1 /**
2  * \file bn_mul.h
3  *
4  * \brief  Multi-precision integer library
5  *
6  *  Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
7  *  SPDX-License-Identifier: Apache-2.0
8  *
9  *  Licensed under the Apache License, Version 2.0 (the "License"); you may
10  *  not use this file except in compliance with the License.
11  *  You may obtain a copy of the License at
12  *
13  *  http://www.apache.org/licenses/LICENSE-2.0
14  *
15  *  Unless required by applicable law or agreed to in writing, software
16  *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
17  *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
18  *  See the License for the specific language governing permissions and
19  *  limitations under the License.
20  *
21  *  This file is part of mbed TLS (https://tls.mbed.org)
22  */
23 /*
24  *      Multiply source vector [s] with b, add result
25  *       to destination vector [d] and set carry c.
26  *
27  *      Currently supports:
28  *
29  *         . IA-32 (386+)         . AMD64 / EM64T
30  *         . IA-32 (SSE2)         . Motorola 68000
31  *         . PowerPC, 32-bit      . MicroBlaze
32  *         . PowerPC, 64-bit      . TriCore
33  *         . SPARC v8             . ARM v3+
34  *         . Alpha                . MIPS32
35  *         . C, longlong          . C, generic
36  */
37 #ifndef MBEDTLS_BN_MUL_H
38 #define MBEDTLS_BN_MUL_H
39 
40 #include "bignum.h"
41 
42 #if defined(MBEDTLS_HAVE_ASM)
43 
44 #ifndef asm
45 #define asm __asm
46 #endif
47 
48 /* armcc5 --gnu defines __GNUC__ but doesn't support GNU's extended asm */
49 #if defined(__GNUC__) && \
50     ( !defined(__ARMCC_VERSION) || __ARMCC_VERSION >= 6000000 )
51 #if defined(__i386__)
52 
53 #define MULADDC_INIT                        \
54     asm(                                    \
55         "movl   %%ebx, %0           \n\t"   \
56         "movl   %5, %%esi           \n\t"   \
57         "movl   %6, %%edi           \n\t"   \
58         "movl   %7, %%ecx           \n\t"   \
59         "movl   %8, %%ebx           \n\t"
60 
61 #define MULADDC_CORE                        \
62         "lodsl                      \n\t"   \
63         "mull   %%ebx               \n\t"   \
64         "addl   %%ecx,   %%eax      \n\t"   \
65         "adcl   $0,      %%edx      \n\t"   \
66         "addl   (%%edi), %%eax      \n\t"   \
67         "adcl   $0,      %%edx      \n\t"   \
68         "movl   %%edx,   %%ecx      \n\t"   \
69         "stosl                      \n\t"
70 
71 #if defined(MBEDTLS_HAVE_SSE2)
72 
73 #define MULADDC_HUIT                            \
74         "movd     %%ecx,     %%mm1      \n\t"   \
75         "movd     %%ebx,     %%mm0      \n\t"   \
76         "movd     (%%edi),   %%mm3      \n\t"   \
77         "paddq    %%mm3,     %%mm1      \n\t"   \
78         "movd     (%%esi),   %%mm2      \n\t"   \
79         "pmuludq  %%mm0,     %%mm2      \n\t"   \
80         "movd     4(%%esi),  %%mm4      \n\t"   \
81         "pmuludq  %%mm0,     %%mm4      \n\t"   \
82         "movd     8(%%esi),  %%mm6      \n\t"   \
83         "pmuludq  %%mm0,     %%mm6      \n\t"   \
84         "movd     12(%%esi), %%mm7      \n\t"   \
85         "pmuludq  %%mm0,     %%mm7      \n\t"   \
86         "paddq    %%mm2,     %%mm1      \n\t"   \
87         "movd     4(%%edi),  %%mm3      \n\t"   \
88         "paddq    %%mm4,     %%mm3      \n\t"   \
89         "movd     8(%%edi),  %%mm5      \n\t"   \
90         "paddq    %%mm6,     %%mm5      \n\t"   \
91         "movd     12(%%edi), %%mm4      \n\t"   \
92         "paddq    %%mm4,     %%mm7      \n\t"   \
93         "movd     %%mm1,     (%%edi)    \n\t"   \
94         "movd     16(%%esi), %%mm2      \n\t"   \
95         "pmuludq  %%mm0,     %%mm2      \n\t"   \
96         "psrlq    $32,       %%mm1      \n\t"   \
97         "movd     20(%%esi), %%mm4      \n\t"   \
98         "pmuludq  %%mm0,     %%mm4      \n\t"   \
99         "paddq    %%mm3,     %%mm1      \n\t"   \
100         "movd     24(%%esi), %%mm6      \n\t"   \
101         "pmuludq  %%mm0,     %%mm6      \n\t"   \
102         "movd     %%mm1,     4(%%edi)   \n\t"   \
103         "psrlq    $32,       %%mm1      \n\t"   \
104         "movd     28(%%esi), %%mm3      \n\t"   \
105         "pmuludq  %%mm0,     %%mm3      \n\t"   \
106         "paddq    %%mm5,     %%mm1      \n\t"   \
107         "movd     16(%%edi), %%mm5      \n\t"   \
108         "paddq    %%mm5,     %%mm2      \n\t"   \
109         "movd     %%mm1,     8(%%edi)   \n\t"   \
110         "psrlq    $32,       %%mm1      \n\t"   \
111         "paddq    %%mm7,     %%mm1      \n\t"   \
112         "movd     20(%%edi), %%mm5      \n\t"   \
113         "paddq    %%mm5,     %%mm4      \n\t"   \
114         "movd     %%mm1,     12(%%edi)  \n\t"   \
115         "psrlq    $32,       %%mm1      \n\t"   \
116         "paddq    %%mm2,     %%mm1      \n\t"   \
117         "movd     24(%%edi), %%mm5      \n\t"   \
118         "paddq    %%mm5,     %%mm6      \n\t"   \
119         "movd     %%mm1,     16(%%edi)  \n\t"   \
120         "psrlq    $32,       %%mm1      \n\t"   \
121         "paddq    %%mm4,     %%mm1      \n\t"   \
122         "movd     28(%%edi), %%mm5      \n\t"   \
123         "paddq    %%mm5,     %%mm3      \n\t"   \
124         "movd     %%mm1,     20(%%edi)  \n\t"   \
125         "psrlq    $32,       %%mm1      \n\t"   \
126         "paddq    %%mm6,     %%mm1      \n\t"   \
127         "movd     %%mm1,     24(%%edi)  \n\t"   \
128         "psrlq    $32,       %%mm1      \n\t"   \
129         "paddq    %%mm3,     %%mm1      \n\t"   \
130         "movd     %%mm1,     28(%%edi)  \n\t"   \
131         "addl     $32,       %%edi      \n\t"   \
132         "addl     $32,       %%esi      \n\t"   \
133         "psrlq    $32,       %%mm1      \n\t"   \
134         "movd     %%mm1,     %%ecx      \n\t"
135 
136 #define MULADDC_STOP                    \
137         "emms                   \n\t"   \
138         "movl   %4, %%ebx       \n\t"   \
139         "movl   %%ecx, %1       \n\t"   \
140         "movl   %%edi, %2       \n\t"   \
141         "movl   %%esi, %3       \n\t"   \
142         : "=m" (t), "=m" (c), "=m" (d), "=m" (s)        \
143         : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b)   \
144         : "eax", "ecx", "edx", "esi", "edi"             \
145     );
146 
147 #else
148 
149 #define MULADDC_STOP                    \
150         "movl   %4, %%ebx       \n\t"   \
151         "movl   %%ecx, %1       \n\t"   \
152         "movl   %%edi, %2       \n\t"   \
153         "movl   %%esi, %3       \n\t"   \
154         : "=m" (t), "=m" (c), "=m" (d), "=m" (s)        \
155         : "m" (t), "m" (s), "m" (d), "m" (c), "m" (b)   \
156         : "eax", "ecx", "edx", "esi", "edi"             \
157     );
158 #endif /* SSE2 */
159 #endif /* i386 */
160 
161 #if defined(__amd64__) || defined (__x86_64__)
162 
163 #define MULADDC_INIT                        \
164     asm(                                    \
165         "movq   %3, %%rsi           \n\t"   \
166         "movq   %4, %%rdi           \n\t"   \
167         "movq   %5, %%rcx           \n\t"   \
168         "movq   %6, %%rbx           \n\t"   \
169         "xorq   %%r8, %%r8          \n\t"
170 
171 #define MULADDC_CORE                        \
172         "movq   (%%rsi), %%rax      \n\t"   \
173         "mulq   %%rbx               \n\t"   \
174         "addq   $8,      %%rsi      \n\t"   \
175         "addq   %%rcx,   %%rax      \n\t"   \
176         "movq   %%r8,    %%rcx      \n\t"   \
177         "adcq   $0,      %%rdx      \n\t"   \
178         "nop                        \n\t"   \
179         "addq   %%rax,   (%%rdi)    \n\t"   \
180         "adcq   %%rdx,   %%rcx      \n\t"   \
181         "addq   $8,      %%rdi      \n\t"
182 
183 #define MULADDC_STOP                        \
184         "movq   %%rcx, %0           \n\t"   \
185         "movq   %%rdi, %1           \n\t"   \
186         "movq   %%rsi, %2           \n\t"   \
187         : "=m" (c), "=m" (d), "=m" (s)                      \
188         : "m" (s), "m" (d), "m" (c), "m" (b)                \
189         : "rax", "rcx", "rdx", "rbx", "rsi", "rdi", "r8"    \
190     );
191 
192 #endif /* AMD64 */
193 
194 #if defined(__mc68020__) || defined(__mcpu32__)
195 
196 #define MULADDC_INIT                    \
197     asm(                                \
198         "movl   %3, %%a2        \n\t"   \
199         "movl   %4, %%a3        \n\t"   \
200         "movl   %5, %%d3        \n\t"   \
201         "movl   %6, %%d2        \n\t"   \
202         "moveq  #0, %%d0        \n\t"
203 
204 #define MULADDC_CORE                    \
205         "movel  %%a2@+, %%d1    \n\t"   \
206         "mulul  %%d2, %%d4:%%d1 \n\t"   \
207         "addl   %%d3, %%d1      \n\t"   \
208         "addxl  %%d0, %%d4      \n\t"   \
209         "moveq  #0,   %%d3      \n\t"   \
210         "addl   %%d1, %%a3@+    \n\t"   \
211         "addxl  %%d4, %%d3      \n\t"
212 
213 #define MULADDC_STOP                    \
214         "movl   %%d3, %0        \n\t"   \
215         "movl   %%a3, %1        \n\t"   \
216         "movl   %%a2, %2        \n\t"   \
217         : "=m" (c), "=m" (d), "=m" (s)              \
218         : "m" (s), "m" (d), "m" (c), "m" (b)        \
219         : "d0", "d1", "d2", "d3", "d4", "a2", "a3"  \
220     );
221 
222 #define MULADDC_HUIT                        \
223         "movel  %%a2@+,  %%d1       \n\t"   \
224         "mulul  %%d2,    %%d4:%%d1  \n\t"   \
225         "addxl  %%d3,    %%d1       \n\t"   \
226         "addxl  %%d0,    %%d4       \n\t"   \
227         "addl   %%d1,    %%a3@+     \n\t"   \
228         "movel  %%a2@+,  %%d1       \n\t"   \
229         "mulul  %%d2,    %%d3:%%d1  \n\t"   \
230         "addxl  %%d4,    %%d1       \n\t"   \
231         "addxl  %%d0,    %%d3       \n\t"   \
232         "addl   %%d1,    %%a3@+     \n\t"   \
233         "movel  %%a2@+,  %%d1       \n\t"   \
234         "mulul  %%d2,    %%d4:%%d1  \n\t"   \
235         "addxl  %%d3,    %%d1       \n\t"   \
236         "addxl  %%d0,    %%d4       \n\t"   \
237         "addl   %%d1,    %%a3@+     \n\t"   \
238         "movel  %%a2@+,  %%d1       \n\t"   \
239         "mulul  %%d2,    %%d3:%%d1  \n\t"   \
240         "addxl  %%d4,    %%d1       \n\t"   \
241         "addxl  %%d0,    %%d3       \n\t"   \
242         "addl   %%d1,    %%a3@+     \n\t"   \
243         "movel  %%a2@+,  %%d1       \n\t"   \
244         "mulul  %%d2,    %%d4:%%d1  \n\t"   \
245         "addxl  %%d3,    %%d1       \n\t"   \
246         "addxl  %%d0,    %%d4       \n\t"   \
247         "addl   %%d1,    %%a3@+     \n\t"   \
248         "movel  %%a2@+,  %%d1       \n\t"   \
249         "mulul  %%d2,    %%d3:%%d1  \n\t"   \
250         "addxl  %%d4,    %%d1       \n\t"   \
251         "addxl  %%d0,    %%d3       \n\t"   \
252         "addl   %%d1,    %%a3@+     \n\t"   \
253         "movel  %%a2@+,  %%d1       \n\t"   \
254         "mulul  %%d2,    %%d4:%%d1  \n\t"   \
255         "addxl  %%d3,    %%d1       \n\t"   \
256         "addxl  %%d0,    %%d4       \n\t"   \
257         "addl   %%d1,    %%a3@+     \n\t"   \
258         "movel  %%a2@+,  %%d1       \n\t"   \
259         "mulul  %%d2,    %%d3:%%d1  \n\t"   \
260         "addxl  %%d4,    %%d1       \n\t"   \
261         "addxl  %%d0,    %%d3       \n\t"   \
262         "addl   %%d1,    %%a3@+     \n\t"   \
263         "addxl  %%d0,    %%d3       \n\t"
264 
265 #endif /* MC68000 */
266 
267 #if defined(__powerpc64__) || defined(__ppc64__)
268 
269 #if defined(__MACH__) && defined(__APPLE__)
270 
271 #define MULADDC_INIT                        \
272     asm(                                    \
273         "ld     r3, %3              \n\t"   \
274         "ld     r4, %4              \n\t"   \
275         "ld     r5, %5              \n\t"   \
276         "ld     r6, %6              \n\t"   \
277         "addi   r3, r3, -8          \n\t"   \
278         "addi   r4, r4, -8          \n\t"   \
279         "addic  r5, r5,  0          \n\t"
280 
281 #define MULADDC_CORE                        \
282         "ldu    r7, 8(r3)           \n\t"   \
283         "mulld  r8, r7, r6          \n\t"   \
284         "mulhdu r9, r7, r6          \n\t"   \
285         "adde   r8, r8, r5          \n\t"   \
286         "ld     r7, 8(r4)           \n\t"   \
287         "addze  r5, r9              \n\t"   \
288         "addc   r8, r8, r7          \n\t"   \
289         "stdu   r8, 8(r4)           \n\t"
290 
291 #define MULADDC_STOP                        \
292         "addze  r5, r5              \n\t"   \
293         "addi   r4, r4, 8           \n\t"   \
294         "addi   r3, r3, 8           \n\t"   \
295         "std    r5, %0              \n\t"   \
296         "std    r4, %1              \n\t"   \
297         "std    r3, %2              \n\t"   \
298         : "=m" (c), "=m" (d), "=m" (s)              \
299         : "m" (s), "m" (d), "m" (c), "m" (b)        \
300         : "r3", "r4", "r5", "r6", "r7", "r8", "r9"  \
301     );
302 
303 
304 #else /* __MACH__ && __APPLE__ */
305 
306 #define MULADDC_INIT                        \
307     asm(                                    \
308         "ld     %%r3, %3            \n\t"   \
309         "ld     %%r4, %4            \n\t"   \
310         "ld     %%r5, %5            \n\t"   \
311         "ld     %%r6, %6            \n\t"   \
312         "addi   %%r3, %%r3, -8      \n\t"   \
313         "addi   %%r4, %%r4, -8      \n\t"   \
314         "addic  %%r5, %%r5,  0      \n\t"
315 
316 #define MULADDC_CORE                        \
317         "ldu    %%r7, 8(%%r3)       \n\t"   \
318         "mulld  %%r8, %%r7, %%r6    \n\t"   \
319         "mulhdu %%r9, %%r7, %%r6    \n\t"   \
320         "adde   %%r8, %%r8, %%r5    \n\t"   \
321         "ld     %%r7, 8(%%r4)       \n\t"   \
322         "addze  %%r5, %%r9          \n\t"   \
323         "addc   %%r8, %%r8, %%r7    \n\t"   \
324         "stdu   %%r8, 8(%%r4)       \n\t"
325 
326 #define MULADDC_STOP                        \
327         "addze  %%r5, %%r5          \n\t"   \
328         "addi   %%r4, %%r4, 8       \n\t"   \
329         "addi   %%r3, %%r3, 8       \n\t"   \
330         "std    %%r5, %0            \n\t"   \
331         "std    %%r4, %1            \n\t"   \
332         "std    %%r3, %2            \n\t"   \
333         : "=m" (c), "=m" (d), "=m" (s)              \
334         : "m" (s), "m" (d), "m" (c), "m" (b)        \
335         : "r3", "r4", "r5", "r6", "r7", "r8", "r9"  \
336     );
337 
338 #endif /* __MACH__ && __APPLE__ */
339 
340 #elif defined(__powerpc__) || defined(__ppc__) /* end PPC64/begin PPC32  */
341 
342 #if defined(__MACH__) && defined(__APPLE__)
343 
344 #define MULADDC_INIT                    \
345     asm(                                \
346         "lwz    r3, %3          \n\t"   \
347         "lwz    r4, %4          \n\t"   \
348         "lwz    r5, %5          \n\t"   \
349         "lwz    r6, %6          \n\t"   \
350         "addi   r3, r3, -4      \n\t"   \
351         "addi   r4, r4, -4      \n\t"   \
352         "addic  r5, r5,  0      \n\t"
353 
354 #define MULADDC_CORE                    \
355         "lwzu   r7, 4(r3)       \n\t"   \
356         "mullw  r8, r7, r6      \n\t"   \
357         "mulhwu r9, r7, r6      \n\t"   \
358         "adde   r8, r8, r5      \n\t"   \
359         "lwz    r7, 4(r4)       \n\t"   \
360         "addze  r5, r9          \n\t"   \
361         "addc   r8, r8, r7      \n\t"   \
362         "stwu   r8, 4(r4)       \n\t"
363 
364 #define MULADDC_STOP                    \
365         "addze  r5, r5          \n\t"   \
366         "addi   r4, r4, 4       \n\t"   \
367         "addi   r3, r3, 4       \n\t"   \
368         "stw    r5, %0          \n\t"   \
369         "stw    r4, %1          \n\t"   \
370         "stw    r3, %2          \n\t"   \
371         : "=m" (c), "=m" (d), "=m" (s)              \
372         : "m" (s), "m" (d), "m" (c), "m" (b)        \
373         : "r3", "r4", "r5", "r6", "r7", "r8", "r9"  \
374     );
375 
376 #else /* __MACH__ && __APPLE__ */
377 
378 #define MULADDC_INIT                        \
379     asm(                                    \
380         "lwz    %%r3, %3            \n\t"   \
381         "lwz    %%r4, %4            \n\t"   \
382         "lwz    %%r5, %5            \n\t"   \
383         "lwz    %%r6, %6            \n\t"   \
384         "addi   %%r3, %%r3, -4      \n\t"   \
385         "addi   %%r4, %%r4, -4      \n\t"   \
386         "addic  %%r5, %%r5,  0      \n\t"
387 
388 #define MULADDC_CORE                        \
389         "lwzu   %%r7, 4(%%r3)       \n\t"   \
390         "mullw  %%r8, %%r7, %%r6    \n\t"   \
391         "mulhwu %%r9, %%r7, %%r6    \n\t"   \
392         "adde   %%r8, %%r8, %%r5    \n\t"   \
393         "lwz    %%r7, 4(%%r4)       \n\t"   \
394         "addze  %%r5, %%r9          \n\t"   \
395         "addc   %%r8, %%r8, %%r7    \n\t"   \
396         "stwu   %%r8, 4(%%r4)       \n\t"
397 
398 #define MULADDC_STOP                        \
399         "addze  %%r5, %%r5          \n\t"   \
400         "addi   %%r4, %%r4, 4       \n\t"   \
401         "addi   %%r3, %%r3, 4       \n\t"   \
402         "stw    %%r5, %0            \n\t"   \
403         "stw    %%r4, %1            \n\t"   \
404         "stw    %%r3, %2            \n\t"   \
405         : "=m" (c), "=m" (d), "=m" (s)              \
406         : "m" (s), "m" (d), "m" (c), "m" (b)        \
407         : "r3", "r4", "r5", "r6", "r7", "r8", "r9"  \
408     );
409 
410 #endif /* __MACH__ && __APPLE__ */
411 
412 #endif /* PPC32 */
413 
414 /*
415  * The Sparc(64) assembly is reported to be broken.
416  * Disable it for now, until we're able to fix it.
417  */
418 #if 0 && defined(__sparc__)
419 #if defined(__sparc64__)
420 
421 #define MULADDC_INIT                                    \
422     asm(                                                \
423                 "ldx     %3, %%o0               \n\t"   \
424                 "ldx     %4, %%o1               \n\t"   \
425                 "ld      %5, %%o2               \n\t"   \
426                 "ld      %6, %%o3               \n\t"
427 
428 #define MULADDC_CORE                                    \
429                 "ld      [%%o0], %%o4           \n\t"   \
430                 "inc     4, %%o0                \n\t"   \
431                 "ld      [%%o1], %%o5           \n\t"   \
432                 "umul    %%o3, %%o4, %%o4       \n\t"   \
433                 "addcc   %%o4, %%o2, %%o4       \n\t"   \
434                 "rd      %%y, %%g1              \n\t"   \
435                 "addx    %%g1, 0, %%g1          \n\t"   \
436                 "addcc   %%o4, %%o5, %%o4       \n\t"   \
437                 "st      %%o4, [%%o1]           \n\t"   \
438                 "addx    %%g1, 0, %%o2          \n\t"   \
439                 "inc     4, %%o1                \n\t"
440 
441         #define MULADDC_STOP                            \
442                 "st      %%o2, %0               \n\t"   \
443                 "stx     %%o1, %1               \n\t"   \
444                 "stx     %%o0, %2               \n\t"   \
445         : "=m" (c), "=m" (d), "=m" (s)          \
446         : "m" (s), "m" (d), "m" (c), "m" (b)    \
447         : "g1", "o0", "o1", "o2", "o3", "o4",   \
448           "o5"                                  \
449         );
450 
451 #else /* __sparc64__ */
452 
453 #define MULADDC_INIT                                    \
454     asm(                                                \
455                 "ld      %3, %%o0               \n\t"   \
456                 "ld      %4, %%o1               \n\t"   \
457                 "ld      %5, %%o2               \n\t"   \
458                 "ld      %6, %%o3               \n\t"
459 
460 #define MULADDC_CORE                                    \
461                 "ld      [%%o0], %%o4           \n\t"   \
462                 "inc     4, %%o0                \n\t"   \
463                 "ld      [%%o1], %%o5           \n\t"   \
464                 "umul    %%o3, %%o4, %%o4       \n\t"   \
465                 "addcc   %%o4, %%o2, %%o4       \n\t"   \
466                 "rd      %%y, %%g1              \n\t"   \
467                 "addx    %%g1, 0, %%g1          \n\t"   \
468                 "addcc   %%o4, %%o5, %%o4       \n\t"   \
469                 "st      %%o4, [%%o1]           \n\t"   \
470                 "addx    %%g1, 0, %%o2          \n\t"   \
471                 "inc     4, %%o1                \n\t"
472 
473 #define MULADDC_STOP                                    \
474                 "st      %%o2, %0               \n\t"   \
475                 "st      %%o1, %1               \n\t"   \
476                 "st      %%o0, %2               \n\t"   \
477         : "=m" (c), "=m" (d), "=m" (s)          \
478         : "m" (s), "m" (d), "m" (c), "m" (b)    \
479         : "g1", "o0", "o1", "o2", "o3", "o4",   \
480           "o5"                                  \
481         );
482 
483 #endif /* __sparc64__ */
484 #endif /* __sparc__ */
485 
486 #if defined(__microblaze__) || defined(microblaze)
487 
488 #define MULADDC_INIT                    \
489     asm(                                \
490         "lwi   r3,   %3         \n\t"   \
491         "lwi   r4,   %4         \n\t"   \
492         "lwi   r5,   %5         \n\t"   \
493         "lwi   r6,   %6         \n\t"   \
494         "andi  r7,   r6, 0xffff \n\t"   \
495         "bsrli r6,   r6, 16     \n\t"
496 
497 #define MULADDC_CORE                    \
498         "lhui  r8,   r3,   0    \n\t"   \
499         "addi  r3,   r3,   2    \n\t"   \
500         "lhui  r9,   r3,   0    \n\t"   \
501         "addi  r3,   r3,   2    \n\t"   \
502         "mul   r10,  r9,  r6    \n\t"   \
503         "mul   r11,  r8,  r7    \n\t"   \
504         "mul   r12,  r9,  r7    \n\t"   \
505         "mul   r13,  r8,  r6    \n\t"   \
506         "bsrli  r8, r10,  16    \n\t"   \
507         "bsrli  r9, r11,  16    \n\t"   \
508         "add   r13, r13,  r8    \n\t"   \
509         "add   r13, r13,  r9    \n\t"   \
510         "bslli r10, r10,  16    \n\t"   \
511         "bslli r11, r11,  16    \n\t"   \
512         "add   r12, r12, r10    \n\t"   \
513         "addc  r13, r13,  r0    \n\t"   \
514         "add   r12, r12, r11    \n\t"   \
515         "addc  r13, r13,  r0    \n\t"   \
516         "lwi   r10,  r4,   0    \n\t"   \
517         "add   r12, r12, r10    \n\t"   \
518         "addc  r13, r13,  r0    \n\t"   \
519         "add   r12, r12,  r5    \n\t"   \
520         "addc   r5, r13,  r0    \n\t"   \
521         "swi   r12,  r4,   0    \n\t"   \
522         "addi   r4,  r4,   4    \n\t"
523 
524 #define MULADDC_STOP                    \
525         "swi   r5,   %0         \n\t"   \
526         "swi   r4,   %1         \n\t"   \
527         "swi   r3,   %2         \n\t"   \
528         : "=m" (c), "=m" (d), "=m" (s)              \
529         : "m" (s), "m" (d), "m" (c), "m" (b)        \
530         : "r3", "r4"  "r5", "r6", "r7", "r8",       \
531           "r9", "r10", "r11", "r12", "r13"          \
532     );
533 
534 #endif /* MicroBlaze */
535 
536 #if defined(__tricore__)
537 
538 #define MULADDC_INIT                            \
539     asm(                                        \
540         "ld.a   %%a2, %3                \n\t"   \
541         "ld.a   %%a3, %4                \n\t"   \
542         "ld.w   %%d4, %5                \n\t"   \
543         "ld.w   %%d1, %6                \n\t"   \
544         "xor    %%d5, %%d5              \n\t"
545 
546 #define MULADDC_CORE                            \
547         "ld.w   %%d0,   [%%a2+]         \n\t"   \
548         "madd.u %%e2, %%e4, %%d0, %%d1  \n\t"   \
549         "ld.w   %%d0,   [%%a3]          \n\t"   \
550         "addx   %%d2,    %%d2,  %%d0    \n\t"   \
551         "addc   %%d3,    %%d3,    0     \n\t"   \
552         "mov    %%d4,    %%d3           \n\t"   \
553         "st.w  [%%a3+],  %%d2           \n\t"
554 
555 #define MULADDC_STOP                            \
556         "st.w   %0, %%d4                \n\t"   \
557         "st.a   %1, %%a3                \n\t"   \
558         "st.a   %2, %%a2                \n\t"   \
559         : "=m" (c), "=m" (d), "=m" (s)          \
560         : "m" (s), "m" (d), "m" (c), "m" (b)    \
561         : "d0", "d1", "e2", "d4", "a2", "a3"    \
562     );
563 
564 #endif /* TriCore */
565 
566 #if defined(__arm__)
567 
568 #if defined(__thumb__) && !defined(__thumb2__)
569 
570 #define MULADDC_INIT                                    \
571     asm(                                                \
572             "ldr    r0, %3                      \n\t"   \
573             "ldr    r1, %4                      \n\t"   \
574             "ldr    r2, %5                      \n\t"   \
575             "ldr    r3, %6                      \n\t"   \
576             "lsr    r7, r3, #16                 \n\t"   \
577             "mov    r9, r7                      \n\t"   \
578             "lsl    r7, r3, #16                 \n\t"   \
579             "lsr    r7, r7, #16                 \n\t"   \
580             "mov    r8, r7                      \n\t"
581 
582 #define MULADDC_CORE                                    \
583             "ldmia  r0!, {r6}                   \n\t"   \
584             "lsr    r7, r6, #16                 \n\t"   \
585             "lsl    r6, r6, #16                 \n\t"   \
586             "lsr    r6, r6, #16                 \n\t"   \
587             "mov    r4, r8                      \n\t"   \
588             "mul    r4, r6                      \n\t"   \
589             "mov    r3, r9                      \n\t"   \
590             "mul    r6, r3                      \n\t"   \
591             "mov    r5, r9                      \n\t"   \
592             "mul    r5, r7                      \n\t"   \
593             "mov    r3, r8                      \n\t"   \
594             "mul    r7, r3                      \n\t"   \
595             "lsr    r3, r6, #16                 \n\t"   \
596             "add    r5, r5, r3                  \n\t"   \
597             "lsr    r3, r7, #16                 \n\t"   \
598             "add    r5, r5, r3                  \n\t"   \
599             "add    r4, r4, r2                  \n\t"   \
600             "mov    r2, #0                      \n\t"   \
601             "adc    r5, r2                      \n\t"   \
602             "lsl    r3, r6, #16                 \n\t"   \
603             "add    r4, r4, r3                  \n\t"   \
604             "adc    r5, r2                      \n\t"   \
605             "lsl    r3, r7, #16                 \n\t"   \
606             "add    r4, r4, r3                  \n\t"   \
607             "adc    r5, r2                      \n\t"   \
608             "ldr    r3, [r1]                    \n\t"   \
609             "add    r4, r4, r3                  \n\t"   \
610             "adc    r2, r5                      \n\t"   \
611             "stmia  r1!, {r4}                   \n\t"
612 
613 #define MULADDC_STOP                                    \
614             "str    r2, %0                      \n\t"   \
615             "str    r1, %1                      \n\t"   \
616             "str    r0, %2                      \n\t"   \
617          : "=m" (c),  "=m" (d), "=m" (s)        \
618          : "m" (s), "m" (d), "m" (c), "m" (b)   \
619          : "r0", "r1", "r2", "r3", "r4", "r5",  \
620            "r6", "r7", "r8", "r9", "cc"         \
621          );
622 
623 #else
624 
625 #define MULADDC_INIT                                    \
626     asm(                                                \
627             "ldr    r0, %3                      \n\t"   \
628             "ldr    r1, %4                      \n\t"   \
629             "ldr    r2, %5                      \n\t"   \
630             "ldr    r3, %6                      \n\t"
631 
632 #define MULADDC_CORE                                    \
633             "ldr    r4, [r0], #4                \n\t"   \
634             "mov    r5, #0                      \n\t"   \
635             "ldr    r6, [r1]                    \n\t"   \
636             "umlal  r2, r5, r3, r4              \n\t"   \
637             "adds   r7, r6, r2                  \n\t"   \
638             "adc    r2, r5, #0                  \n\t"   \
639             "str    r7, [r1], #4                \n\t"
640 
641 #define MULADDC_STOP                                    \
642             "str    r2, %0                      \n\t"   \
643             "str    r1, %1                      \n\t"   \
644             "str    r0, %2                      \n\t"   \
645          : "=m" (c),  "=m" (d), "=m" (s)        \
646          : "m" (s), "m" (d), "m" (c), "m" (b)   \
647          : "r0", "r1", "r2", "r3", "r4", "r5",  \
648            "r6", "r7", "cc"                     \
649          );
650 
651 #endif /* Thumb */
652 
653 #endif /* ARMv3 */
654 
655 #if defined(__alpha__)
656 
657 #define MULADDC_INIT                    \
658     asm(                                \
659         "ldq    $1, %3          \n\t"   \
660         "ldq    $2, %4          \n\t"   \
661         "ldq    $3, %5          \n\t"   \
662         "ldq    $4, %6          \n\t"
663 
664 #define MULADDC_CORE                    \
665         "ldq    $6,  0($1)      \n\t"   \
666         "addq   $1,  8, $1      \n\t"   \
667         "mulq   $6, $4, $7      \n\t"   \
668         "umulh  $6, $4, $6      \n\t"   \
669         "addq   $7, $3, $7      \n\t"   \
670         "cmpult $7, $3, $3      \n\t"   \
671         "ldq    $5,  0($2)      \n\t"   \
672         "addq   $7, $5, $7      \n\t"   \
673         "cmpult $7, $5, $5      \n\t"   \
674         "stq    $7,  0($2)      \n\t"   \
675         "addq   $2,  8, $2      \n\t"   \
676         "addq   $6, $3, $3      \n\t"   \
677         "addq   $5, $3, $3      \n\t"
678 
679 #define MULADDC_STOP                                    \
680         "stq    $3, %0          \n\t"   \
681         "stq    $2, %1          \n\t"   \
682         "stq    $1, %2          \n\t"   \
683         : "=m" (c), "=m" (d), "=m" (s)              \
684         : "m" (s), "m" (d), "m" (c), "m" (b)        \
685         : "$1", "$2", "$3", "$4", "$5", "$6", "$7"  \
686     );
687 #endif /* Alpha */
688 
689 #if defined(__mips__) && !defined(__mips64)
690 
691 #define MULADDC_INIT                    \
692     asm(                                \
693         "lw     $10, %3         \n\t"   \
694         "lw     $11, %4         \n\t"   \
695         "lw     $12, %5         \n\t"   \
696         "lw     $13, %6         \n\t"
697 
698 #define MULADDC_CORE                    \
699         "lw     $14, 0($10)     \n\t"   \
700         "multu  $13, $14        \n\t"   \
701         "addi   $10, $10, 4     \n\t"   \
702         "mflo   $14             \n\t"   \
703         "mfhi   $9              \n\t"   \
704         "addu   $14, $12, $14   \n\t"   \
705         "lw     $15, 0($11)     \n\t"   \
706         "sltu   $12, $14, $12   \n\t"   \
707         "addu   $15, $14, $15   \n\t"   \
708         "sltu   $14, $15, $14   \n\t"   \
709         "addu   $12, $12, $9    \n\t"   \
710         "sw     $15, 0($11)     \n\t"   \
711         "addu   $12, $12, $14   \n\t"   \
712         "addi   $11, $11, 4     \n\t"
713 
714 #define MULADDC_STOP                    \
715         "sw     $12, %0         \n\t"   \
716         "sw     $11, %1         \n\t"   \
717         "sw     $10, %2         \n\t"   \
718         : "=m" (c), "=m" (d), "=m" (s)                      \
719         : "m" (s), "m" (d), "m" (c), "m" (b)                \
720         : "$9", "$10", "$11", "$12", "$13", "$14", "$15"    \
721     );
722 
723 #endif /* MIPS */
724 #endif /* GNUC */
725 
726 #if (defined(_MSC_VER) && defined(_M_IX86)) || defined(__WATCOMC__)
727 
728 #define MULADDC_INIT                            \
729     __asm   mov     esi, s                      \
730     __asm   mov     edi, d                      \
731     __asm   mov     ecx, c                      \
732     __asm   mov     ebx, b
733 
734 #define MULADDC_CORE                            \
735     __asm   lodsd                               \
736     __asm   mul     ebx                         \
737     __asm   add     eax, ecx                    \
738     __asm   adc     edx, 0                      \
739     __asm   add     eax, [edi]                  \
740     __asm   adc     edx, 0                      \
741     __asm   mov     ecx, edx                    \
742     __asm   stosd
743 
744 #if defined(MBEDTLS_HAVE_SSE2)
745 
746 #define EMIT __asm _emit
747 
748 #define MULADDC_HUIT                            \
749     EMIT 0x0F  EMIT 0x6E  EMIT 0xC9             \
750     EMIT 0x0F  EMIT 0x6E  EMIT 0xC3             \
751     EMIT 0x0F  EMIT 0x6E  EMIT 0x1F             \
752     EMIT 0x0F  EMIT 0xD4  EMIT 0xCB             \
753     EMIT 0x0F  EMIT 0x6E  EMIT 0x16             \
754     EMIT 0x0F  EMIT 0xF4  EMIT 0xD0             \
755     EMIT 0x0F  EMIT 0x6E  EMIT 0x66  EMIT 0x04  \
756     EMIT 0x0F  EMIT 0xF4  EMIT 0xE0             \
757     EMIT 0x0F  EMIT 0x6E  EMIT 0x76  EMIT 0x08  \
758     EMIT 0x0F  EMIT 0xF4  EMIT 0xF0             \
759     EMIT 0x0F  EMIT 0x6E  EMIT 0x7E  EMIT 0x0C  \
760     EMIT 0x0F  EMIT 0xF4  EMIT 0xF8             \
761     EMIT 0x0F  EMIT 0xD4  EMIT 0xCA             \
762     EMIT 0x0F  EMIT 0x6E  EMIT 0x5F  EMIT 0x04  \
763     EMIT 0x0F  EMIT 0xD4  EMIT 0xDC             \
764     EMIT 0x0F  EMIT 0x6E  EMIT 0x6F  EMIT 0x08  \
765     EMIT 0x0F  EMIT 0xD4  EMIT 0xEE             \
766     EMIT 0x0F  EMIT 0x6E  EMIT 0x67  EMIT 0x0C  \
767     EMIT 0x0F  EMIT 0xD4  EMIT 0xFC             \
768     EMIT 0x0F  EMIT 0x7E  EMIT 0x0F             \
769     EMIT 0x0F  EMIT 0x6E  EMIT 0x56  EMIT 0x10  \
770     EMIT 0x0F  EMIT 0xF4  EMIT 0xD0             \
771     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
772     EMIT 0x0F  EMIT 0x6E  EMIT 0x66  EMIT 0x14  \
773     EMIT 0x0F  EMIT 0xF4  EMIT 0xE0             \
774     EMIT 0x0F  EMIT 0xD4  EMIT 0xCB             \
775     EMIT 0x0F  EMIT 0x6E  EMIT 0x76  EMIT 0x18  \
776     EMIT 0x0F  EMIT 0xF4  EMIT 0xF0             \
777     EMIT 0x0F  EMIT 0x7E  EMIT 0x4F  EMIT 0x04  \
778     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
779     EMIT 0x0F  EMIT 0x6E  EMIT 0x5E  EMIT 0x1C  \
780     EMIT 0x0F  EMIT 0xF4  EMIT 0xD8             \
781     EMIT 0x0F  EMIT 0xD4  EMIT 0xCD             \
782     EMIT 0x0F  EMIT 0x6E  EMIT 0x6F  EMIT 0x10  \
783     EMIT 0x0F  EMIT 0xD4  EMIT 0xD5             \
784     EMIT 0x0F  EMIT 0x7E  EMIT 0x4F  EMIT 0x08  \
785     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
786     EMIT 0x0F  EMIT 0xD4  EMIT 0xCF             \
787     EMIT 0x0F  EMIT 0x6E  EMIT 0x6F  EMIT 0x14  \
788     EMIT 0x0F  EMIT 0xD4  EMIT 0xE5             \
789     EMIT 0x0F  EMIT 0x7E  EMIT 0x4F  EMIT 0x0C  \
790     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
791     EMIT 0x0F  EMIT 0xD4  EMIT 0xCA             \
792     EMIT 0x0F  EMIT 0x6E  EMIT 0x6F  EMIT 0x18  \
793     EMIT 0x0F  EMIT 0xD4  EMIT 0xF5             \
794     EMIT 0x0F  EMIT 0x7E  EMIT 0x4F  EMIT 0x10  \
795     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
796     EMIT 0x0F  EMIT 0xD4  EMIT 0xCC             \
797     EMIT 0x0F  EMIT 0x6E  EMIT 0x6F  EMIT 0x1C  \
798     EMIT 0x0F  EMIT 0xD4  EMIT 0xDD             \
799     EMIT 0x0F  EMIT 0x7E  EMIT 0x4F  EMIT 0x14  \
800     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
801     EMIT 0x0F  EMIT 0xD4  EMIT 0xCE             \
802     EMIT 0x0F  EMIT 0x7E  EMIT 0x4F  EMIT 0x18  \
803     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
804     EMIT 0x0F  EMIT 0xD4  EMIT 0xCB             \
805     EMIT 0x0F  EMIT 0x7E  EMIT 0x4F  EMIT 0x1C  \
806     EMIT 0x83  EMIT 0xC7  EMIT 0x20             \
807     EMIT 0x83  EMIT 0xC6  EMIT 0x20             \
808     EMIT 0x0F  EMIT 0x73  EMIT 0xD1  EMIT 0x20  \
809     EMIT 0x0F  EMIT 0x7E  EMIT 0xC9
810 
811 #define MULADDC_STOP                            \
812     EMIT 0x0F  EMIT 0x77                        \
813     __asm   mov     c, ecx                      \
814     __asm   mov     d, edi                      \
815     __asm   mov     s, esi                      \
816 
817 #else
818 
819 #define MULADDC_STOP                            \
820     __asm   mov     c, ecx                      \
821     __asm   mov     d, edi                      \
822     __asm   mov     s, esi                      \
823 
824 #endif /* SSE2 */
825 #endif /* MSVC */
826 
827 #endif /* MBEDTLS_HAVE_ASM */
828 
829 #if !defined(MULADDC_CORE)
830 #if defined(MBEDTLS_HAVE_UDBL)
831 
832 #define MULADDC_INIT                    \
833 {                                       \
834     mbedtls_t_udbl r;                           \
835     mbedtls_mpi_uint r0, r1;
836 
837 #define MULADDC_CORE                    \
838     r   = *(s++) * (mbedtls_t_udbl) b;          \
839     r0  = (mbedtls_mpi_uint) r;                   \
840     r1  = (mbedtls_mpi_uint)( r >> biL );         \
841     r0 += c;  r1 += (r0 <  c);          \
842     r0 += *d; r1 += (r0 < *d);          \
843     c = r1; *(d++) = r0;
844 
845 #define MULADDC_STOP                    \
846 }
847 
848 #else
849 #define MULADDC_INIT                    \
850 {                                       \
851     mbedtls_mpi_uint s0, s1, b0, b1;              \
852     mbedtls_mpi_uint r0, r1, rx, ry;              \
853     b0 = ( b << biH ) >> biH;           \
854     b1 = ( b >> biH );
855 
856 #define MULADDC_CORE                    \
857     s0 = ( *s << biH ) >> biH;          \
858     s1 = ( *s >> biH ); s++;            \
859     rx = s0 * b1; r0 = s0 * b0;         \
860     ry = s1 * b0; r1 = s1 * b1;         \
861     r1 += ( rx >> biH );                \
862     r1 += ( ry >> biH );                \
863     rx <<= biH; ry <<= biH;             \
864     r0 += rx; r1 += (r0 < rx);          \
865     r0 += ry; r1 += (r0 < ry);          \
866     r0 +=  c; r1 += (r0 <  c);          \
867     r0 += *d; r1 += (r0 < *d);          \
868     c = r1; *(d++) = r0;
869 
870 #define MULADDC_STOP                    \
871 }
872 
873 #endif /* C (generic)  */
874 #endif /* C (longlong) */
875 
876 #endif /* bn_mul.h */
877