chacha-c64xplus.pl 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925
  1. #! /usr/bin/env perl
  2. # Copyright 2016-2020 The OpenSSL Project Authors. All Rights Reserved.
  3. #
  4. # Licensed under the Apache License 2.0 (the "License"). You may not use
  5. # this file except in compliance with the License. You can obtain a copy
  6. # in the file LICENSE in the source distribution or at
  7. # https://www.openssl.org/source/license.html
  8. #
  9. # ====================================================================
  10. # Written by Andy Polyakov <appro@openssl.org> for the OpenSSL
  11. # project. The module is, however, dual licensed under OpenSSL and
  12. # CRYPTOGAMS licenses depending on where you obtain it. For further
  13. # details see http://www.openssl.org/~appro/cryptogams/.
  14. # ====================================================================
  15. #
  16. # ChaCha20 for C64x+.
  17. #
  18. # October 2015
  19. #
  20. # Performance is 3.54 cycles per processed byte, which is ~4.3 times
  21. # faster than code generated by TI compiler. Compiler also disables
  22. # interrupts for some reason, thus making interrupt response time
  23. # dependent on input length. This module on the other hand is free
  24. # from such limitation.
  25. $output=pop and open STDOUT,">$output";
  26. ($OUT,$INP,$LEN,$KEYB,$COUNTERA)=("A4","B4","A6","B6","A8");
  27. ($KEYA,$COUNTERB,$STEP)=("A7","B7","A3");
  28. @X= ("A16","B16","A17","B17","A18","B18","A19","B19",
  29. "A20","B20","A21","B21","A22","B22","A23","B23");
  30. @Y= ("A24","B24","A25","B25","A26","B26","A27","B27",
  31. "A28","B28","A29","B29","A30","B30","A31","B31");
  32. @DAT=("A6", "A7", "B6", "B7", "A8", "A9", "B8", "B9",
  33. "A10","A11","B10","B11","A12","A13","B12","B13");
  34. # yes, overlaps with @DAT, used only in 2x interleave code path...
  35. @K2x=("A6", "B6", "A7", "B7", "A8", "B8", "A9", "B9",
  36. "A10","B10","A11","B11","A2", "B2", "A13","B13");
  37. $code.=<<___;
  38. .text
  39. .if .ASSEMBLER_VERSION<7000000
  40. .asg 0,__TI_EABI__
  41. .endif
  42. .if __TI_EABI__
  43. .asg ChaCha20_ctr32,_ChaCha20_ctr32
  44. .endif
  45. .asg B3,RA
  46. .asg A15,FP
  47. .asg B15,SP
  48. .global _ChaCha20_ctr32
  49. .align 32
  50. _ChaCha20_ctr32:
  51. .asmfunc stack_usage(40+64)
  52. MV $LEN,A0 ; reassign
  53. [!A0] BNOP RA ; no data
  54. || [A0] STW FP,*SP--(40+64) ; save frame pointer and alloca(40+64)
  55. || [A0] MV SP,FP
  56. [A0] STDW B13:B12,*SP[4+8] ; ABI says so
  57. || [A0] MV $KEYB,$KEYA
  58. || [A0] MV $COUNTERA,$COUNTERB
  59. [A0] STDW B11:B10,*SP[3+8]
  60. || [A0] STDW A13:A12,*FP[-3]
  61. [A0] STDW A11:A10,*FP[-4]
  62. || [A0] MVK 128,$STEP ; 2 * input block size
  63. [A0] LDW *${KEYA}[0],@Y[4] ; load key
  64. || [A0] LDW *${KEYB}[1],@Y[5]
  65. || [A0] MVK 0x00007865,@Y[0] ; synthesize sigma
  66. || [A0] MVK 0x0000646e,@Y[1]
  67. [A0] LDW *${KEYA}[2],@Y[6]
  68. || [A0] LDW *${KEYB}[3],@Y[7]
  69. || [A0] MVKH 0x61700000,@Y[0]
  70. || [A0] MVKH 0x33200000,@Y[1]
  71. LDW *${KEYA}[4],@Y[8]
  72. || LDW *${KEYB}[5],@Y[9]
  73. || MVK 0x00002d32,@Y[2]
  74. || MVK 0x00006574,@Y[3]
  75. LDW *${KEYA}[6],@Y[10]
  76. || LDW *${KEYB}[7],@Y[11]
  77. || MVKH 0x79620000,@Y[2]
  78. || MVKH 0x6b200000,@Y[3]
  79. LDW *${COUNTERA}[0],@Y[12] ; load counter||nonce
  80. || LDW *${COUNTERB}[1],@Y[13]
  81. || CMPLTU A0,$STEP,A1 ; is length < 2*blocks?
  82. LDW *${COUNTERA}[2],@Y[14]
  83. || LDW *${COUNTERB}[3],@Y[15]
  84. || [A1] BNOP top1x?
  85. [A1] MVK 64,$STEP ; input block size
  86. || MVK 10,B0 ; inner loop counter
  87. DMV @Y[2],@Y[0],@X[2]:@X[0] ; copy block
  88. || DMV @Y[3],@Y[1],@X[3]:@X[1]
  89. ||[!A1] STDW @Y[2]:@Y[0],*FP[-12] ; offload key material to stack
  90. ||[!A1] STDW @Y[3]:@Y[1],*SP[2]
  91. DMV @Y[6],@Y[4],@X[6]:@X[4]
  92. || DMV @Y[7],@Y[5],@X[7]:@X[5]
  93. ||[!A1] STDW @Y[6]:@Y[4],*FP[-10]
  94. ||[!A1] STDW @Y[7]:@Y[5],*SP[4]
  95. DMV @Y[10],@Y[8],@X[10]:@X[8]
  96. || DMV @Y[11],@Y[9],@X[11]:@X[9]
  97. ||[!A1] STDW @Y[10]:@Y[8],*FP[-8]
  98. ||[!A1] STDW @Y[11]:@Y[9],*SP[6]
  99. DMV @Y[14],@Y[12],@X[14]:@X[12]
  100. || DMV @Y[15],@Y[13],@X[15]:@X[13]
  101. ||[!A1] MV @Y[12],@K2x[12] ; counter
  102. ||[!A1] MV @Y[13],@K2x[13]
  103. ||[!A1] STW @Y[14],*FP[-6*2]
  104. ||[!A1] STW @Y[15],*SP[8*2]
  105. ___
  106. { ################################################################
  107. # 2x interleave gives 50% performance improvement
  108. #
  109. my ($a0,$a1,$a2,$a3) = (0..3);
  110. my ($b0,$b1,$b2,$b3) = (4..7);
  111. my ($c0,$c1,$c2,$c3) = (8..11);
  112. my ($d0,$d1,$d2,$d3) = (12..15);
  113. $code.=<<___;
  114. outer2x?:
  115. ADD @X[$b1],@X[$a1],@X[$a1]
  116. || ADD @X[$b2],@X[$a2],@X[$a2]
  117. || ADD @X[$b0],@X[$a0],@X[$a0]
  118. || ADD @X[$b3],@X[$a3],@X[$a3]
  119. || DMV @Y[2],@Y[0],@K2x[2]:@K2x[0]
  120. || DMV @Y[3],@Y[1],@K2x[3]:@K2x[1]
  121. XOR @X[$a1],@X[$d1],@X[$d1]
  122. || XOR @X[$a2],@X[$d2],@X[$d2]
  123. || XOR @X[$a0],@X[$d0],@X[$d0]
  124. || XOR @X[$a3],@X[$d3],@X[$d3]
  125. || DMV @Y[6],@Y[4],@K2x[6]:@K2x[4]
  126. || DMV @Y[7],@Y[5],@K2x[7]:@K2x[5]
  127. SWAP2 @X[$d1],@X[$d1] ; rotate by 16
  128. || SWAP2 @X[$d2],@X[$d2]
  129. || SWAP2 @X[$d0],@X[$d0]
  130. || SWAP2 @X[$d3],@X[$d3]
  131. ADD @X[$d1],@X[$c1],@X[$c1]
  132. || ADD @X[$d2],@X[$c2],@X[$c2]
  133. || ADD @X[$d0],@X[$c0],@X[$c0]
  134. || ADD @X[$d3],@X[$c3],@X[$c3]
  135. || DMV @Y[10],@Y[8],@K2x[10]:@K2x[8]
  136. || DMV @Y[11],@Y[9],@K2x[11]:@K2x[9]
  137. XOR @X[$c1],@X[$b1],@X[$b1]
  138. || XOR @X[$c2],@X[$b2],@X[$b2]
  139. || XOR @X[$c0],@X[$b0],@X[$b0]
  140. || XOR @X[$c3],@X[$b3],@X[$b3]
  141. || ADD 1,@Y[12],@Y[12] ; adjust counter for 2nd block
  142. ROTL @X[$b1],12,@X[$b1]
  143. || ROTL @X[$b2],12,@X[$b2]
  144. || MV @Y[14],@K2x[14]
  145. || MV @Y[15],@K2x[15]
  146. top2x?:
  147. ROTL @X[$b0],12,@X[$b0]
  148. || ROTL @X[$b3],12,@X[$b3]
  149. || ADD @Y[$b1],@Y[$a1],@Y[$a1]
  150. || ADD @Y[$b2],@Y[$a2],@Y[$a2]
  151. ADD @Y[$b0],@Y[$a0],@Y[$a0]
  152. || ADD @Y[$b3],@Y[$a3],@Y[$a3]
  153. || ADD @X[$b1],@X[$a1],@X[$a1]
  154. || ADD @X[$b2],@X[$a2],@X[$a2]
  155. || XOR @Y[$a1],@Y[$d1],@Y[$d1]
  156. || XOR @Y[$a2],@Y[$d2],@Y[$d2]
  157. XOR @Y[$a0],@Y[$d0],@Y[$d0]
  158. || XOR @Y[$a3],@Y[$d3],@Y[$d3]
  159. || ADD @X[$b0],@X[$a0],@X[$a0]
  160. || ADD @X[$b3],@X[$a3],@X[$a3]
  161. || XOR @X[$a1],@X[$d1],@X[$d1]
  162. || XOR @X[$a2],@X[$d2],@X[$d2]
  163. XOR @X[$a0],@X[$d0],@X[$d0]
  164. || XOR @X[$a3],@X[$d3],@X[$d3]
  165. || ROTL @X[$d1],8,@X[$d1]
  166. || ROTL @X[$d2],8,@X[$d2]
  167. || SWAP2 @Y[$d1],@Y[$d1] ; rotate by 16
  168. || SWAP2 @Y[$d2],@Y[$d2]
  169. || SWAP2 @Y[$d0],@Y[$d0]
  170. || SWAP2 @Y[$d3],@Y[$d3]
  171. ROTL @X[$d0],8,@X[$d0]
  172. || ROTL @X[$d3],8,@X[$d3]
  173. || ADD @Y[$d1],@Y[$c1],@Y[$c1]
  174. || ADD @Y[$d2],@Y[$c2],@Y[$c2]
  175. || ADD @Y[$d0],@Y[$c0],@Y[$c0]
  176. || ADD @Y[$d3],@Y[$c3],@Y[$c3]
  177. || BNOP middle2x1? ; protect from interrupt
  178. ADD @X[$d1],@X[$c1],@X[$c1]
  179. || ADD @X[$d2],@X[$c2],@X[$c2]
  180. || XOR @Y[$c1],@Y[$b1],@Y[$b1]
  181. || XOR @Y[$c2],@Y[$b2],@Y[$b2]
  182. || XOR @Y[$c0],@Y[$b0],@Y[$b0]
  183. || XOR @Y[$c3],@Y[$b3],@Y[$b3]
  184. ADD @X[$d0],@X[$c0],@X[$c0]
  185. || ADD @X[$d3],@X[$c3],@X[$c3]
  186. || XOR @X[$c1],@X[$b1],@X[$b1]
  187. || XOR @X[$c2],@X[$b2],@X[$b2]
  188. || ROTL @X[$d1],0,@X[$d2] ; moved to avoid cross-path stall
  189. || ROTL @X[$d2],0,@X[$d3]
  190. XOR @X[$c0],@X[$b0],@X[$b0]
  191. || XOR @X[$c3],@X[$b3],@X[$b3]
  192. || MV @X[$d0],@X[$d1]
  193. || MV @X[$d3],@X[$d0]
  194. || ROTL @Y[$b1],12,@Y[$b1]
  195. || ROTL @Y[$b2],12,@Y[$b2]
  196. ROTL @X[$b1],7,@X[$b0] ; avoided cross-path stall
  197. || ROTL @X[$b2],7,@X[$b1]
  198. ROTL @X[$b0],7,@X[$b3]
  199. || ROTL @X[$b3],7,@X[$b2]
  200. middle2x1?:
  201. ROTL @Y[$b0],12,@Y[$b0]
  202. || ROTL @Y[$b3],12,@Y[$b3]
  203. || ADD @X[$b0],@X[$a0],@X[$a0]
  204. || ADD @X[$b1],@X[$a1],@X[$a1]
  205. ADD @X[$b2],@X[$a2],@X[$a2]
  206. || ADD @X[$b3],@X[$a3],@X[$a3]
  207. || ADD @Y[$b1],@Y[$a1],@Y[$a1]
  208. || ADD @Y[$b2],@Y[$a2],@Y[$a2]
  209. || XOR @X[$a0],@X[$d0],@X[$d0]
  210. || XOR @X[$a1],@X[$d1],@X[$d1]
  211. XOR @X[$a2],@X[$d2],@X[$d2]
  212. || XOR @X[$a3],@X[$d3],@X[$d3]
  213. || ADD @Y[$b0],@Y[$a0],@Y[$a0]
  214. || ADD @Y[$b3],@Y[$a3],@Y[$a3]
  215. || XOR @Y[$a1],@Y[$d1],@Y[$d1]
  216. || XOR @Y[$a2],@Y[$d2],@Y[$d2]
  217. XOR @Y[$a0],@Y[$d0],@Y[$d0]
  218. || XOR @Y[$a3],@Y[$d3],@Y[$d3]
  219. || ROTL @Y[$d1],8,@Y[$d1]
  220. || ROTL @Y[$d2],8,@Y[$d2]
  221. || SWAP2 @X[$d0],@X[$d0] ; rotate by 16
  222. || SWAP2 @X[$d1],@X[$d1]
  223. || SWAP2 @X[$d2],@X[$d2]
  224. || SWAP2 @X[$d3],@X[$d3]
  225. ROTL @Y[$d0],8,@Y[$d0]
  226. || ROTL @Y[$d3],8,@Y[$d3]
  227. || ADD @X[$d0],@X[$c2],@X[$c2]
  228. || ADD @X[$d1],@X[$c3],@X[$c3]
  229. || ADD @X[$d2],@X[$c0],@X[$c0]
  230. || ADD @X[$d3],@X[$c1],@X[$c1]
  231. || BNOP middle2x2? ; protect from interrupt
  232. ADD @Y[$d1],@Y[$c1],@Y[$c1]
  233. || ADD @Y[$d2],@Y[$c2],@Y[$c2]
  234. || XOR @X[$c2],@X[$b0],@X[$b0]
  235. || XOR @X[$c3],@X[$b1],@X[$b1]
  236. || XOR @X[$c0],@X[$b2],@X[$b2]
  237. || XOR @X[$c1],@X[$b3],@X[$b3]
  238. ADD @Y[$d0],@Y[$c0],@Y[$c0]
  239. || ADD @Y[$d3],@Y[$c3],@Y[$c3]
  240. || XOR @Y[$c1],@Y[$b1],@Y[$b1]
  241. || XOR @Y[$c2],@Y[$b2],@Y[$b2]
  242. || ROTL @Y[$d1],0,@Y[$d2] ; moved to avoid cross-path stall
  243. || ROTL @Y[$d2],0,@Y[$d3]
  244. XOR @Y[$c0],@Y[$b0],@Y[$b0]
  245. || XOR @Y[$c3],@Y[$b3],@Y[$b3]
  246. || MV @Y[$d0],@Y[$d1]
  247. || MV @Y[$d3],@Y[$d0]
  248. || ROTL @X[$b0],12,@X[$b0]
  249. || ROTL @X[$b1],12,@X[$b1]
  250. ROTL @Y[$b1],7,@Y[$b0] ; avoided cross-path stall
  251. || ROTL @Y[$b2],7,@Y[$b1]
  252. ROTL @Y[$b0],7,@Y[$b3]
  253. || ROTL @Y[$b3],7,@Y[$b2]
  254. middle2x2?:
  255. ROTL @X[$b2],12,@X[$b2]
  256. || ROTL @X[$b3],12,@X[$b3]
  257. || ADD @Y[$b0],@Y[$a0],@Y[$a0]
  258. || ADD @Y[$b1],@Y[$a1],@Y[$a1]
  259. ADD @Y[$b2],@Y[$a2],@Y[$a2]
  260. || ADD @Y[$b3],@Y[$a3],@Y[$a3]
  261. || ADD @X[$b0],@X[$a0],@X[$a0]
  262. || ADD @X[$b1],@X[$a1],@X[$a1]
  263. || XOR @Y[$a0],@Y[$d0],@Y[$d0]
  264. || XOR @Y[$a1],@Y[$d1],@Y[$d1]
  265. XOR @Y[$a2],@Y[$d2],@Y[$d2]
  266. || XOR @Y[$a3],@Y[$d3],@Y[$d3]
  267. || ADD @X[$b2],@X[$a2],@X[$a2]
  268. || ADD @X[$b3],@X[$a3],@X[$a3]
  269. || XOR @X[$a0],@X[$d0],@X[$d0]
  270. || XOR @X[$a1],@X[$d1],@X[$d1]
  271. XOR @X[$a2],@X[$d2],@X[$d2]
  272. || XOR @X[$a3],@X[$d3],@X[$d3]
  273. || ROTL @X[$d0],8,@X[$d0]
  274. || ROTL @X[$d1],8,@X[$d1]
  275. || SWAP2 @Y[$d0],@Y[$d0] ; rotate by 16
  276. || SWAP2 @Y[$d1],@Y[$d1]
  277. || SWAP2 @Y[$d2],@Y[$d2]
  278. || SWAP2 @Y[$d3],@Y[$d3]
  279. ROTL @X[$d2],8,@X[$d2]
  280. || ROTL @X[$d3],8,@X[$d3]
  281. || ADD @Y[$d0],@Y[$c2],@Y[$c2]
  282. || ADD @Y[$d1],@Y[$c3],@Y[$c3]
  283. || ADD @Y[$d2],@Y[$c0],@Y[$c0]
  284. || ADD @Y[$d3],@Y[$c1],@Y[$c1]
  285. || BNOP bottom2x1? ; protect from interrupt
  286. ADD @X[$d0],@X[$c2],@X[$c2]
  287. || ADD @X[$d1],@X[$c3],@X[$c3]
  288. || XOR @Y[$c2],@Y[$b0],@Y[$b0]
  289. || XOR @Y[$c3],@Y[$b1],@Y[$b1]
  290. || XOR @Y[$c0],@Y[$b2],@Y[$b2]
  291. || XOR @Y[$c1],@Y[$b3],@Y[$b3]
  292. ADD @X[$d2],@X[$c0],@X[$c0]
  293. || ADD @X[$d3],@X[$c1],@X[$c1]
  294. || XOR @X[$c2],@X[$b0],@X[$b0]
  295. || XOR @X[$c3],@X[$b1],@X[$b1]
  296. || ROTL @X[$d0],0,@X[$d3] ; moved to avoid cross-path stall
  297. || ROTL @X[$d1],0,@X[$d0]
  298. XOR @X[$c0],@X[$b2],@X[$b2]
  299. || XOR @X[$c1],@X[$b3],@X[$b3]
  300. || MV @X[$d2],@X[$d1]
  301. || MV @X[$d3],@X[$d2]
  302. || ROTL @Y[$b0],12,@Y[$b0]
  303. || ROTL @Y[$b1],12,@Y[$b1]
  304. ROTL @X[$b0],7,@X[$b1] ; avoided cross-path stall
  305. || ROTL @X[$b1],7,@X[$b2]
  306. ROTL @X[$b2],7,@X[$b3]
  307. || ROTL @X[$b3],7,@X[$b0]
  308. || [B0] SUB B0,1,B0 ; decrement inner loop counter
  309. bottom2x1?:
  310. ROTL @Y[$b2],12,@Y[$b2]
  311. || ROTL @Y[$b3],12,@Y[$b3]
  312. || [B0] ADD @X[$b1],@X[$a1],@X[$a1] ; modulo-scheduled
  313. || [B0] ADD @X[$b2],@X[$a2],@X[$a2]
  314. [B0] ADD @X[$b0],@X[$a0],@X[$a0]
  315. || [B0] ADD @X[$b3],@X[$a3],@X[$a3]
  316. || ADD @Y[$b0],@Y[$a0],@Y[$a0]
  317. || ADD @Y[$b1],@Y[$a1],@Y[$a1]
  318. || [B0] XOR @X[$a1],@X[$d1],@X[$d1]
  319. || [B0] XOR @X[$a2],@X[$d2],@X[$d2]
  320. [B0] XOR @X[$a0],@X[$d0],@X[$d0]
  321. || [B0] XOR @X[$a3],@X[$d3],@X[$d3]
  322. || ADD @Y[$b2],@Y[$a2],@Y[$a2]
  323. || ADD @Y[$b3],@Y[$a3],@Y[$a3]
  324. || XOR @Y[$a0],@Y[$d0],@Y[$d0]
  325. || XOR @Y[$a1],@Y[$d1],@Y[$d1]
  326. XOR @Y[$a2],@Y[$d2],@Y[$d2]
  327. || XOR @Y[$a3],@Y[$d3],@Y[$d3]
  328. || ROTL @Y[$d0],8,@Y[$d0]
  329. || ROTL @Y[$d1],8,@Y[$d1]
  330. || [B0] SWAP2 @X[$d1],@X[$d1] ; rotate by 16
  331. || [B0] SWAP2 @X[$d2],@X[$d2]
  332. || [B0] SWAP2 @X[$d0],@X[$d0]
  333. || [B0] SWAP2 @X[$d3],@X[$d3]
  334. ROTL @Y[$d2],8,@Y[$d2]
  335. || ROTL @Y[$d3],8,@Y[$d3]
  336. || [B0] ADD @X[$d1],@X[$c1],@X[$c1]
  337. || [B0] ADD @X[$d2],@X[$c2],@X[$c2]
  338. || [B0] ADD @X[$d0],@X[$c0],@X[$c0]
  339. || [B0] ADD @X[$d3],@X[$c3],@X[$c3]
  340. || [B0] BNOP top2x? ; even protects from interrupt
  341. ADD @Y[$d0],@Y[$c2],@Y[$c2]
  342. || ADD @Y[$d1],@Y[$c3],@Y[$c3]
  343. || [B0] XOR @X[$c1],@X[$b1],@X[$b1]
  344. || [B0] XOR @X[$c2],@X[$b2],@X[$b2]
  345. || [B0] XOR @X[$c0],@X[$b0],@X[$b0]
  346. || [B0] XOR @X[$c3],@X[$b3],@X[$b3]
  347. ADD @Y[$d2],@Y[$c0],@Y[$c0]
  348. || ADD @Y[$d3],@Y[$c1],@Y[$c1]
  349. || XOR @Y[$c2],@Y[$b0],@Y[$b0]
  350. || XOR @Y[$c3],@Y[$b1],@Y[$b1]
  351. || ROTL @Y[$d0],0,@Y[$d3] ; moved to avoid cross-path stall
  352. || ROTL @Y[$d1],0,@Y[$d0]
  353. XOR @Y[$c0],@Y[$b2],@Y[$b2]
  354. || XOR @Y[$c1],@Y[$b3],@Y[$b3]
  355. || MV @Y[$d2],@Y[$d1]
  356. || MV @Y[$d3],@Y[$d2]
  357. || [B0] ROTL @X[$b1],12,@X[$b1]
  358. || [B0] ROTL @X[$b2],12,@X[$b2]
  359. ROTL @Y[$b0],7,@Y[$b1] ; avoided cross-path stall
  360. || ROTL @Y[$b1],7,@Y[$b2]
  361. ROTL @Y[$b2],7,@Y[$b3]
  362. || ROTL @Y[$b3],7,@Y[$b0]
  363. bottom2x2?:
  364. ___
  365. }
  366. $code.=<<___;
  367. ADD @K2x[0],@X[0],@X[0] ; accumulate key material
  368. || ADD @K2x[1],@X[1],@X[1]
  369. || ADD @K2x[2],@X[2],@X[2]
  370. || ADD @K2x[3],@X[3],@X[3]
  371. ADD @K2x[0],@Y[0],@Y[0]
  372. || ADD @K2x[1],@Y[1],@Y[1]
  373. || ADD @K2x[2],@Y[2],@Y[2]
  374. || ADD @K2x[3],@Y[3],@Y[3]
  375. || LDNDW *${INP}++[8],@DAT[1]:@DAT[0]
  376. ADD @K2x[4],@X[4],@X[4]
  377. || ADD @K2x[5],@X[5],@X[5]
  378. || ADD @K2x[6],@X[6],@X[6]
  379. || ADD @K2x[7],@X[7],@X[7]
  380. || LDNDW *${INP}[-7],@DAT[3]:@DAT[2]
  381. ADD @K2x[4],@Y[4],@Y[4]
  382. || ADD @K2x[5],@Y[5],@Y[5]
  383. || ADD @K2x[6],@Y[6],@Y[6]
  384. || ADD @K2x[7],@Y[7],@Y[7]
  385. || LDNDW *${INP}[-6],@DAT[5]:@DAT[4]
  386. ADD @K2x[8],@X[8],@X[8]
  387. || ADD @K2x[9],@X[9],@X[9]
  388. || ADD @K2x[10],@X[10],@X[10]
  389. || ADD @K2x[11],@X[11],@X[11]
  390. || LDNDW *${INP}[-5],@DAT[7]:@DAT[6]
  391. ADD @K2x[8],@Y[8],@Y[8]
  392. || ADD @K2x[9],@Y[9],@Y[9]
  393. || ADD @K2x[10],@Y[10],@Y[10]
  394. || ADD @K2x[11],@Y[11],@Y[11]
  395. || LDNDW *${INP}[-4],@DAT[9]:@DAT[8]
  396. ADD @K2x[12],@X[12],@X[12]
  397. || ADD @K2x[13],@X[13],@X[13]
  398. || ADD @K2x[14],@X[14],@X[14]
  399. || ADD @K2x[15],@X[15],@X[15]
  400. || LDNDW *${INP}[-3],@DAT[11]:@DAT[10]
  401. ADD @K2x[12],@Y[12],@Y[12]
  402. || ADD @K2x[13],@Y[13],@Y[13]
  403. || ADD @K2x[14],@Y[14],@Y[14]
  404. || ADD @K2x[15],@Y[15],@Y[15]
  405. || LDNDW *${INP}[-2],@DAT[13]:@DAT[12]
  406. ADD 1,@Y[12],@Y[12] ; adjust counter for 2nd block
  407. || ADD 2,@K2x[12],@K2x[12] ; increment counter
  408. || LDNDW *${INP}[-1],@DAT[15]:@DAT[14]
  409. .if .BIG_ENDIAN
  410. SWAP2 @X[0],@X[0]
  411. || SWAP2 @X[1],@X[1]
  412. || SWAP2 @X[2],@X[2]
  413. || SWAP2 @X[3],@X[3]
  414. SWAP2 @X[4],@X[4]
  415. || SWAP2 @X[5],@X[5]
  416. || SWAP2 @X[6],@X[6]
  417. || SWAP2 @X[7],@X[7]
  418. SWAP2 @X[8],@X[8]
  419. || SWAP2 @X[9],@X[9]
  420. || SWAP4 @X[0],@X[1]
  421. || SWAP4 @X[1],@X[0]
  422. SWAP2 @X[10],@X[10]
  423. || SWAP2 @X[11],@X[11]
  424. || SWAP4 @X[2],@X[3]
  425. || SWAP4 @X[3],@X[2]
  426. SWAP2 @X[12],@X[12]
  427. || SWAP2 @X[13],@X[13]
  428. || SWAP4 @X[4],@X[5]
  429. || SWAP4 @X[5],@X[4]
  430. SWAP2 @X[14],@X[14]
  431. || SWAP2 @X[15],@X[15]
  432. || SWAP4 @X[6],@X[7]
  433. || SWAP4 @X[7],@X[6]
  434. SWAP4 @X[8],@X[9]
  435. || SWAP4 @X[9],@X[8]
  436. || SWAP2 @Y[0],@Y[0]
  437. || SWAP2 @Y[1],@Y[1]
  438. SWAP4 @X[10],@X[11]
  439. || SWAP4 @X[11],@X[10]
  440. || SWAP2 @Y[2],@Y[2]
  441. || SWAP2 @Y[3],@Y[3]
  442. SWAP4 @X[12],@X[13]
  443. || SWAP4 @X[13],@X[12]
  444. || SWAP2 @Y[4],@Y[4]
  445. || SWAP2 @Y[5],@Y[5]
  446. SWAP4 @X[14],@X[15]
  447. || SWAP4 @X[15],@X[14]
  448. || SWAP2 @Y[6],@Y[6]
  449. || SWAP2 @Y[7],@Y[7]
  450. SWAP2 @Y[8],@Y[8]
  451. || SWAP2 @Y[9],@Y[9]
  452. || SWAP4 @Y[0],@Y[1]
  453. || SWAP4 @Y[1],@Y[0]
  454. SWAP2 @Y[10],@Y[10]
  455. || SWAP2 @Y[11],@Y[11]
  456. || SWAP4 @Y[2],@Y[3]
  457. || SWAP4 @Y[3],@Y[2]
  458. SWAP2 @Y[12],@Y[12]
  459. || SWAP2 @Y[13],@Y[13]
  460. || SWAP4 @Y[4],@Y[5]
  461. || SWAP4 @Y[5],@Y[4]
  462. SWAP2 @Y[14],@Y[14]
  463. || SWAP2 @Y[15],@Y[15]
  464. || SWAP4 @Y[6],@Y[7]
  465. || SWAP4 @Y[7],@Y[6]
  466. SWAP4 @Y[8],@Y[9]
  467. || SWAP4 @Y[9],@Y[8]
  468. SWAP4 @Y[10],@Y[11]
  469. || SWAP4 @Y[11],@Y[10]
  470. SWAP4 @Y[12],@Y[13]
  471. || SWAP4 @Y[13],@Y[12]
  472. SWAP4 @Y[14],@Y[15]
  473. || SWAP4 @Y[15],@Y[14]
  474. .endif
  475. XOR @DAT[0],@X[0],@X[0] ; xor 1st block
  476. || XOR @DAT[3],@X[3],@X[3]
  477. || XOR @DAT[2],@X[2],@X[1]
  478. || XOR @DAT[1],@X[1],@X[2]
  479. || LDNDW *${INP}++[8],@DAT[1]:@DAT[0]
  480. XOR @DAT[4],@X[4],@X[4]
  481. || XOR @DAT[7],@X[7],@X[7]
  482. || LDNDW *${INP}[-7],@DAT[3]:@DAT[2]
  483. XOR @DAT[6],@X[6],@X[5]
  484. || XOR @DAT[5],@X[5],@X[6]
  485. || LDNDW *${INP}[-6],@DAT[5]:@DAT[4]
  486. XOR @DAT[8],@X[8],@X[8]
  487. || XOR @DAT[11],@X[11],@X[11]
  488. || LDNDW *${INP}[-5],@DAT[7]:@DAT[6]
  489. XOR @DAT[10],@X[10],@X[9]
  490. || XOR @DAT[9],@X[9],@X[10]
  491. || LDNDW *${INP}[-4],@DAT[9]:@DAT[8]
  492. XOR @DAT[12],@X[12],@X[12]
  493. || XOR @DAT[15],@X[15],@X[15]
  494. || LDNDW *${INP}[-3],@DAT[11]:@DAT[10]
  495. XOR @DAT[14],@X[14],@X[13]
  496. || XOR @DAT[13],@X[13],@X[14]
  497. || LDNDW *${INP}[-2],@DAT[13]:@DAT[12]
  498. [A0] SUB A0,$STEP,A0 ; SUB A0,128,A0
  499. || LDNDW *${INP}[-1],@DAT[15]:@DAT[14]
  500. XOR @Y[0],@DAT[0],@DAT[0] ; xor 2nd block
  501. || XOR @Y[1],@DAT[1],@DAT[1]
  502. || STNDW @X[2]:@X[0],*${OUT}++[8]
  503. XOR @Y[2],@DAT[2],@DAT[2]
  504. || XOR @Y[3],@DAT[3],@DAT[3]
  505. || STNDW @X[3]:@X[1],*${OUT}[-7]
  506. XOR @Y[4],@DAT[4],@DAT[4]
  507. || [A0] LDDW *FP[-12],@X[2]:@X[0] ; re-load key material from stack
  508. || [A0] LDDW *SP[2], @X[3]:@X[1]
  509. XOR @Y[5],@DAT[5],@DAT[5]
  510. || STNDW @X[6]:@X[4],*${OUT}[-6]
  511. XOR @Y[6],@DAT[6],@DAT[6]
  512. || XOR @Y[7],@DAT[7],@DAT[7]
  513. || STNDW @X[7]:@X[5],*${OUT}[-5]
  514. XOR @Y[8],@DAT[8],@DAT[8]
  515. || [A0] LDDW *FP[-10],@X[6]:@X[4]
  516. || [A0] LDDW *SP[4], @X[7]:@X[5]
  517. XOR @Y[9],@DAT[9],@DAT[9]
  518. || STNDW @X[10]:@X[8],*${OUT}[-4]
  519. XOR @Y[10],@DAT[10],@DAT[10]
  520. || XOR @Y[11],@DAT[11],@DAT[11]
  521. || STNDW @X[11]:@X[9],*${OUT}[-3]
  522. XOR @Y[12],@DAT[12],@DAT[12]
  523. || [A0] LDDW *FP[-8], @X[10]:@X[8]
  524. || [A0] LDDW *SP[6], @X[11]:@X[9]
  525. XOR @Y[13],@DAT[13],@DAT[13]
  526. || STNDW @X[14]:@X[12],*${OUT}[-2]
  527. XOR @Y[14],@DAT[14],@DAT[14]
  528. || XOR @Y[15],@DAT[15],@DAT[15]
  529. || STNDW @X[15]:@X[13],*${OUT}[-1]
  530. [A0] MV @K2x[12],@X[12]
  531. || [A0] MV @K2x[13],@X[13]
  532. || [A0] LDW *FP[-6*2], @X[14]
  533. || [A0] LDW *SP[8*2], @X[15]
  534. [A0] DMV @X[2],@X[0],@Y[2]:@Y[0] ; duplicate key material
  535. || STNDW @DAT[1]:@DAT[0],*${OUT}++[8]
  536. [A0] DMV @X[3],@X[1],@Y[3]:@Y[1]
  537. || STNDW @DAT[3]:@DAT[2],*${OUT}[-7]
  538. [A0] DMV @X[6],@X[4],@Y[6]:@Y[4]
  539. || STNDW @DAT[5]:@DAT[4],*${OUT}[-6]
  540. || CMPLTU A0,$STEP,A1 ; is remaining length < 2*blocks?
  541. ||[!A0] BNOP epilogue?
  542. [A0] DMV @X[7],@X[5],@Y[7]:@Y[5]
  543. || STNDW @DAT[7]:@DAT[6],*${OUT}[-5]
  544. ||[!A1] BNOP outer2x?
  545. [A0] DMV @X[10],@X[8],@Y[10]:@Y[8]
  546. || STNDW @DAT[9]:@DAT[8],*${OUT}[-4]
  547. [A0] DMV @X[11],@X[9],@Y[11]:@Y[9]
  548. || STNDW @DAT[11]:@DAT[10],*${OUT}[-3]
  549. [A0] DMV @X[14],@X[12],@Y[14]:@Y[12]
  550. || STNDW @DAT[13]:@DAT[12],*${OUT}[-2]
  551. [A0] DMV @X[15],@X[13],@Y[15]:@Y[13]
  552. || STNDW @DAT[15]:@DAT[14],*${OUT}[-1]
  553. ;;===== branch to epilogue? is taken here
  554. [A1] MVK 64,$STEP
  555. || [A0] MVK 10,B0 ; inner loop counter
  556. ;;===== branch to outer2x? is taken here
  557. ___
  558. {
  559. my ($a0,$a1,$a2,$a3) = (0..3);
  560. my ($b0,$b1,$b2,$b3) = (4..7);
  561. my ($c0,$c1,$c2,$c3) = (8..11);
  562. my ($d0,$d1,$d2,$d3) = (12..15);
  563. $code.=<<___;
  564. top1x?:
  565. ADD @X[$b1],@X[$a1],@X[$a1]
  566. || ADD @X[$b2],@X[$a2],@X[$a2]
  567. ADD @X[$b0],@X[$a0],@X[$a0]
  568. || ADD @X[$b3],@X[$a3],@X[$a3]
  569. || XOR @X[$a1],@X[$d1],@X[$d1]
  570. || XOR @X[$a2],@X[$d2],@X[$d2]
  571. XOR @X[$a0],@X[$d0],@X[$d0]
  572. || XOR @X[$a3],@X[$d3],@X[$d3]
  573. || SWAP2 @X[$d1],@X[$d1] ; rotate by 16
  574. || SWAP2 @X[$d2],@X[$d2]
  575. SWAP2 @X[$d0],@X[$d0]
  576. || SWAP2 @X[$d3],@X[$d3]
  577. || ADD @X[$d1],@X[$c1],@X[$c1]
  578. || ADD @X[$d2],@X[$c2],@X[$c2]
  579. ADD @X[$d0],@X[$c0],@X[$c0]
  580. || ADD @X[$d3],@X[$c3],@X[$c3]
  581. || XOR @X[$c1],@X[$b1],@X[$b1]
  582. || XOR @X[$c2],@X[$b2],@X[$b2]
  583. XOR @X[$c0],@X[$b0],@X[$b0]
  584. || XOR @X[$c3],@X[$b3],@X[$b3]
  585. || ROTL @X[$b1],12,@X[$b1]
  586. || ROTL @X[$b2],12,@X[$b2]
  587. ROTL @X[$b0],12,@X[$b0]
  588. || ROTL @X[$b3],12,@X[$b3]
  589. ADD @X[$b1],@X[$a1],@X[$a1]
  590. || ADD @X[$b2],@X[$a2],@X[$a2]
  591. ADD @X[$b0],@X[$a0],@X[$a0]
  592. || ADD @X[$b3],@X[$a3],@X[$a3]
  593. || XOR @X[$a1],@X[$d1],@X[$d1]
  594. || XOR @X[$a2],@X[$d2],@X[$d2]
  595. XOR @X[$a0],@X[$d0],@X[$d0]
  596. || XOR @X[$a3],@X[$d3],@X[$d3]
  597. || ROTL @X[$d1],8,@X[$d1]
  598. || ROTL @X[$d2],8,@X[$d2]
  599. ROTL @X[$d0],8,@X[$d0]
  600. || ROTL @X[$d3],8,@X[$d3]
  601. || BNOP middle1x? ; protect from interrupt
  602. ADD @X[$d1],@X[$c1],@X[$c1]
  603. || ADD @X[$d2],@X[$c2],@X[$c2]
  604. ADD @X[$d0],@X[$c0],@X[$c0]
  605. || ADD @X[$d3],@X[$c3],@X[$c3]
  606. || XOR @X[$c1],@X[$b1],@X[$b1]
  607. || XOR @X[$c2],@X[$b2],@X[$b2]
  608. || ROTL @X[$d1],0,@X[$d2] ; moved to avoid cross-path stall
  609. || ROTL @X[$d2],0,@X[$d3]
  610. XOR @X[$c0],@X[$b0],@X[$b0]
  611. || XOR @X[$c3],@X[$b3],@X[$b3]
  612. || ROTL @X[$d0],0,@X[$d1]
  613. || ROTL @X[$d3],0,@X[$d0]
  614. ROTL @X[$b1],7,@X[$b0] ; avoided cross-path stall
  615. || ROTL @X[$b2],7,@X[$b1]
  616. ROTL @X[$b0],7,@X[$b3]
  617. || ROTL @X[$b3],7,@X[$b2]
  618. middle1x?:
  619. ADD @X[$b0],@X[$a0],@X[$a0]
  620. || ADD @X[$b1],@X[$a1],@X[$a1]
  621. ADD @X[$b2],@X[$a2],@X[$a2]
  622. || ADD @X[$b3],@X[$a3],@X[$a3]
  623. || XOR @X[$a0],@X[$d0],@X[$d0]
  624. || XOR @X[$a1],@X[$d1],@X[$d1]
  625. XOR @X[$a2],@X[$d2],@X[$d2]
  626. || XOR @X[$a3],@X[$d3],@X[$d3]
  627. || SWAP2 @X[$d0],@X[$d0] ; rotate by 16
  628. || SWAP2 @X[$d1],@X[$d1]
  629. SWAP2 @X[$d2],@X[$d2]
  630. || SWAP2 @X[$d3],@X[$d3]
  631. || ADD @X[$d0],@X[$c2],@X[$c2]
  632. || ADD @X[$d1],@X[$c3],@X[$c3]
  633. ADD @X[$d2],@X[$c0],@X[$c0]
  634. || ADD @X[$d3],@X[$c1],@X[$c1]
  635. || XOR @X[$c2],@X[$b0],@X[$b0]
  636. || XOR @X[$c3],@X[$b1],@X[$b1]
  637. XOR @X[$c0],@X[$b2],@X[$b2]
  638. || XOR @X[$c1],@X[$b3],@X[$b3]
  639. || ROTL @X[$b0],12,@X[$b0]
  640. || ROTL @X[$b1],12,@X[$b1]
  641. ROTL @X[$b2],12,@X[$b2]
  642. || ROTL @X[$b3],12,@X[$b3]
  643. ADD @X[$b0],@X[$a0],@X[$a0]
  644. || ADD @X[$b1],@X[$a1],@X[$a1]
  645. || [B0] SUB B0,1,B0 ; decrement inner loop counter
  646. ADD @X[$b2],@X[$a2],@X[$a2]
  647. || ADD @X[$b3],@X[$a3],@X[$a3]
  648. || XOR @X[$a0],@X[$d0],@X[$d0]
  649. || XOR @X[$a1],@X[$d1],@X[$d1]
  650. XOR @X[$a2],@X[$d2],@X[$d2]
  651. || XOR @X[$a3],@X[$d3],@X[$d3]
  652. || ROTL @X[$d0],8,@X[$d0]
  653. || ROTL @X[$d1],8,@X[$d1]
  654. ROTL @X[$d2],8,@X[$d2]
  655. || ROTL @X[$d3],8,@X[$d3]
  656. || [B0] BNOP top1x? ; even protects from interrupt
  657. ADD @X[$d0],@X[$c2],@X[$c2]
  658. || ADD @X[$d1],@X[$c3],@X[$c3]
  659. ADD @X[$d2],@X[$c0],@X[$c0]
  660. || ADD @X[$d3],@X[$c1],@X[$c1]
  661. || XOR @X[$c2],@X[$b0],@X[$b0]
  662. || XOR @X[$c3],@X[$b1],@X[$b1]
  663. || ROTL @X[$d0],0,@X[$d3] ; moved to avoid cross-path stall
  664. || ROTL @X[$d1],0,@X[$d0]
  665. XOR @X[$c0],@X[$b2],@X[$b2]
  666. || XOR @X[$c1],@X[$b3],@X[$b3]
  667. || ROTL @X[$d2],0,@X[$d1]
  668. || ROTL @X[$d3],0,@X[$d2]
  669. ROTL @X[$b0],7,@X[$b1] ; avoided cross-path stall
  670. || ROTL @X[$b1],7,@X[$b2]
  671. ROTL @X[$b2],7,@X[$b3]
  672. || ROTL @X[$b3],7,@X[$b0]
  673. ||[!B0] CMPLTU A0,$STEP,A1 ; less than 64 bytes left?
  674. bottom1x?:
  675. ___
  676. }
  677. $code.=<<___;
  678. ADD @Y[0],@X[0],@X[0] ; accumulate key material
  679. || ADD @Y[1],@X[1],@X[1]
  680. || ADD @Y[2],@X[2],@X[2]
  681. || ADD @Y[3],@X[3],@X[3]
  682. ||[!A1] LDNDW *${INP}++[8],@DAT[1]:@DAT[0]
  683. || [A1] BNOP tail?
  684. ADD @Y[4],@X[4],@X[4]
  685. || ADD @Y[5],@X[5],@X[5]
  686. || ADD @Y[6],@X[6],@X[6]
  687. || ADD @Y[7],@X[7],@X[7]
  688. ||[!A1] LDNDW *${INP}[-7],@DAT[3]:@DAT[2]
  689. ADD @Y[8],@X[8],@X[8]
  690. || ADD @Y[9],@X[9],@X[9]
  691. || ADD @Y[10],@X[10],@X[10]
  692. || ADD @Y[11],@X[11],@X[11]
  693. ||[!A1] LDNDW *${INP}[-6],@DAT[5]:@DAT[4]
  694. ADD @Y[12],@X[12],@X[12]
  695. || ADD @Y[13],@X[13],@X[13]
  696. || ADD @Y[14],@X[14],@X[14]
  697. || ADD @Y[15],@X[15],@X[15]
  698. ||[!A1] LDNDW *${INP}[-5],@DAT[7]:@DAT[6]
  699. [!A1] LDNDW *${INP}[-4],@DAT[9]:@DAT[8]
  700. [!A1] LDNDW *${INP}[-3],@DAT[11]:@DAT[10]
  701. LDNDW *${INP}[-2],@DAT[13]:@DAT[12]
  702. LDNDW *${INP}[-1],@DAT[15]:@DAT[14]
  703. .if .BIG_ENDIAN
  704. SWAP2 @X[0],@X[0]
  705. || SWAP2 @X[1],@X[1]
  706. || SWAP2 @X[2],@X[2]
  707. || SWAP2 @X[3],@X[3]
  708. SWAP2 @X[4],@X[4]
  709. || SWAP2 @X[5],@X[5]
  710. || SWAP2 @X[6],@X[6]
  711. || SWAP2 @X[7],@X[7]
  712. SWAP2 @X[8],@X[8]
  713. || SWAP2 @X[9],@X[9]
  714. || SWAP4 @X[0],@X[1]
  715. || SWAP4 @X[1],@X[0]
  716. SWAP2 @X[10],@X[10]
  717. || SWAP2 @X[11],@X[11]
  718. || SWAP4 @X[2],@X[3]
  719. || SWAP4 @X[3],@X[2]
  720. SWAP2 @X[12],@X[12]
  721. || SWAP2 @X[13],@X[13]
  722. || SWAP4 @X[4],@X[5]
  723. || SWAP4 @X[5],@X[4]
  724. SWAP2 @X[14],@X[14]
  725. || SWAP2 @X[15],@X[15]
  726. || SWAP4 @X[6],@X[7]
  727. || SWAP4 @X[7],@X[6]
  728. SWAP4 @X[8],@X[9]
  729. || SWAP4 @X[9],@X[8]
  730. SWAP4 @X[10],@X[11]
  731. || SWAP4 @X[11],@X[10]
  732. SWAP4 @X[12],@X[13]
  733. || SWAP4 @X[13],@X[12]
  734. SWAP4 @X[14],@X[15]
  735. || SWAP4 @X[15],@X[14]
  736. .else
  737. NOP 1
  738. .endif
  739. XOR @X[0],@DAT[0],@DAT[0] ; xor with input
  740. || XOR @X[1],@DAT[1],@DAT[1]
  741. || XOR @X[2],@DAT[2],@DAT[2]
  742. || XOR @X[3],@DAT[3],@DAT[3]
  743. || [A0] SUB A0,$STEP,A0 ; SUB A0,64,A0
  744. XOR @X[4],@DAT[4],@DAT[4]
  745. || XOR @X[5],@DAT[5],@DAT[5]
  746. || XOR @X[6],@DAT[6],@DAT[6]
  747. || XOR @X[7],@DAT[7],@DAT[7]
  748. || STNDW @DAT[1]:@DAT[0],*${OUT}++[8]
  749. XOR @X[8],@DAT[8],@DAT[8]
  750. || XOR @X[9],@DAT[9],@DAT[9]
  751. || XOR @X[10],@DAT[10],@DAT[10]
  752. || XOR @X[11],@DAT[11],@DAT[11]
  753. || STNDW @DAT[3]:@DAT[2],*${OUT}[-7]
  754. XOR @X[12],@DAT[12],@DAT[12]
  755. || XOR @X[13],@DAT[13],@DAT[13]
  756. || XOR @X[14],@DAT[14],@DAT[14]
  757. || XOR @X[15],@DAT[15],@DAT[15]
  758. || STNDW @DAT[5]:@DAT[4],*${OUT}[-6]
  759. || [A0] BNOP top1x?
  760. [A0] DMV @Y[2],@Y[0],@X[2]:@X[0] ; duplicate key material
  761. || [A0] DMV @Y[3],@Y[1],@X[3]:@X[1]
  762. || STNDW @DAT[7]:@DAT[6],*${OUT}[-5]
  763. [A0] DMV @Y[6],@Y[4],@X[6]:@X[4]
  764. || [A0] DMV @Y[7],@Y[5],@X[7]:@X[5]
  765. || STNDW @DAT[9]:@DAT[8],*${OUT}[-4]
  766. [A0] DMV @Y[10],@Y[8],@X[10]:@X[8]
  767. || [A0] DMV @Y[11],@Y[9],@X[11]:@X[9]
  768. || [A0] ADD 1,@Y[12],@Y[12] ; increment counter
  769. || STNDW @DAT[11]:@DAT[10],*${OUT}[-3]
  770. [A0] DMV @Y[14],@Y[12],@X[14]:@X[12]
  771. || [A0] DMV @Y[15],@Y[13],@X[15]:@X[13]
  772. || STNDW @DAT[13]:@DAT[12],*${OUT}[-2]
  773. [A0] MVK 10,B0 ; inner loop counter
  774. || STNDW @DAT[15]:@DAT[14],*${OUT}[-1]
  775. ;;===== branch to top1x? is taken here
  776. epilogue?:
  777. LDDW *FP[-4],A11:A10 ; ABI says so
  778. LDDW *FP[-3],A13:A12
  779. || LDDW *SP[3+8],B11:B10
  780. LDDW *SP[4+8],B13:B12
  781. || BNOP RA
  782. LDW *++SP(40+64),FP ; restore frame pointer
  783. NOP 4
  784. tail?:
  785. LDBU *${INP}++[1],B24 ; load byte by byte
  786. || SUB A0,1,A0
  787. || SUB A0,1,B1
  788. [!B1] BNOP epilogue? ; interrupts are disabled for whole time
  789. || [A0] LDBU *${INP}++[1],B24
  790. || [A0] SUB A0,1,A0
  791. || SUB B1,1,B1
  792. [!B1] BNOP epilogue?
  793. || [A0] LDBU *${INP}++[1],B24
  794. || [A0] SUB A0,1,A0
  795. || SUB B1,1,B1
  796. [!B1] BNOP epilogue?
  797. || ROTL @X[0],0,A24
  798. || [A0] LDBU *${INP}++[1],B24
  799. || [A0] SUB A0,1,A0
  800. || SUB B1,1,B1
  801. [!B1] BNOP epilogue?
  802. || ROTL @X[0],24,A24
  803. || [A0] LDBU *${INP}++[1],A24
  804. || [A0] SUB A0,1,A0
  805. || SUB B1,1,B1
  806. [!B1] BNOP epilogue?
  807. || ROTL @X[0],16,A24
  808. || [A0] LDBU *${INP}++[1],A24
  809. || [A0] SUB A0,1,A0
  810. || SUB B1,1,B1
  811. || XOR A24,B24,B25
  812. STB B25,*${OUT}++[1] ; store byte by byte
  813. ||[!B1] BNOP epilogue?
  814. || ROTL @X[0],8,A24
  815. || [A0] LDBU *${INP}++[1],A24
  816. || [A0] SUB A0,1,A0
  817. || SUB B1,1,B1
  818. || XOR A24,B24,B25
  819. STB B25,*${OUT}++[1]
  820. ___
  821. sub TAIL_STEP {
  822. my $Xi= shift;
  823. my $T = ($Xi=~/^B/?"B24":"A24"); # match @X[i] to avoid cross path
  824. my $D = $T; $D=~tr/AB/BA/;
  825. my $O = $D; $O=~s/24/25/;
  826. $code.=<<___;
  827. ||[!B1] BNOP epilogue?
  828. || ROTL $Xi,0,$T
  829. || [A0] LDBU *${INP}++[1],$D
  830. || [A0] SUB A0,1,A0
  831. || SUB B1,1,B1
  832. || XOR A24,B24,$O
  833. STB $O,*${OUT}++[1]
  834. ||[!B1] BNOP epilogue?
  835. || ROTL $Xi,24,$T
  836. || [A0] LDBU *${INP}++[1],$T
  837. || [A0] SUB A0,1,A0
  838. || SUB B1,1,B1
  839. || XOR A24,B24,$O
  840. STB $O,*${OUT}++[1]
  841. ||[!B1] BNOP epilogue?
  842. || ROTL $Xi,16,$T
  843. || [A0] LDBU *${INP}++[1],$T
  844. || [A0] SUB A0,1,A0
  845. || SUB B1,1,B1
  846. || XOR A24,B24,$O
  847. STB $O,*${OUT}++[1]
  848. ||[!B1] BNOP epilogue?
  849. || ROTL $Xi,8,$T
  850. || [A0] LDBU *${INP}++[1],$T
  851. || [A0] SUB A0,1,A0
  852. || SUB B1,1,B1
  853. || XOR A24,B24,$O
  854. STB $O,*${OUT}++[1]
  855. ___
  856. }
  857. foreach (1..14) { TAIL_STEP(@X[$_]); }
  858. $code.=<<___;
  859. ||[!B1] BNOP epilogue?
  860. || ROTL @X[15],0,B24
  861. || XOR A24,B24,A25
  862. STB A25,*${OUT}++[1]
  863. || ROTL @X[15],24,B24
  864. || XOR A24,B24,A25
  865. STB A25,*${OUT}++[1]
  866. || ROTL @X[15],16,B24
  867. || XOR A24,B24,A25
  868. STB A25,*${OUT}++[1]
  869. || XOR A24,B24,A25
  870. STB A25,*${OUT}++[1]
  871. || XOR A24,B24,B25
  872. STB B25,*${OUT}++[1]
  873. .endasmfunc
  874. .sect .const
  875. .cstring "ChaCha20 for C64x+, CRYPTOGAMS by <appro\@openssl.org>"
  876. .align 4
  877. ___
  878. print $code;
  879. close STDOUT or die "error closing STDOUT: $!";