chacha-ia64.pl 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291
  1. #!/usr/bin/env perl
  2. #
  3. # ====================================================================
  4. # Written by Andy Polyakov, @dot-asm, initially for use with OpenSSL.
  5. # ====================================================================
  6. #
  7. # ChaCha20 for Itanium.
  8. #
  9. # March 2019
  10. #
  11. # Itanium 9xxx, which has pair of shifters, manages to process one byte
  12. # in 9.3 cycles. This aligns perfectly with theoretical estimate.
  13. # On the other hand, pre-9000 CPU has single shifter and each extr/dep
  14. # pairs below takes additional cycle. Then final input->xor->output
  15. # pass runs slower than expected... Overall result is 15.6 cpb, two
  16. # cycles more than theoretical estimate.
  17. $output = pop and open STDOUT, ">$output";
  18. my @k = map("r$_",(16..31));
  19. my @x = map("r$_",(38..53));
  20. my @y = map("r$_",(8..11));
  21. my @z = map("r$_",(15,35..37));
  22. my ($out,$inp,$len,$key,$counter) = map("r$_",(32..36));
  23. $code.=<<___;
  24. #if defined(_HPUX_SOURCE)
  25. # if !defined(_LP64)
  26. # define ADDP addp4
  27. # else
  28. # define ADDP add
  29. # endif
  30. #else
  31. # define ADDP add
  32. #endif
  33. .text
  34. .global ChaCha20_ctr32#
  35. .proc ChaCha20_ctr32#
  36. .align 32
  37. ChaCha20_ctr32:
  38. .prologue
  39. .save ar.pfs,r2
  40. { .mmi; alloc r2=ar.pfs,5,17,0,0
  41. ADDP @k[11]=4,$key
  42. .save ar.lc,r3
  43. mov r3=ar.lc }
  44. { .mmi; ADDP $key=0,$key
  45. ADDP $counter=0,$counter
  46. .save pr,r14
  47. mov r14=pr };;
  48. .body
  49. { .mlx; ld4 @k[4]=[$key],8
  50. movl @k[0]=0x61707865 }
  51. { .mlx; ld4 @k[5]=[@k[11]],8
  52. movl @k[1]=0x3320646e };;
  53. { .mlx; ld4 @k[6]=[$key],8
  54. movl @k[2]=0x79622d32 }
  55. { .mlx; ld4 @k[7]=[@k[11]],8
  56. movl @k[3]=0x6b206574 };;
  57. { .mmi; ld4 @k[8]=[$key],8
  58. ld4 @k[9]=[@k[11]],8
  59. add @k[15]=4,$counter };;
  60. { .mmi; ld4 @k[10]=[$key]
  61. ld4 @k[11]=[@k[11]]
  62. mov @x[0]=@k[0] };;
  63. { .mmi; ld4 @k[12]=[$counter],8
  64. ld4 @k[13]=[@k[15]],8
  65. mov @x[1]=@k[1] };;
  66. { .mmi; ld4 @k[14]=[$counter]
  67. ld4 @k[15]=[@k[15]]
  68. mov @x[2]=@k[2] }
  69. { .mmi; mov @x[3]=@k[3]
  70. mov @x[4]=@k[4]
  71. mov @x[5]=@k[5] };;
  72. { .mmi; mov @x[6]=@k[6]
  73. mov @x[7]=@k[7]
  74. mov @x[8]=@k[8] }
  75. { .mmi; mov @x[9]=@k[9]
  76. mov @x[10]=@k[10]
  77. mov @x[11]=@k[11] }
  78. { .mmi; mov @x[12]=@k[12]
  79. mov @x[13]=@k[13]
  80. mov @x[14]=@k[14] };;
  81. .Loop_outer:
  82. { .mii; mov @x[15]=@k[15]
  83. mov ar.lc=9
  84. mov ar.ec=1 }
  85. { .mmb; cmp.geu p6,p0=64,$len
  86. sub @z[1]=64,$len
  87. brp.loop.imp .Loop_top,.Loop_end-16 };;
  88. .Loop_top:
  89. ___
  90. sub ROUND {
  91. my ($a0,$b0,$c0,$d0)=@_;
  92. my ($a1,$b1,$c1,$d1)=map(($_&~3)+(($_+1)&3),($a0,$b0,$c0,$d0));
  93. my ($a2,$b2,$c2,$d2)=map(($_&~3)+(($_+1)&3),($a1,$b1,$c1,$d1));
  94. my ($a3,$b3,$c3,$d3)=map(($_&~3)+(($_+1)&3),($a2,$b2,$c2,$d2));
  95. $code.=<<___;
  96. { .mmi; add @x[$a0]=@x[$a0],@x[$b0]
  97. add @x[$a1]=@x[$a1],@x[$b1]
  98. add @x[$a2]=@x[$a2],@x[$b2] };;
  99. { .mmi; add @x[$a3]=@x[$a3],@x[$b3]
  100. xor @x[$d0]=@x[$d0],@x[$a0]
  101. xor @x[$d1]=@x[$d1],@x[$a1] };;
  102. { .mmi; xor @x[$d2]=@x[$d2],@x[$a2]
  103. xor @x[$d3]=@x[$d3],@x[$a3]
  104. extr.u @y[0]=@x[$d0],16,16 };;
  105. { .mii; extr.u @y[1]=@x[$d1],16,16
  106. dep @x[$d0]=@x[$d0],@y[0],16,16 };;
  107. { .mii; add @x[$c0]=@x[$c0],@x[$d0]
  108. extr.u @y[2]=@x[$d2],16,16
  109. dep @x[$d1]=@x[$d1],@y[1],16,16 };;
  110. { .mii; add @x[$c1]=@x[$c1],@x[$d1]
  111. xor @x[$b0]=@x[$b0],@x[$c0]
  112. extr.u @y[3]=@x[$d3],16,16 };;
  113. { .mii; xor @x[$b1]=@x[$b1],@x[$c1]
  114. dep @x[$d2]=@x[$d2],@y[2],16,16
  115. dep @x[$d3]=@x[$d3],@y[3],16,16 };;
  116. { .mmi; add @x[$c2]=@x[$c2],@x[$d2]
  117. add @x[$c3]=@x[$c3],@x[$d3]
  118. extr.u @y[0]=@x[$b0],20,12 };;
  119. { .mmi; xor @x[$b2]=@x[$b2],@x[$c2]
  120. xor @x[$b3]=@x[$b3],@x[$c3]
  121. dep.z @x[$b0]=@x[$b0],12,20 };;
  122. { .mii; or @x[$b0]=@x[$b0],@y[0]
  123. extr.u @y[1]=@x[$b1],20,12
  124. dep.z @x[$b1]=@x[$b1],12,20 };;
  125. { .mii; add @x[$a0]=@x[$a0],@x[$b0]
  126. extr.u @y[2]=@x[$b2],20,12
  127. extr.u @y[3]=@x[$b3],20,12 }
  128. { .mii; or @x[$b1]=@x[$b1],@y[1]
  129. dep.z @x[$b2]=@x[$b2],12,20
  130. dep.z @x[$b3]=@x[$b3],12,20 };;
  131. { .mmi; or @x[$b2]=@x[$b2],@y[2]
  132. or @x[$b3]=@x[$b3],@y[3]
  133. add @x[$a1]=@x[$a1],@x[$b1] };;
  134. { .mmi; add @x[$a2]=@x[$a2],@x[$b2]
  135. add @x[$a3]=@x[$a3],@x[$b3]
  136. xor @x[$d0]=@x[$d0],@x[$a0] };;
  137. { .mii; xor @x[$d1]=@x[$d1],@x[$a1]
  138. extr.u @y[0]=@x[$d0],24,8
  139. dep.z @x[$d0]=@x[$d0],8,24 };;
  140. { .mii; or @x[$d0]=@x[$d0],@y[0]
  141. extr.u @y[1]=@x[$d1],24,8
  142. dep.z @x[$d1]=@x[$d1],8,24 };;
  143. { .mmi; or @x[$d1]=@x[$d1],@y[1]
  144. xor @x[$d2]=@x[$d2],@x[$a2]
  145. xor @x[$d3]=@x[$d3],@x[$a3] };;
  146. { .mii; add @x[$c0]=@x[$c0],@x[$d0]
  147. extr.u @y[2]=@x[$d2],24,8
  148. dep.z @x[$d2]=@x[$d2],8,24 };;
  149. { .mii; xor @x[$b0]=@x[$b0],@x[$c0]
  150. extr.u @y[3]=@x[$d3],24,8
  151. dep.z @x[$d3]=@x[$d3],8,24 };;
  152. { .mmi; or @x[$d2]=@x[$d2],@y[2]
  153. or @x[$d3]=@x[$d3],@y[3]
  154. extr.u @y[0]=@x[$b0],25,7 };;
  155. { .mmi; add @x[$c1]=@x[$c1],@x[$d1]
  156. add @x[$c2]=@x[$c2],@x[$d2]
  157. dep.z @x[$b0]=@x[$b0],7,25 };;
  158. { .mmi; xor @x[$b1]=@x[$b1],@x[$c1]
  159. xor @x[$b2]=@x[$b2],@x[$c2]
  160. add @x[$c3]=@x[$c3],@x[$d3] };;
  161. { .mii; xor @x[$b3]=@x[$b3],@x[$c3]
  162. extr.u @y[1]=@x[$b1],25,7
  163. dep.z @x[$b1]=@x[$b1],7,25 };;
  164. { .mii; or @x[$b0]=@x[$b0],@y[0]
  165. extr.u @y[2]=@x[$b2],25,7
  166. dep.z @x[$b2]=@x[$b2],7,25 };;
  167. { .mii; or @x[$b1]=@x[$b1],@y[1]
  168. extr.u @y[3]=@x[$b3],25,7
  169. dep.z @x[$b3]=@x[$b3],7,25 };;
  170. ___
  171. $code.=<<___ if ($d0 == 12);
  172. { .mmi; or @x[$b2]=@x[$b2],@y[2]
  173. or @x[$b3]=@x[$b3],@y[3]
  174. mov @z[0]=-1 };;
  175. ___
  176. $code.=<<___ if ($d0 == 15);
  177. { .mmb; or @x[$b2]=@x[$b2],@y[2]
  178. or @x[$b3]=@x[$b3],@y[3]
  179. br.ctop.sptk .Loop_top };;
  180. ___
  181. }
  182. &ROUND(0, 4, 8, 12);
  183. &ROUND(0, 5, 10, 15);
  184. $code.=<<___;
  185. .Loop_end:
  186. { .mmi; add @x[0]=@x[0],@k[0]
  187. add @x[1]=@x[1],@k[1]
  188. (p6) shr.u @z[0]=@z[0],@z[1] }
  189. { .mmb; add @x[2]=@x[2],@k[2]
  190. add @x[3]=@x[3],@k[3]
  191. clrrrb.pr };;
  192. { .mmi; add @x[4]=@x[4],@k[4]
  193. add @x[5]=@x[5],@k[5]
  194. add @x[6]=@x[6],@k[6] }
  195. { .mmi; add @x[7]=@x[7],@k[7]
  196. add @x[8]=@x[8],@k[8]
  197. add @x[9]=@x[9],@k[9] }
  198. { .mmi; add @x[10]=@x[10],@k[10]
  199. add @x[11]=@x[11],@k[11]
  200. add @x[12]=@x[12],@k[12] }
  201. { .mmi; add @x[13]=@x[13],@k[13]
  202. add @x[14]=@x[14],@k[14]
  203. add @x[15]=@x[15],@k[15] }
  204. { .mmi; add @k[12]=1,@k[12] // next counter
  205. mov pr=@z[0],0x1ffff };;
  206. //////////////////////////////////////////////////////////////////
  207. // Each predicate bit corresponds to byte to be processed. Note
  208. // that p0 is wired to 1, but it works out, because there always
  209. // is at least one byte to process...
  210. { .mmi; (p0) ld1 @z[0]=[$inp],1
  211. shr.u @y[1]=@x[0],8 };;
  212. { .mmi; (p1) ld1 @z[1]=[$inp],1
  213. (p2) shr.u @y[2]=@x[0],16 };;
  214. { .mmi; (p2) ld1 @z[2]=[$inp],1
  215. (p0) xor @z[0]=@z[0],@x[0]
  216. (p3) shr.u @y[3]=@x[0],24 };;
  217. ___
  218. for(my $i0=0; $i0<60; $i0+=4) {
  219. my ($i1, $i2, $i3, $i4, $i5, $i6, $i7) = map($i0+$_,(1..7));
  220. my $k = $i0/4+1;
  221. $code.=<<___;
  222. { .mmi; (p$i3) ld1 @z[3]=[$inp],1
  223. (p$i0) st1 [$out]=@z[0],1
  224. (p$i1) xor @z[1]=@z[1],@y[1] };;
  225. { .mmi; (p$i4) ld1 @z[0]=[$inp],1
  226. (p$i5) shr.u @y[1]=@x[$k],8 }
  227. { .mmi; (p$i1) st1 [$out]=@z[1],1
  228. (p$i2) xor @z[2]=@z[2],@y[2]
  229. (p1) mov @x[$k-1]=@k[$k-1] };;
  230. { .mfi; (p$i5) ld1 @z[1]=[$inp],1
  231. (p$i6) shr.u @y[2]=@x[$k],16 }
  232. { .mfi; (p$i2) st1 [$out]=@z[2],1
  233. (p$i3) xor @z[3]=@z[3],@y[3] };;
  234. { .mfi; (p$i6) ld1 @z[2]=[$inp],1
  235. (p$i7) shr.u @y[3]=@x[$k],24 }
  236. ___
  237. $code.=<<___ if ($i0==0); # p1,p2 are available for reuse in first round
  238. { .mmi; (p$i3) st1 [$out]=@z[3],1
  239. (p$i4) xor @z[0]=@z[0],@x[$k]
  240. cmp.ltu p1,p2=64,$len };;
  241. ___
  242. $code.=<<___ if ($i0>0);
  243. { .mfi; (p$i3) st1 [$out]=@z[3],1
  244. (p$i4) xor @z[0]=@z[0],@x[$k] };;
  245. ___
  246. }
  247. $code.=<<___;
  248. { .mmi; (p63) ld1 @z[3]=[$inp],1
  249. (p60) st1 [$out]=@z[0],1
  250. (p61) xor @z[1]=@z[1],@y[1] };;
  251. { .mmi; (p61) st1 [$out]=@z[1],1
  252. (p62) xor @z[2]=@z[2],@y[2] };;
  253. { .mmi; (p62) st1 [$out]=@z[2],1
  254. (p63) xor @z[3]=@z[3],@y[3]
  255. (p2) mov ar.lc=r3 };;
  256. { .mib; (p63) st1 [$out]=@z[3],1
  257. (p1) add $len=-64,$len
  258. (p1) br.dptk.many .Loop_outer };;
  259. { .mmi; mov @k[4]=0 // wipe key material
  260. mov @k[5]=0
  261. mov @k[6]=0 }
  262. { .mmi; mov @k[7]=0
  263. mov @k[8]=0
  264. mov @k[9]=0 }
  265. { .mmi; mov @k[10]=0
  266. mov @k[11]=0
  267. mov @k[12]=0 }
  268. { .mmi; mov @k[13]=0
  269. mov @k[14]=0
  270. mov @k[15]=0 }
  271. { .mib; mov pr=r14,0x1ffff
  272. br.ret.sptk.many b0 };;
  273. .endp ChaCha20_ctr32#
  274. stringz "ChaCha20 for IA64, CRYPTOGAMS by \@dot-asm"
  275. ___
  276. print $code;
  277. close STDOUT or die "error closing STDOUT: $!";