a_cold",16);
  2764. &movaps ("xmm5","xmm2");
  2765. &set_label("key_192b_warm");
  2766. &shufps ("xmm4","xmm0",0b00010000);
  2767. &movdqa ("xmm3","xmm2");
  2768. &xorps ("xmm0","xmm4");
  2769. &shufps ("xmm4","xmm0",0b10001100);
  2770. &pslldq ("xmm3",4);
  2771. &xorps ("xmm0","xmm4");
  2772. &pshufd ("xmm1","xmm1",0b01010101); # critical path
  2773. &pxor ("xmm2","xmm3");
  2774. &pxor ("xmm0","xmm1");
  2775. &pshufd ("xmm3","xmm0",0b11111111);
  2776. &pxor ("xmm2","xmm3");
  2777. &ret();
  2778. &set_label("key_192b",16);
  2779. &movaps ("xmm3","xmm0");
  2780. &shufps ("xmm5","xmm0",0b01000100);
  2781. &$movekey (&QWP(0,$key),"xmm5");
  2782. &shufps ("xmm3","xmm2",0b01001110);
  2783. &$movekey (&QWP(16,$key),"xmm3");
  2784. &lea ($key,&DWP(32,$key));
  2785. &jmp (&label("key_192b_warm"));
  2786. &set_label("12rounds_alt",16);
  2787. &movdqa ("xmm5",&QWP(0x10,"ebx"));
  2788. &movdqa ("xmm4",&QWP(0x20,"ebx"));
  2789. &mov ($rounds,8);
  2790. &movdqu (&QWP(-16,$key),"xmm0");
  2791. &set_label("loop_key192");
  2792. &movq (&QWP(0,$key),"xmm2");
  2793. &movdqa ("xmm1","xmm2");
  2794. &pshufb ("xmm2","xmm5");
  2795. &aesenclast ("xmm2","xmm4");
  2796. &pslld ("xmm4",1);
  2797. &lea ($key,&DWP(24,$key));
  2798. &movdqa ("xmm3","xmm0");
  2799. &pslldq ("xmm0",4);
  2800. &pxor ("xmm3","xmm0");
  2801. &pslldq ("xmm0",4);
  2802. &pxor ("xmm3","xmm0");
  2803. &pslldq ("xmm0",4);
  2804. &pxor ("xmm0","xmm3");
  2805. &pshufd ("xmm3","xmm0",0xff);
  2806. &pxor ("xmm3","xmm1");
  2807. &pslldq ("xmm1",4);
  2808. &pxor ("xmm3","xmm1");
  2809. &pxor ("xmm0","xmm2");
  2810. &pxor ("xmm2","xmm3");
  2811. &movdqu (&QWP(-16,$key),"xmm0");
  2812. &dec ($rounds);
  2813. &jnz (&label("loop_key192"));
  2814. &mov ($rounds,11);
  2815. &mov (&DWP(32,$key),$rounds);
  2816. &jmp (&label("good_key"));
  2817. &set_label("14rounds",16);
  2818. &movups ("xmm2",&QWP(16,"eax")); # remaining half of *userKey
  2819. &lea ($key,&DWP(16,$key));
  2820. &cmp ("ebp",1<<28);
  2821. &je (&label("14rounds_alt"));
  2822. &mov ($rounds,13);
  2823. &$movekey (&QWP(-32,$key),"xmm0"); # round 0
  2824. &$movekey (&QWP(-16,$key),"xmm2"); # round 1
  2825. &aeskeygenassist("xmm1","xmm2",0x01); # round 2
  2826. &call (&label("key_256a_cold"));
  2827. &aeskeygenassist("xmm1","xmm0",0x01); # round 3
  2828. &call (&label("key_256b"));
  2829. &aeskeygenassist("xmm1","xmm2",0x02); # round 4
  2830. &call (&label("key_256a"));
  2831. &aeskeygenassist("xmm1","xmm0",0x02); # round 5
  2832. &call (&label("key_256b"));
  2833. &aeskeygenassist("xmm1","xmm2",0x04); # round 6
  2834. &call (&label("key_256a"));
  2835. &aeskeygenassist("xmm1","xmm0",0x04); # round 7
  2836. &call (&label("key_256b"));
  2837. &aeskeygenassist("xmm1","xmm2",0x08); # round 8
  2838. &call (&label("key_256a"));
  2839. &aeskeygenassist("xmm1","xmm0",0x08); # round 9
  2840. &call (&label("key_256b"));
  2841. &aeskeygenassist("xmm1","xmm2",0x10); # round 10
  2842. &call (&label("key_256a"));
  2843. &aeskeygenassist("xmm1","xmm0",0x10); # round 11
  2844. &call (&label("key_256b"));
  2845. &aeskeygenassist("xmm1","xmm2",0x20); # round 12
  2846. &call (&label("key_256a"));
  2847. &aeskeygenassist("xmm1","xmm0",0x20); # round 13
  2848. &call (&label("key_256b"));
  2849. &aeskeygenassist("xmm1","xmm2",0x40); # round 14
  2850. &call (&label("key_256a"));
  2851. &$movekey (&QWP(0,$key),"xmm0");
  2852. &mov (&DWP(16,$key),$rounds);
  2853. &xor ("eax","eax");
  2854. &jmp (&label("good_key"));
  2855. &set_label("key_256a",16);
  2856. &$movekey (&QWP(0,$key),"xmm2");
  2857. &lea ($key,&DWP(16,$key));
  2858. &set_label("key_256a_cold");
  2859. &shufps ("xmm4","xmm0",0b00010000);
  2860. &xorps ("xmm0","xmm4");
  2861. &shufps ("xmm4","xmm0",0b10001100);
  2862. &xorps ("xmm0","xmm4");
  2863. &shufps ("xmm1","xmm1",0b11111111); # critical path
  2864. &xorps ("xmm0","xmm1");
  2865. &ret();
  2866. &set_label("key_256b",16);
  2867. &$movekey (&QWP(0,$key),"xmm0");
  2868. &lea ($key,&DWP(16,$key));
  2869. &shufps ("xmm4","xmm2",0b00010000);
  2870. &xorps ("xmm2","xmm4");
  2871. &shufps ("xmm4","xmm2",0b10001100);
  2872. &xorps ("xmm2","xmm4");
  2873. &shufps ("xmm1","xmm1",0b10101010); # critical path
  2874. &xorps ("xmm2","xmm1");
  2875. &ret();
  2876. &set_label("14rounds_alt",16);
  2877. &movdqa ("xmm5",&QWP(0x00,"ebx"));
  2878. &movdqa ("xmm4",&QWP(0x20,"ebx"));
  2879. &mov ($rounds,7);
  2880. &movdqu (&QWP(-32,$key),"xmm0");
  2881. &movdqa ("xmm1","xmm2");
  2882. &movdqu (&QWP(-16,$key),"xmm2");
  2883. &set_label("loop_key256");
  2884. &pshufb ("xmm2","xmm5");
  2885. &aesenclast ("xmm2","xmm4");
  2886. &movdqa ("xmm3","xmm0");
  2887. &pslldq ("xmm0",4);
  2888. &pxor ("xmm3","xmm0");
  2889. &pslldq ("xmm0",4);
  2890. &pxor ("xmm3","xmm0");
  2891. &pslldq ("xmm0",4);
  2892. &pxor ("xmm0","xmm3");
  2893. &pslld ("xmm4",1);
  2894. &pxor ("xmm0","xmm2");
  2895. &movdqu (&QWP(0,$key),"xmm0");
  2896. &dec ($rounds);
  2897. &jz (&label("done_key256"));
  2898. &pshufd ("xmm2","xmm0",0xff);
  2899. &pxor ("xmm3","xmm3");
  2900. &aesenclast ("xmm2","xmm3");
  2901. &movdqa ("xmm3","xmm1");
  2902. &pslldq ("xmm1",4);
  2903. &pxor ("xmm3","xmm1");
  2904. &pslldq ("xmm1",4);
  2905. &pxor ("xmm3","xmm1");
  2906. &pslldq ("xmm1",4);
  2907. &pxor ("xmm1","xmm3");
  2908. &pxor ("xmm2","xmm1");
  2909. &movdqu (&QWP(16,$key),"xmm2");
  2910. &lea ($key,&DWP(32,$key));
  2911. &movdqa ("xmm1","xmm2");
  2912. &jmp (&label("loop_key256"));
  2913. &set_label("done_key256");
  2914. &mov ($rounds,13);
  2915. &mov (&DWP(16,$key),$rounds);
  2916. &set_label("good_key");
  2917. &pxor ("xmm0","xmm0");
  2918. &pxor ("xmm1","xmm1");
  2919. &pxor ("xmm2","xmm2");
  2920. &pxor ("xmm3","xmm3");
  2921. &pxor ("xmm4","xmm4");
  2922. &pxor ("xmm5","xmm5");
  2923. &xor ("eax","eax");
  2924. &pop ("ebx");
  2925. &pop ("ebp");
  2926. &ret ();
  2927. &set_label("bad_pointer",4);
  2928. &mov ("eax",-1);
  2929. &pop ("ebx");
  2930. &pop ("ebp");
  2931. &ret ();
  2932. &set_label("bad_keybits",4);
  2933. &pxor ("xmm0","xmm0");
  2934. &mov ("eax",-2);
  2935. &pop ("ebx");
  2936. &pop ("ebp");
  2937. &ret ();
  2938. &function_end_B("_aesni_set_encrypt_key");
  2939. # int $PREFIX_set_encrypt_key (const unsigned char *userKey, int bits,
  2940. # AES_KEY *key)
  2941. &function_begin_B("${PREFIX}_set_encrypt_key");
  2942. &mov ("eax",&wparam(0));
  2943. &mov ($rounds,&wparam(1));
  2944. &mov ($key,&wparam(2));
  2945. &call ("_aesni_set_encrypt_key");
  2946. &ret ();
  2947. &function_end_B("${PREFIX}_set_encrypt_key");
  2948. # int $PREFIX_set_decrypt_key (const unsigned char *userKey, int bits,
  2949. # AES_KEY *key)
  2950. &function_begin_B("${PREFIX}_set_decrypt_key");
  2951. &mov ("eax",&wparam(0));
  2952. &mov ($rounds,&wparam(1));
  2953. &mov ($key,&wparam(2));
  2954. &call ("_aesni_set_encrypt_key");
  2955. &mov ($key,&wparam(2));
  2956. &shl ($rounds,4); # rounds-1 after _aesni_set_encrypt_key
  2957. &test ("eax","eax");
  2958. &jnz (&label("dec_key_ret"));
  2959. &lea ("eax",&DWP(16,$key,$rounds)); # end of key schedule
  2960. &$movekey ("xmm0",&QWP(0,$key)); # just swap
  2961. &$movekey ("xmm1",&QWP(0,"eax"));
  2962. &$movekey (&QWP(0,"eax"),"xmm0");
  2963. &$movekey (&QWP(0,$key),"xmm1");
  2964. &lea ($key,&DWP(16,$key));
  2965. &lea ("eax",&DWP(-16,"eax"));
  2966. &set_label("dec_key_inverse");
  2967. &$movekey ("xmm0",&QWP(0,$key)); # swap and inverse
  2968. &$movekey ("xmm1",&QWP(0,"eax"));
  2969. &aesimc ("xmm0","xmm0");
  2970. &aesimc ("xmm1","xmm1");
  2971. &lea ($key,&DWP(16,$key));
  2972. &lea ("eax",&DWP(-16,"eax"));
  2973. &$movekey (&QWP(16,"eax"),"xmm0");
  2974. &$movekey (&QWP(-16,$key),"xmm1");
  2975. &cmp ("eax",$key);
  2976. &ja (&label("dec_key_inverse"));
  2977. &$movekey ("xmm0",&QWP(0,$key)); # inverse middle
  2978. &aesimc ("xmm0","xmm0");
  2979. &$movekey (&QWP(0,$key),"xmm0");
  2980. &pxor ("xmm0","xmm0");
  2981. &pxor ("xmm1","xmm1");
  2982. &xor ("eax","eax"); # return success
  2983. &set_label("dec_key_ret");
  2984. &ret ();
  2985. &function_end_B("${PREFIX}_set_decrypt_key");
  2986. &set_label("key_const",64);
  2987. &data_word(0x0c0f0e0d,0x0c0f0e0d,0x0c0f0e0d,0x0c0f0e0d);
  2988. &data_word(0x04070605,0x04070605,0x04070605,0x04070605);
  2989. &data_word(1,1,1,1);
  2990. &data_word(0x1b,0x1b,0x1b,0x1b);
  2991. &asciz("AES for Intel AES-NI, CRYPTOGAMS by <appro\@openssl.org>");
  2992. &asm_finish();
  2993. close STDOUT;