crypton 2.0.1 → 2.1.7
raw patch · 245 files changed
Files
- CHANGELOG.md +718/−1
- Crypto/Cipher/AES/GCM.hs +256/−0
- Crypto/Cipher/AES/Primitive.hs +379/−11
- Crypto/Cipher/ChaCha.hs +16/−3
- Crypto/Cipher/ChaCha/Poly1305.hs +335/−0
- Crypto/Cipher/ChaChaPoly1305.hs +30/−30
- Crypto/Cipher/RC4.hs +8/−1
- Crypto/Cipher/Salsa.hs +17/−4
- Crypto/Hash/Algorithms.hs +2/−0
- Crypto/Hash/Skein256.hs +39/−0
- Crypto/Hash/Skein512.hs +39/−0
- Crypto/Hash/Types.hs +20/−0
- Crypto/Internal/ByteArray.hs +47/−0
- Crypto/Internal/Poly1305.hs +37/−0
- Crypto/MAC/Poly1305.hs +13/−17
- Crypto/Number/Basic.hs +6/−1
- Crypto/Number/ModArithmetic.hs +55/−9
- Crypto/Number/Serialize/Internal.hs +6/−1
- Crypto/PubKey/Curve25519.hs +15/−10
- Crypto/PubKey/ECC/P256.hs +0/−2
- Crypto/PubKey/ECDSA.hs +82/−5
- Crypto/PubKey/RSA/OAEP.hs +3/−4
- Crypto/PubKey/RSA/PKCS15.hs +6/−8
- Crypto/PubKey/RSA/PSS.hs +28/−3
- Crypto/PubKey/RSA/Types.hs +26/−2
- LICENSE +1/−0
- README.md +198/−96
- benchs/Bench.hs +3/−1
- cbits/LICENSE.go +38/−0
- cbits/aes/LICENSE.fusion +29/−0
- cbits/aes/armv8.c +218/−147
- cbits/aes/armv8_impl.c +303/−31
- cbits/aes/block128.h +15/−1
- cbits/aes/gcm_fused_x86.c +1013/−0
- cbits/aes/gcm_fused_x86.h +55/−0
- cbits/aes/gcm_vaes512_x86.c +364/−0
- cbits/aes/gcm_vaes512_x86.h +37/−0
- cbits/aes/gcm_vaes_x86.c +325/−0
- cbits/aes/gcm_vaes_x86.h +35/−0
- cbits/aes/gcm_x86_asm.c +17/−7
- cbits/aes/x86ni.c +22/−7
- cbits/aes/x86ni_impl.c +60/−1
- cbits/crypton_aes.c +259/−8
- cbits/crypton_aes.h +70/−0
- cbits/crypton_align.h +75/−61
- cbits/crypton_armv8_target.h +40/−0
- cbits/crypton_bignum.h +260/−16
- cbits/crypton_bzero.h +27/−0
- cbits/crypton_chacha.c +9/−9
- cbits/crypton_chacha.h +2/−2
- cbits/crypton_chachapoly.c +156/−0
- cbits/crypton_chachapoly.h +62/−0
- cbits/crypton_cpu.c +47/−1
- cbits/crypton_cpu.h +16/−0
- cbits/crypton_ecc.c +25/−4
- cbits/crypton_ecc_s2n.c +204/−0
- cbits/crypton_ecc_s2n.h +27/−0
- cbits/crypton_ecc_s2n_curves.h +76/−0
- cbits/crypton_f2m.c +6/−2
- cbits/crypton_md4.c +11/−19
- cbits/crypton_md5.c +18/−19
- cbits/crypton_modinv.c +74/−0
- cbits/crypton_modinv.h +22/−0
- cbits/crypton_pbkdf2.c +21/−4
- cbits/crypton_powm.c +223/−23
- cbits/crypton_ripemd.c +11/−19
- cbits/crypton_salsa.c +5/−5
- cbits/crypton_salsa.h +3/−3
- cbits/crypton_scrypt.c +2/−2
- cbits/crypton_sha1.c +23/−18
- cbits/crypton_sha256.c +38/−24
- cbits/crypton_sha256.h +12/−0
- cbits/crypton_sha3.c +11/−18
- cbits/crypton_sha512.c +20/−18
- cbits/crypton_sha512.h +12/−0
- cbits/crypton_skein256.c +29/−27
- cbits/crypton_skein256.h +3/−3
- cbits/crypton_skein512.c +34/−35
- cbits/crypton_skein512.h +3/−3
- cbits/crypton_tiger.c +9/−16
- cbits/crypton_xsalsa.c +6/−6
- cbits/curve25519/x25519.c +88/−0
- cbits/curve25519/x25519.h +16/−0
- cbits/decaf/ed448goldilocks/decaf.c +4/−1
- cbits/decaf/include/word.h +1/−1
- cbits/ed25519/ed25519.c +27/−6
- cbits/ed25519/ed25519_s2n.c +65/−0
- cbits/ed25519/ed25519_s2n.h +14/−0
- cbits/include32/p256/p256.h +2/−16
- cbits/include32/p256/p256_gf.h +95/−85
- cbits/include64/p256/p256.h +2/−16
- cbits/include64/p256/p256_gf.h +94/−85
- cbits/include64/p256/p256_s2n.h +25/−0
- cbits/p256/gen_base_table.py +126/−0
- cbits/p256/p256.c +47/−3
- cbits/p256/p256_base_table.c +841/−0
- cbits/p256/p256_ec.c +714/−151
- cbits/p256/p256_s2n.c +61/−0
- cbits/p256/p256_verify.c +300/−0
- cbits/p256/p256_verify.h +19/−0
- cbits/p256/p256_wnaf_table.c +42/−0
- cbits/s2n/COMMIT +1/−0
- cbits/s2n/LICENSE +222/−0
- cbits/s2n/README.md +100/−0
- cbits/s2n/arm/bignum_deamont_p384.S +151/−0
- cbits/s2n/arm/bignum_demont_p256.S +99/−0
- cbits/s2n/arm/bignum_inv_p521.S +1701/−0
- cbits/s2n/arm/bignum_modinv.S +613/−0
- cbits/s2n/arm/bignum_montinv_p384.S +1493/−0
- cbits/s2n/arm/bignum_montmul_p384.S +891/−0
- cbits/s2n/arm/bignum_montmul_p384_alt.S +345/−0
- cbits/s2n/arm/bignum_montsqr_p384.S +671/−0
- cbits/s2n/arm/bignum_montsqr_p384_alt.S +273/−0
- cbits/s2n/arm/bignum_mul_p521.S +1407/−0
- cbits/s2n/arm/bignum_mul_p521_alt.S +538/−0
- cbits/s2n/arm/bignum_neg_p256.S +72/−0
- cbits/s2n/arm/bignum_sqr_p521.S +1125/−0
- cbits/s2n/arm/bignum_sqr_p521_alt.S +374/−0
- cbits/s2n/arm/bignum_tomont_p256.S +122/−0
- cbits/s2n/arm/bignum_tomont_p384.S +138/−0
- cbits/s2n/arm/curve25519_x25519.S +2596/−0
- cbits/s2n/arm/curve25519_x25519_alt.S +1702/−0
- cbits/s2n/arm/curve25519_x25519base.S +9591/−0
- cbits/s2n/arm/curve25519_x25519base_alt.S +9434/−0
- cbits/s2n/arm/edwards25519_encode.S +136/−0
- cbits/s2n/arm/edwards25519_scalarmulbase.S +9635/−0
- cbits/s2n/arm/edwards25519_scalarmulbase_alt.S +9477/−0
- cbits/s2n/arm/p256_montjadd.S +3165/−0
- cbits/s2n/arm/p256_montjadd_alt.S +555/−0
- cbits/s2n/arm/p256_montjdouble.S +1555/−0
- cbits/s2n/arm/p256_montjdouble_alt.S +587/−0
- cbits/s2n/arm/p256_montjmixadd.S +513/−0
- cbits/s2n/arm/p256_montjmixadd_alt.S +517/−0
- cbits/s2n/arm/p256_scalarmul.S +8620/−0
- cbits/s2n/arm/p256_scalarmul_alt.S +6235/−0
- cbits/s2n/arm/p256_scalarmulbase.S +3782/−0
- cbits/s2n/arm/p256_scalarmulbase_alt.S +3057/−0
- cbits/s2n/arm/p384_montjscalarmul.S +10004/−0
- cbits/s2n/arm/p384_montjscalarmul_alt.S +7155/−0
- cbits/s2n/arm/p521_jscalarmul.S +2747/−0
- cbits/s2n/arm/p521_jscalarmul_alt.S +2143/−0
- cbits/s2n/import.sh +112/−0
- cbits/s2n/include/_internal_s2n_bignum_arm.h +103/−0
- cbits/s2n/include/_internal_s2n_bignum_x86_att.h +68/−0
- cbits/s2n/x86_att/bignum_deamont_p384.S +184/−0
- cbits/s2n/x86_att/bignum_deamont_p384_alt.S +184/−0
- cbits/s2n/x86_att/bignum_demont_p256.S +116/−0
- cbits/s2n/x86_att/bignum_demont_p256_alt.S +134/−0
- cbits/s2n/x86_att/bignum_emontredc_8n.S +427/−0
- cbits/s2n/x86_att/bignum_inv_p521.S +2093/−0
- cbits/s2n/x86_att/bignum_kmul_16_32.S +513/−0
- cbits/s2n/x86_att/bignum_kmul_32_64.S +1161/−0
- cbits/s2n/x86_att/bignum_ksqr_16_32.S +545/−0
- cbits/s2n/x86_att/bignum_ksqr_32_64.S +809/−0
- cbits/s2n/x86_att/bignum_modinv.S +714/−0
- cbits/s2n/x86_att/bignum_montinv_p384.S +1834/−0
- cbits/s2n/x86_att/bignum_montmul_p384.S +291/−0
- cbits/s2n/x86_att/bignum_montmul_p384_alt.S +316/−0
- cbits/s2n/x86_att/bignum_montsqr_p384.S +294/−0
- cbits/s2n/x86_att/bignum_montsqr_p384_alt.S +339/−0
- cbits/s2n/x86_att/bignum_mul_p521.S +394/−0
- cbits/s2n/x86_att/bignum_mul_p521_alt.S +321/−0
- cbits/s2n/x86_att/bignum_neg_p256.S +97/−0
- cbits/s2n/x86_att/bignum_sqr_p521.S +302/−0
- cbits/s2n/x86_att/bignum_sqr_p521_alt.S +315/−0
- cbits/s2n/x86_att/bignum_tomont_p256.S +195/−0
- cbits/s2n/x86_att/bignum_tomont_p256_alt.S +203/−0
- cbits/s2n/x86_att/bignum_tomont_p384.S +295/−0
- cbits/s2n/x86_att/bignum_tomont_p384_alt.S +324/−0
- cbits/s2n/x86_att/curve25519_x25519.S +2189/−0
- cbits/s2n/x86_att/curve25519_x25519_alt.S +2350/−0
- cbits/s2n/x86_att/curve25519_x25519base.S +9890/−0
- cbits/s2n/x86_att/curve25519_x25519base_alt.S +9965/−0
- cbits/s2n/x86_att/edwards25519_encode.S +86/−0
- cbits/s2n/x86_att/edwards25519_scalarmulbase.S +9926/−0
- cbits/s2n/x86_att/edwards25519_scalarmulbase_alt.S +10002/−0
- cbits/s2n/x86_att/p256_montjadd.S +593/−0
- cbits/s2n/x86_att/p256_montjadd_alt.S +579/−0
- cbits/s2n/x86_att/p256_montjdouble.S +634/−0
- cbits/s2n/x86_att/p256_montjdouble_alt.S +747/−0
- cbits/s2n/x86_att/p256_montjmixadd.S +567/−0
- cbits/s2n/x86_att/p256_montjmixadd_alt.S +552/−0
- cbits/s2n/x86_att/p256_scalarmul.S +6823/−0
- cbits/s2n/x86_att/p256_scalarmul_alt.S +8672/−0
- cbits/s2n/x86_att/p256_scalarmulbase.S +3571/−0
- cbits/s2n/x86_att/p256_scalarmulbase_alt.S +4212/−0
- cbits/s2n/x86_att/p384_montjscalarmul.S +7418/−0
- cbits/s2n/x86_att/p384_montjscalarmul_alt.S +9440/−0
- cbits/s2n/x86_att/p521_jscalarmul.S +2505/−0
- cbits/s2n/x86_att/p521_jscalarmul_alt.S +2850/−0
- cbits/sha1_armv8.c +8/−12
- cbits/sha1_x86.c +1/−1
- cbits/sha256_armv8.c +7/−11
- cbits/sha3_armv8.c +2/−6
- cbits/sha512_armv8.c +4/−8
- cbits/tests/ct/README +84/−0
- cbits/tests/ct/ct.h +53/−0
- cbits/tests/ct/ct_aes.c +35/−0
- cbits/tests/ct/ct_aes_armv8.c +12/−0
- cbits/tests/ct/ct_canary.c +21/−0
- cbits/tests/ct/ct_chapoly.c +33/−0
- cbits/tests/ct/ct_decaf.c +36/−0
- cbits/tests/ct/ct_ed25519.c +23/−0
- cbits/tests/ct/ct_p256.c +42/−0
- cbits/tests/ct/ct_powm.c +29/−0
- cbits/tests/ct/ct_x25519.c +25/−0
- cbits/tests/ct/known.txt +54/−0
- cbits/tests/ct/run.sh +167/−0
- cbits/tests/endian/README +27/−0
- cbits/tests/endian/endian.c +192/−0
- cbits/tests/endian/run.sh +50/−0
- cbits/tests/endian/vectors.txt +252/−0
- cbits/tests/fuzz/README +35/−0
- cbits/tests/fuzz/corpus/aead-authentic.bin binary
- cbits/tests/fuzz/corpus/ed25519-tampered.bin binary
- cbits/tests/fuzz/corpus/ed25519-valid.bin binary
- cbits/tests/fuzz/corpus/p256-on-curve.bin binary
- cbits/tests/fuzz/fuzz.h +34/−0
- cbits/tests/fuzz/fuzz_aead.c +60/−0
- cbits/tests/fuzz/fuzz_canary.c +41/−0
- cbits/tests/fuzz/fuzz_decaf.c +40/−0
- cbits/tests/fuzz/fuzz_ed25519.c +22/−0
- cbits/tests/fuzz/fuzz_p256.c +33/−0
- cbits/tests/fuzz/run.sh +132/−0
- cbits/tests/fuzz/standalone.c +66/−0
- cbits/tests/perf/floors.txt +22/−0
- cbits/tests/perf/run.sh +102/−0
- cbits/tests/perf/throughput.c +156/−0
- cbits/tests/scrub/README +53/−0
- cbits/tests/scrub/known.txt +16/−0
- cbits/tests/scrub/run.sh +30/−0
- cbits/tests/scrub/scrub.c +271/−0
- cbits/tests/width/ed448_width.c +87/−0
- cbits/tests/width/p256_width.c +144/−0
- cbits/tests/width/run.sh +103/−0
- cbits/tests/width/x25519_width.c +74/−0
- crypton.cabal +237/−44
- tests/BlockCipher/AESSpec.hs +168/−3
- tests/ECDSASpec.hs +34/−0
- tests/HashSpec.hs +52/−14
- tests/KDF/PBKDF2Spec.hs +11/−0
- tests/NumberSpec.hs +32/−0
- tests/PubKey/P256Spec.hs +46/−0
- tests/PubKey/PSSSpec.hs +56/−0
- tests/StreamCipher/ChaChaPoly1305Spec.hs +109/−6
CHANGELOG.md view
@@ -1,7 +1,661 @@ # CHANGELOG for crypton -## 2.0.1+## 2.1.7 +One fix: RSA-PSS verification was accepting a signature RFC 8017 says to+refuse. It is a conformance fault rather than a forgery -- producing such a+signature takes the private key, since it is the signer who chooses the+encoding, and a third party holding a valid signature cannot turn it into+one of these.++* fix(pss): RSA-PSS verification refuses an encoding with a bit set outside+ `emBits`, as RFC 8017 9.1.2 step 6 requires. Step 9 clears those bits in+ DB and crypton did that; clearing is not checking, so an encoding the+ standard calls inconsistent verified as though it were sound -- the bit+ that made it wrong was thrown away before anything looked at it. Only the+ signer can produce such a signature, since it takes the private key to+ sign a chosen encoding, so this is conformance rather than forgery. Found+ with tlsfuzzer, in the `xor 0x80 at 0` case of+ `test-tls13-certificate-verify.py`, while testing hs-tls++## 2.1.6++Two things a caller could walk into, the licence field saying what the tree+actually holds, and the C building without a warning.++* fix(pbkdf2): an output length of zero no longer takes the process down.+ `tryFastPBKDF2_*` passed it through to C, where `assert(out && nout)`+ aborted -- crypton's C is built without `NDEBUG`, so its assertions are+ live in a release. `Crypto.KDF.PBKDF2.tryGenerate` has always answered+ with an empty result for the same request, and the fast paths now agree+* fix(p256): `Crypto.PubKey.ECC.P256.scalarInv` returns on a zero scalar+ rather than looping for ever. `scalarFromBinary` accepts any 256 bits, so+ a zero scalar is easy to come by, and the binary extended Euclid behind+ `scalarInv` has no exit for it: zero stays even and is halved for ever.+ A hang inside a foreign call is not interruptible, so `System.Timeout` was+ no help either. It now answers zero, which is what the function already+ answered for the other input with no inverse, and what `scalarInvSafe`+ answers for both. crypton's own ECDSA was never exposed: it rejects a+ zero scalar before inverting, and uses `scalarInvSafe`+* doc(cabal): the `license:` field says what the tree holds --+ `BSD-3-Clause AND MIT AND ISC` -- and `license-files:` lists the five+ licence texts, where a tool looking for licences will find them. The+ parts of `cbits/aes/gcm_fused_x86.c` that follow picotls's `fusion` now+ carry its MIT notice beside the file. **Nothing is required of a user+ that was not required before**: crypton's own code is BSD-3-Clause as it+ always was, and the MIT and ISC code was already in the tree -- the field+ was silent about it. Raised by Joey Hess in #232, and settled with the+ help of Kazuho Oku, who divided `fusion` between what derives from+ OpenSSL and what does not, and rewrote the former upstream+* fix(c): the sanitizer build is quiet again. `crypton_sha256_finalize` and+ `crypton_sha512_finalize` say that their pointers are never null, which+ they never were. gcc's `-Wstringop-overflow` had been reporting them as+ writing "into a region of size 0" at "address zero" under+ `-fsanitize=undefined`: UndefinedBehaviorSanitizer inserts a null check+ before `memcpy`, because glibc declares `memcpy` nonnull, and the check+ puts a null path in front of the warning pass. Stating the contract+ removes the path rather than the warning, and costs nothing -- compiled as+ the package compiles it, the assembly is identical either way+* fix(pbkdf2): an instantiation whose digest is larger than its block is+ refused where it is written rather than after it has overflowed. The+ macro that builds the three PBKDF2 variants shortens a long key by hashing+ it into a buffer the size of the block, and asserted afterwards that the+ result fitted -- afterwards being too late, since the write has already+ happened. The check is a compile-time one now. The three that exist are+ unaffected: SHA-1, SHA-256 and SHA-512 have digests of 20, 32 and 64 bytes+ against blocks of 64, 64 and 128++## 2.1.5++crypton 2.1.3 and 2.1.4 cannot be built with GCC 14 or newer; it was+reported from a Fedora 43 system, which ships GCC 15. This release is that+fix, and two things that came with it.++* fix(x86): the C builds with GCC 14 and newer again.+ `crypton_sha1_x86_do_chunk` was declared taking `const uint32_t buf[16]`+ while every caller passes a `const uint8_t *`, and GCC 14 made+ `-Wincompatible-pointer-types` an error by default where GCC 13 only warns.+ The declaration now says `const uint8_t buf[64]`, which is the block size+ SHA-1 actually takes and what the two sibling functions already said.+ Reported as #282 and fixed in #284, both by @tbidne, who bisected it to+ the commit that introduced the declaration. CI now builds the C with+ gcc-14 as well, so the next one of these is caught before release+* perf(armv8): AES-GCM is about a quarter faster on AArch64, which puts it+ ahead of OpenSSL 4.0.3 rather than behind it -- 1.15 at AES-128 and 1.06+ at AES-256 on an Apple M4, from 0.86. The GHASH no longer keeps H the way+ GCM writes it; it is twisted once at key setup so that GCM's bit+ reflection is already undone, which turns a reduction of some twenty-five+ shifts and XORs into two PMULL and six EOR, and makes Karatsuba worth+ taking -- three multiplications a block rather than four. Against the+ previous code over 16 KiB messages: 1.34 at AES-128 and 1.23 at AES-256 on+ an M4, and 1.25 across the three key sizes on a Neoverse N2. The scheme+ is ARM's, from the BSD-3-Clause part of+ https://github.com/ARM-software/AArch64cryptolib+* test(armv8): the constant-time harness runs on AArch64, where it never had.+ It was pinned to one x86-64 job, so the AArch64 AES and GHASH had never+ been put to it; they are now, and they let no secret decide a branch or an+ address. Running it somewhere new also found a fault in the harness+ itself: it counted the frame `--track-origins` prints to say where a value+ came from as a place that branched on a secret, which invented a finding+ rather than hiding one++## 2.1.4++2.1.3 could not be built from Hackage at all in the default configuration,+and is deprecated there. This release is that fix and three more.++* fix(cabal): the source distribution carries `cbits/p256/p256_verify.h`.+ No field named it, so it was absent from the 2.1.3 tarball, and+ `cbits/p256/p256_ec.c` includes it whenever `support_s2n_bignum` is on --+ which is every x86-64 and aarch64 machine that leaves the flag alone. The+ package built perfectly from a git checkout and not at all from Hackage.+ Reported as #270 by Laurent P. Rene de Cotret on the day 2.1.3 went out,+ fixed by gev in #271+* fix(armv8): the C builds with gcc before 13 again. A function that uses an+ AArch64 extension says so with `__attribute__((target(...)))`, and the+ spelling used -- `target("+sha3")` -- is one clang has always taken and gcc+ learned in 13. Before that the extension never reaches the function and an+ `always_inline` intrinsic that needs it cannot be inlined, which stops the+ build rather than slowing it. Naming the architecture beside the extension+ is understood by both compilers at every version, so gcc is given that+ spelling. Reported as #273 by gev, against 2.1.1, 2.1.2 and 2.1.3+* fix(sha256): SHA-256 on AArch64 is no longer five times slower than it was+ in 2.1.2 -- 644 MB/s against 3396 over 16 KiB on an Apple M4. The+ CRYPTOGAMS assembly picks its path from `crypton_armcap_P` rather than from+ a flag in the C, and the bit was set only while that flag was still+ unresolved; 2.1.3 added a constructor that resolves it before anything+ runs, so the bit was never set and the assembly took its generic path on+ every processor. SHA-1 was unaffected, its constructor setting the+ corresponding bit itself, and the SHA-512 assembly is x86 only. No test+ could have caught this: the answers were right all along, only slow+* test(ci): three jobs for the three ways the above went unnoticed. One+ builds the source distribution and then builds the library from it+ somewhere other than the checkout, since nothing had ever built a tarball+ and listing one is not building it. One installs gcc-12 and builds the C+ with it, the runner's own gcc being 13, which is why a report covering+ three releases never reproduced here. Both are verified against the bug+ they exist for: each was red before its fix and green after++# CHANGELOG for crypton++## 2.1.3++* fix(number): the arithmetic crypton falls back to when it is built without+ GMP no longer walks off the end of a buffer. `fillPtr` writes a number out+ starting at its last byte and stops at offset zero, so a number of no bytes+ -- which is what zero is -- started it at minus one, and it never stopped.+ The same build also had `exponentiation` fail to terminate on a negative+ exponent, stepping between -1 and -2 until the stack ran out, where+ `expFast` and `expSafe` both reach it; `numBits` fail to terminate on a+ negative number; `numBits 0` answer one where GMP answers zero, so that+ `numBytes 0` claimed a byte that is not there; and a modulus of one answer+ one rather than zero in two places. Every corner is now held to what the+ GMP build answers on the same input, and `-integer-gmp` has a CI job so+ that it stays that way+* fix(cabal): `-fsupport_sse` no longer selects the SSE BLAKE2 and Argon2+ sources on architectures that have no SSE, where they cannot compile, and+ `-fold_toolchain_inliner` links again -- one of the sixteen inline+ definitions in `cbits/decaf/include/word.h` had lost its `static`, which+ `-fgnu89-inline` turns into a duplicate symbol. Both flags now have a CI+ job+* fix(p256): `crypton_p256_shl` and `crypton_p256_shr` no longer shift a+ digit by its own width, which the standard leaves undefined and which x86+ and ARM answer differently. Nothing in the library calls either, which is+ why the sanitizers had not reported them: they can only report what runs+* fix(headers): `crypton_skein256.h` and `crypton_skein512.h` declared six+ functions under a misspelling of the package's own name, so the six the C+ defines had no prototype at all. `crypton_chacha.h` and `crypton_salsa.h`+ each typedef'd a union to the bare name `block`, so no translation unit+ could include both; they are `crypton_chacha_block` and+ `crypton_salsa_block` now+* security(c): seven places that erase key material and then let the memory+ die -- five that `memset` a buffer and `free` it on the next line, two that+ clear a recoded scalar in a local going out of scope -- now write through a+ volatile pointer, which a compiler may not remove. clang at -O2 was+ keeping all seven, but that is its choice rather than a guarantee. RSA-2048+ signing is unchanged at 1479.3 microseconds against 1480.0 on an Apple M4+* perf(ed448): the scalar arithmetic on Apple Silicon runs on 64-bit limbs+ rather than 32-bit ones. decaf sized its field limbs from the architecture+ and its scalar limbs from a macro it worked out from the compiler, and the+ two disagreed wherever `uint_fast32_t` is four bytes, so the same aarch64+ CPU took 64-bit field limbs and 32-bit scalar limbs on macOS and 64-bit for+ both on Linux. Ed448 signing is 5.5% quicker for it, 20.69 to 19.56+ microseconds on an M4+* perf(p256): the one addition in each scalar multiplication that can be a+ point added to itself goes through a complete formula rather than being+ detected and worked around. Kyle Butt pointed out that the comb's table is+ affine, so the same three numbers are the point in projective coordinates+ and in Jacobian ones, which is what lets a comb built on Jacobian+ arithmetic step into the formula for one addition. It costs about a third+ of a percent, and buys an argument a reader had to follow becoming a+ comparison a machine can run+* doc(hash): the Haddock for `Context` says that it is not erased when it+ is finished with, what survives in it, and why scrubbing every one is not+ done -- it costs about 70% of a 32-byte hash, where the allocation is most+ of the work+* test(c): the C is now checked in CI for things the test suite cannot ask+ about: whether it is the same on a 32-bit machine and on a big-endian one,+ whether a private key ever decides a branch or an address, what a secret+ leaves behind in memory, and whether anything breaks on generated input.+ Each of the last four carries a probe that is deliberately wrong and has to+ be reported, because a check that has quietly stopped working otherwise+ reads as a clean bill of health -- which, four times over the course of+ this work, is exactly what it did++* doc(cabal): every dependency has an upper bound, which `cabal check` had+ been asking for, and `bytestring` is no longer listed twice in the same+ `build-depends`++* fix(c): the table that says which AES implementation to call is filled in+ once, before there is a second thread, rather than on every+ `crypton_aes_initkey`. Two threads taking a key at the same time were+ writing the whole table at the same time, which ThreadSanitizer reports+ forty-four times over for eight threads doing nothing else. The same for+ the flags that say whether to use the ARMv8 SHA-1, SHA-256 and SHA-512+ instructions. Nothing has ever come of it -- the values written are the+ same ones every time and the table starts out holding valid generic+ implementations -- but it is a race the standard gives no meaning to.+ Taking an AES key is 6.7% quicker for not doing the work again: 72.1 to+ 67.3 nanoseconds on an Apple M4+* fix(c): the C no longer reads a word off a caller's pointer by casting it,+ which the standard leaves undefined at an address the word type is not+ aligned for and which UndefinedBehaviorSanitizer reported on seventy-eight+ lines. `crypton_align.h`'s accessors go through `memcpy`, the ten hash+ implementations read their block a word at a time rather than pointing at+ it as though it were an array of words, and `block128` is packed so that a+ caller's pointer may be one. The non-aligned trampolines those hashes kept+ for the case are gone with it. Measured on an Apple M4, every hash and+ AES-GCM is where it was, within a tenth of a per cent. The sanitizers now+ run in CI with nothing turned off+* fix(c): two left shifts the C standard leaves undefined, found by building+ the C with UndefinedBehaviorSanitizer and running the test suite. One+ shifted a carry into the sign bit of a signed 64-bit digit in+ `cbits/p256/p256.c`, the other shifted a negative value in+ `cbits/decaf/ed448goldilocks/decaf.c`. Neither miscomputes on any compiler+ crypton is built with, and the values are unchanged; what they were was a+ licence the standard gives the compiler and no reason to give it+* security(cipher): a message of 2^32 bytes or more no longer has its length+ truncated on the way to the C, which takes its lengths as `uint32_t`. It+ used to be: `Crypto.Cipher.ChaCha.combine` given 2^32 + 64 bytes enciphered+ 64 of them and returned the rest as it found the buffer -- 4 GiB of zeros+ where the ciphertext should have been, with nothing returned to say so.+ `Crypto.Hash` has cut its work into 2 GiB pieces for this reason since+ before crypton; nothing else did.++ Where the C carries its state in a context and can simply be called again,+ the work is now cut up the same way and a long message is enciphered:+ `Crypto.Cipher.ChaCha`, `Crypto.Cipher.Salsa`, `Crypto.Cipher.XSalsa`,+ `Crypto.Cipher.RC4`, `Crypto.MAC.Poly1305`, and AES-GCM's incremental+ interface -- which is what `Crypto.Cipher.ChaChaPoly1305` and+ `Crypto.MAC.KMAC` reach it through.++ Where it cannot -- the one-call AEADs, which do the whole message in one+ call, and the AES modes, which are handed the IV and do not hand it back --+ the message is refused: `CryptoError_ParameterInvalid` from+ `Crypto.Cipher.AES.GCM` and `Crypto.Cipher.ChaCha.Poly1305`, and an error+ from AES ECB, CBC, CTR, XTS, OCB and CCM. ECB, CBC and XTS count blocks+ rather than bytes, so their limit is sixteen times further out.+ `Crypto.Cipher.AESGCMSIV` already refused, and still does+* perf(p256): the comb that multiplies the base point takes five bits of the+ scalar at a time from each of two blocks rather than four, over the signed+ all-bits-set representation, so the table stays the same size while the+ loop goes from 32 steps to 26: 25 doublings and 52 mixed additions against+ 31 and 64, which is 19% fewer field operations. An ECDSA P-256 signature+ goes 25.52 to 22.47 microseconds on an Apple M4. This is the C path, which+ x86-64 and AArch64 do not take -- they have the vendored assembly -- so it+ is for i386, armv7, riscv64, ppc64le, s390x and the rest. The arrangement+ was suggested by Kyle Butt.++ One scalar below the order makes the last addition of the comb add a point+ to itself, which the formulas there cannot do; it was found by searching+ the sign patterns rather than by sampling, and the recoder now reports it+ and the answer is the doubling. Every other addition is ruled out, the 48+ from step two upwards by parity and size and the two of step one by+ exhausting the 2^20 sign patterns that could reach them+* security(aes): `Crypto.Cipher.AES.GCM` refuses a nonce of no bytes, which+ its four functions used to accept. SP 800-38D 5.2.1.1 asks for at least+ one byte, and with none GCM's pre-counter block is zero, so the tag of a+ message is `GHASH_H(A, C) XOR E(K, 0^128)` -- and `E(K, 0^128)` is the+ GHASH key `H` itself. One full tag therefore gives `H` away; `H` belongs+ to the key rather than to the nonce, so an attacker who has it, and one+ genuine message under any nonce, can forge a tag that verifies for data of+ their own under that nonce, twelve-byte ones included. `encrypt` and+ `decryptWithTag` now throw `CryptoError_IvSizeInvalid`, `decrypt` gives+ `Nothing` and `encryptWithMask` gives `False` and writes nothing. Only the+ empty nonce is refused; every other length stays allowed. The general+ interface has refused it since 2.1.0 and this module did not. Affects+ 2.1.0, 2.1.1 and 2.1.2. Reported by arybczak in+ [#249](https://github.com/kazu-yamamoto/crypton/issues/249)+* perf(rsa): the multiply-accumulate at the bottom of the modular+ exponentiation takes four limbs to an iteration on AArch64, with the flags+ carrying through two long chains -- one for the low halves of the four+ products, one for the high halves a place up -- where the compiler writes+ a chain per limb and spends two instructions moving each carry between the+ flags and a register. Measured on an Apple M4, an RSA-2048 signature goes+ 593.0 to 515.9 microseconds through the Haskell API and the exponentiation+ itself 590.1 to 514.9. The ragged end of a row -- three limbs, two or+ one -- is written out the same way rather than handed back to C, which+ matters because mont_sqr asks for every length from n-1 down to 1: that is+ a further two per cent of the exponentiation, 514.2 to 504.9. The+ arrangement follows addMulVVWx in Go's crypto/internal/fips140/bigmod,+ which is BSD-3-Clause as this library is; cbits/LICENSE.go carries its+ notice. Three other arrangements were tried and measured worse, and the+ comment above the function says which and why, so that they are not tried+ again+* perf(rsa): a Montgomery multiplication no longer clears its 2n-limb+ scratch first. The first row of the product lands on empty space, so it+ is written rather than added to, and every row after it reads only limbs+ an earlier row has already put there. Worth between a half and one per+ cent of an RSA-2048 signature on an Apple M4, which is less than it+ sounds like it should be: the clearing was cheap, and what it cost was+ mostly the row that had to add to zeros+* perf(rsa): the R^2 that Montgomery arithmetic needs before it can start is+ built by squaring rather than by doubling a bit at a time. Write a value+ as 2^(lgR + d) mod m; a Montgomery squaring divides by R, so it takes that+ to 2^(lgR + 2d) and doubles d. The climb from R to R^2 is then the binary+ expansion of lgR -- ten squarings for a 1024-bit modulus, where there were+ a thousand and twenty-five doublings. On an Apple M4 the setup goes 24.74+ to 2.07 microseconds, and an RSA-2048 signature does it twice, once for+ each CRT half: the signature goes 512.3 to 466.9 through the Haskell API+ and the two exponentiations 502.6 to 457.0. Curves that go through+ crypton_ecc.c pay the same setup once per context and gain the same.+ Public-key operations still go through GMP and do not change+* perf(ecdsa): P-256 verification multiplies both scalars at once, in+ variable time, where it used to do two constant-time multiplications and+ add the results. Everything a verification touches is public -- the+ message, the signature and the public key -- so the constant-time work+ there was paid for nothing, and the two multiplications can share their+ doublings besides. Both scalars go into non-adjacent form, width 7 for+ the base point, whose odd multiples are a table in the library, and width+ 5 for the public key, whose eight are built per call; one pass down the+ digits does a doubling at every step and an addition where a digit is not+ zero. Measured through the Haskell API on an Apple M4, a verification+ goes 30.37 to 25.48 microseconds, and the multiplication itself 29.94 to+ 25.34; on an x86-64, 85.04 to 71.53. Signing is untouched. s2n-bignum's+ point addition is correct except when its two arguments are the same+ point, which is the side condition its proof carries, so a sum that comes+ out as the point at infinity from arguments that were not is given up on+ and the constant-time pair answers instead -- 1203 cases covering that,+ including 41 that take the fallback, agree with the old answers on both+ architectures+* perf(gcm): AES-GCM uses the 512-bit form of the AES and carry-less+ multiply instructions where the processor has them and they are worth+ having, which is Ice Lake and Zen 5 onwards. Four blocks to an+ instruction where the 256-bit form takes two; a group is thirty-two+ blocks in eight registers and its GHASH is two passes of sixteen, since+ sixteen is how many powers of H the table holds. Measured on GitHub's+ runners over 16 KiB, AES-128-GCM and AES-256-GCM in MB/s: an EPYC 9V45+ goes 9616 to 14268 and 8422 to 12674, a Xeon 6973P-C 8095 to 9848 and+ 7187 to 8323, a Xeon 8573C 6983 to 8447 and 6166 to 7113. Zen 4 is left+ on the 256-bit path -- there the 512-bit instructions are two passes+ through a 256-bit datapath, and AES-GCM measured slightly slower -- and+ the run-time check asks for three more bits of XCR0 as well as the+ instruction bits, since a machine can report these and still fault on+ them+* perf(ed25519): the base point multiplication goes through s2n-bignum,+ which signing does twice -- once for the nonce's point and once for the+ public key, which `sign` derives from the secret key every time rather+ than trusting the one it is handed. Measured through the Haskell API on+ an Apple M4, signing goes 11.92 to 7.27 microseconds and `toPublic` 5.97+ to 3.52; at the C level on an x86-64 without ADX, where the `_alt` form+ runs, a public key goes 13.25 to 9.93 and a signature with the key in+ hand 14.74 to 11.34. Verification is untouched: it multiplies two+ scalars at once and crypton's variable-time code is ahead of the+ constant-time assembly there. ed25519-donna's table stays for every+ other architecture, and 5000 key and signature pairs agree between the+ two paths on both architectures+* perf(rsa): the masked scan of the exponentiation's table goes four limbs+ at a time on x86-64 with AVX2. Every entry of the table is read and a+ mask keeps the one the window asks for, which is what keeps the address+ stream off the exponent, and at RSA-2048's CRT size that is two kilobytes+ read per window with 256 windows to an exponentiation -- 11% of the whole+ where s2n-bignum's multiplication runs, measured by taking the scan out+ altogether. With the vector form almost all of it comes back: one+ RSA-2048 CRT private operation goes 812.4 to 720.8 microseconds against a+ 707.1 floor with no scan at all, and on the same machine without ADX+ 1646.1 to 1599.3. AArch64 keeps the scalar form, where the same+ measurement puts the scan at 1% and there is nothing to win. The+ processor is asked once per call, and without the AVX2 bit, or built+ without `use_target_attributes`, the scalar scan is what runs+* perf(rsa): the modular exponentiation squares into the other of its two+ buffers and swaps them, rather than squaring into one and copying it back.+ That is a copy of the modulus' width saved 1280 times per exponentiation,+ and which of the three buffers a pointer names is nobody's secret, so+ nothing about the timing changes. Measured by thread CPU time, best of+ many, on one RSA-2048 CRT private operation: an Apple M4 goes 604.3 to+ 595.9 microseconds and an x86-64 without ADX 1678.0 to 1665.6. Where+ s2n-bignum's multiplication runs the difference is below the noise, that+ multiplication being most of the time there. Also writes down what a+ five-bit window is worth, which was measured and is not taken: 3.5% on the+ M4, 1% the wrong way on an older x86-64, and 7% the wrong way wherever the+ assembly runs, because a table twice as long is a masked scan twice as long++## 2.1.2++* perf(gcm): AES-GCM uses the 256-bit form of the AES and carry-less+ multiply instructions where the processor has them, which is Zen 3 and Ice+ Lake onwards. Measured on an EPYC 7763 over 16 KiB, in the library as+ cabal builds it, AES-128-GCM goes 4245 to 6042 MB/s and AES-256-GCM 3932+ to 5463 -- 1.42 and 1.39 times, and ahead of OpenSSL 3.0.13 on that+ machine, which reaches 4266 and 3946. `crypton_cpu.c` asks the processor+ first and everything else is unchanged+* perf(x25519): X25519 goes through s2n-bignum, and key generation reads a+ table rather than multiplying the base point 9 the general way, which is+ what crypton did for want of anything else. Measured through the Haskell+ API on an Apple M4, the shared secret goes 19.87 to 13.78 microseconds and+ a key generation 19.92 to 3.83 -- on x86-64 the C level is 41.19 to 26.96+ and 41.18 to 8.54. The RFC 7748 vectors say the answers are the same+* perf(ecdsa): inverting modulo the group order, which ECDSA does once per+ signature and once per verification, takes a fixed number of division+ steps instead of a whole exponentiation. Measured on an Apple M4:+ P-256 6.02 to 0.80 microseconds, P-384 31.3 to 1.20, P-521 63.2 to 2.05.+ Through the Haskell API that is ECDSA P-256 signing 11.77 to 7.10, which+ is faster than OpenSSL on that machine, verification 36.75 to 32.10, and+ P-384 signing 171.6 to 151.3. `inverseSafe` carries it, so DSA, ElGamal,+ RSA's `qinv` and `Crypto.PubKey.ECC.Prim` get it too; it checks its answer+ by multiplying out, as it always has, and falls back where that fails+* perf(rsa): the modular exponentiation's Montgomery multiplication and+ square go through s2n-bignum on x86-64 with ADX, which is twice as fast as+ the C there because the C cannot form the two carry chains `ADCX` and+ `ADOX` give: measured on an EPYC 7763 at 1024 bits, 0.4832 to 0.2479+ microseconds for a multiplication and 0.3984 to 0.1994 for a square. The+ window, the table and its masked scan are untouched, and so is every other+ size and architecture -- on AArch64 the C measures faster than the+ assembly, so nothing is even vendored for it+* perf(p256): ECDSA signing is 2.4 times faster and verification 2.2, which+ finishes what the two entries below began. Signing and key generation go+ through s2n-bignum's fixed-base routine, which reads a table of multiples+ of the base point that `cbits/p256/gen_base_table.py` builds and that the+ test suite checks against crypton's own answer; verification goes through+ that one and the variable-point one, with the addition of the two left+ where it was. Measured through the Haskell API on an Apple M4, signing+ goes 28.55 to 12.03 microseconds and verification 82.68 to 37.73, which+ leaves both within a tenth of OpenSSL on that machine where they were at+ four tenths of it. The table costs 52 KiB of constant data, against the+ 2.4 KiB of the one it replaces+* perf(ecc): P-384 and P-521 go through s2n-bignum as well, where the curve+ is exactly one of those two. Measured through the Haskell API on an Apple+ M4, ECDH P-384 goes 549.5 to 75.4 microseconds and ECDSA P-384+ verification 772.4 to 295.8; at the C level P-384 is 7x and P-521 between+ 9 and 10x, on both architectures. Signing does not move: there is no+ fixed-base routine upstream for these two, so it keeps crypton's comb.+ Every other curve `crypton_ecc_mul` is asked about, including these two+ named with a different a or b, goes on to the C as before+* perf(p256): ECDH is 2.7 times faster on x86-64 and AArch64. The+ variable-point scalar multiplication now goes through AWS's+ [s2n-bignum](https://github.com/awslabs/s2n-bignum), vendored in+ `cbits/s2n`: hand-written assembly, constant-time, and carrying a+ machine-checked proof in HOL-Light that it computes what it says. Measured+ through the Haskell API on an Apple M4, ECDH P-256 goes 57.50 to 21.32+ microseconds; at the C level it is 2.6x there, 3.2x on an x86-64 with ADX+ and 2.6x on the `_alt` path taken where `CPUID` does not report it. Its licence is `Apache-2.0 OR ISC OR MIT-0`,+ which is what makes this possible at all -- OpenSSL's and BoringSSL's+ `ecp_nistz256` is Apache-2.0 only. Every other architecture keeps the C,+ as does Windows for now, and `-f-support_s2n_bignum` turns it off+* perf(p256): the field inversion takes the least squarings an exponent of+ 256 bits can be done in. It built the low 94 ones of p-2 in a second+ accumulator and multiplied the two at the end, which cost 287 squarings+ where 255 will do; the exponent is now built left to right from the shape+ of p-2 in one pass. Measured on an Apple M4 the inversion goes 4.224 ->+ 3.765 microseconds, about 11%, which is 0.9% of an ECDH since that is where+ the inversion sits. The same 13 multiplications either way++## 2.1.1++* docs(rsa): the haddock says what the optional blinder covers -- that the+ private exponent is not what is at risk, `expSafe` keeping its value out of+ the work, and that what a blinder covers is the input, which without one is+ the ciphertext as it arrived and so a number an attacker may have chosen.+ The eight places taking a `Maybe Blinder` point at t'Blinder' rather than+ repeating half of it; the four in `Crypto.PubKey.RSA.PSS` said nothing at+ all before++* feat(chachapoly): `Crypto.Cipher.ChaCha.Poly1305`, which does a whole+ ChaCha20-Poly1305 message in one call, the shape `Crypto.Cipher.AES.GCM`+ has. `Crypto.Cipher.ChaChaPoly1305` takes a message in steps, which is+ right when it arrives in pieces and is eight foreign calls and the+ allocations between them when it was already whole. Measured on an Apple+ M4 through the Haskell interface, a 100-byte message goes 0.97 -> 0.415+ microseconds and a 1400-byte one 2.89 -> 2.36. The nonce is the twelve+ bytes RFC 8439 defines; eight is the other ChaCha construction and is+ refused rather than quietly encrypted under a scheme nobody asked for++* feat(gcm): `Crypto.Cipher.AES.GCM.decryptWithTag`, which decrypts and hands+ back the tag it computed rather than comparing it. For a protocol that+ carries the tag apart from the ciphertext, where `decrypt` -- which wants+ the two together -- does not fit. It returns an `AuthTag`, whose `Eq` is a+ constant-time comparison, so the safe way to use it is also the obvious one++* feat(ecdsa): `Crypto.PubKey.ECDSA` gains the deterministic nonce of RFC+ 6979, which `Crypto.PubKey.ECC.ECDSA` already had. The fast module was the+ one without it, so moving to it for the speed meant giving up the one+ protection against the mistake that hands over an ECDSA private key. Three+ new names: `deterministicNonce`, and `signDeterministic` and+ `signDigestDeterministic` over it. Held to the implementation in+ `Crypto.PubKey.ECC.ECDSA`, which is itself held to the vectors in the RFC,+ on P-256, P-384 and P-521 with SHA-1 through SHA-512++## 2.1.0++* perf(p256): a signed five-bit window for the variable-point scalar+ multiplication, which is what ECDH and ECDSA signing spend their time in.+ The scalar is recoded into 52 digits, every one of them odd, so the table+ holds only the odd multiples P, 3P, ..., 31P and a negative digit costs a+ negation of y, which is free. The main loop goes from 252 doublings and 64+ additions to 255 and 51, and -- because no digit is zero and no partial sum+ is the infinity -- it drops the masks that stood in for infinity on every+ iteration. The table is built so that each pair of neighbouring odd+ multiples comes out of one doubling and one addition that shares everything+ but a squaring and a multiplication between X+P and X-P. Counted exactly,+ the field multiplications and squarings go 3477 -> 3326. Measured on an+ idle Intel Haswell, thirty runs each, ECDH is 158.5 -> 153.3 microseconds,+ about 4%; on an Apple M4 under desktop load the difference did not come out+ of the noise. One scalar, 30, would have reached the last addition with+ the accumulator equal to the point being added, which these formulas cannot+ do; the recoder detects that from the scalar and the last iteration doubles+ instead. Suggested by Kyle Butt++* perf(gcm): GHASH takes the ciphertext from the output buffer. A group's+ multiplies are issued between the rounds of the group after it, and the+ blocks were copied into six registers' worth of scratch to wait there --+ six stores a group for bytes that had just been written to the output+ anyway. The multiplies read the output instead, which is what picotls's+ fusion does. On an Intel Haswell this is worth two to three points against+ fusion between 400 and 1440 bytes, and it removes the queue from the+ AES-128 path++* perf(gcm): decryption takes the fused path too, on both x86-64 and+ AArch64. It had been left on the generic framing, so a received packet+ cost what a sent one did before any of this: measured at 100 bytes, three+ times what encrypting the same packet cost on either. It is the simpler of+ the two -- what GHASH absorbs is the ciphertext, and the ciphertext is the+ input, so the multiplies need not wait on the AES and nothing is carried+ between groups. On an Intel Haswell, 100 bytes goes 0.165 -> 0.050+ microseconds and 1440 bytes 0.362 -> 0.290; on an Apple M4, 0.230 -> 0.077+ and 0.396 -> 0.321. Decrypting is now about what encrypting is rather than+ three times it. The tag is still compared a byte at a time over its whole+ length whichever way the answer goes++* perf(gcm): let the one-call interface specialise. `gcmFullEncrypt`,+ `gcmFullDecrypt` and `gcmFullEncryptMask` take three `ByteArrayAccess`+ arguments and were marked `NOINLINE`, which is this module's habit and is+ right for a wrapper that is called once; these are called once a packet.+ With no specialisation every `withByteArray` and every `length` went through+ a dictionary, and on an Apple M4 that measured **0.15 of the 0.265+ microseconds** a 100-byte packet cost through the Haskell interface -- more+ than the encryption it wrapped. Marked `INLINABLE` so the caller can+ specialise them, 100 bytes falls to 0.128, where the same work measured in C+ is 0.114: the Haskell layer costs 0.014 rather than 0.15++* perf(gcm): build the length block and the initial counter in registers.+ The length block -- the two bit counts GHASH ends on -- was assembled by+ sixteen byte stores to the stack and read back, which measured about 9 of+ the 58 nanoseconds a 100-byte packet cost. Reversed the way every block is+ on its way to GHASH, that block is just the two counts as little endian+ words with the message's in the low half, so one `_mm_set_epi64x` makes it+ and no shuffle is needed. The initial counter likewise: the nonce is read+ where it lies and masked, rather than in three pieces of four bytes. On an+ Intel Haswell a 100-byte packet goes from 0.058 to 0.049 microseconds. With+ this every length measured is at 90 per cent of fusion's speed or better --+ 100 bytes 90 and 95 with the header protection mask, 200 bytes 96, 1440+ bytes 94, 16 KiB 95 -- where the series began at 31 per cent for 100 bytes++* perf(gcm): read a short block without going through the stack. Zeroing+ sixteen bytes, copying the block in and loading them back is three trips to+ memory with a store the load must wait for, and at packet lengths that was a+ tenth of the call. The sixteen bytes are read where they lie and what is+ above the length masked off, which is safe everywhere except at the end of a+ page -- and a block near the end of a page whose own bytes stop short of it+ is read aligned, which cannot leave the page, and shuffled down. This is+ how picotls's fusion does it. On an Intel Haswell a 100-byte packet goes+ from 0.0625 to 0.058 microseconds, 79 per cent of fusion's speed against 73,+ and with the header protection mask 83+* perf(gcm): the tail of a message gets what the groups already had. The+ six-wide pass that finishes a message was still running its rounds from a+ loop over a count held in the key, so the compiler could not place the+ waiting multiplies between them, and the blocks it produced went through an+ array indexed by a loop variable, which it cannot see through -- each block+ then reloaded its own keystream from memory. Written out for the ten rounds+ of AES-128, with the multiplies at slots named at compile time, and the+ blocks taken from the registers the pass left them in. The pass itself+ falls from about 29 to 6 nanoseconds; on an Intel Haswell 112 bytes is 13+ per cent faster and 400 bytes goes from 81 to 86 per cent of fusion's speed++* perf(gcm): give E(K,Y0) a lane that would otherwise sit idle, and stop+ copying the last short block through the stack. Six blocks are in flight+ whatever the message length, so a message leaving a tail of four blocks or+ fewer has lanes to spare; the block that masks the tag rides in one of them+ instead of taking ten rounds nothing overlaps, which at 100 bytes measured+ 9.3 of 78.9 nanoseconds. And the last short block was stored to the stack+ and copied back, when the tag that follows it is about to overwrite the+ bytes above it anyway -- where there are sixteen to spare, one store does.+ On an Intel Haswell, 100 bytes goes from 60 to 69 per cent of fusion's speed+ and 200 bytes from 68 to 82++* perf(gcm): build the counter block without leaving the vector registers,+ and keep each power of H beside its Karatsuba term. Both came from reading+ what picotls's `fusion` does differently. The counter was being stepped in+ a general register, byte swapped there and inserted into a vector one, which+ is a move across register files for every lane and six to a group; held+ byte reversed in a vector register instead, `_mm_add_epi32` steps the low+ thirty-two bits and wraps them where GCM wants, and a shuffle puts the bytes+ back. The powers were in two arrays 256 bytes apart, so a multiply touched+ two cache lines for operands it always wants together; they are now+ adjacent. On an Intel Haswell a 1200-byte message goes from 0.311 to 0.281+ microseconds and 1440 bytes from 79 to 90 per cent of fusion's speed. The+ multiplies are also now genuinely issued between the AES rounds, which the+ comment claimed and the generated code did not do: a test before each one+ ended the basic block the scheduler works inside, and the first group is+ peeled so that there is nothing to test++* perf(gcm): the same for AArch64, where what costs is the framing rather+ than a missing fast path. `armv8_impl.c` already encrypts eight blocks at a+ time and folds their GHASH into one reduction; what sat outside it was the+ additional data, the tag and the counter, each reached through the branch+ table so that the running state went back to memory between them and a+ one-block header paid a reduction of its own. Measured on an Apple M4, that+ framing was 0.07 of the 0.112 microseconds a 100-byte packet cost -- more+ than the encryption of the packet itself. Taking the whole message in one+ call, with the tag and the counter in registers from end to end and the+ additional data and the length block riding in the same batches as the+ ciphertext: a 100-byte packet 3.0x, 200 bytes 2.6x, 400 bytes 1.6x, 1200+ bytes 1.30x, 1440 bytes 1.23x, and level from about 6 KB up. With the QUIC+ header protection mask, 100 bytes is 3.3x. Unlike x86-64 there is no length+ above which something else is faster, because there is no vendored assembly+ on this side to hand a long message to, so every length goes this way. Held+ against the interface it replaces on two key sizes, seven lengths of+ additional data, fifteen message lengths up to 16 KB, three tag lengths and+ every sample offset that fits++* perf(gcm): a fused AES-GCM for x86-64, for messages short enough that the+ stitched assembly will not take them. That assembly refuses anything under+ 288 bytes, so until now a QUIC packet paid for the AES key schedule and the+ GHASH one block at a time, through a branch table that put the 128-bit state+ back in memory at every step: a 100-byte packet cost 0.153 us of which the+ encryption was a small part. This is the design Kazuho Oku sets out for+ picotls's `fusion` -- keep AES-NI issuing every clock, six blocks in flight,+ and fit the additional data, the tag and the QUIC header protection mask+ into the gaps between the rounds -- written in C with intrinsics, for the+ reason he gives: what is complicated here is the scheduling, and it has to+ stay readable to stay correct. On an Intel Haswell a 100-byte packet goes+ from 0.153 to 0.082 us and a 1200-byte one from 0.373 to 0.317, and the+ header protection mask becomes **free** wherever it can be taken: 400 bytes+ is 0.131 with it and 0.131 without, against 0.181 and 0.177, because it+ rides in a lane of the AES pipeline that the message length leaves idle+ rather than taking a block of its own. It can be taken there only when the+ sample lies in output already written and the two key schedules are the same+ length, which is what TLS and QUIC do; otherwise it is computed after the+ tag, where everything it may cover exists. Above+ 1536 bytes the assembly is faster -- by 12 per cent at 3 KB and 20 at 16 KB+ -- so longer messages still go there and nothing about TLS-sized records+ changes. The powers of H are built once per key, sixteen of them, which+ adds 512 bytes to what a key holds and no parameter to any interface: a+ power per block of the message would fold the whole GHASH into one reduction+ but would make that state grow with the longest message a caller might send.+ Held against the incremental interface on every combination of three key+ sizes, seven lengths of additional data, twelve message lengths and three+ tag lengths+ * fix(cpu): stop reading Intel's SDBG bit as AMD's XOP, which crashed SHA-512 and ChaCha20 on Broadwell and later. The vendored assembly dispatches on a capability word this library fills, and reads bit 11 of its second dword as@@ -18,6 +672,69 @@ beside it are cleared as well. Reported by @lucasdicioccio, who disassembled the trap [#202](https://github.com/kazu-yamamoto/crypton/issues/202)++* feat(aes): `encryptWithMask`, for the QUIC header protection mask. QUIC+ takes the sample for its header protection from the ciphertext, so the mask+ cannot be had before the encryption -- but it can be had before coming back.+ `newHeaderKey` builds the second key schedule once, where `quic` builds it+ per packet, and `encryptWithMask` seals the message and writes the sixteen+ bytes of mask, both into buffers the caller already has, so that nothing is+ allocated for either. On an Apple M4 the mask then costs about 0.02 us+ against 0.09 to 0.11 asked for separately: a 1440-byte packet goes from+ 0.473 to 0.382 us and a 100-byte one from 0.343 to 0.260. Most of that is+ the allocations rather than the crossing -- a version returning the two as+ bytearrays was measured at 0.419 and 0.299, so it recovered less than a+ third of it -- and the AES block itself is under two nanoseconds++* feat(aes): `Crypto.Cipher.AES.GCM`, for many short messages under one key.+ The interface in `Crypto.Cipher.Types` builds a state from the key *and* the+ nonce and then walks it through appending the additional data, encrypting+ and finalizing, copying the 320-byte state at each step. For a stream that+ is nothing next to the encryption; for a datagram it is most of the work.+ Measured on an Apple M4, a 1440-byte packet with a 20-byte header took+ 1.30 us, of which 0.17 us was the encryption: the AES key schedule and the+ table of multiples of `H` were rebuilt for every nonce although both depend+ on the key alone, and three state copies and four foreign calls carried the+ rest. A `Context` now holds what the key determines and is built once, and+ `encrypt` takes a nonce and a whole message and answers in one call, giving+ the ciphertext with the tag after it -- the shape a packet wants. `decrypt`+ takes that shape back and compares the tag itself, in C, looking at every+ byte either way. 1440 bytes: 1.30 to 0.37 us, 3.5x; 100 bytes 0.83 to 0.23;+ a 16 KiB TLS record 2.86 to 2.20, where the saving is the setup rather than+ the call. A message of 4 KiB or less goes through an unsafe foreign call,+ which is worth 0.075 us and is only right because such a call is over+ quickly; anything longer keeps the safe one. This computes what the general+ interface computes, which the tests hold it to on the same vectors+* Breaking change: fix(chachapoly1305): take a checked key, so that+ initializing cannot fail. The nonce was already a checked type, built by+ `nonce8`, `nonce12` or `nonce24`, so the key length was the only way+ `initialize` and `initializeX` could fail -- and callers answered that with+ `throwCryptoError`, `tls` among them, where+ `noFail (ChaChaPoly1305.nonce12 nonce >>= ChaChaPoly1305.initialize key)`+ re-checked a length once per record for a key fixed for the connection.+ There is now a `Key` with `key` to build one, and+ `initialize :: Key -> Nonce -> State` and+ `initializeX :: Key -> XNonce -> State` are total.+ `aeadChacha20poly1305Init` is unchanged and still reports a bad key length.+ This also closes the last of #28: `initFromRootState` wrapped a+ `throwCryptoError` around a `B.take 32`, and the Poly1305 key type now has a+ home in a hidden module so the modules here that know the length can say so+ [#193](https://github.com/kazu-yamamoto/crypton/issues/193)++* feat(hash): Skein with the digest size as a type parameter. Skein is+ defined for any digest size and the C here has always taken one -- the+ length goes to `crypton_skein512_init` and `crypton_skein512_finalize`, and+ the output is produced in counter mode for as many blocks as are asked for+ -- but Haskell could only reach the four sizes that had a type of their own.+ `Skein256 (bitlen :: Nat)` and `Skein512 (bitlen :: Nat)` take any, in the+ manner `SHAKE128` and `SHAKE256` already did; `Skein512 512` is+ `Skein512_512`, which the tests hold it to, and the named types are+ untouched. This also brought back the `Skein256-160` and `Skein512-160`+ known-answer vectors, which had been commented out of the test suite for+ want of a type to run them against. One large digest is a good deal cheaper+ than the same bytes from repeated small ones: 512 KiB at 947 MB/s in one+ digest against 172 MB/s as 8192 separate `Skein512_512` ones, on an M4+ [#56](https://github.com/kazu-yamamoto/crypton/issues/56) ## 2.0.0
+ Crypto/Cipher/AES/GCM.hs view
@@ -0,0 +1,256 @@+-- |+-- Module : Crypto.Cipher.AES.GCM+-- License : BSD-style+-- Maintainer : Kazu Yamamoto <kazu@iij.ad.jp>+-- Stability : experimental+-- Portability : unknown+--+-- AES-GCM for callers that send many short messages under one key, which is+-- what a datagram transport does.+--+-- The interface in "Crypto.Cipher.Types" builds a state from the key /and/+-- the nonce and then walks it through appending the additional data,+-- encrypting and finalizing, copying the state at each step. For a stream+-- that is nothing next to the encryption. For a QUIC packet it is most of+-- the work: the key schedule and the table of multiples of @H@ depend on the+-- key alone, and rebuilding them for every nonce costs more than encrypting+-- 1440 bytes.+--+-- So here a t'Context' is built from the key once and holds both, and+-- 'encrypt' takes a nonce and a whole message and answers in one call.+--+-- > ctx <- throwCryptoError <$> pure (newContext key)+-- > let packet = encrypt ctx nonce header plaintext 16+--+-- This runs on AES-NI and carry-less multiply, or on the ARMv8 cryptographic+-- extension, and makes no branch and no memory access that depends on the key+-- or on the data. Where the processor has neither, AES falls back to a table+-- driven implementation that is /not/ constant time; see the side channels+-- section of the README, and 'Crypto.System.CPU.processorOptions' for which is+-- in use.+--+-- The result is the ciphertext with the tag after it, which is the shape a+-- packet wants. 'decrypt' takes that shape back, compares the tag itself and+-- answers 'Nothing' when it does not match.+--+-- This computes the same thing as the general interface; the tests hold it to+-- that on the same vectors.+module Crypto.Cipher.AES.GCM (+ Context,+ newContext,+ encrypt,+ decrypt,+ decryptWithTag,++ -- * Header protection+ HeaderKey,+ newHeaderKey,+ encryptWithMask,+) where++import Crypto.Cipher.AES.Primitive (+ AES,+ AESGCMKey,+ gcmFullDecrypt,+ gcmFullDecryptTag,+ gcmFullEncrypt,+ gcmFullEncryptMask,+ gcmKeyInit,+ initAES,+ )+import Crypto.Cipher.Types (AuthTag)+import Crypto.Cipher.Types.AEAD (minimumTagLength)+import Crypto.Error+import Crypto.Internal.ByteArray (ByteArray, ByteArrayAccess)+import qualified Crypto.Internal.ByteArray as B+import Data.Word (Word8)+import Foreign.Ptr (Ptr)++-- | Everything a key determines: the AES key schedule and the table of+-- multiples of @H@. Build it once and encrypt as many messages under it as+-- the key is good for.+data Context = Context !AES !AESGCMKey++-- | Take a key of 16, 24 or 32 bytes. Any other length is reported as+-- 'CryptoError_KeySizeInvalid'.+newContext :: ByteArrayAccess key => key -> CryptoFailable Context+newContext k = do+ aes <- initAES k+ return $ Context aes (gcmKeyInit aes)++-- | Encrypt one message: the nonce, the additional data that is+-- authenticated but not encrypted, the plaintext, and how many bytes of tag+-- to produce, which GCM allows between 4 and 16. Any other length throws+-- 'CryptoError_AuthenticationTagSizeInvalid', and so does 'decryptWithTag'.+--+-- The answer is the ciphertext followed by the tag.+--+-- A nonce must not be used twice with the same t'Context'. Twelve bytes is+-- the size GCM is defined for and the only one that does not cost a further+-- pass. A nonce of no bytes is refused: it would hand out the key GCM+-- authenticates with, so 'encrypt' and 'decryptWithTag' throw+-- 'CryptoError_IvSizeInvalid' for it, 'decrypt' gives 'Nothing' and+-- 'encryptWithMask' gives 'False'.+{-# INLINABLE encrypt #-}+encrypt+ :: ( ByteArrayAccess nonce+ , ByteArrayAccess aad+ , ByteArrayAccess ba+ , ByteArray output+ )+ => Context+ -> nonce+ -> aad+ -> ba+ -> Int+ -> output+encrypt (Context aes gk) nonce aad input taglen+ | tooLongForC aad input =+ throwCryptoError (CryptoFailed CryptoError_ParameterInvalid)+ | badNonce nonce =+ throwCryptoError (CryptoFailed CryptoError_IvSizeInvalid)+ | badTagLength taglen =+ throwCryptoError (CryptoFailed CryptoError_AuthenticationTagSizeInvalid)+ | otherwise = gcmFullEncrypt aes gk nonce aad input taglen++-- | Decrypt one message, in the shape 'encrypt' produced: the ciphertext with+-- its tag after it. The tag is compared here, every byte of it whatever the+-- answer, and a message whose tag does not match gives 'Nothing' rather than+-- the plaintext.+--+-- 'Nothing' also comes back when the nonce has no bytes, the input is+-- shorter than the tag, or the tag length is outside 4 to 16.+{-# INLINABLE decrypt #-}+decrypt+ :: (ByteArrayAccess nonce, ByteArrayAccess aad, ByteArray ba)+ => Context+ -> nonce+ -> aad+ -> ba+ -> Int+ -> Maybe ba+decrypt (Context aes gk) nonce aad input taglen+ | tooLongForC aad input = Nothing+ | badNonce nonce || badTagLength taglen || B.length input < taglen = Nothing+ | otherwise = gcmFullDecrypt aes gk nonce aad body tag+ where+ (body, tag) = B.splitAt (B.length input - taglen) input++-- | Decrypt one message, the tag kept apart, and hand back the tag this end+-- computed.+--+-- For a caller whose protocol hands it the tag separately from the+-- ciphertext, so that 'decrypt' -- which wants the two together and compares+-- them itself -- does not fit. Compare the two tags with '=='; the 'Eq'+-- instance of t'AuthTag' is a constant-time comparison, and taking them apart+-- to compare the bytes is how this goes wrong.+--+-- Nothing here says whether the message is authentic. Until the comparison+-- is made and has come out equal, what this returns is not plaintext, it is+-- what the ciphertext turns into, and a caller must not act on it.+{-# INLINABLE decryptWithTag #-}+decryptWithTag+ :: (ByteArrayAccess nonce, ByteArrayAccess aad, ByteArray ba)+ => Context+ -> nonce+ -> aad+ -> ba+ -> Int+ -> (ba, AuthTag)+decryptWithTag (Context aes gk) nonce aad input taglen+ | tooLongForC aad input =+ throwCryptoError (CryptoFailed CryptoError_ParameterInvalid)+ | badNonce nonce =+ throwCryptoError (CryptoFailed CryptoError_IvSizeInvalid)+ | badTagLength taglen =+ throwCryptoError (CryptoFailed CryptoError_AuthenticationTagSizeInvalid)+ | otherwise = gcmFullDecryptTag aes gk nonce aad input taglen++----------------------------------------------------------------++-- | The key schedule for header protection, which QUIC keeps separately from+-- the one it encrypts with. Built once, like a t'Context'.+newtype HeaderKey = HeaderKey AES++-- | Take a header protection key of 16, 24 or 32 bytes.+newHeaderKey :: ByteArrayAccess key => key -> CryptoFailable HeaderKey+newHeaderKey k = HeaderKey <$> initAES k++-- | Encrypt one message and, from a sample of the ciphertext it just+-- produced, make the header protection mask -- in one call, into two buffers+-- the caller already has.+--+-- QUIC takes its sample from the ciphertext, so the mask cannot be had before+-- the encryption. It can be had before coming back, and with the buffers+-- already there nothing is allocated for either. On an Apple M4 the mask+-- then costs about 0.02 us, where asking for it separately costs 0.11.+--+-- The sealed message wants @length input + taglen@ bytes and the mask+-- sixteen. @sampleOffset@ says where the sixteen bytes of sample begin in+-- the sealed message, counting the tag as part of it.+--+-- 'False' comes back, and nothing is written, when the nonce has no bytes,+-- the sample would not fit, or the tag length is outside 4 to 16.+{-# INLINABLE encryptWithMask #-}+encryptWithMask+ :: (ByteArrayAccess nonce, ByteArrayAccess aad, ByteArrayAccess ba)+ => Context+ -> HeaderKey+ -> nonce+ -> aad+ -> ba+ -> Int+ -- ^ tag length+ -> Int+ -- ^ sample offset+ -> Ptr Word8+ -- ^ where the sealed message goes+ -> Ptr Word8+ -- ^ where the sixteen bytes of mask go+ -> IO Bool+encryptWithMask (Context aes gk) (HeaderKey hp) nonce aad input taglen off outp maskp+ | tooLongForC aad input = return False+ | badNonce nonce = return False+ | off < 0 || badTagLength taglen || off + 16 > B.length input + taglen =+ return False+ | otherwise = do+ gcmFullEncryptMask aes gk hp nonce aad input taglen off outp maskp+ return True++-- | The C behind all four takes its lengths as @uint32_t@, so a message or+-- its additional data from 2^32 bytes up cannot be handed to it: the length+-- would be truncated and most of the buffer left untouched, with nothing to+-- say so. There is no splitting the work here -- the C does the whole+-- message in one call, tag and all -- so such a message is refused.+tooLongForC+ :: (ByteArrayAccess aad, ByteArrayAccess ba) => aad -> ba -> Bool+tooLongForC aad input =+ B.overCLength (B.length aad) || B.overCLength (B.length input)++-- | SP 800-38D 5.2.1.1 asks for at least one byte of IV, and this is why.+--+-- GCM builds its pre-counter block from a nonce that is not twelve bytes as+-- @J0 = GHASH_H(IV || 0^s || [0]_64 || [len(IV)]_64)@. For an empty IV that+-- input is one block of zeros, so @J0@ is zero, and the tag of a message+-- becomes @GHASH_H(A, C) XOR E(K, 0^128)@ -- where @E(K, 0^128)@ is the+-- definition of @H@. The tag of an empty message under an empty nonce is+-- therefore @H@ itself, and any other full tag gives @H@ as the root of a+-- known polynomial.+--+-- @H@ belongs to the key, not to the nonce. An attacker holding it, plus one+-- genuine message under any nonce, has @E(K, J0)@ for that nonce and can make+-- a tag that verifies for data of their own -- under a correct twelve-byte+-- nonce, and for every nonce they have seen. One encryption with an empty+-- nonce and a full tag ends the authenticity of everything under the key.+--+-- 'Crypto.Cipher.AES.Primitive.gcmAeadInit' refuses the empty IV for this+-- reason, and these four have to as well. Only the empty one is refused:+-- SP 800-38D allows every length from one byte up.+badNonce :: ByteArrayAccess nonce => nonce -> Bool+badNonce nonce = B.length nonce == 0++-- | GCM makes a sixteen-byte tag and a shorter one is a prefix of it. Below+-- 'minimumTagLength' it authenticates next to nothing, and past sixteen the+-- C code would read beyond the tag it computed.+badTagLength :: Int -> Bool+badTagLength t = t < minimumTagLength || t > 16
Crypto/Cipher/AES/Primitive.hs view
@@ -40,6 +40,12 @@ -- * Incremental GCM gcmMode, gcmInit,+ AESGCMKey,+ gcmKeyInit,+ gcmFullEncrypt,+ gcmFullEncryptMask,+ gcmFullDecrypt,+ gcmFullDecryptTag, gcmAeadInit, -- * Incremental OCB@@ -158,6 +164,14 @@ sizeGCM :: Int sizeGCM = 320 +-- | The size of what a key determines, which is the 320 bytes above and the+-- powers of H the fused path reads: sixteen of them, and sixteen more for+-- the term the Karatsuba multiplication would otherwise work out every time.+-- The same on every platform, so that this is one number rather than one per+-- architecture; the powers are filled only where that path is compiled in.+sizeGCMKey :: Int+sizeGCMKey = 832+ sizeOCB :: Int sizeOCB = 160 @@ -257,6 +271,7 @@ -- ^ ciphertext output encryptCTR ctx iv input | len <= 0 = B.empty+ | B.overCLength len = error tooLongMessage | B.length iv /= 16 = error $ "AES error: IV length must be block size (16). Its length is: "@@ -351,6 +366,20 @@ c_aes_encrypt_c32 (castPtr o) k v i (fromIntegral len) len = B.length input +-- | What the AES modes say when a message cannot be given to the C, whose+-- lengths are @uint32_t@. Above that the length is truncated on the way+-- down and most of the buffer is left as it was found, with nothing to say+-- so, which is worse than refusing.+--+-- Unlike the stream ciphers, these cannot be done in pieces: the C is handed+-- the IV and does not hand it back, so a second call would start from the+-- wrong place. ECB, CBC and XTS count blocks rather than bytes, so their+-- limit is sixteen times further out than CTR's.+tooLongMessage :: String+tooLongMessage =+ "AES error: message too long for this implementation, whose C takes its "+ ++ "lengths as uint32_t"+ {-# INLINE doECB #-} doECB :: ByteArray ba@@ -359,6 +388,7 @@ -> ba -> ba doECB f ctx input+ | B.overCLength nbBlocks = error tooLongMessage | len == 0 = B.empty | r /= 0 = error $@@ -382,6 +412,7 @@ -> ba -> ba doCBC f ctx (IV iv) input+ | B.overCLength nbBlocks = error tooLongMessage | len == 0 = B.empty | r /= 0 = error $@@ -405,6 +436,7 @@ -> ba -> ba doXTS f (key1, key2) iv spoint input+ | B.overCLength nbBlocks = error tooLongMessage | len == 0 = B.empty | r /= 0 = error $@@ -429,6 +461,190 @@ c_aes_gcm_init (castPtr gcmStPtr) k v (fromIntegral $ B.length iv) return $ AESGCM sm +-- | How long a message may be and still be handed to an unsafe foreign call.+-- Four kibibytes is about half a microsecond of work, and it takes in a+-- datagram of any size a network will carry.+shortMessage :: Int+shortMessage = 4096++-- | The part of a GCM state the key alone determines: H, which is the key+-- applied to a block of zeroes, and the table of its multiples. That is 256+-- of the 320 bytes of a GCM state, and it is the same for every message sent+-- under one key, so a caller that keeps a key can build this once rather than+-- once for every message.+newtype AESGCMKey = AESGCMKey ScrubbedBytes++-- | Build the key part of a GCM state.+{-# NOINLINE gcmKeyInit #-}+gcmKeyInit :: AES -> AESGCMKey+gcmKeyInit ctx = AESGCMKey $ B.allocAndFreeze sizeGCMKey $ \p ->+ keyToPtr ctx $ \k -> c_aes_gcm_key_init (castPtr p) k++-- | Authenticate and encrypt one message in a single call: the nonce, the+-- additional data, the plaintext and the tag, with no state crossing back+-- into Haskell in between. The result is the ciphertext followed by the tag.+{-# INLINABLE gcmFullEncrypt #-}+gcmFullEncrypt+ :: (ByteArrayAccess iv, ByteArrayAccess aad, ByteArrayAccess ba, ByteArray output)+ => AES -> AESGCMKey -> iv -> aad -> ba -> Int -> output+gcmFullEncrypt ctx (AESGCMKey gk) iv aad input taglen =+ B.allocAndFreeze (B.length input + taglen) $ \out ->+ B.withByteArray gk $ \gkp ->+ keyToPtr ctx $ \k ->+ B.withByteArray iv $ \ivp ->+ B.withByteArray aad $ \aadp ->+ B.withByteArray input $ \inp ->+ call+ out+ (castPtr gkp)+ k+ ivp+ (fromIntegral $ B.length iv)+ aadp+ (fromIntegral $ B.length aad)+ inp+ (fromIntegral $ B.length input)+ (fromIntegral taglen)+ where+ -- An unsafe call keeps a capability for as long as it runs, so it is only+ -- right for work that is over quickly. A message this side of+ -- 'shortMessage' is, and it is the short ones the saving matters for: a+ -- safe call costs about 0.075 us whatever the length, which is a fifth of+ -- a 1440-byte packet and a percent of a 16 KiB record.+ call+ | B.length input <= shortMessage = c_aes_gcm_full_encrypt_unsafe+ | otherwise = c_aes_gcm_full_encrypt++-- | Encrypt, and from a sample of the ciphertext just produced make the+-- header protection mask, into buffers the caller owns. QUIC takes its+-- sample from the ciphertext, so the mask cannot be had before the+-- encryption; it can be had before coming back, and with the buffers already+-- there nothing is allocated for either.+--+-- @sampleoff@ is where the sixteen bytes of sample begin in the output.+{-# INLINABLE gcmFullEncryptMask #-}+gcmFullEncryptMask+ :: (ByteArrayAccess iv, ByteArrayAccess aad, ByteArrayAccess ba)+ => AES+ -> AESGCMKey+ -> AES+ -> iv+ -> aad+ -> ba+ -> Int+ -> Int+ -> Ptr Word8+ -> Ptr Word8+ -> IO ()+gcmFullEncryptMask ctx (AESGCMKey gk) hpctx iv aad input taglen sampleoff outp maskp =+ B.withByteArray gk $ \gkp ->+ keyToPtr ctx $ \k ->+ keyToPtr hpctx $ \hk ->+ B.withByteArray iv $ \ivp ->+ B.withByteArray aad $ \aadp ->+ B.withByteArray input $ \inp ->+ call+ outp+ (castPtr gkp)+ k+ ivp+ (fromIntegral $ B.length iv)+ aadp+ (fromIntegral $ B.length aad)+ inp+ (fromIntegral $ B.length input)+ (fromIntegral taglen)+ hk+ (fromIntegral sampleoff)+ maskp+ where+ call+ | B.length input <= shortMessage = c_aes_gcm_full_encrypt_mask_unsafe+ | otherwise = c_aes_gcm_full_encrypt_mask++-- | The same the other way, with the tag compared here rather than by the+-- caller: 'Nothing' when it does not match, and every byte of it is looked at+-- either way. The ciphertext comes in without its tag, which is given+-- separately.+{-# INLINABLE gcmFullDecrypt #-}+gcmFullDecrypt+ :: ( ByteArrayAccess iv+ , ByteArrayAccess aad+ , ByteArrayAccess ba+ , ByteArrayAccess tag+ , ByteArray output+ )+ => AES -> AESGCMKey -> iv -> aad -> ba -> tag -> Maybe output+gcmFullDecrypt ctx (AESGCMKey gk) iv aad input tag = unsafeDoIO $ do+ (r, out) <- B.allocRet (B.length input) $ \outp ->+ B.withByteArray gk $ \gkp ->+ keyToPtr ctx $ \k ->+ B.withByteArray iv $ \ivp ->+ B.withByteArray aad $ \aadp ->+ B.withByteArray input $ \inp ->+ B.withByteArray tag $ \tagp ->+ call+ outp+ (castPtr gkp)+ k+ ivp+ (fromIntegral $ B.length iv)+ aadp+ (fromIntegral $ B.length aad)+ inp+ (fromIntegral $ B.length input)+ tagp+ (fromIntegral $ B.length tag)+ return $ if r /= 0 then Just out else Nothing+ where+ call+ | B.length input <= shortMessage = c_aes_gcm_full_decrypt_unsafe+ | otherwise = c_aes_gcm_full_decrypt++-- | Decrypt one message and hand back the tag that was computed over it,+-- rather than comparing it here.+--+-- For a caller that holds the expected tag in a form of its own and will+-- compare it itself. Compare the two t'AuthTag's with '==', whose instance+-- for that type is a constant-time comparison; taking them apart and+-- comparing the bytes is how this goes wrong.+--+-- Where the tag simply arrives after the ciphertext, 'gcmFullDecrypt' is the+-- one to use: it compares in C and never puts a tag in the caller's hands.+{-# INLINABLE gcmFullDecryptTag #-}+gcmFullDecryptTag+ :: ( ByteArrayAccess iv+ , ByteArrayAccess aad+ , ByteArrayAccess ba+ , ByteArray output+ )+ => AES -> AESGCMKey -> iv -> aad -> ba -> Int -> (output, AuthTag)+gcmFullDecryptTag ctx (AESGCMKey gk) iv aad input taglen = unsafeDoIO $ do+ (tagbs, out) <- B.allocRet (B.length input) $ \outp ->+ B.alloc taglen $ \tagp ->+ B.withByteArray gk $ \gkp ->+ keyToPtr ctx $ \k ->+ B.withByteArray iv $ \ivp ->+ B.withByteArray aad $ \aadp ->+ B.withByteArray input $ \inp ->+ call+ outp+ tagp+ (castPtr gkp)+ k+ ivp+ (fromIntegral $ B.length iv)+ aadp+ (fromIntegral $ B.length aad)+ inp+ (fromIntegral $ B.length input)+ (fromIntegral taglen)+ return (out, AuthTag $ B.convert (tagbs :: B.Bytes))+ where+ call+ | B.length input <= shortMessage = c_aes_gcm_full_decrypt_tag_unsafe+ | otherwise = c_aes_gcm_full_decrypt_tag+ -- | append data which is only going to be authenticated to the GCM context. -- -- needs to happen after initialization and before appending encryption/decryption data.@@ -439,7 +655,8 @@ doAppend = withNewGCMSt gcmSt $ \gcmStPtr -> withByteArray input $ \i ->- c_aes_gcm_aad gcmStPtr i (fromIntegral $ B.length input)+ B.inCLengths (B.length input) $ \off n ->+ c_aes_gcm_aad gcmStPtr (i `plusPtr` off) (fromIntegral n) -- | append data to encrypt and append to the GCM context --@@ -453,7 +670,13 @@ doEnc gcmStPtr aesPtr = B.alloc len $ \o -> withByteArray input $ \i ->- c_aes_gcm_encrypt (castPtr o) gcmStPtr aesPtr i (fromIntegral len)+ B.inCLengths len $ \off n ->+ c_aes_gcm_encrypt+ (castPtr o `plusPtr` off)+ gcmStPtr+ aesPtr+ (i `plusPtr` off)+ (fromIntegral n) -- | append data to decrypt and append to the GCM context --@@ -467,7 +690,13 @@ doDec gcmStPtr aesPtr = B.alloc len $ \o -> withByteArray input $ \i ->- c_aes_gcm_decrypt (castPtr o) gcmStPtr aesPtr i (fromIntegral len)+ B.inCLengths len $ \off n ->+ c_aes_gcm_decrypt+ (castPtr o `plusPtr` off)+ gcmStPtr+ aesPtr+ (i `plusPtr` off)+ (fromIntegral n) -- | Generate the Tag from GCM context {-# NOINLINE gcmFinish #-}@@ -500,9 +729,11 @@ -- The tag length is expressed in bytes and must be in [0..16]. -- The IV length must be in [1..15] bytes per RFC 7253. {-# NOINLINE ocbInitWithTagLength #-}-ocbInitWithTagLength :: ByteArrayAccess iv => AES -> iv -> Int -> CryptoFailable AESOCB+ocbInitWithTagLength+ :: ByteArrayAccess iv => AES -> iv -> Int -> CryptoFailable AESOCB ocbInitWithTagLength ctx iv taglen- | taglen < 0 || taglen > 16 = CryptoFailed CryptoError_AuthenticationTagSizeInvalid+ | taglen < 0 || taglen > 16 =+ CryptoFailed CryptoError_AuthenticationTagSizeInvalid | ivlen < 1 || ivlen > 15 = CryptoFailed CryptoError_IvSizeInvalid | otherwise = CryptoPassed $ unsafeDoIO $ do sm <- B.alloc sizeOCB $ \ocbStPtr ->@@ -522,7 +753,9 @@ -- need to happen after initialization and before appending encryption/decryption data. {-# NOINLINE ocbAppendAAD #-} ocbAppendAAD :: ByteArrayAccess aad => AES -> AESOCB -> aad -> AESOCB-ocbAppendAAD ctx ocb input = unsafeDoIO (snd `fmap` withOCBKeyAndCopySt ctx ocb doAppend)+ocbAppendAAD ctx ocb input+ | B.overCLength (B.length input) = error tooLongMessage+ | otherwise = unsafeDoIO (snd `fmap` withOCBKeyAndCopySt ctx ocb doAppend) where doAppend ocbStPtr aesPtr = withByteArray input $ \i ->@@ -534,7 +767,9 @@ -- need to happen after AAD appending, or after initialization if no AAD data. {-# NOINLINE ocbAppendEncrypt #-} ocbAppendEncrypt :: ByteArray ba => AES -> AESOCB -> ba -> (ba, AESOCB)-ocbAppendEncrypt ctx ocb input = unsafeDoIO $ withOCBKeyAndCopySt ctx ocb doEnc+ocbAppendEncrypt ctx ocb input+ | B.overCLength (B.length input) = error tooLongMessage+ | otherwise = unsafeDoIO $ withOCBKeyAndCopySt ctx ocb doEnc where len = B.length input doEnc ocbStPtr aesPtr =@@ -548,7 +783,9 @@ -- need to happen after AAD appending, or after initialization if no AAD data. {-# NOINLINE ocbAppendDecrypt #-} ocbAppendDecrypt :: ByteArray ba => AES -> AESOCB -> ba -> (ba, AESOCB)-ocbAppendDecrypt ctx ocb input = unsafeDoIO $ withOCBKeyAndCopySt ctx ocb doDec+ocbAppendDecrypt ctx ocb input+ | B.overCLength (B.length input) = error tooLongMessage+ | otherwise = unsafeDoIO $ withOCBKeyAndCopySt ctx ocb doDec where len = B.length input doDec ocbStPtr aesPtr =@@ -608,7 +845,9 @@ -- needs to happen after initialization and before appending encryption/decryption data. {-# NOINLINE ccmAppendAAD #-} ccmAppendAAD :: ByteArrayAccess aad => AES -> AESCCM -> aad -> AESCCM-ccmAppendAAD ctx ccm input = unsafeDoIO $ snd <$> withCCMKeyAndCopySt ctx ccm doAppend+ccmAppendAAD ctx ccm input+ | B.overCLength (B.length input) = error tooLongMessage+ | otherwise = unsafeDoIO $ snd <$> withCCMKeyAndCopySt ctx ccm doAppend where doAppend ccmStPtr aesPtr = withByteArray input $ \i -> c_aes_ccm_aad ccmStPtr aesPtr i (fromIntegral $ B.length input)@@ -619,7 +858,9 @@ -- needs to happen after AAD appending, or after initialization if no AAD data. {-# NOINLINE ccmEncrypt #-} ccmEncrypt :: ByteArray ba => AES -> AESCCM -> ba -> (ba, AESCCM)-ccmEncrypt ctx ccm input = unsafeDoIO $ withCCMKeyAndCopySt ctx ccm cbcmacAndIv+ccmEncrypt ctx ccm input+ | B.overCLength (B.length input) = error tooLongMessage+ | otherwise = unsafeDoIO $ withCCMKeyAndCopySt ctx ccm cbcmacAndIv where len = B.length input cbcmacAndIv ccmStPtr aesPtr =@@ -633,7 +874,9 @@ -- needs to happen after AAD appending, or after initialization if no AAD data. {-# NOINLINE ccmDecrypt #-} ccmDecrypt :: ByteArray ba => AES -> AESCCM -> ba -> (ba, AESCCM)-ccmDecrypt ctx ccm input = unsafeDoIO $ withCCMKeyAndCopySt ctx ccm cbcmacAndIv+ccmDecrypt ctx ccm input+ | B.overCLength (B.length input) = error tooLongMessage+ | otherwise = unsafeDoIO $ withCCMKeyAndCopySt ctx ccm cbcmacAndIv where len = B.length input cbcmacAndIv ccmStPtr aesPtr =@@ -682,6 +925,131 @@ foreign import ccall "crypton_aes.h crypton_aes_encrypt_c32" c_aes_encrypt_c32 :: CString -> Ptr AES -> Ptr Word8 -> CString -> CUInt -> IO ()++foreign import ccall unsafe "crypton_aes.h crypton_aes_gcm_key_init"+ c_aes_gcm_key_init :: Ptr AESGCM -> Ptr AES -> IO ()++foreign import ccall "crypton_aes.h crypton_aes_gcm_full_encrypt"+ c_aes_gcm_full_encrypt+ :: Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> CUInt+ -> IO ()++foreign import ccall "crypton_aes.h crypton_aes_gcm_full_decrypt"+ c_aes_gcm_full_decrypt+ :: Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO CInt++foreign import ccall "crypton_aes.h crypton_aes_gcm_full_decrypt_tag"+ c_aes_gcm_full_decrypt_tag+ :: Ptr Word8+ -> Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> CUInt+ -> IO ()++foreign import ccall unsafe "crypton_aes.h crypton_aes_gcm_full_decrypt_tag"+ c_aes_gcm_full_decrypt_tag_unsafe+ :: Ptr Word8+ -> Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> CUInt+ -> IO ()++foreign import ccall unsafe "crypton_aes.h crypton_aes_gcm_full_encrypt"+ c_aes_gcm_full_encrypt_unsafe+ :: Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> CUInt+ -> IO ()++foreign import ccall unsafe "crypton_aes.h crypton_aes_gcm_full_decrypt"+ c_aes_gcm_full_decrypt_unsafe+ :: Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO CInt++foreign import ccall "crypton_aes.h crypton_aes_gcm_full_encrypt_mask"+ c_aes_gcm_full_encrypt_mask+ :: Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> CUInt+ -> Ptr AES+ -> CUInt+ -> Ptr Word8+ -> IO ()++foreign import ccall unsafe "crypton_aes.h crypton_aes_gcm_full_encrypt_mask"+ c_aes_gcm_full_encrypt_mask_unsafe+ :: Ptr Word8+ -> Ptr AESGCM+ -> Ptr AES+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> CUInt+ -> Ptr AES+ -> CUInt+ -> Ptr Word8+ -> IO () foreign import ccall "crypton_aes.h crypton_aes_gcm_init" c_aes_gcm_init :: Ptr AESGCM -> Ptr AES -> Ptr Word8 -> CUInt -> IO ()
Crypto/Cipher/ChaCha.hs view
@@ -183,10 +183,19 @@ | B.null src = (B.empty, prevSt) | otherwise = unsafeDoIO $ do (out, st) <- B.copyRet prevStMem $ \ctx ->- B.alloc (B.length src) $ \dstPtr ->+ B.alloc n $ \dstPtr -> B.withByteArray src $ \srcPtr ->- ccrypton_chacha_combine dstPtr ctx srcPtr (fromIntegral $ B.length src)+ -- in pieces the C's uint32_t length can hold; it carries+ -- the state in ctx, so it can simply be called again+ B.inCLengths n $ \off len ->+ ccrypton_chacha_combine+ (dstPtr `plusPtr` off)+ ctx+ (srcPtr `plusPtr` off)+ (fromIntegral len) return (out, State st)+ where+ n = B.length src -- | Generate a number of bytes from the ChaCha output directly generate@@ -201,7 +210,11 @@ | otherwise = unsafeDoIO $ do (out, st) <- B.copyRet prevStMem $ \ctx -> B.alloc len $ \dstPtr ->- ccrypton_chacha_generate dstPtr ctx (fromIntegral len)+ B.inCLengths len $ \off n ->+ ccrypton_chacha_generate+ (dstPtr `plusPtr` off)+ ctx+ (fromIntegral n) return (out, State st) -- | similar to 'generate' but assume certains values
+ Crypto/Cipher/ChaCha/Poly1305.hs view
@@ -0,0 +1,335 @@+-- |+-- Module : Crypto.Cipher.ChaCha.Poly1305+-- License : BSD-style+-- Maintainer : Kazu Yamamoto <kazu@iij.ad.jp>+-- Stability : experimental+-- Portability : Good+--+-- ChaCha20-Poly1305 (RFC 8439) a message at a time.+--+-- "Crypto.Cipher.ChaChaPoly1305" takes a message in pieces: a state is+-- started, the additional data appended, the body encrypted and the tag+-- taken, each a step of its own. That is what a protocol wants when the+-- message arrives in pieces, and it is eight foreign calls and the+-- allocations between them when the message was already whole.+--+-- Here the whole message goes in one call.+--+-- The functions are the same shape as "Crypto.Cipher.AES.GCM", so a protocol+-- that offers both ciphers can hold them the same way.+module Crypto.Cipher.ChaCha.Poly1305 (+ Context,+ newContext,+ encrypt,+ decrypt,+ decryptWithTag,+) where++import Crypto.Cipher.Types (AuthTag (..))+import Crypto.Error+import Crypto.Internal.ByteArray (ByteArray, ByteArrayAccess)+import qualified Crypto.Internal.ByteArray as B+import Crypto.Internal.Compat (unsafeDoIO)+import Crypto.Internal.Imports+import Foreign.C.Types (CInt (..), CUInt (..))+import Foreign.Ptr (Ptr, plusPtr)++-- | A key, checked once.+--+-- ChaCha20-Poly1305 has nothing to precompute from a key: the one-time+-- Poly1305 key comes from the nonce, so it differs for every message. This+-- holds the thirty-two bytes and the knowledge that they are thirty-two, and+-- exists so that the interface is the one "Crypto.Cipher.AES.GCM" has.+newtype Context = Context B.ScrubbedBytes++instance NFData Context where+ rnf (Context k) = k `seq` ()++-- | Take a key of 32 bytes. Any other length is reported as+-- 'CryptoError_KeySizeInvalid'.+newContext :: ByteArrayAccess key => key -> CryptoFailable Context+newContext k+ | B.length k /= 32 = CryptoFailed CryptoError_KeySizeInvalid+ | otherwise = CryptoPassed $ Context (B.convert k)+{-# INLINABLE newContext #-}++-- | Encrypt one message. The result is the ciphertext with the tag after it,+-- which is the shape 'decrypt' expects.+--+-- The nonce is the twelve bytes RFC 8439 defines; any other length gives+-- 'CryptoError_IvSizeInvalid'. RFC 8439 requires a 16-byte tag.+{-# INLINABLE encrypt #-}+encrypt+ :: ( ByteArrayAccess nonce+ , ByteArrayAccess aad+ , ByteArrayAccess ba+ , ByteArray output+ )+ => Context+ -> nonce+ -> aad+ -> ba+ -> Int+ -> CryptoFailable output+encrypt (Context k) nonce aad input taglen+ | tooLongForC aad input = CryptoFailed CryptoError_ParameterInvalid+ | not (validNonce nonce) = CryptoFailed CryptoError_IvSizeInvalid+ | badTag taglen = CryptoFailed CryptoError_AuthenticationTagSizeInvalid+ | otherwise =+ CryptoPassed $+ unsafeDoIO $+ B.alloc (B.length input + taglen) $ \out ->+ B.withByteArray k $ \kp ->+ B.withByteArray nonce $ \np ->+ B.withByteArray aad $ \ap ->+ B.withByteArray input $ \ip ->+ (callE (B.length input))+ out+ (out `plusPtr` B.length input)+ (fromIntegral taglen)+ kp+ np+ (fromIntegral $ B.length nonce)+ ap+ (fromIntegral $ B.length aad)+ ip+ (fromIntegral $ B.length input)++-- | Decrypt one message, in the shape 'encrypt' produced: the ciphertext with+-- its tag after it. The tag is compared here, every byte of it whatever the+-- answer, and a message whose tag does not match gives 'Nothing' rather than+-- the plaintext.+--+-- 'Nothing' also comes back when the input is shorter than the tag, or the+-- nonce is not twelve bytes.+{-# INLINABLE decrypt #-}+decrypt+ :: (ByteArrayAccess nonce, ByteArrayAccess aad, ByteArray ba)+ => Context+ -> nonce+ -> aad+ -> ba+ -> Int+ -> Maybe ba+decrypt (Context k) nonce aad input taglen+ | tooLongForC aad input = Nothing+ | not (validNonce nonce) = Nothing+ | badTag taglen || B.length input < taglen = Nothing+ | otherwise = unsafeDoIO $ do+ (r, out) <- B.allocRet bodylen $ \outp ->+ B.withByteArray k $ \kp ->+ B.withByteArray nonce $ \np ->+ B.withByteArray aad $ \ap ->+ B.withByteArray body $ \ip ->+ B.withByteArray tag $ \tp ->+ (callD bodylen)+ outp+ tp+ (fromIntegral taglen)+ kp+ np+ (fromIntegral $ B.length nonce)+ ap+ (fromIntegral $ B.length aad)+ ip+ (fromIntegral bodylen)+ return $ if r /= 0 then Just out else Nothing+ where+ bodylen = B.length input - taglen+ (body, tag) = B.splitAt bodylen input++-- | Decrypt one message, the tag kept apart, and hand back the tag this end+-- computed.+--+-- For a caller whose protocol carries the tag separately from the ciphertext,+-- so that 'decrypt' -- which wants the two together and compares them itself+-- -- does not fit. Compare the two tags with '=='; the 'Eq' instance of+-- t'AuthTag' is a constant-time comparison, and taking them apart to compare+-- the bytes is how this goes wrong.+--+-- Nothing here says whether the message is authentic. Until the comparison+-- is made and has come out equal, what this returns is not plaintext, it is+-- what the ciphertext turns into, and a caller must not act on it.+{-# INLINABLE decryptWithTag #-}+decryptWithTag+ :: (ByteArrayAccess nonce, ByteArrayAccess aad, ByteArray ba)+ => Context+ -> nonce+ -> aad+ -> ba+ -> Int+ -> CryptoFailable (ba, AuthTag)+decryptWithTag (Context k) nonce aad input taglen+ | tooLongForC aad input = CryptoFailed CryptoError_ParameterInvalid+ | not (validNonce nonce) = CryptoFailed CryptoError_IvSizeInvalid+ | badTag taglen = CryptoFailed CryptoError_AuthenticationTagSizeInvalid+ | otherwise = CryptoPassed $ unsafeDoIO $ do+ (tagbs, out) <- B.allocRet (B.length input) $ \outp ->+ B.alloc taglen $ \tagp ->+ B.withByteArray k $ \kp ->+ B.withByteArray nonce $ \np ->+ B.withByteArray aad $ \ap ->+ B.withByteArray input $ \ip ->+ (callT (B.length input))+ outp+ tagp+ (fromIntegral taglen)+ kp+ np+ (fromIntegral $ B.length nonce)+ ap+ (fromIntegral $ B.length aad)+ ip+ (fromIntegral $ B.length input)+ return (out, AuthTag $ B.convert (tagbs :: B.Bytes))++-- | The C takes its lengths as @uint32_t@, so a message or its additional+-- data from 2^32 bytes up cannot be handed to it: the length would be+-- truncated and most of the buffer left untouched, with nothing to say so.+-- The C does the whole message in one call, so there is no splitting it.+tooLongForC+ :: (ByteArrayAccess aad, ByteArrayAccess ba) => aad -> ba -> Bool+tooLongForC aad input =+ B.overCLength (B.length aad) || B.overCLength (B.length input)++-- RFC 8439 is the twelve-byte nonce. ChaCha20 will take eight, but that is+-- the other construction, with a 64-bit block counter, and it is not what+-- this AEAD is defined over -- so it is refused here rather than quietly+-- encrypting under a scheme nobody asked for.+validNonce :: ByteArrayAccess nonce => nonce -> Bool+validNonce n = B.length n == 12++badTag :: Int -> Bool+badTag t = t /= 16++-- | An unsafe call keeps a capability for as long as it runs, so it is only+-- for a message short enough that the run is short. Four kibibytes is what+-- the AES side uses, and it takes in a datagram of any size a network will+-- carry.+shortMessage :: Int+shortMessage = 4096++callE :: Int -> CEncrypt+callE n+ | n <= shortMessage = c_chachapoly_encrypt_unsafe+ | otherwise = c_chachapoly_encrypt++callD :: Int -> CDecrypt+callD n+ | n <= shortMessage = c_chachapoly_decrypt_unsafe+ | otherwise = c_chachapoly_decrypt++callT :: Int -> CEncrypt+callT n+ | n <= shortMessage = c_chachapoly_decrypt_tag_unsafe+ | otherwise = c_chachapoly_decrypt_tag++type CEncrypt =+ Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO ()++type CDecrypt =+ Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO CInt++foreign import ccall "crypton_chachapoly.h crypton_chachapoly_encrypt"+ c_chachapoly_encrypt+ :: Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO ()++foreign import ccall unsafe "crypton_chachapoly.h crypton_chachapoly_encrypt"+ c_chachapoly_encrypt_unsafe+ :: Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO ()++foreign import ccall "crypton_chachapoly.h crypton_chachapoly_decrypt"+ c_chachapoly_decrypt+ :: Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO CInt++foreign import ccall unsafe "crypton_chachapoly.h crypton_chachapoly_decrypt"+ c_chachapoly_decrypt_unsafe+ :: Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO CInt++foreign import ccall "crypton_chachapoly.h crypton_chachapoly_decrypt_tag"+ c_chachapoly_decrypt_tag+ :: Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO ()++foreign import ccall unsafe "crypton_chachapoly.h crypton_chachapoly_decrypt_tag"+ c_chachapoly_decrypt_tag_unsafe+ :: Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> Ptr Word8+ -> CUInt+ -> IO ()
Crypto/Cipher/ChaChaPoly1305.hs view
@@ -1,3 +1,5 @@+{-# LANGUAGE GeneralizedNewtypeDeriving #-}+ -- | -- Module : Crypto.Cipher.ChaChaPoly1305 -- License : BSD-style@@ -28,7 +30,7 @@ -- > -> ByteString -- input plaintext to be encrypted -- > -> CryptoFailable ByteString -- ciphertext with a 128-bit tag attached -- >encrypt nonce key header plaintext = do--- > st1 <- C.nonce12 nonce >>= C.initialize key+-- > st1 <- C.initialize <$> C.key key <*> C.nonce12 nonce -- > let -- > st2 = C.finalizeAAD $ C.appendAAD header st1 -- > (out, st3) = C.encrypt plaintext st2@@ -41,6 +43,8 @@ -- * Low level State,+ Key,+ key, Nonce, XNonce, nonce12,@@ -68,6 +72,7 @@ ) import qualified Crypto.Internal.ByteArray as B import Crypto.Internal.Imports+import qualified Crypto.Internal.Poly1305 as PolyKey import qualified Crypto.MAC.Poly1305 as Poly1305 import qualified Data.ByteArray.Pack as P import Data.Memory.Endian@@ -174,44 +179,39 @@ -- -- The key length need to be 256 bits, and the nonce -- procured using either `nonce8` or `nonce12`-initialize- :: ByteArrayAccess key- => key -> Nonce -> CryptoFailable State-initialize key (Nonce8 nonce) = initialize' key nonce-initialize key (Nonce12 nonce) = initialize' key nonce+-- | A ChaCha20Poly1305 key: thirty-two bytes, checked once here rather than+-- at every use, so that 'initialize' and 'initializeX' cannot fail.+newtype Key = Key ScrubbedBytes+ deriving (ByteArrayAccess, Eq, NFData) -initialize'- :: ByteArrayAccess key- => key -> Bytes -> CryptoFailable State-initialize' key nonce- | B.length key /= 32 = CryptoFailed CryptoError_KeySizeInvalid- | otherwise = CryptoPassed $ initFromRootState rootState- where- rootState = ChaCha.initialize 20 key nonce+-- | Take thirty-two bytes for a key. A different length is reported as+-- 'CryptoError_KeySizeInvalid'; nothing else about a key can be wrong.+key :: ByteArrayAccess ba => ba -> CryptoFailable Key+key k+ | B.length k /= 32 = CryptoFailed CryptoError_KeySizeInvalid+ | otherwise = CryptoPassed $ Key $ B.convert k +initialize :: Key -> Nonce -> State+initialize k (Nonce8 nonce) = initialize' k nonce+initialize k (Nonce12 nonce) = initialize' k nonce++initialize' :: Key -> Bytes -> State+initialize' k nonce = initFromRootState (ChaCha.initialize 20 k nonce)+ initFromRootState :: ChaCha.State -> State initFromRootState rootState = State encState polyState 0 0 where (polyKey, encState) = ChaCha.generate rootState 64- -- 64 bytes are generated so the ChaCha state advances a whole block; the- -- first 32 of them are the key, so the length is right by construction- polyState =- Poly1305.initialize $- throwCryptoError $- Poly1305.key (B.take 32 polyKey :: ScrubbedBytes)+ -- 64 bytes are generated so the ChaCha state advances a whole block, and+ -- the first 32 of them are the key, so there is no length left to check+ polyState = Poly1305.initialize (PolyKey.Key (B.take 32 polyKey)) -- | Initialize a new XChaChaPoly1305 State -- -- The key length needs to be 256 bits, and the nonce -- procured using `nonce24`.-initializeX- :: ByteArrayAccess key- => key -> XNonce -> CryptoFailable State-initializeX key (Nonce24 nonce)- | B.length key /= 32 = CryptoFailed CryptoError_KeySizeInvalid- | otherwise = CryptoPassed $ initFromRootState rootState- where- rootState = ChaCha.initializeX 20 key nonce+initializeX :: Key -> XNonce -> State+initializeX k (Nonce24 nonce) = initFromRootState (ChaCha.initializeX 20 k nonce) -- | Append Authenticated Data to the State and return -- the new modified State.@@ -267,8 +267,8 @@ aeadChacha20poly1305Init :: (ByteArrayAccess k, ByteArrayAccess n) => k -> n -> CryptoFailable (AEAD ChaCha20Poly1305)-aeadChacha20poly1305Init key nonce = do- st0 <- nonce12 nonce >>= initialize key+aeadChacha20poly1305Init k nonce = do+ st0 <- initialize <$> key k <*> nonce12 nonce return $ AEAD model st0 where model =
Crypto/Cipher/RC4.hs view
@@ -98,7 +98,14 @@ B.allocRet len $ \outptr -> B.withByteArray clearText $ \clearPtr -> do st <- B.copy prevSt $ \stPtr ->- c_rc4_combine (castPtr stPtr) clearPtr (fromIntegral len) outptr+ -- in pieces the C's uint32_t length can hold; the state it+ -- keeps means it can simply be called again+ B.inCLengths len $ \off n ->+ c_rc4_combine+ (castPtr stPtr)+ (clearPtr `plusPtr` off)+ (fromIntegral n)+ (outptr `plusPtr` off) return $! State st where -- return $! (State st, B.PS outfptr 0 len)
Crypto/Cipher/Salsa.hs view
@@ -70,10 +70,19 @@ | B.null src = (B.empty, prevSt) | otherwise = unsafeDoIO $ do (out, st) <- B.copyRet prevStMem $ \ctx ->- B.alloc (B.length src) $ \dstPtr ->- B.withByteArray src $ \srcPtr -> do- ccrypton_salsa_combine dstPtr ctx srcPtr (fromIntegral $ B.length src)+ B.alloc n $ \dstPtr ->+ B.withByteArray src $ \srcPtr ->+ -- in pieces the C's uint32_t length can hold; it carries+ -- the state in ctx, so it can simply be called again+ B.inCLengths n $ \off len ->+ ccrypton_salsa_combine+ (dstPtr `plusPtr` off)+ ctx+ (srcPtr `plusPtr` off)+ (fromIntegral len) return (out, State st)+ where+ n = B.length src -- | Generate a number of bytes from the Salsa output directly generate@@ -88,7 +97,11 @@ | otherwise = unsafeDoIO $ do (out, st) <- B.copyRet prevStMem $ \ctx -> B.alloc len $ \dstPtr ->- ccrypton_salsa_generate dstPtr ctx (fromIntegral len)+ B.inCLengths len $ \off n ->+ ccrypton_salsa_generate+ (dstPtr `plusPtr` off)+ ctx+ (fromIntegral n) return (out, State st) foreign import ccall "crypton_salsa_init"
Crypto/Hash/Algorithms.hs view
@@ -48,8 +48,10 @@ Blake2bp (..), Blake2s (..), Blake2sp (..),+ Skein256 (..), Skein256_224 (..), Skein256_256 (..),+ Skein512 (..), Skein512_224 (..), Skein512_256 (..), Skein512_384 (..),
Crypto/Hash/Skein256.hs view
@@ -1,7 +1,11 @@ {-# LANGUAGE DataKinds #-} {-# LANGUAGE DeriveDataTypeable #-} {-# LANGUAGE ForeignFunctionInterface #-}+{-# LANGUAGE KindSignatures #-}+{-# LANGUAGE ScopedTypeVariables #-} {-# LANGUAGE TypeFamilies #-}+{-# LANGUAGE TypeOperators #-}+{-# LANGUAGE UndecidableInstances #-} -- | -- Module : Crypto.Hash.Skein256@@ -13,14 +17,17 @@ -- Module containing the binding functions to work with the -- Skein256 cryptographic hash. module Crypto.Hash.Skein256 (+ Skein256 (..), Skein256_224 (..), Skein256_256 (..), ) where import Crypto.Hash.Types+import Crypto.Internal.Nat import Data.Data import Data.Word (Word32, Word8) import Foreign.Ptr (Ptr)+import GHC.TypeLits (KnownNat, Nat, type (+)) -- | Skein256 (224 bits) cryptographic hash algorithm data Skein256_224 = Skein256_224@@ -51,6 +58,38 @@ hashInternalInit p = c_skein256_init p 256 hashInternalUpdate = c_skein256_update hashInternalFinalize p = c_skein256_finalize p 256++-- | Skein256 with the digest size given as a type parameter of kind 'Nat',+-- in bits. @t'Skein256' 256@ is @t'Skein256_256'@; the sizes with a type of+-- their own+-- above are there for their names, and this one also takes the sizes that+-- have none.+--+-- A size that is not a whole number of bytes is rounded up to the next one,+-- as the implementation underneath does.+--+-- The output is produced in counter mode, a block of it per Threefish call,+-- so one large digest is a good deal cheaper than the same number of bytes+-- taken from repeated small ones: on an Apple M4, 512 KiB arrives at 947 MB/s+-- in one digest against 172 MB/s as 8192 separate @t'Skein256_256'@ ones.+--+-- Note the digest size goes into the configuration block, so it changes the+-- value the message is hashed from: a longer digest is /not/ an extension of+-- a shorter one. That is the opposite of how t'Crypto.Hash.SHAKE.SHAKE128'+-- behaves.+data Skein256 (bitlen :: Nat) = Skein256+ deriving (Show, Data)++instance KnownNat bitlen => HashAlgorithm (Skein256 bitlen) where+ type HashBlockSize (Skein256 bitlen) = 32+ type HashDigestSize (Skein256 bitlen) = Div8 (bitlen + 7)+ type HashInternalContextSize (Skein256 bitlen) = 96+ hashBlockSize _ = 32+ hashDigestSize _ = byteLen (Proxy :: Proxy bitlen)+ hashInternalContextSize _ = 96+ hashInternalInit p = c_skein256_init p (integralNatVal (Proxy :: Proxy bitlen))+ hashInternalUpdate = c_skein256_update+ hashInternalFinalize p = c_skein256_finalize p (integralNatVal (Proxy :: Proxy bitlen)) foreign import ccall unsafe "crypton_skein256_init" c_skein256_init :: Ptr (Context a) -> Word32 -> IO ()
Crypto/Hash/Skein512.hs view
@@ -1,7 +1,11 @@ {-# LANGUAGE DataKinds #-} {-# LANGUAGE DeriveDataTypeable #-} {-# LANGUAGE ForeignFunctionInterface #-}+{-# LANGUAGE KindSignatures #-}+{-# LANGUAGE ScopedTypeVariables #-} {-# LANGUAGE TypeFamilies #-}+{-# LANGUAGE TypeOperators #-}+{-# LANGUAGE UndecidableInstances #-} -- | -- Module : Crypto.Hash.Skein512@@ -13,6 +17,7 @@ -- Module containing the binding functions to work with the -- Skein512 cryptographic hash. module Crypto.Hash.Skein512 (+ Skein512 (..), Skein512_224 (..), Skein512_256 (..), Skein512_384 (..),@@ -20,9 +25,11 @@ ) where import Crypto.Hash.Types+import Crypto.Internal.Nat import Data.Data import Data.Word (Word32, Word8) import Foreign.Ptr (Ptr)+import GHC.TypeLits (KnownNat, Nat, type (+)) -- | Skein512 (224 bits) cryptographic hash algorithm data Skein512_224 = Skein512_224@@ -83,6 +90,38 @@ hashInternalInit p = c_skein512_init p 512 hashInternalUpdate = c_skein512_update hashInternalFinalize p = c_skein512_finalize p 512++-- | Skein512 with the digest size given as a type parameter of kind 'Nat',+-- in bits. @t'Skein512' 512@ is @t'Skein512_512'@; the sizes with a type of+-- their own+-- above are there for their names, and this one also takes the sizes that+-- have none.+--+-- A size that is not a whole number of bytes is rounded up to the next one,+-- as the implementation underneath does.+--+-- The output is produced in counter mode, a block of it per Threefish call,+-- so one large digest is a good deal cheaper than the same number of bytes+-- taken from repeated small ones: on an Apple M4, 512 KiB arrives at 947 MB/s+-- in one digest against 172 MB/s as 8192 separate @t'Skein512_512'@ ones.+--+-- Note the digest size goes into the configuration block, so it changes the+-- value the message is hashed from: a longer digest is /not/ an extension of+-- a shorter one. That is the opposite of how t'Crypto.Hash.SHAKE.SHAKE128'+-- behaves.+data Skein512 (bitlen :: Nat) = Skein512+ deriving (Show, Data)++instance KnownNat bitlen => HashAlgorithm (Skein512 bitlen) where+ type HashBlockSize (Skein512 bitlen) = 64+ type HashDigestSize (Skein512 bitlen) = Div8 (bitlen + 7)+ type HashInternalContextSize (Skein512 bitlen) = 160+ hashBlockSize _ = 64+ hashDigestSize _ = byteLen (Proxy :: Proxy bitlen)+ hashInternalContextSize _ = 160+ hashInternalInit p = c_skein512_init p (integralNatVal (Proxy :: Proxy bitlen))+ hashInternalUpdate = c_skein512_update+ hashInternalFinalize p = c_skein512_finalize p (integralNatVal (Proxy :: Proxy bitlen)) foreign import ccall unsafe "crypton_skein512_init" c_skein512_init :: Ptr (Context a) -> Word32 -> IO ()
Crypto/Hash/Types.hs view
@@ -103,6 +103,26 @@ -- layout is architecture dependent, may contain uninitialized data fragments, -- and change in future versions. The bytearray should not be used as input to -- cryptographic algorithms.+--+-- __A context is not erased when it is finished with.__ A hash algorithm+-- buffers its input a block at a time, and finalizing does not clear what is+-- left there. How much survives depends on where the message ended relative+-- to the block: with SHA-256, a 32-byte message is still in the context in+-- full afterwards, and a 100-byte one leaves its last 36 bytes.+-- @hashFinalize@ works on a copy, so the caller's own context keeps what it+-- had as well. Nothing clears either of them: this is 'Bytes' rather than+-- @ScrubbedBytes@, and the C clears nothing. They go to the garbage+-- collector as they are, and a core file, a crash dump or a swapped page can+-- carry them away afterwards.+--+-- That is a deliberate trade rather than an oversight, and there is no way+-- to ask for the other side of it: no operation here clears a context.+-- Scrubbing them all was measured at about 70% of a 32-byte hash and a third+-- of an incremental one, because the allocation is most of the work when the+-- message is short -- and short hashes are the common case, in HMAC, in+-- HKDF, and anywhere a key or an identifier is hashed. A 64 KB hash does+-- not notice it. Anything that must not be left in memory this way is+-- better not hashed through this interface at all. newtype Context a = Context Bytes deriving (ByteArrayAccess, NFData)
Crypto/Internal/ByteArray.hs view
@@ -14,6 +14,8 @@ module Data.ByteArray.Mapping, module Data.ByteArray.Encoding, constAllZero,+ overCLength,+ inCLengths, allocAndFreezePrimIO, allocAndFreezePrim, bxor,@@ -30,6 +32,51 @@ import Foreign.Storable (peekByteOff) import Crypto.Internal.Compat (unsafeDoIO)++-- | Whether a length is too large to reach the C, which takes its lengths as+-- @uint32_t@.+--+-- From 2^32 up the value is truncated on the way down, and the C then works+-- on the low bits of it and leaves the rest of the buffer as it found it --+-- which for a fresh allocation is zeros. What comes back is as long as the+-- caller asked for, with nothing to say that most of it was never written:+-- a 4 GiB message through Crypto.Cipher.ChaCha.combine came back with 2^32+-- bytes of zeros where the ciphertext should have been.+--+-- Every place that hands a caller's length to the C either turns it away+-- with this or cuts the work into pieces small enough to pass.+--+-- The round trip through 'Word32' rather than a comparison against 2^32,+-- which a 32-bit 'Int' cannot hold. There every non-negative 'Int' passes,+-- which is the right answer: there is no such buffer to be had.+overCLength :: Int -> Bool+overCLength n = fromIntegral (fromIntegral n :: Word32) /= n++-- | Walk a length in pieces small enough to reach the C, calling the action+-- with the offset and the size of each.+--+-- The same 2 GiB step "Crypto.Hash" has always taken, and for the same+-- reason: the C takes its lengths as @uint32_t@, and a 32-bit 'Int' cannot+-- hold a whole one either. This is for the C that keeps its state in a+-- context and can simply be called again -- the stream ciphers, the MACs --+-- where a long message can be enciphered in pieces rather than refused.+inCLengths :: Int -> (Int -> Int -> IO ()) -> IO ()+inCLengths total f = go 0+ where+ go !off+ | off >= total = return ()+ | otherwise = f off n >> go (off + n)+ where+ !n = min (total - off) cChunk++-- | The step 'inCLengths' takes: the largest multiple of 64 that a signed+-- 32-bit integer holds.+--+-- Under 2^31 because a 32-bit 'Int' cannot hold more, and a+-- multiple of 64 because some of the C this feeds -- the AEAD modes -- will+-- take a piece that is not a whole number of blocks only as the last one.+cChunk :: Int+cChunk = 0x7fffffc0 -- | Allocate a pinned 'Prim.ByteArray' of the given size, populate it via a -- 'Ptr', then freeze and return it. The pointer must not be retained after
+ Crypto/Internal/Poly1305.hs view
@@ -0,0 +1,37 @@+{-# LANGUAGE GeneralizedNewtypeDeriving #-}++-- |+-- Module : Crypto.Internal.Poly1305+-- License : BSD-style+-- Maintainer : Kazu Yamamoto <kazu@iij.ad.jp>+-- Stability : experimental+-- Portability : unknown+--+-- The Poly1305 key with its constructor, for the modules here that build one+-- from bytes whose length they already know. "Crypto.MAC.Poly1305" exports+-- the type without the constructor, so that outside this library a key can+-- only be made by 'key', which checks.+module Crypto.Internal.Poly1305 (+ Key (..),+ key,+) where++import Crypto.Error+import Crypto.Internal.ByteArray (ByteArrayAccess, ScrubbedBytes)+import qualified Crypto.Internal.ByteArray as B+import Crypto.Internal.DeepSeq++-- | A Poly1305 key: thirty-two bytes, and the length is checked here rather+-- than at every use. 'Crypto.MAC.Poly1305.initialize' and+-- 'Crypto.MAC.Poly1305.auth' take one of these and cannot fail, so a caller+-- that holds a key does not carry an error case for a length it already knows+-- is right.+newtype Key = Key ScrubbedBytes+ deriving (ByteArrayAccess, Eq, NFData)++-- | Take thirty-two bytes for a key. A different length is reported as+-- 'CryptoError_MacKeyInvalid'; nothing else about a key can be wrong.+key :: ByteArrayAccess ba => ba -> CryptoFailable Key+key k+ | B.length k /= 32 = CryptoFailed CryptoError_MacKeyInvalid+ | otherwise = CryptoPassed $ Key $ B.convert k
Crypto/MAC/Poly1305.hs view
@@ -35,6 +35,7 @@ ) import qualified Crypto.Internal.ByteArray as B import Crypto.Internal.DeepSeq+import Crypto.Internal.Poly1305 (Key (..), key) import Data.Word import Foreign.C.Types import Foreign.Ptr@@ -48,20 +49,6 @@ newtype State = State ScrubbedBytes deriving (ByteArrayAccess) --- | A Poly1305 key: thirty-two bytes, and the length is checked here rather--- than at every use. 'initialize' and 'auth' take one of these and cannot--- fail, so a caller that holds a key does not carry an error case for a--- length it already knows is right.-newtype Key = Key ScrubbedBytes- deriving (ByteArrayAccess, Eq, NFData)---- | Take thirty-two bytes for a key. A different length is reported as--- 'CryptoError_MacKeyInvalid'; nothing else about a key can be wrong.-key :: ByteArrayAccess ba => ba -> CryptoFailable Key-key k- | B.length k /= 32 = CryptoFailed CryptoError_MacKeyInvalid- | otherwise = CryptoPassed $ Key $ B.convert k- -- | Poly1305 State. use State instead of Ctx type Ctx = State @@ -105,7 +92,10 @@ update :: ByteArrayAccess ba => State -> ba -> State update (State prevCtx) d = State $ B.copyAndFreeze prevCtx $ \ctxPtr -> B.withByteArray d $ \dataPtr ->- c_poly1305_update (castPtr ctxPtr) dataPtr (fromIntegral $ B.length d)+ -- in pieces the C's uint32_t length can hold; the context carries+ -- across, so it can simply be called again+ B.inCLengths (B.length d) $ \off n ->+ c_poly1305_update (castPtr ctxPtr) (dataPtr `plusPtr` off) (fromIntegral n) {-# NOINLINE update #-} -- | updates a context with multiples bytestring@@ -114,7 +104,9 @@ where loop [] _ = return () loop (x : xs) ctxPtr = do- B.withByteArray x $ \dataPtr -> c_poly1305_update ctxPtr dataPtr (fromIntegral $ B.length x)+ B.withByteArray x $ \dataPtr ->+ B.inCLengths (B.length x) $ \off n ->+ c_poly1305_update ctxPtr (dataPtr `plusPtr` off) (fromIntegral n) loop xs ctxPtr {-# NOINLINE updates #-} @@ -137,5 +129,9 @@ B.withByteArray k $ \keyPtr -> do c_poly1305_init (castPtr ctxPtr) keyPtr B.withByteArray d $ \dataPtr ->- c_poly1305_update (castPtr ctxPtr) dataPtr (fromIntegral $ B.length d)+ B.inCLengths (B.length d) $ \off n ->+ c_poly1305_update+ (castPtr ctxPtr)+ (dataPtr `plusPtr` off)+ (fromIntegral n) c_poly1305_finalize dst (castPtr ctxPtr)
Crypto/Number/Basic.hs view
@@ -85,7 +85,12 @@ -- | Compute the number of bits for an integer numBits :: Integer -> Int-numBits n = gmpSizeInBits n `onGmpUnsupported` (if n == 0 then 1 else computeBits 0 n)+-- GMP sizes the magnitude and calls zero zero bits, and every caller here --+-- 'numBytes' above all -- is written against that. The fallback used to+-- answer 1 for zero, and to divide a negative number by 256 forever, because+-- the quotient never reaches zero.+numBits n =+ gmpSizeInBits n `onGmpUnsupported` (if n == 0 then 0 else computeBits 0 (abs n)) where computeBits !acc i | q == 0 =
Crypto/Number/ModArithmetic.hs view
@@ -171,9 +171,19 @@ -- | @exponentiation@ computes modular exponentiation as /b^e mod m/ -- using repetitive squaring.+--+-- The corner cases are held to what GMP answers, since that is what this+-- computes on every build that has it: a modulus of one is zero whatever+-- else is asked, and a negative exponent is a request for the inverse of+-- the base raised to its magnitude, which is zero when no inverse exists.+-- Read literally, the recursion below walked a negative exponent from -1 to+-- -2 and back for as long as the stack held. exponentiation :: Integer -> Integer -> Integer -> Integer exponentiation b e m- | b == 1 = b+ | m == 1 = 0+ | e < 0 =+ maybe 0 (\bInv -> exponentiation bInv (negate e) m) (inverse (b `mod` m) m)+ | b == 1 = 1 | e == 0 = 1 | e == 1 = b `mod` m | even e =@@ -240,20 +250,56 @@ -- bits it is given, and a nonce inverted that way has been taken apart before -- by watching the steps go by. ----- The moduli this is for -- the order of a group -- are prime, so the inverse--- comes from 'inverseFermat' instead. When the modulus is not prime, that--- answer is not an inverse, and the result is checked and 'inverse' asked--- instead, so this agrees with 'inverse' on every input. That fallback is--- reached only by parameters that are already broken.+-- The answer comes from a fixed number of division steps where the assembly+-- for them is built, and from 'inverseFermat' where it is not. Either way it+-- is checked here by multiplying out: neither one says when the number has no+-- inverse -- the first returns something that is not one and the second+-- returns something that is not one either -- so the check is what makes this+-- agree with 'inverse' on every input, and 'inverse' is asked when it fails.+-- That fallback is reached only by parameters that are already broken. ----- It costs what an exponentiation costs: around thirty times an 'inverse'--- for a 256-bit modulus.+-- The division steps cost about a twentieth of the exponentiation: on an+-- Apple M4, inverting modulo the P-256 group order is 0.80 microseconds+-- against 6.02, and modulo the P-521 one 2.05 against 63.2. inverseSafe :: Integer -> Integer -> Maybe Integer inverseSafe g m | m > 1 && (g * r) `mod` m == 1 = Just r | otherwise = inverse g m where- r = inverseFermat g m+ r = case inverseSec g m of+ Just v -> v+ Nothing -> inverseFermat g m++-- | The inverse in a fixed number of division steps, from the vendored+-- assembly. 'Nothing' when that is not built, when the modulus is even --+-- where the routine answers without saying it cannot -- or when the numbers+-- are larger than it keeps room for. The answer is not checked here; the+-- caller does that.+inverseSec :: Integer -> Integer -> Maybe Integer+inverseSec g m+ | m <= 1 || even m || g < 0 = Nothing+ | otherwise = unsafeDoIO $+ allocaBytes (3 * mLen) $ \out -> do+ let gp = out `plusPtr` mLen+ mp = gp `plusPtr` mLen+ _ <- Internal.i2ospOf (g `mod` m) gp mLen+ _ <- Internal.i2ospOf m mp mLen+ r <- c_modinv_sec out gp mp (fromIntegral mLen)+ if r == 0+ then do+ !v <- Internal.os2ip out mLen+ return (Just v)+ else return Nothing+ where+ !mLen = numBytes m++foreign import ccall unsafe "crypton_modinv_sec"+ c_modinv_sec+ :: Ptr Word8+ -> Ptr Word8+ -> Ptr Word8+ -> Word32+ -> IO CInt -- | Raised when the assumption about the modulus is invalid. data ModulusAssertionError = ModulusAssertionError
Crypto/Number/Serialize/Internal.hs view
@@ -53,7 +53,12 @@ !padSz = ptrSz - sz fillPtr :: Ptr Word8 -> Int -> Integer -> IO ()-fillPtr p sz m = gmpExportInteger m p `onGmpUnsupported` export (sz - 1) m+fillPtr p sz m+ -- zero is no bytes wide, and the callers above have already written the+ -- room out as zeros. Without this the loop below starts at offset -1,+ -- never meets the 0 it stops at, and walks backwards out of the buffer.+ | sz <= 0 = return ()+ | otherwise = gmpExportInteger m p `onGmpUnsupported` export (sz - 1) m where export ofs i | ofs == 0 = pokeByteOff p ofs (fromIntegral i :: Word8)
Crypto/PubKey/Curve25519.hs view
@@ -1,5 +1,4 @@ {-# LANGUAGE GeneralizedNewtypeDeriving #-}-{-# LANGUAGE MagicHash #-} {-# LANGUAGE ScopedTypeVariables #-} -- |@@ -31,7 +30,6 @@ import Data.Word import Foreign.Ptr import Foreign.Storable-import GHC.Ptr import Crypto.Error import Crypto.Internal.ByteArray (@@ -114,20 +112,19 @@ $ \result -> withByteArray sec $ \psec -> withByteArray pub $ \ppub ->- ccrypton_curve25519 result psec ppub+ ccrypton_x25519 result psec ppub {-# NOINLINE dh #-} -- | Create a public key from a secret key+-- The base point does not go in: where the assembly is built there is a table+-- for this, and it is four to five times less work than multiplying the point+-- 9 the general way. toPublic :: SecretKey -> PublicKey toPublic (SecretKey sec) = PublicKey <$> B.allocAndFreeze 32 $ \result -> withByteArray sec $ \psec ->- ccrypton_curve25519 result psec basePoint- where- basePoint =- Ptr- "\x09\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00\x00"#+ ccrypton_x25519_base result psec {-# NOINLINE toPublic #-} -- | Generate a secret key.@@ -142,12 +139,20 @@ modifyByte :: Ptr Word8 -> Int -> (Word8 -> Word8) -> IO () modifyByte p n f = peekByteOff p n >>= pokeByteOff p n . f -foreign import ccall "crypton_curve25519_donna"- ccrypton_curve25519+foreign import ccall "crypton_x25519"+ ccrypton_x25519 :: Ptr Word8 -- ^ public -> Ptr Word8 -- ^ secret -> Ptr Word8 -- ^ basepoint+ -> IO ()++foreign import ccall "crypton_x25519_base"+ ccrypton_x25519_base+ :: Ptr Word8+ -- ^ public+ -> Ptr Word8+ -- ^ secret -> IO ()
Crypto/PubKey/ECC/P256.hs view
@@ -413,8 +413,6 @@ foreign import ccall "crypton_p256e_scalar_invert" ccrypton_p256e_scalar_invert :: Ptr P256Scalar -> Ptr P256Scalar -> IO () --- foreign import ccall "crypton_p256_modinv"--- ccrypton_p256_modinv :: Ptr P256Scalar -> Ptr P256Scalar -> Ptr P256Scalar -> IO () foreign import ccall "crypton_p256_modinv_vartime" ccrypton_p256_modinv_vartime :: Ptr P256Scalar -> Ptr P256Scalar -> Ptr P256Scalar -> IO ()
Crypto/PubKey/ECDSA.hs view
@@ -48,6 +48,11 @@ signDigest, verify, verifyDigest,++ -- * Deterministic nonces+ deterministicNonce,+ signDeterministic,+ signDigestDeterministic, ) where import Control.Monad@@ -58,8 +63,10 @@ import Crypto.Hash import Crypto.Internal.ByteArray (ByteArray, ByteArrayAccess) import Crypto.Internal.Imports-import Crypto.Number.ModArithmetic (inverseFermat)+import Crypto.Number.Generate (generatePrefix)+import Crypto.Number.ModArithmetic (inverseSafe) import qualified Crypto.PubKey.ECC.P256 as P256+import Crypto.Random.HmacDRG (initial, update) import Crypto.Random.Types import Data.Bits@@ -257,6 +264,75 @@ verify prx hashAlg q sig msg = verifyDigest prx q sig (hashWith hashAlg msg) -- | Truncate a digest based on curve order size.+-- | Deterministic nonce generation according to RFC 6979.+--+-- The nonce is derived from the private key and the message alone, so a+-- signature made this way needs no random number generator and cannot be the+-- one that repeats a nonce -- which, for ECDSA, hands over the private key.+--+-- The hash used to seed the generator is given separately from the one the+-- message was digested with, as RFC 6979 allows.+--+-- The last argument is what to do with a candidate nonce. It may answer+-- 'Nothing', in which case another candidate is drawn, which is what+-- 'signDigestDeterministic' does for the r or s that comes out zero:+--+-- > deterministicNonce prx SHA256 priv digest (\k -> signDigestWith prx k priv digest)+deterministicNonce+ :: (EllipticCurveECDSA curve, HashAlgorithm hashDRG, HashAlgorithm hashDigest)+ => proxy curve+ -> hashDRG+ -> PrivateKey curve+ -> Digest hashDigest+ -> (Scalar curve -> Maybe a)+ -> a+deterministicNonce prx alg d digest go = fst $ withDRG state run+ where+ state = update seed $ initial alg+ -- RFC 6979 section 3.2 step d: int2octets(x) || bits2octets(h1). The+ -- second is the truncated digest taken modulo the order, which is what+ -- scalarAdd with zero does, its contract being to reduce there.+ seed =+ B.append (encodeScalar prx d) (encodeScalar prx z)+ :: B.ScrubbedBytes+ z = scalarAdd prx (tHashDigest prx digest) zeroScalar+ zeroScalar = throwCryptoError $ scalarFromInteger prx 0+ run = do+ k <- generatePrefix (curveOrderBits prx)+ case scalarFromInteger prx k of+ CryptoPassed s+ | scalarIsValid prx s -> maybe run pure (go s)+ _ -> run++-- | Sign a digest with a nonce derived from the private key and the digest,+-- as RFC 6979 says, rather than from a random number generator.+signDigestDeterministic+ :: (EllipticCurveECDSA curve, HashAlgorithm hashDRG, HashAlgorithm hashDigest)+ => proxy curve+ -> hashDRG+ -> PrivateKey curve+ -> Digest hashDigest+ -> Signature curve+signDigestDeterministic prx alg d digest =+ deterministicNonce prx alg d digest $ \k -> signDigestWith prx k d digest++-- | Sign a message with a nonce derived from the private key and the message,+-- as RFC 6979 says, rather than from a random number generator.+signDeterministic+ :: ( EllipticCurveECDSA curve+ , HashAlgorithm hashDRG+ , HashAlgorithm hash+ , ByteArrayAccess msg+ )+ => proxy curve+ -> hashDRG+ -> PrivateKey curve+ -> hash+ -> msg+ -> Signature curve+signDeterministic prx alg d hashAlg msg =+ signDigestDeterministic prx alg d (hashWith hashAlg msg)+ tHashDigest :: (EllipticCurveECDSA curve, HashAlgorithm hash) => proxy curve -> Digest hash -> Scalar curve@@ -296,15 +372,16 @@ => Simple.Scalar curve -> Bool ecScalarIsZero (Simple.Scalar a) = a == 0 +-- | 'inverseSafe' is the one that takes a fixed number of division steps+-- where the assembly for them is built, and checks whatever it gets by+-- multiplying out. It answers 'Nothing' exactly where the exponentiation+-- this used to do answered zero. ecScalarInv :: Simple.Curve c => proxy c -> Simple.Scalar c -> Maybe (Simple.Scalar c)-ecScalarInv prx (Simple.Scalar s)- | i == 0 = Nothing- | otherwise = Just $ Simple.Scalar i+ecScalarInv prx (Simple.Scalar s) = Simple.Scalar <$> inverseSafe s n where n = Simple.curveEccN $ Simple.curveParameters prx- i = inverseFermat s n ecPointX :: Simple.Curve c
Crypto/PubKey/RSA/OAEP.hs view
@@ -181,10 +181,9 @@ -- | Decrypt a ciphertext using OAEP ----- When the signature is not in a context where an attacker could gain--- information from the timing of the operation, the blinder can be set to None.------ If unsure always set a blinder or use decryptSafer+-- The blinder is optional and 'Nothing' is accepted, but see t'Blinder' for+-- what it covers and when leaving it out is a decision rather than a default.+-- 'decryptSafer' generates one for you. -- -- Following RFC 8017, the ciphertext is rejected unless it is exactly as long -- as the modulus (section 7.1.2, step 1) and its integer representative is
Crypto/PubKey/RSA/PKCS15.hs view
@@ -453,10 +453,9 @@ -- | decrypt message using the private key. ----- When the decryption is not in a context where an attacker could gain--- information from the timing of the operation, the blinder can be set to None.------ If unsure always set a blinder or use decryptSafer+-- The blinder is optional and 'Nothing' is accepted, but see t'Blinder' for+-- what it covers and when leaving it out is a decision rather than a default.+-- 'decryptSafer' generates one for you. -- -- The message is returned un-padded. --@@ -508,10 +507,9 @@ -- | sign message using private key, a hash and its ASN1 description ----- When the signature is not in a context where an attacker could gain--- information from the timing of the operation, the blinder can be set to None.------ If unsure always set a blinder or use signSafer+-- The blinder is optional and 'Nothing' is accepted, but see t'Blinder' for+-- what it covers and when leaving it out is a decision rather than a default.+-- 'signSafer' generates one for you. sign :: HashAlgorithmASN1 hashAlg => Maybe Blinder
Crypto/PubKey/RSA/PSS.hs view
@@ -28,7 +28,7 @@ import Crypto.PubKey.RSA.Prim import Crypto.PubKey.RSA.Types import Crypto.Random.Types-import Data.Bits (shiftR, xor, (.&.))+import Data.Bits (complement, shiftR, xor, (.&.)) import Data.Word import Crypto.Internal.ByteArray (ByteArray, ByteArrayAccess)@@ -69,6 +69,9 @@ -- | Sign using the PSS parameters and the salt explicitely passed as parameters. -- -- the function ignore SaltLength from the PSS Parameters+--+-- See t'Blinder' for what the optional blinder covers and when leaving it out+-- is a decision rather than a default. 'signSafer' generates one for you. signDigestWithSalt :: HashAlgorithm hash => ByteString@@ -103,6 +106,9 @@ -- | Sign using the PSS parameters and the salt explicitely passed as parameters. -- -- the function ignore SaltLength from the PSS Parameters+--+-- See t'Blinder' for what the optional blinder covers and when leaving it out+-- is a decision rather than a default. 'signSafer' generates one for you. signWithSalt :: HashAlgorithm hash => ByteString@@ -121,6 +127,9 @@ mHash = hashWith (pssHash params) m -- | Sign using the PSS Parameters+--+-- See t'Blinder' for what the optional blinder covers and when leaving it out+-- is a decision rather than a default. 'signSafer' generates one for you. sign :: (HashAlgorithm hash, MonadRandom m) => Maybe Blinder@@ -137,6 +146,9 @@ return (signWithSalt salt blinder params pk m) -- | Sign using the PSS Parameters+--+-- See t'Blinder' for what the optional blinder covers and when leaving it out+-- is a decision rather than a default. 'signSafer' generates one for you. signDigest :: (HashAlgorithm hash, MonadRandom m) => Maybe Blinder@@ -221,6 +233,7 @@ | B.length s /= k = False | os2ip s >= public_n pk = False | B.any (/= 0) pre = False+ | B.any (\x -> x .&. topBits /= 0) (B.take 1 maskedDB) = False | B.last em /= pssTrailerField params = False | B.any (/= 0) ps0 = False | b1 /= B.singleton 1 = False@@ -234,6 +247,13 @@ emLen = if emTruncate pubBits then k - 1 else k dbLen = emLen - hashLen - 1 pubBits = numBits (public_n pk)+ -- RFC 8017 9.1.2 step 6: the leftmost 8*emLen - emBits bits of the+ -- leftmost octet of maskedDB have to be zero already. Step 9 clears+ -- them in DB, which is what normalizeToKeySize does below, and clearing+ -- is not checking: without this an encoding with the top bit set -- one+ -- the standard calls inconsistent -- verifies as though it were sound,+ -- because the bit that made it wrong is thrown away before it is read.+ topBits = complement (normalizeMask pubBits) -- unmarshall fields (pre, em) = B.splitAt (k - emLen) (ep pk s) -- drop 0..1 byte maskedDB = B.take dbLen em@@ -251,7 +271,12 @@ normalizeToKeySize :: Int -> [Word8] -> [Word8] normalizeToKeySize _ [] = [] -- very unlikely-normalizeToKeySize bits (x : xs) = x .&. mask : xs+normalizeToKeySize bits (x : xs) = x .&. normalizeMask bits : xs++-- | The bits of the leftmost octet that belong to the encoding: the low+-- @emBits `mod` 8@ of them, or all eight when that is zero. Its complement+-- is the bits RFC 8017 requires to be zero.+normalizeMask :: Int -> Word8+normalizeMask bits = if sh > 0 then 0xff `shiftR` (8 - sh) else 0xff where- mask = if sh > 0 then 0xff `shiftR` (8 - sh) else 0xff sh = (bits - 1) .&. 0x7
Crypto/PubKey/RSA/Types.hs view
@@ -27,8 +27,32 @@ import GHC.Generics --- | Blinder which is used to obfuscate the timing--- of the decryption primitive (used by decryption and signing).+-- | A blinder, which keeps the timing of the private key operation from+-- saying anything about the number it was given.+--+-- The private exponent is not what is at risk. 'Crypto.Number.ModArithmetic.expSafe',+-- which the exponentiation goes through, keeps the /value/ of an exponent out+-- of the work it does.+--+-- What a blinder covers is the other side. Without one, the operation runs+-- on the ciphertext as it arrived, so how long it takes depends on a number+-- an attacker may have chosen and can vary -- which is what a remote timing+-- attack on RSA needs. With one, the input is multiplied by a random value+-- first and that value divided out afterwards, so the timing carries nothing+-- an attacker can steer.+--+-- Every private key operation here takes a @'Maybe' t'Blinder'@. The+-- @Safer@ form of each -- 'Crypto.PubKey.RSA.PKCS15.decryptSafer',+-- 'Crypto.PubKey.RSA.PKCS15.signSafer' and their kind -- generates one and is+-- the one to reach for. Pass 'Nothing' only where the input is not attacker+-- controlled and you have decided that it is not.+--+-- A blinder costs one more exponentiation, by the public exponent, which is+-- the cheap direction: measured on an Apple M4, PKCS#1 v1.5 signing goes from+-- about 601 to about 620 microseconds.+--+-- Use a blinder once. 'Crypto.PubKey.RSA.generateBlinder' makes a fresh one;+-- carrying one across operations is not what it is for. data Blinder = Blinder !Integer !Integer deriving (Show, Eq)
LICENSE view
@@ -1,4 +1,5 @@ Copyright (c) 2006-2015 Vincent Hanquez <vincent@snarc.org>+Copyright (c) 2023-2026 Kazu Yamamoto <kazu@iij.ad.jp> All rights reserved.
README.md view
@@ -3,24 +3,78 @@ crypton ========== -Crypton is a fork from cryptonite with the original author's permission.+`crypton` is a fork from `cryptonite` with the original author's permission. -Crypton is a haskell repository of cryptographic primitives. Each crypto-algorithm has specificities that are hard to wrap in common APIs and types,-so instead of trying to provide a common ground for algorithms, this package-provides a non-consistent low-level API. -If you have no idea what you're doing, please do not use this directly.-Instead, rely on higher level protocols or implementations.+`crypton` is a low-level cryptography library. To achieve high+performance, it utilizes C and assembly language to define FFI+bindings, structuring them in a way that makes them easy to use. ++Side channels+-------------++AES is where this matters most, and which implementation runs is decided at+runtime from what the processor has.++On x86-64 with AES-NI and carry-less multiply, and on AArch64 with the ARMv8+cryptographic extension, AES and GHASH are instructions rather than tables.+crypton's AES and AES-GCM then make no branch and no memory access that+depends on the key or on the data: the secrets stay in vector registers and+never reach one a branch can test, which the generated code is checked+against. Every x86-64 part since about 2010 and every AArch64 part in+ordinary use has these.++Where neither is present crypton falls back to a table-driven AES, which+indexes a 256-byte substitution table with data derived from the key and the+input. **That is not constant time**, and on a machine where an attacker can+observe the cache it is open to a timing attack. The fallback exists so that+the library builds and runs everywhere; it is not meant for a setting where+that matters.++`Crypto.System.CPU.processorOptions` says which is in use. `AESNI` in that+list means the instruction path, and `PCLMUL` that GHASH has its instruction+too; without `AESNI` it is the tables. The list also reports `RDRAND`, which+is unrelated to this.++ ghci> import Crypto.System.CPU+ ghci> processorOptions+ [AESNI,PCLMUL]++RSA is the other place to know about, and there the choice is the caller's.+The private key operations in `Crypto.PubKey.RSA.PKCS15`, `.OAEP` and `.PSS`+take a `Maybe Blinder`, and `Nothing` is no harder to write than the safe+form:++ decrypt :: Maybe Blinder -> PrivateKey -> ByteString -> ...+ decryptSafer :: MonadRandom m => PrivateKey -> ByteString -> m ...++The exponent itself is not what is at risk. `expSafe` keeps the *value* of an+exponent out of the work it does, so the private exponent does not leak+through the exponentiation. What a blinder covers is the other side: without+one, the operation runs on the ciphertext the caller was handed, so how long+it takes depends on a number an attacker may have chosen and can vary. That+is what a remote timing attack on RSA needs. With a blinder the input is+multiplied by a random value first and the result divided out afterwards, so+the timing carries nothing an attacker can steer.++`decryptSafer` and `signSafer` generate the blinder themselves and are the+ones to reach for. Pass `Nothing` only where the input is not attacker+controlled and you have decided that it is not.++The RSA rows in the tables below are the unblinded path. A blinder costs one+more exponentiation, by the public exponent, which is the cheap direction:+measured on the M4, signing goes from about 460 to about 476 microseconds,+under four per cent.+ Performance ----------- -The algorithms a TLS connection uses, measured against the previous release-and against OpenSSL on the same machine. Throughput is over 16 KiB messages;-the public key operations are one operation each; every figure is the best of-several runs, and crypton and OpenSSL are run alternately so that neither gets-the quieter machine.+The algorithms a TLS connection uses, measured against the last release+before the rewrite and against OpenSSL on the same machine. Throughput is+over 16 KiB messages; the public key operations are one operation each; every+figure is the best of several runs, and crypton and OpenSSL are run+alternately so that neither gets the quieter machine. Bulk encryption and hashing are measured through crypton's C layer, as `openssl speed` measures OpenSSL's. The public key operations are measured@@ -28,123 +82,171 @@ is what a program actually calls; the Haskell layer adds well under a microsecond, which the X25519 and ECDH P-256 rows confirm by agreeing with a C-level measurement to within a percent. Both releases of crypton are built-the same way -- `-optc-O3`, which is what both of them ask for -- and each-column of a table comes from one run on the machine named above it.+the same way -- `-optc-O3`, which is what each asks for -- and by+`cabal build`, since a copy of the sources compiled by hand does not measure+what a program linking the library gets, and leaves out whole implementations+without saying so. Each column of a table comes from one run on the machine+named above it. ### x86-64 -An AMD EPYC 7763, which has AES-NI, PCLMULQDQ, AVX2, ADX and the SHA-extensions, against OpenSSL 3.0.13.+An AMD EPYC 7763, which has AES-NI, PCLMULQDQ, AVX2, ADX, VAES, VPCLMULQDQ+and the SHA extensions, against OpenSSL 4.0.3. Throughput in MB/s, **higher is better**: -| | crypton 1.1.5 | crypton 2.0.0 | OpenSSL | 2.0.0 / OpenSSL |+| | crypton 1.1.5 | crypton 2.1.5 | OpenSSL | 2.1.5 / OpenSSL | | --- | ---: | ---: | ---: | ---: |-| AES-128-GCM | 1331 | 4118 | 4264 | 0.97 |-| AES-256-GCM | 1090 | 3810 | 3951 | 0.96 |-| ChaCha20-Poly1305 | 398 | 2195 | 2191 | 1.00 |-| SHA-1 | 738 | 1678 | 1672 | 1.00 |-| SHA-256 | 286 | 1585 | 1570 | 1.01 |-| SHA-512 | 448 | 769 | 746 | 1.03 |-| SHA3-256 | 109 | 421 | 426 | 0.99 |+| AES-128-GCM | 1362 | **6038** | 4055 | 1.49 |+| AES-256-GCM | 1093 | **5462** | 3770 | 1.45 |+| ChaCha20-Poly1305 | 399 | 2211 | 2229 | 0.99 |+| SHA-1 | 727 | 1678 | 1673 | 1.00 |+| SHA-256 | 290 | 1585 | 1579 | 1.00 |+| SHA-512 | 463 | 804 | 751 | 1.07 |+| SHA3-256 | 109 | 424 | 425 | 1.00 | -Time per operation in microseconds, **lower is better** -- so the last column-divides OpenSSL's time by crypton's, and is again better the larger it is:+Time per operation in microseconds, **lower is better**: -| | crypton 1.1.5 | crypton 2.0.0 | OpenSSL | OpenSSL / 2.0.0 |+| | crypton 1.1.5 | crypton 2.1.5 | OpenSSL | OpenSSL / 2.1.5 | | --- | ---: | ---: | ---: | ---: |-| X25519 | 43.57 | 43.52 | 36.58 | 0.84 |-| ECDH P-256 | 163.8 | 163.7 | 52.36 | 0.32 |-| ECDH P-384 | 2241 | 1101 | 857.1 | 0.78 |-| Ed25519 sign | 28.52 | 28.25 | 43.49 | 1.54 |-| Ed25519 verify | 46.06 | 46.16 | 119.3 | 2.59 |-| ECDSA P-256 sign | 76.04 | 75.02 | 22.91 | 0.31 |-| ECDSA P-256 verify | 229.2 | 228.5 | 67.98 | 0.30 |-| ECDSA P-384 sign | 2271 | 387.6 | 904.3 | 2.33 |-| ECDSA P-384 verify | 2667 | 1493 | 746.2 | 0.50 |-| RSA-2048 sign/decrypt | 759.8 | 1311 | 660.1 | 0.50 |-| RSA-2048 verify/encrypt | 31.62 | 28.59 | 18.63 | 0.65 |+| X25519 | 45.31 | 28.41 | 36.48 | 1.28 |+| ECDH P-256 | 165.4 | 51.14 | 51.65 | 1.01 |+| ECDH P-384 | 2278 | **165.0** | 847.5 | 5.13 |+| Ed25519 sign | 30.03 | 18.62 | 33.71 | 1.81 |+| Ed25519 verify | 48.05 | 47.66 | 110.6 | 2.32 |+| ECDSA P-256 sign | 81.70 | 18.96 | 21.87 | 1.15 |+| ECDSA P-256 verify | 233.3 | 70.47 | 67.52 | 0.96 |+| ECDSA P-384 sign | 2264 | **303.4** | 890.1 | 2.93 |+| ECDSA P-384 verify | 2676 | **471.4** | 721.5 | 1.53 |+| RSA-2048 sign/decrypt | 759.4 | 612.0 | 659.4 | 1.08 |+| RSA-2048 verify/encrypt | 33.56 | 30.21 | 18.86 | 0.62 | ### AArch64 An Apple M4, which has the AES, PMULL, SHA-1, SHA-2, SHA-512 and SHA-3-instructions, against OpenSSL 3.6.4.+instructions, against OpenSSL 4.0.3. Throughput in MB/s, **higher is better**: -| | crypton 1.1.5 | crypton 2.0.0 | OpenSSL | 2.0.0 / OpenSSL |+| | crypton 1.1.5 | crypton 2.1.5 | OpenSSL | 2.1.5 / OpenSSL | | --- | ---: | ---: | ---: | ---: |-| AES-128-GCM | 126 | 8702 | 10719 | 0.81 |-| AES-256-GCM | 98 | 7648 | 9154 | 0.84 |-| ChaCha20-Poly1305 | 758 | 2323 | 2244 | 1.04 |-| SHA-1 | 1199 | 3380 | 3346 | 1.01 |-| SHA-256 | 467 | 3394 | 3352 | 1.01 |-| SHA-512 | 723 | 1868 | 1851 | 1.01 |-| SHA3-256 | 548 | 1091 | 1054 | 1.04 |+| AES-128-GCM | 127 | **12422** | 10846 | 1.15 |+| AES-256-GCM | 98 | **9721** | 9197 | 1.06 |+| ChaCha20-Poly1305 | 771 | 2319 | 2250 | 1.03 |+| SHA-1 | 1209 | 3389 | 3361 | 1.01 |+| SHA-256 | 474 | 3400 | 3362 | 1.01 |+| SHA-512 | 730 | 1880 | 1883 | 1.00 |+| SHA3-256 | 550 | 1075 | 1065 | 1.01 | -Time per operation in microseconds, **lower is better**; the last column again-divides OpenSSL's time by crypton's:+Time per operation in microseconds, **lower is better**: -| | crypton 1.1.5 | crypton 2.0.0 | OpenSSL | OpenSSL / 2.0.0 |+| | crypton 1.1.5 | crypton 2.1.5 | OpenSSL | OpenSSL / 2.1.5 | | --- | ---: | ---: | ---: | ---: |-| X25519 | 18.44 | 18.41 | 18.41 | 1.00 |-| ECDH P-256 | 69.46 | 56.24 | 24.68 | 0.44 |-| ECDH P-384 | 3252 | 511.1 | 379.7 | 0.74 |-| Ed25519 sign | 13.75 | 13.14 | 15.90 | 1.21 |-| Ed25519 verify | 18.17 | 18.04 | 39.27 | 2.18 |-| ECDSA P-256 sign | 32.56 | 27.91 | 11.05 | 0.40 |-| ECDSA P-256 verify | 96.50 | 80.19 | 32.82 | 0.41 |-| ECDSA P-384 sign | 3219 | 169.3 | 403.4 | 2.38 |-| ECDSA P-384 verify | 3807 | 688.1 | 335.1 | 0.49 |-| RSA-2048 sign/decrypt | 451.8 | 605.4 | 325.0 | 0.54 |-| RSA-2048 verify/encrypt | 18.32 | 15.28 | 8.50 | 0.56 |+| X25519 | 18.27 | **12.22** | 15.53 | 1.27 |+| ECDH P-256 | 68.70 | **20.43** | 24.77 | 1.21 |+| ECDH P-384 | 3328 | **73.50** | 372.6 | 5.07 |+| Ed25519 sign | 13.58 | **7.75** | 13.23 | 1.71 |+| Ed25519 verify | 18.28 | 18.17 | 34.76 | 1.91 |+| ECDSA P-256 sign | 31.97 | **6.55** | 10.92 | 1.67 |+| ECDSA P-256 verify | 95.63 | **26.80** | 32.68 | 1.22 |+| ECDSA P-384 sign | 3219 | **124.1** | 394.2 | 3.18 |+| ECDSA P-384 verify | 3870 | **203.1** | 326.5 | 1.61 |+| RSA-2048 sign/decrypt | 447.9 | 460.1 | 319.9 | 0.70 |+| RSA-2048 verify/encrypt | 18.23 | 15.12 | 8.405 | 0.56 | ### What the numbers say -1.1.5 had no AArch64 code of its own at all, which is why AES-GCM there is-sixty-nine times what it was. On x86-64 it had AES-NI and nothing else. The-curves over a prime field other than P-256 moved from Haskell `Integer`-arithmetic into C, which is the nineteenfold change in ECDSA P-384 signing on-the M4. X25519 and Ed25519 are unchanged between the two releases, and the-rows say so: where they differ by half a percent, that is the measurement and-not the code. P-256 is unchanged on x86-64 and a fifth faster on AArch64,-which is the paragraph below.+There are two changes behind the 1.1.5 column and the 2.1.5 one, not a+single steady improvement. -Where crypton is behind, it is behind for three separate reasons.+The first, in 2.0.0, was a rewrite: the bulk algorithms moved into C, the+curves other than P-256 moved out of Haskell `Integer` arithmetic, and+everything that touches a secret was made to take the same time whatever the+secret is. 1.1.5 had no AArch64 code of its own at all, which is why AES-GCM+there is close to a hundred times what it was, and on x86-64 it had AES-NI+and nothing else. -*P-256.* crypton's field arithmetic is C where OpenSSL's is hand-written-assembly, and that is what is left of the difference: the two differ by about-the same factor on every P-256 row, and nothing above the field -- a wider-window, a different addition formula, another field representation -- recovers-a useful part of it.+The second, from 2.1.0 onwards, is assembly, for the operations where C+cannot reach. Which of the two a row owes its gain to is not the same+everywhere: ECDSA P-384 signing took nineteenfold from the rewrite and a+further fifth from the assembly, while X25519 waited for the assembly+entirely and ECDH P-384 is almost all of it. -The AArch64 rows are better than the x86-64 ones because of where a field-multiplication's latency goes. It ends in a carry chain the width of the-number, and the curve arithmetic has independent products that could cover-that chain -- but only if the compiler inlines the reduction instead of-calling it, since a call is a fence. Asking it to costs code and pays where-there are registers enough to hold two chains at once: a quarter on AArch64,-where there are thirty-one, and nothing on x86-64, where there are fifteen and-the same request makes it slower. So x86-64 is left to the compiler's own-judgement and stays at 0.3.+Most of that assembly is not crypton's. The prime curves, the inverse modulo+a group order, X25519, and RSA's Montgomery multiplication on x86-64 go+through [s2n-bignum](https://github.com/awslabs/s2n-bignum), vendored in+`cbits/s2n`. Every routine in it carries a machine-checked proof in+HOL-Light that it computes what it says, and is written in a constant-time+style. It is `Apache-2.0 OR ISC OR MIT-0`, and crypton takes it under ISC. -*RSA signing.* 2.0.0 is slower than 1.1.5 here on purpose. Its modular-exponentiation no longer indexes a table with the bits of the exponent, and-hiding the exponent is what the difference buys. What is left of the gap-against OpenSSL is the Montgomery multiplication, which is assembly there and-C here.+That licence is why any of this was possible. The obvious assembly to reach+for is OpenSSL's and BoringSSL's `ecp_nistz256`, and it cannot be used here:+it is Apache-2.0 only, and Intel and CloudFlare hold copyright in it besides+OpenSSL, so nobody is in a position to relicense it. -*The AVX-512 instructions.* Neither machine above has them. On one that does--- an EPYC 9V74, measured the same way -- OpenSSL uses them for AES-GCM and-ChaCha20 and reaches 12003 and 3789 MB/s, against 4745 and 2372 for crypton,-whose vendored assembly is generated without them. Those ratios are 0.40 and-0.63 rather than 0.97 and 1.00. Nothing else in either table moves by more-than a few percent between the two processors.+Where crypton is behind, which is now the RSA rows on both architectures and+ECDSA P-256 verification on x86-64, there is one reason. The AES-GCM rows+were the other half of this section until 2.1.5; they are ahead on both+machines now, and what the instructions do is still worth setting out. +*RSA.* 2.0.0 made signing slower than 1.1.5 on purpose: its modular+exponentiation stopped indexing a table with the bits of the exponent, and+hiding the exponent is what the difference bought. On x86-64 that cost is+more than repaid -- s2n-bignum's Montgomery multiplication is twice the C's,+because the C cannot form the two carry chains `ADCX` and `ADOX` give, and+2.1.5 signs in less than 1.1.5 took while keeping what 2.0.0 gained. On+AArch64 there is nothing to use: s2n-bignum has no generic routine for it,+and the same five that help on x86-64 measure level with the C there, so the+C stays and the gap with it. No portable C closes that gap either -- the+measurements are in+[#275](https://github.com/kazu-yamamoto/crypton/issues/275). Verification+does not move much either way: its exponent is 65537, seventeen bits, and+there is no exponentiation to speak of.++*The wide AES instructions.* `VAES` and `VPCLMULQDQ` do two blocks where+`AES-NI` and `PCLMULQDQ` do one, and four in their 512-bit form. crypton uses+the 256-bit form where the processor has it, which is Zen 3 and Ice Lake+onwards, and the 512-bit form where that is worth having, which is Ice Lake and+Zen 5 onwards. There was nothing to borrow: the wide AES-GCM in OpenSSL,+BoringSSL and AWS-LC is Apache-2.0 and s2n-bignum has no GCM, so both files are+crypton's own.++Having the 256-bit one is where the 1.49 in the x86-64 table comes from, and+it is narrower than it sounds. The EPYC 7763 is Zen 3: VAES and VPCLMULQDQ,+no AVX-512. OpenSSL's x86-64 AES-GCM is `aesni-gcm-x86_64.pl`, which is+128-bit -- its `vaesenc`s are the VEX encoding of `AESENC` on `xmm`, and+there is not one `ymm` in the file -- or `aes-gcm-avx512.pl`, which wants+`AVX512VAES`. There is no rung between them, so on this processor OpenSSL+takes a block at a time where crypton takes two. The same idea as theirs,+one step further down the feature ladder; not a better one.++The 512-bit path arrived after 2.1.2, so it is in the 2.1.5 column -- but+neither machine in the tables above has AVX-512, so neither column shows it.+On the runners that do, measured over 16 KiB in MB/s: an EPYC 9V45 (Zen 5)+goes from 9616 to 14268 with it, a Xeon 6973P-C from 8095 to 9848, a Xeon+8573C from 6983 to 8447. OpenSSL on those machines is ahead still -- 25760+on the first of them -- because it interleaves the GHASH with the AES where+crypton does them in turn. Zen 4 keeps the 256-bit path: its 512-bit+instructions are two passes through a 256-bit datapath, so the wider encoding+buys nothing there and costs a little.++AArch64 has no counterpart to any of these: one AES block and one GHASH+multiplication at a time is all the instruction set offers. Its AES-GCM+rows were 0.85 and 0.87 until 2.1.5, for that reason. What closed it was+not width but the GHASH's representation -- H is twisted once at key setup+so that GCM's bit reflection is already undone, which turns a reduction of+some twenty-five shifts and XORs into two PMULL and six EOR and makes+Karatsuba worth taking. The scheme is ARM's, from the BSD-3-Clause part of+[AArch64cryptolib](https://github.com/ARM-software/AArch64cryptolib),+written out in crypton's own intrinsics. The AES there is ahead of+OpenSSL's and always was; it was the GHASH beside it that was behind.+ One row wants a word of its own: crypton's `Ed25519.sign` derives the public key from the secret key every time it signs, so that a caller who passes a public key that does not match cannot be made to leak the private one. That-costs a second scalar multiplication, which OpenSSL's signing does not pay.+costs a second scalar multiplication, which OpenSSL's signing does not pay --+and the row is still 1.71 on AArch64 and 1.81 on x86-64, so the safety is had+for nothing here rather than paid for. SHA-1 is in the tables because a number of protocols and file formats still ask for it, not because it is a good choice for anything new. The algorithms
benchs/Bench.hs view
@@ -195,7 +195,9 @@ where cp k (ini, plain) = let iniState =- throwCryptoError $ CP.initialize k (throwCryptoError $ CP.nonce12 nonce12)+ CP.initialize+ (throwCryptoError $ CP.key k)+ (throwCryptoError $ CP.nonce12 nonce12) afterAAD = CP.finalizeAAD (CP.appendAAD ini iniState) (out, afterEncrypt) = CP.encrypt plain afterAAD outtag = CP.finalize afterEncrypt
+ cbits/LICENSE.go view
@@ -0,0 +1,38 @@+The arrangement of the AArch64 multiply-accumulate loop in+cbits/crypton_bignum.h -- four limbs to an iteration, the low halves of the+products and the high halves accumulated in two chains -- follows+addMulVVWx in Go's crypto/internal/fips140/bigmod/nat_arm64.s, written out+in the assembler that file's compiler speaks. Go is at+https://github.com/golang/go and carries the licence below. That file's+own header reads "Copyright 2013 The Go Authors. All rights reserved. Use+of this source code is governed by a BSD-style license that can be found in+the LICENSE file", and the LICENSE file it means is this one.+++Copyright 2009 The Go Authors.++Redistribution and use in source and binary forms, with or without+modification, are permitted provided that the following conditions are+met:++ * Redistributions of source code must retain the above copyright+notice, this list of conditions and the following disclaimer.+ * Redistributions in binary form must reproduce the above+copyright notice, this list of conditions and the following disclaimer+in the documentation and/or other materials provided with the+distribution.+ * Neither the name of Google LLC nor the names of its+contributors may be used to endorse or promote products derived from+this software without specific prior written permission.++THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS+"AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT+LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR+A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT+OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,+SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT+LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,+DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY+THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT+(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE+OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ cbits/aes/LICENSE.fusion view
@@ -0,0 +1,29 @@+Parts of cbits/aes/gcm_fused_x86.c follow the AES-GCM implementation in+picotls, lib/fusion.c, which is under the MIT license reproduced below.+The design is described by its author at++ http://blog.kazuhooku.com/2020/06/quicaes-gcm-12.html+ http://blog.kazuhooku.com/2020/06/quicaes-gcm-22.html++and the source is at https://github.com/h2o/picotls.+++Copyright (c) 2020-2022 Fastly, Kazuho Oku++Permission is hereby granted, free of charge, to any person obtaining a copy+of this software and associated documentation files (the "Software"), to+deal in the Software without restriction, including without limitation the+rights to use, copy, modify, merge, publish, distribute, sublicense, and/or+sell copies of the Software, and to permit persons to whom the Software is+furnished to do so, subject to the following conditions:++The above copyright notice and this permission notice shall be included in+all copies or substantial portions of the Software.++THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING+FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS+IN THE SOFTWARE.
cbits/aes/armv8.c view
@@ -39,11 +39,7 @@ * * "+crypto" rather than "crypto": GCC rejects the latter. */-#ifdef WITH_TARGET_ATTRIBUTES-#define TARGET_ARMV8_CRYPTO __attribute__((target("+crypto")))-#else-#define TARGET_ARMV8_CRYPTO-#endif+#include "crypton_armv8_target.h" /* forward round keys: nbr + 1 of them, written by the generic key expansion */ #define FWD(key) ((const uint8_t *) (key)->data)@@ -70,14 +66,14 @@ * instructions exist to remove -- but a key schedule is the one thing an * attacker most wants and it costs little to keep it out of the cache. */-TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO static uint32x4_t sub_word(uint32x4_t w) { return vreinterpretq_u32_u8( vaeseq_u8(vreinterpretq_u8_u32(w), vdupq_n_u8(0))); } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO static uint32x4_t sub_rot_word(uint32x4_t w) { const uint8x16_t s = vreinterpretq_u8_u32(sub_word(w));@@ -85,7 +81,7 @@ return vreinterpretq_u32_u8(vextq_u8(s, s, 1)); } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void crypton_aes_armv8_init(aes_key *key, uint8_t *origkey, uint8_t size) { /* 2^0 .. 2^9 in GF(2^8), which is as far as any key size reaches */@@ -147,171 +143,182 @@ /* * GHASH using PMULL, the AArch64 counterpart to PCLMULQDQ. *- * This is a transliteration of gfmul_pclmuldq in x86ni.c rather than a fresh- * formulation: that code is already pinned by the GCM known-answer tests, and- * every operation it uses has a direct NEON equivalent, so translating it is- * easier to check than reasoning about a new reduction from scratch.+ * Not the transliteration of gfmul_pclmuldq in x86ni.c this used to be. The+ * x86 formulation keeps H in the order GCM writes it and pays, at the end of+ * every batch, a reduction that first has to undo GCM's bit reflection: some+ * twenty-five shifts and XORs, and a batch of eight costs it once. *- * _mm_shuffle_epi8 with a reversing mask -> vrev64q_u8 then vextq_u8- * _mm_clmulepi64_si128 -> vmull_p64 / vmull_high_p64- * _mm_slli_si128 / _mm_srli_si128 -> vextq_u8 against zero- * _mm_slli_epi32 / _mm_srli_epi32 -> vshlq_n_u32 / vshrq_n_u32+ * Instead H is twisted once, at key setup, so that the reflection is already+ * undone and a reversed-polynomial multiply lands in the right place. Two+ * things follow. The reduction becomes two PMULL against 0xC2000..0 and six+ * EOR, a third of what it was. And because nothing has to be byte-reversed+ * back and forth, Karatsuba pays: three PMULL a block rather than four, with+ * the middle terms accumulated in a third register and tidied up once per+ * batch.+ *+ * crypton tried Karatsuba in the old representation and measured it 1.6 per+ * cent slower -- the saved PMULL did not cover the extra EOR when the+ * reduction stayed as expensive as it was. It is the pair that pays.+ * Measured over 16 KiB messages, this against the old code:+ *+ * Apple M4 Neoverse N2+ * AES-128-GCM 1.30 1.25+ * AES-192-GCM 1.22 1.25+ * AES-256-GCM 1.19 1.24+ *+ * The scheme is ARM's, from the 'big' AES-GCM kernel of+ * https://github.com/ARM-software/AArch64cryptolib, which is BSD-3-Clause,+ * (c) 2018-2019 ARM Limited. Their kernels under AArch64cryptolib_opt_bigger+ * are faster again and are NOT under that licence, whatever the repository's+ * LICENSE.md says; nothing here comes from those files.+ *+ * The table holds the twisted powers H^1 .. H^8 at htable[0 .. 7] and the+ * Karatsuba half of each -- its high 64 bits XOR its low -- in the first+ * eight bytes of htable[8 .. 15]. The running tag is kept the way GCM+ * writes it at every boundary, and swapped into the internal form on the way+ * in and out, which is two instructions. */ -/* reverse all 16 bytes */-TARGET_ARMV8_CRYPTO-static inline uint8x16_t bswap128(uint8x16_t v)-{- return vextq_u8(vrev64q_u8(v), vrev64q_u8(v), 8);-}--/* shift the whole register left by n bytes, as _mm_slli_si128 does */-#define SHIFT_LEFT_BYTES(v, n) vextq_u8(vdupq_n_u8(0), (v), 16 - (n))-/* and right, as _mm_srli_si128 does */-#define SHIFT_RIGHT_BYTES(v, n) vextq_u8((v), vdupq_n_u8(0), (n))--#define SHL32(v, n) vreinterpretq_u8_u32(vshlq_n_u32(vreinterpretq_u32_u8(v), (n)))-#define SHR32(v, n) vreinterpretq_u8_u32(vshrq_n_u32(vreinterpretq_u32_u8(v), (n)))--TARGET_ARMV8_CRYPTO-static inline uint8x16_t clmul_ll(uint8x16_t a, uint8x16_t b)-{- return vreinterpretq_u8_p128(vmull_p64(- (poly64_t) vgetq_lane_u64(vreinterpretq_u64_u8(a), 0),- (poly64_t) vgetq_lane_u64(vreinterpretq_u64_u8(b), 0)));-}+#define GHASH_MODC ((poly64_t) 0xC200000000000000ul) -TARGET_ARMV8_CRYPTO-static inline uint8x16_t clmul_lh(uint8x16_t a, uint8x16_t b)+/* the internal accumulator form, and back again: its own inverse */+CRYPTON_TARGET_ARMV8_CRYPTO+static inline uint8x16_t ghash_swap(uint8x16_t t) {- return vreinterpretq_u8_p128(vmull_p64(- (poly64_t) vgetq_lane_u64(vreinterpretq_u64_u8(a), 0),- (poly64_t) vgetq_lane_u64(vreinterpretq_u64_u8(b), 1)));+ t = vrev64q_u8(t);+ return vextq_u8(t, t, 8); } -TARGET_ARMV8_CRYPTO-static inline uint8x16_t clmul_hl(uint8x16_t a, uint8x16_t b)+/* the high and low halves XORed together, which is what Karatsuba wants */+CRYPTON_TARGET_ARMV8_CRYPTO+static inline poly64_t ghash_karat(poly64x2_t v) {- return vreinterpretq_u8_p128(vmull_p64(- (poly64_t) vgetq_lane_u64(vreinterpretq_u64_u8(a), 1),- (poly64_t) vgetq_lane_u64(vreinterpretq_u64_u8(b), 0)));+ return (poly64_t) veor_u64(vget_high_u64(vreinterpretq_u64_p64(v)),+ vget_low_u64(vreinterpretq_u64_p64(v))); } -TARGET_ARMV8_CRYPTO-static inline uint8x16_t clmul_hh(uint8x16_t a, uint8x16_t b)-{- return vreinterpretq_u8_p128(vmull_high_p64(- vreinterpretq_p64_u8(a), vreinterpretq_p64_u8(b)));-}+/* the twisted power H^(i+1) */+#define GHASH_POW(ht, i) \+ vreinterpretq_p64_u8(vld1q_u8((const uint8_t *) &(ht)[i]))+/* and its Karatsuba half */+#define GHASH_KARAT(ht, i) \+ ((poly64_t) vgetq_lane_u64( \+ vreinterpretq_u64_u8(vld1q_u8((const uint8_t *) &(ht)[8 + (i)])), 0)) /*- * The 256-bit carry-less product of a (normal byte order) and b (already- * reversed, as it sits in the table), before the reflection fixup and the- * reduction. Split out from the reduction because both of those are linear- * over XOR: several products can be added together and fixed up just once,- * which is what gf_mul4 below does.+ * One block's three partial products, XORed into the accumulators. b is+ * already in the internal form; hp and hk are the power it is to meet. */-TARGET_ARMV8_CRYPTO-static inline void clmul_pmull(uint8x16_t a, uint8x16_t b,- uint8x16_t *lo, uint8x16_t *hi)-{- uint8x16_t t3, t4, t5, t6;-- a = bswap128(a);-- t3 = clmul_ll(a, b);- t4 = clmul_lh(a, b);- t5 = clmul_hl(a, b);- t6 = clmul_hh(a, b);-- t4 = veorq_u8(t4, t5);- t5 = SHIFT_LEFT_BYTES(t4, 8);- t4 = SHIFT_RIGHT_BYTES(t4, 8);-- *lo = veorq_u8(t3, t5);- *hi = veorq_u8(t6, t4);-}+#define GHASH_MUL(b, hp, hk, H, M, L) \+ do { \+ poly64x2_t b__ = (b); \+ poly64x2_t hp__ = (hp); \+ (H) = veorq_u64((H), vreinterpretq_u64_p128( \+ vmull_high_p64(b__, hp__))); \+ (L) = veorq_u64((L), vreinterpretq_u64_p128(vmull_p64( \+ (poly64_t) vgetq_lane_u64(vreinterpretq_u64_p64(b__), 0), \+ (poly64_t) vgetq_lane_u64(vreinterpretq_u64_p64(hp__), 0)))); \+ (M) = veorq_u64((M), vreinterpretq_u64_p128( \+ vmull_p64(ghash_karat(b__), (hk)))); \+ } while (0) -/* Shift the 256-bit product left by one to undo GCM's bit reflection, then- * reduce modulo the GCM polynomial. This is the expensive half. */-TARGET_ARMV8_CRYPTO-static inline uint8x16_t gfred_pmull(uint8x16_t t3, uint8x16_t t6)+/*+ * Finish the Karatsuba -- the middle accumulator still holds only the+ * (ah^al)(bh^bl) terms and wants the other two taken out of it -- and reduce+ * the 256 bits modulo the GCM polynomial. The result is in internal form.+ */+CRYPTON_TARGET_ARMV8_CRYPTO+static inline uint64x2_t ghash_reduce(uint64x2_t H, uint64x2_t M, uint64x2_t L) {- uint8x16_t t2, t4, t5, t7, t8, t9;-- t7 = SHR32(t3, 31);- t8 = SHR32(t6, 31);- t3 = SHL32(t3, 1);- t6 = SHL32(t6, 1);-- t9 = SHIFT_RIGHT_BYTES(t7, 12);- t8 = SHIFT_LEFT_BYTES(t8, 4);- t7 = SHIFT_LEFT_BYTES(t7, 4);- t3 = vorrq_u8(t3, t7);- t6 = vorrq_u8(t6, t8);- t6 = vorrq_u8(t6, t9);-- t7 = SHL32(t3, 31);- t8 = SHL32(t3, 30);- t9 = SHL32(t3, 25);+ uint64x2_t t; - t7 = veorq_u8(t7, t8);- t7 = veorq_u8(t7, t9);- t8 = SHIFT_RIGHT_BYTES(t7, 4);- t7 = SHIFT_LEFT_BYTES(t7, 12);- t3 = veorq_u8(t3, t7);+ M = veorq_u64(M, H);+ M = veorq_u64(M, L); - t2 = SHR32(t3, 1);- t4 = SHR32(t3, 2);- t5 = SHR32(t3, 7);- t2 = veorq_u8(t2, t4);- t2 = veorq_u8(t2, t5);- t2 = veorq_u8(t2, t8);- t3 = veorq_u8(t3, t2);- t6 = veorq_u8(t6, t3);+ t = vreinterpretq_u64_p128(vmull_p64(+ (poly64_t) vgetq_lane_u64(H, 0), GHASH_MODC));+ H = vreinterpretq_u64_u8(vextq_u8(vreinterpretq_u8_u64(H),+ vreinterpretq_u8_u64(H), 8));+ M = veorq_u64(M, t);+ M = veorq_u64(M, H); - return bswap128(t6);+ t = vreinterpretq_u64_p128(vmull_p64(+ (poly64_t) vgetq_lane_u64(M, 0), GHASH_MODC));+ M = vreinterpretq_u64_u8(vextq_u8(vreinterpretq_u8_u64(M),+ vreinterpretq_u8_u64(M), 8));+ L = veorq_u64(L, t);+ return veorq_u64(L, M); } -TARGET_ARMV8_CRYPTO-static uint8x16_t gfmul_pmull(uint8x16_t a, const uint8_t *htable)+/* a single block against H^1, accumulator in internal form */+CRYPTON_TARGET_ARMV8_CRYPTO+static inline uint64x2_t ghash_one(uint64x2_t acc, uint8x16_t blk,+ const block128 *ht) {- uint8x16_t lo, hi;+ uint64x2_t H = vdupq_n_u64(0), M = H, L = H;+ poly64x2_t b; - clmul_pmull(a, vld1q_u8(htable), &lo, &hi);- return gfred_pmull(lo, hi);+ acc = vreinterpretq_u64_u8(vextq_u8(vreinterpretq_u8_u64(acc),+ vreinterpretq_u8_u64(acc), 8));+ b = vreinterpretq_p64_u64(veorq_u64(+ vreinterpretq_u64_u8(vrev64q_u8(blk)), acc));+ GHASH_MUL(b, GHASH_POW(ht, 0), GHASH_KARAT(ht, 0), H, M, L);+ return ghash_reduce(H, M, L); } /*- * With PMULL there is no 4-bit table to fill: H goes in at index 0, byte- * reversed, so that gfmul_pmull does not have to swap it every time. This- * mirrors crypton_aesni_hinit_pclmul.+ * Twist H and raise it to the powers a batch needs. *- * Indices 1..7 get H^2 .. H^8, which is what lets a group of blocks fold- * into one reduction: gf_mul4 uses the first four, the GCM loop all eight.- * The table has sixteen slots, so they are free.+ * The twist is a shift left by one with 0xC2000..01 folded back in when a+ * bit falls off the top -- the same correction the old reduction applied to+ * every product, done once here instead. Each further power is one multiply+ * in the twisted domain; the result comes out of ghash_reduce with its+ * halves swapped, which a batch undoes on the way in, so a stored power has+ * to be swapped back. */-TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void crypton_aes_armv8_hinit_pmull(block128 *htable, const block128 *h) {- uint8x16_t p;+ uint8x16_t hk = vrev64q_u8(vld1q_u8((const uint8_t *) h));+ uint64x2_t shl = vshlq_n_u64(vreinterpretq_u64_u8(hk), 1);+ uint64x2_t shr = vreinterpretq_u64_s64(+ vshrq_n_s64(vreinterpretq_s64_u8(hk), 63));+ uint8x16_t mask = vextq_u8(vreinterpretq_u8_u64(shr),+ vreinterpretq_u8_u64(shr), 12);+ uint64x2_t tc = vdupq_n_u64(0);+ poly64x2_t base, p; int i; - htable[0].q[0] = bitfn_swap64(h->q[1]);- htable[0].q[1] = bitfn_swap64(h->q[0]);+ tc = vsetq_lane_u64(0xC200000000000001ul, tc, 0);+ tc = vsetq_lane_u64(1, tc, 1);+ tc = vandq_u64(vreinterpretq_u64_u8(mask), tc);+ base = vreinterpretq_p64_u64(veorq_u64(tc, shl)); - p = vld1q_u8((const uint8_t *) h);- for (i = 1; i < 8; i++) {- p = gfmul_pmull(p, (const uint8_t *) &htable[0]);- vst1q_u8((uint8_t *) &htable[i], bswap128(p));+ p = base;+ for (i = 0; i < 8; i++) {+ uint64x2_t H = vdupq_n_u64(0), M = H, L = H, r;++ vst1q_u8((uint8_t *) &htable[i],+ vreinterpretq_u8_p64(p));+ vst1q_u8((uint8_t *) &htable[8 + i],+ vreinterpretq_u8_u64(+ vdupq_n_u64((uint64_t) ghash_karat(p))));++ GHASH_MUL(p, base, ghash_karat(base), H, M, L);+ r = ghash_reduce(H, M, L);+ p = vreinterpretq_p64_u8(vextq_u8(vreinterpretq_u8_u64(r),+ vreinterpretq_u8_u64(r), 8)); } } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void crypton_aes_armv8_gf_mul_pmull(block128 *a, const block128 *htable) {- vst1q_u8((uint8_t *) a,- gfmul_pmull(vld1q_u8((const uint8_t *) a), (const uint8_t *) htable));+ uint64x2_t acc = vreinterpretq_u64_u8(+ ghash_swap(vld1q_u8((const uint8_t *) a)));++ acc = ghash_one(acc, vdupq_n_u8(0), htable);+ vst1q_u8((uint8_t *) a, ghash_swap(vreinterpretq_u8_u64(acc))); } /*@@ -320,27 +327,35 @@ * four products can be summed first and reduced once, which is where the * time goes. Aggregated reduction, from the Intel GCM paper. */-TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void crypton_aes_armv8_gf_mul4_pmull(block128 *a, const block128 *blocks, const block128 *htable) {- uint8x16_t lo, hi, l, h;+ uint64x2_t acc = vreinterpretq_u64_u8(+ ghash_swap(vld1q_u8((const uint8_t *) a)));+ uint64x2_t H = vdupq_n_u64(0), M = H, L = H;+ poly64x2_t b; int i; - clmul_pmull(veorq_u8(vld1q_u8((const uint8_t *) a),- vld1q_u8((const uint8_t *) &blocks[0])),- vld1q_u8((const uint8_t *) &htable[3]), &lo, &hi);+ acc = vreinterpretq_u64_u8(vextq_u8(vreinterpretq_u8_u64(acc),+ vreinterpretq_u8_u64(acc), 8));+ b = vreinterpretq_p64_u64(veorq_u64(+ vreinterpretq_u64_u8(vrev64q_u8(+ vld1q_u8((const uint8_t *) &blocks[0]))), acc));+ GHASH_MUL(b, GHASH_POW(htable, 3), GHASH_KARAT(htable, 3), H, M, L); for (i = 1; i < 4; i++) {- clmul_pmull(vld1q_u8((const uint8_t *) &blocks[i]),- vld1q_u8((const uint8_t *) &htable[3 - i]), &l, &h);- lo = veorq_u8(lo, l);- hi = veorq_u8(hi, h);+ b = vreinterpretq_p64_u8(vrev64q_u8(+ vld1q_u8((const uint8_t *) &blocks[i])));+ GHASH_MUL(b, GHASH_POW(htable, 3 - i),+ GHASH_KARAT(htable, 3 - i), H, M, L); } - vst1q_u8((uint8_t *) a, gfred_pmull(lo, hi));+ acc = ghash_reduce(H, M, L);+ vst1q_u8((uint8_t *) a, ghash_swap(vreinterpretq_u8_u64(acc))); } + int crypton_aes_armv8_pmull_available(void) { #if defined(__APPLE__)@@ -359,7 +374,7 @@ * the high half, and fold the bit that leaves the top back in as 0x87. The * block is little-endian, so lane 0 is the low half. */-TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO static inline uint8x16_t gfmulx_neon(uint8x16_t v) { const uint64x2_t x = vreinterpretq_u64_u8(v);@@ -396,3 +411,59 @@ #include <aes/armv8_impl.c> #undef SIZED #undef NBR++/*+ * The fused entry point, over the three key sizes. Each was generated with+ * its round count fixed, which is what lets the eight chains stay in+ * registers; the choice between them is made once per message here.+ */+CRYPTON_TARGET_ARMV8_CRYPTO+void crypton_aes_armv8_gcm_fused(uint8_t *out, const block128 *ht,+ aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *in, uint32_t inlen,+ uint32_t taglen, aes_key *hpkey,+ uint32_t sampleoff, uint8_t *mask)+{+ switch (key->strength) {+ case 0:+ crypton_aes_armv8_gcm_fused128(out, ht, key, nonce, aad, aadlen,+ in, inlen, taglen, hpkey,+ sampleoff, mask);+ break;+ case 1:+ crypton_aes_armv8_gcm_fused192(out, ht, key, nonce, aad, aadlen,+ in, inlen, taglen, hpkey,+ sampleoff, mask);+ break;+ default:+ crypton_aes_armv8_gcm_fused256(out, ht, key, nonce, aad, aadlen,+ in, inlen, taglen, hpkey,+ sampleoff, mask);+ break;+ }+}++CRYPTON_TARGET_ARMV8_CRYPTO+int crypton_aes_armv8_gcm_fused_dec(uint8_t *out, const block128 *ht,+ aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *in, uint32_t inlen,+ const uint8_t *tag, uint32_t taglen,+ uint8_t *outtag)+{+ switch (key->strength) {+ case 0:+ return crypton_aes_armv8_gcm_fused_dec128(out, ht, key, nonce,+ aad, aadlen, in, inlen,+ tag, taglen, outtag);+ case 1:+ return crypton_aes_armv8_gcm_fused_dec192(out, ht, key, nonce,+ aad, aadlen, in, inlen,+ tag, taglen, outtag);+ default:+ return crypton_aes_armv8_gcm_fused_dec256(out, ht, key, nonce,+ aad, aadlen, in, inlen,+ tag, taglen, outtag);+ }+}
cbits/aes/armv8_impl.c view
@@ -25,8 +25,6 @@ #define EACH1(m) m(0) #define EACH8(m) m(0) m(1) m(2) m(3) m(4) m(5) m(6) m(7)-/* the blocks after the first; GHASH folds block 0 in with the tag */-#define EACH7(m) m(1) m(2) m(3) m(4) m(5) m(6) m(7) #define LOAD_IN(i) s[i] = vld1q_u8((const uint8_t *) (input + (i))); #define STORE_OUT(i) vst1q_u8((uint8_t *) (output + (i)), s[i]);@@ -74,7 +72,7 @@ } \ } while (0) -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_encrypt_block)(aes_block *output, aes_key *key, aes_block *input) { const uint8_t *rk = FWD(key);@@ -85,7 +83,7 @@ EACH1(STORE_OUT); } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_decrypt_block)(aes_block *output, aes_key *key, aes_block *input) { const uint8_t *fwd = FWD(key);@@ -97,7 +95,7 @@ EACH1(STORE_OUT); } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_encrypt_ecb)(aes_block *output, aes_key *key, aes_block *input, uint32_t nb_blocks) { const uint8_t *rk = FWD(key);@@ -115,7 +113,7 @@ } } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_decrypt_ecb)(aes_block *output, aes_key *key, aes_block *input, uint32_t nb_blocks) { const uint8_t *fwd = FWD(key);@@ -136,7 +134,7 @@ /* CBC encryption chains, so there is nothing to interleave. It still gains * the round keys staying put. */-TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_encrypt_cbc)(aes_block *output, aes_key *key, aes_block *_iv, aes_block *input, uint32_t nb_blocks) { const uint8_t *rk = FWD(key);@@ -158,7 +156,7 @@ #define CBC_KEEP(i) c[(i) + 1] = s[i]; #define CBC_XOR(i) vst1q_u8((uint8_t *) (output + (i)), veorq_u8(s[i], c[i])); -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_decrypt_cbc)(aes_block *output, aes_key *key, aes_block *_iv, aes_block *input, uint32_t nb_blocks) { const uint8_t *fwd = FWD(key);@@ -192,7 +190,7 @@ #define CTR_XOR(i) vst1q_u8(output + 16 * (i), \ veorq_u8(s[i], vld1q_u8(input + 16 * (i)))); -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_encrypt_ctr)(uint8_t *output, aes_key *key, aes_block *iv, uint8_t *input, uint32_t len) { const uint8_t *rk = FWD(key);@@ -262,6 +260,47 @@ * * GCM's counter is the low 32 bits only and wraps there, so unlike CTR * there is no carry to chase: the top twelve bytes never move.+ *+ * What this loop is short of is not overlap but instructions. A group of+ * eight blocks compiles to 383 of them on an Apple M4, and only 152 are the+ * cipher -- eighty AESE and seventy-two AESMC. The rest is the GHASH and+ * the counters. Measured against OpenSSL on the same machine, 16 KiB+ * messages under AES-128:+ *+ * crypton, this loop with the GHASH taken out 19883 MB/s+ * OpenSSL, AES-128-CTR 17176+ * OpenSSL, AES-128-GCM 9869+ * crypton, AES-128-GCM 8641+ *+ * The cipher here is ahead of OpenSSL's; all of the 0.87 is the GHASH.+ * Four ways of closing it were tried and every one measured worse, so they+ * are written down here rather than tried again. Each was checked to give+ * the same ciphertext and tag as this code for three key sizes and+ * thirty-five lengths, encrypt and decrypt, before being timed:+ *+ * the GHASH held back a group and spread through the next -1.3%+ * group's AES rounds, so that the two do not queue to -3.6%+ * Karatsuba: three multiplications for the two halves -1.6%+ * instead of four+ * the same with every product on a lane the instruction 0.0%+ * reaches, which does remove sixteen fmov a group+ * the same again with the H powers' halves added together -3%+ * already, in the spare half of htable+ *+ * The first fails because there was nothing to gain: a group's AES depends+ * on nothing in the group before it, so a wide out-of-order core already+ * runs the two together, and holding a group back only adds copies. The+ * rest fail for one reason -- none of them makes the loop shorter.+ * Karatsuba buys a PMULL for two EOR and an EXT, and the folded table turns+ * sixteen `dup` into sixteen `ld1r` and sixteen more address adds.+ *+ * That last sentence used to end by saying a count which does come down+ * wants the data laid out differently. It does, and since the GHASH was+ * rewritten against a twisted H -- see cbits/aes/armv8.c -- it is laid out+ * differently, so the figures above are what the *previous* GHASH gave.+ * Karatsuba pays now that the reduction it has to carry is a third of what+ * it was; the other three are untried in the new representation and the+ * first of them has no more reason to work than it had. */ #define GCM_CTR(i) s[i] = vreinterpretq_u8_u32(vsetq_lane_u32(cpu_to_be32(c + 1 + (i)), base, 3)); #define GCM_ENC(i) { const uint8x16_t m_ = vld1q_u8(input + 16 * (i)); \@@ -270,27 +309,33 @@ #define GCM_DEC(i) { const uint8x16_t m_ = vld1q_u8(input + 16 * (i)); \ vst1q_u8(output + 16 * (i), veorq_u8(s[i], m_)); \ s[i] = m_; }-#define GCM_GHASH(i) { uint8x16_t l_, h_; \- clmul_pmull(s[i], vld1q_u8((const uint8_t *) &ht[WAY - 1 - (i)]), \- &l_, &h_); \- glo = veorq_u8(glo, l_); ghi = veorq_u8(ghi, h_); }+#define GCM_GHASH(i) \+ { \+ poly64x2_t b_ = vreinterpretq_p64_u8(vrev64q_u8(s[i])); \+ if ((i) == 0) \+ b_ = vreinterpretq_p64_u64(veorq_u64( \+ vreinterpretq_u64_p64(b_), acc)); \+ GHASH_MUL(b_, GHASH_POW(ht, WAY - 1 - (i)), \+ GHASH_KARAT(ht, WAY - 1 - (i)), gH, gM, gL); \+ } /* the eight blocks now in s[] are the ciphertext; fold them into the tag */ #define GCM_FOLD() \ do { \- uint8x16_t glo, ghi; \- clmul_pmull(veorq_u8(tag, s[0]), \- vld1q_u8((const uint8_t *) &ht[WAY - 1]), \- &glo, &ghi); \- EACH7(GCM_GHASH) \- tag = gfred_pmull(glo, ghi); \+ uint64x2_t gH = vdupq_n_u64(0), gM = gH, gL = gH; \+ acc = vreinterpretq_u64_u8( \+ vextq_u8(vreinterpretq_u8_u64(acc), \+ vreinterpretq_u8_u64(acc), 8)); \+ EACH8(GCM_GHASH) \+ acc = ghash_reduce(gH, gM, gL); \ } while (0) #define GCM_PROLOGUE \ const uint8_t *rk = FWD(key); \ const block128 *ht = gcm->htable; \ uint8x16_t s[WAY]; \- uint8x16_t tag = vld1q_u8((const uint8_t *) &gcm->tag); \+ uint64x2_t acc = vreinterpretq_u64_u8( \+ ghash_swap(vld1q_u8((const uint8_t *) &gcm->tag))); \ uint32_t c = be32_to_cpu(gcm->civ.d[3]); \ uint32x4_t base = vreinterpretq_u32_u8(vld1q_u8((const uint8_t *) &gcm->civ)) @@ -303,16 +348,17 @@ ENC_ROUNDS(EACH1); \ s[0] = veorq_u8(s[0], m_); \ (store_c); \- tag = gfmul_pmull(veorq_u8(tag, (ghash_of)), (const uint8_t *) ht); \+ acc = ghash_one(acc, (ghash_of), ht); \ } while (0) #define GCM_EPILOGUE \ do { \ gcm->civ.d[3] = cpu_to_be32(c); \- vst1q_u8((uint8_t *) &gcm->tag, tag); \+ vst1q_u8((uint8_t *) &gcm->tag, \+ ghash_swap(vreinterpretq_u8_u64(acc))); \ } while (0) -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_gcm_encrypt)(uint8_t *output, aes_gcm *gcm, aes_key *key, uint8_t *input, uint32_t length) { GCM_PROLOGUE;@@ -343,13 +389,12 @@ block128_zero(&m); for (i = 0; i < length; i++) output[i] = m.b[i] = o.b[i];- tag = gfmul_pmull(veorq_u8(tag, vld1q_u8((const uint8_t *) &m)),- (const uint8_t *) ht);+ acc = ghash_one(acc, vld1q_u8((const uint8_t *) &m), ht); } GCM_EPILOGUE; } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_gcm_decrypt)(uint8_t *output, aes_gcm *gcm, aes_key *key, uint8_t *input, uint32_t length) { GCM_PROLOGUE;@@ -381,8 +426,7 @@ vst1q_u8((uint8_t *) &o, s[0]); for (i = 0; i < length; i++) output[i] = o.b[i];- tag = gfmul_pmull(veorq_u8(tag, vld1q_u8((const uint8_t *) &m)),- (const uint8_t *) ht);+ acc = ghash_one(acc, vld1q_u8((const uint8_t *) &m), ht); } GCM_EPILOGUE; }@@ -433,7 +477,7 @@ } while (0); #define XTS_TWEAK_ROLL(i) do { t[i] = tn[i]; } while (0); -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_encrypt_xts)(aes_block *output, aes_key *key, aes_key *key2, aes_block *dataunit, uint32_t spoint, aes_block *input, uint32_t nb_blocks) { const uint8_t *rk = FWD(key);@@ -477,7 +521,7 @@ } } -TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void SIZED(crypton_aes_armv8_decrypt_xts)(aes_block *output, aes_key *key, aes_key *key2, aes_block *dataunit, uint32_t spoint, aes_block *input, uint32_t nb_blocks) { const uint8_t *fwd = FWD(key);@@ -523,9 +567,237 @@ } } +/*+ * One message, one call: the additional data, the counter-mode encryption,+ * the tag and the QUIC header protection mask, with the running tag and the+ * counter kept in registers from end to end.+ *+ * What this saves over composing crypton_aes_gcm_aad, _encrypt and _finish is+ * not the arithmetic but the boundaries. Each of those reaches its+ * primitives through a branch table, so the 128-bit state goes back to memory+ * at every step and a header of one block pays a reduction of its own. On an+ * Apple M4 that framing was 0.07 of the 0.112 microseconds a 100-byte packet+ * cost -- more than the encryption of the packet itself.+ *+ * The GHASH is taken in batches of WAY against the powers of H the key+ * already holds, so a batch costs one reduction rather than one per block,+ * and the additional data and the length block ride in the same batches as+ * the ciphertext instead of being multiplied on their own.+ */++/* start a batch, or continue one; blen is how many blocks this batch holds */+#define FG_ABSORB(blk) \+ do { \+ poly64x2_t b_ = vreinterpretq_p64_u8(vrev64q_u8(blk)); \+ if (bn == 0) { \+ uint32_t left_ = gtotal - gidx; \+ blen = left_ < WAY ? left_ : WAY; \+ acc = vreinterpretq_u64_u8( \+ vextq_u8(vreinterpretq_u8_u64(acc), \+ vreinterpretq_u8_u64(acc), 8)); \+ b_ = vreinterpretq_p64_u64(veorq_u64( \+ vreinterpretq_u64_p64(b_), acc)); \+ gH = vdupq_n_u64(0); \+ gM = gH; \+ gL = gH; \+ } \+ GHASH_MUL(b_, GHASH_POW(ht, blen - bn - 1), \+ GHASH_KARAT(ht, blen - bn - 1), gH, gM, gL); \+ gidx++; bn++; \+ if (bn == blen) { acc = ghash_reduce(gH, gM, gL); bn = 0; } \+ } while (0)++/* a block that is short, zero padded, as GHASH wants it */+#define FG_PARTIAL(p, n) \+ ({ uint8_t buf_[16]; memset(buf_, 0, 16); memcpy(buf_, (p), (n)); \+ vld1q_u8(buf_); })++CRYPTON_TARGET_ARMV8_CRYPTO+void SIZED(crypton_aes_armv8_gcm_fused)(uint8_t *out, const block128 *ht,+ aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *in, uint32_t inlen,+ uint32_t taglen, aes_key *hpkey,+ uint32_t sampleoff, uint8_t *mask)+{+ const uint8_t *rk = FWD(key);+ uint8x16_t s[WAY];+ uint8x16_t ek0;+ uint64x2_t acc = vdupq_n_u64(0), gH = acc, gM = acc, gL = acc;+ uint32x4_t base;+ uint32_t c = 1, bn = 0, blen = 0, gidx = 0;+ uint32_t gtotal = (aadlen + 15) / 16 + (inlen + 15) / 16 + 1;+ uint32_t i, done;+ uint8_t y0[16], lenb[16];+ uint64_t la, lc;++ memcpy(y0, nonce, 12);+ y0[12] = 0; y0[13] = 0; y0[14] = 0; y0[15] = 1;+ base = vreinterpretq_u32_u8(vld1q_u8(y0));++ s[0] = vld1q_u8(y0);+ ENC_ROUNDS(EACH1);+ ek0 = s[0];++ for (i = 0; i + 16 <= aadlen; i += 16)+ FG_ABSORB(vld1q_u8(aad + i));+ if (i < aadlen)+ FG_ABSORB(FG_PARTIAL(aad + i, aadlen - i));++ for (done = 0; done + 16 * WAY <= inlen; done += 16 * WAY) {+ const uint8_t *p = in + done;+ uint8_t *q = out + done;++ EACH8(GCM_CTR);+ c += WAY;+ ENC_ROUNDS(EACH8);+ {+ const uint8_t *input = p;+ uint8_t *output = q;+ EACH8(GCM_ENC);+ }+ FG_ABSORB(s[0]); FG_ABSORB(s[1]); FG_ABSORB(s[2]); FG_ABSORB(s[3]);+ FG_ABSORB(s[4]); FG_ABSORB(s[5]); FG_ABSORB(s[6]); FG_ABSORB(s[7]);+ }++ for (; done < inlen; done += 16) {+ uint32_t n = inlen - done < 16 ? inlen - done : 16;+ uint8x16_t m_ = n == 16 ? vld1q_u8(in + done)+ : FG_PARTIAL(in + done, n);+ c++;+ s[0] = vreinterpretq_u8_u32(vsetq_lane_u32(cpu_to_be32(c), base, 3));+ ENC_ROUNDS(EACH1);+ s[0] = veorq_u8(s[0], m_);+ if (n == 16) {+ vst1q_u8(out + done, s[0]);+ } else {+ uint8_t buf_[16];+ vst1q_u8(buf_, s[0]);+ memcpy(out + done, buf_, n);+ memset(buf_ + n, 0, 16 - n);+ s[0] = vld1q_u8(buf_);+ }+ FG_ABSORB(s[0]);+ }++ la = (uint64_t) aadlen << 3;+ lc = (uint64_t) inlen << 3;+ for (i = 0; i < 8; i++) lenb[i] = (uint8_t) (la >> (56 - 8 * i));+ for (i = 0; i < 8; i++) lenb[8 + i] = (uint8_t) (lc >> (56 - 8 * i));+ FG_ABSORB(vld1q_u8(lenb));++ {+ uint8_t tbuf[16];+ vst1q_u8(tbuf, veorq_u8(ghash_swap(vreinterpretq_u8_u64(acc)), ek0));+ memcpy(out + inlen, tbuf, taglen);+ }++ if (hpkey != 0 && mask != 0) {+ block128 sample, m;+ memcpy(&sample, out + sampleoff, 16);+ crypton_aes_encrypt_ecb(&m, hpkey, &sample, 1);+ memcpy(mask, &m, 16);+ }+}+++/*+ * The same for decryption. GCM_DEC leaves the ciphertext in s[] once it has+ * written the plaintext out, which is what GHASH wants, so the only other+ * difference is the end: the tag is compared here rather than written, every+ * byte of it whichever way the answer goes.+ */+CRYPTON_TARGET_ARMV8_CRYPTO+int SIZED(crypton_aes_armv8_gcm_fused_dec)(uint8_t *out, const block128 *ht,+ aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *in, uint32_t inlen,+ const uint8_t *tagp, uint32_t taglen,+ uint8_t *outtag)+{+ const uint8_t *rk = FWD(key);+ uint8x16_t s[WAY];+ uint8x16_t ek0;+ uint64x2_t acc = vdupq_n_u64(0), gH = acc, gM = acc, gL = acc;+ uint32x4_t base;+ uint32_t c = 1, bn = 0, blen = 0, gidx = 0;+ uint32_t gtotal = (aadlen + 15) / 16 + (inlen + 15) / 16 + 1;+ uint32_t i, done;+ uint8_t y0[16], lenb[16], want[16];+ uint64_t la, lc;+ uint8_t diff = 0;++ memcpy(y0, nonce, 12);+ y0[12] = 0; y0[13] = 0; y0[14] = 0; y0[15] = 1;+ base = vreinterpretq_u32_u8(vld1q_u8(y0));++ s[0] = vld1q_u8(y0);+ ENC_ROUNDS(EACH1);+ ek0 = s[0];++ for (i = 0; i + 16 <= aadlen; i += 16)+ FG_ABSORB(vld1q_u8(aad + i));+ if (i < aadlen)+ FG_ABSORB(FG_PARTIAL(aad + i, aadlen - i));++ for (done = 0; done + 16 * WAY <= inlen; done += 16 * WAY) {+ const uint8_t *p = in + done;+ uint8_t *q = out + done;++ EACH8(GCM_CTR);+ c += WAY;+ ENC_ROUNDS(EACH8);+ {+ const uint8_t *input = p;+ uint8_t *output = q;+ EACH8(GCM_DEC);+ }+ FG_ABSORB(s[0]); FG_ABSORB(s[1]); FG_ABSORB(s[2]); FG_ABSORB(s[3]);+ FG_ABSORB(s[4]); FG_ABSORB(s[5]); FG_ABSORB(s[6]); FG_ABSORB(s[7]);+ }++ for (; done < inlen; done += 16) {+ uint32_t n = inlen - done < 16 ? inlen - done : 16;+ uint8x16_t m_ = n == 16 ? vld1q_u8(in + done)+ : FG_PARTIAL(in + done, n);+ c++;+ s[0] = vreinterpretq_u8_u32(vsetq_lane_u32(cpu_to_be32(c), base, 3));+ ENC_ROUNDS(EACH1);+ {+ uint8x16_t pl = veorq_u8(s[0], m_);+ if (n == 16) {+ vst1q_u8(out + done, pl);+ } else {+ uint8_t buf_[16];+ vst1q_u8(buf_, pl);+ memcpy(out + done, buf_, n);+ }+ }+ FG_ABSORB(m_);+ }++ la = (uint64_t) aadlen << 3;+ lc = (uint64_t) inlen << 3;+ for (i = 0; i < 8; i++) lenb[i] = (uint8_t) (la >> (56 - 8 * i));+ for (i = 0; i < 8; i++) lenb[8 + i] = (uint8_t) (lc >> (56 - 8 * i));+ FG_ABSORB(vld1q_u8(lenb));++ vst1q_u8(want, veorq_u8(ghash_swap(vreinterpretq_u8_u64(acc)), ek0));+ if (outtag) {+ /* The caller holds the expected tag and will compare it itself. */+ memcpy(outtag, want, taglen);+ return 1;+ }+ for (i = 0; i < taglen; i++)+ diff |= (uint8_t) (want[i] ^ tagp[i]);+ return diff == 0;+}++#undef FG_ABSORB+#undef FG_PARTIAL+ #undef WAY #undef EACH1-#undef EACH7 #undef EACH8 #undef LOAD_IN #undef STORE_OUT
cbits/aes/block128.h view
@@ -34,7 +34,21 @@ #include <crypton_bitfn.h> #include <crypton_align.h> -typedef union {+/* Packed, so that the union asks nothing of the address it is at.+ *+ * Several callers here make one of these out of a pointer of their own -- a+ * ciphertext, a tag, a nonce -- and without this that cast produces a pointer+ * the standard says may not exist, and reading q[] out of it is a member+ * access at an address the type is not aligned for. crypton_align.h used to+ * answer that with need_alignment, which is zero on i386 and x86-64: the two+ * places the access is architecturally fine and the standard still says+ * nothing about it. UndefinedBehaviorSanitizer reported it.+ *+ * With the alignment declared to be one, the compiler is the one that knows+ * what the target can do: on i386, x86-64 and AArch64 it emits the same load+ * and store it emitted before, and where a target cannot read a word off an+ * odd address it emits what that target needs. */+typedef union __attribute__((packed)) { uint64_t q[2]; uint32_t d[4]; uint16_t w[8];
+ cbits/aes/gcm_fused_x86.c view
@@ -0,0 +1,1013 @@+/*+ * A fused AES-GCM for x86-64, following the design Kazuho Oku sets out in+ * "QUICむけにAES-GCM実装を最適化した話" and implements in picotls's+ * lib/fusion.c: keep AES-NI issuing every clock and fit everything else --+ * the additional data, the tag, the QUIC header protection mask -- into the+ * gaps it leaves. Written in C with intrinsics rather than assembly, for+ * the same reason he gives: the scheduling is what is complicated here, and+ * it has to stay readable to stay correct.+ *+ * Parts of this file follow fusion closely enough to say so: `loadn` and the+ * two tables it reads, `loadn_page_end` and `storen` are its `loadn128`,+ * `loadn_end_of_page` and `storen128` in another spelling, and the+ * reduction of a 256-bit product is the sequence fusion takes from Gueron's+ * "AES-GCM for Efficient Authenticated Encryption". fusion is under the MIT+ * license, which is in cbits/aes/LICENSE.fusion beside this file.+ *+ * The powers of H are built once per key, so the additional data, the+ * ciphertext and the length block are absorbed against them in batches that+ * share one reduction, rather than each block paying for a reduction of its+ * own. How many powers, and so how large a batch, is+ * CRYPTON_GCM_FUSED_POWERS in crypton_aes.h.+ *+ * Only messages shorter than CRYPTON_GCM_FUSED_MAX_MESSAGE come here. Above+ * that the stitched assembly in cbits/asm is faster, and crypton_aes.c sends+ * them there instead; below it, that assembly will not start at all.+ */++#include <crypton_cpu.h>++#ifdef WITH_GCM_FUSED++#include <stdint.h>+#include <string.h>+#include <wmmintrin.h>+#include <smmintrin.h>+#include <tmmintrin.h>++#include <crypton_aes.h>+#include <aes/gcm_fused_x86.h>++/*+ * aes_key is a struct of bytes, so its round keys sit wherever the members+ * before them leave them -- eight bytes in, as it happens. A __m128i *+ * pointed at that gets an aligned load and a fault, so each round key is+ * fetched with an unaligned load instead. Copying them somewhere aligned+ * would cost a copy per call, which at these message lengths is a tenth of+ * the whole; the load is free from L1 and the round key is fetched once for+ * all six lanes.+ */+#define RK(p, i) \+ _mm_loadu_si128((const __m128i *) ((const uint8_t *) (p) + 16 * (size_t) (i)))++/* a full sixteen-byte reversal: mask bytes 15,14,...,0 */+static const __m128i BSWAP = {0x08090a0b0c0d0e0fLL, 0x0001020304050607LL};+++#define TGT __attribute__((target("aes,pclmul,sse4.1")))++/* the two halves of a value added together: the term Karatsuba needs, and it+ * does not depend on what the value is multiplied by */+TGT static inline __m128i fold(__m128i a)+{+ return _mm_xor_si128(a, _mm_unpackhi_epi64(a, a));+}++/* H multiplied by x in the field, which is what puts H and its powers one+ * bit up: GCM numbers the bits of a field element the other way round from+ * the way the carry-less multiply does, and pre-shifting is what saves the+ * correction after every multiply.+ *+ * Written from the definition. The field is GF(2)[x] modulo x^128 + x^127 ++ * x^126 + x^121 + 1, so multiplying by x is a shift of one place, and the+ * term that leaves the top comes back as the other four. */+TGT static __m128i twist(__m128i h)+{+ /* x^127 + x^126 + x^121 + 1, the terms x^128 is congruent to */+ const __m128i poly = _mm_set_epi64x(0xc200000000000000ULL, 1);+ /* the top bit of each half */+ __m128i tops = _mm_srli_epi64(h, 63);+ /* doubling a polynomial is a shift by one: each half doubles, and the+ * low half's top bit becomes the high half's bottom bit */+ __m128i doubled = _mm_or_si128(_mm_add_epi64(h, h),+ _mm_slli_si128(tops, 8));+ /* bit 127 is the one that leaves the field; spread it to a mask by+ * subtracting it from zero, and it brings the four terms back */+ __m128i mask = _mm_sub_epi64(_mm_setzero_si128(),+ _mm_unpackhi_epi64(tops, tops));++ return _mm_xor_si128(doubled, _mm_and_si128(mask, poly));+}++/* one reduction of a 256-bit product back into the field */+TGT static __m128i reduce256(__m128i lo, __m128i hi)+{+ const __m128i poly = _mm_set_epi64x(0xc200000000000000ULL, 1);+ __m128i t;++ t = _mm_clmulepi64_si128(lo, poly, 0x10);+ lo = _mm_xor_si128(_mm_shuffle_epi32(lo, 0x4e), t);+ t = _mm_clmulepi64_si128(lo, poly, 0x10);+ lo = _mm_xor_si128(_mm_shuffle_epi32(lo, 0x4e), t);+ return _mm_xor_si128(hi, lo);+}++/*+ * One multiply in exactly the form the hot loop uses it: the left operand+ * plain, the right one already twisted. Building the table with the same+ * multiply that consumes it is the only way the two conventions cannot drift+ * apart.+ */+TGT static __m128i mul_twisted(__m128i a, __m128i ht)+{+ __m128i lo = _mm_clmulepi64_si128(a, ht, 0x00);+ __m128i hi = _mm_clmulepi64_si128(a, ht, 0x11);+ __m128i mid = _mm_clmulepi64_si128(fold(a), fold(ht), 0x00);++ mid = _mm_xor_si128(mid, _mm_xor_si128(lo, hi));+ lo = _mm_xor_si128(lo, _mm_slli_si128(mid, 8));+ hi = _mm_xor_si128(hi, _mm_srli_si128(mid, 8));+ return reduce256(lo, hi);+}++TGT void crypton_gcm_fused_key_init(aes_gcm_fused *fk, const aes_key *key)+{+ const uint8_t *rk = key->data;+ const int rounds = key->nbr;+ __m128i h, p;+ int i;++ /* H = E_K(0) */+ h = RK(rk, 0);+ for (i = 1; i < rounds; i++) h = _mm_aesenc_si128(h, RK(rk, i));+ h = _mm_aesenclast_si128(h, RK(rk, rounds));+ h = _mm_shuffle_epi8(h, BSWAP);++ {+ __m128i ht = twist(h);+ p = h;+ for (i = 0; i < CRYPTON_GCM_FUSED_POWERS; i++) {+ __m128i t = twist(p);+ _mm_storeu_si128((__m128i *) &fk->p[i].h, t);+ _mm_storeu_si128((__m128i *) &fk->p[i].r, fold(t));+ p = mul_twisted(p, ht);+ }+ }+}++/*+ * The running product. Three plain locals and a macro, not a struct behind+ * a pointer: taking the address of the accumulators is enough to keep them+ * out of registers, and then every multiply reloads and restores them. That+ * is the same mistake as reaching a table through an index the compiler+ * cannot fold, and it costs more here because it is on the inner path.+ */+#define GHASH_DECL __m128i glo = _mm_setzero_si128(), \+ ghi = _mm_setzero_si128(), \+ gmid = _mm_setzero_si128(), \+ gtag = _mm_setzero_si128(); \+ int gidx = 0, gblen = 0, gbpos = 0++/*+ * Absorb one block. Blocks are taken in batches of at most CRYPTON_GCM_FUSED_POWERS: the+ * first of a batch carries in the value the batch before it reduced to, the+ * rest go in against descending powers, and the batch ends with the one+ * reduction they share. With the batch as long as the message this is+ * picotls's single reduction; with it fixed, the state stays a fixed size.+ */+#define GHASH_ONE(blk, unused_power) \+ do { \+ __m128i _b = (blk); \+ __m128i _h, _r; \+ if (gbpos == 0) { \+ int _left = gtotal - gidx; \+ gblen = _left < CRYPTON_GCM_FUSED_POWERS ? _left : CRYPTON_GCM_FUSED_POWERS; \+ _b = _mm_xor_si128(_b, gtag); \+ glo = ghi = gmid = _mm_setzero_si128(); \+ } \+ _h = _mm_loadu_si128((const __m128i *) &fk->p[gblen-gbpos-1].h); \+ _r = _mm_loadu_si128((const __m128i *) &fk->p[gblen-gbpos-1].r); \+ glo = _mm_xor_si128(glo, _mm_clmulepi64_si128(_b, _h, 0x00)); \+ ghi = _mm_xor_si128(ghi, _mm_clmulepi64_si128(_b, _h, 0x11)); \+ gmid = _mm_xor_si128(gmid, \+ _mm_clmulepi64_si128(fold(_b), _r, 0x00)); \+ gidx++; gbpos++; \+ if (gbpos == gblen) { \+ gtag = ghash_reduce(glo, ghi, gmid); \+ gbpos = 0; \+ } \+ } while (0)++TGT static __m128i ghash_reduce(__m128i glo, __m128i ghi, __m128i gmid)+{+ __m128i mid = _mm_xor_si128(gmid, _mm_xor_si128(glo, ghi));+ __m128i lo = _mm_xor_si128(glo, _mm_slli_si128(mid, 8));+ __m128i hi = _mm_xor_si128(ghi, _mm_srli_si128(mid, 8));++ return reduce256(lo, hi);+}++/* zero every byte from n onwards, so a partial block can be fed to GHASH+ * without being written out and read back */+TGT static __m128i clampn(__m128i v, size_t n)+{+ const __m128i idx = {0x0706050403020100LL, 0x0f0e0d0c0b0a0908LL};+ return _mm_and_si128(v, _mm_cmpgt_epi8(_mm_set1_epi8((char) n), idx));+}++/*+ * A short block, zero padded, without going through the stack.+ *+ * The obvious way -- zero sixteen bytes, copy n in, load them back -- is+ * three trips to memory with a store the load has to wait for, and at these+ * lengths that is a tenth of the whole call. Reading the sixteen bytes and+ * masking off what is above n is two instructions, but it reads past the end+ * of what the caller gave, so it has to be sure those bytes exist.+ *+ * They do unless the block ends a page. A load of sixteen bytes that starts+ * at least sixteen from the end of a page stays inside it; and if the n bytes+ * asked for themselves cross the boundary then the next page is there to be+ * read as well. What is left is a block near the end of a page whose own+ * bytes stop short of it, and that is read aligned -- which cannot leave the+ * page -- and shuffled down. This is how picotls's fusion does it.+ */++/* thirty-two bytes of ones, then thirty-one of zeros: sixteen loaded from+ * 32 - n give n bytes of ones and the rest zeros */+static const uint8_t loadn_mask[63] = {+ 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,+ 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,+ 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,+ 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff};++/* the first sixteen map to byte offsets, the rest to zero */+static const uint8_t loadn_shuffle[31] = {+ 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07,+ 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f,+ 0x80, 0x80, 0x80, 0x80, 0x80, 0x80, 0x80, 0x80,+ 0x80, 0x80, 0x80, 0x80, 0x80, 0x80, 0x80};++#if defined(__has_feature)+#if __has_feature(address_sanitizer)+#define NO_ASAN __attribute__((no_sanitize_address))+#endif+#elif defined(__SANITIZE_ADDRESS__)+#define NO_ASAN __attribute__((no_sanitize_address))+#endif+#ifndef NO_ASAN+#define NO_ASAN+#endif++TGT NO_ASAN static __m128i loadn_page_end(const uint8_t *p, size_t n)+{+ uintptr_t shift = (uintptr_t) p & 15;+ __m128i pattern = _mm_loadu_si128((const __m128i *) (loadn_shuffle + shift));++ (void) n;+ return _mm_shuffle_epi8(+ _mm_load_si128((const __m128i *) ((uintptr_t) p - shift)), pattern);+}++TGT NO_ASAN static __m128i loadn(const uint8_t *p, size_t n)+{+ __m128i mask = _mm_loadu_si128((const __m128i *) (loadn_mask + 32 - n));+ uintptr_t mod4k = (uintptr_t) p % 4096;+ __m128i v;++ if (mod4k <= 4096 - 16 || mod4k + n > 4096)+ v = _mm_loadu_si128((const __m128i *) p);+ else+ v = loadn_page_end(p, n);+ return _mm_and_si128(v, mask);+}++TGT static void storen(uint8_t *p, __m128i v, size_t n)+{+ uint8_t buf[16];+ _mm_storeu_si128((__m128i *) buf, v);+ memcpy(p, buf, n);+}++/* One block. The ten rounds of the common case are written out for the+ * same reason the six-wide group is: a loop over a round count that lives in+ * the key leaves every round key fetched through an index the compiler+ * cannot fold, and adds a branch to a chain that is already latency-bound. */+TGT static __m128i aes_one_block(const uint8_t *rk, int rounds, __m128i v)+{+ const uint8_t *k = rk;+ int i;++ if (rounds == 10) {+ v = _mm_xor_si128(v, RK(k, 0));+ v = _mm_aesenc_si128(v, RK(k, 1));+ v = _mm_aesenc_si128(v, RK(k, 2));+ v = _mm_aesenc_si128(v, RK(k, 3));+ v = _mm_aesenc_si128(v, RK(k, 4));+ v = _mm_aesenc_si128(v, RK(k, 5));+ v = _mm_aesenc_si128(v, RK(k, 6));+ v = _mm_aesenc_si128(v, RK(k, 7));+ v = _mm_aesenc_si128(v, RK(k, 8));+ v = _mm_aesenc_si128(v, RK(k, 9));+ return _mm_aesenclast_si128(v, RK(k, 10));+ }+ v = _mm_xor_si128(v, RK(k, 0));+ for (i = 1; i < rounds; i++) v = _mm_aesenc_si128(v, RK(k, i));+ return _mm_aesenclast_si128(v, RK(k, rounds));+}++/*+ * Six blocks at once, with lane 5 free to run a different key schedule from+ * the rest. Which schedule that lane uses is chosen once, into a pointer,+ * rather than tested inside the rounds, and the six live in named variables+ * rather than an array -- an array indexed by a running variable goes to+ * memory, and then every round is a load and a store instead of a register+ * to register operation, which is the whole of what this is trying to avoid.+ *+ * Lanes beyond what the caller needs still run. Six are in flight whatever+ * the message length, so the spare ones cost nothing, and that is exactly+ * why the header protection mask and E(K,Y0) are worth putting in them+ * instead of giving each a dependent chain of its own.+ */+#define WIDE6(alt) \+ do { \+ const uint8_t *ak = (alt); \+ int r; \+ t0 = _mm_xor_si128(t0, RK(rk, 0)); \+ t1 = _mm_xor_si128(t1, RK(rk, 0)); \+ t2 = _mm_xor_si128(t2, RK(rk, 0)); \+ t3 = _mm_xor_si128(t3, RK(rk, 0)); \+ t4 = _mm_xor_si128(t4, RK(rk, 0)); \+ t5 = _mm_xor_si128(t5, RK(ak, 0)); \+ for (r = 1; r < rounds; r++) { \+ __m128i k = RK(rk, r); \+ t0 = _mm_aesenc_si128(t0, k); \+ t1 = _mm_aesenc_si128(t1, k); \+ t2 = _mm_aesenc_si128(t2, k); \+ t3 = _mm_aesenc_si128(t3, k); \+ t4 = _mm_aesenc_si128(t4, k); \+ t5 = _mm_aesenc_si128(t5, RK(ak, r)); \+ GSTEP(); \+ } \+ { \+ __m128i k = RK(rk, rounds); \+ t0 = _mm_aesenclast_si128(t0, k); \+ t1 = _mm_aesenclast_si128(t1, k); \+ t2 = _mm_aesenclast_si128(t2, k); \+ t3 = _mm_aesenclast_si128(t3, k); \+ t4 = _mm_aesenclast_si128(t4, k); \+ t5 = _mm_aesenclast_si128(t5, RK(ak, rounds)); \+ } \+ } while (0)++/* the same with nothing queued to absorb: the decryption side takes its+ * GHASH straight from the input and has no queue to drain */+#define WIDE6_NOQ(alt) \+ do { \+ const uint8_t *ak = (alt); \+ int r; \+ t0 = _mm_xor_si128(t0, RK(rk, 0)); \+ t1 = _mm_xor_si128(t1, RK(rk, 0)); \+ t2 = _mm_xor_si128(t2, RK(rk, 0)); \+ t3 = _mm_xor_si128(t3, RK(rk, 0)); \+ t4 = _mm_xor_si128(t4, RK(rk, 0)); \+ t5 = _mm_xor_si128(t5, RK(ak, 0)); \+ for (r = 1; r < rounds; r++) { \+ __m128i k = RK(rk, r); \+ t0 = _mm_aesenc_si128(t0, k); \+ t1 = _mm_aesenc_si128(t1, k); \+ t2 = _mm_aesenc_si128(t2, k); \+ t3 = _mm_aesenc_si128(t3, k); \+ t4 = _mm_aesenc_si128(t4, k); \+ t5 = _mm_aesenc_si128(t5, RK(ak, r)); \+ } \+ { \+ __m128i k = RK(rk, rounds); \+ t0 = _mm_aesenclast_si128(t0, k); \+ t1 = _mm_aesenclast_si128(t1, k); \+ t2 = _mm_aesenclast_si128(t2, k); \+ t3 = _mm_aesenclast_si128(t3, k); \+ t4 = _mm_aesenclast_si128(t4, k); \+ t5 = _mm_aesenclast_si128(t5, RK(ak, rounds)); \+ } \+ } while (0)++/*+ * The same written out for the ten rounds of AES-128, with a slot for one+ * queued multiply between each of the first six. The loop above cannot take+ * them: the round count is a value in the key, so there is no place the+ * compiler knows is a round apart from the next, and a test before each+ * multiply would end the basic block the scheduler works inside. This pass+ * runs with a group's multiplies still waiting, and on a short message that+ * is most of what it has to do.+ */+#define WROUND6(r, ak) \+ do { \+ __m128i k = RK(rk, r); \+ t0 = _mm_aesenc_si128(t0, k); \+ t1 = _mm_aesenc_si128(t1, k); \+ t2 = _mm_aesenc_si128(t2, k); \+ t3 = _mm_aesenc_si128(t3, k); \+ t4 = _mm_aesenc_si128(t4, k); \+ t5 = _mm_aesenc_si128(t5, RK(ak, r)); \+ } while (0)++#define WIDE6_10(alt) \+ do { \+ const uint8_t *ak = (alt); \+ t0 = _mm_xor_si128(t0, RK(rk, 0)); \+ t1 = _mm_xor_si128(t1, RK(rk, 0)); \+ t2 = _mm_xor_si128(t2, RK(rk, 0)); \+ t3 = _mm_xor_si128(t3, RK(rk, 0)); \+ t4 = _mm_xor_si128(t4, RK(rk, 0)); \+ t5 = _mm_xor_si128(t5, RK(ak, 0)); \+ WROUND6(1, ak); GAT(0); \+ WROUND6(2, ak); GAT(1); \+ WROUND6(3, ak); GAT(2); \+ WROUND6(4, ak); GAT(3); \+ WROUND6(5, ak); GAT(4); \+ WROUND6(6, ak); GAT(5); \+ WROUND6(7, ak); \+ WROUND6(8, ak); \+ WROUND6(9, ak); \+ { \+ __m128i k = RK(rk, 10); \+ t0 = _mm_aesenclast_si128(t0, k); \+ t1 = _mm_aesenclast_si128(t1, k); \+ t2 = _mm_aesenclast_si128(t2, k); \+ t3 = _mm_aesenclast_si128(t3, k); \+ t4 = _mm_aesenclast_si128(t4, k); \+ t5 = _mm_aesenclast_si128(t5, RK(ak, 10)); \+ } \+ } while (0)++/*+ * v2: six blocks of AES in flight at once, so the ten rounds of one block no+ * longer wait on each other -- AES-NI is pipelined and will take one+ * instruction a clock as long as the instructions in flight are independent.+ * The GHASH multiplies of the group just finished are issued between the+ * rounds of the group now running, which is the stitching: they do not want+ * the same execution port, so held against each other they cost about what+ * the rounds alone cost.+ */++/*+ * The counter block, built without leaving the vector registers.+ *+ * GCM counts in the low 32 bits of the block, big endian, and wraps there.+ * ctr holds the block with its bytes reversed, so those four bytes are the+ * low lane and _mm_add_epi32 steps them without carrying into the nonce+ * above -- which is the wrap GCM asks for. A shuffle puts the bytes back.+ *+ * The obvious way -- increment a uint32_t, byte swap it, pinsrd it in --+ * costs a move from a general register to a vector one for every lane, six+ * to a group, and those do not come free.+ */+#define CTR6(j) \+ do { \+ ctr = _mm_add_epi32(ctr, one32); \+ b##j = _mm_xor_si128(_mm_shuffle_epi8(ctr, BSWAP), RK(rk, 0)); \+ } while (0)++#define ROUND6(r) \+ do { \+ __m128i k = RK(rk, r); \+ b0 = _mm_aesenc_si128(b0, k); \+ b1 = _mm_aesenc_si128(b1, k); \+ b2 = _mm_aesenc_si128(b2, k); \+ b3 = _mm_aesenc_si128(b3, k); \+ b4 = _mm_aesenc_si128(b4, k); \+ b5 = _mm_aesenc_si128(b5, k); \+ } while (0)++#define LAST6(r) \+ do { \+ __m128i k = RK(rk, r); \+ b0 = _mm_aesenclast_si128(b0, k); \+ b1 = _mm_aesenclast_si128(b1, k); \+ b2 = _mm_aesenclast_si128(b2, k); \+ b3 = _mm_aesenclast_si128(b3, k); \+ b4 = _mm_aesenclast_si128(b4, k); \+ b5 = _mm_aesenclast_si128(b5, k); \+ } while (0)++/* one GHASH multiply, taken from a queue of blocks waiting to be absorbed,+ * to be issued in the gaps between AES rounds */+/* A ring, so that a block queued while others are still waiting costs an+ * index and not a move: the queue is walked from both ends and never+ * compacted. */+#define GQ_MASK 15++#define GPUSH(v) \+ do { gq[gw] = (v); gw++; gn++; } while (0)++#define GSTEP() \+ do { \+ if (gn > 0) { \+ GHASH_ONE(gq[gi], gp); \+ gi++; gp--; gn--; \+ } \+ } while (0)++/* the same at a slot the compiler can see, for the unrolled group below */+/*+ * One queued block, at a slot the compiler can see and with nothing to test+ * before it. A test here would end the basic block, and the scheduler works+ * inside one: six tests turn the group into twelve blocks and the multiplies+ * can no longer be moved up among the rounds, which is the whole point of+ * writing them there. The group below is entered only when the queue is+ * full, so there is nothing to test.+ */+/*+ * The block a slot names, read from the output where the group before it+ * left the ciphertext rather than from a copy kept beside it. The copy+ * cost six stores a group for bytes already in memory; picotls's fusion+ * points its GHASH at the output it has just written for the same reason.+ */+#define GAT(j) GHASH_ONE(_mm_shuffle_epi8( \+ _mm_loadu_si128((const __m128i *) (prev + 16 * (j))), BSWAP), gp - (j))++TGT void crypton_gcm_fused_encrypt(uint8_t *out, const aes_gcm_fused *fk,+ const aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, size_t aadlen,+ const uint8_t *in, size_t inlen, size_t taglen,+ const aes_key *hpkey, size_t sampleoff,+ uint8_t *mask)+{+ const uint8_t *rk = key->data;+ const uint8_t *hprk = hpkey != 0 ? hpkey->data : rk;+ const int rounds = key->nbr;+ const int hprounds = hpkey != 0 ? hpkey->nbr : rounds;+ GHASH_DECL;+ __m128i ctrbase, ctr, one32, ek0, tag, b0, b1, b2, b3, b4, b5;+ const int ntail_pre = (int) ((inlen % 96 + 15) / 16);+ int lane_ek0;+ __m128i gq[6];+ unsigned gi = 0, gw = 0;+ int gn = 0;+ size_t nblk = (aadlen + 15) / 16 + (inlen + 15) / 16 + 1;+ const int gtotal = (int) nblk;+ int gp = (int) nblk;+ size_t i;+ size_t done;+ int lane_mask = 0;++ /*+ * Y0: the twelve bytes of nonce and a counter of one. loadn reads the+ * nonce where it lies and masks what is above it, so this is one load+ * rather than three of four bytes each and a set built from them.+ */+ ctrbase = _mm_insert_epi32(loadn(nonce, 12), (int) __builtin_bswap32(1), 3);+ ctr = _mm_shuffle_epi8(ctrbase, BSWAP);+ one32 = _mm_set_epi32(0, 0, 0, 1);++ lane_ek0 = ntail_pre > 0 && ntail_pre <= 4;+ if (!lane_ek0)+ ek0 = aes_one_block(rk, rounds, ctrbase);++ /* The additional data goes in first and takes the highest powers, but it+ * is only queued here: absorbing it takes multiplies, and the multiplies+ * belong in the gaps between the AES rounds below rather than in front+ * of them where nothing else is running. */+ /*+ * The additional data goes in first and takes the highest powers. It is+ * absorbed here rather than queued: what the queue is for is giving the+ * rounds below something to interleave with, and a queue that sometimes+ * holds the header and sometimes does not forces a test before every+ * multiply -- which is what stopped the interleaving from happening at+ * all. See the peeled first group below.+ */+ {+ size_t nfull = aadlen / 16;+ size_t rest = aadlen % 16;++ for (i = 0; i < nfull; i++)+ GHASH_ONE(_mm_shuffle_epi8(+ _mm_loadu_si128((const __m128i *) (aad + i * 16)), BSWAP), 0);+ if (rest)+ GHASH_ONE(_mm_shuffle_epi8(loadn(aad + nfull * 16, rest), BSWAP), 0);+ }++ /* Whole groups of six. The rounds are written out rather than looped:+ * the number of them is a value in the key, so a loop over it leaves the+ * compiler fetching each round key through an index it cannot fold, and+ * the six lanes go to memory with them. Written out, the whole group+ * stays in registers, and the six multiplies of the group before can be+ * placed between the rounds by hand -- which is the stitching: AES-NI+ * and PCLMULQDQ do not contend for the same port, so the multiplies are+ * very nearly free.+ */+ done = 0;+ if (rounds == 10) {+ if (done + 96 <= inlen) {+ const uint8_t *p = in + done;+ uint8_t *q = out + done;++ CTR6(0); CTR6(1); CTR6(2); CTR6(3); CTR6(4); CTR6(5);+ ROUND6(1);+ ROUND6(2);+ ROUND6(3);+ ROUND6(4);+ ROUND6(5);+ ROUND6(6);+ ROUND6(7);+ ROUND6(8);+ ROUND6(9);+ LAST6(10);+ gn = 0; gi = 0; gw = 0;++ b0 = _mm_xor_si128(b0, _mm_loadu_si128((const __m128i *) p));+ b1 = _mm_xor_si128(b1, _mm_loadu_si128((const __m128i *) (p + 16)));+ b2 = _mm_xor_si128(b2, _mm_loadu_si128((const __m128i *) (p + 32)));+ b3 = _mm_xor_si128(b3, _mm_loadu_si128((const __m128i *) (p + 48)));+ b4 = _mm_xor_si128(b4, _mm_loadu_si128((const __m128i *) (p + 64)));+ b5 = _mm_xor_si128(b5, _mm_loadu_si128((const __m128i *) (p + 80)));+ _mm_storeu_si128((__m128i *) q, b0);+ _mm_storeu_si128((__m128i *) (q + 16), b1);+ _mm_storeu_si128((__m128i *) (q + 32), b2);+ _mm_storeu_si128((__m128i *) (q + 48), b3);+ _mm_storeu_si128((__m128i *) (q + 64), b4);+ _mm_storeu_si128((__m128i *) (q + 80), b5);++ done += 96;+ }+ for (; done + 96 <= inlen; done += 96) {+ const uint8_t *p = in + done;+ uint8_t *q = out + done;+ const uint8_t *prev = out + done - 96;++ CTR6(0); CTR6(1); CTR6(2); CTR6(3); CTR6(4); CTR6(5);+ ROUND6(1); GAT(0);+ ROUND6(2); GAT(1);+ ROUND6(3); GAT(2);+ ROUND6(4); GAT(3);+ ROUND6(5); GAT(4);+ ROUND6(6); GAT(5);+ ROUND6(7);+ ROUND6(8);+ ROUND6(9);+ LAST6(10);+ gp -= 6;++ b0 = _mm_xor_si128(b0, _mm_loadu_si128((const __m128i *) p));+ b1 = _mm_xor_si128(b1, _mm_loadu_si128((const __m128i *) (p + 16)));+ b2 = _mm_xor_si128(b2, _mm_loadu_si128((const __m128i *) (p + 32)));+ b3 = _mm_xor_si128(b3, _mm_loadu_si128((const __m128i *) (p + 48)));+ b4 = _mm_xor_si128(b4, _mm_loadu_si128((const __m128i *) (p + 64)));+ b5 = _mm_xor_si128(b5, _mm_loadu_si128((const __m128i *) (p + 80)));+ _mm_storeu_si128((__m128i *) q, b0);+ _mm_storeu_si128((__m128i *) (q + 16), b1);+ _mm_storeu_si128((__m128i *) (q + 32), b2);+ _mm_storeu_si128((__m128i *) (q + 48), b3);+ _mm_storeu_si128((__m128i *) (q + 64), b4);+ _mm_storeu_si128((__m128i *) (q + 80), b5);++ /* straight from the registers the last round left them in: the+ * queue existed only to hold them until the next group's rounds+ * could hide the multiplies, and that is 192 bytes of store and+ * load per 96 bytes of payload */+ }++ } else {+ for (done = 0; done + 96 <= inlen; done += 96) {+ const uint8_t *p = in + done;+ uint8_t *q = out + done;+ int r;++ CTR6(0); CTR6(1); CTR6(2); CTR6(3); CTR6(4); CTR6(5);+ for (r = 1; r < rounds; r++) {+ ROUND6(r);+ GSTEP();+ }+ LAST6(rounds);++ b0 = _mm_xor_si128(b0, _mm_loadu_si128((const __m128i *) p));+ b1 = _mm_xor_si128(b1, _mm_loadu_si128((const __m128i *) (p + 16)));+ b2 = _mm_xor_si128(b2, _mm_loadu_si128((const __m128i *) (p + 32)));+ b3 = _mm_xor_si128(b3, _mm_loadu_si128((const __m128i *) (p + 48)));+ b4 = _mm_xor_si128(b4, _mm_loadu_si128((const __m128i *) (p + 64)));+ b5 = _mm_xor_si128(b5, _mm_loadu_si128((const __m128i *) (p + 80)));+ _mm_storeu_si128((__m128i *) q, b0);+ _mm_storeu_si128((__m128i *) (q + 16), b1);+ _mm_storeu_si128((__m128i *) (q + 32), b2);+ _mm_storeu_si128((__m128i *) (q + 48), b3);+ _mm_storeu_si128((__m128i *) (q + 64), b4);+ _mm_storeu_si128((__m128i *) (q + 80), b5);++ while (gn > 0) GSTEP();+ gi = 0; gw = 0;+ gq[0] = _mm_shuffle_epi8(b0, BSWAP);+ gq[1] = _mm_shuffle_epi8(b1, BSWAP);+ gq[2] = _mm_shuffle_epi8(b2, BSWAP);+ gq[3] = _mm_shuffle_epi8(b3, BSWAP);+ gq[4] = _mm_shuffle_epi8(b4, BSWAP);+ gq[5] = _mm_shuffle_epi8(b5, BSWAP);+ gn = 6;+ }+ }++ /* The tail. The wide pass below runs only when there are blocks for it:+ * sixty AES instructions to fill one lane is not worth it, so a message+ * that ends on a group boundary leaves E(K,Y0) the chain it was given+ * above and takes the mask on one of its own.+ *+ * The spare lane carries the mask only when two things hold. The sample+ * has to lie entirely in output the groups above have already written:+ * this pass reads it while it runs, and the blocks it is itself+ * computing are stored after it, so a sample reaching into them would be+ * read before it exists. And the two key schedules have to have the+ * same number of rounds, because the lanes share the loop that counts+ * them and a shorter schedule would be read past its end. TLS and QUIC+ * satisfy both; anything else gets the mask on a chain of its own, which+ * is what it would have had anyway. */+ {+ __m128i t0, t1, t2, t3, t4, t5;+ __m128i tv[6];+ size_t toff[6];+ int ntail = 0, j;++ if (done >= inlen) goto no_tail;++ for (i = done; i < inlen; i += 16) {+ toff[ntail] = i;+ ctr = _mm_add_epi32(ctr, one32);+ tv[ntail] = _mm_shuffle_epi8(ctr, BSWAP);+ ntail++;+ }++ lane_mask = ntail > 0 && ntail <= 5 && hpkey != 0 && mask != 0+ && hprounds == rounds+ && sampleoff + 16 <= done;++ if (ntail > 0) {+ t0 = tv[0];+ t1 = ntail > 1 ? tv[1] : ctrbase;+ t2 = ntail > 2 ? tv[2] : ctrbase;+ t3 = ntail > 3 ? tv[3] : ctrbase;+ t4 = lane_ek0 ? ctrbase : (ntail > 4 ? tv[4] : ctrbase);+ t5 = lane_mask+ ? _mm_loadu_si128((const __m128i *) (out + sampleoff))+ : (ntail > 5 ? tv[5] : ctrbase);+ /* A group leaves exactly six queued, which is what lets the+ * slots below be named at compile time. Where no group ran+ * there is nothing to place and the plain pass will do. */+ if (rounds == 10 && done >= 96) {+ const uint8_t *prev = out + done - 96;+ WIDE6_10(lane_mask ? hprk : rk);+ } else {+ WIDE6(lane_mask ? hprk : rk);+ }+ if (lane_ek0)+ ek0 = t4;+ else+ tv[4] = t4;+ if (lane_mask)+ _mm_storeu_si128((__m128i *) mask, t5);+ else if (ntail > 5)+ tv[5] = t5;+ }+no_tail:+ while (gn > 0) GSTEP();++ /* The last group's ciphertext is absorbed by the pass above where+ * there is one to absorb it. A message that ends on a group+ * boundary has no such pass, so it is taken here. */+ if (rounds == 10 && done >= 96 && ntail == 0) {+ const uint8_t *prev = out + done - 96;+ GAT(0); GAT(1); GAT(2); GAT(3); GAT(4); GAT(5);+ }++ /*+ * The tail blocks, from the registers the pass left them in. They+ * were going through an array indexed by the loop variable, which+ * the compiler cannot see through and so keeps in memory: every+ * block then reloaded its own keystream. Named one per block and+ * reached by a test on a count instead, they stay where they are.+ */+#define TAILBLK(j, reg) \+ do { \+ size_t off = done + 16 * (j); \+ size_t n = inlen - off < 16 ? inlen - off : 16; \+ __m128i c = _mm_xor_si128(reg, n == 16 \+ ? _mm_loadu_si128((const __m128i *) (in + off)) \+ : loadn(in + off, n)); \+ if (n == 16) { \+ _mm_storeu_si128((__m128i *) (out + off), c); \+ } else { \+ /* the tag goes in directly above, so those bytes are \+ * written over anyway where there are sixteen to spare */ \+ if (n + taglen >= 16) \+ _mm_storeu_si128((__m128i *) (out + off), c); \+ else \+ storen(out + off, c, n); \+ c = clampn(c, n); \+ } \+ GHASH_ONE(_mm_shuffle_epi8(c, BSWAP), gp); \+ gp--; \+ } while (0)++ if (ntail > 0) TAILBLK(0, t0);+ if (ntail > 1) TAILBLK(1, t1);+ if (ntail > 2) TAILBLK(2, t2);+ if (ntail > 3) TAILBLK(3, t3);+ if (ntail > 4) TAILBLK(4, tv[4]);+ if (ntail > 5) TAILBLK(5, tv[5]);+#undef TAILBLK+ }++ {+ /*+ * The length block: the additional data's bit count and the+ * message's, each big endian in a half, and then reversed like+ * every other block on its way to GHASH.+ *+ * Reversed, that block is the two counts as ordinary little endian+ * words with the message's in the low half -- which is one set, and+ * no shuffle. Sixteen byte stores to the stack and a load back is+ * what it cost before.+ */+ GHASH_ONE(_mm_set_epi64x((long long) ((uint64_t) aadlen << 3),+ (long long) ((uint64_t) inlen << 3)), gp);+ }++ tag = _mm_shuffle_epi8(gtag, BSWAP);+ tag = _mm_xor_si128(tag, ek0);+ if (taglen == 16)+ _mm_storeu_si128((__m128i *) (out + inlen), tag);+ else+ storen(out + inlen, tag, taglen);++ /* A sample the pass above could not reach -- because it covered blocks+ * that pass was still computing, or the tag, which is written just now+ * -- is taken here instead, where everything it can cover exists. */+ if (!lane_mask && hpkey != 0 && mask != 0)+ _mm_storeu_si128((__m128i *) mask,+ aes_one_block(hprk, hprounds, _mm_loadu_si128(+ (const __m128i *) (out + sampleoff))));+}+++/*+ * The same for decryption, which is the simpler of the two.+ *+ * What GHASH absorbs here is the ciphertext, and the ciphertext is the+ * input: it is there before any of the AES has run. So there is no queue --+ * the multiplies of a group go between the rounds of that same group rather+ * than waiting for the one after, and nothing is stored and loaded back to+ * carry them across.+ *+ * The tag is compared here, every byte of it whichever way the answer goes,+ * and the answer is 1 for a message whose tag matched.+ */++/* one ciphertext block straight from the input, at a slot named here */+#define DAT(j) GHASH_ONE(_mm_shuffle_epi8( \+ _mm_loadu_si128((const __m128i *) (p + 16 * (j))), BSWAP), 0)++/* the next counter block, into a named register */+#define CTRT(t) \+ do { ctr = _mm_add_epi32(ctr, one32); \+ t = _mm_shuffle_epi8(ctr, BSWAP); } while (0)++TGT int crypton_gcm_fused_decrypt(uint8_t *out, const aes_gcm_fused *fk,+ const aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, size_t aadlen,+ const uint8_t *in, size_t inlen,+ const uint8_t *tag, size_t taglen,+ uint8_t *outtag)+{+ const uint8_t *rk = key->data;+ const int rounds = key->nbr;+ GHASH_DECL;+ __m128i ctrbase, ctr, one32, ek0, want, b0, b1, b2, b3, b4, b5;+ const int ntail_pre = (int) ((inlen % 96 + 15) / 16);+ int lane_ek0, gp = 0;+ const int gtotal = (int) ((aadlen + 15) / 16 + (inlen + 15) / 16 + 1);+ size_t i;+ size_t done;+ uint8_t diff = 0;++ ctrbase = _mm_insert_epi32(loadn(nonce, 12), (int) __builtin_bswap32(1), 3);+ ctr = _mm_shuffle_epi8(ctrbase, BSWAP);+ one32 = _mm_set_epi32(0, 0, 0, 1);++ lane_ek0 = ntail_pre > 0 && ntail_pre <= 5;+ if (!lane_ek0)+ ek0 = aes_one_block(rk, rounds, ctrbase);++ {+ size_t nfull = aadlen / 16;+ size_t rest = aadlen % 16;++ for (i = 0; i < nfull; i++)+ GHASH_ONE(_mm_shuffle_epi8(+ _mm_loadu_si128((const __m128i *) (aad + i * 16)), BSWAP), 0);+ if (rest)+ GHASH_ONE(_mm_shuffle_epi8(loadn(aad + nfull * 16, rest), BSWAP), 0);+ }++ done = 0;+ if (rounds == 10) {+ for (; done + 96 <= inlen; done += 96) {+ const uint8_t *p = in + done;+ uint8_t *q = out + done;++ CTR6(0); CTR6(1); CTR6(2); CTR6(3); CTR6(4); CTR6(5);+ ROUND6(1); DAT(0);+ ROUND6(2); DAT(1);+ ROUND6(3); DAT(2);+ ROUND6(4); DAT(3);+ ROUND6(5); DAT(4);+ ROUND6(6); DAT(5);+ ROUND6(7);+ ROUND6(8);+ ROUND6(9);+ LAST6(10);++ _mm_storeu_si128((__m128i *) q,+ _mm_xor_si128(b0, _mm_loadu_si128((const __m128i *) p)));+ _mm_storeu_si128((__m128i *) (q + 16),+ _mm_xor_si128(b1, _mm_loadu_si128((const __m128i *) (p + 16))));+ _mm_storeu_si128((__m128i *) (q + 32),+ _mm_xor_si128(b2, _mm_loadu_si128((const __m128i *) (p + 32))));+ _mm_storeu_si128((__m128i *) (q + 48),+ _mm_xor_si128(b3, _mm_loadu_si128((const __m128i *) (p + 48))));+ _mm_storeu_si128((__m128i *) (q + 64),+ _mm_xor_si128(b4, _mm_loadu_si128((const __m128i *) (p + 64))));+ _mm_storeu_si128((__m128i *) (q + 80),+ _mm_xor_si128(b5, _mm_loadu_si128((const __m128i *) (p + 80))));+ }+ } else {+ for (; done + 96 <= inlen; done += 96) {+ const uint8_t *p = in + done;+ uint8_t *q = out + done;+ int r;++ CTR6(0); CTR6(1); CTR6(2); CTR6(3); CTR6(4); CTR6(5);+ for (r = 1; r < rounds; r++) {+ ROUND6(r);+ if (r <= 6) DAT(r - 1);+ }+ LAST6(rounds);++ _mm_storeu_si128((__m128i *) q,+ _mm_xor_si128(b0, _mm_loadu_si128((const __m128i *) p)));+ _mm_storeu_si128((__m128i *) (q + 16),+ _mm_xor_si128(b1, _mm_loadu_si128((const __m128i *) (p + 16))));+ _mm_storeu_si128((__m128i *) (q + 32),+ _mm_xor_si128(b2, _mm_loadu_si128((const __m128i *) (p + 32))));+ _mm_storeu_si128((__m128i *) (q + 48),+ _mm_xor_si128(b3, _mm_loadu_si128((const __m128i *) (p + 48))));+ _mm_storeu_si128((__m128i *) (q + 64),+ _mm_xor_si128(b4, _mm_loadu_si128((const __m128i *) (p + 64))));+ _mm_storeu_si128((__m128i *) (q + 80),+ _mm_xor_si128(b5, _mm_loadu_si128((const __m128i *) (p + 80))));+ }+ }++ /* the tail, with E(K,Y0) in a lane the length leaves idle */+ {+ __m128i t0, t1, t2, t3, t4, t5;+ int ntail = (int) ((inlen - done + 15) / 16), j;++ /* the counter is where the groups left it */+ t0 = t1 = t2 = t3 = t4 = t5 = ctrbase;+ if (ntail > 0) CTRT(t0);+ if (ntail > 1) CTRT(t1);+ if (ntail > 2) CTRT(t2);+ if (ntail > 3) CTRT(t3);+ if (ntail > 4) CTRT(t4);+ if (ntail > 5) CTRT(t5);++ if (ntail > 0) {+ WIDE6_NOQ(rk);+ if (lane_ek0) ek0 = t5;+ }++ for (j = 0; j < ntail; j++) {+ size_t off = done + 16 * (size_t) j;+ size_t n = inlen - off < 16 ? inlen - off : 16;+ __m128i c = n == 16 ? _mm_loadu_si128((const __m128i *) (in + off))+ : loadn(in + off, n);+ __m128i ks = j == 0 ? t0 : j == 1 ? t1 : j == 2 ? t2+ : j == 3 ? t3 : j == 4 ? t4 : t5;++ GHASH_ONE(_mm_shuffle_epi8(c, BSWAP), 0);+ {+ __m128i pl = _mm_xor_si128(ks, c);+ if (n == 16)+ _mm_storeu_si128((__m128i *) (out + off), pl);+ else+ storen(out + off, pl, n);+ }+ }+ }++ GHASH_ONE(_mm_set_epi64x((long long) ((uint64_t) aadlen << 3),+ (long long) ((uint64_t) inlen << 3)), gp);++ want = _mm_xor_si128(_mm_shuffle_epi8(gtag, BSWAP), ek0);+ {+ uint8_t got[16];+ _mm_storeu_si128((__m128i *) got, want);+ if (outtag) {+ /* The caller holds the expected tag and will compare it itself. */+ memcpy(outtag, got, taglen);+ return 1;+ }+ for (i = 0; i < taglen; i++)+ diff |= (uint8_t) (got[i] ^ tag[i]);+ }+ return diff == 0;+}++#endif /* WITH_GCM_FUSED */
+ cbits/aes/gcm_fused_x86.h view
@@ -0,0 +1,55 @@+/*+ * Copyright (c) 2026 Kazu Yamamoto <kazu@iij.ad.jp>+ *+ * All rights reserved.+ *+ * Redistribution and use in source and binary forms, with or without+ * modification, are permitted provided that the following conditions+ * are met:+ * 1. Redistributions of source code must retain the above copyright+ * notice, this list of conditions and the following disclaimer.+ * 2. Redistributions in binary form must reproduce the above copyright+ * notice, this list of conditions and the following disclaimer in the+ * documentation and/or other materials provided with the distribution.+ * 3. Neither the name of the author nor the names of his contributors+ * may be used to endorse or promote products derived from this software+ * without specific prior written permission.+ *+ * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND+ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE+ * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE+ * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL+ * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS+ * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)+ * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT+ * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY+ * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF+ * SUCH DAMAGE.+ */++#ifndef CRYPTON_GCM_FUSED_X86_H+#define CRYPTON_GCM_FUSED_X86_H++#include <stdint.h>+#include <stddef.h>+#include <crypton_aes.h>++void crypton_gcm_fused_key_init(aes_gcm_fused *fk, const aes_key *key);++void crypton_gcm_fused_encrypt(uint8_t *out, const aes_gcm_fused *fk,+ const aes_key *key,+ const uint8_t *nonce,+ const uint8_t *aad, size_t aadlen,+ const uint8_t *in, size_t inlen, size_t taglen,+ const aes_key *hpkey, size_t sampleoff,+ uint8_t *mask);++int crypton_gcm_fused_decrypt(uint8_t *out, const aes_gcm_fused *fk,+ const aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, size_t aadlen,+ const uint8_t *in, size_t inlen,+ const uint8_t *tag, size_t taglen,+ uint8_t *outtag);++#endif
+ cbits/aes/gcm_vaes512_x86.c view
@@ -0,0 +1,364 @@+/*+ * AES-GCM through VAES and VPCLMULQDQ in their 512-bit form, which takes+ * four blocks where the 256-bit form in cbits/aes/gcm_vaes_x86.c takes two+ * and the 128-bit one takes one. The instruction rate is the same, so the+ * work per group halves again.+ *+ * This is that file widened and nothing else: the same group of sixteen+ * blocks, the same descending powers of H sharing one reduction, the same+ * round keys read from memory rather than held in registers. Four blocks to+ * a register means the group fills four of them rather than eight, which is+ * what leaves room for the group's own ciphertext to be kept for the GHASH+ * when encrypting.+ *+ * Nothing here is borrowed. OpenSSL's and BoringSSL's AVX-512 AES-GCM is+ * Apache-2.0 and s2n-bignum has no GCM at all.+ *+ * The reduction at the end is a copy of the one in gcm_vaes_x86.c rather+ * than a call to it: the two files are compiled for different instruction+ * sets, and a function compiled for one cannot be inlined into the other.+ */+#include "aes/gcm_vaes512_x86.h"++#ifdef WITH_GCM_VAES512++#include <string.h>+#include <immintrin.h>++#include <aes/gf.h>+#include <aes/block128.h>++#if defined(__clang__) || defined(__GNUC__)+#define V512_TARGET \+ __attribute__((target("avx512f,avx512bw,avx512vl,aes,pclmul,vaes,vpclmulqdq")))+#else+#define V512_TARGET+#endif++/*+ * Thirty-two blocks to a group, four to a register, so eight registers are+ * in flight. The number of registers is what matters as much as the blocks+ * per instruction: AES-NI has a latency of four cycles against a throughput+ * of one, so it takes eight independent chains to keep two ports busy. Four+ * registers of four blocks was written first and measured *slower* than the+ * 256-bit path -- the blocks per instruction had doubled and the chains had+ * halved.+ *+ * The table holds sixteen powers of H, so the GHASH of a group is two passes+ * of sixteen blocks, the second picking up the tag the first leaves.+ */+#define V512WIDE 8+#define V512HALF 4+#define V512BYTES 512++/*+ * The 128-bit multiply of cbits/aes/x86ni.c, done in all four lanes at once.+ * Every shuffle and shift here works inside its own 128-bit lane, so the+ * four products never mix: what comes out is four independent carry-less+ * products, accumulated by the caller and reduced together at the end.+ */+V512_TARGET+static inline void clmul512(__m512i a, __m512i b, __m512i *lo, __m512i *hi)+{+ const __m512i bswap = _mm512_set4_epi32(+ 0x00010203, 0x04050607, 0x08090a0b, 0x0c0d0e0f);+ __m512i t3, t4, t5, t6;++ a = _mm512_shuffle_epi8(a, bswap);++ /* Karatsuba, as in the 128-bit one: three multiplies, not four */+ t3 = _mm512_clmulepi64_epi128(a, b, 0x00);+ t6 = _mm512_clmulepi64_epi128(a, b, 0x11);+ t4 = _mm512_clmulepi64_epi128(+ _mm512_xor_si512(a, _mm512_shuffle_epi32(a, _MM_PERM_BADC)),+ _mm512_xor_si512(b, _mm512_shuffle_epi32(b, _MM_PERM_BADC)),+ 0x00);+ t4 = _mm512_xor_si512(t4, _mm512_xor_si512(t3, t6));++ t5 = _mm512_bslli_epi128(t4, 8);+ t4 = _mm512_bsrli_epi128(t4, 8);++ *lo = _mm512_xor_si512(t3, t5);+ *hi = _mm512_xor_si512(t6, t4);+}++/*+ * The reduction of cbits/aes/x86ni.c. By the time it runs the four lanes+ * have been folded into one, so there is one 256-bit product to reduce.+ */+V512_TARGET+static inline __m128i gfred512(__m128i t3, __m128i t6)+{+ const __m128i bswap = _mm_set_epi8(0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15);+ __m128i t2, t4, t5, t7, t8, t9;++ t7 = _mm_srli_epi32(t3, 31);+ t8 = _mm_srli_epi32(t6, 31);+ t3 = _mm_slli_epi32(t3, 1);+ t6 = _mm_slli_epi32(t6, 1);++ t9 = _mm_srli_si128(t7, 12);+ t8 = _mm_slli_si128(t8, 4);+ t7 = _mm_slli_si128(t7, 4);+ t3 = _mm_or_si128(t3, t7);+ t6 = _mm_or_si128(t6, t8);+ t6 = _mm_or_si128(t6, t9);++ t7 = _mm_slli_epi32(t3, 31);+ t8 = _mm_slli_epi32(t3, 30);+ t9 = _mm_slli_epi32(t3, 25);++ t7 = _mm_xor_si128(t7, t8);+ t7 = _mm_xor_si128(t7, t9);+ t8 = _mm_srli_si128(t7, 4);+ t7 = _mm_slli_si128(t7, 12);+ t3 = _mm_xor_si128(t3, t7);++ t2 = _mm_srli_epi32(t3, 1);+ t4 = _mm_srli_epi32(t3, 2);+ t5 = _mm_srli_epi32(t3, 7);+ t2 = _mm_xor_si128(t2, t4);+ t2 = _mm_xor_si128(t2, t5);+ t2 = _mm_xor_si128(t2, t8);+ t3 = _mm_xor_si128(t3, t2);+ t6 = _mm_xor_si128(t6, t3);++ return _mm_shuffle_epi8(t6, bswap);+}++/* the four 128-bit lanes of a register added together */+V512_TARGET+static inline __m128i fold512(__m512i v)+{+ __m256i h = _mm256_xor_si256(_mm512_castsi512_si256(v),+ _mm512_extracti64x4_epi64(v, 1));++ return _mm_xor_si128(_mm256_castsi256_si128(h),+ _mm256_extracti128_si256(h, 1));+}++/*+ * Sixteen blocks against H^16 .. H^1, one reduction. v[j] holds blocks 4j+ * to 4j+3 in its four lanes, so the powers for it are H^(16-4j) down to+ * H^(13-4j) -- the table's own order the other way round, hence the four+ * 128-bit loads rather than one 512-bit one.+ */+V512_TARGET+static inline __m128i ghash16(__m128i tag, const table_4bit htable,+ const __m512i *v, int fromwire)+{+ __m512i lo = _mm512_setzero_si512(), hi = _mm512_setzero_si512();+ __m512i l, h, b;+ int j;++ for (j = 0; j < V512HALF; j++) {+ const __m128i p0 =+ _mm_loadu_si128((const __m128i *) &htable[15 - 4 * j]);+ const __m128i p1 =+ _mm_loadu_si128((const __m128i *) &htable[14 - 4 * j]);+ const __m128i p2 =+ _mm_loadu_si128((const __m128i *) &htable[13 - 4 * j]);+ const __m128i p3 =+ _mm_loadu_si128((const __m128i *) &htable[12 - 4 * j]);+ __m512i hp = _mm512_castsi128_si512(p0);++ hp = _mm512_inserti32x4(hp, p1, 1);+ hp = _mm512_inserti32x4(hp, p2, 2);+ hp = _mm512_inserti32x4(hp, p3, 3);++ b = fromwire ? _mm512_loadu_si512(v + j) : v[j];+ if (j == 0) /* the running tag joins the first block */+ b = _mm512_xor_si512(+ b, _mm512_inserti32x4(+ _mm512_setzero_si512(), tag, 0));+ clmul512(b, hp, &l, &h);+ lo = _mm512_xor_si512(lo, l);+ hi = _mm512_xor_si512(hi, h);+ }++ /* the four lanes are independent products of the same sum: fold them */+ return gfred512(fold512(lo), fold512(hi));+}++#define KK512(r) _mm512_broadcast_i32x4(_mm_loadu_si128(k_ + (r)))++#define AESENC32(K) \+ do { \+ const __m512i rk = (K); \+ v[0] = _mm512_aesenc_epi128(v[0], rk); \+ v[1] = _mm512_aesenc_epi128(v[1], rk); \+ v[2] = _mm512_aesenc_epi128(v[2], rk); \+ v[3] = _mm512_aesenc_epi128(v[3], rk); \+ v[4] = _mm512_aesenc_epi128(v[4], rk); \+ v[5] = _mm512_aesenc_epi128(v[5], rk); \+ v[6] = _mm512_aesenc_epi128(v[6], rk); \+ v[7] = _mm512_aesenc_epi128(v[7], rk); \+ } while (0)++#define AESLAST32(K) \+ do { \+ const __m512i rk = (K); \+ v[0] = _mm512_aesenclast_epi128(v[0], rk); \+ v[1] = _mm512_aesenclast_epi128(v[1], rk); \+ v[2] = _mm512_aesenclast_epi128(v[2], rk); \+ v[3] = _mm512_aesenclast_epi128(v[3], rk); \+ v[4] = _mm512_aesenclast_epi128(v[4], rk); \+ v[5] = _mm512_aesenclast_epi128(v[5], rk); \+ v[6] = _mm512_aesenclast_epi128(v[6], rk); \+ v[7] = _mm512_aesenclast_epi128(v[7], rk); \+ } while (0)++#define XOR32(K) \+ do { \+ const __m512i rk = (K); \+ v[0] = _mm512_xor_si512(v[0], rk); \+ v[1] = _mm512_xor_si512(v[1], rk); \+ v[2] = _mm512_xor_si512(v[2], rk); \+ v[3] = _mm512_xor_si512(v[3], rk); \+ v[4] = _mm512_xor_si512(v[4], rk); \+ v[5] = _mm512_xor_si512(v[5], rk); \+ v[6] = _mm512_xor_si512(v[6], rk); \+ v[7] = _mm512_xor_si512(v[7], rk); \+ } while (0)++/*+ * The rounds are written out rather than looped for the reason the 128-bit+ * loop gives: the count is a value in the key, and a loop over it leaves the+ * round key reached through an index the compiler cannot fold.+ */+V512_TARGET+static inline __attribute__((always_inline)) void+rounds32(__m512i *v, const uint8_t *k, const int nbr)+{+ const __m128i *k_ = (const __m128i *) k;++ XOR32(KK512(0));+ AESENC32(KK512(1)); AESENC32(KK512(2)); AESENC32(KK512(3));+ AESENC32(KK512(4)); AESENC32(KK512(5)); AESENC32(KK512(6));+ AESENC32(KK512(7)); AESENC32(KK512(8)); AESENC32(KK512(9));+ if (nbr > 10) {+ AESENC32(KK512(10)); AESENC32(KK512(11));+ if (nbr > 12) {+ AESENC32(KK512(12)); AESENC32(KK512(13));+ }+ }+ AESLAST32(_mm512_broadcast_i32x4(_mm_loadu_si128(k_ + nbr)));+}++/* sixteen consecutive counters, four to a register. GCM counts in the low+ * thirty-two bits and wraps there, which is what _mm_add_epi32 does. */+V512_TARGET+static inline __m128i counters32(__m512i *v, __m128i iv, __m128i one,+ __m128i bswap)+{+ int j;++ for (j = 0; j < V512WIDE; j++) {+ __m128i c0, c1, c2, c3;+ __m512i c;++ iv = _mm_add_epi32(iv, one);+ c0 = _mm_shuffle_epi8(iv, bswap);+ iv = _mm_add_epi32(iv, one);+ c1 = _mm_shuffle_epi8(iv, bswap);+ iv = _mm_add_epi32(iv, one);+ c2 = _mm_shuffle_epi8(iv, bswap);+ iv = _mm_add_epi32(iv, one);+ c3 = _mm_shuffle_epi8(iv, bswap);++ c = _mm512_castsi128_si512(c0);+ c = _mm512_inserti32x4(c, c1, 1);+ c = _mm512_inserti32x4(c, c2, 2);+ c = _mm512_inserti32x4(c, c3, 3);+ v[j] = c;+ }+ return iv;+}++/*+ * Inlined into three callers with the round count a constant in each, which+ * folds away the tests inside the group loop -- the same reason the 256-bit+ * file gives, where without it AES-256 lost what AES-128 gained.+ */+V512_TARGET+static inline __attribute__((always_inline)) uint32_t+bulk_n(uint8_t *output, aes_gcm *gcm, const aes_key *key,+ const uint8_t *input, uint32_t length, int decrypt, const int nbr)+{+ const __m128i bswap = _mm_setr_epi8(7,6,5,4,3,2,1,0,15,14,13,12,11,10,9,8);+ const __m128i one = _mm_set_epi32(0, 1, 0, 0);+ __m512i v[V512WIDE];+ __m128i iv, tag;+ uint32_t groups = length / V512BYTES;+ uint32_t done = 0;+ uint32_t g;+ int j;++ if (groups == 0)+ return 0;++ iv = _mm_shuffle_epi8(_mm_loadu_si128((const __m128i *) &gcm->civ), bswap);+ tag = _mm_loadu_si128((const __m128i *) &gcm->tag);++ for (g = 0; g < groups; g++, input += V512BYTES, output += V512BYTES,+ done += V512BYTES) {+ iv = counters32(v, iv, one, bswap);+ rounds32(v, key->data, nbr);++ for (j = 0; j < V512WIDE; j++) {+ const __m512i in =+ _mm512_loadu_si512((const __m512i *) (input + 64 * j));++ v[j] = _mm512_xor_si512(v[j], in);+ _mm512_storeu_si512((__m512i *) (output + 64 * j), v[j]);+ }+ /* sixteen blocks to a pass, since that is how many powers of+ * H the table holds; the second picks up the tag the first+ * leaves */+ tag = ghash16(tag, gcm->htable,+ decrypt ? (const __m512i *) input : v,+ decrypt);+ tag = ghash16(tag, gcm->htable,+ decrypt ? (const __m512i *) (input + 256)+ : v + V512HALF,+ decrypt);+ }++ _mm_storeu_si128((__m128i *) &gcm->civ, _mm_shuffle_epi8(iv, bswap));+ _mm_storeu_si128((__m128i *) &gcm->tag, tag);+ return done;+}++V512_TARGET+static uint32_t bulk(uint8_t *output, aes_gcm *gcm, const aes_key *key,+ const uint8_t *input, uint32_t length, int decrypt)+{+ switch (key->nbr) {+ case 10:+ return bulk_n(output, gcm, key, input, length, decrypt, 10);+ case 12:+ return bulk_n(output, gcm, key, input, length, decrypt, 12);+ case 14:+ return bulk_n(output, gcm, key, input, length, decrypt, 14);+ default:+ return 0; /* not a key length AES has */+ }+}++uint32_t crypton_gcm_vaes512_bulk_encrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input,+ uint32_t length)+{+ return bulk(output, gcm, key, input, length, 0);+}++uint32_t crypton_gcm_vaes512_bulk_decrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input,+ uint32_t length)+{+ return bulk(output, gcm, key, input, length, 1);+}++#endif
+ cbits/aes/gcm_vaes512_x86.h view
@@ -0,0 +1,37 @@+/*+ * AES-GCM in the 512-bit form of the AES and carry-less multiply+ * instructions, which do four blocks where the 128-bit ones do one and the+ * 256-bit ones in cbits/aes/gcm_vaes_x86.c do two.+ */+#ifndef CRYPTON_GCM_VAES512_X86_H+#define CRYPTON_GCM_VAES512_X86_H++#include <crypton_cpu.h>++#if defined(ARCH_X86) && defined(__x86_64__) && defined(WITH_AESNI) \+ && defined(WITH_PCLMUL)+#define WITH_GCM_VAES512+#endif++#ifdef WITH_GCM_VAES512++#include <stdint.h>+#include <crypton_aes.h>++/* The same contract as the 256-bit pair: whole groups off the front, the+ * counter left in gcm->civ and the running tag in gcm->tag, and the number+ * of bytes taken returned, a multiple of 512 and possibly zero. */+uint32_t crypton_gcm_vaes512_bulk_encrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input,+ uint32_t length);+uint32_t crypton_gcm_vaes512_bulk_decrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input,+ uint32_t length);++/* Thirty-two blocks is the least it will start on. */+#define GCM_VAES512_MIN_BLOCKS 32++#endif+#endif
+ cbits/aes/gcm_vaes_x86.c view
@@ -0,0 +1,325 @@+/*+ * AES-GCM through VAES and VPCLMULQDQ: the same AES and carry-less multiply+ * instructions the rest of this directory uses, in their 256-bit form, which+ * takes two blocks where the 128-bit form takes one. The instruction rate is+ * the same, so the throughput is twice -- measured at 2.00 on an EPYC 9V74,+ * for both halves, with nothing else in the loop.+ *+ * Nothing here is borrowed. OpenSSL's and BoringSSL's wide AES-GCM is+ * Apache-2.0, s2n-bignum has no GCM at all, and the CRYPTOGAMS assembly in+ * cbits/asm is 128-bit throughout -- its `vaesenc` is the VEX encoding of+ * AESENC on XMM, not the VAES extension. So this is the 128-bit loop in+ * cbits/aes/x86ni_impl.c widened, and it keeps that loop's shape: a group of+ * counters through the rounds together, the round keys read from memory+ * rather than held in registers, and the group's GHASH folded against+ * descending powers of H so that sixteen blocks share one reduction.+ *+ * The powers come from the table crypton_aesni_hinit_pclmul fills. It has+ * sixteen slots and the 128-bit loop uses eight of them; this uses all+ * sixteen, which is why that function now fills them.+ */+#include "aes/gcm_vaes_x86.h"++#ifdef WITH_GCM_VAES++#include <string.h>+#include <immintrin.h>++#include <aes/gf.h>+#include <aes/block128.h>++#if defined(__clang__) || defined(__GNUC__)+#define VAES_TARGET __attribute__((target("avx2,aes,pclmul,vaes,vpclmulqdq")))+#else+#define VAES_TARGET+#endif++/* sixteen blocks to a group, two to a register */+#define VWIDE 8++/*+ * The 128-bit multiply of cbits/aes/x86ni.c, done in both lanes at once.+ * Every shuffle and shift here works inside its own 128-bit half, so the two+ * products never mix: what comes out is two independent carry-less products,+ * accumulated by the caller and reduced together at the end.+ */+VAES_TARGET+static inline void clmul256(__m256i a, __m256i b, __m256i *lo, __m256i *hi)+{+ const __m256i bswap = _mm256_setr_epi8(+ 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0,+ 15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0);+ __m256i t3, t4, t5, t6;++ a = _mm256_shuffle_epi8(a, bswap);++ /* Karatsuba, as in the 128-bit one: three multiplies, not four */+ t3 = _mm256_clmulepi64_epi128(a, b, 0x00);+ t6 = _mm256_clmulepi64_epi128(a, b, 0x11);+ t4 = _mm256_clmulepi64_epi128(+ _mm256_xor_si256(a, _mm256_shuffle_epi32(a, 0x4e)),+ _mm256_xor_si256(b, _mm256_shuffle_epi32(b, 0x4e)), 0x00);+ t4 = _mm256_xor_si256(t4, _mm256_xor_si256(t3, t6));++ t5 = _mm256_slli_si256(t4, 8);+ t4 = _mm256_srli_si256(t4, 8);++ *lo = _mm256_xor_si256(t3, t5);+ *hi = _mm256_xor_si256(t6, t4);+}++/*+ * The reduction of cbits/aes/x86ni.c, unchanged: by the time it runs the two+ * lanes have been folded into one, so there is one 256-bit product to reduce+ * and no reason to do it twice.+ */+VAES_TARGET+static inline __m128i gfred(__m128i t3, __m128i t6)+{+ const __m128i bswap = _mm_set_epi8(0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15);+ __m128i t2, t4, t5, t7, t8, t9;++ t7 = _mm_srli_epi32(t3, 31);+ t8 = _mm_srli_epi32(t6, 31);+ t3 = _mm_slli_epi32(t3, 1);+ t6 = _mm_slli_epi32(t6, 1);++ t9 = _mm_srli_si128(t7, 12);+ t8 = _mm_slli_si128(t8, 4);+ t7 = _mm_slli_si128(t7, 4);+ t3 = _mm_or_si128(t3, t7);+ t6 = _mm_or_si128(t6, t8);+ t6 = _mm_or_si128(t6, t9);++ t7 = _mm_slli_epi32(t3, 31);+ t8 = _mm_slli_epi32(t3, 30);+ t9 = _mm_slli_epi32(t3, 25);++ t7 = _mm_xor_si128(t7, t8);+ t7 = _mm_xor_si128(t7, t9);+ t8 = _mm_srli_si128(t7, 4);+ t7 = _mm_slli_si128(t7, 12);+ t3 = _mm_xor_si128(t3, t7);++ t2 = _mm_srli_epi32(t3, 1);+ t4 = _mm_srli_epi32(t3, 2);+ t5 = _mm_srli_epi32(t3, 7);+ t2 = _mm_xor_si128(t2, t4);+ t2 = _mm_xor_si128(t2, t5);+ t2 = _mm_xor_si128(t2, t8);+ t3 = _mm_xor_si128(t3, t2);+ t6 = _mm_xor_si128(t6, t3);++ return _mm_shuffle_epi8(t6, bswap);+}++/*+ * Sixteen blocks against H^16 .. H^1, one reduction. v[j] holds blocks 2j+ * and 2j+1 in its low and high halves, so the powers for it are H^(16-2j)+ * low and H^(15-2j) high -- the table's own order the other way round, hence+ * the pair of 128-bit loads rather than one 256-bit one.+ */+VAES_TARGET+static inline __m128i ghash16(__m128i tag, const table_4bit htable,+ const __m256i *v, int fromwire)+{+ __m256i lo = _mm256_setzero_si256(), hi = _mm256_setzero_si256();+ __m256i l, h, b;+ int j;++ for (j = 0; j < VWIDE; j++) {+ const __m256i hp = _mm256_set_m128i(+ _mm_loadu_si128((const __m128i *) &htable[14 - 2 * j]),+ _mm_loadu_si128((const __m128i *) &htable[15 - 2 * j]));++ b = fromwire ? _mm256_loadu_si256(v + j) : v[j];+ if (j == 0) /* the running tag joins the first block */+ b = _mm256_xor_si256(+ b, _mm256_inserti128_si256(+ _mm256_setzero_si256(), tag, 0));+ clmul256(b, hp, &l, &h);+ lo = _mm256_xor_si256(lo, l);+ hi = _mm256_xor_si256(hi, h);+ }++ /* the two lanes are independent products of the same sum: fold them */+ return gfred(_mm_xor_si128(_mm256_castsi256_si128(lo),+ _mm256_extracti128_si256(lo, 1)),+ _mm_xor_si128(_mm256_castsi256_si128(hi),+ _mm256_extracti128_si256(hi, 1)));+}++#define KK(r) _mm256_broadcastsi128_si256(_mm_loadu_si128(k_ + (r)))++#define AESENC16(K) \+ do { \+ const __m256i rk = (K); \+ v[0] = _mm256_aesenc_epi128(v[0], rk); \+ v[1] = _mm256_aesenc_epi128(v[1], rk); \+ v[2] = _mm256_aesenc_epi128(v[2], rk); \+ v[3] = _mm256_aesenc_epi128(v[3], rk); \+ v[4] = _mm256_aesenc_epi128(v[4], rk); \+ v[5] = _mm256_aesenc_epi128(v[5], rk); \+ v[6] = _mm256_aesenc_epi128(v[6], rk); \+ v[7] = _mm256_aesenc_epi128(v[7], rk); \+ } while (0)++#define AESLAST16(K) \+ do { \+ const __m256i rk = (K); \+ v[0] = _mm256_aesenclast_epi128(v[0], rk); \+ v[1] = _mm256_aesenclast_epi128(v[1], rk); \+ v[2] = _mm256_aesenclast_epi128(v[2], rk); \+ v[3] = _mm256_aesenclast_epi128(v[3], rk); \+ v[4] = _mm256_aesenclast_epi128(v[4], rk); \+ v[5] = _mm256_aesenclast_epi128(v[5], rk); \+ v[6] = _mm256_aesenclast_epi128(v[6], rk); \+ v[7] = _mm256_aesenclast_epi128(v[7], rk); \+ } while (0)++#define XOR16(K) \+ do { \+ const __m256i rk = (K); \+ v[0] = _mm256_xor_si256(v[0], rk); \+ v[1] = _mm256_xor_si256(v[1], rk); \+ v[2] = _mm256_xor_si256(v[2], rk); \+ v[3] = _mm256_xor_si256(v[3], rk); \+ v[4] = _mm256_xor_si256(v[4], rk); \+ v[5] = _mm256_xor_si256(v[5], rk); \+ v[6] = _mm256_xor_si256(v[6], rk); \+ v[7] = _mm256_xor_si256(v[7], rk); \+ } while (0)++/*+ * The rounds are written out rather than looped for the reason the 128-bit+ * loop gives: the count is a value in the key, and a loop over it leaves the+ * round key reached through an index the compiler cannot fold.+ */+VAES_TARGET+static inline __attribute__((always_inline)) void+rounds16(__m256i *v, const uint8_t *k, const int nbr)+{+ const __m128i *k_ = (const __m128i *) k;++ XOR16(KK(0));+ AESENC16(KK(1)); AESENC16(KK(2)); AESENC16(KK(3));+ AESENC16(KK(4)); AESENC16(KK(5)); AESENC16(KK(6));+ AESENC16(KK(7)); AESENC16(KK(8)); AESENC16(KK(9));+ if (nbr > 10) {+ AESENC16(KK(10)); AESENC16(KK(11));+ if (nbr > 12) {+ AESENC16(KK(12)); AESENC16(KK(13));+ }+ }+ AESLAST16(_mm256_broadcastsi128_si256(_mm_loadu_si128(k_ + nbr)));+}++/* sixteen consecutive counters, two to a register. GCM counts in the low+ * thirty-two bits and wraps there, which is what _mm_add_epi32 does. */+VAES_TARGET+static inline __m128i counters16(__m256i *v, __m128i iv, __m128i one,+ __m128i bswap)+{+ int j;++ for (j = 0; j < VWIDE; j++) {+ __m128i c0, c1;++ iv = _mm_add_epi32(iv, one);+ c0 = _mm_shuffle_epi8(iv, bswap);+ iv = _mm_add_epi32(iv, one);+ c1 = _mm_shuffle_epi8(iv, bswap);+ v[j] = _mm256_set_m128i(c1, c0);+ }+ return iv;+}++/*+ * The round count is a value in the key, and a test on it inside the group+ * loop is a branch the 128-bit path does not have: that one compiles a+ * separate function for each key length through the SIZED macro. This does+ * the same thing by being inlined into three callers with the count a+ * constant in each, which folds the tests away. Without it AES-256 lost+ * what AES-128 gained.+ */+VAES_TARGET+static inline __attribute__((always_inline)) uint32_t+bulk_n(uint8_t *output, aes_gcm *gcm, const aes_key *key,+ const uint8_t *input, uint32_t length, int decrypt, const int nbr)+{+ const __m128i bswap = _mm_setr_epi8(7,6,5,4,3,2,1,0,15,14,13,12,11,10,9,8);+ const __m128i one = _mm_set_epi32(0, 1, 0, 0);+ __m256i v[VWIDE];+ __m128i iv, tag;+ uint32_t groups = length / 256;+ uint32_t done = 0;+ uint32_t g;+ int j;++ if (groups == 0)+ return 0;++ iv = _mm_shuffle_epi8(_mm_loadu_si128((const __m128i *) &gcm->civ), bswap);+ tag = _mm_loadu_si128((const __m128i *) &gcm->tag);++ for (g = 0; g < groups; g++, input += 256, output += 256, done += 256) {+ iv = counters16(v, iv, one, bswap);+ rounds16(v, key->data, nbr);++ /*+ * The ciphertext is what the tag is taken over, and after+ * this exclusive or it is in v itself when encrypting. When+ * decrypting it is the input, which the GHASH below reads+ * again rather than keeping: there are sixteen vector+ * registers, the group fills eight of them, and a second+ * eight held aside is what makes the compiler spill. The+ * input is in L1 from the load a moment ago.+ */+ for (j = 0; j < VWIDE; j++) {+ const __m256i in =+ _mm256_loadu_si256((const __m256i *) (input + 32 * j));++ v[j] = _mm256_xor_si256(v[j], in);+ _mm256_storeu_si256((__m256i *) (output + 32 * j), v[j]);+ }+ tag = ghash16(tag, gcm->htable,+ decrypt ? (const __m256i *) input : v,+ decrypt);+ }++ _mm_storeu_si128((__m128i *) &gcm->civ, _mm_shuffle_epi8(iv, bswap));+ _mm_storeu_si128((__m128i *) &gcm->tag, tag);+ return done;+}++VAES_TARGET+static uint32_t bulk(uint8_t *output, aes_gcm *gcm, const aes_key *key,+ const uint8_t *input, uint32_t length, int decrypt)+{+ switch (key->nbr) {+ case 10:+ return bulk_n(output, gcm, key, input, length, decrypt, 10);+ case 12:+ return bulk_n(output, gcm, key, input, length, decrypt, 12);+ case 14:+ return bulk_n(output, gcm, key, input, length, decrypt, 14);+ default:+ return 0; /* not a key length AES has */+ }+}++uint32_t crypton_gcm_vaes_bulk_encrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input, uint32_t length)+{+ return bulk(output, gcm, key, input, length, 0);+}++uint32_t crypton_gcm_vaes_bulk_decrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input, uint32_t length)+{+ return bulk(output, gcm, key, input, length, 1);+}++#endif
+ cbits/aes/gcm_vaes_x86.h view
@@ -0,0 +1,35 @@+/*+ * AES-GCM in the 256-bit form of the AES and carry-less multiply+ * instructions, which do two blocks where the 128-bit ones do one.+ */+#ifndef CRYPTON_GCM_VAES_X86_H+#define CRYPTON_GCM_VAES_X86_H++#include <crypton_cpu.h>++#if defined(ARCH_X86) && defined(__x86_64__) && defined(WITH_AESNI) \+ && defined(WITH_PCLMUL)+#define WITH_GCM_VAES+#endif++#ifdef WITH_GCM_VAES++#include <stdint.h>+#include <crypton_aes.h>++/* The bulk of a message in whole groups of sixteen blocks, leaving the+ * counter in gcm->civ and the running tag in gcm->tag where the caller's own+ * loop expects to find them. Returns the number of bytes taken, which is a+ * multiple of 256 and may be zero. */+uint32_t crypton_gcm_vaes_bulk_encrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input, uint32_t length);+uint32_t crypton_gcm_vaes_bulk_decrypt(uint8_t *output, aes_gcm *gcm,+ const aes_key *key,+ const uint8_t *input, uint32_t length);++/* Sixteen blocks is the least it will start on. */+#define GCM_VAES_MIN_BLOCKS 16++#endif+#endif
cbits/aes/gcm_x86_asm.c view
@@ -92,19 +92,29 @@ * H, and every power of it, is kept shifted up by one bit: GCM numbers the * bits of a field element the other way round from the way the carry-less * multiply does, and pre-shifting the operand is what saves the correction- * after each multiply. The bit that falls off the top is the one that the- * polynomial reduces.+ * after each multiply.+ *+ * Written from the definition. The field is GF(2)[x] modulo x^128 + x^127 ++ * x^126 + x^121 + 1, so multiplying by x is a shift of one place, and the+ * term that leaves the top comes back as the other four. */ TARGET_PCLMUL static __m128i twist(__m128i h) {+ /* x^127 + x^126 + x^121 + 1, the terms x^128 is congruent to */ const __m128i poly = _mm_set_epi64x(0xc200000000000000ULL, 1);- __m128i carried = _mm_slli_si128(_mm_srli_epi64(h, 63), 8);- __m128i top = _mm_shuffle_epi32(h, 0xff);- __m128i reduce = _mm_cmpgt_epi32(_mm_setzero_si128(), top);+ /* the top bit of each half */+ __m128i tops = _mm_srli_epi64(h, 63);+ /* doubling a polynomial is a shift by one: each half doubles, and the+ * low half's top bit becomes the high half's bottom bit */+ __m128i doubled = _mm_or_si128(_mm_add_epi64(h, h),+ _mm_slli_si128(tops, 8));+ /* bit 127 is the one that leaves the field; spread it to a mask by+ * subtracting it from zero, and it brings the four terms back */+ __m128i mask = _mm_sub_epi64(_mm_setzero_si128(),+ _mm_unpackhi_epi64(tops, tops)); - h = _mm_or_si128(_mm_slli_epi64(h, 1), carried);- return _mm_xor_si128(h, _mm_and_si128(reduce, poly));+ return _mm_xor_si128(doubled, _mm_and_si128(mask, poly)); } /* the two halves of a value added together, which is the term Karatsuba
cbits/aes/x86ni.c view
@@ -37,6 +37,8 @@ #include <crypton_cpu.h> #include <aes/gf.h> #include <aes/x86ni.h>+#include <aes/gcm_vaes_x86.h>+#include <aes/gcm_vaes512_x86.h> #include <aes/block128.h> #include <aes/gcm_x86_asm.h> @@ -207,13 +209,23 @@ return v; } +/* memcpy rather than a cast, as everything else that moves bytes between a+ * crypton structure and a word does since block128 was packed. The cast+ * this replaces was written in 2014, when block128 was a plain union and+ * taking a __m128i * to one promised nothing the type did not already+ * offer. Packing it dropped its alignment to one, and the promise with it:+ * gcc has reported the cast ever since, and it is right to -- the attribute+ * on the local below is what makes the promise true, and nothing obliges+ * the next edit to keep it. Sixteen bytes of memcpy between a __m128i and+ * a sixteen-byte object is one movdqu, or nothing at all when both stay in+ * registers. */ TARGET_AESNI static __m128i gfmul_generic(__m128i tag, const table_4bit htable) {- aes_block _t ALIGNMENT(16);- _mm_store_si128((__m128i *) &_t, tag);+ aes_block _t;+ memcpy(&_t, &tag, sizeof _t); crypton_aes_generic_gf_mul(&_t, htable);- tag = _mm_load_si128((__m128i *) &_t);+ memcpy(&tag, &_t, sizeof tag); return tag; } @@ -357,11 +369,14 @@ htable[0].q[0] = bitfn_swap64(h->q[1]); htable[0].q[1] = bitfn_swap64(h->q[0]); - /* Indices 1..7 get H^2 .. H^8, which is what lets a group of blocks- * fold into one reduction: gf_mul4 uses the first four, the GCM loop- * all eight. The table has sixteen slots. */+ /* Indices 1..15 get H^2 .. H^16, which is what lets a group of blocks+ * fold into one reduction: gf_mul4 uses the first four, the 128-bit+ * GCM loop eight, and the 256-bit one all sixteen. The table has+ * sixteen slots and now they are all used. Filling the upper half+ * costs eight multiplies once per key, which is nothing beside a+ * message. */ p = _mm_loadu_si128((const __m128i *) h);- for (i = 1; i < 8; i++) {+ for (i = 1; i < 16; i++) { p = gfmul_pclmuldq(p, htable); _mm_storeu_si128((__m128i *) &htable[i], _mm_shuffle_epi8(p, bswap_mask));
cbits/aes/x86ni_impl.c view
@@ -335,9 +335,43 @@ gcm->length_input += length; +#ifdef WITH_GCM_VAES512+ /*+ * The widest form the processor has, first: four blocks to an+ * instruction where the 256-bit one below takes two and the assembly+ * after that takes one. Same contract throughout -- whole groups off+ * the front, the counter and the tag left behind.+ */+ if (nb_blocks >= GCM_VAES512_MIN_BLOCKS+ && (crypton_x86_simd_features() & CRYPTON_X86_VAES512)) {+ uint32_t done = crypton_gcm_vaes512_bulk_encrypt(+ output, gcm, key, input, nb_blocks * 16);++ output += done;+ input += done;+ nb_blocks -= done / 16;+ }+#endif+#ifdef WITH_GCM_VAES+ /*+ * The 256-bit instructions next: they take two blocks where the ones+ * below take one, and the assembly that follows is 128-bit+ * throughout.+ */+ if (nb_blocks >= GCM_VAES_MIN_BLOCKS+ && (crypton_x86_simd_features() & CRYPTON_X86_VAES)) {+ uint32_t done = crypton_gcm_vaes_bulk_encrypt(output, gcm, key,+ input,+ nb_blocks * 16);++ output += done;+ input += done;+ nb_blocks -= done / 16;+ }+#endif #if defined(WITH_X86_GCM_ASM) && defined(WITH_PCLMUL) /*- * The stitched assembly first, which takes whole groups of six+ * The stitched assembly next, which takes whole groups of six * blocks off the front of the message and leaves the counter and the * running tag where the loop below expects to find them. It wants * eighteen blocks before it will start, and answers with what it did.@@ -483,6 +517,31 @@ gcm->length_input += length; +#ifdef WITH_GCM_VAES512+ /* as in encryption; the tag is taken over the input here */+ if (nb_blocks >= GCM_VAES512_MIN_BLOCKS+ && (crypton_x86_simd_features() & CRYPTON_X86_VAES512)) {+ uint32_t done = crypton_gcm_vaes512_bulk_decrypt(+ output, gcm, key, input, nb_blocks * 16);++ output += done;+ input += done;+ nb_blocks -= done / 16;+ }+#endif+#ifdef WITH_GCM_VAES+ /* as in encryption; the tag is taken over the input here */+ if (nb_blocks >= GCM_VAES_MIN_BLOCKS+ && (crypton_x86_simd_features() & CRYPTON_X86_VAES)) {+ uint32_t done = crypton_gcm_vaes_bulk_decrypt(output, gcm, key,+ input,+ nb_blocks * 16);++ output += done;+ input += done;+ nb_blocks -= done / 16;+ }+#endif #if defined(WITH_X86_GCM_ASM) && defined(WITH_PCLMUL) /* the same as encryption, except that decryption has nothing to * hold back and so will start on six blocks */
cbits/crypton_aes.c view
@@ -38,6 +38,9 @@ #include <aes/generic.h> #include <aes/gf.h> #include <aes/x86ni.h>+#ifdef WITH_GCM_FUSED+#include <aes/gcm_fused_x86.h>+#endif void crypton_aes_generic_encrypt_ecb(aes_block *output, aes_key *key, aes_block *input, uint32_t nb_blocks); void crypton_aes_generic_decrypt_ecb(aes_block *output, aes_key *key, aes_block *input, uint32_t nb_blocks);@@ -58,6 +61,18 @@ #ifdef WITH_ARMV8_CRYPTO void crypton_aes_armv8_init(aes_key *key, uint8_t *origkey, uint8_t size);+int crypton_aes_armv8_gcm_fused_dec(uint8_t *out, const block128 *ht,+ aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *in, uint32_t inlen,+ const uint8_t *tag, uint32_t taglen,+ uint8_t *outtag);+void crypton_aes_armv8_gcm_fused(uint8_t *out, const block128 *ht,+ aes_key *key, const uint8_t *nonce,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *in, uint32_t inlen,+ uint32_t taglen, aes_key *hpkey,+ uint32_t sampleoff, uint8_t *mask); #define ARMV8_DECLS(sz) \ void crypton_aes_armv8_encrypt_block##sz(aes_block *output, aes_key *key, aes_block *input); \ void crypton_aes_armv8_decrypt_block##sz(aes_block *output, aes_key *key, aes_block *input); \@@ -410,7 +425,22 @@ } #endif -uint8_t *crypton_aes_cpu_init(void)+/* Which implementation each entry of the branch table names is decided once,+ * before anything else runs.+ *+ * It used to be decided again on every crypton_aes_initkey, which meant two+ * threads taking a key at the same time were writing the whole table at the+ * same time -- a data race for as long as the program used AES, not just at+ * the start. ThreadSanitizer reports forty-two of them for eight threads+ * doing nothing but taking keys. The values written are the same ones every+ * time and the table starts out holding valid generic implementations, so+ * nothing has ever come of it; it is a race the standard gives no meaning to+ * all the same.+ *+ * A constructor runs while there is one thread, which is the cheapest way to+ * have no race at all: no flag to test, no lock to take, and one less thing+ * for crypton_aes_initkey to do per key. */+static void crypton_aes_cpu_setup(void) { #if defined(ARCH_X86) && defined(WITH_AESNI) crypton_aesni_initialize_hw(initialize_table_ni);@@ -418,6 +448,16 @@ #ifdef WITH_ARMV8_CRYPTO initialize_table_armv8(); #endif+}++__attribute__((constructor))+static void crypton_aes_cpu_ctor(void)+{+ crypton_aes_cpu_setup();+}++uint8_t *crypton_aes_cpu_init(void)+{ return crypton_aes_cpu_options; } @@ -428,7 +468,6 @@ case 24: key->nbr = 12; key->strength = 1; break; case 32: key->nbr = 14; key->strength = 2; break; }- crypton_aes_cpu_init(); init_f _init = GET_INIT(key->strength); _init(key, origkey, size); }@@ -532,20 +571,33 @@ crypton_gf_mul4(&gcm->tag, b, gcm->htable); } -void crypton_aes_gcm_init(aes_gcm *gcm, aes_key *key, uint8_t *iv, uint32_t len)+/* The part of the state that depends on the key alone: H = encrypt_K(0^128)+ * and the table of its multiples. It is 256 of the 320 bytes, and a caller+ * that keeps a key can compute it once instead of once per message. */+void crypton_aes_gcm_key_init(aes_gcm_key *gk, aes_key *key) { block128 h;++ block128_zero(&h);+ crypton_aes_encrypt_block(&h, key, &h);+ crypton_hinit(gk->gcm.htable, &h);+#ifdef WITH_GCM_FUSED+ if (crypton_aes_cpu_options[CPU_AESNI]+ && crypton_aes_cpu_options[CPU_PCLMUL])+ crypton_gcm_fused_key_init(&gk->fused, key);+#endif+}++/* Everything else: what the nonce and the message determine. Leaves htable+ * alone, so it runs on a state whose key part is already there. */+static void gcm_message_init(aes_gcm *gcm, uint8_t *iv, uint32_t len)+{ gcm->length_aad = 0; gcm->length_input = 0; - block128_zero(&h); block128_zero(&gcm->tag); block128_zero(&gcm->iv); - /* prepare H : encrypt_K(0^128) */- crypton_aes_encrypt_block(&h, key, &h);- crypton_hinit(gcm->htable, &h);- if (len == 12) { block128_copy_bytes(&gcm->iv, iv, 12); gcm->iv.b[15] = 0x01;@@ -568,6 +620,16 @@ block128_copy_aligned(&gcm->civ, &gcm->iv); } +void crypton_aes_gcm_init(aes_gcm *gcm, aes_key *key, uint8_t *iv, uint32_t len)+{+ block128 h;++ block128_zero(&h);+ crypton_aes_encrypt_block(&h, key, &h);+ crypton_hinit(gcm->htable, &h);+ gcm_message_init(gcm, iv, len);+}+ void crypton_aes_gcm_aad(aes_gcm *gcm, uint8_t *input, uint32_t length) { gcm->length_aad += length;@@ -602,6 +664,195 @@ for (i = 0; i < 16; i++) { tag[i] = gcm->tag.b[i]; }+}++/* One message, one call. The key part of the state comes in already built,+ * the rest is set up on the stack, and the additional data, the encryption+ * and the tag all happen before returning, so nothing crosses a language+ * boundary between them and no intermediate state is copied out. The output+ * buffer takes the ciphertext and then the tag, so it wants length + taglen+ * bytes. */+void crypton_aes_gcm_full_encrypt(uint8_t *output, const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length, uint32_t taglen)+{+ aes_gcm gcm;+ uint8_t tag[16];++#ifdef WITH_GCM_FUSED+ /* Short messages go the other way: the assembly below will not start+ * on anything under 288 bytes, and under about 1.5 KB the fused path+ * is ahead of it even where it does. */+ if (ivlen == 12 && length <= CRYPTON_GCM_FUSED_MAX_MESSAGE+ && crypton_aes_cpu_options[CPU_AESNI]+ && crypton_aes_cpu_options[CPU_PCLMUL]) {+ crypton_gcm_fused_encrypt(output, &gcmkey->fused, key, iv,+ aad, aadlen, input, length, taglen,+ NULL, 0, NULL);+ return;+ }+#endif+#ifdef WITH_ARMV8_CRYPTO+ /* The same on AArch64, where the framing is what costs: composing the+ * additional data, the encryption and the tag reaches each through the+ * branch table, so the running state goes back to memory between them+ * and a one-block header pays a reduction of its own. Measured on an+ * Apple M4, a 100-byte packet is 3.0x faster taken in one call.+ *+ * No length limit, unlike x86: there is no vendored assembly on this+ * side for a long message to be handed to instead, and measured+ * against the path this replaces it is never slower -- 1.25x at 1440+ * bytes, level from about 6 KB up. */+ if (ivlen == 12+ && crypton_aes_cpu_options[CPU_AESNI]+ && crypton_aes_cpu_options[CPU_PCLMUL]) {+ crypton_aes_armv8_gcm_fused(output, gcmkey->gcm.htable, key, iv,+ aad, aadlen, input, length, taglen,+ NULL, 0, NULL);+ return;+ }+#endif+ memcpy(gcm.htable, gcmkey->gcm.htable, sizeof(gcm.htable));+ gcm_message_init(&gcm, iv, ivlen);+ if (aadlen)+ crypton_aes_gcm_aad(&gcm, aad, aadlen);+ if (length)+ crypton_aes_gcm_encrypt(output, &gcm, key, input, length);+ crypton_aes_gcm_finish(tag, &gcm, key);+ memcpy(output + length, tag, taglen);+}++/* The same, and then the header protection mask. QUIC takes its sample from+ * the ciphertext, so the mask cannot be had before the encryption -- but it+ * can be had before returning, which saves a second crossing for one AES+ * block. The block itself is about a nanosecond; what it saves is the call.+ * sampleoff is where the sixteen bytes of sample start in the output. */+void crypton_aes_gcm_full_encrypt_mask(uint8_t *output, const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length, uint32_t taglen,+ aes_key *hpkey, uint32_t sampleoff, uint8_t *mask)+{+ block128 sample, m;++#ifdef WITH_GCM_FUSED+ /* Here the mask rides in a lane of the AES pipeline that the message+ * length leaves idle, so it costs very nearly nothing on top of the+ * encryption rather than a block of its own. */+ if (ivlen == 12 && length <= CRYPTON_GCM_FUSED_MAX_MESSAGE+ && crypton_aes_cpu_options[CPU_AESNI]+ && crypton_aes_cpu_options[CPU_PCLMUL]) {+ crypton_gcm_fused_encrypt(output, &gcmkey->fused, key, iv,+ aad, aadlen, input, length, taglen,+ hpkey, sampleoff, mask);+ return;+ }+#endif+#ifdef WITH_ARMV8_CRYPTO+ /* The same on AArch64, where the framing is what costs: composing the+ * additional data, the encryption and the tag reaches each through the+ * branch table, so the running state goes back to memory between them+ * and a one-block header pays a reduction of its own. Measured on an+ * Apple M4, a 100-byte packet is 3.3x faster taken in one call. */+ if (ivlen == 12+ && crypton_aes_cpu_options[CPU_AESNI]+ && crypton_aes_cpu_options[CPU_PCLMUL]) {+ crypton_aes_armv8_gcm_fused(output, gcmkey->gcm.htable, key, iv,+ aad, aadlen, input, length, taglen,+ hpkey, sampleoff, mask);+ return;+ }+#endif+ crypton_aes_gcm_full_encrypt(output, gcmkey, key, iv, ivlen, aad, aadlen,+ input, length, taglen);+ /* copied rather than cast: the sample lands wherever the header put it+ * and a block128 is read as 64-bit words */+ memcpy(&sample, output + sampleoff, 16);+ crypton_aes_encrypt_block(&m, hpkey, &sample);+ memcpy(mask, &m, 16);+}++/* The same the other way, with the tag checked here rather than by the+ * caller: returns 1 when it matches and 0 when it does not, comparing every+ * byte either way. The plaintext is written whatever the answer, so a caller+ * that gets 0 must not use it. */+/* Decrypt, and either compare the tag or hand it back.+ *+ * With outtag NULL this is the verifying form: the tag is compared here, a+ * byte at a time over its whole length whichever way the answer goes, and the+ * answer is the return value. With outtag not NULL the computed tag is+ * written there instead and the return value is 1 -- for a caller that holds+ * the expected tag in a form of its own and will compare it itself. */+static int gcm_full_decrypt(uint8_t *output, const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length,+ const uint8_t *tag, uint32_t taglen,+ uint8_t *outtag)+{+ aes_gcm gcm;+ uint8_t expected[16];+ uint32_t i;+ uint8_t diff = 0;++#ifdef WITH_GCM_FUSED+ /* The same as the encryption side, and simpler: what GHASH absorbs+ * here is the ciphertext, which is the input, so the multiplies need+ * not wait for anything. Measured on an Intel Haswell, a 100-byte+ * packet was three times the cost of encrypting one before this. */+ if (ivlen == 12 && length <= CRYPTON_GCM_FUSED_MAX_MESSAGE+ && crypton_aes_cpu_options[CPU_AESNI]+ && crypton_aes_cpu_options[CPU_PCLMUL])+ return crypton_gcm_fused_decrypt(output, &gcmkey->fused, key,+ iv, aad, aadlen, input,+ length, tag, taglen, outtag);+#endif+#ifdef WITH_ARMV8_CRYPTO+ if (ivlen == 12+ && crypton_aes_cpu_options[CPU_AESNI]+ && crypton_aes_cpu_options[CPU_PCLMUL])+ return crypton_aes_armv8_gcm_fused_dec(output, gcmkey->gcm.htable,+ key, iv, aad, aadlen,+ input, length, tag, taglen,+ outtag);+#endif+ memcpy(gcm.htable, gcmkey->gcm.htable, sizeof(gcm.htable));+ gcm_message_init(&gcm, iv, ivlen);+ if (aadlen)+ crypton_aes_gcm_aad(&gcm, aad, aadlen);+ if (length)+ crypton_aes_gcm_decrypt(output, &gcm, key, input, length);+ crypton_aes_gcm_finish(expected, &gcm, key);++ if (outtag) {+ memcpy(outtag, expected, taglen);+ return 1;+ }+ for (i = 0; i < taglen; i++)+ diff |= (uint8_t) (expected[i] ^ tag[i]);+ return diff == 0;+}++int crypton_aes_gcm_full_decrypt(uint8_t *output, const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length,+ const uint8_t *tag, uint32_t taglen)+{+ return gcm_full_decrypt(output, gcmkey, key, iv, ivlen, aad, aadlen,+ input, length, tag, taglen, NULL);+}++void crypton_aes_gcm_full_decrypt_tag(uint8_t *output, uint8_t *outtag,+ const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length,+ uint32_t taglen)+{+ (void) gcm_full_decrypt(output, gcmkey, key, iv, ivlen, aad, aadlen,+ input, length, NULL, taglen, outtag); } static inline uint8_t ccm_b0_flags(uint32_t has_adata, uint32_t m, uint32_t l)
cbits/crypton_aes.h view
@@ -55,6 +55,55 @@ uint64_t length_input; } aes_gcm; +/*+ * How many powers of H a key keeps for the fused path in+ * cbits/aes/gcm_fused_x86.c. A power for every block of the message would+ * fold its whole GHASH into one reduction, which is what picotls does, but+ * then the state grows with the longest message a caller might send and a+ * server holding many keys pays it for each. A fixed count costs one+ * reduction per this many blocks and keeps the state one size. Sixteen was+ * measured against 6, 8, 32, 64, 96 and 256: above eight the choice is worth+ * about two per cent, since only messages short enough to take this path at+ * all reach a second batch. Six is worth avoiding -- at 1440 bytes it is+ * slower than not taking the path.+ */+#define CRYPTON_GCM_FUSED_POWERS 16++/*+ * Beyond this many bytes the stitched assembly in cbits/asm is faster than+ * the fused path, so longer messages go there instead. Measured on an Intel+ * Haswell: even at 1440 bytes, the assembly ahead by 12 per cent at 3 KB and+ * 20 per cent at 16 KB, and the fused path ahead by 1.9x at 100 bytes and+ * 1.16x at 1200. QUIC packets fall below this; TLS records do not.+ */+#define CRYPTON_GCM_FUSED_MAX_MESSAGE 1536++/*+ * The powers themselves, each shifted up by one bit, and beside each the+ * halves of it added together for the Karatsuba term. The two are kept+ * adjacent rather than in two arrays: a multiply wants both, and two arrays+ * put them 256 bytes apart, which is two cache lines where this is one.+ *+ * Defined on every platform so that the key state below is one size+ * everywhere; filled only where the fused path is compiled in.+ */+typedef struct {+ struct {+ aes_block h;+ aes_block r;+ } p[CRYPTON_GCM_FUSED_POWERS];+} aes_gcm_fused;++/*+ * Everything a key determines, built once by crypton_aes_gcm_key_init and+ * read by every message sent under that key: the key half of a GCM state,+ * and the powers of H the fused path reads. 832 bytes.+ */+typedef struct {+ aes_gcm gcm;+ aes_gcm_fused fused;+} aes_gcm_key;+ /* size = 4*16+4*4= 80 */ typedef struct { aes_block xi;@@ -104,6 +153,27 @@ uint32_t spoint, aes_block *input, uint32_t nb_blocks); void crypton_aes_gcm_init(aes_gcm *gcm, aes_key *key, uint8_t *iv, uint32_t len);+void crypton_aes_gcm_key_init(aes_gcm_key *gk, aes_key *key);+void crypton_aes_gcm_full_encrypt(uint8_t *output, const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length, uint32_t taglen);+void crypton_aes_gcm_full_encrypt_mask(uint8_t *output, const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length, uint32_t taglen,+ aes_key *hpkey, uint32_t sampleoff, uint8_t *mask);+int crypton_aes_gcm_full_decrypt(uint8_t *output, const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length,+ const uint8_t *tag, uint32_t taglen);+void crypton_aes_gcm_full_decrypt_tag(uint8_t *output, uint8_t *outtag,+ const aes_gcm_key *gcmkey, aes_key *key,+ uint8_t *iv, uint32_t ivlen,+ uint8_t *aad, uint32_t aadlen,+ uint8_t *input, uint32_t length,+ uint32_t taglen); void crypton_aes_gcm_aad(aes_gcm *gcm, uint8_t *input, uint32_t length); void crypton_aes_gcm_encrypt(uint8_t *output, aes_gcm *gcm, aes_key *key, uint8_t *input, uint32_t length); void crypton_aes_gcm_decrypt(uint8_t *output, aes_gcm *gcm, aes_key *key, uint8_t *input, uint32_t length);
cbits/crypton_align.h view
@@ -3,6 +3,8 @@ #include "crypton_bitfn.h" +#include <string.h>+ #if (defined(__i386__)) # define UNALIGNED_ACCESS_OK #elif defined(__x86_64__)@@ -34,107 +36,119 @@ #define need_alignment(p,n) IS_ALIGNED(p,n) #endif -static inline uint32_t load_le32_aligned(const uint8_t *p)-{- return le32_to_cpu(*((uint32_t *) p)); -}+/*+ * Reading and writing a 32- or 64-bit word at a byte pointer.+ *+ * Through memcpy, not a cast to uint32_t * or uint64_t *. A cast is two+ * things the standard does not allow -- a read of the value through the+ * wrong type, and a read at an address that type is not aligned for -- and+ * this file used to do both wherever UNALIGNED_ACCESS_OK is defined, which+ * is i386 and x86-64. UndefinedBehaviorSanitizer reported seventy-eight+ * lines of it.+ *+ * Every compiler crypton is built with turns a memcpy of four or eight bytes+ * into the one load or store the cast used to be, so this is the same code+ * with none of the licence. Where the target cannot do an unaligned load,+ * the compiler is the one that knows, and it emits what the target needs --+ * which is what the byte-at-a-time versions this replaces were for.+ *+ * The _aligned names stay because nineteen files use them. They no longer+ * ask anything of the pointer.+ */ -static inline void store_le32_aligned(uint8_t *dst, const uint32_t v)+static inline uint32_t load_le32(const uint8_t *p) {- *((uint32_t *) dst) = cpu_to_le32(v);-}+ uint32_t v; -static inline void xor_le32_aligned(uint8_t *dst, const uint32_t v)-{- *((uint32_t *) dst) ^= cpu_to_le32(v);+ memcpy(&v, p, sizeof(v));+ return le32_to_cpu(v); } -static inline void store_be32_aligned(uint8_t *dst, const uint32_t v)+static inline uint64_t load_le64(const uint8_t *p) {- *((uint32_t *) dst) = cpu_to_be32(v);-}+ uint64_t v; -static inline void xor_be32_aligned(uint8_t *dst, const uint32_t v)-{- *((uint32_t *) dst) ^= cpu_to_be32(v);+ memcpy(&v, p, sizeof(v));+ return le64_to_cpu(v); } -static inline void store_le64_aligned(uint8_t *dst, const uint64_t v)+static inline uint32_t load_be32(const uint8_t *p) {- *((uint64_t *) dst) = cpu_to_le64(v);-}+ uint32_t v; -static inline void store_be64_aligned(uint8_t *dst, const uint64_t v)-{- *((uint64_t *) dst) = cpu_to_be64(v);+ memcpy(&v, p, sizeof(v));+ return be32_to_cpu(v); } -static inline void xor_be64_aligned(uint8_t *dst, const uint64_t v)+static inline uint64_t load_be64(const uint8_t *p) {- *((uint64_t *) dst) ^= cpu_to_be64(v);-}+ uint64_t v; -#ifdef UNALIGNED_ACCESS_OK-#define load_le32(a) load_le32_aligned(a)-#else-static inline uint32_t load_le32(const uint8_t *p)-{- return ((uint32_t)p[0]) | ((uint32_t)p[1] << 8) | ((uint32_t)p[2] << 16) | ((uint32_t)p[3] << 24);+ memcpy(&v, p, sizeof(v));+ return be64_to_cpu(v); }-#endif -#ifdef UNALIGNED_ACCESS_OK-#define store_le32(a, b) store_le32_aligned(a, b)-#define xor_le32(a, b) xor_le32_aligned(a, b)-#else static inline void store_le32(uint8_t *dst, const uint32_t v) {- dst[0] = v; dst[1] = v >> 8; dst[2] = v >> 16; dst[3] = v >> 24;+ uint32_t w = cpu_to_le32(v);++ memcpy(dst, &w, sizeof(w)); }+ static inline void xor_le32(uint8_t *dst, const uint32_t v) {- dst[0] ^= v; dst[1] ^= v >> 8; dst[2] ^= v >> 16; dst[3] ^= v >> 24;+ store_le32(dst, le32_to_cpu(load_le32(dst)) ^ v); }-#endif -#ifdef UNALIGNED_ACCESS_OK-#define store_be32(a, b) store_be32_aligned(a, b)-#define xor_be32(a, b) xor_be32_aligned(a, b)-#else static inline void store_be32(uint8_t *dst, const uint32_t v) {- dst[3] = v; dst[2] = v >> 8; dst[1] = v >> 16; dst[0] = v >> 24;+ uint32_t w = cpu_to_be32(v);++ memcpy(dst, &w, sizeof(w)); }+ static inline void xor_be32(uint8_t *dst, const uint32_t v) {- dst[3] ^= v; dst[2] ^= v >> 8; dst[1] ^= v >> 16; dst[0] ^= v >> 24;+ uint32_t w;++ memcpy(&w, dst, sizeof(w));+ w ^= cpu_to_be32(v);+ memcpy(dst, &w, sizeof(w)); }-#endif -#ifdef UNALIGNED_ACCESS_OK-#define store_le64(a, b) store_le64_aligned(a, b)-#else static inline void store_le64(uint8_t *dst, const uint64_t v) {- dst[0] = v ; dst[1] = v >> 8 ; dst[2] = v >> 16; dst[3] = v >> 24;- dst[4] = v >> 32; dst[5] = v >> 40; dst[6] = v >> 48; dst[7] = v >> 56;+ uint64_t w = cpu_to_le64(v);++ memcpy(dst, &w, sizeof(w)); }-#endif -#ifdef UNALIGNED_ACCESS_OK-#define store_be64(a, b) store_be64_aligned(a, b)-#define xor_be64(a, b) xor_be64_aligned(a, b)-#else static inline void store_be64(uint8_t *dst, const uint64_t v) {- dst[7] = v ; dst[6] = v >> 8 ; dst[5] = v >> 16; dst[4] = v >> 24;- dst[3] = v >> 32; dst[2] = v >> 40; dst[1] = v >> 48; dst[0] = v >> 56;+ uint64_t w = cpu_to_be64(v);++ memcpy(dst, &w, sizeof(w)); }+ static inline void xor_be64(uint8_t *dst, const uint64_t v) {- dst[7] ^= v ; dst[6] ^= v >> 8 ; dst[5] ^= v >> 16; dst[4] ^= v >> 24;- dst[3] ^= v >> 32; dst[2] ^= v >> 40; dst[1] ^= v >> 48; dst[0] ^= v >> 56;+ uint64_t w;++ memcpy(&w, dst, sizeof(w));+ w ^= cpu_to_be64(v);+ memcpy(dst, &w, sizeof(w)); }-#endif++#define load_le32_aligned(p) load_le32(p)+#define load_le64_aligned(p) load_le64(p)+#define load_be32_aligned(p) load_be32(p)+#define load_be64_aligned(p) load_be64(p)+#define store_le32_aligned(d, v) store_le32(d, v)+#define xor_le32_aligned(d, v) xor_le32(d, v)+#define store_be32_aligned(d, v) store_be32(d, v)+#define xor_be32_aligned(d, v) xor_be32(d, v)+#define store_le64_aligned(d, v) store_le64(d, v)+#define store_be64_aligned(d, v) store_be64(d, v)+#define xor_be64_aligned(d, v) xor_be64(d, v) #endif
+ cbits/crypton_armv8_target.h view
@@ -0,0 +1,40 @@+/*+ * Asking for an AArch64 extension on one function.+ *+ * The instructions these files use are extensions, so a translation unit+ * compiled for the baseline may not emit them, and the function that does has+ * to say which extension it needs. The two compilers spell that differently+ * and did not always:+ *+ * clang target("+crypto") for as long as it matters+ * GCC 13 and up target("+crypto") as well+ * GCC before 13 target("arch=armv8-a+crypto") -- the bare "+feature" form+ * is not understood, and the extension never reaches the+ * function, so an always_inline intrinsic that needs it+ * fails to inline and the build stops+ *+ * That last case is #273: gcc 12.2 on an aarch64 Linux could not build+ * cbits/sha3_armv8.c at all. Naming the architecture as well as the+ * extension is understood by every version of both compilers, so GCC is given+ * that spelling and clang keeps the shorter one, which leaves whatever+ * baseline the caller chose alone.+ */+#ifndef CRYPTON_ARMV8_TARGET_H+#define CRYPTON_ARMV8_TARGET_H++#ifdef WITH_TARGET_ATTRIBUTES+#if defined(__clang__)+#define CRYPTON_TARGET_ARMV8_CRYPTO __attribute__((target("+crypto")))+#define CRYPTON_TARGET_ARMV8_SHA3 __attribute__((target("+sha3")))+#else+#define CRYPTON_TARGET_ARMV8_CRYPTO \+ __attribute__((target("arch=armv8-a+crypto")))+#define CRYPTON_TARGET_ARMV8_SHA3 \+ __attribute__((target("arch=armv8.2-a+sha3")))+#endif+#else+#define CRYPTON_TARGET_ARMV8_CRYPTO+#define CRYPTON_TARGET_ARMV8_SHA3+#endif++#endif
cbits/crypton_bignum.h view
@@ -112,9 +112,196 @@ return (limb_t) 0 - inv; } -/* t += a * b over n limbs, returning the carry. This is where nearly all of- * the time goes, so the limbs are taken eight at a time; what is left over at- * the end is taken one at a time. */+/*+ * t += a * b over n limbs, returning the carry. This is where nearly all of+ * the time goes.+ *+ * The C below takes the limbs eight at a time; what is left over at the end+ * is taken one at a time. On AArch64 the compiler writes each limb as+ * `mul`, `umulh`, `adds`, `cset`, `adds`, `adc`: the carry out of one+ * 128-bit addition leaves the flags for a general register and is added back+ * in the next, because in C each addition is a statement of its own. Two of+ * those instructions are that round trip.+ *+ * Three attempts to take them back measured worse than the C, and are+ * written down here so that they are not tried again -- one RSA-2048 CRT+ * private operation on an Apple M4, best of many:+ *+ * this loop in inline assembly, a carry chain per limb 654.7 us+ * the same with the loads hoisted out of the chain 644.5+ * the multiply interleaved with its reduction (CIOS) 604.1+ * the C below 590.1+ * what the AArch64 block does, four limbs and two chains 514.9+ * the same, with the ragged end of the row written out too 503.4+ *+ * The first two lose because a chain per limb serialises what the spare+ * `cset` lets overlap: `adds`, `adc`, `adds`, `adc` is four dependent steps+ * per limb, and a wide out-of-order core would rather have the extra+ * instruction than the dependency. The third loses because shifting the+ * accumulator down a limb each round costs more than the round trip through+ * 2n limbs that it saves. What works is neither: four limbs to an+ * iteration with the flags carrying through two long chains, one for the low+ * halves of the products and one for the high halves a place up.+ *+ * There is more still there. OpenSSL's armv8-mont.pl runs a 16-limb+ * Montgomery multiplication at about 0.98 multiply-accumulates per cycle;+ * this file was at 0.55 and the block below brings it to 0.64, where 1.0 is+ * the ceiling -- a multiply-accumulate is two instructions and the machine+ * issues two multiplies a cycle. That code cannot be borrowed: it is in+ * OpenSSL's tree only, under Apache-2.0, and CRYPTOGAMS, which this library+ * does vendor from, publishes no Montgomery generator at all. BearSSL's+ * only ARM assembly is 32-bit Thumb for Cortex-M0 to M3, with fifteen-bit+ * limbs for cores that have no fast multiplier, and Botan's AArch64 inline+ * assembly is the `mul`/`umulh`/`adds`/`adc` primitive the compiler already+ * emits.+ */+#if defined(__aarch64__) && LIMB_BITS == 64 \+ && (defined(__GNUC__) || defined(__clang__))+/*+ * Four limbs to an iteration, accumulated in two chains rather than one per+ * limb: the low halves of the four products, with the carry coming in, are+ * one run of `adds` and `adcs`, and the high halves shifted up a place are+ * another. The flags carry the whole way through each, which is what the C+ * above cannot say and what it pays for in `cset` and an extra add.+ *+ * The arrangement is the one in Go's crypto/internal/fips140/bigmod+ * (nat_arm64.s, addMulVVWx), which is BSD-3-Clause like this library --+ * cbits/LICENSE.go carries its notice. Written out here in the assembler+ * this file's compiler speaks.+ */+static inline limb_t addmul_1(limb_t *t, const limb_t *a, uint32_t n, limb_t b)+{+ uint64_t carry = 0;+ uint64_t x0, x1, x2, x3, z0, z1, z2, z3;+ uint64_t l0, l1, l2, l3, h0, h1, h2, h3;+ uint64_t blocks = n / 4, left = n % 4;++ if (blocks) {+ __asm__ volatile(+ "1:\n\t"+ "ldp %[x0], %[x1], [%[a]], #16\n\t"+ "ldp %[x2], %[x3], [%[a]], #16\n\t"+ "ldp %[z0], %[z1], [%[t]]\n\t"+ /* the low halves, one place up from the second chain, with+ * the carry that came in */+ "adds %[z0], %[z0], %[c]\n\t"+ "mul %[l1], %[x1], %[b]\n\t"+ "adcs %[z1], %[z1], %[l1]\n\t"+ "mul %[l2], %[x2], %[b]\n\t"+ "ldp %[z2], %[z3], [%[t], #16]\n\t"+ "adcs %[z2], %[z2], %[l2]\n\t"+ "mul %[l3], %[x3], %[b]\n\t"+ "adcs %[z3], %[z3], %[l3]\n\t"+ "umulh %[h3], %[x3], %[b]\n\t"+ "adc %[h3], %[h3], xzr\n\t"+ /* and the high halves, which is where this block's own carry+ * ends up */+ "mul %[l0], %[x0], %[b]\n\t"+ "adds %[z0], %[z0], %[l0]\n\t"+ "umulh %[h0], %[x0], %[b]\n\t"+ "adcs %[z1], %[z1], %[h0]\n\t"+ "umulh %[h1], %[x1], %[b]\n\t"+ "stp %[z0], %[z1], [%[t]], #16\n\t"+ "adcs %[z2], %[z2], %[h1]\n\t"+ "umulh %[h2], %[x2], %[b]\n\t"+ "adcs %[z3], %[z3], %[h2]\n\t"+ "stp %[z2], %[z3], [%[t]], #16\n\t"+ "adc %[c], %[h3], xzr\n\t"+ "subs %[k], %[k], #1\n\t"+ "b.ne 1b\n\t"+ : [a] "+r"(a), [t] "+r"(t), [c] "+r"(carry), [k] "+r"(blocks),+ [x0] "=&r"(x0), [x1] "=&r"(x1), [x2] "=&r"(x2),+ [x3] "=&r"(x3), [z0] "=&r"(z0), [z1] "=&r"(z1),+ [z2] "=&r"(z2), [z3] "=&r"(z3), [l0] "=&r"(l0),+ [l1] "=&r"(l1), [l2] "=&r"(l2), [l3] "=&r"(l3),+ [h0] "=&r"(h0), [h1] "=&r"(h1), [h2] "=&r"(h2),+ [h3] "=&r"(h3)+ : [b] "r"(b)+ : "cc", "memory");+ }+ /* What is left of the row: three limbs, two, or one, each the same two+ * chains cut short. This is not a rare case to be handed back to C --+ * mont_sqr asks for every length from n-1 down to 1, so three rows in+ * four end ragged. Only 4.7% of the limbs in a 1024-bit exponentiation+ * arrive here, but they were the dearer ones, and writing them out is+ * worth the last two per cent in the table above. The three lengths+ * are spelled out rather than run as 2+1, because chaining two short+ * blocks makes the second wait on the first: that costs two thirds of+ * the gain.+ */+ if (left == 3) {+ __asm__ volatile(+ "ldp %[x0], %[x1], [%[a]]\n\t"+ "ldr %[x2], [%[a], #16]\n\t"+ "add %[a], %[a], #24\n\t"+ "ldp %[z0], %[z1], [%[t]]\n\t"+ "ldr %[z2], [%[t], #16]\n\t"+ "adds %[z0], %[z0], %[c]\n\t"+ "mul %[l1], %[x1], %[b]\n\t"+ "adcs %[z1], %[z1], %[l1]\n\t"+ "mul %[l2], %[x2], %[b]\n\t"+ "adcs %[z2], %[z2], %[l2]\n\t"+ "umulh %[h2], %[x2], %[b]\n\t"+ "adc %[h2], %[h2], xzr\n\t"+ "mul %[l0], %[x0], %[b]\n\t"+ "adds %[z0], %[z0], %[l0]\n\t"+ "umulh %[h0], %[x0], %[b]\n\t"+ "adcs %[z1], %[z1], %[h0]\n\t"+ "umulh %[h1], %[x1], %[b]\n\t"+ "stp %[z0], %[z1], [%[t]], #16\n\t"+ "adcs %[z2], %[z2], %[h1]\n\t"+ "str %[z2], [%[t]], #8\n\t"+ "adc %[c], %[h2], xzr\n\t"+ : [a] "+r"(a), [t] "+r"(t), [c] "+r"(carry),+ [x0] "=&r"(x0), [x1] "=&r"(x1), [x2] "=&r"(x2),+ [z0] "=&r"(z0), [z1] "=&r"(z1), [z2] "=&r"(z2),+ [l0] "=&r"(l0), [l1] "=&r"(l1), [l2] "=&r"(l2),+ [h0] "=&r"(h0), [h1] "=&r"(h1), [h2] "=&r"(h2)+ : [b] "r"(b)+ : "cc", "memory");+ } else if (left == 2) {+ __asm__ volatile(+ "ldp %[x0], %[x1], [%[a]], #16\n\t"+ "ldp %[z0], %[z1], [%[t]]\n\t"+ "adds %[z0], %[z0], %[c]\n\t"+ "mul %[l1], %[x1], %[b]\n\t"+ "adcs %[z1], %[z1], %[l1]\n\t"+ "umulh %[h1], %[x1], %[b]\n\t"+ "adc %[h1], %[h1], xzr\n\t"+ "mul %[l0], %[x0], %[b]\n\t"+ "adds %[z0], %[z0], %[l0]\n\t"+ "umulh %[h0], %[x0], %[b]\n\t"+ "adcs %[z1], %[z1], %[h0]\n\t"+ "stp %[z0], %[z1], [%[t]], #16\n\t"+ "adc %[c], %[h1], xzr\n\t"+ : [a] "+r"(a), [t] "+r"(t), [c] "+r"(carry),+ [x0] "=&r"(x0), [x1] "=&r"(x1), [z0] "=&r"(z0),+ [z1] "=&r"(z1), [l0] "=&r"(l0), [l1] "=&r"(l1),+ [h0] "=&r"(h0), [h1] "=&r"(h1)+ : [b] "r"(b)+ : "cc", "memory");+ } else if (left == 1) {+ __asm__ volatile(+ "ldr %[x0], [%[a]], #8\n\t"+ "ldr %[z0], [%[t]]\n\t"+ "mul %[l0], %[x0], %[b]\n\t"+ "adds %[z0], %[z0], %[c]\n\t"+ "umulh %[h0], %[x0], %[b]\n\t"+ "adc %[h0], %[h0], xzr\n\t"+ "adds %[z0], %[z0], %[l0]\n\t"+ "str %[z0], [%[t]], #8\n\t"+ "adc %[c], %[h0], xzr\n\t"+ : [a] "+r"(a), [t] "+r"(t), [c] "+r"(carry),+ [x0] "=&r"(x0), [z0] "=&r"(z0), [l0] "=&r"(l0),+ [h0] "=&r"(h0)+ : [b] "r"(b)+ : "cc", "memory");+ }+ return carry;+}+#else+/* one limb of it, so that the loops below can say how many they take at a+ * time without saying the rest of it four times over */ #define ADDMUL_STEP(k) \ p = (dlimb_t) a[i + (k)] * b + t[i + (k)] + carry; \ t[i + (k)] = (limb_t) p; \@@ -141,6 +328,7 @@ } return carry; }+#endif /* r = t * R^-1 mod m, with t of 2n limbs and destroyed on the way */ static inline void mont_reduce(limb_t *r, limb_t *t, const limb_t *m, limb_t n0,@@ -165,14 +353,33 @@ select_n(r, r, t + n, take & 1, n); } +/* t = a * b, the low n limbs, returning the limb above them: addmul_1 with+ * nothing to add to, for the row of a product that lands on empty space. */+static inline limb_t mul_1(limb_t *t, const limb_t *a, uint32_t n, limb_t b)+{+ limb_t carry = 0;+ uint32_t i;++ for (i = 0; i < n; i++) {+ dlimb_t p = (dlimb_t) a[i] * b + carry;++ t[i] = (limb_t) p;+ carry = (limb_t) (p >> LIMB_BITS);+ }+ return carry;+}+ /* r = a * b * R^-1 mod m, with t of 2n limbs */ static inline void mont_mul(limb_t *r, const limb_t *a, const limb_t *b, const limb_t *m, limb_t n0, uint32_t n, limb_t *t) { uint32_t i; - memset(t, 0, 2 * n * sizeof(limb_t));- for (i = 0; i < n; i++)+ /* Nothing has to be cleared first. The first row lands on empty space+ * and writes t[0 .. n], and every row after it reads t[i .. i+n-1],+ * whose top limb is the one the row before it wrote. */+ t[n] = mul_1(t, a, n, b[0]);+ for (i = 1; i < n; i++) t[n + i] = addmul_1(t + i, a, n, b[i]); mont_reduce(r, t, m, n0, n); }@@ -186,8 +393,14 @@ limb_t carry = 0; uint32_t i; - memset(t, 0, 2 * n * sizeof(limb_t));- for (i = 0; i + 1 < n; i++)+ /* The first row lands on empty space here too, on t[1 .. n], and the+ * rows between them write t[1 .. 2n-2] before any of it is read. The+ * diagonal below is the only reader of the two ends. */+ t[0] = 0;+ t[2 * n - 1] = 0;+ if (n > 1)+ t[n] = mul_1(t + 1, a + 1, n - 1, a[0]);+ for (i = 1; i + 1 < n; i++) t[n + i] = addmul_1(t + i + i + 1, a + i + 1, n - 1 - i, a[i]); shl1(t, 2 * n); /* their sum is under half of what 2n limbs hold */ for (i = 0; i < n; i++) {@@ -201,15 +414,41 @@ mont_reduce(r, t, m, n0, n); } -/* r2 = R^2 mod m, by doubling+/* a = 2a mod m, for an a already under m */+static inline void dbl_mod(limb_t *a, const limb_t *m, uint32_t n, limb_t *tmp)+{+ limb_t carry = shl1(a, n);+ limb_t borrow = sub_n(tmp, a, m, n);++ select_n(a, tmp, a, (carry | (borrow ^ 1)) & 1, n);+}++/* r2 = R^2 mod m, where R is 2^(n * LIMB_BITS) *+ * Doubling the whole way there is 2n * LIMB_BITS steps, and at RSA sizes+ * that is a tenth of the exponentiation it is setting up for. Only the+ * first half of it has to be done a bit at a time.+ *+ * Write a value as 2^(lgR + d) mod m. A Montgomery squaring divides by R,+ * so it takes that to 2(lgR + d) - lgR = lgR + 2d: it doubles d. So double+ * up to R mod m, where d is zero, take one more step to make d one, and then+ * climb to d = lgR by the binary expansion of lgR -- a squaring for each bit+ * and one more doubling where the bit is set. For a 1024-bit modulus that+ * is ten squarings in place of a thousand and twenty-five doublings, and on+ * an Apple M4 that is 2.1 microseconds against 24.7.+ * * Doubling starts at the highest power of two under the modulus rather than * at one, since everything below that power is where doubling would go- * anyway: for a modulus that fills its limbs that is half the steps.+ * anyway: for a modulus that fills its limbs, that first half is one step.+ *+ * What the trip counts depend on is the modulus' length, which is what the+ * doubling loop showed as well, and nothing else about it. */-static inline void mont_r2(limb_t *r2, const limb_t *m, uint32_t n, limb_t *tmp)+static inline void mont_r2(limb_t *r2, const limb_t *m, limb_t n0, uint32_t n,+ limb_t *t) {- uint32_t i, k = 0, steps;+ uint32_t lgr = n * LIMB_BITS;+ uint32_t i, k = 0, msb = 0; for (i = n; i > 0 && k == 0; i--) if (m[i - 1] != 0) {@@ -225,11 +464,16 @@ if (k == 0) return; /* a modulus of nothing, which the caller rules out */ r2[(k - 1) / LIMB_BITS] = (limb_t) 1 << ((k - 1) % LIMB_BITS);- steps = 2 * n * LIMB_BITS - (k - 1);- for (i = 0; i < steps; i++) {- limb_t carry = shl1(r2, n);- limb_t borrow = sub_n(tmp, r2, m, n);- select_n(r2, tmp, r2, (carry | (borrow ^ 1)) & 1, n);+ for (i = k - 1; i < lgr; i++)+ dbl_mod(r2, m, n, t);+ /* r2 is R mod m, so d is zero and squaring would leave it there */+ dbl_mod(r2, m, n, t);+ while ((lgr >> (msb + 1)) != 0)+ msb++;+ for (i = msb; i > 0; i--) {+ mont_sqr(r2, r2, m, n0, n, t);+ if ((lgr >> (i - 1)) & 1)+ dbl_mod(r2, m, n, t); } }
+ cbits/crypton_bzero.h view
@@ -0,0 +1,27 @@+/*+ * Erasing memory that the compiler is entitled to decide nobody reads.+ *+ * memset on an object that is about to die -- freed, or a local going out of+ * scope -- is a store to memory nothing can observe, and an optimizer may+ * drop it. That is the whole reason explicit_bzero and memset_s exist.+ * Neither is everywhere, so this writes through a volatile pointer, which the+ * standard says cannot be elided.+ *+ * Use it wherever key material stops being needed. Plain memset is still+ * right for memory that is about to be read again.+ */+#ifndef CRYPTON_BZERO_H+#define CRYPTON_BZERO_H++#include <stddef.h>+#include <stdint.h>++static inline void crypton_bzero(void *p, size_t n)+{+ volatile uint8_t *q = (volatile uint8_t *)p;++ while (n--)+ *q++ = 0;+}++#endif
cbits/crypton_chacha.c view
@@ -51,7 +51,7 @@ const crypton_chacha_state *in); void crypton_chacha_simd_generate(int rounds, uint8_t *dst, const crypton_chacha_state *in);-/* The counters in a group must not carry into d[13], which the block loop+/* The counters in a group must not carry into d[13], which the crypton_chacha_block loop * below handles and the vector one does not; that is one run in 2^29. */ #define CHACHA_SIMD_OK(st, n) ((st)->d[12] <= 0xffffffffU - (uint32_t) (n)) #endif@@ -89,7 +89,7 @@ * How much is worth handing over. On AArch64 the module's vector path * starts at three blocks and below that its scalar path measures level with * the C here, so there is nothing to gain; on x86-64 it is ahead from one- * block, the C there having no vector path until eight.+ * crypton_chacha_block, the C there having no vector path until eight. */ #ifndef CHACHA_ASM_MIN_BLOCKS #ifdef WITH_X86_CHACHA_ASM@@ -112,7 +112,7 @@ static const uint8_t sigma[16] = "expand 32-byte k"; static const uint8_t tau[16] = "expand 16-byte k"; -static void chacha_core(int rounds, block *out, const crypton_chacha_state *in)+static void chacha_core(int rounds, crypton_chacha_block *out, const crypton_chacha_state *in) { uint32_t x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15; int i;@@ -296,7 +296,7 @@ void crypton_chacha_combine(uint8_t *dst, crypton_chacha_context *ctx, const uint8_t *src, uint32_t bytes) {- block out;+ crypton_chacha_block out; crypton_chacha_state *st; int i; @@ -434,7 +434,7 @@ void crypton_chacha_generate(uint8_t *dst, crypton_chacha_context *ctx, uint32_t bytes) { crypton_chacha_state *st;- block out;+ crypton_chacha_block out; int i; if (!bytes)@@ -474,7 +474,7 @@ /* xor new 64-bytes chunks and store the left over if any */ for (; bytes >= 64; bytes -= 64, dst += 64) { /* generate new chunk and update state */- chacha_core(ctx->nb_rounds, (block *) dst, st);+ chacha_core(ctx->nb_rounds, (crypton_chacha_block *) dst, st); uint32_t t0 = le32_to_cpu(st->d[12]); st->d[12] = cpu_to_le32(t0 + 1); if (st->d[12] == 0) {@@ -524,9 +524,9 @@ void crypton_chacha_generate_simple_block(uint8_t *dst, crypton_chacha_state *st, uint8_t rounds) { if (ALIGNED64(dst)) {- chacha_core(rounds, (block *) dst, st);+ chacha_core(rounds, (crypton_chacha_block *) dst, st); } else {- block out;+ crypton_chacha_block out; int i; chacha_core(rounds, &out, st); for (i = 0; i < 64; ++i) {@@ -544,7 +544,7 @@ void crypton_chacha_random(uint32_t rounds, uint8_t *dst, crypton_chacha_state *st, uint32_t bytes) {- block out;+ crypton_chacha_block out; if (!bytes) return;
cbits/crypton_chacha.h view
@@ -34,9 +34,9 @@ uint64_t q[8]; uint32_t d[16]; uint8_t b[64];-} block;+} crypton_chacha_block; -typedef block crypton_chacha_state;+typedef crypton_chacha_block crypton_chacha_state; typedef struct { crypton_chacha_state st;
+ cbits/crypton_chachapoly.c view
@@ -0,0 +1,156 @@+/*+ * Copyright (c) 2026 Kazu Yamamoto+ *+ * Redistribution and use in source and binary forms, with or without+ * modification, are permitted provided that the following conditions+ * are met:+ * 1. Redistributions of source code must retain the above copyright+ * notice, this list of conditions and the following disclaimer.+ * 2. Redistributions in binary form must reproduce the above copyright+ * notice, this list of conditions and the following disclaimer in the+ * documentation and/or other materials provided with the distribution.+ *+ * THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND+ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR+ * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS+ * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE+ * POSSIBILITY OF SUCH DAMAGE.+ */++#include <stdint.h>+#include <string.h>++#include "crypton_chacha.h"+#include "crypton_chachapoly.h"+#include "crypton_poly1305.h"++/* RFC 8439. The one-time Poly1305 key is the first 32 bytes of the ChaCha20+ * keystream at counter 0; a whole 64-byte block is generated so the counter+ * lands on 1, which is where the message starts. */+static void chachapoly_start(crypton_chacha_context *cctx, poly1305_ctx *pctx,+ const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen)+{+ uint8_t block[64];++ crypton_chacha_init(cctx, 20, 32, key, noncelen, nonce);+ crypton_chacha_generate(block, cctx, sizeof(block));+ crypton_poly1305_init(pctx, (poly1305_key *) block);+ memset(block, 0, sizeof(block));+}++/* Poly1305 over an associated or encrypted part, then zeros up to the next+ * multiple of sixteen. */+static void absorb_padded(poly1305_ctx *pctx, const uint8_t *p, uint32_t len)+{+ static const uint8_t zeros[16] = {0};+ uint32_t rem;++ if (len)+ crypton_poly1305_update(pctx, (uint8_t *) p, len);+ rem = len % 16;+ if (rem)+ crypton_poly1305_update(pctx, (uint8_t *) zeros, 16 - rem);+}++/* The two lengths, little endian, eight bytes each, which is what the tag+ * ends on. */+static void absorb_lengths(poly1305_ctx *pctx, uint32_t aadlen, uint32_t inlen)+{+ uint8_t lens[16];+ int i;++ for (i = 0; i < 8; i++)+ lens[i] = (uint8_t) (((uint64_t) aadlen) >> (8 * i));+ for (i = 0; i < 8; i++)+ lens[8 + i] = (uint8_t) (((uint64_t) inlen) >> (8 * i));+ crypton_poly1305_update(pctx, lens, sizeof(lens));+}++void crypton_chachapoly_encrypt(uint8_t *out, uint8_t *tag, uint32_t taglen,+ const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *input, uint32_t inlen)+{+ crypton_chacha_context cctx;+ poly1305_ctx pctx;+ poly1305_mac mac;++ chachapoly_start(&cctx, &pctx, key, nonce, noncelen);+ absorb_padded(&pctx, aad, aadlen);+ if (inlen)+ crypton_chacha_combine(out, &cctx, input, inlen);+ /* what the tag covers is the ciphertext, which is now in out */+ absorb_padded(&pctx, out, inlen);+ absorb_lengths(&pctx, aadlen, inlen);+ crypton_poly1305_finalize(mac, &pctx);+ memcpy(tag, mac, taglen);++ memset(&cctx, 0, sizeof(cctx));+ memset(&pctx, 0, sizeof(pctx));+}++/* Shared by the two decrypting entry points: with outtag NULL the tag is+ * compared here and the answer returned, otherwise it is written there. */+static int chachapoly_decrypt(uint8_t *out, const uint8_t *tag, uint32_t taglen,+ uint8_t *outtag, const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *input, uint32_t inlen)+{+ crypton_chacha_context cctx;+ poly1305_ctx pctx;+ poly1305_mac mac;+ uint8_t diff = 0;+ uint32_t i;++ chachapoly_start(&cctx, &pctx, key, nonce, noncelen);+ absorb_padded(&pctx, aad, aadlen);+ /* here the ciphertext is the input, so the tag can be taken before the+ * plaintext is written and out may alias input */+ absorb_padded(&pctx, input, inlen);+ absorb_lengths(&pctx, aadlen, inlen);+ crypton_poly1305_finalize(mac, &pctx);++ if (inlen)+ crypton_chacha_combine(out, &cctx, input, inlen);++ memset(&cctx, 0, sizeof(cctx));+ memset(&pctx, 0, sizeof(pctx));++ if (outtag) {+ memcpy(outtag, mac, taglen);+ return 1;+ }+ for (i = 0; i < taglen; i++)+ diff |= (uint8_t) (mac[i] ^ tag[i]);+ return diff == 0;+}++int crypton_chachapoly_decrypt(uint8_t *out,+ const uint8_t *tag, uint32_t taglen,+ const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *input, uint32_t inlen)+{+ return chachapoly_decrypt(out, tag, taglen, NULL, key, nonce, noncelen,+ aad, aadlen, input, inlen);+}++void crypton_chachapoly_decrypt_tag(uint8_t *out, uint8_t *outtag,+ uint32_t taglen, const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *input, uint32_t inlen)+{+ (void) chachapoly_decrypt(out, NULL, taglen, outtag, key, nonce,+ noncelen, aad, aadlen, input, inlen);+}
+ cbits/crypton_chachapoly.h view
@@ -0,0 +1,62 @@+/*+ * Copyright (c) 2026 Kazu Yamamoto+ *+ * Redistribution and use in source and binary forms, with or without+ * modification, are permitted provided that the following conditions+ * are met:+ * 1. Redistributions of source code must retain the above copyright+ * notice, this list of conditions and the following disclaimer.+ * 2. Redistributions in binary form must reproduce the above copyright+ * notice, this list of conditions and the following disclaimer in the+ * documentation and/or other materials provided with the distribution.+ *+ * THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND+ * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE+ * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR+ * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS+ * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS+ * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN+ * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)+ * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE+ * POSSIBILITY OF SUCH DAMAGE.+ */++#ifndef CRYPTON_CHACHAPOLY_H+#define CRYPTON_CHACHAPOLY_H++#include <stdint.h>++/* ChaCha20-Poly1305 (RFC 8439) as one call.+ *+ * The pieces are the ChaCha20 and Poly1305 already here; what these do is+ * hold them together, which the Haskell above used to do at the cost of eight+ * foreign calls and the allocations between them.+ *+ * The nonce is the twelve bytes RFC 8439 defines. taglen is at most 16.+ */++void crypton_chachapoly_encrypt(uint8_t *out, uint8_t *tag, uint32_t taglen,+ const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *input, uint32_t inlen);++/* Decrypt and compare, a byte at a time over the whole tag whichever way the+ * answer goes. Returns non-zero when the tag matched. */+int crypton_chachapoly_decrypt(uint8_t *out,+ const uint8_t *tag, uint32_t taglen,+ const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *input, uint32_t inlen);++/* Decrypt and hand the computed tag back rather than comparing it. */+void crypton_chachapoly_decrypt_tag(uint8_t *out, uint8_t *outtag,+ uint32_t taglen, const uint8_t *key,+ const uint8_t *nonce, uint32_t noncelen,+ const uint8_t *aad, uint32_t aadlen,+ const uint8_t *input, uint32_t inlen);++#endif
cbits/crypton_cpu.c view
@@ -182,13 +182,23 @@ static uint32_t features = 0; if (!resolved) {- uint32_t eax, ebx, ecx, edx, leaf1, maxleaf, f = 0;+ uint32_t eax, ebx, ecx, edx, leaf1, maxleaf, family, f = 0;+ int amd; cpuid(0, &eax, &ebx, &ecx, &edx); maxleaf = eax;+ /* "AuthenticAMD" arrives as EBX, EDX, ECX in that order */+ amd = (ebx == 0x68747541 && edx == 0x69746e65+ && ecx == 0x444d4163); cpuid(1, &eax, &ebx, &ecx, &edx); leaf1 = ecx;+ /* the family is the base one, and the extended field is+ * added to it only when the base reads 0xf, which is how+ * every AMD Zen part reports */+ family = (eax >> 8) & 0xf;+ if (family == 0xf)+ family += (eax >> 20) & 0xff; if (leaf1 & (1 << 9)) f |= CRYPTON_X86_SSSE3; if (leaf1 & (1 << 1))@@ -223,6 +233,42 @@ if ((ebx & (1 << 5)) && (leaf1 & (1 << 27)) && (leaf1 & (1 << 28)) && ((xcr0() & 6) == 6)) f |= CRYPTON_X86_AVX2;+ /* BMI2 for MULX and ADX for ADCX/ADOX. Both are+ * wanted together and neither touches vector state,+ * so there is nothing to ask the operating system */+ if ((ebx & (1 << 8)) && (ebx & (1 << 19)))+ f |= CRYPTON_X86_ADX;+ /* VAES and VPCLMULQDQ, leaf 7 ECX bits 9 and 10.+ * They are wanted together -- one without the other+ * leaves half of AES-GCM narrow -- and they need the+ * wide registers, so AVX2 has to have answered first,+ * which settles the operating system's part. */+ if ((ecx & (1 << 9)) && (ecx & (1 << 10))+ && (f & CRYPTON_X86_AVX2))+ f |= CRYPTON_X86_VAES;+ /* The same two instructions in their 512-bit form,+ * which wants AVX-512 F, BW and VL as well -- and+ * three more bits of XCR0, for the mask registers and+ * the two upper halves of the vector state. A+ * machine can report the instructions and still fault+ * on them when the operating system has not said it+ * saves that state, which is what those bits are. */+ if ((f & CRYPTON_X86_VAES)+ && (ebx & (1 << 16)) && (ebx & (1u << 30))+ && (ebx & (1u << 31))+ && ((xcr0() & 0xe6) == 0xe6)+ /* Not on Zen 4, which is AMD family 19h with+ * AVX-512: there the 512-bit instructions are two+ * 256-bit passes through a 256-bit datapath, so+ * they carry the wider encoding for none of the+ * throughput, and AES-GCM measures 0.6 to 3+ * per cent slower than the 256-bit path. Zen 5+ * is family 1Ah and does have the wide datapath,+ * where the same code is half as fast again;+ * Zen 3, the other family 19h part, has no+ * AVX-512 at all and never reaches here. */+ && !(amd && family == 0x19))+ f |= CRYPTON_X86_VAES512; } features = f; resolved = 1;
cbits/crypton_cpu.h view
@@ -49,6 +49,22 @@ * in, and the byte-swapping load it reads the message with */ #define CRYPTON_X86_AVX 16 #define CRYPTON_X86_MOVBE 32+/* MULX, ADCX and ADOX together: the two independent carry chains the+ * vendored s2n-bignum assembly wants. They are general-purpose register+ * instructions, so unlike the vector ones above they ask nothing of the+ * operating system. */+#define CRYPTON_X86_ADX 64+/* The AES and carry-less multiply instructions in their 256-bit form, which+ * do two blocks where the 128-bit ones do one. They are VEX-encoded and use+ * the vector registers AVX2 already needs the operating system to save, so+ * they ask nothing further of it -- but AVX2 itself is asked about, since+ * without it there is nowhere to put them. */+#define CRYPTON_X86_VAES 128+/* The same pair in their 512-bit form, four blocks to an instruction. These+ * are EVEX-encoded and need the AVX-512 state as well, which is three more+ * bits of XCR0 than AVX2 wants: the mask registers and the two upper halves+ * of the vector registers. */+#define CRYPTON_X86_VAES512 256 #ifdef ARCH_X86 uint32_t crypton_x86_simd_features(void); #endif
cbits/crypton_ecc.c view
@@ -23,8 +23,12 @@ */ #include <stdlib.h> #include <crypton_bignum.h>+#include <crypton_bzero.h> #include <crypton_ecc.h> #include <crypton_powm.h>+#ifdef CRYPTON_S2N_BIGNUM+#include <crypton_ecc_s2n.h>+#endif /* four bits of scalar per window, so a table of sixteen and no leftover * bits: a byte holds exactly two windows */@@ -220,12 +224,15 @@ static void ctx_free(curve_ctx *c) {+ /* crypton_bzero rather than memset: this memory is freed on the next+ * line, and a store to memory about to die is one an optimizer may+ * drop. Both buffers have held scalars. */ if (c->space != NULL) {- memset(c->space, 0, c->words * sizeof(limb_t));+ crypton_bzero(c->space, c->words * sizeof(limb_t)); free(c->space); } if (c->bytes != NULL) {- memset(c->bytes, 0, 2 * c->plen);+ crypton_bzero(c->bytes, 2 * c->plen); free(c->bytes); } c->space = NULL;@@ -284,10 +291,10 @@ ctx_free(c); return -1; }- mont_r2(c->r2, mp, n, mont_t);+ c->f.n0 = mont_n0(mp[0]);+ mont_r2(c->r2, mp, c->f.n0, n, mont_t); c->f.n = n;- c->f.n0 = mont_n0(mp[0]); c->f.p = mp; c->f.a = ma; c->f.b3 = mb3;@@ -411,6 +418,20 @@ curve_ctx c; uint32_t n, i, j; int ret = -1;++#ifdef CRYPTON_S2N_BIGNUM+ /* Two of the curves that reach here have hand-written assembly, six+ * to ten times faster than what follows; see cbits/s2n/README.md.+ * Anything else, including those two named with a different a or b,+ * goes on down. */+ {+ int s2n_ret;++ if (crypton_s2n_ecc_mul(&s2n_ret, outx, outy, px, py, k, klen,+ a, b, p, plen))+ return s2n_ret;+ }+#endif if (klen == 0 || ctx_init(&c, a, b, p, plen) != 0) return -1;
+ cbits/crypton_ecc_s2n.c view
@@ -0,0 +1,204 @@+#include <string.h>++#include "crypton_ecc_s2n.h"+#include "crypton_ecc_s2n_curves.h"+#include "crypton_cpu.h"++/* P-384, Montgomery domain, six words a coordinate */+extern void p384_montjscalarmul(uint64_t *res, const uint64_t *s, const uint64_t *p);+extern void p384_montjscalarmul_alt(uint64_t *res, const uint64_t *s, const uint64_t *p);+extern void bignum_tomont_p384(uint64_t *z, const uint64_t *x);+extern void bignum_tomont_p384_alt(uint64_t *z, const uint64_t *x);+extern void bignum_deamont_p384(uint64_t *z, const uint64_t *x);+extern void bignum_deamont_p384_alt(uint64_t *z, const uint64_t *x);+extern void bignum_montmul_p384(uint64_t *z, const uint64_t *x, const uint64_t *y);+extern void bignum_montmul_p384_alt(uint64_t *z, const uint64_t *x, const uint64_t *y);+extern void bignum_montsqr_p384(uint64_t *z, const uint64_t *x);+extern void bignum_montsqr_p384_alt(uint64_t *z, const uint64_t *x);+extern void bignum_montinv_p384(uint64_t *z, const uint64_t *x);++/* P-521, ordinary values, nine words a coordinate */+extern void p521_jscalarmul(uint64_t *res, const uint64_t *s, const uint64_t *p);+extern void p521_jscalarmul_alt(uint64_t *res, const uint64_t *s, const uint64_t *p);+extern void bignum_mul_p521(uint64_t *z, const uint64_t *x, const uint64_t *y);+extern void bignum_mul_p521_alt(uint64_t *z, const uint64_t *x, const uint64_t *y);+extern void bignum_sqr_p521(uint64_t *z, const uint64_t *x);+extern void bignum_sqr_p521_alt(uint64_t *z, const uint64_t *x);+extern void bignum_inv_p521(uint64_t *z, const uint64_t *x);++/* One flavour or the other, all the way through: on x86-64 the plain form+ * wants MULX, ADCX and ADOX and _alt is the fallback, so mixing them would+ * fault on a machine without those. */+struct p384_asm {+ void (*tomont)(uint64_t *, const uint64_t *);+ void (*deamont)(uint64_t *, const uint64_t *);+ void (*montmul)(uint64_t *, const uint64_t *, const uint64_t *);+ void (*montsqr)(uint64_t *, const uint64_t *);+ void (*jscalarmul)(uint64_t *, const uint64_t *, const uint64_t *);+};+struct p521_asm {+ void (*mul)(uint64_t *, const uint64_t *, const uint64_t *);+ void (*sqr)(uint64_t *, const uint64_t *);+ void (*jscalarmul)(uint64_t *, const uint64_t *, const uint64_t *);+};++static const struct p384_asm p384_std = {+ bignum_tomont_p384, bignum_deamont_p384, bignum_montmul_p384,+ bignum_montsqr_p384, p384_montjscalarmul+};+static const struct p384_asm p384_alt = {+ bignum_tomont_p384_alt, bignum_deamont_p384_alt,+ bignum_montmul_p384_alt, bignum_montsqr_p384_alt,+ p384_montjscalarmul_alt+};+static const struct p521_asm p521_std = {+ bignum_mul_p521, bignum_sqr_p521, p521_jscalarmul+};+static const struct p521_asm p521_alt = {+ bignum_mul_p521_alt, bignum_sqr_p521_alt, p521_jscalarmul_alt+};++/* The same question as for P-256, answered the same way; see+ * cbits/p256/p256_s2n.c. */+static int use_alt(void)+{+#if defined(__aarch64__) || defined(__arm64__)+#ifdef __APPLE__+ return 1;+#else+ return 0;+#endif+#else+ return (crypton_x86_simd_features() & CRYPTON_X86_ADX) == 0;+#endif+}++#define MAXWORDS 9++static void be_to_le64(uint64_t *w, const uint8_t *b, uint32_t len)+{+ uint32_t i;++ for (i = 0; i < MAXWORDS; i++)+ w[i] = 0;+ for (i = 0; i < len; i++) {+ uint32_t pos = len - 1 - i;+ w[pos / 8] |= (uint64_t)b[i] << (8 * (pos % 8));+ }+}++static void le64_to_be(uint8_t *b, uint32_t len, const uint64_t *w)+{+ uint32_t i;++ for (i = 0; i < len; i++)+ b[len - 1 - i] = (uint8_t)(w[i / 8] >> (8 * (i % 8)));+}++static int is_zero(const uint64_t *w, int words)+{+ uint64_t acc = 0;+ int i;++ for (i = 0; i < words; i++)+ acc |= w[i];+ return acc == 0;+}++static int mul_p384(uint8_t *outx, uint8_t *outy, const uint8_t *px,+ const uint8_t *py, const uint8_t *k, uint32_t klen)+{+ const struct p384_asm *f = use_alt() ? &p384_alt : &p384_std;+ uint64_t pt[18], res[18], sc[MAXWORDS], t[MAXWORDS];+ uint64_t zi[6], zi2[6], zi3[6], num[6];+ static const uint64_t one[6] = {1, 0, 0, 0, 0, 0};++ be_to_le64(t, px, P384_PLEN);+ f->tomont(pt, t);+ be_to_le64(t, py, P384_PLEN);+ f->tomont(pt + 6, t);+ f->tomont(pt + 12, one);+ be_to_le64(sc, k, klen);++ f->jscalarmul(res, sc, pt);+ if (is_zero(res + 12, 6))+ return 1;++ /* affine again: x = X/Z^2, y = Y/Z^3, with the inverse taken in the+ * Montgomery domain so that it lands where the rest of these are */+ bignum_montinv_p384(zi, res + 12);+ f->montsqr(zi2, zi);+ f->montmul(zi3, zi2, zi);+ f->montmul(num, res, zi2);+ f->deamont(t, num);+ le64_to_be(outx, P384_PLEN, t);+ f->montmul(num, res + 6, zi3);+ f->deamont(t, num);+ le64_to_be(outy, P384_PLEN, t);+ return 0;+}++static int mul_p521(uint8_t *outx, uint8_t *outy, const uint8_t *px,+ const uint8_t *py, const uint8_t *k, uint32_t klen)+{+ const struct p521_asm *f = use_alt() ? &p521_alt : &p521_std;+ uint64_t pt[27], res[27], sc[MAXWORDS], t[MAXWORDS];+ uint64_t zi[9], zi2[9], zi3[9];+ static const uint64_t one[9] = {1, 0, 0, 0, 0, 0, 0, 0, 0};++ be_to_le64(pt, px, P521_PLEN);+ be_to_le64(pt + 9, py, P521_PLEN);+ memcpy(pt + 18, one, sizeof(one));+ be_to_le64(sc, k, klen);++ f->jscalarmul(res, sc, pt);+ if (is_zero(res + 18, 9))+ return 1;++ bignum_inv_p521(zi, res + 18);+ f->sqr(zi2, zi);+ f->mul(zi3, zi2, zi);+ f->mul(t, res, zi2);+ le64_to_be(outx, P521_PLEN, t);+ f->mul(t, res + 9, zi3);+ le64_to_be(outy, P521_PLEN, t);+ return 0;+}++int crypton_s2n_ecc_mul(int *ret, uint8_t *outx, uint8_t *outy,+ const uint8_t *px, const uint8_t *py,+ const uint8_t *k, uint32_t klen,+ const uint8_t *a, const uint8_t *b,+ const uint8_t *p, uint32_t plen)+{+ int is384;++ if (plen == P384_PLEN && memcmp(p, P384_P, plen) == 0+ && memcmp(a, P384_A, plen) == 0 && memcmp(b, P384_B, plen) == 0)+ is384 = 1;+ else if (plen == P521_PLEN && memcmp(p, P521_P, plen) == 0+ && memcmp(a, P521_A, plen) == 0+ && memcmp(b, P521_B, plen) == 0)+ is384 = 0;+ else+ return 0; /* some other curve; the C answers it */++ /* A scalar longer than the prime is not something the word arrays+ * here hold, and it is not what any caller of these two curves+ * sends, so leave it to the C rather than grow a second path. */+ if (klen == 0 || klen > plen)+ return 0;++ /* The C does not require the coordinates to be reduced -- it takes+ * whatever fits in its limbs and lets the conversion to Montgomery+ * form reduce it. Rather than carry a reduction here to match, hand+ * that case back: nothing sends one, and this way the two cannot+ * disagree about it. (A differential test against the C found this;+ * the first version of this check returned -1 and was wrong.) */+ if (memcmp(px, p, plen) >= 0 || memcmp(py, p, plen) >= 0)+ return 0;++ *ret = is384 ? mul_p384(outx, outy, px, py, k, klen)+ : mul_p521(outx, outy, px, py, k, klen);+ return 1;+}
+ cbits/crypton_ecc_s2n.h view
@@ -0,0 +1,27 @@+/*+ * P-384 and P-521 through the vendored s2n-bignum assembly, for the two+ * curves it knows among the ones crypton_ecc_mul is asked about.+ *+ * s2n-bignum has no affine wrapper for these two -- only a scalar+ * multiplication on Jacobian points, Montgomery-domain for P-384 and plain+ * for P-521 -- so the conversions in and out are built here out of its own+ * field operations. See cbits/s2n/README.md.+ */+#ifndef CRYPTON_ECC_S2N_H+#define CRYPTON_ECC_S2N_H++#include <stdint.h>++/*+ * Returns 1 if this was a curve it knows and it answered, with *ret set to+ * what crypton_ecc_mul should return -- 0 and the point in outx and outy, 1+ * for the point at infinity, or -1 for arguments it will not take. Returns+ * 0 if the curve is not one of its two and nothing was written.+ */+int crypton_s2n_ecc_mul(int *ret, uint8_t *outx, uint8_t *outy,+ const uint8_t *px, const uint8_t *py,+ const uint8_t *k, uint32_t klen,+ const uint8_t *a, const uint8_t *b,+ const uint8_t *p, uint32_t plen);++#endif
+ cbits/crypton_ecc_s2n_curves.h view
@@ -0,0 +1,76 @@+/*+ * p, a and b of the two curves the vendored s2n-bignum assembly knows, as+ * big-endian bytes, which is how crypton_ecc_mul is given a curve. They are+ * here to be compared against, not computed with: a caller naming some other+ * curve with the same sizes has to go to the C.+ *+ * Generated from `openssl ecparam -name secp384r1 -param_enc explicit -text`+ * and the same for secp521r1, rather than transcribed.+ */+#ifndef CRYPTON_ECC_S2N_CURVES_H+#define CRYPTON_ECC_S2N_CURVES_H++#include <stdint.h>++#define P384_PLEN 48+static const uint8_t P384_P[48] = {+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xfe,+ 0xff,0xff,0xff,0xff,0x00,0x00,0x00,0x00,+ 0x00,0x00,0x00,0x00,0xff,0xff,0xff,0xff+};+static const uint8_t P384_A[48] = {+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xfe,+ 0xff,0xff,0xff,0xff,0x00,0x00,0x00,0x00,+ 0x00,0x00,0x00,0x00,0xff,0xff,0xff,0xfc+};+static const uint8_t P384_B[48] = {+ 0xb3,0x31,0x2f,0xa7,0xe2,0x3e,0xe7,0xe4,+ 0x98,0x8e,0x05,0x6b,0xe3,0xf8,0x2d,0x19,+ 0x18,0x1d,0x9c,0x6e,0xfe,0x81,0x41,0x12,+ 0x03,0x14,0x08,0x8f,0x50,0x13,0x87,0x5a,+ 0xc6,0x56,0x39,0x8d,0x8a,0x2e,0xd1,0x9d,+ 0x2a,0x85,0xc8,0xed,0xd3,0xec,0x2a,0xef+};++#define P521_PLEN 66+static const uint8_t P521_P[66] = {+ 0x01,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff+};+static const uint8_t P521_A[66] = {+ 0x01,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xfc+};+static const uint8_t P521_B[66] = {+ 0x00,0x51,0x95,0x3e,0xb9,0x61,0x8e,0x1c,+ 0x9a,0x1f,0x92,0x9a,0x21,0xa0,0xb6,0x85,+ 0x40,0xee,0xa2,0xda,0x72,0x5b,0x99,0xb3,+ 0x15,0xf3,0xb8,0xb4,0x89,0x91,0x8e,0xf1,+ 0x09,0xe1,0x56,0x19,0x39,0x51,0xec,0x7e,+ 0x93,0x7b,0x16,0x52,0xc0,0xbd,0x3b,0xb1,+ 0xbf,0x07,0x35,0x73,0xdf,0x88,0x3d,0x2c,+ 0x34,0xf1,0xef,0x45,0x1f,0xd4,0x6b,0x50,+ 0x3f,0x00+};++#endif
cbits/crypton_f2m.c view
@@ -25,6 +25,8 @@ #include <stdlib.h> #include <string.h> #include <crypton_cpu.h>+#include "crypton_armv8_target.h"+#include <crypton_bzero.h> #include <crypton_f2m.h> typedef uint64_t limb_t;@@ -89,7 +91,7 @@ #define PMULL_ATTR #define PMULL_ALWAYS 1 #else-#define PMULL_ATTR __attribute__((target("+crypto")))+#define PMULL_ATTR CRYPTON_TARGET_ARMV8_CRYPTO #define PMULL_ALWAYS 0 #endif @@ -543,8 +545,10 @@ ret = 0; done:+ /* freed on the next line, so a plain memset here is a store the+ * optimizer may drop */ if (space != NULL) {- memset(space, 0, words * sizeof(limb_t));+ crypton_bzero(space, words * sizeof(limb_t)); free(space); } return ret;
cbits/crypton_md4.c view
@@ -48,16 +48,17 @@ #define K3 0x6ED9EBA1 #define R(a,b,c,d,f,k,s,i) (a = rol32(a + f(b,c,d) + w[i] + k, s)) -static void md4_do_chunk(struct md4_ctx *ctx, uint32_t *buf)+/* The words are read out of the block rather than the block being pointed at+ * as though it were an array of them; see crypton_md5.c. */+static void md4_do_chunk(struct md4_ctx *ctx, const uint8_t *buf) { uint32_t a, b, c, d;-#ifdef ARCH_IS_BIG_ENDIAN uint32_t w[16];- cpu_to_le32_array(w, (uint32_t *) buf, 16);-#else- uint32_t *w = buf;-#endif+ int wi; + for (wi = 0; wi < 16; wi++)+ w[wi] = load_le32(buf + 4 * wi);+ a = ctx->h[0]; b = ctx->h[1]; c = ctx->h[2]; d = ctx->h[3]; R(a, b, c, d, f1, K1, 3, 0);@@ -125,24 +126,15 @@ if (index && len >= to_fill) { memcpy(ctx->buf + index, data, to_fill);- md4_do_chunk(ctx, (uint32_t *) ctx->buf);+ md4_do_chunk(ctx, ctx->buf); len -= to_fill; data += to_fill; index = 0; } - if (need_alignment(data, 4)) {- uint32_t tramp[16];- ASSERT_ALIGNMENT(tramp, 4);- for (; len >= 64; len -= 64, data += 64) {- memcpy(tramp, data, 64);- md4_do_chunk(ctx, tramp);- }- } else {- /* process as much 64-block as possible */- for (; len >= 64; len -= 64, data += 64)- md4_do_chunk(ctx, (uint32_t *) data);- }+ /* No trampoline: load_le32 does not ask for a boundary. */+ for (; len >= 64; len -= 64, data += 64)+ md4_do_chunk(ctx, data); /* append data into buf */ if (len)
cbits/crypton_md5.c view
@@ -45,15 +45,22 @@ #define f4(x, y, z) (y ^ (x | ~z)) #define R(f, a, b, c, d, i, k, s) a += f(b, c, d) + w[i] + k; a = rol32(a, s); a += b -static void md5_do_chunk(struct md5_ctx *ctx, uint32_t *buf)+/* The sixteen words are read out of the block rather than the block being+ * pointed at as though it were an array of them. A caller's pointer cast to+ * uint32_t * is a pointer the standard says may not exist unless the address+ * is aligned for it, and reading through it is undefined whether or not the+ * machine minds; UndefinedBehaviorSanitizer counted sixty-four of these.+ * load_le32 is a memcpy, which every compiler here turns into the one load+ * the cast used to be, and it takes the endianness with it -- so the two+ * arms this replaces are one. */+static void md5_do_chunk(struct md5_ctx *ctx, const uint8_t *buf) { uint32_t a, b, c, d;-#ifdef ARCH_IS_BIG_ENDIAN uint32_t w[16];- cpu_to_le32_array(w, buf, 16);-#else- uint32_t *w = buf;-#endif+ int wi;++ for (wi = 0; wi < 16; wi++)+ w[wi] = load_le32(buf + 4 * wi); a = ctx->h[0]; b = ctx->h[1]; c = ctx->h[2]; d = ctx->h[3]; R(f1, a, b, c, d, 0, 0xd76aa478, 7);@@ -138,24 +145,16 @@ if (index && len >= to_fill) { memcpy(ctx->buf + index, data, to_fill);- md5_do_chunk(ctx, (uint32_t *) ctx->buf);+ md5_do_chunk(ctx, ctx->buf); len -= to_fill; data += to_fill; index = 0; } - if (need_alignment(data, 4)) {- uint32_t tramp[16];- ASSERT_ALIGNMENT(tramp, 4);- for (; len >= 64; len -= 64, data += 64) {- memcpy(tramp, data, 64);- md5_do_chunk(ctx, tramp);- }- } else {- /* process as much 64-block as possible */- for (; len >= 64; len -= 64, data += 64)- md5_do_chunk(ctx, (uint32_t *) data);- }+ /* No trampoline for a block that is not on a four-byte boundary: the+ * words are read with load_le32 now, which does not ask. */+ for (; len >= 64; len -= 64, data += 64)+ md5_do_chunk(ctx, data); /* append data into buf */ if (len)
+ cbits/crypton_modinv.c view
@@ -0,0 +1,74 @@+/*+ * Inversion modulo an odd number through s2n-bignum, whose routine takes a+ * fixed number of division steps rather than an exponentiation: twenty to+ * thirty times less work than Fermat's little theorem at the sizes here.+ * Measured on an Apple M4, inverting modulo a curve order:+ *+ * Fermat this+ * P-256 6.02 us 0.80+ * P-384 31.3 1.20+ * P-521 63.2 2.05+ *+ * It uses no instruction beyond the base architecture on either x86-64 or+ * AArch64, so unlike the rest of the vendored assembly there is nothing to+ * ask the processor first.+ */+#include <string.h>++#include "crypton_modinv.h"++#ifdef CRYPTON_S2N_BIGNUM++extern void bignum_modinv(uint64_t k, uint64_t *z, const uint64_t *a,+ const uint64_t *b, uint64_t *t);++/* 4096 bits and no more, which covers every modulus that reaches here -- the+ * order of a curve, or a prime factor of an RSA modulus -- and keeps the+ * working space on the stack. Anything larger is handed back. */+#define MODINV_MAXWORDS 64++int crypton_modinv_sec(uint8_t *z, const uint8_t *a, const uint8_t *m,+ uint32_t len)+{+ uint64_t aw[MODINV_MAXWORDS], mw[MODINV_MAXWORDS];+ uint64_t zw[MODINV_MAXWORDS], t[3 * MODINV_MAXWORDS];+ uint32_t k = (len + 7) / 8;+ uint32_t i;++ /* An even modulus is the one case it answers without saying it+ * cannot: it returns a number that is not an inverse rather than+ * failing, so keep it away from here. Every caller's modulus is odd. */+ if (len == 0 || k > MODINV_MAXWORDS || (m[len - 1] & 1) == 0)+ return 1;++ for (i = 0; i < k; i++) {+ aw[i] = 0;+ mw[i] = 0;+ }+ for (i = 0; i < len; i++) {+ uint32_t pos = len - 1 - i;++ aw[pos / 8] |= (uint64_t)a[i] << (8 * (pos % 8));+ mw[pos / 8] |= (uint64_t)m[i] << (8 * (pos % 8));+ }++ bignum_modinv(k, zw, aw, mw, t);++ for (i = 0; i < len; i++)+ z[len - 1 - i] = (uint8_t)(zw[i / 8] >> (8 * (i % 8)));+ return 0;+}++#else++int crypton_modinv_sec(uint8_t *z, const uint8_t *a, const uint8_t *m,+ uint32_t len)+{+ (void)z;+ (void)a;+ (void)m;+ (void)len;+ return 1;+}++#endif
+ cbits/crypton_modinv.h view
@@ -0,0 +1,22 @@+#ifndef CRYPTON_MODINV_H+#define CRYPTON_MODINV_H++#include <stdint.h>++/* z = a^-1 mod m, all three big-endian byte strings of len bytes.+ *+ * Returns 0 with the answer in z, and 1 without touching z when it will not+ * do this one: the assembly it needs is not built, the modulus is even, or+ * the numbers are larger than it keeps room for. A 1 is not an error, it is+ * "ask something else".+ *+ * The answer is not checked here. When a has no inverse the routine+ * underneath returns something that is not one rather than saying so, so the+ * caller has to multiply out and look -- which is what Crypto.Number.+ * ModArithmetic.inverseSafe already did for the exponentiation this+ * replaces.+ */+int crypton_modinv_sec(uint8_t *z, const uint8_t *a, const uint8_t *m,+ uint32_t len);++#endif
cbits/crypton_pbkdf2.c view
@@ -46,6 +46,7 @@ /* Internal function/type names for hash-specific things. */ #define HMAC_CTX(_name) HMAC_ ## _name ## _ctx+#define DIGEST_FITS(_name) pbkdf2_ ## _name ## _digest_fits_in_a_block #define HMAC_INIT(_name) HMAC_ ## _name ## _init #define HMAC_UPDATE(_name) HMAC_ ## _name ## _update #define HMAC_FINAL(_name) HMAC_ ## _name ## _final@@ -79,6 +80,16 @@ */ #define DECL_PBKDF2(_name, _blocksz, _hashsz, _ctx, \ _init, _update, _xform, _final, _xcpy, _xtract, _xxor) \+ /* HMAC_INIT below shortens a key longer than the block by hashing it, \+ * which writes _hashsz bytes into a buffer of _blocksz. An instantiation \+ * whose digest is larger than its block would overflow that buffer, and \+ * would do it before any check inside the function could say so -- which \+ * is where the check used to be. Refuse such an instantiation here \+ * instead, in front of the person writing it. The three below are \+ * SHA-1, SHA-256 and SHA-512, whose digests are 20, 32 and 64 bytes \+ * against blocks of 64, 64 and 128. */ \+ typedef char DIGEST_FITS(_name)[(_hashsz) <= (_blocksz) ? 1 : -1]; \+ \ typedef struct { \ _ctx inner; \ _ctx outer; \@@ -101,9 +112,6 @@ nkey = _hashsz; \ } \ \- /* Standard doesn't cover case where blocksz < hashsz. */ \- assert(nkey <= _blocksz); \- \ /* Right zero-pad short keys. */ \ if (k != key) \ memcpy(k, key, nkey); \@@ -192,7 +200,16 @@ uint8_t *out, size_t nout) \ { \ assert(iterations); \- assert(out && nout); \+ assert(out); \+ \+ /* Zero bytes of derived key is zero bytes of work. RFC 8018 asks for a \+ * positive dkLen and the loop below would write a block regardless, so \+ * this used to be `assert(out && nout)` -- which aborts the process, in \+ * a library built without NDEBUG, on a length the caller chose. \+ * Crypto.KDF.PBKDF2's own tryGenerate returns an empty result for this, \+ * so return and let the two agree. */ \+ if (nout == 0) \+ return; \ \ /* Starting point for inner loop. */ \ HMAC_CTX(_name) ctx; \
cbits/crypton_powm.c view
@@ -20,21 +20,204 @@ #include <stdlib.h> #include <crypton_bignum.h> #include <crypton_powm.h>+#include <crypton_bzero.h> -/* four bits of exponent per window, so a table of sixteen and no leftover- * bits: a byte holds exactly two windows */+/*+ * At RSA sizes on x86-64, the Montgomery multiplication below is the whole+ * cost, and s2n-bignum's is twice as fast because the C cannot form the two+ * carry chains ADCX and ADOX give. The window, the table and its masked+ * scan are unchanged: only the multiply and the square are swapped, and+ * only for the sizes s2n-bignum has a Karatsuba multiplication for.+ *+ * Not on AArch64, where the C measures 5% faster than the assembly.+ * See cbits/s2n/README.md.+ */+#if defined(CRYPTON_S2N_BIGNUM) && defined(__x86_64__)+#define CRYPTON_POWM_S2N 1+#include <crypton_cpu.h>++extern void bignum_kmul_16_32(uint64_t *z, const uint64_t *x,+ const uint64_t *y, uint64_t *t);+extern void bignum_ksqr_16_32(uint64_t *z, const uint64_t *x, uint64_t *t);+extern void bignum_kmul_32_64(uint64_t *z, const uint64_t *x,+ const uint64_t *y, uint64_t *t);+extern void bignum_ksqr_32_64(uint64_t *z, const uint64_t *x, uint64_t *t);+extern uint64_t bignum_emontredc_8n(uint64_t k, uint64_t *z,+ const uint64_t *m, uint64_t w);++/* 16 limbs is 1024 bits and 32 is 2048: the halves a CRT exponentiation+ * works in for RSA-2048 and RSA-4096, and the whole thing without CRT. The+ * reduction wants ADX, so the answer is a run-time one. */+static int powm_s2n_usable(uint32_t n)+{+ return (n == 16 || n == 32)+ && (crypton_x86_simd_features() & CRYPTON_X86_ADX) != 0;+}++/* The scratch the widest of them asks for, in multiples of n: kmul_32_64+ * wants 96 limbs for n = 32. */+#define POWM_S2N_SCRATCH 3++/* bignum_emontredc_8n leaves the result in the top half of z with one more+ * bit as its return value, and what is there is under twice the modulus --+ * the same place mont_reduce ends up, and finished the same way. */+static void powm_s2n_finish(limb_t *r, limb_t *z, const limb_t *m,+ limb_t carry, uint32_t n)+{+ limb_t borrow = sub_n(r, z + n, m, n);+ limb_t take = carry | (borrow ^ 1);++ select_n(r, r, z + n, take & 1, n);+}++static void powm_s2n_mul(limb_t *r, const limb_t *a, const limb_t *b,+ const limb_t *m, limb_t n0, uint32_t n, limb_t *z,+ limb_t *scratch)+{+ if (n == 16)+ bignum_kmul_16_32(z, a, b, scratch);+ else+ bignum_kmul_32_64(z, a, b, scratch);+ powm_s2n_finish(r, z, m, bignum_emontredc_8n(n, z, m, n0), n);+}++static void powm_s2n_sqr(limb_t *r, const limb_t *a, const limb_t *m,+ limb_t n0, uint32_t n, limb_t *z, limb_t *scratch)+{+ if (n == 16)+ bignum_ksqr_16_32(z, a, scratch);+ else+ bignum_ksqr_32_64(z, a, scratch);+ powm_s2n_finish(r, z, m, bignum_emontredc_8n(n, z, m, n0), n);+}+#else+#define POWM_S2N_SCRATCH 0+#endif++/* One or the other, decided once per call */+static void powm_mul(limb_t *r, const limb_t *a, const limb_t *b,+ const limb_t *m, limb_t n0, uint32_t n, limb_t *t,+ limb_t *scratch, int s2n)+{+#ifdef CRYPTON_POWM_S2N+ if (s2n) {+ powm_s2n_mul(r, a, b, m, n0, n, t, scratch);+ return;+ }+#else+ (void)scratch;+ (void)s2n;+#endif+ mont_mul(r, a, b, m, n0, n, t);+}++static void powm_sqr(limb_t *r, const limb_t *a, const limb_t *m, limb_t n0,+ uint32_t n, limb_t *t, limb_t *scratch, int s2n)+{+#ifdef CRYPTON_POWM_S2N+ if (s2n) {+ powm_s2n_sqr(r, a, m, n0, n, t, scratch);+ return;+ }+#else+ (void)scratch;+ (void)s2n;+#endif+ mont_sqr(r, a, m, n0, n, t);+}++/* Four bits of exponent per window, so a table of sixteen and no leftover+ * bits: a byte holds exactly two windows.+ *+ * Five was written and measured, and is not here. A wider window saves+ * multiplications -- 205 of them against 256 at 1024 bits, with the same+ * 1024 squarings -- and pays for it in the masked scan of a table twice as+ * long, and which way that comes out depends on the machine and on which+ * multiplication is running: 3.5% better on an Apple M4, about 1% worse on+ * an older x86-64, and 7% worse anywhere s2n-bignum's multiplication is+ * used, since that makes the scan the expensive half. Six measured level+ * with five on the M4 and seven worse. What would make a wider window pay+ * everywhere is a cheaper scan, not a wider window. */ #define WINDOW_BITS 4 #define TABLE_SIZE (1 << WINDOW_BITS) +/* The masked scan of the table: every entry is read and a mask keeps the one+ * wanted, so that the address stream does not follow the exponent. At+ * RSA-2048's CRT size that is two kilobytes read per window, and the window+ * loop runs 256 times per exponentiation, which is why it is worth a vector+ * register: removing the scan altogether measures 11% of an exponentiation+ * where s2n-bignum's multiplication runs, and the AVX2 form below gets+ * essentially all of it. */+static void scan_table(limb_t *sel, const limb_t *table, uint32_t n, limb_t w)+{+ uint32_t k, l;++ memset(sel, 0, n * sizeof(limb_t));+ for (k = 0; k < TABLE_SIZE; k++) {+ limb_t mask = eq_mask(k, w);++ for (l = 0; l < n; l++)+ sel[l] |= table[k * n + l] & mask;+ }+}++#if defined(__x86_64__) && defined(WITH_TARGET_ATTRIBUTES) && LIMB_BITS == 64+#define CRYPTON_POWM_SCAN_AVX2 1+#include <crypton_cpu.h>+#include <immintrin.h>++/* The same scan four limbs at a time. The sixteen masks are worked out+ * once; after that each register of the answer is one pass over the table's+ * column, reading every entry exactly as the scalar form does. */+__attribute__((target("avx2")))+static void scan_table_avx2(limb_t *sel, const limb_t *table, uint32_t n,+ limb_t w)+{+ __m256i masks[TABLE_SIZE];+ uint32_t k, l;++ for (k = 0; k < TABLE_SIZE; k++)+ masks[k] = _mm256_cmpeq_epi64(+ _mm256_set1_epi64x((long long) k),+ _mm256_set1_epi64x((long long) w));++ for (l = 0; l + 4 <= n; l += 4) {+ __m256i acc = _mm256_setzero_si256();++ for (k = 0; k < TABLE_SIZE; k++) {+ __m256i v = _mm256_loadu_si256(+ (const __m256i *) (table + k * n + l));++ acc = _mm256_or_si256(acc,+ _mm256_and_si256(v, masks[k]));+ }+ _mm256_storeu_si256((__m256i *) (sel + l), acc);+ }++ /* a modulus whose limbs do not come in fours ends here */+ for (; l < n; l++) {+ limb_t v = 0;++ for (k = 0; k < TABLE_SIZE; k++)+ v |= table[k * n + l] & eq_mask(k, w);+ sel[l] = v;+ }+}+#endif+ int crypton_powm_sec(uint8_t *out, const uint8_t *base, uint32_t baselen, const uint8_t *exp, uint32_t explen, const uint8_t *mod, uint32_t modlen) { uint32_t n = (modlen + LIMB_BYTES - 1) / LIMB_BYTES;- uint32_t words = (TABLE_SIZE + 7) * n;- limb_t *space, *m, *r2, *acc, *sel, *prod, *table, *t, n0;+ uint32_t words = (TABLE_SIZE + 7 + POWM_S2N_SCRATCH) * n;+ limb_t *space, *m, *r2, *acc, *sel, *prod, *table, *t, *scratch, n0; uint32_t i, j, k;+ int s2n = 0;+#ifdef CRYPTON_POWM_SCAN_AVX2+ int avx2 = (crypton_x86_simd_features() & CRYPTON_X86_AVX2) != 0;+#endif if (modlen == 0 || n == 0 || (mod[modlen - 1] & 1) == 0) return 1;@@ -50,23 +233,29 @@ prod = sel + n; t = prod + n; table = t + 2 * n;+ scratch = table + TABLE_SIZE * n; +#ifdef CRYPTON_POWM_S2N+ s2n = powm_s2n_usable(n);+#endif+ if (from_be(m, n, mod, modlen) != 0) goto fail;- mont_r2(r2, m, n, t); n0 = mont_n0(m[0]);+ mont_r2(r2, m, n0, n, t); /* table[k] = base^k in Montgomery form, and table[0] = 1 there */ memset(table, 0, n * sizeof(limb_t)); table[0] = 1;- mont_mul(acc, table, r2, m, n0, n, t);+ powm_mul(acc, table, r2, m, n0, n, t, scratch, s2n); memcpy(table, acc, n * sizeof(limb_t)); if (from_be(sel, n, base, baselen) != 0) goto fail;- mont_mul(table + n, sel, r2, m, n0, n, t);+ powm_mul(table + n, sel, r2, m, n0, n, t, scratch, s2n); for (k = 2; k < TABLE_SIZE; k++)- mont_mul(table + k * n, table + (k - 1) * n, table + n, m, n0, n, t);+ powm_mul(table + k * n, table + (k - 1) * n, table + n, m, n0, n,+ t, scratch, s2n); memcpy(acc, table, n * sizeof(limb_t)); @@ -74,38 +263,49 @@ uint32_t nib = i - 1; limb_t w = (exp[explen - 1 - nib / 2] >> (4 * (nib % 2))) & 0xf; + /* squaring into the other buffer and swapping the two saves a+ * copy of the modulus' width every time; which of the three+ * buffers a pointer names is nobody's secret */ for (j = 0; j < WINDOW_BITS; j++) {- mont_sqr(sel, acc, m, n0, n, t);- memcpy(acc, sel, n * sizeof(limb_t));+ limb_t *swap;++ powm_sqr(sel, acc, m, n0, n, t, scratch, s2n);+ swap = acc;+ acc = sel;+ sel = swap; } - /* every entry is read, and a mask keeps the one wanted */- memset(sel, 0, n * sizeof(limb_t));- for (k = 0; k < TABLE_SIZE; k++) {- limb_t mask = eq_mask(k, w);- uint32_t l;+#ifdef CRYPTON_POWM_SCAN_AVX2+ if (avx2)+ scan_table_avx2(sel, table, n, w);+ else+#endif+ scan_table(sel, table, n, w);+ powm_mul(prod, acc, sel, m, n0, n, t, scratch, s2n);+ {+ limb_t *swap = acc; - for (l = 0; l < n; l++)- sel[l] |= table[k * n + l] & mask;+ acc = prod;+ prod = swap; }- mont_mul(prod, acc, sel, m, n0, n, t);- memcpy(acc, prod, n * sizeof(limb_t)); } /* out of Montgomery form */ memset(sel, 0, n * sizeof(limb_t)); sel[0] = 1;- mont_mul(prod, acc, sel, m, n0, n, t);+ powm_mul(prod, acc, sel, m, n0, n, t, scratch, s2n); to_be(out, modlen, prod, n); /* nothing here is the caller's secret, but the exponent's bits passed- * through the accumulators */- memset(space, 0, words * sizeof(limb_t));+ * through the accumulators. crypton_bzero rather than memset, since+ * this memory is freed on the next line and a store to memory about to+ * die is one an optimizer may drop. */+ crypton_bzero(space, words * sizeof(limb_t)); free(space); return 0; fail:- memset(space, 0, words * sizeof(limb_t));+ crypton_bzero(space, words * sizeof(limb_t)); free(space); return 1; }
cbits/crypton_ripemd.c view
@@ -57,16 +57,17 @@ #define R(a, b, c, d, e, f, k, i, s) \ a += f(b, c, d) + w[i] + k; a = rol32(a, s) + e; c = rol32(c, 10) -static void ripemd160_do_chunk(struct ripemd160_ctx *ctx, uint32_t *buf)+/* The words are read out of the block rather than the block being pointed at+ * as though it were an array of them; see crypton_md5.c. */+static void ripemd160_do_chunk(struct ripemd160_ctx *ctx, const uint8_t *buf) { uint32_t a1, b1, c1, d1, e1, a2, b2, c2, d2, e2;-#ifdef ARCH_IS_BIG_ENDIAN uint32_t w[16];- cpu_to_le32_array(w, buf, 16);-#else- uint32_t *w = buf;-#endif+ int wi; + for (wi = 0; wi < 16; wi++)+ w[wi] = load_le32(buf + 4 * wi);+ a1 = ctx->h[0]; b1 = ctx->h[1]; c1 = ctx->h[2]; d1 = ctx->h[3]; e1 = ctx->h[4]; a2 = ctx->h[0]; b2 = ctx->h[1]; c2 = ctx->h[2]; d2 = ctx->h[3]; e2 = ctx->h[4]; @@ -260,24 +261,15 @@ ctx->sz += len; if (index && len >= to_fill) { memcpy(ctx->buf + index, data, to_fill);- ripemd160_do_chunk(ctx, (uint32_t *) ctx->buf);+ ripemd160_do_chunk(ctx, ctx->buf); len -= to_fill; data += to_fill; index = 0; } - if (need_alignment(data, 4)) {- uint32_t tramp[16];- ASSERT_ALIGNMENT(tramp, 4);- for (; len >= 64; len -= 64, data += 64) {- memcpy(tramp, data, 64);- ripemd160_do_chunk(ctx, tramp);- }- } else {- /* process as much 64-block as possible */- for (; len >= 64; len -= 64, data += 64)- ripemd160_do_chunk(ctx, (uint32_t *) data);- }+ /* No trampoline: load_le32 does not ask for a boundary. */+ for (; len >= 64; len -= 64, data += 64)+ ripemd160_do_chunk(ctx, data); /* append data into buf */ if (len)
cbits/crypton_salsa.c view
@@ -59,7 +59,7 @@ QR (x15,x12,x13,x14); \ } -static void salsa_core(int rounds, block *out, const crypton_salsa_state *in)+static void salsa_core(int rounds, crypton_salsa_block *out, const crypton_salsa_state *in) { uint32_t x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15; int i;@@ -94,7 +94,7 @@ out->d[15] = cpu_to_le32(x15); } -void crypton_salsa_core_xor(int rounds, block *out, block *in)+void crypton_salsa_core_xor(int rounds, crypton_salsa_block *out, crypton_salsa_block *in) { uint32_t x0, x1, x2, x3, x4, x5, x6, x7, x8, x9, x10, x11, x12, x13, x14, x15; int i;@@ -165,7 +165,7 @@ void crypton_salsa_combine(uint8_t *dst, crypton_salsa_context *ctx, const uint8_t *src, uint32_t bytes) {- block out;+ crypton_salsa_block out; crypton_salsa_state *st; int i; @@ -225,7 +225,7 @@ void crypton_salsa_generate(uint8_t *dst, crypton_salsa_context *ctx, uint32_t bytes) { crypton_salsa_state *st;- block out;+ crypton_salsa_block out; int i; if (!bytes)@@ -252,7 +252,7 @@ /* xor new 64-bytes chunks and store the left over if any */ for (; bytes >= 64; bytes -= 64, dst += 64) { /* generate new chunk and update state */- salsa_core(ctx->nb_rounds, (block *) dst, st);+ salsa_core(ctx->nb_rounds, (crypton_salsa_block *) dst, st); st->d[8] += 1; if (st->d[8] == 0) st->d[9] += 1;
cbits/crypton_salsa.h view
@@ -34,9 +34,9 @@ uint64_t q[8]; uint32_t d[16]; uint8_t b[64];-} block;+} crypton_salsa_block; -typedef block crypton_salsa_state;+typedef crypton_salsa_block crypton_salsa_state; typedef struct { crypton_salsa_state st;@@ -47,7 +47,7 @@ } crypton_salsa_context; /* for scrypt */-void crypton_salsa_core_xor(int rounds, block *out, block *in);+void crypton_salsa_core_xor(int rounds, crypton_salsa_block *out, crypton_salsa_block *in); void crypton_salsa_init_core(crypton_salsa_state *st, uint32_t keylen, const uint8_t *key, uint32_t ivlen, const uint8_t *iv); void crypton_salsa_init(crypton_salsa_context *ctx, uint8_t nb_rounds, uint32_t keylen, const uint8_t *key, uint32_t ivlen, const uint8_t *iv);
cbits/crypton_scrypt.c view
@@ -37,10 +37,10 @@ array_copy32(X, &in[(2 * r - 1) * 16], 16); for (i = 0; i < 2 * r; i += 2) {- crypton_salsa_core_xor(8, (block *) X, (block *) &in[i*16]);+ crypton_salsa_core_xor(8, (crypton_salsa_block *) X, (crypton_salsa_block *) &in[i*16]); array_copy32(&out[i * 8], X, 16); - crypton_salsa_core_xor(8, (block *) X, (block *) &in[i*16+16]);+ crypton_salsa_core_xor(8, (crypton_salsa_block *) X, (crypton_salsa_block *) &in[i*16+16]); array_copy32(&out[i * 8 + r * 16], X, 16); } }
cbits/crypton_sha1.c view
@@ -32,7 +32,7 @@ * Two threads racing to answer here both write the same value. */ #ifdef WITH_ARMV8_SHA1-extern void crypton_sha1_armv8_do_chunk(uint32_t state[5], const uint32_t buf[16]);+extern void crypton_sha1_armv8_do_chunk(uint32_t state[5], const uint8_t buf[64]); extern void crypton_sha1_armv8_do_chunks(uint32_t state[5], const uint8_t *data, uint32_t blocks); extern int crypton_sha1_armv8_available(void);@@ -55,8 +55,20 @@ const void *data, size_t blocks); #endif +/* Resolved before there is a second thread; see the constructor in+ * cbits/crypton_aes.c for why. The test below then only ever reads. */ static int sha1_use_armv8 = -1;++__attribute__((constructor))+static void sha1_armv8_ctor(void)+{+ sha1_use_armv8 = crypton_sha1_armv8_available();+#ifdef SHA1_ASM+ if (sha1_use_armv8)+ crypton_armcap_P |= CRYPTON_ARMCAP_SHA1; #endif+}+#endif #ifdef WITH_X86_SHA_NI #include "crypton_cpu.h"@@ -89,11 +101,13 @@ #define M(i) (w[i & 0x0f] = rol32(w[i & 0x0f] ^ w[(i - 14) & 0x0f] \ ^ w[(i - 8) & 0x0f] ^ w[(i - 3) & 0x0f], 1)) -static void sha1_do_chunk_generic(struct sha1_ctx *ctx, uint32_t *buf)+/* The words are read out of the block rather than the block being pointed at+ * as though it were an array of them; see crypton_md5.c. */+static void sha1_do_chunk_generic(struct sha1_ctx *ctx, const uint8_t *buf) { uint32_t a, b, c, d, e; uint32_t w[16];-#define CPY(i) w[i] = be32_to_cpu(buf[i])+#define CPY(i) w[i] = load_be32(buf + 4 * (i)) CPY(0); CPY(1); CPY(2); CPY(3); CPY(4); CPY(5); CPY(6); CPY(7); CPY(8); CPY(9); CPY(10); CPY(11); CPY(12); CPY(13); CPY(14); CPY(15); #undef CPY@@ -197,14 +211,14 @@ * They arrived long after the x86-64 baseline, so ask before using them. * Two threads racing to answer here both write the same value. */-extern void crypton_sha1_x86_do_chunk(uint32_t state[5], const uint32_t buf[16]);+extern void crypton_sha1_x86_do_chunk(uint32_t state[5], const uint8_t buf[64]); extern void crypton_sha1_x86_do_chunks(uint32_t state[5], const uint8_t *data, uint32_t blocks); static int sha1_use_x86 = -1; #endif -static inline void sha1_do_chunk(struct sha1_ctx *ctx, uint32_t *buf)+static inline void sha1_do_chunk(struct sha1_ctx *ctx, const uint8_t *buf) { #ifdef WITH_ARMV8_SHA1 if (sha1_use_armv8 < 0) {@@ -247,7 +261,7 @@ /* process partial buffer if there's enough data to make a block */ if (index && len >= to_fill) { memcpy(ctx->buf + index, data, to_fill);- sha1_do_chunk(ctx, (uint32_t *) ctx->buf);+ sha1_do_chunk(ctx, ctx->buf); len -= to_fill; data += to_fill; index = 0;@@ -292,18 +306,9 @@ } #endif - if (need_alignment(data, 4)) {- uint32_t tramp[16];- ASSERT_ALIGNMENT(tramp, 4);- for (; len >= 64; len -= 64, data += 64) {- memcpy(tramp, data, 64);- sha1_do_chunk(ctx, tramp);- }- } else {- /* process as much 64-block as possible */- for (; len >= 64; len -= 64, data += 64)- sha1_do_chunk(ctx, (uint32_t *) data);- }+ /* No trampoline: load_be32 does not ask for a boundary. */+ for (; len >= 64; len -= 64, data += 64)+ sha1_do_chunk(ctx, data); /* append data into buf */ if (len)
cbits/crypton_sha256.c view
@@ -78,13 +78,16 @@ #define s0(x) (ror32(x, 7) ^ ror32(x,18) ^ (x >> 3)) #define s1(x) (ror32(x,17) ^ ror32(x,19) ^ (x >> 10)) -static void sha256_do_chunk_generic(struct sha256_ctx *ctx, uint32_t buf[])+/* The sixteen words are read out of the block rather than the block being+ * pointed at as though it were an array of them; see crypton_md5.c. */+static void sha256_do_chunk_generic(struct sha256_ctx *ctx, const uint8_t *buf) { uint32_t a, b, c, d, e, f, g, h, t1, t2; int i; uint32_t w[64]; - cpu_to_be32_array(w, buf, 16);+ for (i = 0; i < 16; i++)+ w[i] = load_be32(buf + 4 * i); for (i = 16; i < 64; i++) w[i] = s1(w[i - 2]) + w[i - 7] + s0(w[i - 15]) + w[i - 16]; @@ -120,10 +123,18 @@ * sha256_armv8.c. They are optional in ARMv8.0, so ask before using them. * Two threads racing to answer here both write the same value. */-extern void crypton_sha256_armv8_do_chunk(uint32_t state[8], const uint32_t buf[16]);+extern void crypton_sha256_armv8_do_chunk(uint32_t state[8], const uint8_t buf[64]); extern int crypton_sha256_armv8_available(void); +/* Resolved before there is a second thread; see the constructor in+ * cbits/crypton_aes.c for why. The test below then only ever reads. */ static int sha256_use_armv8 = -1;++__attribute__((constructor))+static void sha256_armv8_ctor(void)+{+ sha256_use_armv8 = crypton_sha256_armv8_available();+} #endif #if (defined(WITH_ARMV8_SHA256_ASM) && defined(WITH_ARMV8_SHA2)) \@@ -141,22 +152,34 @@ extern void crypton_sha256_asm_block_data_order(uint32_t state[8], const void *data, size_t blocks); +#ifdef WITH_ARMV8_SHA256_ASM+/* The assembly picks its path from crypton_armcap_P, so the answer to the+ * runtime check has to reach that word rather than the flag above. It is+ * set here, before there is a second thread, for the reason the constructor+ * in cbits/crypton_aes.c gives.+ *+ * This ran from sha256_asm_ready below until 2.1.3, guarded by the flag+ * still being unresolved -- which stopped happening when the constructor+ * above was added, so the bit was never set and the assembly took its+ * generic path. SHA-256 was 5.7 times slower on an Apple M4 for it. */+__attribute__((constructor))+static void sha256_armcap_ctor(void)+{+ if (crypton_sha256_armv8_available())+ crypton_armcap_P |= CRYPTON_ARMCAP_SHA256;+}+#endif+ static void sha256_asm_ready(void) {-#ifdef WITH_ARMV8_SHA256_ASM- if (sha256_use_armv8 < 0) {- if (crypton_sha256_armv8_available())- crypton_armcap_P |= CRYPTON_ARMCAP_SHA256;- sha256_use_armv8 = 1;- }-#else+#ifndef WITH_ARMV8_SHA256_ASM crypton_x86_ia32cap_resolve(); #endif } #endif -static void sha256_do_chunk(struct sha256_ctx *ctx, uint32_t buf[])+static void sha256_do_chunk(struct sha256_ctx *ctx, const uint8_t *buf) { #ifdef SHA256_ASM sha256_asm_ready();@@ -192,7 +215,7 @@ /* process partial buffer if there's enough data to make a block */ if (index && len >= to_fill) { memcpy(ctx->buf + index, data, to_fill);- sha256_do_chunk(ctx, (uint32_t *) ctx->buf);+ sha256_do_chunk(ctx, ctx->buf); len -= to_fill; data += to_fill; index = 0;@@ -211,18 +234,9 @@ len -= (uint32_t) blocks * 64; } #else- if (need_alignment(data, 4)) {- uint32_t tramp[16];- ASSERT_ALIGNMENT(tramp, 4);- for (; len >= 64; len -= 64, data += 64) {- memcpy(tramp, data, 64);- sha256_do_chunk(ctx, tramp);- }- } else {- /* process as much 64-block as possible */- for (; len >= 64; len -= 64, data += 64)- sha256_do_chunk(ctx, (uint32_t *) data);- }+ /* No trampoline: load_be32 does not ask for a boundary. */+ for (; len >= 64; len -= 64, data += 64)+ sha256_do_chunk(ctx, data); #endif /* append data into buf */
cbits/crypton_sha256.h view
@@ -51,6 +51,18 @@ void crypton_sha256_init(struct sha256_ctx *ctx); void crypton_sha256_update(struct sha256_ctx *ctx, const uint8_t *data, uint32_t len);+/* The pointers are all required to be non-null, which is said here so that+ * the compiler knows it too. Both of these write their digest through a+ * loop -- store_be32(out + 4 * i, ...) -- where sha1 and md5 write theirs at+ * constant offsets, and that is the difference that makes gcc's+ * -Wstringop-overflow reason about out being null: with+ * -fsanitize=undefined, UndefinedBehaviorSanitizer inserts a null check+ * before memcpy, because glibc declares memcpy nonnull, and the check puts a+ * null path in front of the warning pass, which then reports writing into+ * "a region of size 0" at "address zero". Saying the pointer is never null+ * removes the path rather than the warning. It costs nothing: compiled as+ * the package compiles it, the assembly is identical with and without. */+__attribute__((nonnull)) void crypton_sha256_finalize(struct sha256_ctx *ctx, uint8_t *out); void crypton_sha256_finalize_prefix(struct sha256_ctx *ctx, const uint8_t *data, uint32_t len, uint32_t n, uint8_t *out);
cbits/crypton_sha3.c view
@@ -102,14 +102,16 @@ #define sha3_asm_absorb crypton_keccak_asm_absorb #endif -static inline void sha3_do_chunk(uint64_t state[25], uint64_t buf[], int bufsz)+/* The words are read out of the block rather than the block being pointed at+ * as though it were an array of them; see crypton_md5.c. */+static inline void sha3_do_chunk(uint64_t state[25], const uint8_t *buf, int bufsz) { int i, j, r; uint64_t tmp, bc[5]; /* merge buf with state */ for (i = 0; i < bufsz; i++)- state[i] ^= le64_to_cpu(buf[i]);+ state[i] ^= load_le64(buf + 8 * i); #ifdef WITH_ARMV8_SHA3 if (sha3_armv8_ok()) {@@ -180,14 +182,14 @@ to_fill = ctx->bufsz - ctx->bufindex; if (ctx->bufindex == ctx->bufsz) {- sha3_do_chunk(ctx->state, (uint64_t *) ctx->buf, ctx->bufsz / 8);+ sha3_do_chunk(ctx->state, ctx->buf, ctx->bufsz / 8); ctx->bufindex = 0; } /* process partial buffer if there's enough data to make a block */ if (ctx->bufindex && len >= to_fill) { memcpy(ctx->buf + ctx->bufindex, data, to_fill);- sha3_do_chunk(ctx->state, (uint64_t *) ctx->buf, ctx->bufsz / 8);+ sha3_do_chunk(ctx->state, ctx->buf, ctx->bufsz / 8); len -= to_fill; data += to_fill; ctx->bufindex = 0;@@ -207,18 +209,9 @@ } #endif - if (need_alignment(data, 8)) {- uint64_t tramp[SHA3_BUF_SIZE_MAX/8];- ASSERT_ALIGNMENT(tramp, 8);- for (; len >= ctx->bufsz; len -= ctx->bufsz, data += ctx->bufsz) {- memcpy(tramp, data, ctx->bufsz);- sha3_do_chunk(ctx->state, tramp, ctx->bufsz / 8);- }- } else {- /* process as much ctx->bufsz-block */- for (; len >= ctx->bufsz; len -= ctx->bufsz, data += ctx->bufsz)- sha3_do_chunk(ctx->state, (uint64_t *) data, ctx->bufsz / 8);- }+ /* No trampoline: load_le64 does not ask for a boundary. */+ for (; len >= ctx->bufsz; len -= ctx->bufsz, data += ctx->bufsz)+ sha3_do_chunk(ctx->state, data, ctx->bufsz / 8); /* append data into buf */@@ -232,7 +225,7 @@ { /* process full buffer if needed */ if (ctx->bufindex == ctx->bufsz) {- sha3_do_chunk(ctx->state, (uint64_t *) ctx->buf, ctx->bufsz / 8);+ sha3_do_chunk(ctx->state, ctx->buf, ctx->bufsz / 8); ctx->bufindex = 0; } @@ -242,7 +235,7 @@ ctx->buf[ctx->bufsz - 1] |= 0x80; /* process */- sha3_do_chunk(ctx->state, (uint64_t *) ctx->buf, ctx->bufsz / 8);+ sha3_do_chunk(ctx->state, ctx->buf, ctx->bufsz / 8); ctx->bufindex = 0; }
cbits/crypton_sha512.c view
@@ -91,13 +91,16 @@ #define s0(x) (ror64(x, 1) ^ ror64(x, 8) ^ (x >> 7)) #define s1(x) (ror64(x, 19) ^ ror64(x, 61) ^ (x >> 6)) -static void sha512_do_chunk_generic(struct sha512_ctx *ctx, uint64_t *buf)+/* The words are read out of the block rather than the block being pointed at+ * as though it were an array of them; see crypton_md5.c. */+static void sha512_do_chunk_generic(struct sha512_ctx *ctx, const uint8_t *buf) { uint64_t a, b, c, d, e, f, g, h, t1, t2; int i; uint64_t w[80]; - cpu_to_be64_array(w, buf, 16);+ for (i = 0; i < 16; i++)+ w[i] = load_be64(buf + 8 * i); for (i = 16; i < 80; i++) w[i] = s1(w[i - 2]) + w[i - 7] + s0(w[i - 15]) + w[i - 16];@@ -135,10 +138,18 @@ * widespread than the SHA-256 ones, so ask before using them. Two threads * racing to answer here both write the same value. */-extern void crypton_sha512_armv8_do_chunk(uint64_t state[8], const uint64_t buf[16]);+extern void crypton_sha512_armv8_do_chunk(uint64_t state[8], const uint8_t buf[128]); extern int crypton_sha512_armv8_available(void); +/* Resolved before there is a second thread; see the constructor in+ * cbits/crypton_aes.c for why. The test below then only ever reads. */ static int sha512_use_armv8 = -1;++__attribute__((constructor))+static void sha512_armv8_ctor(void)+{+ sha512_use_armv8 = crypton_sha512_armv8_available();+} #endif @@ -154,7 +165,7 @@ const void *data, size_t blocks); #endif -static void sha512_do_chunk(struct sha512_ctx *ctx, uint64_t *buf)+static void sha512_do_chunk(struct sha512_ctx *ctx, const uint8_t *buf) { #ifdef SHA512_ASM crypton_x86_ia32cap_resolve();@@ -192,7 +203,7 @@ /* process partial buffer if there's enough data to make a block */ if (index && len >= to_fill) { memcpy(ctx->buf + index, data, to_fill);- sha512_do_chunk(ctx, (uint64_t *) ctx->buf);+ sha512_do_chunk(ctx, ctx->buf); len -= to_fill; data += to_fill; index = 0;@@ -210,18 +221,9 @@ len -= (uint32_t) blocks * 128; } #else- if (need_alignment(data, 8)) {- uint64_t tramp[16];- ASSERT_ALIGNMENT(tramp, 8);- for (; len >= 128; len -= 128, data += 128) {- memcpy(tramp, data, 128);- sha512_do_chunk(ctx, tramp);- }- } else {- /* process as much 128-block as possible */- for (; len >= 128; len -= 128, data += 128)- sha512_do_chunk(ctx, (uint64_t *) data);- }+ /* No trampoline: load_be64 does not ask for a boundary. */+ for (; len >= 128; len -= 128, data += 128)+ sha512_do_chunk(ctx, data); #endif /* append data into buf */@@ -344,7 +346,7 @@ /* re-init the context, otherwise len is changed */ memset(ctx, 0, sizeof(*ctx)); for (i = 0; i < 8; i++)- ctx->h[i] = cpu_to_be64(((uint64_t *) out)[i]);+ ctx->h[i] = load_be64(out + 8 * i); } } }
cbits/crypton_sha512.h view
@@ -50,6 +50,18 @@ void crypton_sha512_init(struct sha512_ctx *ctx); void crypton_sha512_update(struct sha512_ctx *ctx, const uint8_t *data, uint32_t len);+/* The pointers are all required to be non-null, which is said here so that+ * the compiler knows it too. Both of these write their digest through a+ * loop -- store_be32(out + 4 * i, ...) -- where sha1 and md5 write theirs at+ * constant offsets, and that is the difference that makes gcc's+ * -Wstringop-overflow reason about out being null: with+ * -fsanitize=undefined, UndefinedBehaviorSanitizer inserts a null check+ * before memcpy, because glibc declares memcpy nonnull, and the check puts a+ * null path in front of the warning pass, which then reports writing into+ * "a region of size 0" at "address zero". Saying the pointer is never null+ * removes the path rather than the warning. It costs nothing: compiled as+ * the package compiles it, the assembly is identical with and without. */+__attribute__((nonnull)) void crypton_sha512_finalize(struct sha512_ctx *ctx, uint8_t *out); void crypton_sha512_finalize_prefix(struct sha512_ctx *ctx, const uint8_t *data, uint32_t len, uint32_t n, uint8_t *out);
cbits/crypton_skein256.c view
@@ -37,7 +37,9 @@ static const uint8_t K256_6[2] = { 58, 22, }; static const uint8_t K256_7[2] = { 32, 32, }; -static inline void skein256_do_chunk(struct skein256_ctx *ctx, uint64_t *buf, uint32_t len)+/* The four words are read out of the block rather than the block being+ * pointed at as though it were an array of them; see crypton_md5.c. */+static inline void skein256_do_chunk(struct skein256_ctx *ctx, const uint8_t *bufp, uint32_t len) { uint64_t x[4]; uint64_t ts[3];@@ -78,11 +80,18 @@ ROUND(0,3,2,1,K256_7); \ INJECTKEY((i*2) + 2) - x[0] = le64_to_cpu(buf[0]) + ks[0];- x[1] = le64_to_cpu(buf[1]) + ks[1] + ts[0];- x[2] = le64_to_cpu(buf[2]) + ks[2] + ts[1];- x[3] = le64_to_cpu(buf[3]) + ks[3];+ uint64_t buf[4]; + buf[0] = load_le64(bufp);+ buf[1] = load_le64(bufp + 8);+ buf[2] = load_le64(bufp + 16);+ buf[3] = load_le64(bufp + 24);++ x[0] = buf[0] + ks[0];+ x[1] = buf[1] + ks[1] + ts[0];+ x[2] = buf[2] + ks[2] + ts[1];+ x[3] = buf[3] + ks[3];+ /* 9 pass of 8 rounds = 72 rounds */ PASS(0); PASS(1);@@ -98,10 +107,10 @@ ctx->t0 = ts[0]; ctx->t1 = ts[1]; - ctx->h[0] = x[0] ^ cpu_to_le64(buf[0]);- ctx->h[1] = x[1] ^ cpu_to_le64(buf[1]);- ctx->h[2] = x[2] ^ cpu_to_le64(buf[2]);- ctx->h[3] = x[3] ^ cpu_to_le64(buf[3]);+ ctx->h[0] = x[0] ^ buf[0];+ ctx->h[1] = x[1] ^ buf[1];+ ctx->h[2] = x[2] ^ buf[2];+ ctx->h[3] = x[3] ^ buf[3]; } void crypton_skein256_init(struct skein256_ctx *ctx, uint32_t hashlen)@@ -115,7 +124,7 @@ buf[0] = cpu_to_le64((SKEIN_VERSION << 32) | SKEIN_IDSTRING); buf[1] = cpu_to_le64(hashlen); buf[2] = 0; /* tree info, not implemented */- skein256_do_chunk(ctx, buf, 4*8);+ skein256_do_chunk(ctx, (const uint8_t *) buf, 4*8); SET_TYPE(ctx, FLAG_FIRST | FLAG_TYPE(TYPE_MSG)); }@@ -130,7 +139,7 @@ to_fill = 32 - ctx->bufindex; if (ctx->bufindex == 32) {- skein256_do_chunk(ctx, (uint64_t *) ctx->buf, 32);+ skein256_do_chunk(ctx, ctx->buf, 32); ctx->bufindex = 0; } @@ -138,24 +147,17 @@ * and there's without doubt further blocks */ if (ctx->bufindex && len > to_fill) { memcpy(ctx->buf + ctx->bufindex, data, to_fill);- skein256_do_chunk(ctx, (uint64_t *) ctx->buf, 32);+ skein256_do_chunk(ctx, ctx->buf, 32); len -= to_fill; data += to_fill; ctx->bufindex = 0; } - if (need_alignment(data, 8)) {- uint64_t tramp[4];- ASSERT_ALIGNMENT(tramp, 8);- for (; len > 32; len -= 32, data += 32) {- memcpy(tramp, data, 32);- skein256_do_chunk(ctx, tramp, 32);- }- } else {- /* process as much 32-block as possible except the last one in case we finalize */- for (; len > 32; len -= 32, data += 32)- skein256_do_chunk(ctx, (uint64_t *) data, 32);- }+ /* No trampoline for a block that is not on an eight-byte boundary: the+ * words are read with load_le64 now, which does not ask. The last+ * block is left for the finalisation. */+ for (; len > 32; len -= 32, data += 32)+ skein256_do_chunk(ctx, data, 32); /* append data into buf */ if (len) {@@ -174,7 +176,7 @@ /* if buf is not complete pad with 0 bytes */ if (ctx->bufindex < 32) memset(ctx->buf + ctx->bufindex, '\0', 32 - ctx->bufindex);- skein256_do_chunk(ctx, (uint64_t *) ctx->buf, ctx->bufindex);+ skein256_do_chunk(ctx, ctx->buf, ctx->bufindex); memset(ctx->buf, '\0', 32); @@ -187,9 +189,9 @@ /* threefish in counter mode, 0 for 1st 64 bytes, 1 for 2nd 64 bytes, .. */ for (i = 0; i*32 < outsize; i++) { uint64_t w[4];- *((uint64_t *) ctx->buf) = cpu_to_le64(i);+ store_le64(ctx->buf, i); SET_TYPE(ctx, FLAG_FIRST | FLAG_FINAL | FLAG_TYPE(TYPE_OUT));- skein256_do_chunk(ctx, (uint64_t *) ctx->buf, sizeof(uint64_t));+ skein256_do_chunk(ctx, ctx->buf, sizeof(uint64_t)); n = outsize - i * 32; if (n >= 32) n = 32;
cbits/crypton_skein256.h view
@@ -37,8 +37,8 @@ #define SKEIN256_CTX_SIZE sizeof(struct skein256_ctx) -void cryponite_skein256_init(struct skein256_ctx *ctx, uint32_t hashlen);-void cryponite_skein256_update(struct skein256_ctx *ctx, const uint8_t *data, uint32_t len);-void cryponite_skein256_finalize(struct skein256_ctx *ctx, uint32_t hashlen, uint8_t *out);+void crypton_skein256_init(struct skein256_ctx *ctx, uint32_t hashlen);+void crypton_skein256_update(struct skein256_ctx *ctx, const uint8_t *data, uint32_t len);+void crypton_skein256_finalize(struct skein256_ctx *ctx, uint32_t hashlen, uint8_t *out); #endif
cbits/crypton_skein512.c view
@@ -37,7 +37,9 @@ static const uint8_t K512_6[4] = { 25, 29, 39, 43, }; static const uint8_t K512_7[4] = { 8, 35, 56, 22, }; -static inline void skein512_do_chunk(struct skein512_ctx *ctx, uint64_t *buf, uint32_t len)+/* The words are read out of the block rather than the block being pointed at+ * as though it were an array of them; see crypton_md5.c. */+static inline void skein512_do_chunk(struct skein512_ctx *ctx, const uint8_t *bufp, uint32_t len) { uint64_t x[8]; uint64_t ts[3];@@ -88,15 +90,21 @@ ROUND(6,1,0,7,2,5,4,3,K512_7); \ INJECTKEY((i*2) + 2) - x[0] = le64_to_cpu(buf[0]) + ks[0];- x[1] = le64_to_cpu(buf[1]) + ks[1];- x[2] = le64_to_cpu(buf[2]) + ks[2];- x[3] = le64_to_cpu(buf[3]) + ks[3];- x[4] = le64_to_cpu(buf[4]) + ks[4];- x[5] = le64_to_cpu(buf[5]) + ks[5] + ts[0];- x[6] = le64_to_cpu(buf[6]) + ks[6] + ts[1];- x[7] = le64_to_cpu(buf[7]) + ks[7];+ uint64_t buf[8];+ int bi; + for (bi = 0; bi < 8; bi++)+ buf[bi] = load_le64(bufp + 8 * bi);++ x[0] = buf[0] + ks[0];+ x[1] = buf[1] + ks[1];+ x[2] = buf[2] + ks[2];+ x[3] = buf[3] + ks[3];+ x[4] = buf[4] + ks[4];+ x[5] = buf[5] + ks[5] + ts[0];+ x[6] = buf[6] + ks[6] + ts[1];+ x[7] = buf[7] + ks[7];+ /* 9 pass of 8 rounds = 72 rounds */ PASS(0); PASS(1);@@ -112,14 +120,14 @@ ctx->t0 = ts[0]; ctx->t1 = ts[1]; - ctx->h[0] = x[0] ^ cpu_to_le64(buf[0]);- ctx->h[1] = x[1] ^ cpu_to_le64(buf[1]);- ctx->h[2] = x[2] ^ cpu_to_le64(buf[2]);- ctx->h[3] = x[3] ^ cpu_to_le64(buf[3]);- ctx->h[4] = x[4] ^ cpu_to_le64(buf[4]);- ctx->h[5] = x[5] ^ cpu_to_le64(buf[5]);- ctx->h[6] = x[6] ^ cpu_to_le64(buf[6]);- ctx->h[7] = x[7] ^ cpu_to_le64(buf[7]);+ ctx->h[0] = x[0] ^ buf[0];+ ctx->h[1] = x[1] ^ buf[1];+ ctx->h[2] = x[2] ^ buf[2];+ ctx->h[3] = x[3] ^ buf[3];+ ctx->h[4] = x[4] ^ buf[4];+ ctx->h[5] = x[5] ^ buf[5];+ ctx->h[6] = x[6] ^ buf[6];+ ctx->h[7] = x[7] ^ buf[7]; } void crypton_skein512_init(struct skein512_ctx *ctx, uint32_t hashlen)@@ -133,7 +141,7 @@ buf[0] = cpu_to_le64((SKEIN_VERSION << 32) | SKEIN_IDSTRING); buf[1] = cpu_to_le64(hashlen); buf[2] = 0; /* tree info, not implemented */- skein512_do_chunk(ctx, buf, 4*8);+ skein512_do_chunk(ctx, (const uint8_t *) buf, 4*8); SET_TYPE(ctx, FLAG_FIRST | FLAG_TYPE(TYPE_MSG)); }@@ -148,7 +156,7 @@ to_fill = 64 - ctx->bufindex; if (ctx->bufindex == 64) {- skein512_do_chunk(ctx, (uint64_t *) ctx->buf, 64);+ skein512_do_chunk(ctx, ctx->buf, 64); ctx->bufindex = 0; } @@ -156,24 +164,15 @@ * and there's without doubt further blocks */ if (ctx->bufindex && len > to_fill) { memcpy(ctx->buf + ctx->bufindex, data, to_fill);- skein512_do_chunk(ctx, (uint64_t *) ctx->buf, 64);+ skein512_do_chunk(ctx, ctx->buf, 64); len -= to_fill; data += to_fill; ctx->bufindex = 0; } - if (need_alignment(data, 8)) {- uint64_t tramp[8];- ASSERT_ALIGNMENT(tramp, 8);- for (; len > 64; len -= 64, data += 64) {- memcpy(tramp, data, 64);- skein512_do_chunk(ctx, tramp, 64);- }- } else {- /* process as much 64-block as possible except the last one in case we finalize */- for (; len > 64; len -= 64, data += 64)- skein512_do_chunk(ctx, (uint64_t *) data, 64);- }+ /* No trampoline: load_le64 does not ask for a boundary. */+ for (; len > 64; len -= 64, data += 64)+ skein512_do_chunk(ctx, data, 64); /* append data into buf */ if (len) {@@ -192,7 +191,7 @@ /* if buf is not complete pad with 0 bytes */ if (ctx->bufindex < 64) memset(ctx->buf + ctx->bufindex, '\0', 64 - ctx->bufindex);- skein512_do_chunk(ctx, (uint64_t *) ctx->buf, ctx->bufindex);+ skein512_do_chunk(ctx, ctx->buf, ctx->bufindex); memset(ctx->buf, '\0', 64); @@ -205,9 +204,9 @@ /* threefish in counter mode, 0 for 1st 64 bytes, 1 for 2nd 64 bytes, .. */ for (i = 0; i*64 < outsize; i++) { uint64_t w[8];- *((uint64_t *) ctx->buf) = cpu_to_le64(i);+ store_le64(ctx->buf, i); SET_TYPE(ctx, FLAG_FIRST | FLAG_FINAL | FLAG_TYPE(TYPE_OUT));- skein512_do_chunk(ctx, (uint64_t *) ctx->buf, sizeof(uint64_t));+ skein512_do_chunk(ctx, ctx->buf, sizeof(uint64_t)); n = outsize - i * 64; if (n >= 64) n = 64;
cbits/crypton_skein512.h view
@@ -37,8 +37,8 @@ #define SKEIN512_CTX_SIZE sizeof(struct skein512_ctx) -void cryponite_skein512_init(struct skein512_ctx *ctx, uint32_t hashlen);-void cryponite_skein512_update(struct skein512_ctx *ctx, const uint8_t *data, uint32_t len);-void cryponite_skein512_finalize(struct skein512_ctx *ctx, uint32_t hashlen, uint8_t *out);+void crypton_skein512_init(struct skein512_ctx *ctx, uint32_t hashlen);+void crypton_skein512_update(struct skein512_ctx *ctx, const uint8_t *data, uint32_t len);+void crypton_skein512_finalize(struct skein512_ctx *ctx, uint32_t hashlen, uint8_t *out); #endif
cbits/crypton_tiger.c view
@@ -306,7 +306,9 @@ ctx->h[2] = 0xf096a5b4c3b2e187ULL; } -static inline void tiger_do_chunk(struct tiger_ctx *ctx, uint64_t *buf)+/* The words are read out of the block rather than the block being pointed at+ * as though it were an array of them; see crypton_md5.c. */+static inline void tiger_do_chunk(struct tiger_ctx *ctx, const uint8_t *buf) { uint64_t x0, x1, x2, x3, x4, x5, x6, x7; uint64_t a,b,c;@@ -314,8 +316,8 @@ b = ctx->h[1]; c = ctx->h[2]; - x0 = cpu_to_le64(buf[0]); x1 = cpu_to_le64(buf[1]); x2 = cpu_to_le64(buf[2]); x3 = cpu_to_le64(buf[3]);- x4 = cpu_to_le64(buf[4]); x5 = cpu_to_le64(buf[5]); x6 = cpu_to_le64(buf[6]); x7 = cpu_to_le64(buf[7]);+ x0 = load_le64(buf ); x1 = load_le64(buf + 8); x2 = load_le64(buf + 16); x3 = load_le64(buf + 24);+ x4 = load_le64(buf + 32); x5 = load_le64(buf + 40); x6 = load_le64(buf + 48); x7 = load_le64(buf + 56); #define BYTEOF(c, n) ((uint8_t) (c >> ((n * 8)))) @@ -376,24 +378,15 @@ /* process partial buffer if there's enough data to make a block */ if (index && len >= to_fill) { memcpy(ctx->buf + index, data, to_fill);- tiger_do_chunk(ctx, (uint64_t *) ctx->buf);+ tiger_do_chunk(ctx, ctx->buf); len -= to_fill; data += to_fill; index = 0; } - if (need_alignment(data, 8)) {- uint64_t tramp[8];- ASSERT_ALIGNMENT(tramp, 8);- for (; len >= 64; len -= 64, data += 64) {- memcpy(tramp, data, 64);- tiger_do_chunk(ctx, tramp);- }- } else {- /* process as much 64-block as possible */- for (; len >= 64; len -= 64, data += 64)- tiger_do_chunk(ctx, (uint64_t *) data);- }+ /* No trampoline: load_le64 does not ask for a boundary. */+ for (; len >= 64; len -= 64, data += 64)+ tiger_do_chunk(ctx, data); /* append data into buf */ if (len)
cbits/crypton_xsalsa.c view
@@ -41,7 +41,7 @@ memset(ctx, 0, sizeof(*ctx)); ctx->nb_rounds = nb_rounds; - /* Create initial 512-bit input block:+ /* Create initial 512-bit input crypton_salsa_block: (x0, x5, x10, x15) is the Salsa20 constant (x1, x2, x3, x4, x11, x12, x13, x14) is a 256-bit key (x6, x7, x8, x9) is the first 128 bits of a 192-bit nonce@@ -56,7 +56,7 @@ void crypton_xsalsa_derive(crypton_salsa_context *ctx, uint32_t ivlen, const uint8_t *iv) {- /* Finish creating initial 512-bit input block:+ /* Finish creating initial 512-bit input crypton_salsa_block: (x6, x7, x8, x9) is the first 128 bits of a 192-bit nonce Except iv has been shifted by 64 bits so there are now only 128 bits ahead.@@ -65,15 +65,15 @@ ctx->st.d[ 9] += load_le32(iv + 4); /* Compute (z0, z1, . . . , z15) = doubleround ^(r/2) (x0, x1, . . . , x15) */- block hSalsa;- memset(&hSalsa, 0, sizeof(block));+ crypton_salsa_block hSalsa;+ memset(&hSalsa, 0, sizeof(crypton_salsa_block)); crypton_salsa_core_xor(ctx->nb_rounds, &hSalsa, &ctx->st); - /* Build a new 512-bit input block (x′0, x′1, . . . , x′15):+ /* Build a new 512-bit input crypton_salsa_block (x′0, x′1, . . . , x′15): (x′0, x′5, x′10, x′15) is the Salsa20 constant (x′1,x′2,x′3,x′4,x′11,x′12,x′13,x′14) = (z0,z5,z10,z15,z6,z7,z8,z9) (x′6,x′7) is the last 64 bits of the 192-bit nonce- (x′8, x′9) is a 64-bit block counter.+ (x′8, x′9) is a 64-bit crypton_salsa_block counter. */ ctx->st.d[ 1] = hSalsa.d[ 0] - ctx->st.d[ 0]; ctx->st.d[ 2] = hSalsa.d[ 5] - ctx->st.d[ 5];
+ cbits/curve25519/x25519.c view
@@ -0,0 +1,88 @@+/*+ * X25519 through the vendored s2n-bignum where it is built, and through+ * curve25519-donna where it is not.+ *+ * The fixed-base routine is the interesting half: crypton had none, and asked+ * for the public key by multiplying the base point 9 the general way. With a+ * table it is four to five times less work, and a TLS handshake generates a+ * key every time. Measured on an Apple M4:+ *+ * donna s2n+ * shared secret 18.15 us 12.35+ * key generation 18.15 3.65+ *+ * and on an x86-64, 41.19 to 26.96 and 41.18 to 8.54.+ */+#include <string.h>++#include "curve25519/x25519.h"++void crypton_curve25519_donna(uint8_t *mypublic, const uint8_t *secret,+ const uint8_t *basepoint);++/* The assembly takes four little-endian 64-bit words, which is the same bits+ * as the 32 little-endian bytes RFC 7748 sends, so the two cross by copying+ * -- on a little-endian machine, which is the only kind s2n-bignum is for. */+#if defined(CRYPTON_S2N_BIGNUM) && defined(__BYTE_ORDER__) \+ && __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__+#define CRYPTON_X25519_S2N 1+#include "crypton_cpu.h"++extern void curve25519_x25519(uint64_t res[4], const uint64_t scalar[4],+ const uint64_t point[4]);+extern void curve25519_x25519_alt(uint64_t res[4], const uint64_t scalar[4],+ const uint64_t point[4]);+extern void curve25519_x25519base(uint64_t res[4], const uint64_t scalar[4]);+extern void curve25519_x25519base_alt(uint64_t res[4], const uint64_t scalar[4]);++/* The same question as everywhere else in cbits/s2n: a microarchitecture one+ * on ARM that no feature bit answers, and exactly a feature bit on x86-64. */+static int use_alt(void)+{+#if defined(__aarch64__) || defined(__arm64__)+#ifdef __APPLE__+ return 1;+#else+ return 0;+#endif+#else+ return (crypton_x86_simd_features() & CRYPTON_X86_ADX) == 0;+#endif+}+#endif++void crypton_x25519(uint8_t out[32], const uint8_t secret[32],+ const uint8_t point[32])+{+#ifdef CRYPTON_X25519_S2N+ uint64_t r[4], s[4], p[4];++ memcpy(s, secret, 32);+ memcpy(p, point, 32);+ if (use_alt())+ curve25519_x25519_alt(r, s, p);+ else+ curve25519_x25519(r, s, p);+ memcpy(out, r, 32);+#else+ crypton_curve25519_donna(out, secret, point);+#endif+}++void crypton_x25519_base(uint8_t out[32], const uint8_t secret[32])+{+#ifdef CRYPTON_X25519_S2N+ uint64_t r[4], s[4];++ memcpy(s, secret, 32);+ if (use_alt())+ curve25519_x25519base_alt(r, s);+ else+ curve25519_x25519base(r, s);+ memcpy(out, r, 32);+#else+ static const uint8_t nine[32] = {9};++ crypton_curve25519_donna(out, secret, nine);+#endif+}
+ cbits/curve25519/x25519.h view
@@ -0,0 +1,16 @@+#ifndef CRYPTON_X25519_H+#define CRYPTON_X25519_H++#include <stdint.h>++/* out = secret * point, the X25519 of RFC 7748: three 32-byte little-endian+ * strings as they go over the wire. */+void crypton_x25519(uint8_t out[32], const uint8_t secret[32],+ const uint8_t point[32]);++/* out = secret * G, which is the same thing with the base point 9 -- but+ * where the assembly is built this reads a table instead and is four to five+ * times faster, which is what a key generation costs. */+void crypton_x25519_base(uint8_t out[32], const uint8_t secret[32]);++#endif
cbits/decaf/ed448goldilocks/decaf.c view
@@ -1462,7 +1462,10 @@ uint32_t pos = __builtin_ctz((uint32_t)current), odd = (uint32_t)current >> pos; int32_t delta = odd & mask; if (odd & 1<<(table_bits+1)) delta -= (1<<(table_bits+1));- current -= delta << pos;+ /* delta is negative half the time and shifting a negative+ * value left is undefined; current is unsigned, so the shift is+ * done there and means the same thing. */+ current -= (uint64_t)delta << pos; control[position].power = pos + 16*(w-1); control[position].addend = delta; position--;
cbits/decaf/include/word.h view
@@ -68,7 +68,7 @@ * Expand bit 0 of the given uint8_t to a mask_t all 1 or all 0 * The input must be either 0 or 1 */-CRYPTON_DECAF_INLINE mask_t bit_to_mask(uint8_t bit) {+static CRYPTON_DECAF_INLINE mask_t bit_to_mask(uint8_t bit) { #ifdef _MSC_VER #pragma warning ( push) #pragma warning ( disable : 4146)
cbits/ed25519/ed25519.c view
@@ -12,8 +12,33 @@ #include "ed25519-randombytes.h" #include "ed25519-hash.h" #include "ed25519-crypton-exts.h"+#include "ed25519/ed25519_s2n.h" /*+ The base point multiplied by a scalar, packed. s2n-bignum's assembly+ where it is built -- twice the speed of the table below, and signing+ does this twice -- and ed25519-donna's own table where it is not.+*/+static void+ed25519_base_pack(ed25519_public_key out, const bignum256modm s) {+ ge25519 ALIGN(16) p;++#if defined(CRYPTON_S2N_BIGNUM) && defined(__BYTE_ORDER__) \+ && __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__+ unsigned char e[32];++ contract256_modm(e, s);+ if (crypton_ed25519_base_mult(out, e)) {+ memset(e, 0, sizeof e);+ return;+ }+ memset(e, 0, sizeof e);+#endif+ ge25519_scalarmult_base_niels(&p, ge25519_niels_base_multiples, s);+ ge25519_pack(out, &p);+}++/* Generates a (extsk[0..31]) and aExt (extsk[32..63]) */ @@ -38,14 +63,12 @@ void ED25519_FN(ed25519_publickey) (const ed25519_secret_key sk, ed25519_public_key pk) { bignum256modm a;- ge25519 ALIGN(16) A; hash_512bits extsk; /* A = aB */ ed25519_extsk(extsk, sk); expand256_modm(a, extsk, 32);- ge25519_scalarmult_base_niels(&A, ge25519_niels_base_multiples, a);- ge25519_pack(pk, &A);+ ed25519_base_pack(pk, a); } @@ -53,7 +76,6 @@ ED25519_FN(ed25519_sign) (const unsigned char *m, size_t mlen, const ed25519_secret_key sk, const ed25519_public_key pk, ed25519_signature RS) { ed25519_hash_context ctx; bignum256modm r, S, a;- ge25519 ALIGN(16) R; hash_512bits extsk, hashr, hram; ed25519_extsk(extsk, sk);@@ -66,8 +88,7 @@ expand256_modm(r, hashr, 64); /* R = rB */- ge25519_scalarmult_base_niels(&R, ge25519_niels_base_multiples, r);- ge25519_pack(RS, &R);+ ed25519_base_pack(RS, r); /* S = H(R,A,m).. */ ed25519_hram(hram, RS, pk, m, mlen);
+ cbits/ed25519/ed25519_s2n.c view
@@ -0,0 +1,65 @@+/*+ * Ed25519's base point multiplication through the vendored s2n-bignum.+ *+ * Signing does this twice: once for the nonce's point R, and once for the+ * public key, which crypton derives from the secret key at every signature+ * rather than trusting the one it is handed. Both go through here, so both+ * halves of a signature move at once.+ *+ * Measured on an Apple M4, one multiplication with the encoding:+ * ed25519-donna 7.5 us against s2n-bignum 3.5.+ */+#include <string.h>++#include "ed25519/ed25519_s2n.h"++#if defined(CRYPTON_S2N_BIGNUM) && defined(__BYTE_ORDER__) \+ && __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__+#define CRYPTON_ED25519_S2N 1+#include "crypton_cpu.h"++extern void edwards25519_scalarmulbase(uint64_t res[8],+ const uint64_t scalar[4]);+extern void edwards25519_scalarmulbase_alt(uint64_t res[8],+ const uint64_t scalar[4]);+extern void edwards25519_encode(uint8_t z[32], const uint64_t p[8]);++/* The same question as everywhere else in cbits/s2n: a microarchitecture one+ * on ARM that no feature bit answers, and exactly a feature bit on x86-64. */+static int use_alt(void)+{+#if defined(__aarch64__) || defined(__arm64__)+#ifdef __APPLE__+ return 1;+#else+ return 0;+#endif+#else+ return (crypton_x86_simd_features() & CRYPTON_X86_ADX) == 0;+#endif+}+#endif++int crypton_ed25519_base_mult(uint8_t out[32], const uint8_t scalar[32])+{+#ifdef CRYPTON_ED25519_S2N+ /* the assembly takes four little-endian 64-bit words, which is the+ * same bits as the 32 little-endian bytes the scalar is kept in */+ uint64_t s[4], p[8];++ memcpy(s, scalar, 32);+ if (use_alt())+ edwards25519_scalarmulbase_alt(p, s);+ else+ edwards25519_scalarmulbase(p, s);+ edwards25519_encode(out, p);++ memset(s, 0, sizeof s);+ memset(p, 0, sizeof p);+ return 1;+#else+ (void) out;+ (void) scalar;+ return 0;+#endif+}
+ cbits/ed25519/ed25519_s2n.h view
@@ -0,0 +1,14 @@+#ifndef CRYPTON_ED25519_S2N_H+#define CRYPTON_ED25519_S2N_H++#include <stdint.h>++/* The base point multiplied by a scalar, packed into Ed25519's 32-byte+ * encoding. The scalar is 32 little-endian bytes, already reduced.+ *+ * Returns 1 when the vendored s2n-bignum did the work and 0 when it is not+ * built, in which case the caller multiplies the base point itself.+ */+int crypton_ed25519_base_mult(uint8_t out[32], const uint8_t scalar[32]);++#endif
cbits/include32/p256/p256.h view
@@ -83,16 +83,9 @@ const crypton_p256_int* b, crypton_p256_int* c); -// b := 1 / a % MOD-// MOD best be SECP256r1_n-void crypton_p256_modinv(- const crypton_p256_int* MOD,- const crypton_p256_int* a,- crypton_p256_int* b);--// b := 1 / a % MOD+// b := 1 / a % MOD, in time that depends on a // MOD best be SECP256r1_n-// Faster than crypton_p256_modinv()+// Answers zero for an a that has no inverse, which is zero and MOD void crypton_p256_modinv_vartime( const crypton_p256_int* MOD, const crypton_p256_int* a,@@ -130,13 +123,6 @@ void crypton_p256_base_point_mul(const crypton_p256_int *n, crypton_p256_int *out_x, crypton_p256_int *out_y);--// {out_x,out_y} := n{in_x,in_y}-void crypton_p256_point_mul(const crypton_p256_int *n,- const crypton_p256_int *in_x,- const crypton_p256_int *in_y,- crypton_p256_int *out_x,- crypton_p256_int *out_y); // {out_x,out_y} := n1G + n2{in_x,in_y} void crypton_p256_points_mul_vartime(
cbits/include32/p256/p256_gf.h view
@@ -76,6 +76,13 @@ 0 }; static const felem kZero = {0};++/* the curve's b, in Montgomery form, for the complete addition formula */+static const felem kB = {+ 0x13897bbf, 0x9cdf622, 0x43090d8, 0x2e67c4,+ 0x176b5678, 0x2afdc84, 0xd196888, 0xb090e90,+ 0xb8600c3+}; static const felem kP = { 0x1fffffff, 0xfffffff, 0x1fffffff, 0x3ff, 0, 0, 0x200000, 0xf000000,@@ -86,96 +93,99 @@ 0, 0, 0x400000, 0xe000000, 0x1fffffff };-/* kPrecomputed contains precomputed values to aid the calculation of scalar- * multiples of the base point, G. It's actually two, equal length, tables- * concatenated.+/* kPrecomputed holds the multiples of the base point G that the comb in+ * scalar_base_mult reads. Two tables of sixteen affine points, one after the+ * other. *- * The first table contains (x,y) felem pairs for 16 multiples of the base- * point, G.+ * The comb takes five bits of the signed all-bits-set representation at a+ * time, from positions 52 apart, and the two tables are offset from each+ * other by 26: *- * Index | Index (binary) | Value- * 0 | 0000 | 0G (all zeros, omitted)- * 1 | 0001 | G- * 2 | 0010 | 2**64G- * 3 | 0011 | 2**64G + G- * 4 | 0100 | 2**128G- * 5 | 0101 | 2**128G + G- * 6 | 0110 | 2**128G + 2**64G- * 7 | 0111 | 2**128G + 2**64G + G- * 8 | 1000 | 2**192G- * 9 | 1001 | 2**192G + G- * 10 | 1010 | 2**192G + 2**64G- * 11 | 1011 | 2**192G + 2**64G + G- * 12 | 1100 | 2**192G + 2**128G- * 13 | 1101 | 2**192G + 2**128G + G- * 14 | 1110 | 2**192G + 2**128G + 2**64G- * 15 | 1111 | 2**192G + 2**128G + 2**64G + G+ * first table i, 52+i, 104+i, 156+i, 208+i+ * second table 26+i, 78+i, 130+i, 182+i, 234+i *- * The second table follows the same style, but the terms are 2**32G,- * 2**96G, 2**160G, 2**224G.+ * for i from 25 down to 0, which covers all 260 bits between them. *+ * Every digit of that representation is +-1, so a block of five teeth takes+ * one of thirty-two values -- and they come in pairs that differ only by+ * sign. So sixteen entries are enough: the top tooth is taken positive, bit+ * j of the index says that tooth j agrees with it, and where the top tooth is+ * negative the caller negates y, which costs a subtraction. Entry zero is a+ * point like any other here, unlike the unsigned table this replaces, where+ * it stood for the infinity.+ *+ * Index | Index (binary) | Value+ * 0 | 0000 | 2**208G - 2**156G - 2**104G - 2**52G - G+ * 1 | 0001 | 2**208G - 2**156G - 2**104G - 2**52G + G+ * ... | ... | ...+ * 15 | 1111 | 2**208G + 2**156G + 2**104G + 2**52G + G+ * * This is ~2KB of data. */-static const limb kPrecomputed[NLIMBS * 2 * 15 * 2] = {- 0x11522878, 0xe730d41, 0xdb60179, 0x4afe2ff, 0x12883add, 0xcaddd88, 0x119e7edc, 0xd4a6eab, 0x3120bee,- 0x1d2aac15, 0xf25357c, 0x19e45cdd, 0x5c721d0, 0x1992c5a5, 0xa237487, 0x154ba21, 0x14b10bb, 0xae3fe3,- 0xd41a576, 0x922fc51, 0x234994f, 0x60b60d3, 0x164586ae, 0xce95f18, 0x1fe49073, 0x3fa36cc, 0x5ebcd2c,- 0xb402f2f, 0x15c70bf, 0x1561925c, 0x5a26704, 0xda91e90, 0xcdc1c7f, 0x1ea12446, 0xe1ade1e, 0xec91f22,- 0x26f7778, 0x566847e, 0xa0bec9e, 0x234f453, 0x1a31f21a, 0xd85e75c, 0x56c7109, 0xa267a00, 0xb57c050,- 0x98fb57, 0xaa837cc, 0x60c0792, 0xcfa5e19, 0x61bab9e, 0x589e39b, 0xa324c5, 0x7d6dee7, 0x2976e4b,- 0x1fc4124a, 0xa8c244b, 0x1ce86762, 0xcd61c7e, 0x1831c8e0, 0x75774e1, 0x1d96a5a9, 0x843a649, 0xc3ab0fa,- 0x6e2e7d5, 0x7673a2a, 0x178b65e8, 0x4003e9b, 0x1a1f11c2, 0x7816ea, 0xf643e11, 0x58c43df, 0xf423fc2,- 0x19633ffa, 0x891f2b2, 0x123c231c, 0x46add8c, 0x54700dd, 0x59e2b17, 0x172db40f, 0x83e277d, 0xb0dd609,- 0xfd1da12, 0x35c6e52, 0x19ede20c, 0xd19e0c0, 0x97d0f40, 0xb015b19, 0x449e3f5, 0xe10c9e, 0x33ab581,- 0x56a67ab, 0x577734d, 0x1dddc062, 0xc57b10d, 0x149b39d, 0x26a9e7b, 0xc35df9f, 0x48764cd, 0x76dbcca,- 0xca4b366, 0xe9303ab, 0x1a7480e7, 0x57e9e81, 0x1e13eb50, 0xf466cf3, 0x6f16b20, 0x4ba3173, 0xc168c33,- 0x15cb5439, 0x6a38e11, 0x73658bd, 0xb29564f, 0x3f6dc5b, 0x53b97e, 0x1322c4c0, 0x65dd7ff, 0x3a1e4f6,- 0x14e614aa, 0x9246317, 0x1bc83aca, 0xad97eed, 0xd38ce4a, 0xf82b006, 0x341f077, 0xa6add89, 0x4894acd,- 0x9f162d5, 0xf8410ef, 0x1b266a56, 0xd7f223, 0x3e0cb92, 0xe39b672, 0x6a2901a, 0x69a8556, 0x7e7c0,- 0x9b7d8d3, 0x309a80, 0x1ad05f7f, 0xc2fb5dd, 0xcbfd41d, 0x9ceb638, 0x1051825c, 0xda0cf5b, 0x812e881,- 0x6f35669, 0x6a56f2c, 0x1df8d184, 0x345820, 0x1477d477, 0x1645db1, 0xbe80c51, 0xc22be3e, 0xe35e65a,- 0x1aeb7aa0, 0xc375315, 0xf67bc99, 0x7fdd7b9, 0x191fc1be, 0x61235d, 0x2c184e9, 0x1c5a839, 0x47a1e26,- 0xb7cb456, 0x93e225d, 0x14f3c6ed, 0xccc1ac9, 0x17fe37f3, 0x4988989, 0x1a90c502, 0x2f32042, 0xa17769b,- 0xafd8c7c, 0x8191c6e, 0x1dcdb237, 0x16200c0, 0x107b32a1, 0x66c08db, 0x10d06a02, 0x3fc93, 0x5620023,- 0x16722b27, 0x68b5c59, 0x270fcfc, 0xfad0ecc, 0xe5de1c2, 0xeab466b, 0x2fc513c, 0x407f75c, 0xbaab133,- 0x9705fe9, 0xb88b8e7, 0x734c993, 0x1e1ff8f, 0x19156970, 0xabd0f00, 0x10469ea7, 0x3293ac0, 0xcdc98aa,- 0x1d843fd, 0xe14bfe8, 0x15be825f, 0x8b5212, 0xeb3fb67, 0x81cbd29, 0xbc62f16, 0x2b6fcc7, 0xf5a4e29,- 0x13560b66, 0xc0b6ac2, 0x51ae690, 0xd41e271, 0xf3e9bd4, 0x1d70aab, 0x1029f72, 0x73e1c35, 0xee70fbc,- 0xad81baf, 0x9ecc49a, 0x86c741e, 0xfe6be30, 0x176752e7, 0x23d416, 0x1f83de85, 0x27de188, 0x66f70b8,- 0x181cd51f, 0x96b6e4c, 0x188f2335, 0xa5df759, 0x17a77eb6, 0xfeb0e73, 0x154ae914, 0x2f3ec51, 0x3826b59,- 0xb91f17d, 0x1c72949, 0x1362bf0a, 0xe23fddf, 0xa5614b0, 0xf7d8f, 0x79061, 0x823d9d2, 0x8213f39,- 0x1128ae0b, 0xd095d05, 0xb85c0c2, 0x1ecb2ef, 0x24ddc84, 0xe35e901, 0x18411a4a, 0xf5ddc3d, 0x3786689,- 0x52260e8, 0x5ae3564, 0x542b10d, 0x8d93a45, 0x19952aa4, 0x996cc41, 0x1051a729, 0x4be3499, 0x52b23aa,- 0x109f307e, 0x6f5b6bb, 0x1f84e1e7, 0x77a0cfa, 0x10c4df3f, 0x25a02ea, 0xb048035, 0xe31de66, 0xc6ecaa3,- 0x28ea335, 0x2886024, 0x1372f020, 0xf55d35, 0x15e4684c, 0xf2a9e17, 0x1a4a7529, 0xcb7beb1, 0xb2a78a1,- 0x1ab21f1f, 0x6361ccf, 0x6c9179d, 0xb135627, 0x1267b974, 0x4408bad, 0x1cbff658, 0xe3d6511, 0xc7d76f,- 0x1cc7a69, 0xe7ee31b, 0x54fab4f, 0x2b914f, 0x1ad27a30, 0xcd3579e, 0xc50124c, 0x50daa90, 0xb13f72,- 0xb06aa75, 0x70f5cc6, 0x1649e5aa, 0x84a5312, 0x329043c, 0x41c4011, 0x13d32411, 0xb04a838, 0xd760d2d,- 0x1713b532, 0xbaa0c03, 0x84022ab, 0x6bcf5c1, 0x2f45379, 0x18ae070, 0x18c9e11e, 0x20bca9a, 0x66f496b,- 0x3eef294, 0x67500d2, 0xd7f613c, 0x2dbbeb, 0xb741038, 0xe04133f, 0x1582968d, 0xbe985f7, 0x1acbc1a,- 0x1a6a939f, 0x33e50f6, 0xd665ed4, 0xb4b7bd6, 0x1e5a3799, 0x6b33847, 0x17fa56ff, 0x65ef930, 0x21dc4a,- 0x2b37659, 0x450fe17, 0xb357b65, 0xdf5efac, 0x15397bef, 0x9d35a7f, 0x112ac15f, 0x624e62e, 0xa90ae2f,- 0x107eecd2, 0x1f69bbe, 0x77d6bce, 0x5741394, 0x13c684fc, 0x950c910, 0x725522b, 0xdc78583, 0x40eeabb,- 0x1fde328a, 0xbd61d96, 0xd28c387, 0x9e77d89, 0x12550c40, 0x759cb7d, 0x367ef34, 0xae2a960, 0x91b8bdc,- 0x93462a9, 0xf469ef, 0xb2e9aef, 0xd2ca771, 0x54e1f42, 0x7aaa49, 0x6316abb, 0x2413c8e, 0x5425bf9,- 0x1bed3e3a, 0xf272274, 0x1f5e7326, 0x6416517, 0xea27072, 0x9cedea7, 0x6e7633, 0x7c91952, 0xd806dce,- 0x8e2a7e1, 0xe421e1a, 0x418c9e1, 0x1dbc890, 0x1b395c36, 0xa1dc175, 0x1dc4ef73, 0x8956f34, 0xe4b5cf2,- 0x1b0d3a18, 0x3194a36, 0x6c2641f, 0xe44124c, 0xa2f4eaa, 0xa8c25ba, 0xf927ed7, 0x627b614, 0x7371cca,- 0xba16694, 0x417bc03, 0x7c0a7e3, 0x9c35c19, 0x1168a205, 0x8b6b00d, 0x10e3edc9, 0x9c19bf2, 0x5882229,- 0x1b2b4162, 0xa5cef1a, 0x1543622b, 0x9bd433e, 0x364e04d, 0x7480792, 0x5c9b5b3, 0xe85ff25, 0x408ef57,- 0x1814cfa4, 0x121b41b, 0xd248a0f, 0x3b05222, 0x39bb16a, 0xc75966d, 0xa038113, 0xa4a1769, 0x11fbc6c,- 0x917e50e, 0xeec3da8, 0x169d6eac, 0x10c1699, 0xa416153, 0xf724912, 0x15cd60b7, 0x4acbad9, 0x5efc5fa,- 0xf150ed7, 0x122b51, 0x1104b40a, 0xcb7f442, 0xfbb28ff, 0x6ac53ca, 0x196142cc, 0x7bf0fa9, 0x957651,- 0x4e0f215, 0xed439f8, 0x3f46bd5, 0x5ace82f, 0x110916b6, 0x6db078, 0xffd7d57, 0xf2ecaac, 0xca86dec,- 0x15d6b2da, 0x965ecc9, 0x1c92b4c2, 0x1f3811, 0x1cb080f5, 0x2d8b804, 0x19d1c12d, 0xf20bd46, 0x1951fa7,- 0xa3656c3, 0x523a425, 0xfcd0692, 0xd44ddc8, 0x131f0f5b, 0xaf80e4a, 0xcd9fc74, 0x99bb618, 0x2db944c,- 0xa673090, 0x1c210e1, 0x178c8d23, 0x1474383, 0x10b8743d, 0x985a55b, 0x2e74779, 0x576138, 0x9587927,- 0x133130fa, 0xbe05516, 0x9f4d619, 0xbb62570, 0x99ec591, 0xd9468fe, 0x1d07782d, 0xfc72e0b, 0x701b298,- 0x1863863b, 0x85954b8, 0x121a0c36, 0x9e7fedf, 0xf64b429, 0x9b9d71e, 0x14e2f5d8, 0xf858d3a, 0x942eea8,- 0xda5b765, 0x6edafff, 0xa9d18cc, 0xc65e4ba, 0x1c747e86, 0xe4ea915, 0x1981d7a1, 0x8395659, 0x52ed4e2,- 0x87d43b7, 0x37ab11b, 0x19d292ce, 0xf8d4692, 0x18c3053f, 0x8863e13, 0x4c146c0, 0x6bdf55a, 0x4e4457d,- 0x16152289, 0xac78ec2, 0x1a59c5a2, 0x2028b97, 0x71c2d01, 0x295851f, 0x404747b, 0x878558d, 0x7d29aa4,- 0x13d8341f, 0x8daefd7, 0x139c972d, 0x6b7ea75, 0xd4a9dde, 0xff163d8, 0x81d55d7, 0xa5bef68, 0xb7b30d8,- 0xbe73d6f, 0xaa88141, 0xd976c81, 0x7e7a9cc, 0x18beb771, 0xd773cbd, 0x13f51951, 0x9d0c177, 0x1c49a78,+static const limb kPrecomputed[NLIMBS * 2 * 16 * 2] = {+ 0xe01bd76, 0xa0be8b3, 0x8494c1d, 0x609ab3d, 0x1188042f, 0x499c03d, 0x1df7cd26, 0x51b33c5, 0x1fb3bce,+ 0x39cdd45, 0xdc0dd9b, 0xe3053d7, 0x1ffaf46, 0x9ac284a, 0xac051d4, 0x1c09fe1b, 0x8227cbf, 0x5bf049b,+ 0xb9487d, 0x2ecb75f, 0x194825bf, 0xd70cf28, 0x14e528f3, 0x4d8670c, 0x35bbabb, 0x6b692ca, 0xd96d08,+ 0x1db081dc, 0xa87ea7b, 0x190e5549, 0xa4cf420, 0x1e151385, 0xaf3d4bd, 0x4057e9f, 0x5078feb, 0x154519a,+ 0xbf15dea, 0x453fa25, 0x1171c85a, 0x576c824, 0x154e7060, 0x71ede6e, 0x160467a2, 0xdea8a44, 0x81ffcb1,+ 0x61a56fa, 0x76119b9, 0x110bfb9b, 0x3d527ea, 0x1997bdb4, 0xe1d1253, 0x180ce91c, 0x11950ee, 0x53d5938,+ 0x694e7c9, 0xe0cf337, 0x16d8ae50, 0x202517f, 0x4d02e16, 0xd13b5fd, 0xfae97eb, 0xa1c7f60, 0x1206fe8,+ 0x11b1c908, 0xf8a82f, 0x6ab17a0, 0x48058e8, 0x2d0feb, 0xfada550, 0x658edb9, 0xa17567a, 0x8daa44d,+ 0x6361dc9, 0xec00c0e, 0x151a7b1c, 0xb35a683, 0x1643fe02, 0x70155c0, 0x1f131d45, 0x3998068, 0x25beef8,+ 0x88138de, 0x8995ce4, 0x18565c50, 0x60f12b6, 0xc47a656, 0x4a82bd9, 0xb547a17, 0xb333474, 0xe86513a,+ 0x7f8d2bc, 0x7f0f16c, 0x8cde475, 0x1ac3d5c, 0x1a832c9a, 0x6a93e7a, 0x19833281, 0xcec82db, 0x4f08cc,+ 0x72c4394, 0x4686520, 0x1e845ce, 0xfb181a1, 0xf5135a5, 0xa1265d6, 0x6c63ce8, 0xe81797e, 0x5dbcd5a,+ 0x2a5d603, 0x1ad4e91, 0xc86e1b3, 0x793abea, 0x1b8610a4, 0x8d5b975, 0x74dd850, 0xbbca81, 0xd7c35d8,+ 0x1bab7afc, 0x4df749, 0x4acb4ea, 0xfae8c89, 0x14552ae5, 0x6dc1c20, 0x14f629f, 0x2368fe5, 0xe5a9cba,+ 0x67576f7, 0x9c77c50, 0x1d63c92a, 0xbbb9ef8, 0xa7530d4, 0x963335, 0xfa09c54, 0xb6d03e3, 0xed1a022,+ 0x19c59f49, 0x45c823d, 0x17a28df1, 0x80ae516, 0xe2ada82, 0x19b97fb, 0x13a9ebf, 0xf1e7606, 0xde03632,+ 0x14e318b9, 0x7b57b83, 0x51a9a92, 0x3378a17, 0x1cde9289, 0x45956c2, 0x2bbab5e, 0x780b1f5, 0x8356034,+ 0x75eca28, 0x6f39648, 0xf2fdbda, 0x4c65cd9, 0xb3759e7, 0x710c0b1, 0xda24432, 0x8d236aa, 0xf4c449f,+ 0xaf9ba24, 0xb83ea7f, 0x1e46ecc3, 0x3f277b0, 0x6acdecd, 0x1f597d1, 0x8483d72, 0x57d29dd, 0x66d4060,+ 0x167c14af, 0xc142ded, 0xc1689ca, 0x651aa52, 0x8d05768, 0x9709cfa, 0x165fd283, 0x9f6f583, 0x9833b54,+ 0xd17e2d6, 0x2915c32, 0x1970ef24, 0xe8ca45b, 0x11c29e09, 0x8121f26, 0xb5afbe1, 0x10c80ec, 0x834a25c,+ 0xa37f0b0, 0xd6bac16, 0xed484fc, 0x8799206, 0x13db8bb1, 0xdce615c, 0x13320329, 0x79dc25, 0x914e7af,+ 0x860a414, 0xb8a9434, 0x50396ce, 0x902d3e6, 0x15c152f3, 0x3753c64, 0x970c055, 0xba296fb, 0x64bd63b,+ 0x118cbb94, 0x9d4274f, 0x121cdbfe, 0xb9137cf, 0xc8bddf1, 0xa1598d0, 0x446ab41, 0x11f1df2, 0x68115f1,+ 0x2f1f708, 0xee35192, 0x1dfeb3fc, 0x4e1e1a6, 0x1d9adcbb, 0x6688662, 0x63ad21b, 0x9d9a9e1, 0xb0f8b4b,+ 0xcd8bc3a, 0x3577d8, 0x1ffcb97d, 0xd31e8d6, 0x1c776310, 0x95b4ef7, 0x185a82ed, 0xe40bbb0, 0xbca1ea,+ 0x19462e0b, 0x2252179, 0x14f14f09, 0x565e68d, 0x7ba5f37, 0x4cd1858, 0x167941b3, 0x4d1c7a7, 0x7aef1ab,+ 0x1599efe9, 0x658e78d, 0x1ad33917, 0x7e74797, 0x19152edc, 0xdf7dc18, 0xdf677c, 0x9315d96, 0x4ba8eec,+ 0xc45cd82, 0x1acfa03, 0xe265b49, 0xcfa6eb, 0x89d7619, 0x7b05, 0x1ba11068, 0xe1672d3, 0x655622a,+ 0x1607ca6, 0x339049, 0x5454f70, 0x10edd75, 0x1133ceb7, 0xe3eec39, 0xc263156, 0xeb6ddbe, 0x10360a7,+ 0xfd5f981, 0x47dd502, 0x1e66dbbe, 0x8820b63, 0xeee91ef, 0xffde293, 0xb66325d, 0x3a5a2a, 0x6a2acbb,+ 0x11e949bc, 0xf6a6d57, 0x6b2ca24, 0xad903ec, 0x1e55de0, 0xe7074ed, 0xe681934, 0xea44010, 0xaa490cc,+ 0x512324a, 0x6a5eb00, 0xee5e100, 0xd60a02b, 0x1b89c993, 0x5cffb70, 0xa49030c, 0x405aee, 0xe1b27cc,+ 0x2e73a15, 0x9ca8dc0, 0x781dbff, 0x9fd85e0, 0x1884e4c8, 0x40873f6, 0x32d4b69, 0xf42f753, 0xeaf4c38,+ 0x2802a4c, 0x1283dac, 0x759100a, 0xcb3ba75, 0xf3203d3, 0xf89b8aa, 0x7caa59e, 0x384a60a, 0x37f69e7,+ 0x1e56d569, 0x120c552, 0x181734aa, 0x4fcd9b4, 0x7918e4e, 0xcd7938a, 0x2bbd8b2, 0x19f4f97, 0xa7af533,+ 0xbb69948, 0x3eff33e, 0x1f3ac118, 0x3739770, 0x58898fd, 0x623fafb, 0xa7e6d93, 0xd31a676, 0x615192d,+ 0xf543d28, 0xe61ce5a, 0x10ae4b39, 0xcd5a8d7, 0x1b34c6de, 0x81997ad, 0x198e2093, 0xd9b6ff7, 0x9a5954f,+ 0x16782589, 0xed3c1ab, 0x62dc4a5, 0xac12d0c, 0x8bc8b7c, 0x168ec4e, 0x177e11dc, 0x407df09, 0x4056e85,+ 0x9858305, 0xfe445e9, 0x18b1230a, 0x815ee9f, 0xa852eb4, 0x89444e0, 0x1a83481, 0x479359b, 0x2192576,+ 0x16d5e61b, 0xfe480c4, 0x1d60b8b7, 0x1c6e798, 0x1a01310, 0x9998572, 0x7c59f75, 0x49dda87, 0xe75e0b6,+ 0x1b2b7536, 0xb267d8, 0x15443085, 0x45e5924, 0x7fb947f, 0x296915d, 0x38fc56b, 0x4bae39f, 0xb218e7c,+ 0x115c3b16, 0x9d95f0c, 0xa50ac4c, 0xcce8037, 0xc3c7ba3, 0xf02773a, 0xbc2ad54, 0x26914c1, 0x19a4b8d,+ 0x3f8a1a6, 0xa0b8459, 0x1f77a521, 0x7d93297, 0x1dddb4b2, 0x9e4cd1c, 0x6e28403, 0xd7ce413, 0x5575b62,+ 0x12bb7dc1, 0xbdfb15e, 0xa542867, 0xe943d3e, 0x1367fbdd, 0x37b387, 0x14e4d75f, 0xb90b09d, 0xbf6ec28,+ 0xa5182c8, 0x1e5b34e, 0xabe4602, 0x1c13efa, 0x8d1182, 0x1c2947a, 0x1e04e0e3, 0x6caecdb, 0x40f14e8,+ 0x1b845e4a, 0xa9fb149, 0xb34f513, 0x3a0fdbb, 0xfad2335, 0x5bb9342, 0x18c5ad62, 0xc97fdc3, 0x31225c7,+ 0xb28a9ee, 0x585915, 0x1e355da1, 0x26ed08e, 0xc7d06a, 0xa65f219, 0x1fdf45cd, 0xc8323ea, 0x297b9ee,+ 0x1c031098, 0x9c39cf0, 0x1287d79f, 0x69a9e32, 0x10015650, 0x1c3dfc3, 0x12dcd848, 0x3155a59, 0xeff3212,+ 0x1a6ecdd0, 0xd26bd07, 0x18e077ab, 0x442b477, 0x46b735f, 0x495d60c, 0x1b57a6e5, 0x76a368a, 0xf53bd50,+ 0xf12c5e0, 0x80a9b4, 0x15562060, 0x4102113, 0xa144ab5, 0x5fa4e9, 0x1009f5e9, 0xe34343a, 0x26fda5a,+ 0x159e06a4, 0x5fa3aad, 0x10259b5f, 0xa69947d, 0x1190417e, 0x987da3f, 0x14e1e868, 0xdcb7e1e, 0x8890f9f,+ 0x14dece80, 0x94bbf5c, 0x18513a17, 0x4ca31ca, 0xc0a2713, 0xbc46074, 0x1536f6a5, 0x43991aa, 0xb9f8f1c,+ 0x987ba48, 0xb0829ae, 0xd29d324, 0x6339c35, 0x18ace0a4, 0x5d53b55, 0xff829f4, 0xe882ecf, 0xc05164c,+ 0x6bd6bba, 0x9dfc14f, 0x1981cab3, 0xcfebf18, 0x1ddac868, 0x94ec6d4, 0x5abd4b, 0x737fdb3, 0x18f531f,+ 0xd3c2a71, 0x337178f, 0x9f7c32e, 0xd9d7fda, 0x137d191f, 0xdd0757b, 0x14b6d65, 0x179f37a, 0x67b10e1,+ 0x1bfb2cfd, 0xfe4ca43, 0x1fee2930, 0x98c2aa0, 0x9826788, 0xeaf4ceb, 0x17a6be82, 0xc899ed1, 0x500fb01,+ 0x10918e6f, 0x36179ed, 0xbca6643, 0x2d80942, 0xf1ef61, 0xadca21c, 0xbe5b3a7, 0xadae157, 0x12daac,+ 0x1337dda8, 0x6326e5d, 0x2738e1b, 0x5cb5c54, 0x98ec8a0, 0x252647d, 0x1d5c173c, 0xbdf848d, 0x9e5217b,+ 0x1d64f447, 0xb71d1a, 0xb2c2360, 0xccb6bee, 0x1245995e, 0x94a9130, 0x5b93d91, 0x76c57ff, 0xeaa91d1,+ 0x3941881, 0xc2aafbd, 0x1c0540d0, 0x1a938f0, 0x1304b724, 0x8524e10, 0x1bef780f, 0xbc0ea48, 0xbe90dae,+ 0x1d10d5d8, 0xca979e2, 0x10db5cc4, 0x54e2493, 0x44d38f3, 0xbcb73b, 0x12dcff4, 0xd0ab219, 0xde69db2,+ 0x13594366, 0xc30e05f, 0xfc245d4, 0x8c5b52f, 0x81901c7, 0xa9d1e03, 0x11ead62e, 0xb7be89b, 0xc9c8486,+ 0x132a6fa0, 0x56af9b8, 0x41cb561, 0xf74418c, 0x141c461a, 0xbc18514, 0x1d6bbb68, 0x96d43c2, 0x7108696 };
cbits/include64/p256/p256.h view
@@ -83,16 +83,9 @@ const crypton_p256_int* b, crypton_p256_int* c); -// b := 1 / a % MOD-// MOD best be SECP256r1_n-void crypton_p256_modinv(- const crypton_p256_int* MOD,- const crypton_p256_int* a,- crypton_p256_int* b);--// b := 1 / a % MOD+// b := 1 / a % MOD, in time that depends on a // MOD best be SECP256r1_n-// Faster than crypton_p256_modinv()+// Answers zero for an a that has no inverse, which is zero and MOD void crypton_p256_modinv_vartime( const crypton_p256_int* MOD, const crypton_p256_int* a,@@ -130,13 +123,6 @@ void crypton_p256_base_point_mul(const crypton_p256_int *n, crypton_p256_int *out_x, crypton_p256_int *out_y);--// {out_x,out_y} := n{in_x,in_y}-void crypton_p256_point_mul(const crypton_p256_int *n,- const crypton_p256_int *in_x,- const crypton_p256_int *in_y,- crypton_p256_int *out_x,- crypton_p256_int *out_y); // {out_x,out_y} := n1G + n2{in_x,in_y} void crypton_p256_points_mul_vartime(
cbits/include64/p256/p256_gf.h view
@@ -104,102 +104,111 @@ 2, 0xfc00000000000, 0x7ffffffffffff, 0xfff7fffffffff, 0x7ffff }; static const felem kZero = {0};++/* the curve's b, in Montgomery form, for the complete addition formula */+static const felem kB = {+ 0x1bec453897bbf, 0x33e210c243627, 0x484bb5ab3c017, 0x41a32d11055fb,+ 0x2e18030ec243a+}; static const felem kP = { 0x7ffffffffffff, 0x1fffffffffff, 0, 0x4000000000, 0x3fffffffc0000 }; static const felem k2P = { 0x7fffffffffffe, 0x3fffffffffff, 0, 0x8000000000, 0x7fffffff80000 };-/* kPrecomputed contains precomputed values to aid the calculation of scalar- * multiples of the base point, G. It's actually two, equal length, tables- * concatenated.+/* kPrecomputed holds the multiples of the base point G that the comb in+ * scalar_base_mult reads. Two tables of sixteen affine points, one after the+ * other. *- * The first table contains (x,y) felem pairs for 16 multiples of the base- * point, G.+ * The comb takes five bits of the signed all-bits-set representation at a+ * time, from positions 52 apart, and the two tables are offset from each+ * other by 26: *- * Index | Index (binary) | Value- * 0 | 0000 | 0G (all zeros, omitted)- * 1 | 0001 | G- * 2 | 0010 | 2**64G- * 3 | 0011 | 2**64G + G- * 4 | 0100 | 2**128G- * 5 | 0101 | 2**128G + G- * 6 | 0110 | 2**128G + 2**64G- * 7 | 0111 | 2**128G + 2**64G + G- * 8 | 1000 | 2**192G- * 9 | 1001 | 2**192G + G- * 10 | 1010 | 2**192G + 2**64G- * 11 | 1011 | 2**192G + 2**64G + G- * 12 | 1100 | 2**192G + 2**128G- * 13 | 1101 | 2**192G + 2**128G + G- * 14 | 1110 | 2**192G + 2**128G + 2**64G- * 15 | 1111 | 2**192G + 2**128G + 2**64G + G+ * first table i, 52+i, 104+i, 156+i, 208+i+ * second table 26+i, 78+i, 130+i, 182+i, 234+i *- * The second table follows the same style, but the terms are 2**32G,- * 2**96G, 2**160G, 2**224G.+ * for i from 25 down to 0, which covers all 260 bits between them. *+ * Every digit of that representation is +-1, so a block of five teeth takes+ * one of thirty-two values -- and they come in pairs that differ only by+ * sign. So sixteen entries are enough: the top tooth is taken positive, bit+ * j of the index says that tooth j agrees with it, and where the top tooth is+ * negative the caller negates y, which costs a subtraction. Entry zero is a+ * point like any other here, unlike the unsigned table this replaces, where+ * it stood for the infinity.+ *+ * Index | Index (binary) | Value+ * 0 | 0000 | 2**208G - 2**156G - 2**104G - 2**52G - G+ * 1 | 0001 | 2**208G - 2**156G - 2**104G - 2**52G + G+ * ... | ... | ...+ * 15 | 1111 | 2**208G + 2**156G + 2**104G + 2**52G + G+ * * This is ~2KB of data. */-static const limb kPrecomputed[NLIMBS * 2 * 15 * 2] = {- 0x661a831522878, 0xf17fb6d805e79, 0x5889441d6ea57, 0xae33cfdb995bb, 0xc482fbb529ba,- 0x4a6af9d2aac15, 0x90e867917377c, 0x487cc962d2ae3, 0xec2a97443446e, 0x2b8ff8c52c42,- 0x45f8a2d41a576, 0xb06988d2653e4, 0x718b22c357305, 0x33fc920e79d2b, 0x17af34b0fe8db,- 0x38e17eb402f2f, 0x3382558649705, 0x47f6d48f482d1, 0x7bd42488d9b83, 0x3b247c8b86b78,- 0x4d08fc26f7778, 0x7a29a82fb2795, 0x75cd18f90d11a, 0xad8e213b0bc, 0x2d5f0142899e8,- 0x506f98098fb57, 0x2f0c98301e4aa, 0x39b30dd5cf67d, 0x9c146498ab13c, 0xa5db92df5b7b,- 0x184897fc4124a, 0xe3f73a19d8aa, 0x4e1c18e47066b, 0x27b2d4b52eaee, 0x30eac3ea10e99,- 0x4e74546e2e7d5, 0x1f4dde2d97a1d, 0x6ead0f88e1200, 0x7dec87c220f02, 0x3d08ff096310f,- 0x23e5659633ffa, 0x6ec648f08c722, 0x3172a3806ea35, 0xf6e5b681eb3c5, 0x2c3758260f89d,- 0x38dca4fd1da12, 0xf06067b78830d, 0x3194be87a068c, 0x78893c7eb602b, 0xcead60438432,- 0x6ee69a56a67ab, 0xd886f77701895, 0x67b0a4d9cee2b, 0x3586bbf3e4d53, 0x1db6f32921d93,- 0x260756ca4b366, 0x4f40e9d2039fa, 0x4f3f09f5a82bf, 0xccde2d641e8cd, 0x305a30cd2e8c5,- 0x471c235cb5439, 0xab279cd962f5a, 0x17e1fb6e2dd94, 0xfe64589800a77, 0xe8793d99775f,- 0x48c62f4e614aa, 0xbf76ef20eb2a4, 0x669c672556c, 0x24683e0eff056, 0x12252b369ab76,- 0x821de9f162d5, 0xf911ec99a95be, 0x6721f065c906b, 0x58d452035c736, 0x1f9f01a6a15,- 0x6135009b7d8d3, 0xdaeeeb417dfc0, 0x63865fea0ee17, 0x6e0a304b939d6, 0x204ba2076833d,- 0x4ade586f35669, 0x2c1077e34611a, 0x5b1a3bea3b81a, 0xf97d018a22c8b, 0x38d7996b08af8,- 0x6ea62baeb7aa0, 0xebdcbd9ef2670, 0x35dc8fe0df3fe, 0xe458309d20c24, 0x11e87898716a0,- 0x7c44bab7cb456, 0xd64d3cf1bb64, 0x189bff1bf9e66, 0xb5218a049311, 0x285dda6cbcc81,- 0x3238dcafd8c7c, 0x607736c8de0, 0xdb83d99508b1, 0x4e1a0d404cd81, 0x1588008c00ff2,- 0x16b8b36722b27, 0x876609c3f3f1a, 0x66b72ef0e17d6, 0x705f8a279d568, 0x2eaac4cd01fdd,- 0x1171ce9705fe9, 0xffc79cd3264ee, 0x700c8ab4b80f0, 0x208d3d4f57a1, 0x337262a8ca4eb,- 0x297fd01d843fd, 0xa90956fa097f8, 0x529759fdb3845, 0x1d78c5e2d0397, 0x3d6938a4adbf3,- 0x16d5853560b66, 0xf138946b9a430, 0x2ab79f4dea6a0, 0xd42053ee43ae1, 0x3b9c3ef1cf870,- 0x598934ad81baf, 0x5f1821b1d07a7, 0x416bb3a973ff3, 0x23f07bd0a047a, 0x19bdc2e09f786,- 0x56dc9981cd51f, 0xfbace23c8cd65, 0x673bd3bf5b52e, 0x46a95d229fd61, 0xe09ad64bcfb1,- 0xe5292b91f17d, 0xfeefcd8afc287, 0x58f52b0a58711, 0x4800f20c201ef, 0x2084fce608f67,- 0x12ba0b128ae0b, 0x5977ae17030b4, 0x101126ee420f6, 0xf70823495c6bd, 0xde19a27d7770,- 0x5c6ac852260e8, 0x9d22950ac4356, 0x441cca955246c, 0x660a34e5332d9, 0x14ac8ea92f8d2,- 0x6b6d7709f307e, 0x67d7e13879db, 0x2ea8626f9fbbd, 0x99609006a4b40, 0x31bb2a8f8c779,- 0x10c04828ea335, 0xae9acdcbc080a, 0x617af2342607a, 0xc7494ea53e553, 0x2ca9e2872defa,- 0x6c399fab21f1f, 0xab139b245e758, 0x3ad933dcba589, 0x4797fecb08811, 0x31f5dbf8f594,- 0x7dc6361cc7a69, 0xc8a7953ead3f9, 0x79ed693d18015, 0x418a024999a6a, 0x2c4fdc9436aa,- 0x1eb98cb06aa75, 0x2989592796a9c, 0x11194821e425, 0xe27a648228388, 0x35d834b6c12a0,- 0x541807713b532, 0x7ae0a1008aaee, 0x7017a29bcb5e, 0x6b193c23c315c, 0x19bd25ac82f2a,- 0x6a01a43eef294, 0xddf5b5fd84f19, 0x33f5ba081c016, 0xdeb052d1bc082, 0x6b2f06afa617,- 0x7ca1eda6a939f, 0xbdeb35997b50c, 0x47f2d1bccda5, 0xc2ff4adfed667, 0x87712997be4,- 0x21fc2e2b37659, 0xf7d62cd5ed951, 0x27fa9cbdf7efa, 0xba25582bf3a6b, 0x2a42b8bd89398,- 0x6d377d07eecd2, 0x9ca1df5af387, 0x1109e3427e2ba, 0xce4aa4572a19, 0x103baaef71e16,- 0x2c3b2dfde328a, 0xbec4b4a30e1ef, 0x37d92a86204f3, 0x806cfde68eb39, 0x246e2f72b8aa5,- 0x68d3de93462a9, 0x53b8acba6bbc3, 0x2492a70fa1696, 0x38c62d5760f55, 0x15096fe4904f2,- 0x4e44e9bed3e3a, 0xb28bfd79cc9bc, 0x6a77513839320, 0x480dcec6739db, 0x3601b739f2465,- 0x43c348e2a7e1, 0xe448106327879, 0x175d9cae1b0ed, 0xd3b89dee743b8, 0x392d73ca255bc,- 0x32946db0d3a18, 0x9261b09907cc, 0x5ba517a755722, 0x51f24fdaf5184, 0x1cdc732989ed8,- 0x2f7806ba16694, 0xae0c9f029f8d0, 0xd8b45102ce1, 0xca1c7db9316d6, 0x162088a67066f,- 0x39de35b2b4162, 0xa19f550d88ae9, 0x7921b27026cde, 0x94b936b66e900, 0x1023bd5fa17fc,- 0x436837814cfa4, 0x29113492283c4, 0x66d1cdd8b51d8, 0xa540702278eb2, 0x47ef1b29285d,- 0x587b50917e50e, 0xb4cda75bab3b, 0x112520b0a9886, 0x66b9ac16fee49, 0x17bf17e92b2eb,- 0x2456a2f150ed7, 0xfa214412d0280, 0x3ca7dd947fe5b, 0xa72c28598d58a, 0x255d945efc3e,- 0x2873f04e0f215, 0x74178fd1af57b, 0x788848b5b2d6, 0xb1ffafaae0db6, 0x32a1b7b3cbb2a,- 0x4bd9935d6b2da, 0x9c08f24ad30a5, 0x4e58407a80f, 0x1b3a3825a5b17, 0x6547e9fc82f5,- 0x47484aa3656c3, 0x6ee43f341a494, 0x64a98f87adea2, 0x619b3f8e95f01, 0xb6e513266ed8,- 0x421c2a673090, 0xa1c1de32348c7, 0x55b85c3a1e8a3, 0xe05ce8ef330b4, 0x2561e49c15d84,- 0x40aa2d33130fa, 0x12b827d35866f, 0xfe4cf62c8ddb, 0x2fa0ef05bb28d, 0x1c06ca63f1cb8,- 0x32a971863863b, 0xff6fc86830da1, 0x71e7b25a14cf3, 0xea9c5ebb1373a, 0x250bbaa3e1634,- 0x5b5ffeda5b765, 0xf25d2a746331b, 0x115e3a3f43632, 0x67303af43c9d5, 0x14bb538a0e559,- 0x75623687d43b7, 0xa349674a4b38d, 0x613c61829ffc6, 0x689828d8110c7, 0x139115f5af7d5,- 0xf1d856152289, 0x45cbe967168ab, 0x51f38e1680901, 0x34808e8f652b0, 0x1f4a6a921e156,- 0x35dfaf3d8341f, 0xf53ace725cb63, 0x3d86a54eef35b, 0xa103aabaffe2c, 0x2decc36296fbd,- 0x510282be73d6f, 0xd4e6365db206a, 0x4bdc5f5bb8bf3, 0xde7ea32a3aee7, 0x71269e274305,+static const limb kPrecomputed[NLIMBS * 2 * 16 * 2] = {+ 0x17d166e01bd76, 0xd59ea12530768, 0x3d8c40217b04, 0x17bef9a4c9338, 0x7ecef3946ccf,+ 0x1bb3639cdd45, 0xd7a338c14f5f7, 0x1d44d614250ff, 0xff813fc37580a, 0x16fc126e089f2,+ 0x596ebe0b9487d, 0x6794652096fcb, 0x70ca729479eb8, 0x286b775769b0c, 0x365b421ada4b,+ 0xfd4f7db081dc, 0x7a1064395526a, 0x4bdf0a89c2d26, 0xac80afd3f5e7a, 0x551466941e3f,+ 0x27f44abf15dea, 0x641245c721691, 0x66eaa738302bb, 0x12c08cf44e3db, 0x207ff2c77aa29,+ 0x42337261a56fa, 0x93f5442fee6dd, 0x253ccbdeda1ea, 0xbb019d239c3a2, 0x14f564e046543,+ 0x19e66e694e7c9, 0x28bfdb62b9438, 0x5fd268170b101, 0x81f5d2fd7a276, 0x481bfa2871fd,+ 0x71505f1b1c908, 0x2c741aac5e803, 0x55001687f5a40, 0xe8cb1db73f5b4, 0x236a913685d59,+ 0x181c6361dc9, 0xd341d469ec73b, 0x5c0b21ff0159a, 0xa3e263a8ae02a, 0x96fbbe0e6601,+ 0x32b9c888138de, 0x895b615971422, 0x3d9623d32b307, 0xd16a8f42e9505, 0x3a1944eacccd1,+ 0x61e2d87f8d2bc, 0x1eae233791d5f, 0x67ad41964d0d6, 0x6f3066502d527, 0x13c23333b20b,+ 0x50ca4072c4394, 0xc0d087a117391, 0x5d67a89ad2fd8, 0xf8d8c79d1424c, 0x176f356ba05e5,+ 0x5a9d222a5d603, 0xd5f5321b86cc6, 0x175dc308523c9, 0x4e9bb0a11ab7, 0x35f0d7602ef2a,+ 0x1bee93bab7afc, 0x464492b2d3a81, 0x420a2a9572fd7, 0x9429ec53edb83, 0x396a72e88da3f,+ 0xef8a067576f7, 0xcf7c758f24aa7, 0x33553a986a5dd, 0x8df4138a812c6, 0x3b46808adb40f,+ 0x39047b9c59f49, 0x728b5e8a37c51, 0x7fb7156d41405, 0x182753d7e3372, 0x3780d8cbc79d8,+ 0x6af7074e318b9, 0xc50b946a6a49e, 0x6c2e6f494499b, 0xd457756bc8b2a, 0x20d580d1e02c7,+ 0x672c9075eca28, 0x2e6cbcbf6f69b, 0xb159bacf3a63, 0xa9b448864e218, 0x3d31127e348da,+ 0x7d4feaf9ba24, 0x3bd8791bb30ee, 0x7d13566f669f9, 0x750907ae43eb2, 0x19b501815f4a7,+ 0x285bdb67c14af, 0xd529305a272b0, 0x4fa4682bb4328, 0xecbfa5072e13, 0x260ced527dbd6,+ 0x22b864d17e2d6, 0x522de5c3bc90a, 0x7268e14f04f46, 0xb16b5f7c30243, 0x20d2897043203,+ 0x57582ca37f0b0, 0xc9033b5213f35, 0x15c9edc5d8c3c, 0x966640653b9cc, 0x24539ebc1e770,+ 0x152868860a414, 0x69f3140e5b3ae, 0x464ae0a979c81, 0xed2e180aa6ea7, 0x192f58eee8a5b,+ 0x284e9f18cbb94, 0x9be7c8736ffa7, 0xd0645eef8dc8, 0xc888d568342b3, 0x1a0457c447c77,+ 0x46a3242f1f708, 0xf0d377facff3b, 0x662ecd6e5da70, 0x84c75a436cd10, 0x2c3e2d2e766a7,+ 0x6aefb0cd8bc3a, 0xf46b7ff2e5f40, 0x6f7e3bb188698, 0xc30b505db2b69, 0x2f287ab902ee,+ 0x4a42f39462e0b, 0xf346d3c53c248, 0x583dd2f9bab2, 0x9ecf2836699a3, 0x1ebbc6ad3471e,+ 0x31cf1b599efe9, 0xa3cbeb4ce45d9, 0x418c8a976e3f3, 0x581becef9befb, 0x12ea3bb24c576,+ 0x59f406c45cd82, 0xd375b8996d246, 0x30544ebb0c867, 0x4f74220d0000f, 0x195588ab859cb,+ 0x6720921607ca6, 0x6eba95153dc00, 0x439899e75b887, 0xf984c62adc7dd, 0x40d829fadb76,+ 0x7baa04fd5f981, 0x5b1f99b6ef91, 0x29377748f7c41, 0xa96cc64bbffbc, 0x1a8ab2ec0e968,+ 0x54daaf1e949bc, 0x81f61acb2893d, 0x4ed0f2aef056c, 0x41cd03269ce0e, 0x2a924333a9100,+ 0x4bd600512324a, 0x5015bb978401a, 0x370dc4e4c9eb0, 0xb94920618b9ff, 0x386c9f301016b,+ 0x151b802e73a15, 0xc2f01e076ffe7, 0x3f6c4272644fe, 0x4c65a96d2810e, 0x3abd30e3d0bdd,+ 0x507b582802a4c, 0xdd3a9d6440284, 0xaa79901e9e59, 0x28f954b3df137, 0xdfda79ce1298,+ 0x418aa5e56d569, 0x6cda605cd2a84, 0x38a3c8c72727e, 0x5c577b1659af2, 0x29ebd4cc67d3e,+ 0x5fe67cbb69948, 0xcbb87ceb0460f, 0x2fb2c44c7e9b9, 0xd94fcdb26c47f, 0x185464b74c699,+ 0x439cb4f543d28, 0xd46bc2b92ce79, 0x7add9a636f66a, 0xdf31c41270332, 0x2696553f66dbf,+ 0x2783576782589, 0x968618b71297b, 0x44e45e45be560, 0x26efc23b82d1d, 0x1015ba1501f7c,+ 0x488bd29858305, 0xf74fe2c48c2bf, 0x4e0542975a40a, 0x6c35069031288, 0x86495d91e4d6,+ 0x4901896d5e61b, 0x73cc7582e2dff, 0x5720d009880e3, 0x1cf8b3eeb3330, 0x39d782d92776a,+ 0x64cfb1b2b7536, 0x2c925510c2142, 0x15d3fdca3fa2f, 0x7c71f8ad652d2, 0x2c8639f12eb8e,+ 0x32be1915c3b16, 0x401ba942b1327, 0x73a61e3dd1e67, 0x57855aa9e04e, 0x6692e349a453,+ 0x1708b23f8a1a6, 0x994bfdde94868, 0x51ceeeda593ec, 0x4cdc508073c99, 0x155d6d8b5f390,+ 0x3f62bd2bb7dc1, 0x1e9f2950a19ef, 0x3879b3fdeef4a, 0x769c9aebe06f6, 0x2fdbb0a2e42c2,+ 0x4b669ca5182c8, 0x9f7d2af918087, 0x47a04688c10e0, 0x6fc09c1c63852, 0x103c53a1b2bb3,+ 0x3f6293b845e4a, 0x7eddacd3d44ea, 0x3427d6919a9d0, 0xf18b5ac4b772, 0xc48971f25ff7,+ 0x30b22ab28a9ee, 0x684778d576841, 0x219063e835137, 0xabfbe8b9b4cbe, 0xa5ee7bb20c8f,+ 0x739e1c031098, 0x4f194a1f5e7e7, 0x7c3800ab2834d, 0x665b9b090387b, 0x3bfcc848c5569,+ 0x4d7a0fa6ecdd0, 0x5a3be381deaf4, 0x60c235b9afa21, 0x2b6af4dca92ba, 0x3d4ef541da8da,+ 0x15368f12c5e0, 0x1089d55881802, 0x4e950a255aa08, 0xea013ebd20bf4, 0x9bf696b8d0d0,+ 0x74755b59e06a4, 0xca3ec0966d7d7, 0x23f8c820bf534, 0x7a9c3d0d130fb, 0x22243e7f72df8,+ 0x177eb94dece80, 0x18e56144e85e5, 0x746051389a65, 0xaaa6ded4b788c, 0x2e7e3c710e646,+ 0x10535c987ba48, 0xce1ab4a74c92c, 0x355c567052319, 0x3dff053e8baa7, 0x30145933a20bb,+ 0x3f829e6bd6bba, 0x5f8c66072ace7, 0x6d4eed643467f, 0xcc0b57a9729d8, 0x63d4c7dcdff6,+ 0x6e2f1ed3c2a71, 0xbfed27df0cb8c, 0x57b9be8c8fece, 0xe8296dacbba0e, 0x19ec43845e7cd,+ 0x499487bfb2cfd, 0x15507fb8a4c3f, 0x4eb4c133c44c6, 0x46f4d7d05d5e9, 0x1403ec072267b,+ 0x42f3db0918e6f, 0x4a12f29990cd, 0x21c078f7b096c, 0x5d7cb674f5b94, 0x4b6ab2b6b85,+ 0x64dcbb337dda8, 0xae2a09ce386d8, 0x47d4c764502e5, 0x37ab82e784a4c, 0x279485eef7e12,+ 0x6e3a35d64f447, 0xb5f72cb08d802, 0x130922ccaf665, 0xfcb727b232952, 0x3aaa4745db15f,+ 0x555f7a3941881, 0x9c78701503430, 0x6109825b920d4, 0x237def01f0a49, 0x2fa436baf03a9,+ 0x52f3c5d10d5d8, 0x1249c36d73132, 0x73b2269c79aa7, 0x6425b9fe81796, 0x379a76cb42ac8,+ 0x61c0bf3594366, 0xda97bf0917530, 0x60340c80e3c62, 0x6e3d5ac5d53a3, 0x3272121adefa2,+ 0x55f37132a6fa0, 0x20c61072d5855, 0x514a0e230d7ba, 0xbad776d17830, 0x1c421a5a5b50f };
+ cbits/include64/p256/p256_s2n.h view
@@ -0,0 +1,25 @@+/*+ * The vendored s2n-bignum assembly, behind one call that picks the variant+ * the machine wants. See cbits/s2n/README.md for which and why.+ *+ * Only declared in the 64-bit field build: s2n-bignum is x86-64 and AArch64+ * only, and this interface is the four little-endian 64-bit words those+ * architectures give crypton_p256_int anyway.+ */+#ifndef CRYPTON_P256_S2N_H+#define CRYPTON_P256_S2N_H++#include <stdint.h>++/* res = scalar * point, all of them affine and not in Montgomery form:+ * point is x then y, four words each, and res the same. The point at+ * infinity goes in and comes out as (0, 0). */+void crypton_s2n_p256_scalarmul(uint64_t res[8], const uint64_t scalar[4],+ const uint64_t point[8]);++/* res = scalar * G, the same shape out. The table it reads and the window+ * width it was built for are in cbits/p256/p256_base_table.c, which+ * cbits/p256/gen_base_table.py writes. */+void crypton_s2n_p256_scalarmulbase(uint64_t res[8], const uint64_t scalar[4]);++#endif
+ cbits/p256/gen_base_table.py view
@@ -0,0 +1,126 @@+#!/usr/bin/env python3+"""Build the two tables of multiples of the base point that crypton reads.++ ./gen_base_table.py 5 p256_base_table.c # for p256_scalarmulbase+ ./gen_base_table.py odd 7 p256_wnaf_table.c # for p256_verify.c++Its own words for the layout: for each i, j with blocksize*i <= 256 and+1 <= j <= B, where B = 2^(blocksize-1), the multiple 2^(blocksize*i) * j * P+goes at tab + 64*(B*i + (j-1)), as a Montgomery-affine pair, four+little-endian 64-bit words each.++Five is the blocksize crypton ships: on an Apple M4 it is 6.40 microseconds+against 7.15 for four and 6.10 for six, and the table is 52 KiB against 33+and 88. Nothing outside this file knows the number -- it is written into+the generated file and read from there.++The curve constants come from `openssl ecparam`, not from memory, and the+generated table is checked against crypton's own base-point multiplication+by the test suite, so a mistake here does not pass quietly.+"""+import subprocess, re, sys++def curve():+ out = subprocess.run(["openssl","ecparam","-name","prime256v1",+ "-param_enc","explicit","-text","-noout"],+ capture_output=True, text=True).stdout+ f, cur = {}, None+ for line in out.splitlines():+ m = re.match(r'^(Prime|A|B|Generator \(uncompressed\)|Order):?\s*$', line.strip())+ if m:+ cur = m.group(1); f[cur] = ""; continue+ if cur and re.match(r'^\s+[0-9a-f]{2}[:0-9a-f]*:?\s*$', line):+ f[cur] += line.strip()+ elif cur and line and not line.startswith(' '):+ cur = None+ def num(s):+ return int.from_bytes(bytes(int(v,16) for v in s.strip(':').split(':') if v), 'big')+ g = bytes(int(v,16) for v in f['Generator (uncompressed)'].strip(':').split(':') if v)+ assert g[0] == 4 and len(g) == 65+ return (num(f['Prime']), num(f['A']), num(f['B']),+ int.from_bytes(g[1:33],'big'), int.from_bytes(g[33:],'big'), num(f['Order']))++P, A, B, GX, GY, N = curve()+assert (GY*GY - GX**3 - A*GX - B) % P == 0, "the generator is not on the curve"++def add(p, q):+ if p is None: return q+ if q is None: return p+ (x1,y1),(x2,y2) = p,q+ if x1 == x2:+ if (y1 + y2) % P == 0: return None+ l = (3*x1*x1 + A) * pow(2*y1, -1, P) % P+ else:+ l = (y2-y1) * pow(x2-x1, -1, P) % P+ x3 = (l*l - x1 - x2) % P+ return (x3, (l*(x1-x3) - y1) % P)++R = 1 << 256+def mont(v): return v * R % P+def words(v): return [(v >> (64*k)) & 0xFFFFFFFFFFFFFFFF for k in range(4)]++def table(blocksize):+ Bn = 1 << (blocksize - 1)+ blocks = 256 // blocksize + 1+ out = []+ base = (GX, GY) # 2^(blocksize*i) * P+ for i in range(blocks):+ acc = None+ for j in range(1, Bn + 1):+ acc = add(acc, base) # j * base+ out.append(acc)+ for _ in range(blocksize):+ base = add(base, base)+ return blocks, Bn, out++def odd_table(width):+ """The odd multiples 1P, 3P, ..., (2^(width-1)-1)P, which is what the+ windowed form in cbits/p256/p256_verify.c reads for the base point."""+ n = 1 << (width - 2)+ twice = add((GX, GY), (GX, GY))+ out, acc = [], (GX, GY)+ for _ in range(n):+ out.append(acc)+ acc = add(acc, twice)+ return out++def emit_odd(width, path):+ pts = odd_table(width)+ with open(path, 'w') as fh:+ fh.write("/* Generated by cbits/p256/gen_base_table.py; do not hand-edit.\n"+ " * The odd multiples of the base point, in Montgomery-affine\n"+ " * form, which cbits/p256/p256_verify.c reads. A verification\n"+ " * is public, so this table is walked in variable time. */\n")+ fh.write("#include <stdint.h>\n\n")+ fh.write(f"const uint64_t crypton_p256_wnaf_width = {width};\n\n")+ fh.write(f"const uint64_t crypton_p256_wnaf_table[{len(pts)*8}] = {{\n")+ for (x, y) in pts:+ ws = words(mont(x)) + words(mont(y))+ fh.write("\t" + ",".join(f"0x{w:016x}ULL" for w in ws) + ",\n")+ fh.write("};\n")+ return len(pts), len(pts) * 64++def emit(blocksize, path):+ blocks, Bn, pts = table(blocksize)+ with open(path, 'w') as fh:+ fh.write("/* Generated by cbits/p256/gen_base_table.py; do not hand-edit.\n"+ " * The multiples of the base point that s2n-bignum's\n"+ " * p256_scalarmulbase reads, in Montgomery-affine form. */\n")+ fh.write("#include <stdint.h>\n\n")+ fh.write(f"const uint64_t crypton_p256_s2n_base_blocksize = {blocksize};\n\n")+ fh.write(f"const uint64_t crypton_p256_s2n_base_table[{len(pts)*8}] = {{\n")+ for (x, y) in pts:+ ws = words(mont(x)) + words(mont(y))+ fh.write("\t" + ",".join(f"0x{w:016x}ULL" for w in ws) + ",\n")+ fh.write("};\n")+ return blocks, Bn, len(pts)*64++if __name__ == "__main__":+ if sys.argv[1] == "odd":+ w = int(sys.argv[2]); path = sys.argv[3]+ n, size = emit_odd(w, path)+ print(f"width {w}: {n} odd multiples = {size} bytes")+ else:+ b = int(sys.argv[1]); path = sys.argv[2]+ blocks, Bn, size = emit(b, path)+ print(f"blocksize {b}: {blocks} blocks x {Bn} = {size} bytes")
cbits/p256/p256.c view
@@ -39,6 +39,15 @@ #include "p256/p256.h" +#ifdef CRYPTON_S2N_BIGNUM+extern void bignum_modinv(uint64_t k, uint64_t *z, const uint64_t *a,+ const uint64_t *b, uint64_t *t);+/* the digits are handed over as they lie */+#if P256_BITSPERDIGIT != 64 || P256_NDIGITS != 4+#error "CRYPTON_S2N_BIGNUM wants the 64-bit crypton_p256_int"+#endif+#endif+ const crypton_p256_int crypton_SECP256r1_n = // curve order {{P256_LITERAL(0xfc632551, 0xf3b9cac2), P256_LITERAL(0xa7179e84, 0xbce6faad), P256_LITERAL(-1, -1), P256_LITERAL(0, -1)}};@@ -214,7 +223,11 @@ n %= P256_BITSPERDIGIT; for (i = P256_NDIGITS - 1; i > 0; --i) { crypton_p256_digit accu = (P256_DIGIT(a, i) << n);- accu |= (P256_DIGIT(a, i - 1) >> (P256_BITSPERDIGIT - n));+ /* n is zero as often as it is anything else, and a digit shifted by its+ * own width is undefined: x86 takes the count modulo the width and hands+ * back the whole digit, ARM hands back nothing. Two shifts that are each+ * inside the width say the intended nothing on both. */+ accu |= (P256_DIGIT(a, i - 1) >> (P256_BITSPERDIGIT - 1 - n) >> 1); P256_DIGIT(b, i) = accu; } P256_DIGIT(b, i) = (P256_DIGIT(a, i) << n);@@ -230,7 +243,8 @@ n %= P256_BITSPERDIGIT; for (i = 0; i < P256_NDIGITS - 1; ++i) { crypton_p256_digit accu = (P256_DIGIT(a, i) >> n);- accu |= (P256_DIGIT(a, i + 1) << (P256_BITSPERDIGIT - n));+ /* the same full-width shift as in crypton_p256_shl above */+ accu |= (P256_DIGIT(a, i + 1) << (P256_BITSPERDIGIT - 1 - n) << 1); P256_DIGIT(b, i) = accu; } P256_DIGIT(b, i) = (P256_DIGIT(a, i) >> n);@@ -244,8 +258,11 @@ accu |= (P256_DIGIT(a, i + 1) << (P256_BITSPERDIGIT - 1)); P256_DIGIT(b, i) = accu; }+ /* The shift is unsigned: highbit is a carry, zero or one, and one shifted+ * into the sign bit of the signed digit is an overflow the standard leaves+ * undefined. The value put into b is the same either way. */ P256_DIGIT(b, i) = (P256_DIGIT(a, i) >> 1) |- (((crypton_p256_sdigit) highbit) << (P256_BITSPERDIGIT - 1));+ (((crypton_p256_digit) highbit) << (P256_BITSPERDIGIT - 1)); } // Return -1, 0, 1 for a < b, a == b or a > b respectively.@@ -312,6 +329,22 @@ crypton_p256_int U = *MOD; crypton_p256_int V = *a; + /* Zero has no inverse, and the loop below never finds that out: V stays+ even forever, so it is halved forever, and the only break is in the+ branch both U and V have to be odd to reach. The other input without an+ inverse is MOD itself -- 2*MOD does not fit in 256 bits, so there is no+ third -- and that one already leaves here as zero, which is also what+ Crypto.PubKey.ECC.P256's scalarInvSafe answers for both. Answer the+ same for zero rather than not answering.++ Reachable: Crypto.PubKey.ECC.P256 exports scalarInv, and scalarFromBinary+ accepts any 256 bits. A hang inside a foreign call cannot be interrupted+ by System.Timeout either. */+ if (crypton_p256_is_zero(a)) {+ crypton_p256_clear(b);+ return;+ }+ for (;;) { if (crypton_p256_is_even(&U)) { crypton_p256_shr1(&U, 0, &U);@@ -480,6 +513,16 @@ // b = 1/a mod n, using Fermat's little theorem. void crypton_p256e_scalar_invert(const crypton_p256_int* a, crypton_p256_int* b) {+#ifdef CRYPTON_S2N_BIGNUM+ /* The assembly, which takes a fixed number of division steps instead: 0.80+ * microseconds against 6.02 on an Apple M4. It answers zero where a has no+ * inverse, which is what the chain below does as well, and the caller reads+ * a zero as "no inverse". */+ uint64_t t[12];++ bignum_modinv(4, P256_DIGITS(b), P256_DIGITS(a),+ P256_DIGITS(&crypton_SECP256r1_n), t);+#else crypton_p256_int _1, _10, _11, _101, _111, _1010, _1111; crypton_p256_int _10101, _101010, _101111, x6, x8, x16, x32; int i;@@ -534,4 +577,5 @@ // Demontgomerize crypton_p256e_montmul(b, &crypton_SECP256r1_one, b);+#endif }
+ cbits/p256/p256_base_table.c view
@@ -0,0 +1,841 @@+/* Generated by cbits/p256/gen_base_table.py; do not hand-edit.+ * The multiples of the base point that s2n-bignum's+ * p256_scalarmulbase reads, in Montgomery-affine form. */+#include <stdint.h>++const uint64_t crypton_p256_s2n_base_blocksize = 5;++const uint64_t crypton_p256_s2n_base_table[6656] = {+ 0x79e730d418a9143cULL,0x75ba95fc5fedb601ULL,0x79fb732b77622510ULL,0x18905f76a53755c6ULL,0xddf25357ce95560aULL,0x8b4ab8e4ba19e45cULL,0xd2e88688dd21f325ULL,0x8571ff1825885d85ULL,+ 0x850046d410ddd64dULL,0xaa6ae3c1a433827dULL,0x732205038d1490d9ULL,0xf6bb32e43dcf3a3bULL,0x2f3648d361bee1a5ULL,0x152cd7cbeb236ff8ULL,0x19a8fb0e92042dbeULL,0x78c577510a5b8a3bULL,+ 0xffac3f904eebc127ULL,0xb027f84a087d81fbULL,0x66ad77dd87cbbc98ULL,0x26936a3fb6ff747eULL,0xb04c5c1fc983a7ebULL,0x583e47ad0861fe1aULL,0x788208311a2ee98eULL,0xd5f06a29e587cc07ULL,+ 0x74b0b50d46918dccULL,0x4650a6edc623c173ULL,0x0cdaacace8100af2ULL,0x577362f541b0176bULL,0x2d96f24ce4cbaba6ULL,0x17628471fad6f447ULL,0x6b6c36dee5ddd22eULL,0x84b14c394c5ab863ULL,+ 0xbe1b8aaec45c61f5ULL,0x90ec649a94b9537dULL,0x941cb5aad076c20cULL,0xc9079605890523c8ULL,0xeb309b4ae7ba4f10ULL,0x73c568efe5eb882bULL,0x3540a9877e7a1f68ULL,0x73a076bb2dd1e916ULL,+ 0x403947373e77664aULL,0x55ae744f346cee3eULL,0xd50a961a5b17a3adULL,0x13074b5954213673ULL,0x93d36220d377e44bULL,0x299c2b53adff14b5ULL,0xf424d44cef639f11ULL,0xa4c9916d4a07f75fULL,+ 0x0746354ea0173b4fULL,0x2bd20213d23c00f7ULL,0xf43eaab50c23bb08ULL,0x13ba5119c3123e03ULL,0x2847d0303f5b9d4dULL,0x6742f2f25da67bddULL,0xef933bdc77c94195ULL,0xeaedd9156e240867ULL,+ 0x27f14cd19499a78fULL,0x462ab5c56f9b3455ULL,0x8f90f02af02cfc6bULL,0xb763891eb265230dULL,0xf59da3a9532d4977ULL,0x21e3327dcf9eba15ULL,0x123c7b84be60bbf0ULL,0x56ec12f27706df76ULL,+ 0x75c96e8f264e20e8ULL,0xabe6bfed59a7a841ULL,0x2cc09c0444c8eb00ULL,0xe05b3080f0c4e16bULL,0x1eb7777aa45f3314ULL,0x56af7bedce5d45e3ULL,0x2b6e019a88b12f1aULL,0x086659cdfd835f9bULL,+ 0x2c18dbd19dc21ec8ULL,0x98f9868a0fcf8139ULL,0x737d2cd648250b49ULL,0xcc61c94724b3428fULL,0x0c2b407880dd9e76ULL,0xc43a8991383fbe08ULL,0x5f7d2d65779be5d2ULL,0x78719a54eb3b4ab5ULL,+ 0xea7d260a6245e404ULL,0x9de407956e7fdfe0ULL,0x1ff3a4158dac1ab5ULL,0x3e7090f1649c9073ULL,0x1a7685612b944e88ULL,0x250f939ee57f61c8ULL,0x0c0daa891ead643dULL,0x68930023e125b88eULL,+ 0x04b71aa7d2697768ULL,0xabdedef5ca345a33ULL,0x2409d29dee37385eULL,0x4ee1df77cb83e156ULL,0x0cac12d91cbb5b43ULL,0x170ed2f6ca895637ULL,0x28228cfa8ade6d66ULL,0x7ff57c9553238acaULL,+ 0xccc425634b2ed709ULL,0x0e356769856fd30dULL,0xbcbcd43f559e9811ULL,0x738477ac5395b759ULL,0x35752b90c00ee17fULL,0x68748390742ed2e3ULL,0x7cd06422bd1f5bc1ULL,0xfbc08769c9e7b797ULL,+ 0xa242a35bb0cf664aULL,0x126e48f77f9707e3ULL,0x1717bf54c6832660ULL,0xfaae7332fd12c72eULL,0x27b52db7995d586bULL,0xbe29569e832237c2ULL,0xe8e4193e2a65e7dbULL,0x152706dc2eaa1bbbULL,+ 0x72bcd8b7bc60055bULL,0x03cc23ee56e27e4bULL,0xee337424e4819370ULL,0xe2aa0e430ad3da09ULL,0x40b8524f6383c45dULL,0xd766355442a41b25ULL,0x64efa6de778a4797ULL,0x2042170a7079adf4ULL,+ 0x808b0b650bc6fb80ULL,0x5882e0753ffe2e6bULL,0xd5ef2f7c2c83f549ULL,0x54d63c809103b723ULL,0xf2f11bd652a23f9bULL,0x3670c3194b0b6587ULL,0x55c4623bb1580e9eULL,0x64edf7b201efe220ULL,+ 0xd8c5fccfc5e3a3d8ULL,0xbefd904c4079dfbfULL,0xbc6d6a58fead0197ULL,0x39227077695532a4ULL,0x09e23e6ddbef42f5ULL,0x7e449b64480a9908ULL,0x7b969c1aad9a2e40ULL,0x6231d7929591c2a4ULL,+ 0xdb6d96f305968b80ULL,0x380a0913089f73b9ULL,0x7da70b83c2c61e01ULL,0x95fb8394569b38c7ULL,0x9a3c651280edfe2fULL,0x8f726bb98faeaf82ULL,0x8010a4a078424bf8ULL,0x296720440e844970ULL,+ 0x802b8d2333e12b70ULL,0x6d490a4b19dd329bULL,0x14f356cc6abc354dULL,0x11eddf7fd0a0da0dULL,0x1e208328d87fd1d8ULL,0xfd2f4f8cfd025813ULL,0x03b48cc47c29bca2ULL,0x3f2a78b3241a2b71ULL,+ 0x63c5cb817a2ad62aULL,0x7ef2b6b9ac62ff54ULL,0x3749bba4b3ad9db5ULL,0xad311f2c46d5a617ULL,0xb77a8087c2ff3b6dULL,0xb46feaf3367834ffULL,0xf8aa266d75d6b138ULL,0xfa38d320ec008188ULL,+ 0xc04afa1ae3451a09ULL,0x7cc69103bc117423ULL,0x876be3aa51cf56eeULL,0xe7577d57ad844a25ULL,0x266fed8cdb77f341ULL,0xcfa258dc23ae4a2aULL,0x53a7a98cda782760ULL,0x04b48868ceaf7d4aULL,+ 0xc0f2affc4e6916c6ULL,0x6fb94957811842daULL,0x6034bcb624b4d157ULL,0xde2efdc7992efb90ULL,0xd66f7eceac793c87ULL,0x02f026267dc6fdcdULL,0x90d3235c9aa1c501ULL,0xf6e494962b4666f0ULL,+ 0x082736d19c0859c3ULL,0x89ea5516b269386aULL,0xf25071871aa87b33ULL,0xe9d82f5f704e8236ULL,0x7834612442e855f5ULL,0x209f50fe395e00d8ULL,0xcd9e03aae6e7e62bULL,0xb4b4959e5e5be37bULL,+ 0x486d8ffa696946fcULL,0x50fbc6d8b9cba56dULL,0x7e3d423e90f35a15ULL,0x7c3da195c0dd962cULL,0xe673fdb03cfd5d8bULL,0x0704b7c2889dfca5ULL,0xf6ce581ff52305aaULL,0x399d49eb914d5e53ULL,+ 0x7966afbb10e6d950ULL,0x37e4a4c4e2bf970aULL,0x23d0c8559d54ca2aULL,0x13d62865fee39a10ULL,0x15f53c38d3bd15e9ULL,0x014b8bed84a80bccULL,0x10674c77bfd8f608ULL,0x4dfab986c93fbfefULL,+ 0x24c97c367b92d453ULL,0xd2c271a2249a26c0ULL,0x60eb4b2b89d14a39ULL,0x1198de20432e8005ULL,0x9eabea75799b80d9ULL,0xab6e0c2b8f826ae5ULL,0xca004eedd10061ecULL,0x31a9f439e99c4fd8ULL,+ 0x734c8b75b5498a7cULL,0xaeccad8a29f64c2dULL,0x95dd54fa295b1677ULL,0x383902a0b4c54968ULL,0x78cb276feb9d33a9ULL,0x00aedca1af552869ULL,0xa01d14594c5c1630ULL,0xfeba17067cf7d50dULL,+ 0x380a496d6ec293cdULL,0x733dbda78e7051f5ULL,0x037e388db849140aULL,0xee4b32b05946dbf6ULL,0xb1c4fda9cae368d1ULL,0x5001a7b0fdb0b2f3ULL,0x6df593742e3ac46eULL,0x4af675f239b3e656ULL,+ 0x1a1fffdcc01b0a46ULL,0x07ad675f83f843c2ULL,0xbcec2d076738e81aULL,0x910aec75aa8b7da8ULL,0x13b4d740a4509ba7ULL,0x057010734c7b8216ULL,0x3d75c8f71591f1e5ULL,0x134c1b6f0dfe1d90ULL,+ 0xb20e7c44d67826ebULL,0x1212d3cfac379637ULL,0x614f67877de03a5dULL,0x7538a2fc802baa26ULL,0x133c37a19d252415ULL,0x7db390506eb4b587ULL,0x5d40d7574c49d1d9ULL,0xf1126b99a801c4baULL,+ 0x39a7aeb9c56729fcULL,0x21a59448e7a8bd85ULL,0xd7c6da5d049d10c6ULL,0x93a4c4a8c5197afbULL,0xd185539c25933861ULL,0x4994bcba27494d9dULL,0xef033de14ce7bfa9ULL,0x22e9b000321f9236ULL,+ 0x44e3811039949296ULL,0x5b63827b361db1b5ULL,0x3e5323ed206eaff5ULL,0x942370d2c21f4290ULL,0xf2caaf2ee0d985a1ULL,0x192cc64b7239846dULL,0x7c0b8f47ae6312f8ULL,0x7dc61f9196620108ULL,+ 0x4f7081e144cc3addULL,0xd5ffa1d687be82cfULL,0x89890b6c0edd6472ULL,0xada26e1a3ed17863ULL,0x276f271563483caaULL,0xe6924cd92f6077fdULL,0x05a7fe980a466e3cULL,0xf1c794b0b1902d1fULL,+ 0x3d2b24b9eb7926b8ULL,0xbff88cb3cdbe5509ULL,0xd0f399afe4dd640bULL,0x3c5fe1302f76ed45ULL,0x6f3562f43764fb3dULL,0x7b5af3183151b62dULL,0xd5bd0bc7d79ce5f3ULL,0xfdaf6b20ec66890fULL,+ 0x32027fe891e5d7d3ULL,0xf14b7d1773a07678ULL,0xf88497b3c0dfdd61ULL,0xf7c2eec02a8c4f48ULL,0xaa5573f43756e621ULL,0xc013a2401825b948ULL,0x1c03b34563878572ULL,0xa0472bea653a4184ULL,+ 0x6772b0e5ab4b35a2ULL,0x1d8b6001f5eeaacfULL,0x728f7ce4795b9580ULL,0x4a20ed2a41fb81daULL,0x9f685cd44fec01e6ULL,0x3ed7ddcca7ff50adULL,0x460fd2640c2d97fdULL,0x3a241426eb82f4f9ULL,+ 0x29ae2cf983dfedc9ULL,0xf84371348d87631aULL,0xaf5717117429c8d2ULL,0x18d15867146d9272ULL,0x83053ecf69769bb7ULL,0xc55eb856c479ab82ULL,0x5ef7791c21b0f4b2ULL,0xaa5956ba3d491525ULL,+ 0x84cfbfa1c5c5ea50ULL,0xd3baf14c67960681ULL,0x263984030dd50942ULL,0xe4b7839c4716a663ULL,0xd5f1f794e7de6dc0ULL,0x5cd0f4d4622aa7ceULL,0x5295f3f159acfeecULL,0x8d933552953e0607ULL,+ 0xe652533b3cef0d7dULL,0xd94f7b182bbb4381ULL,0x838752be0e80f500ULL,0x8e6e24889e9c9bfbULL,0xc975169716caca6aULL,0x866c49d838531ad9ULL,0xc917e2397151ade1ULL,0x2d016ec16037c407ULL,+ 0x80009862d5d721d5ULL,0x0c3357a35bd3a182ULL,0x27f3a83b7aa2cda4ULL,0xb58ae74ef6f83085ULL,0x2a911a812e6dad6bULL,0xde286051f43d6c5bULL,0x4bdccc41f996c4d8ULL,0xe7312ec00ae1e24eULL,+ 0x903f6e3960e913afULL,0xb2b58bee98bf140dULL,0x9deff025354890b8ULL,0x155810068d2e924eULL,0xb5755db493c95e5bULL,0x3fac42f0dae20eb8ULL,0x9377c8c109b6d8e0ULL,0xa43e2b46ab47ceffULL,+ 0x5f57b2fbfacfa459ULL,0x874b1498c1b5aa6bULL,0xb9e89acac4db2092ULL,0x1362bf8ddf4381daULL,0x25d76830b76328a0ULL,0x38188b7098572ae4ULL,0xb43e941429132f7dULL,0x7895a29f22dd42c9ULL,+ 0xcbde78dd5e22cbb2ULL,0xf449c85b76bb4391ULL,0x4289f357b6a4273bULL,0x9fce23fd48e84a19ULL,0xcfc32730939eb3b4ULL,0x8b3d982c16c32280ULL,0x5ac234bad5f1346cULL,0x781954b470769fc9ULL,+ 0x6faf68feaae6ee70ULL,0x78f4cc155602b0c9ULL,0x7e3321a86e94052aULL,0x2fb3a0d6734d5d80ULL,0xf3b98f3bb25a43baULL,0x30bf803119ee2951ULL,0x7ffee43321b0612aULL,0x12f775e42eb821d0ULL,+ 0x4fdff805f57209b5ULL,0x9bd65ac3f952ac8dULL,0x02a3abd3c7969a6fULL,0x1359927ef523775fULL,0xe09b463f88d2e861ULL,0x661d2199623287c3ULL,0x821e64495a70eb7aULL,0x0afbbb1dd67dc684ULL,+ 0x7418e3d3acff89f9ULL,0x227f16aed852251fULL,0xdd5bc6e4eb84658bULL,0xf066b9c8f90a9f7eULL,0xc2369071800a7f87ULL,0x383ddc0d5a72862aULL,0x5b48465d8a776da5ULL,0x3d82f64f5e2d8318ULL,+ 0x5852104b87453b28ULL,0x073e8128b387344dULL,0x300e78e4817cfc08ULL,0x3a82ed4799362088ULL,0xe222304c88de46a4ULL,0x666c94fd57fadf4aULL,0x40b2d08ea0c8e108ULL,0x4b2955b909e050faULL,+ 0xf8d112e76e6485b3ULL,0x4d3e24db771c52f8ULL,0x48e3ee41684a2f6dULL,0x7161957d21d95551ULL,0x19631283cdb12a6cULL,0xbf3fa8822e50e164ULL,0xf6254b633166cc73ULL,0x3aefa7aeaee8cc38ULL,+ 0x79b0fe623b36f9fdULL,0x26543b23fde19fc0ULL,0x136e64a0958482efULL,0x23f637719b095825ULL,0x14cfd596b6a1142eULL,0x5ea6aac6335aac0bULL,0x86a0e8bdf3081dd5ULL,0x5fb89d79003dc12aULL,+ 0x0f0165fce3779ee3ULL,0xe00e7f9dbd495d9eULL,0x1fa4efa220284e7aULL,0x4564bade47ac6219ULL,0x90e6312ac4708e8eULL,0x4f5725fba71e9adfULL,0xe95f55ae3d684b9fULL,0x47f7ccb11e94b415ULL,+ 0xda3a77e5522e6b69ULL,0x69c908c3bbcd6c18ULL,0x1f1b9e48d924fd56ULL,0x37c64e36aa4bb3f7ULL,0x5a4fdbdfee478d7dULL,0xba75c8bc0193f7a0ULL,0x84bc1e8456cd16dfULL,0x1fb08f0846fad151ULL,+ 0x3617890361a341c1ULL,0x3604dc600cfd6142ULL,0x022295eb8533316cULL,0x3dbde4ac44af2922ULL,0x898afc5d1c7eef69ULL,0x58896805d14f4fa1ULL,0x05002160203c21caULL,0x6f0d1f3040ef730bULL,+ 0x48201b4b12cfe297ULL,0x3eee129c292f74e5ULL,0xe1fe114ec9e874e8ULL,0x899b055c92c5fc41ULL,0x4e477a643a39c8cfULL,0x82f09efe78963cc9ULL,0x6fd3fd8fd333f863ULL,0x85132b2adc949c63ULL,+ 0xbd9b8b1dbe7a2af3ULL,0xec51caa94fb74a72ULL,0xb9937a4b63879697ULL,0x7c9a9d20ec2687d5ULL,0x1773e44f6ef5f014ULL,0x8abcf412e90c6900ULL,0x387bd0228142161eULL,0x50393755fcb6ff2aULL,+ 0x766e072232398baaULL,0x205fee425cfca031ULL,0xa49f53417a029cf2ULL,0xa88c68b84023890dULL,0xbc2750417337aaa8ULL,0x9ed364ad0eb384f4ULL,0xe0816f8529aba92fULL,0x2e9e194104e38a88ULL,+ 0xfabf770977f7195aULL,0x8ec86167adeb838fULL,0xea1285a8bb4f012dULL,0xd68835039a3eab3fULL,0xee5d24f8309004c2ULL,0xa96e4b7613ffe95eULL,0x0cdffe12bd223ea4ULL,0x8f5c2ee5b6739a53ULL,+ 0xecace1dda1887395ULL,0x40960f36932a65deULL,0x9611ff5c3aa95529ULL,0xc58215b07c1e5a36ULL,0xd48c9b58f0e1a524ULL,0xb406856bf590dfb8ULL,0xc7605e049cd95662ULL,0x0dd036eea33ecf82ULL,+ 0x3d61333959145a65ULL,0xcd9bc368fa406337ULL,0x82d11be32d8a52a0ULL,0xf6877b2797a1c590ULL,0x837a819bf5cbdb25ULL,0x2a4fd1d8de090249ULL,0x622a7de774990e5fULL,0x840fa5a07945511bULL,+ 0xfe2893277946d3f9ULL,0xe132bd2407472273ULL,0xeeeb510c1eb6ae86ULL,0x777708c5f0595067ULL,0x18e2c8cd1297029eULL,0x2c61095cbbf9305eULL,0xe466c2586b85d6d9ULL,0x8ac06c36da1ea530ULL,+ 0xe58e90b36b0cf82eULL,0x6438d2462615b5e7ULL,0x07b1f8fc669c145aULL,0xb0d8b2da36f1e1cbULL,0x54d5dadbd9184c4dULL,0x3dbb18d5f93d9976ULL,0x0a3e0f56d1147d47ULL,0x2afa8c8da0a48609ULL,+ 0x871239ad653ae326ULL,0x14bcf72aa74cbb43ULL,0x8737650e20d4c083ULL,0x3df86536110ed4afULL,0xd2d86fe7b53ca555ULL,0x688cb00dabd5d538ULL,0xcf81bda31ad38468ULL,0x7ccfe3ccf01167b6ULL,+ 0x26e08c07e3533d77ULL,0xd7222e6a2e341c99ULL,0x9d60ec3d8d2dc4edULL,0xbdfe0d8f7c476cf8ULL,0x1fe59ab61d056605ULL,0xa9ea9df686a8551fULL,0x8489941e47fb8d8cULL,0xfeb874eb4a7f1b10ULL,+ 0x61fc181060a71676ULL,0xe852d1a8f66a8ad1ULL,0x172bbd656417231eULL,0x0d6de7bd3babb11fULL,0x6fde6f88c8e347f8ULL,0x1c5875479bd99cc3ULL,0x78e54ed034076950ULL,0x97f0f334796e83baULL,+ 0xed406aa9bd763802ULL,0xc21486a065303da1ULL,0x61ae291ec7e62ec4ULL,0x622a0492df99333eULL,0x7fd80c9dbb7a8ee0ULL,0xdc2ed3bc6c01aedbULL,0x35c35a1208be74ecULL,0xd540cb1a469f671fULL,+ 0xa7a8746a584c5e20ULL,0x267e4ea1b9dc7035ULL,0x593a15cfb9548c9bULL,0x5e6e21354bd012f3ULL,0xdf31cc6a8c8f936eULL,0x8af84d04b5c241dcULL,0x63990a6f345efb86ULL,0x6fef4e61b9b962cbULL,+ 0xf6368f0925722608ULL,0x131260db131cf5c6ULL,0x40eb353bfab4f7acULL,0x85c7888037eee829ULL,0x4c1581ffc3bdf24eULL,0x5bff75cbf5c3c5a8ULL,0x35e8c83fa14e6f40ULL,0xb81d1c0f0295e0caULL,+ 0xf2efe23d442a8ad1ULL,0xc3816a7d06b9c164ULL,0xa9df2d8bdc0aa5e5ULL,0x191ae46f120a8e65ULL,0x83667f8700611c5bULL,0x83171ed7ff109948ULL,0x33a2ecf8ca695952ULL,0xfa4a73eef48d1a13ULL,+ 0xfcde7cc8f43a730fULL,0xe89b6f3c33ab590eULL,0xc823f529ad03240bULL,0x82b79afe98bea5dbULL,0x568f2856962fe5deULL,0x0c590adb60c591f3ULL,0x1fc74a144a28a858ULL,0x3b662498b3203f4cULL,+ 0x48fc4ed082dd1b6aULL,0x5783a13867b703afULL,0x2463cb9a005d6aaaULL,0xd31ec55c706ecd43ULL,0x9f8ed33f8e9a7641ULL,0x625453ed098d9e7aULL,0xa3beade4ec887493ULL,0x442b80505a795566ULL,+ 0x91e3cf0d6c39765aULL,0xa2db3acdac3cca0bULL,0x288f2f08cb953b50ULL,0x2414582ccf43cf1aULL,0x8dec8bbc60eee9a8ULL,0x54c79f02729aa042ULL,0xd81cd5ec6532f5d5ULL,0xa672303acf82e15fULL,+ 0x46df582d3bfab839ULL,0x92474e042f8adadeULL,0x36a7766a147a1bc3ULL,0xb6940f540dc0f979ULL,0x44738ef2f2759f25ULL,0x9dd95789a719f4c6ULL,0x2859b7f40750c345ULL,0x5e788bf2b22180d5ULL,+ 0x376aafa8719c0563ULL,0xcd8ad2dcbc5fc79fULL,0x303fdb9fcb750cd3ULL,0x14ff052f4418b08eULL,0xf75084cf3e2d6520ULL,0x7ebdf0f8144ed509ULL,0xf43bf0f2d3f25b98ULL,0x86ad71cfa354d837ULL,+ 0xa839c9fdfd67ca25ULL,0x023e626860f2015cULL,0x2414a7930e7b2a65ULL,0x92dbe372b13edcbbULL,0xf64981ee64c2200fULL,0x94fb9cdf8446f2f3ULL,0x01411a6a3f1367bbULL,0x7985c1915a1e8331ULL,+ 0xb827fe9226f43572ULL,0xdfd3ab5b5d824758ULL,0x315dd23a539094c1ULL,0x85c0e37a66623d68ULL,0x575c79727be19ae0ULL,0x616a3396df0d36b5ULL,0xa1ebb3c826b1ff7eULL,0x635b9485140ad453ULL,+ 0xc8123c6037e2efeaULL,0x8d49b502034a96f6ULL,0x466a346b973e4a95ULL,0xf176b5bab7de00ffULL,0x1c58fa3b82dfa945ULL,0x2eb27a9609e429aeULL,0x57c67a67a12b187cULL,0xb155ba82e2298bbaULL,+ 0x92bf3cdada430c0bULL,0x4702850e3a96dac6ULL,0xc91cf0a515ac326aULL,0x95de4f49ab8c25e4ULL,0xb01bad09e265c17cULL,0x24e45464087b3881ULL,0xd43e583ce1fac5caULL,0xe17cb3186ead97a6ULL,+ 0xf1a542073d99bcfaULL,0x59db703ce8becf6dULL,0x2e455142d2459569ULL,0xb0ee5143a901b910ULL,0xfc05d451e26d994fULL,0x7a6062b41360caafULL,0xdf1ded5f4fa639b1ULL,0xaf930348d335b8b0ULL,+ 0x6cc3924374dcec46ULL,0x33cfc02d54c2b73fULL,0x82917844f26cd99cULL,0x8819dd95d1773f89ULL,0x09572aa60871f427ULL,0x8e0cf365f6f01c34ULL,0x7fa52988bff1f5afULL,0x4eb357eae75e8e50ULL,+ 0x3d8f248a21fd0861ULL,0xade3bd649bd5a4b6ULL,0xcb56c953c2e2a6bfULL,0x699cd2b5287d6c5fULL,0xdebce1be47d05e8fULL,0x1a4fbb13a8f53732ULL,0x97163beaa5852b08ULL,0x92c49e6ceec6987aULL,+ 0xd9d0c8c4868af75dULL,0xd7325cff45c8c7eaULL,0xab471996cc81ecb0ULL,0xff5d55f3611824edULL,0xbe3145411977a0eeULL,0x5085c4c5722038c6ULL,0x2d5335bff94bb495ULL,0x894ad8a6c8e2a082ULL,+ 0x540234b22c11bb37ULL,0x2d0366dded4c74a3ULL,0xf9a968daeec5f25dULL,0x3660106867b63142ULL,0x07cd6d2c68d7b6d4ULL,0xa8f74f090c842942ULL,0xe27514047768b1eeULL,0x4b5f7e89fe62aee4ULL,+ 0xf2369f0b879fbbedULL,0x0ff0ae86da9d1869ULL,0x5251d75956766f45ULL,0x4984d8c02be8d0fcULL,0x7ecc95a6d21008f0ULL,0x29bd54a03a1a1c49ULL,0xab9828c5d26c50f3ULL,0x32c0087c51d0d251ULL,+ 0x47feeb6662b5f3afULL,0xcefab5610abb3734ULL,0x449de60e19f35cb1ULL,0x39f8db14157f0eb9ULL,0xffaecc5b3c61bfd6ULL,0xa5a4d41d41216703ULL,0x7f8fabed224e1cc2ULL,0x0d5a8186871ad953ULL,+ 0x190d8ea601799a52ULL,0xa20cec41b86d2952ULL,0x3062ffb27fff2a7cULL,0x741b32e579f19d37ULL,0xf80d81814eb57d47ULL,0x7a2d0ed416aef06bULL,0x09735fb01cecb588ULL,0x1641caaac6061f5bULL,+ 0xae2ad171656e8c3aULL,0xc0e2a4631acd0705ULL,0x006f6a8aa0b6055cULL,0xaf4513d72b65a26eULL,0x3f549e14d616d5bcULL,0x64ee395571253b1fULL,0xe8b10bc1b8ce243aULL,0xbcbeace5913a4e77ULL,+ 0x68d32256f779d6a7ULL,0x20423b4d19e7284eULL,0xde19aa1b38f3b153ULL,0x73d0b6c28444f703ULL,0x666161489c64e6a3ULL,0x99587c3737256224ULL,0x6f5277fe61331563ULL,0x7174ad4aa656502eULL,+ 0xec1ffc920133918dULL,0x15d9bf5eb2c9ef97ULL,0x7885b542fc6cbb9aULL,0x8abe64535720cf5dULL,0x4e715dced4ec68abULL,0x57a67614279c24a3ULL,0x788ed52a31bb61cfULL,0xaba82444f437a003ULL,+ 0x7f99824f20151427ULL,0x206828b692430206ULL,0xaa9097d7e1112357ULL,0xacf9a2f209e414ecULL,0xdbdac9da27915356ULL,0x7e0734b7001efee3ULL,0x54fab5bbd2b288e2ULL,0x4c630fc4f62dd09cULL,+ 0x6d883e66bd70a5e1ULL,0x9bd884c1d05de713ULL,0x48d9d445d4d8487dULL,0x8440cd8b0eeae405ULL,0xa3cd0f293d26f83eULL,0x3fd9453022a3c5e4ULL,0x63a078663ffa2ca7ULL,0xbfeadd2900d4a097ULL,+ 0x13aea559d68432baULL,0x940043fbd33915dbULL,0x476c7c94e2e8da08ULL,0x6b1630c4443065bbULL,0xd6d8546d19f06c75ULL,0x7e1e98c22eb35abdULL,0x751c9310f0157d8eULL,0xdef84327f6fa6075ULL,+ 0x765b993c3a7a4e0eULL,0xfb8f4aef9d79d314ULL,0x5ea2c50e2a19eb24ULL,0x925016e5b891bc8cULL,0x8f70afdc3ad1ece7ULL,0x0abba84cf08fabe2ULL,0x0a9922c815f6132bULL,0x6c0213735d076d77ULL,+ 0x00af2615a4453961ULL,0x1705494b993d112cULL,0x0032e12aa1cdd652ULL,0x0ebfa612046d9cb3ULL,0x9f03a9f31b63728cULL,0x8f3618a2de022b05ULL,0xd5b24d903e77c5c9ULL,0x837838a372acb77cULL,+ 0xfe65cbd98fceb047ULL,0xde872ef53f8b11a1ULL,0x9aba0d3d8fec802fULL,0x139f1d329a9f381dULL,0x0721aed9c587958dULL,0x066a015cb9f6a7daULL,0x059ec4e3ed5d9d06ULL,0x144285716cbaca1fULL,+ 0x66fe0fffe298cdf5ULL,0x3f61bea47b2e51b6ULL,0x7d372117bad3afa4ULL,0x6521a09cef656e2fULL,0xb3b8c966e8a58fe7ULL,0x25203a115a47ebc7ULL,0xfe81588d5c4be573ULL,0x6132e2f31f49a03cULL,+ 0xec1ab0130f8c2c99ULL,0x60e8968ff17725c2ULL,0xe1a4a593940a980bULL,0x15ed15b020e9ccb1ULL,0x77d754cc64a00becULL,0x90d09c3341687382ULL,0x294fe02dc31fb651ULL,0x8372cd1a1c94ae53ULL,+ 0x8537107a1ac2703bULL,0xb49258d86bc857b5ULL,0x57df14debcdaccd1ULL,0x24ab68d7c4ae8529ULL,0x7ed8b5d4734e59d0ULL,0x5f8740c8c495cc80ULL,0x84aedd5a291db9b3ULL,0x80b360f84fb995beULL,+ 0x55d5c68da61a76faULL,0x598b441dca1554dcULL,0xd39923b9773b279cULL,0x33331d3c36bf9efcULL,0x2d4c848e298de399ULL,0xcfdb8e77a1a27f56ULL,0x94c855ea57b8ab70ULL,0xdcdb9dae6f7879baULL,+ 0x4c4f07367f636a38ULL,0x9f943fb70e76d5cbULL,0xb03510baa8b68b8bULL,0xc246780a9ed07a1fULL,0x3c0514156d549fc2ULL,0xc2953f31607781caULL,0x955e2c69d8d95413ULL,0xb300fadc7bd282e3ULL,+ 0xa14b1163c27901b4ULL,0xfd9236e0899b8bf3ULL,0x42b091eccbc6da0aULL,0xbb1dac6f5ad1d297ULL,0x80e61d53a91cf76eULL,0x4110a412d31f1ee7ULL,0x2d87c3ba13efcf77ULL,0x1f374bb4df450d76ULL,+ 0x202886024147519aULL,0xd0981eac26b372f0ULL,0xa9d4a7caa785ebc8ULL,0xd953c50ddbdf58e9ULL,0x9d6361ccfd590f8fULL,0x72e9626b44e6c917ULL,0x7fd9611022eb64cfULL,0x863ebb7e9eb288f3ULL,+ 0x15e10a0a097e4403ULL,0xcb3d0a8619854665ULL,0x88d8e211d67d4826ULL,0xb39af66e0b9d2839ULL,0xa5f94588bd475ca8ULL,0xe06b7966c077b80bULL,0xfedb1485da27c26cULL,0xd290d33afe0fd5e0ULL,+ 0x686202f31306583dULL,0x05b10da0437c622eULL,0xbf9aaa0f076a7bc8ULL,0x25e94efb8f8f4e43ULL,0x8a35c9b7fa3dc26dULL,0xe0e5fb9396ff03c5ULL,0xa77e3843ebc394ceULL,0xcede65958361de60ULL,+ 0xbf9075090c22b540ULL,0x2cde42aab7c267d4ULL,0xba18f9ed5ab0d693ULL,0x3ba62aa66e4660d9ULL,0xb24bf97bab9ea96aULL,0x5d039642e3b60e32ULL,0x4e6a45067c4d9bd5ULL,0x666c5b9e7ed4a6a4ULL,+ 0x877b7cf5678a31b0ULL,0xd50301ae3998b620ULL,0x734257c5c00fb396ULL,0xf9fb18a004e672a6ULL,0xff8bd8ebe8758851ULL,0x1e64e4c65d99ba44ULL,0x4b8eaedf7dfd93b7ULL,0xba2f2a9804e76b8cULL,+ 0xae02a2f09b56ddbdULL,0x1339b5ac8a2f1cf3ULL,0xf2b569c7839dff0dULL,0xb0b9e864fee9a43dULL,0x4ff8ca4177bb064eULL,0x145a2812fd249f63ULL,0x3ab7beacf86f689aULL,0x9bafec2701d35f5eULL,+ 0xbba23fddae57c7b7ULL,0x345342f21b932522ULL,0xfd9c80fe556d4aa3ULL,0xa03907ba6525bb61ULL,0x38b010e1ff218933ULL,0xc066b654aa52117bULL,0x8e14192094f2e6eaULL,0x66a27dca0d32f2b2ULL,+ 0xb2e6b121fbabbe92ULL,0x281850fbe1330076ULL,0x093581ec97890015ULL,0x69b1dded75ff77f5ULL,0x7cf0b18fab105105ULL,0x953ced31a89ccfefULL,0x3151f85feb914009ULL,0x3c9f1b8788ed48adULL,+ 0xa18f07e0e90fb21eULL,0x00fd2b80bba7fca1ULL,0x20387f2795cd67b5ULL,0x5b89a4e7d39707f7ULL,0x8f83ad3f894407ceULL,0xa0025b946c226132ULL,0xc79563c7f906c13bULL,0x5f548f314e7bb025ULL,+ 0xff7589494fde0c1fULL,0xbf8a1abee5b6ec20ULL,0x702278fb87e1db6cULL,0xc447ad7a35ed658fULL,0x48d4aa3803d0ccf2ULL,0x80acb338819a7c03ULL,0x9bc7c89e6e17ceccULL,0x46736b8b03be1d82ULL,+ 0x2126f742d43b5eaaULL,0x054a0766dfa59b85ULL,0x9d0d5e36126bfd45ULL,0xa1f8fbd7384f8a8fULL,0x317680f5d563fcccULL,0x48ca5055f280a928ULL,0xe00b81b227b578cfULL,0x10aad9182994a514ULL,+ 0xe63f301f358bcdc0ULL,0x07689e990a9d47f8ULL,0x1f689e2f4f43d43aULL,0x4d542a1690920904ULL,0xaea293d59ca0a707ULL,0xd061fe458ac68065ULL,0x1033bf1b0090008cULL,0x29749558c08a6db6ULL,+ 0x0ee6d3a7c35d8794ULL,0x042e65580356bae5ULL,0x9f59698d643322fdULL,0x9379ae1550a61967ULL,0x64b9ae62fcc9981eULL,0xaed3d6316d2934c6ULL,0x2454b3025e4e65ebULL,0xab09f647f9950428ULL,+ 0xb2083a1222248accULL,0x1f6ec0ef3264e366ULL,0x5659b7045afdee28ULL,0x7a823a40e6430bb5ULL,0x24592a04e1900a79ULL,0xcde09d4ac9ee6576ULL,0x52b6463f4b5ea54aULL,0x1efe9ed3d3ca65a7ULL,+ 0xe27a6dbe305406ddULL,0x8eb7dc7fdd5d1957ULL,0xf54a6876387d4d8fULL,0x9c479409c7762de4ULL,0xbe4d5b5d99b30778ULL,0x25380c566e793682ULL,0x602d37f3dac740e3ULL,0x140deabe1566e4aeULL,+ 0x4481d067afd32acfULL,0xd8f0fccae1f71ccfULL,0xd208dd0cb596f2daULL,0xd049d7309aad93f9ULL,0xc79f263d42ab580eULL,0x09411bb123f707b4ULL,0x8cfde1ff835e0edaULL,0x7270749090f03402ULL,+ 0xeaee6126c49a861eULL,0x024f3b65e14f0d06ULL,0x51a3f1e8c69bfc17ULL,0xc3c3a8e9a7686381ULL,0x3400752cb103d4c8ULL,0x02bc46139218b36bULL,0xc67f75eb7651504aULL,0xd6848b56d02aebfaULL,+ 0xbd9802e6c30fa92bULL,0x5a70d96d9a552784ULL,0x9085c4ea3f83169bULL,0xfa9423bb06908228ULL,0x2ffebe12fe97a5b9ULL,0x85da604971b99118ULL,0x9cbc2f7f63178846ULL,0xfd96bc709153218eULL,+ 0x958381db1782269bULL,0xae34bf792597e550ULL,0xbb5c60645f385153ULL,0x6f0e96afe3088048ULL,0xbf6a021577884456ULL,0xb3b5688c69310ea7ULL,0x17c9429504fad2deULL,0xe020f0e517896d4dULL,+ 0x730ba0ab0976505fULL,0x567f6813095e2ec5ULL,0x470620106331ab71ULL,0x72cfa97741d22b9fULL,0x33e55ead8a2373daULL,0xa8d0d5f47ba45a68ULL,0xba1d8f9c03029d15ULL,0x8f34f1ccfc55b9f3ULL,+ 0xcca4428dbbe5a1a9ULL,0x8187fd5f3126bd67ULL,0x0036973a48105826ULL,0xa39b6663b8bd61a0ULL,0x6d42deef2d65a808ULL,0x4969044f94636b19ULL,0xf611ee47dd5d564cULL,0x7b2f3a49d2873077ULL,+ 0x94157d45300eb294ULL,0x2b2a656e169c1494ULL,0xc000dd76d3a47aa9ULL,0xa2864e4fa6243ea4ULL,0x82716c47db89842eULL,0x12dfd7d761479fb7ULL,0x3b9a2c56e0b2f6dcULL,0x46be862ad7f85d67ULL,+ 0x03b0d8dd0f82b214ULL,0x460c34f9f103cbc6ULL,0xf32e5c0318d79e19ULL,0x8b8888baa84117f8ULL,0x8f3c37dcc0722677ULL,0x10d21be91c1c0f27ULL,0xd47c8468e0f7a0c6ULL,0x9bf02213adecc0e0ULL,+ 0x0baa7d1242b48b99ULL,0x1bcb665d48424096ULL,0x8b847cd6ebfb5cfbULL,0x87c2ae569ad4d10dULL,0xf1cbb1220de36726ULL,0xe7043c683fdfbd21ULL,0x4bd0826a4e79d460ULL,0x11f5e5984bd1a2cbULL,+ 0x97554160b7fe7b6eULL,0x7d16189a400a3fb2ULL,0xd73e9beae328ca1eULL,0x0dd04b97e793d8ccULL,0xa9c83c9b506db8ccULL,0x5cd47aaecf38814cULL,0x26fc430db64b45e6ULL,0x079b5499d818ea84ULL,+ 0xebb01102c1c24a3bULL,0xca24e5681c161c1aULL,0x103eea6936f00a4aULL,0x9ad76ee876176c7bULL,0x97451fc2538e0ff7ULL,0x94f898096604b3b0ULL,0x6311436e3249cfd7ULL,0x27b4a7bd41224f69ULL,+ 0x03b5d21ae0ac2941ULL,0x279b0254c2d31937ULL,0x3307c052cac992d0ULL,0x6aa7cb92efa8b1f3ULL,0x5a1825800d37c7a5ULL,0x13380c37342d5422ULL,0x92ac2d66d5d2ef92ULL,0x035a70c9030c63c6ULL,+ 0xc16025dd4ce4f152ULL,0x1f419a71f9df7c06ULL,0x6d5b221491e4bb14ULL,0xfc43c6cc839fb4ceULL,0x49f06591925d6b2dULL,0x4b37d9d362186598ULL,0x8c54a971d01b1629ULL,0xe1a9c29f51d50e05ULL,+ 0x5109b78571ba1861ULL,0x48b22d5cd0c8f93dULL,0xe8fa84a78633bb93ULL,0x53fba6ba5aebbd08ULL,0x7ff27df3e5eea7d8ULL,0x521c879668ca7158ULL,0xb9d5133bce6f1a05ULL,0x2d50cd53fd0ebee4ULL,+ 0x889f6d65533ef217ULL,0x7158c7e4c3ca2e87ULL,0xfb670dfbdc2b4167ULL,0x75910a01844c257fULL,0xf336bf07cf88577dULL,0x22245250e45e2aceULL,0x2ed92e8d7ca23d85ULL,0x29f8be4c2b812f58ULL,+ 0xfbb9b2452133ffd9ULL,0x39a8b2f1830f1a20ULL,0x484bc97dd5a1f52aULL,0xd6aebf56a40eddf8ULL,0x32257acb76ccdac6ULL,0xaf4d36ec1586ff27ULL,0x8eaa8863f8de7dd1ULL,0x0045d5cf88647c16ULL,+ 0xc51e414351facc61ULL,0xbaf2647de68a25bcULL,0x8f5271a00ff872edULL,0x8f32ef993d2d9659ULL,0xca12488c7593cbd4ULL,0xed266c5d02b82fabULL,0x0a2f78ad14eb3f16ULL,0xc34049484d47afe3ULL,+ 0xa6f3d574c005979dULL,0xc2072b426a40e350ULL,0xfca5c1568de2ecf9ULL,0xa8c8bf5ba515344eULL,0x97aee555114df14aULL,0xd4374a4dfdc5ec6bULL,0x754cc28f2ca85418ULL,0x71cb9e27d3c41f78ULL,+ 0x09c1670209470496ULL,0xa489a5edebd23815ULL,0xc4dde4648edd4398ULL,0x3ca7b94a80111696ULL,0x3c385d682ad636a4ULL,0x6702702508dc5f1eULL,0x0c1965deafa21943ULL,0x18666e16610be69eULL,+ 0x6792fd350369c8e1ULL,0x9271aa62b9dc843bULL,0x8711a4b14d02e2abULL,0x02b2a3e27ee1a383ULL,0xb226e35f0e2b379bULL,0x3d3de39cd652ab25ULL,0xaca6d4c93b560106ULL,0xeced0cf4c95bd877ULL,+ 0x45beb4ca2a604b3bULL,0x56f651843a616762ULL,0xf52f5a70978b806eULL,0x7aa3978711dc4480ULL,0xe13fac2a0e01fabcULL,0x7c6ee8a5237d99f9ULL,0x251384ee05211ffeULL,0x4ff6976d1bc9d3ebULL,+ 0x8910507903605c39ULL,0xf0843d9ea142c96cULL,0xf374493416923684ULL,0x732caa2ffa0a2893ULL,0xb2e8c27061160170ULL,0xc32788cc437fbaa3ULL,0x39cd818ea6eda3acULL,0xe2e942399e2b2e07ULL,+ 0xdde0492316e043a2ULL,0x98a452611dd3d209ULL,0xeaf9f61bd431ebe8ULL,0x00919f4dbaf56abdULL,0xe42417db6d8774b1ULL,0x5fc5279c58e0e309ULL,0x64aa40613adf81eaULL,0xef419edabc627c7fULL,+ 0x3919759239ef620fULL,0x9d47284074fa29c4ULL,0x4e428fa39d416d83ULL,0xd1a7c25129f30269ULL,0x46076e1cd746218fULL,0xf3ad6ee8110d967eULL,0xfbb5f434a00ae61fULL,0x3cd2c01980d4c929ULL,+ 0xfa24d0537a4af00fULL,0x3f938926ca294614ULL,0x0d700c183982182eULL,0x801334434cc59947ULL,0xf0397106ec87c925ULL,0x62bd59fc0ed6665cULL,0xe8414348c7cca8b5ULL,0x574c76209f9f0a30ULL,+ 0x6967d39b0260e52aULL,0xd42585cc90653325ULL,0x0d9bd60521ca7954ULL,0x4fa2087781ed57b3ULL,0x60c1eff8e34a0bbeULL,0x56b0040c84f6ef64ULL,0x28be2b24b1af8483ULL,0xb2278163f5531614ULL,+ 0x95be42e2bb8b6a07ULL,0x64be74eeca23f86aULL,0xa73d74fd154ce470ULL,0x1c2d2857d8dc076aULL,0xb1fa1c575a887868ULL,0x38df8e0b3de64818ULL,0xd88e52f9c34e8967ULL,0x274b4f018b4cc76cULL,+ 0x59c81ec2c11c208bULL,0x240207da4e3a7234ULL,0x4957eb80f4a089d8ULL,0xc86960bc2137a072ULL,0xde1154fd7f1a932cULL,0xb517fe74d3f2fa17ULL,0x2d5d94557111c0ebULL,0x2aa3378980929d36ULL,+ 0x3f5c05b4f8b7559dULL,0x0be4c7acfae29200ULL,0xdd6d3ef756532accULL,0xf6c3ed87eea7a285ULL,0xe463b0a8f46ec59bULL,0x531d9b14ecea6c83ULL,0x3d6bdbafc2dc836bULL,0x3ee501e92ab27f0bULL,+ 0x8df275455922ac1cULL,0xa7b3ef5ca52b3f63ULL,0x8e77b21471de57c4ULL,0x31682c10834c008bULL,0xc76824f04bd55d31ULL,0xb6d1c08617b61c71ULL,0x31db0903c2a5089dULL,0x9c092172184e5d3fULL,+ 0x5ace5035ea6c3997ULL,0x54259aaac2610befULL,0xef18bb3f3c80dd39ULL,0x6910b95b5fc3fa39ULL,0xfce2f51043e09aeeULL,0xced56c9fa7675665ULL,0x10e265acd872db61ULL,0x6982812eae9fce69ULL,+ 0xb8fa3d931341ed7aULL,0x4223272ca7b59d49ULL,0x3dcb194783b8c4a4ULL,0x4e413c01ed1302e4ULL,0x6d999127e17e44ceULL,0xee86bf7533b3adfbULL,0xf6902fe625aa96caULL,0xb73540e4e5aae47dULL,+ 0xcc50ef6c872b4a60ULL,0xab2a34a44613521bULL,0x39c5c190983e15d1ULL,0x61dde5df59905512ULL,0xe417f6219f2275f3ULL,0x0750c8b6451d894bULL,0x75b04ab978b0bdaaULL,0x3bfd9fd4458589bdULL,+ 0xaafcbfabaf95894cULL,0x7b9bdc07276b2241ULL,0xeaf983625bdda48bULL,0x5977faf2a3fcb4dfULL,0xbed042ef052c4b5bULL,0x9fe87f71067591f0ULL,0xc89c73ca22f24ec7ULL,0x7d37fa9ee64a9f1bULL,+ 0xbd78148045ee2f40ULL,0x75e354af416b60cfULL,0xde0b58a18d49a8c4ULL,0xe40e94e2fa359536ULL,0xbd4fa59f62accd76ULL,0x05cf466a8c762837ULL,0xb5abda99448c277bULL,0x5a9e01bf48b13740ULL,+ 0xb51e55e6f2606a82ULL,0xe25f706190f2fb57ULL,0xacef6c2ab1a4e37cULL,0x864e359d5dcf2706ULL,0x479e6b187ce57316ULL,0x2cab25003a96b23dULL,0xed4898628ef16df7ULL,0x2056538cef3758b5ULL,+ 0xef69a0c3d41d3bd3ULL,0xb533b8c907a26bdeULL,0xe2801d97db2edf9fULL,0xdc4a8269e1877af0ULL,0x6c1c58513d590dbeULL,0x84632f6bee4e9357ULL,0xd36d36b779b33374ULL,0xb46833e39bbca2e6ULL,+ 0xcc7a64880a750c0fULL,0x39bacfe34e548e83ULL,0x3d418c760c110f05ULL,0x3e4daa4cb1f11588ULL,0x2733e7b55ffc69ffULL,0x46f147bc92053127ULL,0x885b2434d722df94ULL,0x6a444f65e6fc6b7cULL,+ 0x008be4bb346ac9cbULL,0x2e6cb02429811bb2ULL,0xa6ccc747f41540c1ULL,0xf119334efbf6de47ULL,0x4e6bffe9cc97fe6eULL,0x7f4b578bf3d82883ULL,0x459db722753dd1c7ULL,0x05843cd82066b495ULL,+ 0x7cb88cd5dbf2af33ULL,0xded9566eaf6b0eabULL,0xd1caf5488e40d844ULL,0x3ae59bd67ce1f67fULL,0xacf4ad33dd82429eULL,0xcc7ebd2bbc4467c7ULL,0xf4f6e95de783d011ULL,0x5197e39116e92db7ULL,+ 0xd4f2031885e7a4afULL,0x291bf9a0f7a6878dULL,0xadd8b6eebd051913ULL,0x174f5124f36be034ULL,0x2ac3364527f60189ULL,0xd8902eed8b37ec73ULL,0x546166a11cfdb42eULL,0x31c4e3b807076421ULL,+ 0x7de29dfdbc6ebdfbULL,0xa1ee450589de549bULL,0xfd7181aa3ef26a64ULL,0x003179eedf2f3980ULL,0x1bce4d30fd71bc78ULL,0xeb842b14be86a583ULL,0xe00125dc5eb85711ULL,0x9f586983ff11f405ULL,+ 0x5b5a089eb833eccbULL,0xc1b3077a7bc51c79ULL,0xe581157f9fbe0e93ULL,0xab487d695b29b172ULL,0xc72551082222f24bULL,0x338cd22cf6dd35dfULL,0x92010e6f5fc24afeULL,0xf8298f15681d46edULL,+ 0x2ce7f723042389edULL,0xdf7de0d5a54b1972ULL,0xb8ea2e142c251d75ULL,0xd22a4d37f4e8e8c8ULL,0xe99958566c29c8bcULL,0x9fefdbfe1d1e201eULL,0xb97d946edac885c9ULL,0xf6ea9767d38eac70ULL,+ 0x9aaca8e974e75a2eULL,0xcda6fc1eadac968fULL,0x3f6651bf46306befULL,0xc7445e4ecb2ed7f9ULL,0x584a12d8d1571ac1ULL,0x684846c4daf3a679ULL,0xcfc622a9863fbc43ULL,0x2f9e101dea6814f2ULL,+ 0x7a1a465ac3f16ea8ULL,0x115a461db2f1d11cULL,0x4767dd956c68a172ULL,0x3392f2ebd13a4698ULL,0xc7a99ccde526cdc7ULL,0x8e537fdc22292b81ULL,0x76d8cf69a6d39198ULL,0xffc5ff432446852dULL,+ 0x97b14f7ea90567e6ULL,0x513257b7b6ae5cb7ULL,0x85454a3c9f10903dULL,0xd8d2c9ad69bc3724ULL,0x38da93246b29cb44ULL,0xb540a21d77c8cbacULL,0x9bbfe43501918e42ULL,0xfffa707a56c3614eULL,+ 0x56c2e05b1cb76219ULL,0x0ec0bf9171567e7eULL,0xe7076f8661c4c910ULL,0xd67b085bbabc04d9ULL,0x9fb904595e93a96aULL,0x7526c1eafbdc249aULL,0x0d44d367ecdd0bb7ULL,0x953999179dc0d695ULL,+ 0x2ccbc583a4c506ecULL,0x957ed188d1acfe97ULL,0x8baed83312f1aea2ULL,0xef2a6cb48325362dULL,0x130dde428e195c43ULL,0xc842025a0e6050c6ULL,0x2da972a708686a5dULL,0xb52999a1e508b4a8ULL,+ 0x83f49167ceca9754ULL,0x426d2cf64b7939a0ULL,0x2555e355723fd0bfULL,0xa96e6d06c4f144e2ULL,0x4768a8dd87880e61ULL,0x15543815e508e4d5ULL,0x09d7e772b1b65e15ULL,0x63439dd6ac302fa0ULL,+ 0xb11df8e1698e04ccULL,0x877be203169005c8ULL,0x32749e8c4f3c6179ULL,0x2dbc9d0a7853fc05ULL,0x187d4f939454d937ULL,0xe682ce9db4800e1bULL,0xa9129ad8165e68e8ULL,0x0fe29735be7f785bULL,+ 0x31019ccf3a4434b4ULL,0xa34581111a7954dcULL,0xa9dac80de34972a7ULL,0xb043d05474f6b8ddULL,0x021c319e11137b1aULL,0x00a754ceed5cc03fULL,0x0aa2c794cbea5ad4ULL,0x093e67f470c015b6ULL,+ 0x20ac0351d598d710ULL,0x272c4166cb3a4da4ULL,0xdb82fe1aca71de1fULL,0x746e79f2d8f54b0fULL,0x6e7fc7364b573e9bULL,0x75d03f46fd4b5040ULL,0x5c1cc36d0b98d87bULL,0x513ba3f11f472da1ULL,+ 0x859d3145983c38b5ULL,0xb14f176c637abc8bULL,0x2793fb9dcaff7be6ULL,0xebe5a55f35a66a5aULL,0x7cec1dcd9f87dc59ULL,0x7c595cd3fbdbf560ULL,0x5b543b2226eb3257ULL,0x69080646c4c935fdULL,+ 0xdca3b70678a6513bULL,0x92ea4a2a9edb1943ULL,0x02642216db6e2dd8ULL,0x9b45d0b49fd57894ULL,0x114e70dbc69d11aeULL,0x1477dd194c57595fULL,0xbc2208b4ec77c272ULL,0x95c5b4d7db68f59cULL,+ 0xfe541fa47ea67c77ULL,0x952bd2afe3ea810cULL,0x791fef568d01d374ULL,0xa3a1c6210f11336eULL,0x5ad0d5a9c7ec6d79ULL,0xff7038af3225c342ULL,0x003c6689bc69601bULL,0x25059bc745e8747dULL,+ 0x9a75c80676cb2566ULL,0x8f76acb1b24892d9ULL,0x7ae7b9cc1f08fe45ULL,0x19ef73296a4907d8ULL,0x2db4ab715f228bf0ULL,0xf3cdea39817032d7ULL,0x0b1f482edcabe3c0ULL,0x3baf76b4bb86325cULL,+ 0x6aac688eadd70482ULL,0x708de92a7b4a4e8aULL,0x75b6dd73758a6eefULL,0xea4bf352725b3c43ULL,0x10041f2c87912868ULL,0xb1b1be95ef09297aULL,0x19ae23c5a9f3860aULL,0xc4f0f839515dcf4bULL,+ 0xc71e27bf8538a5c6ULL,0x195c63dd89abff17ULL,0xfd3152851b71e3daULL,0x9cbdfda7fa680fa0ULL,0x9db876ca849d7eabULL,0xebe2764b3c273271ULL,0x663357e3f208dceaULL,0x8c5bd833565b1b70ULL,+ 0x75900d7c2fa4f126ULL,0x08a3b8655c99a232ULL,0x2478b6bfdb25e0c3ULL,0x482cc2c271db2edfULL,0x37df7e645f321bb8ULL,0x8a93821b9a8005b4ULL,0x3fa2f10ccc8c1958ULL,0x0d3322182c269d0aULL,+ 0xba5514df3fd165e8ULL,0x499fd6a9061f8811ULL,0x72cd1fe0bfef9f00ULL,0x120a4bb979ad7e8aULL,0xf2ffd0955f4a5ac5ULL,0xcfd174f195a7a2f0ULL,0xd42301ba9d17baf1ULL,0xd2fa487a77f22089ULL,+ 0xb93452381d531696ULL,0x57201c0088cdde69ULL,0xdde922519a86afc7ULL,0xe3043895bd35cea8ULL,0x7608c1e18555970dULL,0x8267dfa92535935eULL,0xd4c60a57322ea38bULL,0xe0bf7977804ef8b5ULL,+ 0x6233ea68c094dbb5ULL,0xb77d062ed968d410ULL,0x3e719bbc58b3002dULL,0x68e7dd3d3dc49d58ULL,0x8d825740013a5e58ULL,0x213117473c9e3c1bULL,0x0cb0a2a77c99b6abULL,0x5c48a3b3c2f888f2ULL,+ 0xc7913e91991724f3ULL,0x5eda799c39cbd686ULL,0xddb595c763d4fc1eULL,0x6b63b80bac4fed54ULL,0x6ea0fc697e5fb516ULL,0x737708bad0f1c964ULL,0x9628745f11a92ca5ULL,0x61f379589a86967aULL,+ 0x5320fd610979e6b3ULL,0x1d0bd3e593d40723ULL,0x0ac006fcaa80baccULL,0xb1d9c60ed2002515ULL,0x610e7ed0af780b92ULL,0xf5bf446e80a9ce31ULL,0x441c011d3c20b54bULL,0x77f76da1191596c3ULL,+ 0x9af39b2caa665072ULL,0x78322fa4efd324efULL,0x3d153394c327bd31ULL,0x81d5f2713129dab0ULL,0xc72e0c42f48027f5ULL,0xaa40cdbc8536e717ULL,0xf45a657a2d369d0fULL,0xb03bbfc4ea7f74e6ULL,+ 0x7a04d5429b6a42eaULL,0xfa597e853daf41b9ULL,0x4c58ec27726b0b89ULL,0xed8eb16a030d43deULL,0x65e1e5e1ec9dcf57ULL,0xb7a770c1697cff81ULL,0x1e6d918f9f6e2b22ULL,0x7c277a9ac64e82b7ULL,+ 0x46a8c4180d738dedULL,0x6f1a5bb0e0de5729ULL,0xf10230b98ba81675ULL,0x32c6f30c112b33d4ULL,0x7559129dd8fffb62ULL,0x6a281b47b459bf05ULL,0x77c1bd3afa3b6776ULL,0x0709b3807829973aULL,+ 0x0875e0c1da36cb47ULL,0xfdf5b7cb1e0210f0ULL,0x7e0c7e4d3a3787c8ULL,0xf043f5262b1c741fULL,0x76df1b006d74d72dULL,0x0514df7338b45ba9ULL,0xaecf7c3e0a6b797aULL,0x5e30b285ddeaac39ULL,+ 0x8c26b232a3326505ULL,0x38d69272ee1d41bfULL,0x0459453effe32afaULL,0xce8143ad7cb3ea87ULL,0x932ec1fa7e6ab666ULL,0x6cd2d23022286264ULL,0x459a46fe6736f8edULL,0x50bf0d009eca85bbULL,+ 0x15c78f7d605238a5ULL,0xe9d87842448496abULL,0xcfcf75d0d210acc1ULL,0x2948f2295c8c14e2ULL,0xe81fd76de8daf0cbULL,0xd02d11e4a03be800ULL,0x0c4df3518778d30cULL,0x3482bc96965139cbULL,+ 0x0b825852877a21ecULL,0x300414a70f537a94ULL,0x3f1cba4021a9a6a2ULL,0x50824eee76943c00ULL,0xa0dbfcecf83cba5dULL,0xf953814893b4f3c0ULL,0x6174416248f24dd7ULL,0x5322d64de4fb09ddULL,+ 0x56b6cf278a448bbcULL,0x0ca898dfc85251daULL,0x9082cad836e79b24ULL,0x2e7b9ed31a8e51a7ULL,0xdc7d318a43e1c802ULL,0x4750e523cbf8689dULL,0x9887a072f0071b1aULL,0x52090f87814bfdc1ULL,+ 0x574473843d9325f3ULL,0xa9bef2d0f371cb84ULL,0x77d2188ba61e36c5ULL,0xbbd6a7d7c602df72ULL,0xba3aa9028f61bc0bULL,0xf49085ed6ed0b6a1ULL,0x8bc625d6ae6e8298ULL,0x832b0b1da2e9c01dULL,+ 0x5bebf2196196bc6eULL,0x0e66736bef097efdULL,0x1128f3b8ea87293aULL,0x2998e4056addfcdeULL,0x55cc31b85d16c961ULL,0x87a434e12418f056ULL,0x2e94aaccdc9fe819ULL,0x94a486c1a56490c6ULL,+ 0xa337c447f1f0ced1ULL,0x800cc7939492dd2bULL,0x4b93151dbea08efaULL,0x820cf3f8de0a741eULL,0xff1982dc1c0f7d13ULL,0xef92196084dde6caULL,0x1ad7d97245f96ee3ULL,0x319c8dbe29dea0c7ULL,+ 0x1ff2385bde259ec8ULL,0xf6b0836a30f67b0dULL,0x04cc65b006661cffULL,0x467e6358d4230f5cULL,0xce468c802dbed3d3ULL,0x7b984262f1920da6ULL,0x34d257421537479fULL,0x5c8aa88c87bb8de1ULL,+ 0xd3ea38717b82b99bULL,0x75922d4d470eb624ULL,0x8f66ec543b95d466ULL,0x66e673ccbee1e346ULL,0x6afe67c4b5f2b89aULL,0x3de9c1e6290e5cd3ULL,0x8c278bb6310a2adaULL,0x420fa3840bdb323bULL,+ 0x646f96796424c49bULL,0xf888dfe867c241c9ULL,0xe12d4b9324f68b49ULL,0x9a6b62d8a571df20ULL,0x81b4b26d179483cbULL,0x666f96329511fae2ULL,0xd281b3e4d53aa51fULL,0x7f96a7657f3dbd16ULL,+ 0x8553d37c051af62bULL,0xe9a998eb0bf94496ULL,0xe0844f9fb0d59aa1ULL,0x983fd558e6afb813ULL,0x9670c0ca65d69804ULL,0x732b22de6ea5ff2dULL,0xd7640ba95fd8623bULL,0x9f619163a6351782ULL,+ 0xf167b4e0bdefdd4fULL,0x69958465f366e401ULL,0x5aa368aba73bbec0ULL,0x121487097b240c21ULL,0x378c323318969006ULL,0xcb4d73cee1fe53d1ULL,0x5f50a80e130c4361ULL,0xd67f59517ef5212bULL,+ 0x332f81088cad38c0ULL,0x471b7e906bd68ae2ULL,0x56ac3fb20d8e27a3ULL,0xb54660db136b4b0dULL,0x123a1e11a6fd8de4ULL,0x44dbffeaa37799efULL,0x4540b977ce6ac17cULL,0x495173a8af60acefULL,+ 0xeb4437434573eab0ULL,0x11570dfbd1ac6031ULL,0xf7d9b45b44dd9afdULL,0xb8066add22067231ULL,0x15f92ad8f8a3f0b4ULL,0x9e0e4899e0ace2a2ULL,0xbdcd0aadfab38b80ULL,0x46506ae917020052ULL,+ 0x429a69f78fca399dULL,0xfe9e27d20207bb63ULL,0xec655ed68788f582ULL,0xa426d748adb75f6eULL,0x18695c02ca81c66dULL,0x84fb8d27a531d425ULL,0x3a3a8956deff48baULL,0xaf1d0d56766d2247ULL,+ 0x5a059565352c4b5cULL,0x49261531590bc3e2ULL,0x809f7521f66f9f5fULL,0x2baef6bfc70a4a9bULL,0xe7e6fa6509ed3561ULL,0x11370233984b230cULL,0x2151659bd04cdc69ULL,0xbdb83c63f007d416ULL,+ 0x9ebb284d391c2a82ULL,0xbcdd4863158308e8ULL,0x006f16ec83f1edcaULL,0xa13e2c37695dc6c8ULL,0x2ab756f04a057a87ULL,0xa8765500a6b48f98ULL,0x4252face68651c44ULL,0xa52b540be1765e02ULL,+ 0xcb35a1a85ca37ff0ULL,0xe1a04f1ccd2f1c8fULL,0x238816ce15a26112ULL,0xe206a111095b177eULL,0x3c10b6048a424149ULL,0xc6a3f56774752cfbULL,0xbf16a37a47f1dbb8ULL,0x7c372f9ad31a3dfbULL,+ 0x122d05b5c20b4d2aULL,0xff659cf50c662a67ULL,0xed57c128e8ffc9e9ULL,0x0fbb15859e987683ULL,0xadd70df247319a2bULL,0x4b98baba374be470ULL,0xf03d747356a7b307ULL,0x342e696e3efebf30ULL,+ 0xf84b48f7864ac537ULL,0x04713409a6940d3dULL,0x014db22d6174c7aeULL,0xc73a1c438c213034ULL,0x18ac4ea5ffdd93ecULL,0x724fc7576102783eULL,0x9fe13fcc91c3e83fULL,0x92a8c2c8f08f0bf5ULL,+ 0x7f2e22fd8f67f6deULL,0xab018833d8693177ULL,0x266d1db6863eca95ULL,0x6bb7732b31b5ef2bULL,0x4fa927c6915f80ceULL,0x6fa1d6d25f90efd8ULL,0x7bd75de8456b48adULL,0xd2cb507a845b6429ULL,+ 0xa72cf82ae255d7ecULL,0x52025c23a460e204ULL,0x10ae542d7d5b0a44ULL,0xa85143109305aedaULL,0x958315f5a14bbfe8ULL,0x3f361826385365feULL,0xc2b3a36b66d95040ULL,0x12c7b3347cf4eda2ULL,+ 0xa545b4d1e744119dULL,0x4c93b169829a71e7ULL,0x2dbb908c6117fcbfULL,0x4dc97320b35a3d85ULL,0x94c04f856bf88105ULL,0x452e1bce1b51bc1fULL,0x0c41ff50b3013af3ULL,0xf07af445224d7e24ULL,+ 0xbdb9e57ca3d24f6aULL,0x8a8246d7f345a763ULL,0x73bd2a6d98cfbb5fULL,0x1dd8e85e86ed04dbULL,0x76f2da42c01f420bULL,0x7ef0547364407bc7ULL,0x7e98ba7faff548f5ULL,0x6b7afbeefd30b64aULL,+ 0x4f922fc516a0d2bbULL,0x0d5cc16c1a623499ULL,0x9241cf3a57c62c8bULL,0x2f5e6961fd1b667fULL,0x5c15c70bf5a01797ULL,0x3d20b44d60956192ULL,0x04911b37071fdb52ULL,0xf648f9168d6f0f7bULL,+ 0x027cc8b8fac61d9aULL,0x7d25e062e3c6fe8aULL,0xe08805bfe5bff503ULL,0x13271e6c6ff632f7ULL,0x55dca6c0232f76a5ULL,0x8957c32d701ef426ULL,0xee728bcba10a5178ULL,0x5ea60411b62c5173ULL,+ 0x9ad5462bb4d8bc50ULL,0x181c0b16a9195770ULL,0xebd4fe1c78412a68ULL,0xae0341bcc0dff48cULL,0xb6bc45cf7003e866ULL,0xf11a6dea8a24a41bULL,0x5407151ad04c24c2ULL,0x62c9d27dda5b7b68ULL,+ 0x32865719a8afd30bULL,0x867983288a826dceULL,0xdf04e891c4a8fbe0ULL,0xbb6b6e1bebf56ad3ULL,0x0a695b11471f1ff0ULL,0xd76c3389be15baf0ULL,0x018edb95be96c43eULL,0xf2beaaf490794158ULL,+ 0x0a50b12e523b8bf6ULL,0x8009eb5b8f910c1bULL,0xf535af824a167588ULL,0x0f835f9cfb2a2abdULL,0xf59b29312afceb62ULL,0xc797df2a169d383fULL,0xeb3f5fb066ac02b0ULL,0x029d4c6fdaa2d0caULL,+ 0x87a7ebd1e0a1b12aULL,0x1e4ef88d770ba95fULL,0x8c33345cdc2ae9cbULL,0xcecf127601cc8403ULL,0x687c012e1b39b80fULL,0xfd90d0ad35c33ba4ULL,0xa3ef5a675c9661c2ULL,0x368fc88ee017429eULL,+ 0xb82226052b7ce542ULL,0xe6d4ce997472bde1ULL,0x53e16ebe09d2f4daULL,0x180ff42e53b92b2eULL,0xc59bcc022c34a1c6ULL,0x3803d6f9422c46c2ULL,0x18aff74f5c14a8a2ULL,0x55aebf8010a08b28ULL,+ 0xb956970e2fdd23ccULL,0xb80288bc5682e971ULL,0xe6e6d91e9ae86ebcULL,0x0564c83f8c9f1939ULL,0x551932a239560368ULL,0xe893752b049c28e2ULL,0x0b03cee5a6a158c3ULL,0xe12d656b04964263ULL,+ 0x58af2010f5b343bcULL,0x0f2e400af2f142feULL,0x3483bfdea85f4bdfULL,0xf0b1d09303bfeaa9ULL,0x2ea01b95c7081603ULL,0xe943e4c93dba1097ULL,0x47be92adb438f3a6ULL,0x00bb7742e5bf6636ULL,+ 0x4ed714576be5f7deULL,0xd93006f8c2263c9eULL,0xe073694ccacacb36ULL,0x2ff7a5b43ae118abULL,0x3cce53f1cd871236ULL,0xf156a39dc2aa6d52ULL,0x9cc5f271b198d76dULL,0xbc615b6f81383d39ULL,+ 0x137a4fb486df2a61ULL,0xa1ed9c07ecf7b4a2ULL,0xb2e460e27bd042ffULL,0xb7f5e2fa5f62f5ecULL,0x7aa6ec6bcc2423b7ULL,0x75ce0a7fba63eea7ULL,0x67a45fb1f250a6e1ULL,0x93bc919ce53cdc9fULL,+ 0x67930af231f63950ULL,0xa77797c114caa2c9ULL,0x526e80ee27ac7e62ULL,0xe1e6e62658b28aecULL,0x636178b0b3c9fef0ULL,0xaf7752e06d5f90beULL,0x94ecaf18eece51cfULL,0x2864d0edca806e1fULL,+ 0xec2fccaaddce3345ULL,0x2a6811b7012a4350ULL,0x96760ff1ac598bdcULL,0x054d652ad1bf4128ULL,0x0a1151d492a21005ULL,0xad7f397133110fdfULL,0x8c95928c1960100fULL,0x6c91c8257bf03362ULL,+ 0x17785b7799eb6df0ULL,0x26c3cc517386b779ULL,0x345ed9886417a48eULL,0xe990b4e407d6ef31ULL,0x0f456b7e2586abbaULL,0x239ca6a559c96e9aULL,0xe327459ce2eb4206ULL,0x3a4c3313a002b90aULL,+ 0x19e6125dec3f1decULL,0x07b1f040911178daULL,0xd93ededa904a6738ULL,0x55187a5a0bebedcdULL,0xf7d04722eb329d41ULL,0xf449099ef170b391ULL,0xfd317a69ca99f828ULL,0x50c3db2b34a4976dULL,+ 0x3806b69b92222f1fULL,0x5a2459ca6cf7ae70ULL,0x6789f69ca85217eeULL,0x5f232b5ee3dc85acULL,0x660e3ec548e9e516ULL,0x124b4e473197eb31ULL,0x10a0cb13aafcca23ULL,0x7bd63ba48213224fULL,+ 0xb674481b7bfe7178ULL,0x4e1debae65405868ULL,0x061b2821c48c867dULL,0x69c15b35513b30eaULL,0x3b4a166636871088ULL,0xe5e29f5d1220b1ffULL,0x4b82bb35233d9f4dULL,0x4e07633318cdc675ULL,+ 0x0d53f5c7a3e6fcedULL,0xe8cbbdd5f45fbdebULL,0xf85c01df13339a70ULL,0x0ff71880142ceb81ULL,0x4c4e8774bd70437aULL,0x5fb32891ba0bda6aULL,0x1cdbebd2f18bd26eULL,0x2f9526f103a9d522ULL,+ 0x40ce305192c4d684ULL,0x8b04d7257612efcdULL,0xb9dcda366f9cae20ULL,0x0edc4d24f058856cULL,0x64f2e6bf85427900ULL,0x3de81295dc09dfeaULL,0xd41b4487379bf26cULL,0x50b62c6d6df135a9ULL,+ 0xd4f8e3b4c72dfe67ULL,0xc416b0f690e19fdfULL,0x18b9098d4c13bd35ULL,0xac11118a15b8cb9eULL,0xf598a318f0062841ULL,0xbfe0602f89f356f4ULL,0x7ae3637e30177a0cULL,0x3409774761136537ULL,+ 0x0db2fb5ed005832aULL,0x5f5efd3b91042e4fULL,0x8c4ffdc6ed70f8caULL,0xe4645d0bb52da9ccULL,0x9596f58bc9001d1fULL,0x52c8f0bc4e117205ULL,0xfd4aa0d2e398a084ULL,0x815bfe3a104f49deULL,+ 0x97e5443f23885e5fULL,0xf72f8f99e8433aabULL,0xbd00b154e4d4e604ULL,0xd0b35e6ae5e173ffULL,0x57b2a0489164722dULL,0x3e3c665b88761ec8ULL,0x6bdd13973da83832ULL,0x3c8b1a1e73dafe3bULL,+ 0x4497ace654317cacULL,0xbe600ab9521771b3ULL,0xb42e409eb0dfe8b8ULL,0x386a67d73942310fULL,0x25548d8d4431cc28ULL,0xa7cff142985dc524ULL,0x4d60f5a193c4be32ULL,0x83ebd5c8d071c6e1ULL,+ 0xba3a80a7b1fd2b0bULL,0x9b3ad3965bec33e8ULL,0xb3868d6179743fb3ULL,0xcfd169fcfdb462faULL,0xd3b499d79ce0a6afULL,0x55dc1cf1e42d3ff8ULL,0x04fb9e6cc6c3e1b2ULL,0x47e6961d6f69a474ULL,+ 0x54eb3acce548b37bULL,0xb38e754284d40549ULL,0x8c3daa517b341b4fULL,0x2f6928ec690bf7faULL,0x0496b32386ce6c41ULL,0x01be1c5510adadcdULL,0xc04e67e74bb5faf9ULL,0x3cbaf678e15c9985ULL,+ 0x8cd1214550ca4247ULL,0xba1aa47ae7dd30aaULL,0x2f81ddf1e58fee24ULL,0x03452936eec9b0e8ULL,0x8bdc3b81243aea96ULL,0x9a2919af15c3d0e5ULL,0x9ea640ec10948361ULL,0x5ac86d5b6e0bcccfULL,+ 0xf892d918c36cf440ULL,0xaed3e837c939719cULL,0xb07b08d2c0218b64ULL,0x6f1bcbbace9790ddULL,0x4a84d6ed60919b8eULL,0xd89007918ac1f9ebULL,0xf84941aa0dd5daefULL,0xb22fe40a67fd62c5ULL,+ 0x97e15ba2157f2db3ULL,0xbda2fc8f8e28ca9cULL,0x5d050da437b9f454ULL,0x3d57eb572379d72eULL,0xe9b5eba2fb5ee997ULL,0x01648ca2e11538caULL,0x32bb76f6f6327974ULL,0x338f14b8ff3f4bb7ULL,+ 0x524d226ad7ab9a2dULL,0x9c00090d7dfae958ULL,0x0ba5f5398751d8c2ULL,0x8afcbcdd3ab8262dULL,0x57392729e99d043bULL,0xef51263baebc943aULL,0x9feace9320862935ULL,0x639efc03b06c817bULL,+ 0x1fe054b366b4be7aULL,0x3f25a9de84a37a1eULL,0xf39ef1ad78d75cd9ULL,0xd7b58f495062c1b5ULL,0x6f74f9a9ff563436ULL,0xf718ff29e8af51e7ULL,0x5234d31315e97fecULL,0xb6a8e2b1292f1c0aULL,+ 0xa7f53aa8327720c1ULL,0x956ca322ba092cc8ULL,0x8f03d64a28746c4dULL,0x51fe178266d0d392ULL,0xd19b34db3c832c80ULL,0x60dccc5c6da2e3b4ULL,0x245dd62e0a104cccULL,0xa7ab1de1620b21fdULL,+ 0xb293ae0b3893d123ULL,0xf7b75783b15ee71cULL,0x5aa3c61442a9468bULL,0xd686123cdb15d744ULL,0x8c616891a7ab4116ULL,0x6fcd72c8a4e6a459ULL,0xac21911077e5fad7ULL,0xfb6a20e7704fa46bULL,+ 0xe839be7d341d81dcULL,0xcddb688932148379ULL,0xda6211a1f7026eadULL,0xf3b2575ff4d1cc5eULL,0x40cfc8f6a7a73ae6ULL,0x83879a5e61d5b483ULL,0xc5acb1ed41a50ebcULL,0x59a60cc83c07d8faULL,+ 0x439530b665c7322dULL,0xcf12cc01b3c1b3fbULL,0xc70b01860172f685ULL,0xb915ee221b58391dULL,0x9afdf03ba317db24ULL,0x87dec65917b8ffc4ULL,0x7f46597be4d3d050ULL,0x80a1c1ed006500e7ULL,+ 0x3e22a7b397acf4ecULL,0x0426c4005ea8b640ULL,0x5e3295a64e969285ULL,0x22aabc59a6a45670ULL,0xb929714c5f5942bcULL,0x9a6168bdfa3182edULL,0x2216a665104152baULL,0x46908d03b6926368ULL,+ 0x52cb8ac6c2babcc1ULL,0x4748d448fe81ae8dULL,0x5844f03f80f1a711ULL,0x3db784b2f8df4ac4ULL,0xad918f122df1fe36ULL,0xe40f25b9f33cc7c0ULL,0x4700d0e73b5e5555ULL,0x5c28fa08b03326f9ULL,+ 0xa9f5d8745a1251fbULL,0x967747a8c72725c7ULL,0x195c33e531ffe89eULL,0x609d210fe964935eULL,0xcafd6ca82fe12227ULL,0xaf9b5b960426469dULL,0x2e9ee04c5693183cULL,0x1084a333c8146fefULL,+ 0x56dab1c8321a518cULL,0xfd4439a68bce226fULL,0xe0b30d194facb9faULL,0xb5052f307583571bULL,0x1442641012afd476ULL,0xd02e417203fe624aULL,0xfc394f65531c92e6ULL,0x16d4bf5ad4bc0b52ULL,+ 0xce06b88210395755ULL,0x117ce6345ec1df80ULL,0xfefae513eff55e96ULL,0xcf36cba6fd7fed1eULL,0x7340eca9a40ebf88ULL,0xe6ec1bcfb3d37e12ULL,0xca51b64e86bbf9ffULL,0x4e0dbb588b40e05eULL,+ 0x120ad0bf5f8b8a84ULL,0xbfa00f36866f3edeULL,0xa8c6064ec30ebc2cULL,0xc39e40b823001e3bULL,0x9614f7cde7b1cbabULL,0xcd4420c704a56284ULL,0x8446a8f316857a19ULL,0x519b93b1e6f706cbULL,+ 0x96649933aed1d1f7ULL,0x566eaff350563090ULL,0x345057f0ad2e39cfULL,0x148ff65b1f832124ULL,0x042e89d4cf94cf0dULL,0x319bec84520c58b3ULL,0x2a2676265361aa0dULL,0xc86fa3028fbc87adULL,+ 0x3805e5b80863b664ULL,0x8be7ac6b3cabdb53ULL,0x9f7d70505dfeff91ULL,0x7dea8bd095896206ULL,0x28005a3b410e3c4eULL,0x24a4f0e9bc603ebfULL,0xcc4fd5ae4aec15d2ULL,0x4dc253f80f96641dULL,+ 0x359d7b9c7ea2ee34ULL,0x3fd0d94c09cc3a71ULL,0xbb53c31c3a1ea37aULL,0x533425facf818c87ULL,0x7cd199c3810156e0ULL,0x0ea020e430c16448ULL,0xe557ba094a642542ULL,0xe657e7e79465f5eaULL,+ 0xea723ad1fbc82439ULL,0xc726868bf896e9fdULL,0xd97c913c511c33ffULL,0x8a3fa8e2e2114231ULL,0x2a6c0e5608445b3eULL,0x2c4cd884f8d098d3ULL,0x7bf51faf2fea77d4ULL,0x709f208a7b1c4f71ULL,+ 0xfc83d2ab5c8b06d5ULL,0xb1a785a2fe4eac46ULL,0xb99315bc846f7779ULL,0xcf31d816ef9ea505ULL,0x2391fe6a15d7dc85ULL,0x2f132b04b4016b33ULL,0x29547fe3181cb4c7ULL,0xdb66d8a6650155a1ULL,+ 0x5b9e4843f45aac50ULL,0xc31e042e91eaaad0ULL,0x6e8c0b345a54eea0ULL,0xf0437b94962c7a57ULL,0xe4531ce8fe1d348bULL,0xe1489378e3786432ULL,0xd5e19c4a3f510d38ULL,0x4df3f016ce348b00ULL,+ 0x59cd0e8b593d070fULL,0x437575165255625dULL,0x551fdda75b7a0399ULL,0x7bb6e6b02dec1eebULL,0x729bb662334c0922ULL,0x3df631df0cf41b79ULL,0x01abf3c578f32402ULL,0xfcb4666c9cd33c88ULL,+ 0xb805b445735e843cULL,0x2a8e890d97379134ULL,0xebc7c10c52ab9f87ULL,0xcbb5e1ecb80a92b6ULL,0xd6ada2d9dc2c4efeULL,0xfccf504eae8cc7bdULL,0x650115acb2418a74ULL,0x8dd90e06c52bd80cULL,+ 0x6b66d7e1adc1696fULL,0x98ebe5930acd72d0ULL,0x65f24550cc1b7435ULL,0xce231393b4b9a5ecULL,0x234a22d4db067df9ULL,0x98dda095caff9b00ULL,0x1bbc75a06100c9c1ULL,0x1560a9c8939cf695ULL,+ 0xe4050f1cf1c367caULL,0x9bc85a9bc90fbc7dULL,0xa373c4a2e1a11032ULL,0xb64232b7ad0393a9ULL,0xf5577eb0167dad29ULL,0x1604f30194b78ab2ULL,0x0baa94afe829348bULL,0x77fbd8dd41654342ULL,+ 0x31f14802fcf0a7fdULL,0x42fd07895488b01eULL,0x71d78d6d9952b498ULL,0x8eb572d907ac5201ULL,0xe0a2a44c4d194a88ULL,0xd2b63fd9ba017e66ULL,0x78efc6c8f888aefcULL,0xb76f6bda4a881a11ULL,+ 0xa2f7932c68af43eeULL,0x5502468e703d00bdULL,0xe5dc978f2fb061f5ULL,0xc9a1904a28c815adULL,0xd3af538d470c56a4ULL,0x159abc5f193d8cedULL,0x2a37245f20108ef3ULL,0xfa17081e223f7178ULL,+ 0x1fe2a9b2b4b4b67cULL,0xc1d10df0e8020604ULL,0x9d64abfcbc8058d8ULL,0x8943b9b2712a0fbbULL,0x90eed9143b3def04ULL,0x85ab3aa24ce775ffULL,0x605fd4ca7bbc9040ULL,0x8b34a564e2c75dfbULL,+ 0x5c18acf88e2f7d90ULL,0xfdbf33d777be32cdULL,0x0a085cd7d2eb5ee9ULL,0x2d702cfbb3201115ULL,0xb6e0ebdb85c88ce8ULL,0x23a3ce3c1e01d617ULL,0x3041618e567333acULL,0x9dd0fd8f157edb6bULL,+ 0xb2b2610798fa7aaaULL,0x41209ee4f073aa4eULL,0xf1570359f2d6b19bULL,0xcbe6868cfc577cafULL,0x186c4bdc32c04dd3ULL,0xa6c35faecfeee397ULL,0xb4a1b312f086c0cfULL,0xe0a5ccc6d9461fe2ULL,+ 0x516ff3a36fa6110cULL,0x74fb1eb1fb93561fULL,0x6c0c90478457522bULL,0xcfd321046bb8bdc6ULL,0x2d6884a2cc80ad57ULL,0x7c27fc3586a9b637ULL,0x3461baedadf4e8cdULL,0x1d56251a617242f0ULL,+ 0xb84011a9431dd80eULL,0xeb7c7cca73306cd9ULL,0x20fadd29d1b3b730ULL,0x83858b5bfe37b3d3ULL,0xbf4cd193b6251d5cULL,0x1cca1fd31352d952ULL,0xc66157a490fbc051ULL,0x7990a63889b98636ULL,+ 0x892c81a321175ec1ULL,0x9159a505ee018109ULL,0xc70130532d8be316ULL,0x76060c21426fa2e5ULL,0x074d2dfc6b6f0f22ULL,0x9725fc64ca01a671ULL,0x3f6679b92770bd8eULL,0x8fe6604fd7c9b3feULL,+ 0xce711154b6e00a84ULL,0xd9fe7e4224890e60ULL,0xd10bc6c34560988fULL,0xbdc2ef526859b004ULL,0xdcf0d868d5c890eeULL,0x893115e6119c47dcULL,0xe97966fbee714567ULL,0x117813355c85aa53ULL,+ 0x71d530cc73204349ULL,0xc9df473d94a0679cULL,0xc572f0014261e031ULL,0x9786b71f22f135feULL,0xed6505fa6b64e56fULL,0xe2fb48e905219c46ULL,0x0dbec45bedf53d71ULL,0xd7d782f2c589f406ULL,+ 0x350fb66b73ed0966ULL,0x968e4b082886032bULL,0x5a16ed6e88390493ULL,0x0a83ce84a121edbeULL,0x7c86fc10a3d9cda0ULL,0x5a40a6d595ce67fbULL,0x6cb8cda7f937dbf6ULL,0x95b44768651f6283ULL,+ 0x06513c8a446cd7f4ULL,0x158c423b906d52a6ULL,0x71503261c423866cULL,0x4b96f57093c148eeULL,0x5daf9cc7239a8523ULL,0x611b597695ac4b8bULL,0xde3981db724bf7f6ULL,0x7e7d0f7867afc443ULL,+ 0x984f101ed6fc3837ULL,0x340bf99f5e1b3a09ULL,0xbb96036f06942626ULL,0x7bc878ab0c7da618ULL,0xb37416441c6fb035ULL,0xc65bd5aea182fe9fULL,0x1b9c2fb86cc7a67aULL,0x8d1b19af5ce68d7dULL,+ 0x3d1ab80c8ce59954ULL,0x742c5a9478222ac0ULL,0x3ddacbf894f878ddULL,0xfc085117e7d54a99ULL,0xfb0f1dfa21e38ec2ULL,0x1c7b59cb16f4ff7fULL,0x988752397ea888feULL,0x705d270cb10dc889ULL,+ 0xe5aa692a87dec0e1ULL,0x010ded8df7b39d00ULL,0x7b1b80c854cfa0b5ULL,0x66beb876a0f8ea28ULL,0x50d7f5313476cd0eULL,0xa63d0e65b08d3949ULL,0x1a09eea953479fc6ULL,0x82ae9891f499e742ULL,+ 0xab58b9105ca7d866ULL,0x582967e23adb3b34ULL,0x89ae4447cceac0bcULL,0x919c667c7bf56af5ULL,0x9aec17b160f5dcd7ULL,0xec697b9fddcaadbcULL,0x0b98f341463467f5ULL,0xb187f1f7a967132fULL,+ 0xeb5ddcb6ec7fae9fULL,0x995f2714efb66e5aULL,0xdee95d8e69445d52ULL,0x1b6c2d4609e27620ULL,0x32621c318129d716ULL,0xb03909f10958c1aaULL,0x8c468ef91af4af63ULL,0x162c429ffba5cdf6ULL,+ 0xe8cb5eef9c053df7ULL,0x8de25b37b300ea6fULL,0xdb03fa92c849cffbULL,0x242e43a7e84169bbULL,0xe4fa51f4dd6f958eULL,0x6925a77ff4445a8dULL,0xe6e72a50e90d8949ULL,0xc66648e32b1f6390ULL,+ 0x6c3b96f31711ebecULL,0x2da40f1fce98fdc4ULL,0xb99774d357b4411fULL,0x87c8bdf415b65bb6ULL,0xda3a89e3c2eef12dULL,0xde95bb9b3c7471f3ULL,0x600f225bd812c594ULL,0x54907c5d2b75a56bULL,+ 0x699e4d2945c1dd53ULL,0xcadc5898231debb5ULL,0xdf49fcc7a77f00e0ULL,0x93057bbfa73e5a0eULL,0x2f8b7ecd027a4cd1ULL,0x114734b3c614011aULL,0xe7a01db767677c68ULL,0x89d9be5e7e273f4fULL,+ 0xe0deee5931fba239ULL,0xf47424d398bd91d1ULL,0x0f8886f4071a3c1dULL,0x3f7d41e8a819233bULL,0x708623c2cf6eb998ULL,0x86bb49af609a287fULL,0x942bb24963c90762ULL,0x0ef6eea555a9654bULL,+ 0x4add4a2e649d4e57ULL,0xcd53a2b01917526eULL,0xc526233020b44ac4ULL,0x4028746abaa2c31dULL,0x5131839064291d4cULL,0xbf48f151ee5ad909ULL,0xcce57f597b185681ULL,0x7c3ac1b04854d442ULL,+ 0xa80d1db6f79588c0ULL,0xfa52fc69b55768ccULL,0x0b4df1ae7f54438aULL,0x0cadd1a7f9b46a4fULL,0xb40ea6b31803dd6fULL,0x488e4fa555eaae35ULL,0x9f047d55382e4e16ULL,0xc9b5b7e02f6e0c98ULL,+ 0xc19972d0b611c24bULL,0x1d468e6560a8f351ULL,0xeb7580697bcf6421ULL,0xec9dd0ee88fbc491ULL,0x5b59d2bf956c2e32ULL,0x73dc6864dcddf94eULL,0xfd5e2321bcee7665ULL,0xa7b4f8ef5e9a06c4ULL,+ 0x03cc8f17cf41c6e8ULL,0xf1f03c2a037b925cULL,0xc39c19cc66d2427cULL,0x823d24ba7b6c18e4ULL,0x32ef9013901f0b4fULL,0x684360f1f8941c2eULL,0x0ebaff522c28092eULL,0x7891e4e3256c932fULL,+ 0x174e8f82d8d38a9bULL,0x2e97c600e7de1391ULL,0xc5709850a1c175ddULL,0x969041a032ae5035ULL,0xcbfd533b76a2086bULL,0xd6bba71bd7c2e8feULL,0xb2d58ee6099dfb67ULL,0x3a8b342d064a85d9ULL,+ 0xf83cbf0502f40d9aULL,0x4681c4682c318a4dULL,0x985756180e9c2674ULL,0xbe79d0461847092eULL,0xaf1e480a78bd01e0ULL,0x6dd359e472a51db9ULL,0x62ce3821e3afbab6ULL,0xc5cee5b617733199ULL,+ 0x671ed8fc3b922bf8ULL,0xe4d8c0a04c29b133ULL,0x87eb12393b6e99c4ULL,0xaff3974c8793bebaULL,0x037494052c18df9bULL,0xc5c3a29391007139ULL,0x6a77234fe37a0b95ULL,0x02c29a21b661c96bULL,+ 0x5a52fe2e34d74e31ULL,0xa352c3103bf79ab6ULL,0x97ff6c5aabfeeb8fULL,0xbfbe8feff5c97305ULL,0xd6081ce6a7904608ULL,0x1f812f3ac4fca249ULL,0x9b24bc9ab9e5e200ULL,0x91022c6738012ee8ULL,+ 0x184de7d7cc5f4394ULL,0xb5551b5c4536e142ULL,0x2e89b212d34aa60aULL,0x14a96feaf50051d5ULL,0x4e21ef740d12bb0bULL,0xc522f02060b9677eULL,0x8b12e4672df7731dULL,0x39f803827b326d31ULL,+ 0xc12738b67c4a658aULL,0xb3c4763940e72182ULL,0x3b77be468798e44fULL,0xdc047df217a7f85fULL,0x2439d4c55e59d92dULL,0xcedca475e8e64d8dULL,0xa724cd0d87ca9b16ULL,0x35e4fd59a5540dfeULL,+ 0x9894344f3a29467aULL,0xde81e949c51eba6dULL,0xdaea066ba5e5c2f2ULL,0x3fc8a61408c8c7b3ULL,0x7adff88f06d0de9fULL,0xbbc11cf53b75ce0aULL,0x9fbb7accfbbc87d5ULL,0xa1458e267badfde2ULL,+ 0x1cb43668e039c256ULL,0x5f26fb8b7c17fd5dULL,0xeee426af79aa062bULL,0x072002d0d78fbf04ULL,0x4c9ca237e84fb7e3ULL,0xb401d8a10c82133dULL,0xaaa525926d7e4181ULL,0xe943083373dbb152ULL,+ 0x2f5fad1e6ee7c983ULL,0xeb0f9d7cb41328f5ULL,0x9ba68b441d78d5f7ULL,0xa06b3b9e35bc726fULL,0xa2550255593e1ff1ULL,0x552dd43ddfbec115ULL,0x2c48a7abbba8f046ULL,0xd4fc56a3ad0bf133ULL,+ 0xf92dda31be24319aULL,0x03f7d28be095a8e7ULL,0xa52fe84098782185ULL,0x276ddafe29c24dbcULL,0x80cd54961d7a64ebULL,0xe43608897f1dbe42ULL,0x2f81a8778438d2d5ULL,0x7e4d52a885169036ULL,+ 0x62f21cefba04b5d1ULL,0x9a442707224c7352ULL,0xbf07966c33c6171fULL,0xdb7ba8911e0816b0ULL,0x306fea59033745a9ULL,0x2aacf7e0c0a78f67ULL,0xb5aa3883ad251bf9ULL,0x345aede926bd7086ULL,+ 0x19e3d5b11d59715dULL,0xc7eaa762d788983eULL,0xe5a730b0abf1f248ULL,0xfbab8084fae3fd83ULL,0x65e50d2153765b2fULL,0xbdd4e083fa127f3dULL,0x9cf3c074397b1b10ULL,0x59f8090cb1b59fd3ULL,+ 0xdc1de17d98119f10ULL,0x74353c5d488c36a6ULL,0x14aaf33a3d8e23dfULL,0x31e075c078baf593ULL,0x0f7ca03a46d1ca3cULL,0x99c5e3ac47b660c7ULL,0x70d0241388fe2e59ULL,0x2e9a6be12a7ec005ULL,+ 0x7b15fd9d615faa8fULL,0x8fa1eb40968554edULL,0x7bb4447e7aa44882ULL,0x2bb2d0d1029fff32ULL,0x075e2a646caa6d2fULL,0x8eb879de22e7351bULL,0xbcd5624e9a506c62ULL,0x218eaef0a87e24dcULL,+ 0xac449695241fbd6fULL,0x67c9b170081c1223ULL,0x16868f21b56aac6fULL,0x34bd8fa3f8bcb721ULL,0x06b6bd33b6691c76ULL,0x6c924766381a7973ULL,0x6a12444ca54078dbULL,0xd02e91a96d1051ccULL,+ 0x37e5684744ddfa35ULL,0x9ccfc5c5dab3f747ULL,0x9ac1df3f1ee96cf4ULL,0x0c0571a13b480b8fULL,0x2fbeb3d54b3a7b3cULL,0x35c036695dcdbb99ULL,0x52a0f5dcb2415b3aULL,0xd57759b44413ed9aULL,+ 0x077379c00b33d3f8ULL,0x421883c67064e409ULL,0x2d0873d76c29c8f6ULL,0xbfa433a3d274c0c8ULL,0x56dc778f23a5891eULL,0xd663bf6535e2de04ULL,0x488fdb485db517ceULL,0x00bba55e19b226c2ULL,+ 0x1fe647d83d30a2c5ULL,0x0857f77ef78a81dcULL,0x11d5a334131a4a9bULL,0xc0a94af929d393f5ULL,0xbc3a5c0bdaa6ec1aULL,0xba9fe49388d2d7edULL,0xbb4335b4bb614797ULL,0x991c4d6872f83533ULL,+ 0xedbbeee78a058fb6ULL,0xb9d19ddcfb09121aULL,0xa41bb45bd34dddceULL,0x2dbc80b900964bc4ULL,0x4ed9137d1d6cb654ULL,0x1b9016db483d01c5ULL,0x5fc501bc6528e22eULL,0xb2d2f8816cad646bULL,+ 0x53258c28d2f01cb3ULL,0x93d6eaa3d75db0b1ULL,0x419a2b0de87d0db4ULL,0xa1e48f03d8fe8493ULL,0xf747faf6c508b23aULL,0xf137571a35d53549ULL,0x9f5e58e2fcf9b838ULL,0xc7186ceea7fd3cf5ULL,+ 0x5e76fb2f286bad39ULL,0xbad9efe39dcad1e2ULL,0x60e75190edc7e904ULL,0x6a6f063e0fecb5a5ULL,0x5150ed85aed8acc3ULL,0xb56ccfbc6d20af6cULL,0x7e0d1e982c69dbfaULL,0xabf5628a7c7e10a9ULL,+ 0x77b868cee978a1d3ULL,0xe3a68b337ab92d04ULL,0x5102979487a5b862ULL,0x5f0606c33a61d41dULL,0x2814be276f9326f1ULL,0x2f521c14c6fe3c2eULL,0x17464d7dacdf7351ULL,0x10f5f9d3777f7e44ULL,+ 0xb06b1244c5f95cd8ULL,0xda8c8af0f4ab95f4ULL,0x1bae59c2b9e5836dULL,0x07d51e7e3acffffcULL,0x01e15e6ac2ccbcdaULL,0x3bc1923f8528c3e0ULL,0x43324577a49fead4ULL,0x61a1b8842aa7a711ULL,+ 0x4fe7ee31b0e63d34ULL,0xf4600572a9e54fabULL,0xc0493334d5e7b5a4ULL,0x8589fb9206d54831ULL,0xaa70f5cc6583553aULL,0x0879094ae25649e5ULL,0xcc90450710044652ULL,0xebb0696d02541c4fULL,+ 0x172a5247d95ea168ULL,0x1758fada2970764aULL,0xac803a511d978169ULL,0x299cfe2ede77e01bULL,0x652a1e17b0a98927ULL,0x2e26e1d120014495ULL,0x7ae0af9f7175b56aULL,0xc2e22a80d64b9f95ULL,+ 0x758c1a3ea2dee7a6ULL,0xdcde2f3c734b2284ULL,0xaba445d24eaba6adULL,0x35aaf66876cee0a7ULL,0x7e0b04a9e5aa049aULL,0xe74083ad91103e84ULL,0xbeb183ce40afecc3ULL,0x6b89de9fea043f7aULL,+ 0xafbfb1eda4f7e665ULL,0x403cce6aa23df8e7ULL,0xb49cc83f1312c2f4ULL,0xe1cc2366771a9c34ULL,0x7ab6a6c0db92faacULL,0xacd15e0dec3befe1ULL,0x7f8ed988583a0f36ULL,0x1821de7705f9be09ULL,+ 0xb99f0e0399375235ULL,0x7614c847b9917970ULL,0xfec93ce9524ec067ULL,0xe40e7bf89b122520ULL,0xb5670631ee4c4774ULL,0x6f03847a3b04914cULL,0xc96e9429dc9dd226ULL,0x43489b6c8c57c1f8ULL,+ 0x7b9722a5c5f26464ULL,0xca4c3dfba442809aULL,0x7d10986723644810ULL,0x9e4951723c924f82ULL,0xef4a6968a2c5bc14ULL,0x750eac4f68de6b7aULL,0x4e01884d52a2cbb5ULL,0xac40830af4a5f446ULL,+ 0x0e299d23fe67ba66ULL,0x9145076093cf2f34ULL,0xf45b5ea997fcf913ULL,0x5be008438bd7dddaULL,0x358c3e05d53ff04dULL,0xbf7ccdc35de91ef7ULL,0xad684dbfb69ec1a0ULL,0x367e7cf2801fd997ULL,+ 0x8c54f1076103adf8ULL,0x2d813d6cbe8e9810ULL,0xb1466fa85fbd3c9bULL,0x68c65d2240e1ca76ULL,0xb81baa40255f9164ULL,0x5b34c3eed1a864b2ULL,0x3602209b122ca141ULL,0xe7d7248e885badebULL,+ 0x46ffd227cc2338fbULL,0x89ff6fa990e26153ULL,0xbe570779331a0076ULL,0x43d241c506e1f3afULL,0xfdcdb97dde9b62a3ULL,0x6a06e984a0ae30eaULL,0xc9bf16804fbddf7dULL,0x170471a2d36163c4ULL,+ 0xfd23e207a6469d43ULL,0xcb9f5f112f753a85ULL,0xde2625d4fbb5ca72ULL,0x82e4e54ab7b1c78bULL,0x2cd0ca5378b9e814ULL,0xfcd44051125b817aULL,0xb68f719f30cfd965ULL,0x31644719d848a974ULL,+ 0xff5ba8ae3113655eULL,0xfa2c6e2b57b83180ULL,0x1c48271977e0eabeULL,0xf9f3c555337fea97ULL,0x340f7022a42581cbULL,0xe1de0bc218f710e3ULL,0xee640adef62e5aa8ULL,0x16b2389149428940ULL,+ 0x5045738f25f653f5ULL,0xe42b8cb83764f635ULL,0xb4f89406dc11ffc3ULL,0x99593144b6b3e4aaULL,0x81c849f3c9740052ULL,0x2c9cf4c155ffc48bULL,0x6299e52177f67a49ULL,0x5869f6e3c00c6c62ULL,+ 0x361619e455950cc3ULL,0xc71d665c56b66bb8ULL,0xea034b34afac6d84ULL,0xa987f832e5e4c7e3ULL,0xa07427727a79a6a7ULL,0x56e5d017e26d6c23ULL,0x7e50b97638167e10ULL,0xaa6c81efe88aa84eULL,+ 0xb84186f75fe01576ULL,0x446e276cdea51395ULL,0xf3c5ef8105f3f8d4ULL,0x3d7f7df674f7f142ULL,0x7c69b565f9ef1656ULL,0x87efa4247c414ef6ULL,0xeb7e620d3d292060ULL,0x50b1de346eec21aeULL,+ 0x0ca1f3b7b0dc8595ULL,0x27de46089f1d9f2eULL,0x1af3bf39badd82a7ULL,0x79356a7965862448ULL,0xc0602345f5f9a052ULL,0x1a8b0f89139a42f9ULL,0xb53eee42844d40fcULL,0x93b0bfe54e5b6368ULL,+ 0x0f893a5dc8de610bULL,0xe8c515fb67e223ceULL,0x7774bfa64ead6dc5ULL,0x89d20f95925c728fULL,0x7a1e0966098583ceULL,0xa2eedb9493f2a7d7ULL,0x1b2820974c304d4aULL,0x0842e3dac077282dULL,+ 0xa1010e9d74cd06ffULL,0x9c17c7dfaca3eeacULL,0x74c86cd38063aa2bULL,0x8595c4b3734614ffULL,0xa3de00ca990f62ccULL,0xd9bed213ca0c3be5ULL,0x7886078adf8ce9f5ULL,0xddb27ce35cd44444ULL,+ 0x5a3097befc15aa1eULL,0x40d12548b54b0745ULL,0x5bad4706519a5f12ULL,0xed03f717a439dee6ULL,0x0794bb6c4a02c499ULL,0xf725083dcffe71d2ULL,0x2cad75190f3adcafULL,0x7f68ea1c43729310ULL,+ 0x9c7c581d26ee8382ULL,0xcf17dcc5359d638eULL,0xee8273abb728ae3dULL,0x1d112926f821f047ULL,0x1149847750491a74ULL,0x687fa761fde0dfb9ULL,0x2c2580227ea435abULL,0x6b8bdb9491ce7e3fULL,+ 0x9c806d8af7f91d0fULL,0x3b61b0f1a82a5728ULL,0x4640032d94d76754ULL,0x273eb5de47d834c6ULL,0x2988abf77b4e4d53ULL,0xb7ce66bfde401777ULL,0x9fba6b32715071b3ULL,0x82413c24ad3a1a98ULL,+ 0x75537b7e3cc8ac85ULL,0x8d725f57dd02753bULL,0xfd05ff64b737df2fULL,0x55fe8712f6d2531dULL,0x57ce04a96ab6b01cULL,0x69a02a897cd93724ULL,0x4f82ac35cf86699bULL,0x8242d3ad9cb4b232ULL,+ 0x69c435269be47be0ULL,0x323b7dd8cb28fea1ULL,0xfa5538ba3a6c67e5ULL,0xef921d701d378e46ULL,0xf92961fc3c4b880eULL,0x3f6f914e98940a67ULL,0xa990eb0afef0ff39ULL,0xa6c2920ff0eeff9cULL,+ 0xb23a03a553fb2b56ULL,0x6ce141e74e057f78ULL,0x796525c389e490d9ULL,0x0bc95725a31a7e75ULL,0x1ec567911220fd06ULL,0x716e3a3c408b0bd6ULL,0x31cd6bf7e8ebeba9ULL,0xa7326ca6bee6b670ULL,+ 0x70b63d32343bf1a9ULL,0x8fd3bd2837d1a6b1ULL,0x0454879c316865b4ULL,0xee959ff6c458efa2ULL,0x0461dcf89706dc3fULL,0x737db0e2164e4b2eULL,0x092626802f8843c8ULL,0x54498bbc7745e6f6ULL,+ 0x5341352b5acf6e10ULL,0xc50343fdafe652c3ULL,0x4af3792d18577a7fULL,0xe1a4c617af16823dULL,0x9b26d0cd33425d0aULL,0x306399ed9b7bc47fULL,0x2a792f33706bb20bULL,0x3121961498111055ULL,+ 0x4c1f428cd5f30851ULL,0x94dfed272a4f6630ULL,0x4df53772fc5d48a4ULL,0xdd2d5a2f933260ceULL,0x574115bdd44cc7a5ULL,0x4ba6b20dbd12533aULL,0x30e93cb8243057c9ULL,0x794c486a14de320eULL,+ 0x6095355699f241d7ULL,0xee4adbd7001a349dULL,0x0b35bf6aaa89e491ULL,0x7f0076f4136f7546ULL,0xd19a18ba9264da3dULL,0x6eb2d2cd62a7a28bULL,0xcdba941f8761c971ULL,0x1550518ba3be4a5dULL,+ 0xc232d97302f1cd1eULL,0xce87eacb1dd212a4ULL,0x6e4c8c73e69802f7ULL,0x12ef02901fffddbdULL,0x941ec74e1bcea6e2ULL,0xd0b540243cb92cbbULL,0x809fb9d47e8f9d05ULL,0x3bf16159f2992aaeULL,+ 0xb2497007eafbb1e1ULL,0xd75c9ce6e75b7a93ULL,0x3558352defb68d78ULL,0xa2f26699223f6396ULL,0xeb911ecfe469b17aULL,0x62545779e72d3ec2ULL,0x8ea47de782cb113fULL,0xebe4b0864e1fa98dULL,+ 0xbdb8e675b055cb40ULL,0x898f8e7b977b5167ULL,0xecc65651b82fb863ULL,0x565448146d88f01fULL,0xb0928e95263a75a9ULL,0xcfb6836f1a22fcdaULL,0x651d14db3f3bd37cULL,0x1d3837fbb6ad4664ULL,+ 0x20d3c982cf7d62d2ULL,0x1f36e29d23ba8150ULL,0x48ae0bf092763f9eULL,0x7a527e6b1d3a7007ULL,0xb4a89097581a85e3ULL,0x1f1a520fdc158be5ULL,0xf98db37d167d726eULL,0x8802786e1113e862ULL,+ 0xefb2149e36f09ab0ULL,0x03f163ca4a10bb5bULL,0xd029704506e20998ULL,0x56f0af001b5a3babULL,0x7af4cfec70880e0dULL,0x7332a66fbe3d913fULL,0x32e6c84a7eceb4bdULL,0xedc4a79a9c228f55ULL,+ 0xc37c7dd0c55c4496ULL,0xa6a9635725bbabd2ULL,0x5b7e63f2add7f363ULL,0x9dce37822e73f1dfULL,0xe1e5a16ab2b91f71ULL,0xe44898235ba0163cULL,0xf2759c32f6e515adULL,0xa5e2f1f88615eecfULL,+ 0x74519be7abded551ULL,0x03d358b8c8b74410ULL,0x4d00b10b0e10d9a9ULL,0x6392b0b128da52b7ULL,0x6744a2980b75c904ULL,0xc305b0aea8f7f96cULL,0x042e421d182cf932ULL,0xf6fc5d509e4636caULL,+ 0x795847c9d64cc78cULL,0x6c50621b9b6cb27bULL,0x07099bf8df8022abULL,0x48f862ebc04eda1dULL,0xd12732ede1603c16ULL,0x19a80e0f5c9a9450ULL,0xe2257f54b429b4fcULL,0x66d3b2c645460515ULL,+ 0x6ca4f87e822e37beULL,0x73f237b4253bda4eULL,0xf747f3a241190aebULL,0xf06fa36f804cf284ULL,0x0a6bbb6efc621c12ULL,0x5d624b6440b80ec6ULL,0x4b0724257ba556f3ULL,0x7fa0c3543e2d20a8ULL,+ 0xe921fa31e3229d41ULL,0xa929c65294531bd4ULL,0x84156027a6d38209ULL,0xf3d69f736bdb97bdULL,0x8906d19a16833631ULL,0x68a34c2e03d51be3ULL,0xcb59583b0e511cd8ULL,0x99ce6bfdfdc132a8ULL,+ 0x3facdaaaffcdb463ULL,0x658bbc1a34a38b08ULL,0x12a801f8f1a9078dULL,0x1567bcf96ab855deULL,0xe08498e03572359bULL,0xcf0353e58659e68bULL,0xbb86e9c87d23807cULL,0xbc08728d2198e8a2ULL,+ 0x8de2b7bc453cadd6ULL,0x203900a7bc0bc1f8ULL,0xbcd86e47a6abd3afULL,0x911cac128502effbULL,0x2d550242ec965469ULL,0x0e9f769229e0017eULL,0x633f078f65979885ULL,0xfb87d4494cf751efULL,+ 0xe1790e4bfc25419aULL,0x364672034bff3cfdULL,0xc8db638625b6e83fULL,0x6cc69f236cad6fd2ULL,0x0219e45a6bc68bb9ULL,0xe43d79b6297f7334ULL,0x7d445368465dc97cULL,0x4b9eea322a0b949aULL,+ 0x1b96c6ba6102d021ULL,0xeaafac782f4461eaULL,0xd4b85c41c49f19a8ULL,0x275c28e4cf538875ULL,0x35451a9ddd2e54e0ULL,0x6991adb50605618bULL,0x5b8b4bcd7b36cd24ULL,0x372a4f8c56f37216ULL,+ 0xc890bd73a6a5da60ULL,0x6f083da0dc4c9ff0ULL,0xf4e14d94f0536e57ULL,0xf9ee1edaaaec8243ULL,0x571241ec8bdcf8e7ULL,0xa5db82710b041e26ULL,0x9a0b9a99e3fff040ULL,0xcaaf21dd7c271202ULL,+ 0xb4e2b2e14f0dd2e8ULL,0xe77e7c4f0a377ac7ULL,0x69202c3f0d7a2198ULL,0xf759b7ff28200eb8ULL,0xc87526eddcfe314eULL,0xeb84c52453d5cf99ULL,0xb1b52ace515138b6ULL,0x5aa7ff8c23fca3f4ULL,+ 0xff0b13c3b9791a26ULL,0x960022dacdd58b16ULL,0xdbd55c9257aad2deULL,0x3baaaaa3f30fe619ULL,0x9a4b23460d881efdULL,0x506416c046325e2aULL,0x91381e76035c18d4ULL,0xb3bb68bef27817b0ULL,+ 0x15bfb8bf5116f937ULL,0x7c64a586c1268943ULL,0x71e25cc38419a2c8ULL,0x9fd6b0c48335f463ULL,0x4bf0ba3ce8ee0e0eULL,0x6f6fba60298c21faULL,0x57d57b39ae66bee0ULL,0x292d513022672544ULL,+ 0xf451105dbab093b3ULL,0x012f59b902839986ULL,0x8a9158023474a89cULL,0x048c919c2de03e97ULL,0xc476a2b591071cd5ULL,0x791ed89a034970a5ULL,0x89bd9042e1b7994bULL,0x8eaf5179a1057ffdULL,+ 0x6066e2a2d551ee10ULL,0x87a8f1d8727e09a6ULL,0x00d08bab2c01148dULL,0x6da8e4f1424f33feULL,0x466d17f0cf9a4e71ULL,0xff5020103bf5cb19ULL,0xdccf97d8d062ecc0ULL,0x80c0d9af81d80ac4ULL,+ 0x98857ceb1bf4581cULL,0xe635e186aca7b166ULL,0x278ddd22659722acULL,0xa0903c4c1db68007ULL,0x366e458948f21402ULL,0x31b49c14b96abda2ULL,0x329c4b09e0403190ULL,0x97197ca3d29f43feULL,+ 0x03e2de1cf3480d4aULL,0xf0d8edc7bc8acf1aULL,0xf23e330368295a9cULL,0xfadd5f68c546a97dULL,0x895597ad96f8acb1ULL,0xbddd49d5671bdae2ULL,0x16fcd52821dd43f4ULL,0xa5a454126619141aULL,+ 0xfa32c79f439f29cfULL,0x7bf321c04dd82a3bULL,0xff127f54eaa2c1b1ULL,0xa8365f2df35e9618ULL,0x852d29024d0ef8ddULL,0x395ce2c159228c4aULL,0xb69f44e8215afed3ULL,0x16c1f898b27458e3ULL,+ 0x8ce9b6bfc360e25aULL,0xe6425195075a1a78ULL,0x9dc756a8481732f4ULL,0x83c0440f5432b57aULL,0xc670b3f1d720281fULL,0x2205910ed135e051ULL,0xded14b0edb052be7ULL,0x697b3d27c568ea39ULL,+ 0xdef29005dc453233ULL,0xc208c47a2fac4bcfULL,0x6057a3feac3d55acULL,0x1723725d902c1207ULL,0x9c31c62733eb0fecULL,0x4913ccdbbb3c63bbULL,0x113e542b07305838ULL,0x9d48e72a310c2d97ULL,+ 0x54424ec4d9bbeb3dULL,0x34ceafe3d7b2921cULL,0x5e68022e296d37c5ULL,0xa28e0a2b359f16b0ULL,0xfdd82dd9bc3f9d73ULL,0x6939a8f9baf3e1ffULL,0x55cff45c31736dc4ULL,0x910f56427892e8e7ULL,+ 0xde09b349dfe39260ULL,0x984612f773549093ULL,0x7cede28167853b02ULL,0x7d809bb429d17703ULL,0x450b6bfb2756c4f0ULL,0xc59ff9ba93f02b80ULL,0x3e69545720ad9561ULL,0x0c7cf0be3331e2c7ULL,+ 0x2e599b9afb3ff9edULL,0x28c2e0ab17f6515cULL,0x1cbee4fd474da449ULL,0x071279a44f364452ULL,0x97abff6601fbe855ULL,0x3ee394e85fda51c4ULL,0x190385f667597c0bULL,0x6e9fccc6a27ee34bULL,+ 0xced2d419362fb228ULL,0x894637c206aa0be4ULL,0x7a4fc55eb294b197ULL,0xd9cbac1cfd4ca1e8ULL,0x068b74800ccdb6ceULL,0xca4c556580dfaa49ULL,0xe835382176033b78ULL,0x35db7525c5ce98a7ULL,+ 0x8cf5927274fd1997ULL,0x987d2031ffadeb58ULL,0x5647c6c3d4db260cULL,0xf08bb13b985543beULL,0x566eeb1056fad695ULL,0x39e17dde68334cc7ULL,0x8a97b3bb7ddd1db2ULL,0xf91199d8c1c5a300ULL,+ 0x402fa437bdc47fe4ULL,0x35bd25234f3751f0ULL,0x8c2281b7cf57d485ULL,0x50083ea58f607cb6ULL,0x6f41e480df6d730dULL,0x1164e47e91bb06a2ULL,0xd9040c22391fb48aULL,0xe12df251da23dda7ULL,+ 0x0b89de9314092ebbULL,0xf17256bd428e240cULL,0xcf89a7f393d2f064ULL,0x4f57841ee1ed3b14ULL,0x4ee14405e708d855ULL,0x856aae7203f1c3d0ULL,0xc8e5424fbdd7eed5ULL,0x3333e4ef73ab4270ULL,+ 0xf9cf2b5148f835b1ULL,0x4a70faf32adaaba8ULL,0xa0d2e24fed7beadeULL,0x2b1e4e6715f04032ULL,0xeadbc0b91fb3ceeeULL,0xb817b0863a54b0b4ULL,0x14a787257fd4a188ULL,0xff13304623482e60ULL,+ 0x312012ec4efe42dcULL,0x7251b2c2c664b2bcULL,0x996c2e6b798f9cb9ULL,0x3543376a3b8f3465ULL,0x337ae8416fbfb6a9ULL,0xe0893a840cb91a03ULL,0x53744e9d7b02d855ULL,0x7e673186206d473fULL,+ 0x9509996f3ef143dbULL,0x9cf1e82e399378bcULL,0xb59cd09b0b8ccc89ULL,0x64b4a2fc52cda6beULL,0xd3bda8b31bcd55dfULL,0xfec4e87d2507cb37ULL,0x3d48a85eb610e49bULL,0x02fbe1bd1f9cc445ULL,+ 0x3bc77adedda492f8ULL,0xc11a3aea78297205ULL,0x5e89a3e734931b4cULL,0x17512e2e9f5694bbULL,0x5dc349f3177bf8b6ULL,0x232ea4ba08c7ff3eULL,0x9c4f9d16f511145dULL,0xccf109a333b379c3ULL,+ 0x60e2857080eb24a9ULL,0x7bedfb4d488e0cfdULL,0x721ebbd7c259cdb8ULL,0x0b0da855bc6390a9ULL,0x2b4d04dbde314c70ULL,0xcdbf1fbc6c32e846ULL,0x33833eabb162fc9eULL,0x9939b48bb0dd3ab7ULL,+ 0x96892c1f711b0eb9ULL,0xb905f2c8780ab954ULL,0xace26309a20792dbULL,0xec8ac9b30684e126ULL,0x486ad8b6b40a2447ULL,0x60121fc19fe3fb24ULL,0x5626fccf1a8e3b3fULL,0x4e5686226ad1f394ULL,+ 0x5cfbbb22236f4a98ULL,0x0b0c59e9066800bbULL,0x4ac69a8f5a9a7774ULL,0x2b33f804d6bec948ULL,0xb372929532e6c466ULL,0x68956d0f4e599c73ULL,0xa47a249f155c31ccULL,0x24d80f0de1ce284eULL,+ 0x5a4b46c64a8a3d62ULL,0x8469c4d0247743d2ULL,0x2bb3a13d88f7e433ULL,0x62b23a1001be5849ULL,0xe83596b4a63d1a4cULL,0x454e7fea7d183f3eULL,0x643fce6117afb01cULL,0x4e65e5e61c4c3638ULL,+ 0xb7e830e3dc09508bULL,0xfaf6d2cf74317655ULL,0x72606cebdf690355ULL,0x48bb92b3d0c3ded6ULL,0x65b754845c7cf892ULL,0xf6cd7ac9d5d5f01fULL,0xc2c30a5996401d69ULL,0x91268650ed921878ULL,+ 0xe5db77176add8545ULL,0x1b71cb6672c49b66ULL,0xd856073968421d77ULL,0x03840fe883e3afeaULL,0xb391dad51ec69977ULL,0xae243fb9307f6726ULL,0xc88ac87be8ca160cULL,0x5174cced4ce355f4ULL,+ 0x752067f8ff81578eULL,0x786221509045447dULL,0xc0c22fcf0505aa6fULL,0x1030f0a66bed1c77ULL,0x31f29f151f0bd739ULL,0x2d7989c7e6debe85ULL,0x5c070e728e677e98ULL,0x0a817bd306e81fd5ULL,+ 0xc1e17eb6cbc613e5ULL,0x33131d55497ea61cULL,0x2f69d39eaf7eded5ULL,0x73c2f434de6af11bULL,0x4ca52493a4a375faULL,0x5f06787cb833c5c2ULL,0x814e091f3e6e71cfULL,0x76451f578b746666ULL,+ 0x01c7e082e1539388ULL,0xfd286f30759a9c6bULL,0x94581041176bacfbULL,0xe580f07c3bc3de53ULL,0xdcdb6f75884d772fULL,0xd75c3bb840bb9d4fULL,0xdc6c2e4edb083011ULL,0xe18789a2cd9c298dULL,+ 0x5ee6ab8495fe1347ULL,0xab0f6c396f24503cULL,0x807e3ffb4486dd6bULL,0xf00b6c748002fef5ULL,0x48bff9a6a7862999ULL,0x85e5a06cbed89e26ULL,0x86d311af3d8419ebULL,0x24f3ad7834733f16ULL,+ 0x5e20551311820d44ULL,0x0c651bcc86c4473aULL,0x1d230c2b9bd80eefULL,0x042c4a1207515be5ULL,0x42517ca0bfe9e284ULL,0xe8f605782369827aULL,0x184f04f01638699dULL,0x174618edf2bc6d05ULL,+ 0x5e3e03fc6c68d687ULL,0x3e732c3d1ff052c7ULL,0xf2d0efa66ed16e7aULL,0x63d92b26b65bb746ULL,0xffcd82badd44867cULL,0xa71b4a9ef8c081b8ULL,0x6c1676a7736c8785ULL,0xbe2c06169d8932d0ULL,+ 0x7bfa1a4b9eca1c9fULL,0x960bc1dc8ce5e535ULL,0xe267d9f317eec30aULL,0x06fb89ef6c257d38ULL,0x2328999ad364a26dULL,0x69b794cb26eaab58ULL,0xad28ab1fb85ba596ULL,0x05dcbff356d0aa94ULL,+ 0x53376d282bcffbc4ULL,0x708817a706eadb7aULL,0x6ff50e05cd35ae69ULL,0x63b5fb7574bc7fdeULL,0x71c9e953e7fe08c4ULL,0xb4d8bfd4f583ca18ULL,0xde8d788245e81c5cULL,0xa5f5e93ce0474138ULL,+ 0x426c160f293c9f31ULL,0x8eb56333e864d7a7ULL,0xbe1164023ebbba30ULL,0x64c2bae32fd5a302ULL,0x800601e1265aff7bULL,0x52d8a88066fd4b14ULL,0x5aba20e746075a9cULL,0xdaa32bf87e1234c6ULL,+ 0x80f9bdef694db7e0ULL,0xedca8787b9fcddc6ULL,0x51981c3403b8dce1ULL,0x4274dcf170e10ba1ULL,0xf72743b86def6d1aULL,0xd25b1670ebdb1866ULL,0xc4491e8c050c6f58ULL,0x2be2b2ab87fbd7f5ULL,+ 0x3e0e5c9dd111f8ecULL,0xbcc33f8db7c4e760ULL,0x702f9a91bd392a51ULL,0x7da4a795c132e92dULL,0x1a0b0ae30bb1151bULL,0x54febac802e32251ULL,0xea3a5082694e9e78ULL,0xe58ffec1e4fe40b8ULL,+ 0xfbb8349d29c4120bULL,0x9f94391fc0d0d915ULL,0xc4074fa75410ba51ULL,0xa66adbf6150a5911ULL,0xc164543c34bfca38ULL,0xe0f27560b9e1ccfcULL,0x99da0f53e820219cULL,0xe8234498c6b4997aULL,+ 0x7b23c513516e19e4ULL,0x56e2e847c5c4d593ULL,0x9f727d735ce71ef6ULL,0x5b6304a6f79a44c5ULL,0x6638a7363ab7e433ULL,0x1adea470fe742f83ULL,0xe054b8545b7fc19fULL,0xf935381aba1d0698ULL,+ 0xb5504f9d918e4936ULL,0x65035ef6b2513982ULL,0x0553a0c26f4d9cb9ULL,0x6cb10d56bea85509ULL,0x48d957b7a242da11ULL,0x16a4d3dd672b7268ULL,0x3d7e637c8502a96bULL,0x27c7032b730d463bULL,+ 0x55366b7d5846426fULL,0xe7d09e89247d441dULL,0x510b404d736fbf48ULL,0x7fa003d0e784bd7dULL,0x25f7614f17fd9596ULL,0x49e0e0a135cb98dbULL,0x2c65957b2e83a76aULL,0x5d40da8dcddbe0f8ULL,+ 0x37f68bb4a595939dULL,0x0355647928740217ULL,0x8e740e7c84ad7612ULL,0xd89bc8439044695fULL,0xf7f3da5d85a9184dULL,0x562563bb9fc0b074ULL,0x06d2e6aaf88a888eULL,0x612d8643161fbe7cULL,+ 0x9fb3bba354530bb2ULL,0xbde3ef77cb0869eaULL,0x89bc90460b431163ULL,0x4d03d7d2e4819a35ULL,0x33ae4f9e43b6a782ULL,0x216db3079c88a686ULL,0x91dd88e000ffedd9ULL,0xb280da9f12bd4840ULL,+ 0x458f86913e538cd7ULL,0xa7001f6c8e08ad53ULL,0x52b8c6e6bf5d15ffULL,0x548234a4011215ddULL,0xff5a9d2d3d5b4045ULL,0xb0ffeeb64a904190ULL,0x55a3aca448607f8bULL,0x8cbd665c30a0672aULL,+ 0xa37f3573f37f5937ULL,0xeb0f6c7dd1e4fca5ULL,0x2965a554ac8ab0fcULL,0x17fbf56c274676acULL,0x2e2f6bd9acf7d720ULL,0x41fc8f8810224766ULL,0x517a14b385d53befULL,0xdae327a57d76a7d1ULL,+ 0x515d5c891f5f82dcULL,0x9a7f67d76361079eULL,0xa8da81e311a35330ULL,0xe44990c44b18be1bULL,0xc7d5ed95af103e59ULL,0xece8aba78dac9261ULL,0xbe82b0999394b8d3ULL,0x6830f09a16adfe83ULL,+ 0x43c41ac194d7d9b1ULL,0x5bafdd82c82e7f17ULL,0xdf0614c15fda0fcaULL,0x74b043a7a8ae37adULL,0x3ba6afa19e71734cULL,0x15d5437e9c450f2eULL,0x4a5883fe67e242b1ULL,0x5143bdc22c1953c2ULL,+ 0xa2a9ce7c6b53f5f9ULL,0x642465951b176d99ULL,0xb1298d36b95c081bULL,0x53505bb81d9a9ee6ULL,0x3f6f9e61f2ba70b0ULL,0xd07e16c98afad453ULL,0x9f1694bbe7eb4a6aULL,0xdfebced93cb0bc8eULL,+ 0xc676d7f2b1f3390bULL,0x9f7a1b8ca5b61272ULL,0x4ebebfc9c2e127a9ULL,0x4602500c5dd997bfULL,0x7f09771c4711230fULL,0x058eb37c020f09c1ULL,0xab693d4bfee5e38bULL,0x9289eb1f4653cbc0ULL,+ 0xa44d2b391770f5a7ULL,0xe4d4d7910e44eb82ULL,0x42e69d1e3f69712aULL,0xbf11c4d6ac6a820eULL,0xb5e7f3e542c4224cULL,0xd6b4e81c449d941cULL,0x5d72bd165450e878ULL,0x6a61e28aee25ac54ULL,+ 0x54da9dc7ab952578ULL,0xb5423df226e84d0bULL,0xa8b64eeb9b872042ULL,0xac2057825990f6dfULL,0x4ff696eb21f4c77aULL,0x1a79c3e4aab273afULL,0x29bc922e9436b3f1ULL,0xff807ef8d6d9a27aULL,+ 0xc7f3a8f833f6746cULL,0x21e46f65fea990caULL,0x915fd5c5caddb0a9ULL,0xbd41f01678614555ULL,0x346f4434426ffb58ULL,0x8055943614dbc204ULL,0xf3dd20fe5a969b7fULL,0x9d59e956e899a39aULL,+ 0x3c2f0ba9b733aa5fULL,0xdece47cbf05af235ULL,0xf8e3f715a2ac82a5ULL,0xc97ba6412203f18aULL,0xc3af550409c11060ULL,0x56ea2c0546af512dULL,0xfac28daff3f28146ULL,0x87fab43a959ef494ULL,+ 0x09891641d4c5105fULL,0x1ae80f8e6d7fbd65ULL,0x9d67225fbee6bdb0ULL,0x3b433b597fc4d860ULL,0x44e66db693e85638ULL,0xf7b59252e3e9862fULL,0xdb785157665c32ecULL,0x702fefd7ae362f50ULL,+ 0xfe756a5c97290293ULL,0xbf04a19cd388acbfULL,0xfbbbb9cf5e916bdaULL,0xf489527391f93becULL,0xdee07ec32a5923d7ULL,0xc7bc949bfde0c370ULL,0xbd5121750419d8fcULL,0x54f5d4763fdcc93fULL,+ 0x3754475d0fefb0c3ULL,0xd48fb56b46d7c35dULL,0xa070b633363798a4ULL,0xae89f3d28fdb98e6ULL,0x970b89c86363d14cULL,0x8981752167abd27dULL,0x9bf7d47444d5a021ULL,0xb3083bafcac72aeeULL,+ 0x0acda2ffcc5e62e9ULL,0x3b8b7d755edb02a4ULL,0xa700741c66120c76ULL,0xf77e847f7d974064ULL,0x0d310678a5e3d464ULL,0xde68b1f346bf35a3ULL,0xcae83028d32f9043ULL,0x724e4717517cb0cbULL,+ 0x389741debe949a44ULL,0x638e9388546a4fa5ULL,0x3fe6419ca0047bdcULL,0x7047f648aaea57caULL,0x54e48a9041fbab17ULL,0xda8e0b28576bdba2ULL,0xe807eebcc72afddcULL,0x07d3336df42577bfULL,+ 0xfae8563b4f3011dbULL,0xda33776536610c03ULL,0xad4f6f2a6381af0bULL,0xc277984cd95378ecULL,0x5ab0a10c5751d2b2ULL,0x70a18bb97a4bf3f4ULL,0x38d07ad4eae3caf3ULL,0xe8ef552fec430361ULL,+ 0x62a8c244bfe20925ULL,0x91c19ac38fdce867ULL,0x5a96a5d5dd387063ULL,0x61d587d421d324f6ULL,0xe87673a2a37173eaULL,0x2384800853778b65ULL,0x10f8441e05bab43eULL,0xfa11fe124621efbeULL,+ 0xedd0389a8391d54bULL,0xdac74c08c8afe546ULL,0x8525a4ad5be60bbdULL,0x2419ac9690ad7b87ULL,0x078a3a0277eee51bULL,0xe86ecf367239768dULL,0xcb0a259d8fd48035ULL,0x94db43cb9d29ca5bULL,+ 0x047b772e81685d7bULL,0x23f27d81bf34a976ULL,0xc27608e2915f48efULL,0x3b0b43faa521d5c3ULL,0x7613fb2663ca7284ULL,0x7f5729b41d4db837ULL,0x87b14898583b526bULL,0x00b732a6bbadd3d1ULL,+ 0x4fffa25b90f8550aULL,0x254db3d31c8dae9dULL,0x58cef963c1fbb232ULL,0xad1cb481a4bfdf0fULL,0x84d26ea1958773c2ULL,0x58622664010114f1ULL,0xeadb3a87f051e67eULL,0xf3185722b69e45c6ULL,+ 0x8e02f4262048e396ULL,0x436b50b6383d9de4ULL,0xf78d3481471e85adULL,0x8b01ea6ad005c8d6ULL,0xd3c7afee97015c07ULL,0x46cdf1a94e3ba2aeULL,0x7a42e50183d3a1d2ULL,0xd54b5268b541dff4ULL,+ 0xe120c4f948a48e22ULL,0xf24977eed0335a96ULL,0x9af3442336151c7bULL,0xe2815a7fd36648d8ULL,0xb4d2deba66e0a6b2ULL,0x783a84cf817515e8ULL,0x78424c0bff3ff24aULL,0x12dd1bb638e1c5d9ULL,+ 0x3f24cf304e23e9bcULL,0x4387f816126e3624ULL,0x26a46a033b0b6d61ULL,0xaf1bc8458b2d777cULL,0x25c401ba527de79cULL,0x0e1346d44261bbb6ULL,0x4b96c44b287b4bc7ULL,0x658493c75254562fULL,+ 0xfcb0e9d8fdd41d98ULL,0x8be980c1bcc7c7fbULL,0xa72e86506f8fa4d9ULL,0x356b14ad748cb88dULL,0xfd9fccefea6178f2ULL,0xc84a620d78bb0e35ULL,0xbc75367c62f391a9ULL,0x6a83a5c623100c05ULL,+ 0x23f949feb8a24a20ULL,0x17ebfed1f52ca53fULL,0x9b691bbebcfb4853ULL,0x5617ff6b6278a05dULL,0x241b34c5e3c99ebdULL,0xfc64242e1784156aULL,0x4206482f695d67dfULL,0xb967ce0eee27c011ULL,+ 0xb4480f0441c23fa3ULL,0xb4712eb0c1989a2eULL,0x3ccbba0f93a29ca7ULL,0x6e205c14d619428cULL,0x90db7957b3641686ULL,0x0432691d45ac8b4eULL,0x07a759acf64e0350ULL,0x0514d89c9c972517ULL,+ 0xe3b22c6bc4fe3c39ULL,0xba4a81536c7bebdfULL,0xf23ab6b725693459ULL,0x53bc377014922b11ULL,0x4645c8ab5afc60dbULL,0xaa02235520b9f2a3ULL,0x52a2954cce0fc507ULL,0x8c2731bb7ce1c2e7ULL,+ 0x5066efb6d9790ed6ULL,0xa77a0cbca6aa793bULL,0x1a915f3c223e042eULL,0x1c5def0469c5874bULL,0x0e83007873b6c1daULL,0x55cf85d2fcd8557aULL,0x0f7c7c760460f3b1ULL,0x87052acb46e58063ULL,+ 0x6a7091c2e48fb889ULL,0x26882c137b8a9d06ULL,0xa24986631b82a0e2ULL,0x844ed7363518152dULL,0x282f476fd86e27c7ULL,0xa04edaca04afefdcULL,0x8b256ebc6119e34dULL,0x56a413e90787d78bULL,+ 0x16eab6a20d645fd6ULL,0x632cbd8df61d3148ULL,0xcc1bf7cf62079ae9ULL,0x257ee5c7f33eccbbULL,0xbf6b34a81680ac73ULL,0xaa084e8872c77aa0ULL,0x7b5a864e05a0a1d1ULL,0x0641f6db359a1b16ULL,+ 0xf01d095dc8385050ULL,0x0d54a5d5df4b441cULL,0x2a37ccb40927706aULL,0xdf008f5445d7eb7eULL,0x74eb34f35bf716c7ULL,0x57a65b58641bd6caULL,0xef345e4835e6fa02ULL,0x191f913b88342a09ULL,+ 0x1554d46da670ff1dULL,0x24833d88cb97a1ccULL,0x8fa6ab3cded97493ULL,0x215e037189926498ULL,0x549bd592e56d74ffULL,0x58a8caf543b5e1ecULL,0x3c6087a323e93cb9ULL,0x8b0549875648b83cULL,+ 0x82ee061d5a74be50ULL,0xe41781c4dea16ff5ULL,0xe0b0c81e99bfc8a2ULL,0x624f4d690b547e2dULL,0x3a83545dbdcc9ae4ULL,0x2573dbb6409b1e8eULL,0x482960c4a6c93539ULL,0xf01059ad5ae18798ULL,+ 0xc431a238013ff83bULL,0x7c0018b2fad69d08ULL,0x99aeb52a4c9589eaULL,0x121f41ab9b1cf19fULL,0x0cfbbcbaef0f5958ULL,0x8deb3aeb7be8fbdcULL,0x12b954081f15aa31ULL,0x5acc09b34c0c06fdULL,+ 0x775cbfa86d518ffbULL,0xdecee1f6930f124bULL,0x9a402804f5e81d0fULL,0x0e8225c52a0eeb2fULL,0x884a5d39fee9e867ULL,0x9540428ffb505454ULL,0xb2bf2e20107a70d1ULL,0xd9917c3ba010b2aaULL,+ 0xa98f42fa3d843d53ULL,0x33777cc613ef927aULL,0xc440cdbecb84ca74ULL,0x8c22f9631dc7c5ddULL,0x4bc82b70c8d94708ULL,0x7e0b43fcc814364fULL,0x286d4e2486f59b7eULL,0x1abc895e4d6bf4c4ULL,+ 0x38151e274d559d96ULL,0x4f18c0d3b8db6c01ULL,0x49a3aa836f9921afULL,0xdbeab27b8c046029ULL,0x242b9eaa7040bf3bULL,0x39c479e51614b091ULL,0x338ede2b0e4baf5dULL,0x5bb192b7f0a53945ULL,+ 0x896d572337e440d7ULL,0x685c5fd9ade23f68ULL,0xb5b1a26dc2c64918ULL,0xb9390e30dad6580cULL,0x87911c4e7dee5b9bULL,0xb90c5053deb04f6eULL,0x37b942a18f065aa6ULL,0x34acdf2a1ca0928dULL,+ 0x733b64d39de40ca3ULL,0x1d4b6d6fd2f3857eULL,0xbe2be8e9b2ed92f7ULL,0x64ca7047b77da248ULL,0xc65dae9b8da99315ULL,0x9c1451750fc698a4ULL,0x8a296b94ff958c27ULL,0x38684e0843950097ULL,+ 0x7872e34b3390ff23ULL,0x968ce4abde7d18efULL,0x9b4a745e627fe7b1ULL,0x9607b0a0caff3e2aULL,0x1b05818eeb40e3a5ULL,0x6ac62204c0fa8d7aULL,0xb5b9058571ed4809ULL,0xb2432ef0f7cb65f2ULL,+ 0x715c9f973112795fULL,0xe8244437984e6ee1ULL,0x55cb4858ecb66bcdULL,0x7c136735abaffbeeULL,0x546615955dbec38eULL,0x51c0782c388ad153ULL,0x9ba4c53ac6e0952fULL,0x27e6782a1b21dfa8ULL,+ 0xfeb09740e2c2bf15ULL,0x627a2205a9e99704ULL,0xec8d73d0c2fbc565ULL,0x223eed8fc20c8de8ULL,0x1ee32583a8363b49ULL,0x1a0b6cb9c9c2b0a6ULL,0x49f7c3d290dbc85cULL,0xa8dfbb971ef4c1acULL,+ 0xc16c236e846e364fULL,0x7f33527cdea50ca0ULL,0xc48107750926b86dULL,0x6c2a36090598e70cULL,0xa6755e52f024e924ULL,0xe0fa07a49db4afcaULL,0x15c3ce7d66831790ULL,0x5b4ef350a6cbb0d6ULL,+ 0x42806b2da6dc1d29ULL,0xd3030009f871e144ULL,0xa1feb333aaf49276ULL,0xb5583b9ec70bc04bULL,0x1db0be7895695f20ULL,0xfc84181189d012b5ULL,0x6409f27205f61643ULL,0x40d34174d5883128ULL,+ 0x05214c050f15dde9ULL,0xa47a76a80d5f2b82ULL,0xbb254d3062e82b62ULL,0x11a05fe03ec955eeULL,0x7eaff46e9d529b36ULL,0x55ab13018f9e3df6ULL,0xc463e37199317698ULL,0xfd251438ccda47adULL,+ 0x8c3c669c72ba075bULL,0x89f78b55ba469015ULL,0x5706aade3e9f8ba8ULL,0x6d8bd565b32d7ed7ULL,0x25f4e63b805f08d6ULL,0x7f48200dc3bcc1b5ULL,0x4e801968b025d847ULL,0x74afac0487cbe0a8ULL,+ 0xe2a37598a9d82abfULL,0x5f188ccbe6c170f5ULL,0x816822005066b087ULL,0xda22c212c7155adaULL,0x151e5d3afbddb479ULL,0x4b606b846d715b99ULL,0x4a73b54bf997cb2eULL,0x9a1bfe433ecd8b66ULL,+ 0x79732522cccc18adULL,0xaadf3f8df1a6e027ULL,0xf7382c9317c2354dULL,0x5ce1680cd818b689ULL,0x359ebbfcd9ecbee9ULL,0x4330689c1cae62acULL,0xb55ce5b4c51ac38aULL,0x7921dfeafe238ee8ULL,+ 0xe13122f3dbfb894eULL,0xbe9b79f6ce274b18ULL,0x85a49de5ca58aadfULL,0x2495775811487351ULL,0x111def61bb939099ULL,0x1d6a974a26d13694ULL,0x4474b4ced3fc253bULL,0x3a1485e64c5db15eULL,+ 0x65994ddb0f5f27caULL,0xe85461fba80d59ffULL,0xff05481a66601023ULL,0xc665427afc9ebbfbULL,0xb0571a697587fd52ULL,0x935289f88d49efceULL,0x61becc60ea420688ULL,0xb22639d913a786afULL,+ 0x5afddab61430c9abULL,0x0bdd41d32238e997ULL,0xf0947430418042aeULL,0x71f9addacdddc4cbULL,0x7090c016c52dd907ULL,0xd9bdf44d29e2047fULL,0xe6f1fe801b1011a6ULL,0xb63accbcd9acdc78ULL,+ 0x264c76680448087cULL,0xac30903f71432daeULL,0x3851b26600f9bf47ULL,0x400ed3116cdd6d03ULL,0x045e79fef8fd2424ULL,0xfdfd974afa6da98bULL,0x45c9f6410c1e673aULL,0x76f2e7335b2c5168ULL,+ 0x7817acab4baef62eULL,0x9f5a2202a85b91e8ULL,0x9666ebe66ce57610ULL,0x32ad31f3f73bfe03ULL,0x628330a425bcf4d6ULL,0xea950593515056e6ULL,0x59811c89e1332156ULL,0xc89cf1fe8c11b2d7ULL,+ 0x889e5acbc46d7ce1ULL,0x9a515bb78b085877ULL,0xfac1a03d0b7a5050ULL,0x7d3e738af2926035ULL,0x861cc2ce2a6cb0ebULL,0x6f2e29558f7adc79ULL,0x61c4d45133016376ULL,0xd9fd2c805ad59090ULL,+ 0x0ad7337ac0b7eff3ULL,0x8552225ec5e48b3cULL,0xe6f78b0c73f13a5fULL,0x5e70062e82349cbeULL,0x6b8d5048e7073969ULL,0x392d2a29c33cb3d2ULL,0xee4f727c4ecaa20fULL,0xa068c99e2ccde707ULL,+ 0x1888d65861a023efULL,0x1d72aab4b9e5246eULL,0xa9a26348e5563ec0ULL,0xa0971963c3439a43ULL,0x567dd54badb9b5b7ULL,0x73fac1a1c45a524bULL,0x8fe97ef7fe38e608ULL,0x608748d23f384f48ULL,+ 0xebde86ec1ed66f18ULL,0x225d906bd61fce43ULL,0x5cab07d6e8bed74dULL,0x16e4617f27855ab7ULL,0x6568aaddb2fbc3ddULL,0xedb5484f8aeddf5bULL,0x878f20e86dcf2fadULL,0x3516497c615f5699ULL,+ 0xef0a3fecfa181e69ULL,0x9ea02f8130d69a98ULL,0xb2e9cf8e66eab95dULL,0x520f2beb24720021ULL,0x621c540a1df84361ULL,0x1203772171fa6d5dULL,0x6e3c7b510ff5f6ffULL,0x817a069babb2bef3ULL,+ 0x83572fb6b294cda6ULL,0x6ce9bf75b9039f34ULL,0x20e012f0095cbb21ULL,0xa0aecc1bd063f0daULL,0x57c21c3af02909e5ULL,0xc7d59ecf48ce9cdcULL,0x2732b8448ae336f8ULL,0x056e37233f4f85f4ULL,+ 0x8a10b53189e800caULL,0x50fe0c17145208fdULL,0x9e43c0d3b714ba37ULL,0x427d200e34189accULL,0x05dee24fe616e2c0ULL,0x9c25f4c8ee1854c1ULL,0x4d3222a58f342a73ULL,0x0807804fa027c952ULL,+ 0xc222653a4f0d56f3ULL,0x961e4047ca28b805ULL,0x2c03f8b04a73434bULL,0x4c966787ab712a19ULL,0xcc196c42864fee42ULL,0xc1be93da5b0ece5cULL,0xa87d9f22c131c159ULL,0x2bb6d593dce45655ULL,+ 0x22c49ec9b809b7ceULL,0x8a41486be2c72c2cULL,0x813b9420fea0bf36ULL,0xb3d36ee9a66dac69ULL,0x6fddc08a328cc987ULL,0x0a3bcd2c3a326461ULL,0x7103c49dd810dbbaULL,0xf9d81a284b78a4c4ULL,+ 0x3de865ade4d55941ULL,0xdedafa5e30384087ULL,0x6f414abb4ef18b9bULL,0x9ee9ea42faee5268ULL,0x260faa1637a55a4aULL,0xeb19a514015f93b9ULL,0x51d7ebd29e9c3598ULL,0x523fc56d1932178eULL,+ 0x501d070cb98fe684ULL,0xd60fbe9a124a1458ULL,0xa45761c892bc6b3fULL,0xf5384858fe6f27cbULL,0x4b0271f7b59e763bULL,0x3d4606a95b5a8e5eULL,0x1eda5d9b05a48292ULL,0xda7731d0e6fec446ULL,+ 0xa3e3369390d45871ULL,0xe976404006166d8dULL,0xb5c3368289a90403ULL,0x4bd1798372f1d637ULL,0xa616679ed5d2c53aULL,0x5ec4bcd8fdcf3b87ULL,0xae6d7613b66a694eULL,0x7460fc76e3fc27e5ULL,+ 0x70469b8295caabeeULL,0xde024ca5889501e3ULL,0x6bdadc06076ed265ULL,0x0cb1236b5a0ef8b2ULL,0x4065ddbf0972ebf9ULL,0xf1dd387522aca432ULL,0xa88b97cf744aff76ULL,0xd1359afdfe8e3d24ULL,+ 0x52a3ba2b91502cf3ULL,0x2c3832a8084db75dULL,0x04a12dddde30b1c9ULL,0x7802eabce31fd60cULL,0x33707327a37fddabULL,0x65d6f2abfaafa973ULL,0x3525c5b811e6f91aULL,0x76aeb0c95f46530bULL,+ 0xe8815ff62f93a675ULL,0xa6ec968405f48679ULL,0x6dcbb556358ae884ULL,0x0af61472e19e3873ULL,0x72334372a5f696beULL,0xc65e57ea6f22fb70ULL,0x268da30c946cea90ULL,0x136a8a8765681b2aULL,+ 0xad5e81dc0f9f44d4ULL,0xf09a69602c46585aULL,0xd1649164c447d1b1ULL,0x3b4b36c8879dc8b1ULL,0x20d4177b3b6b234cULL,0x096a25051730d9d0ULL,0x0611b9b8ef80531dULL,0xba904b3b64bb495dULL,+ 0x1192d9d493a3147aULL,0x9f30a5dc9a565545ULL,0x90b1f9cb6ef07212ULL,0x299585460d87fc13ULL,0xd3323effc17db9baULL,0xcb18548ccb1644a8ULL,0x18a306d44f49ffbcULL,0x28d658f14c2e8684ULL,+ 0x44ba60cda99f8c71ULL,0x67b7abdb4bf742ffULL,0x66310f9c914b3f99ULL,0xae430a32f412c161ULL,0x1e6776d388ace52fULL,0x4bc0fa2452d7067dULL,0x03c286aa8f07cd1bULL,0x4cb8f38ca985b2c1ULL,+ 0x83ccbe808c3bff36ULL,0x005a0bd25263e575ULL,0x460d7dda259bdcd1ULL,0x4a1c5642fa5cab6bULL,0x2b7bdbb99fe4fc88ULL,0x09418e28cc97bbb5ULL,0xd8274fb4a12321aeULL,0xb137007d5c87b64eULL,+ 0x80531fe1c63c4962ULL,0x50541e89981fdb25ULL,0xdc1291a1fd4c2b6bULL,0xc0693a17a6df4fcaULL,0xb2c4604e0117f203ULL,0x245f19630a99b8d0ULL,0xaedc20aac6212c44ULL,0xb1ed4e56520f52a8ULL,+ 0xb5560fb6700a1acdULL,0xe823fd73fd999681ULL,0xda915d1f6cb4e1baULL,0x0d0301186ebe00a3ULL,0x744fb0c989fca8cdULL,0x970d01dbf9da0e0bULL,0x0ad8c5647931d76fULL,0xb15737bff659b96aULL,+ 0xa12b384ece53c2d0ULL,0x779d897d5e4606daULL,0xa53e47b073ec12b0ULL,0x462dbbba5756f1adULL,0x69fe09f2cafe37b6ULL,0x273d1ebfecce2e17ULL,0x8ac1d5383cf607fdULL,0x8035f7ff12e10c25ULL,+ 0xca442d5a2093c22aULL,0xebd0bd31d5703aedULL,0x308f2afd653287b6ULL,0x9bb88bac0d1bc8baULL,0xfbaf853875c1e3b2ULL,0xbd2ac950ca11447cULL,0x286d816cea5c4c8dULL,0xdc3aa80028dc3208ULL,+ 0x854d34c77e6c5520ULL,0xc27df9efdcb9ea58ULL,0x405f2369d686666dULL,0x29d1febf0417aa85ULL,0x9846819e93470afeULL,0x3e6a9669e2a27f9eULL,0x24d008a2e31e6504ULL,0xdba7cecf9cb7680aULL,+ 0x26a43e41d07fa53dULL,0x3154a78a74e35bc5ULL,0x7b768924e0da2f8cULL,0xba964a2b23613f9aULL,0x5a548d35ba1d16c4ULL,0x2e1bfed1fb54d057ULL,0xff992136bc640205ULL,0xf39cb9148156df29ULL,+ 0xc913e64699b444adULL,0xddfce99dc40504c5ULL,0x58482a99d42e53dbULL,0x9aaf2c25d1aff537ULL,0xee90f7962664cf67ULL,0x74ab5c99f1393e2bULL,0xfad0faeae6225bb0ULL,0xc355648c2d63dd6cULL,+ 0xe4e31d271d91cf9dULL,0xcb35d4fdb377b20aULL,0x74de1e45055e1327ULL,0x3298e31b28703e75ULL,0x55087237de013339ULL,0x32cbf30123d101c6ULL,0xc70dba22e8aab0dcULL,0x4a52623d3d155bb9ULL,+ 0xecaff541338d6e43ULL,0x56f7dd734541d5ccULL,0xb5d426de96bc88caULL,0x48d94f6b9ed3a2c3ULL,0x6354a3bb2ef8279cULL,0xd575465b0b1867f2ULL,0xef99b0ff95225151ULL,0xf3e19d88f94500d8ULL,+ 0xdbf435acc85dcf57ULL,0x61745658c88f5415ULL,0x26367e9a17c55807ULL,0x22d077a5ca90c56fULL,0xfbf72258a2e04e76ULL,0xba965d3e6e06e405ULL,0x5724d06fe3e6f954ULL,0x3e47d47581251a74ULL,+ 0xb8ba0151e0fb82f7ULL,0x0d160726d5668ac2ULL,0x622ba25814d711b0ULL,0x6addf5577f3fe2f2ULL,0x2b831e1c6b9c9435ULL,0xce3a060ab73826bdULL,0x93fa11c11c240f89ULL,0x4f9cc8d8956e303aULL,+ 0x4b9331f6641f82c9ULL,0xd97c7c54dffec756ULL,0xf5ee6d1f1a9158abULL,0x054493a385c3da7fULL,0xa57a05f5eb7d96dfULL,0xa3afd447e4473a39ULL,0x42a4d9c488e16d55ULL,0x83e144f5f5f876aeULL,+ 0x92a83268e32dd620ULL,0x913ec99f627849a2ULL,0xedd8fdfa2c378882ULL,0xaf96f33eee6f8cfeULL,0xc06737e5dc3fa8a5ULL,0x236bb531b0b03a1dULL,0x33e59f2989f037b0ULL,0x13f9b5a7d9a12a53ULL,+ 0x50d8ae9559029aa6ULL,0xd74e292c5a4db2edULL,0x0b9c3355848f373dULL,0xec018db6ac45ab38ULL,0x1f44690269cc53a8ULL,0x8c4b628d1a879864ULL,0x1c743d284b13475eULL,0xbf4a933873de19f6ULL,+ 0x4a8a4f47f0cefa69ULL,0xdc8e4cbaa4546866ULL,0x359ba69b23f603c1ULL,0xdab4d601187b7ac5ULL,0xa6ca4337c1ebc8d9ULL,0x9fa6585452b4074bULL,0x1a4b4f81902fb733ULL,0xd2bb5d7aa525deaaULL,+ 0xeb2e92d5f81f9567ULL,0x54cb95ea4d698470ULL,0x5f2acb28e04c81ebULL,0x1c1ebfc4f8ceec64ULL,0x8f799fac06e07423ULL,0x72225f9937fa0c85ULL,0xb0cd861634f4db44ULL,0x5ec36159752c9091ULL,+ 0x0d0df6ce51efb310ULL,0xcb5b2eb4958df5beULL,0xd6459e2936158e59ULL,0x82aae2b91466e336ULL,0xfb658a39411aa636ULL,0x7152ecc5d4c0a933ULL,0xf10c758a49f026b7ULL,0xf4837f97cb09311fULL,+ 0x994f523a626332d5ULL,0x7bc388335561bb44ULL,0x005ed4b03d845ea2ULL,0xd39d3ee1c2a1f08aULL,0x6561fdd3e7676b0dULL,0x620e35fffb706017ULL,0x36ce424ff264f9a8ULL,0xc4c3419fda2681f7ULL,+ 0x00f831769bb81648ULL,0xd69eb485653120d0ULL,0xd17d75f44ccabc62ULL,0x34a07f82b749fcb1ULL,0x2c3af787bbfb5554ULL,0xb06ed4d062e283f8ULL,0x5722889fa19213a0ULL,0x162b085edcf3c7b4ULL,+ 0x36d90ddaeb300f7aULL,0x9dcf7dfcedb5e801ULL,0x645cb26874d5244cULL,0xa127ee79348e3aa2ULL,0x488acc53575f1dbbULL,0x95037e8580e6161eULL,0x57e59283292650d0ULL,0xabe67d9914938216ULL,+ 0x32670d2f7189e71fULL,0xc64387485ecf91e7ULL,0x15758e57db757a21ULL,0x427d09f8290a9ce5ULL,0x846a308f38384a7aULL,0xaac3acb4b0732b99ULL,0x9e94100917845819ULL,0x95cba111a7ce5e03ULL,+ 0xeb81aa377378058eULL,0x41c746a104411154ULL,0xa10c73bcfb828ac7ULL,0x6439be919d972b29ULL,0x4bf3b4b043a2fbadULL,0x39e6dadf82b5e840ULL,0x4f7164086397bd4cULL,0x0f7de5687f1eeccbULL,+ 0xdb332a73f37ec3c3ULL,0xc65259bddd59eba0ULL,0x2291709cdb4d3257ULL,0x9a793b25bd389390ULL,0xf39fe34be43756f0ULL,0x2f76bdce9afb56c9ULL,0x9f37867a61208b27ULL,0xea1d4307089972c3ULL,+ 0xd0a744878a429f4fULL,0x0649712bdb516609ULL,0xb826ba57e769b5dfULL,0x82335df21fc7aaf2ULL,0x2389f0675c93d995ULL,0x59ac367a68677be6ULL,0xa77985ff21d9951bULL,0x038956fb85011cceULL,+ 0x97b7851aaaca5e9bULL,0x518aa52156713b97ULL,0x3357e8c7150a61f6ULL,0x7842e7e2ec2c2b69ULL,0x8dffaf656868a548ULL,0xd963bd82e068fc81ULL,0x64da5c8b65917733ULL,0x927090ff7b247328ULL,+ 0xd6ffdb942f6d0d97ULL,0x05c3ee41443b9373ULL,0xb2e541ebffd36db6ULL,0xb7415a96ce1dcc3eULL,0xe383682e163aa2f6ULL,0x46febdd42f3af218ULL,0x90a0507ebafdbadbULL,0x4ca8ab4dce52e21aULL,+ 0xa3f0832e1b7cfb73ULL,0x7a8afe523ec354c9ULL,0xae91c97e378eadcaULL,0x7449c599ac3b32bbULL,0xa619c3710b1c4655ULL,0x692e4c6af79da87eULL,0xff3f5d86de38d96aULL,0xc5320f421c08c0ecULL,+ 0x92a6f2bc8fec5decULL,0xa71383ff84d6786cULL,0x87588c06dbffa084ULL,0x0d85f5ca6857e715ULL,0xe87311b3b6c774d4ULL,0x672357c84c3521a8ULL,0xe5fe74615b29fe0fULL,0x02bc51105b7158cdULL,+ 0x37a01e48a105fc8eULL,0x769d754a289ba48cULL,0xc08c6fe1d51c2180ULL,0xb032dd33b7bd1387ULL,0x953826db020b0aa6ULL,0x05137e800664c73cULL,0xc66302c4660cf95dULL,0x99004e11b2cef28aULL,+ 0x824f5b284f973536ULL,0xb43e299ed35b04eaULL,0xc72c88f74da03089ULL,0x8269d57a45a2e42cULL,0x7c1e63fc6607b38eULL,0xe89e2aaf29390b0cULL,0xc7c740da1bee2869ULL,0x8556f6fcaf3fb974ULL,+ 0x1a0a3995a4b6bed1ULL,0x2dab579597095c54ULL,0x06c6a1ff2aa73ce9ULL,0xadd0a54b4de438a7ULL,0x160b6b1afca906cdULL,0x25fc601629de10ddULL,0x348e9c99d3633da3ULL,0x1fe3f746158a4d5aULL,+ 0xc253edc88be85c1dULL,0xdd3d0e483ca09cb6ULL,0xb997f6879ae3055aULL,0x0c929ad007431dbfULL,0xcef1621584d2db42ULL,0xb50df3ef078828cdULL,0x4589da9d6dbd4b66ULL,0xbc4fd2e3d99c2b04ULL,+ 0x214bc9a7d298c241ULL,0xe3b697ba56807cfdULL,0xef1c78024564eadbULL,0xdde8cdcfb48149c5ULL,0x946bf0a75a4d2604ULL,0x27154d7f6c1538afULL,0x95cc9230de5b1fccULL,0xd88519e966864f82ULL,+ 0xb828dd1a7cb1282cULL,0xa08d7626be46973aULL,0x6baf8d40e708d6b2ULL,0x72571fa14daeb3f3ULL,0x85b1732ff22dfd98ULL,0x87ab01a70087108dULL,0xaaaafea85988207aULL,0xccc832f869f00755ULL,+ 0x488f1185ca8d9d1aULL,0xadf2c77dd987ded2ULL,0x5f3039f060c46124ULL,0xe5d70b7571e095f4ULL,0x82d586506260e70fULL,0x39d75ea7f750d105ULL,0x8cf3d0b175bac364ULL,0xf3a7564d21d01329ULL,+ 0x94ab4700ec3128c2ULL,0x6c76d8628e383f49ULL,0xdc36b150c03024ebULL,0xfb43947753daac69ULL,0xfc68764a8dc79623ULL,0x5b86995db440fbb2ULL,0xd66879bfccc5ee0dULL,0x0522894295aa8bd3ULL,+ 0xb24aa43e3fcd3efcULL,0xdd26c034b8088e9aULL,0xa5ef4dc9bd3d46eaULL,0xa2f99d588a4c6a6fULL,0xddabd3552f1da46cULL,0x72c3f8ce1afacdd1ULL,0xd90c4eee92d40578ULL,0xd28bb41fca623b94ULL,+ 0x5e7c3becee8314f3ULL,0x1c068aeddbea298fULL,0x08d381f17c80acecULL,0x03b56be8e330495bULL,0xaeffb8f29222882dULL,0x95ff38f6c4af8bf7ULL,0x50e32d351fc57d8cULL,0x6635be5217b444f0ULL,+ 0x242792d2e7417ce1ULL,0xff42bc71970ee7f5ULL,0x1ff4dc6d5c67a41eULL,0x77709b7b20882a58ULL,0x3554731dbe217f2cULL,0x2af2a8cd5bb72177ULL,0x58eee769591dd059ULL,0xbb2930c94bba6477ULL,+ 0x174a9126cecdaa7aULL,0xfc8c7e0e0b13247bULL,0x29c110d23484c1c4ULL,0xf8eb8757831dfc3bULL,0x022f0212c0067452ULL,0x3f6f69ee7b9b926cULL,0x09032da0ef42daf4ULL,0x79f00ade83f80de4ULL,+ 0x1e6adddaf176f2c0ULL,0x01ca4604e2572658ULL,0x0a404ded85342ffbULL,0x8cf60f96441838d6ULL,0x9bbc691cc9071c4aULL,0xfd58874434442803ULL,0x97101c85809c0d81ULL,0xa7fb754c8c456f7fULL,+ 0xf8559ff4c1e99d81ULL,0x08e1a7d6a3c617c0ULL,0xb398fd43248c6ba7ULL,0x6ffedd91d1283794ULL,0x8a6a59d2d629d208ULL,0xa9d141d53490530eULL,0x42f6fc1838505989ULL,0x09bf250d479d94eeULL,+ 0x6af7a1d5af71013fULL,0xe68216e50bedc946ULL,0xf4cba30bd27370a0ULL,0x7981afbf870421ccULL,0x02496a679449f0e1ULL,0x86cfc4be0a47edaeULL,0x3073c936b1feca22ULL,0xf569461203f8f8fbULL,+ 0xec14f9e12cb7191eULL,0x78ea1bd8e5b08ea6ULL,0x3c65aa9b46332bb9ULL,0x84cc22b3bf80ce25ULL,0x0098e9e9d49d5bf1ULL,0xcd4ec1c619087da4ULL,0x3c9d07c5aef6e357ULL,0x839a02689f8f64b8ULL,+ 0xbcadd6715bde48f8ULL,0xc97038732189bc7dULL,0x5d45299ec709ee8aULL,0xd1287ee2845aaff8ULL,0x7d1f8874db1dbf1fULL,0xea46588b990c88d6ULL,0x60ba649a84368313ULL,0xd5fdcbce60d543aeULL,+ 0xf795643037577dd8ULL,0x83b82af429c5fe88ULL,0x9c1bea26cdbdc132ULL,0x589fa0869c04339eULL,0x033e9538b13799dfULL,0x85fa8b21d295d034ULL,0xdf17f73fbd9ddccaULL,0xf32bd122ddb66334ULL,+ 0xcf3de9959890272dULL,0x75f3432a3e713a10ULL,0x5e13479fe28227b8ULL,0xb8561ea9fefacdc8ULL,0xa6a297a08332aafdULL,0x9b0d8bb573809b62ULL,0xd2fa1cfd0c63036fULL,0x7a16eb55bd64bda8ULL,+ 0x4cc34ec13cf48283ULL,0xb09daa259c8a705eULL,0xd1e9d0d05b7d4f84ULL,0x4df6ef64db38929dULL,0xe16b0763aa21ba46ULL,0xc6b1d178a293f8fbULL,0x0ff5b602d520aabfULL,0x94d671bdc339397aULL,+ 0xf7e48e8a2ac13e27ULL,0x4494f6df4eb1a9f5ULL,0xedbf84eb981f0a62ULL,0x49badc32536438f0ULL,0x50bea541004f7571ULL,0xbac67d10df1c94eeULL,0x253d73a1b727bc31ULL,0xb3d01cf230686e28ULL,+ 0xd433e50f6d3549cfULL,0x6f33696ffacd665eULL,0x695bfdacce11fcb4ULL,0x810ee252af7c9860ULL,0x65450fe17159bb2cULL,0xf7dfbebe758b357bULL,0x2b057e74d69fea72ULL,0xd485717a92731745ULL,+ 0x896c42e8ee36860cULL,0xdaf04dfd4113c22dULL,0x1adbb7b744104213ULL,0xe5fd5fa11fd394eaULL,0x68235d941a4e0551ULL,0x6772cfbe18d10151ULL,0x276071e309984523ULL,0xe4e879de5a56ba98ULL,+ 0x6c8d0aa9b898fd52ULL,0x2fb38a57be9af1a7ULL,0xe1f2b9a93b4f03f8ULL,0x2b1aad44c3f0cc6fULL,0x58b5332e7cf2c084ULL,0x1c57d96f0367d26dULL,0x2297eabdfa6e4a8dULL,0x65a947ee4a0e2b6aULL,+ 0xaaafafb0285b9491ULL,0x01a0be881e4c705eULL,0xff1d4f5d2ad9caabULL,0x6e349a4ac37a233fULL,0xcf1c12464a1c6a16ULL,0xd99e6b6629383260ULL,0xea3d43665f6d5471ULL,0x36974d04ff8cc89bULL,+ 0xf535b616fdd5b854ULL,0x592549c85728719fULL,0xe231468606921cadULL,0x98c8ce34311b1ef8ULL,0x28b937e7e9090b36ULL,0x67fc3ab90bf7bbb7ULL,0x12337097a9d87974ULL,0x3e5adca1f970e3feULL,+ 0xc26c49a1cfe89d80ULL,0xb42c026dda9c8371ULL,0xca6c013adad066d2ULL,0xfb8f722856a4f3eeULL,0x08b579ecd850935bULL,0x34c1a74cd631e1b3ULL,0xcb5fe596ac198534ULL,0x39ff21f6e1f24f25ULL,+ 0xcdcc68a7b3f85ff0ULL,0xacd21cdd1a888044ULL,0xb6719b2e05dbe894ULL,0xfae1d3d88b8260d4ULL,0xedfedece8a1c5d92ULL,0xbca01a94dc52077eULL,0xc085549c16dd13edULL,0xdc5c3bae495ebaadULL,+ 0x27f29e148f929057ULL,0x7a64ae06c0c853dfULL,0x256cd18358e9c5ceULL,0x9d9cce82ded092a5ULL,0xcc6e59796e93b7c7ULL,0xe1e4709231bb9e27ULL,0xb70b3083aa9e29a0ULL,0xbf181a753785e644ULL,+ 0xcc17063fbe7b643aULL,0x7872e1c846085760ULL,0x86b0fffbb4214c9eULL,0xb18bbc0e72bf3638ULL,0x8b17de0c722591c9ULL,0x1edeab1948c29e0cULL,0x9fbfd98ef4304f20ULL,0x2d1dbb6b9c77ffb6ULL,+ 0xf53f2c658ead09f7ULL,0x1335e1d59780d14dULL,0x69cc20e0cd1b66bcULL,0x9b670a37bbe0bfc8ULL,0xce53dc8128efbeedULL,0x0c74e77c8326a6e5ULL,0x3604e0d2b88e9a63ULL,0xbab38fca13dc2248ULL,+ 0x255616d3c7141771ULL,0xa86691ab2f226b66ULL,0xda19fea4b3ca63a9ULL,0xfc05dc42ae672f2bULL,0xa9c6e786718ba28fULL,0x07b7995b9c66b984ULL,0x0f434f551b3702f2ULL,0xd6f6212fda84eeffULL,+ 0x8ed6e8c85c0a3f1eULL,0xbcad24927c87c37fULL,0xfdfb62bb9ee3b78dULL,0xeba8e477cbceba46ULL,0x37d38cb0eeaede4bULL,0x0bc498e87976deb6ULL,0xb2944c046b6147fbULL,0x8b123f35f71f9609ULL,+ 0x4b0e7987b5b41d78ULL,0xea7df9074bf0c4f8ULL,0xb4d03560fab80ecdULL,0x6cf306f6fb1db7e5ULL,0x0d59fb5689fd4773ULL,0xab254f4000f9be33ULL,0x18a09a9277352da4ULL,0xf81862f5641ea3efULL,+ 0xa155dcc7de79dc24ULL,0xf1168a32558f69cdULL,0xbac215950d1850dfULL,0x15c8295bb204c848ULL,0xf661aa367d8184ffULL,0xc396228e30447bdbULL,0x11cd5143bde4a59eULL,0xe3a26e3b6beab5e6ULL,+ 0xb59b01579f759d01ULL,0xa2923d2f7eae4fdeULL,0x18327757690ba8c0ULL,0x4bf7e38b44f51443ULL,0xb6812563b413fc26ULL,0xedb7d36379e53b36ULL,0x4fa585c4c389f66dULL,0x8e1adc3154bd3416ULL,+ 0xd3b3a13f1402b9d0ULL,0x573441c32c7bc863ULL,0x4b301ec4578c3e6eULL,0xc26fc9c40adaf57eULL,0x96e71bfd7493cea3ULL,0xd05d4b3f1af81456ULL,0xdaca2a8a6a8c608fULL,0x53ef07f60725b276ULL,+ 0xa6b5c9d646ac49d2ULL,0x42c77c0b83137aa9ULL,0x24d000fc68225a38ULL,0x0f63cfc82fe1e907ULL,0x22d1b01bc6441f95ULL,0x7d38f719ec8e448fULL,0x9b33fa5f787fb1baULL,0x94dcfda1190158dfULL,+ 0x211cde10296c36efULL,0x7ee8967282c4da77ULL,0xb617d270a57836daULL,0xf0cd9c319cb7560bULL,0x01fdcbf7e455fe90ULL,0x3fb53cbb7e7334f3ULL,0x781e2ea44e7de4ecULL,0x8adab3ad0b384fd0ULL,+ 0x01778a2b599ff0f9ULL,0x68a923d78104fc6bULL,0x5bfa44dfda694ff3ULL,0x4f7199dbf7667f12ULL,0xc06d8ff6e46f2a79ULL,0x08b5deade9f8131dULL,0x02519a59abb4ce7cULL,0xc4f710bcb42aec3eULL,+ 0x3014368b4ed80940ULL,0x67e6d0567a6fceddULL,0x7c208c49ca97579fULL,0xfe3d7a81a23597f6ULL,0x5e2032027e096ae2ULL,0xb1f3e1e724b39366ULL,0x26da26f32fdcdffcULL,0x79422f1d6097be83ULL,+ 0x50549c748c878145ULL,0x67f14edf39c63565ULL,0x22ddf78c9bcf2d5eULL,0xffaa842f68201d10ULL,0x47d94a9dd1b2de28ULL,0xc09c4be8054be414ULL,0xac80e178ca82755bULL,0xe3251d105697c3bdULL,+ 0x2bbe09d35001417bULL,0x795e84ee5962ed5eULL,0x5b79d1ca279f46c3ULL,0x1f7f8a3b83836a2eULL,0x692200b14a64dc32ULL,0xc84243350f84f739ULL,0xf110da07cc9155c0ULL,0xee8fbe61594b0507ULL,+ 0x2f6a5391035703ccULL,0x9899bf6a40c7e24dULL,0xc3f7f248bbfcbb9aULL,0xf65027ded555875bULL,0xa7a16b69ffff3b37ULL,0x67b6eb54145b4431ULL,0x19d7e1d249afd679ULL,0xbd819bab110fccdfULL,+ 0x263a2cfb9db3b381ULL,0x9c3a2deed4df0a4bULL,0x728d06e97d04e61fULL,0x8b1adfbc42449325ULL,0x6ec1d9397e053a1bULL,0xee2be5c766daf707ULL,0x80ba1e14810ac7abULL,0xdd2ae778f530f174ULL,+ 0x3e708e703b9f0426ULL,0xe5b02fb60c84f17cULL,0x2f4ff35be3b70a0bULL,0x781b3c5f9b15565dULL,0xe76c636a6e124c3aULL,0xbde81eba8b496784ULL,0xa412f8e2443f0370ULL,0x15d42362999be45dULL,+ 0x0f503ae2a4af76c1ULL,0x550e66dc08276fe7ULL,0x11e0c1fcbf3a33c6ULL,0x42be231006629f85ULL,0xedf7743e516ace49ULL,0xce436668436a2262ULL,0xe1ac7036446ca192ULL,0x73631cb5476fe13eULL,+ 0xd47f82d4a160bcfaULL,0x258fb075b8ceb1f2ULL,0x4f818e8fdf5a8d25ULL,0x6685475e6fd31c9dULL,0xcef6385ae1e9b13fULL,0xe0a42594f0508bdbULL,0x5ad7ae16aef1f90dULL,0x45a155ef63f8a81eULL,+ 0x8ca407c28034b95eULL,0xc93eb97617bdc560ULL,0x4ec24e8d339807e8ULL,0x91b734d6dd64a4ebULL,0xd0fece398f668b26ULL,0x4822cc4b141823d5ULL,0xb953bc32f09e4e00ULL,0xca0a7c6006d861aeULL,+ 0x4c74d4470f33e712ULL,0x3cec1e0625a87cb0ULL,0x5cec0610e5962db4ULL,0xd971af1571a256aaULL,0xa044c983a2ef4ac9ULL,0xcaa1da63d74e9d00ULL,0xfb972d834673d881ULL,0x50747c5a03a26c8bULL,+ 0x04349982a3e25566ULL,0xeef9075e18e1b896ULL,0x4c7bead092b2d24bULL,0xd99f72fb0a21ba55ULL,0xb93e09315005e541ULL,0x2a7a98389ece3205ULL,0xeb388ed11462f2f6ULL,0xb488b15a2e3460a6ULL,+ 0x43f6cd67969d56afULL,0x9e0d872cdfc58a8bULL,0x401c1509a4e70377ULL,0x103d1a1308ad646cULL,0x078ee37e9d062427ULL,0x4e69c5acb9bef78cULL,0x521ec00136e66142ULL,0x8de1ecb2a634cd82ULL,+ 0x0435d97a205b9d8bULL,0x6eb8f064056756d4ULL,0xd5e88a8bb6f8210eULL,0x070ef12dec9fd9eaULL,0x4d8495053bcc876aULL,0x12a75338a7404ce3ULL,0xd22b49e1b8a1db5eULL,0xec1f205114bfa5adULL,+ 0x43ed81b5c4e83d33ULL,0xd9f358795efd488bULL,0x164a620f9deb4d0fULL,0xc6927bdbac6a7394ULL,0x45c28df79f9e0f03ULL,0x2868661efcd7e1a9ULL,0x7cf4e8d0ffa348f1ULL,0x6bd4c284398538e0ULL,+ 0x56036e8c06d75fc1ULL,0x2dcf7bb73249a89fULL,0x81dd1d3de245e7ddULL,0xf578dc4bebd6e2a7ULL,0x4c028903df2ce7a0ULL,0xaee362889c39afacULL,0xdc847c31146404abULL,0x6304c0d8a4e97818ULL,+ 0xfb6836c327d02dccULL,0x5ad009827a68bcc2ULL,0x1b24b44c005e912dULL,0xcc83d20f811fdcfeULL,0x36527ec1666fba0cULL,0x6994819714754635ULL,0xfcdcb1a8556da9c2ULL,0xa593426781a732b2ULL,+ 0xe4ac8b33070d3aabULL,0x2643672b9a2cd5e5ULL,0x52eff79b1cfc9173ULL,0x665ca49b90a7c13fULL,0x5a8dda59b3efb998ULL,0x8a5b922d052f1341ULL,0xae9ebbab3cf9a530ULL,0x35986e7bf56da4d7ULL,+ 0x63ee4cbd8088b454ULL,0xdb7f32f79a9e0c8aULL,0xb377d4186b2447cbULL,0xe3e982aad370219bULL,0x06ccc1e4c2a2a593ULL,0x72c368650773f24fULL,0xa13b4da795859423ULL,0x8bbf1d3375040c8fULL,+ 0x03c187d0ad886aacULL,0x5c16878ab771b645ULL,0xb07dfc6fc74045abULL,0x2c6360bf7800caedULL,0x24295bb5b9c972a3ULL,0xc9e6f88e7c9a6dbaULL,0x90ffbf2492a79aa6ULL,0xde29d50a41c26ac2ULL,+ 0xb1f0fb68d84d835dULL,0xc90caf39861dc1e6ULL,0x12e5b0467594f8d7ULL,0x26897ae265012b92ULL,0xbcf68a08a4d6755dULL,0x403ee41c0991fbdaULL,0x733e343e3bbf17e8ULL,0xd2c7980d679b3d65ULL,+ 0x534acf4fda79e5acULL,0x68b83b3a8630215fULL,0x5c748b2ed085756eULL,0xb0317258e5d37cb2ULL,0x6735841ac5ccc2c4ULL,0x7d7dc96b3d9d5069ULL,0xa147e410fd1754bdULL,0x65296e94d399ddd5ULL,+ 0x1e71c9a1deb8568bULL,0xa35daea080fb3d32ULL,0xe8b6f2662cf8fb81ULL,0x6d51afe89490696aULL,0x81beac6e51803a19ULL,0xe3d24b7f86219080ULL,0x727cfd9ddf6f463cULL,0x8c6865ca72284ee8ULL,+ 0xe00df169d23233f3ULL,0x3e32279677cb637fULL,0x1f897c0e1da0cf6cULL,0xa651f5d831d6bbddULL,0xdd61af191a230c76ULL,0xbd527272cdaa5e4aULL,0xca753636d0abcd7eULL,0x78bdd37c370bd8dcULL,+ 0xcddb27c17078c432ULL,0xe1961b9cb77fedb7ULL,0x1edc2f5cc2290570ULL,0x2c3fefca19cbd886ULL,0xcf880a36c2af389aULL,0x96c610fdbda71ceaULL,0xf03977a932aa8463ULL,0x8eb7763f8586d90aULL,+ 0x831ab3edf0290a8fULL,0xcae81966cb47c387ULL,0xaad7dece184efb4fULL,0xdcfc53b34749110eULL,0x6698f23c4cb632f9ULL,0xc42a1ad6b91f8067ULL,0xb116a81d6284180aULL,0xebedf5f8e901326fULL,+ 0x91633f0ab2cf8940ULL,0x72b0b1786f948f51ULL,0x2d28dc30782653c8ULL,0x88829849db903a05ULL,0xb8095d0c6a19d2bbULL,0x4b9e7f0c86f782cbULL,0x7af739882d907064ULL,0xd12be0fe8b32643cULL,+ 0x9561f28b638a7e81ULL,0x54155cdf5980ddc3ULL,0xb2db4a96d26f247aULL,0x9d774e4e4787d100ULL,0x1a9e6e2e078637d2ULL,0x1c363e2d5e0ae06aULL,0x7493483ee9cfa354ULL,0x76843cb37f74b98dULL,+ 0x0491f1bc789a283bULL,0x72d3ac3d880836f4ULL,0xaa1c5ea388e5402dULL,0x1b192421d5cc473dULL,0x5c0b99989dc84cacULL,0xb0a8482d9c6e75b8ULL,0x639961d03a191ce2ULL,0xda3bc8656d837930ULL,+ 0xd7e0c4cdb30cfb3aULL,0x6d09b8c16c9db4c8ULL,0x40ba1a4207c8d9dfULL,0x6fd495f71c52c66dULL,0xfb0e169f275264daULL,0x80c2b746e57d8362ULL,0xedd987f749ad7222ULL,0xfdc229af4398ec7bULL,+ 0xb0d1ed8452666a58ULL,0x4bcb6e00e6a9c3c2ULL,0x3c57411c26906408ULL,0xcfc2075513556400ULL,0xa08b1c505294dba3ULL,0xa30ba2868b7dd31eULL,0xd70ba90e991eca74ULL,0x094e142ce762c2b9ULL,+ 0xb81d783e979f3925ULL,0x1efd130aaf4c89a7ULL,0x525c2144fd1bf7faULL,0x4b2969041b265a9eULL,0xed8e9634b9db65b6ULL,0x35c82e3203599d8aULL,0xdaa7a54f403563f3ULL,0x9df088ad022c38abULL,+ 0xe5cfb066bb3fd30aULL,0x429169daeff0354eULL,0x809cf8523524e36cULL,0x136f4fb30155be1dULL,0x4826af011fbba712ULL,0x6ef0f0b4506ba1a1ULL,0xd9928b3177aea73eULL,0xe2bf6af25eaa244eULL,+ 0x8d084f124237b64bULL,0x688ebe99e3ecfd07ULL,0x57b8a70cf6845dd8ULL,0x808fc59c5da4a325ULL,0xa9032b2ba3585862ULL,0xb66825d5edf29386ULL,0xb5a5a8db431ec29bULL,0xbb143a983a1e8dc8ULL,+ 0x35ee94ce12ae381bULL,0x3a7f176c86ccda90ULL,0xc63a657e4606eacaULL,0x9ae5a38043cd04dfULL,0x9bec8d15ed251b46ULL,0x1f5d6d30caca5e64ULL,0x347b3b359ff20f07ULL,0x4d65f034f7e4b286ULL,+ 0x9e93ba24f111661eULL,0xedced484b105eb04ULL,0x96dc9ba1f424b578ULL,0xbf8f66b7e83e9069ULL,0x872d4df4d7ed8216ULL,0xbf07f3778e2cbecfULL,0x4281d89998e73754ULL,0xfec85fbb8aab8708ULL,+ 0x9a3c0deea5ba5b0bULL,0xe6a116ce42d05299ULL,0xae9775fee9b02d42ULL,0x72b05200a1545cb6ULL,0xbc506f7d31a3b4eaULL,0xe58930788bbd9b32ULL,0xc8bc5f37e4b12a97ULL,0x6b000c064a73b671ULL,+ 0x13b5bf22765fa7d0ULL,0x59805bf01d6a5370ULL,0x67a5e29d4280db98ULL,0x4f53916f776b1ce3ULL,0x714ff61f33ddf626ULL,0x4206238ea085d103ULL,0x1c50d4b7e5809ee3ULL,0x999f450d85f8eb1dULL,+ 0x658a6051e4c79e9bULL,0x1394cb73c66a9feaULL,0x27f31ed5c6be7b23ULL,0xf4c88f365aa6f8feULL,0x0fb0721f4aaa499eULL,0x68b3a7d5e3fb2a6bULL,0xa788097d3a92851dULL,0x060e7f8ae96f4913ULL,+ 0x82eebe731a3a93bcULL,0x42bbf465a21adc1aULL,0xc10b6fa4ef030efdULL,0x247aa4c787b097bbULL,0x8b8dc632f60c77daULL,0x6ffbc26ac223523eULL,0xa4f6ff11344579cfULL,0x5825653c980250f6ULL,+ 0xb2dd097ebc1aa2b9ULL,0x0788939337a0333aULL,0x1cf55e7137a0db38ULL,0x2648487f792c1613ULL,0xdad013363fcef261ULL,0x6239c81d0eabf129ULL,0x8ee761de9d276be2ULL,0x406a7a341eda6ad3ULL,+ 0x4bf367ba4a493b31ULL,0x54f20a529bf7f026ULL,0xb696e0629795914bULL,0xcddab96d8bf236acULL,0x4ff2c70aed25ea13ULL,0xfa1d09eb81cbbbe7ULL,0x88fc8c87468544c5ULL,0x847a670d696b3317ULL,+ 0xf133421e64bcb626ULL,0xaea638c826dee0b5ULL,0xd6e7680bb310346cULL,0xe06f4097d5d4ced3ULL,0x099614527512a30bULL,0xf3d867fde589a59aULL,0x2e73254f52d0c180ULL,0x9063d8a3333c74acULL,+ 0xeda6c595d314e7bcULL,0x2ee7464b467899edULL,0x1cef423c0a1ed5d3ULL,0x217e76ea69cc7613ULL,0x27ccce1fe7cda917ULL,0x12d8016b8a893f16ULL,0xbcd6de849fc74f6bULL,0xfa5817e2f3144e61ULL,+ 0x1f3541640821ee4cULL,0x1583eab40bc61992ULL,0x7490caf61d72879fULL,0x998ad9f3f76ae7b2ULL,0x1e181950a41157f7ULL,0xa9d7e1e6e8da3a7eULL,0x963784eb8426b95fULL,0x0ee4ed6e542e2a10ULL,+ 0xb79d4cc5ac751e7bULL,0x93f96472fd4211bdULL,0x8c72d3d2c8de4fc6ULL,0x7b69cbf5df44f064ULL,0x3da90ca2f4bf94e1ULL,0x1a5325f8f12894e2ULL,0x0a437f6c7917d60bULL,0x9be7048696c9cb5dULL,+ 0x949c9976e1337c26ULL,0x6faadebdd73d68e5ULL,0x9e158614f1b768d9ULL,0x22dfa5579cc4f069ULL,0xccd6da17be93c6d6ULL,0x24866c61a504f5b9ULL,0x2121353c8d694da1ULL,0x1c6ca5800140b8c6ULL,+ 0xf1604a7dd4b79bb8ULL,0xaee806fb52c878c8ULL,0x34144f118d47b8e8ULL,0x72edf52b949f9054ULL,0xebfca84e2127015aULL,0x9051d0c09cb7cef3ULL,0x86e8fe58296deec8ULL,0x33b2818841010d74ULL,+ 0xbd5660ed9aed9f40ULL,0x70ca6ad1532a8c99ULL,0xc4978bfb95c371eaULL,0xe5464d0d7003109dULL,0x1af32fdfd9e535efULL,0xabf57ea798c9185bULL,0xed7a741712b42488ULL,0x8e0296a7e97286faULL,+ 0x01079383171b445fULL,0x9bcf21e38131ad4cULL,0x8cdfe205c93987e8ULL,0xe63f4152c92e8c8fULL,0x729462a930add43dULL,0x62ebb143c980f05aULL,0x4f3954e53b06e968ULL,0xfe1d75ad242cf6b1ULL,+ 0x8b57416e1f017d5eULL,0x375333967674e99bULL,0x6e6d94c0e8f488a0ULL,0xb93a787adc16f95eULL,0xc3ac51a2dcc99cccULL,0xc134b4139aa47c1dULL,0xf28fcdafafdfd8d5ULL,0x0d57bd8e10b831edULL,+ 0x9276fbccf0bcfc46ULL,0x3a822aceb5cffee6ULL,0x328ed2fec75d915bULL,0xa145c113c359476cULL,0xf61a81538be17bcdULL,0x01e867c3aa6c3d8fULL,0x5634e15d6516c82fULL,0xc1437bd26948b9b0ULL,+ 0xd2fcd2006c19d4c7ULL,0xa0f3c437e1b1e976ULL,0xf0545ff694f237e8ULL,0xdd10ec3fc0bf8bb1ULL,0x4f89696cac7cd3e1ULL,0xed3714ec5f24bfe6ULL,0x363eb1d85faf7706ULL,0xfcbd604dc027cc32ULL,+ 0x5f95c6c7af8685c8ULL,0xd4c1c8ce2f8f01aaULL,0xc44bbe322574692aULL,0xb8003478d4a4a068ULL,0x7c8fc6e52eca3cdbULL,0xea1db16bec04d399ULL,0xb05bc82e8f2bc5cfULL,0x763d517ff44793d2ULL,+ 0x16ce8eddc355363bULL,0x4af2f70ff8820d6eULL,0xcb7ed4d27661a508ULL,0x41d3444edd195472ULL,0x17fea2b438da9649ULL,0x9bf69356aeb4a200ULL,0xa13b5f916ab19c3dULL,0xc0519c14dc9360a6ULL,+ 0xc2571ae92e42e171ULL,0xcb31ab63ed41ccf9ULL,0x37f3c576b5c8854fULL,0x66e5191bc62392a1ULL,0x71565a1c6cd5683bULL,0x484b0283606fe689ULL,0xf3a25d6767e2fda6ULL,0x87ba21de8a65c0a4ULL,+ 0xde74e49ca70684d1ULL,0x3ae8766133e80c3dULL,0x5984a2a916a5c34dULL,0x09a83eccb8298c35ULL,0x9a19867caa4ca4c0ULL,0x02085610b375b8ffULL,0xf296328bf70396dcULL,0x9c9ddc4cde6fae63ULL,+ 0x4451c1b808bd98d0ULL,0x644b1cd46575f240ULL,0x6907eb337375d270ULL,0x56c8bebdfa2286bdULL,0xc713d2acc4632b46ULL,0x17da427aafd60242ULL,0x313065b7c95c7546ULL,0xf8239898bf17a3deULL,+ 0x94683d260b083b6eULL,0x0a3752eb06f6a54dULL,0x48bedc23752074ddULL,0x637622fc3e822593ULL,0xea0005136be55d3bULL,0x9f5e12f4324d006dULL,0x529486a964fc0270ULL,0x09ba0d0c923399e6ULL,+ 0x363858473a977080ULL,0x4cf8e1b80c6a6ab6ULL,0x919a5c6c0482261eULL,0x517a9ad0e5ce4806ULL,0x2792d40c056aa7aaULL,0x4c7c6adae56c61b0ULL,0xf19cb178a4b19e0cULL,0x046d5c4fe4ba267fULL,+ 0xd3e926ab121550b3ULL,0xe4975e4ac147ce84ULL,0x7a8be0f95eff722aULL,0x71e4702c6fd4f2a0ULL,0x13b92acf3cb7b280ULL,0xc588716d28272d73ULL,0x862c7bf3daa9fe5cULL,0x78c008f2e2a79e42ULL,+ 0xf3b7963f4c830320ULL,0x842c7aa0903203e3ULL,0xaf22ca0ae7327afbULL,0x38e13092967609b6ULL,0x73b8fb62757558f1ULL,0x3cc3e831f7eca8c1ULL,0xe4174474f6331627ULL,0xa77989cac3c40234ULL,+ 0xae8317f4b0166f7aULL,0xfbd3e3f7ceec74e6ULL,0xfdb516ace0874bfdULL,0x3d846019c681f3a3ULL,0x0b12ee5c7c1620b0ULL,0xba68b4dd2b63c501ULL,0xac03cd326668c51eULL,0x2a6279f74e0bcb5bULL,+ 0xfd8e139f8f5fcda8ULL,0xf3e558c4bdee5bfdULL,0xd76cbaf4e33f9f77ULL,0x3a4c97a471771969ULL,0xda27e84bf6dce6a7ULL,0xff373d9613e6c2d1ULL,0xf115193cd759a6e9ULL,0x3f9b702563d2262cULL,+ 0x12536fea87baa627ULL,0x58c1fec1f72aa680ULL,0x6c29b637601e5dc9ULL,0x9e3c3c1cde9e01b9ULL,0xefc8127b2bcfe0b0ULL,0x351071022a12f50dULL,0x6ccd6cb14879b397ULL,0xf792f804f8a82f21ULL,+ 0x8c3184911a335cc8ULL,0x563459ba6a5913e4ULL,0x1b920d61c7b32919ULL,0x805ab8b6a02425adULL,0x2ac512da8d006086ULL,0x6ca4846abcf5c0fdULL,0xafea51d8ac2138d7ULL,0xcb647545344cd443ULL,+ 0xa3f4f521e447f2c4ULL,0x81b8da7a604291f0ULL,0xd680bc467d5926deULL,0x84f21fd534a1202fULL,0x1d1e31814e9df3d8ULL,0x1ca4861a39ab8d34ULL,0x809ddeec5b19aa4aULL,0x59f72f7e4d329366ULL,+ 0x9f1b2466cdedca85ULL,0x140bb7101a09538cULL,0xac8ae8515e11115dULL,0x0d63ff676f03f59eULL,0x755e55517d234afbULL,0x61c2db4e7e208fc1ULL,0xaa9859cef28a4b5dULL,0xbdd6d4fc34af030fULL,+ 0x3f39e67f906151e5ULL,0xcea27f5f55e10649ULL,0xdca1d4e1c17cf7b7ULL,0x0c326d122fe2362dULL,0x05f7ac337dd35df3ULL,0x0c3b7639c396dbdfULL,0x0912f5ac03b7db1cULL,0x9dea4b705c9ed4a9ULL,+ 0x511053e453544774ULL,0x834d0ecc3adba2bcULL,0x4215d7f7bae371f5ULL,0xfcfd57bf6c8663bcULL,0xded2383dd6901b1dULL,0x3b49fbb4b5587dc3ULL,0xfd44a08d07625f62ULL,0x3ee4d65b9de9b762ULL,+ 0x3e56fe5bdf53aad0ULL,0x51314de5e4604a67ULL,0x386ad98607a261a0ULL,0x8b7e021217afcc91ULL,0xcbf411273b72aec5ULL,0x13c85d05c4f9f509ULL,0xeda56845b6484b57ULL,0x13cb1642b3d0995bULL,+ 0x5a994b6e717815deULL,0xd995c7a0a7e131d1ULL,0xc8b46df226c023aaULL,0x8cfd094d702afcedULL,0x7bc743cdced6a886ULL,0xb7d70ec41fcabe75ULL,0x2a6c9e47ddac9390ULL,0x720694259310aa90ULL,+ 0xa607b3263e8f793cULL,0xa541166ecde3b289ULL,0xf44ff2924a915b21ULL,0x68bea906b58ecda6ULL,0xd85b37b440292897ULL,0xd2a508ae4b768423ULL,0xd10bb79da413bbbeULL,0x0262f481061491f4ULL,+ 0xd17e80f55464d0ebULL,0x89d3e1a767a613a7ULL,0x77791260c8c97dadULL,0xec2ff21fe4f0cbe7ULL,0xed984ac2e9e6bc10ULL,0xe3c53de877cba305ULL,0x9bbaf9b283624fdcULL,0x5e9451cd1485c0ecULL,+ 0xfdfc9f63b7abad11ULL,0xc7ec3a9263a46189ULL,0x49ebee42f67037b7ULL,0x8247f504cdac1710ULL,0xfc518f8d397583e5ULL,0xe7d24de70c3f8c2eULL,0x354832669c5edcb1ULL,0x94bba483f8c2cefcULL,+ 0x1f13756db1761ec8ULL,0xe53c8b98a4b97e55ULL,0xb2aee3f84096cc28ULL,0x48c361a0920f1a8dULL,0xa98b672d8c31190aULL,0x7bc1e7d1001855d4ULL,0x242cfb07bf3f4b2aULL,0x9bf44a3f32a28bc4ULL,+ 0xeba8976299da550cULL,0xb2c1781a16baa042ULL,0x3068b082788c2f9dULL,0xc0fa414594869a9eULL,0x73bd9e39d50b693fULL,0xb79e2a9c988e2c5eULL,0xf1cb8de40f8f9f62ULL,0x415b04ee1ea50c7bULL,+ 0x64e5137d0d63d1faULL,0x658fc05202a9d89fULL,0x4889487450436309ULL,0xe9ae30f8d598da61ULL,0x2ed710d1818baf91ULL,0xe27e9e068b6a0c20ULL,0x1e28dcfb1c1a6b44ULL,0x883acb64d6ac57dcULL,+ 0x8735728dc2c6ff70ULL,0x79d6122fc5dc2235ULL,0x23f5d00319e277f9ULL,0x7ee84e25dded8cc7ULL,0x91a8afb063cd880aULL,0x3f3ea7c63574af60ULL,0x0cfcdc8402de7f42ULL,0x62d0792fb31aa152ULL,+ 0xb02c83f9dec31a21ULL,0x988c8b236ad9d573ULL,0x53e983aea57be365ULL,0xe968734d646f834eULL,0x9137ea8f5da6309bULL,0x10f3a624c1f1ce16ULL,0x782a9ea2ca440921ULL,0xdf94739e5b46f1b5ULL,+ 0x1df165a434a35ea8ULL,0x3418e0f74d4412f6ULL,0x5af1f8af518836c3ULL,0x42ceef4d130e1965ULL,0x5560ca0b543a1957ULL,0xc33761e5886cb123ULL,0x66624b1ffe98ed30ULL,0xf772f4bf1090997dULL,+ 0x56f8410ef4f8b16aULL,0x97241afec47b266aULL,0x0a406b8e6d9c87c1ULL,0x803f3e02cd42ab1bULL,0x7f0309a804dbec69ULL,0xa83b85f73bbad05fULL,0xc6097273ad8e197fULL,0xc097440e5067adc1ULL,+ 0xc507b6dd418e7dddULL,0x39888d93472f19d6ULL,0x7eae26be0c27eb4dULL,0x17b53ed3fbabb884ULL,0xfc27021b2b01ae4fULL,0x88462e87cf488682ULL,0xbee096ec215e2d87ULL,0xeb2fea9ad242e29bULL,+ 0xbbcc00c756b95bceULL,0x5ec03906616da680ULL,0x79162ee672214252ULL,0x43132b6386a892d2ULL,0x4bdd3ff22f3263bfULL,0xd5b3733c9cd0a142ULL,0x592eaa8244415ccbULL,0x663e89248d5474eaULL,+ 0x0d38ab35ce7c42d4ULL,0x9fd493ef82feab10ULL,0x46056b6d82111b45ULL,0xda11dae173efc5c3ULL,0xdc7402785545a7fbULL,0xbdb2601c40d507e6ULL,0x121dfeeb7066fa58ULL,0x214369a839ae8c2aULL,+ 0x3f747fa0b311898cULL,0xe2a272e4cd0eac65ULL,0x4bba5851f914d0bcULL,0x7a1a9660c4a43ee3ULL,0xe5a367cea1c8cde9ULL,0x9d958ba97271abe3ULL,0xf3ff7eb63d1615cdULL,0xa2280dcef5ae20b0ULL,+ 0x8c0ed566d4312483ULL,0x5179a95d643e216fULL,0xcc185fec17044493ULL,0xb306333954991a21ULL,0xd801ecdb0081a726ULL,0x0149b0c64fa89bbbULL,0xafe9065a4391b6b9ULL,0xedc92786d633f3a3ULL,+ 0xd6d9d9e37a6a308bULL,0x623758304c2767d3ULL,0x874a8bc6f38cbeb6ULL,0xd94d3f1accb6fd9eULL,0x92a9735bba21f248ULL,0x272ad0e56cd1efb0ULL,0x7437b69c05b03284ULL,0xe7f047026948c225ULL,+ 0x9ae868a9e9adfe1cULL,0x3984403d314e39bbULL,0xb5875720f2fe378fULL,0x33f901e0ba44a628ULL,0xea1125fe3652438cULL,0xae9ec4e69dd1f20bULL,0x1e740d9ebebf7fbdULL,0x6dbd3ddc42dbe79cULL,+ 0x266344a43794f8dcULL,0xdcca923a483c5c36ULL,0x2d6b6bbf3f9d10a0ULL,0xb320c5ca81d9bdf3ULL,0x620e28ff47b50a95ULL,0x933e3b01cef03371ULL,0xf081bf8599100153ULL,0x183be9a0c3a8c8d6ULL,+ 0x8a9443d77613aa81ULL,0x8010080085fe6584ULL,0x70fc4dbc7fb10288ULL,0xf58280d3e86beee8ULL,0x14fdd82f7c978c38ULL,0xdf1204c10de44d7bULL,0xa08a1c844160252fULL,0x591554cac17646a5ULL,+ 0x7ddc81ea77b46a08ULL,0xcf5a6477c7480699ULL,0x43a8cb346633f683ULL,0x1b867e6b92363c60ULL,0x439211141f60558eULL,0xcdbcdd632f41450eULL,0x7fc04601cc630e8bULL,0xea7c66d597038b43ULL,+ 0x34fc8820fbeee3f9ULL,0x93e5349049091afdULL,0x764b9be59a31f35cULL,0x71f3786457e3d924ULL,0x02fb34e0943aa75eULL,0xa18c9c58ab8ff6e4ULL,0x080f31b133cf0d19ULL,0x5c9682db083518a7ULL,+ 0xb6c185c341dca566ULL,0x7de7fedad8622aa3ULL,0x99e84d92901b6dfbULL,0x30a02b0e7c4ad288ULL,0xc7c81daa2fd3cf36ULL,0xd1319547df89e59fULL,0xb2be8184cd496733ULL,0xd5f449eb93d3412bULL,+ 0xc492ec644cd8f64cULL,0x58a2d790279d7b51ULL,0x0ced1fc51fc75256ULL,0x3e658aed8f433017ULL,0x0b61942e05da59ebULL,0xba3d60a30ddc3722ULL,0x7c311cd1742e7f87ULL,0x6473ffeef6b01b6eULL,+ 0x8303604f692ac542ULL,0xf079ffe1227b91d3ULL,0x19f63e6315aaf9bdULL,0xf99ee565f1f344fbULL,0x8a1d661fd6219199ULL,0x8c883bc6d48ce41cULL,0x1065118f3c74d904ULL,0x713889ee0faf8b1bULL,+ 0xc035f697960eb8c7ULL,0xf1599f2ce2de04d3ULL,0x892450f8d2ad9228ULL,0x7d48129bb829c1abULL,0x24d785e13a50afc9ULL,0x2745ba2763a96ee0ULL,0x956534013bfb6d7bULL,0x536202671bad2a42ULL,+ 0x972b3f8f81a1b3beULL,0x4f3ce145ce2764a0ULL,0xe2d0f1cc28c4f5f7ULL,0xdeee0c0dc7f3985bULL,0x7df4adc0d39e25c3ULL,0x40619820c467a080ULL,0x440ebc9361cf5a58ULL,0x527729a6422ad600ULL,+ 0xa691398a4a9eb3f0ULL,0x56c1dbff3b99a48fULL,0x9a87e1b91b4b5b32ULL,0xad6396145378b5feULL,0x437a243ec26b5302ULL,0x0275878c3ccb4c10ULL,0x0e81e4a21de07015ULL,0x0c6265c9850df3c0ULL,+ 0xca6c0937b1b76ba6ULL,0x1a2eab854d2026dcULL,0xb1715e1519d9ae0aULL,0xf1ad9199bac4a026ULL,0x35b3dfb807ea7b0eULL,0xedf5496f3ed9eb89ULL,0x8932e5ff2d6d08abULL,0xf314874e25bd2731ULL,+ 0xc8327149a8c25ff6ULL,0x29bf2556782e6569ULL,0x9012f5c6cd68fc38ULL,0x3e67e8bd3b982ad5ULL,0x5e3a75386ecdca88ULL,0xf297eaa6c1753a04ULL,0x10121e5405db3256ULL,0xab9697d4f0851055ULL,+ 0xefb26a753f73f449ULL,0x1d1c94f88d44fc79ULL,0x49f0fbc53bc0dc4dULL,0xb747ea0b3698a0d0ULL,0x5218c3fe228d291eULL,0x35b804b543c129d6ULL,0xfac859b8d1acc516ULL,0x6c10697d95d6e668ULL,+ 0xe5d27171f6bdf1bfULL,0x0b77b876facb0d8fULL,0xda95471d8496a31bULL,0x46a50dbb3f16b103ULL,0x2a4f3f977b865bffULL,0x848195e66b1c198cULL,0x491ad08821702ea6ULL,0x3f20b43749035228ULL,+ 0xc38e438f0876fd4eULL,0x45f0c30783d2f383ULL,0x203cc2ecb10934cbULL,0x6a8f24392c9d46eeULL,0xf16b431b65ccde7bULL,0x41e2cd1827e76a6fULL,0xb9c8cf8f4e3484d7ULL,0x64426efd8315244aULL,+ 0xe6ec98093a69fc01ULL,0x7e20fecbfaa9dfc2ULL,0x5cfdbb07f56f2a55ULL,0xb1cd68680bbdbfdfULL,0x247b4995986eb9edULL,0x74785bf53dd0955eULL,0x88f74f61c0c7a201ULL,0x8861a15b5d01a80dULL,+ 0x1c0a8e44fc94dea3ULL,0x34c8cdbfdad6a0b0ULL,0x919c384004113cefULL,0xfd32fba415490ffaULL,0x58d190f6795dcfb7ULL,0xfef01b0383588bafULL,0x9e6d1d63ca1fc1c0ULL,0x53173f96f0a41ac9ULL,+ 0x54637e4182997cc1ULL,0x08c5a96ce3720c9cULL,0x78bce01c11de5d45ULL,0x49d623e50dfdd75aULL,0x8c72a4680fb2a3acULL,0xcc53bbff319c25afULL,0x198eba7978a92421ULL,0xcd61f28ba3bdecf3ULL,+ 0x2b1d402aba16f73bULL,0x2fb310148cf9b9fcULL,0x2d51e60e446ef7bfULL,0xc731021bb91e1745ULL,0x9d3b47244fee99d4ULL,0x4bca48b6fac5c1eaULL,0x70f5f514bbea9af7ULL,0x751f55a5974c283aULL,+ 0x23899fe8662595c2ULL,0x495d672711a80773ULL,0x86c971d2b0d1d43bULL,0xb518637c93b7a65fULL,0x30e453bad98c99ceULL,0xba6e0d4a14d39f5bULL,0xf7db02a6431ce415ULL,0xcd909c7cf6e1d823ULL,+ 0x6e30251acb452fdbULL,0x31ee696550f30650ULL,0xb0b3e508933548d9ULL,0xb8949a4ff4b0ef5bULL,0x208b83263c88f3bdULL,0xab147c30db1d9989ULL,0xed6515fd44d4df03ULL,0x17a12f75e72eb0c5ULL,+ 0x25914f7881fdad90ULL,0xcf638f560d2cf6abULL,0xb90bc03fcc054de5ULL,0x932811a718b06350ULL,0x2f00b3309bbd11ffULL,0x76108a6fb4044974ULL,0x801bb9e0a851d266ULL,0x0dd099bebf8990c1ULL,+ 0x14c6dd8a58d6cd46ULL,0x9cb633b58e6634d2ULL,0xc1305047f81bc328ULL,0x12ede0e226a177e5ULL,0x332cca62065a6f4fULL,0xc3a47ecd67be487bULL,0x741eb1870f47ed1cULL,0x99e66e58e7598b14ULL,+ 0xebd6a6777b0ac93dULL,0xa6e37b0d78f5e0d7ULL,0x2516c09676f5492bULL,0x1e4bf8889ac05f3aULL,0xcdb42ce04df0ba2bULL,0x935d5cfd5062341bULL,0x8a30333382acac20ULL,0x429438c45198b00eULL,+ 0xfb2838be67e573e0ULL,0x05891db94084c44bULL,0x9131137396c1c2c5ULL,0x6aebfa3fd958444bULL,0xac9cdce9e56e55c1ULL,0x7148ced32caa46d0ULL,0x2e10c7efb61fe8ebULL,0x9fd835daff97cf4dULL,+ 0x6c626f56c1770616ULL,0x5351909e09da9a2dULL,0xe58e6825a3730e45ULL,0x9d8c8bc003ef0a79ULL,0x543f78b6056becfdULL,0x33f13253a090b36dULL,0x82ad4997794432f9ULL,0x1386493c4721f502ULL,+ 0x3794eefa5abea82aULL,0x8dc611b993fe62d4ULL,0x69f1af37281ef606ULL,0x6af546c839839e69ULL,0x625578c7c977ec23ULL,0xa8de294cbd5c0576ULL,0xe2ddaf0f7cd1a4c0ULL,0x8243fc704f95f4d4ULL,+ 0xe566f400b008733aULL,0xcba0697d512e1f57ULL,0x9537c2b240509cd0ULL,0x5f989c6957353d8cULL,0x7dbec9724c3c2b2fULL,0x90e02fa8ff031fa8ULL,0xf4d15c53cfd5d11fULL,0xb3404fae48314dfcULL,+ 0xa36da109081e9387ULL,0xfb9780d78c935828ULL,0xd5940332e540b015ULL,0xc9d7b51be0f466faULL,0xfaadcd41d6d9f671ULL,0xba6c1e28b1a2ac17ULL,0x066a7833ed201e5fULL,0x19d99719f90f462bULL,+ 0xf02cc3a9f327a07fULL,0xefb27a9b4490937dULL,0x81451e96b1b3afa5ULL,0x67e24de891883be4ULL,0x1ad65d4770869e54ULL,0xd36291a464a3856aULL,0x070a1abf7132e880ULL,0x9511d0a30e28dfdfULL,+ 0xfdeed650f8d1cac4ULL,0xeb99194b6d16bda5ULL,0xb53b19f71cabbe46ULL,0x5f45af5039b9276cULL,0xd0784c6126ee9d77ULL,0xf7a1558b0c02ca5dULL,0xb61d6c59f032e720ULL,0xae3ffb95470cf3f7ULL,+ 0x9b185facc72a4be5ULL,0xf66de2364d848089ULL,0xba14d07c717afea9ULL,0x25bfbfc02d551c1cULL,0x2cef0ecd4cdf3d88ULL,0x8cee2aa3647f73c4ULL,0xc10a7d3d722d67f7ULL,0x090037a294564a21ULL,+ 0xe6567987fa9ced27ULL,0x36b2d8842a9e5dbcULL,0xf4bdeec6380d8e8cULL,0xb5e6a6b0dbc300d0ULL,0x7ba7e9b9592bef36ULL,0x2b373c4fee81b749ULL,0x484b5e01f0ce596bULL,0x7cc51c62c0bf54ccULL,+ 0x6ac07bb84f3815c4ULL,0xddb9f6241aa9017eULL,0x31e30228ca85720aULL,0xe59d63f57cb75838ULL,0x69e18e777baad2d0ULL,0x2cfdb784d42f5d73ULL,0x025dd53df5774983ULL,0x2f80e7cee042cd52ULL,+ 0x4bf56bafec695bb0ULL,0x22da1ca8f13c78adULL,0x0f9c4b131182abb0ULL,0x02ea555aae7d249eULL,0x868583f25e05d9e3ULL,0xe09cdcdf70382afaULL,0xdf072ec787080408ULL,0x0a317847cbf75658ULL,+ 0x43f18d7f4d6ee4abULL,0xd3ac8cde9570c3dcULL,0x527e49070b8c9b2aULL,0x716709a7c5a4c0f1ULL,0x930852b0916a26b1ULL,0x3cc17fcf4e071177ULL,0x34f5e3d459694868ULL,0xee0341aba28f655dULL,+ 0xf431f462060b5f61ULL,0xa56f46b47bd057c2ULL,0x348dca6c47e1bf65ULL,0x9a38783e41bcf1ffULL,0x7a5d33a9da710718ULL,0x5a7799872e0aeaf6ULL,0xca87314d2d29d187ULL,0xfa0edc3ec687d733ULL,+ 0x1c894849cb198ac7ULL,0xa884a93d0f264665ULL,0x2da964ef9b200678ULL,0x3c351b87009834e6ULL,0xafb2ef9fe2c4b44bULL,0x580f6c473326790cULL,0xb84805210b02264aULL,0x8ba6f9e242a194e2ULL,+ 0x39d934abd3c095f1ULL,0x04b261bee4b76d71ULL,0x1d2e6970e73e6984ULL,0x879fb23b5e5fcb11ULL,0x11506c72dfd75490ULL,0x3a97d08561bcf1c1ULL,0x43201d82bf5e7007ULL,0x7f0ac52f798232a7ULL,+ 0xb25101fb319d7682ULL,0xb02931290a982feeULL,0x51c1c9b90261b344ULL,0x0e008c5bbfd371faULL,0xd866dd1c0278ca33ULL,0x666f76a6e5aa53b1ULL,0xe5cfb7796013a2cfULL,0x1d3a1aada3521836ULL,+ 0x76b4131a567193ecULL,0xaf3c305ae5f6e70bULL,0x9587bd39031eebddULL,0x5709def871bbe831ULL,0x570599830eb2b669ULL,0x4d80ce1b875b7029ULL,0x838a7da80364ac16ULL,0x2f431d23be1c83abULL,+ 0xe781276638235d4eULL,0x1c62bd67496e3298ULL,0x8378660c3f175bc8ULL,0x4d04e18917afdd4dULL,0x32a8160185a8068cULL,0xdb58e4e192b29a85ULL,0xe8a65b86c70d8a3bULL,0x5f0e6f4e98a0403bULL,+ 0x2c2492b73f894ae0ULL,0xf59df3e5b75f18ceULL,0x7cb740d28f53cad0ULL,0x3eb585fbc4f01294ULL,0x17da0c8632c7f717ULL,0xeb8c795baf943f4cULL,0x4ee23fb5f67c51d2ULL,0xef18757568889949ULL,+ 0x3ea011a4e822f0d0ULL,0xbc647ad15a8704f8ULL,0xbb315b3550c6820fULL,0x863dec3db7e76becULL,0x01ff5d3af017bfc7ULL,0x20054439976b8229ULL,0x067fca370bbd0d3bULL,0xf63dde647f5e3d0fULL,+ 0x75d9bc15adf7cccfULL,0x81a3e5d6dfa1e1b0ULL,0x8c39e444249bc17eULL,0xf37dccb28ea7fd43ULL,0xda654873907fba12ULL,0x35daa6da4a372904ULL,0x0564cfc66283a6c5ULL,0xd09fa4f64a9395bfULL,+ 0xb510b3b56aa39dffULL,0x59b43da29f8e4d8cULL,0xa8ce31fd9e4c4b9fULL,0x0e20be26c1303c01ULL,0x18187182e8ee47c9ULL,0xd9687cdb7db98101ULL,0x7a520e4da1e14ff6ULL,0x429808ba8836d572ULL,+ 0x174d46996d16768eULL,0x9fc4ff6a628bf217ULL,0x77705a94154e490dULL,0x9d96dd288d2d997aULL,0x77e2d9d8ce5d72c4ULL,0x9d06c5a4c11c714fULL,0x02aa513679e4a03eULL,0x1386b3c2030ff28bULL,+ 0x26a42d69ea40dc3aULL,0xdc84ad22aecc018fULL,0x25c36c7b3270f04aULL,0x46ba6d4750fa72edULL,0x6c37d1c593e58a8eULL,0xa2394731120c088cULL,0xc3be4263cb6e86daULL,0x2c417d367126d038ULL,+ 0xcca523bb440e2229ULL,0x324673a273ef4d04ULL,0xaf3adf343e11ec39ULL,0x6136d7f1dc5968d3ULL,0x7a7b2899b053a927ULL,0x3eaa2661ae067ecdULL,0x8549b9c802779cd9ULL,0x061d7940c53385eaULL,+ 0xe07141fcaaa2902bULL,0x539ad799e4f69ad3ULL,0xa6453f94813f9ffdULL,0xc58d3c48375bc2f7ULL,0xb3326fad5dc64e96ULL,0x3aafcaa9b240e354ULL,0x1d1b0903aca1e7a9ULL,0x4ceb97671211b8a0ULL,+ 0x1eb4de4687032d58ULL,0xc54f3d835e2c79e0ULL,0x07818df45d04ef23ULL,0x55faa9c8673d41b4ULL,0xced64f6f89b95355ULL,0x4860d2eab7415c84ULL,0x5fdb9bd2050ebad3ULL,0xdb53e0cc6685a5bfULL,+ 0x919fca5fabfae1caULL,0x937afaac1a21459bULL,0x9e0ca91c1f66a4d2ULL,0x194cc7f323ec1331ULL,0xad25143a8aa11690ULL,0xbe40ad8d09b59e08ULL,0x37d60d9be750860aULL,0x6c53b008c6bf434cULL,+ 0x832d7080eb6b242dULL,0xd30bd0233b71e246ULL,0x7027991bbe31139dULL,0x68797e91462e4e53ULL,0x423fe20a6b4e185aULL,0x82f2c67e42d9b707ULL,0x25c817684cf7811bULL,0xbd53005e045bb95dULL,+ 0xe5f649be9d8e68fdULL,0xdb0f05331b044320ULL,0xf6fde9b3e0c33398ULL,0x92f4209b66c8cfaeULL,0xe9d1afcc1a739d4bULL,0x09aea75fa28ab8deULL,0x14375fb5eac6f1d0ULL,0x6420b560708f7aa5ULL,+ 0x9eae499c6254dc41ULL,0x7e2939247a837e7eULL,0x74aec08c090524a7ULL,0xf82b92198d6f55f2ULL,0x493c962e1402cec5ULL,0x9f17ca17fa2f30e7ULL,0xbcd783e8e9b879cbULL,0xea3d8c145a6f145fULL,+ 0xdede15e75e0dee6eULL,0x74f24872dc628aa2ULL,0xd3e9c4fe7861bb93ULL,0x56d4822a6187b2e0ULL,0xb66417cfc59826f9ULL,0xca2609692408169eULL,0xedf69d06c79ef885ULL,0x00031f8adc7d138fULL,+ 0x103c46e60ebcf726ULL,0x4482b8316231470eULL,0x6f6dfaca487c2109ULL,0x2e0ace9762e666efULL,0x3246a9d31f8d1f42ULL,0x1b1e83f1574944d2ULL,0x13dfa63aa57f334bULL,0x0cf8daed9f025d81ULL,+ 0x30d78ea800ee11c1ULL,0xeb053cd4b5e3dd75ULL,0x9b65b13ed58c43c5ULL,0xc3ad49bdbd151663ULL,0x99fd8e41b6427990ULL,0x12cf15bd707eae1eULL,0x29ad4f1b1aabb71eULL,0x5143e74d07545d0eULL,+ 0x30266336c88bdee1ULL,0x25f293065876767cULL,0x9c078571c6731996ULL,0xc88690b2ed552951ULL,0x274f2c2d852705b4ULL,0xb0bf8d444e09552dULL,0x7628beeb986575d1ULL,0x407be2387f864651ULL,+ 0x0e5e3049a639fc6bULL,0xe75c35d986003625ULL,0x0cf35bd85dcc1646ULL,0x8bcaced26c26273aULL,0xe22ecf1db5536742ULL,0x013dd8971a9e068bULL,0x17f411cb8a7909c5ULL,0x5757ac98861dd506ULL,+ 0x85de1f0d1e935abbULL,0xdefd10b4154de37aULL,0xb8d9e392369cebb5ULL,0x54d5ef9b761324beULL,0x4d6341ba74f17e26ULL,0xc0a0e3c878c1dde4ULL,0xa6d7758187d918fdULL,0x6687601502ca3a13ULL,+ 0xc7313e9cf36658f0ULL,0xc433ef1c71f8057eULL,0x853262461b6a835aULL,0xc8f053987c86394cULL,0xff398cdfe983c4a1ULL,0xbf5e816203b7b931ULL,0x93193c46b7b9045bULL,0x1e4ebf5da4a6e46bULL,+ 0xf9942a6043a24fe7ULL,0x29c1191effb3492bULL,0x9f662449902fde05ULL,0xc792a7ac6713c32dULL,0x2fd88ad8b737982cULL,0x7e3a0319a21e60e3ULL,0x09b0de447383591aULL,0x6df141ee8310a456ULL,+ 0xaec1a039e6d6f471ULL,0x14b2ba0f1198d12eULL,0xebc1a1603aeee5acULL,0x401f4836e0b964ceULL,0x2ee437964fd03f66ULL,0x3fdb4e49dd8f3f12ULL,0x6ef267f629380f18ULL,0x3e8e96708da64d16ULL,+ 0xbc19180c207674f1ULL,0x112e09a733ae8fdbULL,0x996675546aaeb71eULL,0x79432af1e101b1c7ULL,0xd5eb558fde2ddec6ULL,0x81392d1f5357753fULL,0xa7a76b973ae1158aULL,0x416fbbff4a899991ULL,+ 0x9e65fdfd0d4a9dcfULL,0x7bc29e48944ddf12ULL,0xbc1a92d93c856866ULL,0x273c69056e98dfe2ULL,0x69fce418cdfaa6b8ULL,0x606bd8235061c69fULL,0x42d495a06af75e27ULL,0x8ed3d5056d873a1fULL,+ 0xaf5528416ab25b6aULL,0xc6c0ffc72b1a4523ULL,0xab18827b21c99e03ULL,0x060e86489034691bULL,0x5207f90f93c7f398ULL,0x9f4a96cb82f8d10bULL,0xdd71cd793ad0f9e3ULL,0x84f435d2fc3a54f5ULL,+ 0x4b03c55b8e33787fULL,0xef42f975a6384673ULL,0xff7304f75051b9f0ULL,0x18aca1dc741c87c2ULL,0x56f120a72d4bfe80ULL,0xfd823b3d053e732cULL,0x11bccfe47537ca16ULL,0xdf6c9c741b5a996bULL,+ 0xee7332c7904fc3faULL,0x14a23f45c7e3636aULL,0xc38659c3f091d9aaULL,0x4a995e5db12d8540ULL,0x20a53becf3a5598aULL,0x56534b17b1eaa995ULL,0x9ed3dca4bf04e03cULL,0x716c563ad8d56268ULL,+ 0x5043dea7e0f222c2ULL,0x309d42ac72e65142ULL,0x94fe9ddd9216cd30ULL,0xd6539c7d0f87feecULL,0x03c5a57c432ac7d7ULL,0x72692cf0327fda10ULL,0xec28c85f280698deULL,0x2331fb467ec283b1ULL,+ 0xa0158eeae457a477ULL,0xd19857dbee6ddc05ULL,0xb326522418c41671ULL,0x3ffdfc7e3c2c0d58ULL,0x3a3a525426ee7cdaULL,0x341b0869df02c3a8ULL,0xa023bf42723bbfc8ULL,0x3d15002a14452691ULL,+ 0xc961b2f687500b96ULL,0x795510e72dcd9425ULL,0x0308172978615433ULL,0xe5d0145465445029ULL,0x5bd13302bf690cbeULL,0x44e48831731eca67ULL,0x73306bc72b8038a4ULL,0x351d151ebf57bf02ULL,+ 0x5ef7324c85edfa30ULL,0x2597655487d4f3daULL,0x352f5bc0dcb50c86ULL,0x8f6927b04832a96cULL,0xd08ee1ba55f2f94cULL,0x6a996f99344b45faULL,0xe133cb8da8aa455dULL,0x5d0721ec758dc1f7ULL,+ 0xf3d44e1f9a876441ULL,0x82bc0c14147a818dULL,0x33ddc1170603eddeULL,0x77163f2e0a25f260ULL,0xb54c02caa3bfaa53ULL,0xbd1b2502e2256982ULL,0xc4e1728c1a6f37dcULL,0xfe36c213814c94a5ULL,+ 0xf3cae7e9262a3539ULL,0x78a49d1d6670d59eULL,0x37de0f63c1c5e1b9ULL,0x3072c30c69cb7c1cULL,0x1d278a5277c850e6ULL,0x84f15f8f1f6a3de6ULL,0x46a8bb45592ca7adULL,0x1912e3eee4d424b8ULL,+ 0xc1ffe2d490e31734ULL,0x91b1f1267fca007cULL,0x5459b1d0ae3f77e8ULL,0x262b051d46425c88ULL,0xcf5c8f765c51e274ULL,0x997481e2304e6146ULL,0x6fc1198bd84046b5ULL,0x1cb0a6bbe7f7a6bdULL,+ 0x6ba7a92079e5fb67ULL,0xe1331feb70aa725eULL,0x5080ccf57df5d837ULL,0xe4cae01d7ff72e21ULL,0xd9243ee60412a77dULL,0x06ff7cacdf449025ULL,0xbe75f7cd23ef5a31ULL,0xbc9578220ddef7a8ULL,+ 0xc4737ad11b7f30b0ULL,0x525ab2c63629dcf9ULL,0x963f4cc1186ae160ULL,0x8507671373e6b6e0ULL,0xd9be3180f6998bcfULL,0x93d91da3b1c8d8d8ULL,0xf902ce661b8c0054ULL,0x47e7924d74a8a768ULL,+ 0xdc988086365e668bULL,0xada8dcdaaabda5fbULL,0xbc146b4c255f1fbeULL,0x9cfcde29cf34cfc3ULL,0xacbb453e7e85d1e4ULL,0x9ca09679f92358b5ULL,0x15fc2d96240823ffULL,0x8d65adf70c11d11eULL,+ 0x323cfd177e19a46fULL,0x0948a7a786161156ULL,0x50d06b977e7d3363ULL,0x41c47ec1a702579dULL,0x9455998e59e9260bULL,0xc865e44446c24260ULL,0x393021ec13bc3744ULL,0x4981994ecd92a14aULL,+ 0x8cf7230cb0ce1c55ULL,0x5b534d050bbfb607ULL,0xee1ef1130e16363bULL,0x27e0aa7ab4999e82ULL,0xce1dac2d79362c41ULL,0x67920c9091bb6cb0ULL,0x1e648d632223df24ULL,0x0f7d9eefe32e8f28ULL,+ 0x9766f264d66f51c0ULL,0x644317ab5d9ccea5ULL,0xa39b37bcd721e232ULL,0x98bdde0bb9daf737ULL,0xc2ecc758165166bdULL,0x0951a285a2802108ULL,0xe39fbf24997aa66fULL,0x1a2f6862db62da27ULL,+ 0x775557f10296f4fdULL,0x1dca76a3ea51b436ULL,0xf3e98f60fb950805ULL,0x31ff32ea831cf7f1ULL,0x643e7bf18d2c714bULL,0x64b5c3392e9d2acaULL,0xa9fd9ccc6adc2d23ULL,0xfc2397eccc721b9bULL,+ 0xab651fc764465367ULL,0xe43870152b098f57ULL,0x0a91d519d382376fULL,0xb5afdb0a53cad929ULL,0x457e1875138d5523ULL,0xa92becae1aecacfbULL,0x0762f6e811484f49ULL,0x114b5c86dda16c2bULL,+ 0x6943f39afa833834ULL,0x22951722a6328562ULL,0x81d63dd54170fc10ULL,0x9f5fa58faecc2e6dULL,0xb66c8725e77d9a3bULL,0x11235cea6384ebe0ULL,0x06a8c1185845e24aULL,0x0137b286ebd093b1ULL,+ 0xdb567d6ac42bd6d2ULL,0x6df86468bb1f96aeULL,0x0efe5b1a4843b28eULL,0x961bbb056379b240ULL,0xb6caf5f070a6a26bULL,0x70686c0d328e6e39ULL,0x80da06cf895fc8d3ULL,0x804d8810b363fdc9ULL,+ 0x63b99ce74462007dULL,0xb8ab48a54cb5f5b7ULL,0x9ec673d2f55edde7ULL,0xd1567f748cfaefdaULL,0x46381b6b0887bcecULL,0x694497cee178f3c2ULL,0x5e6525e31e6266cbULL,0x5931de26697d6413ULL,+ 0x14e49da11f17a34cULL,0x5420ab39235a1456ULL,0xb76372412f50363bULL,0x7b15d623c3fabb6eULL,0xa0ef40b1e274e49cULL,0x5cf5074496b1860aULL,0xd6583fbf66afe5a4ULL,0x44240510f47e3e9aULL,+ 0x142b55021a93507aULL,0xb4cd11878d3c06cfULL,0xdf70e76a91ec3f40ULL,0x484e81ad4e7553c2ULL,0x830f87b5272e9d6eULL,0xea1c93e5c6ff514aULL,0x67cc2adcc4192a8eULL,0xc77e27e242f4535aULL,+ 0xb5358b1e48ac2840ULL,0x18311294ecba9477ULL,0xda58f990a6946b43ULL,0x3098baf99ab41819ULL,0x66c4c1584198da52ULL,0xab4fc17c146bfd1bULL,0x2f0a4c3cbf36a908ULL,0x2ae9e34b58cf7838ULL,+ 0x45eb40ec0ccced58ULL,0x25cd4b9c0da44f98ULL,0x43e06458871812c6ULL,0x99f80d5516cef651ULL,0x571340c9ce6dc153ULL,0x138d5117d8665521ULL,0xacdb45bc4e07014dULL,0x2f34bb3884b60b91ULL,+ 0x417499e84a34f239ULL,0x15fdb83cb90402d5ULL,0xb75f46bf433aa832ULL,0xb61e15af63215db1ULL,0xaabe59d4a127f89aULL,0x5d541e0c07e816daULL,0xaaba0659a618b692ULL,0x5532773317266026ULL,+ 0x8cda9cf2d0c05199ULL,0x502fbc22fae78454ULL,0xc0bda9dff572a182ULL,0x5f9b71b86158b372ULL,0xe0f33a592b82dd07ULL,0x763027359523032eULL,0x7fe1a721c4505a32ULL,0x7b6e3e82f796409fULL,+ 0x023c155d3f6effc7ULL,0x1fbd69ff9c90f0c7ULL,0xe5d7da8abeec2c5dULL,0x8813872bd7e86273ULL,0x9f3bc2c655f5e228ULL,0x11482869b0923b41ULL,0x65d75c741aa307caULL,0xda92c2577f24eee5ULL,+ 0x26357732edc665d1ULL,0x9fb5b731a939ef1bULL,0x7db720fb94968089ULL,0x36f75f2c33138c52ULL,0xf8b793ec48d3cb97ULL,0x8dff1d456d261726ULL,0xfb65791b885c4ffbULL,0xf7c79e2df1a3a870ULL,+ 0x08dd1028754c92e1ULL,0xca90b57acf0fef34ULL,0x1a9b84ac8af55919ULL,0xaa95e0e1ed93686bULL,0x46737315167021a4ULL,0x6cb6a0da20d5ff98ULL,0xecc4801a1092e706ULL,0xedcab23a3c5e61a6ULL,+ 0xb4c66356ea37ba9eULL,0x1adc84150afff55dULL,0xf0080ef9596cc862ULL,0x756c85b86d647ab6ULL,0xc9db94aa1db9c215ULL,0x2dd36db12013b1a5ULL,0xde6ac61c4286c903ULL,0x3fd32f88c76cf884ULL,+ 0x7f1290fca06d107eULL,0x697261fdb7661137ULL,0x1bb5be4e947b4b38ULL,0xb49826b63bb79130ULL,0x019ddfe85ba8bffbULL,0xb1af79007e3fa8e4ULL,0x72e1bdf201bcfe7fULL,0x2ed3ca8fd1169aeaULL,+ 0x3befda8cd745fff1ULL,0x70b9e9b669b9924eULL,0xa5df48cfd1511381ULL,0x84f93fe2d06bc535ULL,0xaa42c5a9b279a6c3ULL,0x651da6c4d8f96132ULL,0xb0368c8b01b6aea5ULL,0x64e44c47ac7862a2ULL,+ 0xe17a9947d9de99a8ULL,0xc2e61b2dc93477bdULL,0x57f684d41d19e287ULL,0x843c2122fe358135ULL,0xe2d3e2e904f7e8abULL,0xbf93ffe9b5f27aeeULL,0x29830d1d7b1858c4ULL,0xa8f449648106adbfULL,+ 0xe3417bc035d0b34aULL,0x440b386b8327c0a7ULL,0x8fb7262dac0362d1ULL,0x2c41114ce0cdf943ULL,0x2ba5cef1ad95a0b1ULL,0xc09b37a867d54362ULL,0x26d6cdd201e486c9ULL,0x20477abf42ff9297ULL,+ 0xa004dcb3292a9287ULL,0xddc15cf677b092c7ULL,0x083a8464806c0605ULL,0x4a68df703db997b0ULL,0x9c134e4505bf7dd0ULL,0xa4e63d398ccf7f8cULL,0xa6e6517f41b5f8afULL,0xaa8b9342ad7bc1ccULL,+ 0xc41764717af715d2ULL,0xe2f7f594d0134a96ULL,0x2c1873efa41ec956ULL,0xe4e7b4f677821304ULL,0xe5c8ff9788d5374aULL,0x2b915e6380823d5bULL,0xea6bc755b2ee8fe2ULL,0x6657624ce7112651ULL,+ 0xd6f800e07442f1d5ULL,0x475607d166e0e3abULL,0x82807f16b7c64047ULL,0x8858e1e3a749883dULL,0x5859120b8231ee10ULL,0x1b80e7eb638a1eceULL,0xcb72525ac6aa73a4ULL,0xa7cdea3d844423acULL,+ 0x57477b11e51732d2ULL,0xdfd6eb282538fc0eULL,0x5c43b0cc3b39eec5ULL,0x6af12778cb36cc57ULL,0x70b0852d06c425aeULL,0x6df92f8c5c221b9bULL,0x6c8d4f9ece826d9cULL,0xf59aba7bb49359c3ULL,+ 0xd2eb2cf152bfda05ULL,0xe0e4c4e96197b98cULL,0x1d35076cf8a1726fULL,0x6c06085b2db11e3dULL,0x15c0c4d74463ba14ULL,0x9d292f830030238cULL,0x1311ee8b3727536dULL,0xfeea86efbeaedc1eULL,+ 0xa7f96054afa05dd8ULL,0x26dfcf21fcaf119eULL,0xe20ef2e30564bb59ULL,0xef4dca5061cb02b8ULL,0xcda7838a65d30672ULL,0x8b08d534fd657e86ULL,0x4c5b439546d595c8ULL,0x39b58725425cb836ULL,+ 0xfda853931a62cc26ULL,0x23c69b9650c0e052ULL,0xa227df15bfc633f3ULL,0x2ac788481bae7d48ULL,0x487878f9187d073dULL,0x6c2be919967f807dULL,0x765861d8336e6d8fULL,0x88b8974cce528a43ULL,+ 0xc37e2c2e421d3aa4ULL,0xf926407ce84fa840ULL,0x18abc03d1454e41cULL,0x26605ecd3f7af644ULL,0x242341a6d6a5eabfULL,0x1edb84f4216b668eULL,0xd836edb804010102ULL,0x5b337ce7945e1d8cULL,+ 0x666ba2dccc78cf66ULL,0xb30181746fdbff77ULL,0x8d4dd0db168d4668ULL,0x259455d01dab3a2aULL,0xf58564c5cde3acecULL,0x7714192513adb276ULL,0x527d725d8a303f65ULL,0x55deb6c9e6f38f7bULL,+ 0x864d05d73272d838ULL,0xe22924f9fa6295c5ULL,0x8189593f6c2fda32ULL,0x330d7189b184b544ULL,0x79efa62cbde1f714ULL,0x35771c94e5cb1a63ULL,0x2f4826b8641c8332ULL,0x00a894fbc8cee854ULL,+ 0xdcdacd0a1058a318ULL,0x369cf3f578053a9aULL,0xc6c3de5031c68de2ULL,0x4653a5763c4b6d9fULL,0x1688dd5aaa4e5c97ULL,0x5be80aa1b7ab3c74ULL,0x70cefe7cbc65c283ULL,0x57f95f1306867091ULL,+ 0xc240b6de34eaacdaULL,0xd9e116e82ba0f1deULL,0xcbe45ec779438e55ULL,0x91787c9d96f752d7ULL,0x897f532bf129ac2fULL,0xd307b7c85a36e22cULL,0x91940675749fb8f3ULL,0xd14f95d0157fdb28ULL,+ 0x1625360416df4285ULL,0xb0c9babbd0c56ae2ULL,0x73032b19cfc5cfc3ULL,0xe497e5c309752056ULL,0x12096bb4164bda96ULL,0x1ee42419a0b74da1ULL,0x8fc36243403826baULL,0x0c8f0069dc09e660ULL,+ 0xc44b74a15b0ec6f5ULL,0x47989fe45289b2b8ULL,0x745f848458d6fc73ULL,0xec362a6ff61c70abULL,0x070c98a7b3a8ad41ULL,0x73a20fc07b63db51ULL,0xed2c2173f44c35f4ULL,0x8a56149d9acc9dcaULL,+ 0xa395c36f35d33ae7ULL,0x200ea12350bb5a94ULL,0x20c789bd0bafe84bULL,0x243ef52d0919276aULL,0x3934c577e23ae233ULL,0xb93807afa460d1ecULL,0xb72a53b1f8fa76a4ULL,0xd8914cb0c3ca4491ULL,+ 0x4c076b86d23ddc82ULL,0x03fd344c7e0143f0ULL,0xa95362ff317af2c5ULL,0x0add3db7e18b7a4fULL,0x9c673e3f8260e01bULL,0xfbeb49e554a1cc91ULL,0x91351bf292f2e433ULL,0xc755e7ec851141ebULL,+ 0x2bf5db47f23206d5ULL,0x2f6d34201d260152ULL,0x17b876533f8ff89aULL,0x5157c30c378fa458ULL,0x7517c5c52d4fb936ULL,0xef22f7ace6518cdcULL,0xdeb483e6bf847a64ULL,0xf508455892e0fa89ULL,+ 0xab9659d8df7304d4ULL,0xb71bcf1bff210e8eULL,0xa9a2438bd73fbd60ULL,0x4595cd1f5d11b4deULL,0x9c0d329a4835859dULL,0x4a0f0d2d7dbb6e56ULL,0xc6038e5edf928a4eULL,0xc94296218f5ad154ULL,+ 0x08a33840a70c6ec4ULL,0x9e8819f7e0311195ULL,0xed209d96708ab202ULL,0x10d7c4e7ce943a27ULL,0x372fb317a29b49a1ULL,0x57a67fb346627d1fULL,0xf912561e7cdf39ecULL,0xfa3ce6f26f7c8f17ULL,+ 0x91213462f23f2d92ULL,0x6cab71bd60b94078ULL,0x6bdd0a63176cde20ULL,0x54c9b20cee4d54bcULL,0x3cd2d8aa9f2ac02fULL,0x03f8e617206eedb0ULL,0xc7f68e1693086434ULL,0x831469c592dd3db9ULL,+ 0xfe7d7465653f3c5fULL,0x283dd45ef040feb1ULL,0x91fe599bf3b7edfeULL,0x5ff039ad80379311ULL,0xbf76995b4e96fa49ULL,0x2640b6b2a3e25094ULL,0x8b096341c1c83f74ULL,0xd2bec884fa560ac3ULL,+ 0x8521df248f981354ULL,0x587e23ec3588a259ULL,0xcbedf281d7a0992cULL,0x06930a5538961407ULL,0x09320debbe5bbe21ULL,0xa7ffa5b52491817fULL,0xe6c8b4d909065160ULL,0xac4f3992fff6d2a9ULL,+ 0x2e4eb2a3cc53da66ULL,0x04708a71f17a9b4eULL,0xdbfdc7b20de05b2cULL,0x4cdc9aee4907a201ULL,0xe5cc8dfc6c475566ULL,0x2b83cbfb47be1691ULL,0x695833a74c05c3fdULL,0xee938a7243b0deb0ULL,+ 0x7aa7a1583ae9c1bdULL,0xe0af6d98e37ce240ULL,0xe54342d928ab38b4ULL,0xe8b750070a1c98caULL,0xefce86afe02358f2ULL,0x31b8b856ea921228ULL,0x052a19120a1c67fcULL,0xb4069ea4e3aead59ULL,+ 0x3b826205c6ffcfe6ULL,0x2eb31256aa39418aULL,0xc4b4a9e1c18521fbULL,0x48614dd8db610615ULL,0x04c362bbeea7475fULL,0x916ab969a8ead162ULL,0x6a7975bc0310a876ULL,0xea4e7d11ecc77ec4ULL,+ 0x3232d6e27fa03cb3ULL,0xdb938e5b0fdd7d88ULL,0x04c1d2cd2ccbfc5dULL,0xd2f45c12af3a580fULL,0x592620b57883e614ULL,0x5fd27e68be7c5f26ULL,0x139e45a91567e1e3ULL,0x2cc71d2d44d8aaafULL,+ 0x6ef493c706ba8e6fULL,0x05c07bf8123deffdULL,0xcebf9b4d9c2b5a4fULL,0xf958147e2d038e9cULL,0x5af5cee03e5561c4ULL,0x8d0b5a7a794a6afcULL,0x9de22df13772168bULL,0xe5d249c5d84097fdULL,+ 0x4a9090cde36d0757ULL,0xf722d7b1d9a29382ULL,0xfb7fb04c04b48ddfULL,0x628ad2a7ebe16f43ULL,0xcd3fbfb520226040ULL,0x6c34ecb15104b6c4ULL,0x30c0754ec903c188ULL,0xec336b082d23cab0ULL,+ 0x74c70b4295c69248ULL,0x8813259dfed90303ULL,0xa3e330684b8cc87aULL,0xe689371c111a7a95ULL,0x52bfbbf7fbbbc20bULL,0x73a8543d65f9a6e2ULL,0x67bb2fdd7e413e6dULL,0xa066b3efc5cf2032ULL,+ 0x473d62a21e206ee5ULL,0xf1e274808c49a633ULL,0x87ab956ce9f6b2c3ULL,0x61830b4862b606eaULL,0x67cd6846e78e815fULL,0xfe40139f4c02082aULL,0x52bbbfcb952ec365ULL,0x74c116426b9836abULL,+ 0xcf61b89c44f48971ULL,0xe2d700f76d660683ULL,0x72ef285cd1d431bdULL,0x0593b24e9bdebf4aULL,0x4084bc5b0561f8a1ULL,0x84ce74d0aa16f256ULL,0x9cbc79d309f6d277ULL,0xa94fe2fe4139bdfeULL,+ 0x9f51439e558df019ULL,0x230da4baac712b27ULL,0x518919e355185a24ULL,0x4dcefcdd84b78f50ULL,0xa7d90fb2a47d4c5aULL,0x55ac9abfb30e009eULL,0xfd2fc35974eed273ULL,0xb72d824cdbea8fafULL,+ 0x549db2b5ef7d9289ULL,0x2480d4a8197f015aULL,0x61d5590bc40493b6ULL,0x3a55b52e6f780331ULL,0x40eb8115309eadb0ULL,0xdea7de5a92e5c625ULL,0x64d631f0cc6a3d5aULL,0x9d5e9d7c93e8dd61ULL,+ 0x196860411e84e0e5ULL,0xa5db84d3aea34c93ULL,0xf9d5bb197073a732ULL,0xb8d2fe566bcfd7c0ULL,0x45775f36f3eb82faULL,0x8cb20cccfdff8b58ULL,0x1659b65f8374c110ULL,0xb8b4a422330c789aULL,+ 0xc925ff87aedbae9fULL,0x7daf0eb936880a54ULL,0x9284ddf59c4d0e71ULL,0x1581cf93316f8cf5ULL,0x3eeca8873ac1f452ULL,0xb417fce9fb6aeffeULL,0xa5918046eefb8dc3ULL,0x73d318ac02209400ULL,+ 0xc4f4cda3af2ebc2fULL,0xa0af843dcb4efe24ULL,0x53b857c19ccd10b1ULL,0xddc9d1eb914d3e04ULL,0x7bdec8bb62771debULL,0x829277aa91c5aa81ULL,0x7af18dd6832391aeULL,0x1740f316c71a84caULL,+ 0xdd4a12d8e12b31f8ULL,0x577e29bc177736e6ULL,0x2353722ba88935e8ULL,0xca1d3729015f286dULL,0x86c7b6a239a3e035ULL,0x6e5250bfd3b03a9fULL,0x79d98930fd0d536eULL,0x8c4cbbabfa0c3832ULL,+ 0x2d500910cab91f1eULL,0xbedd9e444d1cd216ULL,0xd634b74fedd02252ULL,0xbd60f8e11258617aULL,0xd8c7537b9e05614aULL,0xfd26c766e7af5fc5ULL,0x0660b581582bd926ULL,0x87019244acf07fc8ULL,+ 0xafa26ccfaf64ecb6ULL,0xe6054f974bd72775ULL,0xbbcbab5b140f695aULL,0xbc71b4a4e348efdeULL,0xfc2e52becc96d963ULL,0x150abf5f5e5d9018ULL,0xbd182fa604568771ULL,0x35b4c06170339f83ULL,+ 0x8928e99aeeaf8c49ULL,0xee7aa73d6e24d728ULL,0x4c5007c2e72b156cULL,0x5fcf57c5ed408a1dULL,0x9f719e39b6057604ULL,0x7d343c01c2868bbfULL,0x2cca254b7e103e2dULL,0xe6eb38a9f131bea2ULL,+ 0xc624a04e5f40ff52ULL,0x3611d7cffcd2914aULL,0xb7e8b42b1fd3bfd6ULL,0x6cde40fdfa85063aULL,0x7811c449178b7e5bULL,0x4cb609312972cc13ULL,0xf579125e33b46135ULL,0xca102ef788a4e56eULL,+ 0x0ba4e3520a981b0dULL,0x1c354cb3bd1a41a4ULL,0x1aabaa3adf9fab9cULL,0x0701a7d153c418d5ULL,0xdd1a7cefdcf2b921ULL,0x6ceef0b3bcf48061ULL,0x1083b598de25cce6ULL,0x890a54c7e90a5e34ULL,+ 0xc535956640ac1807ULL,0xd4c1e56684da0b1eULL,0xc4b33f97e0b82421ULL,0xd0bd23177b41be00ULL,0x53a4b42e147b72e1ULL,0xf8d39f5ff777104cULL,0x36e64e64d3fb530dULL,0xa7a6ba6756074fddULL,+ 0x405718db4f6d01b1ULL,0xe73c6bc28f11e8a0ULL,0xac11bb8ca0591a3bULL,0x12d09a5a0acc4531ULL,0xcbf174eee7de13f4ULL,0x177e2be6044fd682ULL,0x65f574cb1c48af70ULL,0xce5966929961cb7cULL,+ 0x989fe84ebc6fab9fULL,0xe70ce6b1c80f6474ULL,0xbe9ff3053b02a1bcULL,0x12ef486699c0afd3ULL,0x22d957f9e3411a26ULL,0x0b41d8817b485b98ULL,0x820e56d04ae20119ULL,0x81e3d01f328528e0ULL,+ 0xc59eed6c048752a1ULL,0x41f2702ea01341b4ULL,0x6e35903b9dc6b092ULL,0x4291aba81f5b5b23ULL,0x8173aa70a653d61dULL,0xd1b648d44f2eb51eULL,0x31b7ce065ab93f8fULL,0xa55408ee99e2f4feULL,+ 0x1fa4ed0985e34160ULL,0xa26d7dc37a03cde2ULL,0x1dac0848fa84df2dULL,0x5e9a28d61b697108ULL,0xa88004d914ea0ea1ULL,0xa8d154283ffe5520ULL,0x4f422dae639b139cULL,0xeedccc0dd4b5a861ULL,+ 0xb33e624f8be762b4ULL,0x2a9ee4d1058e3413ULL,0x968e636967d805faULL,0x9848949b7db8bfd7ULL,0x5308d7e5d23a8417ULL,0x892f3b1df3e29da5ULL,0xc95c139e3dee471fULL,0x8631594dd757e089ULL,+ 0x1083e2ea1f095615ULL,0x0a28ad7714e68c33ULL,0x6bfc02523d8818beULL,0xb585113af35850cdULL,0x7d935f0b30df8aa1ULL,0xaddda07c4ab7e3acULL,0x92c34299552f00cbULL,0xc33ed1de2909df6cULL,+ 0x2dc40d483e07113cULL,0x6e4a5d397d8b63aeULL,0x5582a94b79684c2bULL,0x932b33d4622da26cULL,0xf534f6510dbbf08dULL,0x211d07c964c23a52ULL,0x0eeece0fee5bdc9bULL,0xdf178168f7015558ULL,+ 0xabe7905a83cdd60eULL,0x50602fb5a1170184ULL,0x689886cdb023642aULL,0xd568d090a6e1fb00ULL,0x5b1922c70259217fULL,0x93831cd9c43141e4ULL,0xdfca35870c95f86eULL,0xdec2057a568ae828ULL,+ 0x568f8925913cc16dULL,0x18bc5b6de1a26f5aULL,0xdfa413bef5f499aeULL,0xf8835decc3f0ae84ULL,0xb6e60bd865a40ab0ULL,0x65596439194b377eULL,0xbcd8562592084a69ULL,0x5ce433b94f23ede0ULL,+ 0x860d523d42e06189ULL,0xbf0779414e3aff13ULL,0x0b616dcac1b20650ULL,0xe66dd6d12131300dULL,0xd4a0fd67ff99abdeULL,0xc9903550c7aac50dULL,0x022ecf8b7c46b2d7ULL,0x3333b1e83abf92afULL,+ 0xc0da65e784d6365dULL,0xbcb7443f8f759fb8ULL,0x35c712b17ae81930ULL,0x80428dff4c6e08abULL,0xf19dafefa4faf843ULL,0xced8538dffa9855fULL,0x20ac409cbe3ac7ceULL,0x358c1fb6882da71eULL,+ 0xefecdef7be42a582ULL,0xd3fc608065046be6ULL,0xc9af13c809e8dba9ULL,0x1e6c9847641491ffULL,0x3b574925d30c31f7ULL,0xb7eb72baac2a2122ULL,0x776a0dacef0859e7ULL,0x06fec31421900942ULL,+ 0x324794b07e50122bULL,0xdd744f8b4af07ca5ULL,0x30a12f08d63fc97bULL,0x39650f1a76626d9dULL,0x101b47f71fa38477ULL,0x3d815f19d4dc124fULL,0x1569ae95b26eb58aULL,0xc3cde18895fb1887ULL,+ 0x7ec62fbbf4737f21ULL,0xd8dba5ab6209f5acULL,0x24b5d7a9a5f9adbeULL,0x707d28f7a61dc768ULL,0x7711460bcaa999eaULL,0xba7b174d1c92e4ccULL,0x3c4bab6618d4bf2dULL,0xb8f0c980eb8bd279ULL,+ 0x9d658932790691bfULL,0xed61058906b736aeULL,0x712c2f04c0d63b6eULL,0x5cf06fd5c63d488fULL,0x97363facd9588e41ULL,0x1f9bf7622b93257eULL,0xa9d1ffc4667acaceULL,0x1cf4a1aa0a061ecfULL,+ 0x28d675b2c0519a23ULL,0x9ebf94fe4f6952e3ULL,0xf28bb767a2294a8aULL,0x85512b4dfe0af3f5ULL,0x18958ba899b16a0dULL,0x95c2430cba7548a7ULL,0xb30d1b10a16be615ULL,0xe3ebbb9785bfb74cULL,+ 0x07b53f5eb2e63645ULL,0xbe57e54784c84232ULL,0xd779c2167214d5cfULL,0x617969cd029a3acaULL,0xd17668cd8a7017a0ULL,0x77b4d19abe9b7ee8ULL,0x58fd0e939c161776ULL,0xa8c4f4efd5968a72ULL,+ 0x81eeb865d2fdca23ULL,0x5a15ee08cc8ef895ULL,0x768fa10a01905614ULL,0xeff5b8ef880ee19bULL,0xf0c0cabbcb1c8a0eULL,0x2e1ee9cdb8c838f9ULL,0x0587d8b88a4a14c0ULL,0xf6f278962ff698e5ULL,+ 0x519d34b3bf44da80ULL,0x283834f95ab32e66ULL,0x6e6087976278a000ULL,0x1e62960e627312f6ULL,0x9b87b27be6901c55ULL,0x80e7853824fdbc1fULL,0xbbbc09512facc27dULL,0x06394239ac143b5aULL,+ 0x9c4b646e9e2fce99ULL,0x68a210811e80857fULL,0x06d54e443643b52aULL,0xde8d6d630d8eb843ULL,0x7032156342146a0aULL,0x8ba826f25eaa3622ULL,0x227a58bd86138787ULL,0x43b6c03c10281d37ULL,+ 0x02b37a952f41deffULL,0x0e44a59ae63b89b7ULL,0x673257dc143ff951ULL,0x19c02205d752baf4ULL,0x46c23069c4b7d692ULL,0x2e6392c3fd1502acULL,0x6057b1a21b220846ULL,0xe51ff9460c1b5b63ULL,+ 0x6e85cb51566c5c43ULL,0xcff9c9193597f046ULL,0x9354e90c4994d94aULL,0xe0a393322147927dULL,0x8427fac10dc1eb2bULL,0x88cfd8c22ff319faULL,0xe2d4e68401965274ULL,0xfa2e067d67aaa746ULL,+ 0xb6d92a7f3e5f9f11ULL,0x9afe153ad6cb3b8eULL,0x4d1a6dd7ddf800bdULL,0xf6c13cc0caf17e19ULL,0x15f6c58e325fc3eeULL,0x71095400a31dc3b2ULL,0x168e7c07afa3d3e7ULL,0x3f8417a194c7ae2dULL,+ 0xec234772813b230dULL,0x634d0f5f17344427ULL,0x11548ab1d77fc56aULL,0x7fab1750ce06af77ULL,0xb62c10a74f7c4f83ULL,0xa7d2edc4220a67d9ULL,0x1c404170921209a0ULL,0x0b9815a0face59f0ULL,+ 0x2842589b319540c3ULL,0x18490f59a283d6f8ULL,0xa2731f84daae9fcbULL,0x3db6d960c3683ba0ULL,0xc85c63bb14611069ULL,0xb19436af0788bf05ULL,0x905459df347460d2ULL,0x73f6e094e11a7db1ULL,+ 0xdc7f938eb6357f37ULL,0xc5d00f792bd8aa62ULL,0xc878dcb92ca979fcULL,0x37e83ed9eb023a99ULL,0x6b23e2731560bf3dULL,0x1086e4591d0fae61ULL,0x782483169a9414bdULL,0x1b956bc0f0ea9ea1ULL,+ 0x7b85bb91c31b9c38ULL,0x0c5aa90b48ef57b5ULL,0xdedeb169af3bab6fULL,0xe610ad732d373685ULL,0xf13870df02ba8e15ULL,0x0337edb68ca7f771ULL,0xe4acf747b62c036cULL,0xd921d576b6b94e81ULL,+ 0xdbc864392c422f7aULL,0xfb635362ed348898ULL,0x83084668c45bfcd1ULL,0xc357c9e32b315e11ULL,0xb173b5405b2e5b8cULL,0x7e946931e102b9a4ULL,0x17c890eb7b0fb199ULL,0xec225a83d61b662bULL,+ 0xf306a3c8ee3c76cbULL,0x3cf11623d32a1f6eULL,0xe6d5ab646863e956ULL,0x3b8a4cbe5c005c26ULL,0xdcd529a59ce6bb27ULL,0xc4afaa5204d4b16fULL,0xb0624a267923798dULL,0x85e56df66b307fabULL,+ 0x0281893c2bf29698ULL,0x91fc19a4d7ce7603ULL,0x75a5dca3ad9a558fULL,0x40ceb3fa4d50bf77ULL,0x1baf6060bc9ba369ULL,0x927e1037597888c2ULL,0xd936bf1986a34c07ULL,0xd4cf10c1c34ae980ULL,+ 0x3a3e5334859dd614ULL,0x9c475b5b18d0c8eeULL,0x63080d1f07cd51d5ULL,0xc9c0d0a6b88b4326ULL,0x1ac98691c234296fULL,0x2a0a83a494887fb6ULL,0x565114270cea9cf2ULL,0x5230a6e8a24802f5ULL,+ 0xf7a2bf0f72e3d5c1ULL,0x377174464f21439eULL,0xfedcbf259ce30334ULL,0xe0030a787ce202f9ULL,0x6f2d9ebf1202e9caULL,0xe79dde6c75e6e591ULL,0xf52072aff1dac4f8ULL,0x6c8d087ebb9b404dULL,+ 0xad0fc73dbce913afULL,0x909e587b458a07cbULL,0x1300da84d4f00c8aULL,0x425cd048b54466acULL,0xb59cb9be90e9d8bfULL,0x991616db3e431b0eULL,0xd3aa117a531aecffULL,0x91af92d359f4dc3bULL,+ 0x9b1ec292e93fda29ULL,0x76bb6c17e97d91bcULL,0x7509d95faface1e6ULL,0x3653fe47be855ae3ULL,0x73180b280f680e75ULL,0x75eefd1beeb6c26cULL,0xa4cdf29fb66d4236ULL,0x2d70a9976b5821d8ULL,+ 0x7a3ee20720445c36ULL,0x71d1ac8259877174ULL,0x0fc539f7949f73e9ULL,0xd05cf3d7982e3081ULL,0x8758e20b7b1c7129ULL,0xffadcc20569e61f2ULL,0xb05d3a2f59544c2dULL,0xbe16f5c19fff5e53ULL,+ 0x73cf65b8aad58135ULL,0x622c2119037aa5beULL,0x79373b3f646fd6a0ULL,0x0e029db50d3978cfULL,0x8bdfc43794fba037ULL,0xaefbd687620797a6ULL,0x3fa5382bbd30d38eULL,0x7627cfbf585d7464ULL,+ 0xb2330fef4e4ca463ULL,0xbcef72873566cc63ULL,0xd161d2cacf780900ULL,0x135dc5395b54827dULL,0x638f052e27bf1bc6ULL,0x10a224f007dfa06cULL,0xe973586d6d3321daULL,0x8b0c573826152c8fULL,+ 0x9910ba6b23a5d896ULL,0x1fe19e357fe4364eULL,0x6e1da8c39a33c677ULL,0x15b4488b29fd9fd0ULL,0x1f4392541a1f22bfULL,0x920a8a70ab8163e8ULL,0x3fd1b24907e5658eULL,0xf2c4f79cb6ec839bULL,+ 0x8b5c619c76497ee8ULL,0x5d2b0ac6c717370eULL,0x98204cb64fcf68e1ULL,0x0bdec21162bc6792ULL,0x6973ccefa63b1011ULL,0xf9e3fa97e0de1ac5ULL,0x5efb693e3d0e0c8bULL,0x037248e9d2d4fcb4ULL,+ 0xd3694e2ab20364e4ULL,0x62699718e770b20dULL,0x6183291b6ed77d1cULL,0x69aada7f6d6180a5ULL,0x51f9054bf185509bULL,0xfd7e845678701077ULL,0xd6a2308a7fb96d8dULL,0xd53e48d228dc87eeULL,+ 0x80802dc91ec34f9eULL,0xd8772d3533810603ULL,0x3f06d66c530cb4f3ULL,0x7be5ed0dc475c129ULL,0xcb9e3c1931e82b10ULL,0xc63d2857c9ff6b4cULL,0xb92118c692a1b45eULL,0x0aec44147285bbcaULL,+ 0x37071afbe8316c45ULL,0x982be4fd46700b8bULL,0x8d5d177c64ff8578ULL,0x5ec40582c9a82fa7ULL,0x5518e37bcfa86678ULL,0x24e809f49f031284ULL,0x312f39604bbbb74cULL,0xad4b4f6fc0c14de6ULL,+ 0xa3d6f4868eb6e843ULL,0x6415834bac4ab3abULL,0x028a81514f3cf2dcULL,0xf3b4962f5f3e6c3eULL,0x9119ae90987dd2f2ULL,0x437a6d8ae10bce55ULL,0xc31cdd6b9b149ed6ULL,0x1b77791d06871332ULL,+ 0x9c34b650e16e05e9ULL,0x965a774094e74640ULL,0xa3fd22fbcea3f029ULL,0x1eb6a9688f95277cULL,0x2520a63d7bad84f6ULL,0xad917201f58f2feeULL,0xea92c1669b840d48ULL,0x12109c4aacef5cbdULL,+ 0xfc189ae71e29a3efULL,0xcbe906f04c93302eULL,0xd0107914ceaae10eULL,0xb7a23f34b68e19f8ULL,0xe9d875c2efd2119dULL,0x03198c6efcadc9c8ULL,0x65591bf64da17113ULL,0x3cf0bbf83d443038ULL,+ 0xab293027aad991c1ULL,0x598d0bf8849be4b7ULL,0x8c94a21ab972da90ULL,0xada4cfdd7ecfa840ULL,0x93d4b9c0fbcec63aULL,0x7ca617a203219a34ULL,0x900424eb6a652a55ULL,0xaf9346e9eb8562e0ULL,+ 0xc3e04d7902381461ULL,0xb1643ab5911bc478ULL,0xc92becfa390b3ef2ULL,0x54476778acd2f1b6ULL,0x8daa0c4d66bf3aafULL,0x2bc1287b2c21c65aULL,0xee182910b5a13ac3ULL,0xbb04730090b0790aULL,+ 0x83766947d17d4e0bULL,0xc5772beefdc3a47bULL,0x765a50db1a6fd0ffULL,0x17f904ba45b0995eULL,0xcee643832883487eULL,0xf56db7f3c270aaedULL,0x6738d94f46cb1fd9ULL,0xc8fa426a142fd4d5ULL,+ 0xae485bb72b724759ULL,0x945353e1b2d4c63aULL,0x82159d07de7d6f2cULL,0x389caef34ec5b109ULL,0x4a8ebb53db65ef14ULL,0x2dc2cb7edd99de43ULL,0x816fa3ed83f2405fULL,0x73429bb9c14208a3ULL,+ 0x08ed8febd56daf06ULL,0x8d98277b4a837f69ULL,0x9947c636a9b6e05aULL,0x58c8a77ac0d58abdULL,0xf45496a45f121e4fULL,0x16cd67c71076d3d3ULL,0xecbd1958e3fb0c5dULL,0xfbe185ec38e1eb47ULL,+ 0xb7ef9760ff79d2eeULL,0xdd4d06aff39e7832ULL,0xfd025001b905b499ULL,0x98fe1c61f5b61d31ULL,0xa9f83980c5f12805ULL,0x376e3b783009cd9aULL,0xa322b09f514eb16dULL,0x08e213122c3832dfULL,+ 0xaea68626dc4ad4f4ULL,0x5dc516824ddbc0b6ULL,0xa76697bd602e9065ULL,0xbeeb3ea58c37888eULL,0x1ec4a2f214569113ULL,0xe48b820ca35f4484ULL,0x9fb560949ae44df2ULL,0x6ca1346292cc09fdULL,+ 0xb618d590b01e6e27ULL,0x047e2ccde180b2dcULL,0xd1b299b504aea4a9ULL,0x412c9e1e9fa403a4ULL,0x88d28a3679407552ULL,0x49c50136f332b8e3ULL,0x3a1b6fcce668de19ULL,0x178851bc75122b97ULL,+ 0x197dd46d95a7b1a2ULL,0x9c4e7ad63c6341fbULL,0x426eca29484c2eceULL,0x9211e489de7f4f8aULL,0x14997f6ec78ef1f4ULL,0x2b2c091006574586ULL,0x17286a6e1c3eede8ULL,0x25f92e470f60e018ULL,+ 0xb4e370af3aeac968ULL,0xe4f7fee9c4b63266ULL,0xb4acd4c2e3ac5664ULL,0xf8910bd2ceb38cbfULL,0x1c3ae50cc9c0726eULL,0x15309569d97b40bfULL,0x70884b7ffd5a5a1bULL,0x3890896aef8314cdULL,+ 0x090d7d205ffe7b37ULL,0x3b7f3efb1747d2daULL,0xa2cb525fb54fc519ULL,0x6e220932f66a971eULL,0xddc160dfb486d440ULL,0x7fcfec463fe13465ULL,0x83da7e4e76e4c151ULL,0xd6fa48a1d8d302b5ULL,+ 0x5ced3c9f82e4c634ULL,0x8efb83143a4464f8ULL,0xe706381b7a1dca25ULL,0x6cd15a3c5a2a412bULL,0x9347a8fdbfcd8fb5ULL,0x31db2eef6e54cd22ULL,0xc4aeb11ef8d8932fULL,0x11e7c1ed344411afULL,+ 0xae4065ef12045cf9ULL,0x6fcb2caf9ccce8bdULL,0x1fa0ba4ef2cf6525ULL,0xf683125dcb72c312ULL,0xa01da4eae312410eULL,0x67e286776cd8e830ULL,0xabd9575298fb3f07ULL,0x05f11e11eef649a5ULL,+ 0x996884f5903fa271ULL,0xe6da0fd2b9da921eULL,0xa6f2f2695db01e54ULL,0x1ee3e9bd6876214eULL,0xa26e181ce27a9497ULL,0x36d254e48e215e04ULL,0x42f32a6c252cabcaULL,0x9948148780b57614ULL,+ 0xea961058fa28a7e0ULL,0xc726cf250bf5ec74ULL,0xe74d55c8db229666ULL,0x0bd9abbfa57f5799ULL,0x7479ef074dfc47b3ULL,0xd9c65fc30c52f91dULL,0x8e0283fe36a8bde2ULL,0xa32a8b5e7d4b7280ULL,+ 0xab41b43a43228d83ULL,0x24ae1c304ad63f99ULL,0x8e525f1a46a51229ULL,0x14af860fcd26d2b4ULL,0xd6baef613f714aa1ULL,0xf51865adeb78795eULL,0xd3e21fcee6a9d694ULL,0x82ceb1dd8a37b527ULL,+ 0x8605d27d48307682ULL,0x745aaba3e10566daULL,0xe57cae36bff2d7abULL,0x91332ba14b127823ULL,0xcb5c3638f3429f43ULL,0x43a21c4fec462929ULL,0xe9bc95352b18b7bdULL,0x8c2addf3e78cb0c6ULL,+ 0x4a665bfd2f9fd51aULL,0x7f2f1fe2481b97f7ULL,0xcad05d69ad36ce50ULL,0x314fc2a4844f4dedULL,0xd5593d8cb55fc5c6ULL,0xe3510ce8bfb1e23dULL,0xf9b7be6937453cceULL,0xd3541b7969fae631ULL,+ 0xb013cbcad7154cedULL,0x949b28573f52651aULL,0x03b41f6e9f5e642eULL,0xc3a3462986ed94a4ULL,0xf3c86cd6222b24dcULL,0x7578fe8a028c9c26ULL,0xaac7bfa12edad3b6ULL,0x4112c5d78847940aULL,+ 0x99296525eca445dfULL,0xf1af24f22cdfa4c6ULL,0xf5b4eb61eba6d3bcULL,0x4560910c98972cc7ULL,0x54751c32093eaa32ULL,0x018313497d3c67bbULL,0x3bd90ce62d871110ULL,0x75fc863a538baa7eULL,+ 0x8fe1f8b64ae3a278ULL,0x160c5306137cdf65ULL,0x22f029e733be0492ULL,0x79a680427a75cd82ULL,0x1d8c094a5b3f3adaULL,0x5d723bbe165c3250ULL,0x08b958ffa5792e22ULL,0x829fa986b11c1eaaULL,+ 0x711b8a4176a9f05dULL,0x06ca4e4b9011d488ULL,0x543bc62ba248a65eULL,0x017535ffc9290894ULL,0x840b84ce406851d7ULL,0xafa3acdf90e960b4ULL,0xac3394af7128fd34ULL,0x54eb4d5b2ac0f92cULL,+ 0x923ea73e4a14f836ULL,0xc8cc8c57f0946328ULL,0xce3f117fe917a4dfULL,0x6372f933f72ce929ULL,0x75000249c29ba567ULL,0xcbd437e68c829ccaULL,0x6c63aaabdd02ec7aULL,0xe9b2f90c7b42bd17ULL,+ 0xdb09e87355dbd4b3ULL,0x1f8799286639bbb1ULL,0xb83e47e51c651962ULL,0xd4ef0fb6c43fb574ULL,0x27d3b9d8f1bfb12aULL,0x6ab877e86e5e8b72ULL,0x8eebdc9d157b9014ULL,0x4c2110053aa5cb64ULL,+};
cbits/p256/p256_ec.c view
@@ -33,8 +33,18 @@ // See http://www.imperialviolet.org/2010/12/04/ecc.html ([1]) for background. #include "p256/p256_gf.h"+#include "crypton_bzero.h" +#ifdef CRYPTON_S2N_BIGNUM+#include "p256/p256_s2n.h"+#include "p256/p256_verify.h"+/* the memcpy below is the two representations being the same thing */+#if P256_BITSPERDIGIT != 64 || P256_NDIGITS != 4+#error "CRYPTON_S2N_BIGNUM wants the 64-bit crypton_p256_int"+#endif+#endif + /* Field element operations: */ /* felem_inv calculates |out| = |in|^{-1}@@ -43,69 +53,95 @@ * a^p = a (mod p) * a^{p-1} = 1 (mod p) * a^{p-2} = a^{-1} (mod p)- */+ *+ * The exponent is built left to right from the shape of p - 2, which for+ * this prime is+ *+ * ffffffff 00000001 00000000 00000000 00000000 ffffffff ffffffff fffffffd+ * \__32 ones__/ \_31 zeros, one 1_/ \______ 96 zeros ______/ \_94 ones, 0, 1_/+ *+ * A run of k zeros is k squarings; a run of k ones is k squarings and one+ * multiplication by a^(2^k - 1), which is why the powers below are kept. The+ * whole chain is 255 squarings, which is the least an exponent of 256 bits+ * can be done in, and 13 multiplications.+ *+ * The chain this replaces built the low 94 ones in a second accumulator and+ * multiplied the two at the end, which cost 32 squarings more than the 255. */ static void felem_inv(felem out, const felem in) {- felem ftmp, ftmp2;- /* each e_I will hold |in|^{2^I - 1} */- felem e2, e4, e8, e16, e32, e64;+ felem ftmp, x2, x4, x8, x16, x32; unsigned i; - felem_square(ftmp, in); /* 2^1 */- felem_mul(ftmp, in, ftmp); /* 2^2 - 2^0 */- felem_assign(e2, ftmp);- felem_square(ftmp, ftmp); /* 2^3 - 2^1 */- felem_square(ftmp, ftmp); /* 2^4 - 2^2 */- felem_mul(ftmp, ftmp, e2); /* 2^4 - 2^0 */- felem_assign(e4, ftmp);- felem_square(ftmp, ftmp); /* 2^5 - 2^1 */- felem_square(ftmp, ftmp); /* 2^6 - 2^2 */- felem_square(ftmp, ftmp); /* 2^7 - 2^3 */- felem_square(ftmp, ftmp); /* 2^8 - 2^4 */- felem_mul(ftmp, ftmp, e4); /* 2^8 - 2^0 */- felem_assign(e8, ftmp);+ /* x{k} holds in^(2^k - 1), a run of k ones. */+ felem_square(ftmp, in);+ felem_mul(x2, ftmp, in); /* 2^2 - 1 */++ felem_square(ftmp, x2);+ felem_square(ftmp, ftmp);+ felem_mul(x4, ftmp, x2); /* 2^4 - 1 */++ felem_assign(ftmp, x4);+ for (i = 0; i < 4; i++) {+ felem_square(ftmp, ftmp);+ }+ felem_mul(x8, ftmp, x4); /* 2^8 - 1 */++ felem_assign(ftmp, x8); for (i = 0; i < 8; i++) { felem_square(ftmp, ftmp);- } /* 2^16 - 2^8 */- felem_mul(ftmp, ftmp, e8); /* 2^16 - 2^0 */- felem_assign(e16, ftmp);+ }+ felem_mul(x16, ftmp, x8); /* 2^16 - 1 */++ felem_assign(ftmp, x16); for (i = 0; i < 16; i++) { felem_square(ftmp, ftmp);- } /* 2^32 - 2^16 */- felem_mul(ftmp, ftmp, e16); /* 2^32 - 2^0 */- felem_assign(e32, ftmp);+ }+ felem_mul(x32, ftmp, x16); /* 2^32 - 1 */++ /* The top 32 ones. */+ felem_assign(ftmp, x32);++ /* 31 zeros and a one: the 00000001 word. */ for (i = 0; i < 32; i++) { felem_square(ftmp, ftmp);- } /* 2^64 - 2^32 */- felem_assign(e64, ftmp);- felem_mul(ftmp, ftmp, in); /* 2^64 - 2^32 + 2^0 */- for (i = 0; i < 192; i++) {+ }+ felem_mul(ftmp, ftmp, in);++ /* 96 zeros. */+ for (i = 0; i < 96; i++) { felem_square(ftmp, ftmp);- } /* 2^256 - 2^224 + 2^192 */+ } - felem_mul(ftmp2, e64, e32); /* 2^64 - 2^0 */+ /* 94 ones, as 32 + 32 + 16 + 8 + 4 + 2. */+ for (i = 0; i < 32; i++) {+ felem_square(ftmp, ftmp);+ }+ felem_mul(ftmp, ftmp, x32);+ for (i = 0; i < 32; i++) {+ felem_square(ftmp, ftmp);+ }+ felem_mul(ftmp, ftmp, x32); for (i = 0; i < 16; i++) {- felem_square(ftmp2, ftmp2);- } /* 2^80 - 2^16 */- felem_mul(ftmp2, ftmp2, e16); /* 2^80 - 2^0 */+ felem_square(ftmp, ftmp);+ }+ felem_mul(ftmp, ftmp, x16); for (i = 0; i < 8; i++) {- felem_square(ftmp2, ftmp2);- } /* 2^88 - 2^8 */- felem_mul(ftmp2, ftmp2, e8); /* 2^88 - 2^0 */+ felem_square(ftmp, ftmp);+ }+ felem_mul(ftmp, ftmp, x8); for (i = 0; i < 4; i++) {- felem_square(ftmp2, ftmp2);- } /* 2^92 - 2^4 */- felem_mul(ftmp2, ftmp2, e4); /* 2^92 - 2^0 */- felem_square(ftmp2, ftmp2); /* 2^93 - 2^1 */- felem_square(ftmp2, ftmp2); /* 2^94 - 2^2 */- felem_mul(ftmp2, ftmp2, e2); /* 2^94 - 2^0 */- felem_square(ftmp2, ftmp2); /* 2^95 - 2^1 */- felem_square(ftmp2, ftmp2); /* 2^96 - 2^2 */- felem_mul(ftmp2, ftmp2, in); /* 2^96 - 3 */+ felem_square(ftmp, ftmp);+ }+ felem_mul(ftmp, ftmp, x4);+ felem_square(ftmp, ftmp);+ felem_square(ftmp, ftmp);+ felem_mul(ftmp, ftmp, x2); - felem_mul(out, ftmp2, ftmp); /* 2^256 - 2^224 + 2^192 + 2^96 - 3 */+ /* A zero and a one: the d of fffffffd. */+ felem_square(ftmp, ftmp);+ felem_square(ftmp, ftmp);+ felem_mul(out, ftmp, in); } - /* Group operations: * * Elements of the elliptic curve group are represented in Jacobian@@ -298,7 +334,8 @@ } /* select_affine_point sets {out_x,out_y} to the index'th entry of table.- * On entry: index < 16, table[0] must be zero. */+ * On entry: index < 16. Every entry is a point of its own -- the signed+ * representation has no zero digit -- so the scan starts at zero. */ static void select_affine_point(felem out_x, felem out_y, const limb* table, limb index) { limb i, j;@@ -306,7 +343,7 @@ memset(out_x, 0, sizeof(felem)); memset(out_y, 0, sizeof(felem)); - for (i = 1; i < 16; i++) {+ for (i = 0; i < 16; i++) { limb mask = i ^ index; mask |= mask >> 2; mask |= mask >> 1;@@ -321,95 +358,306 @@ } } -/* select_jacobian_point sets {out_x,out_y,out_z} to the index'th entry of- * table. On entry: index < 16, table[0] must be zero. */-static void select_jacobian_point(felem out_x, felem out_y, felem out_z,- const limb* table, limb index) {- limb i, j;+/* words_are_zero returns 1 when |v| is zero and 0 otherwise, without a+ * branch. */+static u32 words_are_zero(u32 v) {+ v |= v >> 16;+ v |= v >> 8;+ v |= v >> 4;+ v |= v >> 2;+ v |= v >> 1;+ return (v & 1) ^ 1;+} - memset(out_x, 0, sizeof(felem));- memset(out_y, 0, sizeof(felem));- memset(out_z, 0, sizeof(felem));+/* The comb: five teeth to a block, the teeth of a block 52 apart and the two+ * blocks 26 from each other, so 26 steps cover all 260 bits between them.+ *+ * first block i, 52+i, 104+i, 156+i, 208+i+ * second block 26+i, 78+i, 130+i, 182+i, 234+i+ *+ * Five teeth would want a table of 32, but the signed representation makes+ * every digit +-1, so the thirty-two values come in pairs that differ by sign+ * and sixteen entries serve: kPrecomputed holds the ones whose top tooth is+ * positive and the other sign is a negated y. That is the whole of the gain+ * over the four-tooth unsigned comb this replaces, which took 32 steps for+ * the same 256 bits: 25 doublings and 52 mixed additions against 31 and 64.+ */+#define COMB_TEETH 5+#define COMB_STEPS 26+#define COMB_SPAN (2 * COMB_STEPS) /* 52, the distance between a block's teeth */+#define COMB_WORDS 9 /* 260 bits of signs, with room to add into */+#define COMB_BIT(t, q) (((t)[(q) >> 5] >> ((q) & 31)) & 1) - /* The implicit value at index 0 is all zero. We don't need to perform that- * iteration of the loop because we already set out_* to zero. */- table += 3 * NLIMBS;+/* comb_recode writes into |out| the value whose bits are the signs of the+ * scalar's all-bits-set representation: digit j is +1 where bit j of |out| is+ * set and -1 where it is not.+ *+ * For an odd k below 2^260 there is exactly one such representation, and it+ * is (k + 2^260 - 1) / 2 read as bits -- an addition and a shift, and that is+ * all the recoding is. An even scalar has the order added to make it odd,+ * which changes the scalar and not the point it selects.+ *+ * Constant time in the scalar: every branch below is on a loop counter. */+static void comb_recode(u32 out[COMB_WORDS],+ const crypton_p256_int* scalar) {+ u32 k[COMB_WORDS], ord[COMB_WORDS];+ u64 carry;+ int i; - // Hit all entries to obscure cache profiling.- for (i = 1; i < 16; i++) {- limb mask = i ^ index;- mask |= mask >> 2;- mask |= mask >> 1;- mask &= 1;- mask--;- for (j = 0; j < NLIMBS; j++, table++) {- out_x[j] |= *table & mask;- }- for (j = 0; j < NLIMBS; j++, table++) {- out_y[j] |= *table & mask;- }- for (j = 0; j < NLIMBS; j++, table++) {- out_z[j] |= *table & mask;+ for (i = 0; i < COMB_WORDS; i++) {+ k[i] = 0;+ ord[i] = 0;+ }+ for (i = 0; i < 256; i += 32) {+ k[i >> 5] = (u32)(P256_DIGIT(scalar, i / P256_BITSPERDIGIT)+ >> (i % P256_BITSPERDIGIT));+ ord[i >> 5] = (u32)(P256_DIGIT(&crypton_SECP256r1_n, i / P256_BITSPERDIGIT)+ >> (i % P256_BITSPERDIGIT));+ }++ /* an even scalar becomes odd by taking on the order */+ {+ u32 addmask = (u32)0 - (u32)((k[0] & 1) ^ 1);++ carry = 0;+ for (i = 0; i < COMB_WORDS; i++) {+ u64 v = (u64)k[i] + (u64)(ord[i] & addmask) + carry;+ k[i] = (u32)v;+ carry = v >> 32; } }++ /* out = (k + 2^260 - 1) >> 1 */+ carry = 0;+ for (i = 0; i < COMB_WORDS; i++) {+ u64 v = (u64)k[i] + (u64)(i < 8 ? 0xffffffffu : 0xfu) + carry;+ out[i] = (u32)v;+ carry = v >> 32;+ }+ for (i = 0; i < COMB_WORDS - 1; i++) {+ out[i] = (out[i] >> 1) | (out[i + 1] << 31);+ }+ out[COMB_WORDS - 1] >>= 1;+ } +/* point_add_complete_mixed sets {x3,y3,z3} = {x1,y1,z1} + {x2,y2}, where the+ * accumulator is in projective coordinates and the added point is affine.+ *+ * This is Renes-Costello-Batina algorithm 5, for a curve with a = -3. It is+ * complete: it is right when the two points are the same, when either is the+ * point at infinity, and when they are each other's negation, which is what+ * point_add_mixed cannot say. It costs 11 multiplications and two by b,+ * against point_add_mixed's 8 multiplications and 3 squarings.+ *+ * The table this comb reads is affine, and an affine point has Z = 1, so+ * Z = Z^2 = Z^3 and the same three numbers are the point in projective+ * coordinates and in Jacobian ones. That is what lets a comb built on+ * Jacobian arithmetic step into this formula for one addition and back out.+ */+static void point_add_complete_mixed(felem x3, felem y3, felem z3,+ const felem x1, const felem y1,+ const felem z1, const felem x2,+ const felem y2) {+ felem t0, t1, t2, t3, t4, xx, yy, zz;++ felem_mul(t0, x1, x2);+ felem_mul(t1, y1, y2);+ felem_sum(t3, x2, y2);+ felem_sum(t4, x1, y1);+ felem_mul(t3, t3, t4);+ felem_sum(t4, t0, t1);+ felem_diff(t3, t3, t4);+ felem_mul(t4, y2, z1);+ felem_sum(t4, t4, y1);+ felem_mul(yy, x2, z1);+ felem_sum(yy, yy, x1);+ felem_mul(zz, kB, z1);+ felem_diff(xx, yy, zz);+ felem_sum(zz, xx, xx);+ felem_sum(xx, xx, zz);+ felem_diff(zz, t1, xx);+ felem_sum(xx, t1, xx);+ felem_mul(yy, kB, yy);+ felem_sum(t1, z1, z1);+ felem_sum(t2, t1, z1);+ felem_diff(yy, yy, t2);+ felem_diff(yy, yy, t0);+ felem_sum(t1, yy, yy);+ felem_sum(yy, t1, yy);+ felem_sum(t1, t0, t0);+ felem_sum(t0, t1, t0);+ felem_diff(t0, t0, t2);+ felem_mul(t1, t4, yy);+ felem_mul(t2, t0, yy);+ felem_mul(yy, xx, zz);+ felem_sum(y3, yy, t2);+ felem_mul(xx, t3, xx);+ felem_diff(x3, xx, t1);+ felem_mul(zz, t4, zz);+ felem_mul(t1, t3, t0);+ felem_sum(z3, zz, t1);+}++/* point_add_complete sets {x3,y3,z3} = {x1,y1,z1} + {x2,y2,z2}, both in+ * projective coordinates.+ *+ * Renes-Costello-Batina algorithm 4, for a = -3, and complete for the same+ * reasons as the mixed one above. It costs 12 multiplications and two by b,+ * against point_add's 11 multiplications and 5 squarings.+ */+static void point_add_complete(felem x3, felem y3, felem z3, const felem x1,+ const felem y1, const felem z1, const felem x2,+ const felem y2, const felem z2) {+ felem t0, t1, t2, t3, t4, xx, yy, zz;++ felem_mul(t0, x1, x2);+ felem_mul(t1, y1, y2);+ felem_mul(t2, z1, z2);+ felem_sum(t3, x1, y1);+ felem_sum(t4, x2, y2);+ felem_mul(t3, t3, t4);+ felem_sum(t4, t0, t1);+ felem_diff(t3, t3, t4);+ felem_sum(t4, y1, z1);+ felem_sum(xx, y2, z2);+ felem_mul(t4, t4, xx);+ felem_sum(xx, t1, t2);+ felem_diff(t4, t4, xx);+ felem_sum(xx, x1, z1);+ felem_sum(yy, x2, z2);+ felem_mul(xx, xx, yy);+ felem_sum(yy, t0, t2);+ felem_diff(yy, xx, yy);+ felem_mul(zz, kB, t2);+ felem_diff(xx, yy, zz);+ felem_sum(zz, xx, xx);+ felem_sum(xx, xx, zz);+ felem_diff(zz, t1, xx);+ felem_sum(xx, t1, xx);+ felem_mul(yy, kB, yy);+ felem_sum(t1, t2, t2);+ felem_sum(t2, t1, t2);+ felem_diff(yy, yy, t2);+ felem_diff(yy, yy, t0);+ felem_sum(t1, yy, yy);+ felem_sum(yy, t1, yy);+ felem_sum(t1, t0, t0);+ felem_sum(t0, t1, t0);+ felem_diff(t0, t0, t2);+ felem_mul(t1, t4, yy);+ felem_mul(t2, t0, yy);+ felem_mul(yy, xx, zz);+ felem_sum(y3, yy, t2);+ felem_mul(xx, t3, xx);+ felem_diff(x3, xx, t1);+ felem_mul(zz, t4, zz);+ felem_mul(t1, t3, t0);+ felem_sum(z3, zz, t1);+}++/* jacobian_to_projective sets {x2,y2,z2} to the projective form of the+ * Jacobian point {x1,y1,z1}: (X/Z^2, Y/Z^3) is (XZ : Y : Z^3). */+static void jacobian_to_projective(felem x2, felem y2, felem z2,+ const felem x1, const felem y1,+ const felem z1) {+ felem zz, zzz;++ felem_square(zz, z1);+ felem_mul(zzz, zz, z1);+ felem_mul(x2, x1, z1);+ memcpy(y2, y1, sizeof(felem));+ memcpy(z2, zzz, sizeof(felem));+}++/* projective_to_jacobian is the other way: (X/Z) is (XZ : YZ^2 : Z). */+static void projective_to_jacobian(felem x2, felem y2, felem z2,+ const felem x1, const felem y1,+ const felem z1) {+ felem zz;++ felem_square(zz, z1);+ felem_mul(x2, x1, z1);+ felem_mul(y2, y1, zz);+ memcpy(z2, z1, sizeof(felem));+}+ /* scalar_base_mult sets {nx,ny,nz} = scalar*G where scalar is a little-endian * number. Note that the value of scalar must be less than the order of the * group. */ static void scalar_base_mult(felem nx, felem ny, felem nz, const crypton_p256_int* scalar) {- int i, j;- limb n_is_infinity_mask = -1, p_is_noninfinite_mask, mask;- u32 table_offset;+ u32 rec[COMB_WORDS];+ limb n_is_infinity_mask = -1, mask;+ felem px, py, negy, tx, ty, tz, jx, jy, jz, cx, cy, cz;+ int i, blk, j; - felem px, py;- felem tx, ty, tz;+ comb_recode(rec, scalar); memset(nx, 0, sizeof(felem)); memset(ny, 0, sizeof(felem)); memset(nz, 0, sizeof(felem)); - /* The loop adds bits at positions 0, 64, 128 and 192, followed by- * positions 32,96,160 and 224 and does this 32 times. */- for (i = 0; i < 32; i++) {- if (i) {+ for (i = COMB_STEPS - 1; i >= 0; i--) {+ if (i != COMB_STEPS - 1) { point_double(nx, ny, nz, nx, ny, nz); }- table_offset = 0;- for (j = 0; j <= 32; j += 32) {- char bit0 = crypton_p256_get_bit(scalar, 31 - i + j);- char bit1 = crypton_p256_get_bit(scalar, 95 - i + j);- char bit2 = crypton_p256_get_bit(scalar, 159 - i + j);- char bit3 = crypton_p256_get_bit(scalar, 223 - i + j);- limb index = bit0 | (bit1 << 1) | (bit2 << 2) | (bit3 << 3); - select_affine_point(px, py, kPrecomputed + table_offset, index);- table_offset += 30 * NLIMBS;+ for (blk = 0; blk < 2; blk++) {+ u32 base = (u32)(blk * COMB_STEPS + i);+ u32 top = COMB_BIT(rec, base + (COMB_TEETH - 1) * COMB_SPAN);+ limb index = 0; - /* Since scalar is less than the order of the group, we know that- * {nx,ny,nz} != {px,py,1}, unless both are zero, which we handle- * below. */- point_add_mixed(tx, ty, tz, nx, ny, nz, px, py);- /* The result of point_add_mixed is incorrect if {nx,ny,nz} is zero- * (a.k.a. the point at infinity). We handle that situation by- * copying the point from the table. */+ for (j = 0; j < COMB_TEETH - 1; j++) {+ /* a tooth agreeing with the top one is a set bit of the index */+ index |= (limb)(COMB_BIT(rec, base + (u32)j * COMB_SPAN) ^ top ^ 1)+ << j;+ }++ select_affine_point(px, py, kPrecomputed + blk * 16 * 2 * NLIMBS, index);+ felem_diff(negy, kZero, py);+ copy_conditional(py, negy, (limb)0 - (limb)(top ^ 1));++ /* The last addition is the one that can be a point added to itself:+ * entering it the accumulator is (k' - B)*G and what it adds is B*G,+ * where B is the second block's digit at step zero, so the two meet+ * when k' = 2B modulo the order. One scalar below the order does+ * that, and point_add_mixed cannot answer it.+ *+ * So that one addition goes through the complete formula instead.+ * The table is affine, so the point just selected is the same three+ * numbers read as projective coordinates as read as Jacobian ones --+ * which is what lets a comb built on Jacobian arithmetic step into+ * the formula for an addition and back out of it. The accumulator+ * is not affine and is converted.+ *+ * Measured on an M4, thread CPU time, the whole base point+ * multiplication is 17.34 us this way against 17.30 us with an extra+ * doubling and a mask, which is inside the spread of either. */+ if (i == 0 && blk == 1) {+ jacobian_to_projective(jx, jy, jz, nx, ny, nz);+ point_add_complete_mixed(cx, cy, cz, jx, jy, jz, px, py);+ projective_to_jacobian(tx, ty, tz, cx, cy, cz);+ } else {+ point_add_mixed(tx, ty, tz, nx, ny, nz, px, py);+ }++ /* The accumulator is the infinity until the first of these, and+ * point_add_mixed cannot start from it; the point itself is the sum. */ copy_conditional(nx, px, n_is_infinity_mask); copy_conditional(ny, py, n_is_infinity_mask); copy_conditional(nz, kOne, n_is_infinity_mask);-- /* Equally, the result is also wrong if the point from the table is- * zero, which happens when the index is zero. We handle that by- * only copying from {tx,ty,tz} to {nx,ny,nz} if index != 0. */- p_is_noninfinite_mask = NON_ZERO_TO_ALL_ONES(index);- mask = p_is_noninfinite_mask & ~n_is_infinity_mask;+ mask = ~n_is_infinity_mask; copy_conditional(nx, tx, mask); copy_conditional(ny, ty, mask); copy_conditional(nz, tz, mask);- /* If p was not zero, then n is now non-zero. */- n_is_infinity_mask &= ~p_is_noninfinite_mask;+ n_is_infinity_mask = 0; } }++ /* The recoded scalar is the private key in another representation, so it+ * does not stay on the stack. */+ crypton_bzero(rec, sizeof(rec)); } /* point_to_affine converts a Jacobian point to an affine point. If the input@@ -424,67 +672,309 @@ felem_mul(y_out, ny, z_inv); } -/* scalar_base_mult sets {nx,ny,nz} = scalar*{x,y}. */-static void scalar_mult(felem nx, felem ny, felem nz, const felem x,- const felem y, const crypton_p256_int* scalar) {- int i;- felem px, py, pz, tx, ty, tz;- felem precomp[16][3];- limb n_is_infinity_mask, index, p_is_noninfinite_mask, mask;+/* point_add_mixed_pm sets {xp,yp,zp} = {x1,y1,z1} + {x2,y2} and+ * {xm,ym,zm} = {x1,y1,z1} - {x2,y2}, where {x2,y2} is affine.+ *+ * Negating the second point changes the sign of s2 and so of r, and nothing+ * else: z1z1, tmp, u2, z1z1z1, h, i, j, v, the output z and the product y1*j+ * are common to the two. What the second point costs over the first is one+ * squaring (r*r) and one multiplication (by r), rather than another eleven.+ *+ * The same restrictions as point_add_mixed: this does not handle P+P,+ * infinity+P nor P+infinity. */+static void point_add_mixed_pm(felem xp, felem yp, felem zp,+ felem xm, felem ym, felem zm,+ const felem x1, const felem y1, const felem z1,+ const felem x2, const felem y2) {+ felem z1z1, z1z1z1, s2, u2, h, i, j, r, rr, v, y1j, tmp; - /* We precompute 0,1,2,... times {x,y}. */- memset(precomp, 0, sizeof(felem) * 3);- memcpy(&precomp[1][0], x, sizeof(felem));- memcpy(&precomp[1][1], y, sizeof(felem));- memcpy(&precomp[1][2], kOne, sizeof(felem));+ felem_square(z1z1, z1);+ felem_sum(tmp, z1, z1); - for (i = 2; i < 16; i += 2) {- point_double(precomp[i][0], precomp[i][1], precomp[i][2],- precomp[i / 2][0], precomp[i / 2][1], precomp[i / 2][2]);+ felem_mul(u2, x2, z1z1);+ felem_mul(z1z1z1, z1, z1z1);+ felem_mul(s2, y2, z1z1z1);+ felem_diff(h, u2, x1);+ felem_sum(i, h, h);+ felem_square(i, i);+ felem_mul(j, h, i);+ felem_mul(v, x1, i);+ felem_mul(y1j, y1, j); - point_add_mixed(precomp[i + 1][0], precomp[i + 1][1], precomp[i + 1][2],- precomp[i][0], precomp[i][1], precomp[i][2], x, y);+ /* The two points share their z. */+ felem_mul(zp, tmp, h);+ felem_assign(zm, zp);++ /* X + P */+ felem_diff(r, s2, y1);+ felem_sum(r, r, r);+ felem_square(rr, r);+ felem_diff(xp, rr, j);+ felem_diff(xp, xp, v);+ felem_diff(xp, xp, v);+ felem_diff(tmp, v, xp);+ felem_mul(yp, tmp, r);+ felem_diff(yp, yp, y1j);+ felem_diff(yp, yp, y1j);++ /* X - P. Negating the point negates s2, so r becomes -q where+ * q = 2*(s2 + y1). The square is the same either way, and the sign is+ * carried into y by taking (xm - v) where the other took (v - xp):+ * xm = q^2 - j - 2v+ * ym = (v - xm)*(-q) - 2*y1*j = (xm - v)*q - 2*y1*j+ * so no field negation is needed. */+ felem_sum(r, s2, y1);+ felem_sum(r, r, r);+ felem_square(rr, r);+ felem_diff(xm, rr, j);+ felem_diff(xm, xm, v);+ felem_diff(xm, xm, v);+ felem_diff(tmp, xm, v);+ felem_mul(ym, tmp, r);+ felem_diff(ym, ym, y1j);+ felem_diff(ym, ym, y1j);+}++/* select_jacobian_odd sets {out_x,out_y,out_z} to the index'th of the 16+ * entries of table, for index < 16. There is no implicit infinity at index+ * zero, as the unsigned window this replaces had: every entry is a real+ * point, which is what lets the signed representation below do without the+ * infinity masks. */+static void select_jacobian_odd(felem out_x, felem out_y, felem out_z,+ const limb* table, limb index) {+ limb i, j;++ memset(out_x, 0, sizeof(felem));+ memset(out_y, 0, sizeof(felem));+ memset(out_z, 0, sizeof(felem));++ for (i = 0; i < 16; i++) {+ limb mask = i ^ index;+ mask |= mask >> 2;+ mask |= mask >> 1;+ mask &= 1;+ mask--;+ for (j = 0; j < NLIMBS; j++, table++) {+ out_x[j] |= *table & mask;+ }+ for (j = 0; j < NLIMBS; j++, table++) {+ out_y[j] |= *table & mask;+ }+ for (j = 0; j < NLIMBS; j++, table++) {+ out_z[j] |= *table & mask;+ } }+} - memset(nx, 0, sizeof(felem));- memset(ny, 0, sizeof(felem));- memset(nz, 0, sizeof(felem));- n_is_infinity_mask = -1;+/* The scalar, recoded: 52 signed odd digits, each in {+-1,+-3,...,+-31}, so+ * that scalar = sum d_i * 32^i. A digit is one byte: the low four bits are+ * the table index (|d|-1)/2, and bit four is set when d is negative. One+ * byte rather than a byte and a word because this is the private key in+ * another form and has to be wiped afterwards. */+#define SABS_DIGITS 52+#define SABS_INDEX(b) ((limb)((b) & 15))+#define SABS_NEGMASK(b) ((limb)0 - (limb)((b) >> 4))+typedef struct {+ u8 digit[SABS_DIGITS];+} sabs_scalar; - /* We add in a window of four bits each iteration and do this 64 times. */- for (i = 0; i < 256; i += 4) {- if (i) {- point_double(nx, ny, nz, nx, ny, nz);- point_double(nx, ny, nz, nx, ny, nz);- point_double(nx, ny, nz, nx, ny, nz);- point_double(nx, ny, nz, nx, ny, nz);++/* sabs_recode writes the signed representation of |scalar| into |out|.+ *+ * The recoding is the regular one of Joye and Tunstall: take the low six bits,+ * subtract 32, and carry the difference upwards. It needs an odd input, which+ * is arranged by adding the group order to an even scalar -- that changes the+ * scalar but not the point it selects, the order being the order. A zero+ * scalar is replaced by one and the caller is told, since zero times a point+ * is the infinity this code deliberately cannot represent.+ *+ * Constant time in the scalar: every branch below is on a loop counter. */+static limb sabs_recode(sabs_scalar* out,+ const crypton_p256_int* scalar) {+ u32 k[9], n[9];+ u32 nonzero;+ limb is_zero_mask;+ int i, b;++ for (i = 0; i < 9; i++) {+ k[i] = 0;+ n[i] = 0;+ }+ /* A word at a time. Bit at a time would be 512 calls into another+ * translation unit, which the compiler cannot inline away. */+ for (b = 0; b < 256; b += 32) {+ k[b >> 5] = (u32)(P256_DIGIT(scalar, b / P256_BITSPERDIGIT)+ >> (b % P256_BITSPERDIGIT));+ n[b >> 5] = (u32)(P256_DIGIT(&crypton_SECP256r1_n, b / P256_BITSPERDIGIT)+ >> (b % P256_BITSPERDIGIT));+ }++ /* Replace a zero scalar by one, and report it. */+ nonzero = 0;+ for (i = 0; i < 9; i++) {+ nonzero |= k[i];+ }+ {+ u32 z = words_are_zero(nonzero);+ k[0] |= z;+ is_zero_mask = (limb)0 - (limb)z;+ }++ /* An even scalar becomes odd by adding the order. The sum is below 2^257,+ * which is why nine words and fifty-two digits are enough. */+ {+ u32 addmask = (u32)0 - (u32)((k[0] & 1) ^ 1);+ u64 carry = 0;+ for (i = 0; i < 9; i++) {+ u64 t = (u64)k[i] + (u64)(n[i] & addmask) + carry;+ k[i] = (u32)t;+ carry = t >> 32; }+ } - index = (crypton_p256_get_bit(scalar, 255 - i - 0) << 3) |- (crypton_p256_get_bit(scalar, 255 - i - 1) << 2) |- (crypton_p256_get_bit(scalar, 255 - i - 2) << 1) |- crypton_p256_get_bit(scalar, 255 - i - 3);+ for (i = 0; i < SABS_DIGITS - 1; i++) {+ u32 r6 = k[0] & 63; /* odd, so never 32 */+ u32 hi = (r6 >> 5) & 1; /* 1 when the digit is positive */+ u32 wabs = ((r6 - 32) & (0u - hi)) | ((32 - r6) & (hi - 1));+ u32 mlo = 32u - r6; /* two's complement of the digit's negation */+ u32 ext = 0u - hi; /* its sign extension */+ u64 carry = 0;+ int w; - /* See the comments in scalar_base_mult about handling infinities. */- select_jacobian_point(px, py, pz, precomp[0][0], index);- point_add(tx, ty, tz, nx, ny, nz, px, py, pz);- copy_conditional(nx, px, n_is_infinity_mask);- copy_conditional(ny, py, n_is_infinity_mask);- copy_conditional(nz, pz, n_is_infinity_mask);+ out->digit[i] = (u8)(((wabs - 1) >> 1) | ((hi ^ 1) << 4)); - p_is_noninfinite_mask = NON_ZERO_TO_ALL_ONES(index);- mask = p_is_noninfinite_mask & ~n_is_infinity_mask;+ /* k -= digit, i.e. k += -digit, sign extended over the nine words. */+ for (w = 0; w < 9; w++) {+ u64 t = (u64)k[w] + (u64)(w == 0 ? mlo : ext) + carry;+ k[w] = (u32)t;+ carry = t >> 32;+ }+ /* k >>= 5 */+ for (w = 0; w < 8; w++) {+ k[w] = (k[w] >> 5) | (k[w + 1] << 27);+ }+ k[8] >>= 5;+ } - copy_conditional(nx, tx, mask);- copy_conditional(ny, ty, mask);- copy_conditional(nz, tz, mask);- n_is_infinity_mask &= ~p_is_noninfinite_mask;+ /* What is left is odd, positive and at most five: the scalar is below+ * 2^257 and fifty-one digits have taken 255 bits off it, each leaving a+ * remainder below one. */+ out->digit[SABS_DIGITS - 1] = (u8)((k[0] - 1) >> 1);++ return is_zero_mask;+}++/* scalar_mult sets {nx,ny,nz} = scalar*{x,y}.+ *+ * A five-bit signed window. The scalar is recoded into 52 digits, every one+ * of them odd and none of them zero, so the table holds only the odd+ * multiples P, 3P, ..., 31P and a negative digit is served by negating y,+ * which is free. Against the four-bit unsigned window this replaces, the+ * main loop trades 252 doublings and 64 additions for 255 and 51, and --+ * because no digit is zero and no partial sum is the infinity -- it drops the+ * masks that stood in for infinity on every iteration.+ *+ * The table is built so that each pair of neighbouring odd multiples comes+ * out of one doubling and one shared addition:+ *+ * 2P = 2*P 3P = 2P + P+ * 6P = 2*(3P) 5P = 6P - P, 7P = 6P + P+ * 10P = 2*(5P) 9P = 10P - P, 11P = 10P + P+ * ...+ * 30P = 2*(15P) 29P = 30P - P, 31P = 30P + P+ *+ * which is eight doublings, one mixed addition and seven shared pairs. */+static void scalar_mult(felem nx, felem ny, felem nz, const felem x,+ const felem y, const crypton_p256_int* scalar) {+ /* odd[k] is (2k+1)*P, for k in 0..15. */+ felem odd[16][3];+ felem dx, dy, dz, px, py, pz, negy, ddx, ddy, ddz, qx, qy, qz, cx, cy, cz;+ sabs_scalar rec;+ limb is_zero_mask;+ int i, k;++ is_zero_mask = sabs_recode(&rec, scalar);++ felem_assign(odd[0][0], x);+ felem_assign(odd[0][1], y);+ memcpy(odd[0][2], kOne, sizeof(felem));++ /* 3P = 2P + P */+ point_double(dx, dy, dz, x, y, kOne);+ point_add_mixed(odd[1][0], odd[1][1], odd[1][2], dx, dy, dz, x, y);++ /* (4k+2)P from (2k+1)P, then (4k+1)P and (4k+3)P from it. */+ for (k = 1; k < 8; k++) {+ point_double(dx, dy, dz, odd[k][0], odd[k][1], odd[k][2]);+ point_add_mixed_pm(odd[2 * k + 1][0], odd[2 * k + 1][1], odd[2 * k + 1][2],+ odd[2 * k][0], odd[2 * k][1], odd[2 * k][2],+ dx, dy, dz, x, y); }++ /* The top digit initialises the accumulator; it is always positive. */+ select_jacobian_odd(nx, ny, nz, odd[0][0],+ SABS_INDEX(rec.digit[SABS_DIGITS - 1]));++ for (i = SABS_DIGITS - 2; i >= 0; i--) {+ point_double(nx, ny, nz, nx, ny, nz);+ point_double(nx, ny, nz, nx, ny, nz);+ point_double(nx, ny, nz, nx, ny, nz);+ point_double(nx, ny, nz, nx, ny, nz);+ point_double(nx, ny, nz, nx, ny, nz);++ select_jacobian_odd(px, py, pz, odd[0][0], SABS_INDEX(rec.digit[i]));+ felem_diff(negy, kZero, py);+ copy_conditional(py, negy, SABS_NEGMASK(rec.digit[i]));++ /* On the last step alone the accumulator can be the very point being+ * added -- the accumulator is (k' - d0)*P and it adds d0*P, so the two+ * meet when k' = 2*d0 modulo the order, which the scalar 30 does with a+ * digit of 15 -- and point_add answers the infinity where the truth is+ * twice that point. That one addition goes through the complete formula+ * instead, with both points converted to projective coordinates and the+ * answer converted back. One of fifty-one iterations pays for it, and+ * it comes to a field multiplication less than the doubling and the mask+ * it replaces.+ *+ * point_add finishes with z before it touches x, and with each of x and+ * y before the next, so on every other step the accumulator can be its+ * own output. */+ if (i == 0) {+ jacobian_to_projective(ddx, ddy, ddz, nx, ny, nz);+ jacobian_to_projective(qx, qy, qz, px, py, pz);+ point_add_complete(cx, cy, cz, ddx, ddy, ddz, qx, qy, qz);+ projective_to_jacobian(nx, ny, nz, cx, cy, cz);+ } else {+ point_add(nx, ny, nz, nx, ny, nz, px, py, pz);+ }+ }++ /* Zero was replaced by one on the way in; put the infinity back. All+ * three coordinates, not just z: crypton_p256_points_mul_vartime reads the+ * comment above it as saying the whole point is zero. */+ for (i = 0; i < NLIMBS; i++) {+ nx[i] &= ~is_zero_mask;+ ny[i] &= ~is_zero_mask;+ nz[i] &= ~is_zero_mask;+ }++ /* The recoded scalar is the private key in another representation, so it+ * does not stay on the stack. */+ crypton_bzero(&rec, sizeof(rec)); } /* crypton_p256_base_point_mul sets {out_x,out_y} = nG, where n is < the * order of the group. */ void crypton_p256_base_point_mul(const crypton_p256_int* n, crypton_p256_int* out_x, crypton_p256_int* out_y) {+#ifdef CRYPTON_S2N_BIGNUM+ /* The assembly, four times faster, and constant time as this has to be:+ * it is how a public key is derived from a private one. */+ uint64_t res[8];++ crypton_s2n_p256_scalarmulbase(res, P256_DIGITS(n));+ memcpy(P256_DIGITS(out_x), res, P256_NBYTES);+ memcpy(P256_DIGITS(out_y), res + P256_NDIGITS, P256_NBYTES);+#else felem x, y, z; scalar_base_mult(x, y, z, n);@@ -496,8 +986,29 @@ from_montgomery(out_x, x_affine); from_montgomery(out_y, y_affine); }+#endif } +#ifdef CRYPTON_S2N_BIGNUM+/* An affine point from the assembly as the Jacobian triple the addition+ * below wants, keeping this file's convention that the point at infinity is+ * all three coordinates zero -- the assembly says it with (0, 0). */+static void s2n_lift(felem x, felem y, felem z, const uint64_t res[8]) {+ crypton_p256_int t;+ uint64_t any = 0;+ int i;++ for (i = 0; i < 2 * P256_NDIGITS; i++)+ any |= res[i];++ memcpy(P256_DIGITS(&t), res, P256_NBYTES);+ to_montgomery(x, &t);+ memcpy(P256_DIGITS(&t), res + P256_NDIGITS, P256_NBYTES);+ to_montgomery(y, &t);+ memcpy(z, any != 0 ? kOne : kZero, sizeof(felem));+}+#endif+ /* crypton_p256_points_mul_vartime sets {out_x,out_y} = n1*G + n2*{in_x,in_y}, where * n1 and n2 are < the order of the group. *@@ -516,10 +1027,48 @@ return; } +#ifdef CRYPTON_S2N_BIGNUM+ {+ /* Both scalars at once, in variable time, which is what the two+ * multiplications below are not: they are constant time, and pay for it,+ * over values that are all public here. It gives up on the one case the+ * assembly's addition does not cover -- adding a point to itself -- and+ * then the constant-time pair answers instead. */+ uint64_t jr[3 * P256_NDIGITS];++ if (crypton_p256_verify_mul(jr, P256_DIGITS(n1), P256_DIGITS(n2),+ P256_DIGITS(in_x), P256_DIGITS(in_y))) {+ crypton_p256_int t;++ memcpy(P256_DIGITS(&t), jr, P256_NBYTES);+ to_montgomery(x1, &t);+ memcpy(P256_DIGITS(&t), jr + P256_NDIGITS, P256_NBYTES);+ to_montgomery(y1, &t);+ memcpy(P256_DIGITS(&t), jr + 2 * P256_NDIGITS, P256_NBYTES);+ to_montgomery(z1, &t);++ point_to_affine(px, py, x1, y1, z1);+ from_montgomery(out_x, px);+ from_montgomery(out_y, py);+ return;+ }+ }+ {+ uint64_t r1[8], r2[8], pt[2 * P256_NDIGITS];++ memcpy(pt, P256_DIGITS(in_x), P256_NBYTES);+ memcpy(pt + P256_NDIGITS, P256_DIGITS(in_y), P256_NBYTES);+ crypton_s2n_p256_scalarmulbase(r1, P256_DIGITS(n1));+ crypton_s2n_p256_scalarmul(r2, P256_DIGITS(n2), pt);+ s2n_lift(x1, y1, z1, r1);+ s2n_lift(x2, y2, z2, r2);+ }+#else to_montgomery(px, in_x); to_montgomery(py, in_y); scalar_base_mult(x1, y1, z1, n1); scalar_mult(x2, y2, z2, px, py, n2);+#endif if (crypton_p256_is_zero(n2) != 0) { /* If n2 == 0, then {x2,y2,z2} is zero and the result is just@@ -581,6 +1130,19 @@ void crypton_p256e_point_mul(const crypton_p256_int* n, const crypton_p256_int* in_x, const crypton_p256_int* in_y, crypton_p256_int* out_x, crypton_p256_int* out_y) {+#ifdef CRYPTON_S2N_BIGNUM+ /* The vendored assembly, which answers the same thing two and a half to+ * three times faster. Both sides are four little-endian 64-bit words of+ * an ordinary affine coordinate, so the points cross as they are, and+ * both give (0, 0) for the point at infinity. See cbits/s2n/README.md. */+ uint64_t point[8], res[8];++ memcpy(point, P256_DIGITS(in_x), P256_NBYTES);+ memcpy(point + P256_NDIGITS, P256_DIGITS(in_y), P256_NBYTES);+ crypton_s2n_p256_scalarmul(res, P256_DIGITS(n), point);+ memcpy(P256_DIGITS(out_x), res, P256_NBYTES);+ memcpy(P256_DIGITS(out_y), res + P256_NDIGITS, P256_NBYTES);+#else felem x, y, z, px, py; to_montgomery(px, in_x);@@ -589,4 +1151,5 @@ point_to_affine(px, py, x, y, z); from_montgomery(out_x, px); from_montgomery(out_y, py);+#endif }
+ cbits/p256/p256_s2n.c view
@@ -0,0 +1,61 @@+/*+ * Choosing between s2n-bignum's two forms of each routine. The reasoning+ * is in cbits/s2n/README.md; in short, on ARM the choice is a+ * microarchitecture one that no feature bit answers, and on x86-64 it is+ * exactly a feature bit.+ */+#include "p256/p256_s2n.h"+#include "crypton_cpu.h"++extern void p256_scalarmul(uint64_t res[8], const uint64_t scalar[4],+ const uint64_t point[8]);+extern void p256_scalarmul_alt(uint64_t res[8], const uint64_t scalar[4],+ const uint64_t point[8]);+extern void p256_scalarmulbase(uint64_t res[8], const uint64_t scalar[4],+ uint64_t blocksize, const uint64_t *table);+extern void p256_scalarmulbase_alt(uint64_t res[8], const uint64_t scalar[4],+ uint64_t blocksize, const uint64_t *table);++extern const uint64_t crypton_p256_s2n_base_blocksize;+extern const uint64_t crypton_p256_s2n_base_table[];++void crypton_s2n_p256_scalarmul(uint64_t res[8], const uint64_t scalar[4],+ const uint64_t point[8])+{+#if defined(__aarch64__) || defined(__arm64__)+#ifdef __APPLE__+ /* the _alt form is the one written for high multiplier throughput,+ * and it is 30-40% faster on Apple silicon */+ p256_scalarmul_alt(res, scalar, point);+#else+ p256_scalarmul(res, scalar, point);+#endif+#else+ if (crypton_x86_simd_features() & CRYPTON_X86_ADX)+ p256_scalarmul(res, scalar, point);+ else+ p256_scalarmul_alt(res, scalar, point);+#endif+}++void crypton_s2n_p256_scalarmulbase(uint64_t res[8], const uint64_t scalar[4])+{+#if defined(__aarch64__) || defined(__arm64__)+#ifdef __APPLE__+ p256_scalarmulbase_alt(res, scalar, crypton_p256_s2n_base_blocksize,+ crypton_p256_s2n_base_table);+#else+ p256_scalarmulbase(res, scalar, crypton_p256_s2n_base_blocksize,+ crypton_p256_s2n_base_table);+#endif+#else+ if (crypton_x86_simd_features() & CRYPTON_X86_ADX)+ p256_scalarmulbase(res, scalar,+ crypton_p256_s2n_base_blocksize,+ crypton_p256_s2n_base_table);+ else+ p256_scalarmulbase_alt(res, scalar,+ crypton_p256_s2n_base_blocksize,+ crypton_p256_s2n_base_table);+#endif+}
+ cbits/p256/p256_verify.c view
@@ -0,0 +1,300 @@+/*+ * The double scalar multiplication ECDSA verification does, in variable+ * time.+ *+ * Verification asks for u1*G + u2*Q, and crypton used to work that out as+ * two separate constant-time multiplications and an addition. Nothing here+ * is secret -- the message, the signature and the public key are all sent in+ * the clear -- so the constant-time work is paid for nothing, and the two+ * multiplications can share their doublings besides. Measured, those two+ * were 84% of a verification.+ *+ * So this is the usual interleaved windowed form: both scalars in+ * width-5 non-adjacent form, a table of odd multiples of each point, and one+ * pass down the digits with a doubling at every step and an addition where a+ * digit is not zero. It is s2n-bignum's Jacobian point arithmetic+ * underneath, the same assembly the constant-time paths use.+ *+ * s2n-bignum's p256_montjadd is correct except when its two arguments are+ * the same point -- that is the side condition its proof carries -- so every+ * sum is checked for the sign of that, which is a zero z where neither+ * argument had one. There the answer is given up on and the caller falls+ * back to the constant-time pair, which has no such condition. With random+ * inputs it does not happen; it is here because an attacker chooses the+ * public key and the signature.+ */+#include <string.h>++#include "p256/p256.h"++#ifdef CRYPTON_S2N_BIGNUM++#include "crypton_cpu.h"+#include "p256/p256_verify.h"++/* a Jacobian triple in the Montgomery domain, as the assembly keeps them */+#define JAC 12+#define AFF 8++extern void p256_montjadd(uint64_t p3[JAC], const uint64_t p1[JAC],+ const uint64_t p2[JAC]);+extern void p256_montjadd_alt(uint64_t p3[JAC], const uint64_t p1[JAC],+ const uint64_t p2[JAC]);+extern void p256_montjdouble(uint64_t p3[JAC], const uint64_t p1[JAC]);+extern void p256_montjdouble_alt(uint64_t p3[JAC], const uint64_t p1[JAC]);+extern void p256_montjmixadd(uint64_t p3[JAC], const uint64_t p1[JAC],+ const uint64_t p2[AFF]);+extern void p256_montjmixadd_alt(uint64_t p3[JAC], const uint64_t p1[JAC],+ const uint64_t p2[AFF]);++/* the odd multiples of the base point, from cbits/p256/gen_base_table.py */+extern const uint64_t crypton_p256_wnaf_width;+extern const uint64_t crypton_p256_wnaf_table[];+extern void bignum_tomont_p256(uint64_t z[4], const uint64_t x[4]);+extern void bignum_demont_p256(uint64_t z[4], const uint64_t x[4]);+extern void bignum_neg_p256(uint64_t z[4], const uint64_t x[4]);+#if !defined(__aarch64__) && !defined(__arm64__)+extern void bignum_tomont_p256_alt(uint64_t z[4], const uint64_t x[4]);+extern void bignum_demont_p256_alt(uint64_t z[4], const uint64_t x[4]);+#endif++/* The same question as everywhere else in cbits/s2n: a microarchitecture one+ * on ARM that no feature bit answers, and exactly a feature bit on x86-64. */+static int use_alt(void)+{+#if defined(__aarch64__) || defined(__arm64__)+#ifdef __APPLE__+ return 1;+#else+ return 0;+#endif+#else+ return (crypton_x86_simd_features() & CRYPTON_X86_ADX) == 0;+#endif+}++static void padd(uint64_t r[JAC], const uint64_t a[JAC], const uint64_t b[JAC],+ int alt)+{+ if (alt)+ p256_montjadd_alt(r, a, b);+ else+ p256_montjadd(r, a, b);+}++static void pmixadd(uint64_t r[JAC], const uint64_t a[JAC],+ const uint64_t b[AFF], int alt)+{+ if (alt)+ p256_montjmixadd_alt(r, a, b);+ else+ p256_montjmixadd(r, a, b);+}++static void pdouble(uint64_t r[JAC], const uint64_t a[JAC], int alt)+{+ if (alt)+ p256_montjdouble_alt(r, a);+ else+ p256_montjdouble(r, a);+}++static void tomont(uint64_t z[4], const uint64_t x[4])+{+#if defined(__aarch64__) || defined(__arm64__)+ bignum_tomont_p256(z, x);+#else+ if (use_alt())+ bignum_tomont_p256_alt(z, x);+ else+ bignum_tomont_p256(z, x);+#endif+}++static void demont(uint64_t z[4], const uint64_t x[4])+{+#if defined(__aarch64__) || defined(__arm64__)+ bignum_demont_p256(z, x);+#else+ if (use_alt())+ bignum_demont_p256_alt(z, x);+ else+ bignum_demont_p256(z, x);+#endif+}++static int is_infinity(const uint64_t p[JAC])+{+ return (p[8] | p[9] | p[10] | p[11]) == 0;+}++/*+ * The base point's table is a constant, so its window is as wide as the+ * table is worth carrying: seven bits, thirty-two odd multiples, two+ * kilobytes, and one addition every eight digits. The public key's table+ * has to be built for each verification, so five bits is the trade there --+ * eight entries, seven point operations to build, and one addition every+ * six digits.+ */+#define WG 7+#define TG (1 << (WG - 2))+#define WQ 5+#define TQ (1 << (WQ - 2))+#define NAF_MAX 258++/*+ * The width-W non-adjacent form of a scalar, one signed digit per bit+ * position: odd or zero, and never two non-zero digits within W of each+ * other. Returns how many digits were written.+ *+ * The scalar is public, so the loop may look at it.+ */+static int wnaf(int8_t out[NAF_MAX], const uint64_t in[4], int w)+{+ uint64_t k[5];+ int len = 0;++ memcpy(k, in, 32);+ k[4] = 0;++ while (k[0] | k[1] | k[2] | k[3] | k[4]) {+ int d = 0;++ if (k[0] & 1) {+ d = (int) (k[0] & ((1u << w) - 1));+ if (d >= (1 << (w - 1)))+ d -= 1 << w;+ if (d > 0) {+ uint64_t borrow = (uint64_t) d;+ int i;++ for (i = 0; i < 5 && borrow; i++) {+ uint64_t t = k[i];++ k[i] = t - borrow;+ borrow = (k[i] > t);+ }+ } else {+ uint64_t carry = (uint64_t) (-d);+ int i;++ for (i = 0; i < 5 && carry; i++) {+ k[i] += carry;+ carry = (k[i] < carry);+ }+ }+ }+ out[len++] = (int8_t) d;++ { /* k >>= 1 */+ int i;++ for (i = 0; i < 4; i++)+ k[i] = (k[i] >> 1) | (k[i + 1] << 63);+ k[4] >>= 1;+ }+ }+ return len;+}++/* P, 3P, 5P, ..., (2*TQ-1)P from a Jacobian P */+static int build_table(uint64_t t[TQ][JAC], const uint64_t p[JAC], int alt)+{+ uint64_t twice[JAC];+ int i;++ memcpy(t[0], p, sizeof(uint64_t) * JAC);+ pdouble(twice, p, alt);+ for (i = 1; i < TQ; i++) {+ padd(t[i], t[i - 1], twice, alt);+ /* the table is built from a point and its double, which are+ * never the same point unless the point has order two, and+ * P-256 has none */+ if (is_infinity(t[i]) && !is_infinity(t[i - 1])+ && !is_infinity(twice))+ return 0;+ }+ return 1;+}++/* the table entry for a digit, negated when the digit is */+static void pick(uint64_t out[JAC], const uint64_t t[TQ][JAC], int digit)+{+ int idx = (digit > 0 ? digit : -digit) / 2;++ memcpy(out, t[idx], sizeof(uint64_t) * JAC);+ if (digit < 0)+ bignum_neg_p256(out + 4, out + 4);+}++/* the same from the base point's affine table */+static void pick_affine(uint64_t out[AFF], int digit)+{+ int idx = (digit > 0 ? digit : -digit) / 2;++ memcpy(out, crypton_p256_wnaf_table + (size_t) idx * AFF,+ sizeof(uint64_t) * AFF);+ if (digit < 0)+ bignum_neg_p256(out + 4, out + 4);+}++int crypton_p256_verify_mul(uint64_t out[JAC], const uint64_t n1[4],+ const uint64_t n2[4], const uint64_t qx[4],+ const uint64_t qy[4])+{+ /* the Montgomery form of one, which is the z of an affine point */+ static const uint64_t mont_one[4] = {+ 0x0000000000000001ULL, 0xffffffff00000000ULL,+ 0xffffffffffffffffULL, 0x00000000fffffffeULL+ };+ uint64_t tq[TQ][JAC];+ uint64_t q[JAC], acc[JAC], addend[JAC], aff[AFF], sum[JAC];+ int8_t naf1[NAF_MAX], naf2[NAF_MAX];+ int len1, len2, len, i;+ /* asked once rather than at every point operation */+ const int alt = use_alt();++ /* the generated table has to be the width this file walks it at */+ if (crypton_p256_wnaf_width != WG)+ return 0;++ tomont(q, qx);+ tomont(q + 4, qy);+ memcpy(q + 8, mont_one, sizeof mont_one);++ if (!build_table(tq, q, alt))+ return 0;++ len1 = wnaf(naf1, n1, WG);+ len2 = wnaf(naf2, n2, WQ);+ len = len1 > len2 ? len1 : len2;++ memset(acc, 0, sizeof acc);+ for (i = len - 1; i >= 0; i--) {+ pdouble(acc, acc, alt);++ if (i < len1 && naf1[i] != 0) {+ /* the base point's entries are affine, which is a+ * cheaper addition and no table to build */+ pick_affine(aff, naf1[i]);+ pmixadd(sum, acc, aff, alt);+ if (is_infinity(sum) && !is_infinity(acc))+ return 0;+ memcpy(acc, sum, sizeof acc);+ }+ if (i < len2 && naf2[i] != 0) {+ pick(addend, tq, naf2[i]);+ padd(sum, acc, addend, alt);+ if (is_infinity(sum) && !is_infinity(acc))+ return 0;+ memcpy(acc, sum, sizeof acc);+ }+ }++ demont(out, acc);+ demont(out + 4, acc + 4);+ demont(out + 8, acc + 8);+ return 1;+}++#endif
+ cbits/p256/p256_verify.h view
@@ -0,0 +1,19 @@+#ifndef CRYPTON_P256_VERIFY_H+#define CRYPTON_P256_VERIFY_H++#include <stdint.h>++/*+ * n1*G + n2*Q, in variable time, as a Jacobian triple in the plain domain.+ *+ * Returns 1 when the answer is in `out`, and 0 when the walk met the one+ * case s2n-bignum's point addition does not cover -- adding a point to+ * itself -- in which case the caller works the answer out the constant-time+ * way instead. Nothing here is secret: it is all in the signature and the+ * public key.+ */+int crypton_p256_verify_mul(uint64_t out[12], const uint64_t n1[4],+ const uint64_t n2[4], const uint64_t qx[4],+ const uint64_t qy[4]);++#endif
+ cbits/p256/p256_wnaf_table.c view
@@ -0,0 +1,42 @@+/* Generated by cbits/p256/gen_base_table.py; do not hand-edit.+ * The odd multiples of the base point, in Montgomery-affine+ * form, which cbits/p256/p256_verify.c reads. A verification+ * is public, so this table is walked in variable time. */+#include <stdint.h>++const uint64_t crypton_p256_wnaf_width = 7;++const uint64_t crypton_p256_wnaf_table[256] = {+ 0x79e730d418a9143cULL,0x75ba95fc5fedb601ULL,0x79fb732b77622510ULL,0x18905f76a53755c6ULL,0xddf25357ce95560aULL,0x8b4ab8e4ba19e45cULL,0xd2e88688dd21f325ULL,0x8571ff1825885d85ULL,+ 0xffac3f904eebc127ULL,0xb027f84a087d81fbULL,0x66ad77dd87cbbc98ULL,0x26936a3fb6ff747eULL,0xb04c5c1fc983a7ebULL,0x583e47ad0861fe1aULL,0x788208311a2ee98eULL,0xd5f06a29e587cc07ULL,+ 0xbe1b8aaec45c61f5ULL,0x90ec649a94b9537dULL,0x941cb5aad076c20cULL,0xc9079605890523c8ULL,0xeb309b4ae7ba4f10ULL,0x73c568efe5eb882bULL,0x3540a9877e7a1f68ULL,0x73a076bb2dd1e916ULL,+ 0x0746354ea0173b4fULL,0x2bd20213d23c00f7ULL,0xf43eaab50c23bb08ULL,0x13ba5119c3123e03ULL,0x2847d0303f5b9d4dULL,0x6742f2f25da67bddULL,0xef933bdc77c94195ULL,0xeaedd9156e240867ULL,+ 0x75c96e8f264e20e8ULL,0xabe6bfed59a7a841ULL,0x2cc09c0444c8eb00ULL,0xe05b3080f0c4e16bULL,0x1eb7777aa45f3314ULL,0x56af7bedce5d45e3ULL,0x2b6e019a88b12f1aULL,0x086659cdfd835f9bULL,+ 0xea7d260a6245e404ULL,0x9de407956e7fdfe0ULL,0x1ff3a4158dac1ab5ULL,0x3e7090f1649c9073ULL,0x1a7685612b944e88ULL,0x250f939ee57f61c8ULL,0x0c0daa891ead643dULL,0x68930023e125b88eULL,+ 0xccc425634b2ed709ULL,0x0e356769856fd30dULL,0xbcbcd43f559e9811ULL,0x738477ac5395b759ULL,0x35752b90c00ee17fULL,0x68748390742ed2e3ULL,0x7cd06422bd1f5bc1ULL,0xfbc08769c9e7b797ULL,+ 0x72bcd8b7bc60055bULL,0x03cc23ee56e27e4bULL,0xee337424e4819370ULL,0xe2aa0e430ad3da09ULL,0x40b8524f6383c45dULL,0xd766355442a41b25ULL,0x64efa6de778a4797ULL,0x2042170a7079adf4ULL,+ 0x97091dcbd53c5c9dULL,0xf17624b6ac0a177bULL,0xb0f139752cfe2dffULL,0xc1a35c0a6c7a574eULL,0x227d314693e79987ULL,0x0575bf30e89cb80eULL,0x2f4e247f0d1883bbULL,0xebd512263274c3d0ULL,+ 0xfea912baa5659ae8ULL,0x68363aba25e1a16eULL,0xb8842277752c41acULL,0xfe545c282897c3fcULL,0x2d36e9e7dc4c696bULL,0x5806244afba977c5ULL,0x85665e9be39508c1ULL,0xf720ee256d12597bULL,+ 0x562e4cecc135b208ULL,0x74e1b2654783f47dULL,0x6d2a506c5a3f3b30ULL,0xecead9f4c16762fcULL,0xf29dd4b2e286e5b9ULL,0x1b0fadc083bb3c61ULL,0x7a75023e7fac29a4ULL,0xc086d5f1c9477fa3ULL,+ 0xf4f876532de45068ULL,0x37c7a7e89e2e1f6eULL,0xd0825fa2a3584069ULL,0xaf2cea7c1727bf42ULL,0x0360a4fb9e4785a9ULL,0xe5fda49c27299f4aULL,0x48068e1371ac2f71ULL,0x83d0687b9077666fULL,+ 0xa4a319acd837879fULL,0x6fc1b49eed6b67b0ULL,0xe395993332f1f3afULL,0x966742eb65432a2eULL,0x4b8dc9feb4966228ULL,0x96cc631243f43950ULL,0x12068859c9b731eeULL,0x7b948dc356f79968ULL,+ 0x042c2af497e2feb4ULL,0xd36a42d7aebf7313ULL,0x49d2c9eb084ffdd7ULL,0x9f8aa54b2ef7c76aULL,0x9200b7ba09895e70ULL,0x3bd0c66fddb7fb58ULL,0x2d97d10878eb4cbbULL,0x2d431068d84bde31ULL,+ 0x5e5db46acb66e132ULL,0xf1be963a0d925880ULL,0x944a70270317b9e2ULL,0xe266f95948603d48ULL,0x98db66735c208899ULL,0x90472447a2fb18a3ULL,0x8a966939777c619fULL,0x3798142a2a3be21bULL,+ 0xe2f73c696755ff89ULL,0xdd3cf7e7473017e6ULL,0x8ef5689d3cf7600dULL,0x948dc4f8b1fc87b4ULL,0xd9e9fe814ea53299ULL,0x2d921ca298eb6028ULL,0xfaecedfd0c9803fcULL,0xf38ae8914d7b4745ULL,+ 0x871514560f664534ULL,0x85ceae7c4b68f103ULL,0xac09c4ae65578ab9ULL,0x33ec6868f044b10cULL,0x6ac4832b3a8ec1f1ULL,0x5509d1285847d5efULL,0xf909604f763f1574ULL,0xb16c4303c32f63c4ULL,+ 0xfd16847fdec67ef5ULL,0x742ee464233e76b7ULL,0x0b8e4134efc2b4c8ULL,0xca640b8642a3e521ULL,0x653a01908ceb6aa9ULL,0x313c300c547852d5ULL,0x24e4ab126b237af7ULL,0x2ba901628bb47af8ULL,+ 0x00467bc58cce08b5ULL,0xb636458c7f178d55ULL,0xc5748baea677d806ULL,0x2763a387dfa394ebULL,0xa12b448a7d3cebb6ULL,0xe7adda3e6f20d850ULL,0xf63ebce51558462cULL,0x58b36143620088a8ULL,+ 0xa9d89488a059c142ULL,0x6f5ae714ff0b9346ULL,0x068f237d16fb3664ULL,0x5853e4c4363186acULL,0xe2d87d2363c52f98ULL,0x2ec4a76681828876ULL,0x47b864fae14e7b1cULL,0x0c0bc0e569192408ULL,+ 0x624d60492ed22e91ULL,0x6fdfe0b56f072822ULL,0xeeca111539ce2271ULL,0x98100a4fdb01614fULL,0xb6b0daa2a35c628fULL,0xb6f94d2ec87e9a47ULL,0xc67732591d57d9ceULL,0xf70bfeec03884a7bULL,+ 0x4ff23ffd248a7d06ULL,0x80c5bfb4878873faULL,0xb7d9ad9005745981ULL,0x179c85db3db01994ULL,0xba41b06261a6966cULL,0x4d82d052eadce5a8ULL,0x9e91cd3ba5e6a318ULL,0x47795f4f95b2dda0ULL,+ 0x1ee426ccd5cd79bfULL,0x0032940b946c6e18ULL,0x1b1e8ae057477f58ULL,0xe94f7d346d823278ULL,0xc747cb96782ba21aULL,0xc5254469f72b33a5ULL,0x772ef6dec7f80c81ULL,0xd73acbfe2cd9e6b5ULL,+ 0x283c7513caa76097ULL,0x0a624fa936c83906ULL,0x6b20afec715af2c7ULL,0x4b969974eba78bfdULL,0x220755ccd921d60eULL,0x9b944e107baeca13ULL,0x04819d515ded93d4ULL,0x9bbff86e6dddfd27ULL,+ 0x21950b421ff6acd3ULL,0xffe7048453dc6909ULL,0xff4cd0b228766127ULL,0xabdbe6084fb7db2bULL,0x837c92285e1109e8ULL,0x26147d27f4645b5aULL,0x4d78f592f7818ed8ULL,0xd394077ef247fa36ULL,+ 0x508cec1c3b3f64c9ULL,0xe20bc0ba1e5edf3fULL,0xda1deb852f4318d4ULL,0xd20ebe0d5c3fa443ULL,0x370b4ea773241ea3ULL,0x61f1511c5e1a5f65ULL,0x99a5e23d82681c62ULL,0xd731e383a2f54c2dULL,+ 0x97359638546c4d8dULL,0x5f9c3fc492f24679ULL,0x912e8beda8c8acd9ULL,0xec3a318d306634b0ULL,0x80167f41c31cb264ULL,0x3db82f6f522113f2ULL,0xb155bcd2dcafe197ULL,0xfba1da5943465283ULL,+ 0x258bbbf9e7305683ULL,0x31eea5bf07ef5be6ULL,0x0deb0e4a46c814c1ULL,0x5cee8449a7b730ddULL,0xeab495c5a0182bdeULL,0xee759f879e27a6b4ULL,0xc2cf6a6880e518caULL,0x25e8013ff14cf3f4ULL,+ 0x3ec832e77acaca28ULL,0x1bfeea57c7385b29ULL,0x068212e3fd1eaf38ULL,0xc13298306acf8cccULL,0xb909f2db2aac9e59ULL,0x5748060db661782aULL,0xc5ab2632c79b7a01ULL,0xda44c6c600017626ULL,+ 0x69d44ed65c46aa8eULL,0x2100d5d3a8d063d1ULL,0xcb9727eaa2d17c36ULL,0x4c2bab1b8add53b7ULL,0xa084e90c15426704ULL,0x778afcd3a837ebeaULL,0x6651f7017ce477f8ULL,0xa062499846fb7a8bULL,+ 0x3667eb1a7f4c04ccULL,0x59556621a9404f84ULL,0x71cdf6537eceb50aULL,0x994a44a69b8335faULL,0xd7faf819dbeb9b69ULL,0x473c5680eed4350dULL,0xb6658466da44bba2ULL,0x0d1bc780872bdbf3ULL,+ 0xb8d3d9319ff91fe5ULL,0x039c4800f0518eedULL,0x95c376329182cb26ULL,0x0763a43482fc568dULL,0x707c04d5383e76baULL,0xac98b930824e8197ULL,0x92bf7c8f91230de0ULL,0x90876a0140959b70ULL,+};
+ cbits/s2n/COMMIT view
@@ -0,0 +1,1 @@+62ec77dc6c2c8cc4c48c768f5f785240b55a47bf
+ cbits/s2n/LICENSE view
@@ -0,0 +1,222 @@+SPDX-License-Identifier: Apache-2.0 OR ISC or MIT-0+++Apache 2.0 license+-------------------------------------+++ Apache License+ Version 2.0, January 2004+ http://www.apache.org/licenses/++ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION++ 1. Definitions.++ "License" shall mean the terms and conditions for use, reproduction,+ and distribution as defined by Sections 1 through 9 of this document.++ "Licensor" shall mean the copyright owner or entity authorized by+ the copyright owner that is granting the License.++ "Legal Entity" shall mean the union of the acting entity and all+ other entities that control, are controlled by, or are under common+ control with that entity. For the purposes of this definition,+ "control" means (i) the power, direct or indirect, to cause the+ direction or management of such entity, whether by contract or+ otherwise, or (ii) ownership of fifty percent (50%) or more of the+ outstanding shares, or (iii) beneficial ownership of such entity.++ "You" (or "Your") shall mean an individual or Legal Entity+ exercising permissions granted by this License.++ "Source" form shall mean the preferred form for making modifications,+ including but not limited to software source code, documentation+ source, and configuration files.++ "Object" form shall mean any form resulting from mechanical+ transformation or translation of a Source form, including but+ not limited to compiled object code, generated documentation,+ and conversions to other media types.++ "Work" shall mean the work of authorship, whether in Source or+ Object form, made available under the License, as indicated by a+ copyright notice that is included in or attached to the work+ (an example is provided in the Appendix below).++ "Derivative Works" shall mean any work, whether in Source or Object+ form, that is based on (or derived from) the Work and for which the+ editorial revisions, annotations, elaborations, or other modifications+ represent, as a whole, an original work of authorship. For the purposes+ of this License, Derivative Works shall not include works that remain+ separable from, or merely link (or bind by name) to the interfaces of,+ the Work and Derivative Works thereof.++ "Contribution" shall mean any work of authorship, including+ the original version of the Work and any modifications or additions+ to that Work or Derivative Works thereof, that is intentionally+ submitted to Licensor for inclusion in the Work by the copyright owner+ or by an individual or Legal Entity authorized to submit on behalf of+ the copyright owner. For the purposes of this definition, "submitted"+ means any form of electronic, verbal, or written communication sent+ to the Licensor or its representatives, including but not limited to+ communication on electronic mailing lists, source code control systems,+ and issue tracking systems that are managed by, or on behalf of, the+ Licensor for the purpose of discussing and improving the Work, but+ excluding communication that is conspicuously marked or otherwise+ designated in writing by the copyright owner as "Not a Contribution."++ "Contributor" shall mean Licensor and any individual or Legal Entity+ on behalf of whom a Contribution has been received by Licensor and+ subsequently incorporated within the Work.++ 2. Grant of Copyright License. Subject to the terms and conditions of+ this License, each Contributor hereby grants to You a perpetual,+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable+ copyright license to reproduce, prepare Derivative Works of,+ publicly display, publicly perform, sublicense, and distribute the+ Work and such Derivative Works in Source or Object form.++ 3. Grant of Patent License. Subject to the terms and conditions of+ this License, each Contributor hereby grants to You a perpetual,+ worldwide, non-exclusive, no-charge, royalty-free, irrevocable+ (except as stated in this section) patent license to make, have made,+ use, offer to sell, sell, import, and otherwise transfer the Work,+ where such license applies only to those patent claims licensable+ by such Contributor that are necessarily infringed by their+ Contribution(s) alone or by combination of their Contribution(s)+ with the Work to which such Contribution(s) was submitted. If You+ institute patent litigation against any entity (including a+ cross-claim or counterclaim in a lawsuit) alleging that the Work+ or a Contribution incorporated within the Work constitutes direct+ or contributory patent infringement, then any patent licenses+ granted to You under this License for that Work shall terminate+ as of the date such litigation is filed.++ 4. Redistribution. You may reproduce and distribute copies of the+ Work or Derivative Works thereof in any medium, with or without+ modifications, and in Source or Object form, provided that You+ meet the following conditions:++ (a) You must give any other recipients of the Work or+ Derivative Works a copy of this License; and++ (b) You must cause any modified files to carry prominent notices+ stating that You changed the files; and++ (c) You must retain, in the Source form of any Derivative Works+ that You distribute, all copyright, patent, trademark, and+ attribution notices from the Source form of the Work,+ excluding those notices that do not pertain to any part of+ the Derivative Works; and++ (d) If the Work includes a "NOTICE" text file as part of its+ distribution, then any Derivative Works that You distribute must+ include a readable copy of the attribution notices contained+ within such NOTICE file, excluding those notices that do not+ pertain to any part of the Derivative Works, in at least one+ of the following places: within a NOTICE text file distributed+ as part of the Derivative Works; within the Source form or+ documentation, if provided along with the Derivative Works; or,+ within a display generated by the Derivative Works, if and+ wherever such third-party notices normally appear. The contents+ of the NOTICE file are for informational purposes only and+ do not modify the License. You may add Your own attribution+ notices within Derivative Works that You distribute, alongside+ or as an addendum to the NOTICE text from the Work, provided+ that such additional attribution notices cannot be construed+ as modifying the License.++ You may add Your own copyright statement to Your modifications and+ may provide additional or different license terms and conditions+ for use, reproduction, or distribution of Your modifications, or+ for any such Derivative Works as a whole, provided Your use,+ reproduction, and distribution of the Work otherwise complies with+ the conditions stated in this License.++ 5. Submission of Contributions. Unless You explicitly state otherwise,+ any Contribution intentionally submitted for inclusion in the Work+ by You to the Licensor shall be under the terms and conditions of+ this License, without any additional terms or conditions.+ Notwithstanding the above, nothing herein shall supersede or modify+ the terms of any separate license agreement you may have executed+ with Licensor regarding such Contributions.++ 6. Trademarks. This License does not grant permission to use the trade+ names, trademarks, service marks, or product names of the Licensor,+ except as required for reasonable and customary use in describing the+ origin of the Work and reproducing the content of the NOTICE file.++ 7. Disclaimer of Warranty. Unless required by applicable law or+ agreed to in writing, Licensor provides the Work (and each+ Contributor provides its Contributions) on an "AS IS" BASIS,+ WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or+ implied, including, without limitation, any warranties or conditions+ of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A+ PARTICULAR PURPOSE. You are solely responsible for determining the+ appropriateness of using or redistributing the Work and assume any+ risks associated with Your exercise of permissions under this License.++ 8. Limitation of Liability. In no event and under no legal theory,+ whether in tort (including negligence), contract, or otherwise,+ unless required by applicable law (such as deliberate and grossly+ negligent acts) or agreed to in writing, shall any Contributor be+ liable to You for damages, including any direct, indirect, special,+ incidental, or consequential damages of any character arising as a+ result of this License or out of the use or inability to use the+ Work (including but not limited to damages for loss of goodwill,+ work stoppage, computer failure or malfunction, or any and all+ other commercial damages or losses), even if such Contributor+ has been advised of the possibility of such damages.++ 9. Accepting Warranty or Additional Liability. While redistributing+ the Work or Derivative Works thereof, You may choose to offer,+ and charge a fee for, acceptance of support, warranty, indemnity,+ or other liability obligations and/or rights consistent with this+ License. However, in accepting such obligations, You may act only+ on Your own behalf and on Your sole responsibility, not on behalf+ of any other Contributor, and only if You agree to indemnify,+ defend, and hold each Contributor harmless for any liability+ incurred by, or claims asserted against, such Contributor by reason+ of your accepting any such warranty or additional liability.++ END OF TERMS AND CONDITIONS+++ISC license+-------------------------------------++Copyright Amazon.com, Inc. or its affiliates.++Permission to use, copy, modify, and/or distribute this software for any+purpose with or without fee is hereby granted, provided that the above+copyright notice and this permission notice appear in all copies.++THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES+WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF+MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR+ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES+WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN+ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF+OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.+++MIT-0 license+-------------------------------------++Copyright 2021-2024 Amazon.com, Inc. or its affiliates.++Permission is hereby granted, free of charge, to any person obtaining a+copy of this software and associated documentation files (the "Software"),+to deal in the Software without restriction, including without limitation+the rights to use, copy, modify, merge, publish, distribute, sublicense,+and/or sell copies of the Software, and to permit persons to whom the+Software is furnished to do so.++THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR+IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,+FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE+AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER+LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING+FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER+DEALINGS IN THE SOFTWARE.
+ cbits/s2n/README.md view
@@ -0,0 +1,100 @@+# s2n-bignum++Assembly for the NIST prime curves from AWS's+[s2n-bignum](https://github.com/awslabs/s2n-bignum), vendored here.++`COMMIT` holds the upstream revision these files came from, and `import.sh`+fetches them again. The files are unmodified: the choice between the two+variants of each routine is made in crypton's own C, not by editing theirs.++## Why++crypton's P-256 is portable C, and on the two architectures s2n-bignum+covers, hand-written assembly beats it by a lot. Measured against crypton's+own code in the same process, agreeing with it on every scalar tried:++| | crypton | s2n-bignum |+| --- | ---: | ---: |+| Apple M4 | 52.9 us | **20.6** |+| x86-64 with ADX (EPYC 9V74) | 175.9 | **54.5** |+| x86-64, ADX not advertised | 156.1 | **59.4** |++The third row is the `_alt` path, which is what crypton picks where `CPUID`+does not report ADX. It was measured on a KVM guest whose `CPUID` says so+while the host underneath runs ADX instructions anyway, so it says what the+two implementations cost relative to each other on that path, not what an+actual pre-Broadwell part would do.++Each routine also carries a machine-checked proof in HOL-Light that it+computes what it says, and is written in a constant-time style.++## Licence++`Apache-2.0 OR ISC OR MIT-0`, one of which is on every file and all three in+`LICENSE`. crypton is BSD-3, so it takes these under **ISC** -- the MIT-0+option would do as well, and the Apache one is the reason OpenSSL's and+BoringSSL's `ecp_nistz256`, which is Apache-2.0 only, cannot be used here.++## Which variant++Both forms of each routine are vendored, because which one is faster is not+the same question on the two architectures:++* **On ARM**, `_alt` is written for parts with high multiplier throughput,+ which is what Apple silicon is, and it wins there by 30-40%. The plain+ form is for parts that pipeline `UMULH` less well. There is no feature bit+ for this, so the choice is made at compile time on `__APPLE__`.+* **On x86-64**, the plain form uses `MULX`, `ADCX` and `ADOX`, and `_alt` is+ the fallback for processors without them. That *is* a feature bit, so the+ choice is made at run time, from `crypton_x86_simd_features()`.++## RSA++`crypton_powm.c`'s modular exponentiation also borrows from here, but only its+innermost step and only on x86-64: `bignum_kmul_16_32`, `bignum_ksqr_16_32`,+`bignum_kmul_32_64`, `bignum_ksqr_32_64` and `bignum_emontredc_8n` replace the+C's Montgomery multiplication and square. The window, the table and its masked+scan are crypton's throughout. Sixteen limbs is 1024 bits and thirty-two is+2048: the halves a CRT exponentiation works in for RSA-2048 and RSA-4096, and+the whole thing without CRT. The reduction wants ADX, so the choice is made at+run time like the other x86-64 ones.++It is twice the C, because the C cannot form the two carry chains `ADCX` and+`ADOX` give. Measured on an EPYC 7763 at 1024 bits:++| | C | s2n-bignum |+| --- | ---: | ---: |+| multiplication | 0.4832 us | **0.2479** |+| square | 0.3984 | **0.1994** |++**Nothing is vendored for AArch64**, where the same five routines measure level+with the C. That took three attempts to establish, and the first two were+wrong in opposite directions: a reading when the x86-64 routines went in put+the C 5% ahead, and one on 2026-09-26 put the assembly 4% ahead. Both were+wall-clock times on a machine with other work on it, where a swing of that size+says nothing. Measured by thread CPU time, taking the best of twenty-five+batches and alternating the two binaries with the order swapped, one RSA-2048+CRT private operation is 598.9 us through the C and 597.7 through the assembly:+two tenths of a per cent, which is nothing. The two agree on 200 random cases+at 1024 and 2048 bits, so both were computing the same thing. Five files for+nothing is not a trade, so the C stays.++The gap to OpenSSL on Apple silicon -- about half its speed -- is assembly and+not the C, and no portable C closes it. BearSSL's `i62`, which is as far as+portable C is known to go -- 62-bit limbs in 64-bit words, so that a+multiply-accumulate fits an `__int128` with no carry chain at all, and a+five-bit window against crypton's four -- was built and measured the same way+on the same machine: 626.4 us against crypton's C at 668.0, a tie.++`bignum_emontredc_8n_cdiff` was tried too and is not the answer either: it+wants a precomputation this test did not give it, and was slower besides. What+the window is worth, and why it is four and not five, is in+`cbits/crypton_powm.c` beside the constant.++## What is not here++s2n-bignum has only x86-64 and AArch64, so crypton's C stays and is what+every other architecture uses. `p384_montjscalarmul` and `p521_jscalarmul`+have no affine wrapper upstream; crypton's is in `cbits/p256/p256_s2n.c`'s+sibling for those curves. There is no fixed-base routine for P-384 or+P-521 at all, so signing on those curves keeps crypton's comb.
+ cbits/s2n/arm/bignum_deamont_p384.S view
@@ -0,0 +1,151 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert from almost-Montgomery form, z := (x / 2^384) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_deamont_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Convert a 6-digit bignum x out of its (optionally almost) Montgomery form,+// "almost" meaning any 6-digit input will work, with no range restriction.+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_deamont_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_deamont_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_deamont_p384)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_deamont_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_deamont_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_deamont_p384_alt)+ .text+ .balign 4++// ---------------------------------------------------------------------------+// Core one-step "short" Montgomery reduction macro. Takes input in+// [d5;d4;d3;d2;d1;d0] and returns result in [d6;d5;d4;d3;d2;d1],+// adding to the existing contents of [d5;d4;d3;d2;d1]. It is fine+// for d6 to be the same register as d0.+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+// ---------------------------------------------------------------------------++#define montreds(d6,d5,d4,d3,d2,d1,d0, t3,t2,t1) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+/* Recycle d0 (which we know gets implicitly cancelled) to store it */ \+ lsl t1, d0, #32 __LF \+ add d0, t1, d0 __LF \+/* Now let [t2;t1] = 2^64 * w - w + w_hi where w_hi = floor(w/2^32) */ \+/* We need to subtract 2^32 * this, and we can ignore its lower 32 */ \+/* bits since by design it will cancel anyway; we only need the w_hi */ \+/* part to get the carry propagation going. */ \+ lsr t1, d0, #32 __LF \+ subs t1, t1, d0 __LF \+ sbc t2, d0, xzr __LF \+/* Now select in t1 the field to subtract from d1 */ \+ extr t1, t2, t1, #32 __LF \+/* And now get the terms to subtract from d2 and d3 */ \+ lsr t2, t2, #32 __LF \+ adds t2, t2, d0 __LF \+ adc t3, xzr, xzr __LF \+/* Do the subtraction of that portion */ \+ subs d1, d1, t1 __LF \+ sbcs d2, d2, t2 __LF \+ sbcs d3, d3, t3 __LF \+ sbcs d4, d4, xzr __LF \+ sbcs d5, d5, xzr __LF \+/* Now effectively add 2^384 * w by taking d0 as the input for last sbc */ \+ sbc d6, d0, xzr++// Input parameters++#define z x0+#define x x1++// Rotating registers for the intermediate windows++#define d0 x2+#define d1 x3+#define d2 x4+#define d3 x5+#define d4 x6+#define d5 x7++// Other temporaries++#define u x8+#define v x9+#define w x10++S2N_BN_SYMBOL(bignum_deamont_p384):++S2N_BN_SYMBOL(bignum_deamont_p384_alt):+ CFI_START++// Set up an initial window with the input x and an extra leading zero++ ldp d0, d1, [x]+ ldp d2, d3, [x, #16]+ ldp d4, d5, [x, #32]++// Systematically scroll left doing 1-step reductions++ montreds(d0,d5,d4,d3,d2,d1,d0, u,v,w)++ montreds(d1,d0,d5,d4,d3,d2,d1, u,v,w)++ montreds(d2,d1,d0,d5,d4,d3,d2, u,v,w)++ montreds(d3,d2,d1,d0,d5,d4,d3, u,v,w)++ montreds(d4,d3,d2,d1,d0,d5,d4, u,v,w)++ montreds(d5,d4,d3,d2,d1,d0,d5, u,v,w)++// Now compare end result in [d5;d4;d3;d2;d1;d0] = dd with p_384 by *adding*+// 2^384 - p_384 = [0;0;0;w;v;u]. This will set CF if+// dd + (2^384 - p_384) >= 2^384, hence iff dd >= p_384++ mov u, #0xffffffff00000001+ mov v, #0x00000000ffffffff+ mov w, #0x0000000000000001++ adds xzr, d0, u+ adcs xzr, d1, v+ adcs xzr, d2, w+ adcs xzr, d3, xzr+ adcs xzr, d4, xzr+ adcs xzr, d5, xzr++// Convert the condition dd >= p_384 into a bitmask in w and do a masked+// subtraction of p_384, via a masked addition of 2^384 - p_384:++ csetm w, cs+ and u, u, w+ adds d0, d0, u+ and v, v, w+ adcs d1, d1, v+ and w, w, #1+ adcs d2, d2, w+ adcs d3, d3, xzr+ adcs d4, d4, xzr+ adc d5, d5, xzr++// Store it back++ stp d0, d1, [z]+ stp d2, d3, [z, #16]+ stp d4, d5, [z, #32]++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_deamont_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_demont_p256.S view
@@ -0,0 +1,99 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert from Montgomery form z := (x / 2^256) mod p_256, assuming x reduced+// Input x[4]; output z[4]+//+// extern void bignum_demont_p256(uint64_t z[static 4],+// const uint64_t x[static 4]);+//+// This assumes the input is < p_256 for correctness. If this is not the case,+// use the variant "bignum_deamont_p256" instead.+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_demont_p256)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_demont_p256)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_demont_p256)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_demont_p256_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_demont_p256_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_demont_p256_alt)+ .text+ .balign 4++// ---------------------------------------------------------------------------+// Core one-step "short" Montgomery reduction macro. Takes input in+// [d3;d2;d1;d0] and returns result in [d4;d3;d2;d1], adding to the+// existing contents of [d3;d2;d1] and generating d4 from zero, re-using+// d0 as a temporary internally together with t0, t1 and t2.+// It is fine for d4 to be the same register as d0, and it often is.+// ---------------------------------------------------------------------------++#define montreds(d4,d3,d2,d1,d0, t2,t1,t0) \+/* Let w = d0, the original word we use as offset; d0 gets recycled */ \+/* First let [t2;t1] = 2^32 * w */ \+/* then let [d0;t0] = (2^64 - 2^32 + 1) * w (overwrite old d0) */ \+ lsl t1, d0, #32 __LF \+ subs t0, d0, t1 __LF \+ lsr t2, d0, #32 __LF \+ sbc d0, d0, t2 __LF \+/* Hence [d4;..;d1] := [d3;d2;d1;0] + (2^256 - 2^224 + 2^192 + 2^96) * w */ \+ adds d1, d1, t1 __LF \+ adcs d2, d2, t2 __LF \+ adcs d3, d3, t0 __LF \+ adc d4, d0, xzr++// Input parameters++#define z x0+#define x x1++// Rotating registers for the intermediate windows (with repetitions)++#define d0 x2+#define d1 x3+#define d2 x4+#define d3 x5++// Other temporaries++#define u x6+#define v x7+#define w x8++S2N_BN_SYMBOL(bignum_demont_p256):++S2N_BN_SYMBOL(bignum_demont_p256_alt):+ CFI_START++// Set up an initial window with the input x and an extra leading zero++ ldp d0, d1, [x]+ ldp d2, d3, [x, #16]++// Systematically scroll left doing 1-step reductions++ montreds(d0,d3,d2,d1,d0, u,v,w)++ montreds(d1,d0,d3,d2,d1, u,v,w)++ montreds(d2,d1,d0,d3,d2, u,v,w)++ montreds(d3,d2,d1,d0,d3, u,v,w)++// Write back result++ stp d0, d1, [z]+ stp d2, d3, [z, #16]++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_demont_p256)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_inv_p521.S view
@@ -0,0 +1,1701 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Modular inverse modulo p_521 = 2^521 - 1+// Input x[9]; output z[9]+//+// extern void bignum_inv_p521(uint64_t z[static 9],const uint64_t x[static 9]);+//+// Assuming the 9-digit input x is coprime to p_521, i.e. is not divisible+// by it, returns z < p_521 such that x * z == 1 (mod p_521). Note that+// x does not need to be reduced modulo p_521, but the output always is.+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_inv_p521)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_inv_p521)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_inv_p521)++ .text+ .balign 4++// Size in bytes of a 64-bit word++#define N 8++// Used for the return pointer++#define res x20++// Loop counter and d = 2 * delta value for divstep++#define i x21+#define d x22++// Registers used for matrix element magnitudes and signs++#define m00 x10+#define m01 x11+#define m10 x12+#define m11 x13+#define s00 x14+#define s01 x15+#define s10 x16+#define s11 x17++// Initial carries for combinations++#define car0 x9+#define car1 x19++// Input and output, plain registers treated according to pattern++#define reg0 x0, #0+#define reg1 x1, #0+#define reg2 x2, #0+#define reg3 x3, #0+#define reg4 x4, #0++#define x x1, #0+#define z x0, #0++// Pointer-offset pairs for temporaries on stack++#define f sp, #0+#define g sp, #(9*N)+#define u sp, #(18*N)+#define v sp, #(27*N)++// Total size to reserve on the stack++#define NSPACE 36*N++// Very similar to a subroutine call to the s2n-bignum word_divstep59.+// But different in register usage and returning the final matrix in+// registers as follows+//+// [ m00 m01]+// [ m10 m11]++#define divstep59() \+ and x4, x2, #0xfffff __LF \+ orr x4, x4, #0xfffffe0000000000 __LF \+ and x5, x3, #0xfffff __LF \+ orr x5, x5, #0xc000000000000000 __LF \+ tst x5, #0x1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ asr x5, x5, #1 __LF \+ add x8, x4, #0x100, lsl #12 __LF \+ sbfx x8, x8, #21, #21 __LF \+ mov x11, #0x100000 __LF \+ add x11, x11, x11, lsl #21 __LF \+ add x9, x4, x11 __LF \+ asr x9, x9, #42 __LF \+ add x10, x5, #0x100, lsl #12 __LF \+ sbfx x10, x10, #21, #21 __LF \+ add x11, x5, x11 __LF \+ asr x11, x11, #42 __LF \+ mul x6, x8, x2 __LF \+ mul x7, x9, x3 __LF \+ mul x2, x10, x2 __LF \+ mul x3, x11, x3 __LF \+ add x4, x6, x7 __LF \+ add x5, x2, x3 __LF \+ asr x2, x4, #20 __LF \+ asr x3, x5, #20 __LF \+ and x4, x2, #0xfffff __LF \+ orr x4, x4, #0xfffffe0000000000 __LF \+ and x5, x3, #0xfffff __LF \+ orr x5, x5, #0xc000000000000000 __LF \+ tst x5, #0x1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ asr x5, x5, #1 __LF \+ add x12, x4, #0x100, lsl #12 __LF \+ sbfx x12, x12, #21, #21 __LF \+ mov x15, #0x100000 __LF \+ add x15, x15, x15, lsl #21 __LF \+ add x13, x4, x15 __LF \+ asr x13, x13, #42 __LF \+ add x14, x5, #0x100, lsl #12 __LF \+ sbfx x14, x14, #21, #21 __LF \+ add x15, x5, x15 __LF \+ asr x15, x15, #42 __LF \+ mul x6, x12, x2 __LF \+ mul x7, x13, x3 __LF \+ mul x2, x14, x2 __LF \+ mul x3, x15, x3 __LF \+ add x4, x6, x7 __LF \+ add x5, x2, x3 __LF \+ asr x2, x4, #20 __LF \+ asr x3, x5, #20 __LF \+ and x4, x2, #0xfffff __LF \+ orr x4, x4, #0xfffffe0000000000 __LF \+ and x5, x3, #0xfffff __LF \+ orr x5, x5, #0xc000000000000000 __LF \+ tst x5, #0x1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ mul x2, x12, x8 __LF \+ mul x3, x12, x9 __LF \+ mul x6, x14, x8 __LF \+ mul x7, x14, x9 __LF \+ madd x8, x13, x10, x2 __LF \+ madd x9, x13, x11, x3 __LF \+ madd x16, x15, x10, x6 __LF \+ madd x17, x15, x11, x7 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ asr x5, x5, #1 __LF \+ add x12, x4, #0x100, lsl #12 __LF \+ sbfx x12, x12, #22, #21 __LF \+ mov x15, #0x100000 __LF \+ add x15, x15, x15, lsl #21 __LF \+ add x13, x4, x15 __LF \+ asr x13, x13, #43 __LF \+ add x14, x5, #0x100, lsl #12 __LF \+ sbfx x14, x14, #22, #21 __LF \+ add x15, x5, x15 __LF \+ asr x15, x15, #43 __LF \+ mneg x2, x12, x8 __LF \+ mneg x3, x12, x9 __LF \+ mneg x4, x14, x8 __LF \+ mneg x5, x14, x9 __LF \+ msub m00, x13, x16, x2 __LF \+ msub m01, x13, x17, x3 __LF \+ msub m10, x15, x16, x4 __LF \+ msub m11, x15, x17, x5++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(bignum_inv_p521):+ CFI_START++// Save registers and make room for temporaries++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_DEC_SP(NSPACE)++// Save the return pointer for the end so we can overwrite x0 later++ mov res, x0++// Copy the prime p_521 = 2^521 - 1 into the f variable++ mov x10, #0xFFFFFFFFFFFFFFFF+ stp x10, x10, [f]+ stp x10, x10, [f+16]+ stp x10, x10, [f+32]+ stp x10, x10, [f+48]+ mov x11, #0x1FF+ str x11, [f+64]++// Copy the input into the g variable, but reduce it strictly mod p_521+// so that g <= f as assumed in the bound proof. This code fragment is+// very similar to bignum_mod_p521_9 complete with carry condensation.++ ldr x8, [x1, #64]+ lsr x9, x8, #9++ subs xzr, xzr, xzr+ ldp x10, x11, [x1]+ adcs xzr, x10, x9+ adcs xzr, x11, xzr+ ldp x12, x13, [x1, #16]+ and x7, x12, x13+ adcs xzr, x7, xzr+ ldp x14, x15, [x1, #32]+ and x7, x14, x15+ adcs xzr, x7, xzr+ ldp x16, x17, [x1, #48]+ and x7, x16, x17+ adcs xzr, x7, xzr+ orr x7, x8, #~0x1FF+ adcs x7, x7, xzr++ adcs x10, x10, x9+ adcs x11, x11, xzr+ adcs x12, x12, xzr+ adcs x13, x13, xzr+ adcs x14, x14, xzr+ adcs x15, x15, xzr+ adcs x16, x16, xzr+ adcs x17, x17, xzr+ adc x8, x8, xzr+ and x8, x8, #0x1FF++ stp x10, x11, [g]+ stp x12, x13, [g+16]+ stp x14, x15, [g+32]+ stp x16, x17, [g+48]+ str x8, [g+64]++// Also maintain weakly reduced < 2*p_521 vector [u,v] such that+// [f,g] == x * 2^{1239-59*i} * [u,v] (mod p_521)+// starting with [p_521,x] == x * 2^{1239-59*0} * [0,2^-1239] (mod p_521)+// Note that because (2^{a+521} == 2^a) (mod p_521) we simply have+// (2^-1239 == 2^324) (mod p_521) so the constant initializer is simple.+//+// Based on the standard divstep bound, for inputs <= 2^b we need at least+// n >= (9437 * b + 1) / 4096. Since b is 521, that means 1201 iterations.+// Since we package divstep in multiples of 59 bits, we do 21 blocks of 59+// making *1239* total. (With a bit more effort we could avoid the full 59+// divsteps and use a shorter tail computation, but we keep it simple.)+// Hence, after the 21st iteration we have [f,g] == x * [u,v] and since+// |f| = 1 we get the modular inverse from u by flipping its sign with f.++ stp xzr, xzr, [u]+ stp xzr, xzr, [u+16]+ stp xzr, xzr, [u+32]+ stp xzr, xzr, [u+48]+ str xzr, [u+64]++ mov x10, #16+ stp xzr, xzr, [v]+ stp xzr, xzr, [v+16]+ stp xzr, x10, [v+32]+ stp xzr, xzr, [v+48]+ str xzr, [v+64]++// Start of main loop. We jump into the middle so that the divstep+// portion is common to the special 21st iteration after a uniform+// first 20.++ mov i, #21+ mov d, #1+ b Lbignum_inv_p521_midloop++Lbignum_inv_p521_loop:++// Separate the matrix elements into sign-magnitude pairs++ cmp m00, xzr+ csetm s00, mi+ cneg m00, m00, mi++ cmp m01, xzr+ csetm s01, mi+ cneg m01, m01, mi++ cmp m10, xzr+ csetm s10, mi+ cneg m10, m10, mi++ cmp m11, xzr+ csetm s11, mi+ cneg m11, m11, mi++// Adjust the initial values to allow for complement instead of negation+// This initial offset is the same for [f,g] and [u,v] compositions.+// Save it in stable registers for the [u,v] part and do [f,g] first.++ and x0, m00, s00+ and x1, m01, s01+ add car0, x0, x1++ and x0, m10, s10+ and x1, m11, s11+ add car1, x0, x1++// Now the computation of the updated f and g values. This maintains a+// 2-word carry between stages so we can conveniently insert the shift+// right by 59 before storing back, and not overwrite digits we need+// again of the old f and g values.+//+// Digit 0 of [f,g]++ ldr x7, [f]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, car0, x0+ adc x2, xzr, x1+ ldr x8, [g]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ adc x2, x2, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, car1, x0+ adc x3, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ adc x3, x3, x1++// Digit 1 of [f,g]++ ldr x7, [f+N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [g+N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [f]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [g]++// Digit 2 of [f,g]++ ldr x7, [f+2*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [g+2*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [f+N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [g+N]++// Digit 3 of [f,g]++ ldr x7, [f+3*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, xzr, x1+ ldr x8, [g+3*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [f+2*N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x2, x2, x0+ adc x6, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [g+2*N]++// Digit 4 of [f,g]++ ldr x7, [f+4*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x3, x3, x0+ adc x4, xzr, x1+ ldr x8, [g+4*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [f+3*N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x6, x6, x0+ adc x5, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [g+3*N]++// Digit 5 of [f,g]++ ldr x7, [f+5*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, x4, x0+ adc x2, xzr, x1+ ldr x8, [g+5*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [f+4*N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, x5, x0+ adc x3, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [g+4*N]++// Digit 6 of [f,g]++ ldr x7, [f+6*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [g+6*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [f+5*N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [g+5*N]++// Digit 7 of [f,g]++ ldr x7, [f+7*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [g+7*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [f+6*N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [g+6*N]++// Digits 8 and 9 of [f,g]++ ldr x7, [f+8*N]+ eor x1, x7, s00+ asr x3, x1, #63+ and x3, x3, m00+ neg x3, x3+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [g+8*N]+ eor x1, x8, s01+ asr x0, x1, #63+ and x0, x0, m01+ sub x3, x3, x0+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [f+7*N]+ extr x5, x3, x5, #59+ str x5, [f+8*N]++ eor x1, x7, s10+ asr x5, x1, #63+ and x5, x5, m10+ neg x5, x5+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, s11+ asr x0, x1, #63+ and x0, x0, m11+ sub x5, x5, x0+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [g+7*N]+ extr x2, x5, x2, #59+ str x2, [g+8*N]++// Now the computation of the updated u and v values and their+// modular reductions. A very similar accumulation except that+// the top words of u and v are unsigned and we don't shift.+//+// Digit 0 of [u,v]++ ldr x7, [u]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, car0, x0+ adc x2, xzr, x1+ ldr x8, [v]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u]+ adc x2, x2, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, car1, x0+ adc x3, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ str x5, [v]+ adc x3, x3, x1++// Digit 1 of [u,v]++ ldr x7, [u+N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [v+N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ str x2, [u+N]+ adc x6, x6, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x3, x3, x0+ str x3, [v+N]+ adc x4, x4, x1++// Digit 2 of [u,v]++ ldr x7, [u+2*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [v+2*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ str x6, [u+2*N]+ adc x5, x5, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x4, x4, x0+ str x4, [v+2*N]+ adc x2, x2, x1++// Digit 3 of [u,v]++ ldr x7, [u+3*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, xzr, x1+ ldr x8, [v+3*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ str x5, [u+3*N]+ adc x3, x3, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x2, x2, x0+ adc x6, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x2, x2, x0+ str x2, [v+3*N]+ adc x6, x6, x1++// Digit 4 of [u,v]++ ldr x7, [u+4*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x3, x3, x0+ adc x4, xzr, x1+ ldr x8, [v+4*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x3, x3, x0+ str x3, [u+4*N]+ adc x4, x4, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x6, x6, x0+ adc x5, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x6, x6, x0+ str x6, [v+4*N]+ adc x5, x5, x1++// Digit 5 of [u,v]++ ldr x7, [u+5*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, x4, x0+ adc x2, xzr, x1+ ldr x8, [v+5*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u+5*N]+ adc x2, x2, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, x5, x0+ adc x3, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ str x5, [v+5*N]+ adc x3, x3, x1++// Digit 6 of [u,v]++ ldr x7, [u+6*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [v+6*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ str x2, [u+6*N]+ adc x6, x6, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x3, x3, x0+ str x3, [v+6*N]+ adc x4, x4, x1++// Digit 7 of [u,v]++ ldr x7, [u+7*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [v+7*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ str x6, [u+7*N]+ adc x5, x5, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x4, x4, x0+ str x4, [v+7*N]+ adc x2, x2, x1++// Digits 8 and 9 of u (top is unsigned)++ ldr x7, [u+8*N]+ eor x1, x7, s00+ and x3, s00, m00+ neg x3, x3+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [v+8*N]+ eor x1, x8, s01+ and x0, s01, m01+ sub x3, x3, x0+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ adc x3, x3, x1++// Modular reduction of u, reloading as needed from u[0],...,u[7],x5,x3++ extr x6, x3, x5, #9+ ldp x0, x1, [u]+ add x6, x6, x3, asr #63+ sub x5, x5, x6, lsl #9+ adds x0, x0, x6+ asr x6, x6, #63+ adcs x1, x1, x6+ stp x0, x1, [u]+ ldp x0, x1, [u+16]+ adcs x0, x0, x6+ adcs x1, x1, x6+ stp x0, x1, [u+16]+ ldp x0, x1, [u+32]+ adcs x0, x0, x6+ adcs x1, x1, x6+ stp x0, x1, [u+32]+ ldp x0, x1, [u+48]+ adcs x0, x0, x6+ adcs x1, x1, x6+ stp x0, x1, [u+48]+ adc x5, x5, x6+ str x5, [u+64]++// Digits 8 and 9 of v (top is unsigned)++ eor x1, x7, s10+ and x5, s10, m10+ neg x5, x5+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, s11+ and x0, s11, m11+ sub x5, x5, x0+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x2, x2, x0+ adc x5, x5, x1++// Modular reduction of v, reloading as needed from v[0],...,v[7],x2,x5++ extr x6, x5, x2, #9+ ldp x0, x1, [v]+ add x6, x6, x5, asr #63+ sub x2, x2, x6, lsl #9+ adds x0, x0, x6+ asr x6, x6, #63+ adcs x1, x1, x6+ stp x0, x1, [v]+ ldp x0, x1, [v+16]+ adcs x0, x0, x6+ adcs x1, x1, x6+ stp x0, x1, [v+16]+ ldp x0, x1, [v+32]+ adcs x0, x0, x6+ adcs x1, x1, x6+ stp x0, x1, [v+32]+ ldp x0, x1, [v+48]+ adcs x0, x0, x6+ adcs x1, x1, x6+ stp x0, x1, [v+48]+ adc x2, x2, x6+ str x2, [v+64]++Lbignum_inv_p521_midloop:++ mov x1, d+ ldr x2, [f]+ ldr x3, [g]+ divstep59()+ mov d, x1++// Next iteration++ subs i, i, #1+ bne Lbignum_inv_p521_loop++// The 21st and last iteration does not need anything except the+// u value and the sign of f; the latter can be obtained from the+// lowest word of f. So it's done differently from the main loop.+// Find the sign of the new f. For this we just need one digit+// since we know (for in-scope cases) that f is either +1 or -1.+// We don't explicitly shift right by 59 either, but looking at+// bit 63 (or any bit >= 60) of the unshifted result is enough+// to distinguish -1 from +1; this is then made into a mask.++ ldr x0, [f]+ ldr x1, [g]+ mul x0, x0, m00+ madd x1, x1, m01, x0+ asr x0, x1, #63++// Now separate out the matrix into sign-magnitude pairs+// and adjust each one based on the sign of f.+//+// Note that at this point we expect |f|=1 and we got its+// sign above, so then since [f,0] == x * [u,v] (mod p_521)+// we want to flip the sign of u according to that of f.++ cmp m00, xzr+ csetm s00, mi+ cneg m00, m00, mi+ eor s00, s00, x0++ cmp m01, xzr+ csetm s01, mi+ cneg m01, m01, mi+ eor s01, s01, x0++ cmp m10, xzr+ csetm s10, mi+ cneg m10, m10, mi+ eor s10, s10, x0++ cmp m11, xzr+ csetm s11, mi+ cneg m11, m11, mi+ eor s11, s11, x0++// Adjust the initial value to allow for complement instead of negation++ and x0, m00, s00+ and x1, m01, s01+ add car0, x0, x1++// Digit 0 of [u]++ ldr x7, [u]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, car0, x0+ adc x2, xzr, x1+ ldr x8, [v]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u]+ adc x2, x2, x1++// Digit 1 of [u]++ ldr x7, [u+N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [v+N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ str x2, [u+N]+ adc x6, x6, x1++// Digit 2 of [u]++ ldr x7, [u+2*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [v+2*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ str x6, [u+2*N]+ adc x5, x5, x1++// Digit 3 of [u]++ ldr x7, [u+3*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, xzr, x1+ ldr x8, [v+3*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ str x5, [u+3*N]+ adc x3, x3, x1++// Digit 4 of [u]++ ldr x7, [u+4*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x3, x3, x0+ adc x4, xzr, x1+ ldr x8, [v+4*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x3, x3, x0+ str x3, [u+4*N]+ adc x4, x4, x1++// Digit 5 of [u]++ ldr x7, [u+5*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, x4, x0+ adc x2, xzr, x1+ ldr x8, [v+5*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u+5*N]+ adc x2, x2, x1++// Digit 6 of [u]++ ldr x7, [u+6*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [v+6*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ str x2, [u+6*N]+ adc x6, x6, x1++// Digit 7 of [u]++ ldr x7, [u+7*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [v+7*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ str x6, [u+7*N]+ adc x5, x5, x1++// Digits 8 and 9 of u (top is unsigned)++ ldr x7, [u+8*N]+ eor x1, x7, s00+ and x3, s00, m00+ neg x3, x3+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [v+8*N]+ eor x1, x8, s01+ and x0, s01, m01+ sub x3, x3, x0+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ adc x3, x3, x1++// Modular reduction of u, reloading as needed from u[0],...,u[7],x5,x3++ extr x6, x3, x5, #9+ ldp x10, x11, [u]+ add x6, x6, x3, asr #63+ sub x5, x5, x6, lsl #9+ adds x10, x10, x6+ asr x6, x6, #63+ adcs x11, x11, x6+ ldp x12, x13, [u+16]+ adcs x12, x12, x6+ adcs x13, x13, x6+ ldp x14, x15, [u+32]+ adcs x14, x14, x6+ adcs x15, x15, x6+ ldp x16, x17, [u+48]+ adcs x16, x16, x6+ adcs x17, x17, x6+ adc x19, x5, x6++// Further strict reduction ready for the output, which just means+// a conditional subtraction of p_521++ subs x0, x10, #-1+ adcs x1, x11, xzr+ adcs x2, x12, xzr+ adcs x3, x13, xzr+ adcs x4, x14, xzr+ adcs x5, x15, xzr+ adcs x6, x16, xzr+ adcs x7, x17, xzr+ mov x8, #0x1FF+ sbcs x8, x19, x8++ csel x0, x0, x10, cs+ csel x1, x1, x11, cs+ csel x2, x2, x12, cs+ csel x3, x3, x13, cs+ csel x4, x4, x14, cs+ csel x5, x5, x15, cs+ csel x6, x6, x16, cs+ csel x7, x7, x17, cs+ csel x8, x8, x19, cs++// Store it back to the final output++ stp x0, x1, [res]+ stp x2, x3, [res, #16]+ stp x4, x5, [res, #32]+ stp x6, x7, [res, #48]+ str x8, [res, #64]++// Restore stack and registers++ CFI_INC_SP(NSPACE)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_inv_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/bignum_modinv.S view
@@ -0,0 +1,613 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Invert modulo m, z = (1/a) mod b, assuming b is an odd number > 1, coprime a+// Inputs a[k], b[k]; output z[k]; temporary buffer t[>=3*k]+//+// extern void bignum_modinv(uint64_t k, uint64_t *z, const uint64_t *a,+// const uint64_t *b, uint64_t *t);+//+// k-digit (digit=64 bits) "z := a^-1 mod b" (modular inverse of a modulo b)+// using t as a temporary buffer (t at least 3*k words = 24*k bytes), and+// assuming that a and b are coprime *and* that b is an odd number > 1.+//+// Standard ARM ABI: X0 = k, X1 = z, X2 = a, X3 = b, X4 = t+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_modinv)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_modinv)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_modinv)+ .text+ .balign 4++// We get CHUNKSIZE bits per outer iteration, 64 minus a few for proxy errors++#define CHUNKSIZE 58++// Pervasive variables++#define k x0+#define z x1+#define b x3+#define w x4++// This one is recycled after initial copying in of a as outer loop counter++#define a x2+#define t x2++// Additional variables; later ones are currently rather high regs++#define l x5++#define m x21+#define n x22++// The matrix of update factors to apply to m and n+// Also used a couple of additional temporary variables for the swapping loop+// Also used as an extra down-counter in corrective negation loops++#define m_m x6+#define m_n x7+#define n_m x8+#define n_n x9++#define j x6++// General temporary variables and loop counters++#define i x10+#define t1 x11+#define t2 x12++// High and low proxies for the inner loop+// Then re-used for high and carry words during actual cross-multiplications++#define m_hi x13+#define n_hi x14+#define m_lo x15+#define n_lo x16++#define h1 x13+#define h2 x14+#define l1 x15+#define l2 x16++#define c1 x17+#define c2 x19++// Negated modular inverse for Montgomery++#define v x20++// Some more intuitive names for temp regs in initial word-level negmodinv.+// These just use t1 and t2 again, though carefully since t1 = initial b[0]++#define one t2+#define e1 t2+#define e2 t1+#define e4 t2+#define e8 t1++S2N_BN_SYMBOL(bignum_modinv):+ CFI_START++// We make use of registers beyond the modifiable++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)++// If k = 0 then do nothing (this is out of scope anyway)++ cbz k, Lbignum_modinv_end++// Set up the additional two buffers m and n beyond w in temp space++ lsl i, k, #3+ add m, w, i+ add n, m, i++// Initialize the main buffers with their starting values:+// m = a, n = b, w = b (to be tweaked to b - 1) and z = 0++ mov i, xzr+Lbignum_modinv_copyloop:+ ldr t1, [a, i, lsl #3]+ ldr t2, [b, i, lsl #3]+ str t1, [m, i, lsl #3]+ str t2, [n, i, lsl #3]+ str t2, [w, i, lsl #3]+ str xzr, [z, i, lsl #3]+ add i, i, #1+ cmp i, k+ bcc Lbignum_modinv_copyloop++// Tweak down w to b - 1 (this crude approach is safe as b needs to be odd+// for it to be in scope). We have then established the congruence invariant:+//+// a * w == -m (mod b)+// a * z == n (mod b)+//+// This, with the bound w <= b and z <= b, is maintained round the outer loop++ ldr t1, [w]+ sub t2, t1, #1+ str t2, [w]++// Compute v = negated modular inverse of b mod 2^64, reusing t1 from above+// This is used for Montgomery reduction operations each time round the loop++ lsl v, t1, #2+ sub v, t1, v+ eor v, v, #2+ mov one, #1+ madd e1, t1, v, one+ mul e2, e1, e1+ madd v, e1, v, v+ mul e4, e2, e2+ madd v, e2, v, v+ mul e8, e4, e4+ madd v, e4, v, v+ madd v, e8, v, v++// Set up the outer loop count of 128 * k+// The invariant is that m * n < 2^t at all times.++ lsl t, k, #7++// Start of the main outer loop iterated t / CHUNKSIZE times++Lbignum_modinv_outerloop:++// We need only bother with sharper l = min k (ceil(t/64)) digits+// for the computations on m and n (but we still need k for w and z).+// Either both m and n fit in l digits, or m has become zero and so+// nothing happens in the loop anyway and this makes no difference.++ add i, t, #63+ lsr l, i, #6+ cmp l, k+ csel l, k, l, cs++// Select upper and lower proxies for both m and n to drive the inner+// loop. The lower proxies are simply the lowest digits themselves,+// m_lo = m[0] and n_lo = n[0], while the upper proxies are bitfields+// of the two inputs selected so their top bit (63) aligns with the+// most significant bit of *either* of the two inputs.++ mov h1, xzr // Previous high and low for m+ mov l1, xzr+ mov h2, xzr // Previous high and low for n+ mov l2, xzr+ mov c2, xzr // Mask flag: previous word of one was nonzero+ // and in this case h1 and h2 are those words+ mov i, xzr+Lbignum_modinv_toploop:+ ldr t1, [m, i, lsl #3]+ ldr t2, [n, i, lsl #3]+ orr c1, t1, t2+ cmp c1, xzr+ and c1, c2, h1+ csel l1, c1, l1, ne+ and c1, c2, h2+ csel l2, c1, l2, ne+ csel h1, t1, h1, ne+ csel h2, t2, h2, ne+ csetm c2, ne+ add i, i, #1+ cmp i, l+ bcc Lbignum_modinv_toploop++ orr t1, h1, h2+ clz t2, t1+ negs c1, t2+ lsl h1, h1, t2+ csel l1, l1, xzr, ne+ lsl h2, h2, t2+ csel l2, l2, xzr, ne+ lsr l1, l1, c1+ lsr l2, l2, c1+ orr m_hi, h1, l1+ orr n_hi, h2, l2++ ldr m_lo, [m]+ ldr n_lo, [n]++// Now the inner loop, with i as loop counter from CHUNKSIZE down.+// This records a matrix of updates to apply to the initial+// values of m and n with, at stage j:+//+// sgn * m' = (m_m * m - m_n * n) / 2^j+// -sgn * n' = (n_m * m - n_n * n) / 2^j+//+// where "sgn" is either +1 or -1, and we lose track of which except+// that both instance above are the same. This throwing away the sign+// costs nothing (since we have to correct in general anyway because+// of the proxied comparison) and makes things a bit simpler. But it+// is simply the parity of the number of times the first condition,+// used as the swapping criterion, fires in this loop.++ mov m_m, #1+ mov m_n, xzr+ mov n_m, xzr+ mov n_n, #1++ mov i, #CHUNKSIZE++// Conceptually in the inner loop we follow these steps:+//+// * If m_lo is odd and m_hi < n_hi, then swap the four pairs+// (m_hi,n_hi); (m_lo,n_lo); (m_m,n_m); (m_n,n_n)+//+// * Now, if m_lo is odd (old or new, doesn't matter as initial n_lo is odd)+// m_hi := m_hi - n_hi, m_lo := m_lo - n_lo+// m_m := m_m + n_m, m_n := m_n + n_n+//+// * Halve and double them+// m_hi := m_hi / 2, m_lo := m_lo / 2+// n_m := n_m * 2, n_n := n_n * 2+//+// The actual computation computes updates before actually swapping and+// then corrects as needed. It also maintains the invariant ~ZF <=> odd(m_lo),+// since it seems to reduce the dependent latency. Set that up first.++ ands xzr, m_lo, #1++Lbignum_modinv_innerloop:++// At the start of the loop ~ZF <=> m_lo is odd; mask values accordingly+// Set the flags for m_hi - [~ZF] * n_hi so we know to flip things.++ csel t1, n_hi, xzr, ne+ csel t2, n_lo, xzr, ne+ csel c1, n_m, xzr, ne+ csel c2, n_n, xzr, ne+ ccmp m_hi, n_hi, #0x2, ne++// Compute subtractive updates, trivial in the case ZF <=> even(m_lo).++ sub t1, m_hi, t1+ sub t2, m_lo, t2++// If the subtraction borrows, swap things appropriately, negating where+// we've already subtracted so things are as if we actually swapped first.++ csel n_hi, n_hi, m_hi, cs+ cneg t1, t1, cc+ csel n_lo, n_lo, m_lo, cs+ cneg m_lo, t2, cc+ csel n_m, n_m, m_m, cs+ csel n_n, n_n, m_n, cs++// Update and shift while setting oddness flag for next iteration+// We look at bit 1 of t2 (m_lo before possible negation), which is+// safe because it is even.++ ands xzr, t2, #2+ add m_m, m_m, c1+ add m_n, m_n, c2+ lsr m_hi, t1, #1+ lsr m_lo, m_lo, #1+ add n_m, n_m, n_m+ add n_n, n_n, n_n++// Next iteration; don't disturb the flags since they are used at entry++ sub i, i, #1+ cbnz i, Lbignum_modinv_innerloop++// Apply the update to w and z, using addition in this case, and also take+// the chance to shift an additional 6 = 64-CHUNKSIZE bits to be ready for a+// Montgomery multiplication. Because we know that m_m + m_n <= 2^58 and+// w, z <= b < 2^{64k}, we know that both of these fit in k+1 words.+// We do this before the m-n update to allow us to play with c1 and c2 here.+//+// h1::w = 2^6 * (m_m * w + m_n * z)+// h2::z = 2^6 * (n_m * w + n_n * z)+//+// with c1 and c2 recording previous words for the shifting part++ mov h1, xzr+ mov h2, xzr+ mov c1, xzr+ mov c2, xzr++ mov i, xzr+Lbignum_modinv_congloop:+ ldr t1, [w, i, lsl #3]+ ldr t2, [z, i, lsl #3]++ mul l1, m_m, t1+ mul l2, m_n, t2+ adds l1, l1, h1+ umulh h1, m_m, t1+ adc h1, h1, xzr+ adds l1, l1, l2+ extr c1, l1, c1, #CHUNKSIZE+ str c1, [w, i, lsl #3]+ mov c1, l1+ umulh l1, m_n, t2+ adc h1, h1, l1++ mul l1, n_m, t1+ mul l2, n_n, t2+ adds l1, l1, h2+ umulh h2, n_m, t1+ adc h2, h2, xzr+ adds l1, l1, l2+ extr c2, l1, c2, #CHUNKSIZE+ str c2, [z, i, lsl #3]+ mov c2, l1+ umulh l1, n_n, t2+ adc h2, h2, l1++ add i, i, #1+ cmp i, k+ bcc Lbignum_modinv_congloop++ extr h1, h1, c1, #CHUNKSIZE+ extr h2, h2, c2, #CHUNKSIZE++// Do a Montgomery reduction of h1::w++ ldr t1, [w]+ mul c1, t1, v+ ldr t2, [b]+ mul l1, c1, t2+ umulh l2, c1, t2+ adds t1, t1, l1 // Will be zero but want the carry++ mov i, #1+ sub t1, k, #1+ cbz t1, Lbignum_modinv_wmontend+Lbignum_modinv_wmontloop:+ ldr t1, [b, i, lsl #3]+ ldr t2, [w, i, lsl #3]+ mul l1, c1, t1+ adcs t2, t2, l2+ umulh l2, c1, t1+ adc l2, l2, xzr+ adds t2, t2, l1+ sub l1, i, #1+ str t2, [w, l1, lsl #3]+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_wmontloop+Lbignum_modinv_wmontend:+ adcs l2, l2, h1+ adc h1, xzr, xzr+ sub l1, i, #1+ str l2, [w, l1, lsl #3]++ subs i, xzr, xzr+Lbignum_modinv_wcmploop:+ ldr t1, [w, i, lsl #3]+ ldr t2, [b, i, lsl #3]+ sbcs xzr, t1, t2+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_wcmploop++ sbcs xzr, h1, xzr+ csetm h1, cs++ subs i, xzr, xzr+Lbignum_modinv_wcorrloop:+ ldr t1, [w, i, lsl #3]+ ldr t2, [b, i, lsl #3]+ and t2, t2, h1+ sbcs t1, t1, t2+ str t1, [w, i, lsl #3]+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_wcorrloop++// Do a Montgomery reduction of h2::z++ ldr t1, [z]+ mul c1, t1, v+ ldr t2, [b]+ mul l1, c1, t2+ umulh l2, c1, t2+ adds t1, t1, l1 // Will be zero but want the carry++ mov i, #1+ sub t1, k, #1+ cbz t1, Lbignum_modinv_zmontend+Lbignum_modinv_zmontloop:+ ldr t1, [b, i, lsl #3]+ ldr t2, [z, i, lsl #3]+ mul l1, c1, t1+ adcs t2, t2, l2+ umulh l2, c1, t1+ adc l2, l2, xzr+ adds t2, t2, l1+ sub l1, i, #1+ str t2, [z, l1, lsl #3]+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_zmontloop+Lbignum_modinv_zmontend:+ adcs l2, l2, h2+ adc h2, xzr, xzr+ sub l1, i, #1+ str l2, [z, l1, lsl #3]++ subs i, xzr, xzr+Lbignum_modinv_zcmploop:+ ldr t1, [z, i, lsl #3]+ ldr t2, [b, i, lsl #3]+ sbcs xzr, t1, t2+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_zcmploop++ sbcs xzr, h2, xzr+ csetm h2, cs++ subs i, xzr, xzr+Lbignum_modinv_zcorrloop:+ ldr t1, [z, i, lsl #3]+ ldr t2, [b, i, lsl #3]+ and t2, t2, h2+ sbcs t1, t1, t2+ str t1, [z, i, lsl #3]+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_zcorrloop++// Now actually compute the updates to m and n corresponding to the matrix,+// and correct the signs if they have gone negative. First we compute the+// (k+1)-sized updates with the following invariant (here c1 and c2 are in+// fact carry bitmasks, either 0 or -1):+//+// c1::h1::m = m_m * m - m_n * n+// c2::h2::n = n_m * m - n_n * n++ mov h1, xzr+ mov h2, xzr+ mov c1, xzr+ mov c2, xzr+ mov i, xzr+Lbignum_modinv_crossloop:+ ldr t1, [m, i, lsl #3]+ ldr t2, [n, i, lsl #3]++ mul l1, m_m, t1+ mul l2, m_n, t2+ adds l1, l1, h1+ umulh h1, m_m, t1+ adc h1, h1, xzr+ subs l1, l1, l2+ str l1, [m, i, lsl #3]+ umulh l1, m_n, t2+ sub c1, l1, c1+ sbcs h1, h1, c1+ csetm c1, cc++ mul l1, n_m, t1+ mul l2, n_n, t2+ adds l1, l1, h2+ umulh h2, n_m, t1+ adc h2, h2, xzr+ subs l1, l1, l2+ str l1, [n, i, lsl #3]+ umulh l1, n_n, t2+ sub c2, l1, c2+ sbcs h2, h2, c2+ csetm c2, cc++ add i, i, #1+ cmp i, l+ bcc Lbignum_modinv_crossloop++// Write back m optionally negated and shifted right CHUNKSIZE bits++ adds xzr, c1, c1++ ldr l1, [m]+ mov i, xzr+ sub j, l, #1+ cbz j, Lbignum_modinv_negskip1++Lbignum_modinv_negloop1:+ add t1, i, #8+ ldr t2, [m, t1]+ extr l1, t2, l1, #CHUNKSIZE+ eor l1, l1, c1+ adcs l1, l1, xzr+ str l1, [m, i]+ mov l1, t2+ add i, i, #8+ sub j, j, #1+ cbnz j, Lbignum_modinv_negloop1+Lbignum_modinv_negskip1:+ extr l1, h1, l1, #CHUNKSIZE+ eor l1, l1, c1+ adcs l1, l1, xzr+ str l1, [m, i]++// Write back n optionally negated and shifted right CHUNKSIZE bits++ adds xzr, c2, c2++ ldr l1, [n]+ mov i, xzr+ sub j, l, #1+ cbz j, Lbignum_modinv_negskip2+Lbignum_modinv_negloop2:+ add t1, i, #8+ ldr t2, [n, t1]+ extr l1, t2, l1, #CHUNKSIZE+ eor l1, l1, c2+ adcs l1, l1, xzr+ str l1, [n, i]+ mov l1, t2+ add i, i, #8+ sub j, j, #1+ cbnz j, Lbignum_modinv_negloop2+Lbignum_modinv_negskip2:+ extr l1, h2, l1, #CHUNKSIZE+ eor l1, l1, c2+ adcs l1, l1, xzr+ str l1, [n, i]++// Finally, use the signs c1 and c2 to do optional modular negations of+// w and z respectively, flipping c2 to make signs work. We don't make+// any checks for zero values, but we certainly retain w <= b and z <= b.+// This is enough for the Montgomery step in the next iteration to give+// strict reduction w < b amd z < b, and anyway when we terminate we+// could not have z = b since it violates the coprimality assumption for+// in-scope cases.++ mov i, xzr+ adds xzr, c1, c1+Lbignum_modinv_wfliploop:+ ldr t1, [b, i, lsl #3]+ ldr t2, [w, i, lsl #3]+ and t1, t1, c1+ eor t2, t2, c1+ adcs t1, t1, t2+ str t1, [w, i, lsl #3]+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_wfliploop++ mvn c2, c2++ mov i, xzr+ adds xzr, c2, c2+Lbignum_modinv_zfliploop:+ ldr t1, [b, i, lsl #3]+ ldr t2, [z, i, lsl #3]+ and t1, t1, c2+ eor t2, t2, c2+ adcs t1, t1, t2+ str t1, [z, i, lsl #3]+ add i, i, #1+ sub t1, i, k+ cbnz t1, Lbignum_modinv_zfliploop++// End of main loop. We can stop if t' <= 0 since then m * n < 2^0, which+// since n is odd and m and n are coprime (in the in-scope cases) means+// m = 0, n = 1 and hence from the congruence invariant a * z == 1 (mod b).+// Moreover we do in fact need to maintain strictly t > 0 in the main loop,+// or the computation of the optimized digit bound l could collapse to 0.++ subs t, t, #CHUNKSIZE+ bhi Lbignum_modinv_outerloop++Lbignum_modinv_end:+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_modinv)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_montinv_p384.S view
@@ -0,0 +1,1493 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery inverse modulo p_384 = 2^384 - 2^128 - 2^96 + 2^32 - 1+// Input x[6]; output z[6]+//+// extern void bignum_montinv_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// If the 6-digit input x is coprime to p_384, i.e. is not divisible+// by it, returns z < p_384 such that x * z == 2^768 (mod p_384). This+// is effectively "Montgomery inverse" because if we consider x and z as+// Montgomery forms of X and Z, i.e. x == 2^384 * X and z == 2^384 * Z+// (both mod p_384) then X * Z == 1 (mod p_384). That is, this function+// gives the analog of the modular inverse bignum_inv_p384 but with both+// input and output in the Montgomery domain. Note that x does not need+// to be reduced modulo p_384, but the output always is. If the input+// is divisible (i.e. is 0 or p_384), then there can be no solution to+// the congruence x * z == 2^768 (mod p_384), and z = 0 is returned.+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montinv_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montinv_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montinv_p384)++ .text+ .balign 4++// Size in bytes of a 64-bit word++#define N 8++// Used for the return pointer++#define res x20++// Loop counter and d = 2 * delta value for divstep++#define i x21+#define d x22++// Registers used for matrix element magnitudes and signs++#define m00 x10+#define m01 x11+#define m10 x12+#define m11 x13+#define s00 x14+#define s01 x15+#define s10 x16+#define s11 x17++// Initial carries for combinations++#define car0 x9+#define car1 x19++// Input and output, plain registers treated according to pattern++#define reg0 x0, #0+#define reg1 x1, #0+#define reg2 x2, #0+#define reg3 x3, #0+#define reg4 x4, #0++#define x x1, #0+#define z x0, #0++// Pointer-offset pairs for temporaries on stack+// The u and v variables are 6 words each as expected, but the f and g+// variables are 8 words each -- they need to have at least one extra+// word for a sign word, and to preserve alignment we "round up" to 8.+// In fact, we currently keep an extra word in u and v as well.++#define f sp, #0+#define g sp, #(8*N)+#define u sp, #(16*N)+#define v sp, #(24*N)++// Total size to reserve on the stack++#define NSPACE 32*N++// ---------------------------------------------------------------------------+// Core signed almost-Montgomery reduction macro. Takes input in+// [d6;d5;d4;d3;d2;d1;d0] and returns result in [d6;d5d4;d3;d2;d1], adding+// to the existing [d6;d5;d4;d3;d2;d1], and re-using d0 as a temporary+// internally as well as t0, t1, t2. This is almost-Montgomery, i.e. the+// result fits in 6 digits but is not necessarily strictly reduced mod p_384.+// ---------------------------------------------------------------------------++#define amontred(d6,d5,d4,d3,d2,d1,d0, t3,t2,t1) \+/* We only know the input is -2^444 < x < 2^444. To do traditional */ \+/* unsigned Montgomery reduction, start by adding 2^61 * p_384. */ \+ mov t1, #0xe000000000000000 __LF \+ adds d0, d0, t1 __LF \+ mov t2, #0x000000001fffffff __LF \+ adcs d1, d1, t2 __LF \+ mov t3, #0xffffffffe0000000 __LF \+ bic t3, t3, #0x2000000000000000 __LF \+ adcs d2, d2, t3 __LF \+ sbcs d3, d3, xzr __LF \+ sbcs d4, d4, xzr __LF \+ sbcs d5, d5, xzr __LF \+ mov t1, #0x1fffffffffffffff __LF \+ adc d6, d6, t1 __LF \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+/* Store it back into d0 since we no longer need that digit. */ \+ add d0, d0, d0, lsl #32 __LF \+/* Now let [t3;t2;t1;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel d0 so we don't need it */ \+ mov t1, #0xffffffff00000001 __LF \+ umulh t1, t1, d0 __LF \+ mov t2, #0x00000000ffffffff __LF \+ mul t3, t2, d0 __LF \+ umulh t2, t2, d0 __LF \+ adds t1, t1, t3 __LF \+ adcs t2, t2, d0 __LF \+ cset t3, cs __LF \+/* Now x + p_384 * w = (x + 2^384 * w) - (2^384 - p_384) * w */ \+/* We catch the net top carry from add-subtract in the digit d0 */ \+ adds d6, d6, d0 __LF \+ cset d0, cs __LF \+ subs d1, d1, t1 __LF \+ sbcs d2, d2, t2 __LF \+ sbcs d3, d3, t3 __LF \+ sbcs d4, d4, xzr __LF \+ sbcs d5, d5, xzr __LF \+ sbcs d6, d6, xzr __LF \+ sbcs d0, d0, xzr __LF \+/* Now if d0 is nonzero we subtract p_384 (almost-Montgomery) */ \+ neg d0, d0 __LF \+ and t1, d0, #0x00000000ffffffff __LF \+ and t2, d0, #0xffffffff00000000 __LF \+ and t3, d0, #0xfffffffffffffffe __LF \+ subs d1, d1, t1 __LF \+ sbcs d2, d2, t2 __LF \+ sbcs d3, d3, t3 __LF \+ sbcs d4, d4, d0 __LF \+ sbcs d5, d5, d0 __LF \+ sbc d6, d6, d0++// Very similar to a subroutine call to the s2n-bignum word_divstep59.+// But different in register usage and returning the final matrix in+// registers as follows+//+// [ m00 m01]+// [ m10 m11]++#define divstep59() \+ and x4, x2, #0xfffff __LF \+ orr x4, x4, #0xfffffe0000000000 __LF \+ and x5, x3, #0xfffff __LF \+ orr x5, x5, #0xc000000000000000 __LF \+ tst x5, #0x1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ asr x5, x5, #1 __LF \+ add x8, x4, #0x100, lsl #12 __LF \+ sbfx x8, x8, #21, #21 __LF \+ mov x11, #0x100000 __LF \+ add x11, x11, x11, lsl #21 __LF \+ add x9, x4, x11 __LF \+ asr x9, x9, #42 __LF \+ add x10, x5, #0x100, lsl #12 __LF \+ sbfx x10, x10, #21, #21 __LF \+ add x11, x5, x11 __LF \+ asr x11, x11, #42 __LF \+ mul x6, x8, x2 __LF \+ mul x7, x9, x3 __LF \+ mul x2, x10, x2 __LF \+ mul x3, x11, x3 __LF \+ add x4, x6, x7 __LF \+ add x5, x2, x3 __LF \+ asr x2, x4, #20 __LF \+ asr x3, x5, #20 __LF \+ and x4, x2, #0xfffff __LF \+ orr x4, x4, #0xfffffe0000000000 __LF \+ and x5, x3, #0xfffff __LF \+ orr x5, x5, #0xc000000000000000 __LF \+ tst x5, #0x1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ asr x5, x5, #1 __LF \+ add x12, x4, #0x100, lsl #12 __LF \+ sbfx x12, x12, #21, #21 __LF \+ mov x15, #0x100000 __LF \+ add x15, x15, x15, lsl #21 __LF \+ add x13, x4, x15 __LF \+ asr x13, x13, #42 __LF \+ add x14, x5, #0x100, lsl #12 __LF \+ sbfx x14, x14, #21, #21 __LF \+ add x15, x5, x15 __LF \+ asr x15, x15, #42 __LF \+ mul x6, x12, x2 __LF \+ mul x7, x13, x3 __LF \+ mul x2, x14, x2 __LF \+ mul x3, x15, x3 __LF \+ add x4, x6, x7 __LF \+ add x5, x2, x3 __LF \+ asr x2, x4, #20 __LF \+ asr x3, x5, #20 __LF \+ and x4, x2, #0xfffff __LF \+ orr x4, x4, #0xfffffe0000000000 __LF \+ and x5, x3, #0xfffff __LF \+ orr x5, x5, #0xc000000000000000 __LF \+ tst x5, #0x1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ mul x2, x12, x8 __LF \+ mul x3, x12, x9 __LF \+ mul x6, x14, x8 __LF \+ mul x7, x14, x9 __LF \+ madd x8, x13, x10, x2 __LF \+ madd x9, x13, x11, x3 __LF \+ madd x16, x15, x10, x6 __LF \+ madd x17, x15, x11, x7 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ tst x5, #0x2 __LF \+ asr x5, x5, #1 __LF \+ csel x6, x4, xzr, ne __LF \+ ccmp x1, xzr, #0x8, ne __LF \+ cneg x1, x1, ge __LF \+ cneg x6, x6, ge __LF \+ csel x4, x5, x4, ge __LF \+ add x5, x5, x6 __LF \+ add x1, x1, #0x2 __LF \+ asr x5, x5, #1 __LF \+ add x12, x4, #0x100, lsl #12 __LF \+ sbfx x12, x12, #22, #21 __LF \+ mov x15, #0x100000 __LF \+ add x15, x15, x15, lsl #21 __LF \+ add x13, x4, x15 __LF \+ asr x13, x13, #43 __LF \+ add x14, x5, #0x100, lsl #12 __LF \+ sbfx x14, x14, #22, #21 __LF \+ add x15, x5, x15 __LF \+ asr x15, x15, #43 __LF \+ mneg x2, x12, x8 __LF \+ mneg x3, x12, x9 __LF \+ mneg x4, x14, x8 __LF \+ mneg x5, x14, x9 __LF \+ msub m00, x13, x16, x2 __LF \+ msub m01, x13, x17, x3 __LF \+ msub m10, x15, x16, x4 __LF \+ msub m11, x15, x17, x5++S2N_BN_SYMBOL(bignum_montinv_p384):+ CFI_START++// Save registers and make room for temporaries++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(NSPACE)++// Save the return pointer for the end so we can overwrite x0 later++ mov res, x0++// Copy the prime and input into the main f and g variables respectively.+// Make sure x is reduced so that g <= f as assumed in the bound proof.++ mov x10, #0x00000000ffffffff+ mov x11, #0xffffffff00000000+ mov x12, #0xfffffffffffffffe+ mov x15, #0xffffffffffffffff+ stp x10, x11, [f]+ stp x12, x15, [f+2*N]+ stp x15, x15, [f+4*N]+ str xzr, [f+6*N]++ ldp x2, x3, [x1]+ subs x10, x2, x10+ sbcs x11, x3, x11+ ldp x4, x5, [x1, #(2*N)]+ sbcs x12, x4, x12+ sbcs x13, x5, x15+ ldp x6, x7, [x1, #(4*N)]+ sbcs x14, x6, x15+ sbcs x15, x7, x15++ csel x2, x2, x10, cc+ csel x3, x3, x11, cc+ csel x4, x4, x12, cc+ csel x5, x5, x13, cc+ csel x6, x6, x14, cc+ csel x7, x7, x15, cc++ stp x2, x3, [g]+ stp x4, x5, [g+2*N]+ stp x6, x7, [g+4*N]+ str xzr, [g+6*N]++// Also maintain reduced < 2^384 vector [u,v] such that+// [f,g] == x * 2^{5*i-843} * [u,v] (mod p_384)+// starting with [p_384,x] == x * 2^{5*0-843} * [0,2^843] (mod p_384)+// The weird-looking 5*i modifications come in because we are doing+// 64-bit word-sized Montgomery reductions at each stage, which is+// 5 bits more than the 59-bit requirement to keep things stable.+// After the 15th and last iteration and sign adjustment, when+// f == 1 for in-scope cases, we have x * 2^{75-843} * u == 1, i.e.+// x * u == 2^768 as required.++ stp xzr, xzr, [u]+ stp xzr, xzr, [u+2*N]+ stp xzr, xzr, [u+4*N]++// The starting constant 2^843 mod p_384 is+// 0x0000000000000800:00001000000007ff:fffff00000000000+// :00001000000007ff:fffff00000000800:0000000000000000+// where colons separate 64-bit subwords, least significant at the right.+// Not all of these are single loads on ARM so this is a bit dynamic++ mov x12, #0xfffff00000000000+ orr x10, x12, #0x0000000000000800+ stp xzr, x10, [v]+ mov x11, #0x00000000000007ff+ orr x11, x11, #0x0000100000000000+ stp x11, x12, [v+2*N]+ mov x12, #0x0000000000000800+ stp x11, x12, [v+4*N]++// Start of main loop. We jump into the middle so that the divstep+// portion is common to the special fifteenth iteration after a uniform+// first 14.++ mov i, #15+ mov d, #1+ b Lbignum_montinv_p384_midloop++Lbignum_montinv_p384_loop:++// Separate the matrix elements into sign-magnitude pairs++ cmp m00, xzr+ csetm s00, mi+ cneg m00, m00, mi++ cmp m01, xzr+ csetm s01, mi+ cneg m01, m01, mi++ cmp m10, xzr+ csetm s10, mi+ cneg m10, m10, mi++ cmp m11, xzr+ csetm s11, mi+ cneg m11, m11, mi++// Adjust the initial values to allow for complement instead of negation+// This initial offset is the same for [f,g] and [u,v] compositions.+// Save it in stable registers for the [u,v] part and do [f,g] first.++ and x0, m00, s00+ and x1, m01, s01+ add car0, x0, x1++ and x0, m10, s10+ and x1, m11, s11+ add car1, x0, x1++// Now the computation of the updated f and g values. This maintains a+// 2-word carry between stages so we can conveniently insert the shift+// right by 59 before storing back, and not overwrite digits we need+// again of the old f and g values.+//+// Digit 0 of [f,g]++ ldr x7, [f]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, car0, x0+ adc x2, xzr, x1+ ldr x8, [g]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ adc x2, x2, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, car1, x0+ adc x3, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ adc x3, x3, x1++// Digit 1 of [f,g]++ ldr x7, [f+N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [g+N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [f]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [g]++// Digit 2 of [f,g]++ ldr x7, [f+2*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [g+2*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [f+N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [g+N]++// Digit 3 of [f,g]++ ldr x7, [f+3*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, xzr, x1+ ldr x8, [g+3*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [f+2*N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x2, x2, x0+ adc x6, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [g+2*N]++// Digit 4 of [f,g]++ ldr x7, [f+4*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x3, x3, x0+ adc x4, xzr, x1+ ldr x8, [g+4*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [f+3*N]++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x6, x6, x0+ adc x5, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [g+3*N]++// Digits 5 and 6 of [f,g]++ ldr x7, [f+5*N]+ eor x1, x7, s00+ ldr x23, [f+6*N]+ eor x2, x23, s00+ and x2, x2, m00+ neg x2, x2+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, x4, x0+ adc x2, x2, x1+ ldr x8, [g+5*N]+ eor x1, x8, s01+ ldr x24, [g+6*N]+ eor x0, x24, s01+ and x0, x0, m01+ sub x2, x2, x0+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [f+4*N]+ extr x4, x2, x4, #59+ str x4, [f+5*N]+ asr x2, x2, #59+ str x2, [f+6*N]++ eor x1, x7, s10+ eor x4, x23, s10+ and x4, x4, m10+ neg x4, x4+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, x5, x0+ adc x4, x4, x1+ eor x1, x8, s11+ eor x0, x24, s11+ and x0, x0, m11+ sub x4, x4, x0+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ adc x4, x4, x1+ extr x6, x5, x6, #59+ str x6, [g+4*N]+ extr x5, x4, x5, #59+ str x5, [g+5*N]+ asr x4, x4, #59+ str x4, [g+6*N]++// Now the computation of the updated u and v values and their+// Montgomery reductions. A very similar accumulation except that+// the top words of u and v are unsigned and we don't shift.+//+// Digit 0 of [u,v]++ ldr x7, [u]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, car0, x0+ adc x2, xzr, x1+ ldr x8, [v]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u]+ adc x2, x2, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, car1, x0+ adc x3, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ str x5, [v]+ adc x3, x3, x1++// Digit 1 of [u,v]++ ldr x7, [u+N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [v+N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ str x2, [u+N]+ adc x6, x6, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x3, x3, x0+ str x3, [v+N]+ adc x4, x4, x1++// Digit 2 of [u,v]++ ldr x7, [u+2*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [v+2*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ str x6, [u+2*N]+ adc x5, x5, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x4, x4, x0+ str x4, [v+2*N]+ adc x2, x2, x1++// Digit 3 of [u,v]++ ldr x7, [u+3*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, xzr, x1+ ldr x8, [v+3*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ str x5, [u+3*N]+ adc x3, x3, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x2, x2, x0+ adc x6, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x2, x2, x0+ str x2, [v+3*N]+ adc x6, x6, x1++// Digit 4 of [u,v]++ ldr x7, [u+4*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x3, x3, x0+ adc x4, xzr, x1+ ldr x8, [v+4*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x3, x3, x0+ str x3, [u+4*N]+ adc x4, x4, x1++ eor x1, x7, s10+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x6, x6, x0+ adc x5, xzr, x1+ eor x1, x8, s11+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x6, x6, x0+ str x6, [v+4*N]+ adc x5, x5, x1++// Digits 5 and 6 of [u,v] (top is unsigned)++ ldr x7, [u+5*N]+ eor x1, x7, s00+ and x2, s00, m00+ neg x2, x2+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, x4, x0+ adc x2, x2, x1+ ldr x8, [v+5*N]+ eor x1, x8, s01+ and x0, s01, m01+ sub x2, x2, x0+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u+5*N]+ adc x2, x2, x1+ str x2, [u+6*N]++ eor x1, x7, s10+ and x4, s10, m10+ neg x4, x4+ mul x0, x1, m10+ umulh x1, x1, m10+ adds x5, x5, x0+ adc x4, x4, x1+ eor x1, x8, s11+ and x0, s11, m11+ sub x4, x4, x0+ mul x0, x1, m11+ umulh x1, x1, m11+ adds x5, x5, x0+ str x5, [v+5*N]+ adc x4, x4, x1+ str x4, [v+6*N]++// Montgomery reduction of u++ ldp x0, x1, [u]+ ldp x2, x3, [u+16]+ ldp x4, x5, [u+32]+ ldr x6, [u+48]+ amontred(x6,x5,x4,x3,x2,x1,x0, x9,x8,x7)+ stp x1, x2, [u]+ stp x3, x4, [u+16]+ stp x5, x6, [u+32]++// Montgomery reduction of v++ ldp x0, x1, [v]+ ldp x2, x3, [v+16]+ ldp x4, x5, [v+32]+ ldr x6, [v+48]+ amontred(x6,x5,x4,x3,x2,x1,x0, x9,x8,x7)+ stp x1, x2, [v]+ stp x3, x4, [v+16]+ stp x5, x6, [v+32]++Lbignum_montinv_p384_midloop:++ mov x1, d+ ldr x2, [f]+ ldr x3, [g]+ divstep59()+ mov d, x1++// Next iteration++ subs i, i, #1+ bne Lbignum_montinv_p384_loop++// The 15th and last iteration does not need anything except the+// u value and the sign of f; the latter can be obtained from the+// lowest word of f. So it's done differently from the main loop.+// Find the sign of the new f. For this we just need one digit+// since we know (for in-scope cases) that f is either +1 or -1.+// We don't explicitly shift right by 59 either, but looking at+// bit 63 (or any bit >= 60) of the unshifted result is enough+// to distinguish -1 from +1; this is then made into a mask.++ ldr x0, [f]+ ldr x1, [g]+ mul x0, x0, m00+ madd x1, x1, m01, x0+ asr x0, x1, #63++// Now separate out the matrix into sign-magnitude pairs+// and adjust each one based on the sign of f.+//+// Note that at this point we expect |f|=1 and we got its+// sign above, so then since [f,0] == x * 2^{-768} [u,v] (mod p_384)+// we want to flip the sign of u according to that of f.++ cmp m00, xzr+ csetm s00, mi+ cneg m00, m00, mi+ eor s00, s00, x0++ cmp m01, xzr+ csetm s01, mi+ cneg m01, m01, mi+ eor s01, s01, x0++ cmp m10, xzr+ csetm s10, mi+ cneg m10, m10, mi+ eor s10, s10, x0++ cmp m11, xzr+ csetm s11, mi+ cneg m11, m11, mi+ eor s11, s11, x0++// Adjust the initial value to allow for complement instead of negation++ and x0, m00, s00+ and x1, m01, s01+ add car0, x0, x1++// Digit 0 of [u]++ ldr x7, [u]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, car0, x0+ adc x2, xzr, x1+ ldr x8, [v]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u]+ adc x2, x2, x1++// Digit 1 of [u]++ ldr x7, [u+N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [v+N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x2, x2, x0+ str x2, [u+N]+ adc x6, x6, x1++// Digit 2 of [u]++ ldr x7, [u+2*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [v+2*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x6, x6, x0+ str x6, [u+2*N]+ adc x5, x5, x1++// Digit 3 of [u]++ ldr x7, [u+3*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x5, x5, x0+ adc x3, xzr, x1+ ldr x8, [v+3*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x5, x5, x0+ str x5, [u+3*N]+ adc x3, x3, x1++// Digit 4 of [u]++ ldr x7, [u+4*N]+ eor x1, x7, s00+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x3, x3, x0+ adc x4, xzr, x1+ ldr x8, [v+4*N]+ eor x1, x8, s01+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x3, x3, x0+ str x3, [u+4*N]+ adc x4, x4, x1++// Digits 5 and 6 of [u] (top is unsigned)++ ldr x7, [u+5*N]+ eor x1, x7, s00+ and x2, s00, m00+ neg x2, x2+ mul x0, x1, m00+ umulh x1, x1, m00+ adds x4, x4, x0+ adc x2, x2, x1+ ldr x8, [v+5*N]+ eor x1, x8, s01+ and x0, s01, m01+ sub x2, x2, x0+ mul x0, x1, m01+ umulh x1, x1, m01+ adds x4, x4, x0+ str x4, [u+5*N]+ adc x2, x2, x1+ str x2, [u+6*N]++// Montgomery reduction of u. This needs to be strict not "almost"+// so it is followed by an optional subtraction of p_384++ ldp x10, x0, [u]+ ldp x1, x2, [u+16]+ ldp x3, x4, [u+32]+ ldr x5, [u+48]+ amontred(x5,x4,x3,x2,x1,x0,x10, x9,x8,x7)++ mov x10, #0x00000000ffffffff+ subs x10, x0, x10+ mov x11, #0xffffffff00000000+ sbcs x11, x1, x11+ mov x12, #0xfffffffffffffffe+ sbcs x12, x2, x12+ mov x15, #0xffffffffffffffff+ sbcs x13, x3, x15+ sbcs x14, x4, x15+ sbcs x15, x5, x15++ csel x0, x0, x10, cc+ csel x1, x1, x11, cc+ csel x2, x2, x12, cc+ csel x3, x3, x13, cc+ csel x4, x4, x14, cc+ csel x5, x5, x15, cc++// Store it back to the final output++ stp x0, x1, [res]+ stp x2, x3, [res, #16]+ stp x4, x5, [res, #32]++// Restore stack and registers++ CFI_INC_SP(NSPACE)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montinv_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/bignum_montmul_p384.S view
@@ -0,0 +1,891 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery multiply, z := (x * y / 2^384) mod p_384+// Inputs x[6], y[6]; output z[6]+//+// extern void bignum_montmul_p384(uint64_t z[static 6],+// const uint64_t x[static 6],+// const uint64_t y[static 6]);+//+// Does z := (2^{-384} * x * y) mod p_384, assuming that the inputs x and y+// satisfy x * y <= 2^384 * p_384 (in particular this is true if we are in+// the "usual" case x < p_384 and y < p_384).+//+// Standard ARM ABI: X0 = z, X1 = x, X2 = y+// ----------------------------------------------------------------------------++// bignum_montmul_p384 is functionally equivalent to+// unopt/bignum_montmul_p384_base.+// It is written in a way that+// 1. A subset of scalar multiplications in bignum_montmul_p384 are carefully+// chosen and vectorized+// 2. The vectorized assembly is rescheduled using the SLOTHY superoptimizer.+// https://github.com/slothy-optimizer/slothy+//+// The output program of step 1. is as follows:+//+// stp x19, x20, [sp, #-16]!+// stp x21, x22, [sp, #-16]!+// stp x23, x24, [sp, #-16]!+// ldp x3, x21, [x1]+// ldr q30, [x1]+// ldp x8, x24, [x1, #16]+// ldp x5, x10, [x1, #32]+// ldp x13, x23, [x2]+// ldr q19, [x2]+// ldp x6, x14, [x2, #16]+// ldp x15, x17, [x2, #32]+// ldr q1, [x1, #32]+// ldr q28, [x2, #32]+// uzp1 v5.4S, v19.4S, v30.4S+// rev64 v19.4S, v19.4S+// uzp1 v0.4S, v30.4S, v30.4S+// mul v21.4S, v19.4S, v30.4S+// uaddlp v19.2D, v21.4S+// shl v19.2D, v19.2D, #32+// umlal v19.2D, v0.2S, v5.2S+// mov x12, v19.d[0]+// mov x16, v19.d[1]+// mul x20, x8, x6+// umulh x4, x3, x13+// umulh x1, x21, x23+// umulh x2, x8, x6+// adds x4, x4, x16+// adcs x19, x1, x20+// adc x20, x2, xzr+// adds x11, x4, x12+// adcs x16, x19, x4+// adcs x1, x20, x19+// adc x2, x20, xzr+// adds x7, x16, x12+// adcs x4, x1, x4+// adcs x9, x2, x19+// adc x19, x20, xzr+// subs x2, x3, x21+// cneg x20, x2, cc+// csetm x16, cc+// subs x2, x23, x13+// cneg x2, x2, cc+// mul x1, x20, x2+// umulh x2, x20, x2+// cinv x16, x16, cc+// eor x1, x1, x16+// eor x2, x2, x16+// cmn x16, #0x1+// adcs x11, x11, x1+// adcs x7, x7, x2+// adcs x4, x4, x16+// adcs x9, x9, x16+// adc x19, x19, x16+// subs x2, x3, x8+// cneg x20, x2, cc+// csetm x16, cc+// subs x2, x6, x13+// cneg x2, x2, cc+// mul x1, x20, x2+// umulh x2, x20, x2+// cinv x16, x16, cc+// eor x1, x1, x16+// eor x2, x2, x16+// cmn x16, #0x1+// adcs x7, x7, x1+// adcs x4, x4, x2+// adcs x9, x9, x16+// adc x19, x19, x16+// subs x2, x21, x8+// cneg x20, x2, cc+// csetm x16, cc+// subs x2, x6, x23+// cneg x2, x2, cc+// mul x1, x20, x2+// umulh x2, x20, x2+// cinv x16, x16, cc+// eor x1, x1, x16+// eor x2, x2, x16+// cmn x16, #0x1+// adcs x4, x4, x1+// adcs x20, x9, x2+// adc x16, x19, x16+// lsl x2, x12, #32+// add x19, x2, x12+// lsr x2, x19, #32+// subs x1, x2, x19+// sbc x2, x19, xzr+// extr x1, x2, x1, #32+// lsr x2, x2, #32+// adds x12, x2, x19+// adc x2, xzr, xzr+// subs x1, x11, x1+// sbcs x7, x7, x12+// sbcs x4, x4, x2+// sbcs x20, x20, xzr+// sbcs x16, x16, xzr+// sbc x9, x19, xzr+// lsl x2, x1, #32+// add x19, x2, x1+// lsr x2, x19, #32+// subs x1, x2, x19+// sbc x2, x19, xzr+// extr x1, x2, x1, #32+// lsr x2, x2, #32+// adds x12, x2, x19+// adc x2, xzr, xzr+// subs x1, x7, x1+// sbcs x4, x4, x12+// sbcs x20, x20, x2+// sbcs x16, x16, xzr+// sbcs x7, x9, xzr+// sbc x9, x19, xzr+// lsl x2, x1, #32+// add x19, x2, x1+// lsr x2, x19, #32+// subs x1, x2, x19+// sbc x2, x19, xzr+// extr x12, x2, x1, #32+// lsr x2, x2, #32+// adds x1, x2, x19+// adc x2, xzr, xzr+// subs x4, x4, x12+// sbcs x20, x20, x1+// sbcs x16, x16, x2+// sbcs x12, x7, xzr+// sbcs x1, x9, xzr+// sbc x2, x19, xzr+// stp x4, x20, [x0] // @slothy:writes=buffer0+// stp x16, x12, [x0, #16] // @slothy:writes=buffer16+// stp x1, x2, [x0, #32] // @slothy:writes=buffer32+// mul x22, x24, x14+// movi v31.2D, #0x00000000ffffffff+// uzp2 v16.4S, v28.4S, v28.4S+// xtn v6.2S, v1.2D+// xtn v30.2S, v28.2D+// rev64 v28.4S, v28.4S+// umull v5.2D, v6.2S, v30.2S+// umull v0.2D, v6.2S, v16.2S+// uzp2 v19.4S, v1.4S, v1.4S+// mul v20.4S, v28.4S, v1.4S+// usra v0.2D, v5.2D, #32+// umull v1.2D, v19.2S, v16.2S+// uaddlp v24.2D, v20.4S+// and v5.16B, v0.16B, v31.16B+// umlal v5.2D, v19.2S, v30.2S+// shl v19.2D, v24.2D, #32+// usra v1.2D, v0.2D, #32+// umlal v19.2D, v6.2S, v30.2S+// usra v1.2D, v5.2D, #32+// mov x20, v19.d[0]+// mov x16, v19.d[1]+// umulh x12, x24, x14+// mov x1, v1.d[0]+// mov x2, v1.d[1]+// adds x4, x12, x20+// adcs x20, x1, x16+// adc x16, x2, xzr+// adds x7, x4, x22+// adcs x12, x20, x4+// adcs x1, x16, x20+// adc x2, x16, xzr+// adds x9, x12, x22+// adcs x19, x1, x4+// adcs x4, x2, x20+// adc x20, x16, xzr+// subs x2, x24, x5+// cneg x16, x2, cc+// csetm x12, cc+// subs x2, x15, x14+// cneg x2, x2, cc+// mul x1, x16, x2+// umulh x2, x16, x2+// cinv x12, x12, cc+// eor x1, x1, x12+// eor x2, x2, x12+// cmn x12, #0x1+// adcs x11, x7, x1+// adcs x9, x9, x2+// adcs x19, x19, x12+// adcs x4, x4, x12+// adc x20, x20, x12+// subs x2, x24, x10+// cneg x16, x2, cc+// csetm x12, cc+// subs x2, x17, x14+// cneg x2, x2, cc+// mul x1, x16, x2+// umulh x2, x16, x2+// cinv x12, x12, cc+// eor x1, x1, x12+// eor x2, x2, x12+// cmn x12, #0x1+// adcs x7, x9, x1+// adcs x19, x19, x2+// adcs x4, x4, x12+// adc x20, x20, x12+// subs x2, x5, x10+// cneg x16, x2, cc+// csetm x12, cc+// subs x2, x17, x15+// cneg x2, x2, cc+// mul x1, x16, x2+// umulh x2, x16, x2+// cinv x16, x12, cc+// eor x1, x1, x16+// eor x2, x2, x16+// cmn x16, #0x1+// adcs x19, x19, x1+// adcs x12, x4, x2+// adc x1, x20, x16+// subs x2, x24, x3+// sbcs x24, x5, x21+// sbcs x21, x10, x8+// ngc x5, xzr+// cmn x5, #0x1+// eor x2, x2, x5+// adcs x4, x2, xzr+// eor x2, x24, x5+// adcs x20, x2, xzr+// eor x2, x21, x5+// adc x16, x2, xzr+// subs x2, x13, x14+// sbcs x24, x23, x15+// sbcs x8, x6, x17+// ngc x21, xzr+// cmn x21, #0x1+// eor x2, x2, x21+// adcs x15, x2, xzr+// eor x2, x24, x21+// adcs x14, x2, xzr+// eor x2, x8, x21+// adc x6, x2, xzr+// eor x9, x5, x21+// ldp x21, x2, [x0] // @slothy:reads=buffer0+// adds x10, x22, x21+// adcs x5, x11, x2+// ldp x21, x2, [x0, #16] // @slothy:reads=buffer16+// adcs x24, x7, x21+// adcs x8, x19, x2+// ldp x21, x2, [x0, #32] // @slothy:reads=buffer32+// adcs x21, x12, x21+// adcs x2, x1, x2+// adc x19, xzr, xzr+// stp x10, x5, [x0] // @slothy:writes=buffer0+// stp x24, x8, [x0, #16] // @slothy:writes=buffer16+// stp x21, x2, [x0, #32] // @slothy:writes=buffer32+// mul x12, x4, x15+// mul x5, x20, x14+// mul x24, x16, x6+// umulh x8, x4, x15+// umulh x21, x20, x14+// umulh x2, x16, x6+// adds x10, x8, x5+// adcs x5, x21, x24+// adc x24, x2, xzr+// adds x23, x10, x12+// adcs x8, x5, x10+// adcs x21, x24, x5+// adc x2, x24, xzr+// adds x13, x8, x12+// adcs x1, x21, x10+// adcs x10, x2, x5+// adc x5, x24, xzr+// subs x2, x4, x20+// cneg x24, x2, cc+// csetm x8, cc+// subs x2, x14, x15+// cneg x2, x2, cc+// mul x21, x24, x2+// umulh x2, x24, x2+// cinv x8, x8, cc+// eor x21, x21, x8+// eor x2, x2, x8+// cmn x8, #0x1+// adcs x23, x23, x21+// adcs x13, x13, x2+// adcs x1, x1, x8+// adcs x10, x10, x8+// adc x5, x5, x8+// subs x2, x4, x16+// cneg x24, x2, cc+// csetm x8, cc+// subs x2, x6, x15+// cneg x2, x2, cc+// mul x21, x24, x2+// umulh x2, x24, x2+// cinv x8, x8, cc+// eor x21, x21, x8+// eor x2, x2, x8+// cmn x8, #0x1+// adcs x4, x13, x21+// adcs x13, x1, x2+// adcs x1, x10, x8+// adc x10, x5, x8+// subs x2, x20, x16+// cneg x24, x2, cc+// csetm x8, cc+// subs x2, x6, x14+// cneg x2, x2, cc+// mul x21, x24, x2+// umulh x2, x24, x2+// cinv x5, x8, cc+// eor x21, x21, x5+// eor x2, x2, x5+// cmn x5, #0x1+// adcs x24, x13, x21+// adcs x8, x1, x2+// adc x21, x10, x5+// ldp x20, x16, [x0] // @slothy:reads=buffer0+// ldp x17, x15, [x0, #16] // @slothy:reads=buffer16+// ldp x14, x6, [x0, #32] // @slothy:reads=buffer32+// cmn x9, #0x1+// eor x2, x12, x9+// adcs x12, x2, x20+// eor x2, x23, x9+// adcs x23, x2, x16+// eor x2, x4, x9+// adcs x13, x2, x17+// eor x2, x24, x9+// adcs x10, x2, x15+// eor x2, x8, x9+// adcs x5, x2, x14+// eor x2, x21, x9+// adcs x24, x2, x6+// adcs x1, x9, x19+// adcs x8, x9, xzr+// adcs x21, x9, xzr+// adc x2, x9, xzr+// adds x10, x10, x20+// adcs x5, x5, x16+// adcs x24, x24, x17+// adcs x17, x1, x15+// adcs x15, x8, x14+// adcs x14, x21, x6+// adc x6, x2, x19+// lsl x2, x12, #32+// add x1, x2, x12+// lsr x2, x1, #32+// subs x21, x2, x1+// sbc x2, x1, xzr+// extr x21, x2, x21, #32+// lsr x2, x2, #32+// adds x8, x2, x1+// adc x2, xzr, xzr+// subs x21, x23, x21+// sbcs x23, x13, x8+// sbcs x10, x10, x2+// sbcs x5, x5, xzr+// sbcs x24, x24, xzr+// sbc x13, x1, xzr+// lsl x2, x21, #32+// add x1, x2, x21+// lsr x2, x1, #32+// subs x21, x2, x1+// sbc x2, x1, xzr+// extr x21, x2, x21, #32+// lsr x2, x2, #32+// adds x8, x2, x1+// adc x2, xzr, xzr+// subs x21, x23, x21+// sbcs x10, x10, x8+// sbcs x5, x5, x2+// sbcs x24, x24, xzr+// sbcs x23, x13, xzr+// sbc x13, x1, xzr+// lsl x2, x21, #32+// add x1, x2, x21+// lsr x2, x1, #32+// subs x21, x2, x1+// sbc x2, x1, xzr+// extr x8, x2, x21, #32+// lsr x2, x2, #32+// adds x21, x2, x1+// adc x2, xzr, xzr+// subs x10, x10, x8+// sbcs x5, x5, x21+// sbcs x24, x24, x2+// sbcs x8, x23, xzr+// sbcs x21, x13, xzr+// sbc x2, x1, xzr+// adds x23, x17, x8+// adcs x13, x15, x21+// adcs x1, x14, x2+// adc x2, x6, xzr+// add x8, x2, #0x1+// lsl x2, x8, #32+// subs x21, x8, x2+// sbc x2, x2, xzr+// adds x10, x10, x21+// adcs x5, x5, x2+// adcs x24, x24, x8+// adcs x8, x23, xzr+// adcs x21, x13, xzr+// adcs x13, x1, xzr+// csetm x1, cc+// mov x2, #0xffffffff+// and x2, x2, x1+// adds x10, x10, x2+// eor x2, x2, x1+// adcs x5, x5, x2+// mov x2, #0xfffffffffffffffe+// and x2, x2, x1+// adcs x24, x24, x2+// adcs x8, x8, x1+// adcs x21, x21, x1+// adc x2, x13, x1+// stp x10, x5, [x0] // @slothy:writes=buffer0+// stp x24, x8, [x0, #16] // @slothy:writes=buffer16+// stp x21, x2, [x0, #32] // @slothy:writes=buffer32+// ldp x23, x24, [sp], #16+// ldp x21, x22, [sp], #16+// ldp x19, x20, [sp], #16+// ret+//+// The bash script used for step 2 is as follows:+//+// # Store the assembly instructions except the last 'ret' and+// # callee-register store/loads as, say, 'input.S'.+// export OUTPUTS="[hint_buffer0,hint_buffer16,hint_buffer32]"+// export RESERVED_REGS="[x18,x25,x26,x27,x28,x29,x30,sp,q8,q9,q10,q11,q12,q13,q14,q15,v8,v9,v10,v11,v12,v13,v14,v15]"+// <s2n-bignum>/tools/external/slothy.sh input.S my_out_dir+// # my_out_dir/3.opt.s is the optimized assembly. Its output may differ+// # from this file since the sequence is non-deterministically chosen.+// # Please add 'ret' at the end of the output assembly.+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montmul_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montmul_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montmul_p384)+ .text+ .balign 4++S2N_BN_SYMBOL(bignum_montmul_p384):+ CFI_START++// Save some registers++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)++ ldr q3, [x1]+ ldr q25, [x2]+ ldp x13, x23, [x2]+ ldp x3, x21, [x1]+ rev64 v23.4S, v25.4S+ uzp1 v17.4S, v25.4S, v3.4S+ umulh x15, x3, x13+ mul v6.4S, v23.4S, v3.4S+ uzp1 v3.4S, v3.4S, v3.4S+ ldr q27, [x2, #32]+ ldp x8, x24, [x1, #16]+ subs x6, x3, x21+ ldr q0, [x1, #32]+ movi v23.2D, #0x00000000ffffffff+ csetm x10, cc+ umulh x19, x21, x23+ rev64 v4.4S, v27.4S+ uzp2 v25.4S, v27.4S, v27.4S+ cneg x4, x6, cc+ subs x7, x23, x13+ xtn v22.2S, v0.2D+ xtn v24.2S, v27.2D+ cneg x20, x7, cc+ ldp x6, x14, [x2, #16]+ mul v27.4S, v4.4S, v0.4S+ uaddlp v20.2D, v6.4S+ cinv x5, x10, cc+ mul x16, x4, x20+ uzp2 v6.4S, v0.4S, v0.4S+ umull v21.2D, v22.2S, v25.2S+ shl v0.2D, v20.2D, #32+ umlal v0.2D, v3.2S, v17.2S+ mul x22, x8, x6+ umull v1.2D, v6.2S, v25.2S+ subs x12, x3, x8+ umull v20.2D, v22.2S, v24.2S+ cneg x17, x12, cc+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc+ usra v21.2D, v20.2D, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2D, v21.2D, #32+ adds x22, x15, x7+ and v26.16B, v21.16B, v23.16B+ adcs x16, x12, x15+ uaddlp v25.2D, v27.4S+ adcs x9, x19, x12+ umlal v26.2D, v6.2S, v24.2S+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2D, v25.2D, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc+ cinv x10, x10, cc+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc+ eor x19, x19, x10+ csetm x4, cc+ subs x16, x6, x23+ cneg x16, x16, cc+ umlal v27.2D, v22.2S, v24.2S+ mul x15, x20, x16+ cinv x4, x4, cc+ cmn x10, #0x1+ usra v1.2D, v26.2D, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [x2, #32]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [x1, #32]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [x0]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [x0, #16]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc+ csetm x2, cc+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc+ cneg x19, x19, cc+ stp x9, x20, [x0, #32]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc+ csetm x12, cc+ subs x9, x17, x14+ cinv x12, x12, cc+ cneg x9, x9, cc+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc+ cneg x24, x10, cc+ subs x10, x17, x15+ cinv x7, x7, cc+ cneg x10, x10, cc+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [x0]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [x0, #16]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [x0, #32]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [x0]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [x0, #16]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [x0, #32]+ cneg x3, x21, cc+ csetm x24, cc+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc+ csetm x16, cc+ subs x21, x6, x15+ cneg x22, x21, cc+ cinv x21, x24, cc+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc+ csetm x24, cc+ subs x20, x14, x15+ cinv x24, x24, cc+ mul x22, x3, x22+ cneg x3, x20, cc+ subs x13, x6, x14+ cneg x20, x13, cc+ cinv x15, x16, cc+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [x0]+ ldp x21, x12, [x0, #16]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [x0, #32]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [x0]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [x0, #16]+ adc x12, x15, x23+ stp x21, x12, [x0, #32]++// Restore registers and return++ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montmul_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_montmul_p384_alt.S view
@@ -0,0 +1,345 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery multiply, z := (x * y / 2^384) mod p_384+// Inputs x[6], y[6]; output z[6]+//+// extern void bignum_montmul_p384_alt(uint64_t z[static 6],+// const uint64_t x[static 6],+// const uint64_t y[static 6]);+//+// Does z := (2^{-384} * x * y) mod p_384, assuming that the inputs x and y+// satisfy x * y <= 2^384 * p_384 (in particular this is true if we are in+// the "usual" case x < p_384 and y < p_384).+//+// Standard ARM ABI: X0 = z, X1 = x, X2 = y+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montmul_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montmul_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montmul_p384_alt)+ .text+ .balign 4++// ---------------------------------------------------------------------------+// Core one-step "short" Montgomery reduction macro. Takes input in+// [d5;d4;d3;d2;d1;d0] and returns result in [d6;d5;d4;d3;d2;d1],+// adding to the existing contents of [d5;d4;d3;d2;d1]. It is fine+// for d6 to be the same register as d0.+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+// ---------------------------------------------------------------------------++#define montreds(d6,d5,d4,d3,d2,d1,d0, t3,t2,t1) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+/* Store it in d6 to make the 2^384 * w contribution already */ \+ lsl t1, d0, #32 __LF \+ add d6, t1, d0 __LF \+/* Now let [t3;t2;t1;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel d0 so we don't need it */ \+ mov t1, #0xffffffff00000001 __LF \+ umulh t1, t1, d6 __LF \+ mov t2, #0x00000000ffffffff __LF \+ mul t3, t2, d6 __LF \+ umulh t2, t2, d6 __LF \+ adds t1, t1, t3 __LF \+ adcs t2, t2, d6 __LF \+ adc t3, xzr, xzr __LF \+/* Now add it, by subtracting from 2^384 * w + x */ \+ subs d1, d1, t1 __LF \+ sbcs d2, d2, t2 __LF \+ sbcs d3, d3, t3 __LF \+ sbcs d4, d4, xzr __LF \+ sbcs d5, d5, xzr __LF \+ sbc d6, d6, xzr+++#define z x0+#define x x1+#define y x2++// These are repeated mod 2 as we load pairs of inputs++#define a0 x3+#define a1 x4+#define a2 x3+#define a3 x4+#define a4 x3+#define a5 x4++#define b0 x5+#define b1 x6+#define b2 x7+#define b3 x8+#define b4 x9+#define b5 x10++#define l x11++#define u0 x12+#define u1 x13+#define u2 x14+#define u3 x15+#define u4 x16+#define u5 x17+#define u6 x19+#define u7 x20+#define u8 x21+#define u9 x22+#define u10 x2 // same as y+#define u11 x1 // same as x+#define h b5 // same as b5++S2N_BN_SYMBOL(bignum_montmul_p384_alt):+ CFI_START++// Save more registers++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)++// Load operands and set up row 0 = [u6;...;u0] = a0 * [b5;...;b0]++ ldp a0, a1, [x]+ ldp b0, b1, [y]++ mul u0, a0, b0+ umulh u1, a0, b0+ mul l, a0, b1+ umulh u2, a0, b1+ adds u1, u1, l++ ldp b2, b3, [y, #16]++ mul l, a0, b2+ umulh u3, a0, b2+ adcs u2, u2, l++ mul l, a0, b3+ umulh u4, a0, b3+ adcs u3, u3, l++ ldp b4, b5, [y, #32]++ mul l, a0, b4+ umulh u5, a0, b4+ adcs u4, u4, l++ mul l, a0, b5+ umulh u6, a0, b5+ adcs u5, u5, l++ adc u6, u6, xzr++// Row 1 = [u7;...;u0] = [a1;a0] * [b5;...;b0]++ mul l, a1, b0+ adds u1, u1, l+ mul l, a1, b1+ adcs u2, u2, l+ mul l, a1, b2+ adcs u3, u3, l+ mul l, a1, b3+ adcs u4, u4, l+ mul l, a1, b4+ adcs u5, u5, l+ mul l, a1, b5+ adcs u6, u6, l+ cset u7, cs++ umulh l, a1, b0+ adds u2, u2, l+ umulh l, a1, b1+ adcs u3, u3, l+ umulh l, a1, b2+ adcs u4, u4, l+ umulh l, a1, b3+ adcs u5, u5, l+ umulh l, a1, b4+ adcs u6, u6, l+ umulh l, a1, b5+ adc u7, u7, l++// Row 2 = [u8;...;u0] = [a2;a1;a0] * [b5;...;b0]++ ldp a2, a3, [x, #16]++ mul l, a2, b0+ adds u2, u2, l+ mul l, a2, b1+ adcs u3, u3, l+ mul l, a2, b2+ adcs u4, u4, l+ mul l, a2, b3+ adcs u5, u5, l+ mul l, a2, b4+ adcs u6, u6, l+ mul l, a2, b5+ adcs u7, u7, l+ cset u8, cs++ umulh l, a2, b0+ adds u3, u3, l+ umulh l, a2, b1+ adcs u4, u4, l+ umulh l, a2, b2+ adcs u5, u5, l+ umulh l, a2, b3+ adcs u6, u6, l+ umulh l, a2, b4+ adcs u7, u7, l+ umulh l, a2, b5+ adc u8, u8, l++// Row 3 = [u9;...;u0] = [a3;a2;a1;a0] * [b5;...;b0]++ mul l, a3, b0+ adds u3, u3, l+ mul l, a3, b1+ adcs u4, u4, l+ mul l, a3, b2+ adcs u5, u5, l+ mul l, a3, b3+ adcs u6, u6, l+ mul l, a3, b4+ adcs u7, u7, l+ mul l, a3, b5+ adcs u8, u8, l+ cset u9, cs++ umulh l, a3, b0+ adds u4, u4, l+ umulh l, a3, b1+ adcs u5, u5, l+ umulh l, a3, b2+ adcs u6, u6, l+ umulh l, a3, b3+ adcs u7, u7, l+ umulh l, a3, b4+ adcs u8, u8, l+ umulh l, a3, b5+ adc u9, u9, l++// Row 4 = [u10;...;u0] = [a4;a3;a2;a1;a0] * [b5;...;b0]++ ldp a4, a5, [x, #32]++ mul l, a4, b0+ adds u4, u4, l+ mul l, a4, b1+ adcs u5, u5, l+ mul l, a4, b2+ adcs u6, u6, l+ mul l, a4, b3+ adcs u7, u7, l+ mul l, a4, b4+ adcs u8, u8, l+ mul l, a4, b5+ adcs u9, u9, l+ cset u10, cs++ umulh l, a4, b0+ adds u5, u5, l+ umulh l, a4, b1+ adcs u6, u6, l+ umulh l, a4, b2+ adcs u7, u7, l+ umulh l, a4, b3+ adcs u8, u8, l+ umulh l, a4, b4+ adcs u9, u9, l+ umulh l, a4, b5+ adc u10, u10, l++// Row 5 = [u11;...;u0] = [a5;a4;a3;a2;a1;a0] * [b5;...;b0]++ mul l, a5, b0+ adds u5, u5, l+ mul l, a5, b1+ adcs u6, u6, l+ mul l, a5, b2+ adcs u7, u7, l+ mul l, a5, b3+ adcs u8, u8, l+ mul l, a5, b4+ adcs u9, u9, l+ mul l, a5, b5+ adcs u10, u10, l+ cset u11, cs++ umulh l, a5, b0+ adds u6, u6, l+ umulh l, a5, b1+ adcs u7, u7, l+ umulh l, a5, b2+ adcs u8, u8, l+ umulh l, a5, b3+ adcs u9, u9, l+ umulh l, a5, b4+ adcs u10, u10, l+ umulh l, a5, b5+ adc u11, u11, l++// Montgomery rotate the low half++ montreds(u0,u5,u4,u3,u2,u1,u0, b0,b1,b2)+ montreds(u1,u0,u5,u4,u3,u2,u1, b0,b1,b2)+ montreds(u2,u1,u0,u5,u4,u3,u2, b0,b1,b2)+ montreds(u3,u2,u1,u0,u5,u4,u3, b0,b1,b2)+ montreds(u4,u3,u2,u1,u0,u5,u4, b0,b1,b2)+ montreds(u5,u4,u3,u2,u1,u0,u5, b0,b1,b2)++// Add up the high and low parts as [h; u5;u4;u3;u2;u1;u0] = z++ adds u0, u0, u6+ adcs u1, u1, u7+ adcs u2, u2, u8+ adcs u3, u3, u9+ adcs u4, u4, u10+ adcs u5, u5, u11+ adc h, xzr, xzr++// Now add [h; u11;u10;u9;u8;u7;u6] = z + (2^384 - p_384)++ mov l, #0xffffffff00000001+ adds u6, u0, l+ mov l, #0x00000000ffffffff+ adcs u7, u1, l+ mov l, #0x0000000000000001+ adcs u8, u2, l+ adcs u9, u3, xzr+ adcs u10, u4, xzr+ adcs u11, u5, xzr+ adcs h, h, xzr++// Now z >= p_384 iff h is nonzero, so select accordingly++ csel u0, u0, u6, eq+ csel u1, u1, u7, eq+ csel u2, u2, u8, eq+ csel u3, u3, u9, eq+ csel u4, u4, u10, eq+ csel u5, u5, u11, eq++// Store back final result++ stp u0, u1, [z]+ stp u2, u3, [z, #16]+ stp u4, u5, [z, #32]++// Restore registers++ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montmul_p384_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_montsqr_p384.S view
@@ -0,0 +1,671 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery square, z := (x^2 / 2^384) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_montsqr_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Does z := (x^2 / 2^384) mod p_384, assuming x^2 <= 2^384 * p_384, which is+// guaranteed in particular if x < p_384 initially (the "intended" case).+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++// bignum_montsqr_p384 is functionally equivalent to+// unopt/bignum_montsqr_p384_base.+// It is written in a way that+// 1. A subset of scalar multiplications in bignum_montsqr_p384 are carefully+// chosen and vectorized+// 2. The vectorized assembly is rescheduled using the SLOTHY superoptimizer.+// https://github.com/slothy-optimizer/slothy+//+// The output program of step 1. is as follows:+//+// ldp x9, x2, [x1]+// ldr q18, [x1]+// ldr q19, [x1]+// ldp x4, x6, [x1, #16]+// ldp x5, x10, [x1, #32]+// ldr q21, [x1, #32]+// ldr q28, [x1, #32]+// mul x12, x9, x2+// mul x1, x9, x4+// mul x13, x2, x4+// movi v0.2D, #0x00000000ffffffff+// uzp2 v5.4S, v19.4S, v19.4S+// xtn v25.2S, v18.2D+// xtn v4.2S, v19.2D+// rev64 v23.4S, v19.4S+// umull v20.2D, v25.2S, v4.2S+// umull v30.2D, v25.2S, v5.2S+// uzp2 v19.4S, v18.4S, v18.4S+// mul v22.4S, v23.4S, v18.4S+// usra v30.2D, v20.2D, #32+// umull v18.2D, v19.2S, v5.2S+// uaddlp v22.2D, v22.4S+// and v20.16B, v30.16B, v0.16B+// umlal v20.2D, v19.2S, v4.2S+// shl v19.2D, v22.2D, #32+// usra v18.2D, v30.2D, #32+// umlal v19.2D, v25.2S, v4.2S+// usra v18.2D, v20.2D, #32+// mov x7, v19.d[0]+// mov x17, v19.d[1]+// mul x16, x4, x4+// umulh x3, x9, x2+// adds x15, x1, x3+// umulh x1, x9, x4+// adcs x13, x13, x1+// umulh x1, x2, x4+// adcs x8, x1, xzr+// mov x11, v18.d[0]+// mov x14, v18.d[1]+// umulh x1, x4, x4+// adds x3, x12, x12+// adcs x15, x15, x15+// adcs x13, x13, x13+// adcs x12, x8, x8+// adc x1, x1, xzr+// adds x11, x11, x3+// adcs x3, x17, x15+// adcs x17, x14, x13+// adcs x15, x16, x12+// adc x13, x1, xzr+// lsl x1, x7, #32+// add x16, x1, x7+// lsr x1, x16, #32+// subs x12, x1, x16+// sbc x1, x16, xzr+// extr x12, x1, x12, #32+// lsr x1, x1, #32+// adds x7, x1, x16+// adc x1, xzr, xzr+// subs x12, x11, x12+// sbcs x11, x3, x7+// sbcs x17, x17, x1+// sbcs x15, x15, xzr+// sbcs x13, x13, xzr+// sbc x3, x16, xzr+// lsl x1, x12, #32+// add x16, x1, x12+// lsr x1, x16, #32+// subs x12, x1, x16+// sbc x1, x16, xzr+// extr x12, x1, x12, #32+// lsr x1, x1, #32+// adds x7, x1, x16+// adc x1, xzr, xzr+// subs x12, x11, x12+// sbcs x17, x17, x7+// sbcs x15, x15, x1+// sbcs x13, x13, xzr+// sbcs x11, x3, xzr+// sbc x3, x16, xzr+// lsl x1, x12, #32+// add x16, x1, x12+// lsr x1, x16, #32+// subs x12, x1, x16+// sbc x1, x16, xzr+// extr x7, x1, x12, #32+// lsr x1, x1, #32+// adds x12, x1, x16+// adc x1, xzr, xzr+// subs x17, x17, x7+// sbcs x15, x15, x12+// sbcs x13, x13, x1+// sbcs x7, x11, xzr+// sbcs x12, x3, xzr+// sbc x1, x16, xzr+// stp x17, x15, [x0] // @slothy:writes=buffer0+// stp x13, x7, [x0, #16] // @slothy:writes=buffer16+// stp x12, x1, [x0, #32] // @slothy:writes=buffer32+// mul x14, x9, x6+// mul x15, x2, x5+// mul x13, x4, x10+// umulh x7, x9, x6+// umulh x12, x2, x5+// umulh x1, x4, x10+// adds x15, x7, x15+// adcs x16, x12, x13+// adc x13, x1, xzr+// adds x11, x15, x14+// adcs x7, x16, x15+// adcs x12, x13, x16+// adc x1, x13, xzr+// adds x17, x7, x14+// adcs x15, x12, x15+// adcs x3, x1, x16+// adc x16, x13, xzr+// subs x1, x9, x2+// cneg x13, x1, cc+// csetm x7, cc+// subs x1, x5, x6+// cneg x1, x1, cc+// mul x12, x13, x1+// umulh x1, x13, x1+// cinv x7, x7, cc+// eor x12, x12, x7+// eor x1, x1, x7+// cmn x7, #0x1+// adcs x11, x11, x12+// adcs x17, x17, x1+// adcs x15, x15, x7+// adcs x3, x3, x7+// adc x16, x16, x7+// subs x9, x9, x4+// cneg x13, x9, cc+// csetm x7, cc+// subs x1, x10, x6+// cneg x1, x1, cc+// mul x12, x13, x1+// umulh x1, x13, x1+// cinv x7, x7, cc+// eor x12, x12, x7+// eor x1, x1, x7+// cmn x7, #0x1+// adcs x17, x17, x12+// adcs x15, x15, x1+// adcs x13, x3, x7+// adc x7, x16, x7+// subs x2, x2, x4+// cneg x12, x2, cc+// csetm x1, cc+// subs x2, x10, x5+// cneg x2, x2, cc+// mul x4, x12, x2+// umulh x2, x12, x2+// cinv x1, x1, cc+// eor x4, x4, x1+// eor x2, x2, x1+// cmn x1, #0x1+// adcs x12, x15, x4+// adcs x4, x13, x2+// adc x2, x7, x1+// adds x1, x14, x14+// adcs x16, x11, x11+// adcs x17, x17, x17+// adcs x15, x12, x12+// adcs x13, x4, x4+// adcs x7, x2, x2+// adc x12, xzr, xzr+// ldp x4, x2, [x0] // @slothy:reads=buffer0+// adds x1, x1, x4+// adcs x16, x16, x2+// ldp x4, x2, [x0, #16] // @slothy:reads=buffer16+// adcs x17, x17, x4+// adcs x15, x15, x2+// ldp x4, x2, [x0, #32] // @slothy:reads=buffer32+// adcs x13, x13, x4+// adcs x7, x7, x2+// adc x11, x12, xzr+// lsl x2, x1, #32+// add x12, x2, x1+// lsr x2, x12, #32+// subs x4, x2, x12+// sbc x2, x12, xzr+// extr x4, x2, x4, #32+// lsr x2, x2, #32+// adds x1, x2, x12+// adc x2, xzr, xzr+// subs x4, x16, x4+// sbcs x16, x17, x1+// sbcs x17, x15, x2+// sbcs x15, x13, xzr+// sbcs x13, x7, xzr+// sbc x7, x12, xzr+// lsl x2, x4, #32+// add x12, x2, x4+// lsr x2, x12, #32+// subs x4, x2, x12+// sbc x2, x12, xzr+// extr x4, x2, x4, #32+// lsr x2, x2, #32+// adds x1, x2, x12+// adc x2, xzr, xzr+// subs x4, x16, x4+// sbcs x16, x17, x1+// sbcs x17, x15, x2+// sbcs x15, x13, xzr+// sbcs x13, x7, xzr+// sbc x7, x12, xzr+// lsl x2, x4, #32+// add x12, x2, x4+// lsr x2, x12, #32+// subs x4, x2, x12+// sbc x2, x12, xzr+// extr x1, x2, x4, #32+// lsr x2, x2, #32+// adds x4, x2, x12+// adc x2, xzr, xzr+// subs x3, x16, x1+// sbcs x17, x17, x4+// sbcs x15, x15, x2+// sbcs x1, x13, xzr+// sbcs x4, x7, xzr+// sbc x2, x12, xzr+// adds x13, x11, x1+// adcs x7, x4, xzr+// adcs x12, x2, xzr+// adcs x16, xzr, xzr+// mul x2, x6, x6+// adds x3, x3, x2+// xtn v30.2S, v28.2D+// shrn v26.2S, v28.2D, #32+// umull v26.2D, v30.2S, v26.2S+// shl v19.2D, v26.2D, #33+// umlal v19.2D, v30.2S, v30.2S+// mov x1, v19.d[0]+// mov x4, v19.d[1]+// umulh x2, x6, x6+// adcs x17, x17, x2+// umulh x2, x5, x5+// adcs x15, x15, x1+// adcs x13, x13, x2+// umulh x2, x10, x10+// adcs x7, x7, x4+// adcs x12, x12, x2+// adc x16, x16, xzr+// dup v28.2D, x6+// movi v0.2D, #0x00000000ffffffff+// uzp2 v5.4S, v21.4S, v21.4S+// xtn v25.2S, v28.2D+// xtn v4.2S, v21.2D+// rev64 v19.4S, v21.4S+// umull v30.2D, v25.2S, v4.2S+// umull v23.2D, v25.2S, v5.2S+// uzp2 v20.4S, v28.4S, v28.4S+// mul v19.4S, v19.4S, v28.4S+// usra v23.2D, v30.2D, #32+// umull v18.2D, v20.2S, v5.2S+// uaddlp v19.2D, v19.4S+// and v30.16B, v23.16B, v0.16B+// umlal v30.2D, v20.2S, v4.2S+// shl v19.2D, v19.2D, #32+// usra v18.2D, v23.2D, #32+// umlal v19.2D, v25.2S, v4.2S+// usra v18.2D, v30.2D, #32+// mov x6, v19.d[0]+// mov x1, v19.d[1]+// mul x4, x5, x10+// mov x2, v18.d[0]+// adds x1, x1, x2+// mov x2, v18.d[1]+// adcs x4, x4, x2+// umulh x5, x5, x10+// adc x2, x5, xzr+// adds x5, x6, x6+// adcs x6, x1, x1+// adcs x1, x4, x4+// adcs x4, x2, x2+// adc x2, xzr, xzr+// adds x17, x17, x5+// adcs x15, x15, x6+// adcs x13, x13, x1+// adcs x7, x7, x4+// adcs x12, x12, x2+// adc x2, x16, xzr+// mov x5, #0xffffffff00000001+// mov x6, #0xffffffff+// mov x1, #0x1+// cmn x3, x5+// adcs xzr, x17, x6+// adcs xzr, x15, x1+// adcs xzr, x13, xzr+// adcs xzr, x7, xzr+// adcs xzr, x12, xzr+// adc x2, x2, xzr+// neg x4, x2+// and x2, x5, x4+// adds x10, x3, x2+// and x2, x6, x4+// adcs x5, x17, x2+// and x2, x1, x4+// adcs x6, x15, x2+// adcs x1, x13, xzr+// adcs x4, x7, xzr+// adc x2, x12, xzr+// stp x10, x5, [x0] // @slothy:writes=buffer0+// stp x6, x1, [x0, #16] // @slothy:writes=buffer16+// stp x4, x2, [x0, #32] // @slothy:writes=buffer32+// ret+//+// The bash script used for step 2 is as follows:+//+// # Store the assembly instructions except the last 'ret' as, say, 'input.S'.+// export OUTPUTS="[hint_buffer0,hint_buffer16,hint_buffer32]"+// export RESERVED_REGS="[x18,x19,x20,x21,x22,x23,x24,x25,x26,x27,x28,x29,x30,sp,q8,q9,q10,q11,q12,q13,q14,q15,v8,v9,v10,v11,v12,v13,v14,v15]"+// <s2n-bignum>/tools/external/slothy.sh input.S my_out_dir+// # my_out_dir/3.opt.s is the optimized assembly. Its output may differ+// # from this file since the sequence is non-deterministically chosen.+// # Please add 'ret' at the end of the output assembly.++++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montsqr_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montsqr_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montsqr_p384)+ .text+ .balign 4++S2N_BN_SYMBOL(bignum_montsqr_p384):+ CFI_START++ ldr q1, [x1]+ ldp x9, x2, [x1]+ ldr q0, [x1]+ ldp x4, x6, [x1, #16]+ rev64 v21.4S, v1.4S+ uzp2 v28.4S, v1.4S, v1.4S+ umulh x7, x9, x2+ xtn v17.2S, v1.2D+ mul v27.4S, v21.4S, v0.4S+ ldr q20, [x1, #32]+ xtn v30.2S, v0.2D+ ldr q1, [x1, #32]+ uzp2 v31.4S, v0.4S, v0.4S+ ldp x5, x10, [x1, #32]+ umulh x8, x9, x4+ uaddlp v3.2D, v27.4S+ umull v16.2D, v30.2S, v17.2S+ mul x16, x9, x4+ umull v27.2D, v30.2S, v28.2S+ shrn v0.2S, v20.2D, #32+ xtn v7.2S, v20.2D+ shl v20.2D, v3.2D, #32+ umull v3.2D, v31.2S, v28.2S+ mul x3, x2, x4+ umlal v20.2D, v30.2S, v17.2S+ umull v22.2D, v7.2S, v0.2S+ usra v27.2D, v16.2D, #32+ umulh x11, x2, x4+ movi v21.2D, #0x00000000ffffffff+ uzp2 v28.4S, v1.4S, v1.4S+ adds x15, x16, x7+ and v5.16B, v27.16B, v21.16B+ adcs x3, x3, x8+ usra v3.2D, v27.2D, #32+ dup v29.2D, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2D, v31.2S, v17.2S+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2D, v22.2D, #33+ xtn v25.2S, v29.2D+ rev64 v31.4S, v1.4S+ lsl x13, x14, #32+ uzp2 v6.4S, v29.4S, v29.4S+ umlal v19.2D, v7.2S, v7.2S+ usra v3.2D, v5.2D, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4S, v31.4S, v29.4S+ xtn v4.2S, v1.2D+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2D, v25.2S, v28.2S+ adcs x11, x16, x16+ umull v21.2D, v25.2S, v4.2S+ mov x17, v3.d[0]+ umull v18.2D, v6.2S, v28.2S+ adc x16, x8, xzr+ uaddlp v16.2D, v17.4S+ movi v1.2D, #0x00000000ffffffff+ subs x13, x13, x12+ usra v31.2D, v21.2D, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2D, v16.2D, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16B, v31.16B, v1.16B+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2D, v6.2S, v4.2S+ usra v18.2D, v31.2D, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2D, v25.2S, v4.2S+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2D, v3.2D, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [x0] // @slothy:writes=buffer0+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [x0, #16] // @slothy:writes=buffer16+ csetm x15, cc+ cneg x1, x1, cc+ stp x11, x14, [x0, #32] // @slothy:writes=buffer32+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc+ cinv x16, x15, cc+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc+ cneg x9, x9, cc+ subs x4, x2, x4+ cneg x4, x4, cc+ csetm x7, cc+ subs x2, x10, x6+ cinv x8, x8, cc+ cneg x2, x2, cc+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc+ cneg x1, x1, cc+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [x0, #16] // @slothy:reads=buffer16+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [x0] // @slothy:reads=buffer0+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [x0, #32] // @slothy:reads=buffer32+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001+ adcs x14, x14, x2+ mov x2, #0x1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [x0] // @slothy:writes=buffer0+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [x0, #16] // @slothy:writes=buffer16+ adc x17, x14, xzr+ stp x2, x17, [x0, #32] // depth 72 // @slothy:writes=buffer32++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montsqr_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_montsqr_p384_alt.S view
@@ -0,0 +1,273 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery square, z := (x^2 / 2^384) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_montsqr_p384_alt(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Does z := (x^2 / 2^384) mod p_384, assuming x^2 <= 2^384 * p_384, which is+// guaranteed in particular if x < p_384 initially (the "intended" case).+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montsqr_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montsqr_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montsqr_p384_alt)+ .text+ .balign 4++// ---------------------------------------------------------------------------+// Core one-step "short" Montgomery reduction macro. Takes input in+// [d5;d4;d3;d2;d1;d0] and returns result in [d6;d5;d4;d3;d2;d1],+// adding to the existing contents of [d5;d4;d3;d2;d1]. It is fine+// for d6 to be the same register as d0.+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+// ---------------------------------------------------------------------------++#define montreds(d6,d5,d4,d3,d2,d1,d0, t3,t2,t1) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+/* Store it in d6 to make the 2^384 * w contribution already */ \+ lsl t1, d0, #32 __LF \+ add d6, t1, d0 __LF \+/* Now let [t3;t2;t1;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel d0 so we don't need it */ \+ mov t1, #0xffffffff00000001 __LF \+ umulh t1, t1, d6 __LF \+ mov t2, #0x00000000ffffffff __LF \+ mul t3, t2, d6 __LF \+ umulh t2, t2, d6 __LF \+ adds t1, t1, t3 __LF \+ adcs t2, t2, d6 __LF \+ adc t3, xzr, xzr __LF \+/* Now add it, by subtracting from 2^384 * w + x */ \+ subs d1, d1, t1 __LF \+ sbcs d2, d2, t2 __LF \+ sbcs d3, d3, t3 __LF \+ sbcs d4, d4, xzr __LF \+ sbcs d5, d5, xzr __LF \+ sbc d6, d6, xzr++#define z x0+#define x x1++#define a0 x2+#define a1 x3+#define a2 x4+#define a3 x5+#define a4 x6+#define a5 x7++#define l x8++#define u0 x2 // The same as a0, which is safe+#define u1 x9+#define u2 x10+#define u3 x11+#define u4 x12+#define u5 x13+#define u6 x14+#define u7 x15+#define u8 x16+#define u9 x17+#define u10 x19+#define u11 x20+#define h x6 // same as a4++S2N_BN_SYMBOL(bignum_montsqr_p384_alt):+ CFI_START++// It's convenient to have two more registers to play with++ CFI_PUSH2(x19,x20)++// Load all the elements as [a5;a4;a3;a2;a1;a0], set up an initial+// window [u8;u7; u6;u5; u4;u3; u2;u1] = [34;05;03;01], and then+// chain in the addition of 02 + 12 + 13 + 14 + 15 to that window+// (no carry-out possible since we add it to the top of a product).++ ldp a0, a1, [x]++ mul u1, a0, a1+ umulh u2, a0, a1++ ldp a2, a3, [x, #16]++ mul l, a0, a2+ adds u2, u2, l++ mul u3, a0, a3+ mul l, a1, a2+ adcs u3, u3, l++ umulh u4, a0, a3+ mul l, a1, a3+ adcs u4, u4, l++ ldp a4, a5, [x, #32]++ mul u5, a0, a5+ mul l, a1, a4+ adcs u5, u5, l++ umulh u6, a0, a5+ mul l, a1, a5+ adcs u6, u6, l++ mul u7, a3, a4+ adcs u7, u7, xzr++ umulh u8, a3, a4+ adc u8, u8, xzr++ umulh l, a0, a2+ adds u3, u3, l+ umulh l, a1, a2+ adcs u4, u4, l+ umulh l, a1, a3+ adcs u5, u5, l+ umulh l, a1, a4+ adcs u6, u6, l+ umulh l, a1, a5+ adcs u7, u7, l+ adc u8, u8, xzr++// Now chain in the 04 + 23 + 24 + 25 + 35 + 45 terms++ mul l, a0, a4+ adds u4, u4, l+ mul l, a2, a3+ adcs u5, u5, l+ mul l, a2, a4+ adcs u6, u6, l+ mul l, a2, a5+ adcs u7, u7, l+ mul l, a3, a5+ adcs u8, u8, l+ mul u9, a4, a5+ adcs u9, u9, xzr+ umulh u10, a4, a5+ adc u10, u10, xzr++ umulh l, a0, a4+ adds u5, u5, l+ umulh l, a2, a3+ adcs u6, u6, l+ umulh l, a2, a4+ adcs u7, u7, l+ umulh l, a2, a5+ adcs u8, u8, l+ umulh l, a3, a5+ adcs u9, u9, l+ adc u10, u10, xzr++// Double that, with u11 holding the top carry++ adds u1, u1, u1+ adcs u2, u2, u2+ adcs u3, u3, u3+ adcs u4, u4, u4+ adcs u5, u5, u5+ adcs u6, u6, u6+ adcs u7, u7, u7+ adcs u8, u8, u8+ adcs u9, u9, u9+ adcs u10, u10, u10+ cset u11, cs++// Add the homogeneous terms 00 + 11 + 22 + 33 + 44 + 55++ umulh l, a0, a0+ mul u0, a0, a0+ adds u1, u1, l++ mul l, a1, a1+ adcs u2, u2, l+ umulh l, a1, a1+ adcs u3, u3, l++ mul l, a2, a2+ adcs u4, u4, l+ umulh l, a2, a2+ adcs u5, u5, l++ mul l, a3, a3+ adcs u6, u6, l+ umulh l, a3, a3+ adcs u7, u7, l++ mul l, a4, a4+ adcs u8, u8, l+ umulh l, a4, a4+ adcs u9, u9, l++ mul l, a5, a5+ adcs u10, u10, l+ umulh l, a5, a5+ adc u11, u11, l++// Montgomery rotate the low half++ montreds(u0,u5,u4,u3,u2,u1,u0, a1,a2,a3)+ montreds(u1,u0,u5,u4,u3,u2,u1, a1,a2,a3)+ montreds(u2,u1,u0,u5,u4,u3,u2, a1,a2,a3)+ montreds(u3,u2,u1,u0,u5,u4,u3, a1,a2,a3)+ montreds(u4,u3,u2,u1,u0,u5,u4, a1,a2,a3)+ montreds(u5,u4,u3,u2,u1,u0,u5, a1,a2,a3)++// Add up the high and low parts as [h; u5;u4;u3;u2;u1;u0] = z++ adds u0, u0, u6+ adcs u1, u1, u7+ adcs u2, u2, u8+ adcs u3, u3, u9+ adcs u4, u4, u10+ adcs u5, u5, u11+ adc h, xzr, xzr++// Now add [h; u11;u10;u9;u8;u7;u6] = z + (2^384 - p_384)++ mov l, #0xffffffff00000001+ adds u6, u0, l+ mov l, #0x00000000ffffffff+ adcs u7, u1, l+ mov l, #0x0000000000000001+ adcs u8, u2, l+ adcs u9, u3, xzr+ adcs u10, u4, xzr+ adcs u11, u5, xzr+ adcs h, h, xzr++// Now z >= p_384 iff h is nonzero, so select accordingly++ csel u0, u0, u6, eq+ csel u1, u1, u7, eq+ csel u2, u2, u8, eq+ csel u3, u3, u9, eq+ csel u4, u4, u10, eq+ csel u5, u5, u11, eq++// Store back final result++ stp u0, u1, [z]+ stp u2, u3, [z, #16]+ stp u4, u5, [z, #32]++// Restore registers++ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montsqr_p384_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_mul_p521.S view
@@ -0,0 +1,1407 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Multiply modulo p_521, z := (x * y) mod p_521, assuming x and y reduced+// Inputs x[9], y[9]; output z[9]+//+// extern void bignum_mul_p521(uint64_t z[static 9], const uint64_t x[static 9],+// const uint64_t y[static 9]);+//+// Standard ARM ABI: X0 = z, X1 = x, X2 = y+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++// bignum_mul_p521 is functionally equivalent to unopt/bignum_mul_p521_base.+// It is written in a way that+// 1. A subset of scalar multiplications in bignum_montmul_p384 are carefully+// chosen and vectorized+// 2. The vectorized assembly is rescheduled using the SLOTHY superoptimizer.+// https://github.com/slothy-optimizer/slothy+//+// The output program of step 1. is as follows:+//+// stp x19, x20, [sp, #-16]!+// stp x21, x22, [sp, #-16]!+// stp x23, x24, [sp, #-16]!+// stp x25, x26, [sp, #-16]!+// sub sp, sp, #80+// ldp x15, x21, [x1]+// ldp x10, x17, [x1, #16]+// ldp x13, x16, [x2]+// ldr q18, [x1]+// ldr q28, [x2]+// ldp x5, x20, [x2, #16]+// movi v16.2D, #0x00000000ffffffff+// uzp2 v7.4S, v28.4S, v28.4S+// xtn v4.2S, v18.2D+// xtn v1.2S, v28.2D+// rev64 v27.4S, v28.4S+// umull v21.2D, v4.2S, v1.2S+// umull v28.2D, v4.2S, v7.2S+// uzp2 v5.4S, v18.4S, v18.4S+// mul v18.4S, v27.4S, v18.4S+// usra v28.2D, v21.2D, #32+// umull v29.2D, v5.2S, v7.2S+// uaddlp v18.2D, v18.4S+// and v16.16B, v28.16B, v16.16B+// umlal v16.2D, v5.2S, v1.2S+// shl v18.2D, v18.2D, #32+// usra v29.2D, v28.2D, #32+// umlal v18.2D, v4.2S, v1.2S+// usra v29.2D, v16.2D, #32+// mov x8, v18.d[0]+// mov x9, v18.d[1]+// mul x6, x10, x5+// mul x19, x17, x20+// mov x14, v29.d[0]+// adds x9, x9, x14+// mov x14, v29.d[1]+// adcs x6, x6, x14+// umulh x14, x10, x5+// adcs x19, x19, x14+// umulh x14, x17, x20+// adc x14, x14, xzr+// adds x11, x9, x8+// adcs x9, x6, x9+// adcs x6, x19, x6+// adcs x19, x14, x19+// adc x14, xzr, x14+// adds x3, x9, x8+// adcs x24, x6, x11+// adcs x9, x19, x9+// adcs x6, x14, x6+// adcs x19, xzr, x19+// adc x14, xzr, x14+// subs x4, x10, x17+// cneg x4, x4, cc+// csetm x7, cc+// subs x23, x20, x5+// cneg x23, x23, cc+// mul x22, x4, x23+// umulh x4, x4, x23+// cinv x7, x7, cc+// cmn x7, #0x1+// eor x23, x22, x7+// adcs x6, x6, x23+// eor x4, x4, x7+// adcs x19, x19, x4+// adc x14, x14, x7+// subs x4, x15, x21+// cneg x4, x4, cc+// csetm x7, cc+// subs x23, x16, x13+// cneg x23, x23, cc+// mul x22, x4, x23+// umulh x4, x4, x23+// cinv x7, x7, cc+// cmn x7, #0x1+// eor x23, x22, x7+// adcs x11, x11, x23+// eor x4, x4, x7+// adcs x3, x3, x4+// adcs x24, x24, x7+// adcs x9, x9, x7+// adcs x6, x6, x7+// adcs x19, x19, x7+// adc x14, x14, x7+// subs x4, x21, x17+// cneg x4, x4, cc+// csetm x7, cc+// subs x23, x20, x16+// cneg x23, x23, cc+// mul x22, x4, x23+// umulh x4, x4, x23+// cinv x7, x7, cc+// cmn x7, #0x1+// eor x23, x22, x7+// adcs x9, x9, x23+// eor x4, x4, x7+// adcs x6, x6, x4+// adcs x19, x19, x7+// adc x14, x14, x7+// subs x4, x15, x10+// cneg x4, x4, cc+// csetm x7, cc+// subs x23, x5, x13+// cneg x23, x23, cc+// mul x22, x4, x23+// umulh x4, x4, x23+// cinv x7, x7, cc+// cmn x7, #0x1+// eor x23, x22, x7+// adcs x3, x3, x23+// eor x4, x4, x7+// adcs x24, x24, x4+// adcs x9, x9, x7+// adcs x6, x6, x7+// adcs x19, x19, x7+// adc x14, x14, x7+// subs x17, x15, x17+// cneg x17, x17, cc+// csetm x4, cc+// subs x13, x20, x13+// cneg x13, x13, cc+// mul x20, x17, x13+// umulh x17, x17, x13+// cinv x13, x4, cc+// cmn x13, #0x1+// eor x20, x20, x13+// adcs x20, x24, x20+// eor x17, x17, x13+// adcs x17, x9, x17+// adcs x9, x6, x13+// adcs x6, x19, x13+// adc x13, x14, x13+// subs x21, x21, x10+// cneg x21, x21, cc+// csetm x10, cc+// subs x16, x5, x16+// cneg x16, x16, cc+// mul x5, x21, x16+// umulh x21, x21, x16+// cinv x10, x10, cc+// cmn x10, #0x1+// eor x16, x5, x10+// adcs x16, x20, x16+// eor x21, x21, x10+// adcs x21, x17, x21+// adcs x17, x9, x10+// adcs x5, x6, x10+// adc x10, x13, x10+// lsl x13, x8, #9+// extr x20, x11, x8, #55+// extr x8, x3, x11, #55+// extr x9, x16, x3, #55+// lsr x16, x16, #55+// stp x21, x17, [sp] // @slothy:writes=stack0+// stp x5, x10, [sp, #16] // @slothy:writes=stack16+// stp x13, x20, [sp, #32] // @slothy:writes=stack32+// stp x8, x9, [sp, #48] // @slothy:writes=stack48+// str x16, [sp, #64] // @slothy:writes=stack64+// ldp x21, x10, [x1, #32]+// ldp x17, x13, [x1, #48]+// ldp x16, x5, [x2, #32]+// ldr q18, [x1, #32]+// ldr q28, [x2, #32]+// ldp x20, x8, [x2, #48]+// movi v16.2D, #0x00000000ffffffff+// uzp2 v7.4S, v28.4S, v28.4S+// xtn v4.2S, v18.2D+// xtn v1.2S, v28.2D+// rev64 v28.4S, v28.4S+// umull v27.2D, v4.2S, v1.2S+// umull v29.2D, v4.2S, v7.2S+// uzp2 v21.4S, v18.4S, v18.4S+// mul v28.4S, v28.4S, v18.4S+// usra v29.2D, v27.2D, #32+// umull v18.2D, v21.2S, v7.2S+// uaddlp v28.2D, v28.4S+// and v16.16B, v29.16B, v16.16B+// umlal v16.2D, v21.2S, v1.2S+// shl v28.2D, v28.2D, #32+// usra v18.2D, v29.2D, #32+// umlal v28.2D, v4.2S, v1.2S+// usra v18.2D, v16.2D, #32+// mov x9, v28.d[0]+// mov x6, v28.d[1]+// mul x19, x17, x20+// mul x14, x13, x8+// mov x11, v18.d[0]+// adds x6, x6, x11+// mov x11, v18.d[1]+// adcs x19, x19, x11+// umulh x11, x17, x20+// adcs x14, x14, x11+// umulh x11, x13, x8+// adc x11, x11, xzr+// adds x3, x6, x9+// adcs x6, x19, x6+// adcs x19, x14, x19+// adcs x14, x11, x14+// adc x11, xzr, x11+// adds x24, x6, x9+// adcs x4, x19, x3+// adcs x6, x14, x6+// adcs x19, x11, x19+// adcs x14, xzr, x14+// adc x11, xzr, x11+// subs x7, x17, x13+// cneg x7, x7, cc+// csetm x23, cc+// subs x22, x8, x20+// cneg x22, x22, cc+// mul x12, x7, x22+// umulh x7, x7, x22+// cinv x23, x23, cc+// cmn x23, #0x1+// eor x22, x12, x23+// adcs x19, x19, x22+// eor x7, x7, x23+// adcs x14, x14, x7+// adc x11, x11, x23+// subs x7, x21, x10+// cneg x7, x7, cc+// csetm x23, cc+// subs x22, x5, x16+// cneg x22, x22, cc+// mul x12, x7, x22+// umulh x7, x7, x22+// cinv x23, x23, cc+// cmn x23, #0x1+// eor x22, x12, x23+// adcs x3, x3, x22+// eor x7, x7, x23+// adcs x24, x24, x7+// adcs x4, x4, x23+// adcs x6, x6, x23+// adcs x19, x19, x23+// adcs x14, x14, x23+// adc x11, x11, x23+// subs x7, x10, x13+// cneg x7, x7, cc+// csetm x23, cc+// subs x22, x8, x5+// cneg x22, x22, cc+// mul x12, x7, x22+// umulh x7, x7, x22+// cinv x23, x23, cc+// cmn x23, #0x1+// eor x22, x12, x23+// adcs x6, x6, x22+// eor x7, x7, x23+// adcs x19, x19, x7+// adcs x14, x14, x23+// adc x11, x11, x23+// subs x7, x21, x17+// cneg x7, x7, cc+// csetm x23, cc+// subs x22, x20, x16+// cneg x22, x22, cc+// mul x12, x7, x22+// umulh x7, x7, x22+// cinv x23, x23, cc+// cmn x23, #0x1+// eor x22, x12, x23+// adcs x24, x24, x22+// eor x7, x7, x23+// adcs x4, x4, x7+// adcs x6, x6, x23+// adcs x19, x19, x23+// adcs x14, x14, x23+// adc x11, x11, x23+// subs x7, x21, x13+// cneg x7, x7, cc+// csetm x23, cc+// subs x22, x8, x16+// cneg x22, x22, cc+// mul x12, x7, x22+// umulh x7, x7, x22+// cinv x23, x23, cc+// cmn x23, #0x1+// eor x22, x12, x23+// adcs x4, x4, x22+// eor x7, x7, x23+// adcs x6, x6, x7+// adcs x19, x19, x23+// adcs x14, x14, x23+// adc x11, x11, x23+// subs x7, x10, x17+// cneg x7, x7, cc+// csetm x23, cc+// subs x22, x20, x5+// cneg x22, x22, cc+// mul x12, x7, x22+// umulh x7, x7, x22+// cinv x23, x23, cc+// cmn x23, #0x1+// eor x22, x12, x23+// adcs x4, x4, x22+// eor x7, x7, x23+// adcs x6, x6, x7+// adcs x19, x19, x23+// adcs x14, x14, x23+// adc x11, x11, x23+// ldp x7, x23, [sp] // @slothy:reads=stack0+// adds x9, x9, x7+// adcs x3, x3, x23+// stp x9, x3, [sp] // @slothy:writes=stack0+// ldp x9, x3, [sp, #16] // @slothy:reads=stack16+// adcs x9, x24, x9+// adcs x3, x4, x3+// stp x9, x3, [sp, #16] // @slothy:writes=stack16+// ldp x9, x3, [sp, #32] // @slothy:reads=stack32+// adcs x9, x6, x9+// adcs x6, x19, x3+// stp x9, x6, [sp, #32] // @slothy:writes=stack32+// ldp x9, x6, [sp, #48] // @slothy:reads=stack48+// adcs x9, x14, x9+// adcs x6, x11, x6+// stp x9, x6, [sp, #48] // @slothy:writes=stack48+// ldr x9, [sp, #64] // @slothy:reads=stack64+// adc x9, x9, xzr+// str x9, [sp, #64] // @slothy:writes=stack64+// ldp x9, x6, [x1]+// subs x21, x21, x9+// sbcs x10, x10, x6+// ldp x9, x6, [x1, #16]+// sbcs x17, x17, x9+// sbcs x13, x13, x6+// csetm x9, cc+// ldp x6, x19, [x2]+// subs x16, x6, x16+// sbcs x5, x19, x5+// ldp x6, x19, [x2, #16]+// sbcs x20, x6, x20+// sbcs x8, x19, x8+// csetm x6, cc+// eor x21, x21, x9+// subs x21, x21, x9+// eor x10, x10, x9+// sbcs x10, x10, x9+// eor x17, x17, x9+// sbcs x17, x17, x9+// eor x13, x13, x9+// sbc x13, x13, x9+// eor x16, x16, x6+// subs x16, x16, x6+// eor x5, x5, x6+// sbcs x5, x5, x6+// eor x20, x20, x6+// sbcs x20, x20, x6+// eor x8, x8, x6+// sbc x8, x8, x6+// eor x9, x6, x9+// mul x6, x21, x16+// mul x19, x10, x5+// mul x14, x17, x20+// mul x11, x13, x8+// umulh x3, x21, x16+// adds x19, x19, x3+// umulh x3, x10, x5+// adcs x14, x14, x3+// umulh x3, x17, x20+// adcs x11, x11, x3+// umulh x3, x13, x8+// adc x3, x3, xzr+// adds x24, x19, x6+// adcs x19, x14, x19+// adcs x14, x11, x14+// adcs x11, x3, x11+// adc x3, xzr, x3+// adds x4, x19, x6+// adcs x7, x14, x24+// adcs x19, x11, x19+// adcs x14, x3, x14+// adcs x11, xzr, x11+// adc x3, xzr, x3+// subs x23, x17, x13+// cneg x23, x23, cc+// csetm x22, cc+// subs x12, x8, x20+// cneg x12, x12, cc+// mul x15, x23, x12+// umulh x23, x23, x12+// cinv x22, x22, cc+// cmn x22, #0x1+// eor x12, x15, x22+// adcs x14, x14, x12+// eor x23, x23, x22+// adcs x11, x11, x23+// adc x3, x3, x22+// subs x23, x21, x10+// cneg x23, x23, cc+// csetm x22, cc+// subs x12, x5, x16+// cneg x12, x12, cc+// mul x15, x23, x12+// umulh x23, x23, x12+// cinv x22, x22, cc+// cmn x22, #0x1+// eor x12, x15, x22+// adcs x24, x24, x12+// eor x23, x23, x22+// adcs x4, x4, x23+// adcs x7, x7, x22+// adcs x19, x19, x22+// adcs x14, x14, x22+// adcs x11, x11, x22+// adc x3, x3, x22+// subs x23, x10, x13+// cneg x23, x23, cc+// csetm x22, cc+// subs x12, x8, x5+// cneg x12, x12, cc+// mul x15, x23, x12+// umulh x23, x23, x12+// cinv x22, x22, cc+// cmn x22, #0x1+// eor x12, x15, x22+// adcs x19, x19, x12+// eor x23, x23, x22+// adcs x14, x14, x23+// adcs x11, x11, x22+// adc x3, x3, x22+// subs x23, x21, x17+// cneg x23, x23, cc+// csetm x22, cc+// subs x12, x20, x16+// cneg x12, x12, cc+// mul x15, x23, x12+// umulh x23, x23, x12+// cinv x22, x22, cc+// cmn x22, #0x1+// eor x12, x15, x22+// adcs x4, x4, x12+// eor x23, x23, x22+// adcs x7, x7, x23+// adcs x19, x19, x22+// adcs x14, x14, x22+// adcs x11, x11, x22+// adc x3, x3, x22+// subs x21, x21, x13+// cneg x21, x21, cc+// csetm x13, cc+// subs x16, x8, x16+// cneg x16, x16, cc+// mul x8, x21, x16+// umulh x21, x21, x16+// cinv x13, x13, cc+// cmn x13, #0x1+// eor x16, x8, x13+// adcs x16, x7, x16+// eor x21, x21, x13+// adcs x21, x19, x21+// adcs x8, x14, x13+// adcs x19, x11, x13+// adc x13, x3, x13+// subs x10, x10, x17+// cneg x10, x10, cc+// csetm x17, cc+// subs x5, x20, x5+// cneg x5, x5, cc+// mul x20, x10, x5+// umulh x10, x10, x5+// cinv x17, x17, cc+// cmn x17, #0x1+// eor x5, x20, x17+// adcs x16, x16, x5+// eor x10, x10, x17+// adcs x21, x21, x10+// adcs x10, x8, x17+// adcs x5, x19, x17+// adc x17, x13, x17+// ldp x13, x20, [sp] // @slothy:reads=stack0+// ldp x8, x19, [sp, #16] // @slothy:reads=stack16+// eor x6, x6, x9+// adds x6, x6, x13+// eor x14, x24, x9+// adcs x14, x14, x20+// eor x11, x4, x9+// adcs x11, x11, x8+// eor x16, x16, x9+// adcs x16, x16, x19+// eor x21, x21, x9+// ldp x3, x24, [sp, #32] // @slothy:reads=stack32+// ldp x4, x7, [sp, #48] // @slothy:reads=stack48+// ldr x23, [sp, #64] // @slothy:reads=stack64+// adcs x21, x21, x3+// eor x10, x10, x9+// adcs x10, x10, x24+// eor x5, x5, x9+// adcs x5, x5, x4+// eor x17, x17, x9+// adcs x17, x17, x7+// adc x22, x23, xzr+// adds x21, x21, x13+// adcs x10, x10, x20+// adcs x13, x5, x8+// adcs x17, x17, x19+// and x5, x9, #0x1ff+// lsl x20, x6, #9+// orr x5, x20, x5+// adcs x5, x3, x5+// extr x20, x14, x6, #55+// adcs x20, x24, x20+// extr x8, x11, x14, #55+// adcs x8, x4, x8+// extr x9, x16, x11, #55+// adcs x9, x7, x9+// lsr x16, x16, #55+// adc x16, x16, x23+// ldr x6, [x2, #64]+// ldp x19, x14, [x1]+// and x11, x19, #0xfffffffffffff+// mul x11, x6, x11+// ldr x3, [x1, #64]+// ldp x24, x4, [x2]+// and x7, x24, #0xfffffffffffff+// mul x7, x3, x7+// add x11, x11, x7+// extr x19, x14, x19, #52+// and x19, x19, #0xfffffffffffff+// mul x19, x6, x19+// extr x24, x4, x24, #52+// and x24, x24, #0xfffffffffffff+// mul x24, x3, x24+// add x19, x19, x24+// lsr x24, x11, #52+// add x19, x19, x24+// lsl x11, x11, #12+// extr x11, x19, x11, #12+// adds x21, x21, x11+// ldp x11, x24, [x1, #16]+// ldp x7, x23, [x2, #16]+// extr x14, x11, x14, #40+// and x14, x14, #0xfffffffffffff+// mul x14, x6, x14+// extr x4, x7, x4, #40+// and x4, x4, #0xfffffffffffff+// mul x4, x3, x4+// add x14, x14, x4+// lsr x4, x19, #52+// add x14, x14, x4+// lsl x19, x19, #12+// extr x19, x14, x19, #24+// adcs x10, x10, x19+// extr x19, x24, x11, #28+// and x19, x19, #0xfffffffffffff+// mul x19, x6, x19+// extr x11, x23, x7, #28+// and x11, x11, #0xfffffffffffff+// mul x11, x3, x11+// add x19, x19, x11+// lsr x11, x14, #52+// add x19, x19, x11+// lsl x14, x14, #12+// extr x14, x19, x14, #36+// adcs x13, x13, x14+// and x14, x10, x13+// ldp x11, x4, [x1, #32]+// ldp x7, x12, [x2, #32]+// extr x24, x11, x24, #16+// and x24, x24, #0xfffffffffffff+// mul x24, x6, x24+// extr x23, x7, x23, #16+// and x23, x23, #0xfffffffffffff+// mul x23, x3, x23+// add x24, x24, x23+// lsl x23, x22, #48+// add x24, x24, x23+// lsr x23, x19, #52+// add x24, x24, x23+// lsl x19, x19, #12+// extr x19, x24, x19, #48+// adcs x17, x17, x19+// and x19, x14, x17+// lsr x14, x11, #4+// and x14, x14, #0xfffffffffffff+// mul x14, x6, x14+// lsr x23, x7, #4+// and x23, x23, #0xfffffffffffff+// mul x23, x3, x23+// add x14, x14, x23+// lsr x23, x24, #52+// add x14, x14, x23+// lsl x24, x24, #12+// extr x24, x14, x24, #60+// extr x11, x4, x11, #56+// and x11, x11, #0xfffffffffffff+// mul x11, x6, x11+// extr x7, x12, x7, #56+// and x7, x7, #0xfffffffffffff+// mul x7, x3, x7+// add x11, x11, x7+// lsr x14, x14, #52+// add x14, x11, x14+// lsl x11, x24, #8+// extr x11, x14, x11, #8+// adcs x5, x5, x11+// and x19, x19, x5+// ldp x11, x24, [x1, #48]+// ldp x2, x7, [x2, #48]+// extr x4, x11, x4, #44+// and x4, x4, #0xfffffffffffff+// mul x4, x6, x4+// extr x23, x2, x12, #44+// and x23, x23, #0xfffffffffffff+// mul x23, x3, x23+// add x4, x4, x23+// lsr x23, x14, #52+// add x4, x4, x23+// lsl x14, x14, #12+// extr x14, x4, x14, #20+// adcs x20, x20, x14+// and x19, x19, x20+// extr x14, x24, x11, #32+// and x14, x14, #0xfffffffffffff+// mul x14, x6, x14+// extr x2, x7, x2, #32+// and x2, x2, #0xfffffffffffff+// mul x2, x3, x2+// add x2, x14, x2+// lsr x14, x4, #52+// add x2, x2, x14+// lsl x14, x4, #12+// extr x14, x2, x14, #32+// adcs x8, x8, x14+// and x19, x19, x8+// lsr x14, x24, #20+// mul x14, x6, x14+// lsr x11, x7, #20+// mul x11, x3, x11+// add x14, x14, x11+// lsr x11, x2, #52+// add x14, x14, x11+// lsl x2, x2, #12+// extr x2, x14, x2, #44+// adcs x9, x9, x2+// and x2, x19, x9+// mul x6, x6, x3+// lsr x19, x14, #44+// add x6, x6, x19+// adc x16, x16, x6+// lsr x6, x16, #9+// orr x16, x16, #0xfffffffffffffe00+// cmp xzr, xzr+// adcs xzr, x21, x6+// adcs xzr, x2, xzr+// adcs xzr, x16, xzr+// adcs x21, x21, x6+// adcs x10, x10, xzr+// adcs x13, x13, xzr+// adcs x17, x17, xzr+// adcs x5, x5, xzr+// adcs x20, x20, xzr+// adcs x8, x8, xzr+// adcs x9, x9, xzr+// adc x16, x16, xzr+// and x2, x21, #0x1ff+// extr x21, x10, x21, #9+// extr x10, x13, x10, #9+// stp x21, x10, [x0] // @slothy:writes=buffer0+// extr x21, x17, x13, #9+// extr x10, x5, x17, #9+// stp x21, x10, [x0, #16] // @slothy:writes=buffer16+// extr x21, x20, x5, #9+// extr x10, x8, x20, #9+// stp x21, x10, [x0, #32] // @slothy:writes=buffer32+// extr x21, x9, x8, #9+// extr x10, x16, x9, #9+// stp x21, x10, [x0, #48] // @slothy:writes=buffer48+// str x2, [x0, #64] // @slothy:writes=buffer64+// add sp, sp, #80+// ldp x25, x26, [sp], #16+// ldp x23, x24, [sp], #16+// ldp x21, x22, [sp], #16+// ldp x19, x20, [sp], #16+// ret+//+// The bash script used for step 2 is as follows:+//+// # Store the assembly instructions except the last 'ret',+// # callee-register store/loads and add/sub sp #80 as, say, 'input.S'.+// export OUTPUTS="[hint_buffer0,hint_buffer16,hint_buffer32,hint_buffer48,hint_buffer64]"+// export RESERVED_REGS="[x18,x27,x28,x29,x30,sp,q8,q9,q10,q11,q12,q13,q14,q15,v8,v9,v10,v11,v12,v13,v14,v15]"+// <s2n-bignum>/tools/external/slothy.sh input.S my_out_dir+// # my_out_dir/3.opt.s is the optimized assembly. Its output may differ+// # from this file since the sequence is non-deterministically chosen.+// # Please add 'ret' at the end of the output assembly.++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_mul_p521)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_mul_p521)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_mul_p521)+ .text+ .balign 4++S2N_BN_SYMBOL(bignum_mul_p521):+ CFI_START++// Save registers and make space for the temporary buffer++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_DEC_SP(80)++ ldr q6, [x2]+ ldp x10, x17, [x1, #16]+ ldr q4, [x1]+ ldr q16, [x2, #32]+ ldp x5, x20, [x2, #16]+ ldr q2, [x1, #32]+ movi v31.2D, #0x00000000ffffffff+ uzp2 v17.4S, v6.4S, v6.4S+ rev64 v7.4S, v6.4S+ ldp x15, x21, [x1]+ xtn v25.2S, v6.2D+ xtn v22.2S, v4.2D+ subs x14, x10, x17+ mul v7.4S, v7.4S, v4.4S+ csetm x8, cc+ rev64 v3.4S, v16.4S+ xtn v1.2S, v16.2D+ ldp x13, x16, [x2]+ mul x26, x10, x5+ uzp2 v16.4S, v16.4S, v16.4S+ uaddlp v26.2D, v7.4S+ cneg x4, x14, cc+ subs x24, x15, x21+ xtn v5.2S, v2.2D+ mul v28.4S, v3.4S, v2.4S+ shl v26.2D, v26.2D, #32+ mul x22, x17, x20+ umull v20.2D, v22.2S, v25.2S+ uzp2 v6.4S, v4.4S, v4.4S+ umull v18.2D, v22.2S, v17.2S+ uzp2 v4.4S, v2.4S, v2.4S+ cneg x14, x24, cc+ csetm x7, cc+ umulh x11, x17, x20+ usra v18.2D, v20.2D, #32+ uaddlp v7.2D, v28.4S+ subs x19, x16, x13+ umlal v26.2D, v22.2S, v25.2S+ cneg x19, x19, cc+ shl v28.2D, v7.2D, #32+ umull v7.2D, v5.2S, v1.2S+ umull v30.2D, v5.2S, v16.2S+ cinv x6, x7, cc+ mul x25, x14, x19+ umlal v28.2D, v5.2S, v1.2S+ umull v21.2D, v6.2S, v17.2S+ umulh x14, x14, x19+ usra v30.2D, v7.2D, #32+ subs x9, x20, x5+ and v29.16B, v18.16B, v31.16B+ cinv x23, x8, cc+ mov x8, v26.d[1]+ cneg x12, x9, cc+ usra v21.2D, v18.2D, #32+ umlal v29.2D, v6.2S, v25.2S+ mul x24, x4, x12+ umull v18.2D, v4.2S, v16.2S+ movi v25.2D, #0x00000000ffffffff+ eor x9, x14, x6+ and v7.16B, v30.16B, v25.16B+ usra v21.2D, v29.2D, #32+ umulh x7, x10, x5+ usra v18.2D, v30.2D, #32+ umlal v7.2D, v4.2S, v1.2S+ mov x19, v21.d[0]+ umulh x3, x4, x12+ mov x14, v21.d[1]+ usra v18.2D, v7.2D, #32+ adds x4, x8, x19+ mov x8, v26.d[0]+ adcs x19, x26, x14+ adcs x14, x22, x7+ adc x12, x11, xzr+ adds x11, x4, x8+ adcs x26, x19, x4+ adcs x22, x14, x19+ eor x4, x24, x23+ adcs x14, x12, x14+ eor x7, x25, x6+ adc x25, xzr, x12+ eor x19, x3, x23+ adds x3, x26, x8+ adcs x24, x22, x11+ adcs x12, x14, x26+ adcs x22, x25, x22+ adcs x26, xzr, x14+ adc x14, xzr, x25+ cmn x23, #0x1+ adcs x22, x22, x4+ adcs x19, x26, x19+ adc x25, x14, x23+ subs x14, x21, x17+ cneg x23, x14, cc+ csetm x26, cc+ subs x4, x20, x16+ cneg x14, x4, cc+ cinv x4, x26, cc+ cmn x6, #0x1+ adcs x11, x11, x7+ mul x7, x23, x14+ adcs x9, x3, x9+ adcs x26, x24, x6+ umulh x3, x23, x14+ adcs x14, x12, x6+ adcs x22, x22, x6+ adcs x12, x19, x6+ extr x24, x11, x8, #55+ adc x6, x25, x6+ subs x19, x15, x17+ csetm x17, cc+ cneg x23, x19, cc+ subs x19, x20, x13+ lsl x25, x8, #9+ eor x8, x7, x4+ cneg x20, x19, cc+ umulh x7, x23, x20+ cinv x19, x17, cc+ subs x17, x15, x10+ csetm x15, cc+ stp x25, x24, [sp, #32]+ cneg x24, x17, cc+ mul x20, x23, x20+ subs x25, x5, x13+ cneg x13, x25, cc+ cinv x15, x15, cc+ mul x25, x24, x13+ subs x21, x21, x10+ csetm x23, cc+ cneg x17, x21, cc+ subs x21, x5, x16+ umulh x13, x24, x13+ cinv x10, x23, cc+ cneg x23, x21, cc+ cmn x4, #0x1+ adcs x14, x14, x8+ eor x21, x3, x4+ adcs x21, x22, x21+ eor x5, x20, x19+ adcs x24, x12, x4+ mul x12, x17, x23+ eor x8, x25, x15+ adc x25, x6, x4+ cmn x15, #0x1+ adcs x6, x9, x8+ ldp x20, x8, [x2, #48]+ eor x9, x13, x15+ adcs x4, x26, x9+ umulh x26, x17, x23+ ldp x17, x13, [x1, #48]+ adcs x9, x14, x15+ adcs x16, x21, x15+ adcs x14, x24, x15+ eor x21, x7, x19+ mul x23, x17, x20+ adc x24, x25, x15+ cmn x19, #0x1+ adcs x7, x4, x5+ adcs x9, x9, x21+ umulh x3, x13, x8+ adcs x16, x16, x19+ adcs x22, x14, x19+ eor x5, x12, x10+ adc x12, x24, x19+ cmn x10, #0x1+ adcs x19, x7, x5+ eor x14, x26, x10+ mov x7, v28.d[1]+ adcs x24, x9, x14+ extr x4, x19, x6, #55+ umulh x15, x17, x20+ mov x14, v18.d[1]+ lsr x9, x19, #55+ adcs x5, x16, x10+ mov x16, v18.d[0]+ adcs x19, x22, x10+ str x9, [sp, #64]+ extr x25, x6, x11, #55+ adc x21, x12, x10+ subs x26, x17, x13+ stp x25, x4, [sp, #48]+ stp x19, x21, [sp, #16]+ csetm x6, cc+ cneg x4, x26, cc+ mul x19, x13, x8+ subs x11, x8, x20+ stp x24, x5, [sp]+ ldp x21, x10, [x1, #32]+ cinv x12, x6, cc+ cneg x6, x11, cc+ mov x9, v28.d[0]+ umulh x25, x4, x6+ adds x22, x7, x16+ ldp x16, x5, [x2, #32]+ adcs x14, x23, x14+ adcs x11, x19, x15+ adc x24, x3, xzr+ adds x3, x22, x9+ adcs x15, x14, x22+ mul x22, x4, x6+ adcs x6, x11, x14+ adcs x4, x24, x11+ eor x14, x25, x12+ adc x26, xzr, x24+ subs x7, x21, x10+ csetm x23, cc+ cneg x19, x7, cc+ subs x24, x5, x16+ cneg x11, x24, cc+ cinv x7, x23, cc+ adds x25, x15, x9+ eor x23, x22, x12+ adcs x22, x6, x3+ mul x24, x19, x11+ adcs x15, x4, x15+ adcs x6, x26, x6+ umulh x19, x19, x11+ adcs x11, xzr, x4+ adc x26, xzr, x26+ cmn x12, #0x1+ adcs x4, x6, x23+ eor x6, x24, x7+ adcs x14, x11, x14+ adc x26, x26, x12+ subs x11, x10, x13+ cneg x12, x11, cc+ csetm x11, cc+ eor x19, x19, x7+ subs x24, x8, x5+ cinv x11, x11, cc+ cneg x24, x24, cc+ cmn x7, #0x1+ adcs x3, x3, x6+ mul x23, x12, x24+ adcs x25, x25, x19+ adcs x6, x22, x7+ umulh x19, x12, x24+ adcs x22, x15, x7+ adcs x12, x4, x7+ eor x24, x23, x11+ adcs x4, x14, x7+ adc x26, x26, x7+ eor x19, x19, x11+ subs x14, x21, x17+ cneg x7, x14, cc+ csetm x14, cc+ subs x23, x20, x16+ cinv x14, x14, cc+ cneg x23, x23, cc+ cmn x11, #0x1+ adcs x22, x22, x24+ mul x24, x7, x23+ adcs x15, x12, x19+ adcs x4, x4, x11+ adc x19, x26, x11+ umulh x26, x7, x23+ subs x7, x21, x13+ eor x11, x24, x14+ cneg x23, x7, cc+ csetm x12, cc+ subs x7, x8, x16+ cneg x7, x7, cc+ cinv x12, x12, cc+ cmn x14, #0x1+ eor x26, x26, x14+ adcs x11, x25, x11+ mul x25, x23, x7+ adcs x26, x6, x26+ adcs x6, x22, x14+ adcs x24, x15, x14+ umulh x23, x23, x7+ adcs x4, x4, x14+ adc x22, x19, x14+ eor x14, x25, x12+ eor x7, x23, x12+ cmn x12, #0x1+ adcs x14, x26, x14+ ldp x19, x25, [x2]+ ldp x15, x23, [x2, #16]+ adcs x26, x6, x7+ adcs x24, x24, x12+ adcs x7, x4, x12+ adc x4, x22, x12+ subs x19, x19, x16+ ldp x16, x22, [x1]+ sbcs x6, x25, x5+ ldp x12, x25, [x1, #16]+ sbcs x15, x15, x20+ sbcs x8, x23, x8+ csetm x23, cc+ subs x21, x21, x16+ eor x16, x19, x23+ sbcs x19, x10, x22+ eor x22, x6, x23+ eor x8, x8, x23+ sbcs x6, x17, x12+ sbcs x13, x13, x25+ csetm x12, cc+ subs x10, x10, x17+ cneg x17, x10, cc+ csetm x25, cc+ subs x5, x20, x5+ eor x10, x19, x12+ cneg x19, x5, cc+ eor x20, x15, x23+ eor x21, x21, x12+ cinv x15, x25, cc+ mul x25, x17, x19+ subs x16, x16, x23+ sbcs x5, x22, x23+ eor x6, x6, x12+ sbcs x20, x20, x23+ eor x22, x13, x12+ sbc x8, x8, x23+ subs x21, x21, x12+ umulh x19, x17, x19+ sbcs x10, x10, x12+ sbcs x17, x6, x12+ eor x6, x19, x15+ eor x19, x25, x15+ umulh x25, x17, x20+ sbc x13, x22, x12+ cmn x15, #0x1+ adcs x22, x14, x19+ adcs x19, x26, x6+ ldp x6, x26, [sp]+ adcs x14, x24, x15+ umulh x24, x21, x16+ adcs x7, x7, x15+ adc x15, x4, x15+ adds x4, x9, x6+ eor x9, x23, x12+ adcs x12, x3, x26+ stp x4, x12, [sp]+ ldp x4, x26, [sp, #16]+ umulh x12, x10, x5+ ldp x6, x23, [sp, #32]+ adcs x3, x11, x4+ mul x4, x13, x8+ adcs x26, x22, x26+ ldp x22, x11, [sp, #48]+ adcs x6, x19, x6+ stp x3, x26, [sp, #16]+ mul x26, x10, x5+ adcs x14, x14, x23+ stp x6, x14, [sp, #32]+ ldr x6, [sp, #64]+ adcs x22, x7, x22+ adcs x14, x15, x11+ mul x11, x17, x20+ adc x19, x6, xzr+ stp x22, x14, [sp, #48]+ adds x14, x26, x24+ str x19, [sp, #64]+ umulh x19, x13, x8+ adcs x7, x11, x12+ adcs x22, x4, x25+ mul x6, x21, x16+ adc x19, x19, xzr+ subs x11, x17, x13+ cneg x12, x11, cc+ csetm x11, cc+ subs x24, x8, x20+ cinv x11, x11, cc+ cneg x24, x24, cc+ adds x4, x14, x6+ adcs x14, x7, x14+ mul x3, x12, x24+ adcs x7, x22, x7+ adcs x22, x19, x22+ umulh x12, x12, x24+ adc x24, xzr, x19+ adds x19, x14, x6+ eor x3, x3, x11+ adcs x26, x7, x4+ adcs x14, x22, x14+ adcs x25, x24, x7+ adcs x23, xzr, x22+ eor x7, x12, x11+ adc x12, xzr, x24+ subs x22, x21, x10+ cneg x24, x22, cc+ csetm x22, cc+ subs x15, x5, x16+ cinv x22, x22, cc+ cneg x15, x15, cc+ cmn x11, #0x1+ adcs x3, x25, x3+ mul x25, x24, x15+ adcs x23, x23, x7+ adc x11, x12, x11+ subs x7, x10, x13+ umulh x15, x24, x15+ cneg x12, x7, cc+ csetm x7, cc+ eor x24, x25, x22+ eor x25, x15, x22+ cmn x22, #0x1+ adcs x24, x4, x24+ adcs x19, x19, x25+ adcs x15, x26, x22+ adcs x4, x14, x22+ adcs x26, x3, x22+ adcs x25, x23, x22+ adc x23, x11, x22+ subs x14, x21, x17+ cneg x3, x14, cc+ csetm x11, cc+ subs x14, x8, x5+ cneg x14, x14, cc+ cinv x7, x7, cc+ subs x13, x21, x13+ cneg x21, x13, cc+ csetm x13, cc+ mul x22, x12, x14+ subs x8, x8, x16+ cinv x13, x13, cc+ umulh x14, x12, x14+ cneg x12, x8, cc+ subs x8, x20, x16+ cneg x8, x8, cc+ cinv x16, x11, cc+ eor x22, x22, x7+ cmn x7, #0x1+ eor x14, x14, x7+ adcs x4, x4, x22+ mul x11, x3, x8+ adcs x22, x26, x14+ adcs x14, x25, x7+ eor x25, x24, x9+ adc x26, x23, x7+ umulh x7, x3, x8+ subs x17, x10, x17+ cneg x24, x17, cc+ eor x3, x11, x16+ csetm x11, cc+ subs x20, x20, x5+ cneg x5, x20, cc+ cinv x11, x11, cc+ cmn x16, #0x1+ mul x17, x21, x12+ eor x8, x7, x16+ adcs x10, x19, x3+ and x19, x9, #0x1ff+ adcs x20, x15, x8+ umulh x15, x21, x12+ eor x12, x10, x9+ eor x8, x6, x9+ adcs x6, x4, x16+ adcs x4, x22, x16+ adcs x21, x14, x16+ adc x7, x26, x16+ mul x10, x24, x5+ cmn x13, #0x1+ ldp x3, x14, [x1]+ eor x17, x17, x13+ umulh x5, x24, x5+ adcs x20, x20, x17+ eor x17, x15, x13+ adcs x16, x6, x17+ eor x22, x10, x11+ adcs x23, x4, x13+ extr x10, x14, x3, #52+ and x26, x3, #0xfffffffffffff+ adcs x24, x21, x13+ and x15, x10, #0xfffffffffffff+ adc x6, x7, x13+ cmn x11, #0x1+ adcs x17, x20, x22+ eor x4, x5, x11+ ldp x21, x10, [sp]+ adcs x7, x16, x4+ eor x16, x17, x9+ eor x13, x7, x9+ ldp x3, x17, [sp, #16]+ adcs x7, x23, x11+ eor x23, x7, x9+ ldp x5, x22, [sp, #32]+ adcs x7, x24, x11+ adc x24, x6, x11+ ldr x6, [x2, #64]+ adds x20, x8, x21+ lsl x11, x20, #9+ eor x4, x7, x9+ orr x7, x11, x19+ eor x8, x24, x9+ adcs x11, x25, x10+ mul x26, x6, x26+ ldp x19, x24, [sp, #48]+ adcs x12, x12, x3+ adcs x16, x16, x17+ adcs x9, x13, x5+ ldr x25, [sp, #64]+ extr x20, x11, x20, #55+ adcs x13, x23, x22+ adcs x4, x4, x19+ extr x23, x12, x11, #55+ adcs x8, x8, x24+ adc x11, x25, xzr+ adds x21, x9, x21+ extr x9, x16, x12, #55+ lsr x12, x16, #55+ adcs x10, x13, x10+ mul x15, x6, x15+ adcs x13, x4, x3+ ldp x16, x4, [x2]+ ldr x3, [x1, #64]+ adcs x17, x8, x17+ adcs x5, x5, x7+ adcs x20, x22, x20+ adcs x8, x19, x23+ and x22, x16, #0xfffffffffffff+ ldp x19, x7, [x1, #16]+ adcs x9, x24, x9+ extr x24, x4, x16, #52+ adc x16, x12, x25+ mul x22, x3, x22+ and x25, x24, #0xfffffffffffff+ extr x14, x19, x14, #40+ and x12, x14, #0xfffffffffffff+ extr x23, x7, x19, #28+ ldp x19, x24, [x2, #16]+ mul x14, x3, x25+ and x23, x23, #0xfffffffffffff+ add x22, x26, x22+ lsl x11, x11, #48+ lsr x26, x22, #52+ lsl x25, x22, #12+ mul x22, x6, x12+ extr x12, x19, x4, #40+ add x4, x15, x14+ mul x15, x6, x23+ add x4, x4, x26+ extr x23, x24, x19, #28+ ldp x14, x19, [x1, #32]+ and x26, x12, #0xfffffffffffff+ extr x12, x4, x25, #12+ and x25, x23, #0xfffffffffffff+ adds x21, x21, x12+ mul x12, x3, x26+ extr x23, x14, x7, #16+ and x23, x23, #0xfffffffffffff+ mul x7, x3, x25+ ldp x25, x26, [x2, #32]+ add x12, x22, x12+ extr x22, x19, x14, #56+ mul x23, x6, x23+ lsr x14, x14, #4+ extr x24, x25, x24, #16+ add x7, x15, x7+ and x15, x24, #0xfffffffffffff+ and x22, x22, #0xfffffffffffff+ lsr x24, x4, #52+ mul x15, x3, x15+ and x14, x14, #0xfffffffffffff+ add x12, x12, x24+ lsl x24, x4, #12+ lsr x4, x12, #52+ extr x24, x12, x24, #24+ adcs x10, x10, x24+ lsl x24, x12, #12+ add x12, x7, x4+ mul x22, x6, x22+ add x4, x23, x15+ extr x7, x12, x24, #36+ adcs x13, x13, x7+ lsl x15, x12, #12+ add x7, x4, x11+ lsr x24, x12, #52+ ldp x23, x11, [x2, #48]+ add x4, x7, x24+ mul x12, x6, x14+ extr x7, x26, x25, #56+ extr x14, x4, x15, #48+ and x2, x7, #0xfffffffffffff+ extr x24, x11, x23, #32+ ldp x15, x7, [x1, #48]+ and x1, x24, #0xfffffffffffff+ lsr x24, x4, #52+ mul x2, x3, x2+ extr x26, x23, x26, #44+ lsr x23, x25, #4+ and x23, x23, #0xfffffffffffff+ and x25, x26, #0xfffffffffffff+ extr x26, x7, x15, #32+ extr x19, x15, x19, #44+ mul x23, x3, x23+ and x15, x26, #0xfffffffffffff+ lsl x26, x4, #12+ and x4, x19, #0xfffffffffffff+ lsr x11, x11, #20+ mul x19, x6, x4+ adcs x17, x17, x14+ add x14, x22, x2+ add x22, x12, x23+ lsr x7, x7, #20+ add x22, x22, x24+ extr x2, x22, x26, #60+ mul x24, x3, x25+ lsr x22, x22, #52+ add x14, x14, x22+ lsl x22, x2, #8+ extr x22, x14, x22, #8+ lsl x2, x14, #12+ mul x1, x3, x1+ adcs x12, x5, x22+ mul x5, x6, x15+ and x26, x10, x13+ and x4, x26, x17+ add x23, x19, x24+ lsr x14, x14, #52+ mul x22, x3, x11+ add x11, x23, x14+ extr x25, x11, x2, #20+ lsl x19, x11, #12+ adcs x25, x20, x25+ and x14, x4, x12+ add x1, x5, x1+ and x14, x14, x25+ mul x15, x6, x7+ add x26, x15, x22+ mul x6, x6, x3+ lsr x22, x11, #52+ add x4, x1, x22+ lsr x1, x4, #52+ extr x3, x4, x19, #32+ lsl x15, x4, #12+ add x7, x26, x1+ adcs x23, x8, x3+ extr x20, x7, x15, #44+ and x3, x14, x23+ lsr x19, x7, #44+ adcs x7, x9, x20+ add x11, x6, x19+ adc x4, x16, x11+ lsr x14, x4, #9+ cmp xzr, xzr+ and x15, x3, x7+ orr x3, x4, #0xfffffffffffffe00+ adcs xzr, x21, x14+ adcs xzr, x15, xzr+ adcs xzr, x3, xzr+ adcs x11, x21, x14+ and x14, x11, #0x1ff+ adcs x1, x10, xzr+ extr x10, x1, x11, #9+ str x14, [x0, #64]+ adcs x14, x13, xzr+ extr x11, x14, x1, #9+ adcs x1, x17, xzr+ extr x4, x1, x14, #9+ stp x10, x11, [x0]+ adcs x11, x12, xzr+ extr x14, x11, x1, #9+ adcs x10, x25, xzr+ extr x11, x10, x11, #9+ stp x4, x14, [x0, #16]+ adcs x14, x23, xzr+ extr x10, x14, x10, #9+ adcs x1, x7, xzr+ stp x11, x10, [x0, #32]+ extr x14, x1, x14, #9+ adc x10, x3, xzr+ extr x26, x10, x1, #9+ stp x14, x26, [x0, #48]++// Restore regs and return++ CFI_INC_SP(80)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_mul_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_mul_p521_alt.S view
@@ -0,0 +1,538 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Multiply modulo p_521, z := (x * y) mod p_521, assuming x and y reduced+// Inputs x[9], y[9]; output z[9]+//+// extern void bignum_mul_p521_alt(uint64_t z[static 9],+// const uint64_t x[static 9],+// const uint64_t y[static 9]);+//+// Standard ARM ABI: X0 = z, X1 = x, X2 = y+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_mul_p521_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_mul_p521_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_mul_p521_alt)+ .text+ .balign 4++#define z x0+#define x x1+#define y x2++// These are repeated mod 2 as we load paris of inputs++#define a0 x3+#define a1 x4+#define a2 x3+#define a3 x4+#define a4 x3+#define a5 x4+#define a6 x3+#define a7 x4+#define a8 x3++#define b0 x5+#define b1 x6+#define b2 x7+#define b3 x8+#define b4 x9+#define b5 x10+#define b6 x11+#define b7 x12+#define b8 x13++#define t x14++// These repeat mod 11 as we stash some intermediate results in the+// output buffer.++#define u0 x15+#define u1 x16+#define u2 x17+#define u3 x19+#define u4 x20+#define u5 x21+#define u6 x22+#define u7 x23+#define u8 x24+#define u9 x25+#define u10 x26+#define u11 x15+#define u12 x16+#define u13 x17+#define u14 x19+#define u15 x20+#define u16 x21++S2N_BN_SYMBOL(bignum_mul_p521_alt):+ CFI_START++// Save more registers and make temporary space on stack++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_DEC_SP(64)++// Load operands and set up row 0 = [u9;...;u0] = a0 * [b8;...;b0]++ ldp a0, a1, [x]+ ldp b0, b1, [y]++ mul u0, a0, b0+ umulh u1, a0, b0+ mul t, a0, b1+ umulh u2, a0, b1+ adds u1, u1, t++ ldp b2, b3, [y, #16]++ mul t, a0, b2+ umulh u3, a0, b2+ adcs u2, u2, t++ mul t, a0, b3+ umulh u4, a0, b3+ adcs u3, u3, t++ ldp b4, b5, [y, #32]++ mul t, a0, b4+ umulh u5, a0, b4+ adcs u4, u4, t++ mul t, a0, b5+ umulh u6, a0, b5+ adcs u5, u5, t++ ldp b6, b7, [y, #48]++ mul t, a0, b6+ umulh u7, a0, b6+ adcs u6, u6, t++ ldr b8, [y, #64]++ mul t, a0, b7+ umulh u8, a0, b7+ adcs u7, u7, t++ mul t, a0, b8+ umulh u9, a0, b8+ adcs u8, u8, t++ adc u9, u9, xzr++// Row 1 = [u10;...;u0] = [a1;a0] * [b8;...;b0]++ mul t, a1, b0+ adds u1, u1, t+ mul t, a1, b1+ adcs u2, u2, t+ mul t, a1, b2+ adcs u3, u3, t+ mul t, a1, b3+ adcs u4, u4, t+ mul t, a1, b4+ adcs u5, u5, t+ mul t, a1, b5+ adcs u6, u6, t+ mul t, a1, b6+ adcs u7, u7, t+ mul t, a1, b7+ adcs u8, u8, t+ mul t, a1, b8+ adcs u9, u9, t+ cset u10, cs++ umulh t, a1, b0+ adds u2, u2, t+ umulh t, a1, b1+ adcs u3, u3, t+ umulh t, a1, b2+ adcs u4, u4, t+ umulh t, a1, b3+ adcs u5, u5, t+ umulh t, a1, b4+ adcs u6, u6, t+ umulh t, a1, b5+ adcs u7, u7, t+ umulh t, a1, b6+ adcs u8, u8, t+ umulh t, a1, b7+ adcs u9, u9, t+ umulh t, a1, b8+ adc u10, u10, t++ stp u0, u1, [sp]++// Row 2 = [u11;...;u0] = [a2;a1;a0] * [b8;...;b0]++ ldp a2, a3, [x, #16]++ mul t, a2, b0+ adds u2, u2, t+ mul t, a2, b1+ adcs u3, u3, t+ mul t, a2, b2+ adcs u4, u4, t+ mul t, a2, b3+ adcs u5, u5, t+ mul t, a2, b4+ adcs u6, u6, t+ mul t, a2, b5+ adcs u7, u7, t+ mul t, a2, b6+ adcs u8, u8, t+ mul t, a2, b7+ adcs u9, u9, t+ mul t, a2, b8+ adcs u10, u10, t+ cset u11, cs++ umulh t, a2, b0+ adds u3, u3, t+ umulh t, a2, b1+ adcs u4, u4, t+ umulh t, a2, b2+ adcs u5, u5, t+ umulh t, a2, b3+ adcs u6, u6, t+ umulh t, a2, b4+ adcs u7, u7, t+ umulh t, a2, b5+ adcs u8, u8, t+ umulh t, a2, b6+ adcs u9, u9, t+ umulh t, a2, b7+ adcs u10, u10, t+ umulh t, a2, b8+ adc u11, u11, t++// Row 3 = [u12;...;u0] = [a3;a2;a1;a0] * [b8;...;b0]++ mul t, a3, b0+ adds u3, u3, t+ mul t, a3, b1+ adcs u4, u4, t+ mul t, a3, b2+ adcs u5, u5, t+ mul t, a3, b3+ adcs u6, u6, t+ mul t, a3, b4+ adcs u7, u7, t+ mul t, a3, b5+ adcs u8, u8, t+ mul t, a3, b6+ adcs u9, u9, t+ mul t, a3, b7+ adcs u10, u10, t+ mul t, a3, b8+ adcs u11, u11, t+ cset u12, cs++ umulh t, a3, b0+ adds u4, u4, t+ umulh t, a3, b1+ adcs u5, u5, t+ umulh t, a3, b2+ adcs u6, u6, t+ umulh t, a3, b3+ adcs u7, u7, t+ umulh t, a3, b4+ adcs u8, u8, t+ umulh t, a3, b5+ adcs u9, u9, t+ umulh t, a3, b6+ adcs u10, u10, t+ umulh t, a3, b7+ adcs u11, u11, t+ umulh t, a3, b8+ adc u12, u12, t++ stp u2, u3, [sp, #16]++// Row 4 = [u13;...;u0] = [a4;a3;a2;a1;a0] * [b8;...;b0]++ ldp a4, a5, [x, #32]++ mul t, a4, b0+ adds u4, u4, t+ mul t, a4, b1+ adcs u5, u5, t+ mul t, a4, b2+ adcs u6, u6, t+ mul t, a4, b3+ adcs u7, u7, t+ mul t, a4, b4+ adcs u8, u8, t+ mul t, a4, b5+ adcs u9, u9, t+ mul t, a4, b6+ adcs u10, u10, t+ mul t, a4, b7+ adcs u11, u11, t+ mul t, a4, b8+ adcs u12, u12, t+ cset u13, cs++ umulh t, a4, b0+ adds u5, u5, t+ umulh t, a4, b1+ adcs u6, u6, t+ umulh t, a4, b2+ adcs u7, u7, t+ umulh t, a4, b3+ adcs u8, u8, t+ umulh t, a4, b4+ adcs u9, u9, t+ umulh t, a4, b5+ adcs u10, u10, t+ umulh t, a4, b6+ adcs u11, u11, t+ umulh t, a4, b7+ adcs u12, u12, t+ umulh t, a4, b8+ adc u13, u13, t++// Row 5 = [u14;...;u0] = [a5;a4;a3;a2;a1;a0] * [b8;...;b0]++ mul t, a5, b0+ adds u5, u5, t+ mul t, a5, b1+ adcs u6, u6, t+ mul t, a5, b2+ adcs u7, u7, t+ mul t, a5, b3+ adcs u8, u8, t+ mul t, a5, b4+ adcs u9, u9, t+ mul t, a5, b5+ adcs u10, u10, t+ mul t, a5, b6+ adcs u11, u11, t+ mul t, a5, b7+ adcs u12, u12, t+ mul t, a5, b8+ adcs u13, u13, t+ cset u14, cs++ umulh t, a5, b0+ adds u6, u6, t+ umulh t, a5, b1+ adcs u7, u7, t+ umulh t, a5, b2+ adcs u8, u8, t+ umulh t, a5, b3+ adcs u9, u9, t+ umulh t, a5, b4+ adcs u10, u10, t+ umulh t, a5, b5+ adcs u11, u11, t+ umulh t, a5, b6+ adcs u12, u12, t+ umulh t, a5, b7+ adcs u13, u13, t+ umulh t, a5, b8+ adc u14, u14, t++ stp u4, u5, [sp, #32]++// Row 6 = [u15;...;u0] = [a6;a5;a4;a3;a2;a1;a0] * [b8;...;b0]++ ldp a6, a7, [x, #48]++ mul t, a6, b0+ adds u6, u6, t+ mul t, a6, b1+ adcs u7, u7, t+ mul t, a6, b2+ adcs u8, u8, t+ mul t, a6, b3+ adcs u9, u9, t+ mul t, a6, b4+ adcs u10, u10, t+ mul t, a6, b5+ adcs u11, u11, t+ mul t, a6, b6+ adcs u12, u12, t+ mul t, a6, b7+ adcs u13, u13, t+ mul t, a6, b8+ adcs u14, u14, t+ cset u15, cs++ umulh t, a6, b0+ adds u7, u7, t+ umulh t, a6, b1+ adcs u8, u8, t+ umulh t, a6, b2+ adcs u9, u9, t+ umulh t, a6, b3+ adcs u10, u10, t+ umulh t, a6, b4+ adcs u11, u11, t+ umulh t, a6, b5+ adcs u12, u12, t+ umulh t, a6, b6+ adcs u13, u13, t+ umulh t, a6, b7+ adcs u14, u14, t+ umulh t, a6, b8+ adc u15, u15, t++// Row 7 = [u16;...;u0] = [a7;a6;a5;a4;a3;a2;a1;a0] * [b8;...;b0]++ mul t, a7, b0+ adds u7, u7, t+ mul t, a7, b1+ adcs u8, u8, t+ mul t, a7, b2+ adcs u9, u9, t+ mul t, a7, b3+ adcs u10, u10, t+ mul t, a7, b4+ adcs u11, u11, t+ mul t, a7, b5+ adcs u12, u12, t+ mul t, a7, b6+ adcs u13, u13, t+ mul t, a7, b7+ adcs u14, u14, t+ mul t, a7, b8+ adcs u15, u15, t+ cset u16, cs++ umulh t, a7, b0+ adds u8, u8, t+ umulh t, a7, b1+ adcs u9, u9, t+ umulh t, a7, b2+ adcs u10, u10, t+ umulh t, a7, b3+ adcs u11, u11, t+ umulh t, a7, b4+ adcs u12, u12, t+ umulh t, a7, b5+ adcs u13, u13, t+ umulh t, a7, b6+ adcs u14, u14, t+ umulh t, a7, b7+ adcs u15, u15, t+ umulh t, a7, b8+ adc u16, u16, t++ stp u6, u7, [sp, #48]++// Row 8 = [u16;...;u0] = [a8;a7;a6;a5;a4;a3;a2;a1;a0] * [b8;...;b0]++ ldr a8, [x, #64]++ mul t, a8, b0+ adds u8, u8, t+ mul t, a8, b1+ adcs u9, u9, t+ mul t, a8, b2+ adcs u10, u10, t+ mul t, a8, b3+ adcs u11, u11, t+ mul t, a8, b4+ adcs u12, u12, t+ mul t, a8, b5+ adcs u13, u13, t+ mul t, a8, b6+ adcs u14, u14, t+ mul t, a8, b7+ adcs u15, u15, t+ mul t, a8, b8+ adc u16, u16, t++ umulh t, a8, b0+ adds u9, u9, t+ umulh t, a8, b1+ adcs u10, u10, t+ umulh t, a8, b2+ adcs u11, u11, t+ umulh t, a8, b3+ adcs u12, u12, t+ umulh t, a8, b4+ adcs u13, u13, t+ umulh t, a8, b5+ adcs u14, u14, t+ umulh t, a8, b6+ adcs u15, u15, t+ umulh t, a8, b7+ adc u16, u16, t++// Now we have the full product, which we consider as+// 2^521 * h + l. Form h + l + 1++ subs xzr, xzr, xzr+ ldp b0, b1, [sp]+ extr t, u9, u8, #9+ adcs b0, b0, t+ extr t, u10, u9, #9+ adcs b1, b1, t+ ldp b2, b3, [sp, #16]+ extr t, u11, u10, #9+ adcs b2, b2, t+ extr t, u12, u11, #9+ adcs b3, b3, t+ ldp b4, b5, [sp, #32]+ extr t, u13, u12, #9+ adcs b4, b4, t+ extr t, u14, u13, #9+ adcs b5, b5, t+ ldp b6, b7, [sp, #48]+ extr t, u15, u14, #9+ adcs b6, b6, t+ extr t, u16, u15, #9+ adcs b7, b7, t+ orr b8, u8, #~0x1FF+ lsr t, u16, #9+ adcs b8, b8, t++// Now CF is set if h + l + 1 >= 2^521, which means it's already+// the answer, while if ~CF the answer is h + l so we should subtract+// 1 (all considered in 521 bits). Hence subtract ~CF and mask.++ sbcs b0, b0, xzr+ sbcs b1, b1, xzr+ sbcs b2, b2, xzr+ sbcs b3, b3, xzr+ sbcs b4, b4, xzr+ sbcs b5, b5, xzr+ sbcs b6, b6, xzr+ sbcs b7, b7, xzr+ sbc b8, b8, xzr+ and b8, b8, #0x1FF++// Store back digits of final result++ stp b0, b1, [z]+ stp b2, b3, [z, #16]+ stp b4, b5, [z, #32]+ stp b6, b7, [z, #48]+ str b8, [z, #64]++// Restore registers++ CFI_INC_SP(64)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_mul_p521_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_neg_p256.S view
@@ -0,0 +1,72 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Negate modulo p_256, z := (-x) mod p_256, assuming x reduced+// Input x[4]; output z[4]+//+// extern void bignum_neg_p256(uint64_t z[static 4], const uint64_t x[static 4]);+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_neg_p256)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_neg_p256)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_neg_p256)+ .text+ .balign 4++#define z x0+#define x x1++#define p x2+#define t x3++#define d0 x4+#define d1 x5+#define d2 x6+#define d3 x7+++S2N_BN_SYMBOL(bignum_neg_p256):+ CFI_START++// Load the 4 digits of x++ ldp d0, d1, [x]+ ldp d2, d3, [x, #16]++// Set a bitmask p for the input being nonzero, so that we avoid doing+// -0 = p_256 and hence maintain strict modular reduction++ orr t, d0, d1+ orr p, d2, d3+ orr p, p, t+ cmp p, #0+ csetm p, ne++// Mask the nontrivial words of p_256 = [n3;0;n1;-1] and subtract++ subs d0, p, d0+ and t, p, #0x00000000ffffffff+ sbcs d1, t, d1+ sbcs d2, xzr, d2+ and t, p, #0xffffffff00000001+ sbc d3, t, d3++// Write back the result++ stp d0, d1, [z]+ stp d2, d3, [z, #16]++// Return++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_neg_p256)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_sqr_p521.S view
@@ -0,0 +1,1125 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Square modulo p_521, z := (x^2) mod p_521, assuming x reduced+// Input x[9]; output z[9]+//+// extern void bignum_sqr_p521(uint64_t z[static 9], const uint64_t x[static 9]);+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++// bignum_sqr_p521 is functionally equivalent to unopt/bignum_sqr_p521_base.+// It is written in a way that+// 1. A subset of scalar multiplications in bignum_montmul_p384 are carefully+// chosen and vectorized+// 2. The vectorized assembly is rescheduled using the SLOTHY superoptimizer.+// https://github.com/slothy-optimizer/slothy+//+// The output program of step 1. is as follows:+//+// stp x19, x20, [sp, #-16]!+// stp x21, x22, [sp, #-16]!+// stp x23, x24, [sp, #-16]!+// ldp x20, x19, [x1]+// ldr q23, [x1]+// ldr q1, [x1]+// ldr q16, [x1]+// ldp x14, x12, [x1, #16]+// ldr q28, [x1, #16]+// ldr q31, [x1, #16]+// ldp x9, x2, [x1, #32]+// ldr q29, [x1, #32]+// ldr q4, [x1, #32]+// ldr q5, [x1]+// ldr q2, [x1, #32]+// ldp x6, x13, [x1, #48]+// ldr q24, [x1, #48]+// ldr q27, [x1, #48]+// ldr q0, [x1, #16]+// ldr q30, [x1, #48]+// mul x17, x9, x6+// mul x10, x2, x13+// umulh x24, x9, x6+// subs x4, x9, x2+// cneg x4, x4, cc+// csetm x16, cc+// subs x3, x13, x6+// cneg x23, x3, cc+// mul x3, x4, x23+// umulh x4, x4, x23+// cinv x22, x16, cc+// eor x23, x3, x22+// eor x16, x4, x22+// adds x3, x17, x24+// adc x24, x24, xzr+// umulh x4, x2, x13+// adds x3, x3, x10+// adcs x24, x24, x4+// adc x4, x4, xzr+// adds x24, x24, x10+// adc x10, x4, xzr+// cmn x22, #0x1+// adcs x4, x3, x23+// adcs x24, x24, x16+// adc x10, x10, x22+// adds x8, x17, x17+// adcs x22, x4, x4+// adcs x5, x24, x24+// adcs x11, x10, x10+// adc x23, xzr, xzr+// movi v25.2D, #0xffffffff+// uzp2 v19.4S, v4.4S, v4.4S+// xtn v26.2S, v29.2D+// xtn v22.2S, v4.2D+// rev64 v4.4S, v4.4S+// umull v7.2D, v26.2S, v22.2S+// umull v21.2D, v26.2S, v19.2S+// uzp2 v17.4S, v29.4S, v29.4S+// mul v4.4S, v4.4S, v29.4S+// usra v21.2D, v7.2D, #32+// umull v18.2D, v17.2S, v19.2S+// uaddlp v4.2D, v4.4S+// and v7.16B, v21.16B, v25.16B+// umlal v7.2D, v17.2S, v22.2S+// shl v4.2D, v4.2D, #32+// usra v18.2D, v21.2D, #32+// umlal v4.2D, v26.2S, v22.2S+// usra v18.2D, v7.2D, #32+// mov x15, v4.d[0]+// mov x16, v4.d[1]+// mul x3, x9, x2+// mov x10, v18.d[0]+// mov x17, v18.d[1]+// umulh x4, x9, x2+// adds x24, x10, x3+// adcs x10, x16, x4+// adc x17, x17, xzr+// adds x7, x24, x3+// adcs x10, x10, x4+// adc x17, x17, xzr+// adds x8, x8, x10+// adcs x22, x22, x17+// adcs x21, x5, xzr+// adcs x5, x11, xzr+// adc x11, x23, xzr+// movi v25.2D, #0xffffffff+// uzp2 v19.4S, v27.4S, v27.4S+// xtn v26.2S, v24.2D+// xtn v22.2S, v27.2D+// rev64 v4.4S, v27.4S+// umull v7.2D, v26.2S, v22.2S+// umull v21.2D, v26.2S, v19.2S+// uzp2 v17.4S, v24.4S, v24.4S+// mul v4.4S, v4.4S, v24.4S+// usra v21.2D, v7.2D, #32+// umull v18.2D, v17.2S, v19.2S+// uaddlp v4.2D, v4.4S+// and v7.16B, v21.16B, v25.16B+// umlal v7.2D, v17.2S, v22.2S+// shl v4.2D, v4.2D, #32+// usra v18.2D, v21.2D, #32+// umlal v4.2D, v26.2S, v22.2S+// usra v18.2D, v7.2D, #32+// mov x23, v4.d[0]+// mov x16, v4.d[1]+// mul x3, x6, x13+// mov x10, v18.d[0]+// mov x17, v18.d[1]+// umulh x4, x6, x13+// adds x24, x10, x3+// adcs x10, x16, x4+// adc x17, x17, xzr+// adds x24, x24, x3+// adcs x10, x10, x4+// adc x17, x17, xzr+// adds x23, x23, x21+// adcs x16, x24, x5+// adcs x3, x10, x11+// adc x21, x17, xzr+// ldr x17, [x1, #64]+// add x5, x17, x17+// mul x11, x17, x17+// and x17, x20, #0xfffffffffffff+// mul x4, x5, x17+// extr x17, x19, x20, #52+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x4, #52+// add x24, x10, x17+// lsl x17, x4, #12+// extr x17, x24, x17, #12+// adds x15, x15, x17+// extr x17, x14, x19, #40+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x24, #52+// add x4, x10, x17+// lsl x17, x24, #12+// extr x17, x4, x17, #24+// adcs x7, x7, x17+// extr x17, x12, x14, #28+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x4, #52+// add x24, x10, x17+// lsl x17, x4, #12+// extr x17, x24, x17, #36+// adcs x8, x8, x17+// extr x17, x9, x12, #16+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x24, #52+// add x4, x10, x17+// lsl x17, x24, #12+// extr x17, x4, x17, #48+// adcs x22, x22, x17+// lsr x17, x9, #4+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x4, #52+// add x24, x10, x17+// lsl x17, x4, #12+// extr x4, x24, x17, #60+// extr x17, x2, x9, #56+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x24, #52+// add x24, x10, x17+// lsl x17, x4, #8+// extr x17, x24, x17, #8+// adcs x23, x23, x17+// extr x17, x6, x2, #44+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x24, #52+// add x4, x10, x17+// lsl x17, x24, #12+// extr x17, x4, x17, #20+// adcs x16, x16, x17+// extr x17, x13, x6, #32+// and x17, x17, #0xfffffffffffff+// mul x10, x5, x17+// lsr x17, x4, #52+// add x24, x10, x17+// lsl x17, x4, #12+// extr x17, x24, x17, #32+// adcs x3, x3, x17+// lsr x17, x13, #20+// mul x10, x5, x17+// lsr x17, x24, #52+// add x10, x10, x17+// lsl x17, x24, #12+// extr x17, x10, x17, #44+// adcs x4, x21, x17+// lsr x17, x10, #44+// adc x24, x11, x17+// extr x10, x7, x15, #9+// extr x17, x8, x7, #9+// stp x10, x17, [x0] // @slothy:writes=buffer0+// extr x10, x22, x8, #9+// extr x17, x23, x22, #9+// stp x10, x17, [x0, #16] // @slothy:writes=buffer16+// extr x10, x16, x23, #9+// extr x17, x3, x16, #9+// stp x10, x17, [x0, #32] // @slothy:writes=buffer32+// extr x10, x4, x3, #9+// extr x17, x24, x4, #9+// stp x10, x17, [x0, #48] // @slothy:writes=buffer48+// and x10, x15, #0x1ff+// lsr x17, x24, #9+// add x17, x10, x17+// str x17, [x0, #64] // @slothy:writes=buffer64+// uzp1 v17.4S, v28.4S, v23.4S+// rev64 v4.4S, v28.4S+// uzp1 v7.4S, v23.4S, v23.4S+// mul v4.4S, v4.4S, v23.4S+// uaddlp v4.2D, v4.4S+// shl v4.2D, v4.2D, #32+// umlal v4.2D, v7.2S, v17.2S+// mov x8, v4.d[0]+// mov x22, v4.d[1]+// umulh x23, x20, x14+// subs x17, x20, x19+// cneg x4, x17, cc+// csetm x24, cc+// subs x17, x12, x14+// cneg x17, x17, cc+// mul x10, x4, x17+// umulh x17, x4, x17+// cinv x16, x24, cc+// eor x3, x10, x16+// eor x4, x17, x16+// adds x24, x8, x23+// adc x10, x23, xzr+// umulh x17, x19, x12+// adds x24, x24, x22+// adcs x10, x10, x17+// adc x17, x17, xzr+// adds x10, x10, x22+// adc x17, x17, xzr+// cmn x16, #0x1+// adcs x24, x24, x3+// adcs x10, x10, x4+// adc x17, x17, x16+// adds x15, x8, x8+// adcs x7, x24, x24+// adcs x8, x10, x10+// adcs x22, x17, x17+// adc x23, xzr, xzr+// movi v25.2D, #0xffffffff+// uzp2 v19.4S, v16.4S, v16.4S+// xtn v26.2S, v1.2D+// xtn v22.2S, v16.2D+// rev64 v4.4S, v16.4S+// umull v7.2D, v26.2S, v22.2S+// umull v21.2D, v26.2S, v19.2S+// uzp2 v17.4S, v1.4S, v1.4S+// mul v4.4S, v4.4S, v1.4S+// usra v21.2D, v7.2D, #32+// umull v18.2D, v17.2S, v19.2S+// uaddlp v4.2D, v4.4S+// and v7.16B, v21.16B, v25.16B+// umlal v7.2D, v17.2S, v22.2S+// shl v4.2D, v4.2D, #32+// usra v18.2D, v21.2D, #32+// umlal v4.2D, v26.2S, v22.2S+// usra v18.2D, v7.2D, #32+// mov x21, v4.d[0]+// mov x16, v4.d[1]+// mul x3, x20, x19+// mov x10, v18.d[0]+// mov x17, v18.d[1]+// umulh x4, x20, x19+// adds x24, x10, x3+// adcs x10, x16, x4+// adc x17, x17, xzr+// adds x5, x24, x3+// adcs x10, x10, x4+// adc x17, x17, xzr+// adds x11, x15, x10+// adcs x15, x7, x17+// adcs x7, x8, xzr+// adcs x8, x22, xzr+// adc x22, x23, xzr+// xtn v7.2S, v31.2D+// shrn v4.2S, v31.2D, #32+// umull v4.2D, v7.2S, v4.2S+// shl v4.2D, v4.2D, #33+// umlal v4.2D, v7.2S, v7.2S+// mov x23, v4.d[0]+// mov x16, v4.d[1]+// mul x3, x14, x12+// umulh x10, x14, x14+// umulh x17, x12, x12+// umulh x4, x14, x12+// adds x24, x10, x3+// adcs x10, x16, x4+// adc x17, x17, xzr+// adds x24, x24, x3+// adcs x10, x10, x4+// adc x17, x17, xzr+// adds x16, x23, x7+// adcs x3, x24, x8+// adcs x4, x10, x22+// adc x24, x17, xzr+// ldp x10, x17, [x0] // @slothy:reads=buffer0+// adds x10, x10, x21+// adcs x17, x17, x5+// stp x10, x17, [x0] // @slothy:writes=buffer0+// ldp x10, x17, [x0, #16] // @slothy:reads=buffer16+// adcs x10, x10, x11+// adcs x17, x17, x15+// stp x10, x17, [x0, #16] // @slothy:writes=buffer16+// ldp x10, x17, [x0, #32] // @slothy:reads=buffer32+// adcs x10, x10, x16+// adcs x17, x17, x3+// stp x10, x17, [x0, #32] // @slothy:writes=buffer32+// ldp x10, x17, [x0, #48] // @slothy:reads=buffer48+// adcs x10, x10, x4+// adcs x17, x17, x24+// stp x10, x17, [x0, #48] // @slothy:writes=buffer48+// ldr x17, [x0, #64] // @slothy:reads=buffer64+// adc x17, x17, xzr+// str x17, [x0, #64] // @slothy:writes=buffer64+// movi v25.2D, #0xffffffff+// uzp2 v19.4S, v2.4S, v2.4S+// xtn v26.2S, v5.2D+// xtn v22.2S, v2.2D+// rev64 v4.4S, v2.4S+// umull v7.2D, v26.2S, v22.2S+// umull v21.2D, v26.2S, v19.2S+// uzp2 v17.4S, v5.4S, v5.4S+// mul v4.4S, v4.4S, v5.4S+// usra v21.2D, v7.2D, #32+// umull v18.2D, v17.2S, v19.2S+// uaddlp v4.2D, v4.4S+// and v7.16B, v21.16B, v25.16B+// umlal v7.2D, v17.2S, v22.2S+// shl v4.2D, v4.2D, #32+// usra v18.2D, v21.2D, #32+// umlal v4.2D, v26.2S, v22.2S+// usra v18.2D, v7.2D, #32+// mov x5, v4.d[0]+// mov x4, v4.d[1]+// movi v25.2D, #0xffffffff+// uzp2 v17.4S, v30.4S, v30.4S+// xtn v19.2S, v0.2D+// xtn v26.2S, v30.2D+// rev64 v4.4S, v30.4S+// umull v7.2D, v19.2S, v26.2S+// umull v22.2D, v19.2S, v17.2S+// uzp2 v21.4S, v0.4S, v0.4S+// mul v4.4S, v4.4S, v0.4S+// usra v22.2D, v7.2D, #32+// umull v17.2D, v21.2S, v17.2S+// uaddlp v4.2D, v4.4S+// and v7.16B, v22.16B, v25.16B+// umlal v7.2D, v21.2S, v26.2S+// shl v4.2D, v4.2D, #32+// usra v17.2D, v22.2D, #32+// umlal v4.2D, v19.2S, v26.2S+// usra v17.2D, v7.2D, #32+// mov x24, v4.d[0]+// mov x10, v4.d[1]+// mov x17, v18.d[0]+// adds x4, x4, x17+// mov x17, v18.d[1]+// adcs x24, x24, x17+// mov x17, v17.d[0]+// adcs x10, x10, x17+// mov x17, v17.d[1]+// adc x17, x17, xzr+// adds x15, x4, x5+// adcs x4, x24, x4+// adcs x24, x10, x24+// adcs x10, x17, x10+// adc x17, xzr, x17+// adds x7, x4, x5+// adcs x8, x24, x15+// adcs x22, x10, x4+// adcs x23, x17, x24+// adcs x16, xzr, x10+// adc x3, xzr, x17+// subs x17, x14, x12+// cneg x24, x17, cc+// csetm x4, cc+// subs x17, x13, x6+// cneg x10, x17, cc+// mul x17, x24, x10+// umulh x24, x24, x10+// cinv x10, x4, cc+// cmn x10, #0x1+// eor x17, x17, x10+// adcs x23, x23, x17+// eor x17, x24, x10+// adcs x16, x16, x17+// adc x3, x3, x10+// subs x17, x20, x19+// cneg x24, x17, cc+// csetm x4, cc+// subs x17, x2, x9+// cneg x10, x17, cc+// mul x17, x24, x10+// umulh x24, x24, x10+// cinv x10, x4, cc+// cmn x10, #0x1+// eor x17, x17, x10+// adcs x11, x15, x17+// eor x17, x24, x10+// adcs x15, x7, x17+// adcs x7, x8, x10+// adcs x22, x22, x10+// adcs x23, x23, x10+// adcs x16, x16, x10+// adc x3, x3, x10+// subs x17, x19, x12+// cneg x24, x17, cc+// csetm x4, cc+// subs x17, x13, x2+// cneg x10, x17, cc+// mul x17, x24, x10+// umulh x24, x24, x10+// cinv x10, x4, cc+// cmn x10, #0x1+// eor x17, x17, x10+// adcs x8, x22, x17+// eor x17, x24, x10+// adcs x23, x23, x17+// adcs x16, x16, x10+// adc x3, x3, x10+// subs x17, x20, x14+// cneg x24, x17, cc+// csetm x4, cc+// subs x17, x6, x9+// cneg x10, x17, cc+// mul x17, x24, x10+// umulh x24, x24, x10+// cinv x10, x4, cc+// cmn x10, #0x1+// eor x17, x17, x10+// adcs x22, x15, x17+// eor x17, x24, x10+// adcs x4, x7, x17+// adcs x24, x8, x10+// adcs x23, x23, x10+// adcs x16, x16, x10+// adc x3, x3, x10+// subs x12, x20, x12+// cneg x10, x12, cc+// csetm x17, cc+// subs x12, x13, x9+// cneg x9, x12, cc+// mul x12, x10, x9+// umulh x13, x10, x9+// cinv x9, x17, cc+// cmn x9, #0x1+// eor x12, x12, x9+// adcs x4, x4, x12+// eor x12, x13, x9+// adcs x24, x24, x12+// adcs x10, x23, x9+// adcs x17, x16, x9+// adc x13, x3, x9+// subs x19, x19, x14+// cneg x12, x19, cc+// csetm x9, cc+// subs x6, x6, x2+// cneg x14, x6, cc+// mul x19, x12, x14+// umulh x12, x12, x14+// cinv x14, x9, cc+// cmn x14, #0x1+// eor x19, x19, x14+// adcs x23, x4, x19+// eor x19, x12, x14+// adcs x16, x24, x19+// adcs x6, x10, x14+// adcs x2, x17, x14+// adc x9, x13, x14+// ldp x12, x14, [x0] // @slothy:reads=buffer0+// extr x19, x6, x16, #8+// adds x10, x19, x12+// extr x19, x2, x6, #8+// adcs x17, x19, x14+// ldp x14, x12, [x0, #16] // @slothy:reads=buffer16+// extr x19, x9, x2, #8+// adcs x13, x19, x14+// and x14, x17, x13+// lsr x19, x9, #8+// adcs x6, x19, x12+// and x9, x14, x6+// ldp x14, x12, [x0, #32] // @slothy:reads=buffer32+// lsl x19, x5, #1+// adcs x2, x19, x14+// and x14, x9, x2+// extr x19, x11, x5, #63+// adcs x3, x19, x12+// and x9, x14, x3+// ldp x14, x12, [x0, #48] // @slothy:reads=buffer48+// extr x19, x22, x11, #63+// adcs x4, x19, x14+// and x14, x9, x4+// extr x19, x23, x22, #63+// adcs x24, x19, x12+// and x12, x14, x24+// ldr x14, [x0, #64] // @slothy:reads=buffer64+// extr x19, x16, x23, #63+// and x19, x19, #0x1ff+// adc x19, x14, x19+// lsr x14, x19, #9+// orr x19, x19, #0xfffffffffffffe00+// cmp xzr, xzr+// adcs xzr, x10, x14+// adcs xzr, x12, xzr+// adcs xzr, x19, xzr+// adcs x10, x10, x14+// adcs x17, x17, xzr+// adcs x13, x13, xzr+// adcs x6, x6, xzr+// adcs x2, x2, xzr+// adcs x9, x3, xzr+// adcs x12, x4, xzr+// adcs x14, x24, xzr+// adc x19, x19, xzr+// and x19, x19, #0x1ff+// stp x10, x17, [x0] // @slothy:writes=buffer0+// stp x13, x6, [x0, #16] // @slothy:writes=buffer16+// stp x2, x9, [x0, #32] // @slothy:writes=buffer32+// stp x12, x14, [x0, #48] // @slothy:writes=buffer48+// str x19, [x0, #64] // @slothy:writes=buffer64+// ldp x23, x24, [sp], #16+// ldp x21, x22, [sp], #16+// ldp x19, x20, [sp], #16+// ret+//+// The bash script used for step 2 is as follows:+//+// # Store the assembly instructions except the last 'ret',+// # callee-register store/loads as, say, 'input.S'.+// export OUTPUTS="[hint_buffer0,hint_buffer16,hint_buffer32,hint_buffer48,hint_buffer64]"+// export RESERVED_REGS="[x18,x25,x26,x27,x28,x29,x30,sp,q8,q9,q10,q11,q12,q13,q14,q15,v8,v9,v10,v11,v12,v13,v14,v15]"+// <s2n-bignum>/tools/external/slothy.sh input.S my_out_dir+// # my_out_dir/3.opt.s is the optimized assembly. Its output may differ+// # from this file since the sequence is non-deterministically chosen.+// # Please add 'ret' at the end of the output assembly.++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_sqr_p521)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_sqr_p521)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_sqr_p521)+ .text+ .balign 4++S2N_BN_SYMBOL(bignum_sqr_p521):+ CFI_START++// Save registers++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)++ ldr q23, [x1, #32]+ ldp x9, x2, [x1, #32]+ ldr q16, [x1, #32]+ ldr q20, [x1, #48]+ ldp x6, x13, [x1, #48]+ rev64 v2.4S, v23.4S+ mul x14, x9, x2+ ldr q31, [x1, #48]+ subs x22, x9, x2+ uzp2 v26.4S, v23.4S, v23.4S+ mul v30.4S, v2.4S, v16.4S+ xtn v0.2S, v20.2D+ csetm x12, cc+ xtn v21.2S, v16.2D+ xtn v23.2S, v23.2D+ umulh x10, x9, x6+ rev64 v27.4S, v31.4S+ umull v2.2D, v21.2S, v26.2S+ cneg x23, x22, cc+ uaddlp v25.2D, v30.4S+ umull v18.2D, v21.2S, v23.2S+ mul x22, x9, x6+ mul v6.4S, v27.4S, v20.4S+ uzp2 v17.4S, v20.4S, v20.4S+ shl v20.2D, v25.2D, #32+ uzp2 v27.4S, v31.4S, v31.4S+ mul x16, x2, x13+ umlal v20.2D, v21.2S, v23.2S+ usra v2.2D, v18.2D, #32+ adds x8, x22, x10+ umull v25.2D, v17.2S, v27.2S+ xtn v31.2S, v31.2D+ movi v1.2D, #0xffffffff+ adc x3, x10, xzr+ umulh x21, x2, x13+ uzp2 v21.4S, v16.4S, v16.4S+ umull v18.2D, v0.2S, v27.2S+ subs x19, x13, x6+ and v7.16B, v2.16B, v1.16B+ umull v27.2D, v0.2S, v31.2S+ cneg x20, x19, cc+ movi v30.2D, #0xffffffff+ umull v16.2D, v21.2S, v26.2S+ umlal v7.2D, v21.2S, v23.2S+ mul x19, x23, x20+ cinv x7, x12, cc+ uaddlp v6.2D, v6.4S+ eor x12, x19, x7+ adds x11, x8, x16+ umulh x10, x23, x20+ ldr q1, [x1]+ usra v16.2D, v2.2D, #32+ adcs x19, x3, x21+ shl v2.2D, v6.2D, #32+ adc x20, x21, xzr+ adds x17, x19, x16+ usra v18.2D, v27.2D, #32+ adc x19, x20, xzr+ cmn x7, #0x1+ umlal v2.2D, v0.2S, v31.2S+ umulh x16, x9, x2+ adcs x8, x11, x12+ usra v16.2D, v7.2D, #32+ ldr x12, [x1, #64]+ eor x20, x10, x7+ umulh x10, x6, x13+ mov x23, v2.d[0]+ mov x3, v2.d[1]+ adcs x21, x17, x20+ usra v25.2D, v18.2D, #32+ and v23.16B, v18.16B, v30.16B+ adc x7, x19, x7+ adds x22, x22, x22+ ldr q7, [x1, #16]+ adcs x17, x8, x8+ umlal v23.2D, v17.2S, v31.2S+ mov x19, v16.d[0]+ mul x11, x12, x12+ ldr q4, [x1]+ usra v25.2D, v23.2D, #32+ add x5, x12, x12+ adcs x15, x21, x21+ ldr q28, [x1]+ mov x12, v20.d[1]+ adcs x24, x7, x7+ mov x21, v16.d[1]+ adc x4, xzr, xzr+ adds x19, x19, x14+ ldr q18, [x1, #16]+ xtn v26.2S, v1.2D+ adcs x8, x12, x16+ adc x21, x21, xzr+ adds x7, x19, x14+ xtn v23.2S, v7.2D+ rev64 v21.4S, v28.4S+ adcs x12, x8, x16+ ldp x20, x19, [x1]+ mov x16, v25.d[1]+ xtn v22.2S, v28.2D+ adc x14, x21, xzr+ adds x8, x22, x12+ uzp2 v24.4S, v28.4S, v28.4S+ rev64 v28.4S, v18.4S+ mul x12, x6, x13+ mul v16.4S, v21.4S, v1.4S+ shrn v31.2S, v7.2D, #32+ adcs x22, x17, x14+ mov x14, v25.d[0]+ and x21, x20, #0xfffffffffffff+ umull v17.2D, v26.2S, v24.2S+ ldr q2, [x1, #32]+ adcs x17, x15, xzr+ ldr q30, [x1, #48]+ umull v7.2D, v26.2S, v22.2S+ adcs x15, x24, xzr+ ldr q0, [x1, #16]+ movi v6.2D, #0xffffffff+ adc x4, x4, xzr+ adds x14, x14, x12+ uzp1 v27.4S, v18.4S, v4.4S+ uzp2 v19.4S, v1.4S, v1.4S+ adcs x24, x3, x10+ mul x3, x5, x21+ umull v29.2D, v23.2S, v31.2S+ ldr q5, [x1]+ adc x21, x16, xzr+ adds x16, x14, x12+ extr x12, x19, x20, #52+ umull v18.2D, v19.2S, v24.2S+ adcs x24, x24, x10+ and x10, x12, #0xfffffffffffff+ ldp x14, x12, [x1, #16]+ usra v17.2D, v7.2D, #32+ adc x21, x21, xzr+ adds x23, x23, x17+ mul x17, x5, x10+ shl v21.2D, v29.2D, #33+ lsl x10, x3, #12+ lsr x1, x3, #52+ rev64 v29.4S, v2.4S+ uaddlp v25.2D, v16.4S+ add x17, x17, x1+ adcs x16, x16, x15+ extr x3, x14, x19, #40+ mov x15, v20.d[0]+ extr x10, x17, x10, #12+ and x3, x3, #0xfffffffffffff+ shl v3.2D, v25.2D, #32+ and v6.16B, v17.16B, v6.16B+ mul x1, x5, x3+ usra v18.2D, v17.2D, #32+ adcs x3, x24, x4+ extr x4, x12, x14, #28+ umlal v6.2D, v19.2S, v22.2S+ xtn v20.2S, v2.2D+ umlal v3.2D, v26.2S, v22.2S+ movi v26.2D, #0xffffffff+ lsr x24, x17, #52+ and x4, x4, #0xfffffffffffff+ uzp2 v19.4S, v2.4S, v2.4S+ add x1, x1, x24+ mul x24, x5, x4+ lsl x4, x17, #12+ xtn v24.2S, v5.2D+ extr x17, x1, x4, #24+ adc x21, x21, xzr+ umlal v21.2D, v23.2S, v23.2S+ adds x4, x15, x10+ lsl x10, x1, #12+ adcs x15, x7, x17+ mul v23.4S, v28.4S, v4.4S+ and x7, x4, #0x1ff+ lsr x17, x1, #52+ umulh x1, x19, x12+ uzp2 v17.4S, v5.4S, v5.4S+ extr x4, x15, x4, #9+ add x24, x24, x17+ mul v29.4S, v29.4S, v5.4S+ extr x17, x24, x10, #36+ extr x10, x9, x12, #16+ uzp1 v28.4S, v4.4S, v4.4S+ adcs x17, x8, x17+ and x8, x10, #0xfffffffffffff+ umull v16.2D, v24.2S, v20.2S+ extr x10, x17, x15, #9+ mul x15, x5, x8+ stp x4, x10, [x0]+ lsl x4, x24, #12+ lsr x8, x9, #4+ uaddlp v4.2D, v23.4S+ and x8, x8, #0xfffffffffffff+ umull v23.2D, v24.2S, v19.2S+ mul x8, x5, x8+ extr x10, x2, x9, #56+ lsr x24, x24, #52+ and x10, x10, #0xfffffffffffff+ add x15, x15, x24+ extr x4, x15, x4, #48+ mul x24, x5, x10+ lsr x10, x15, #52+ usra v23.2D, v16.2D, #32+ add x10, x8, x10+ shl v4.2D, v4.2D, #32+ adcs x22, x22, x4+ extr x4, x6, x2, #44+ lsl x15, x15, #12+ lsr x8, x10, #52+ extr x15, x10, x15, #60+ and x10, x4, #0xfffffffffffff+ umlal v4.2D, v28.2S, v27.2S+ add x8, x24, x8+ extr x4, x13, x6, #32+ mul x24, x5, x10+ uzp2 v16.4S, v30.4S, v30.4S+ lsl x10, x15, #8+ rev64 v28.4S, v30.4S+ and x15, x4, #0xfffffffffffff+ extr x4, x8, x10, #8+ mul x10, x5, x15+ lsl x15, x8, #12+ adcs x23, x23, x4+ lsr x4, x8, #52+ lsr x8, x13, #20+ add x4, x24, x4+ mul x8, x5, x8+ lsr x24, x4, #52+ extr x15, x4, x15, #20+ lsl x4, x4, #12+ add x10, x10, x24+ adcs x15, x16, x15+ extr x4, x10, x4, #32+ umulh x5, x20, x14+ adcs x3, x3, x4+ usra v18.2D, v6.2D, #32+ lsl x16, x10, #12+ extr x24, x15, x23, #9+ lsr x10, x10, #52+ uzp2 v27.4S, v0.4S, v0.4S+ add x8, x8, x10+ extr x10, x3, x15, #9+ extr x4, x22, x17, #9+ and v25.16B, v23.16B, v26.16B+ lsr x17, x8, #44+ extr x15, x8, x16, #44+ extr x16, x23, x22, #9+ xtn v7.2S, v30.2D+ mov x8, v4.d[0]+ stp x24, x10, [x0, #32]+ uaddlp v30.2D, v29.4S+ stp x4, x16, [x0, #16]+ umulh x24, x20, x19+ adcs x15, x21, x15+ adc x16, x11, x17+ subs x11, x20, x19+ xtn v5.2S, v0.2D+ csetm x17, cc+ extr x3, x15, x3, #9+ mov x22, v4.d[1]+ cneg x21, x11, cc+ subs x10, x12, x14+ mul v31.4S, v28.4S, v0.4S+ cneg x10, x10, cc+ cinv x11, x17, cc+ shl v4.2D, v30.2D, #32+ umull v28.2D, v5.2S, v16.2S+ extr x23, x16, x15, #9+ adds x4, x8, x5+ mul x17, x21, x10+ umull v22.2D, v5.2S, v7.2S+ adc x15, x5, xzr+ adds x4, x4, x22+ uaddlp v2.2D, v31.4S+ lsr x5, x16, #9+ adcs x16, x15, x1+ mov x15, v18.d[0]+ adc x1, x1, xzr+ umulh x10, x21, x10+ adds x22, x16, x22+ umlal v4.2D, v24.2S, v20.2S+ umull v30.2D, v27.2S, v16.2S+ stp x3, x23, [x0, #48]+ add x3, x7, x5+ adc x16, x1, xzr+ usra v28.2D, v22.2D, #32+ mul x23, x20, x19+ eor x1, x17, x11+ cmn x11, #0x1+ mov x17, v18.d[1]+ umull v18.2D, v17.2S, v19.2S+ adcs x7, x4, x1+ eor x1, x10, x11+ umlal v25.2D, v17.2S, v20.2S+ movi v16.2D, #0xffffffff+ adcs x22, x22, x1+ usra v18.2D, v23.2D, #32+ umulh x4, x14, x14+ adc x1, x16, x11+ adds x10, x8, x8+ shl v23.2D, v2.2D, #32+ str x3, [x0, #64]+ adcs x5, x7, x7+ and v16.16B, v28.16B, v16.16B+ usra v30.2D, v28.2D, #32+ adcs x7, x22, x22+ mov x21, v3.d[1]+ adcs x11, x1, x1+ umlal v16.2D, v27.2S, v7.2S+ adc x22, xzr, xzr+ adds x16, x15, x23+ mul x8, x14, x12+ umlal v23.2D, v5.2S, v7.2S+ usra v18.2D, v25.2D, #32+ umulh x15, x14, x12+ adcs x21, x21, x24+ usra v30.2D, v16.2D, #32+ adc x1, x17, xzr+ adds x3, x16, x23+ adcs x21, x21, x24+ adc x1, x1, xzr+ adds x24, x10, x21+ umulh x21, x12, x12+ adcs x16, x5, x1+ adcs x10, x7, xzr+ mov x17, v21.d[1]+ adcs x23, x11, xzr+ adc x5, x22, xzr+ adds x1, x4, x8+ adcs x22, x17, x15+ ldp x17, x4, [x0]+ mov x11, v21.d[0]+ adc x21, x21, xzr+ adds x1, x1, x8+ adcs x15, x22, x15+ adc x8, x21, xzr+ adds x22, x11, x10+ mov x21, v3.d[0]+ adcs x11, x1, x23+ ldp x1, x10, [x0, #16]+ adcs x15, x15, x5+ adc x7, x8, xzr+ adds x8, x17, x21+ mov x23, v4.d[1]+ ldp x5, x21, [x0, #32]+ adcs x17, x4, x3+ ldr x4, [x0, #64]+ mov x3, v18.d[0]+ adcs x24, x1, x24+ stp x8, x17, [x0]+ adcs x17, x10, x16+ ldp x1, x16, [x0, #48]+ adcs x5, x5, x22+ adcs x8, x21, x11+ stp x5, x8, [x0, #32]+ adcs x1, x1, x15+ mov x15, v23.d[1]+ adcs x21, x16, x7+ stp x1, x21, [x0, #48]+ adc x10, x4, xzr+ subs x7, x14, x12+ mov x16, v18.d[1]+ cneg x5, x7, cc+ csetm x4, cc+ subs x11, x13, x6+ mov x8, v23.d[0]+ cneg x7, x11, cc+ cinv x21, x4, cc+ mov x11, v30.d[0]+ adds x4, x23, x3+ mul x22, x5, x7+ mov x23, v30.d[1]+ adcs x8, x8, x16+ adcs x16, x15, x11+ adc x11, x23, xzr+ umulh x3, x5, x7+ stp x24, x17, [x0, #16]+ mov x5, v4.d[0]+ subs x15, x20, x19+ cneg x7, x15, cc+ str x10, [x0, #64]+ csetm x1, cc+ subs x24, x2, x9+ cneg x17, x24, cc+ cinv x15, x1, cc+ adds x23, x4, x5+ umulh x1, x7, x17+ adcs x24, x8, x4+ adcs x10, x16, x8+ eor x8, x22, x21+ adcs x16, x11, x16+ mul x22, x7, x17+ eor x17, x1, x15+ adc x1, xzr, x11+ adds x11, x24, x5+ eor x7, x3, x21+ adcs x3, x10, x23+ adcs x24, x16, x24+ adcs x4, x1, x10+ eor x10, x22, x15+ adcs x16, xzr, x16+ adc x1, xzr, x1+ cmn x21, #0x1+ adcs x8, x4, x8+ adcs x22, x16, x7+ adc x7, x1, x21+ subs x21, x19, x12+ csetm x4, cc+ cneg x1, x21, cc+ subs x21, x13, x2+ cinv x16, x4, cc+ cneg x4, x21, cc+ cmn x15, #0x1+ adcs x21, x23, x10+ mul x23, x1, x4+ adcs x11, x11, x17+ adcs x3, x3, x15+ umulh x1, x1, x4+ adcs x24, x24, x15+ adcs x8, x8, x15+ adcs x22, x22, x15+ eor x17, x23, x16+ adc x15, x7, x15+ subs x7, x20, x14+ cneg x7, x7, cc+ csetm x4, cc+ subs x10, x20, x12+ cneg x23, x10, cc+ csetm x10, cc+ subs x12, x6, x9+ cinv x20, x4, cc+ cneg x12, x12, cc+ cmn x16, #0x1+ eor x1, x1, x16+ adcs x17, x24, x17+ mul x4, x7, x12+ adcs x8, x8, x1+ umulh x1, x7, x12+ adcs x24, x22, x16+ adc x7, x15, x16+ subs x12, x13, x9+ cneg x12, x12, cc+ cinv x13, x10, cc+ subs x19, x19, x14+ mul x9, x23, x12+ cneg x19, x19, cc+ csetm x10, cc+ eor x16, x1, x20+ subs x22, x6, x2+ umulh x12, x23, x12+ eor x1, x4, x20+ cinv x4, x10, cc+ cneg x22, x22, cc+ cmn x20, #0x1+ adcs x15, x11, x1+ eor x6, x12, x13+ adcs x10, x3, x16+ adcs x17, x17, x20+ eor x23, x9, x13+ adcs x2, x8, x20+ mul x11, x19, x22+ adcs x24, x24, x20+ adc x7, x7, x20+ cmn x13, #0x1+ adcs x3, x10, x23+ umulh x22, x19, x22+ adcs x17, x17, x6+ eor x12, x22, x4+ extr x22, x15, x21, #63+ adcs x8, x2, x13+ extr x21, x21, x5, #63+ ldp x16, x23, [x0]+ adcs x20, x24, x13+ eor x1, x11, x4+ adc x6, x7, x13+ cmn x4, #0x1+ ldp x2, x7, [x0, #16]+ adcs x1, x3, x1+ extr x19, x1, x15, #63+ adcs x14, x17, x12+ extr x1, x14, x1, #63+ lsl x17, x5, #1+ adcs x8, x8, x4+ extr x12, x8, x14, #8+ ldp x15, x11, [x0, #32]+ adcs x9, x20, x4+ adc x3, x6, x4+ adds x16, x12, x16+ extr x6, x9, x8, #8+ ldp x14, x12, [x0, #48]+ extr x8, x3, x9, #8+ adcs x20, x6, x23+ ldr x24, [x0, #64]+ lsr x6, x3, #8+ adcs x8, x8, x2+ and x2, x1, #0x1ff+ and x1, x20, x8+ adcs x4, x6, x7+ adcs x3, x17, x15+ and x1, x1, x4+ adcs x9, x21, x11+ and x1, x1, x3+ adcs x6, x22, x14+ and x1, x1, x9+ and x21, x1, x6+ adcs x14, x19, x12+ adc x1, x24, x2+ cmp xzr, xzr+ orr x12, x1, #0xfffffffffffffe00+ lsr x1, x1, #9+ adcs xzr, x16, x1+ and x21, x21, x14+ adcs xzr, x21, xzr+ adcs xzr, x12, xzr+ adcs x21, x16, x1+ adcs x1, x20, xzr+ adcs x19, x8, xzr+ stp x21, x1, [x0]+ adcs x1, x4, xzr+ adcs x21, x3, xzr+ stp x19, x1, [x0, #16]+ adcs x1, x9, xzr+ stp x21, x1, [x0, #32]+ adcs x21, x6, xzr+ adcs x1, x14, xzr+ stp x21, x1, [x0, #48]+ adc x1, x12, xzr+ and x1, x1, #0x1ff+ str x1, [x0, #64]++// Restore regs and return++ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_sqr_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_sqr_p521_alt.S view
@@ -0,0 +1,374 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Square modulo p_521, z := (x^2) mod p_521, assuming x reduced+// Input x[9]; output z[9]+//+// extern void bignum_sqr_p521_alt(uint64_t z[static 9],+// const uint64_t x[static 9]);+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_sqr_p521_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_sqr_p521_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_sqr_p521_alt)+ .text+ .balign 4++#define z x0+#define x x1++#define a0 x2+#define a1 x3+#define a2 x4+#define a3 x5+#define a4 x6+#define a5 x7+#define a6 x8+#define a7 x9+#define a8 x1 // Overwrites input argument at last load++#define l x10++#define u0 x2 // The same as a0+#define u1 x11+#define u2 x12+#define u3 x13+#define u4 x14+#define u5 x15+#define u6 x16+#define u7 x17+#define u8 x19+#define u9 x20+#define u10 x21+#define u11 x22+#define u12 x23+#define u13 x24+#define u14 x25+#define u15 x26+#define u16 x4 // The same as a2++S2N_BN_SYMBOL(bignum_sqr_p521_alt):+ CFI_START++// It's convenient to have more registers to play with++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)++// Load low 8 elements as [a7;a6;a5;a4;a3;a2;a1;a0], set up an initial+// window [u8;u7;u6;u5;u4;u3;u2;u1] = 10 + 20 + 30 + 40 + 50 + 60 + 70++ ldp a0, a1, [x]++ mul u1, a0, a1+ umulh u2, a0, a1++ ldp a2, a3, [x, #16]++ mul l, a0, a2+ umulh u3, a0, a2+ adds u2, u2, l++ ldp a4, a5, [x, #32]++ mul l, a0, a3+ umulh u4, a0, a3+ adcs u3, u3, l++ ldp a6, a7, [x, #48]++ mul l, a0, a4+ umulh u5, a0, a4+ adcs u4, u4, l++ mul l, a0, a5+ umulh u6, a0, a5+ adcs u5, u5, l++ mul l, a0, a6+ umulh u7, a0, a6+ adcs u6, u6, l++ mul l, a0, a7+ umulh u8, a0, a7+ adcs u7, u7, l++ adc u8, u8, xzr++// Add in the next diagonal = 21 + 31 + 41 + 51 + 61 + 71 + 54++ mul l, a1, a2+ adds u3, u3, l+ mul l, a1, a3+ adcs u4, u4, l+ mul l, a1, a4+ adcs u5, u5, l+ mul l, a1, a5+ adcs u6, u6, l+ mul l, a1, a6+ adcs u7, u7, l+ mul l, a1, a7+ adcs u8, u8, l+ cset u9, cs++ umulh l, a1, a2+ adds u4, u4, l+ umulh l, a1, a3+ adcs u5, u5, l+ umulh l, a1, a4+ adcs u6, u6, l+ umulh l, a1, a5+ adcs u7, u7, l+ umulh l, a1, a6+ adcs u8, u8, l+ umulh l, a1, a7+ adc u9, u9, l+ mul l, a4, a5+ umulh u10, a4, a5+ adds u9, u9, l+ adc u10, u10, xzr++// And the next one = 32 + 42 + 52 + 62 + 72 + 64 + 65++ mul l, a2, a3+ adds u5, u5, l+ mul l, a2, a4+ adcs u6, u6, l+ mul l, a2, a5+ adcs u7, u7, l+ mul l, a2, a6+ adcs u8, u8, l+ mul l, a2, a7+ adcs u9, u9, l+ mul l, a4, a6+ adcs u10, u10, l+ cset u11, cs++ umulh l, a2, a3+ adds u6, u6, l+ umulh l, a2, a4+ adcs u7, u7, l+ umulh l, a2, a5+ adcs u8, u8, l+ umulh l, a2, a6+ adcs u9, u9, l+ umulh l, a2, a7+ adcs u10, u10, l+ umulh l, a4, a6+ adc u11, u11, l+ mul l, a5, a6+ umulh u12, a5, a6+ adds u11, u11, l+ adc u12, u12, xzr++// And the final one = 43 + 53 + 63 + 73 + 74 + 75 + 76++ mul l, a3, a4+ adds u7, u7, l+ mul l, a3, a5+ adcs u8, u8, l+ mul l, a3, a6+ adcs u9, u9, l+ mul l, a3, a7+ adcs u10, u10, l+ mul l, a4, a7+ adcs u11, u11, l+ mul l, a5, a7+ adcs u12, u12, l+ cset u13, cs++ umulh l, a3, a4+ adds u8, u8, l+ umulh l, a3, a5+ adcs u9, u9, l+ umulh l, a3, a6+ adcs u10, u10, l+ umulh l, a3, a7+ adcs u11, u11, l+ umulh l, a4, a7+ adcs u12, u12, l+ umulh l, a5, a7+ adc u13, u13, l+ mul l, a6, a7+ umulh u14, a6, a7+ adds u13, u13, l+ adc u14, u14, xzr++// Double that, with u15 holding the top carry++ adds u1, u1, u1+ adcs u2, u2, u2+ adcs u3, u3, u3+ adcs u4, u4, u4+ adcs u5, u5, u5+ adcs u6, u6, u6+ adcs u7, u7, u7+ adcs u8, u8, u8+ adcs u9, u9, u9+ adcs u10, u10, u10+ adcs u11, u11, u11+ adcs u12, u12, u12+ adcs u13, u13, u13+ adcs u14, u14, u14+ cset u15, cs++// Add the homogeneous terms 00 + 11 + 22 + 33 + 44 + 55 + 66 + 77++ umulh l, a0, a0+ adds u1, u1, l++ mul l, a1, a1+ adcs u2, u2, l+ umulh l, a1, a1+ adcs u3, u3, l++ mul l, a2, a2+ adcs u4, u4, l+ umulh l, a2, a2+ adcs u5, u5, l++ mul l, a3, a3+ adcs u6, u6, l+ umulh l, a3, a3+ adcs u7, u7, l++ mul l, a4, a4+ adcs u8, u8, l+ umulh l, a4, a4+ adcs u9, u9, l++ mul l, a5, a5+ adcs u10, u10, l+ umulh l, a5, a5+ adcs u11, u11, l++ mul l, a6, a6+ adcs u12, u12, l+ umulh l, a6, a6+ adcs u13, u13, l++ mul l, a7, a7+ adcs u14, u14, l+ umulh l, a7, a7+ adc u15, u15, l++// Now load in the top digit a8, and immediately double the register++ ldr a8, [x, #64]+ add a8, a8, a8++// Add (2 * a8) * [a7;...;a0] into the top of the buffer+// At the end of the first chain we form u16 = a8 ^ 2.+// This needs us to shift right the modified a8 again but it saves a+// register, and the overall performance impact seems slightly positive.++ mul l, a8, a0+ adds u8, u8, l+ umulh l, a8, a0+ adcs u9, u9, l+ mul l, a8, a2+ adcs u10, u10, l+ umulh l, a8, a2+ adcs u11, u11, l+ mul l, a8, a4+ adcs u12, u12, l+ umulh l, a8, a4+ adcs u13, u13, l+ mul l, a8, a6+ adcs u14, u14, l+ umulh l, a8, a6+ adcs u15, u15, l+ lsr u16, a8, #1+ mul u16, u16, u16+ adc u16, u16, xzr++ mul l, a8, a1+ adds u9, u9, l+ umulh l, a8, a1+ adcs u10, u10, l+ mul l, a8, a3+ adcs u11, u11, l+ umulh l, a8, a3+ adcs u12, u12, l+ mul l, a8, a5+ adcs u13, u13, l+ umulh l, a8, a5+ adcs u14, u14, l+ mul l, a8, a7+ adcs u15, u15, l+ umulh l, a8, a7+ adc u16, u16, l++// Finally squeeze in the lowest mul. This didn't need to be involved+// in the addition chains and moreover lets us re-use u0 == a0++ mul u0, a0, a0++// Now we have the full product, which we consider as+// 2^521 * h + l. Form h + l + 1++ subs xzr, xzr, xzr+ extr l, u9, u8, #9+ adcs u0, u0, l+ extr l, u10, u9, #9+ adcs u1, u1, l+ extr l, u11, u10, #9+ adcs u2, u2, l+ extr l, u12, u11, #9+ adcs u3, u3, l+ extr l, u13, u12, #9+ adcs u4, u4, l+ extr l, u14, u13, #9+ adcs u5, u5, l+ extr l, u15, u14, #9+ adcs u6, u6, l+ extr l, u16, u15, #9+ adcs u7, u7, l+ orr u8, u8, #~0x1FF+ lsr l, u16, #9+ adcs u8, u8, l++// Now CF is set if h + l + 1 >= 2^521, which means it's already+// the answer, while if ~CF the answer is h + l so we should subtract+// 1 (all considered in 521 bits). Hence subtract ~CF and mask.++ sbcs u0, u0, xzr+ sbcs u1, u1, xzr+ sbcs u2, u2, xzr+ sbcs u3, u3, xzr+ sbcs u4, u4, xzr+ sbcs u5, u5, xzr+ sbcs u6, u6, xzr+ sbcs u7, u7, xzr+ sbc u8, u8, xzr+ and u8, u8, #0x1FF++// Store back digits of final result++ stp u0, u1, [z]+ stp u2, u3, [z, #16]+ stp u4, u5, [z, #32]+ stp u6, u7, [z, #48]+ str u8, [z, #64]++// Restore registers and return++ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_sqr_p521_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_tomont_p256.S view
@@ -0,0 +1,122 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert to Montgomery form z := (2^256 * x) mod p_256+// Input x[4]; output z[4]+//+// extern void bignum_tomont_p256(uint64_t z[static 4],+// const uint64_t x[static 4]);+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p256)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p256)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p256)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p256_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p256_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p256_alt)+ .text+ .balign 4++// ----------------------------------------------------------------------------+// Core "x |-> (2^64 * x) mod p_256" macro, with x assumed to be < p_256.+// Input is in [d4;d3;d2;d1] and output in [d3;d2;d1;d0]+// using d4 as well as t1, t2, t3 as temporaries.+// ----------------------------------------------------------------------------++#define modstep_p256(d4, d3,d2,d1,d0, t1,t2,t3) \+/* Writing the input as z = 2^256 * h + 2^192 * l + t = 2^192 * hl + t, */ \+/* our quotient approximation is MIN ((hl + hl>>32 + 1)>>64) (2^64 - 1). */ \+ subs xzr, xzr, xzr __LF/* Set carry flag for +1 */ \+ extr t3, d4, d3, #32 __LF \+ adcs xzr, d3, t3 __LF \+ lsr t3, d4, #32 __LF \+ adcs t3, d4, t3 __LF \+ csetm d0, cs __LF \+ orr t3, t3, d0 __LF \+/* First do [t2;t1] = 2^32 * q, which we use twice */ \+ lsl t1, t3, #32 __LF \+ lsr t2, t3, #32 __LF \+/* Add 2^224 * q to sum */ \+ adds d3, d3, t1 __LF \+ adc d4, d4, t2 __LF \+/* Accumulate [t2;t1;d0] = (2^96 - 1) * q */ \+ subs d0, xzr, t3 __LF \+ sbcs t1, t1, xzr __LF \+ sbc t2, t2, xzr __LF \+/* Subtract (2^256 + 2^192 + 2^96 - 1) * q */ \+ subs d0, xzr, d0 __LF \+ sbcs d1, d1, t1 __LF \+ sbcs d2, d2, t2 __LF \+ sbcs d3, d3, t3 __LF \+ sbcs d4, d4, t3 __LF \+/* Use top word as mask to correct */ \+ adds d0, d0, d4 __LF \+ mov t1, #0x00000000ffffffff __LF \+ and t1, t1, d4 __LF \+ adcs d1, d1, t1 __LF \+ adcs d2, d2, xzr __LF \+ mov t1, #0xffffffff00000001 __LF \+ and t1, t1, d4 __LF \+ adc d3, d3, t1++#define d0 x2+#define d1 x3+#define d2 x4+#define d3 x5+#define d4 x6++#define t0 x1+#define t1 x7+#define t2 x8+#define t3 x9++S2N_BN_SYMBOL(bignum_tomont_p256):++S2N_BN_SYMBOL(bignum_tomont_p256_alt):+ CFI_START++// Load the input++ ldp d0, d1, [x1]+ ldp d2, d3, [x1, #16]++// Do an initial reduction to make sure this is < p_256, using just+// a copy of the bignum_mod_p256_4 code. This is needed to set up the+// invariant "input < p_256" for the main modular reduction steps.++ mov t0, #0xffffffffffffffff+ mov t1, #0x00000000ffffffff+ mov t3, #0xffffffff00000001+ subs t0, d0, t0+ sbcs t1, d1, t1+ sbcs t2, d2, xzr+ sbcs t3, d3, t3+ csel d0, d0, t0, cc+ csel d1, d1, t1, cc+ csel d2, d2, t2, cc+ csel d3, d3, t3, cc++// Successively multiply by 2^64 and reduce++ modstep_p256(d3,d2,d1,d0,d4, t1,t2,t3)+ modstep_p256(d2,d1,d0,d4,d3, t1,t2,t3)+ modstep_p256(d1,d0,d4,d3,d2, t1,t2,t3)+ modstep_p256(d0,d4,d3,d2,d1, t1,t2,t3)++// Store the result and return++ stp d1, d2, [x0]+ stp d3, d4, [x0, #16]++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_tomont_p256)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/bignum_tomont_p384.S view
@@ -0,0 +1,138 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert to Montgomery form z := (2^384 * x) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_tomont_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Standard ARM ABI: X0 = z, X1 = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p384)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p384_alt)+ .text+ .balign 4++// ----------------------------------------------------------------------------+// Core "x |-> (2^64 * x) mod p_384" macro, with x assumed to be < p_384.+// Input is in [d6;d5;d4;d3;d2;d1] and output in [d5;d4;d3;d2;d1;d0]+// using d6 as well as t1, t2, t3 as temporaries.+// ----------------------------------------------------------------------------++#define modstep_p384(d6,d5,d4,d3,d2,d1,d0, t1,t2,t3) \+/* Initial quotient approximation q = min (h + 1) (2^64 - 1) */ \+ adds d6, d6, #1 __LF \+ csetm t3, cs __LF \+ add d6, d6, t3 __LF \+ orn t3, xzr, t3 __LF \+ sub t2, d6, #1 __LF \+ sub t1, xzr, d6 __LF \+/* Correction term [d6;t2;t1;d0] = q * (2^384 - p_384) */ \+ lsl d0, t1, #32 __LF \+ extr t1, t2, t1, #32 __LF \+ lsr t2, t2, #32 __LF \+ adds d0, d0, d6 __LF \+ adcs t1, t1, xzr __LF \+ adcs t2, t2, d6 __LF \+ adc d6, xzr, xzr __LF \+/* Addition to the initial value */ \+ adds d1, d1, t1 __LF \+ adcs d2, d2, t2 __LF \+ adcs d3, d3, d6 __LF \+ adcs d4, d4, xzr __LF \+ adcs d5, d5, xzr __LF \+ adc t3, t3, xzr __LF \+/* Use net top of the 7-word answer in t3 for masked correction */ \+ mov t1, #0x00000000ffffffff __LF \+ and t1, t1, t3 __LF \+ adds d0, d0, t1 __LF \+ eor t1, t1, t3 __LF \+ adcs d1, d1, t1 __LF \+ mov t1, #0xfffffffffffffffe __LF \+ and t1, t1, t3 __LF \+ adcs d2, d2, t1 __LF \+ adcs d3, d3, t3 __LF \+ adcs d4, d4, t3 __LF \+ adc d5, d5, t3++S2N_BN_SYMBOL(bignum_tomont_p384):++S2N_BN_SYMBOL(bignum_tomont_p384_alt):+ CFI_START++#define d0 x2+#define d1 x3+#define d2 x4+#define d3 x5+#define d4 x6+#define d5 x7+#define d6 x8++#define t1 x9+#define t2 x10+#define t3 x11++#define n0 x8+#define n1 x9+#define n2 x10+#define n3 x11+#define n4 x12+#define n5 x1++// Load the inputs++ ldp d0, d1, [x1]+ ldp d2, d3, [x1, #16]+ ldp d4, d5, [x1, #32]++// Do an initial reduction to make sure this is < p_384, using just+// a copy of the bignum_mod_p384_6 code. This is needed to set up the+// invariant "input < p_384" for the main modular reduction steps.++ mov n0, #0x00000000ffffffff+ mov n1, #0xffffffff00000000+ mov n2, #0xfffffffffffffffe+ subs n0, d0, n0+ sbcs n1, d1, n1+ sbcs n2, d2, n2+ adcs n3, d3, xzr+ adcs n4, d4, xzr+ adcs n5, d5, xzr+ csel d0, d0, n0, cc+ csel d1, d1, n1, cc+ csel d2, d2, n2, cc+ csel d3, d3, n3, cc+ csel d4, d4, n4, cc+ csel d5, d5, n5, cc++// Successively multiply by 2^64 and reduce++ modstep_p384(d5,d4,d3,d2,d1,d0,d6, t1,t2,t3)+ modstep_p384(d4,d3,d2,d1,d0,d6,d5, t1,t2,t3)+ modstep_p384(d3,d2,d1,d0,d6,d5,d4, t1,t2,t3)+ modstep_p384(d2,d1,d0,d6,d5,d4,d3, t1,t2,t3)+ modstep_p384(d1,d0,d6,d5,d4,d3,d2, t1,t2,t3)+ modstep_p384(d0,d6,d5,d4,d3,d2,d1, t1,t2,t3)++// Store the result and return++ stp d1, d2, [x0]+ stp d3, d4, [x0, #16]+ stp d5, d6, [x0, #32]++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_tomont_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/curve25519_x25519.S view
@@ -0,0 +1,2596 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// **********************************************************************+// This code is substantially derived from Emil Lenngren's implementation+//+// https://github.com/Emill/X25519-AArch64/blob/master/X25519_AArch64.pdf+// https://github.com/Emill/X25519-AArch64+//+// and the SLOTHY-based re-engineering of that code by Abdulrahman, Becker,+// Kannwischer and Klein:+//+// https://eprint.iacr.org/2022/1303.pdf+// https://github.com/slothy-optimizer/slothy/tree/main/paper+// **********************************************************************++// ----------------------------------------------------------------------------+// The x25519 function for curve25519+// Inputs scalar[4], point[4]; output res[4]+//+// extern void curve25519_x25519+// (uint64_t res[static 4],const uint64_t scalar[static 4],+// const uint64_t point[static 4]);+//+// Given a scalar n and the X coordinate of an input point P = (X,Y) on+// curve25519 (Y can live in any extension field of characteristic 2^255-19),+// this returns the X coordinate of n * P = (X, Y), or 0 when n * P is the+// point at infinity. Both n and X inputs are first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748);+// in particular the lower three bits of n are set to zero. Does not implement+// the zero-check specified in Section 6.1.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519)++ .text+ .balign 4++// Pointer-offset pairs for temporaries on stack++#define scalar sp, #0+#define pointx sp, #32+#define mask1 sp, #72+#define mask2 sp, #80+#define tmpa sp, #88+#define tmpb sp, #128+#define xn sp, #128+#define zn sp, #160++#define res sp, #192+#define i sp, #200+#define swap sp, #208++// Total size to reserve on the stack++#define NSPACE 224+#define regsave sp, #NSPACE++S2N_BN_SYMBOL(curve25519_x25519):+ CFI_START++// Save registers and make additional room #NSPACE for temporaries.+// We only need to save the low 64-bits of the Q8...Q15 registers+// according to the ABI, so we use a save of the D8...D15 forms.++ CFI_DEC_SP(NSPACE+160)+ CFI_STACKSAVE2(d8,d9,NSPACE+0)+ CFI_STACKSAVE2(d10,d11,NSPACE+16)+ CFI_STACKSAVE2(d12,d13,NSPACE+32)+ CFI_STACKSAVE2(d14,d15,NSPACE+48)+ CFI_STACKSAVE2(x19,x20,NSPACE+64)+ CFI_STACKSAVE2(x21,x22,NSPACE+80)+ CFI_STACKSAVE2(x23,x24,NSPACE+96)+ CFI_STACKSAVE2(x25,x26,NSPACE+112)+ CFI_STACKSAVE2(x27,x28,NSPACE+128)+ CFI_STACKSAVE2(x29,x30,NSPACE+144)++// Move the output pointer to a stable place++ str x0, [res]++// Copy the scalar to the corresponding local variable while+// mangling it. In principle it becomes 01xxx...xxx000 where+// the xxx are the corresponding bits of the original input+// scalar. We actually don't bother forcing the MSB to zero,+// but rather start the main loop below at 254 instead of 255.++ ldp x10, x11, [x1]+ bic x10, x10, #7+ stp x10, x11, [scalar]+ ldp x12, x13, [x1, #16]+ orr x13, x13, #0x4000000000000000+ stp x12, x13, [scalar+16]++// Discard the MSB of the point X coordinate (this is in+// accordance with the RFC, mod 2^255, *not* 2^255-19).+// Then recode it into the unsaturated base 25.5 form.++ ldp x0, x1, [x2]+ ldp x2, x3, [x2, #16]++ lsr x12, x0, #51+ lsr x17, x2, #51+ orr x12, x12, x1, lsl #13+ orr x17, x17, x3, lsl #13+ ubfx x8, x3, #12, #26+ ubfx x9, x3, #38, #25+ ubfx x11, x0, #26, #25+ ubfx x13, x1, #13, #25+ lsr x14, x1, #38+ ubfx x16, x2, #25, #26+ and x10, x0, #0x3ffffff+ and x12, x12, #0x3ffffff+ and x15, x2, #0x1ffffff+ and x17, x17, #0x1ffffff+ orr x10, x10, x11, lsl #32+ orr x11, x12, x13, lsl #32+ orr x12, x14, x15, lsl #32+ orr x13, x16, x17, lsl #32+ orr x14, x8, x9, lsl #32++ stp x10, x11, [pointx+0]+ stp x12, x13, [pointx+16]+ str x14, [pointx+32]++// Initialize (X2,Z2) = (1,0), the identity (projective point at infinity)++ mov x1, #1+ mov v0.d[0], x1+ mov v2.d[0], xzr+ mov v4.d[0], xzr+ mov v6.d[0], xzr+ mov v8.d[0], xzr++ mov v1.d[0], xzr+ mov v3.d[0], xzr+ mov v5.d[0], xzr+ mov v7.d[0], xzr+ mov v9.d[0], xzr++// Initialize (X3,Z3) = (X,1), projective representation of X++ mov v10.d[0], x10+ mov v12.d[0], x11+ mov v14.d[0], x12+ mov v16.d[0], x13+ mov v18.d[0], x14++ mov v11.d[0], x1+ mov v13.d[0], xzr+ mov v15.d[0], xzr+ mov v17.d[0], xzr+ mov v19.d[0], xzr++// Set up some constants used repeatedly in the main loop:+//+// Q31 = 0x1300000013 (two 32-bit copies of 19)+// Q30 = 0x3ffffff0000000003ffffff (two 64-bit copies of 2^26-1)+// Q29 = mask1 = (0x07ffffc,0x07fffffe)+// Q28 = mask2 = (0x07ffffb4,0x07fffffe)++ mov w0, #19+ add x0, x0, x0, lsl #32+ mov v31.d[0], x0+ mov v31.d[1], xzr++ mov x0, #67108863 // #(1<<26)-1+ mov v30.d[0], x0+ mov v30.d[1], x0++ mov x0, #0x07fffffe07fffffe+ sub x1, x0, #74 // #0xfe-0xb4+ sub x0, x0, #2++ stp x0, x1, [mask1]+ ldp d29, d28, [mask1]++// The main loop over (modified) bits from i = 254, ..., i = 0 (inclusive);+// we explicitly skip bit 255 because it should be forced to zero initially.+// This is a classic Montgomery ladder using a "swap" variable.+// It's assumed x0 = i at the start of the loop, but that is volatile and+// needs to be reloaded from memory at the end of the loop.++ str xzr, [swap]+ mov x0, #254+ str x0, [i]++Lcurve25519_x25519_scalarloop:++ lsr x1, x0, #6+ ldr x2, [sp, x1, lsl #3] // Exploiting scalar = sp exactly+ lsr x2, x2, x0+ and x2, x2, #1++ ldr x0, [swap]+ cmp x0, x2+ str x2, [swap]++// The following inner loop code is derived closely following Lenngren's+// implementation available at "https://github.com/Emill/X25519-AArch64".+// In particular, the basic dataflow and the organization between integer+// and SIMD units is identical, with only a few minor changes to some+// individual instructions (for miscellaneous reasons). The scheduling+// was redone from scratch by SLOTHY starting from the un-interleaved+// form in the SLOTHY work cited above, and using the same scripts.+//+// The intermediate value annotations were added to provide data that+// is used in the formal proof, indicating which lines assign specific+// digits of the various intermediate results (mainly of field+// operations, sometimes other transformations). The names used for+// the intermediate results are similar but not identical to those in+// the abstract Algorithm 1 description in Lenngren's paper. Almost+// all equations are to be interpreted as field operations, i.e. as+// arithmetic modulo 2^255-19, not simple numeric equalities.+//+// b = x2 - z2+// d = x3 - z3+// a = x2 + z2+// c = x3 + z3+// f = if flip then c else a+// g = if flip then d else b+// aa = f^2+// bb = g^2+// bbalt = bb (change of representation)+// e = aa - bb+// bce = bbalt + 121666 * e+// z4 = bce * e+// bc = b * c+// ad = a * d+// t1 = ad + bc+// t2 = ad - bc+// x5 = t1^2+// t3 = t2^2+// x4 = aa * bb+// z5 = x * t3+//+// Then the main variables are updated for the next iteration as+//+// (x2',z2') = (x4,z4)+// (x3',z3') = (x5,z5)++ add v22.2s, v2.2s, v3.2s // ubignum_of_qreglist 1 // INTERMEDIATE a+ sub v21.2s, v28.2s, v1.2s+ add v25.2s, v0.2s, v1.2s // ubignum_of_qreglist 0 // INTERMEDIATE a+ sub v24.2s, v29.2s, v3.2s+ add v3.2s, v18.2s, v19.2s // ubignum_of_qreglist 4 // INTERMEDIATE c+ add v0.2s, v0.2s, v21.2s // ubignum_of_qreglist 0 // INTERMEDIATE b+ sub v20.2s, v29.2s, v15.2s+ sub v1.2s, v29.2s, v5.2s+ sub v26.2s, v28.2s, v11.2s+ sub v21.2s, v29.2s, v19.2s+ add v19.2s, v10.2s, v11.2s // ubignum_of_qreglist 0 // INTERMEDIATE c+ add v11.2s, v14.2s, v20.2s // ubignum_of_qreglist 2 // INTERMEDIATE d+ add v21.2s, v18.2s, v21.2s // ubignum_of_qreglist 4 // INTERMEDIATE d+ sub v20.2s, v29.2s, v17.2s+ add v18.2s, v2.2s, v24.2s // ubignum_of_qreglist 1 // INTERMEDIATE b+ add v14.2s, v14.2s, v15.2s // ubignum_of_qreglist 2 // INTERMEDIATE c+ add v15.2s, v16.2s, v17.2s // ubignum_of_qreglist 3 // INTERMEDIATE c+ add v2.2s, v16.2s, v20.2s // ubignum_of_qreglist 3 // INTERMEDIATE d+ add v24.2s, v12.2s, v13.2s // ubignum_of_qreglist 1 // INTERMEDIATE c+ add v26.2s, v10.2s, v26.2s // ubignum_of_qreglist 0 // INTERMEDIATE d+ sub v10.2s, v29.2s, v13.2s+ sub v13.2s, v29.2s, v7.2s+ add v23.2s, v6.2s, v7.2s // ubignum_of_qreglist 3 // INTERMEDIATE a+ sub v7.2s, v29.2s, v9.2s+ add v27.2s, v12.2s, v10.2s // ubignum_of_qreglist 1 // INTERMEDIATE d+ fcsel d20, d22, d24, eq // ubignum_of_qreglist 1 // INTERMEDIATE f+ add v28.2s, v4.2s, v5.2s // ubignum_of_qreglist 2 // INTERMEDIATE a+ fcsel d12, d23, d15, eq // ubignum_of_qreglist 3 // INTERMEDIATE f+ add v7.2s, v8.2s, v7.2s // ubignum_of_qreglist 4 // INTERMEDIATE b+ fcsel d16, d25, d19, eq // ubignum_of_qreglist 0 // INTERMEDIATE f+ mov x0, v20.d[0]+ fcsel d5, d28, d14, eq // ubignum_of_qreglist 2 // INTERMEDIATE f+ mov x21, v12.d[0]+ fcsel d29, d7, d21, eq // ubignum_of_qreglist 4 // INTERMEDIATE g+ mov x5, v16.d[0]+ lsr x26, x0, #32+ add x29, x21, x21+ umull x15, w5, w29+ add v13.2s, v6.2s, v13.2s // ubignum_of_qreglist 3 // INTERMEDIATE b+ add x12, x26, x26+ mov x30, v5.d[0]+ fcsel d10, d18, d27, eq // ubignum_of_qreglist 1 // INTERMEDIATE g+ lsr x11, x5, #32+ lsr x10, x30, #32+ trn2 v20.2s, v21.2s, v3.2s+ add v9.2s, v8.2s, v9.2s // ubignum_of_qreglist 4 // INTERMEDIATE a+ add x14, x11, x11+ trn2 v6.2s, v2.2s, v15.2s+ trn1 v12.2s, v25.2s, v0.2s+ add v1.2s, v4.2s, v1.2s // ubignum_of_qreglist 2 // INTERMEDIATE b+ trn1 v16.2s, v23.2s, v13.2s+ fcsel d8, d13, d2, eq // ubignum_of_qreglist 3 // INTERMEDIATE g+ trn2 v17.2s, v27.2s, v24.2s+ str d29, [tmpb+32]+ add x17, x10, x10+ trn2 v4.2s, v28.2s, v1.2s+ trn1 v5.2s, v28.2s, v1.2s+ trn1 v28.2s, v2.2s, v15.2s+ trn1 v2.2s, v22.2s, v18.2s+ fcsel d29, d0, d26, eq // ubignum_of_qreglist 0 // INTERMEDIATE g+ trn2 v15.2s, v22.2s, v18.2s+ umull v22.2d, v12.2s, v20.2s+ umull x22, w30, w17+ stp d29, d10, [tmpb+0]+ trn2 v10.2s, v23.2s, v13.2s+ trn2 v23.2s, v11.2s, v14.2s+ trn1 v13.2s, v27.2s, v24.2s+ fcsel d27, d1, d11, eq // ubignum_of_qreglist 2 // INTERMEDIATE g+ trn1 v14.2s, v11.2s, v14.2s+ umlal v22.2d, v2.2s, v6.2s+ umull x25, w30, w30+ umlal v22.2d, v5.2s, v23.2s+ add x3, x30, x30+ umlal v22.2d, v16.2s, v17.2s+ add w30, w21, w21, lsl #1;+ stp d27, d8, [tmpb+16]+ add w30, w30, w21, lsl #4+ trn1 v11.2s, v26.2s, v19.2s+ trn2 v8.2s, v26.2s, v19.2s+ trn2 v19.2s, v25.2s, v0.2s+ mul v29.2s, v20.2s, v31.2s+ ldr x20, [tmpb+24]+ umull v25.2d, v19.2s, v6.2s+ add x1, x0, x0+ umull v27.2d, v19.2s, v23.2s+ umull x9, w5, w1+ umull v0.2d, v12.2s, v23.2s+ lsr x24, x20, #32+ mul v20.2s, v23.2s, v31.2s+ lsr x16, x21, #32+ umlal v25.2d, v15.2s, v23.2s+ umaddl x13, w11, w14, x9+ umlal v25.2d, v4.2s, v17.2s+ umaddl x9, w14, w17, x15+ umull v24.2d, v12.2s, v6.2s+ add w2, w16, w16, lsl #1;+ fcsel d26, d9, d3, eq // ubignum_of_qreglist 4 // INTERMEDIATE f+ add w2, w2, w16, lsl #4+ trn1 v18.2s, v21.2s, v3.2s+ umull v3.2d, v19.2s, v29.2s+ umull x28, w5, w3+ mul v1.2s, v6.2s, v31.2s+ umull x8, w5, w5+ umlal v24.2d, v2.2s, v23.2s+ umaddl x13, w21, w30, x13+ mul v23.2s, v17.2s, v31.2s+ umaddl x27, w14, w12, x28+ trn2 v6.2s, v9.2s, v7.2s+ mov x6, v26.d[0]+ umlal v3.2d, v15.2s, v1.2s+ add x16, x16, x16+ umlal v3.2d, v4.2s, v20.2s+ lsr x4, x6, #32+ umlal v3.2d, v10.2s, v23.2s+ add x7, x6, x6+ umull v26.2d, v19.2s, v8.2s+ add x23, x4, x4+ umaddl x28, w5, w23, x22+ trn1 v7.2s, v9.2s, v7.2s+ umlal v27.2d, v15.2s, v17.2s+ add w15, w4, w4, lsl #1;+ umlal v27.2d, v4.2s, v8.2s+ add w15, w15, w4, lsl #4+ add w22, w10, w10, lsl #1;+ umlal v24.2d, v5.2s, v17.2s+ add w22, w22, w10, lsl #4+ umaddl x10, w11, w7, x28+ umlal v25.2d, v10.2s, v8.2s+ umull x21, w5, w16+ umlal v25.2d, v6.2s, v29.2s+ umaddl x23, w15, w23, x25+ umlal v27.2d, v10.2s, v29.2s+ umull x19, w5, w12+ umlal v27.2d, v6.2s, v1.2s+ umaddl x25, w11, w29, x21+ umlal v0.2d, v2.2s, v17.2s+ umaddl x28, w0, w3, x9+ shl v21.2d, v25.2d, #1+ umaddl x4, w11, w1, x19+ umaddl x21, w2, w29, x4+ mul v25.2s, v8.2s, v31.2s+ umlal v24.2d, v16.2s, v8.2s+ umaddl x19, w0, w17, x25+ umlal v24.2d, v7.2s, v29.2s+ umull x25, w5, w17+ umlal v24.2d, v19.2s, v28.2s+ umaddl x4, w0, w16, x10+ umull v9.2d, v12.2s, v8.2s+ umaddl x23, w5, w7, x23+ umlal v21.2d, v12.2s, v18.2s+ add w10, w6, w6, lsl #1;+ shl v27.2d, v27.2d, #1+ add w10, w10, w6, lsl #4+ umaddl x28, w26, w12, x28+ umlal v26.2d, v15.2s, v29.2s+ umaddl x9, w14, w16, x23+ umlal v9.2d, v2.2s, v29.2s+ umaddl x22, w22, w17, x8+ umlal v21.2d, v2.2s, v28.2s+ umaddl x28, w6, w10, x28+ umaddl x27, w0, w0, x27+ add x8, x14, x14+ umlal v0.2d, v5.2s, v8.2s+ umull x5, w5, w14+ umlal v9.2d, v5.2s, v1.2s+ umaddl x14, w0, w29, x9+ umlal v26.2d, v4.2s, v1.2s+ umaddl x6, w2, w16, x27+ umlal v22.2d, v7.2s, v8.2s+ umaddl x5, w30, w17, x5+ umaddl x5, w2, w3, x5+ add x23, x17, x17+ umlal v27.2d, v12.2s, v28.2s+ umaddl x13, w2, w23, x13+ umlal v26.2d, v10.2s, v20.2s+ add x9, x12, x12+ umlal v9.2d, v16.2s, v20.2s+ umaddl x27, w10, w29, x6+ umlal v0.2d, v16.2s, v29.2s+ umaddl x6, w11, w3, x25+ umlal v22.2d, v19.2s, v18.2s+ umaddl x19, w26, w3, x19+ mul v18.2s, v18.2s, v31.2s+ umaddl x23, w15, w23, x27+ umlal v3.2d, v6.2s, v25.2s+ umaddl x0, w0, w12, x6+ umlal v0.2d, v7.2s, v1.2s+ add x11, x16, x16+ umlal v9.2d, v7.2s, v23.2s+ umaddl x6, w12, w17, x14+ umlal v9.2d, v19.2s, v11.2s+ umaddl x25, w26, w29, x4+ umlal v9.2d, v15.2s, v18.2s+ umaddl x14, w10, w3, x13+ umull v25.2d, v12.2s, v17.2s+ umaddl x27, w10, w16, x0+ umlal v26.2d, v6.2s, v23.2s+ add x0, x25, x6, lsr #26+ mul v23.2s, v28.2s, v31.2s+ umaddl x12, w10, w12, x5+ shl v3.2d, v3.2d, #1+ add x16, x22, x0, lsr #25+ umlal v21.2d, v5.2s, v14.2s+ bic x22, x0, #0x1ffffff+ umlal v3.2d, v12.2s, v11.2s+ add x26, x16, x22, lsr #24+ umlal v3.2d, v2.2s, v18.2s+ umaddl x16, w10, w17, x21+ umlal v3.2d, v5.2s, v23.2s+ add x22, x26, x22, lsr #21+ umlal v9.2d, v4.2s, v23.2s+ umaddl x5, w15, w29, x27+ umull v17.2d, v19.2s, v17.2s+ umaddl x17, w30, w3, x22+ umlal v25.2d, v2.2s, v8.2s+ umaddl x25, w15, w3, x16+ umlal v25.2d, v5.2s, v29.2s+ umaddl x26, w15, w7, x19+ umlal v0.2d, v19.2s, v14.2s+ umaddl x17, w2, w9, x17+ umlal v17.2d, v15.2s, v8.2s+ ldr x19, [tmpb+0]+ umlal v17.2d, v4.2s, v29.2s+ ldr x7, [tmpb+8]+ shl v29.2d, v26.2d, #1+ umaddl x13, w10, w1, x17+ umlal v0.2d, v15.2s, v13.2s+ lsr x2, x19, #32+ umlal v29.2d, v12.2s, v13.2s+ umaddl x27, w15, w1, x12+ umlal v29.2d, v2.2s, v11.2s+ umaddl x30, w15, w8, x13+ umlal v29.2d, v5.2s, v18.2s+ add x4, x7, x7+ umlal v29.2d, v16.2s, v23.2s+ umaddl x29, w15, w9, x14+ umlal v0.2d, v4.2s, v11.2s+ add x17, x27, x30, lsr #26+ umlal v0.2d, v10.2s, v18.2s+ umaddl x16, w15, w11, x28+ umlal v0.2d, v6.2s, v23.2s+ add x1, x29, x17, lsr #25+ umlal v25.2d, v16.2s, v1.2s+ umull x11, w19, w4+ ldr x8, [tmpb+32]+ mul v26.2s, v14.2s, v31.2s+ umlal v17.2d, v10.2s, v1.2s+ ldr x15, [tmpb+16]+ umlal v17.2d, v6.2s, v20.2s+ and x9, x30, #0x3ffffff+ bfi x9, x17, #32, #25 // ubignum_of_preglist 0 // INTERMEDIATE aa+ add x17, x2, x2+ lsr x10, x15, #32+ add x27, x25, x1, lsr #26+ umlal v25.2d, v7.2s, v20.2s+ add x13, x10, x10+ umlal v25.2d, v19.2s, v13.2s+ add x29, x23, x27, lsr #25+ umlal v25.2d, v15.2s, v11.2s+ lsr x30, x8, #32+ umlal v25.2d, v4.2s, v18.2s+ add x23, x5, x29, lsr #26+ umlal v25.2d, v10.2s, v23.2s+ and x14, x29, #0x3ffffff+ umlal v25.2d, v6.2s, v26.2s+ add x5, x16, x23, lsr #25+ shl v8.2d, v17.2d, #1+ umaddl x12, w2, w17, x11+ and x29, x5, #0x3ffffff+ umull x21, w19, w19+ umlal v29.2d, v7.2s, v26.2s+ add w16, w10, w10, lsl #1;+ umlal v3.2d, v16.2s, v26.2s+ add w16, w16, w10, lsl #4+ bfi x14, x23, #32, #25 // ubignum_of_preglist 2 // INTERMEDIATE aa+ add w10, w24, w24, lsl #1;+ add x22, x26, x5, lsr #26+ add w10, w10, w24, lsl #4+ umlal v8.2d, v12.2s, v14.2s+ umaddl x25, w16, w13, x21+ umlal v8.2d, v2.2s, v13.2s+ bfi x29, x22, #32, #25 // ubignum_of_preglist 3 // INTERMEDIATE aa+ umlal v8.2d, v5.2s, v11.2s+ add x26, x24, x24+ umlal v8.2d, v16.2s, v18.2s+ stp x14, x29, [tmpa+16]+ umlal v8.2d, v7.2s, v23.2s+ add w24, w30, w30, lsl #1;+ usra v25.2d, v29.2d, #26+ add w24, w24, w30, lsl #4+ umull x29, w15, w15+ umlal v27.2d, v2.2s, v14.2s+ umull x3, w15, w13+ umlal v27.2d, v5.2s, v13.2s+ add x21, x20, x20+ umlal v24.2d, v15.2s, v14.2s+ umull x5, w19, w21+ umlal v24.2d, v4.2s, v13.2s+ and x11, x1, #0x3ffffff+ usra v8.2d, v25.2d, #25+ and x1, x0, #0x1ffffff+ umlal v27.2d, v16.2s, v11.2s+ umaddl x23, w17, w13, x5+ umlal v27.2d, v7.2s, v18.2s+ add x5, x30, x30+ usra v0.2d, v8.2d, #26+ add x0, x15, x15+ umlal v24.2d, v10.2s, v11.2s+ umaddl x23, w7, w0, x23+ umlal v24.2d, v6.2s, v18.2s+ lsr x30, x7, #32+ usra v27.2d, v0.2d, #25+ add x16, x30, x30+ and v20.16b, v8.16b, v30.16b // ubignum_of_hreglist 4 + ubignum_of_lreglist 4 // INTERMEDIATE H|L = bc|ad+ umaddl x15, w30, w16, x23+ ushr v23.2d, v30.2d, #1+ add w23, w8, w8, lsl #1;+ usra v24.2d, v27.2d, #26+ add w23, w23, w8, lsl #4+ umaddl x14, w19, w5, x3+ and v8.16b, v27.16b, v30.16b // ubignum_of_hreglist 6 + ubignum_of_lreglist 6 // INTERMEDIATE H|L = bc|ad+ add x28, x8, x8+ and v27.16b, v0.16b, v23.16b // ubignum_of_hreglist 5 + ubignum_of_lreglist 5 // INTERMEDIATE H|L = bc|ad+ umaddl x8, w8, w23, x15+ and v5.16b, v24.16b, v23.16b // ubignum_of_hreglist 7 + ubignum_of_lreglist 7 // INTERMEDIATE H|L = bc|ad+ umaddl x3, w2, w28, x14+ umlal v22.2d, v15.2s, v28.2s+ bfi x11, x27, #32, #25 // ubignum_of_preglist 1 // INTERMEDIATE aa+ uzp1 v5.4s, v8.4s, v5.4s+ umaddl x14, w24, w5, x29+ umaddl x5, w19, w28, x14+ ldr d18, [mask1]+ mov v18.d[1], v18.d[0]+ umaddl x15, w7, w26, x3+ mul v12.2s, v13.2s, v31.2s+ umlal v21.2d, v16.2s, v13.2s+ stp x9, x11, [tmpa+0]+ umlal v21.2d, v7.2s, v11.2s+ umaddl x29, w17, w26, x5+ umlal v22.2d, v4.2s, v14.2s+ add w14, w20, w20, lsl #1;+ umlal v22.2d, v10.2s, v13.2s+ add w14, w14, w20, lsl #4+ umull x3, w19, w0+ umlal v22.2d, v6.2s, v11.2s+ umaddl x29, w7, w21, x29+ usra v21.2d, v24.2d, #25+ umaddl x11, w20, w14, x12+ and v0.16b, v25.16b, v23.16b+ umaddl x5, w30, w21, x15+ and v14.16b, v29.16b, v30.16b+ umaddl x12, w16, w13, x29+ usra v22.2d, v21.2d, #26+ umaddl x29, w17, w16, x3+ umlal v3.2d, v7.2s, v12.2s+ add x9, x26, x26+ and v1.16b, v21.16b, v30.16b // ubignum_of_hreglist 8 + ubignum_of_lreglist 8 // INTERMEDIATE H|L = bc|ad+ add x27, x5, x12, lsr #26+ bic v8.16b, v22.16b, v23.16b+ umaddl x29, w7, w7, x29+ and v17.16b, v22.16b, v23.16b // ubignum_of_hreglist 9 + ubignum_of_lreglist 9 // INTERMEDIATE H|L = bc|ad+ add x5, x25, x27, lsr #25+ usra v3.2d, v8.2d, #25+ umaddl x25, w24, w9, x8+ umlal v9.2d, v10.2s, v26.2s+ add x8, x13, x13+ trn1 v22.4s, v1.4s, v17.4s+ umaddl x11, w10, w8, x11+ usra v3.2d, v8.2d, #24+ umull x20, w19, w16+ add v26.2s, v22.2s, v18.2s+ ldr d28, [mask2]+ umlal v9.2d, v6.2s, v12.2s+ umaddl x3, w23, w0, x11+ usra v3.2d, v8.2d, #21+ umaddl x29, w10, w26, x29+ uzp1 v11.4s, v20.4s, v27.4s+ umaddl x20, w2, w4, x20+ umaddl x9, w10, w21, x20+ mov v17.d[0], v22.d[1]+ usra v9.2d, v3.2d, #26+ umull x15, w19, w13+ and v7.16b, v3.16b, v30.16b // ubignum_of_hreglist 0 + ubignum_of_lreglist 0 // INTERMEDIATE H|L = bc|ad+ add x11, x16, x16+ uzp2 v1.4s, v11.4s, v5.4s+ umaddl x20, w23, w13, x9+ and v8.16b, v9.16b, v23.16b // ubignum_of_hreglist 1 + ubignum_of_lreglist 1 // INTERMEDIATE H|L = bc|ad+ umaddl x9, w2, w0, x15+ usra v14.2d, v9.2d, #25+ and x6, x6, #0x3ffffff+ uzp1 v7.4s, v7.4s, v8.4s+ umaddl x29, w23, w21, x29+ uzp1 v27.4s, v11.4s, v5.4s+ umull x15, w19, w26+ usra v0.2d, v14.2d, #26 // ubignum_of_hreglist 3 + ubignum_of_lreglist 3 // INTERMEDIATE H|L = bc|ad+ add x6, x6, x22, lsr #25+ and v3.16b, v14.16b, v30.16b // ubignum_of_hreglist 2 + ubignum_of_lreglist 2 // INTERMEDIATE H|L = bc|ad+ bic x22, x27, #0x1ffffff+ sub v2.2s, v26.2s, v17.2s+ add v9.2s, v22.2s, v17.2s+ uzp1 v14.4s, v3.4s, v0.4s+ umaddl x2, w2, w21, x15+ add v5.4s, v27.4s, v18.4s+ add x5, x5, x22, lsr #24+ zip1 v22.2s, v2.2s, v9.2s // ubignum_of_h32reglist 8 + ubignum_of_l32reglist 8 // INTERMEDIATE H|L = t1|t2+ mov v18.b[0], v28.b[0]+ uzp1 v8.4s, v7.4s, v14.4s+ add x22, x5, x22, lsr #21+ uzp2 v3.4s, v7.4s, v14.4s+ umaddl x5, w7, w16, x9+ add v25.4s, v8.4s, v18.4s+ umaddl x15, w14, w0, x22+ add v12.4s, v27.4s, v1.4s+ add x9, x17, x17+ sub v14.4s, v5.4s, v1.4s+ umull x19, w19, w17+ sub v18.4s, v25.4s, v3.4s+ ldr x22, [tmpa+8]+ add v20.4s, v8.4s, v3.4s+ umaddl x15, w10, w11, x15+ zip1 v16.4s, v14.4s, v12.4s // ubignum_of_h32reglist 4 + ubignum_of_l32reglist 4 // INTERMEDIATE H|L = t1|t2+ umaddl x14, w14, w13, x19+ zip2 v14.4s, v14.4s, v12.4s // ubignum_of_h32reglist 6 + ubignum_of_l32reglist 6 // INTERMEDIATE H|L = t1|t2+ and x17, x27, #0x1ffffff+ zip2 v0.4s, v18.4s, v20.4s // ubignum_of_h32reglist 2 + ubignum_of_l32reglist 2 // INTERMEDIATE H|L = t1|t2+ umaddl x15, w23, w4, x15+ zip1 v1.4s, v18.4s, v20.4s // ubignum_of_h32reglist 0 + ubignum_of_l32reglist 0 // INTERMEDIATE H|L = t1|t2+ umaddl x10, w10, w0, x14+ zip2 v5.2s, v2.2s, v9.2s // ubignum_of_h32reglist 9 + ubignum_of_l32reglist 9 // INTERMEDIATE H|L = t1|t2+ shl v24.2s, v0.2s, #1+ mov v19.d[0], v1.d[1] // ubignum_of_h32reglist 1 + ubignum_of_l32reglist 1 // INTERMEDIATE H|L = t1|t2+ shl v26.2s, v22.2s, #1+ shl v17.2s, v16.2s, #1+ mov v15.d[0], v0.d[1] // ubignum_of_h32reglist 3 + ubignum_of_l32reglist 3 // INTERMEDIATE H|L = t1|t2+ shl v7.2s, v5.2s, #1+ shl v18.2s, v19.2s, #1+ umull v11.2d, v1.2s, v24.2s+ umaddl x19, w23, w16, x10+ umull v6.2d, v1.2s, v17.2s+ umaddl x10, w7, w13, x2+ mov v4.d[0], v16.d[1] // ubignum_of_h32reglist 5 + ubignum_of_l32reglist 5 // INTERMEDIATE H|L = t1|t2+ mov v10.d[0], v14.d[1] // ubignum_of_h32reglist 7 + ubignum_of_l32reglist 7 // INTERMEDIATE H|L = t1|t2+ umull v9.2d, v1.2s, v26.2s+ ldr x13, [tmpa+0]+ shl v28.2s, v15.2s, #1+ shl v3.2s, v10.2s, #1+ ldr x14, [tmpa+16]+ mul v12.2s, v10.2s, v31.2s+ umull v25.2d, v1.2s, v7.2s+ ldr x2, [tmpa+24]+ umlal v6.2d, v18.2s, v28.2s+ umaddl x27, w30, w0, x10+ umaddl x16, w24, w0, x20+ shl v13.2s, v14.2s, #1+ umaddl x5, w23, w26, x5+ mul v2.2s, v22.2s, v31.2s+ umull v21.2d, v1.2s, v13.2s+ umaddl x23, w24, w8, x29+ umlal v11.2d, v18.2s, v19.2s+ mov x10, #0x07fffffe07fffffe+ sub x10, x10, #2+ umaddl x26, w24, w21, x5+ mul v29.2s, v14.2s, v31.2s+ umlal v25.2d, v19.2s, v26.2s+ add x7, x1, x6, lsr #26+ mul v20.2s, v4.2s, v31.2s+ and x6, x6, #0x3ffffff+ shl v8.2s, v18.2s, #1+ shl v4.2s, v4.2s, #1+ umlal v11.2d, v29.2s, v14.2s+ bfi x6, x7, #32, #26 // ubignum_of_preglist 4 // INTERMEDIATE aa+ umlal v25.2d, v0.2s, v3.2s+ umaddl x0, w24, w4, x19+ umlal v25.2d, v15.2s, v13.2s+ str x6, [tmpa+32]+ umlal v21.2d, v18.2s, v4.2s+ umaddl x8, w24, w11, x3+ umlal v21.2d, v0.2s, v17.2s+ ldr x30, [tmpa+32]+ mul v14.2s, v5.2s, v31.2s+ add x2, x2, x10+ shl v5.2s, v28.2s, #1+ shl v27.2s, v4.2s, #1+ umlal v6.2d, v0.2s, v0.2s+ umaddl x11, w24, w9, x15+ umlal v6.2d, v12.2s, v3.2s+ add x4, x30, x10+ umlal v11.2d, v14.2s, v5.2s+ add x3, x22, x10+ umlal v11.2d, v2.2s, v17.2s+ add x6, x0, x11, lsr #26+ umlal v11.2d, v12.2s, v27.2s+ add x14, x14, x10+ umlal v6.2d, v14.2s, v27.2s+ add x8, x8, x6, lsr #25+ umlal v6.2d, v2.2s, v13.2s+ movk x10, #0xffb4+ umlal v25.2d, v16.2s, v4.2s+ add x29, x16, x8, lsr #26+ umull v27.2d, v1.2s, v3.2s+ and x11, x11, #0x3ffffff+ umlal v9.2d, v18.2s, v3.2s+ add x19, x13, x10+ umlal v9.2d, v0.2s, v13.2s+ and x5, x8, #0x3ffffff+ umlal v9.2d, v28.2s, v4.2s+ bfi x11, x6, #32, #25 // ubignum_of_preglist 0 // INTERMEDIATE bb+ umlal v9.2d, v16.2s, v16.2s+ umaddl x30, w24, w28, x27+ umlal v9.2d, v14.2s, v7.2s+ sub x13, x19, x11+ umull v10.2d, v1.2s, v18.2s+ add x7, x23, x29, lsr #25+ umlal v21.2d, v28.2s, v15.2s+ lsr x16, x13, #32 // ubignum_of_wreglist 1 + ubignum_of_wreglist 0 // INTERMEDIATE e+ umlal v21.2d, v2.2s, v22.2s+ add x0, x26, x7, lsr #26+ usra v25.2d, v9.2d, #26+ and x20, x7, #0x3ffffff+ umull v22.2d, v1.2s, v1.2s+ add x8, x25, x0, lsr #25+ umull v7.2d, v1.2s, v28.2s+ and x1, x29, #0x1ffffff // ubignum_of_xreglist 3 // INTERMEDIATE bbalt+ bic v18.16b, v25.16b, v23.16b+ and x19, x8, #0x3ffffff+ and v16.16b, v9.16b, v30.16b+ and x7, x12, #0x3ffffff+ usra v22.2d, v18.2d, #25+ add x10, x30, x8, lsr #26+ umlal v7.2d, v19.2s, v24.2s+ bfi x5, x29, #32, #25 // ubignum_of_preglist 1 // INTERMEDIATE bb+ and v9.16b, v25.16b, v23.16b+ add x27, x7, x10, lsr #25+ usra v22.2d, v18.2d, #24+ mov x21, #60833+ lsl x21, x21, #1+ add x15, x17, x27, lsr #26+ shl v25.2s, v3.2s, #1+ umlal v7.2d, v14.2s, v17.2s+ and x29, x27, #0x3ffffff+ usra v22.2d, v18.2d, #21+ bfi x29, x15, #32, #26 // ubignum_of_preglist 4 // INTERMEDIATE bb // ***SOURCE*** ubignum_of_xreglist 9 // INTERMEDIATE bbalt+ umlal v10.2d, v14.2s, v24.2s+ and x17, x6, #0x1ffffff // ubignum_of_xreglist 1 // INTERMEDIATE bbalt+ umlal v10.2d, v2.2s, v28.2s+ sub x6, x3, x5+ umlal v10.2d, v12.2s, v17.2s+ umaddl x25, w16, w21, x17+ umlal v10.2d, v29.2s, v4.2s+ mov w12, w5 // ubignum_of_xreglist 2 // INTERMEDIATE bbalt+ umlal v22.2d, v20.2s, v4.2s+ lsr x26, x6, #32 // ubignum_of_wreglist 3 + ubignum_of_wreglist 2 // INTERMEDIATE e+ umlal v22.2d, v14.2s, v8.2s+ and x24, x0, #0x1ffffff // ubignum_of_xreglist 5 // INTERMEDIATE bbalt+ umlal v22.2d, v2.2s, v24.2s+ stp x11, x5, [tmpb+0]+ umlal v22.2d, v12.2s, v5.2s+ bfi x20, x0, #32, #25 // ubignum_of_preglist 2 // INTERMEDIATE bb+ umlal v22.2d, v29.2s, v17.2s+ umaddl x12, w6, w21, x12+ umull v18.2d, v1.2s, v4.2s+ bfi x19, x10, #32, #25 // ubignum_of_preglist 3 // INTERMEDIATE bb+ umlal v7.2d, v2.2s, v4.2s+ sub x7, x14, x20+ umlal v27.2d, v19.2s, v13.2s+ mov w8, w20 // ubignum_of_xreglist 4 // INTERMEDIATE bbalt+ usra v10.2d, v22.2d, #26+ lsr x14, x7, #32 // ubignum_of_wreglist 5 + ubignum_of_wreglist 4 // INTERMEDIATE e+ umlal v18.2d, v19.2s, v17.2s+ and x28, x10, #0x1ffffff // ubignum_of_xreglist 7 // INTERMEDIATE bbalt+ umlal v7.2d, v12.2s, v13.2s+ sub x5, x2, x19+ usra v11.2d, v10.2d, #25+ mov w2, w19 // ubignum_of_xreglist 6 // INTERMEDIATE bbalt+ umlal v27.2d, v0.2s, v4.2s+ umlal v21.2d, v14.2s, v25.2s+ sub x23, x4, x29+ usra v7.2d, v11.2d, #26+ mov w0, w29 // ubignum_of_xreglist 8 // INTERMEDIATE bbalt+ umlal v18.2d, v0.2s, v28.2s+ lsr x22, x23, #32 // ubignum_of_wreglist 9 + ubignum_of_wreglist 8 // INTERMEDIATE e+ umlal v27.2d, v15.2s, v17.2s+ str x29, [tmpb+32]+ usra v6.2d, v7.2d, #25+ mov w17, w11 // ubignum_of_xreglist 0 // INTERMEDIATE bbalt+ and v0.16b, v22.16b, v30.16b // ubignum_of_hreglist 0 + ubignum_of_lreglist 0 // INTERMEDIATE H|L = x5|t3+ umaddl x27, w26, w21, x1+ umlal v18.2d, v14.2s, v13.2s+ umaddl x30, w23, w21, x0+ umlal v18.2d, v2.2s, v3.2s+ lsr x10, x5, #32 // ubignum_of_wreglist 7 + ubignum_of_wreglist 6 // INTERMEDIATE e+ and v4.16b, v6.16b, v30.16b // ubignum_of_hreglist 4 + ubignum_of_lreglist 4 // INTERMEDIATE H|L = x5|t3+ and v1.16b, v10.16b, v23.16b // ubignum_of_hreglist 1 + ubignum_of_lreglist 1 // INTERMEDIATE H|L = x5|t3+ umaddl x4, w14, w21, x24+ ldr x0, [tmpa+0]+ mov v0.s[1], w0+ lsr x0, x0, #32+ mov v1.s[1], w0+ umaddl x9, w7, w21, x8+ usra v18.2d, v6.2d, #26+ umaddl x24, w10, w21, x28+ and v3.16b, v7.16b, v23.16b // ubignum_of_hreglist 3 + ubignum_of_lreglist 3 // INTERMEDIATE H|L = x5|t3+ umaddl x8, w22, w21, x15+ umlal v27.2d, v14.2s, v26.2s+ umaddl x15, w13, w21, x17+ usra v21.2d, v18.2d, #25+ stp x20, x19, [tmpb+16]+ and v2.16b, v11.16b, v30.16b // ubignum_of_hreglist 2 + ubignum_of_lreglist 2 // INTERMEDIATE H|L = x5|t3+ lsr x29, x8, #25+ ldr x3, [tmpb+0]+ mov v10.s[1], w3+ lsr x3, x3, #32+ mov v11.s[1], w3+ add x17, x15, x29+ usra v27.2d, v21.2d, #26+ add x28, x17, x29, lsl #1+ and v6.16b, v21.16b, v30.16b // ubignum_of_hreglist 6 + ubignum_of_lreglist 6 // INTERMEDIATE H|L = x5|t3+ and x20, x8, #0x1ffffff+ and v5.16b, v18.16b, v23.16b // ubignum_of_hreglist 5 + ubignum_of_lreglist 5 // INTERMEDIATE H|L = x5|t3+ add x17, x28, x29, lsl #4+ and v7.16b, v27.16b, v23.16b // ubignum_of_hreglist 7 + ubignum_of_lreglist 7 // INTERMEDIATE H|L = x5|t3+ ldr x3, [tmpb+8]+ mov v22.s[1], w3+ lsr x3, x3, #32+ mov v23.s[1], w3+ add x29, x25, x17, lsr #26+ ldr x15, [pointx+0]+ mov v10.s[0], w15+ lsr x15, x15, #32+ mov v11.s[0], w15+ and x11, x17, #0x3ffffff // ubignum_of_xreglist 0 // INTERMEDIATE bce+ usra v16.2d, v27.2d, #25+ add x8, x12, x29, lsr #25+ ldr x3, [tmpb+16]+ mov v14.s[1], w3+ lsr x3, x3, #32+ mov v15.s[1], w3+ and x12, x29, #0x1ffffff // ubignum_of_xreglist 1 // INTERMEDIATE bce+ ldr x15, [pointx+8]+ mov v22.s[0], w15+ lsr x15, x15, #32+ mov v23.s[0], w15+ add x28, x27, x8, lsr #26+ and v8.16b, v16.16b, v30.16b // ubignum_of_hreglist 8 + ubignum_of_lreglist 8 // INTERMEDIATE H|L = x5|t3+ umull x1, w12, w10+ ldr x3, [tmpb+24]+ mov v17.s[1], w3+ lsr x3, x3, #32+ mov v18.s[1], w3+ add x25, x9, x28, lsr #25+ ldr x15, [pointx+16]+ mov v14.s[0], w15+ lsr x15, x15, #32+ mov v15.s[0], w15+ umaddl x19, w5, w21, x2+ usra v9.2d, v16.2d, #26 // ubignum_of_hreglist 8 + ubignum_of_lreglist 8 // INTERMEDIATE H|L = x5|t3+ add x2, x4, x25, lsr #26+ ldr x3, [tmpb+32]+ mov v24.s[1], w3+ lsr x3, x3, #32+ mov v25.s[1], w3+ umull x3, w12, w23+ ldr x15, [pointx+24]+ mov v17.s[0], w15+ lsr x15, x15, #32+ mov v18.s[0], w15+ add x29, x19, x2, lsr #25+ umull v26.2d, v0.2s, v23.2s+ and x21, x28, #0x1ffffff // ubignum_of_xreglist 3 // INTERMEDIATE bce+ ldr x0, [tmpa+8]+ mov v2.s[1], w0+ lsr x0, x0, #32+ mov v3.s[1], w0+ umaddl x27, w21, w5, x3+ ldr x15, [pointx+32]+ mov v24.s[0], w15+ lsr x15, x15, #32+ mov v25.s[0], w15+ add x17, x24, x29, lsr #26+ umull v29.2d, v1.2s, v18.2s+ and x15, x8, #0x3ffffff // ubignum_of_xreglist 2 // INTERMEDIATE bce+ umull v20.2d, v0.2s, v15.2s+ add x19, x30, x17, lsr #25+ and x3, x17, #0x1ffffff // ubignum_of_xreglist 7 // INTERMEDIATE bce+ mul v12.2s, v25.2s, v31.2s+ ldr x0, [tmpa+16]+ mov v4.s[1], w0+ lsr x0, x0, #32+ mov v5.s[1], w0+ add x4, x20, x19, lsr #26 // ubignum_of_xreglist 9 // INTERMEDIATE bce+ umlal v26.2d, v2.2s, v11.2s+ add w28, w3, w3, lsl #1;+ umlal v20.2d, v2.2s, v23.2s+ add w28, w28, w3, lsl #4+ umull x8, w12, w5+ ldr x0, [tmpa+24]+ mov v6.s[1], w0+ lsr x0, x0, #32+ mov v7.s[1], w0+ and x30, x25, #0x3ffffff // ubignum_of_xreglist 4 // INTERMEDIATE bce+ mul v16.2s, v18.2s, v31.2s+ add w17, w4, w4, lsl #1;+ umull v21.2d, v1.2s, v15.2s+ add w17, w17, w4, lsl #4+ umaddl x25, w21, w7, x8+ umlal v20.2d, v4.2s, v11.2s+ add w8, w21, w21, lsl #1;+ ldr x0, [tmpa+32]+ add w8, w8, w21, lsl #4+ mov v8.s[1], w0+ lsr x0, x0, #32+ mov v9.s[1], w0+ and x2, x2, #0x1ffffff // ubignum_of_xreglist 5 // INTERMEDIATE bce+ umlal v29.2d, v3.2s, v15.2s+ umaddl x24, w2, w6, x25+ umull v13.2d, v0.2s, v25.2s+ umaddl x25, w2, w7, x27+ umaddl x0, w3, w6, x25+ mul v19.2s, v15.2s, v31.2s+ umull v27.2d, v0.2s, v18.2s+ umaddl x20, w3, w13, x24+ umlal v20.2d, v6.2s, v12.2s+ umaddl x24, w21, w14, x1+ umlal v13.2d, v2.2s, v18.2s+ umaddl x9, w4, w13, x0+ umull v25.2d, v0.2s, v11.2s+ umaddl x20, w17, w23, x20+ umlal v27.2d, v2.2s, v15.2s+ umaddl x0, w2, w26, x24+ umull v28.2d, v1.2s, v11.2s+ umull x24, w17, w5+ umlal v29.2d, v5.2s, v23.2s+ umaddl x9, w11, w22, x9+ umlal v13.2d, v4.2s, v15.2s+ umaddl x27, w3, w16, x0+ umlal v27.2d, v4.2s, v23.2s+ umull x0, w17, w14+ umlal v27.2d, v6.2s, v11.2s+ umull x4, w12, w14+ umlal v27.2d, v8.2s, v12.2s+ umaddl x25, w11, w10, x20+ umlal v27.2d, v1.2s, v17.2s+ umaddl x0, w28, w10, x0+ umlal v13.2d, v6.2s, v23.2s+ umull x3, w17, w6+ umlal v13.2d, v8.2s, v11.2s+ umaddl x1, w21, w26, x4+ umlal v20.2d, v8.2s, v16.2s+ umaddl x4, w2, w13, x24+ umlal v28.2d, v3.2s, v12.2s+ umaddl x20, w28, w7, x3+ umlal v29.2d, v7.2s, v11.2s+ and x3, x19, #0x3ffffff // ubignum_of_xreglist 9 // INTERMEDIATE bce+ umlal v29.2d, v9.2s, v12.2s+ umaddl x19, w17, w22, x27+ add w27, w2, w2, lsl #1;+ mul v18.2s, v24.2s, v31.2s+ add w27, w27, w2, lsl #4+ umlal v21.2d, v3.2s, v23.2s+ umull x24, w17, w7+ umlal v13.2d, v1.2s, v24.2s+ add x19, x19, x19+ shl v29.2d, v29.2d, #1+ umaddl x1, w2, w16, x1+ umull v15.2d, v1.2s, v23.2s+ umaddl x0, w27, w22, x0+ umlal v29.2d, v0.2s, v24.2s+ umaddl x2, w28, w5, x24+ mul v24.2s, v23.2s, v31.2s+ umaddl x4, w28, w23, x4+ umlal v21.2d, v5.2s, v11.2s+ umaddl x24, w27, w5, x20+ umlal v20.2d, v1.2s, v14.2s+ umaddl x20, w11, w23, x19+ umlal v26.2d, v4.2s, v12.2s+ umaddl x19, w27, w23, x2+ umlal v26.2d, v6.2s, v16.2s+ umaddl x2, w21, w6, x4+ umlal v29.2d, v2.2s, v17.2s+ umaddl x24, w8, w23, x24+ umlal v15.2d, v3.2s, v11.2s+ umaddl x0, w21, w16, x0+ umaddl x4, w21, w13, x19+ mul v23.2s, v11.2s, v31.2s+ umlal v20.2d, v3.2s, v22.2s+ umaddl x2, w12, w7, x2+ umlal v20.2d, v5.2s, v10.2s+ umaddl x19, w12, w26, x0+ umlal v29.2d, v4.2s, v14.2s+ umaddl x0, w12, w13, x24+ umlal v26.2d, v8.2s, v19.2s+ umaddl x20, w15, w5, x20+ umlal v26.2d, v1.2s, v22.2s+ umaddl x21, w15, w10, x9+ umlal v26.2d, v3.2s, v10.2s+ and x9, x29, #0x3ffffff // ubignum_of_xreglist 6 // INTERMEDIATE bce+ umlal v29.2d, v6.2s, v22.2s+ umaddl x20, w30, w7, x20+ umaddl x1, w28, w22, x1+ add x24, x19, x19+ umull v11.2d, v1.2s, v12.2s+ add w19, w3, w3, lsl #1;+ umlal v26.2d, v5.2s, v18.2s+ add w19, w19, w3, lsl #4+ umaddl x20, w9, w6, x20+ umlal v29.2d, v8.2s, v10.2s+ add w29, w9, w9, lsl #1;+ umlal v13.2d, v3.2s, v17.2s+ add w29, w29, w9, lsl #4+ umaddl x2, w19, w10, x2+ umlal v11.2d, v3.2s, v16.2s+ umaddl x21, w30, w14, x21+ umlal v11.2d, v5.2s, v19.2s+ umaddl x20, w3, w13, x20+ umlal v11.2d, v7.2s, v24.2s+ umaddl x2, w29, w22, x2+ umlal v11.2d, v9.2s, v23.2s+ umaddl x21, w9, w26, x21+ ushr v23.2d, v30.2d, #1+ umaddl x1, w17, w10, x1+ umlal v13.2d, v5.2s, v14.2s+ umaddl x24, w19, w5, x24+ umlal v27.2d, v3.2s, v14.2s+ umaddl x21, w3, w16, x21+ shl v11.2d, v11.2d, #1+ add w3, w30, w30, lsl #1;+ umlal v28.2d, v5.2s, v16.2s+ add w3, w3, w30, lsl #4+ umaddl x24, w29, w23, x24+ umlal v28.2d, v7.2s, v19.2s+ add x1, x1, x1+ umlal v28.2d, v9.2s, v24.2s+ umaddl x1, w11, w5, x1+ umlal v15.2d, v5.2s, v12.2s+ umaddl x24, w30, w13, x24+ umlal v15.2d, v7.2s, v16.2s+ umaddl x25, w15, w14, x25+ umlal v15.2d, v9.2s, v19.2s+ umaddl x1, w15, w7, x1+ shl v28.2d, v28.2d, #1+ umaddl x24, w15, w6, x24+ umlal v21.2d, v7.2s, v12.2s+ umaddl x2, w30, w16, x2+ umlal v21.2d, v9.2s, v16.2s+ umaddl x25, w30, w26, x25+ shl v15.2d, v15.2d, #1+ umaddl x30, w30, w6, x1+ umlal v28.2d, v0.2s, v22.2s+ umaddl x1, w15, w26, x2+ umlal v28.2d, v2.2s, v10.2s+ umaddl x2, w9, w16, x25+ shl v21.2d, v21.2d, #1+ umaddl x24, w11, w7, x24+ umlal v15.2d, v0.2s, v14.2s+ umaddl x1, w11, w14, x1+ umlal v21.2d, v0.2s, v17.2s+ umaddl x25, w9, w13, x30+ umlal v28.2d, v4.2s, v18.2s+ umaddl x0, w19, w26, x0+ umlal v25.2d, v2.2s, v12.2s+ add x1, x1, x24, lsr #26+ umlal v25.2d, v4.2s, v16.2s+ umaddl x30, w19, w22, x2+ umlal v21.2d, v2.2s, v14.2s+ umaddl x4, w12, w6, x4+ mul v14.2s, v14.2s, v31.2s+ umaddl x25, w19, w23, x25+ and x2, x1, #0x1ffffff+ mul v16.2s, v17.2s, v31.2s+ umlal v25.2d, v6.2s, v19.2s+ umaddl x9, w19, w14, x4+ umlal v13.2d, v7.2s, v22.2s+ add x25, x25, x1, lsr #25+ umlal v21.2d, v4.2s, v22.2s+ umaddl x0, w29, w14, x0+ umlal v26.2d, v7.2s, v16.2s+ add x30, x30, x25, lsr #26+ umlal v26.2d, v9.2s, v14.2s+ add w1, w15, w15, lsl #1;+ umlal v28.2d, v6.2s, v16.2s+ add w1, w1, w15, lsl #4+ add x4, x20, x30, lsr #25+ umlal v28.2d, v8.2s, v14.2s+ and x25, x25, #0x3ffffff+ umlal v15.2d, v2.2s, v22.2s+ add x21, x21, x4, lsr #26+ umlal v11.2d, v0.2s, v10.2s+ bfi x25, x30, #32, #25 // ubignum_of_preglist 3 // INTERMEDIATE z4+ umlal v11.2d, v2.2s, v18.2s+ bic x30, x21, #0x3ffffff+ usra v26.2d, v28.2d, #26+ lsr x20, x30, #26+ umlal v15.2d, v4.2s, v10.2s+ add x20, x20, x30, lsr #25+ umlal v15.2d, v6.2s, v18.2s+ umaddl x9, w29, w10, x9+ umlal v15.2d, v8.2s, v16.2s+ add x30, x20, x30, lsr #22+ umlal v27.2d, v5.2s, v22.2s+ umull x20, w17, w26+ umlal v20.2d, v7.2s, v18.2s+ umaddl x30, w17, w16, x30+ umlal v20.2d, v9.2s, v16.2s+ umaddl x17, w3, w10, x0+ usra v15.2d, v26.2d, #25+ umaddl x0, w28, w14, x20+ umlal v27.2d, v7.2s, v10.2s+ umaddl x20, w28, w26, x30+ umlal v27.2d, v9.2s, v18.2s+ add w28, w12, w12, lsl #1;+ usra v20.2d, v15.2d, #26+ add w28, w28, w12, lsl #4+ umaddl x30, w27, w10, x0+ and v17.16b, v15.16b, v30.16b // ubignum_of_hreglist 4 + ubignum_of_lreglist 4 // INTERMEDIATE H|L = x4|z5+ umaddl x27, w27, w14, x20+ umaddl x0, w8, w10, x27+ mul v12.2s, v22.2s, v31.2s+ and v15.16b, v20.16b, v23.16b // ubignum_of_hreglist 5 + ubignum_of_lreglist 5 // INTERMEDIATE H|L = x4|z5+ umaddl x14, w3, w22, x9+ umlal v21.2d, v6.2s, v10.2s+ umaddl x27, w8, w22, x30+ trn1 v15.4s, v17.4s, v15.4s // FINAL z3+ umaddl x10, w28, w22, x0+ umlal v11.2d, v4.2s, v16.2s+ umaddl x30, w15, w16, x14+ and v26.16b, v26.16b, v23.16b+ umaddl x28, w12, w16, x27+ umlal v21.2d, v8.2s, v18.2s+ add x10, x10, x10+ umlal v25.2d, v8.2s, v24.2s+ umaddl x20, w19, w6, x10+ umlal v25.2d, v1.2s, v10.2s+ add x28, x28, x28+ umlal v25.2d, v3.2s, v18.2s+ umaddl x28, w19, w7, x28+ usra v21.2d, v20.2d, #25+ umaddl x0, w29, w7, x20+ umlal v11.2d, v6.2s, v14.2s+ umaddl x10, w11, w26, x30+ umlal v13.2d, v9.2s, v10.2s+ umaddl x19, w29, w5, x28+ usra v27.2d, v21.2d, #26+ umaddl x0, w3, w5, x0+ umlal v25.2d, v5.2s, v16.2s+ umaddl x20, w1, w22, x17+ and v20.16b, v28.16b, v30.16b+ umaddl x29, w3, w23, x19+ usra v29.2d, v27.2d, #25+ umaddl x3, w1, w23, x0+ and v27.16b, v27.16b, v23.16b // ubignum_of_hreglist 7 + ubignum_of_lreglist 7 // INTERMEDIATE H|L = x4|z5+ umlal v11.2d, v8.2s, v12.2s+ umaddl x12, w15, w13, x29+ usra v13.2d, v29.2d, #26+ umaddl x7, w11, w13, x3+ trn1 v6.4s, v6.4s, v7.4s+ umaddl x17, w11, w16, x20+ umlal v25.2d, v7.2s, v14.2s+ and x23, x4, #0x3ffffff+ bic v19.16b, v13.16b, v23.16b+ umaddl x19, w11, w6, x12+ and v28.16b, v13.16b, v23.16b // ubignum_of_hreglist 9 + ubignum_of_lreglist 9 // INTERMEDIATE H|L = x4|z5+ add x3, x17, x7, lsr #26+ usra v11.2d, v19.2d, #25+ trn1 v2.4s, v2.4s, v3.4s+ add x17, x19, x3, lsr #25+ and v13.16b, v21.16b, v30.16b // ubignum_of_hreglist 6 + ubignum_of_lreglist 6 // INTERMEDIATE H|L = x4|z5+ and x5, x7, #0x3ffffff+ usra v11.2d, v19.2d, #24+ add x7, x10, x17, lsr #26+ trn1 v0.4s, v0.4s, v1.4s+ and x19, x24, #0x3ffffff+ and v21.16b, v29.16b, v30.16b // ubignum_of_hreglist 8 + ubignum_of_lreglist 8 // INTERMEDIATE H|L = x4|z5+ add x29, x19, x7, lsr #25+ usra v11.2d, v19.2d, #21+ bfi x5, x3, #32, #25 // ubignum_of_preglist 0 // INTERMEDIATE z4+ trn1 v17.4s, v13.4s, v27.4s // FINAL z3+ add x19, x2, x29, lsr #26+ trn1 v19.4s, v21.4s, v28.4s // FINAL z3+ and x3, x29, #0x3ffffff+ mov v16.d[0], v6.d[1] // FINAL x3+ mov v6.d[0], v17.d[1] // FINAL x2+ trn1 v8.4s, v8.4s, v9.4s+ bfi x3, x19, #32, #26 // ubignum_of_preglist 2 // INTERMEDIATE z4+ and v21.16b, v11.16b, v30.16b // ubignum_of_hreglist 0 + ubignum_of_lreglist 0 // INTERMEDIATE H|L = x4|z5+ bfi x23, x21, #32, #26 // ubignum_of_preglist 4 // INTERMEDIATE z4+ mov v18.d[0], v8.d[1] // FINAL x3+ mov v8.d[0], v19.d[1] // FINAL x2+ umlal v25.2d, v9.2s, v12.2s+ mov v9.d[0], x23 // FINAL z2+ mov v7.d[0], x25 // FINAL z2+ ldr d29, [mask1]+ mov v12.d[0], v2.d[1] // FINAL x3+ trn1 v4.4s, v4.4s, v5.4s+ and x17, x17, #0x3ffffff+ usra v25.2d, v11.2d, #26+ mov v10.d[0], v0.d[1] // FINAL x3+ mov v14.d[0], v4.d[1] // FINAL x3+ mov v4.d[0], v15.d[1] // FINAL x2+ usra v20.2d, v25.2d, #25+ and v27.16b, v25.16b, v23.16b // ubignum_of_hreglist 1 + ubignum_of_lreglist 1 // INTERMEDIATE H|L = x4|z5+ bfi x17, x7, #32, #25 // ubignum_of_preglist 1 // INTERMEDIATE z4+ mov v5.d[0], x3+ mov v1.d[0], x5 // FINAL z2+ usra v26.2d, v20.2d, #26 // ubignum_of_hreglist 3 + ubignum_of_lreglist 3 // INTERMEDIATE H|L = x4|z5+ and v28.16b, v20.16b, v30.16b // ubignum_of_hreglist 2 + ubignum_of_lreglist 2 // INTERMEDIATE H|L = x4|z5+ trn1 v11.4s, v21.4s, v27.4s // FINAL z3+ trn1 v13.4s, v28.4s, v26.4s // FINAL z3+ mov v0.d[0], v11.d[1] // FINAL x2+ mov v3.d[0], x17 // FINAL z2+ mov v2.d[0], v13.d[1] // FINAL x2+ ldr d28, [mask2]++ ldr x0, [i]+ subs x0, x0, #1+ str x0, [i]+ bcs Lcurve25519_x25519_scalarloop++// Repack X2 into the saturated representation as 256-bit value xn.+// This does not fully normalize mod 2^255-19 but stays within 256 bits.++ mov w0, v0.s[0]+ mov w1, v0.s[1]+ mov w2, v2.s[0]+ mov w3, v2.s[1]+ mov w4, v4.s[0]+ mov w5, v4.s[1]+ mov w6, v6.s[0]+ mov w7, v6.s[1]+ mov w8, v8.s[0]+ mov w9, v8.s[1]++ add x0, x0, x1, lsl #26+ add x1, x2, x3, lsl #26+ add x2, x4, x5, lsl #26+ add x3, x6, x7, lsl #26+ add x4, x8, x9, lsl #26++ adds x0, x0, x1, lsl #51+ lsr x6, x1, #13+ lsl x7, x2, #38+ adcs x1, x6, x7+ lsr x8, x2, #26+ lsl x9, x3, #25+ adcs x2, x8, x9+ lsr x10, x3, #39+ lsl x11, x4, #12+ adc x3, x10, x11+ stp x0, x1, [xn]+ stp x2, x3, [xn+16]++// Repack Z2 into the saturated representation as 256-bit value zn.+// This does not fully normalize mod 2^255-19. However since Z2,+// unlike X2, was not repacked (within the last multiplication) in+// right-to-left order, its top digit can be any 26-bit value, on+// the face of it. To make sure we don't overflow 256 bits here+// we remove b = 25th bit of the 9th digit (now scaled by 2^230+// giving bit 25 a final weighting of 2^255) and add 19 * b to+// to the bottom of the sum here to compensate mod 2^255-19.++ mov w0, v1.s[0]+ mov w1, v1.s[1]+ mov w2, v3.s[0]+ mov w3, v3.s[1]+ mov w4, v5.s[0]+ mov w5, v5.s[1]+ mov w6, v7.s[0]+ mov w7, v7.s[1]+ mov w8, v9.s[0]+ mov w9, v9.s[1]++ mov w10, #19+ add x0, x0, x1, lsl #26+ tst x9, #0x2000000+ add x1, x2, x3, lsl #26+ csel x10, x10, xzr, ne+ add x2, x4, x5, lsl #26+ and x9, x9, #0x1FFFFFF+ add x3, x6, x7, lsl #26+ add x0, x0, x10+ add x4, x8, x9, lsl #26++ adds x0, x0, x1, lsl #51+ lsr x6, x1, #13+ lsl x7, x2, #38+ adcs x1, x6, x7+ lsr x8, x2, #26+ lsl x9, x3, #25+ adcs x2, x8, x9+ lsr x10, x3, #39+ lsl x11, x4, #12+ adc x3, x10, x11+ stp x0, x1, [zn]+ stp x2, x3, [zn+16]++// Because the lowest bit (indeed, the three lowest bits) of the scalar+// were forced to zero, we know that the projective result of the scalar+// multiplication was in (X2,Z2) and is now (xn,zn) in saturated form.+// Prepare to call the modular inverse function to get zn' = 1/zn.++ add x0, zn+ add x1, zn++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "arm/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 128 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, xn, and zn.++ mov x20, x0+ mov x10, #0xffffffffffffffed+ mov x11, #0xffffffffffffffff+ stp x10, x11, [sp]+ mov x12, #0x7fffffffffffffff+ stp x11, x12, [sp, #16]+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x7, #0x13+ lsr x6, x5, #63+ madd x6, x7, x6, x7+ adds x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ orr x5, x5, #0x8000000000000000+ adcs x5, x5, xzr+ csel x6, x7, xzr, cc+ subs x2, x2, x6+ sbcs x3, x3, xzr+ sbcs x4, x4, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ stp x2, x3, [sp, #32]+ stp x4, x5, [sp, #48]+ stp xzr, xzr, [sp, #64]+ stp xzr, xzr, [sp, #80]+ mov x10, #0x2099+ movk x10, #0x7502, lsl #16+ movk x10, #0x9e23, lsl #32+ movk x10, #0xa0f9, lsl #48+ mov x11, #0x2595+ movk x11, #0x1d13, lsl #16+ movk x11, #0x8f3f, lsl #32+ movk x11, #0xa8c6, lsl #48+ mov x12, #0x5242+ movk x12, #0x5ac, lsl #16+ movk x12, #0x8938, lsl #32+ movk x12, #0x6c6c, lsl #48+ mov x13, #0x615+ movk x13, #0x4177, lsl #16+ movk x13, #0x8b2, lsl #32+ movk x13, #0x2765, lsl #48+ stp x10, x11, [sp, #96]+ stp x12, x13, [sp, #112]+ mov x21, #0xa+ mov x22, #0x1+ b Lcurve25519_x25519_invmidloop+Lcurve25519_x25519_invloop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #32]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #40]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #32]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #40]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ asr x3, x1, #63+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ asr x0, x1, #63+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ eor x1, x7, x16+ asr x5, x1, #63+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ asr x0, x1, #63+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #48]+ extr x2, x5, x2, #59+ str x2, [sp, #56]+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #96]+ adc x3, x3, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #104]+ adc x4, x4, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #112]+ adc x2, x2, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ add x6, x6, x3, asr #63+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x3, x6, x3+ ldr x6, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x3+ asr x3, x3, #63+ adcs x6, x6, x3+ adc x5, x5, x3+ stp x0, x1, [sp, #64]+ stp x6, x5, [sp, #80]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x6, x5, x2, #63+ ldp x0, x1, [sp, #96]+ add x6, x6, x5, asr #63+ mov x5, #0x13+ mul x4, x6, x5+ add x2, x2, x6, lsl #63+ smulh x5, x6, x5+ ldr x3, [sp, #112]+ adds x0, x0, x4+ adcs x1, x1, x5+ asr x5, x5, #63+ adcs x3, x3, x5+ adc x2, x2, x5+ stp x0, x1, [sp, #96]+ stp x3, x2, [sp, #112]+Lcurve25519_x25519_invmidloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #32]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Lcurve25519_x25519_invloop+ ldr x0, [sp]+ ldr x1, [sp, #32]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ tst x3, x3+ cinc x6, x6, pl+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x6, x6, x3+ ldr x2, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x6+ asr x6, x6, #63+ adcs x2, x2, x6+ adcs x5, x5, x6+ csel x3, x3, xzr, mi+ subs x0, x0, x3+ sbcs x1, x1, xzr+ sbcs x2, x2, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ mov x4, x20+ stp x0, x1, [x4]+ stp x2, x5, [x4, #16]++// Now the result is xn * (1/zn), fully reduced modulo p.+// Note that in the degenerate case zn = 0 (mod p_25519), the+// modular inverse code above will produce 1/zn = 0, giving+// the correct overall X25519 result of zero for the point at+// infinity. The multiplication below is just an inlined+// version of bignum_mul_p25519 except for the detailed+// addressing of inputs and outputs++ ldr x17, [res]++ ldp x3, x4, [xn]+ ldp x5, x6, [zn]+ umull x7, w3, w5+ lsr x0, x3, #32+ umull x15, w0, w5+ lsr x16, x5, #32+ umull x8, w16, w0+ umull x16, w3, w16+ adds x7, x7, x15, lsl #32+ lsr x15, x15, #32+ adc x8, x8, x15+ adds x7, x7, x16, lsl #32+ lsr x16, x16, #32+ adc x8, x8, x16+ mul x9, x4, x6+ umulh x10, x4, x6+ subs x4, x4, x3+ cneg x4, x4, cc+ csetm x16, cc+ adds x9, x9, x8+ adc x10, x10, xzr+ subs x3, x5, x6+ cneg x3, x3, cc+ cinv x16, x16, cc+ mul x15, x4, x3+ umulh x3, x4, x3+ adds x8, x7, x9+ adcs x9, x9, x10+ adc x10, x10, xzr+ cmn x16, #0x1+ eor x15, x15, x16+ adcs x8, x15, x8+ eor x3, x3, x16+ adcs x9, x3, x9+ adc x10, x10, x16+ ldp x3, x4, [xn+16]+ ldp x5, x6, [zn+16]+ umull x11, w3, w5+ lsr x0, x3, #32+ umull x15, w0, w5+ lsr x16, x5, #32+ umull x12, w16, w0+ umull x16, w3, w16+ adds x11, x11, x15, lsl #32+ lsr x15, x15, #32+ adc x12, x12, x15+ adds x11, x11, x16, lsl #32+ lsr x16, x16, #32+ adc x12, x12, x16+ mul x13, x4, x6+ umulh x14, x4, x6+ subs x4, x4, x3+ cneg x4, x4, cc+ csetm x16, cc+ adds x13, x13, x12+ adc x14, x14, xzr+ subs x3, x5, x6+ cneg x3, x3, cc+ cinv x16, x16, cc+ mul x15, x4, x3+ umulh x3, x4, x3+ adds x12, x11, x13+ adcs x13, x13, x14+ adc x14, x14, xzr+ cmn x16, #0x1+ eor x15, x15, x16+ adcs x12, x15, x12+ eor x3, x3, x16+ adcs x13, x3, x13+ adc x14, x14, x16+ ldp x3, x4, [xn+16]+ ldp x15, x16, [xn]+ subs x3, x3, x15+ sbcs x4, x4, x16+ csetm x16, cc+ ldp x15, x0, [zn]+ subs x5, x15, x5+ sbcs x6, x0, x6+ csetm x0, cc+ eor x3, x3, x16+ subs x3, x3, x16+ eor x4, x4, x16+ sbc x4, x4, x16+ eor x5, x5, x0+ subs x5, x5, x0+ eor x6, x6, x0+ sbc x6, x6, x0+ eor x16, x0, x16+ adds x11, x11, x9+ adcs x12, x12, x10+ adcs x13, x13, xzr+ adc x14, x14, xzr+ mul x2, x3, x5+ umulh x0, x3, x5+ mul x15, x4, x6+ umulh x1, x4, x6+ subs x4, x4, x3+ cneg x4, x4, cc+ csetm x9, cc+ adds x15, x15, x0+ adc x1, x1, xzr+ subs x6, x5, x6+ cneg x6, x6, cc+ cinv x9, x9, cc+ mul x5, x4, x6+ umulh x6, x4, x6+ adds x0, x2, x15+ adcs x15, x15, x1+ adc x1, x1, xzr+ cmn x9, #0x1+ eor x5, x5, x9+ adcs x0, x5, x0+ eor x6, x6, x9+ adcs x15, x6, x15+ adc x1, x1, x9+ adds x9, x11, x7+ adcs x10, x12, x8+ adcs x11, x13, x11+ adcs x12, x14, x12+ adcs x13, x13, xzr+ adc x14, x14, xzr+ cmn x16, #0x1+ eor x2, x2, x16+ adcs x9, x2, x9+ eor x0, x0, x16+ adcs x10, x0, x10+ eor x15, x15, x16+ adcs x11, x15, x11+ eor x1, x1, x16+ adcs x12, x1, x12+ adcs x13, x13, x16+ adc x14, x14, x16+ mov x3, #0x26+ umull x4, w11, w3+ add x4, x4, w7, uxtw+ lsr x7, x7, #32+ lsr x11, x11, #32+ umaddl x11, w11, w3, x7+ mov x7, x4+ umull x4, w12, w3+ add x4, x4, w8, uxtw+ lsr x8, x8, #32+ lsr x12, x12, #32+ umaddl x12, w12, w3, x8+ mov x8, x4+ umull x4, w13, w3+ add x4, x4, w9, uxtw+ lsr x9, x9, #32+ lsr x13, x13, #32+ umaddl x13, w13, w3, x9+ mov x9, x4+ umull x4, w14, w3+ add x4, x4, w10, uxtw+ lsr x10, x10, #32+ lsr x14, x14, #32+ umaddl x14, w14, w3, x10+ mov x10, x4+ lsr x0, x14, #31+ mov x5, #0x13+ umaddl x5, w5, w0, x5+ add x7, x7, x5+ adds x7, x7, x11, lsl #32+ extr x3, x12, x11, #32+ adcs x8, x8, x3+ extr x3, x13, x12, #32+ adcs x9, x9, x3+ extr x3, x14, x13, #32+ lsl x5, x0, #63+ eor x10, x10, x5+ adc x10, x10, x3+ mov x3, #0x13+ tst x10, #0x8000000000000000+ csel x3, x3, xzr, pl+ subs x7, x7, x3+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ and x10, x10, #0x7fffffffffffffff+ stp x7, x8, [x17]+ stp x9, x10, [x17, #16]++// Restore stack and registers (this will zero the tops of Q8...Q15).++ CFI_STACKLOAD2(d8,d9,NSPACE+0)+ CFI_STACKLOAD2(d10,d11,NSPACE+16)+ CFI_STACKLOAD2(d12,d13,NSPACE+32)+ CFI_STACKLOAD2(d14,d15,NSPACE+48)+ CFI_STACKLOAD2(x19,x20,NSPACE+64)+ CFI_STACKLOAD2(x21,x22,NSPACE+80)+ CFI_STACKLOAD2(x23,x24,NSPACE+96)+ CFI_STACKLOAD2(x25,x26,NSPACE+112)+ CFI_STACKLOAD2(x27,x28,NSPACE+128)+ CFI_STACKLOAD2(x29,x30,NSPACE+144)+ CFI_INC_SP((NSPACE+160))+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/curve25519_x25519_alt.S view
@@ -0,0 +1,1702 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// The x25519 function for curve25519+// Inputs scalar[4], point[4]; output res[4]+//+// extern void curve25519_x25519_alt+// (uint64_t res[static 4],const uint64_t scalar[static 4],+// const uint64_t point[static 4]);+//+// Given a scalar n and the X coordinate of an input point P = (X,Y) on+// curve25519 (Y can live in any extension field of characteristic 2^255-19),+// this returns the X coordinate of n * P = (X, Y), or 0 when n * P is the+// point at infinity. Both n and X inputs are first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748);+// in particular the lower three bits of n are set to zero. Does not implement+// the zero-check specified in Section 6.1.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519_alt)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable homes for the input result argument during the whole body+// and other variables that are only needed prior to the modular inverse.++#define res x23+#define i x20+#define swap x21++// Pointers to result x coord to be written++#define resx res, #0++// Pointer-offset pairs for temporaries on stack with some aliasing.++#define scalar sp, #(0*NUMSIZE)++#define pointx sp, #(1*NUMSIZE)++#define zm sp, #(2*NUMSIZE)+#define sm sp, #(2*NUMSIZE)+#define dpro sp, #(2*NUMSIZE)++#define sn sp, #(3*NUMSIZE)++#define dm sp, #(4*NUMSIZE)++#define zn sp, #(5*NUMSIZE)+#define dn sp, #(5*NUMSIZE)+#define e sp, #(5*NUMSIZE)++#define dmsn sp, #(6*NUMSIZE)+#define p sp, #(6*NUMSIZE)++#define xm sp, #(7*NUMSIZE)+#define dnsm sp, #(7*NUMSIZE)+#define spro sp, #(7*NUMSIZE)++#define d sp, #(8*NUMSIZE)++#define xn sp, #(9*NUMSIZE)+#define s sp, #(9*NUMSIZE)++// Total size to reserve on the stack++#define NSPACE 10*NUMSIZE++// Macro wrapping up the basic field operation bignum_mul_p25519_alt, only+// trivially different from a pure function call to that subroutine.++#define mul_p25519(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x15, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x16, x3, x10 __LF \+ adcs x15, x15, x11 __LF \+ adc x16, x16, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x16, x16, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x15, x15, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x16, x16, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x15, x15, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x16, x16, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x15, x15, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x16, x16, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ mov x7, #0x26 __LF \+ mul x11, x7, x16 __LF \+ umulh x9, x7, x16 __LF \+ adds x12, x12, x11 __LF \+ mul x11, x7, x3 __LF \+ umulh x3, x7, x3 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x7, x4 __LF \+ umulh x4, x7, x4 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x7, x5 __LF \+ umulh x5, x7, x5 __LF \+ adcs x15, x15, x11 __LF \+ cset x16, cs __LF \+ adds x15, x15, x4 __LF \+ adc x16, x16, x5 __LF \+ cmn x15, x15 __LF \+ orr x15, x15, #0x8000000000000000 __LF \+ adc x8, x16, x16 __LF \+ mov x7, #0x13 __LF \+ madd x11, x7, x8, x7 __LF \+ adds x12, x12, x11 __LF \+ adcs x13, x13, x9 __LF \+ adcs x14, x14, x3 __LF \+ adcs x15, x15, xzr __LF \+ csel x7, x7, xzr, cc __LF \+ subs x12, x12, x7 __LF \+ sbcs x13, x13, xzr __LF \+ sbcs x14, x14, xzr __LF \+ sbc x15, x15, xzr __LF \+ and x15, x15, #0x7fffffffffffffff __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x15, [P0+16]++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x15, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x16, x3, x10 __LF \+ adcs x15, x15, x11 __LF \+ adc x16, x16, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x16, x16, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x15, x15, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x16, x16, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x15, x15, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x16, x16, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x15, x15, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x16, x16, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ mov x7, #0x26 __LF \+ mul x11, x7, x16 __LF \+ umulh x9, x7, x16 __LF \+ adds x12, x12, x11 __LF \+ mul x11, x7, x3 __LF \+ umulh x3, x7, x3 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x7, x4 __LF \+ umulh x4, x7, x4 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x7, x5 __LF \+ umulh x5, x7, x5 __LF \+ adcs x15, x15, x11 __LF \+ cset x16, cs __LF \+ adds x15, x15, x4 __LF \+ adc x16, x16, x5 __LF \+ cmn x15, x15 __LF \+ bic x15, x15, #0x8000000000000000 __LF \+ adc x8, x16, x16 __LF \+ mov x7, #0x13 __LF \+ mul x11, x7, x8 __LF \+ adds x12, x12, x11 __LF \+ adcs x13, x13, x9 __LF \+ adcs x14, x14, x3 __LF \+ adc x15, x15, xzr __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x15, [P0+16]++// Squaring just giving a result < 2 * p_25519, which is done by+// basically skipping the +1 in the quotient estimate and the final+// optional correction.++#define sqr_4(P0,P1) \+ ldp x2, x3, [P1] __LF \+ mul x9, x2, x3 __LF \+ umulh x10, x2, x3 __LF \+ ldp x4, x5, [P1+16] __LF \+ mul x11, x2, x5 __LF \+ umulh x12, x2, x5 __LF \+ mul x7, x2, x4 __LF \+ umulh x6, x2, x4 __LF \+ adds x10, x10, x7 __LF \+ adcs x11, x11, x6 __LF \+ mul x7, x3, x4 __LF \+ umulh x6, x3, x4 __LF \+ adc x6, x6, xzr __LF \+ adds x11, x11, x7 __LF \+ mul x13, x4, x5 __LF \+ umulh x14, x4, x5 __LF \+ adcs x12, x12, x6 __LF \+ mul x7, x3, x5 __LF \+ umulh x6, x3, x5 __LF \+ adc x6, x6, xzr __LF \+ adds x12, x12, x7 __LF \+ adcs x13, x13, x6 __LF \+ adc x14, x14, xzr __LF \+ adds x9, x9, x9 __LF \+ adcs x10, x10, x10 __LF \+ adcs x11, x11, x11 __LF \+ adcs x12, x12, x12 __LF \+ adcs x13, x13, x13 __LF \+ adcs x14, x14, x14 __LF \+ cset x6, cs __LF \+ umulh x7, x2, x2 __LF \+ mul x8, x2, x2 __LF \+ adds x9, x9, x7 __LF \+ mul x7, x3, x3 __LF \+ adcs x10, x10, x7 __LF \+ umulh x7, x3, x3 __LF \+ adcs x11, x11, x7 __LF \+ mul x7, x4, x4 __LF \+ adcs x12, x12, x7 __LF \+ umulh x7, x4, x4 __LF \+ adcs x13, x13, x7 __LF \+ mul x7, x5, x5 __LF \+ adcs x14, x14, x7 __LF \+ umulh x7, x5, x5 __LF \+ adc x6, x6, x7 __LF \+ mov x3, #0x26 __LF \+ mul x7, x3, x12 __LF \+ umulh x4, x3, x12 __LF \+ adds x8, x8, x7 __LF \+ mul x7, x3, x13 __LF \+ umulh x13, x3, x13 __LF \+ adcs x9, x9, x7 __LF \+ mul x7, x3, x14 __LF \+ umulh x14, x3, x14 __LF \+ adcs x10, x10, x7 __LF \+ mul x7, x3, x6 __LF \+ umulh x6, x3, x6 __LF \+ adcs x11, x11, x7 __LF \+ cset x12, cs __LF \+ adds x11, x11, x14 __LF \+ adc x12, x12, x6 __LF \+ cmn x11, x11 __LF \+ bic x11, x11, #0x8000000000000000 __LF \+ adc x2, x12, x12 __LF \+ mov x3, #0x13 __LF \+ mul x7, x3, x2 __LF \+ adds x8, x8, x7 __LF \+ adcs x9, x9, x4 __LF \+ adcs x10, x10, x13 __LF \+ adc x11, x11, xzr __LF \+ stp x8, x9, [P0] __LF \+ stp x10, x11, [P0+16]++// Modular addition with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ adds x3, x3, x7 __LF \+ adcs x4, x4, x8 __LF \+ ldp x5, x6, [P1+16] __LF \+ ldp x7, x8, [P2+16] __LF \+ adcs x5, x5, x7 __LF \+ adcs x6, x6, x8 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(p0,p1,p2) \+ ldp x5, x6, [p1] __LF \+ ldp x4, x3, [p2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [p1+16] __LF \+ ldp x4, x3, [p2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ mov x4, #38 __LF \+ csel x3, x4, xzr, lo __LF \+ subs x5, x5, x3 __LF \+ sbcs x6, x6, xzr __LF \+ sbcs x7, x7, xzr __LF \+ sbc x8, x8, xzr __LF \+ stp x5, x6, [p0] __LF \+ stp x7, x8, [p0+16]++// Combined z = c * x + y with reduction only < 2 * p_25519+// where c is initially in the X1 register. It is assumed+// that 19 * (c * x + y) < 2^60 * 2^256 so we don't need a+// high mul in the final part.++#define cmadd_4(p0,p2,p3) \+ ldp x7, x8, [p2] __LF \+ ldp x9, x10, [p2+16] __LF \+ mul x3, x1, x7 __LF \+ mul x4, x1, x8 __LF \+ mul x5, x1, x9 __LF \+ mul x6, x1, x10 __LF \+ umulh x7, x1, x7 __LF \+ umulh x8, x1, x8 __LF \+ umulh x9, x1, x9 __LF \+ umulh x10, x1, x10 __LF \+ adds x4, x4, x7 __LF \+ adcs x5, x5, x8 __LF \+ adcs x6, x6, x9 __LF \+ adc x10, x10, xzr __LF \+ ldp x7, x8, [p3] __LF \+ adds x3, x3, x7 __LF \+ adcs x4, x4, x8 __LF \+ ldp x7, x8, [p3+16] __LF \+ adcs x5, x5, x7 __LF \+ adcs x6, x6, x8 __LF \+ adc x10, x10, xzr __LF \+ cmn x6, x6 __LF \+ bic x6, x6, #0x8000000000000000 __LF \+ adc x8, x10, x10 __LF \+ mov x9, #19 __LF \+ mul x7, x8, x9 __LF \+ adds x3, x3, x7 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [p0] __LF \+ stp x5, x6, [p0+16]++// Multiplex: z := if NZ then x else y++#define mux_4(p0,p1,p2) \+ ldp x0, x1, [p1] __LF \+ ldp x2, x3, [p2] __LF \+ csel x0, x0, x2, ne __LF \+ csel x1, x1, x3, ne __LF \+ stp x0, x1, [p0] __LF \+ ldp x0, x1, [p1+16] __LF \+ ldp x2, x3, [p2+16] __LF \+ csel x0, x0, x2, ne __LF \+ csel x1, x1, x3, ne __LF \+ stp x0, x1, [p0+16]++S2N_BN_SYMBOL(curve25519_x25519_alt):+ CFI_START++// Save regs and make room for temporaries++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(NSPACE)++// Move the output pointer to a stable place++ mov res, x0++// Copy the inputs to the local variables with minimal mangling:+//+// - The scalar is in principle turned into 01xxx...xxx000 but+// in the structure below the special handling of these bits is+// explicit in the main computation; the scalar is just copied.+//+// - The point x coord is reduced mod 2^255 by masking off the+// top bit. In the main loop we only need reduction < 2 * p_25519.++ ldp x10, x11, [x1]+ stp x10, x11, [scalar]+ ldp x12, x13, [x1, #16]+ stp x12, x13, [scalar+16]++ ldp x10, x11, [x2]+ stp x10, x11, [pointx]+ ldp x12, x13, [x2, #16]+ and x13, x13, #0x7fffffffffffffff+ stp x12, x13, [pointx+16]++// Initialize with explicit doubling in order to handle set bit 254.+// Set swap = 1 and (xm,zm) = (x,1) then double as (xn,zn) = 2 * (x,1).+// We use the fact that the point x coordinate is still in registers.+// Since zm = 1 we could do the doubling with an operation count of+// 2 * S + M instead of 2 * S + 2 * M, but it doesn't seem worth+// the slight complication arising from a different linear combination.++ mov swap, #1+ stp x10, x11, [xm]+ stp x12, x13, [xm+16]+ stp swap, xzr, [zm]+ stp xzr, xzr, [zm+16]++ sub_twice4(d,xm,zm)+ add_twice4(s,xm,zm)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ mov x1, 0xdb42+ orr x1, x1, 0x10000+ cmadd_4(e,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++// The main loop over unmodified bits from i = 253, ..., i = 3 (inclusive).+// This is a classic Montgomery ladder, with the main coordinates only+// reduced mod 2 * p_25519, some intermediate results even more loosely.++ mov i, #253++Lcurve25519_x25519_alt_scalarloop:++// sm = xm + zm; sn = xn + zn; dm = xm - zm; dn = xn - zn++ sub_twice4(dm,xm,zm)+ add_twice4(sn,xn,zn)+ sub_twice4(dn,xn,zn)+ add_twice4(sm,xm,zm)++// ADDING: dmsn = dm * sn+// DOUBLING: mux d = xt - zt and s = xt + zt for appropriate choice of (xt,zt)++ mul_4(dmsn,sn,dm)++ lsr x0, i, #6+ ldr x2, [sp, x0, lsl #3] // Exploiting scalar = sp exactly+ lsr x2, x2, i+ and x2, x2, #1++ cmp swap, x2+ mov swap, x2++ mux_4(d,dm,dn)+ mux_4(s,sm,sn)++// ADDING: dnsm = sm * dn++ mul_4(dnsm,sm,dn)++// DOUBLING: d = (xt - zt)^2++ sqr_4(d,d)++// ADDING: dpro = (dmsn - dnsm)^2, spro = (dmsn + dnsm)^2+// DOUBLING: s = (xt + zt)^2++ sub_twice4(dpro,dmsn,dnsm)+ sqr_4(s,s)+ add_twice4(spro,dmsn,dnsm)+ sqr_4(dpro,dpro)++// DOUBLING: p = 4 * xt * zt = s - d++ sub_twice4(p,s,d)++// ADDING: xm' = (dmsn + dnsm)^2++ sqr_4(xm,spro)++// DOUBLING: e = 121666 * p + d++ mov x1, 0xdb42+ orr x1, x1, 0x10000+ cmadd_4(e,p,d)++// DOUBLING: xn' = (xt + zt)^2 * (xt - zt)^2 = s * d++ mul_4(xn,s,d)++// ADDING: zm' = x * (dmsn - dnsm)^2++ mul_4(zm,dpro,pointx)++// DOUBLING: zn' = (4 * xt * zt) * ((xt - zt)^2 + 121666 * (4 * xt * zt))+// = p * (d + 121666 * p)++ mul_4(zn,p,e)++// Loop down as far as 3 (inclusive)++ sub i, i, #1+ cmp i, #3+ bcs Lcurve25519_x25519_alt_scalarloop++// Multiplex directly into (xn,zn) then do three pure doubling steps;+// this accounts for the implicit zeroing of the three lowest bits+// of the scalar.++ cmp swap, xzr+ mux_4(xn,xm,xn)+ mux_4(zn,zm,zn)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ mov x1, 0xdb42+ orr x1, x1, 0x10000+ cmadd_4(e,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ mov x1, 0xdb42+ orr x1, x1, 0x10000+ cmadd_4(e,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ mov x1, 0xdb42+ orr x1, x1, 0x10000+ cmadd_4(e,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++// The projective result of the scalar multiplication is now (xn,zn).+// Prepare to call the modular inverse function to get zn' = 1/zn++ add x0, zn+ add x1, zn++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "arm/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 128 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, xn and zn.++ mov x20, x0+ mov x10, #0xffffffffffffffed+ mov x11, #0xffffffffffffffff+ stp x10, x11, [sp]+ mov x12, #0x7fffffffffffffff+ stp x11, x12, [sp, #16]+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x7, #0x13+ lsr x6, x5, #63+ madd x6, x7, x6, x7+ adds x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ orr x5, x5, #0x8000000000000000+ adcs x5, x5, xzr+ csel x6, x7, xzr, cc+ subs x2, x2, x6+ sbcs x3, x3, xzr+ sbcs x4, x4, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ stp x2, x3, [sp, #32]+ stp x4, x5, [sp, #48]+ stp xzr, xzr, [sp, #64]+ stp xzr, xzr, [sp, #80]+ mov x10, #0x2099+ movk x10, #0x7502, lsl #16+ movk x10, #0x9e23, lsl #32+ movk x10, #0xa0f9, lsl #48+ mov x11, #0x2595+ movk x11, #0x1d13, lsl #16+ movk x11, #0x8f3f, lsl #32+ movk x11, #0xa8c6, lsl #48+ mov x12, #0x5242+ movk x12, #0x5ac, lsl #16+ movk x12, #0x8938, lsl #32+ movk x12, #0x6c6c, lsl #48+ mov x13, #0x615+ movk x13, #0x4177, lsl #16+ movk x13, #0x8b2, lsl #32+ movk x13, #0x2765, lsl #48+ stp x10, x11, [sp, #96]+ stp x12, x13, [sp, #112]+ mov x21, #0xa+ mov x22, #0x1+ b Lcurve25519_x25519_alt_invmidloop+Lcurve25519_x25519_alt_invloop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #32]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #40]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #32]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #40]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ asr x3, x1, #63+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ asr x0, x1, #63+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ eor x1, x7, x16+ asr x5, x1, #63+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ asr x0, x1, #63+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #48]+ extr x2, x5, x2, #59+ str x2, [sp, #56]+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #96]+ adc x3, x3, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #104]+ adc x4, x4, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #112]+ adc x2, x2, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ add x6, x6, x3, asr #63+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x3, x6, x3+ ldr x6, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x3+ asr x3, x3, #63+ adcs x6, x6, x3+ adc x5, x5, x3+ stp x0, x1, [sp, #64]+ stp x6, x5, [sp, #80]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x6, x5, x2, #63+ ldp x0, x1, [sp, #96]+ add x6, x6, x5, asr #63+ mov x5, #0x13+ mul x4, x6, x5+ add x2, x2, x6, lsl #63+ smulh x5, x6, x5+ ldr x3, [sp, #112]+ adds x0, x0, x4+ adcs x1, x1, x5+ asr x5, x5, #63+ adcs x3, x3, x5+ adc x2, x2, x5+ stp x0, x1, [sp, #96]+ stp x3, x2, [sp, #112]+Lcurve25519_x25519_alt_invmidloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #32]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Lcurve25519_x25519_alt_invloop+ ldr x0, [sp]+ ldr x1, [sp, #32]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ tst x3, x3+ cinc x6, x6, pl+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x6, x6, x3+ ldr x2, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x6+ asr x6, x6, #63+ adcs x2, x2, x6+ adcs x5, x5, x6+ csel x3, x3, xzr, mi+ subs x0, x0, x3+ sbcs x1, x1, xzr+ sbcs x2, x2, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ mov x4, x20+ stp x0, x1, [x4]+ stp x2, x5, [x4, #16]++// Now the result is xn * (1/zn), fully reduced modulo p.+// Note that in the degenerate case zn = 0 (mod p_25519), the+// modular inverse code above will produce 1/zn = 0, giving+// the correct overall X25519 result of zero for the point at+// infinity.++ mul_p25519(resx,xn,zn)++// Restore stack and registers++ CFI_INC_SP(NSPACE)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/curve25519_x25519base.S view
@@ -0,0 +1,9591 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// The x25519 function for curve25519 on base element 9+// Input scalar[4]; output res[4]+//+// extern void curve25519_x25519base+// (uint64_t res[static 4],const uint64_t scalar[static 4]);+//+// Given a scalar n, returns the X coordinate of n * G where G = (9,...) is+// the standard generator. The scalar is first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748).+//+// Standard ARM ABI: X0 = res, X1 = scalar+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519base)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519base)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519base)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable home for the input result argument during the whole body++#define res x23++// Other variables that are only needed prior to the modular inverse.++#define tab x19++#define i x20++#define bias x21++#define bf x22+#define ix x22++// Pointer-offset pairs for result and temporaries on stack with some aliasing.++#define resx res, #(0*NUMSIZE)++#define scalar sp, #(0*NUMSIZE)++#define tabent sp, #(1*NUMSIZE)+#define ymx_2 sp, #(1*NUMSIZE)+#define xpy_2 sp, #(2*NUMSIZE)+#define kxy_2 sp, #(3*NUMSIZE)++#define acc sp, #(4*NUMSIZE)+#define x_1 sp, #(4*NUMSIZE)+#define y_1 sp, #(5*NUMSIZE)+#define z_1 sp, #(6*NUMSIZE)+#define w_1 sp, #(7*NUMSIZE)+#define x_3 sp, #(4*NUMSIZE)+#define y_3 sp, #(5*NUMSIZE)+#define z_3 sp, #(6*NUMSIZE)+#define w_3 sp, #(7*NUMSIZE)++#define tmpspace sp, #(8*NUMSIZE)+#define t0 sp, #(8*NUMSIZE)+#define t1 sp, #(9*NUMSIZE)+#define t2 sp, #(10*NUMSIZE)+#define t3 sp, #(11*NUMSIZE)+#define t4 sp, #(12*NUMSIZE)+#define t5 sp, #(13*NUMSIZE)++// Total size to reserve on the stack++#define NSPACE 14*NUMSIZE++// Macro wrapping up the basic field operation bignum_mul_p25519, only+// trivially different from a pure function call to that subroutine.++#define mul_p25519(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x5, x6, [P2] __LF \+ umull x7, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x8, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x7, x7, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x8, x8, x15 __LF \+ adds x7, x7, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x8, x8, x16 __LF \+ mul x9, x4, x6 __LF \+ umulh x10, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x9, x9, x8 __LF \+ adc x10, x10, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x8, x7, x9 __LF \+ adcs x9, x9, x10 __LF \+ adc x10, x10, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x8, x15, x8 __LF \+ eor x3, x3, x16 __LF \+ adcs x9, x3, x9 __LF \+ adc x10, x10, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x5, x6, [P2+16] __LF \+ umull x11, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x12, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x11, x11, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x12, x12, x15 __LF \+ adds x11, x11, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x12, x12, x16 __LF \+ mul x13, x4, x6 __LF \+ umulh x14, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x13, x13, x12 __LF \+ adc x14, x14, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x12, x11, x13 __LF \+ adcs x13, x13, x14 __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x12, x15, x12 __LF \+ eor x3, x3, x16 __LF \+ adcs x13, x3, x13 __LF \+ adc x14, x14, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x15, x16, [P1] __LF \+ subs x3, x3, x15 __LF \+ sbcs x4, x4, x16 __LF \+ csetm x16, cc __LF \+ ldp x15, x0, [P2] __LF \+ subs x5, x15, x5 __LF \+ sbcs x6, x0, x6 __LF \+ csetm x0, cc __LF \+ eor x3, x3, x16 __LF \+ subs x3, x3, x16 __LF \+ eor x4, x4, x16 __LF \+ sbc x4, x4, x16 __LF \+ eor x5, x5, x0 __LF \+ subs x5, x5, x0 __LF \+ eor x6, x6, x0 __LF \+ sbc x6, x6, x0 __LF \+ eor x16, x0, x16 __LF \+ adds x11, x11, x9 __LF \+ adcs x12, x12, x10 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ mul x2, x3, x5 __LF \+ umulh x0, x3, x5 __LF \+ mul x15, x4, x6 __LF \+ umulh x1, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x9, cc __LF \+ adds x15, x15, x0 __LF \+ adc x1, x1, xzr __LF \+ subs x6, x5, x6 __LF \+ cneg x6, x6, cc __LF \+ cinv x9, x9, cc __LF \+ mul x5, x4, x6 __LF \+ umulh x6, x4, x6 __LF \+ adds x0, x2, x15 __LF \+ adcs x15, x15, x1 __LF \+ adc x1, x1, xzr __LF \+ cmn x9, #0x1 __LF \+ eor x5, x5, x9 __LF \+ adcs x0, x5, x0 __LF \+ eor x6, x6, x9 __LF \+ adcs x15, x6, x15 __LF \+ adc x1, x1, x9 __LF \+ adds x9, x11, x7 __LF \+ adcs x10, x12, x8 __LF \+ adcs x11, x13, x11 __LF \+ adcs x12, x14, x12 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x2, x2, x16 __LF \+ adcs x9, x2, x9 __LF \+ eor x0, x0, x16 __LF \+ adcs x10, x0, x10 __LF \+ eor x15, x15, x16 __LF \+ adcs x11, x15, x11 __LF \+ eor x1, x1, x16 __LF \+ adcs x12, x1, x12 __LF \+ adcs x13, x13, x16 __LF \+ adc x14, x14, x16 __LF \+ mov x3, #0x26 __LF \+ umull x4, w11, w3 __LF \+ add x4, x4, w7, uxtw __LF \+ lsr x7, x7, #32 __LF \+ lsr x11, x11, #32 __LF \+ umaddl x11, w11, w3, x7 __LF \+ mov x7, x4 __LF \+ umull x4, w12, w3 __LF \+ add x4, x4, w8, uxtw __LF \+ lsr x8, x8, #32 __LF \+ lsr x12, x12, #32 __LF \+ umaddl x12, w12, w3, x8 __LF \+ mov x8, x4 __LF \+ umull x4, w13, w3 __LF \+ add x4, x4, w9, uxtw __LF \+ lsr x9, x9, #32 __LF \+ lsr x13, x13, #32 __LF \+ umaddl x13, w13, w3, x9 __LF \+ mov x9, x4 __LF \+ umull x4, w14, w3 __LF \+ add x4, x4, w10, uxtw __LF \+ lsr x10, x10, #32 __LF \+ lsr x14, x14, #32 __LF \+ umaddl x14, w14, w3, x10 __LF \+ mov x10, x4 __LF \+ lsr x0, x14, #31 __LF \+ mov x5, #0x13 __LF \+ umaddl x5, w5, w0, x5 __LF \+ add x7, x7, x5 __LF \+ adds x7, x7, x11, lsl #32 __LF \+ extr x3, x12, x11, #32 __LF \+ adcs x8, x8, x3 __LF \+ extr x3, x13, x12, #32 __LF \+ adcs x9, x9, x3 __LF \+ extr x3, x14, x13, #32 __LF \+ lsl x5, x0, #63 __LF \+ eor x10, x10, x5 __LF \+ adc x10, x10, x3 __LF \+ mov x3, #0x13 __LF \+ tst x10, #0x8000000000000000 __LF \+ csel x3, x3, xzr, pl __LF \+ subs x7, x7, x3 __LF \+ sbcs x8, x8, xzr __LF \+ sbcs x9, x9, xzr __LF \+ sbc x10, x10, xzr __LF \+ and x10, x10, #0x7fffffffffffffff __LF \+ stp x7, x8, [P0] __LF \+ stp x9, x10, [P0+16]++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x5, x6, [P2] __LF \+ umull x7, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x8, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x7, x7, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x8, x8, x15 __LF \+ adds x7, x7, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x8, x8, x16 __LF \+ mul x9, x4, x6 __LF \+ umulh x10, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x9, x9, x8 __LF \+ adc x10, x10, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x8, x7, x9 __LF \+ adcs x9, x9, x10 __LF \+ adc x10, x10, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x8, x15, x8 __LF \+ eor x3, x3, x16 __LF \+ adcs x9, x3, x9 __LF \+ adc x10, x10, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x5, x6, [P2+16] __LF \+ umull x11, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x12, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x11, x11, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x12, x12, x15 __LF \+ adds x11, x11, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x12, x12, x16 __LF \+ mul x13, x4, x6 __LF \+ umulh x14, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x13, x13, x12 __LF \+ adc x14, x14, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x12, x11, x13 __LF \+ adcs x13, x13, x14 __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x12, x15, x12 __LF \+ eor x3, x3, x16 __LF \+ adcs x13, x3, x13 __LF \+ adc x14, x14, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x15, x16, [P1] __LF \+ subs x3, x3, x15 __LF \+ sbcs x4, x4, x16 __LF \+ csetm x16, cc __LF \+ ldp x15, x0, [P2] __LF \+ subs x5, x15, x5 __LF \+ sbcs x6, x0, x6 __LF \+ csetm x0, cc __LF \+ eor x3, x3, x16 __LF \+ subs x3, x3, x16 __LF \+ eor x4, x4, x16 __LF \+ sbc x4, x4, x16 __LF \+ eor x5, x5, x0 __LF \+ subs x5, x5, x0 __LF \+ eor x6, x6, x0 __LF \+ sbc x6, x6, x0 __LF \+ eor x16, x0, x16 __LF \+ adds x11, x11, x9 __LF \+ adcs x12, x12, x10 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ mul x2, x3, x5 __LF \+ umulh x0, x3, x5 __LF \+ mul x15, x4, x6 __LF \+ umulh x1, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x9, cc __LF \+ adds x15, x15, x0 __LF \+ adc x1, x1, xzr __LF \+ subs x6, x5, x6 __LF \+ cneg x6, x6, cc __LF \+ cinv x9, x9, cc __LF \+ mul x5, x4, x6 __LF \+ umulh x6, x4, x6 __LF \+ adds x0, x2, x15 __LF \+ adcs x15, x15, x1 __LF \+ adc x1, x1, xzr __LF \+ cmn x9, #0x1 __LF \+ eor x5, x5, x9 __LF \+ adcs x0, x5, x0 __LF \+ eor x6, x6, x9 __LF \+ adcs x15, x6, x15 __LF \+ adc x1, x1, x9 __LF \+ adds x9, x11, x7 __LF \+ adcs x10, x12, x8 __LF \+ adcs x11, x13, x11 __LF \+ adcs x12, x14, x12 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x2, x2, x16 __LF \+ adcs x9, x2, x9 __LF \+ eor x0, x0, x16 __LF \+ adcs x10, x0, x10 __LF \+ eor x15, x15, x16 __LF \+ adcs x11, x15, x11 __LF \+ eor x1, x1, x16 __LF \+ adcs x12, x1, x12 __LF \+ adcs x13, x13, x16 __LF \+ adc x14, x14, x16 __LF \+ mov x3, #0x26 __LF \+ umull x4, w11, w3 __LF \+ add x4, x4, w7, uxtw __LF \+ lsr x7, x7, #32 __LF \+ lsr x11, x11, #32 __LF \+ umaddl x11, w11, w3, x7 __LF \+ mov x7, x4 __LF \+ umull x4, w12, w3 __LF \+ add x4, x4, w8, uxtw __LF \+ lsr x8, x8, #32 __LF \+ lsr x12, x12, #32 __LF \+ umaddl x12, w12, w3, x8 __LF \+ mov x8, x4 __LF \+ umull x4, w13, w3 __LF \+ add x4, x4, w9, uxtw __LF \+ lsr x9, x9, #32 __LF \+ lsr x13, x13, #32 __LF \+ umaddl x13, w13, w3, x9 __LF \+ mov x9, x4 __LF \+ umull x4, w14, w3 __LF \+ add x4, x4, w10, uxtw __LF \+ lsr x10, x10, #32 __LF \+ lsr x14, x14, #32 __LF \+ umaddl x14, w14, w3, x10 __LF \+ mov x10, x4 __LF \+ lsr x0, x14, #31 __LF \+ mov x5, #0x13 __LF \+ umull x5, w5, w0 __LF \+ add x7, x7, x5 __LF \+ adds x7, x7, x11, lsl #32 __LF \+ extr x3, x12, x11, #32 __LF \+ adcs x8, x8, x3 __LF \+ extr x3, x13, x12, #32 __LF \+ adcs x9, x9, x3 __LF \+ extr x3, x14, x13, #32 __LF \+ lsl x5, x0, #63 __LF \+ eor x10, x10, x5 __LF \+ adc x10, x10, x3 __LF \+ stp x7, x8, [P0] __LF \+ stp x9, x10, [P0+16]++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ mov x4, #38 __LF \+ csel x3, x4, xzr, lo __LF \+ subs x5, x5, x3 __LF \+ sbcs x6, x6, xzr __LF \+ sbcs x7, x7, xzr __LF \+ sbc x8, x8, xzr __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ adds x3, x3, x7 __LF \+ adcs x4, x4, x8 __LF \+ ldp x5, x6, [P1+16] __LF \+ ldp x7, x8, [P2+16] __LF \+ adcs x5, x5, x7 __LF \+ adcs x6, x6, x8 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++#define double_twice4(P0,P1) \+ ldp x3, x4, [P1] __LF \+ adds x3, x3, x3 __LF \+ adcs x4, x4, x4 __LF \+ ldp x5, x6, [P1+16] __LF \+ adcs x5, x5, x5 __LF \+ adcs x6, x6, x6 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++S2N_BN_SYMBOL(curve25519_x25519base):+ CFI_START++// Save regs and make room for temporaries++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(NSPACE)++// Move the output pointer to a stable place++ mov res, x0++// Copy the input scalar to its local variable while mangling it.+// In principle the mangling is into 01xxx...xxx000, but actually+// we only clear the top two bits so 00xxx...xxxxxx. The additional+// 2^254 * G is taken care of by the starting value for the addition+// chain below, while we never look at the three low bits at all.++ ldp x10, x11, [x1]+ stp x10, x11, [scalar]+ ldp x12, x13, [x1, #16]+ bic x13, x13, #0xc000000000000000+ stp x12, x13, [scalar+16]++// The main part of the computation is on the edwards25519 curve in+// extended-projective coordinates (X,Y,Z,T), representing a point+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// Only at the very end do we translate back to curve25519. So G+// below means the generator within edwards25519 corresponding to+// (9,...) for curve25519, via the standard isomorphism.+//+// Initialize accumulator "acc" to either (2^254 + 8) * G or just 2^254 * G+// depending on bit 3 of the scalar, the only nonzero bit of the bottom 4.+// Thus, we have effectively dealt with bits 0, 1, 2, 3, 254 and 255.++ ldr x0, [scalar]+ ands xzr, x0, #8++#if defined(__ELF__)+ adrp tab, S2N_BN_SYMBOL(curve25519_x25519base_constant)+ add tab, tab, :lo12:S2N_BN_SYMBOL(curve25519_x25519base_constant)+#else+ adrp tab, S2N_BN_SYMBOL(curve25519_x25519base_constant)@PAGE+ add tab, tab, S2N_BN_SYMBOL(curve25519_x25519base_constant)@PAGEOFF+#endif++ ldp x0, x1, [tab]+ ldp x2, x3, [tab, #96]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc]++ ldp x0, x1, [tab, #1*16]+ ldp x2, x3, [tab, #96+1*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+1*16]++ ldp x0, x1, [tab, #2*16]+ ldp x2, x3, [tab, #96+2*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+2*16]++ ldp x0, x1, [tab, #3*16]+ ldp x2, x3, [tab, #96+3*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+3*16]++ mov x0, #1+ stp x0, xzr, [acc+4*16]+ stp xzr, xzr, [acc+5*16]++ ldp x0, x1, [tab, #4*16]+ ldp x2, x3, [tab, #96+4*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+6*16]++ ldp x0, x1, [tab, #5*16]+ ldp x2, x3, [tab, #96+5*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+7*16]++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 4 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * G at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * G = (16 * (h + 1) - (16 - l)) * G is used+// when l >= 9. Note that we can't have any bias left over at the+// end because of the clearing of bit 255 of the scalar, meaning the+// l >= 9 case cannot arise on the last iteration.++ mov i, 4+ add tab, tab, #192+ mov bias, xzr++// Start of the main loop, repeated 63 times for i = 4, 8, ..., 252++Lcurve25519_x25519base_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ lsr x0, i, #6+ ldr x2, [sp, x0, lsl #3] // Exploiting scalar = sp exactly+ lsr x2, x2, i+ and x2, x2, #15+ add bf, x2, bias++ cmp bf, 9+ cset bias, cs++ mov x0, 16+ sub x0, x0, bf+ cmp bias, xzr+ csel ix, x0, bf, ne++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ mov x0, #1+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, #1+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr++ cmp ix, #1+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #2+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #3+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #4+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #5+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #6+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #7+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #8+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++// We now have the triple from the table in registers as follows+//+// [x3;x2;x1;x0] = y - x+// [x7;x6;x5;x4] = x + y+// [x11;x10;x9;x8] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmp bias, #0++ csel x12, x0, x4, eq+ csel x13, x1, x5, eq+ csel x14, x2, x6, eq+ csel x15, x3, x7, eq+ stp x12, x13, [tabent]+ stp x14, x15, [tabent+16]++ csel x12, x0, x4, ne+ csel x13, x1, x5, ne+ csel x14, x2, x6, ne+ csel x15, x3, x7, ne+ stp x12, x13, [tabent+32]+ stp x14, x15, [tabent+48]++ mov x0, #-19+ subs x0, x0, x8+ mov x2, #-1+ sbcs x1, x2, x9+ sbcs x2, x2, x10+ mov x3, #0x7FFFFFFFFFFFFFFF+ sbc x3, x3, x11++ cmp ix, xzr+ ccmp bias, xzr, #4, ne++ csel x0, x0, x8, ne+ csel x1, x1, x9, ne+ stp x0, x1, [tabent+64]+ csel x2, x2, x10, ne+ csel x3, x3, x11, ne+ stp x2, x3, [tabent+80]++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ add i, i, 4+ cmp i, 256+ bcc Lcurve25519_x25519base_scalarloop++// Now we need to translate from Edwards curve edwards25519 back+// to the Montgomery form curve25519. The mapping in the affine+// representations is+//+// (x,y) |-> ((1 + y) / (1 - y), c * (1 + y) / ((1 - y) * x))+//+// For x25519, we only need the x coordinate, and we compute this as+//+// (1 + y) / (1 - y) = (x + x * y) / (x - x * y)+// = (X/Z + T/Z) / (X/Z - T/Z)+// = (X + T) / (X - T)+// = (X + T) * inverse(X - T)+//+// We could equally well use (Z + Y) / (Z - Y), but the above has the+// same cost, and it more explicitly forces zero output whenever X = 0,+// regardless of how the modular inverse behaves on zero inputs. In+// the present setting (base point 9, mangled scalar) that doesn't+// really matter anyway since X = 0 never arises, but it seems a+// little bit tidier. Note that both Edwards point (0,1) which maps to+// the Montgomery point at infinity, and Edwards (0,-1) which maps to+// Montgomery (0,0) [this is the 2-torsion point] are both by definition+// mapped to 0 by the X coordinate mapping used to define curve25519.+//+// First the addition and subtraction:++ add_twice4(t1,x_3,w_3)+ sub_twice4(t2,x_3,w_3)++// Prepare to call the modular inverse function to get t0 = 1/t2+// Note that this works for the weakly normalized z_3 equally well.+// The non-coprime case z_3 == 0 (mod p_25519) cannot arise anyway.++ add x0, t0+ add x1, t2++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "arm/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 128 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, t0, t1, t2.++ mov x20, x0+ mov x10, #0xffffffffffffffed+ mov x11, #0xffffffffffffffff+ stp x10, x11, [sp]+ mov x12, #0x7fffffffffffffff+ stp x11, x12, [sp, #16]+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x7, #0x13+ lsr x6, x5, #63+ madd x6, x7, x6, x7+ adds x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ orr x5, x5, #0x8000000000000000+ adcs x5, x5, xzr+ csel x6, x7, xzr, cc+ subs x2, x2, x6+ sbcs x3, x3, xzr+ sbcs x4, x4, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ stp x2, x3, [sp, #32]+ stp x4, x5, [sp, #48]+ stp xzr, xzr, [sp, #64]+ stp xzr, xzr, [sp, #80]+ mov x10, #0x2099+ movk x10, #0x7502, lsl #16+ movk x10, #0x9e23, lsl #32+ movk x10, #0xa0f9, lsl #48+ mov x11, #0x2595+ movk x11, #0x1d13, lsl #16+ movk x11, #0x8f3f, lsl #32+ movk x11, #0xa8c6, lsl #48+ mov x12, #0x5242+ movk x12, #0x5ac, lsl #16+ movk x12, #0x8938, lsl #32+ movk x12, #0x6c6c, lsl #48+ mov x13, #0x615+ movk x13, #0x4177, lsl #16+ movk x13, #0x8b2, lsl #32+ movk x13, #0x2765, lsl #48+ stp x10, x11, [sp, #96]+ stp x12, x13, [sp, #112]+ mov x21, #0xa+ mov x22, #0x1+ b Lcurve25519_x25519base_invmidloop+Lcurve25519_x25519base_invloop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #32]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #40]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #32]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #40]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ asr x3, x1, #63+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ asr x0, x1, #63+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ eor x1, x7, x16+ asr x5, x1, #63+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ asr x0, x1, #63+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #48]+ extr x2, x5, x2, #59+ str x2, [sp, #56]+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #96]+ adc x3, x3, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #104]+ adc x4, x4, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #112]+ adc x2, x2, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ add x6, x6, x3, asr #63+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x3, x6, x3+ ldr x6, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x3+ asr x3, x3, #63+ adcs x6, x6, x3+ adc x5, x5, x3+ stp x0, x1, [sp, #64]+ stp x6, x5, [sp, #80]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x6, x5, x2, #63+ ldp x0, x1, [sp, #96]+ add x6, x6, x5, asr #63+ mov x5, #0x13+ mul x4, x6, x5+ add x2, x2, x6, lsl #63+ smulh x5, x6, x5+ ldr x3, [sp, #112]+ adds x0, x0, x4+ adcs x1, x1, x5+ asr x5, x5, #63+ adcs x3, x3, x5+ adc x2, x2, x5+ stp x0, x1, [sp, #96]+ stp x3, x2, [sp, #112]+Lcurve25519_x25519base_invmidloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #32]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Lcurve25519_x25519base_invloop+ ldr x0, [sp]+ ldr x1, [sp, #32]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ tst x3, x3+ cinc x6, x6, pl+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x6, x6, x3+ ldr x2, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x6+ asr x6, x6, #63+ adcs x2, x2, x6+ adcs x5, x5, x6+ csel x3, x3, xzr, mi+ subs x0, x0, x3+ sbcs x1, x1, xzr+ sbcs x2, x2, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ mov x4, x20+ stp x0, x1, [x4]+ stp x2, x5, [x4, #16]++// The final result is (X + T) / (X - T)+// This is the only operation in the whole computation that+// fully reduces modulo p_25519 since now we want the canonical+// answer as output.++ mul_p25519(resx,t1,t0)++// Restore stack and registers++ CFI_INC_SP(NSPACE)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519base)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(curve25519_x25519base_constant), %object+.size S2N_BN_SYMBOL(curve25519_x25519base_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(curve25519_x25519base_constant):++// 2^254 * G and (2^254 + 8) * G in extended-projective coordinates+// but with Z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x251037f7cf4e861d+ .quad 0x10ede0fb19fb128f+ .quad 0x96c033b175f5e2c8+ .quad 0x055f070d6c15fb0d+ .quad 0x7c52af2c97473e69+ .quad 0x022f82391bad8378+ .quad 0x9991e1b02adb476f+ .quad 0x511144a03a99b855+ .quad 0x5fafc3b88ff2e4ae+ .quad 0x855e4ff0de1230ff+ .quad 0x72e302a348492870+ .quad 0x1253c19e53dbe1bc++ .quad 0x331d086e0d9abcaa+ .quad 0x1e23c96d311a10c9+ .quad 0x96d0f95e58c13478+ .quad 0x2f72f7384fcfcc59+ .quad 0x39a6cd1cfd7d87c9+ .quad 0x9867a0abd8ae153a+ .quad 0xa49d2a5f35986745+ .quad 0x57012940cdfe82e1+ .quad 0x5046a6532ec5544a+ .quad 0x6d674004739ff6c9+ .quad 0x9bbaa44b234a70e3+ .quad 0x5e6d8901138cf386++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^4 * 1 * G++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * G++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * G++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * G++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * G++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * G++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * G++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * G++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * G++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * G++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * G++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * G++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * G++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * G++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * G++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * G++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * G++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * G++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * G++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * G++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * G++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * G++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * G++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * G++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * G++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * G++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * G++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * G++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * G++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * G++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * G++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * G++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * G++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * G++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * G++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * G++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * G++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * G++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * G++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * G++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * G++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * G++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * G++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * G++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * G++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * G++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * G++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * G++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * G++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * G++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * G++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * G++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * G++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * G++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * G++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * G++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * G++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * G++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * G++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * G++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * G++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * G++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * G++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * G++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * G++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * G++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * G++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * G++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * G++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * G++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * G++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * G++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * G++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * G++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * G++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * G++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * G++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * G++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * G++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * G++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * G++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * G++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * G++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * G++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * G++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * G++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * G++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * G++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * G++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * G++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * G++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * G++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * G++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * G++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * G++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * G++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * G++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * G++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * G++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * G++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * G++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * G++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * G++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * G++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * G++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * G++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * G++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * G++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * G++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * G++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * G++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * G++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * G++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * G++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * G++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * G++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * G++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * G++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * G++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * G++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * G++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * G++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * G++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * G++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * G++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * G++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * G++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * G++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * G++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * G++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * G++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * G++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * G++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * G++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * G++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * G++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * G++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * G++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * G++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * G++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * G++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * G++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * G++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * G++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * G++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * G++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * G++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * G++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * G++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * G++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * G++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * G++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * G++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * G++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * G++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * G++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * G++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * G++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * G++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * G++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * G++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * G++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * G++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * G++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * G++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * G++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * G++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * G++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * G++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * G++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * G++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * G++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * G++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * G++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * G++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * G++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * G++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * G++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * G++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * G++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * G++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * G++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * G++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * G++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * G++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * G++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * G++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * G++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * G++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * G++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * G++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * G++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * G++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * G++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * G++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * G++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * G++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * G++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * G++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * G++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * G++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * G++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * G++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * G++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * G++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * G++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * G++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * G++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * G++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * G++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * G++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * G++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * G++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * G++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * G++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * G++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * G++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * G++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * G++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * G++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * G++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * G++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * G++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * G++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * G++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * G++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * G++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * G++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * G++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * G++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * G++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * G++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * G++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * G++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * G++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * G++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * G++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * G++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * G++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * G++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * G++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * G++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * G++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * G++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * G++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * G++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * G++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * G++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * G++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * G++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * G++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * G++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * G++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * G++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * G++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * G++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * G++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * G++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * G++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * G++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * G++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * G++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * G++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * G++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * G++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * G++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * G++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * G++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * G++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * G++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * G++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * G++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * G++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * G++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * G++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * G++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * G++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * G++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * G++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * G++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * G++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * G++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * G++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * G++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * G++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * G++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * G++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * G++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * G++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * G++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * G++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * G++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * G++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * G++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * G++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * G++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * G++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * G++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * G++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * G++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * G++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * G++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * G++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * G++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * G++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * G++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * G++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * G++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * G++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * G++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * G++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * G++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * G++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * G++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * G++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * G++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * G++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * G++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * G++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * G++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * G++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * G++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * G++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * G++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * G++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * G++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * G++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * G++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * G++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * G++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * G++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * G++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * G++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * G++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * G++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * G++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * G++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * G++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * G++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * G++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * G++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * G++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * G++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * G++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * G++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * G++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * G++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * G++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * G++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * G++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * G++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * G++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * G++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * G++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * G++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * G++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * G++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * G++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * G++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * G++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * G++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * G++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * G++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * G++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * G++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * G++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * G++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * G++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * G++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * G++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * G++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * G++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * G++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * G++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * G++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * G++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * G++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * G++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * G++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * G++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * G++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * G++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * G++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * G++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * G++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * G++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * G++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * G++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * G++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * G++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * G++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * G++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * G++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * G++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * G++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * G++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * G++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * G++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * G++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * G++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * G++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * G++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * G++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * G++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * G++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * G++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * G++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * G++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * G++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * G++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * G++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * G++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * G++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * G++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * G++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * G++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * G++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * G++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * G++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * G++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * G++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * G++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * G++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * G++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * G++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * G++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * G++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * G++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * G++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * G++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * G++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * G++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * G++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * G++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * G++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * G++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * G++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * G++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * G++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * G++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * G++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * G++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * G++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * G++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * G++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * G++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * G++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * G++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * G++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * G++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * G++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * G++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * G++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * G++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * G++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * G++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * G++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * G++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * G++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * G++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * G++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * G++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * G++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * G++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * G++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * G++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * G++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * G++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * G++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * G++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * G++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * G++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * G++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * G++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * G++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * G++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * G++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * G++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * G++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * G++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * G++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * G++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * G++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * G++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * G++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * G++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * G++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * G++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * G++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * G++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * G++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * G++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * G++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * G++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * G++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * G++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f++ // 2^252 * 1 * G++ .quad 0xb1507ca1ab1c6eb9+ .quad 0xbd448f3e16b687b3+ .quad 0x3455fb7f2c7a91ab+ .quad 0x7579229e2f2adec1+ .quad 0x6ab5dcb85b1c16b7+ .quad 0x94c0fce83c7b27a5+ .quad 0xa4b11c1a735517be+ .quad 0x499238d0ba0eafaa+ .quad 0xecf46e527aba8b57+ .quad 0x15a08c478bd1647b+ .quad 0x7af1c6a65f706fef+ .quad 0x6345fa78f03a30d5++ // 2^252 * 2 * G++ .quad 0xdf02f95f1015e7a1+ .quad 0x790ec41da9b40263+ .quad 0x4d3a0ea133ea1107+ .quad 0x54f70be7e33af8c9+ .quad 0x93d3cbe9bdd8f0a4+ .quad 0xdb152c1bfd177302+ .quad 0x7dbddc6d7f17a875+ .quad 0x3e1a71cc8f426efe+ .quad 0xc83ca3e390babd62+ .quad 0x80ede3670291c833+ .quad 0xc88038ccd37900c4+ .quad 0x2c5fc0231ec31fa1++ // 2^252 * 3 * G++ .quad 0xfeba911717038b4f+ .quad 0xe5123721c9deef81+ .quad 0x1c97e4e75d0d8834+ .quad 0x68afae7a23dc3bc6+ .quad 0xc422e4d102456e65+ .quad 0x87414ac1cad47b91+ .quad 0x1592e2bba2b6ffdd+ .quad 0x75d9d2bff5c2100f+ .quad 0x5bd9b4763626e81c+ .quad 0x89966936bca02edd+ .quad 0x0a41193d61f077b3+ .quad 0x3097a24200ce5471++ // 2^252 * 4 * G++ .quad 0x57427734c7f8b84c+ .quad 0xf141a13e01b270e9+ .quad 0x02d1adfeb4e564a6+ .quad 0x4bb23d92ce83bd48+ .quad 0xa162e7246695c486+ .quad 0x131d633435a89607+ .quad 0x30521561a0d12a37+ .quad 0x56704bada6afb363+ .quad 0xaf6c4aa752f912b9+ .quad 0x5e665f6cd86770c8+ .quad 0x4c35ac83a3c8cd58+ .quad 0x2b7a29c010a58a7e++ // 2^252 * 5 * G++ .quad 0xc4007f77d0c1cec3+ .quad 0x8d1020b6bac492f8+ .quad 0x32ec29d57e69daaf+ .quad 0x599408759d95fce0+ .quad 0x33810a23bf00086e+ .quad 0xafce925ee736ff7c+ .quad 0x3d60e670e24922d4+ .quad 0x11ce9e714f96061b+ .quad 0x219ef713d815bac1+ .quad 0xf141465d485be25c+ .quad 0x6d5447cc4e513c51+ .quad 0x174926be5ef44393++ // 2^252 * 6 * G++ .quad 0xb5deb2f9fc5bd5bb+ .quad 0x92daa72ae1d810e1+ .quad 0xafc4cfdcb72a1c59+ .quad 0x497d78813fc22a24+ .quad 0x3ef5d41593ea022e+ .quad 0x5cbcc1a20ed0eed6+ .quad 0x8fd24ecf07382c8c+ .quad 0x6fa42ead06d8e1ad+ .quad 0xe276824a1f73371f+ .quad 0x7f7cf01c4f5b6736+ .quad 0x7e201fe304fa46e7+ .quad 0x785a36a357808c96++ // 2^252 * 7 * G++ .quad 0x825fbdfd63014d2b+ .quad 0xc852369c6ca7578b+ .quad 0x5b2fcd285c0b5df0+ .quad 0x12ab214c58048c8f+ .quad 0x070442985d517bc3+ .quad 0x6acd56c7ae653678+ .quad 0x00a27983985a7763+ .quad 0x5167effae512662b+ .quad 0xbd4ea9e10f53c4b6+ .quad 0x1673dc5f8ac91a14+ .quad 0xa8f81a4e2acc1aba+ .quad 0x33a92a7924332a25++ // 2^252 * 8 * G++ .quad 0x9dd1f49927996c02+ .quad 0x0cb3b058e04d1752+ .quad 0x1f7e88967fd02c3e+ .quad 0x2f964268cb8b3eb1+ .quad 0x7ba95ba0218f2ada+ .quad 0xcff42287330fb9ca+ .quad 0xdada496d56c6d907+ .quad 0x5380c296f4beee54+ .quad 0x9d4f270466898d0a+ .quad 0x3d0987990aff3f7a+ .quad 0xd09ef36267daba45+ .quad 0x7761455e7b1c669c
+ cbits/s2n/arm/curve25519_x25519base_alt.S view
@@ -0,0 +1,9434 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// The x25519 function for curve25519 on base element 9+// Input scalar[4]; output res[4]+//+// extern void curve25519_x25519base_alt+// (uint64_t res[static 4],const uint64_t scalar[static 4]);+//+// Given a scalar n, returns the X coordinate of n * G where G = (9,...) is+// the standard generator. The scalar is first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748).+//+// Standard ARM ABI: X0 = res, X1 = scalar+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519base_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519base_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519base_alt)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable home for the input result argument during the whole body++#define res x23++// Other variables that are only needed prior to the modular inverse.++#define tab x19++#define i x20++#define bias x21++#define bf x22+#define ix x22++// Pointer-offset pairs for result and temporaries on stack with some aliasing.++#define resx res, #(0*NUMSIZE)++#define scalar sp, #(0*NUMSIZE)++#define tabent sp, #(1*NUMSIZE)+#define ymx_2 sp, #(1*NUMSIZE)+#define xpy_2 sp, #(2*NUMSIZE)+#define kxy_2 sp, #(3*NUMSIZE)++#define acc sp, #(4*NUMSIZE)+#define x_1 sp, #(4*NUMSIZE)+#define y_1 sp, #(5*NUMSIZE)+#define z_1 sp, #(6*NUMSIZE)+#define w_1 sp, #(7*NUMSIZE)+#define x_3 sp, #(4*NUMSIZE)+#define y_3 sp, #(5*NUMSIZE)+#define z_3 sp, #(6*NUMSIZE)+#define w_3 sp, #(7*NUMSIZE)++#define tmpspace sp, #(8*NUMSIZE)+#define t0 sp, #(8*NUMSIZE)+#define t1 sp, #(9*NUMSIZE)+#define t2 sp, #(10*NUMSIZE)+#define t3 sp, #(11*NUMSIZE)+#define t4 sp, #(12*NUMSIZE)+#define t5 sp, #(13*NUMSIZE)++// Total size to reserve on the stack++#define NSPACE 14*NUMSIZE++// Macro wrapping up the basic field operation bignum_mul_p25519_alt, only+// trivially different from a pure function call to that subroutine.++#define mul_p25519(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x15, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x16, x3, x10 __LF \+ adcs x15, x15, x11 __LF \+ adc x16, x16, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x16, x16, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x15, x15, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x16, x16, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x15, x15, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x16, x16, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x15, x15, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x16, x16, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ mov x7, #0x26 __LF \+ mul x11, x7, x16 __LF \+ umulh x9, x7, x16 __LF \+ adds x12, x12, x11 __LF \+ mul x11, x7, x3 __LF \+ umulh x3, x7, x3 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x7, x4 __LF \+ umulh x4, x7, x4 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x7, x5 __LF \+ umulh x5, x7, x5 __LF \+ adcs x15, x15, x11 __LF \+ cset x16, cs __LF \+ adds x15, x15, x4 __LF \+ adc x16, x16, x5 __LF \+ cmn x15, x15 __LF \+ orr x15, x15, #0x8000000000000000 __LF \+ adc x8, x16, x16 __LF \+ mov x7, #0x13 __LF \+ madd x11, x7, x8, x7 __LF \+ adds x12, x12, x11 __LF \+ adcs x13, x13, x9 __LF \+ adcs x14, x14, x3 __LF \+ adcs x15, x15, xzr __LF \+ csel x7, x7, xzr, cc __LF \+ subs x12, x12, x7 __LF \+ sbcs x13, x13, xzr __LF \+ sbcs x14, x14, xzr __LF \+ sbc x15, x15, xzr __LF \+ and x15, x15, #0x7fffffffffffffff __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x15, [P0+16]++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x15, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x16, x3, x10 __LF \+ adcs x15, x15, x11 __LF \+ adc x16, x16, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x16, x16, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x15, x15, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x16, x16, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x15, x15, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x16, x16, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x15, x15, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x16, x16, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ mov x7, #0x26 __LF \+ mul x11, x7, x16 __LF \+ umulh x9, x7, x16 __LF \+ adds x12, x12, x11 __LF \+ mul x11, x7, x3 __LF \+ umulh x3, x7, x3 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x7, x4 __LF \+ umulh x4, x7, x4 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x7, x5 __LF \+ umulh x5, x7, x5 __LF \+ adcs x15, x15, x11 __LF \+ cset x16, cs __LF \+ adds x15, x15, x4 __LF \+ adc x16, x16, x5 __LF \+ cmn x15, x15 __LF \+ bic x15, x15, #0x8000000000000000 __LF \+ adc x8, x16, x16 __LF \+ mov x7, #0x13 __LF \+ mul x11, x7, x8 __LF \+ adds x12, x12, x11 __LF \+ adcs x13, x13, x9 __LF \+ adcs x14, x14, x3 __LF \+ adc x15, x15, xzr __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x15, [P0+16]++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ mov x4, #38 __LF \+ csel x3, x4, xzr, lo __LF \+ subs x5, x5, x3 __LF \+ sbcs x6, x6, xzr __LF \+ sbcs x7, x7, xzr __LF \+ sbc x8, x8, xzr __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ adds x3, x3, x7 __LF \+ adcs x4, x4, x8 __LF \+ ldp x5, x6, [P1+16] __LF \+ ldp x7, x8, [P2+16] __LF \+ adcs x5, x5, x7 __LF \+ adcs x6, x6, x8 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++#define double_twice4(P0,P1) \+ ldp x3, x4, [P1] __LF \+ adds x3, x3, x3 __LF \+ adcs x4, x4, x4 __LF \+ ldp x5, x6, [P1+16] __LF \+ adcs x5, x5, x5 __LF \+ adcs x6, x6, x6 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++S2N_BN_SYMBOL(curve25519_x25519base_alt):+ CFI_START++// Save regs and make room for temporaries++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(NSPACE)++// Move the output pointer to a stable place++ mov res, x0++// Copy the input scalar to its local variable while mangling it.+// In principle the mangling is into 01xxx...xxx000, but actually+// we only clear the top two bits so 00xxx...xxxxxx. The additional+// 2^254 * G is taken care of by the starting value for the addition+// chain below, while we never look at the three low bits at all.++ ldp x10, x11, [x1]+ stp x10, x11, [scalar]+ ldp x12, x13, [x1, #16]+ bic x13, x13, #0xc000000000000000+ stp x12, x13, [scalar+16]++// The main part of the computation is on the edwards25519 curve in+// extended-projective coordinates (X,Y,Z,T), representing a point+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// Only at the very end do we translate back to curve25519. So G+// below means the generator within edwards25519 corresponding to+// (9,...) for curve25519, via the standard isomorphism.+//+// Initialize accumulator "acc" to either (2^254 + 8) * G or just 2^254 * G+// depending on bit 3 of the scalar, the only nonzero bit of the bottom 4.+// Thus, we have effectively dealt with bits 0, 1, 2, 3, 254 and 255.++ ldr x0, [scalar]+ ands xzr, x0, #8++#if defined(__ELF__)+ adrp tab, S2N_BN_SYMBOL(curve25519_x25519base_alt_constant)+ add tab, tab, :lo12:S2N_BN_SYMBOL(curve25519_x25519base_alt_constant)+#else+ adrp tab, S2N_BN_SYMBOL(curve25519_x25519base_alt_constant)@PAGE+ add tab, tab, S2N_BN_SYMBOL(curve25519_x25519base_alt_constant)@PAGEOFF+#endif++ ldp x0, x1, [tab]+ ldp x2, x3, [tab, #96]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc]++ ldp x0, x1, [tab, #1*16]+ ldp x2, x3, [tab, #96+1*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+1*16]++ ldp x0, x1, [tab, #2*16]+ ldp x2, x3, [tab, #96+2*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+2*16]++ ldp x0, x1, [tab, #3*16]+ ldp x2, x3, [tab, #96+3*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+3*16]++ mov x0, #1+ stp x0, xzr, [acc+4*16]+ stp xzr, xzr, [acc+5*16]++ ldp x0, x1, [tab, #4*16]+ ldp x2, x3, [tab, #96+4*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+6*16]++ ldp x0, x1, [tab, #5*16]+ ldp x2, x3, [tab, #96+5*16]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+7*16]++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 4 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * G at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * G = (16 * (h + 1) - (16 - l)) * G is used+// when l >= 9. Note that we can't have any bias left over at the+// end because of the clearing of bit 255 of the scalar, meaning the+// l >= 9 case cannot arise on the last iteration.++ mov i, 4+ add tab, tab, #192+ mov bias, xzr++// Start of the main loop, repeated 63 times for i = 4, 8, ..., 252++Lcurve25519_x25519base_alt_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ lsr x0, i, #6+ ldr x2, [sp, x0, lsl #3] // Exploiting scalar = sp exactly+ lsr x2, x2, i+ and x2, x2, #15+ add bf, x2, bias++ cmp bf, 9+ cset bias, cs++ mov x0, 16+ sub x0, x0, bf+ cmp bias, xzr+ csel ix, x0, bf, ne++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ mov x0, #1+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, #1+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr++ cmp ix, #1+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #2+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #3+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #4+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #5+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #6+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #7+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #8+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++// We now have the triple from the table in registers as follows+//+// [x3;x2;x1;x0] = y - x+// [x7;x6;x5;x4] = x + y+// [x11;x10;x9;x8] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmp bias, #0++ csel x12, x0, x4, eq+ csel x13, x1, x5, eq+ csel x14, x2, x6, eq+ csel x15, x3, x7, eq+ stp x12, x13, [tabent]+ stp x14, x15, [tabent+16]++ csel x12, x0, x4, ne+ csel x13, x1, x5, ne+ csel x14, x2, x6, ne+ csel x15, x3, x7, ne+ stp x12, x13, [tabent+32]+ stp x14, x15, [tabent+48]++ mov x0, #-19+ subs x0, x0, x8+ mov x2, #-1+ sbcs x1, x2, x9+ sbcs x2, x2, x10+ mov x3, #0x7FFFFFFFFFFFFFFF+ sbc x3, x3, x11++ cmp ix, xzr+ ccmp bias, xzr, #4, ne++ csel x0, x0, x8, ne+ csel x1, x1, x9, ne+ stp x0, x1, [tabent+64]+ csel x2, x2, x10, ne+ csel x3, x3, x11, ne+ stp x2, x3, [tabent+80]++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ add i, i, 4+ cmp i, 256+ bcc Lcurve25519_x25519base_alt_scalarloop++// Now we need to translate from Edwards curve edwards25519 back+// to the Montgomery form curve25519. The mapping in the affine+// representations is+//+// (x,y) |-> ((1 + y) / (1 - y), c * (1 + y) / ((1 - y) * x))+//+// For x25519, we only need the x coordinate, and we compute this as+//+// (1 + y) / (1 - y) = (x + x * y) / (x - x * y)+// = (X/Z + T/Z) / (X/Z - T/Z)+// = (X + T) / (X - T)+// = (X + T) * inverse(X - T)+//+// We could equally well use (Z + Y) / (Z - Y), but the above has the+// same cost, and it more explicitly forces zero output whenever X = 0,+// regardless of how the modular inverse behaves on zero inputs. In+// the present setting (base point 9, mangled scalar) that doesn't+// really matter anyway since X = 0 never arises, but it seems a+// little bit tidier. Note that both Edwards point (0,1) which maps to+// the Montgomery point at infinity, and Edwards (0,-1) which maps to+// Montgomery (0,0) [this is the 2-torsion point] are both by definition+// mapped to 0 by the X coordinate mapping used to define curve25519.+//+// First the addition and subtraction:++ add_twice4(t1,x_3,w_3)+ sub_twice4(t2,x_3,w_3)++// Prepare to call the modular inverse function to get t0 = 1/t2+// Note that this works for the weakly normalized z_3 equally well.+// The non-coprime case z_3 == 0 (mod p_25519) cannot arise anyway.++ add x0, t0+ add x1, t2++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "arm/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 128 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, t0, t1, t2.++ mov x20, x0+ mov x10, #0xffffffffffffffed+ mov x11, #0xffffffffffffffff+ stp x10, x11, [sp]+ mov x12, #0x7fffffffffffffff+ stp x11, x12, [sp, #16]+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x7, #0x13+ lsr x6, x5, #63+ madd x6, x7, x6, x7+ adds x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ orr x5, x5, #0x8000000000000000+ adcs x5, x5, xzr+ csel x6, x7, xzr, cc+ subs x2, x2, x6+ sbcs x3, x3, xzr+ sbcs x4, x4, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ stp x2, x3, [sp, #32]+ stp x4, x5, [sp, #48]+ stp xzr, xzr, [sp, #64]+ stp xzr, xzr, [sp, #80]+ mov x10, #0x2099+ movk x10, #0x7502, lsl #16+ movk x10, #0x9e23, lsl #32+ movk x10, #0xa0f9, lsl #48+ mov x11, #0x2595+ movk x11, #0x1d13, lsl #16+ movk x11, #0x8f3f, lsl #32+ movk x11, #0xa8c6, lsl #48+ mov x12, #0x5242+ movk x12, #0x5ac, lsl #16+ movk x12, #0x8938, lsl #32+ movk x12, #0x6c6c, lsl #48+ mov x13, #0x615+ movk x13, #0x4177, lsl #16+ movk x13, #0x8b2, lsl #32+ movk x13, #0x2765, lsl #48+ stp x10, x11, [sp, #96]+ stp x12, x13, [sp, #112]+ mov x21, #0xa+ mov x22, #0x1+ b Lcurve25519_x25519base_alt_invmidloop+Lcurve25519_x25519base_alt_invloop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #32]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #40]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #32]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #40]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ asr x3, x1, #63+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ asr x0, x1, #63+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ eor x1, x7, x16+ asr x5, x1, #63+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ asr x0, x1, #63+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #48]+ extr x2, x5, x2, #59+ str x2, [sp, #56]+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #96]+ adc x3, x3, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #104]+ adc x4, x4, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #112]+ adc x2, x2, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ add x6, x6, x3, asr #63+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x3, x6, x3+ ldr x6, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x3+ asr x3, x3, #63+ adcs x6, x6, x3+ adc x5, x5, x3+ stp x0, x1, [sp, #64]+ stp x6, x5, [sp, #80]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x6, x5, x2, #63+ ldp x0, x1, [sp, #96]+ add x6, x6, x5, asr #63+ mov x5, #0x13+ mul x4, x6, x5+ add x2, x2, x6, lsl #63+ smulh x5, x6, x5+ ldr x3, [sp, #112]+ adds x0, x0, x4+ adcs x1, x1, x5+ asr x5, x5, #63+ adcs x3, x3, x5+ adc x2, x2, x5+ stp x0, x1, [sp, #96]+ stp x3, x2, [sp, #112]+Lcurve25519_x25519base_alt_invmidloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #32]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Lcurve25519_x25519base_alt_invloop+ ldr x0, [sp]+ ldr x1, [sp, #32]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ tst x3, x3+ cinc x6, x6, pl+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x6, x6, x3+ ldr x2, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x6+ asr x6, x6, #63+ adcs x2, x2, x6+ adcs x5, x5, x6+ csel x3, x3, xzr, mi+ subs x0, x0, x3+ sbcs x1, x1, xzr+ sbcs x2, x2, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ mov x4, x20+ stp x0, x1, [x4]+ stp x2, x5, [x4, #16]++// The final result is (X + T) / (X - T)+// This is the only operation in the whole computation that+// fully reduces modulo p_25519 since now we want the canonical+// answer as output.++ mul_p25519(resx,t1,t0)++// Restore stack and registers++ CFI_INC_SP(NSPACE)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519base_alt)+++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(curve25519_x25519base_alt_constant), %object+.size S2N_BN_SYMBOL(curve25519_x25519base_alt_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(curve25519_x25519base_alt_constant):++// 2^254 * G and (2^254 + 8) * G in extended-projective coordinates+// but with Z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x251037f7cf4e861d+ .quad 0x10ede0fb19fb128f+ .quad 0x96c033b175f5e2c8+ .quad 0x055f070d6c15fb0d+ .quad 0x7c52af2c97473e69+ .quad 0x022f82391bad8378+ .quad 0x9991e1b02adb476f+ .quad 0x511144a03a99b855+ .quad 0x5fafc3b88ff2e4ae+ .quad 0x855e4ff0de1230ff+ .quad 0x72e302a348492870+ .quad 0x1253c19e53dbe1bc++ .quad 0x331d086e0d9abcaa+ .quad 0x1e23c96d311a10c9+ .quad 0x96d0f95e58c13478+ .quad 0x2f72f7384fcfcc59+ .quad 0x39a6cd1cfd7d87c9+ .quad 0x9867a0abd8ae153a+ .quad 0xa49d2a5f35986745+ .quad 0x57012940cdfe82e1+ .quad 0x5046a6532ec5544a+ .quad 0x6d674004739ff6c9+ .quad 0x9bbaa44b234a70e3+ .quad 0x5e6d8901138cf386++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^4 * 1 * G++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * G++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * G++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * G++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * G++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * G++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * G++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * G++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * G++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * G++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * G++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * G++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * G++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * G++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * G++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * G++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * G++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * G++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * G++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * G++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * G++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * G++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * G++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * G++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * G++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * G++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * G++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * G++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * G++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * G++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * G++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * G++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * G++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * G++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * G++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * G++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * G++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * G++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * G++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * G++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * G++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * G++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * G++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * G++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * G++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * G++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * G++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * G++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * G++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * G++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * G++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * G++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * G++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * G++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * G++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * G++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * G++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * G++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * G++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * G++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * G++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * G++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * G++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * G++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * G++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * G++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * G++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * G++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * G++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * G++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * G++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * G++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * G++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * G++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * G++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * G++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * G++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * G++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * G++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * G++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * G++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * G++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * G++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * G++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * G++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * G++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * G++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * G++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * G++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * G++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * G++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * G++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * G++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * G++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * G++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * G++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * G++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * G++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * G++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * G++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * G++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * G++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * G++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * G++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * G++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * G++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * G++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * G++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * G++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * G++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * G++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * G++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * G++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * G++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * G++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * G++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * G++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * G++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * G++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * G++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * G++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * G++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * G++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * G++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * G++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * G++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * G++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * G++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * G++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * G++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * G++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * G++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * G++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * G++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * G++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * G++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * G++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * G++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * G++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * G++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * G++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * G++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * G++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * G++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * G++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * G++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * G++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * G++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * G++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * G++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * G++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * G++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * G++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * G++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * G++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * G++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * G++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * G++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * G++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * G++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * G++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * G++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * G++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * G++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * G++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * G++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * G++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * G++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * G++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * G++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * G++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * G++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * G++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * G++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * G++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * G++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * G++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * G++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * G++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * G++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * G++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * G++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * G++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * G++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * G++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * G++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * G++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * G++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * G++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * G++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * G++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * G++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * G++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * G++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * G++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * G++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * G++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * G++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * G++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * G++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * G++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * G++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * G++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * G++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * G++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * G++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * G++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * G++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * G++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * G++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * G++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * G++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * G++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * G++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * G++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * G++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * G++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * G++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * G++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * G++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * G++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * G++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * G++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * G++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * G++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * G++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * G++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * G++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * G++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * G++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * G++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * G++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * G++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * G++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * G++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * G++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * G++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * G++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * G++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * G++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * G++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * G++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * G++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * G++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * G++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * G++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * G++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * G++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * G++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * G++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * G++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * G++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * G++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * G++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * G++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * G++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * G++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * G++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * G++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * G++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * G++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * G++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * G++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * G++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * G++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * G++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * G++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * G++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * G++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * G++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * G++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * G++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * G++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * G++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * G++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * G++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * G++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * G++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * G++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * G++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * G++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * G++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * G++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * G++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * G++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * G++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * G++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * G++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * G++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * G++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * G++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * G++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * G++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * G++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * G++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * G++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * G++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * G++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * G++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * G++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * G++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * G++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * G++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * G++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * G++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * G++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * G++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * G++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * G++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * G++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * G++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * G++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * G++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * G++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * G++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * G++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * G++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * G++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * G++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * G++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * G++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * G++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * G++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * G++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * G++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * G++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * G++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * G++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * G++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * G++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * G++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * G++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * G++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * G++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * G++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * G++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * G++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * G++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * G++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * G++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * G++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * G++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * G++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * G++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * G++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * G++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * G++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * G++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * G++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * G++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * G++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * G++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * G++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * G++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * G++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * G++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * G++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * G++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * G++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * G++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * G++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * G++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * G++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * G++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * G++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * G++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * G++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * G++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * G++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * G++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * G++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * G++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * G++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * G++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * G++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * G++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * G++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * G++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * G++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * G++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * G++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * G++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * G++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * G++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * G++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * G++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * G++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * G++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * G++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * G++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * G++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * G++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * G++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * G++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * G++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * G++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * G++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * G++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * G++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * G++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * G++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * G++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * G++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * G++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * G++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * G++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * G++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * G++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * G++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * G++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * G++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * G++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * G++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * G++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * G++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * G++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * G++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * G++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * G++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * G++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * G++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * G++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * G++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * G++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * G++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * G++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * G++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * G++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * G++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * G++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * G++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * G++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * G++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * G++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * G++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * G++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * G++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * G++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * G++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * G++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * G++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * G++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * G++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * G++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * G++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * G++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * G++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * G++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * G++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * G++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * G++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * G++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * G++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * G++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * G++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * G++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * G++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * G++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * G++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * G++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * G++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * G++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * G++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * G++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * G++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * G++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * G++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * G++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * G++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * G++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * G++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * G++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * G++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * G++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * G++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * G++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * G++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * G++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * G++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * G++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * G++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * G++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * G++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * G++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * G++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * G++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * G++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * G++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * G++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * G++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * G++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * G++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * G++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * G++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * G++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * G++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f++ // 2^252 * 1 * G++ .quad 0xb1507ca1ab1c6eb9+ .quad 0xbd448f3e16b687b3+ .quad 0x3455fb7f2c7a91ab+ .quad 0x7579229e2f2adec1+ .quad 0x6ab5dcb85b1c16b7+ .quad 0x94c0fce83c7b27a5+ .quad 0xa4b11c1a735517be+ .quad 0x499238d0ba0eafaa+ .quad 0xecf46e527aba8b57+ .quad 0x15a08c478bd1647b+ .quad 0x7af1c6a65f706fef+ .quad 0x6345fa78f03a30d5++ // 2^252 * 2 * G++ .quad 0xdf02f95f1015e7a1+ .quad 0x790ec41da9b40263+ .quad 0x4d3a0ea133ea1107+ .quad 0x54f70be7e33af8c9+ .quad 0x93d3cbe9bdd8f0a4+ .quad 0xdb152c1bfd177302+ .quad 0x7dbddc6d7f17a875+ .quad 0x3e1a71cc8f426efe+ .quad 0xc83ca3e390babd62+ .quad 0x80ede3670291c833+ .quad 0xc88038ccd37900c4+ .quad 0x2c5fc0231ec31fa1++ // 2^252 * 3 * G++ .quad 0xfeba911717038b4f+ .quad 0xe5123721c9deef81+ .quad 0x1c97e4e75d0d8834+ .quad 0x68afae7a23dc3bc6+ .quad 0xc422e4d102456e65+ .quad 0x87414ac1cad47b91+ .quad 0x1592e2bba2b6ffdd+ .quad 0x75d9d2bff5c2100f+ .quad 0x5bd9b4763626e81c+ .quad 0x89966936bca02edd+ .quad 0x0a41193d61f077b3+ .quad 0x3097a24200ce5471++ // 2^252 * 4 * G++ .quad 0x57427734c7f8b84c+ .quad 0xf141a13e01b270e9+ .quad 0x02d1adfeb4e564a6+ .quad 0x4bb23d92ce83bd48+ .quad 0xa162e7246695c486+ .quad 0x131d633435a89607+ .quad 0x30521561a0d12a37+ .quad 0x56704bada6afb363+ .quad 0xaf6c4aa752f912b9+ .quad 0x5e665f6cd86770c8+ .quad 0x4c35ac83a3c8cd58+ .quad 0x2b7a29c010a58a7e++ // 2^252 * 5 * G++ .quad 0xc4007f77d0c1cec3+ .quad 0x8d1020b6bac492f8+ .quad 0x32ec29d57e69daaf+ .quad 0x599408759d95fce0+ .quad 0x33810a23bf00086e+ .quad 0xafce925ee736ff7c+ .quad 0x3d60e670e24922d4+ .quad 0x11ce9e714f96061b+ .quad 0x219ef713d815bac1+ .quad 0xf141465d485be25c+ .quad 0x6d5447cc4e513c51+ .quad 0x174926be5ef44393++ // 2^252 * 6 * G++ .quad 0xb5deb2f9fc5bd5bb+ .quad 0x92daa72ae1d810e1+ .quad 0xafc4cfdcb72a1c59+ .quad 0x497d78813fc22a24+ .quad 0x3ef5d41593ea022e+ .quad 0x5cbcc1a20ed0eed6+ .quad 0x8fd24ecf07382c8c+ .quad 0x6fa42ead06d8e1ad+ .quad 0xe276824a1f73371f+ .quad 0x7f7cf01c4f5b6736+ .quad 0x7e201fe304fa46e7+ .quad 0x785a36a357808c96++ // 2^252 * 7 * G++ .quad 0x825fbdfd63014d2b+ .quad 0xc852369c6ca7578b+ .quad 0x5b2fcd285c0b5df0+ .quad 0x12ab214c58048c8f+ .quad 0x070442985d517bc3+ .quad 0x6acd56c7ae653678+ .quad 0x00a27983985a7763+ .quad 0x5167effae512662b+ .quad 0xbd4ea9e10f53c4b6+ .quad 0x1673dc5f8ac91a14+ .quad 0xa8f81a4e2acc1aba+ .quad 0x33a92a7924332a25++ // 2^252 * 8 * G++ .quad 0x9dd1f49927996c02+ .quad 0x0cb3b058e04d1752+ .quad 0x1f7e88967fd02c3e+ .quad 0x2f964268cb8b3eb1+ .quad 0x7ba95ba0218f2ada+ .quad 0xcff42287330fb9ca+ .quad 0xdada496d56c6d907+ .quad 0x5380c296f4beee54+ .quad 0x9d4f270466898d0a+ .quad 0x3d0987990aff3f7a+ .quad 0xd09ef36267daba45+ .quad 0x7761455e7b1c669c
+ cbits/s2n/arm/edwards25519_encode.S view
@@ -0,0 +1,136 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Encode edwards25519 point into compressed form as 256-bit number+// Input p[8]; output z[32] (bytes)+//+// extern void edwards25519_encode(uint8_t z[static 32],+// const uint64_t p[static 8]);+//+// This assumes that the input buffer p points to a pair of 256-bit+// numbers x (at p) and y (at p+4) representing a point (x,y) on the+// edwards25519 curve. It is assumed that both x and y are < p_25519+// but there is no checking of this, nor of the fact that (x,y) is+// in fact on the curve.+//+// The output in z is a little-endian array of bytes corresponding to+// the standard compressed encoding of a point as 2^255 * x_0 + y+// where x_0 is the least significant bit of x.+// See "https://datatracker.ietf.org/doc/html/rfc8032#section-5.1.2"+// In this implementation, y is simply truncated to 255 bits, but if+// it is reduced mod p_25519 as expected this does not affect values.+//+// Standard ARM ABI: X0 = z, X1 = p+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(edwards25519_encode)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(edwards25519_encode)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(edwards25519_encode)+ .text+ .balign 4++#define z x0+#define p x1++#define y0 x2+#define y1 x3+#define y2 x4+#define y3 x5+#define y0short w2+#define y1short w3+#define y2short w4+#define y3short w5+#define xb x6++S2N_BN_SYMBOL(edwards25519_encode):+ CFI_START++// Load lowest word of x coordinate in xb and full y as [y3;y2;y1;y0].++ ldr xb, [p]+ ldp y0, y1, [p, #32]+ ldp y2, y3, [p, #48]++// Compute the encoded form, making the LSB of x the MSB of the encoding++ and y3, y3, #0x7FFFFFFFFFFFFFFF+ orr y3, y3, xb, lsl #63++// Write back in a byte-oriented fashion to be independent of endianness++ strb y0short, [z]+ lsr y0, y0, #8+ strb y0short, [z, #1]+ lsr y0, y0, #8+ strb y0short, [z, #2]+ lsr y0, y0, #8+ strb y0short, [z, #3]+ lsr y0, y0, #8+ strb y0short, [z, #4]+ lsr y0, y0, #8+ strb y0short, [z, #5]+ lsr y0, y0, #8+ strb y0short, [z, #6]+ lsr y0, y0, #8+ strb y0short, [z, #7]++ strb y1short, [z, #8]+ lsr y1, y1, #8+ strb y1short, [z, #9]+ lsr y1, y1, #8+ strb y1short, [z, #10]+ lsr y1, y1, #8+ strb y1short, [z, #11]+ lsr y1, y1, #8+ strb y1short, [z, #12]+ lsr y1, y1, #8+ strb y1short, [z, #13]+ lsr y1, y1, #8+ strb y1short, [z, #14]+ lsr y1, y1, #8+ strb y1short, [z, #15]++ strb y2short, [z, #16]+ lsr y2, y2, #8+ strb y2short, [z, #17]+ lsr y2, y2, #8+ strb y2short, [z, #18]+ lsr y2, y2, #8+ strb y2short, [z, #19]+ lsr y2, y2, #8+ strb y2short, [z, #20]+ lsr y2, y2, #8+ strb y2short, [z, #21]+ lsr y2, y2, #8+ strb y2short, [z, #22]+ lsr y2, y2, #8+ strb y2short, [z, #23]++ strb y3short, [z, #24]+ lsr y3, y3, #8+ strb y3short, [z, #25]+ lsr y3, y3, #8+ strb y3short, [z, #26]+ lsr y3, y3, #8+ strb y3short, [z, #27]+ lsr y3, y3, #8+ strb y3short, [z, #28]+ lsr y3, y3, #8+ strb y3short, [z, #29]+ lsr y3, y3, #8+ strb y3short, [z, #30]+ lsr y3, y3, #8+ strb y3short, [z, #31]++// Return++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(edwards25519_encode)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/arm/edwards25519_scalarmulbase.S view
@@ -0,0 +1,9635 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for the edwards25519 standard basepoint+// Input scalar[4]; output res[8]+//+// extern void edwards25519_scalarmulbase+// (uint64_t res[static 8],const uint64_t scalar[static 4]);+//+// Given a scalar n, returns point (X,Y) = n * B where B = (...,4/5) is+// the standard basepoint for the edwards25519 (Ed25519) curve.+//+// Standard ARM ABI: X0 = res, X1 = scalar+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(edwards25519_scalarmulbase)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(edwards25519_scalarmulbase)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(edwards25519_scalarmulbase)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable home for the input result argument during the whole body++#define res x23++// Other variables that are only needed prior to the modular inverse.++#define tab x19++#define i x20++#define bias x21++#define bf x22+#define ix x22++// Pointer-offset pairs for result and temporaries on stack with some aliasing.++#define resx res, #(0*NUMSIZE)+#define resy res, #(1*NUMSIZE)++#define scalar sp, #(0*NUMSIZE)++#define tabent sp, #(1*NUMSIZE)+#define ymx_2 sp, #(1*NUMSIZE)+#define xpy_2 sp, #(2*NUMSIZE)+#define kxy_2 sp, #(3*NUMSIZE)++#define acc sp, #(4*NUMSIZE)+#define x_1 sp, #(4*NUMSIZE)+#define y_1 sp, #(5*NUMSIZE)+#define z_1 sp, #(6*NUMSIZE)+#define w_1 sp, #(7*NUMSIZE)+#define x_3 sp, #(4*NUMSIZE)+#define y_3 sp, #(5*NUMSIZE)+#define z_3 sp, #(6*NUMSIZE)+#define w_3 sp, #(7*NUMSIZE)++#define tmpspace sp, #(8*NUMSIZE)+#define t0 sp, #(8*NUMSIZE)+#define t1 sp, #(9*NUMSIZE)+#define t2 sp, #(10*NUMSIZE)+#define t3 sp, #(11*NUMSIZE)+#define t4 sp, #(12*NUMSIZE)+#define t5 sp, #(13*NUMSIZE)++// Total size to reserve on the stack++#define NSPACE 14*NUMSIZE++// Load 64-bit immediate into a register++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++// Macro wrapping up the basic field operation bignum_mul_p25519, only+// trivially different from a pure function call to that subroutine.++#define mul_p25519(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x5, x6, [P2] __LF \+ umull x7, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x8, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x7, x7, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x8, x8, x15 __LF \+ adds x7, x7, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x8, x8, x16 __LF \+ mul x9, x4, x6 __LF \+ umulh x10, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x9, x9, x8 __LF \+ adc x10, x10, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x8, x7, x9 __LF \+ adcs x9, x9, x10 __LF \+ adc x10, x10, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x8, x15, x8 __LF \+ eor x3, x3, x16 __LF \+ adcs x9, x3, x9 __LF \+ adc x10, x10, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x5, x6, [P2+16] __LF \+ umull x11, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x12, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x11, x11, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x12, x12, x15 __LF \+ adds x11, x11, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x12, x12, x16 __LF \+ mul x13, x4, x6 __LF \+ umulh x14, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x13, x13, x12 __LF \+ adc x14, x14, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x12, x11, x13 __LF \+ adcs x13, x13, x14 __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x12, x15, x12 __LF \+ eor x3, x3, x16 __LF \+ adcs x13, x3, x13 __LF \+ adc x14, x14, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x15, x16, [P1] __LF \+ subs x3, x3, x15 __LF \+ sbcs x4, x4, x16 __LF \+ csetm x16, cc __LF \+ ldp x15, x0, [P2] __LF \+ subs x5, x15, x5 __LF \+ sbcs x6, x0, x6 __LF \+ csetm x0, cc __LF \+ eor x3, x3, x16 __LF \+ subs x3, x3, x16 __LF \+ eor x4, x4, x16 __LF \+ sbc x4, x4, x16 __LF \+ eor x5, x5, x0 __LF \+ subs x5, x5, x0 __LF \+ eor x6, x6, x0 __LF \+ sbc x6, x6, x0 __LF \+ eor x16, x0, x16 __LF \+ adds x11, x11, x9 __LF \+ adcs x12, x12, x10 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ mul x2, x3, x5 __LF \+ umulh x0, x3, x5 __LF \+ mul x15, x4, x6 __LF \+ umulh x1, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x9, cc __LF \+ adds x15, x15, x0 __LF \+ adc x1, x1, xzr __LF \+ subs x6, x5, x6 __LF \+ cneg x6, x6, cc __LF \+ cinv x9, x9, cc __LF \+ mul x5, x4, x6 __LF \+ umulh x6, x4, x6 __LF \+ adds x0, x2, x15 __LF \+ adcs x15, x15, x1 __LF \+ adc x1, x1, xzr __LF \+ cmn x9, #0x1 __LF \+ eor x5, x5, x9 __LF \+ adcs x0, x5, x0 __LF \+ eor x6, x6, x9 __LF \+ adcs x15, x6, x15 __LF \+ adc x1, x1, x9 __LF \+ adds x9, x11, x7 __LF \+ adcs x10, x12, x8 __LF \+ adcs x11, x13, x11 __LF \+ adcs x12, x14, x12 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x2, x2, x16 __LF \+ adcs x9, x2, x9 __LF \+ eor x0, x0, x16 __LF \+ adcs x10, x0, x10 __LF \+ eor x15, x15, x16 __LF \+ adcs x11, x15, x11 __LF \+ eor x1, x1, x16 __LF \+ adcs x12, x1, x12 __LF \+ adcs x13, x13, x16 __LF \+ adc x14, x14, x16 __LF \+ mov x3, #0x26 __LF \+ umull x4, w11, w3 __LF \+ add x4, x4, w7, uxtw __LF \+ lsr x7, x7, #32 __LF \+ lsr x11, x11, #32 __LF \+ umaddl x11, w11, w3, x7 __LF \+ mov x7, x4 __LF \+ umull x4, w12, w3 __LF \+ add x4, x4, w8, uxtw __LF \+ lsr x8, x8, #32 __LF \+ lsr x12, x12, #32 __LF \+ umaddl x12, w12, w3, x8 __LF \+ mov x8, x4 __LF \+ umull x4, w13, w3 __LF \+ add x4, x4, w9, uxtw __LF \+ lsr x9, x9, #32 __LF \+ lsr x13, x13, #32 __LF \+ umaddl x13, w13, w3, x9 __LF \+ mov x9, x4 __LF \+ umull x4, w14, w3 __LF \+ add x4, x4, w10, uxtw __LF \+ lsr x10, x10, #32 __LF \+ lsr x14, x14, #32 __LF \+ umaddl x14, w14, w3, x10 __LF \+ mov x10, x4 __LF \+ lsr x0, x14, #31 __LF \+ mov x5, #0x13 __LF \+ umaddl x5, w5, w0, x5 __LF \+ add x7, x7, x5 __LF \+ adds x7, x7, x11, lsl #32 __LF \+ extr x3, x12, x11, #32 __LF \+ adcs x8, x8, x3 __LF \+ extr x3, x13, x12, #32 __LF \+ adcs x9, x9, x3 __LF \+ extr x3, x14, x13, #32 __LF \+ lsl x5, x0, #63 __LF \+ eor x10, x10, x5 __LF \+ adc x10, x10, x3 __LF \+ mov x3, #0x13 __LF \+ tst x10, #0x8000000000000000 __LF \+ csel x3, x3, xzr, pl __LF \+ subs x7, x7, x3 __LF \+ sbcs x8, x8, xzr __LF \+ sbcs x9, x9, xzr __LF \+ sbc x10, x10, xzr __LF \+ and x10, x10, #0x7fffffffffffffff __LF \+ stp x7, x8, [P0] __LF \+ stp x9, x10, [P0+16]++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x5, x6, [P2] __LF \+ umull x7, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x8, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x7, x7, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x8, x8, x15 __LF \+ adds x7, x7, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x8, x8, x16 __LF \+ mul x9, x4, x6 __LF \+ umulh x10, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x9, x9, x8 __LF \+ adc x10, x10, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x8, x7, x9 __LF \+ adcs x9, x9, x10 __LF \+ adc x10, x10, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x8, x15, x8 __LF \+ eor x3, x3, x16 __LF \+ adcs x9, x3, x9 __LF \+ adc x10, x10, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x5, x6, [P2+16] __LF \+ umull x11, w3, w5 __LF \+ lsr x0, x3, #32 __LF \+ umull x15, w0, w5 __LF \+ lsr x16, x5, #32 __LF \+ umull x12, w16, w0 __LF \+ umull x16, w3, w16 __LF \+ adds x11, x11, x15, lsl #32 __LF \+ lsr x15, x15, #32 __LF \+ adc x12, x12, x15 __LF \+ adds x11, x11, x16, lsl #32 __LF \+ lsr x16, x16, #32 __LF \+ adc x12, x12, x16 __LF \+ mul x13, x4, x6 __LF \+ umulh x14, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x16, cc __LF \+ adds x13, x13, x12 __LF \+ adc x14, x14, xzr __LF \+ subs x3, x5, x6 __LF \+ cneg x3, x3, cc __LF \+ cinv x16, x16, cc __LF \+ mul x15, x4, x3 __LF \+ umulh x3, x4, x3 __LF \+ adds x12, x11, x13 __LF \+ adcs x13, x13, x14 __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x15, x15, x16 __LF \+ adcs x12, x15, x12 __LF \+ eor x3, x3, x16 __LF \+ adcs x13, x3, x13 __LF \+ adc x14, x14, x16 __LF \+ ldp x3, x4, [P1+16] __LF \+ ldp x15, x16, [P1] __LF \+ subs x3, x3, x15 __LF \+ sbcs x4, x4, x16 __LF \+ csetm x16, cc __LF \+ ldp x15, x0, [P2] __LF \+ subs x5, x15, x5 __LF \+ sbcs x6, x0, x6 __LF \+ csetm x0, cc __LF \+ eor x3, x3, x16 __LF \+ subs x3, x3, x16 __LF \+ eor x4, x4, x16 __LF \+ sbc x4, x4, x16 __LF \+ eor x5, x5, x0 __LF \+ subs x5, x5, x0 __LF \+ eor x6, x6, x0 __LF \+ sbc x6, x6, x0 __LF \+ eor x16, x0, x16 __LF \+ adds x11, x11, x9 __LF \+ adcs x12, x12, x10 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ mul x2, x3, x5 __LF \+ umulh x0, x3, x5 __LF \+ mul x15, x4, x6 __LF \+ umulh x1, x4, x6 __LF \+ subs x4, x4, x3 __LF \+ cneg x4, x4, cc __LF \+ csetm x9, cc __LF \+ adds x15, x15, x0 __LF \+ adc x1, x1, xzr __LF \+ subs x6, x5, x6 __LF \+ cneg x6, x6, cc __LF \+ cinv x9, x9, cc __LF \+ mul x5, x4, x6 __LF \+ umulh x6, x4, x6 __LF \+ adds x0, x2, x15 __LF \+ adcs x15, x15, x1 __LF \+ adc x1, x1, xzr __LF \+ cmn x9, #0x1 __LF \+ eor x5, x5, x9 __LF \+ adcs x0, x5, x0 __LF \+ eor x6, x6, x9 __LF \+ adcs x15, x6, x15 __LF \+ adc x1, x1, x9 __LF \+ adds x9, x11, x7 __LF \+ adcs x10, x12, x8 __LF \+ adcs x11, x13, x11 __LF \+ adcs x12, x14, x12 __LF \+ adcs x13, x13, xzr __LF \+ adc x14, x14, xzr __LF \+ cmn x16, #0x1 __LF \+ eor x2, x2, x16 __LF \+ adcs x9, x2, x9 __LF \+ eor x0, x0, x16 __LF \+ adcs x10, x0, x10 __LF \+ eor x15, x15, x16 __LF \+ adcs x11, x15, x11 __LF \+ eor x1, x1, x16 __LF \+ adcs x12, x1, x12 __LF \+ adcs x13, x13, x16 __LF \+ adc x14, x14, x16 __LF \+ mov x3, #0x26 __LF \+ umull x4, w11, w3 __LF \+ add x4, x4, w7, uxtw __LF \+ lsr x7, x7, #32 __LF \+ lsr x11, x11, #32 __LF \+ umaddl x11, w11, w3, x7 __LF \+ mov x7, x4 __LF \+ umull x4, w12, w3 __LF \+ add x4, x4, w8, uxtw __LF \+ lsr x8, x8, #32 __LF \+ lsr x12, x12, #32 __LF \+ umaddl x12, w12, w3, x8 __LF \+ mov x8, x4 __LF \+ umull x4, w13, w3 __LF \+ add x4, x4, w9, uxtw __LF \+ lsr x9, x9, #32 __LF \+ lsr x13, x13, #32 __LF \+ umaddl x13, w13, w3, x9 __LF \+ mov x9, x4 __LF \+ umull x4, w14, w3 __LF \+ add x4, x4, w10, uxtw __LF \+ lsr x10, x10, #32 __LF \+ lsr x14, x14, #32 __LF \+ umaddl x14, w14, w3, x10 __LF \+ mov x10, x4 __LF \+ lsr x0, x14, #31 __LF \+ mov x5, #0x13 __LF \+ umull x5, w5, w0 __LF \+ add x7, x7, x5 __LF \+ adds x7, x7, x11, lsl #32 __LF \+ extr x3, x12, x11, #32 __LF \+ adcs x8, x8, x3 __LF \+ extr x3, x13, x12, #32 __LF \+ adcs x9, x9, x3 __LF \+ extr x3, x14, x13, #32 __LF \+ lsl x5, x0, #63 __LF \+ eor x10, x10, x5 __LF \+ adc x10, x10, x3 __LF \+ stp x7, x8, [P0] __LF \+ stp x9, x10, [P0+16]++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ mov x4, #38 __LF \+ csel x3, x4, xzr, lo __LF \+ subs x5, x5, x3 __LF \+ sbcs x6, x6, xzr __LF \+ sbcs x7, x7, xzr __LF \+ sbc x8, x8, xzr __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ adds x3, x3, x7 __LF \+ adcs x4, x4, x8 __LF \+ ldp x5, x6, [P1+16] __LF \+ ldp x7, x8, [P2+16] __LF \+ adcs x5, x5, x7 __LF \+ adcs x6, x6, x8 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++#define double_twice4(P0,P1) \+ ldp x3, x4, [P1] __LF \+ adds x3, x3, x3 __LF \+ adcs x4, x4, x4 __LF \+ ldp x5, x6, [P1+16] __LF \+ adcs x5, x5, x5 __LF \+ adcs x6, x6, x6 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++S2N_BN_SYMBOL(edwards25519_scalarmulbase):+ CFI_START++// Save regs and make room for temporaries++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(NSPACE)++// Move the output pointer to a stable place++ mov res, x0++// Copy the input scalar x to its local variable while reducing it+// modulo 2^252 + m where m = 27742317777372353535851937790883648493;+// this is the order of the basepoint so this doesn't change the result.+// First do q = floor(x/2^252) and x' = x - q * (2^252 + m), which gives+// an initial result -15 * m <= x' < 2^252++ ldp x10, x11, [x1]+ ldp x12, x13, [x1, #16]++ lsr x9, x13, #60++ movbig(x0,#0x5812,#0x631a,#0x5cf5,#0xd3ed);+ movbig(x1,#0x14de,#0xf9de,#0xa2f7,#0x9cd6);++ mul x2, x9, x0+ mul x3, x9, x1+ umulh x4, x9, x0+ umulh x5, x9, x1++ adds x3, x3, x4+ adc x4, x5, xzr+ lsl x5, x9, #60++ subs x10, x10, x2+ sbcs x11, x11, x3+ sbcs x12, x12, x4+ sbcs x13, x13, x5++// If x' < 0 then just directly negate it; this makes sure the+// reduced argument is strictly 0 <= x' < 2^252, but now we need+// to record (done via bit 255 of the reduced scalar, which is+// ignored in the main loop) when we negated so we can flip+// the sign of the eventual point to compensate.++ csetm x9, cc+ adds xzr, x9, x9+ eor x10, x10, x9+ adcs x10, x10, xzr+ eor x11, x11, x9+ adcs x11, x11, xzr+ eor x12, x12, x9+ adcs x12, x12, xzr+ eor x13, x13, x9+ adc x13, x13, xzr++ and x9, x9, #0x8000000000000000+ orr x13, x13, x9++// And before we store the scalar, test and reset bit 251 to+// initialize the main loop just below.++ stp x10, x11, [scalar]+ tst x13, #0x0800000000000000+ bic x13, x13, #0x0800000000000000+ stp x12, x13, [scalar+16]++// The main part of the computation is in extended-projective coordinates+// (X,Y,Z,T), representing an affine point on the edwards25519 curve+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// In comments B means the standard basepoint (x,4/5) =+// (0x216....f25d51a,0x6666..666658).+//+// Initialize accumulator "acc" to either 0 or 2^251 * B depending on+// bit 251 of the (reduced) scalar. That leaves bits 0..250 to handle.++#if defined(__ELF__)+ adrp tab, S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant)+ add tab, tab, :lo12:S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant)+#else+ adrp tab, S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant)@PAGE+ add tab, tab, S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant)@PAGEOFF+#endif++ ldp x0, x1, [tab]+ ldp x2, x3, [tab, #96]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc]++ ldp x0, x1, [tab, #1*16]+ ldp x2, x3, [tab, #(96+1*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+1*16]++ ldp x0, x1, [tab, #2*16]+ ldp x2, x3, [tab, #(96+2*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+2*16]++ ldp x0, x1, [tab, #3*16]+ ldp x2, x3, [tab, #(96+3*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+3*16]++ mov x0, #1+ stp x0, xzr, [acc+4*16]+ stp xzr, xzr, [acc+5*16]++ ldp x0, x1, [tab, #4*16]+ ldp x2, x3, [tab, #(96+4*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+6*16]++ ldp x0, x1, [tab, #5*16]+ ldp x2, x3, [tab, #(96+5*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+7*16]++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 0 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * B at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * B = (16 * (h + 1) - (16 - l)) * B is used+// when l >= 9. Note that we can't have any bias left over at the+// end because we made sure bit 251 is clear in the reduced scalar.++ mov i, 0+ add tab, tab, #192+ mov bias, xzr++// Start of the main loop, repeated 63 times for i = 0, 4, 8, ..., 248++Ledwards25519_scalarmulbase_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ lsr x0, i, #6+ ldr x2, [sp, x0, lsl #3] // Exploiting scalar = sp exactly+ lsr x2, x2, i+ and x2, x2, #15+ add bf, x2, bias++ cmp bf, 9+ cset bias, cs++ mov x0, 16+ sub x0, x0, bf+ cmp bias, xzr+ csel ix, x0, bf, ne++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ mov x0, #1+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, #1+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr++ cmp ix, #1+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #2+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #3+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #4+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #5+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #6+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #7+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #8+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++// We now have the triple from the table in registers as follows+//+// [x3;x2;x1;x0] = y - x+// [x7;x6;x5;x4] = x + y+// [x11;x10;x9;x8] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmp bias, #0++ csel x12, x0, x4, eq+ csel x13, x1, x5, eq+ csel x14, x2, x6, eq+ csel x15, x3, x7, eq+ stp x12, x13, [tabent]+ stp x14, x15, [tabent+16]++ csel x12, x0, x4, ne+ csel x13, x1, x5, ne+ csel x14, x2, x6, ne+ csel x15, x3, x7, ne+ stp x12, x13, [tabent+32]+ stp x14, x15, [tabent+48]++ mov x0, #-19+ subs x0, x0, x8+ mov x2, #-1+ sbcs x1, x2, x9+ sbcs x2, x2, x10+ mov x3, #0x7FFFFFFFFFFFFFFF+ sbc x3, x3, x11++ cmp ix, xzr+ ccmp bias, xzr, #4, ne++ csel x0, x0, x8, ne+ csel x1, x1, x9, ne+ stp x0, x1, [tabent+64]+ csel x2, x2, x10, ne+ csel x3, x3, x11, ne+ stp x2, x3, [tabent+80]++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd_alt(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ add i, i, 4+ cmp i, 252+ bcc Ledwards25519_scalarmulbase_scalarloop++// Insert the optional negation of the projective X coordinate, and+// so by extension the final affine x coordinate x = X/Z and thus+// the point P = (x,y). We only know X < 2 * p_25519, so we do the+// negation as 2 * p_25519 - X to keep it nonnegative. From this+// point on we don't need any normalization of the coordinates+// except for making sure that they fit in 4 digits.++ ldp x0, x1, [x_3]+ ldp x2, x3, [x_3+16]+ mov x4, #0xffffffffffffffda+ subs x4, x4, x0+ mov x7, #0xffffffffffffffff+ sbcs x5, x7, x1+ sbcs x6, x7, x2+ sbc x7, x7, x3+ ldr x10, [scalar+24]+ tst x10, #0x8000000000000000+ csel x0, x4, x0, ne+ csel x1, x5, x1, ne+ csel x2, x6, x2, ne+ csel x3, x7, x3, ne+ stp x0, x1, [x_3]+ stp x2, x3, [x_3+16]++// Now we need to map out of the extended-projective representation+// (X,Y,Z,W) back to the affine form (x,y) = (X/Z,Y/Z). This means+// first calling the modular inverse to get w_3 = 1/z_3.++ add x0, w_3+ add x1, z_3++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "arm/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 128 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, w_3, x_3+// and y_3.++ mov x20, x0+ mov x10, #0xffffffffffffffed+ mov x11, #0xffffffffffffffff+ stp x10, x11, [sp]+ mov x12, #0x7fffffffffffffff+ stp x11, x12, [sp, #16]+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x7, #0x13+ lsr x6, x5, #63+ madd x6, x7, x6, x7+ adds x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ orr x5, x5, #0x8000000000000000+ adcs x5, x5, xzr+ csel x6, x7, xzr, cc+ subs x2, x2, x6+ sbcs x3, x3, xzr+ sbcs x4, x4, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ stp x2, x3, [sp, #32]+ stp x4, x5, [sp, #48]+ stp xzr, xzr, [sp, #64]+ stp xzr, xzr, [sp, #80]+ mov x10, #0x2099+ movk x10, #0x7502, lsl #16+ movk x10, #0x9e23, lsl #32+ movk x10, #0xa0f9, lsl #48+ mov x11, #0x2595+ movk x11, #0x1d13, lsl #16+ movk x11, #0x8f3f, lsl #32+ movk x11, #0xa8c6, lsl #48+ mov x12, #0x5242+ movk x12, #0x5ac, lsl #16+ movk x12, #0x8938, lsl #32+ movk x12, #0x6c6c, lsl #48+ mov x13, #0x615+ movk x13, #0x4177, lsl #16+ movk x13, #0x8b2, lsl #32+ movk x13, #0x2765, lsl #48+ stp x10, x11, [sp, #96]+ stp x12, x13, [sp, #112]+ mov x21, #0xa+ mov x22, #0x1+ b Ledwards25519_scalarmulbase_invmidloop+Ledwards25519_scalarmulbase_invloop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #32]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #40]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #32]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #40]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ asr x3, x1, #63+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ asr x0, x1, #63+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ eor x1, x7, x16+ asr x5, x1, #63+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ asr x0, x1, #63+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #48]+ extr x2, x5, x2, #59+ str x2, [sp, #56]+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #96]+ adc x3, x3, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #104]+ adc x4, x4, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #112]+ adc x2, x2, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ add x6, x6, x3, asr #63+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x3, x6, x3+ ldr x6, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x3+ asr x3, x3, #63+ adcs x6, x6, x3+ adc x5, x5, x3+ stp x0, x1, [sp, #64]+ stp x6, x5, [sp, #80]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x6, x5, x2, #63+ ldp x0, x1, [sp, #96]+ add x6, x6, x5, asr #63+ mov x5, #0x13+ mul x4, x6, x5+ add x2, x2, x6, lsl #63+ smulh x5, x6, x5+ ldr x3, [sp, #112]+ adds x0, x0, x4+ adcs x1, x1, x5+ asr x5, x5, #63+ adcs x3, x3, x5+ adc x2, x2, x5+ stp x0, x1, [sp, #96]+ stp x3, x2, [sp, #112]+Ledwards25519_scalarmulbase_invmidloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #32]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Ledwards25519_scalarmulbase_invloop+ ldr x0, [sp]+ ldr x1, [sp, #32]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ tst x3, x3+ cinc x6, x6, pl+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x6, x6, x3+ ldr x2, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x6+ asr x6, x6, #63+ adcs x2, x2, x6+ adcs x5, x5, x6+ csel x3, x3, xzr, mi+ subs x0, x0, x3+ sbcs x1, x1, xzr+ sbcs x2, x2, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ mov x4, x20+ stp x0, x1, [x4]+ stp x2, x5, [x4, #16]++// The final result is x = X * inv(Z), y = Y * inv(Z).+// These are the only operations in the whole computation that+// fully reduce modulo p_25519 since now we want the canonical+// answer as output.++ mul_p25519(resx,x_3,w_3)+ mul_p25519(resy,y_3,w_3)++// Restore stack and registers++ CFI_INC_SP(NSPACE)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(edwards25519_scalarmulbase)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant), %object+.size S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant):++// 0 * B = 0 and 2^251 * B in extended-projective coordinates+// but with Z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000001+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x525f946d7c7220e7+ .quad 0x4636b0b2f1e35444+ .quad 0x796e9d70e892ae0f+ .quad 0x03dec05fa937adb1+ .quad 0x6d1c271cc6375515+ .quad 0x462588c4a4ca4f14+ .quad 0x691129fee55afc39+ .quad 0x15949f784d8472f5+ .quad 0xbd89e510afad0049+ .quad 0x4d1f08c073b9860e+ .quad 0x07716e8b2d00af9d+ .quad 0x70d685f68f859714++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^0 * 1 * G++ .quad 0x9d103905d740913e+ .quad 0xfd399f05d140beb3+ .quad 0xa5c18434688f8a09+ .quad 0x44fd2f9298f81267+ .quad 0x2fbc93c6f58c3b85+ .quad 0xcf932dc6fb8c0e19+ .quad 0x270b4898643d42c2+ .quad 0x07cf9d3a33d4ba65+ .quad 0xabc91205877aaa68+ .quad 0x26d9e823ccaac49e+ .quad 0x5a1b7dcbdd43598c+ .quad 0x6f117b689f0c65a8++ // 2^0 * 2 * G++ .quad 0x8a99a56042b4d5a8+ .quad 0x8f2b810c4e60acf6+ .quad 0xe09e236bb16e37aa+ .quad 0x6bb595a669c92555+ .quad 0x9224e7fc933c71d7+ .quad 0x9f469d967a0ff5b5+ .quad 0x5aa69a65e1d60702+ .quad 0x590c063fa87d2e2e+ .quad 0x43faa8b3a59b7a5f+ .quad 0x36c16bdd5d9acf78+ .quad 0x500fa0840b3d6a31+ .quad 0x701af5b13ea50b73++ // 2^0 * 3 * G++ .quad 0x56611fe8a4fcd265+ .quad 0x3bd353fde5c1ba7d+ .quad 0x8131f31a214bd6bd+ .quad 0x2ab91587555bda62+ .quad 0xaf25b0a84cee9730+ .quad 0x025a8430e8864b8a+ .quad 0xc11b50029f016732+ .quad 0x7a164e1b9a80f8f4+ .quad 0x14ae933f0dd0d889+ .quad 0x589423221c35da62+ .quad 0xd170e5458cf2db4c+ .quad 0x5a2826af12b9b4c6++ // 2^0 * 4 * G++ .quad 0x95fe050a056818bf+ .quad 0x327e89715660faa9+ .quad 0xc3e8e3cd06a05073+ .quad 0x27933f4c7445a49a+ .quad 0x287351b98efc099f+ .quad 0x6765c6f47dfd2538+ .quad 0xca348d3dfb0a9265+ .quad 0x680e910321e58727+ .quad 0x5a13fbe9c476ff09+ .quad 0x6e9e39457b5cc172+ .quad 0x5ddbdcf9102b4494+ .quad 0x7f9d0cbf63553e2b++ // 2^0 * 5 * G++ .quad 0x7f9182c3a447d6ba+ .quad 0xd50014d14b2729b7+ .quad 0xe33cf11cb864a087+ .quad 0x154a7e73eb1b55f3+ .quad 0xa212bc4408a5bb33+ .quad 0x8d5048c3c75eed02+ .quad 0xdd1beb0c5abfec44+ .quad 0x2945ccf146e206eb+ .quad 0xbcbbdbf1812a8285+ .quad 0x270e0807d0bdd1fc+ .quad 0xb41b670b1bbda72d+ .quad 0x43aabe696b3bb69a++ // 2^0 * 6 * G++ .quad 0x499806b67b7d8ca4+ .quad 0x575be28427d22739+ .quad 0xbb085ce7204553b9+ .quad 0x38b64c41ae417884+ .quad 0x3a0ceeeb77157131+ .quad 0x9b27158900c8af88+ .quad 0x8065b668da59a736+ .quad 0x51e57bb6a2cc38bd+ .quad 0x85ac326702ea4b71+ .quad 0xbe70e00341a1bb01+ .quad 0x53e4a24b083bc144+ .quad 0x10b8e91a9f0d61e3++ // 2^0 * 7 * G++ .quad 0xba6f2c9aaa3221b1+ .quad 0x6ca021533bba23a7+ .quad 0x9dea764f92192c3a+ .quad 0x1d6edd5d2e5317e0+ .quad 0x6b1a5cd0944ea3bf+ .quad 0x7470353ab39dc0d2+ .quad 0x71b2528228542e49+ .quad 0x461bea69283c927e+ .quad 0xf1836dc801b8b3a2+ .quad 0xb3035f47053ea49a+ .quad 0x529c41ba5877adf3+ .quad 0x7a9fbb1c6a0f90a7++ // 2^0 * 8 * G++ .quad 0xe2a75dedf39234d9+ .quad 0x963d7680e1b558f9+ .quad 0x2c2741ac6e3c23fb+ .quad 0x3a9024a1320e01c3+ .quad 0x59b7596604dd3e8f+ .quad 0x6cb30377e288702c+ .quad 0xb1339c665ed9c323+ .quad 0x0915e76061bce52f+ .quad 0xe7c1f5d9c9a2911a+ .quad 0xb8a371788bcca7d7+ .quad 0x636412190eb62a32+ .quad 0x26907c5c2ecc4e95++ // 2^4 * 1 * B++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * B++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * B++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * B++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * B++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * B++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * B++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * B++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * B++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * B++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * B++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * B++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * B++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * B++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * B++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * B++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * B++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * B++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * B++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * B++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * B++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * B++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * B++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * B++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * B++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * B++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * B++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * B++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * B++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * B++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * B++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * B++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * B++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * B++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * B++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * B++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * B++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * B++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * B++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * B++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * B++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * B++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * B++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * B++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * B++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * B++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * B++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * B++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * B++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * B++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * B++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * B++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * B++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * B++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * B++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * B++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * B++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * B++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * B++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * B++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * B++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * B++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * B++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * B++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * B++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * B++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * B++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * B++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * B++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * B++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * B++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * B++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * B++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * B++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * B++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * B++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * B++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * B++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * B++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * B++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * B++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * B++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * B++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * B++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * B++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * B++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * B++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * B++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * B++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * B++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * B++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * B++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * B++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * B++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * B++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * B++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * B++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * B++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * B++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * B++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * B++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * B++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * B++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * B++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * B++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * B++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * B++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * B++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * B++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * B++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * B++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * B++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * B++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * B++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * B++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * B++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * B++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * B++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * B++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * B++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * B++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * B++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * B++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * B++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * B++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * B++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * B++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * B++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * B++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * B++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * B++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * B++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * B++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * B++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * B++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * B++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * B++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * B++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * B++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * B++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * B++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * B++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * B++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * B++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * B++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * B++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * B++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * B++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * B++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * B++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * B++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * B++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * B++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * B++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * B++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * B++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * B++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * B++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * B++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * B++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * B++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * B++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * B++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * B++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * B++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * B++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * B++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * B++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * B++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * B++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * B++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * B++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * B++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * B++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * B++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * B++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * B++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * B++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * B++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * B++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * B++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * B++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * B++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * B++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * B++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * B++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * B++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * B++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * B++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * B++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * B++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * B++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * B++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * B++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * B++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * B++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * B++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * B++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * B++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * B++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * B++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * B++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * B++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * B++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * B++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * B++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * B++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * B++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * B++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * B++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * B++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * B++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * B++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * B++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * B++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * B++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * B++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * B++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * B++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * B++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * B++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * B++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * B++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * B++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * B++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * B++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * B++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * B++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * B++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * B++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * B++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * B++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * B++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * B++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * B++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * B++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * B++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * B++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * B++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * B++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * B++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * B++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * B++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * B++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * B++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * B++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * B++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * B++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * B++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * B++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * B++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * B++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * B++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * B++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * B++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * B++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * B++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * B++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * B++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * B++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * B++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * B++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * B++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * B++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * B++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * B++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * B++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * B++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * B++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * B++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * B++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * B++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * B++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * B++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * B++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * B++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * B++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * B++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * B++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * B++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * B++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * B++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * B++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * B++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * B++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * B++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * B++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * B++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * B++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * B++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * B++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * B++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * B++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * B++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * B++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * B++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * B++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * B++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * B++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * B++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * B++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * B++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * B++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * B++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * B++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * B++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * B++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * B++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * B++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * B++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * B++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * B++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * B++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * B++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * B++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * B++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * B++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * B++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * B++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * B++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * B++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * B++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * B++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * B++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * B++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * B++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * B++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * B++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * B++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * B++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * B++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * B++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * B++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * B++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * B++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * B++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * B++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * B++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * B++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * B++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * B++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * B++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * B++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * B++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * B++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * B++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * B++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * B++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * B++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * B++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * B++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * B++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * B++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * B++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * B++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * B++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * B++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * B++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * B++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * B++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * B++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * B++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * B++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * B++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * B++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * B++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * B++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * B++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * B++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * B++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * B++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * B++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * B++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * B++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * B++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * B++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * B++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * B++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * B++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * B++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * B++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * B++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * B++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * B++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * B++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * B++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * B++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * B++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * B++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * B++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * B++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * B++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * B++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * B++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * B++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * B++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * B++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * B++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * B++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * B++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * B++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * B++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * B++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * B++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * B++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * B++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * B++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * B++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * B++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * B++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * B++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * B++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * B++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * B++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * B++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * B++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * B++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * B++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * B++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * B++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * B++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * B++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * B++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * B++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * B++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * B++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * B++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * B++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * B++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * B++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * B++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * B++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * B++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * B++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * B++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * B++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * B++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * B++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * B++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * B++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * B++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * B++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * B++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * B++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * B++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * B++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * B++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * B++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * B++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * B++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * B++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * B++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * B++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * B++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * B++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * B++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * B++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * B++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * B++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * B++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * B++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * B++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * B++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * B++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * B++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * B++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * B++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * B++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * B++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * B++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * B++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * B++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * B++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * B++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * B++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * B++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * B++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * B++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * B++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * B++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * B++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * B++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * B++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * B++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * B++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * B++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * B++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * B++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * B++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * B++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * B++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * B++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * B++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * B++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * B++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * B++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f
+ cbits/s2n/arm/edwards25519_scalarmulbase_alt.S view
@@ -0,0 +1,9477 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for the edwards25519 standard basepoint+// Input scalar[4]; output res[8]+//+// extern void edwards25519_scalarmulbase_alt+// (uint64_t res[static 8],const uint64_t scalar[static 4]);+//+// Given a scalar n, returns point (X,Y) = n * B where B = (...,4/5) is+// the standard basepoint for the edwards25519 (Ed25519) curve.+//+// Standard ARM ABI: X0 = res, X1 = scalar+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(edwards25519_scalarmulbase_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(edwards25519_scalarmulbase_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(edwards25519_scalarmulbase_alt)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable home for the input result argument during the whole body++#define res x23++// Other variables that are only needed prior to the modular inverse.++#define tab x19++#define i x20++#define bias x21++#define bf x22+#define ix x22++// Pointer-offset pairs for result and temporaries on stack with some aliasing.++#define resx res, #(0*NUMSIZE)+#define resy res, #(1*NUMSIZE)++#define scalar sp, #(0*NUMSIZE)++#define tabent sp, #(1*NUMSIZE)+#define ymx_2 sp, #(1*NUMSIZE)+#define xpy_2 sp, #(2*NUMSIZE)+#define kxy_2 sp, #(3*NUMSIZE)++#define acc sp, #(4*NUMSIZE)+#define x_1 sp, #(4*NUMSIZE)+#define y_1 sp, #(5*NUMSIZE)+#define z_1 sp, #(6*NUMSIZE)+#define w_1 sp, #(7*NUMSIZE)+#define x_3 sp, #(4*NUMSIZE)+#define y_3 sp, #(5*NUMSIZE)+#define z_3 sp, #(6*NUMSIZE)+#define w_3 sp, #(7*NUMSIZE)++#define tmpspace sp, #(8*NUMSIZE)+#define t0 sp, #(8*NUMSIZE)+#define t1 sp, #(9*NUMSIZE)+#define t2 sp, #(10*NUMSIZE)+#define t3 sp, #(11*NUMSIZE)+#define t4 sp, #(12*NUMSIZE)+#define t5 sp, #(13*NUMSIZE)++// Total size to reserve on the stack++#define NSPACE 14*NUMSIZE++// Load 64-bit immediate into a register++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++// Macro wrapping up the basic field operation bignum_mul_p25519_alt, only+// trivially different from a pure function call to that subroutine.++#define mul_p25519(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x15, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x16, x3, x10 __LF \+ adcs x15, x15, x11 __LF \+ adc x16, x16, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x16, x16, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x15, x15, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x16, x16, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x15, x15, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x16, x16, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x15, x15, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x16, x16, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ mov x7, #0x26 __LF \+ mul x11, x7, x16 __LF \+ umulh x9, x7, x16 __LF \+ adds x12, x12, x11 __LF \+ mul x11, x7, x3 __LF \+ umulh x3, x7, x3 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x7, x4 __LF \+ umulh x4, x7, x4 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x7, x5 __LF \+ umulh x5, x7, x5 __LF \+ adcs x15, x15, x11 __LF \+ cset x16, cs __LF \+ adds x15, x15, x4 __LF \+ adc x16, x16, x5 __LF \+ cmn x15, x15 __LF \+ orr x15, x15, #0x8000000000000000 __LF \+ adc x8, x16, x16 __LF \+ mov x7, #0x13 __LF \+ madd x11, x7, x8, x7 __LF \+ adds x12, x12, x11 __LF \+ adcs x13, x13, x9 __LF \+ adcs x14, x14, x3 __LF \+ adcs x15, x15, xzr __LF \+ csel x7, x7, xzr, cc __LF \+ subs x12, x12, x7 __LF \+ sbcs x13, x13, xzr __LF \+ sbcs x14, x14, xzr __LF \+ sbc x15, x15, xzr __LF \+ and x15, x15, #0x7fffffffffffffff __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x15, [P0+16]++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x15, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x16, x3, x10 __LF \+ adcs x15, x15, x11 __LF \+ adc x16, x16, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x16, x16, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x15, x15, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x16, x16, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x15, x15, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x15, x15, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x16, x16, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x15, x15, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x16, x16, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x16, x16, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ mov x7, #0x26 __LF \+ mul x11, x7, x16 __LF \+ umulh x9, x7, x16 __LF \+ adds x12, x12, x11 __LF \+ mul x11, x7, x3 __LF \+ umulh x3, x7, x3 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x7, x4 __LF \+ umulh x4, x7, x4 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x7, x5 __LF \+ umulh x5, x7, x5 __LF \+ adcs x15, x15, x11 __LF \+ cset x16, cs __LF \+ adds x15, x15, x4 __LF \+ adc x16, x16, x5 __LF \+ cmn x15, x15 __LF \+ bic x15, x15, #0x8000000000000000 __LF \+ adc x8, x16, x16 __LF \+ mov x7, #0x13 __LF \+ mul x11, x7, x8 __LF \+ adds x12, x12, x11 __LF \+ adcs x13, x13, x9 __LF \+ adcs x14, x14, x3 __LF \+ adc x15, x15, xzr __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x15, [P0+16]++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ mov x4, #38 __LF \+ csel x3, x4, xzr, lo __LF \+ subs x5, x5, x3 __LF \+ sbcs x6, x6, xzr __LF \+ sbcs x7, x7, xzr __LF \+ sbc x8, x8, xzr __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ adds x3, x3, x7 __LF \+ adcs x4, x4, x8 __LF \+ ldp x5, x6, [P1+16] __LF \+ ldp x7, x8, [P2+16] __LF \+ adcs x5, x5, x7 __LF \+ adcs x6, x6, x8 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++#define double_twice4(P0,P1) \+ ldp x3, x4, [P1] __LF \+ adds x3, x3, x3 __LF \+ adcs x4, x4, x4 __LF \+ ldp x5, x6, [P1+16] __LF \+ adcs x5, x5, x5 __LF \+ adcs x6, x6, x6 __LF \+ mov x9, #38 __LF \+ csel x9, x9, xzr, cs __LF \+ adds x3, x3, x9 __LF \+ adcs x4, x4, xzr __LF \+ adcs x5, x5, xzr __LF \+ adc x6, x6, xzr __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt):+ CFI_START++// Save regs and make room for temporaries++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(NSPACE)++// Move the output pointer to a stable place++ mov res, x0++// Copy the input scalar x to its local variable while reducing it+// modulo 2^252 + m where m = 27742317777372353535851937790883648493;+// this is the order of the basepoint so this doesn't change the result.+// First do q = floor(x/2^252) and x' = x - q * (2^252 + m), which gives+// an initial result -15 * m <= x' < 2^252++ ldp x10, x11, [x1]+ ldp x12, x13, [x1, #16]++ lsr x9, x13, #60++ movbig(x0,#0x5812,#0x631a,#0x5cf5,#0xd3ed);+ movbig(x1,#0x14de,#0xf9de,#0xa2f7,#0x9cd6);++ mul x2, x9, x0+ mul x3, x9, x1+ umulh x4, x9, x0+ umulh x5, x9, x1++ adds x3, x3, x4+ adc x4, x5, xzr+ lsl x5, x9, #60++ subs x10, x10, x2+ sbcs x11, x11, x3+ sbcs x12, x12, x4+ sbcs x13, x13, x5++// If x' < 0 then just directly negate it; this makes sure the+// reduced argument is strictly 0 <= x' < 2^252, but now we need+// to record (done via bit 255 of the reduced scalar, which is+// ignored in the main loop) when we negated so we can flip+// the sign of the eventual point to compensate.++ csetm x9, cc+ adds xzr, x9, x9+ eor x10, x10, x9+ adcs x10, x10, xzr+ eor x11, x11, x9+ adcs x11, x11, xzr+ eor x12, x12, x9+ adcs x12, x12, xzr+ eor x13, x13, x9+ adc x13, x13, xzr++ and x9, x9, #0x8000000000000000+ orr x13, x13, x9++// And before we store the scalar, test and reset bit 251 to+// initialize the main loop just below.++ stp x10, x11, [scalar]+ tst x13, #0x0800000000000000+ bic x13, x13, #0x0800000000000000+ stp x12, x13, [scalar+16]++// The main part of the computation is in extended-projective coordinates+// (X,Y,Z,T), representing an affine point on the edwards25519 curve+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// In comments B means the standard basepoint (x,4/5) =+// (0x216....f25d51a,0x6666..666658).+//+// Initialize accumulator "acc" to either 0 or 2^251 * B depending on+// bit 251 of the (reduced) scalar. That leaves bits 0..250 to handle.++#if defined(__ELF__)+ adrp tab, S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant)+ add tab, tab, :lo12:S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant)+#else+ adrp tab, S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant)@PAGE+ add tab, tab, S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant)@PAGEOFF+#endif++ ldp x0, x1, [tab]+ ldp x2, x3, [tab, #96]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc]++ ldp x0, x1, [tab, #1*16]+ ldp x2, x3, [tab, #(96+1*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+1*16]++ ldp x0, x1, [tab, #2*16]+ ldp x2, x3, [tab, #(96+2*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+2*16]++ ldp x0, x1, [tab, #3*16]+ ldp x2, x3, [tab, #(96+3*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+3*16]++ mov x0, #1+ stp x0, xzr, [acc+4*16]+ stp xzr, xzr, [acc+5*16]++ ldp x0, x1, [tab, #4*16]+ ldp x2, x3, [tab, #(96+4*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+6*16]++ ldp x0, x1, [tab, #5*16]+ ldp x2, x3, [tab, #(96+5*16)]+ csel x0, x0, x2, eq+ csel x1, x1, x3, eq+ stp x0, x1, [acc+7*16]++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 0 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * B at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * B = (16 * (h + 1) - (16 - l)) * B is used+// when l >= 9. Note that we can't have any bias left over at the+// end because we made sure bit 251 is clear in the reduced scalar.++ mov i, 0+ add tab, tab, #192+ mov bias, xzr++// Start of the main loop, repeated 63 times for i = 0, 4, 8, ..., 248++Ledwards25519_scalarmulbase_alt_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ lsr x0, i, #6+ ldr x2, [sp, x0, lsl #3] // Exploiting scalar = sp exactly+ lsr x2, x2, i+ and x2, x2, #15+ add bf, x2, bias++ cmp bf, 9+ cset bias, cs++ mov x0, 16+ sub x0, x0, bf+ cmp bias, xzr+ csel ix, x0, bf, ne++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ mov x0, #1+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, #1+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr++ cmp ix, #1+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #2+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #3+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #4+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #5+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #6+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #7+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++ cmp ix, #8+ ldp x12, x13, [tab]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x12, x13, [tab, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x12, x13, [tab, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x12, x13, [tab, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x12, x13, [tab, #64]+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x12, x13, [tab, #80]+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ add tab, tab, #96++// We now have the triple from the table in registers as follows+//+// [x3;x2;x1;x0] = y - x+// [x7;x6;x5;x4] = x + y+// [x11;x10;x9;x8] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmp bias, #0++ csel x12, x0, x4, eq+ csel x13, x1, x5, eq+ csel x14, x2, x6, eq+ csel x15, x3, x7, eq+ stp x12, x13, [tabent]+ stp x14, x15, [tabent+16]++ csel x12, x0, x4, ne+ csel x13, x1, x5, ne+ csel x14, x2, x6, ne+ csel x15, x3, x7, ne+ stp x12, x13, [tabent+32]+ stp x14, x15, [tabent+48]++ mov x0, #-19+ subs x0, x0, x8+ mov x2, #-1+ sbcs x1, x2, x9+ sbcs x2, x2, x10+ mov x3, #0x7FFFFFFFFFFFFFFF+ sbc x3, x3, x11++ cmp ix, xzr+ ccmp bias, xzr, #4, ne++ csel x0, x0, x8, ne+ csel x1, x1, x9, ne+ stp x0, x1, [tabent+64]+ csel x2, x2, x10, ne+ csel x3, x3, x11, ne+ stp x2, x3, [tabent+80]++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd_alt(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ add i, i, 4+ cmp i, 252+ bcc Ledwards25519_scalarmulbase_alt_scalarloop++// Insert the optional negation of the projective X coordinate, and+// so by extension the final affine x coordinate x = X/Z and thus+// the point P = (x,y). We only know X < 2 * p_25519, so we do the+// negation as 2 * p_25519 - X to keep it nonnegative. From this+// point on we don't need any normalization of the coordinates+// except for making sure that they fit in 4 digits.++ ldp x0, x1, [x_3]+ ldp x2, x3, [x_3+16]+ mov x4, #0xffffffffffffffda+ subs x4, x4, x0+ mov x7, #0xffffffffffffffff+ sbcs x5, x7, x1+ sbcs x6, x7, x2+ sbc x7, x7, x3+ ldr x10, [scalar+24]+ tst x10, #0x8000000000000000+ csel x0, x4, x0, ne+ csel x1, x5, x1, ne+ csel x2, x6, x2, ne+ csel x3, x7, x3, ne+ stp x0, x1, [x_3]+ stp x2, x3, [x_3+16]++// Now we need to map out of the extended-projective representation+// (X,Y,Z,W) back to the affine form (x,y) = (X/Z,Y/Z). This means+// first calling the modular inverse to get w_3 = 1/z_3.++ add x0, w_3+ add x1, z_3++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "arm/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 128 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, w_3, x_3+// and y_3.++ mov x20, x0+ mov x10, #0xffffffffffffffed+ mov x11, #0xffffffffffffffff+ stp x10, x11, [sp]+ mov x12, #0x7fffffffffffffff+ stp x11, x12, [sp, #16]+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x7, #0x13+ lsr x6, x5, #63+ madd x6, x7, x6, x7+ adds x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ orr x5, x5, #0x8000000000000000+ adcs x5, x5, xzr+ csel x6, x7, xzr, cc+ subs x2, x2, x6+ sbcs x3, x3, xzr+ sbcs x4, x4, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ stp x2, x3, [sp, #32]+ stp x4, x5, [sp, #48]+ stp xzr, xzr, [sp, #64]+ stp xzr, xzr, [sp, #80]+ mov x10, #0x2099+ movk x10, #0x7502, lsl #16+ movk x10, #0x9e23, lsl #32+ movk x10, #0xa0f9, lsl #48+ mov x11, #0x2595+ movk x11, #0x1d13, lsl #16+ movk x11, #0x8f3f, lsl #32+ movk x11, #0xa8c6, lsl #48+ mov x12, #0x5242+ movk x12, #0x5ac, lsl #16+ movk x12, #0x8938, lsl #32+ movk x12, #0x6c6c, lsl #48+ mov x13, #0x615+ movk x13, #0x4177, lsl #16+ movk x13, #0x8b2, lsl #32+ movk x13, #0x2765, lsl #48+ stp x10, x11, [sp, #96]+ stp x12, x13, [sp, #112]+ mov x21, #0xa+ mov x22, #0x1+ b Ledwards25519_scalarmulbase_alt_invmidloop+Ledwards25519_scalarmulbase_alt_invloop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #32]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #40]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #32]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #40]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ asr x3, x1, #63+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ asr x0, x1, #63+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ eor x1, x7, x16+ asr x5, x1, #63+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ asr x0, x1, #63+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #48]+ extr x2, x5, x2, #59+ str x2, [sp, #56]+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #96]+ adc x3, x3, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #104]+ adc x4, x4, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #112]+ adc x2, x2, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ add x6, x6, x3, asr #63+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x3, x6, x3+ ldr x6, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x3+ asr x3, x3, #63+ adcs x6, x6, x3+ adc x5, x5, x3+ stp x0, x1, [sp, #64]+ stp x6, x5, [sp, #80]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x6, x5, x2, #63+ ldp x0, x1, [sp, #96]+ add x6, x6, x5, asr #63+ mov x5, #0x13+ mul x4, x6, x5+ add x2, x2, x6, lsl #63+ smulh x5, x6, x5+ ldr x3, [sp, #112]+ adds x0, x0, x4+ adcs x1, x1, x5+ asr x5, x5, #63+ adcs x3, x3, x5+ adc x2, x2, x5+ stp x0, x1, [sp, #96]+ stp x3, x2, [sp, #112]+Ledwards25519_scalarmulbase_alt_invmidloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #32]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Ledwards25519_scalarmulbase_alt_invloop+ ldr x0, [sp]+ ldr x1, [sp, #32]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #64]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #96]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #64]+ adc x2, x2, x1+ ldr x7, [sp, #72]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #104]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #72]+ adc x6, x6, x1+ ldr x7, [sp, #80]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #112]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #80]+ adc x5, x5, x1+ ldr x7, [sp, #88]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #120]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x3, x5, #63+ ldp x0, x1, [sp, #64]+ tst x3, x3+ cinc x6, x6, pl+ mov x3, #0x13+ mul x4, x6, x3+ add x5, x5, x6, lsl #63+ smulh x6, x6, x3+ ldr x2, [sp, #80]+ adds x0, x0, x4+ adcs x1, x1, x6+ asr x6, x6, #63+ adcs x2, x2, x6+ adcs x5, x5, x6+ csel x3, x3, xzr, mi+ subs x0, x0, x3+ sbcs x1, x1, xzr+ sbcs x2, x2, xzr+ sbc x5, x5, xzr+ and x5, x5, #0x7fffffffffffffff+ mov x4, x20+ stp x0, x1, [x4]+ stp x2, x5, [x4, #16]++// The final result is x = X * inv(Z), y = Y * inv(Z).+// These are the only operations in the whole computation that+// fully reduce modulo p_25519 since now we want the canonical+// answer as output.++ mul_p25519(resx,x_3,w_3)+ mul_p25519(resy,y_3,w_3)++// Restore stack and registers++ CFI_INC_SP(NSPACE)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)++ CFI_RET++S2N_BN_SIZE_DIRECTIVE(edwards25519_scalarmulbase_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant), %object+.size S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant):++// 0 * B = 0 and 2^251 * B in extended-projective coordinates+// but with Z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000001+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x525f946d7c7220e7+ .quad 0x4636b0b2f1e35444+ .quad 0x796e9d70e892ae0f+ .quad 0x03dec05fa937adb1+ .quad 0x6d1c271cc6375515+ .quad 0x462588c4a4ca4f14+ .quad 0x691129fee55afc39+ .quad 0x15949f784d8472f5+ .quad 0xbd89e510afad0049+ .quad 0x4d1f08c073b9860e+ .quad 0x07716e8b2d00af9d+ .quad 0x70d685f68f859714++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^0 * 1 * G++ .quad 0x9d103905d740913e+ .quad 0xfd399f05d140beb3+ .quad 0xa5c18434688f8a09+ .quad 0x44fd2f9298f81267+ .quad 0x2fbc93c6f58c3b85+ .quad 0xcf932dc6fb8c0e19+ .quad 0x270b4898643d42c2+ .quad 0x07cf9d3a33d4ba65+ .quad 0xabc91205877aaa68+ .quad 0x26d9e823ccaac49e+ .quad 0x5a1b7dcbdd43598c+ .quad 0x6f117b689f0c65a8++ // 2^0 * 2 * G++ .quad 0x8a99a56042b4d5a8+ .quad 0x8f2b810c4e60acf6+ .quad 0xe09e236bb16e37aa+ .quad 0x6bb595a669c92555+ .quad 0x9224e7fc933c71d7+ .quad 0x9f469d967a0ff5b5+ .quad 0x5aa69a65e1d60702+ .quad 0x590c063fa87d2e2e+ .quad 0x43faa8b3a59b7a5f+ .quad 0x36c16bdd5d9acf78+ .quad 0x500fa0840b3d6a31+ .quad 0x701af5b13ea50b73++ // 2^0 * 3 * G++ .quad 0x56611fe8a4fcd265+ .quad 0x3bd353fde5c1ba7d+ .quad 0x8131f31a214bd6bd+ .quad 0x2ab91587555bda62+ .quad 0xaf25b0a84cee9730+ .quad 0x025a8430e8864b8a+ .quad 0xc11b50029f016732+ .quad 0x7a164e1b9a80f8f4+ .quad 0x14ae933f0dd0d889+ .quad 0x589423221c35da62+ .quad 0xd170e5458cf2db4c+ .quad 0x5a2826af12b9b4c6++ // 2^0 * 4 * G++ .quad 0x95fe050a056818bf+ .quad 0x327e89715660faa9+ .quad 0xc3e8e3cd06a05073+ .quad 0x27933f4c7445a49a+ .quad 0x287351b98efc099f+ .quad 0x6765c6f47dfd2538+ .quad 0xca348d3dfb0a9265+ .quad 0x680e910321e58727+ .quad 0x5a13fbe9c476ff09+ .quad 0x6e9e39457b5cc172+ .quad 0x5ddbdcf9102b4494+ .quad 0x7f9d0cbf63553e2b++ // 2^0 * 5 * G++ .quad 0x7f9182c3a447d6ba+ .quad 0xd50014d14b2729b7+ .quad 0xe33cf11cb864a087+ .quad 0x154a7e73eb1b55f3+ .quad 0xa212bc4408a5bb33+ .quad 0x8d5048c3c75eed02+ .quad 0xdd1beb0c5abfec44+ .quad 0x2945ccf146e206eb+ .quad 0xbcbbdbf1812a8285+ .quad 0x270e0807d0bdd1fc+ .quad 0xb41b670b1bbda72d+ .quad 0x43aabe696b3bb69a++ // 2^0 * 6 * G++ .quad 0x499806b67b7d8ca4+ .quad 0x575be28427d22739+ .quad 0xbb085ce7204553b9+ .quad 0x38b64c41ae417884+ .quad 0x3a0ceeeb77157131+ .quad 0x9b27158900c8af88+ .quad 0x8065b668da59a736+ .quad 0x51e57bb6a2cc38bd+ .quad 0x85ac326702ea4b71+ .quad 0xbe70e00341a1bb01+ .quad 0x53e4a24b083bc144+ .quad 0x10b8e91a9f0d61e3++ // 2^0 * 7 * G++ .quad 0xba6f2c9aaa3221b1+ .quad 0x6ca021533bba23a7+ .quad 0x9dea764f92192c3a+ .quad 0x1d6edd5d2e5317e0+ .quad 0x6b1a5cd0944ea3bf+ .quad 0x7470353ab39dc0d2+ .quad 0x71b2528228542e49+ .quad 0x461bea69283c927e+ .quad 0xf1836dc801b8b3a2+ .quad 0xb3035f47053ea49a+ .quad 0x529c41ba5877adf3+ .quad 0x7a9fbb1c6a0f90a7++ // 2^0 * 8 * G++ .quad 0xe2a75dedf39234d9+ .quad 0x963d7680e1b558f9+ .quad 0x2c2741ac6e3c23fb+ .quad 0x3a9024a1320e01c3+ .quad 0x59b7596604dd3e8f+ .quad 0x6cb30377e288702c+ .quad 0xb1339c665ed9c323+ .quad 0x0915e76061bce52f+ .quad 0xe7c1f5d9c9a2911a+ .quad 0xb8a371788bcca7d7+ .quad 0x636412190eb62a32+ .quad 0x26907c5c2ecc4e95++ // 2^4 * 1 * B++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * B++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * B++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * B++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * B++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * B++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * B++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * B++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * B++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * B++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * B++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * B++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * B++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * B++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * B++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * B++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * B++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * B++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * B++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * B++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * B++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * B++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * B++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * B++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * B++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * B++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * B++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * B++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * B++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * B++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * B++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * B++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * B++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * B++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * B++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * B++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * B++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * B++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * B++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * B++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * B++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * B++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * B++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * B++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * B++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * B++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * B++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * B++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * B++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * B++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * B++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * B++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * B++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * B++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * B++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * B++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * B++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * B++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * B++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * B++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * B++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * B++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * B++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * B++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * B++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * B++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * B++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * B++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * B++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * B++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * B++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * B++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * B++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * B++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * B++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * B++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * B++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * B++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * B++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * B++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * B++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * B++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * B++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * B++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * B++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * B++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * B++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * B++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * B++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * B++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * B++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * B++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * B++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * B++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * B++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * B++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * B++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * B++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * B++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * B++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * B++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * B++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * B++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * B++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * B++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * B++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * B++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * B++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * B++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * B++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * B++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * B++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * B++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * B++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * B++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * B++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * B++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * B++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * B++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * B++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * B++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * B++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * B++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * B++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * B++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * B++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * B++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * B++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * B++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * B++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * B++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * B++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * B++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * B++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * B++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * B++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * B++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * B++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * B++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * B++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * B++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * B++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * B++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * B++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * B++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * B++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * B++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * B++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * B++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * B++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * B++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * B++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * B++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * B++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * B++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * B++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * B++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * B++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * B++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * B++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * B++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * B++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * B++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * B++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * B++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * B++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * B++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * B++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * B++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * B++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * B++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * B++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * B++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * B++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * B++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * B++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * B++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * B++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * B++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * B++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * B++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * B++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * B++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * B++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * B++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * B++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * B++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * B++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * B++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * B++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * B++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * B++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * B++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * B++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * B++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * B++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * B++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * B++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * B++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * B++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * B++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * B++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * B++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * B++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * B++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * B++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * B++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * B++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * B++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * B++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * B++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * B++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * B++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * B++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * B++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * B++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * B++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * B++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * B++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * B++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * B++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * B++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * B++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * B++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * B++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * B++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * B++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * B++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * B++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * B++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * B++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * B++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * B++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * B++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * B++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * B++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * B++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * B++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * B++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * B++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * B++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * B++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * B++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * B++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * B++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * B++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * B++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * B++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * B++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * B++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * B++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * B++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * B++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * B++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * B++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * B++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * B++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * B++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * B++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * B++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * B++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * B++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * B++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * B++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * B++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * B++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * B++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * B++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * B++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * B++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * B++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * B++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * B++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * B++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * B++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * B++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * B++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * B++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * B++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * B++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * B++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * B++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * B++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * B++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * B++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * B++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * B++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * B++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * B++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * B++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * B++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * B++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * B++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * B++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * B++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * B++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * B++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * B++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * B++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * B++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * B++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * B++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * B++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * B++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * B++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * B++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * B++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * B++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * B++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * B++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * B++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * B++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * B++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * B++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * B++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * B++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * B++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * B++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * B++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * B++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * B++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * B++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * B++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * B++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * B++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * B++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * B++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * B++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * B++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * B++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * B++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * B++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * B++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * B++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * B++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * B++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * B++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * B++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * B++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * B++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * B++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * B++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * B++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * B++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * B++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * B++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * B++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * B++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * B++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * B++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * B++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * B++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * B++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * B++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * B++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * B++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * B++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * B++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * B++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * B++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * B++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * B++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * B++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * B++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * B++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * B++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * B++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * B++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * B++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * B++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * B++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * B++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * B++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * B++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * B++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * B++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * B++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * B++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * B++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * B++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * B++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * B++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * B++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * B++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * B++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * B++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * B++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * B++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * B++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * B++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * B++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * B++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * B++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * B++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * B++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * B++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * B++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * B++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * B++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * B++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * B++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * B++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * B++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * B++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * B++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * B++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * B++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * B++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * B++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * B++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * B++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * B++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * B++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * B++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * B++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * B++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * B++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * B++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * B++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * B++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * B++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * B++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * B++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * B++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * B++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * B++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * B++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * B++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * B++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * B++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * B++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * B++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * B++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * B++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * B++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * B++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * B++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * B++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * B++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * B++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * B++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * B++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * B++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * B++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * B++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * B++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * B++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * B++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * B++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * B++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * B++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * B++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * B++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * B++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * B++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * B++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * B++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * B++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * B++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * B++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * B++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * B++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * B++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * B++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * B++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * B++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * B++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * B++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * B++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * B++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * B++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * B++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * B++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * B++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * B++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * B++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * B++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * B++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * B++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * B++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * B++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * B++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * B++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * B++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * B++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * B++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * B++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * B++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * B++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * B++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * B++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * B++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * B++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * B++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * B++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * B++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f
+ cbits/s2n/arm/p256_montjadd.S view
@@ -0,0 +1,3165 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjadd(uint64_t p3[static 12], const uint64_t p1[static 12],+// const uint64_t p2[static 12]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard ARM ABI: X0 = p3, X1 = p1, X2 = p2+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++// This is functionally equivalent to p256_montjadd in unopt/p256_montjadd.S.+// This is the result of doing the following sequence of optimizations:+// 1. Function inlining+// 2. Eliminating redundant load/store instructions+// 3. Folding (add addr, const) + load/store+// Function inlining is done manually. The second and third optimizations are+// done by a script.++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjadd)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjadd)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjadd)++ .text+ .balign 4++#define NUMSIZE 32+#define NSPACE NUMSIZE*7++S2N_BN_SYMBOL(p256_montjadd):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_PUSH2(x27,x30)+ CFI_DEC_SP(NSPACE)++ mov x21, x0+ mov x22, x1+ mov x23, x2+ mov x0, sp+ ldr q19, [x22, #64]+ ldp x9, x13, [x22, #64]+ ldr q23, [x22, #80]+ ldr q0, [x22, #64]+ ldp x1, x10, [x22, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x19, x3, x16, cs+ csel x14, x8, x14, cs+ csel x12, x11, x12, cs+ csel x20, x5, x2, cs+ stp x14, x12, [x0, #16]+ stp x19, x20, [x0]+ ldr q19, [x23, #64]+ ldp x9, x13, [x23, #64]+ ldr q23, [x23, #80]+ ldr q0, [x23, #64]+ ldp x1, x10, [x23, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs+ csel x14, x8, x14, cs+ csel x12, x11, x12, cs+ csel x2, x5, x2, cs+ stp x14, x12, [sp, #176]+ stp x16, x2, [sp, #160]+ ldr q20, [x22, #32]+ ldp x7, x17, [x23, #64]+ ldr q0, [x23, #64]+ ldp x6, x10, [x22, #32]+ ldp x11, x15, [x23, #80]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x22, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [x23, #80]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x22, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #192]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #208]+ ldr q20, [x23, #32]+ ldp x7, x17, [x22, #64]+ ldr q0, [x22, #64]+ ldp x6, x10, [x23, #32]+ ldp x11, x15, [x22, #80]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x23, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [x22, #80]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x23, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x24, x11, x13+ and x1, x1, x13+ adcs x25, x4, x1+ and x1, x12, x13+ stp x24, x25, [sp, #32]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #48]+ mov x1, sp+ ldr q20, [x23, #0]+ ldr q0, [x1]+ ldp x6, x10, [x23, #0]+ ldp x11, x15, [x1, #16]+ rev64 v16.4s, v20.4s+ subs x4, x19, x20+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x20, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x19+ ldr q20, [x23, #16]+ sbcs x5, x15, x20+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x19, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [x1, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x23, #16]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #64]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #80]+ ldr q20, [x22, #0]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [x22, #0]+ ldp x11, x15, [sp, #176]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x22, #16]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x22, #16]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #128]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #144]+ mov x1, sp+ ldr q20, [sp, #32]+ ldp x7, x17, [x1]+ ldr q0, [x1]+ ldp x11, x15, [x1, #16]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x25+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x24+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x25, x24+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [x1, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x24, x7+ sbcs x9, x25, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x24, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x25, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x24+ eor x1, x10, x5+ adcs x16, x2, x25+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x19, x11, x13+ and x1, x1, x13+ adcs x20, x4, x1+ and x1, x12, x13+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #48]+ ldr q20, [sp, #192]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [sp, #192]+ ldp x11, x15, [sp, #176]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #208]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #208]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x9, x11, x13+ and x1, x1, x13+ adcs x10, x4, x1+ and x1, x12, x13+ stp x9, x10, [sp, #192]+ adcs x11, x7, xzr+ adc x12, x17, x1+ stp x11, x12, [sp, #208]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x13, x5, x3+ and x4, x3, #0xffffffff+ adcs x24, x6, x4+ adcs x25, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x26, x8, x4+ stp x13, x24, [sp, #160]+ stp x25, x26, [sp, #176]+ subs x5, x19, x9+ sbcs x6, x20, x10+ ldp x7, x8, [sp, #48]+ sbcs x7, x7, x11+ sbcs x8, x8, x12+ csetm x3, cc+ adds x19, x5, x3+ and x4, x3, #0xffffffff+ adcs x20, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x19, x20, [sp, #32]+ stp x7, x8, [sp, #48]+ ldr q19, [sp, #160]+ ldr q23, [sp, #176]+ ldr q0, [sp, #160]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x13, x24+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x13, x24+ umulh x15, x13, x25+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x13, x24+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x26, x25+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x24, x26+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x25, x26+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x25, x26+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x26, x26+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x26, x26+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x25, x25+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x25, x25+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x24, x3, x16, cs+ csel x25, x8, x14, cs+ csel x26, x11, x12, cs+ csel x27, x5, x2, cs+ stp x25, x26, [sp, #112]+ stp x24, x27, [sp, #96]+ mov x0, sp+ ldr q19, [sp, #32]+ ldr q23, [sp, #48]+ ldr q0, [sp, #32]+ ldp x1, x10, [sp, #48]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x19, x20+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x19, x20+ umulh x15, x19, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x19, x20+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x20, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs+ csel x14, x8, x14, cs+ csel x12, x11, x12, cs+ csel x2, x5, x2, cs+ stp x14, x12, [x0, #16]+ stp x16, x2, [x0]+ ldr q20, [sp, #128]+ ldr q0, [sp, #96]+ ldp x6, x10, [sp, #128]+ rev64 v16.4s, v20.4s+ subs x4, x24, x27+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x27, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x25, x24+ ldr q20, [sp, #144]+ sbcs x5, x26, x27+ ngc x17, xzr+ subs x8, x25, x26+ uaddlp v27.2d, v16.4s+ umulh x4, x24, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #112]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #144]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x25, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x26, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x25+ eor x1, x10, x5+ adcs x16, x2, x26+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x19, x11, x13+ and x1, x1, x13+ adcs x20, x4, x1+ and x1, x12, x13+ stp x19, x20, [sp, #128]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #144]+ ldr q20, [sp, #64]+ ldr q0, [sp, #96]+ ldp x6, x10, [sp, #64]+ ldp x11, x15, [sp, #112]+ rev64 v16.4s, v20.4s+ subs x4, x24, x27+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x27, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x24+ ldr q20, [sp, #80]+ sbcs x5, x15, x27+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x24, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #112]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #80]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x9, x11, x13+ and x1, x1, x13+ adcs x10, x4, x1+ and x1, x12, x13+ stp x9, x10, [sp, #64]+ adcs x11, x7, xzr+ adc x12, x17, x1+ stp x11, x12, [sp, #80]+ mov x0, sp+ mov x1, sp+ ldp x5, x6, [x1]+ subs x5, x5, x19+ sbcs x6, x6, x20+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x24, x5, x3+ and x4, x3, #0xffffffff+ adcs x25, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x7, x8, [x0, #16]+ subs x5, x9, x19+ sbcs x6, x10, x20+ ldp x4, x3, [sp, #144]+ sbcs x7, x11, x4+ sbcs x8, x12, x3+ csetm x3, cc+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldr q20, [x22, #64]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [x22, #64]+ ldp x11, x15, [sp, #176]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x22, #80]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x22, #80]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #160]+ adcs x19, x7, xzr+ adc x20, x17, x1+ stp x19, x20, [sp, #176]+ mov x0, sp+ mov x1, sp+ ldp x4, x3, [sp, #64]+ subs x5, x24, x4+ sbcs x6, x25, x3+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [sp, #80]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x9, x5, x3+ and x4, x3, #0xffffffff+ adcs x10, x6, x4+ adcs x11, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x3, x8, x4+ stp x9, x10, [x0]+ stp x11, x3, [x0, #16]+ ldp x5, x6, [sp, #128]+ subs x5, x5, x9+ sbcs x6, x6, x10+ ldp x7, x8, [sp, #144]+ sbcs x7, x7, x11+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldr q20, [sp, #192]+ ldp x7, x17, [sp, #96]+ ldr q0, [sp, #96]+ ldp x6, x10, [sp, #192]+ ldp x11, x15, [sp, #112]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #208]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #112]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #208]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #96]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #112]+ ldr q20, [x23, #64]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [x23, #64]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x19, x7+ ldr q20, [x23, #80]+ sbcs x5, x20, x17+ ngc x17, xzr+ subs x8, x19, x20+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x23, #80]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x24, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x25, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x24+ eor x1, x10, x5+ adcs x16, x2, x25+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x19, x11, x13+ and x1, x1, x13+ adcs x20, x4, x1+ and x1, x12, x13+ stp x19, x20, [sp, #160]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #176]+ ldr q20, [sp, #128]+ ldp x7, x17, [sp, #32]+ ldr q0, [sp, #32]+ ldp x6, x10, [sp, #128]+ ldp x11, x15, [sp, #48]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #144]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #48]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #144]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x5, x11, x13+ and x1, x1, x13+ adcs x6, x4, x1+ and x1, x12, x13+ adcs x7, x7, xzr+ adc x9, x17, x1+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x9, x3+ csetm x3, cc+ adds x15, x5, x3+ and x4, x3, #0xffffffff+ adcs x24, x6, x4+ adcs x25, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x26, x8, x4+ stp x15, x24, [sp, #128]+ stp x25, x26, [sp, #144]+ ldp x0, x1, [x22, #64]+ ldp x2, x3, [x22, #80]+ orr x12, x0, x1+ orr x13, x2, x3+ orr x12, x12, x13+ cmp x12, xzr+ cset x12, ne+ ldp x4, x5, [x23, #64]+ ldp x6, x7, [x23, #80]+ orr x13, x4, x5+ orr x14, x6, x7+ orr x13, x13, x14+ cmp x13, xzr+ cset x13, ne+ cmp x13, x12+ csel x8, x0, x19, cc+ csel x9, x1, x20, cc+ csel x8, x4, x8, hi+ csel x9, x5, x9, hi+ ldp x10, x11, [sp, #176]+ csel x10, x2, x10, cc+ csel x11, x3, x11, cc+ csel x10, x6, x10, hi+ csel x11, x7, x11, hi+ ldp x12, x13, [x22]+ ldp x0, x1, [sp]+ csel x0, x12, x0, cc+ csel x1, x13, x1, cc+ ldp x12, x13, [x23]+ csel x0, x12, x0, hi+ csel x1, x13, x1, hi+ ldp x12, x13, [x22, #16]+ ldp x2, x3, [sp, #16]+ csel x2, x12, x2, cc+ csel x3, x13, x3, cc+ ldp x12, x13, [x23, #16]+ csel x2, x12, x2, hi+ csel x3, x13, x3, hi+ ldp x12, x13, [x22, #32]+ csel x4, x12, x15, cc+ csel x5, x13, x24, cc+ ldp x12, x13, [x23, #32]+ csel x4, x12, x4, hi+ csel x5, x13, x5, hi+ ldp x12, x13, [x22, #48]+ csel x6, x12, x25, cc+ csel x7, x13, x26, cc+ ldp x12, x13, [x23, #48]+ csel x6, x12, x6, hi+ csel x7, x13, x7, hi+ stp x0, x1, [x21]+ stp x2, x3, [x21, #16]+ stp x4, x5, [x21, #32]+ stp x6, x7, [x21, #48]+ stp x8, x9, [x21, #64]+ stp x10, x11, [x21, #80]++ CFI_INC_SP(NSPACE)+ CFI_POP2(x27,x30)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_montjadd_alt.S view
@@ -0,0 +1,555 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjadd_alt(uint64_t p3[static 12],+// const uint64_t p1[static 12],+// const uint64_t p2[static 12]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard ARM ABI: X0 = p3, X1 = p1, X2 = p2+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjadd_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjadd_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjadd_alt)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable homes for input arguments during main code sequence++#define input_z x15+#define input_x x16+#define input_y x17++// Pointer-offset pairs for inputs and outputs++#define x_1 input_x, #0+#define y_1 input_x, #NUMSIZE+#define z_1 input_x, #(2*NUMSIZE)++#define x_2 input_y, #0+#define y_2 input_y, #NUMSIZE+#define z_2 input_y, #(2*NUMSIZE)++#define x_3 input_z, #0+#define y_3 input_z, #NUMSIZE+#define z_3 input_z, #(2*NUMSIZE)++// Pointer-offset pairs for temporaries, with some aliasing+// #NSPACE is the total stack needed for these temporaries++#define z1sq sp, #(NUMSIZE*0)+#define ww sp, #(NUMSIZE*0)+#define resx sp, #(NUMSIZE*0)++#define yd sp, #(NUMSIZE*1)+#define y2a sp, #(NUMSIZE*1)++#define x2a sp, #(NUMSIZE*2)+#define zzx2 sp, #(NUMSIZE*2)++#define zz sp, #(NUMSIZE*3)+#define t1 sp, #(NUMSIZE*3)++#define t2 sp, #(NUMSIZE*4)+#define x1a sp, #(NUMSIZE*4)+#define zzx1 sp, #(NUMSIZE*4)+#define resy sp, #(NUMSIZE*4)++#define xd sp, #(NUMSIZE*5)+#define z2sq sp, #(NUMSIZE*5)+#define resz sp, #(NUMSIZE*5)++#define y1a sp, #(NUMSIZE*6)++#define NSPACE NUMSIZE*7++// Corresponds to bignum_montmul_p256_alt except registers++#define montmul_p256(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x0, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x1, x3, x10 __LF \+ adcs x0, x0, x11 __LF \+ adc x1, x1, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x1, x1, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x0, x0, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x1, x1, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x1, x1, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x0, x0, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x1, x1, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x0, x0, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x1, x1, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ mov x10, #0xffffffff00000001 __LF \+ adds x13, x13, x12, lsl #32 __LF \+ lsr x11, x12, #32 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x12, x10 __LF \+ umulh x12, x12, x10 __LF \+ adcs x0, x0, x11 __LF \+ adc x12, x12, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x1, x1, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ adds x14, x14, x13, lsl #32 __LF \+ lsr x11, x13, #32 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x13, x10 __LF \+ umulh x13, x13, x10 __LF \+ adcs x12, x12, x11 __LF \+ adc x13, x13, xzr __LF \+ adds x0, x0, x14, lsl #32 __LF \+ lsr x11, x14, #32 __LF \+ adcs x12, x12, x11 __LF \+ mul x11, x14, x10 __LF \+ umulh x14, x14, x10 __LF \+ adcs x13, x13, x11 __LF \+ adc x14, x14, xzr __LF \+ adds x12, x12, x0, lsl #32 __LF \+ lsr x11, x0, #32 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x0, x10 __LF \+ umulh x0, x0, x10 __LF \+ adcs x14, x14, x11 __LF \+ adc x0, x0, xzr __LF \+ adds x12, x12, x1 __LF \+ adcs x13, x13, x3 __LF \+ adcs x14, x14, x4 __LF \+ adcs x0, x0, x5 __LF \+ cset x8, cs __LF \+ mov x11, #0xffffffff __LF \+ adds x1, x12, #0x1 __LF \+ sbcs x3, x13, x11 __LF \+ sbcs x4, x14, xzr __LF \+ sbcs x5, x0, x10 __LF \+ sbcs xzr, x8, xzr __LF \+ csel x12, x12, x1, cc __LF \+ csel x13, x13, x3, cc __LF \+ csel x14, x14, x4, cc __LF \+ csel x0, x0, x5, cc __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x0, [P0+16]++// Corresponds exactly to bignum_montsqr_p256_alt++#define montsqr_p256(P0,P1) \+ ldp x2, x3, [P1] __LF \+ mul x9, x2, x3 __LF \+ umulh x10, x2, x3 __LF \+ ldp x4, x5, [P1+16] __LF \+ mul x11, x2, x5 __LF \+ umulh x12, x2, x5 __LF \+ mul x6, x2, x4 __LF \+ umulh x7, x2, x4 __LF \+ adds x10, x10, x6 __LF \+ adcs x11, x11, x7 __LF \+ mul x6, x3, x4 __LF \+ umulh x7, x3, x4 __LF \+ adc x7, x7, xzr __LF \+ adds x11, x11, x6 __LF \+ mul x13, x4, x5 __LF \+ umulh x14, x4, x5 __LF \+ adcs x12, x12, x7 __LF \+ mul x6, x3, x5 __LF \+ umulh x7, x3, x5 __LF \+ adc x7, x7, xzr __LF \+ adds x12, x12, x6 __LF \+ adcs x13, x13, x7 __LF \+ adc x14, x14, xzr __LF \+ adds x9, x9, x9 __LF \+ adcs x10, x10, x10 __LF \+ adcs x11, x11, x11 __LF \+ adcs x12, x12, x12 __LF \+ adcs x13, x13, x13 __LF \+ adcs x14, x14, x14 __LF \+ cset x7, cs __LF \+ umulh x6, x2, x2 __LF \+ mul x8, x2, x2 __LF \+ adds x9, x9, x6 __LF \+ mul x6, x3, x3 __LF \+ adcs x10, x10, x6 __LF \+ umulh x6, x3, x3 __LF \+ adcs x11, x11, x6 __LF \+ mul x6, x4, x4 __LF \+ adcs x12, x12, x6 __LF \+ umulh x6, x4, x4 __LF \+ adcs x13, x13, x6 __LF \+ mul x6, x5, x5 __LF \+ adcs x14, x14, x6 __LF \+ umulh x6, x5, x5 __LF \+ adc x7, x7, x6 __LF \+ adds x9, x9, x8, lsl #32 __LF \+ lsr x3, x8, #32 __LF \+ adcs x10, x10, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x8, x3 __LF \+ umulh x8, x8, x3 __LF \+ adcs x11, x11, x2 __LF \+ adc x8, x8, xzr __LF \+ adds x10, x10, x9, lsl #32 __LF \+ lsr x3, x9, #32 __LF \+ adcs x11, x11, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x9, x3 __LF \+ umulh x9, x9, x3 __LF \+ adcs x8, x8, x2 __LF \+ adc x9, x9, xzr __LF \+ adds x11, x11, x10, lsl #32 __LF \+ lsr x3, x10, #32 __LF \+ adcs x8, x8, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x10, x3 __LF \+ umulh x10, x10, x3 __LF \+ adcs x9, x9, x2 __LF \+ adc x10, x10, xzr __LF \+ adds x8, x8, x11, lsl #32 __LF \+ lsr x3, x11, #32 __LF \+ adcs x9, x9, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x11, x3 __LF \+ umulh x11, x11, x3 __LF \+ adcs x10, x10, x2 __LF \+ adc x11, x11, xzr __LF \+ adds x8, x8, x12 __LF \+ adcs x9, x9, x13 __LF \+ adcs x10, x10, x14 __LF \+ adcs x11, x11, x7 __LF \+ cset x2, cs __LF \+ mov x3, #0xffffffff __LF \+ mov x5, #0xffffffff00000001 __LF \+ adds x12, x8, #0x1 __LF \+ sbcs x13, x9, x3 __LF \+ sbcs x14, x10, xzr __LF \+ sbcs x7, x11, x5 __LF \+ sbcs xzr, x2, xzr __LF \+ csel x8, x8, x12, cc __LF \+ csel x9, x9, x13, cc __LF \+ csel x10, x10, x14, cc __LF \+ csel x11, x11, x7, cc __LF \+ stp x8, x9, [P0] __LF \+ stp x10, x11, [P0+16]++// Almost-Montgomery variant which we use when an input to other muls+// with the other argument fully reduced (which is always safe).++#define amontsqr_p256(P0,P1) \+ ldp x2, x3, [P1] __LF \+ mul x9, x2, x3 __LF \+ umulh x10, x2, x3 __LF \+ ldp x4, x5, [P1+16] __LF \+ mul x11, x2, x5 __LF \+ umulh x12, x2, x5 __LF \+ mul x6, x2, x4 __LF \+ umulh x7, x2, x4 __LF \+ adds x10, x10, x6 __LF \+ adcs x11, x11, x7 __LF \+ mul x6, x3, x4 __LF \+ umulh x7, x3, x4 __LF \+ adc x7, x7, xzr __LF \+ adds x11, x11, x6 __LF \+ mul x13, x4, x5 __LF \+ umulh x14, x4, x5 __LF \+ adcs x12, x12, x7 __LF \+ mul x6, x3, x5 __LF \+ umulh x7, x3, x5 __LF \+ adc x7, x7, xzr __LF \+ adds x12, x12, x6 __LF \+ adcs x13, x13, x7 __LF \+ adc x14, x14, xzr __LF \+ adds x9, x9, x9 __LF \+ adcs x10, x10, x10 __LF \+ adcs x11, x11, x11 __LF \+ adcs x12, x12, x12 __LF \+ adcs x13, x13, x13 __LF \+ adcs x14, x14, x14 __LF \+ cset x7, cs __LF \+ umulh x6, x2, x2 __LF \+ mul x8, x2, x2 __LF \+ adds x9, x9, x6 __LF \+ mul x6, x3, x3 __LF \+ adcs x10, x10, x6 __LF \+ umulh x6, x3, x3 __LF \+ adcs x11, x11, x6 __LF \+ mul x6, x4, x4 __LF \+ adcs x12, x12, x6 __LF \+ umulh x6, x4, x4 __LF \+ adcs x13, x13, x6 __LF \+ mul x6, x5, x5 __LF \+ adcs x14, x14, x6 __LF \+ umulh x6, x5, x5 __LF \+ adc x7, x7, x6 __LF \+ adds x9, x9, x8, lsl #32 __LF \+ lsr x3, x8, #32 __LF \+ adcs x10, x10, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x8, x3 __LF \+ umulh x8, x8, x3 __LF \+ adcs x11, x11, x2 __LF \+ adc x8, x8, xzr __LF \+ adds x10, x10, x9, lsl #32 __LF \+ lsr x3, x9, #32 __LF \+ adcs x11, x11, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x9, x3 __LF \+ umulh x9, x9, x3 __LF \+ adcs x8, x8, x2 __LF \+ adc x9, x9, xzr __LF \+ adds x11, x11, x10, lsl #32 __LF \+ lsr x3, x10, #32 __LF \+ adcs x8, x8, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x10, x3 __LF \+ umulh x10, x10, x3 __LF \+ adcs x9, x9, x2 __LF \+ adc x10, x10, xzr __LF \+ adds x8, x8, x11, lsl #32 __LF \+ lsr x3, x11, #32 __LF \+ adcs x9, x9, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x11, x3 __LF \+ umulh x11, x11, x3 __LF \+ adcs x10, x10, x2 __LF \+ adc x11, x11, xzr __LF \+ adds x8, x8, x12 __LF \+ adcs x9, x9, x13 __LF \+ adcs x10, x10, x14 __LF \+ adcs x11, x11, x7 __LF \+ mov x2, #0xffffffffffffffff __LF \+ csel x2, xzr, x2, cc __LF \+ mov x3, #0xffffffff __LF \+ csel x3, xzr, x3, cc __LF \+ mov x5, #0xffffffff00000001 __LF \+ csel x5, xzr, x5, cc __LF \+ subs x8, x8, x2 __LF \+ sbcs x9, x9, x3 __LF \+ sbcs x10, x10, xzr __LF \+ sbc x11, x11, x5 __LF \+ stp x8, x9, [P0] __LF \+ stp x10, x11, [P0+16]++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ csetm x3, cc __LF \+ adds x5, x5, x3 __LF \+ mov x4, #0xffffffff __LF \+ and x4, x4, x3 __LF \+ adcs x6, x6, x4 __LF \+ adcs x7, x7, xzr __LF \+ mov x4, #0xffffffff00000001 __LF \+ and x4, x4, x3 __LF \+ adc x8, x8, x4 __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++S2N_BN_SYMBOL(p256_montjadd_alt):+ CFI_START++// Make room on stack for temporary variables+// Move the input arguments to stable places++ CFI_DEC_SP(NSPACE)++ mov input_z, x0+ mov input_x, x1+ mov input_y, x2++// Main code, just a sequence of basic field operations+// 12 * multiply + 4 * square + 7 * subtract++ amontsqr_p256(z1sq,z_1)+ amontsqr_p256(z2sq,z_2)++ montmul_p256(y1a,z_2,y_1)+ montmul_p256(y2a,z_1,y_2)++ montmul_p256(x2a,z1sq,x_2)+ montmul_p256(x1a,z2sq,x_1)+ montmul_p256(y2a,z1sq,y2a)+ montmul_p256(y1a,z2sq,y1a)++ sub_p256(xd,x2a,x1a)+ sub_p256(yd,y2a,y1a)++ amontsqr_p256(zz,xd)+ montsqr_p256(ww,yd)++ montmul_p256(zzx1,zz,x1a)+ montmul_p256(zzx2,zz,x2a)++ sub_p256(resx,ww,zzx1)+ sub_p256(t1,zzx2,zzx1)++ montmul_p256(xd,xd,z_1)++ sub_p256(resx,resx,zzx2)++ sub_p256(t2,zzx1,resx)++ montmul_p256(t1,t1,y1a)+ montmul_p256(resz,xd,z_2)+ montmul_p256(t2,yd,t2)++ sub_p256(resy,t2,t1)++// Load in the z coordinates of the inputs to check for P1 = 0 and P2 = 0+// The condition codes get set by a comparison (P2 != 0) - (P1 != 0)+// So "HI" <=> CF /\ ~ZF <=> P1 = 0 /\ ~(P2 = 0)+// and "LO" <=> ~CF <=> ~(P1 = 0) /\ P2 = 0++ ldp x0, x1, [z_1]+ ldp x2, x3, [z_1+16]++ orr x12, x0, x1+ orr x13, x2, x3+ orr x12, x12, x13+ cmp x12, xzr+ cset x12, ne++ ldp x4, x5, [z_2]+ ldp x6, x7, [z_2+16]++ orr x13, x4, x5+ orr x14, x6, x7+ orr x13, x13, x14+ cmp x13, xzr+ cset x13, ne++ cmp x13, x12++// Multiplex the outputs accordingly, re-using the z's in registers++ ldp x8, x9, [resz]+ csel x8, x0, x8, lo+ csel x9, x1, x9, lo+ csel x8, x4, x8, hi+ csel x9, x5, x9, hi+ ldp x10, x11, [resz+16]+ csel x10, x2, x10, lo+ csel x11, x3, x11, lo+ csel x10, x6, x10, hi+ csel x11, x7, x11, hi++ ldp x12, x13, [x_1]+ ldp x0, x1, [resx]+ csel x0, x12, x0, lo+ csel x1, x13, x1, lo+ ldp x12, x13, [x_2]+ csel x0, x12, x0, hi+ csel x1, x13, x1, hi++ ldp x12, x13, [x_1+16]+ ldp x2, x3, [resx+16]+ csel x2, x12, x2, lo+ csel x3, x13, x3, lo+ ldp x12, x13, [x_2+16]+ csel x2, x12, x2, hi+ csel x3, x13, x3, hi++ ldp x12, x13, [y_1]+ ldp x4, x5, [resy]+ csel x4, x12, x4, lo+ csel x5, x13, x5, lo+ ldp x12, x13, [y_2]+ csel x4, x12, x4, hi+ csel x5, x13, x5, hi++ ldp x12, x13, [y_1+16]+ ldp x6, x7, [resy+16]+ csel x6, x12, x6, lo+ csel x7, x13, x7, lo+ ldp x12, x13, [y_2+16]+ csel x6, x12, x6, hi+ csel x7, x13, x7, hi++// Finally store back the multiplexed values++ stp x0, x1, [x_3]+ stp x2, x3, [x_3+16]+ stp x4, x5, [y_3]+ stp x6, x7, [y_3+16]+ stp x8, x9, [z_3]+ stp x10, x11, [z_3+16]++// Restore registers and return++ CFI_INC_SP(NSPACE)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjadd_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_montjdouble.S view
@@ -0,0 +1,1555 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point doubling on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjdouble(uint64_t p3[static 12],+// const uint64_t p1[static 12]);+//+// Does p3 := 2 * p1 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard ARM ABI: X0 = p3, X1 = p1+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++// This is functionally equivalent to p256_montjdouble in unopt/p256_montjdouble.S.+// This is the result of doing the following sequence of optimizations:+// 1. Function inlining+// 2. Eliminating redundant load/store instructions+// 3. Folding (add addr, const) + load/store+// Function inlining is done manually. The second and third optimizations are+// done by a script.++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjdouble)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjdouble)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjdouble)+ .text+ .balign 4++#define NUMSIZE 32+#define NSPACE NUMSIZE*6++S2N_BN_SYMBOL(p256_montjdouble):+ CFI_START++ CFI_DEC_SP(NSPACE+80)+ CFI_STACKSAVE2(x19,x20,NSPACE)+ CFI_STACKSAVE2(x21,x22,NSPACE+16)+ CFI_STACKSAVE2(x23,x24,NSPACE+32)+ CFI_STACKSAVE2(x25,x26,NSPACE+48)+ CFI_STACKSAVE1Z(x27,NSPACE+64)++ mov x19, x0+ mov x20, x1+ mov x0, sp+ ldr q19, [x20, #64]+ ldp x9, x13, [x20, #64]+ ldr q23, [x20, #80]+ ldr q0, [x20, #64]+ ldp x1, x10, [x20, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x21, x3, x16, cs+ csel x22, x8, x14, cs+ csel x23, x11, x12, cs+ csel x24, x5, x2, cs+ stp x22, x23, [x0, #16]+ stp x21, x24, [x0]+ ldr q19, [x20, #32]+ ldp x9, x13, [x20, #32]+ ldr q23, [x20, #48]+ ldr q0, [x20, #32]+ ldp x1, x10, [x20, #48]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs+ csel x14, x8, x14, cs+ csel x12, x11, x12, cs+ csel x2, x5, x2, cs+ stp x14, x12, [sp, #48]+ stp x16, x2, [sp, #32]+ ldp x5, x6, [x20, #0]+ subs x5, x5, x21+ sbcs x6, x6, x24+ ldp x7, x8, [x20, #16]+ sbcs x7, x7, x22+ sbcs x8, x8, x23+ csetm x3, cc+ adds x10, x5, x3+ and x4, x3, #0xffffffff+ adcs x25, x6, x4+ adcs x26, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x27, x8, x4+ stp x10, x25, [sp, #96]+ stp x26, x27, [sp, #112]+ ldp x5, x6, [x20]+ adds x5, x5, x21+ adcs x6, x6, x24+ ldp x7, x8, [x20, #16]+ adcs x7, x7, x22+ adcs x8, x8, x23+ csetm x3, cs+ subs x9, x5, x3+ and x1, x3, #0xffffffff+ sbcs x5, x6, x1+ sbcs x7, x7, xzr+ and x2, x3, #0xffffffff00000001+ sbc x8, x8, x2+ stp x9, x5, [sp, #64]+ stp x7, x8, [sp, #80]+ ldr q20, [sp, #96]+ ldr q0, [sp, #64]+ rev64 v16.4s, v20.4s+ subs x4, x9, x5+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x5, x25+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x7, x9+ ldr q20, [sp, #112]+ sbcs x5, x8, x5+ ngc x17, xzr+ subs x8, x7, x8+ uaddlp v27.2d, v16.4s+ umulh x4, x9, x10+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x25, x10+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #80]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x10, x26+ sbcs x9, x25, x27+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x27, x26+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x21, x3, x13+ adcs x22, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x23, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x24, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x21+ adcs x15, x16, x22+ eor x5, x17, x4+ adcs x9, x1, x23+ eor x1, x10, x5+ adcs x16, x2, x24+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x21, x11, x13+ and x1, x1, x13+ adcs x22, x4, x1+ and x1, x12, x13+ stp x21, x22, [sp, #96]+ adcs x23, x7, xzr+ adc x24, x17, x1+ stp x23, x24, [sp, #112]+ ldp x4, x5, [x20, #32]+ ldp x8, x9, [x20, #64]+ adds x4, x4, x8+ adcs x5, x5, x9+ ldp x6, x7, [x20, #48]+ ldp x10, x11, [x20, #80]+ adcs x6, x6, x10+ adcs x7, x7, x11+ adc x3, xzr, xzr+ adds x8, x4, #0x1+ mov x9, #0xffffffff+ sbcs x9, x5, x9+ sbcs x10, x6, xzr+ mov x11, #0xffffffff00000001+ sbcs x11, x7, x11+ sbcs x3, x3, xzr+ csel x4, x4, x8, cc+ csel x5, x5, x9, cc+ csel x6, x6, x10, cc+ csel x7, x7, x11, cc+ stp x4, x5, [sp, #64]+ stp x6, x7, [sp, #80]+ ldr q20, [sp, #32]+ ldp x7, x17, [x20, #0]+ ldr q0, [x20, #0]+ ldp x6, x10, [sp, #32]+ ldp x11, x15, [x20, #16]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [x20, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x20, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x20+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x20, x11, x13+ and x1, x1, x13+ adcs x25, x4, x1+ and x1, x12, x13+ stp x20, x25, [sp, #128]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #144]+ ldr q19, [sp, #96]+ ldr q23, [sp, #112]+ ldr q0, [sp, #96]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x21, x22+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x21, x22+ umulh x15, x21, x23+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x21, x22+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x24, x23+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x22, x24+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x23, x24+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x23, x24+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x24, x24+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x24, x24+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x23, x23+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x23, x23+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x21, x3, x16, cs+ csel x22, x8, x14, cs+ csel x23, x11, x12, cs+ csel x24, x5, x2, cs+ ldr q19, [sp, #64]+ ldp x9, x13, [sp, #64]+ ldr q23, [sp, #80]+ ldr q0, [sp, #64]+ ldp x1, x10, [sp, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x13, x3, x16, cs+ csel x14, x8, x14, cs+ csel x15, x11, x12, cs+ csel x26, x5, x2, cs+ mov x1, #0x9+ mov x2, #0xffffffffffffffff+ subs x9, x2, x21+ mov x2, #0xffffffff+ sbcs x10, x2, x24+ ngcs x11, x22+ mov x2, #0xffffffff00000001+ sbc x12, x2, x23+ mul x3, x1, x9+ mul x4, x1, x10+ mul x5, x1, x11+ mul x6, x1, x12+ umulh x9, x1, x9+ umulh x10, x1, x10+ umulh x11, x1, x11+ umulh x7, x1, x12+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, xzr+ mov x1, #0xc+ mul x8, x20, x1+ umulh x9, x20, x1+ adds x3, x3, x8+ mul x8, x25, x1+ umulh x10, x25, x1+ adcs x4, x4, x8+ ldp x11, x12, [sp, #144]+ mul x8, x11, x1+ umulh x11, x11, x1+ adcs x5, x5, x8+ mul x8, x12, x1+ umulh x12, x12, x1+ adcs x6, x6, x8+ adc x7, x7, xzr+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, x12+ add x8, x7, #0x1+ lsl x10, x8, #32+ adds x6, x6, x10+ adc x7, x7, xzr+ neg x9, x8+ sub x10, x10, #0x1+ subs x3, x3, x9+ sbcs x4, x4, x10+ sbcs x5, x5, xzr+ sbcs x6, x6, x8+ sbc x8, x7, x8+ adds x20, x3, x8+ and x9, x8, #0xffffffff+ adcs x21, x4, x9+ adcs x22, x5, xzr+ neg x10, x9+ adc x23, x6, x10+ stp x20, x21, [sp, #160]+ stp x22, x23, [sp, #176]+ mov x2, sp+ ldp x4, x3, [x2]+ subs x5, x13, x4+ sbcs x6, x26, x3+ ldp x4, x3, [x2, #16]+ sbcs x7, x14, x4+ sbcs x8, x15, x3+ csetm x3, cc+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #64]+ stp x7, x8, [sp, #80]+ mov x0, sp+ ldr q19, [sp, #32]+ ldp x9, x13, [sp, #32]+ ldr q23, [sp, #48]+ ldr q0, [sp, #32]+ ldp x1, x10, [sp, #48]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x24, x3, x16, cs+ csel x25, x8, x14, cs+ csel x26, x11, x12, cs+ csel x27, x5, x2, cs+ stp x25, x26, [x0, #16]+ stp x24, x27, [x0]+ ldr q20, [sp, #96]+ ldr q0, [sp, #160]+ ldp x6, x10, [sp, #96]+ rev64 v16.4s, v20.4s+ subs x4, x20, x21+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x21, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x22, x20+ ldr q20, [sp, #112]+ sbcs x5, x23, x21+ ngc x17, xzr+ subs x8, x22, x23+ uaddlp v27.2d, v16.4s+ umulh x4, x20, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc+ shl v17.2d, v27.2d, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #112]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x20, x3, x13+ adcs x21, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x22, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x23, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x20+ adcs x15, x16, x21+ eor x5, x17, x4+ adcs x9, x1, x22+ eor x1, x10, x5+ adcs x16, x2, x23+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x14, x11, x13+ and x1, x1, x13+ adcs x15, x4, x1+ and x1, x12, x13+ stp x14, x15, [sp, #96]+ adcs x13, x7, xzr+ adc x20, x17, x1+ stp x13, x20, [sp, #112]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #32]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #48]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [x19, #64]+ stp x7, x8, [x19, #80]+ ldp x1, x2, [sp, #128]+ lsl x0, x1, #2+ ldp x6, x7, [sp, #160]+ subs x0, x0, x6+ extr x1, x2, x1, #62+ sbcs x1, x1, x7+ ldp x3, x4, [sp, #144]+ extr x2, x3, x2, #62+ ldp x6, x7, [sp, #176]+ sbcs x2, x2, x6+ extr x3, x4, x3, #62+ sbcs x3, x3, x7+ lsr x4, x4, #62+ sbc x4, x4, xzr+ add x5, x4, #0x1+ lsl x8, x5, #32+ negs x6, x8+ ngcs x7, xzr+ sbc x8, x8, x5+ adds x0, x0, x5+ adcs x1, x1, x6+ adcs x2, x2, x7+ adcs x3, x3, x8+ csetm x5, cc+ adds x0, x0, x5+ and x6, x5, #0xffffffff+ adcs x1, x1, x6+ adcs x2, x2, xzr+ neg x7, x6+ adc x3, x3, x7+ stp x0, x1, [x19]+ stp x2, x3, [x19, #16]+ mov x2, #0xffffffffffffffff+ subs x9, x2, x24+ mov x2, #0xffffffff+ sbcs x10, x2, x27+ ngcs x11, x25+ mov x2, #0xffffffff00000001+ sbc x12, x2, x26+ lsl x3, x9, #3+ extr x4, x10, x9, #61+ extr x5, x11, x10, #61+ extr x6, x12, x11, #61+ lsr x7, x12, #61+ mov x1, #0x3+ mul x8, x14, x1+ umulh x9, x14, x1+ adds x3, x3, x8+ mul x8, x15, x1+ umulh x10, x15, x1+ adcs x4, x4, x8+ mul x8, x13, x1+ umulh x11, x13, x1+ adcs x5, x5, x8+ mul x8, x20, x1+ umulh x12, x20, x1+ adcs x6, x6, x8+ adc x7, x7, xzr+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, x12+ add x8, x7, #0x1+ lsl x10, x8, #32+ adds x6, x6, x10+ adc x7, x7, xzr+ neg x9, x8+ sub x10, x10, #0x1+ subs x3, x3, x9+ sbcs x4, x4, x10+ sbcs x5, x5, xzr+ sbcs x6, x6, x8+ sbc x8, x7, x8+ adds x3, x3, x8+ and x9, x8, #0xffffffff+ adcs x4, x4, x9+ adcs x5, x5, xzr+ neg x10, x9+ adc x6, x6, x10+ stp x3, x4, [x19, #32]+ stp x5, x6, [x19, #48]++ CFI_STACKLOAD1Z(x27,NSPACE+64)+ CFI_STACKLOAD2(x25,x26,NSPACE+48)+ CFI_STACKLOAD2(x23,x24,NSPACE+32)+ CFI_STACKLOAD2(x21,x22,NSPACE+16)+ CFI_STACKLOAD2(x19,x20,NSPACE)+ CFI_INC_SP((NSPACE+80))+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjdouble)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_montjdouble_alt.S view
@@ -0,0 +1,587 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point doubling on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjdouble_alt(uint64_t p3[static 12],+// const uint64_t p1[static 12]);+//+// Does p3 := 2 * p1 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard ARM ABI: X0 = p3, X1 = p1+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjdouble_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjdouble_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjdouble_alt)+ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable homes for input arguments during main code sequence++#define input_z x15+#define input_x x16++// Pointer-offset pairs for inputs and outputs++#define x_1 input_x, #0+#define y_1 input_x, #NUMSIZE+#define z_1 input_x, #(2*NUMSIZE)++#define x_3 input_z, #0+#define y_3 input_z, #NUMSIZE+#define z_3 input_z, #(2*NUMSIZE)++// Pointer-offset pairs for temporaries, with some aliasing+// #NSPACE is the total stack needed for these temporaries++#define z2 sp, #(NUMSIZE*0)+#define y4 sp, #(NUMSIZE*0)++#define y2 sp, #(NUMSIZE*1)++#define t1 sp, #(NUMSIZE*2)++#define t2 sp, #(NUMSIZE*3)+#define x2p sp, #(NUMSIZE*3)+#define dx2 sp, #(NUMSIZE*3)++#define xy2 sp, #(NUMSIZE*4)++#define x4p sp, #(NUMSIZE*5)+#define d sp, #(NUMSIZE*5)++#define NSPACE NUMSIZE*6++// Corresponds exactly to bignum_montmul_p256_alt except registers++#define montmul_p256(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x0, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x1, x3, x10 __LF \+ adcs x0, x0, x11 __LF \+ adc x1, x1, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x1, x1, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x0, x0, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x1, x1, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x1, x1, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x0, x0, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x1, x1, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x0, x0, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x1, x1, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ mov x10, #0xffffffff00000001 __LF \+ adds x13, x13, x12, lsl #32 __LF \+ lsr x11, x12, #32 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x12, x10 __LF \+ umulh x12, x12, x10 __LF \+ adcs x0, x0, x11 __LF \+ adc x12, x12, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x1, x1, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ adds x14, x14, x13, lsl #32 __LF \+ lsr x11, x13, #32 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x13, x10 __LF \+ umulh x13, x13, x10 __LF \+ adcs x12, x12, x11 __LF \+ adc x13, x13, xzr __LF \+ adds x0, x0, x14, lsl #32 __LF \+ lsr x11, x14, #32 __LF \+ adcs x12, x12, x11 __LF \+ mul x11, x14, x10 __LF \+ umulh x14, x14, x10 __LF \+ adcs x13, x13, x11 __LF \+ adc x14, x14, xzr __LF \+ adds x12, x12, x0, lsl #32 __LF \+ lsr x11, x0, #32 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x0, x10 __LF \+ umulh x0, x0, x10 __LF \+ adcs x14, x14, x11 __LF \+ adc x0, x0, xzr __LF \+ adds x12, x12, x1 __LF \+ adcs x13, x13, x3 __LF \+ adcs x14, x14, x4 __LF \+ adcs x0, x0, x5 __LF \+ cset x8, cs __LF \+ mov x11, #0xffffffff __LF \+ adds x1, x12, #0x1 __LF \+ sbcs x3, x13, x11 __LF \+ sbcs x4, x14, xzr __LF \+ sbcs x5, x0, x10 __LF \+ sbcs xzr, x8, xzr __LF \+ csel x12, x12, x1, cc __LF \+ csel x13, x13, x3, cc __LF \+ csel x14, x14, x4, cc __LF \+ csel x0, x0, x5, cc __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x0, [P0+16]++// Corresponds exactly to bignum_montsqr_p256_alt++#define montsqr_p256(P0,P1) \+ ldp x2, x3, [P1] __LF \+ mul x9, x2, x3 __LF \+ umulh x10, x2, x3 __LF \+ ldp x4, x5, [P1+16] __LF \+ mul x11, x2, x5 __LF \+ umulh x12, x2, x5 __LF \+ mul x6, x2, x4 __LF \+ umulh x7, x2, x4 __LF \+ adds x10, x10, x6 __LF \+ adcs x11, x11, x7 __LF \+ mul x6, x3, x4 __LF \+ umulh x7, x3, x4 __LF \+ adc x7, x7, xzr __LF \+ adds x11, x11, x6 __LF \+ mul x13, x4, x5 __LF \+ umulh x14, x4, x5 __LF \+ adcs x12, x12, x7 __LF \+ mul x6, x3, x5 __LF \+ umulh x7, x3, x5 __LF \+ adc x7, x7, xzr __LF \+ adds x12, x12, x6 __LF \+ adcs x13, x13, x7 __LF \+ adc x14, x14, xzr __LF \+ adds x9, x9, x9 __LF \+ adcs x10, x10, x10 __LF \+ adcs x11, x11, x11 __LF \+ adcs x12, x12, x12 __LF \+ adcs x13, x13, x13 __LF \+ adcs x14, x14, x14 __LF \+ cset x7, hs __LF \+ umulh x6, x2, x2 __LF \+ mul x8, x2, x2 __LF \+ adds x9, x9, x6 __LF \+ mul x6, x3, x3 __LF \+ adcs x10, x10, x6 __LF \+ umulh x6, x3, x3 __LF \+ adcs x11, x11, x6 __LF \+ mul x6, x4, x4 __LF \+ adcs x12, x12, x6 __LF \+ umulh x6, x4, x4 __LF \+ adcs x13, x13, x6 __LF \+ mul x6, x5, x5 __LF \+ adcs x14, x14, x6 __LF \+ umulh x6, x5, x5 __LF \+ adc x7, x7, x6 __LF \+ mov x5, #-4294967295 __LF \+ adds x9, x9, x8, lsl #32 __LF \+ lsr x3, x8, #32 __LF \+ adcs x10, x10, x3 __LF \+ mul x2, x8, x5 __LF \+ umulh x8, x8, x5 __LF \+ adcs x11, x11, x2 __LF \+ adc x8, x8, xzr __LF \+ adds x10, x10, x9, lsl #32 __LF \+ lsr x3, x9, #32 __LF \+ adcs x11, x11, x3 __LF \+ mul x2, x9, x5 __LF \+ umulh x9, x9, x5 __LF \+ adcs x8, x8, x2 __LF \+ adc x9, x9, xzr __LF \+ adds x11, x11, x10, lsl #32 __LF \+ lsr x3, x10, #32 __LF \+ adcs x8, x8, x3 __LF \+ mul x2, x10, x5 __LF \+ umulh x10, x10, x5 __LF \+ adcs x9, x9, x2 __LF \+ adc x10, x10, xzr __LF \+ adds x8, x8, x11, lsl #32 __LF \+ lsr x3, x11, #32 __LF \+ adcs x9, x9, x3 __LF \+ mul x2, x11, x5 __LF \+ umulh x11, x11, x5 __LF \+ adcs x10, x10, x2 __LF \+ adc x11, x11, xzr __LF \+ adds x8, x8, x12 __LF \+ adcs x9, x9, x13 __LF \+ adcs x10, x10, x14 __LF \+ adcs x11, x11, x7 __LF \+ cset x2, hs __LF \+ mov x3, #4294967295 __LF \+ adds x12, x8, #1 __LF \+ sbcs x13, x9, x3 __LF \+ sbcs x14, x10, xzr __LF \+ sbcs x7, x11, x5 __LF \+ sbcs xzr, x2, xzr __LF \+ csel x8, x8, x12, lo __LF \+ csel x9, x9, x13, lo __LF \+ csel x10, x10, x14, lo __LF \+ csel x11, x11, x7, lo __LF \+ stp x8, x9, [P0] __LF \+ stp x10, x11, [P0+16]++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ csetm x3, lo __LF \+ adds x5, x5, x3 __LF \+ and x4, x3, #0xffffffff __LF \+ adcs x6, x6, x4 __LF \+ adcs x7, x7, xzr __LF \+ and x4, x3, #0xffffffff00000001 __LF \+ adc x8, x8, x4 __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++// Corresponds exactly to bignum_add_p256++#define add_p256(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ adds x5, x5, x4 __LF \+ adcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ adcs x7, x7, x4 __LF \+ adcs x8, x8, x3 __LF \+ adc x3, xzr, xzr __LF \+ cmn x5, #1 __LF \+ mov x4, #4294967295 __LF \+ sbcs xzr, x6, x4 __LF \+ sbcs xzr, x7, xzr __LF \+ mov x4, #-4294967295 __LF \+ sbcs xzr, x8, x4 __LF \+ adcs x3, x3, xzr __LF \+ csetm x3, ne __LF \+ subs x5, x5, x3 __LF \+ and x4, x3, #0xffffffff __LF \+ sbcs x6, x6, x4 __LF \+ sbcs x7, x7, xzr __LF \+ and x4, x3, #0xffffffff00000001 __LF \+ sbc x8, x8, x4 __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++// A weak version of add that only guarantees sum in 4 digits++#define weakadd_p256(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ adds x5, x5, x4 __LF \+ adcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ adcs x7, x7, x4 __LF \+ adcs x8, x8, x3 __LF \+ csetm x3, cs __LF \+ subs x5, x5, x3 __LF \+ and x1, x3, #4294967295 __LF \+ sbcs x6, x6, x1 __LF \+ sbcs x7, x7, xzr __LF \+ and x2, x3, #-4294967295 __LF \+ sbc x8, x8, x2 __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++// P0 = C * P1 - D * P2 computed as D * (p_256 - P2) + C * P1+// Quotient estimation is done just as q = h + 1 as in bignum_triple_p256+// This also applies to the other functions following.++#define cmsub_p256(P0,C,P1,D,P2) \+ mov x1, D __LF \+ mov x2, #-1 __LF \+ ldp x9, x10, [P2] __LF \+ subs x9, x2, x9 __LF \+ mov x2, #4294967295 __LF \+ sbcs x10, x2, x10 __LF \+ ldp x11, x12, [P2+16] __LF \+ sbcs x11, xzr, x11 __LF \+ mov x2, #-4294967295 __LF \+ sbc x12, x2, x12 __LF \+ mul x3, x1, x9 __LF \+ mul x4, x1, x10 __LF \+ mul x5, x1, x11 __LF \+ mul x6, x1, x12 __LF \+ umulh x9, x1, x9 __LF \+ umulh x10, x1, x10 __LF \+ umulh x11, x1, x11 __LF \+ umulh x7, x1, x12 __LF \+ adds x4, x4, x9 __LF \+ adcs x5, x5, x10 __LF \+ adcs x6, x6, x11 __LF \+ adc x7, x7, xzr __LF \+ mov x1, C __LF \+ ldp x9, x10, [P1] __LF \+ mul x8, x9, x1 __LF \+ umulh x9, x9, x1 __LF \+ adds x3, x3, x8 __LF \+ mul x8, x10, x1 __LF \+ umulh x10, x10, x1 __LF \+ adcs x4, x4, x8 __LF \+ ldp x11, x12, [P1+16] __LF \+ mul x8, x11, x1 __LF \+ umulh x11, x11, x1 __LF \+ adcs x5, x5, x8 __LF \+ mul x8, x12, x1 __LF \+ umulh x12, x12, x1 __LF \+ adcs x6, x6, x8 __LF \+ adc x7, x7, xzr __LF \+ adds x4, x4, x9 __LF \+ adcs x5, x5, x10 __LF \+ adcs x6, x6, x11 __LF \+ adc x7, x7, x12 __LF \+ add x8, x7, #1 __LF \+ lsl x10, x8, #32 __LF \+ adds x6, x6, x10 __LF \+ adc x7, x7, xzr __LF \+ neg x9, x8 __LF \+ sub x10, x10, #1 __LF \+ subs x3, x3, x9 __LF \+ sbcs x4, x4, x10 __LF \+ sbcs x5, x5, xzr __LF \+ sbcs x6, x6, x8 __LF \+ sbc x8, x7, x8 __LF \+ adds x3, x3, x8 __LF \+ and x9, x8, #4294967295 __LF \+ adcs x4, x4, x9 __LF \+ adcs x5, x5, xzr __LF \+ neg x10, x9 __LF \+ adc x6, x6, x10 __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++// P0 = 4 * P1 - P2, by direct subtraction of P2; the method+// in bignum_cmul_p256 etc. for quotient estimation still+// works when the value to be reduced is negative, as+// long as it is > -p_256, which is the case here. The+// actual accumulation of q * p_256 is done a bit differently+// so it works for the q = 0 case.++#define cmsub41_p256(P0,P1,P2) \+ ldp x1, x2, [P1] __LF \+ lsl x0, x1, #2 __LF \+ ldp x6, x7, [P2] __LF \+ subs x0, x0, x6 __LF \+ extr x1, x2, x1, #62 __LF \+ sbcs x1, x1, x7 __LF \+ ldp x3, x4, [P1+16] __LF \+ extr x2, x3, x2, #62 __LF \+ ldp x6, x7, [P2+16] __LF \+ sbcs x2, x2, x6 __LF \+ extr x3, x4, x3, #62 __LF \+ sbcs x3, x3, x7 __LF \+ lsr x4, x4, #62 __LF \+ sbc x4, x4, xzr __LF \+ add x5, x4, #1 __LF \+ lsl x8, x5, #32 __LF \+ subs x6, xzr, x8 __LF \+ sbcs x7, xzr, xzr __LF \+ sbc x8, x8, x5 __LF \+ adds x0, x0, x5 __LF \+ adcs x1, x1, x6 __LF \+ adcs x2, x2, x7 __LF \+ adcs x3, x3, x8 __LF \+ csetm x5, cc __LF \+ adds x0, x0, x5 __LF \+ and x6, x5, #4294967295 __LF \+ adcs x1, x1, x6 __LF \+ adcs x2, x2, xzr __LF \+ neg x7, x6 __LF \+ adc x3, x3, x7 __LF \+ stp x0, x1, [P0] __LF \+ stp x2, x3, [P0+16]++// P0 = 3 * P1 - 8 * P2, computed as (p_256 - P2) << 3 + 3 * P1++#define cmsub38_p256(P0,P1,P2) \+ mov x1, 8 __LF \+ mov x2, #-1 __LF \+ ldp x9, x10, [P2] __LF \+ subs x9, x2, x9 __LF \+ mov x2, #4294967295 __LF \+ sbcs x10, x2, x10 __LF \+ ldp x11, x12, [P2+16] __LF \+ sbcs x11, xzr, x11 __LF \+ mov x2, #-4294967295 __LF \+ sbc x12, x2, x12 __LF \+ lsl x3, x9, #3 __LF \+ extr x4, x10, x9, #61 __LF \+ extr x5, x11, x10, #61 __LF \+ extr x6, x12, x11, #61 __LF \+ lsr x7, x12, #61 __LF \+ mov x1, 3 __LF \+ ldp x9, x10, [P1] __LF \+ mul x8, x9, x1 __LF \+ umulh x9, x9, x1 __LF \+ adds x3, x3, x8 __LF \+ mul x8, x10, x1 __LF \+ umulh x10, x10, x1 __LF \+ adcs x4, x4, x8 __LF \+ ldp x11, x12, [P1+16] __LF \+ mul x8, x11, x1 __LF \+ umulh x11, x11, x1 __LF \+ adcs x5, x5, x8 __LF \+ mul x8, x12, x1 __LF \+ umulh x12, x12, x1 __LF \+ adcs x6, x6, x8 __LF \+ adc x7, x7, xzr __LF \+ adds x4, x4, x9 __LF \+ adcs x5, x5, x10 __LF \+ adcs x6, x6, x11 __LF \+ adc x7, x7, x12 __LF \+ add x8, x7, #1 __LF \+ lsl x10, x8, #32 __LF \+ adds x6, x6, x10 __LF \+ adc x7, x7, xzr __LF \+ neg x9, x8 __LF \+ sub x10, x10, #1 __LF \+ subs x3, x3, x9 __LF \+ sbcs x4, x4, x10 __LF \+ sbcs x5, x5, xzr __LF \+ sbcs x6, x6, x8 __LF \+ sbc x8, x7, x8 __LF \+ adds x3, x3, x8 __LF \+ and x9, x8, #4294967295 __LF \+ adcs x4, x4, x9 __LF \+ adcs x5, x5, xzr __LF \+ neg x10, x9 __LF \+ adc x6, x6, x10 __LF \+ stp x3, x4, [P0] __LF \+ stp x5, x6, [P0+16]++S2N_BN_SYMBOL(p256_montjdouble_alt):+ CFI_START++// Make room on stack for temporary variables++ CFI_DEC_SP(NSPACE)++// Move the input arguments to stable places++ mov input_z, x0+ mov input_x, x1++// Main code, just a sequence of basic field operations++// z2 = z^2+// y2 = y^2++ montsqr_p256(z2,z_1)+ montsqr_p256(y2,y_1)++// x2p = x^2 - z^4 = (x + z^2) * (x - z^2)++ sub_p256(t2,x_1,z2)+ weakadd_p256(t1,x_1,z2)+ montmul_p256(x2p,t1,t2)++// t1 = y + z+// xy2 = x * y^2+// x4p = x2p^2++ add_p256(t1,y_1,z_1)+ montmul_p256(xy2,x_1,y2)+ montsqr_p256(x4p,x2p)++// t1 = (y + z)^2++ montsqr_p256(t1,t1)++// d = 12 * xy2 - 9 * x4p+// t1 = y^2 + 2 * y * z++ cmsub_p256(d,12,xy2,9,x4p)+ sub_p256(t1,t1,z2)++// y4 = y^4++ montsqr_p256(y4,y2)++// dx2 = d * x2p++ montmul_p256(dx2,d,x2p)++// z_3' = 2 * y * z++ sub_p256(z_3,t1,y2)++// x' = 4 * xy2 - d++ cmsub41_p256(x_3,xy2,d)++// y' = 3 * dx2 - 8 * y4++ cmsub38_p256(y_3,dx2,y4)++// Restore stack and return++ CFI_INC_SP(NSPACE)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjdouble_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_montjmixadd.S view
@@ -0,0 +1,513 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point mixed addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjmixadd(uint64_t p3[static 12],+// const uint64_t p1[static 12],+// const uint64_t p2[static 8]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+// The "mixed" part means that p2 only has x and y coordinates, with the+// implicit z coordinate assumed to be the identity.+//+// Standard ARM ABI: X0 = p3, X1 = p1, X2 = p2+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjmixadd)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjmixadd)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjmixadd)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable homes for input arguments during main code sequence++#define input_z x17+#define input_x x19+#define input_y x20++// Pointer-offset pairs for inputs and outputs++#define x_1 input_x, #0+#define y_1 input_x, #NUMSIZE+#define z_1 input_x, #(2*NUMSIZE)++#define x_2 input_y, #0+#define y_2 input_y, #NUMSIZE++#define x_3 input_z, #0+#define y_3 input_z, #NUMSIZE+#define z_3 input_z, #(2*NUMSIZE)++// Pointer-offset pairs for temporaries, with some aliasing+// #NSPACE is the total stack needed for these temporaries++#define zp2 sp, #(NUMSIZE*0)+#define ww sp, #(NUMSIZE*0)+#define resx sp, #(NUMSIZE*0)++#define yd sp, #(NUMSIZE*1)+#define y2a sp, #(NUMSIZE*1)++#define x2a sp, #(NUMSIZE*2)+#define zzx2 sp, #(NUMSIZE*2)++#define zz sp, #(NUMSIZE*3)+#define t1 sp, #(NUMSIZE*3)++#define t2 sp, #(NUMSIZE*4)+#define zzx1 sp, #(NUMSIZE*4)+#define resy sp, #(NUMSIZE*4)++#define xd sp, #(NUMSIZE*5)+#define resz sp, #(NUMSIZE*5)++#define NSPACE NUMSIZE*6++// Corresponds to bignum_montmul_p256 but uses x0 in place of x17++#define montmul_p256(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x5, x6, [P1+16] __LF \+ ldp x7, x8, [P2] __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x7 __LF \+ mul x13, x4, x8 __LF \+ umulh x12, x3, x7 __LF \+ adds x16, x11, x13 __LF \+ umulh x14, x4, x8 __LF \+ adcs x0, x12, x14 __LF \+ adcs x14, x14, xzr __LF \+ adds x12, x12, x16 __LF \+ adcs x13, x13, x0 __LF \+ adcs x14, x14, xzr __LF \+ subs x15, x3, x4 __LF \+ cneg x15, x15, lo __LF \+ csetm x1, lo __LF \+ subs x0, x8, x7 __LF \+ cneg x0, x0, lo __LF \+ mul x16, x15, x0 __LF \+ umulh x0, x15, x0 __LF \+ cinv x1, x1, lo __LF \+ eor x16, x16, x1 __LF \+ eor x0, x0, x1 __LF \+ cmn x1, #1 __LF \+ adcs x12, x12, x16 __LF \+ adcs x13, x13, x0 __LF \+ adc x14, x14, x1 __LF \+ lsl x0, x11, #32 __LF \+ subs x1, x11, x0 __LF \+ lsr x16, x11, #32 __LF \+ sbc x11, x11, x16 __LF \+ adds x12, x12, x0 __LF \+ adcs x13, x13, x16 __LF \+ adcs x14, x14, x1 __LF \+ adc x11, x11, xzr __LF \+ lsl x0, x12, #32 __LF \+ subs x1, x12, x0 __LF \+ lsr x16, x12, #32 __LF \+ sbc x12, x12, x16 __LF \+ adds x13, x13, x0 __LF \+ adcs x14, x14, x16 __LF \+ adcs x11, x11, x1 __LF \+ adc x12, x12, xzr __LF \+ stp x13, x14, [P0] __LF \+ stp x11, x12, [P0+16] __LF \+ mul x11, x5, x9 __LF \+ mul x13, x6, x10 __LF \+ umulh x12, x5, x9 __LF \+ adds x16, x11, x13 __LF \+ umulh x14, x6, x10 __LF \+ adcs x0, x12, x14 __LF \+ adcs x14, x14, xzr __LF \+ adds x12, x12, x16 __LF \+ adcs x13, x13, x0 __LF \+ adcs x14, x14, xzr __LF \+ subs x15, x5, x6 __LF \+ cneg x15, x15, lo __LF \+ csetm x1, lo __LF \+ subs x0, x10, x9 __LF \+ cneg x0, x0, lo __LF \+ mul x16, x15, x0 __LF \+ umulh x0, x15, x0 __LF \+ cinv x1, x1, lo __LF \+ eor x16, x16, x1 __LF \+ eor x0, x0, x1 __LF \+ cmn x1, #1 __LF \+ adcs x12, x12, x16 __LF \+ adcs x13, x13, x0 __LF \+ adc x14, x14, x1 __LF \+ subs x3, x5, x3 __LF \+ sbcs x4, x6, x4 __LF \+ ngc x5, xzr __LF \+ cmn x5, #1 __LF \+ eor x3, x3, x5 __LF \+ adcs x3, x3, xzr __LF \+ eor x4, x4, x5 __LF \+ adcs x4, x4, xzr __LF \+ subs x7, x7, x9 __LF \+ sbcs x8, x8, x10 __LF \+ ngc x9, xzr __LF \+ cmn x9, #1 __LF \+ eor x7, x7, x9 __LF \+ adcs x7, x7, xzr __LF \+ eor x8, x8, x9 __LF \+ adcs x8, x8, xzr __LF \+ eor x10, x5, x9 __LF \+ ldp x15, x1, [P0] __LF \+ adds x15, x11, x15 __LF \+ adcs x1, x12, x1 __LF \+ ldp x5, x9, [P0+16] __LF \+ adcs x5, x13, x5 __LF \+ adcs x9, x14, x9 __LF \+ adc x2, xzr, xzr __LF \+ mul x11, x3, x7 __LF \+ mul x13, x4, x8 __LF \+ umulh x12, x3, x7 __LF \+ adds x16, x11, x13 __LF \+ umulh x14, x4, x8 __LF \+ adcs x0, x12, x14 __LF \+ adcs x14, x14, xzr __LF \+ adds x12, x12, x16 __LF \+ adcs x13, x13, x0 __LF \+ adcs x14, x14, xzr __LF \+ subs x3, x3, x4 __LF \+ cneg x3, x3, lo __LF \+ csetm x4, lo __LF \+ subs x0, x8, x7 __LF \+ cneg x0, x0, lo __LF \+ mul x16, x3, x0 __LF \+ umulh x0, x3, x0 __LF \+ cinv x4, x4, lo __LF \+ eor x16, x16, x4 __LF \+ eor x0, x0, x4 __LF \+ cmn x4, #1 __LF \+ adcs x12, x12, x16 __LF \+ adcs x13, x13, x0 __LF \+ adc x14, x14, x4 __LF \+ cmn x10, #1 __LF \+ eor x11, x11, x10 __LF \+ adcs x11, x11, x15 __LF \+ eor x12, x12, x10 __LF \+ adcs x12, x12, x1 __LF \+ eor x13, x13, x10 __LF \+ adcs x13, x13, x5 __LF \+ eor x14, x14, x10 __LF \+ adcs x14, x14, x9 __LF \+ adcs x3, x2, x10 __LF \+ adcs x4, x10, xzr __LF \+ adc x10, x10, xzr __LF \+ adds x13, x13, x15 __LF \+ adcs x14, x14, x1 __LF \+ adcs x3, x3, x5 __LF \+ adcs x4, x4, x9 __LF \+ adc x10, x10, x2 __LF \+ lsl x0, x11, #32 __LF \+ subs x1, x11, x0 __LF \+ lsr x16, x11, #32 __LF \+ sbc x11, x11, x16 __LF \+ adds x12, x12, x0 __LF \+ adcs x13, x13, x16 __LF \+ adcs x14, x14, x1 __LF \+ adc x11, x11, xzr __LF \+ lsl x0, x12, #32 __LF \+ subs x1, x12, x0 __LF \+ lsr x16, x12, #32 __LF \+ sbc x12, x12, x16 __LF \+ adds x13, x13, x0 __LF \+ adcs x14, x14, x16 __LF \+ adcs x11, x11, x1 __LF \+ adc x12, x12, xzr __LF \+ adds x3, x3, x11 __LF \+ adcs x4, x4, x12 __LF \+ adc x10, x10, xzr __LF \+ add x2, x10, #1 __LF \+ lsl x16, x2, #32 __LF \+ adds x4, x4, x16 __LF \+ adc x10, x10, xzr __LF \+ neg x15, x2 __LF \+ sub x16, x16, #1 __LF \+ subs x13, x13, x15 __LF \+ sbcs x14, x14, x16 __LF \+ sbcs x3, x3, xzr __LF \+ sbcs x4, x4, x2 __LF \+ sbcs x7, x10, x2 __LF \+ adds x13, x13, x7 __LF \+ mov x10, #4294967295 __LF \+ and x10, x10, x7 __LF \+ adcs x14, x14, x10 __LF \+ adcs x3, x3, xzr __LF \+ mov x10, #-4294967295 __LF \+ and x10, x10, x7 __LF \+ adc x4, x4, x10 __LF \+ stp x13, x14, [P0] __LF \+ stp x3, x4, [P0+16]++// Corresponds to bignum_montsqr_p256 but uses x0 in place of x17++#define montsqr_p256(P0,P1) \+ ldp x2, x3, [P1] __LF \+ ldp x4, x5, [P1+16] __LF \+ umull x15, w2, w2 __LF \+ lsr x11, x2, #32 __LF \+ umull x16, w11, w11 __LF \+ umull x11, w2, w11 __LF \+ adds x15, x15, x11, lsl #33 __LF \+ lsr x11, x11, #31 __LF \+ adc x16, x16, x11 __LF \+ umull x0, w3, w3 __LF \+ lsr x11, x3, #32 __LF \+ umull x1, w11, w11 __LF \+ umull x11, w3, w11 __LF \+ mul x12, x2, x3 __LF \+ umulh x13, x2, x3 __LF \+ adds x0, x0, x11, lsl #33 __LF \+ lsr x11, x11, #31 __LF \+ adc x1, x1, x11 __LF \+ adds x12, x12, x12 __LF \+ adcs x13, x13, x13 __LF \+ adc x1, x1, xzr __LF \+ adds x16, x16, x12 __LF \+ adcs x0, x0, x13 __LF \+ adc x1, x1, xzr __LF \+ lsl x12, x15, #32 __LF \+ subs x13, x15, x12 __LF \+ lsr x11, x15, #32 __LF \+ sbc x15, x15, x11 __LF \+ adds x16, x16, x12 __LF \+ adcs x0, x0, x11 __LF \+ adcs x1, x1, x13 __LF \+ adc x15, x15, xzr __LF \+ lsl x12, x16, #32 __LF \+ subs x13, x16, x12 __LF \+ lsr x11, x16, #32 __LF \+ sbc x16, x16, x11 __LF \+ adds x0, x0, x12 __LF \+ adcs x1, x1, x11 __LF \+ adcs x15, x15, x13 __LF \+ adc x16, x16, xzr __LF \+ mul x6, x2, x4 __LF \+ mul x14, x3, x5 __LF \+ umulh x8, x2, x4 __LF \+ subs x10, x2, x3 __LF \+ cneg x10, x10, lo __LF \+ csetm x13, lo __LF \+ subs x12, x5, x4 __LF \+ cneg x12, x12, lo __LF \+ mul x11, x10, x12 __LF \+ umulh x12, x10, x12 __LF \+ cinv x13, x13, lo __LF \+ eor x11, x11, x13 __LF \+ eor x12, x12, x13 __LF \+ adds x7, x6, x8 __LF \+ adc x8, x8, xzr __LF \+ umulh x9, x3, x5 __LF \+ adds x7, x7, x14 __LF \+ adcs x8, x8, x9 __LF \+ adc x9, x9, xzr __LF \+ adds x8, x8, x14 __LF \+ adc x9, x9, xzr __LF \+ cmn x13, #1 __LF \+ adcs x7, x7, x11 __LF \+ adcs x8, x8, x12 __LF \+ adc x9, x9, x13 __LF \+ adds x6, x6, x6 __LF \+ adcs x7, x7, x7 __LF \+ adcs x8, x8, x8 __LF \+ adcs x9, x9, x9 __LF \+ adc x10, xzr, xzr __LF \+ adds x6, x6, x0 __LF \+ adcs x7, x7, x1 __LF \+ adcs x8, x8, x15 __LF \+ adcs x9, x9, x16 __LF \+ adc x10, x10, xzr __LF \+ lsl x12, x6, #32 __LF \+ subs x13, x6, x12 __LF \+ lsr x11, x6, #32 __LF \+ sbc x6, x6, x11 __LF \+ adds x7, x7, x12 __LF \+ adcs x8, x8, x11 __LF \+ adcs x9, x9, x13 __LF \+ adcs x10, x10, x6 __LF \+ adc x6, xzr, xzr __LF \+ lsl x12, x7, #32 __LF \+ subs x13, x7, x12 __LF \+ lsr x11, x7, #32 __LF \+ sbc x7, x7, x11 __LF \+ adds x8, x8, x12 __LF \+ adcs x9, x9, x11 __LF \+ adcs x10, x10, x13 __LF \+ adcs x6, x6, x7 __LF \+ adc x7, xzr, xzr __LF \+ mul x11, x4, x4 __LF \+ adds x8, x8, x11 __LF \+ mul x12, x5, x5 __LF \+ umulh x11, x4, x4 __LF \+ adcs x9, x9, x11 __LF \+ adcs x10, x10, x12 __LF \+ umulh x12, x5, x5 __LF \+ adcs x6, x6, x12 __LF \+ adc x7, x7, xzr __LF \+ mul x11, x4, x5 __LF \+ umulh x12, x4, x5 __LF \+ adds x11, x11, x11 __LF \+ adcs x12, x12, x12 __LF \+ adc x13, xzr, xzr __LF \+ adds x9, x9, x11 __LF \+ adcs x10, x10, x12 __LF \+ adcs x6, x6, x13 __LF \+ adcs x7, x7, xzr __LF \+ mov x11, #4294967295 __LF \+ adds x5, x8, #1 __LF \+ sbcs x11, x9, x11 __LF \+ mov x13, #-4294967295 __LF \+ sbcs x12, x10, xzr __LF \+ sbcs x13, x6, x13 __LF \+ sbcs xzr, x7, xzr __LF \+ csel x8, x5, x8, hs __LF \+ csel x9, x11, x9, hs __LF \+ csel x10, x12, x10, hs __LF \+ csel x6, x13, x6, hs __LF \+ stp x8, x9, [P0] __LF \+ stp x10, x6, [P0+16]++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ csetm x3, cc __LF \+ adds x5, x5, x3 __LF \+ mov x4, #0xffffffff __LF \+ and x4, x4, x3 __LF \+ adcs x6, x6, x4 __LF \+ adcs x7, x7, xzr __LF \+ mov x4, #0xffffffff00000001 __LF \+ and x4, x4, x3 __LF \+ adc x8, x8, x4 __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++S2N_BN_SYMBOL(p256_montjmixadd):+ CFI_START++// Save regs and make room on stack for temporary variables++ CFI_PUSH2(x19,x20)+ CFI_DEC_SP(NSPACE)++// Move the input arguments to stable places++ mov input_z, x0+ mov input_x, x1+ mov input_y, x2++// Main code, just a sequence of basic field operations+// 8 * multiply + 3 * square + 7 * subtract++ montsqr_p256(zp2,z_1)+ montmul_p256(y2a,z_1,y_2)++ montmul_p256(x2a,zp2,x_2)+ montmul_p256(y2a,zp2,y2a)++ sub_p256(xd,x2a,x_1)+ sub_p256(yd,y2a,y_1)++ montsqr_p256(zz,xd)+ montsqr_p256(ww,yd)++ montmul_p256(zzx1,zz,x_1)+ montmul_p256(zzx2,zz,x2a)++ sub_p256(resx,ww,zzx1)+ sub_p256(t1,zzx2,zzx1)++ montmul_p256(resz,xd,z_1)++ sub_p256(resx,resx,zzx2)++ sub_p256(t2,zzx1,resx)++ montmul_p256(t1,t1,y_1)+ montmul_p256(t2,yd,t2)++ sub_p256(resy,t2,t1)++// Test if z_1 = 0 to decide if p1 = 0 (up to projective equivalence)++ ldp x0, x1, [z_1]+ ldp x2, x3, [z_1+16]+ orr x4, x0, x1+ orr x5, x2, x3+ orr x4, x4, x5+ cmp x4, xzr++// Multiplex: if p1 <> 0 just copy the computed result from the staging area.+// If p1 = 0 then return the point p2 augmented with a z = 1 coordinate (in+// Montgomery form so not the simple constant 1 but rather 2^256 - p_256),+// hence giving 0 + p2 = p2 for the final result.++ ldp x0, x1, [resx]+ ldp x12, x13, [x_2]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x2, x3, [resx+16]+ ldp x12, x13, [x_2+16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne++ ldp x4, x5, [resy]+ ldp x12, x13, [y_2]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x6, x7, [resy+16]+ ldp x12, x13, [y_2+16]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne++ ldp x8, x9, [resz]+ mov x12, #0x0000000000000001+ mov x13, #0xffffffff00000000+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x10, x11, [resz+16]+ mov x12, #0xffffffffffffffff+ mov x13, #0x00000000fffffffe+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne++ stp x0, x1, [x_3]+ stp x2, x3, [x_3+16]+ stp x4, x5, [y_3]+ stp x6, x7, [y_3+16]+ stp x8, x9, [z_3]+ stp x10, x11, [z_3+16]++// Restore registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_montjmixadd_alt.S view
@@ -0,0 +1,517 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point mixed addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjmixadd_alt(uint64_t p3[static 12],+// const uint64_t p1[static 12],+// const uint64_t p2[static 8]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+// The "mixed" part means that p2 only has x and y coordinates, with the+// implicit z coordinate assumed to be the identity.+//+// Standard ARM ABI: X0 = p3, X1 = p1, X2 = p2+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjmixadd_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjmixadd_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjmixadd_alt)++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Stable homes for input arguments during main code sequence++#define input_z x15+#define input_x x16+#define input_y x17++// Pointer-offset pairs for inputs and outputs++#define x_1 input_x, #0+#define y_1 input_x, #NUMSIZE+#define z_1 input_x, #(2*NUMSIZE)++#define x_2 input_y, #0+#define y_2 input_y, #NUMSIZE++#define x_3 input_z, #0+#define y_3 input_z, #NUMSIZE+#define z_3 input_z, #(2*NUMSIZE)++// Pointer-offset pairs for temporaries, with some aliasing+// #NSPACE is the total stack needed for these temporaries++#define zp2 sp, #(NUMSIZE*0)+#define ww sp, #(NUMSIZE*0)+#define resx sp, #(NUMSIZE*0)++#define yd sp, #(NUMSIZE*1)+#define y2a sp, #(NUMSIZE*1)++#define x2a sp, #(NUMSIZE*2)+#define zzx2 sp, #(NUMSIZE*2)++#define zz sp, #(NUMSIZE*3)+#define t1 sp, #(NUMSIZE*3)++#define t2 sp, #(NUMSIZE*4)+#define zzx1 sp, #(NUMSIZE*4)+#define resy sp, #(NUMSIZE*4)++#define xd sp, #(NUMSIZE*5)+#define resz sp, #(NUMSIZE*5)++#define NSPACE NUMSIZE*6++// Corresponds to bignum_montmul_p256_alt except registers++#define montmul_p256(P0,P1,P2) \+ ldp x3, x4, [P1] __LF \+ ldp x7, x8, [P2] __LF \+ mul x12, x3, x7 __LF \+ umulh x13, x3, x7 __LF \+ mul x11, x3, x8 __LF \+ umulh x14, x3, x8 __LF \+ adds x13, x13, x11 __LF \+ ldp x9, x10, [P2+16] __LF \+ mul x11, x3, x9 __LF \+ umulh x0, x3, x9 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x3, x10 __LF \+ umulh x1, x3, x10 __LF \+ adcs x0, x0, x11 __LF \+ adc x1, x1, xzr __LF \+ ldp x5, x6, [P1+16] __LF \+ mul x11, x4, x7 __LF \+ adds x13, x13, x11 __LF \+ mul x11, x4, x8 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x4, x9 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x4, x10 __LF \+ adcs x1, x1, x11 __LF \+ umulh x3, x4, x10 __LF \+ adc x3, x3, xzr __LF \+ umulh x11, x4, x7 __LF \+ adds x14, x14, x11 __LF \+ umulh x11, x4, x8 __LF \+ adcs x0, x0, x11 __LF \+ umulh x11, x4, x9 __LF \+ adcs x1, x1, x11 __LF \+ adc x3, x3, xzr __LF \+ mul x11, x5, x7 __LF \+ adds x14, x14, x11 __LF \+ mul x11, x5, x8 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x5, x9 __LF \+ adcs x1, x1, x11 __LF \+ mul x11, x5, x10 __LF \+ adcs x3, x3, x11 __LF \+ umulh x4, x5, x10 __LF \+ adc x4, x4, xzr __LF \+ umulh x11, x5, x7 __LF \+ adds x0, x0, x11 __LF \+ umulh x11, x5, x8 __LF \+ adcs x1, x1, x11 __LF \+ umulh x11, x5, x9 __LF \+ adcs x3, x3, x11 __LF \+ adc x4, x4, xzr __LF \+ mul x11, x6, x7 __LF \+ adds x0, x0, x11 __LF \+ mul x11, x6, x8 __LF \+ adcs x1, x1, x11 __LF \+ mul x11, x6, x9 __LF \+ adcs x3, x3, x11 __LF \+ mul x11, x6, x10 __LF \+ adcs x4, x4, x11 __LF \+ umulh x5, x6, x10 __LF \+ adc x5, x5, xzr __LF \+ mov x10, #0xffffffff00000001 __LF \+ adds x13, x13, x12, lsl #32 __LF \+ lsr x11, x12, #32 __LF \+ adcs x14, x14, x11 __LF \+ mul x11, x12, x10 __LF \+ umulh x12, x12, x10 __LF \+ adcs x0, x0, x11 __LF \+ adc x12, x12, xzr __LF \+ umulh x11, x6, x7 __LF \+ adds x1, x1, x11 __LF \+ umulh x11, x6, x8 __LF \+ adcs x3, x3, x11 __LF \+ umulh x11, x6, x9 __LF \+ adcs x4, x4, x11 __LF \+ adc x5, x5, xzr __LF \+ adds x14, x14, x13, lsl #32 __LF \+ lsr x11, x13, #32 __LF \+ adcs x0, x0, x11 __LF \+ mul x11, x13, x10 __LF \+ umulh x13, x13, x10 __LF \+ adcs x12, x12, x11 __LF \+ adc x13, x13, xzr __LF \+ adds x0, x0, x14, lsl #32 __LF \+ lsr x11, x14, #32 __LF \+ adcs x12, x12, x11 __LF \+ mul x11, x14, x10 __LF \+ umulh x14, x14, x10 __LF \+ adcs x13, x13, x11 __LF \+ adc x14, x14, xzr __LF \+ adds x12, x12, x0, lsl #32 __LF \+ lsr x11, x0, #32 __LF \+ adcs x13, x13, x11 __LF \+ mul x11, x0, x10 __LF \+ umulh x0, x0, x10 __LF \+ adcs x14, x14, x11 __LF \+ adc x0, x0, xzr __LF \+ adds x12, x12, x1 __LF \+ adcs x13, x13, x3 __LF \+ adcs x14, x14, x4 __LF \+ adcs x0, x0, x5 __LF \+ cset x8, cs __LF \+ mov x11, #0xffffffff __LF \+ adds x1, x12, #0x1 __LF \+ sbcs x3, x13, x11 __LF \+ sbcs x4, x14, xzr __LF \+ sbcs x5, x0, x10 __LF \+ sbcs xzr, x8, xzr __LF \+ csel x12, x12, x1, cc __LF \+ csel x13, x13, x3, cc __LF \+ csel x14, x14, x4, cc __LF \+ csel x0, x0, x5, cc __LF \+ stp x12, x13, [P0] __LF \+ stp x14, x0, [P0+16]++// Corresponds exactly to bignum_montsqr_p256_alt++#define montsqr_p256(P0,P1) \+ ldp x2, x3, [P1] __LF \+ mul x9, x2, x3 __LF \+ umulh x10, x2, x3 __LF \+ ldp x4, x5, [P1+16] __LF \+ mul x11, x2, x5 __LF \+ umulh x12, x2, x5 __LF \+ mul x6, x2, x4 __LF \+ umulh x7, x2, x4 __LF \+ adds x10, x10, x6 __LF \+ adcs x11, x11, x7 __LF \+ mul x6, x3, x4 __LF \+ umulh x7, x3, x4 __LF \+ adc x7, x7, xzr __LF \+ adds x11, x11, x6 __LF \+ mul x13, x4, x5 __LF \+ umulh x14, x4, x5 __LF \+ adcs x12, x12, x7 __LF \+ mul x6, x3, x5 __LF \+ umulh x7, x3, x5 __LF \+ adc x7, x7, xzr __LF \+ adds x12, x12, x6 __LF \+ adcs x13, x13, x7 __LF \+ adc x14, x14, xzr __LF \+ adds x9, x9, x9 __LF \+ adcs x10, x10, x10 __LF \+ adcs x11, x11, x11 __LF \+ adcs x12, x12, x12 __LF \+ adcs x13, x13, x13 __LF \+ adcs x14, x14, x14 __LF \+ cset x7, cs __LF \+ umulh x6, x2, x2 __LF \+ mul x8, x2, x2 __LF \+ adds x9, x9, x6 __LF \+ mul x6, x3, x3 __LF \+ adcs x10, x10, x6 __LF \+ umulh x6, x3, x3 __LF \+ adcs x11, x11, x6 __LF \+ mul x6, x4, x4 __LF \+ adcs x12, x12, x6 __LF \+ umulh x6, x4, x4 __LF \+ adcs x13, x13, x6 __LF \+ mul x6, x5, x5 __LF \+ adcs x14, x14, x6 __LF \+ umulh x6, x5, x5 __LF \+ adc x7, x7, x6 __LF \+ adds x9, x9, x8, lsl #32 __LF \+ lsr x3, x8, #32 __LF \+ adcs x10, x10, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x8, x3 __LF \+ umulh x8, x8, x3 __LF \+ adcs x11, x11, x2 __LF \+ adc x8, x8, xzr __LF \+ adds x10, x10, x9, lsl #32 __LF \+ lsr x3, x9, #32 __LF \+ adcs x11, x11, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x9, x3 __LF \+ umulh x9, x9, x3 __LF \+ adcs x8, x8, x2 __LF \+ adc x9, x9, xzr __LF \+ adds x11, x11, x10, lsl #32 __LF \+ lsr x3, x10, #32 __LF \+ adcs x8, x8, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x10, x3 __LF \+ umulh x10, x10, x3 __LF \+ adcs x9, x9, x2 __LF \+ adc x10, x10, xzr __LF \+ adds x8, x8, x11, lsl #32 __LF \+ lsr x3, x11, #32 __LF \+ adcs x9, x9, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x11, x3 __LF \+ umulh x11, x11, x3 __LF \+ adcs x10, x10, x2 __LF \+ adc x11, x11, xzr __LF \+ adds x8, x8, x12 __LF \+ adcs x9, x9, x13 __LF \+ adcs x10, x10, x14 __LF \+ adcs x11, x11, x7 __LF \+ cset x2, cs __LF \+ mov x3, #0xffffffff __LF \+ mov x5, #0xffffffff00000001 __LF \+ adds x12, x8, #0x1 __LF \+ sbcs x13, x9, x3 __LF \+ sbcs x14, x10, xzr __LF \+ sbcs x7, x11, x5 __LF \+ sbcs xzr, x2, xzr __LF \+ csel x8, x8, x12, cc __LF \+ csel x9, x9, x13, cc __LF \+ csel x10, x10, x14, cc __LF \+ csel x11, x11, x7, cc __LF \+ stp x8, x9, [P0] __LF \+ stp x10, x11, [P0+16]++// Almost-Montgomery variant which we use when an input to other muls+// with the other argument fully reduced (which is always safe).++#define amontsqr_p256(P0,P1) \+ ldp x2, x3, [P1] __LF \+ mul x9, x2, x3 __LF \+ umulh x10, x2, x3 __LF \+ ldp x4, x5, [P1+16] __LF \+ mul x11, x2, x5 __LF \+ umulh x12, x2, x5 __LF \+ mul x6, x2, x4 __LF \+ umulh x7, x2, x4 __LF \+ adds x10, x10, x6 __LF \+ adcs x11, x11, x7 __LF \+ mul x6, x3, x4 __LF \+ umulh x7, x3, x4 __LF \+ adc x7, x7, xzr __LF \+ adds x11, x11, x6 __LF \+ mul x13, x4, x5 __LF \+ umulh x14, x4, x5 __LF \+ adcs x12, x12, x7 __LF \+ mul x6, x3, x5 __LF \+ umulh x7, x3, x5 __LF \+ adc x7, x7, xzr __LF \+ adds x12, x12, x6 __LF \+ adcs x13, x13, x7 __LF \+ adc x14, x14, xzr __LF \+ adds x9, x9, x9 __LF \+ adcs x10, x10, x10 __LF \+ adcs x11, x11, x11 __LF \+ adcs x12, x12, x12 __LF \+ adcs x13, x13, x13 __LF \+ adcs x14, x14, x14 __LF \+ cset x7, cs __LF \+ umulh x6, x2, x2 __LF \+ mul x8, x2, x2 __LF \+ adds x9, x9, x6 __LF \+ mul x6, x3, x3 __LF \+ adcs x10, x10, x6 __LF \+ umulh x6, x3, x3 __LF \+ adcs x11, x11, x6 __LF \+ mul x6, x4, x4 __LF \+ adcs x12, x12, x6 __LF \+ umulh x6, x4, x4 __LF \+ adcs x13, x13, x6 __LF \+ mul x6, x5, x5 __LF \+ adcs x14, x14, x6 __LF \+ umulh x6, x5, x5 __LF \+ adc x7, x7, x6 __LF \+ adds x9, x9, x8, lsl #32 __LF \+ lsr x3, x8, #32 __LF \+ adcs x10, x10, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x8, x3 __LF \+ umulh x8, x8, x3 __LF \+ adcs x11, x11, x2 __LF \+ adc x8, x8, xzr __LF \+ adds x10, x10, x9, lsl #32 __LF \+ lsr x3, x9, #32 __LF \+ adcs x11, x11, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x9, x3 __LF \+ umulh x9, x9, x3 __LF \+ adcs x8, x8, x2 __LF \+ adc x9, x9, xzr __LF \+ adds x11, x11, x10, lsl #32 __LF \+ lsr x3, x10, #32 __LF \+ adcs x8, x8, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x10, x3 __LF \+ umulh x10, x10, x3 __LF \+ adcs x9, x9, x2 __LF \+ adc x10, x10, xzr __LF \+ adds x8, x8, x11, lsl #32 __LF \+ lsr x3, x11, #32 __LF \+ adcs x9, x9, x3 __LF \+ mov x3, #0xffffffff00000001 __LF \+ mul x2, x11, x3 __LF \+ umulh x11, x11, x3 __LF \+ adcs x10, x10, x2 __LF \+ adc x11, x11, xzr __LF \+ adds x8, x8, x12 __LF \+ adcs x9, x9, x13 __LF \+ adcs x10, x10, x14 __LF \+ adcs x11, x11, x7 __LF \+ mov x2, #0xffffffffffffffff __LF \+ csel x2, xzr, x2, cc __LF \+ mov x3, #0xffffffff __LF \+ csel x3, xzr, x3, cc __LF \+ mov x5, #0xffffffff00000001 __LF \+ csel x5, xzr, x5, cc __LF \+ subs x8, x8, x2 __LF \+ sbcs x9, x9, x3 __LF \+ sbcs x10, x10, xzr __LF \+ sbc x11, x11, x5 __LF \+ stp x8, x9, [P0] __LF \+ stp x10, x11, [P0+16]++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ ldp x5, x6, [P1] __LF \+ ldp x4, x3, [P2] __LF \+ subs x5, x5, x4 __LF \+ sbcs x6, x6, x3 __LF \+ ldp x7, x8, [P1+16] __LF \+ ldp x4, x3, [P2+16] __LF \+ sbcs x7, x7, x4 __LF \+ sbcs x8, x8, x3 __LF \+ csetm x3, cc __LF \+ adds x5, x5, x3 __LF \+ mov x4, #0xffffffff __LF \+ and x4, x4, x3 __LF \+ adcs x6, x6, x4 __LF \+ adcs x7, x7, xzr __LF \+ mov x4, #0xffffffff00000001 __LF \+ and x4, x4, x3 __LF \+ adc x8, x8, x4 __LF \+ stp x5, x6, [P0] __LF \+ stp x7, x8, [P0+16]++S2N_BN_SYMBOL(p256_montjmixadd_alt):+ CFI_START++// Make room on stack for temporary variables+// Move the input arguments to stable places++ CFI_DEC_SP(NSPACE)++ mov input_z, x0+ mov input_x, x1+ mov input_y, x2++// Main code, just a sequence of basic field operations+// 8 * multiply + 3 * square + 7 * subtract++ amontsqr_p256(zp2,z_1)+ montmul_p256(y2a,z_1,y_2)++ montmul_p256(x2a,zp2,x_2)+ montmul_p256(y2a,zp2,y2a)++ sub_p256(xd,x2a,x_1)+ sub_p256(yd,y2a,y_1)++ amontsqr_p256(zz,xd)+ montsqr_p256(ww,yd)++ montmul_p256(zzx1,zz,x_1)+ montmul_p256(zzx2,zz,x2a)++ sub_p256(resx,ww,zzx1)+ sub_p256(t1,zzx2,zzx1)++ montmul_p256(resz,xd,z_1)++ sub_p256(resx,resx,zzx2)++ sub_p256(t2,zzx1,resx)++ montmul_p256(t1,t1,y_1)+ montmul_p256(t2,yd,t2)++ sub_p256(resy,t2,t1)++// Test if z_1 = 0 to decide if p1 = 0 (up to projective equivalence)++ ldp x0, x1, [z_1]+ ldp x2, x3, [z_1+16]+ orr x4, x0, x1+ orr x5, x2, x3+ orr x4, x4, x5+ cmp x4, xzr++// Multiplex: if p1 <> 0 just copy the computed result from the staging area.+// If p1 = 0 then return the point p2 augmented with a z = 1 coordinate (in+// Montgomery form so not the simple constant 1 but rather 2^256 - p_256),+// hence giving 0 + p2 = p2 for the final result.++ ldp x0, x1, [resx]+ ldp x12, x13, [x_2]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x2, x3, [resx+16]+ ldp x12, x13, [x_2+16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne++ ldp x4, x5, [resy]+ ldp x12, x13, [y_2]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x6, x7, [resy+16]+ ldp x12, x13, [y_2+16]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne++ ldp x8, x9, [resz]+ mov x12, #0x0000000000000001+ mov x13, #0xffffffff00000000+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x10, x11, [resz+16]+ mov x12, #0xffffffffffffffff+ mov x13, #0x00000000fffffffe+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne++ stp x0, x1, [x_3]+ stp x2, x3, [x_3+16]+ stp x4, x5, [y_3]+ stp x6, x7, [y_3+16]+ stp x8, x9, [z_3]+ stp x10, x11, [z_3+16]++// Restore stack and return++ CFI_INC_SP(NSPACE)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjmixadd_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_scalarmul.S view
@@ -0,0 +1,8620 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for P-256+// Input scalar[4], point[8]; output res[8]+//+// extern void p256_scalarmul+// (uint64_t res[static 8],+// const uint64_t scalar[static 4],+// const uint64_t point[static 8]);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, returns the point (X,Y) = n * P. The input and output+// are affine points, and in the case of the point at infinity as+// the result, (0,0) is returned.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmul)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmul)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmul)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Safe copies of inputs (res lasts the whole code, point not so long)+// and additional values in variables, with some aliasing++#define res x19+#define sgn x20+#define j x20+#define point x21++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on the table, which is no longer needed at the end.++#define scalarb sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define tabent sp, #(4*NUMSIZE)++#define tab sp, #(7*NUMSIZE)++#define z2 sp, #(7*NUMSIZE)+#define z3 sp, #(8*NUMSIZE)++#define NSPACE 31*NUMSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p256_scalarmul):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the "res" and "point" input arguments. We load and process the+// scalar immediately so we don't bother preserving that input argument.+// Also, "point" is only needed early on and so its register gets re-used.++ mov res, x0+ mov point, x2++// Load the digits of group order n_256 = [x12;x13;x14;x15]++ movbig(x12, #0xf3b9, #0xcac2, #0xfc63, #0x2551)+ movbig(x13, #0xbce6, #0xfaad, #0xa717, #0x9e84)+ mov x14, #0xffffffffffffffff+ mov x15, #0xffffffff00000000++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256++ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]++ subs x6, x2, x12+ sbcs x7, x3, x13+ sbcs x8, x4, x14+ sbcs x9, x5, x15++ csel x2, x2, x6, cc+ csel x3, x3, x7, cc+ csel x4, x4, x8, cc+ csel x5, x5, x9, cc++// Now if the top bit of the reduced scalar is set, negate it mod n_256,+// i.e. do n |-> n_256 - n. Remember the sign as "sgn" so we can+// correspondingly negate the point below.++ subs x6, x12, x2+ sbcs x7, x13, x3+ sbcs x8, x14, x4+ sbc x9, x15, x5++ tst x5, #0x8000000000000000+ csel x2, x2, x6, eq+ csel x3, x3, x7, eq+ csel x4, x4, x8, eq+ csel x5, x5, x9, eq+ cset sgn, ne++// In either case then add the recoding constant 0x08888...888 to allow+// signed digits.++ mov x6, 0x8888888888888888+ adds x2, x2, x6+ adcs x3, x3, x6+ bic x7, x6, #0xF000000000000000+ adcs x4, x4, x6+ adc x5, x5, x7++ stp x2, x3, [scalarb]+ stp x4, x5, [scalarb+16]++// Set the tab[0] table entry to Montgomery-Jacobian point = 1 * P+// The z coordinate is just the Montgomery form of the constant 1.++ add x0, tab+ mov x1, point+ CFI_BL(Lp256_scalarmul_local_tomont_p256)++ add x1, point, #32+ add x0, tab+32+ CFI_BL(Lp256_scalarmul_local_tomont_p256)++ mov x0, #0x0000000000000001+ mov x1, #0xffffffff00000000+ stp x0, x1, [tab+64]+ mov x2, #0xffffffffffffffff+ mov x3, #0x00000000fffffffe+ stp x2, x3, [tab+80]++// If the top bit of the scalar was set, negate (y coordinate of) the point++ ldp x4, x5, [tab+32]+ ldp x6, x7, [tab+48]++ mov x0, 0xffffffffffffffff+ subs x0, x0, x4+ mov x1, 0x00000000ffffffff+ sbcs x1, x1, x5+ mov x3, 0xffffffff00000001+ sbcs x2, xzr, x6+ sbc x3, x3, x7++ cmp sgn, xzr+ csel x4, x0, x4, ne+ csel x5, x1, x5, ne+ csel x6, x2, x6, ne+ csel x7, x3, x7, ne++ stp x4, x5, [tab+32]+ stp x6, x7, [tab+48]++// Compute and record tab[1] = 2 * p, ..., tab[7] = 8 * P++ add x0, tab+96*1+ add x1, tab+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++ add x0, tab+96*2+ add x1, tab+96*1+ add x2, tab+ CFI_BL(Lp256_scalarmul_local_p256_montjmixadd)++ add x0, tab+96*3+ add x1, tab+96*1+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++ add x0, tab+96*4+ add x1, tab+96*3+ add x2, tab+ CFI_BL(Lp256_scalarmul_local_p256_montjmixadd)++ add x0, tab+96*5+ add x1, tab+96*2+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++ add x0, tab+96*6+ add x1, tab+96*5+ add x2, tab+ CFI_BL(Lp256_scalarmul_local_p256_montjmixadd)++ add x0, tab+96*7+ add x1, tab+96*3+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++// Initialize the accumulator as a table entry for top 4 bits (unrecoded)++ ldr x14, [scalarb+24]+ lsr x14, x14, #60++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ add x15, tab++ .set i, 1+.rep 8+ cmp x14, #i+ ldp x12, x13, [x15]+ csel x0, x12, x0, eq+ csel x1, x13, x1, eq+ ldp x12, x13, [x15, #16]+ csel x2, x12, x2, eq+ csel x3, x13, x3, eq+ ldp x12, x13, [x15, #32]+ csel x4, x12, x4, eq+ csel x5, x13, x5, eq+ ldp x12, x13, [x15, #48]+ csel x6, x12, x6, eq+ csel x7, x13, x7, eq+ ldp x12, x13, [x15, #64]+ csel x8, x12, x8, eq+ csel x9, x13, x9, eq+ ldp x12, x13, [x15, #80]+ csel x10, x12, x10, eq+ csel x11, x13, x11, eq+ add x15, x15, #96+ .set i, (i+1)+.endr+ stp x0, x1, [acc]+ stp x2, x3, [acc+16]+ stp x4, x5, [acc+32]+ stp x6, x7, [acc+48]+ stp x8, x9, [acc+64]+ stp x10, x11, [acc+80]++ mov j, #252++// Main loop over size-4 bitfields: double 4 times then add signed digit++Lp256_scalarmul_loop:+ sub j, j, #4++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_local_p256_montjdouble)++ lsr x2, j, #6+ ldr x14, [sp, x2, lsl #3] // Exploits scalarb = sp exactly+ lsr x14, x14, j+ and x14, x14, #15++ subs x14, x14, #8+ cset x16, lo // x16 = sign of digit (1 = negative)+ cneg x14, x14, lo // x14 = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ add x15, tab+ .set i, 1+.rep 8+ cmp x14, #i+ ldp x12, x13, [x15]+ csel x0, x12, x0, eq+ csel x1, x13, x1, eq+ ldp x12, x13, [x15, #16]+ csel x2, x12, x2, eq+ csel x3, x13, x3, eq+ ldp x12, x13, [x15, #32]+ csel x4, x12, x4, eq+ csel x5, x13, x5, eq+ ldp x12, x13, [x15, #48]+ csel x6, x12, x6, eq+ csel x7, x13, x7, eq+ ldp x12, x13, [x15, #64]+ csel x8, x12, x8, eq+ csel x9, x13, x9, eq+ ldp x12, x13, [x15, #80]+ csel x10, x12, x10, eq+ csel x11, x13, x11, eq+ add x15, x15, #96+ .set i, (i+1)+.endr++// Store it to "tabent" with the y coordinate optionally negated++ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]++ mov x0, 0xffffffffffffffff+ subs x0, x0, x4+ mov x1, 0x00000000ffffffff+ sbcs x1, x1, x5+ mov x3, 0xffffffff00000001+ sbcs x2, xzr, x6+ sbc x3, x3, x7++ cmp x16, xzr+ csel x4, x0, x4, ne+ csel x5, x1, x5, ne+ csel x6, x2, x6, ne+ csel x7, x3, x7, ne++ stp x4, x5, [tabent+32]+ stp x6, x7, [tabent+48]+ stp x8, x9, [tabent+64]+ stp x10, x11, [tabent+80]++ add x0, acc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp256_scalarmul_local_p256_montjadd)++ cbnz j, Lp256_scalarmul_loop++// That's the end of the main loop, and we just need to translate+// back from the Jacobian representation to affine. First of all,+// let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ add x0, z2+ add x1, acc+64+ CFI_BL(Lp256_scalarmul_local_montsqr_p256)++ add x0, z3+ add x2, z2+ add x1, acc+64+ CFI_BL(Lp256_scalarmul_local_montmul_p256)++ add x0, z2+ add x1, z3+ CFI_BL(Lp256_scalarmul_local_demont_p256)++ add x0, z3+ add x1, z2+ CFI_BL(Lp256_scalarmul_local_inv_p256)++ add x0, z2+ add x2, z3+ add x1, acc+64+ CFI_BL(Lp256_scalarmul_local_montmul_p256)++// Convert back from Jacobian (X,Y,Z) |-> (X/Z^2, Y/Z^3)++ add x1, acc+ add x2, z2+ mov x0, res+ CFI_BL(Lp256_scalarmul_local_montmul_p256)++ add x0, res, #32+ add x1, acc+32+ add x2, z3+ CFI_BL(Lp256_scalarmul_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x21,x30)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmul)++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_demont_p256)++Lp256_scalarmul_local_demont_p256:+ CFI_START+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ lsl x7, x2, #32+ subs x8, x2, x7+ lsr x6, x2, #32+ sbc x2, x2, x6+ adds x3, x3, x7+ adcs x4, x4, x6+ adcs x5, x5, x8+ adc x2, x2, xzr+ lsl x7, x3, #32+ subs x8, x3, x7+ lsr x6, x3, #32+ sbc x3, x3, x6+ adds x4, x4, x7+ adcs x5, x5, x6+ adcs x2, x2, x8+ adc x3, x3, xzr+ lsl x7, x4, #32+ subs x8, x4, x7+ lsr x6, x4, #32+ sbc x4, x4, x6+ adds x5, x5, x7+ adcs x2, x2, x6+ adcs x3, x3, x8+ adc x4, x4, xzr+ lsl x7, x5, #32+ subs x8, x5, x7+ lsr x6, x5, #32+ sbc x5, x5, x6+ adds x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x8+ adc x5, x5, xzr+ stp x2, x3, [x0]+ stp x4, x5, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_demont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_inv_p256)++Lp256_scalarmul_local_inv_p256:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(160)+ mov x20, x0+ mov x10, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x13, #0xffffffff00000001+ stp x10, x11, [sp]+ stp xzr, x13, [sp, #16]+ str xzr, [sp, #32]+ ldp x2, x3, [x1]+ subs x10, x2, x10+ sbcs x11, x3, x11+ ldp x4, x5, [x1, #16]+ sbcs x12, x4, xzr+ sbcs x13, x5, x13+ csel x2, x2, x10, cc+ csel x3, x3, x11, cc+ csel x4, x4, x12, cc+ csel x5, x5, x13, cc+ stp x2, x3, [sp, #48]+ stp x4, x5, [sp, #64]+ str xzr, [sp, #80]+ stp xzr, xzr, [sp, #96]+ stp xzr, xzr, [sp, #112]+ mov x10, #0x4000000000000+ stp x10, xzr, [sp, #128]+ stp xzr, xzr, [sp, #144]+ mov x21, #0xa+ mov x22, #0x1+ b Lp256_scalarmul_inv_midloop+Lp256_scalarmul_inv_loop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #48]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #64]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #56]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ ldr x23, [sp, #32]+ eor x3, x23, x14+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #72]+ eor x1, x8, x15+ ldr x24, [sp, #80]+ eor x0, x24, x15+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ asr x3, x3, #59+ str x3, [sp, #32]+ eor x1, x7, x16+ eor x5, x23, x16+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ eor x0, x24, x17+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #64]+ extr x2, x5, x2, #59+ str x2, [sp, #72]+ asr x5, x5, #59+ str x5, [sp, #80]+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #128]+ adc x3, x3, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #136]+ adc x4, x4, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #144]+ adc x2, x2, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x6, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x6, x6, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x6, x6, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x6, x6, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ stp x1, x6, [sp, #96]+ stp x5, x3, [sp, #112]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ ldp x0, x1, [sp, #128]+ ldr x3, [sp, #144]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x3, x3, x11+ mov x10, #0x2000000000000000+ adcs x2, x2, x10+ mov x14, #0x1fffffffe0000000+ adc x5, x5, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x3, x3, x10+ adcs x2, x2, x14+ adcs x5, x5, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x3, x3, x11+ sbcs x2, x2, xzr+ sbc x5, x5, x10+ stp x1, x3, [sp, #128]+ stp x2, x5, [sp, #144]+Lp256_scalarmul_inv_midloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #48]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Lp256_scalarmul_inv_loop+ ldr x0, [sp]+ ldr x1, [sp, #48]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x2, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x2, x2, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x2, x2, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x2, x2, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ mov x10, #0xffffffffffffffff+ subs x10, x1, x10+ mov x11, #0xffffffff+ sbcs x11, x2, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x5, xzr+ sbcs x13, x3, x13+ csel x10, x1, x10, cc+ csel x11, x2, x11, cc+ csel x12, x5, x12, cc+ csel x13, x3, x13, cc+ stp x10, x11, [x20]+ stp x12, x13, [x20, #16]+ CFI_INC_SP(160)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_inv_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_montmul_p256)++Lp256_scalarmul_local_montmul_p256:+ CFI_START+ ldr q20, [x2]+ ldp x7, x17, [x1]+ ldr q0, [x1]+ ldp x6, x10, [x2]+ ldp x11, x15, [x1, #16]+ rev64 v16.4S, v20.4S+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4S, v16.4S, v0.4S+ umulh x12, x17, x10+ uzp1 v28.4S, v20.4S, v0.4S+ subs x14, x11, x7+ ldr q20, [x2, #16]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2D, v16.4S+ umulh x4, x7, x6+ uzp1 v21.4S, v0.4S, v0.4S+ cneg x11, x8, cc+ shl v17.2D, v27.2D, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2D, v21.2S, v28.2S+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [x1, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2S, v20.2D+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4S, v20.4S, v20.4S+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2S, v28.2D+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x2, #16]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x9, x3, x13+ adcs x3, x8, x7+ umulh x8, x14, x11+ umull v21.2D, v0.2S, v1.2S+ adcs x12, x10, x12+ umull v3.2D, v0.2S, v16.2S+ adc x15, x15, xzr+ rev64 v24.4S, v20.4S+ stp x12, x15, [x0, #16]+ movi v2.2D, #0x00000000ffffffff+ mul x10, x14, x11+ mul v4.4S, v24.4S, v28.4S+ subs x13, x14, x5+ uzp2 v19.4S, v28.4S, v28.4S+ csetm x15, cc+ usra v3.2D, v21.2D, #32+ mul x7, x5, x1+ umull v21.2D, v19.2S, v16.2S+ cneg x13, x13, cc+ uaddlp v5.2D, v4.4S+ subs x11, x1, x11+ and v16.16B, v3.16B, v2.16B+ umulh x5, x5, x1+ shl v24.2D, v5.2D, #32+ cneg x11, x11, cc+ umlal v16.2D, v19.2S, v1.2S+ cinv x12, x15, cc+ umlal v24.2D, v0.2S, v1.2S+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ stp x9, x3, [x0]+ usra v21.2D, v3.2D, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2D, v16.2D, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ ldp x15, x8, [x0]+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ ldp x9, x13, [x0, #16]+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x15+ adcs x15, x16, x8+ eor x5, x17, x4+ adcs x9, x1, x9+ eor x1, x10, x5+ adcs x16, x2, x13+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [x0]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_montmul_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_montsqr_p256)++Lp256_scalarmul_local_montsqr_p256:+ CFI_START+ ldr q19, [x1]+ ldp x9, x13, [x1]+ ldr q23, [x1, #16]+ ldr q0, [x1]+ ldp x1, x10, [x1, #16]+ uzp2 v29.4S, v19.4S, v19.4S+ xtn v4.2S, v19.2D+ umulh x8, x9, x13+ rev64 v20.4S, v23.4S+ umull v16.2D, v19.2S, v19.2S+ umull v1.2D, v29.2S, v4.2S+ mul v20.4S, v20.4S, v0.4S+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2D, v19.4S, v19.4S+ mov x4, v16.d[0]+ uzp1 v17.4S, v23.4S, v0.4S+ uaddlp v19.2D, v20.4S+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4S, v0.4S, v0.4S+ shl v19.2D, v19.2D, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2D, v20.2S, v17.2S+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs+ csel x14, x8, x14, cs+ csel x12, x11, x12, cs+ csel x2, x5, x2, cs+ stp x14, x12, [x0, #16]+ stp x16, x2, [x0]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_montsqr_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_tomont_p256)++Lp256_scalarmul_local_tomont_p256:+ CFI_START+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x1, #0xffffffffffffffff+ mov x7, #0xffffffff+ mov x9, #0xffffffff00000001+ subs x1, x2, x1+ sbcs x7, x3, x7+ sbcs x8, x4, xzr+ sbcs x9, x5, x9+ csel x2, x2, x1, cc+ csel x3, x3, x7, cc+ csel x4, x4, x8, cc+ csel x5, x5, x9, cc+ cmp xzr, xzr+ extr x9, x5, x4, #32+ adcs xzr, x4, x9+ lsr x9, x5, #32+ adcs x9, x5, x9+ csetm x6, cs+ orr x9, x9, x6+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x4, x4, x7+ adc x5, x5, x8+ negs x6, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x6, x6+ sbcs x2, x2, x7+ sbcs x3, x3, x8+ sbcs x4, x4, x9+ sbcs x5, x5, x9+ adds x6, x6, x5+ mov x7, #0xffffffff+ and x7, x7, x5+ adcs x2, x2, x7+ adcs x3, x3, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x5+ adc x4, x4, x7+ cmp xzr, xzr+ extr x9, x4, x3, #32+ adcs xzr, x3, x9+ lsr x9, x4, #32+ adcs x9, x4, x9+ csetm x5, cs+ orr x9, x9, x5+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x3, x3, x7+ adc x4, x4, x8+ negs x5, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x5, x5+ sbcs x6, x6, x7+ sbcs x2, x2, x8+ sbcs x3, x3, x9+ sbcs x4, x4, x9+ adds x5, x5, x4+ mov x7, #0xffffffff+ and x7, x7, x4+ adcs x6, x6, x7+ adcs x2, x2, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x4+ adc x3, x3, x7+ cmp xzr, xzr+ extr x9, x3, x2, #32+ adcs xzr, x2, x9+ lsr x9, x3, #32+ adcs x9, x3, x9+ csetm x4, cs+ orr x9, x9, x4+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x2, x2, x7+ adc x3, x3, x8+ negs x4, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x4, x4+ sbcs x5, x5, x7+ sbcs x6, x6, x8+ sbcs x2, x2, x9+ sbcs x3, x3, x9+ adds x4, x4, x3+ mov x7, #0xffffffff+ and x7, x7, x3+ adcs x5, x5, x7+ adcs x6, x6, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x3+ adc x2, x2, x7+ cmp xzr, xzr+ extr x9, x2, x6, #32+ adcs xzr, x6, x9+ lsr x9, x2, #32+ adcs x9, x2, x9+ csetm x3, cs+ orr x9, x9, x3+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x6, x6, x7+ adc x2, x2, x8+ negs x3, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x3, x3+ sbcs x4, x4, x7+ sbcs x5, x5, x8+ sbcs x6, x6, x9+ sbcs x2, x2, x9+ adds x3, x3, x2+ mov x7, #0xffffffff+ and x7, x7, x2+ adcs x4, x4, x7+ adcs x5, x5, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x2+ adc x6, x6, x7+ stp x3, x4, [x0]+ stp x5, x6, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_tomont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_p256_montjadd)++Lp256_scalarmul_local_p256_montjadd:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_PUSH2(x27,x30)+ CFI_DEC_SP(224)+ mov x21, x0+ mov x22, x1+ mov x23, x2+ mov x0, sp+ ldr q19, [x22, #64]+ ldp x9, x13, [x22, #64]+ ldr q23, [x22, #80]+ ldr q0, [x22, #64]+ ldp x1, x10, [x22, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x19, x3, x16, cs // cs = hs, nlast+ csel x14, x8, x14, cs // cs = hs, nlast+ csel x12, x11, x12, cs // cs = hs, nlast+ csel x20, x5, x2, cs // cs = hs, nlast+ stp x14, x12, [x0, #16]+ stp x19, x20, [x0]+ ldr q19, [x23, #64]+ ldp x9, x13, [x23, #64]+ ldr q23, [x23, #80]+ ldr q0, [x23, #64]+ ldp x1, x10, [x23, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs // cs = hs, nlast+ csel x14, x8, x14, cs // cs = hs, nlast+ csel x12, x11, x12, cs // cs = hs, nlast+ csel x2, x5, x2, cs // cs = hs, nlast+ stp x14, x12, [sp, #176]+ stp x16, x2, [sp, #160]+ ldr q20, [x22, #32]+ ldp x7, x17, [x23, #64]+ ldr q0, [x23, #64]+ ldp x6, x10, [x22, #32]+ ldp x11, x15, [x23, #80]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x22, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [x23, #80]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x22, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #192]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #208]+ ldr q20, [x23, #32]+ ldp x7, x17, [x22, #64]+ ldr q0, [x22, #64]+ ldp x6, x10, [x23, #32]+ ldp x11, x15, [x22, #80]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x23, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [x22, #80]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x23, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x24, x11, x13+ and x1, x1, x13+ adcs x25, x4, x1+ and x1, x12, x13+ stp x24, x25, [sp, #32]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #48]+ mov x1, sp+ ldr q20, [x23]+ ldr q0, [x1]+ ldp x6, x10, [x23]+ ldp x11, x15, [x1, #16]+ rev64 v16.4s, v20.4s+ subs x4, x19, x20+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x20, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x19+ ldr q20, [x23, #16]+ sbcs x5, x15, x20+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x19, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [x1, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x23, #16]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #64]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #80]+ ldr q20, [x22]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [x22]+ ldp x11, x15, [sp, #176]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x22, #16]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x22, #16]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #128]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #144]+ mov x1, sp+ ldr q20, [sp, #32]+ ldp x7, x17, [x1]+ ldr q0, [x1]+ ldp x11, x15, [x1, #16]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x25+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x24+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x25, x24+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [x1, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x24, x7+ sbcs x9, x25, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x24, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x25, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x24+ eor x1, x10, x5+ adcs x16, x2, x25+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x19, x11, x13+ and x1, x1, x13+ adcs x20, x4, x1+ and x1, x12, x13+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #48]+ ldr q20, [sp, #192]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [sp, #192]+ ldp x11, x15, [sp, #176]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #208]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #208]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x9, x11, x13+ and x1, x1, x13+ adcs x10, x4, x1+ and x1, x12, x13+ stp x9, x10, [sp, #192]+ adcs x11, x7, xzr+ adc x12, x17, x1+ stp x11, x12, [sp, #208]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc // cc = lo, ul, last+ adds x13, x5, x3+ and x4, x3, #0xffffffff+ adcs x24, x6, x4+ adcs x25, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x26, x8, x4+ stp x13, x24, [sp, #160]+ stp x25, x26, [sp, #176]+ subs x5, x19, x9+ sbcs x6, x20, x10+ ldp x7, x8, [sp, #48]+ sbcs x7, x7, x11+ sbcs x8, x8, x12+ csetm x3, cc // cc = lo, ul, last+ adds x19, x5, x3+ and x4, x3, #0xffffffff+ adcs x20, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x19, x20, [sp, #32]+ stp x7, x8, [sp, #48]+ ldr q19, [sp, #160]+ ldr q23, [sp, #176]+ ldr q0, [sp, #160]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x13, x24+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x13, x24+ umulh x15, x13, x25+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x13, x24+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x26, x25+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x24, x26+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x25, x26+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x25, x26+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x26, x26+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x26, x26+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x25, x25+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x25, x25+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x24, x3, x16, cs // cs = hs, nlast+ csel x25, x8, x14, cs // cs = hs, nlast+ csel x26, x11, x12, cs // cs = hs, nlast+ csel x27, x5, x2, cs // cs = hs, nlast+ stp x25, x26, [sp, #112]+ stp x24, x27, [sp, #96]+ mov x0, sp+ ldr q19, [sp, #32]+ ldr q23, [sp, #48]+ ldr q0, [sp, #32]+ ldp x1, x10, [sp, #48]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x19, x20+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x19, x20+ umulh x15, x19, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x19, x20+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x20, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs // cs = hs, nlast+ csel x14, x8, x14, cs // cs = hs, nlast+ csel x12, x11, x12, cs // cs = hs, nlast+ csel x2, x5, x2, cs // cs = hs, nlast+ stp x14, x12, [x0, #16]+ stp x16, x2, [x0]+ ldr q20, [sp, #128]+ ldr q0, [sp, #96]+ ldp x6, x10, [sp, #128]+ rev64 v16.4s, v20.4s+ subs x4, x24, x27+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x27, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x25, x24+ ldr q20, [sp, #144]+ sbcs x5, x26, x27+ ngc x17, xzr+ subs x8, x25, x26+ uaddlp v27.2d, v16.4s+ umulh x4, x24, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #112]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #144]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x25, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x26, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x25+ eor x1, x10, x5+ adcs x16, x2, x26+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x19, x11, x13+ and x1, x1, x13+ adcs x20, x4, x1+ and x1, x12, x13+ stp x19, x20, [sp, #128]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #144]+ ldr q20, [sp, #64]+ ldr q0, [sp, #96]+ ldp x6, x10, [sp, #64]+ ldp x11, x15, [sp, #112]+ rev64 v16.4s, v20.4s+ subs x4, x24, x27+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x27, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x24+ ldr q20, [sp, #80]+ sbcs x5, x15, x27+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x24, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #112]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #80]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x9, x11, x13+ and x1, x1, x13+ adcs x10, x4, x1+ and x1, x12, x13+ stp x9, x10, [sp, #64]+ adcs x11, x7, xzr+ adc x12, x17, x1+ stp x11, x12, [sp, #80]+ mov x0, sp+ mov x1, sp+ ldp x5, x6, [x1]+ subs x5, x5, x19+ sbcs x6, x6, x20+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc // cc = lo, ul, last+ adds x24, x5, x3+ and x4, x3, #0xffffffff+ adcs x25, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x7, x8, [x0, #16]+ subs x5, x9, x19+ sbcs x6, x10, x20+ ldp x4, x3, [sp, #144]+ sbcs x7, x11, x4+ sbcs x8, x12, x3+ csetm x3, cc // cc = lo, ul, last+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldr q20, [x22, #64]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [x22, #64]+ ldp x11, x15, [sp, #176]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [x22, #80]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x22, #80]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #160]+ adcs x19, x7, xzr+ adc x20, x17, x1+ stp x19, x20, [sp, #176]+ mov x0, sp+ mov x1, sp+ ldp x4, x3, [sp, #64]+ subs x5, x24, x4+ sbcs x6, x25, x3+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [sp, #80]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc // cc = lo, ul, last+ adds x9, x5, x3+ and x4, x3, #0xffffffff+ adcs x10, x6, x4+ adcs x11, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x3, x8, x4+ stp x9, x10, [x0]+ stp x11, x3, [x0, #16]+ ldp x5, x6, [sp, #128]+ subs x5, x5, x9+ sbcs x6, x6, x10+ ldp x7, x8, [sp, #144]+ sbcs x7, x7, x11+ sbcs x8, x8, x3+ csetm x3, cc // cc = lo, ul, last+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldr q20, [sp, #192]+ ldp x7, x17, [sp, #96]+ ldr q0, [sp, #96]+ ldp x6, x10, [sp, #192]+ ldp x11, x15, [sp, #112]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #208]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #112]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #208]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [sp, #96]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #112]+ ldr q20, [x23, #64]+ ldp x7, x17, [sp, #160]+ ldr q0, [sp, #160]+ ldp x6, x10, [x23, #64]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x19, x7+ ldr q20, [x23, #80]+ sbcs x5, x20, x17+ ngc x17, xzr+ subs x8, x19, x20+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x23, #80]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x19, x3, x13+ adcs x20, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x24, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x25, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x19+ adcs x15, x16, x20+ eor x5, x17, x4+ adcs x9, x1, x24+ eor x1, x10, x5+ adcs x16, x2, x25+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x19, x11, x13+ and x1, x1, x13+ adcs x20, x4, x1+ and x1, x12, x13+ stp x19, x20, [sp, #160]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #176]+ ldr q20, [sp, #128]+ ldp x7, x17, [sp, #32]+ ldr q0, [sp, #32]+ ldp x6, x10, [sp, #128]+ ldp x11, x15, [sp, #48]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #144]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #48]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #144]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x24, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x24+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x5, x11, x13+ and x1, x1, x13+ adcs x6, x4, x1+ and x1, x12, x13+ adcs x7, x7, xzr+ adc x9, x17, x1+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x9, x3+ csetm x3, cc // cc = lo, ul, last+ adds x15, x5, x3+ and x4, x3, #0xffffffff+ adcs x24, x6, x4+ adcs x25, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x26, x8, x4+ stp x15, x24, [sp, #128]+ stp x25, x26, [sp, #144]+ ldp x0, x1, [x22, #64]+ ldp x2, x3, [x22, #80]+ orr x12, x0, x1+ orr x13, x2, x3+ orr x12, x12, x13+ cmp x12, xzr+ cset x12, ne // ne = any+ ldp x4, x5, [x23, #64]+ ldp x6, x7, [x23, #80]+ orr x13, x4, x5+ orr x14, x6, x7+ orr x13, x13, x14+ cmp x13, xzr+ cset x13, ne // ne = any+ cmp x13, x12+ csel x8, x0, x19, cc // cc = lo, ul, last+ csel x9, x1, x20, cc // cc = lo, ul, last+ csel x8, x4, x8, hi // hi = pmore+ csel x9, x5, x9, hi // hi = pmore+ ldp x10, x11, [sp, #176]+ csel x10, x2, x10, cc // cc = lo, ul, last+ csel x11, x3, x11, cc // cc = lo, ul, last+ csel x10, x6, x10, hi // hi = pmore+ csel x11, x7, x11, hi // hi = pmore+ ldp x12, x13, [x22]+ ldp x0, x1, [sp]+ csel x0, x12, x0, cc // cc = lo, ul, last+ csel x1, x13, x1, cc // cc = lo, ul, last+ ldp x12, x13, [x23]+ csel x0, x12, x0, hi // hi = pmore+ csel x1, x13, x1, hi // hi = pmore+ ldp x12, x13, [x22, #16]+ ldp x2, x3, [sp, #16]+ csel x2, x12, x2, cc // cc = lo, ul, last+ csel x3, x13, x3, cc // cc = lo, ul, last+ ldp x12, x13, [x23, #16]+ csel x2, x12, x2, hi // hi = pmore+ csel x3, x13, x3, hi // hi = pmore+ ldp x12, x13, [x22, #32]+ csel x4, x12, x15, cc // cc = lo, ul, last+ csel x5, x13, x24, cc // cc = lo, ul, last+ ldp x12, x13, [x23, #32]+ csel x4, x12, x4, hi // hi = pmore+ csel x5, x13, x5, hi // hi = pmore+ ldp x12, x13, [x22, #48]+ csel x6, x12, x25, cc // cc = lo, ul, last+ csel x7, x13, x26, cc // cc = lo, ul, last+ ldp x12, x13, [x23, #48]+ csel x6, x12, x6, hi // hi = pmore+ csel x7, x13, x7, hi // hi = pmore+ stp x0, x1, [x21]+ stp x2, x3, [x21, #16]+ stp x4, x5, [x21, #32]+ stp x6, x7, [x21, #48]+ stp x8, x9, [x21, #64]+ stp x10, x11, [x21, #80]+ CFI_INC_SP(224)+ CFI_POP2(x27,x30)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_p256_montjadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_p256_montjdouble)++Lp256_scalarmul_local_p256_montjdouble:+ CFI_START+ CFI_DEC_SP(272)+ stp x19, x20, [sp, #192]+ stp x21, x22, [sp, #208]+ stp x23, x24, [sp, #224]+ stp x25, x26, [sp, #240]+ stp x27, xzr, [sp, #256]+ mov x19, x0+ mov x20, x1+ mov x0, sp+ ldr q19, [x20, #64]+ ldp x9, x13, [x20, #64]+ ldr q23, [x20, #80]+ ldr q0, [x20, #64]+ ldp x1, x10, [x20, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x21, x3, x16, cs // cs = hs, nlast+ csel x22, x8, x14, cs // cs = hs, nlast+ csel x23, x11, x12, cs // cs = hs, nlast+ csel x24, x5, x2, cs // cs = hs, nlast+ stp x22, x23, [x0, #16]+ stp x21, x24, [x0]+ ldr q19, [x20, #32]+ ldp x9, x13, [x20, #32]+ ldr q23, [x20, #48]+ ldr q0, [x20, #32]+ ldp x1, x10, [x20, #48]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs // cs = hs, nlast+ csel x14, x8, x14, cs // cs = hs, nlast+ csel x12, x11, x12, cs // cs = hs, nlast+ csel x2, x5, x2, cs // cs = hs, nlast+ stp x14, x12, [sp, #48]+ stp x16, x2, [sp, #32]+ ldp x5, x6, [x20]+ subs x5, x5, x21+ sbcs x6, x6, x24+ ldp x7, x8, [x20, #16]+ sbcs x7, x7, x22+ sbcs x8, x8, x23+ csetm x3, cc // cc = lo, ul, last+ adds x10, x5, x3+ and x4, x3, #0xffffffff+ adcs x25, x6, x4+ adcs x26, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x27, x8, x4+ stp x10, x25, [sp, #96]+ stp x26, x27, [sp, #112]+ ldp x5, x6, [x20]+ adds x5, x5, x21+ adcs x6, x6, x24+ ldp x7, x8, [x20, #16]+ adcs x7, x7, x22+ adcs x8, x8, x23+ csetm x3, cs // cs = hs, nlast+ subs x9, x5, x3+ and x1, x3, #0xffffffff+ sbcs x5, x6, x1+ sbcs x7, x7, xzr+ and x2, x3, #0xffffffff00000001+ sbc x8, x8, x2+ stp x9, x5, [sp, #64]+ stp x7, x8, [sp, #80]+ ldr q20, [sp, #96]+ ldr q0, [sp, #64]+ rev64 v16.4s, v20.4s+ subs x4, x9, x5+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x5, x25+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x7, x9+ ldr q20, [sp, #112]+ sbcs x5, x8, x5+ ngc x17, xzr+ subs x8, x7, x8+ uaddlp v27.2d, v16.4s+ umulh x4, x9, x10+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x25, x10+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #80]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x10, x26+ sbcs x9, x25, x27+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x27, x26+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x21, x3, x13+ adcs x22, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x23, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x24, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x21+ adcs x15, x16, x22+ eor x5, x17, x4+ adcs x9, x1, x23+ eor x1, x10, x5+ adcs x16, x2, x24+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x21, x11, x13+ and x1, x1, x13+ adcs x22, x4, x1+ and x1, x12, x13+ stp x21, x22, [sp, #96]+ adcs x23, x7, xzr+ adc x24, x17, x1+ stp x23, x24, [sp, #112]+ ldp x4, x5, [x20, #32]+ ldp x8, x9, [x20, #64]+ adds x4, x4, x8+ adcs x5, x5, x9+ ldp x6, x7, [x20, #48]+ ldp x10, x11, [x20, #80]+ adcs x6, x6, x10+ adcs x7, x7, x11+ adc x3, xzr, xzr+ adds x8, x4, #0x1+ mov x9, #0xffffffff // #4294967295+ sbcs x9, x5, x9+ sbcs x10, x6, xzr+ mov x11, #0xffffffff00000001 // #-4294967295+ sbcs x11, x7, x11+ sbcs x3, x3, xzr+ csel x4, x4, x8, cc // cc = lo, ul, last+ csel x5, x5, x9, cc // cc = lo, ul, last+ csel x6, x6, x10, cc // cc = lo, ul, last+ csel x7, x7, x11, cc // cc = lo, ul, last+ stp x4, x5, [sp, #64]+ stp x6, x7, [sp, #80]+ ldr q20, [sp, #32]+ ldp x7, x17, [x20]+ ldr q0, [x20]+ ldp x6, x10, [sp, #32]+ ldp x11, x15, [x20, #16]+ rev64 v16.4s, v20.4s+ subs x4, x7, x17+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x17, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x11, x7+ ldr q20, [sp, #48]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2d, v16.4s+ umulh x4, x7, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [x20, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #48]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x20, x3, x13+ adcs x25, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x26, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x27, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x20+ adcs x15, x16, x25+ eor x5, x17, x4+ adcs x9, x1, x26+ eor x1, x10, x5+ adcs x16, x2, x27+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x20, x11, x13+ and x1, x1, x13+ adcs x25, x4, x1+ and x1, x12, x13+ stp x20, x25, [sp, #128]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [sp, #144]+ ldr q19, [sp, #96]+ ldr q23, [sp, #112]+ ldr q0, [sp, #96]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x21, x22+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x21, x22+ umulh x15, x21, x23+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x21, x22+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x24, x23+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x22, x24+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x23, x24+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x23, x24+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x24, x24+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x24, x24+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x23, x23+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x23, x23+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x21, x3, x16, cs // cs = hs, nlast+ csel x22, x8, x14, cs // cs = hs, nlast+ csel x23, x11, x12, cs // cs = hs, nlast+ csel x24, x5, x2, cs // cs = hs, nlast+ ldr q19, [sp, #64]+ ldp x9, x13, [sp, #64]+ ldr q23, [sp, #80]+ ldr q0, [sp, #64]+ ldp x1, x10, [sp, #80]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x13, x3, x16, cs // cs = hs, nlast+ csel x14, x8, x14, cs // cs = hs, nlast+ csel x15, x11, x12, cs // cs = hs, nlast+ csel x26, x5, x2, cs // cs = hs, nlast+ mov x1, #0x9 // #9+ mov x2, #0xffffffffffffffff // #-1+ subs x9, x2, x21+ mov x2, #0xffffffff // #4294967295+ sbcs x10, x2, x24+ ngcs x11, x22+ mov x2, #0xffffffff00000001 // #-4294967295+ sbc x12, x2, x23+ mul x3, x1, x9+ mul x4, x1, x10+ mul x5, x1, x11+ mul x6, x1, x12+ umulh x9, x1, x9+ umulh x10, x1, x10+ umulh x11, x1, x11+ umulh x7, x1, x12+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, xzr+ mov x1, #0xc // #12+ mul x8, x20, x1+ umulh x9, x20, x1+ adds x3, x3, x8+ mul x8, x25, x1+ umulh x10, x25, x1+ adcs x4, x4, x8+ ldp x11, x12, [sp, #144]+ mul x8, x11, x1+ umulh x11, x11, x1+ adcs x5, x5, x8+ mul x8, x12, x1+ umulh x12, x12, x1+ adcs x6, x6, x8+ adc x7, x7, xzr+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, x12+ add x8, x7, #0x1+ lsl x10, x8, #32+ adds x6, x6, x10+ adc x7, x7, xzr+ neg x9, x8+ sub x10, x10, #0x1+ subs x3, x3, x9+ sbcs x4, x4, x10+ sbcs x5, x5, xzr+ sbcs x6, x6, x8+ sbc x8, x7, x8+ adds x20, x3, x8+ and x9, x8, #0xffffffff+ adcs x21, x4, x9+ adcs x22, x5, xzr+ neg x10, x9+ adc x23, x6, x10+ stp x20, x21, [sp, #160]+ stp x22, x23, [sp, #176]+ mov x2, sp+ ldp x4, x3, [x2]+ subs x5, x13, x4+ sbcs x6, x26, x3+ ldp x4, x3, [x2, #16]+ sbcs x7, x14, x4+ sbcs x8, x15, x3+ csetm x3, cc // cc = lo, ul, last+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #64]+ stp x7, x8, [sp, #80]+ mov x0, sp+ ldr q19, [sp, #32]+ ldp x9, x13, [sp, #32]+ ldr q23, [sp, #48]+ ldr q0, [sp, #32]+ ldp x1, x10, [sp, #48]+ uzp2 v29.4s, v19.4s, v19.4s+ xtn v4.2s, v19.2d+ umulh x8, x9, x13+ rev64 v20.4s, v23.4s+ umull v16.2d, v19.2s, v19.2s+ umull v1.2d, v29.2s, v4.2s+ mul v20.4s, v20.4s, v0.4s+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2d, v19.4s, v19.4s+ mov x4, v16.d[0]+ uzp1 v17.4s, v23.4s, v0.4s+ uaddlp v19.2d, v20.4s+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc // cc = lo, ul, last+ cneg x6, x14, cc // cc = lo, ul, last+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc // cc = lo, ul, last+ cinv x2, x5, cc // cc = lo, ul, last+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4s, v0.4s, v0.4s+ shl v19.2d, v19.2d, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2d, v20.2s, v17.2s+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff // #4294967295+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001 // #-4294967295+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x24, x3, x16, cs // cs = hs, nlast+ csel x25, x8, x14, cs // cs = hs, nlast+ csel x26, x11, x12, cs // cs = hs, nlast+ csel x27, x5, x2, cs // cs = hs, nlast+ stp x25, x26, [x0, #16]+ stp x24, x27, [x0]+ ldr q20, [sp, #96]+ ldr q0, [sp, #160]+ ldp x6, x10, [sp, #96]+ rev64 v16.4s, v20.4s+ subs x4, x20, x21+ csetm x3, cc // cc = lo, ul, last+ cneg x13, x4, cc // cc = lo, ul, last+ mul v16.4s, v16.4s, v0.4s+ umulh x12, x21, x10+ uzp1 v28.4s, v20.4s, v0.4s+ subs x14, x22, x20+ ldr q20, [sp, #112]+ sbcs x5, x23, x21+ ngc x17, xzr+ subs x8, x22, x23+ uaddlp v27.2d, v16.4s+ umulh x4, x20, x6+ uzp1 v21.4s, v0.4s, v0.4s+ cneg x11, x8, cc // cc = lo, ul, last+ shl v17.2d, v27.2d, #32+ csetm x15, cc // cc = lo, ul, last+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2d, v21.2s, v28.2s+ cneg x8, x9, cc // cc = lo, ul, last+ cinv x9, x3, cc // cc = lo, ul, last+ cmn x17, #0x1+ ldr q28, [sp, #176]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2s, v20.2d+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4s, v20.4s, v20.4s+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2s, v28.2d+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [sp, #112]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc // cc = lo, ul, last+ cneg x6, x6, cc // cc = lo, ul, last+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x20, x3, x13+ adcs x21, x8, x7+ umulh x8, x14, x11+ umull v21.2d, v0.2s, v1.2s+ adcs x22, x10, x12+ umull v3.2d, v0.2s, v16.2s+ adc x23, x15, xzr+ rev64 v24.4s, v20.4s+ movi v2.2d, #0xffffffff+ mul x10, x14, x11+ mul v4.4s, v24.4s, v28.4s+ subs x13, x14, x5+ uzp2 v19.4s, v28.4s, v28.4s+ csetm x15, cc // cc = lo, ul, last+ usra v3.2d, v21.2d, #32+ mul x7, x5, x1+ umull v21.2d, v19.2s, v16.2s+ cneg x13, x13, cc // cc = lo, ul, last+ uaddlp v5.2d, v4.4s+ subs x11, x1, x11+ and v16.16b, v3.16b, v2.16b+ umulh x5, x5, x1+ shl v24.2d, v5.2d, #32+ cneg x11, x11, cc // cc = lo, ul, last+ umlal v16.2d, v19.2s, v1.2s+ cinv x12, x15, cc // cc = lo, ul, last+ umlal v24.2d, v0.2s, v1.2s+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ usra v21.2d, v3.2d, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2d, v16.2d, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x20+ adcs x15, x16, x21+ eor x5, x17, x4+ adcs x9, x1, x22+ eor x1, x10, x5+ adcs x16, x2, x23+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff // #4294967295+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001 // #-4294967295+ adds x14, x11, x13+ and x1, x1, x13+ adcs x15, x4, x1+ and x1, x12, x13+ stp x14, x15, [sp, #96]+ adcs x13, x7, xzr+ adc x20, x17, x1+ stp x13, x20, [sp, #112]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #32]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #48]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc // cc = lo, ul, last+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [x19, #64]+ stp x7, x8, [x19, #80]+ ldp x1, x2, [sp, #128]+ lsl x0, x1, #2+ ldp x6, x7, [sp, #160]+ subs x0, x0, x6+ extr x1, x2, x1, #62+ sbcs x1, x1, x7+ ldp x3, x4, [sp, #144]+ extr x2, x3, x2, #62+ ldp x6, x7, [sp, #176]+ sbcs x2, x2, x6+ extr x3, x4, x3, #62+ sbcs x3, x3, x7+ lsr x4, x4, #62+ sbc x4, x4, xzr+ add x5, x4, #0x1+ lsl x8, x5, #32+ negs x6, x8+ ngcs x7, xzr+ sbc x8, x8, x5+ adds x0, x0, x5+ adcs x1, x1, x6+ adcs x2, x2, x7+ adcs x3, x3, x8+ csetm x5, cc // cc = lo, ul, last+ adds x0, x0, x5+ and x6, x5, #0xffffffff+ adcs x1, x1, x6+ adcs x2, x2, xzr+ neg x7, x6+ adc x3, x3, x7+ stp x0, x1, [x19]+ stp x2, x3, [x19, #16]+ mov x2, #0xffffffffffffffff // #-1+ subs x9, x2, x24+ mov x2, #0xffffffff // #4294967295+ sbcs x10, x2, x27+ ngcs x11, x25+ mov x2, #0xffffffff00000001 // #-4294967295+ sbc x12, x2, x26+ lsl x3, x9, #3+ extr x4, x10, x9, #61+ extr x5, x11, x10, #61+ extr x6, x12, x11, #61+ lsr x7, x12, #61+ mov x1, #0x3 // #3+ mul x8, x14, x1+ umulh x9, x14, x1+ adds x3, x3, x8+ mul x8, x15, x1+ umulh x10, x15, x1+ adcs x4, x4, x8+ mul x8, x13, x1+ umulh x11, x13, x1+ adcs x5, x5, x8+ mul x8, x20, x1+ umulh x12, x20, x1+ adcs x6, x6, x8+ adc x7, x7, xzr+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, x12+ add x8, x7, #0x1+ lsl x10, x8, #32+ adds x6, x6, x10+ adc x7, x7, xzr+ neg x9, x8+ sub x10, x10, #0x1+ subs x3, x3, x9+ sbcs x4, x4, x10+ sbcs x5, x5, xzr+ sbcs x6, x6, x8+ sbc x8, x7, x8+ adds x3, x3, x8+ and x9, x8, #0xffffffff+ adcs x4, x4, x9+ adcs x5, x5, xzr+ neg x10, x9+ adc x6, x6, x10+ stp x3, x4, [x19, #32]+ stp x5, x6, [x19, #48]+ ldp x27, xzr, [sp, #256]+ ldp x25, x26, [sp, #240]+ ldp x23, x24, [sp, #224]+ ldp x21, x22, [sp, #208]+ ldp x19, x20, [sp, #192]+ CFI_INC_SP(272)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_p256_montjdouble)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_local_p256_montjmixadd)++Lp256_scalarmul_local_p256_montjmixadd:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_DEC_SP(192)+ mov x17, x0+ mov x19, x1+ mov x20, x2+ ldp x2, x3, [x19, #64]+ ldp x4, x5, [x19, #80]+ umull x15, w2, w2+ lsr x11, x2, #32+ umull x16, w11, w11+ umull x11, w2, w11+ adds x15, x15, x11, lsl #33+ lsr x11, x11, #31+ adc x16, x16, x11+ umull x0, w3, w3+ lsr x11, x3, #32+ umull x1, w11, w11+ umull x11, w3, w11+ mul x12, x2, x3+ umulh x13, x2, x3+ adds x0, x0, x11, lsl #33+ lsr x11, x11, #31+ adc x1, x1, x11+ adds x12, x12, x12+ adcs x13, x13, x13+ adc x1, x1, xzr+ adds x16, x16, x12+ adcs x0, x0, x13+ adc x1, x1, xzr+ lsl x12, x15, #32+ subs x13, x15, x12+ lsr x11, x15, #32+ sbc x15, x15, x11+ adds x16, x16, x12+ adcs x0, x0, x11+ adcs x1, x1, x13+ adc x15, x15, xzr+ lsl x12, x16, #32+ subs x13, x16, x12+ lsr x11, x16, #32+ sbc x16, x16, x11+ adds x0, x0, x12+ adcs x1, x1, x11+ adcs x15, x15, x13+ adc x16, x16, xzr+ mul x6, x2, x4+ mul x14, x3, x5+ umulh x8, x2, x4+ subs x10, x2, x3+ cneg x10, x10, cc+ csetm x13, cc+ subs x12, x5, x4+ cneg x12, x12, cc+ mul x11, x10, x12+ umulh x12, x10, x12+ cinv x13, x13, cc+ eor x11, x11, x13+ eor x12, x12, x13+ adds x7, x6, x8+ adc x8, x8, xzr+ umulh x9, x3, x5+ adds x7, x7, x14+ adcs x8, x8, x9+ adc x9, x9, xzr+ adds x8, x8, x14+ adc x9, x9, xzr+ cmn x13, #0x1+ adcs x7, x7, x11+ adcs x8, x8, x12+ adc x9, x9, x13+ adds x6, x6, x6+ adcs x7, x7, x7+ adcs x8, x8, x8+ adcs x9, x9, x9+ adc x10, xzr, xzr+ adds x6, x6, x0+ adcs x7, x7, x1+ adcs x8, x8, x15+ adcs x9, x9, x16+ adc x10, x10, xzr+ lsl x12, x6, #32+ subs x13, x6, x12+ lsr x11, x6, #32+ sbc x6, x6, x11+ adds x7, x7, x12+ adcs x8, x8, x11+ adcs x9, x9, x13+ adcs x10, x10, x6+ adc x6, xzr, xzr+ lsl x12, x7, #32+ subs x13, x7, x12+ lsr x11, x7, #32+ sbc x7, x7, x11+ adds x8, x8, x12+ adcs x9, x9, x11+ adcs x10, x10, x13+ adcs x6, x6, x7+ adc x7, xzr, xzr+ mul x11, x4, x4+ adds x8, x8, x11+ mul x12, x5, x5+ umulh x11, x4, x4+ adcs x9, x9, x11+ adcs x10, x10, x12+ umulh x12, x5, x5+ adcs x6, x6, x12+ adc x7, x7, xzr+ mul x11, x4, x5+ umulh x12, x4, x5+ adds x11, x11, x11+ adcs x12, x12, x12+ adc x13, xzr, xzr+ adds x9, x9, x11+ adcs x10, x10, x12+ adcs x6, x6, x13+ adcs x7, x7, xzr+ mov x11, #0xffffffff+ adds x5, x8, #0x1+ sbcs x11, x9, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x10, xzr+ sbcs x13, x6, x13+ sbcs xzr, x7, xzr+ csel x8, x5, x8, cs+ csel x9, x11, x9, cs+ csel x10, x12, x10, cs+ csel x6, x13, x6, cs+ stp x8, x9, [sp]+ stp x10, x6, [sp, #16]+ ldp x3, x4, [x19, #64]+ ldp x5, x6, [x19, #80]+ ldp x7, x8, [x20, #32]+ ldp x9, x10, [x20, #48]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #32]+ stp x11, x12, [sp, #48]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #32]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #48]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #32]+ stp x3, x4, [sp, #48]+ ldp x3, x4, [sp]+ ldp x5, x6, [sp, #16]+ ldp x7, x8, [x20]+ ldp x9, x10, [x20, #16]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #64]+ stp x11, x12, [sp, #80]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #64]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #80]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #64]+ stp x3, x4, [sp, #80]+ ldp x3, x4, [sp]+ ldp x5, x6, [sp, #16]+ ldp x7, x8, [sp, #32]+ ldp x9, x10, [sp, #48]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #32]+ stp x11, x12, [sp, #48]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #32]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #48]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #32]+ stp x3, x4, [sp, #48]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [x19]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [x19, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #160]+ stp x7, x8, [sp, #176]+ ldp x5, x6, [sp, #32]+ ldp x4, x3, [x19, #32]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #48]+ ldp x4, x3, [x19, #48]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #32]+ stp x7, x8, [sp, #48]+ ldp x2, x3, [sp, #160]+ ldp x4, x5, [sp, #176]+ umull x15, w2, w2+ lsr x11, x2, #32+ umull x16, w11, w11+ umull x11, w2, w11+ adds x15, x15, x11, lsl #33+ lsr x11, x11, #31+ adc x16, x16, x11+ umull x0, w3, w3+ lsr x11, x3, #32+ umull x1, w11, w11+ umull x11, w3, w11+ mul x12, x2, x3+ umulh x13, x2, x3+ adds x0, x0, x11, lsl #33+ lsr x11, x11, #31+ adc x1, x1, x11+ adds x12, x12, x12+ adcs x13, x13, x13+ adc x1, x1, xzr+ adds x16, x16, x12+ adcs x0, x0, x13+ adc x1, x1, xzr+ lsl x12, x15, #32+ subs x13, x15, x12+ lsr x11, x15, #32+ sbc x15, x15, x11+ adds x16, x16, x12+ adcs x0, x0, x11+ adcs x1, x1, x13+ adc x15, x15, xzr+ lsl x12, x16, #32+ subs x13, x16, x12+ lsr x11, x16, #32+ sbc x16, x16, x11+ adds x0, x0, x12+ adcs x1, x1, x11+ adcs x15, x15, x13+ adc x16, x16, xzr+ mul x6, x2, x4+ mul x14, x3, x5+ umulh x8, x2, x4+ subs x10, x2, x3+ cneg x10, x10, cc+ csetm x13, cc+ subs x12, x5, x4+ cneg x12, x12, cc+ mul x11, x10, x12+ umulh x12, x10, x12+ cinv x13, x13, cc+ eor x11, x11, x13+ eor x12, x12, x13+ adds x7, x6, x8+ adc x8, x8, xzr+ umulh x9, x3, x5+ adds x7, x7, x14+ adcs x8, x8, x9+ adc x9, x9, xzr+ adds x8, x8, x14+ adc x9, x9, xzr+ cmn x13, #0x1+ adcs x7, x7, x11+ adcs x8, x8, x12+ adc x9, x9, x13+ adds x6, x6, x6+ adcs x7, x7, x7+ adcs x8, x8, x8+ adcs x9, x9, x9+ adc x10, xzr, xzr+ adds x6, x6, x0+ adcs x7, x7, x1+ adcs x8, x8, x15+ adcs x9, x9, x16+ adc x10, x10, xzr+ lsl x12, x6, #32+ subs x13, x6, x12+ lsr x11, x6, #32+ sbc x6, x6, x11+ adds x7, x7, x12+ adcs x8, x8, x11+ adcs x9, x9, x13+ adcs x10, x10, x6+ adc x6, xzr, xzr+ lsl x12, x7, #32+ subs x13, x7, x12+ lsr x11, x7, #32+ sbc x7, x7, x11+ adds x8, x8, x12+ adcs x9, x9, x11+ adcs x10, x10, x13+ adcs x6, x6, x7+ adc x7, xzr, xzr+ mul x11, x4, x4+ adds x8, x8, x11+ mul x12, x5, x5+ umulh x11, x4, x4+ adcs x9, x9, x11+ adcs x10, x10, x12+ umulh x12, x5, x5+ adcs x6, x6, x12+ adc x7, x7, xzr+ mul x11, x4, x5+ umulh x12, x4, x5+ adds x11, x11, x11+ adcs x12, x12, x12+ adc x13, xzr, xzr+ adds x9, x9, x11+ adcs x10, x10, x12+ adcs x6, x6, x13+ adcs x7, x7, xzr+ mov x11, #0xffffffff+ adds x5, x8, #0x1+ sbcs x11, x9, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x10, xzr+ sbcs x13, x6, x13+ sbcs xzr, x7, xzr+ csel x8, x5, x8, cs+ csel x9, x11, x9, cs+ csel x10, x12, x10, cs+ csel x6, x13, x6, cs+ stp x8, x9, [sp, #96]+ stp x10, x6, [sp, #112]+ ldp x2, x3, [sp, #32]+ ldp x4, x5, [sp, #48]+ umull x15, w2, w2+ lsr x11, x2, #32+ umull x16, w11, w11+ umull x11, w2, w11+ adds x15, x15, x11, lsl #33+ lsr x11, x11, #31+ adc x16, x16, x11+ umull x0, w3, w3+ lsr x11, x3, #32+ umull x1, w11, w11+ umull x11, w3, w11+ mul x12, x2, x3+ umulh x13, x2, x3+ adds x0, x0, x11, lsl #33+ lsr x11, x11, #31+ adc x1, x1, x11+ adds x12, x12, x12+ adcs x13, x13, x13+ adc x1, x1, xzr+ adds x16, x16, x12+ adcs x0, x0, x13+ adc x1, x1, xzr+ lsl x12, x15, #32+ subs x13, x15, x12+ lsr x11, x15, #32+ sbc x15, x15, x11+ adds x16, x16, x12+ adcs x0, x0, x11+ adcs x1, x1, x13+ adc x15, x15, xzr+ lsl x12, x16, #32+ subs x13, x16, x12+ lsr x11, x16, #32+ sbc x16, x16, x11+ adds x0, x0, x12+ adcs x1, x1, x11+ adcs x15, x15, x13+ adc x16, x16, xzr+ mul x6, x2, x4+ mul x14, x3, x5+ umulh x8, x2, x4+ subs x10, x2, x3+ cneg x10, x10, cc+ csetm x13, cc+ subs x12, x5, x4+ cneg x12, x12, cc+ mul x11, x10, x12+ umulh x12, x10, x12+ cinv x13, x13, cc+ eor x11, x11, x13+ eor x12, x12, x13+ adds x7, x6, x8+ adc x8, x8, xzr+ umulh x9, x3, x5+ adds x7, x7, x14+ adcs x8, x8, x9+ adc x9, x9, xzr+ adds x8, x8, x14+ adc x9, x9, xzr+ cmn x13, #0x1+ adcs x7, x7, x11+ adcs x8, x8, x12+ adc x9, x9, x13+ adds x6, x6, x6+ adcs x7, x7, x7+ adcs x8, x8, x8+ adcs x9, x9, x9+ adc x10, xzr, xzr+ adds x6, x6, x0+ adcs x7, x7, x1+ adcs x8, x8, x15+ adcs x9, x9, x16+ adc x10, x10, xzr+ lsl x12, x6, #32+ subs x13, x6, x12+ lsr x11, x6, #32+ sbc x6, x6, x11+ adds x7, x7, x12+ adcs x8, x8, x11+ adcs x9, x9, x13+ adcs x10, x10, x6+ adc x6, xzr, xzr+ lsl x12, x7, #32+ subs x13, x7, x12+ lsr x11, x7, #32+ sbc x7, x7, x11+ adds x8, x8, x12+ adcs x9, x9, x11+ adcs x10, x10, x13+ adcs x6, x6, x7+ adc x7, xzr, xzr+ mul x11, x4, x4+ adds x8, x8, x11+ mul x12, x5, x5+ umulh x11, x4, x4+ adcs x9, x9, x11+ adcs x10, x10, x12+ umulh x12, x5, x5+ adcs x6, x6, x12+ adc x7, x7, xzr+ mul x11, x4, x5+ umulh x12, x4, x5+ adds x11, x11, x11+ adcs x12, x12, x12+ adc x13, xzr, xzr+ adds x9, x9, x11+ adcs x10, x10, x12+ adcs x6, x6, x13+ adcs x7, x7, xzr+ mov x11, #0xffffffff+ adds x5, x8, #0x1+ sbcs x11, x9, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x10, xzr+ sbcs x13, x6, x13+ sbcs xzr, x7, xzr+ csel x8, x5, x8, cs+ csel x9, x11, x9, cs+ csel x10, x12, x10, cs+ csel x6, x13, x6, cs+ stp x8, x9, [sp]+ stp x10, x6, [sp, #16]+ ldp x3, x4, [sp, #96]+ ldp x5, x6, [sp, #112]+ ldp x7, x8, [x19]+ ldp x9, x10, [x19, #16]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #128]+ stp x11, x12, [sp, #144]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #128]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #144]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #128]+ stp x3, x4, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x5, x6, [sp, #112]+ ldp x7, x8, [sp, #64]+ ldp x9, x10, [sp, #80]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #64]+ stp x11, x12, [sp, #80]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #64]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #80]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #64]+ stp x3, x4, [sp, #80]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldp x3, x4, [sp, #160]+ ldp x5, x6, [sp, #176]+ ldp x7, x8, [x19, #64]+ ldp x9, x10, [x19, #80]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #160]+ stp x11, x12, [sp, #176]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #160]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #176]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #160]+ stp x3, x4, [sp, #176]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #64]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #80]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x5, x6, [sp, #112]+ ldp x7, x8, [x19, #32]+ ldp x9, x10, [x19, #48]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #96]+ stp x11, x12, [sp, #112]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #96]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #112]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #96]+ stp x3, x4, [sp, #112]+ ldp x3, x4, [sp, #32]+ ldp x5, x6, [sp, #48]+ ldp x7, x8, [sp, #128]+ ldp x9, x10, [sp, #144]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #128]+ stp x11, x12, [sp, #144]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #128]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #144]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #128]+ stp x3, x4, [sp, #144]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x0, x1, [x19, #64]+ ldp x2, x3, [x19, #80]+ orr x4, x0, x1+ orr x5, x2, x3+ orr x4, x4, x5+ cmp x4, xzr+ ldp x0, x1, [sp]+ ldp x12, x13, [x20]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x2, x3, [sp, #16]+ ldp x12, x13, [x20, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x4, x5, [sp, #128]+ ldp x12, x13, [x20, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x6, x7, [sp, #144]+ ldp x12, x13, [x20, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x8, x9, [sp, #160]+ mov x12, #0x1+ mov x13, #0xffffffff00000000+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x10, x11, [sp, #176]+ mov x12, #0xffffffffffffffff+ mov x13, #0xfffffffe+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ stp x0, x1, [x17]+ stp x2, x3, [x17, #16]+ stp x4, x5, [x17, #32]+ stp x6, x7, [x17, #48]+ stp x8, x9, [x17, #64]+ stp x10, x11, [x17, #80]+ CFI_INC_SP(192)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_local_p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_scalarmul_alt.S view
@@ -0,0 +1,6235 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for P-256+// Input scalar[4], point[8]; output res[8]+//+// extern void p256_scalarmul_alt+// (uint64_t res[static 8],+// const uint64_t scalar[static 4],+// const uint64_t point[static 8]);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, returns the point (X,Y) = n * P. The input and output+// are affine points, and in the case of the point at infinity as+// the result, (0,0) is returned.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmul_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmul_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmul_alt)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Safe copies of inputs (res lasts the whole code, point not so long)+// and additional values in variables, with some aliasing++#define res x19+#define sgn x20+#define j x20+#define point x21++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on the table, which is no longer needed at the end.++#define scalarb sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define tabent sp, #(4*NUMSIZE)++#define tab sp, #(7*NUMSIZE)++#define z2 sp, #(7*NUMSIZE)+#define z3 sp, #(8*NUMSIZE)++#define NSPACE 31*NUMSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p256_scalarmul_alt):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the "res" and "point" input arguments. We load and process the+// scalar immediately so we don't bother preserving that input argument.+// Also, "point" is only needed early on and so its register gets re-used.++ mov res, x0+ mov point, x2++// Load the digits of group order n_256 = [x12;x13;x14;x15]++ movbig(x12, #0xf3b9, #0xcac2, #0xfc63, #0x2551)+ movbig(x13, #0xbce6, #0xfaad, #0xa717, #0x9e84)+ mov x14, #0xffffffffffffffff+ mov x15, #0xffffffff00000000++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256++ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]++ subs x6, x2, x12+ sbcs x7, x3, x13+ sbcs x8, x4, x14+ sbcs x9, x5, x15++ csel x2, x2, x6, cc+ csel x3, x3, x7, cc+ csel x4, x4, x8, cc+ csel x5, x5, x9, cc++// Now if the top bit of the reduced scalar is set, negate it mod n_256,+// i.e. do n |-> n_256 - n. Remember the sign as "sgn" so we can+// correspondingly negate the point below.++ subs x6, x12, x2+ sbcs x7, x13, x3+ sbcs x8, x14, x4+ sbc x9, x15, x5++ tst x5, #0x8000000000000000+ csel x2, x2, x6, eq+ csel x3, x3, x7, eq+ csel x4, x4, x8, eq+ csel x5, x5, x9, eq+ cset sgn, ne++// In either case then add the recoding constant 0x08888...888 to allow+// signed digits.++ mov x6, 0x8888888888888888+ adds x2, x2, x6+ adcs x3, x3, x6+ bic x7, x6, #0xF000000000000000+ adcs x4, x4, x6+ adc x5, x5, x7++ stp x2, x3, [scalarb]+ stp x4, x5, [scalarb+16]++// Set the tab[0] table entry to Montgomery-Jacobian point = 1 * P+// The z coordinate is just the Montgomery form of the constant 1.++ add x0, tab+ mov x1, point+ CFI_BL(Lp256_scalarmul_alt_local_tomont_p256)++ add x1, point, #32+ add x0, tab+32+ CFI_BL(Lp256_scalarmul_alt_local_tomont_p256)++ mov x0, #0x0000000000000001+ mov x1, #0xffffffff00000000+ stp x0, x1, [tab+64]+ mov x2, #0xffffffffffffffff+ mov x3, #0x00000000fffffffe+ stp x2, x3, [tab+80]++// If the top bit of the scalar was set, negate (y coordinate of) the point++ ldp x4, x5, [tab+32]+ ldp x6, x7, [tab+48]++ mov x0, 0xffffffffffffffff+ subs x0, x0, x4+ mov x1, 0x00000000ffffffff+ sbcs x1, x1, x5+ mov x3, 0xffffffff00000001+ sbcs x2, xzr, x6+ sbc x3, x3, x7++ cmp sgn, xzr+ csel x4, x0, x4, ne+ csel x5, x1, x5, ne+ csel x6, x2, x6, ne+ csel x7, x3, x7, ne++ stp x4, x5, [tab+32]+ stp x6, x7, [tab+48]++// Compute and record tab[1] = 2 * p, ..., tab[7] = 8 * P++ add x0, tab+96*1+ add x1, tab+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++ add x0, tab+96*2+ add x1, tab+96*1+ add x2, tab+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjmixadd)++ add x0, tab+96*3+ add x1, tab+96*1+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++ add x0, tab+96*4+ add x1, tab+96*3+ add x2, tab+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjmixadd)++ add x0, tab+96*5+ add x1, tab+96*2+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++ add x0, tab+96*6+ add x1, tab+96*5+ add x2, tab+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjmixadd)++ add x0, tab+96*7+ add x1, tab+96*3+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++// Initialize the accumulator as a table entry for top 4 bits (unrecoded)++ ldr x14, [scalarb+24]+ lsr x14, x14, #60++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ add x15, tab++ .set i, 1+.rep 8+ cmp x14, #i+ ldp x12, x13, [x15]+ csel x0, x12, x0, eq+ csel x1, x13, x1, eq+ ldp x12, x13, [x15, #16]+ csel x2, x12, x2, eq+ csel x3, x13, x3, eq+ ldp x12, x13, [x15, #32]+ csel x4, x12, x4, eq+ csel x5, x13, x5, eq+ ldp x12, x13, [x15, #48]+ csel x6, x12, x6, eq+ csel x7, x13, x7, eq+ ldp x12, x13, [x15, #64]+ csel x8, x12, x8, eq+ csel x9, x13, x9, eq+ ldp x12, x13, [x15, #80]+ csel x10, x12, x10, eq+ csel x11, x13, x11, eq+ add x15, x15, #96+ .set i, (i+1)+.endr+ stp x0, x1, [acc]+ stp x2, x3, [acc+16]+ stp x4, x5, [acc+32]+ stp x6, x7, [acc+48]+ stp x8, x9, [acc+64]+ stp x10, x11, [acc+80]++ mov j, #252++// Main loop over size-4 bitfields: double 4 times then add signed digit++Lp256_scalarmul_alt_loop:+ sub j, j, #4++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjdouble)++ lsr x2, j, #6+ ldr x14, [sp, x2, lsl #3] // Exploits scalarb = sp exactly+ lsr x14, x14, j+ and x14, x14, #15++ subs x14, x14, #8+ cset x16, lo // x16 = sign of digit (1 = negative)+ cneg x14, x14, lo // x14 = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ add x15, tab+ .set i, 1+.rep 8+ cmp x14, #i+ ldp x12, x13, [x15]+ csel x0, x12, x0, eq+ csel x1, x13, x1, eq+ ldp x12, x13, [x15, #16]+ csel x2, x12, x2, eq+ csel x3, x13, x3, eq+ ldp x12, x13, [x15, #32]+ csel x4, x12, x4, eq+ csel x5, x13, x5, eq+ ldp x12, x13, [x15, #48]+ csel x6, x12, x6, eq+ csel x7, x13, x7, eq+ ldp x12, x13, [x15, #64]+ csel x8, x12, x8, eq+ csel x9, x13, x9, eq+ ldp x12, x13, [x15, #80]+ csel x10, x12, x10, eq+ csel x11, x13, x11, eq+ add x15, x15, #96+ .set i, (i+1)+.endr++// Store it to "tabent" with the y coordinate optionally negated++ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]++ mov x0, 0xffffffffffffffff+ subs x0, x0, x4+ mov x1, 0x00000000ffffffff+ sbcs x1, x1, x5+ mov x3, 0xffffffff00000001+ sbcs x2, xzr, x6+ sbc x3, x3, x7++ cmp x16, xzr+ csel x4, x0, x4, ne+ csel x5, x1, x5, ne+ csel x6, x2, x6, ne+ csel x7, x3, x7, ne++ stp x4, x5, [tabent+32]+ stp x6, x7, [tabent+48]+ stp x8, x9, [tabent+64]+ stp x10, x11, [tabent+80]++ add x0, acc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp256_scalarmul_alt_local_p256_montjadd)++ cbnz j, Lp256_scalarmul_alt_loop++// That's the end of the main loop, and we just need to translate+// back from the Jacobian representation to affine. First of all,+// let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ add x0, z2+ add x1, acc+64+ CFI_BL(Lp256_scalarmul_alt_local_montsqr_p256)++ add x0, z3+ add x2, z2+ add x1, acc+64+ CFI_BL(Lp256_scalarmul_alt_local_montmul_p256)++ add x0, z2+ add x1, z3+ CFI_BL(Lp256_scalarmul_alt_local_demont_p256)++ add x0, z3+ add x1, z2+ CFI_BL(Lp256_scalarmul_alt_local_inv_p256)++ add x0, z2+ add x2, z3+ add x1, acc+64+ CFI_BL(Lp256_scalarmul_alt_local_montmul_p256)++// Convert back from Jacobian (X,Y,Z) |-> (X/Z^2, Y/Z^3)++ add x1, acc+ add x2, z2+ mov x0, res+ CFI_BL(Lp256_scalarmul_alt_local_montmul_p256)++ add x0, res, #32+ add x1, acc+32+ add x2, z3+ CFI_BL(Lp256_scalarmul_alt_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x21,x30)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmul_alt)++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_demont_p256)++Lp256_scalarmul_alt_local_demont_p256:+ CFI_START+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ lsl x7, x2, #32+ subs x8, x2, x7+ lsr x6, x2, #32+ sbc x2, x2, x6+ adds x3, x3, x7+ adcs x4, x4, x6+ adcs x5, x5, x8+ adc x2, x2, xzr+ lsl x7, x3, #32+ subs x8, x3, x7+ lsr x6, x3, #32+ sbc x3, x3, x6+ adds x4, x4, x7+ adcs x5, x5, x6+ adcs x2, x2, x8+ adc x3, x3, xzr+ lsl x7, x4, #32+ subs x8, x4, x7+ lsr x6, x4, #32+ sbc x4, x4, x6+ adds x5, x5, x7+ adcs x2, x2, x6+ adcs x3, x3, x8+ adc x4, x4, xzr+ lsl x7, x5, #32+ subs x8, x5, x7+ lsr x6, x5, #32+ sbc x5, x5, x6+ adds x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x8+ adc x5, x5, xzr+ stp x2, x3, [x0]+ stp x4, x5, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_demont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_inv_p256)++Lp256_scalarmul_alt_local_inv_p256:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(160)+ mov x20, x0+ mov x10, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x13, #0xffffffff00000001+ stp x10, x11, [sp]+ stp xzr, x13, [sp, #16]+ str xzr, [sp, #32]+ ldp x2, x3, [x1]+ subs x10, x2, x10+ sbcs x11, x3, x11+ ldp x4, x5, [x1, #16]+ sbcs x12, x4, xzr+ sbcs x13, x5, x13+ csel x2, x2, x10, cc+ csel x3, x3, x11, cc+ csel x4, x4, x12, cc+ csel x5, x5, x13, cc+ stp x2, x3, [sp, #48]+ stp x4, x5, [sp, #64]+ str xzr, [sp, #80]+ stp xzr, xzr, [sp, #96]+ stp xzr, xzr, [sp, #112]+ mov x10, #0x4000000000000+ stp x10, xzr, [sp, #128]+ stp xzr, xzr, [sp, #144]+ mov x21, #0xa+ mov x22, #0x1+ b Lp256_scalarmul_alt_inv_midloop+Lp256_scalarmul_alt_inv_loop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #48]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #64]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #56]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ ldr x23, [sp, #32]+ eor x3, x23, x14+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #72]+ eor x1, x8, x15+ ldr x24, [sp, #80]+ eor x0, x24, x15+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ asr x3, x3, #59+ str x3, [sp, #32]+ eor x1, x7, x16+ eor x5, x23, x16+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ eor x0, x24, x17+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #64]+ extr x2, x5, x2, #59+ str x2, [sp, #72]+ asr x5, x5, #59+ str x5, [sp, #80]+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #128]+ adc x3, x3, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #136]+ adc x4, x4, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #144]+ adc x2, x2, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x6, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x6, x6, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x6, x6, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x6, x6, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ stp x1, x6, [sp, #96]+ stp x5, x3, [sp, #112]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ ldp x0, x1, [sp, #128]+ ldr x3, [sp, #144]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x3, x3, x11+ mov x10, #0x2000000000000000+ adcs x2, x2, x10+ mov x14, #0x1fffffffe0000000+ adc x5, x5, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x3, x3, x10+ adcs x2, x2, x14+ adcs x5, x5, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x3, x3, x11+ sbcs x2, x2, xzr+ sbc x5, x5, x10+ stp x1, x3, [sp, #128]+ stp x2, x5, [sp, #144]+Lp256_scalarmul_alt_inv_midloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #48]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ b.ne Lp256_scalarmul_alt_inv_loop+ ldr x0, [sp]+ ldr x1, [sp, #48]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x2, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x2, x2, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x2, x2, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x2, x2, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ mov x10, #0xffffffffffffffff+ subs x10, x1, x10+ mov x11, #0xffffffff+ sbcs x11, x2, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x5, xzr+ sbcs x13, x3, x13+ csel x10, x1, x10, cc+ csel x11, x2, x11, cc+ csel x12, x5, x12, cc+ csel x13, x3, x13, cc+ stp x10, x11, [x20]+ stp x12, x13, [x20, #16]+ CFI_INC_SP(160)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_inv_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_montmul_p256)++Lp256_scalarmul_alt_local_montmul_p256:+ CFI_START+ ldp x3, x4, [x1]+ ldp x7, x8, [x2]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x2, #16]+ mul x11, x3, x9+ umulh x15, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x16, x3, x10+ adcs x15, x15, x11+ adc x16, x16, xzr+ ldp x5, x6, [x1, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x15, x15, x11+ mul x11, x4, x10+ adcs x16, x16, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x15, x15, x11+ umulh x11, x4, x9+ adcs x16, x16, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x15, x15, x11+ mul x11, x5, x9+ adcs x16, x16, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x15, x15, x11+ umulh x11, x5, x8+ adcs x16, x16, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x15, x15, x11+ mul x11, x6, x8+ adcs x16, x16, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x15, x15, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x16, x16, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x15, x15, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x15, x15, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x15, lsl #32+ lsr x11, x15, #32+ adcs x13, x13, x11+ mul x11, x15, x10+ umulh x15, x15, x10+ adcs x14, x14, x11+ adc x15, x15, xzr+ adds x12, x12, x16+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x15, x15, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x16, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x15, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x16, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x15, x15, x5, cc+ stp x12, x13, [x0]+ stp x14, x15, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_montmul_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_montsqr_p256)++Lp256_scalarmul_alt_local_montsqr_p256:+ CFI_START+ ldp x2, x3, [x1]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x1, #16]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ mov x5, #0xffffffff00000001+ adds x9, x9, x8, lsl #32+ lsr x2, x8, #32+ adcs x10, x10, x2+ mul x2, x8, x5+ umulh x8, x8, x5+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x2, x9, #32+ adcs x11, x11, x2+ mul x2, x9, x5+ umulh x9, x9, x5+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x2, x10, #32+ adcs x8, x8, x2+ mul x2, x10, x5+ umulh x10, x10, x5+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x2, x11, #32+ adcs x9, x9, x2+ mul x2, x11, x5+ umulh x11, x11, x5+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [x0]+ stp x10, x11, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_montsqr_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_tomont_p256)++Lp256_scalarmul_alt_local_tomont_p256:+ CFI_START+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ mov x1, #0xffffffffffffffff+ mov x7, #0xffffffff+ mov x9, #0xffffffff00000001+ subs x1, x2, x1+ sbcs x7, x3, x7+ sbcs x8, x4, xzr+ sbcs x9, x5, x9+ csel x2, x2, x1, cc+ csel x3, x3, x7, cc+ csel x4, x4, x8, cc+ csel x5, x5, x9, cc+ cmp xzr, xzr+ extr x9, x5, x4, #32+ adcs xzr, x4, x9+ lsr x9, x5, #32+ adcs x9, x5, x9+ csetm x6, cs+ orr x9, x9, x6+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x4, x4, x7+ adc x5, x5, x8+ negs x6, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x6, x6+ sbcs x2, x2, x7+ sbcs x3, x3, x8+ sbcs x4, x4, x9+ sbcs x5, x5, x9+ adds x6, x6, x5+ mov x7, #0xffffffff+ and x7, x7, x5+ adcs x2, x2, x7+ adcs x3, x3, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x5+ adc x4, x4, x7+ cmp xzr, xzr+ extr x9, x4, x3, #32+ adcs xzr, x3, x9+ lsr x9, x4, #32+ adcs x9, x4, x9+ csetm x5, cs+ orr x9, x9, x5+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x3, x3, x7+ adc x4, x4, x8+ negs x5, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x5, x5+ sbcs x6, x6, x7+ sbcs x2, x2, x8+ sbcs x3, x3, x9+ sbcs x4, x4, x9+ adds x5, x5, x4+ mov x7, #0xffffffff+ and x7, x7, x4+ adcs x6, x6, x7+ adcs x2, x2, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x4+ adc x3, x3, x7+ cmp xzr, xzr+ extr x9, x3, x2, #32+ adcs xzr, x2, x9+ lsr x9, x3, #32+ adcs x9, x3, x9+ csetm x4, cs+ orr x9, x9, x4+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x2, x2, x7+ adc x3, x3, x8+ negs x4, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x4, x4+ sbcs x5, x5, x7+ sbcs x6, x6, x8+ sbcs x2, x2, x9+ sbcs x3, x3, x9+ adds x4, x4, x3+ mov x7, #0xffffffff+ and x7, x7, x3+ adcs x5, x5, x7+ adcs x6, x6, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x3+ adc x2, x2, x7+ cmp xzr, xzr+ extr x9, x2, x6, #32+ adcs xzr, x6, x9+ lsr x9, x2, #32+ adcs x9, x2, x9+ csetm x3, cs+ orr x9, x9, x3+ lsl x7, x9, #32+ lsr x8, x9, #32+ adds x6, x6, x7+ adc x2, x2, x8+ negs x3, x9+ sbcs x7, x7, xzr+ sbc x8, x8, xzr+ negs x3, x3+ sbcs x4, x4, x7+ sbcs x5, x5, x8+ sbcs x6, x6, x9+ sbcs x2, x2, x9+ adds x3, x3, x2+ mov x7, #0xffffffff+ and x7, x7, x2+ adcs x4, x4, x7+ adcs x5, x5, xzr+ mov x7, #0xffffffff00000001+ and x7, x7, x2+ adc x6, x6, x7+ stp x3, x4, [x0]+ stp x5, x6, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_tomont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_p256_montjadd)++Lp256_scalarmul_alt_local_p256_montjadd:+ CFI_START+ CFI_DEC_SP(224)+ mov x15, x0+ mov x16, x1+ mov x17, x2+ ldp x2, x3, [x16, #64]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x16, #80]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ mov x2, #0xffffffffffffffff+ csel x2, xzr, x2, cc+ mov x3, #0xffffffff+ csel x3, xzr, x3, cc+ mov x5, #0xffffffff00000001+ csel x5, xzr, x5, cc+ subs x8, x8, x2+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbc x11, x11, x5+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x2, x3, [x17, #64]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x17, #80]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ mov x2, #0xffffffffffffffff+ csel x2, xzr, x2, cc+ mov x3, #0xffffffff+ csel x3, xzr, x3, cc+ mov x5, #0xffffffff00000001+ csel x5, xzr, x5, cc+ subs x8, x8, x2+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbc x11, x11, x5+ stp x8, x9, [sp, #160]+ stp x10, x11, [sp, #176]+ ldp x3, x4, [x17, #64]+ ldp x7, x8, [x16, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [x17, #80]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #192]+ stp x14, x0, [sp, #208]+ ldp x3, x4, [x16, #64]+ ldp x7, x8, [x17, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x17, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [x16, #80]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #32]+ stp x14, x0, [sp, #48]+ ldp x3, x4, [sp]+ ldp x7, x8, [x17]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x17, #16]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #64]+ stp x14, x0, [sp, #80]+ ldp x3, x4, [sp, #160]+ ldp x7, x8, [x16]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #16]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #176]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x3, x4, [sp]+ ldp x7, x8, [sp, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #32]+ stp x14, x0, [sp, #48]+ ldp x3, x4, [sp, #160]+ ldp x7, x8, [sp, #192]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #208]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #176]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #192]+ stp x14, x0, [sp, #208]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #160]+ stp x7, x8, [sp, #176]+ ldp x5, x6, [sp, #32]+ ldp x4, x3, [sp, #192]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #48]+ ldp x4, x3, [sp, #208]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #32]+ stp x7, x8, [sp, #48]+ ldp x2, x3, [sp, #160]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #176]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ mov x2, #0xffffffffffffffff+ csel x2, xzr, x2, cc+ mov x3, #0xffffffff+ csel x3, xzr, x3, cc+ mov x5, #0xffffffff00000001+ csel x5, xzr, x5, cc+ subs x8, x8, x2+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbc x11, x11, x5+ stp x8, x9, [sp, #96]+ stp x10, x11, [sp, #112]+ ldp x2, x3, [sp, #32]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #48]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ mov x5, #0xffffffff00000001+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [sp, #128]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #144]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [sp, #64]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #80]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #64]+ stp x14, x0, [sp, #80]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldp x3, x4, [sp, #160]+ ldp x7, x8, [x16, #64]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #80]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #176]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #160]+ stp x14, x0, [sp, #176]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #64]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #80]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [sp, #192]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #208]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #96]+ stp x14, x0, [sp, #112]+ ldp x3, x4, [sp, #160]+ ldp x7, x8, [x17, #64]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x17, #80]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #176]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #160]+ stp x14, x0, [sp, #176]+ ldp x3, x4, [sp, #32]+ ldp x7, x8, [sp, #128]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #144]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #48]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x0, x1, [x16, #64]+ ldp x2, x3, [x16, #80]+ orr x12, x0, x1+ orr x13, x2, x3+ orr x12, x12, x13+ cmp x12, xzr+ cset x12, ne+ ldp x4, x5, [x17, #64]+ ldp x6, x7, [x17, #80]+ orr x13, x4, x5+ orr x14, x6, x7+ orr x13, x13, x14+ cmp x13, xzr+ cset x13, ne+ cmp x13, x12+ ldp x8, x9, [sp, #160]+ csel x8, x0, x8, cc+ csel x9, x1, x9, cc+ csel x8, x4, x8, hi+ csel x9, x5, x9, hi+ ldp x10, x11, [sp, #176]+ csel x10, x2, x10, cc+ csel x11, x3, x11, cc+ csel x10, x6, x10, hi+ csel x11, x7, x11, hi+ ldp x12, x13, [x16]+ ldp x0, x1, [sp]+ csel x0, x12, x0, cc+ csel x1, x13, x1, cc+ ldp x12, x13, [x17]+ csel x0, x12, x0, hi+ csel x1, x13, x1, hi+ ldp x12, x13, [x16, #16]+ ldp x2, x3, [sp, #16]+ csel x2, x12, x2, cc+ csel x3, x13, x3, cc+ ldp x12, x13, [x17, #16]+ csel x2, x12, x2, hi+ csel x3, x13, x3, hi+ ldp x12, x13, [x16, #32]+ ldp x4, x5, [sp, #128]+ csel x4, x12, x4, cc+ csel x5, x13, x5, cc+ ldp x12, x13, [x17, #32]+ csel x4, x12, x4, hi+ csel x5, x13, x5, hi+ ldp x12, x13, [x16, #48]+ ldp x6, x7, [sp, #144]+ csel x6, x12, x6, cc+ csel x7, x13, x7, cc+ ldp x12, x13, [x17, #48]+ csel x6, x12, x6, hi+ csel x7, x13, x7, hi+ stp x0, x1, [x15]+ stp x2, x3, [x15, #16]+ stp x4, x5, [x15, #32]+ stp x6, x7, [x15, #48]+ stp x8, x9, [x15, #64]+ stp x10, x11, [x15, #80]+ CFI_INC_SP(224)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_p256_montjadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_p256_montjdouble)++Lp256_scalarmul_alt_local_p256_montjdouble:+ CFI_START+ CFI_DEC_SP(192)+ mov x15, x0+ mov x16, x1+ ldp x2, x3, [x16, #64]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x16, #80]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ mov x5, #0xffffffff00000001+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mul x2, x8, x5+ umulh x8, x8, x5+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mul x2, x9, x5+ umulh x9, x9, x5+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mul x2, x10, x5+ umulh x10, x10, x5+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mul x2, x11, x5+ umulh x11, x11, x5+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x2, x3, [x16, #32]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x16, #48]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ mov x5, #0xffffffff00000001+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mul x2, x8, x5+ umulh x8, x8, x5+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mul x2, x9, x5+ umulh x9, x9, x5+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mul x2, x10, x5+ umulh x10, x10, x5+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mul x2, x11, x5+ umulh x11, x11, x5+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp, #32]+ stp x10, x11, [sp, #48]+ ldp x5, x6, [x16]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x16, #16]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldp x5, x6, [x16]+ ldp x4, x3, [sp]+ adds x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x16, #16]+ ldp x4, x3, [sp, #16]+ adcs x7, x7, x4+ adcs x8, x8, x3+ csetm x3, cs+ subs x5, x5, x3+ and x1, x3, #0xffffffff+ sbcs x6, x6, x1+ sbcs x7, x7, xzr+ and x2, x3, #0xffffffff00000001+ sbc x8, x8, x2+ stp x5, x6, [sp, #64]+ stp x7, x8, [sp, #80]+ ldp x3, x4, [sp, #64]+ ldp x7, x8, [sp, #96]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #112]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #80]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #96]+ stp x14, x0, [sp, #112]+ ldp x5, x6, [x16, #32]+ ldp x4, x3, [x16, #64]+ adds x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x16, #48]+ ldp x4, x3, [x16, #80]+ adcs x7, x7, x4+ adcs x8, x8, x3+ adc x3, xzr, xzr+ cmn x5, #0x1+ mov x4, #0xffffffff+ sbcs xzr, x6, x4+ sbcs xzr, x7, xzr+ mov x4, #0xffffffff00000001+ sbcs xzr, x8, x4+ adcs x3, x3, xzr+ csetm x3, ne+ subs x5, x5, x3+ and x4, x3, #0xffffffff+ sbcs x6, x6, x4+ sbcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ sbc x8, x8, x4+ stp x5, x6, [sp, #64]+ stp x7, x8, [sp, #80]+ ldp x3, x4, [x16]+ ldp x7, x8, [sp, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [x16, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x2, x3, [sp, #96]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #112]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ mov x5, #0xffffffff00000001+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mul x2, x8, x5+ umulh x8, x8, x5+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mul x2, x9, x5+ umulh x9, x9, x5+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mul x2, x10, x5+ umulh x10, x10, x5+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mul x2, x11, x5+ umulh x11, x11, x5+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp, #160]+ stp x10, x11, [sp, #176]+ ldp x2, x3, [sp, #64]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #80]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ mov x5, #0xffffffff00000001+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mul x2, x8, x5+ umulh x8, x8, x5+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mul x2, x9, x5+ umulh x9, x9, x5+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mul x2, x10, x5+ umulh x10, x10, x5+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mul x2, x11, x5+ umulh x11, x11, x5+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp, #64]+ stp x10, x11, [sp, #80]+ mov x1, #0x9+ mov x2, #0xffffffffffffffff+ ldp x9, x10, [sp, #160]+ subs x9, x2, x9+ mov x2, #0xffffffff+ sbcs x10, x2, x10+ ldp x11, x12, [sp, #176]+ ngcs x11, x11+ mov x2, #0xffffffff00000001+ sbc x12, x2, x12+ mul x3, x1, x9+ mul x4, x1, x10+ mul x5, x1, x11+ mul x6, x1, x12+ umulh x9, x1, x9+ umulh x10, x1, x10+ umulh x11, x1, x11+ umulh x7, x1, x12+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, xzr+ mov x1, #0xc+ ldp x9, x10, [sp, #128]+ mul x8, x9, x1+ umulh x9, x9, x1+ adds x3, x3, x8+ mul x8, x10, x1+ umulh x10, x10, x1+ adcs x4, x4, x8+ ldp x11, x12, [sp, #144]+ mul x8, x11, x1+ umulh x11, x11, x1+ adcs x5, x5, x8+ mul x8, x12, x1+ umulh x12, x12, x1+ adcs x6, x6, x8+ adc x7, x7, xzr+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, x12+ add x8, x7, #0x1+ lsl x10, x8, #32+ adds x6, x6, x10+ adc x7, x7, xzr+ neg x9, x8+ sub x10, x10, #0x1+ subs x3, x3, x9+ sbcs x4, x4, x10+ sbcs x5, x5, xzr+ sbcs x6, x6, x8+ sbc x8, x7, x8+ adds x3, x3, x8+ and x9, x8, #0xffffffff+ adcs x4, x4, x9+ adcs x5, x5, xzr+ neg x10, x9+ adc x6, x6, x10+ stp x3, x4, [sp, #160]+ stp x5, x6, [sp, #176]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [sp, #64]+ stp x7, x8, [sp, #80]+ ldp x2, x3, [sp, #32]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #48]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ mov x5, #0xffffffff00000001+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mul x2, x8, x5+ umulh x8, x8, x5+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mul x2, x9, x5+ umulh x9, x9, x5+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mul x2, x10, x5+ umulh x10, x10, x5+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mul x2, x11, x5+ umulh x11, x11, x5+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x3, x4, [sp, #160]+ ldp x7, x8, [sp, #96]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #112]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #176]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #96]+ stp x14, x0, [sp, #112]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #32]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #48]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ and x4, x3, #0xffffffff+ adcs x6, x6, x4+ adcs x7, x7, xzr+ and x4, x3, #0xffffffff00000001+ adc x8, x8, x4+ stp x5, x6, [x15, #64]+ stp x7, x8, [x15, #80]+ ldp x1, x2, [sp, #128]+ lsl x0, x1, #2+ ldp x6, x7, [sp, #160]+ subs x0, x0, x6+ extr x1, x2, x1, #62+ sbcs x1, x1, x7+ ldp x3, x4, [sp, #144]+ extr x2, x3, x2, #62+ ldp x6, x7, [sp, #176]+ sbcs x2, x2, x6+ extr x3, x4, x3, #62+ sbcs x3, x3, x7+ lsr x4, x4, #62+ sbc x4, x4, xzr+ add x5, x4, #0x1+ lsl x8, x5, #32+ negs x6, x8+ ngcs x7, xzr+ sbc x8, x8, x5+ adds x0, x0, x5+ adcs x1, x1, x6+ adcs x2, x2, x7+ adcs x3, x3, x8+ csetm x5, cc+ adds x0, x0, x5+ and x6, x5, #0xffffffff+ adcs x1, x1, x6+ adcs x2, x2, xzr+ neg x7, x6+ adc x3, x3, x7+ stp x0, x1, [x15]+ stp x2, x3, [x15, #16]+ mov x1, #0x8+ mov x2, #0xffffffffffffffff+ ldp x9, x10, [sp]+ subs x9, x2, x9+ mov x2, #0xffffffff+ sbcs x10, x2, x10+ ldp x11, x12, [sp, #16]+ ngcs x11, x11+ mov x2, #0xffffffff00000001+ sbc x12, x2, x12+ lsl x3, x9, #3+ extr x4, x10, x9, #61+ extr x5, x11, x10, #61+ extr x6, x12, x11, #61+ lsr x7, x12, #61+ mov x1, #0x3+ ldp x9, x10, [sp, #96]+ mul x8, x9, x1+ umulh x9, x9, x1+ adds x3, x3, x8+ mul x8, x10, x1+ umulh x10, x10, x1+ adcs x4, x4, x8+ ldp x11, x12, [sp, #112]+ mul x8, x11, x1+ umulh x11, x11, x1+ adcs x5, x5, x8+ mul x8, x12, x1+ umulh x12, x12, x1+ adcs x6, x6, x8+ adc x7, x7, xzr+ adds x4, x4, x9+ adcs x5, x5, x10+ adcs x6, x6, x11+ adc x7, x7, x12+ add x8, x7, #0x1+ lsl x10, x8, #32+ adds x6, x6, x10+ adc x7, x7, xzr+ neg x9, x8+ sub x10, x10, #0x1+ subs x3, x3, x9+ sbcs x4, x4, x10+ sbcs x5, x5, xzr+ sbcs x6, x6, x8+ sbc x8, x7, x8+ adds x3, x3, x8+ and x9, x8, #0xffffffff+ adcs x4, x4, x9+ adcs x5, x5, xzr+ neg x10, x9+ adc x6, x6, x10+ stp x3, x4, [x15, #32]+ stp x5, x6, [x15, #48]+ CFI_INC_SP(192)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_p256_montjdouble)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_local_p256_montjmixadd)++Lp256_scalarmul_alt_local_p256_montjmixadd:+ CFI_START+ CFI_DEC_SP(192)+ mov x15, x0+ mov x16, x1+ mov x17, x2+ ldp x2, x3, [x16, #64]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x16, #80]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ mov x2, #0xffffffffffffffff+ csel x2, xzr, x2, cc+ mov x3, #0xffffffff+ csel x3, xzr, x3, cc+ mov x5, #0xffffffff00000001+ csel x5, xzr, x5, cc+ subs x8, x8, x2+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbc x11, x11, x5+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x3, x4, [x16, #64]+ ldp x7, x8, [x17, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x17, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [x16, #80]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #32]+ stp x14, x0, [sp, #48]+ ldp x3, x4, [sp]+ ldp x7, x8, [x17]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x17, #16]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #64]+ stp x14, x0, [sp, #80]+ ldp x3, x4, [sp]+ ldp x7, x8, [sp, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #32]+ stp x14, x0, [sp, #48]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [x16]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [x16, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #160]+ stp x7, x8, [sp, #176]+ ldp x5, x6, [sp, #32]+ ldp x4, x3, [x16, #32]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #48]+ ldp x4, x3, [x16, #48]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #32]+ stp x7, x8, [sp, #48]+ ldp x2, x3, [sp, #160]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #176]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ mov x2, #0xffffffffffffffff+ csel x2, xzr, x2, cc+ mov x3, #0xffffffff+ csel x3, xzr, x3, cc+ mov x5, #0xffffffff00000001+ csel x5, xzr, x5, cc+ subs x8, x8, x2+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbc x11, x11, x5+ stp x8, x9, [sp, #96]+ stp x10, x11, [sp, #112]+ ldp x2, x3, [sp, #32]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #48]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ mov x5, #0xffffffff00000001+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [x16]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #16]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [sp, #64]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #80]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #64]+ stp x14, x0, [sp, #80]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldp x3, x4, [sp, #160]+ ldp x7, x8, [x16, #64]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #80]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #176]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #160]+ stp x14, x0, [sp, #176]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #64]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #80]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [x16, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #96]+ stp x14, x0, [sp, #112]+ ldp x3, x4, [sp, #32]+ ldp x7, x8, [sp, #128]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #144]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #48]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x0, x1, [x16, #64]+ ldp x2, x3, [x16, #80]+ orr x4, x0, x1+ orr x5, x2, x3+ orr x4, x4, x5+ cmp x4, xzr+ ldp x0, x1, [sp]+ ldp x12, x13, [x17]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x2, x3, [sp, #16]+ ldp x12, x13, [x17, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x4, x5, [sp, #128]+ ldp x12, x13, [x17, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x6, x7, [sp, #144]+ ldp x12, x13, [x17, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x8, x9, [sp, #160]+ mov x12, #0x1+ mov x13, #0xffffffff00000000+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x10, x11, [sp, #176]+ mov x12, #0xffffffffffffffff+ mov x13, #0xfffffffe+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ stp x0, x1, [x15]+ stp x2, x3, [x15, #16]+ stp x4, x5, [x15, #32]+ stp x6, x7, [x15, #48]+ stp x8, x9, [x15, #64]+ stp x10, x11, [x15, #80]+ CFI_INC_SP(192)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_local_p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_scalarmulbase.S view
@@ -0,0 +1,3782 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for precomputed point on NIST curve P-256+// Input scalar[4], blocksize, table[]; output res[8]+//+// extern void p256_scalarmulbase+// (uint64_t res[static 8],+// const uint64_t scalar[static 4],+// uint64_t blocksize,+// const uint64_t *table);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, the input argument "table" is expected to be a table of+// multiples of the point P in Montgomery-affine form, with each block+// corresponding to "blocksize" bits of the scalar as follows, where+// B = 2^{blocksize-1} (e.g. B = 8 for blocksize = 4):+//+// For each i,j with blocksize * i <= 256 and 1 <= j <= B+// the multiple 2^{blocksize * i} * j * P is stored at+// tab[8 * (B * i + (j - 1))], considered as uint64_t pointers+// or tab + 64 * (B * i + (j - 1)) as byte pointers.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = blocksize, X3 = table+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmulbase)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmulbase)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmulbase)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Safe copies of inputs and additional variables, with some aliasing++#define res x19+#define blocksize x20+#define table x21+#define i x22+#define bf x23+#define cf x24+#define j x25++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on "nacc", which is no longer needed at the end.+// Uppercase syntactic variants make x86_att version simpler to generate++#define rscalar sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define nacc sp, #(4*NUMSIZE)+#define tabent sp, #(7*NUMSIZE)++#define z2 sp, #(4*NUMSIZE)+#define z3 sp, #(5*NUMSIZE)++#define NSPACE 9*NUMSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p256_scalarmulbase):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the input arguments except the scalar, since that gets absorbed+// immediately. The "table" value subsequently gets shifted up each iteration+// of the loop, while "res" and "blocksize" are static throughout.++ mov res, x0+ mov blocksize, x2+ mov table, x3++// Load the digits of group order n_256 = [x15;x14;x13;x12]++ movbig(x12, #0xf3b9, #0xcac2, #0xfc63, #0x2551)+ movbig(x13, #0xbce6, #0xfaad, #0xa717, #0x9e84)+ mov x14, #0xffffffffffffffff+ mov x15, #0xffffffff00000000++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256+// Store it to "rscalar" (reduced scalar)++ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]++ subs x6, x2, x12+ sbcs x7, x3, x13+ sbcs x8, x4, x14+ sbcs x9, x5, x15++ csel x2, x2, x6, cc+ csel x3, x3, x7, cc+ csel x4, x4, x8, cc+ csel x5, x5, x9, cc++ stp x2, x3, [rscalar]+ stp x4, x5, [rscalar+16]++// Initialize the accumulator to all zeros and the "carry flag" cf to 0++ stp xzr, xzr, [acc]+ stp xzr, xzr, [acc+16]+ stp xzr, xzr, [acc+32]+ stp xzr, xzr, [acc+48]+ stp xzr, xzr, [acc+64]+ stp xzr, xzr, [acc+80]+ mov cf, xzr++// Main loop over {i >= 0 | blocksize * i <= 256}. Note the non-strict+// inequality, to allow top carry for any choices of blocksize.++ mov i, xzr++Lp256_scalarmulbase_loop:++// The next raw bitfield is bf = bitfield(blocksize * i,blocksize) + cf,+// adding in the deferred carry cf. We then shift the whole scalar right+// by blocksize so we can keep picking bitfield(0,blocksize).++ ldp x0, x1, [rscalar]+ ldp x2, x3, [rscalar+16]++ mov x4, #1+ lsl x4, x4, blocksize+ sub x4, x4, #1+ and x4, x4, x0+ add bf, x4, cf++ neg x8, blocksize++ lsl x5, x1, x8++ lsr x0, x0, blocksize+ orr x0, x0, x5++ lsl x6, x2, x8+ lsr x1, x1, blocksize+ orr x1, x1, x6++ lsl x7, x3, x8+ lsr x2, x2, blocksize+ orr x2, x2, x7++ lsr x3, x3, blocksize++ stp x0, x1, [rscalar]+ stp x2, x3, [rscalar+16]++// Now if bf <= B we just select entry j, unnegated and set cf = 0.+// If bf > B we set j = 2 * B - bf and negate the j'th entry, setting cf = 1.+// In either case we ultimately add bf, in the latter case with deferred+// carry as 2 * B - (2 * B - bf) = bf.++ mov x0, #1+ lsl x1, x0, blocksize+ lsr x0, x1, #1++ sub x2, x1, bf++ cmp x0, bf+ cset cf, cc+ csel j, x2, bf, cc++// Load table entry j - 1 for nonzero j in constant-time style.++ mov x16, #1+ lsl x16, x16, blocksize+ lsr x16, x16, #1+ mov x17, j++Lp256_scalarmulbase_tabloop:+ ldp x8, x9, [table]+ ldp x10, x11, [table, #16]+ ldp x12, x13, [table, #32]+ ldp x14, x15, [table, #48]++ subs x17, x17, #1+ csel x0, x8, x0, eq+ csel x1, x9, x1, eq+ csel x2, x10, x2, eq+ csel x3, x11, x3, eq+ csel x4, x12, x4, eq+ csel x5, x13, x5, eq+ csel x6, x14, x6, eq+ csel x7, x15, x7, eq++ add table, table, #64++ sub x16, x16, #1+ cbnz x16, Lp256_scalarmulbase_tabloop++// Before storing back, optionally negate the y coordinate of the table entry++ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]++ mov x0, 0xffffffffffffffff+ subs x0, x0, x4+ mov x1, 0x00000000ffffffff+ sbcs x1, x1, x5+ mov x3, 0xffffffff00000001+ sbcs x2, xzr, x6+ sbc x3, x3, x7++ cmp cf, xzr+ csel x4, x0, x4, ne+ csel x5, x1, x5, ne+ csel x6, x2, x6, ne+ csel x7, x3, x7, ne++ stp x4, x5, [tabent+32]+ stp x6, x7, [tabent+48]++// Add the adjusted table point to the accumulator++ add x0, nacc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp256_scalarmulbase_local_p256_montjmixadd)++// However, only commit that update to the accumulator if j is nonzero,+// because the mixed addition function does not handle this case directly,+// and in any case we didn't choose the table entry appropriately.++ cmp j, xzr+ ldp x0, x1, [acc]+ ldp x12, x13, [nacc]+ csel x0, x12, x0, ne+ csel x1, x13, x1, ne++ ldp x2, x3, [acc+16]+ ldp x12, x13, [nacc+16]+ csel x2, x12, x2, ne+ csel x3, x13, x3, ne++ ldp x4, x5, [acc+32]+ ldp x12, x13, [nacc+32]+ csel x4, x12, x4, ne+ csel x5, x13, x5, ne++ ldp x6, x7, [acc+48]+ ldp x12, x13, [nacc+48]+ csel x6, x12, x6, ne+ csel x7, x13, x7, ne++ ldp x8, x9, [acc+64]+ ldp x12, x13, [nacc+64]+ csel x8, x12, x8, ne+ csel x9, x13, x9, ne++ ldp x10, x11, [acc+80]+ ldp x12, x13, [nacc+80]+ csel x10, x12, x10, ne+ csel x11, x13, x11, ne++ stp x0, x1, [acc]+ stp x2, x3, [acc+16]+ stp x4, x5, [acc+32]+ stp x6, x7, [acc+48]+ stp x8, x9, [acc+64]+ stp x10, x11, [acc+80]++// Loop while blocksize * i <= 256++ add i, i, #1+ mul x0, blocksize, i+ cmp x0, #257+ bcc Lp256_scalarmulbase_loop++// That's the end of the main loop, and we just need to translate+// back from the Jacobian representation to affine. First of all,+// let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ add x0, z2+ add x1, acc+64+ CFI_BL(Lp256_scalarmulbase_local_montsqr_p256)++ add x0, z3+ add x1, acc+64+ add x2, z2+ CFI_BL(Lp256_scalarmulbase_local_montmul_p256)++ add x0, z2+ add x1, z3+ CFI_BL(Lp256_scalarmulbase_local_demont_p256)++ add x0, z3+ add x1, z2+ CFI_BL(Lp256_scalarmulbase_local_inv_p256)++ add x0, z2+ add x1, acc+64+ add x2, z3+ CFI_BL(Lp256_scalarmulbase_local_montmul_p256)++// Convert back from Jacobian (X,Y,Z) |-> (X/Z^2, Y/Z^3)++ mov x0, res+ add x1, acc+ add x2, z2+ CFI_BL(Lp256_scalarmulbase_local_montmul_p256)++ add x0, res, #32+ add x1, acc+32+ add x2, z3+ CFI_BL(Lp256_scalarmulbase_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x25,x30)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmulbase)++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_demont_p256)++Lp256_scalarmulbase_local_demont_p256:+ CFI_START+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ lsl x7, x2, #32+ subs x8, x2, x7+ lsr x6, x2, #32+ sbc x2, x2, x6+ adds x3, x3, x7+ adcs x4, x4, x6+ adcs x5, x5, x8+ adc x2, x2, xzr+ lsl x7, x3, #32+ subs x8, x3, x7+ lsr x6, x3, #32+ sbc x3, x3, x6+ adds x4, x4, x7+ adcs x5, x5, x6+ adcs x2, x2, x8+ adc x3, x3, xzr+ lsl x7, x4, #32+ subs x8, x4, x7+ lsr x6, x4, #32+ sbc x4, x4, x6+ adds x5, x5, x7+ adcs x2, x2, x6+ adcs x3, x3, x8+ adc x4, x4, xzr+ lsl x7, x5, #32+ subs x8, x5, x7+ lsr x6, x5, #32+ sbc x5, x5, x6+ adds x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x8+ adc x5, x5, xzr+ stp x2, x3, [x0]+ stp x4, x5, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_demont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_inv_p256)++Lp256_scalarmulbase_local_inv_p256:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(160)+ mov x20, x0+ mov x10, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x13, #0xffffffff00000001+ stp x10, x11, [sp]+ stp xzr, x13, [sp, #16]+ str xzr, [sp, #32]+ ldp x2, x3, [x1]+ subs x10, x2, x10+ sbcs x11, x3, x11+ ldp x4, x5, [x1, #16]+ sbcs x12, x4, xzr+ sbcs x13, x5, x13+ csel x2, x2, x10, cc+ csel x3, x3, x11, cc+ csel x4, x4, x12, cc+ csel x5, x5, x13, cc+ stp x2, x3, [sp, #48]+ stp x4, x5, [sp, #64]+ str xzr, [sp, #80]+ stp xzr, xzr, [sp, #96]+ stp xzr, xzr, [sp, #112]+ mov x10, #0x4000000000000+ stp x10, xzr, [sp, #128]+ stp xzr, xzr, [sp, #144]+ mov x21, #0xa+ mov x22, #0x1+ b Lp256_scalarmulbase_inv_midloop+Lp256_scalarmulbase_inv_loop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #48]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #64]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #56]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ ldr x23, [sp, #32]+ eor x3, x23, x14+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #72]+ eor x1, x8, x15+ ldr x24, [sp, #80]+ eor x0, x24, x15+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ asr x3, x3, #59+ str x3, [sp, #32]+ eor x1, x7, x16+ eor x5, x23, x16+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ eor x0, x24, x17+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #64]+ extr x2, x5, x2, #59+ str x2, [sp, #72]+ asr x5, x5, #59+ str x5, [sp, #80]+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #128]+ adc x3, x3, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #136]+ adc x4, x4, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #144]+ adc x2, x2, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x6, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x6, x6, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x6, x6, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x6, x6, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ stp x1, x6, [sp, #96]+ stp x5, x3, [sp, #112]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ ldp x0, x1, [sp, #128]+ ldr x3, [sp, #144]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x3, x3, x11+ mov x10, #0x2000000000000000+ adcs x2, x2, x10+ mov x14, #0x1fffffffe0000000+ adc x5, x5, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x3, x3, x10+ adcs x2, x2, x14+ adcs x5, x5, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x3, x3, x11+ sbcs x2, x2, xzr+ sbc x5, x5, x10+ stp x1, x3, [sp, #128]+ stp x2, x5, [sp, #144]+Lp256_scalarmulbase_inv_midloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #48]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ bne Lp256_scalarmulbase_inv_loop+ ldr x0, [sp]+ ldr x1, [sp, #48]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x2, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x2, x2, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x2, x2, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x2, x2, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ mov x10, #0xffffffffffffffff+ subs x10, x1, x10+ mov x11, #0xffffffff+ sbcs x11, x2, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x5, xzr+ sbcs x13, x3, x13+ csel x10, x1, x10, cc+ csel x11, x2, x11, cc+ csel x12, x5, x12, cc+ csel x13, x3, x13, cc+ stp x10, x11, [x20]+ stp x12, x13, [x20, #16]+ CFI_INC_SP(160)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_inv_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_montmul_p256)++Lp256_scalarmulbase_local_montmul_p256:+ CFI_START+ ldr q20, [x2]+ ldp x7, x17, [x1]+ ldr q0, [x1]+ ldp x6, x10, [x2]+ ldp x11, x15, [x1, #16]+ rev64 v16.4S, v20.4S+ subs x4, x7, x17+ csetm x3, cc+ cneg x13, x4, cc+ mul v16.4S, v16.4S, v0.4S+ umulh x12, x17, x10+ uzp1 v28.4S, v20.4S, v0.4S+ subs x14, x11, x7+ ldr q20, [x2, #16]+ sbcs x5, x15, x17+ ngc x17, xzr+ subs x8, x11, x15+ uaddlp v27.2D, v16.4S+ umulh x4, x7, x6+ uzp1 v21.4S, v0.4S, v0.4S+ cneg x11, x8, cc+ shl v17.2D, v27.2D, #32+ csetm x15, cc+ subs x9, x10, x6+ eor x7, x14, x17+ umlal v17.2D, v21.2S, v28.2S+ cneg x8, x9, cc+ cinv x9, x3, cc+ cmn x17, #0x1+ ldr q28, [x1, #16]+ adcs x14, x7, xzr+ mul x7, x13, x8+ eor x1, x5, x17+ adcs x5, x1, xzr+ xtn v1.2S, v20.2D+ mov x1, v17.d[0]+ mov x3, v17.d[1]+ uzp2 v16.4S, v20.4S, v20.4S+ umulh x16, x13, x8+ eor x13, x7, x9+ adds x8, x1, x3+ adcs x7, x4, x12+ xtn v0.2S, v28.2D+ adcs x12, x12, xzr+ adds x8, x4, x8+ adcs x3, x3, x7+ ldp x7, x2, [x2, #16]+ adcs x12, x12, xzr+ cmn x9, #0x1+ adcs x8, x8, x13+ eor x13, x16, x9+ adcs x16, x3, x13+ lsl x3, x1, #32+ adc x13, x12, x9+ subs x12, x6, x7+ sbcs x9, x10, x2+ lsr x10, x1, #32+ ngc x4, xzr+ subs x6, x2, x7+ cinv x2, x15, cc+ cneg x6, x6, cc+ subs x7, x1, x3+ eor x9, x9, x4+ sbc x1, x1, x10+ adds x15, x8, x3+ adcs x3, x16, x10+ mul x16, x11, x6+ adcs x8, x13, x7+ eor x13, x12, x4+ adc x10, x1, xzr+ cmn x4, #0x1+ umulh x6, x11, x6+ adcs x11, x13, xzr+ adcs x1, x9, xzr+ lsl x13, x15, #32+ subs x12, x15, x13+ lsr x7, x15, #32+ sbc x15, x15, x7+ adds x9, x3, x13+ adcs x3, x8, x7+ umulh x8, x14, x11+ umull v21.2D, v0.2S, v1.2S+ adcs x12, x10, x12+ umull v3.2D, v0.2S, v16.2S+ adc x15, x15, xzr+ rev64 v24.4S, v20.4S+ stp x12, x15, [x0, #16]+ movi v2.2D, #0x00000000ffffffff+ mul x10, x14, x11+ mul v4.4S, v24.4S, v28.4S+ subs x13, x14, x5+ uzp2 v19.4S, v28.4S, v28.4S+ csetm x15, cc+ usra v3.2D, v21.2D, #32+ mul x7, x5, x1+ umull v21.2D, v19.2S, v16.2S+ cneg x13, x13, cc+ uaddlp v5.2D, v4.4S+ subs x11, x1, x11+ and v16.16B, v3.16B, v2.16B+ umulh x5, x5, x1+ shl v24.2D, v5.2D, #32+ cneg x11, x11, cc+ umlal v16.2D, v19.2S, v1.2S+ cinv x12, x15, cc+ umlal v24.2D, v0.2S, v1.2S+ adds x15, x10, x7+ mul x14, x13, x11+ eor x1, x6, x2+ adcs x6, x8, x5+ stp x9, x3, [x0]+ usra v21.2D, v3.2D, #32+ adcs x9, x5, xzr+ umulh x11, x13, x11+ adds x15, x8, x15+ adcs x7, x7, x6+ eor x8, x14, x12+ usra v21.2D, v16.2D, #32+ adcs x13, x9, xzr+ cmn x12, #0x1+ mov x9, v24.d[1]+ adcs x14, x15, x8+ eor x6, x11, x12+ adcs x6, x7, x6+ mov x5, v24.d[0]+ mov x11, v21.d[1]+ mov x7, v21.d[0]+ adc x3, x13, x12+ adds x12, x5, x9+ adcs x13, x7, x11+ ldp x15, x8, [x0]+ adcs x11, x11, xzr+ adds x12, x7, x12+ eor x16, x16, x2+ adcs x7, x9, x13+ adcs x11, x11, xzr+ cmn x2, #0x1+ ldp x9, x13, [x0, #16]+ adcs x16, x12, x16+ adcs x1, x7, x1+ adc x2, x11, x2+ adds x7, x5, x15+ adcs x15, x16, x8+ eor x5, x17, x4+ adcs x9, x1, x9+ eor x1, x10, x5+ adcs x16, x2, x13+ adc x2, xzr, xzr+ cmn x5, #0x1+ eor x13, x14, x5+ adcs x14, x1, x7+ eor x1, x6, x5+ adcs x6, x13, x15+ adcs x10, x1, x9+ eor x4, x3, x5+ mov x1, #0xffffffff+ adcs x8, x4, x16+ lsr x13, x14, #32+ adcs x17, x2, x5+ adcs x11, x5, xzr+ adc x4, x5, xzr+ adds x12, x10, x7+ adcs x7, x8, x15+ adcs x5, x17, x9+ adcs x9, x11, x16+ lsl x11, x14, #32+ adc x10, x4, x2+ subs x17, x14, x11+ sbc x4, x14, x13+ adds x11, x6, x11+ adcs x12, x12, x13+ lsl x15, x11, #32+ adcs x17, x7, x17+ lsr x7, x11, #32+ adc x13, x4, xzr+ subs x4, x11, x15+ sbc x11, x11, x7+ adds x8, x12, x15+ adcs x15, x17, x7+ adcs x4, x13, x4+ adc x11, x11, xzr+ adds x7, x5, x4+ adcs x17, x9, x11+ adc x13, x10, xzr+ add x12, x13, #0x1+ neg x11, x12+ lsl x4, x12, #32+ adds x17, x17, x4+ sub x4, x4, #0x1+ adc x13, x13, xzr+ subs x11, x8, x11+ sbcs x4, x15, x4+ sbcs x7, x7, xzr+ sbcs x17, x17, x12+ sbcs x13, x13, x12+ mov x12, #0xffffffff00000001+ adds x11, x11, x13+ and x1, x1, x13+ adcs x4, x4, x1+ and x1, x12, x13+ stp x11, x4, [x0]+ adcs x4, x7, xzr+ adc x1, x17, x1+ stp x4, x1, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_montmul_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_montsqr_p256)++Lp256_scalarmulbase_local_montsqr_p256:+ CFI_START+ ldr q19, [x1]+ ldp x9, x13, [x1]+ ldr q23, [x1, #16]+ ldr q0, [x1]+ ldp x1, x10, [x1, #16]+ uzp2 v29.4S, v19.4S, v19.4S+ xtn v4.2S, v19.2D+ umulh x8, x9, x13+ rev64 v20.4S, v23.4S+ umull v16.2D, v19.2S, v19.2S+ umull v1.2D, v29.2S, v4.2S+ mul v20.4S, v20.4S, v0.4S+ subs x14, x9, x13+ umulh x15, x9, x1+ mov x16, v16.d[1]+ umull2 v4.2D, v19.4S, v19.4S+ mov x4, v16.d[0]+ uzp1 v17.4S, v23.4S, v0.4S+ uaddlp v19.2D, v20.4S+ lsr x7, x8, #63+ mul x11, x9, x13+ mov x12, v1.d[0]+ csetm x5, cc+ cneg x6, x14, cc+ mov x3, v4.d[1]+ mov x14, v4.d[0]+ subs x2, x10, x1+ mov x9, v1.d[1]+ cneg x17, x2, cc+ cinv x2, x5, cc+ adds x5, x4, x12, lsl #33+ extr x4, x8, x11, #63+ lsr x8, x12, #31+ uzp1 v20.4S, v0.4S, v0.4S+ shl v19.2D, v19.2D, #32+ adc x16, x16, x8+ adds x8, x14, x9, lsl #33+ lsr x14, x9, #31+ lsl x9, x5, #32+ umlal v19.2D, v20.2S, v17.2S+ adc x14, x3, x14+ adds x16, x16, x11, lsl #1+ lsr x3, x5, #32+ umulh x12, x6, x17+ adcs x4, x8, x4+ adc x11, x14, x7+ subs x8, x5, x9+ sbc x5, x5, x3+ adds x16, x16, x9+ mov x14, v19.d[0]+ mul x17, x6, x17+ adcs x3, x4, x3+ lsl x7, x16, #32+ umulh x13, x13, x10+ adcs x11, x11, x8+ lsr x8, x16, #32+ adc x5, x5, xzr+ subs x9, x16, x7+ sbc x16, x16, x8+ adds x7, x3, x7+ mov x3, v19.d[1]+ adcs x6, x11, x8+ umulh x11, x1, x10+ adcs x5, x5, x9+ eor x8, x12, x2+ adc x9, x16, xzr+ adds x16, x14, x15+ adc x15, x15, xzr+ adds x12, x16, x3+ eor x16, x17, x2+ mul x4, x1, x10+ adcs x15, x15, x13+ adc x17, x13, xzr+ adds x15, x15, x3+ adc x3, x17, xzr+ cmn x2, #0x1+ mul x17, x10, x10+ adcs x12, x12, x16+ adcs x16, x15, x8+ umulh x10, x10, x10+ adc x2, x3, x2+ adds x14, x14, x14+ adcs x12, x12, x12+ adcs x16, x16, x16+ adcs x2, x2, x2+ adc x15, xzr, xzr+ adds x14, x14, x7+ mul x3, x1, x1+ adcs x12, x12, x6+ lsr x7, x14, #32+ adcs x16, x16, x5+ lsl x5, x14, #32+ umulh x13, x1, x1+ adcs x2, x2, x9+ mov x6, #0xffffffff+ adc x15, x15, xzr+ adds x8, x4, x4+ adcs x1, x11, x11+ mov x11, #0xffffffff00000001+ adc x4, xzr, xzr+ subs x9, x14, x5+ sbc x14, x14, x7+ adds x12, x12, x5+ adcs x16, x16, x7+ lsl x5, x12, #32+ lsr x7, x12, #32+ adcs x2, x2, x9+ adcs x14, x15, x14+ adc x15, xzr, xzr+ subs x9, x12, x5+ sbc x12, x12, x7+ adds x16, x16, x5+ adcs x2, x2, x7+ adcs x14, x14, x9+ adcs x12, x15, x12+ adc x15, xzr, xzr+ adds x16, x16, x3+ adcs x2, x2, x13+ adcs x14, x14, x17+ adcs x12, x12, x10+ adc x15, x15, xzr+ adds x2, x2, x8+ adcs x14, x14, x1+ adcs x12, x12, x4+ adcs x15, x15, xzr+ adds x3, x16, #0x1+ sbcs x5, x2, x6+ sbcs x8, x14, xzr+ sbcs x11, x12, x11+ sbcs xzr, x15, xzr+ csel x16, x3, x16, cs+ csel x14, x8, x14, cs+ csel x12, x11, x12, cs+ csel x2, x5, x2, cs+ stp x14, x12, [x0, #16]+ stp x16, x2, [x0]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_montsqr_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_p256_montjmixadd)++Lp256_scalarmulbase_local_p256_montjmixadd:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_DEC_SP(192)+ mov x17, x0+ mov x19, x1+ mov x20, x2+ ldp x2, x3, [x19, #64]+ ldp x4, x5, [x19, #80]+ umull x15, w2, w2+ lsr x11, x2, #32+ umull x16, w11, w11+ umull x11, w2, w11+ adds x15, x15, x11, lsl #33+ lsr x11, x11, #31+ adc x16, x16, x11+ umull x0, w3, w3+ lsr x11, x3, #32+ umull x1, w11, w11+ umull x11, w3, w11+ mul x12, x2, x3+ umulh x13, x2, x3+ adds x0, x0, x11, lsl #33+ lsr x11, x11, #31+ adc x1, x1, x11+ adds x12, x12, x12+ adcs x13, x13, x13+ adc x1, x1, xzr+ adds x16, x16, x12+ adcs x0, x0, x13+ adc x1, x1, xzr+ lsl x12, x15, #32+ subs x13, x15, x12+ lsr x11, x15, #32+ sbc x15, x15, x11+ adds x16, x16, x12+ adcs x0, x0, x11+ adcs x1, x1, x13+ adc x15, x15, xzr+ lsl x12, x16, #32+ subs x13, x16, x12+ lsr x11, x16, #32+ sbc x16, x16, x11+ adds x0, x0, x12+ adcs x1, x1, x11+ adcs x15, x15, x13+ adc x16, x16, xzr+ mul x6, x2, x4+ mul x14, x3, x5+ umulh x8, x2, x4+ subs x10, x2, x3+ cneg x10, x10, cc+ csetm x13, cc+ subs x12, x5, x4+ cneg x12, x12, cc+ mul x11, x10, x12+ umulh x12, x10, x12+ cinv x13, x13, cc+ eor x11, x11, x13+ eor x12, x12, x13+ adds x7, x6, x8+ adc x8, x8, xzr+ umulh x9, x3, x5+ adds x7, x7, x14+ adcs x8, x8, x9+ adc x9, x9, xzr+ adds x8, x8, x14+ adc x9, x9, xzr+ cmn x13, #0x1+ adcs x7, x7, x11+ adcs x8, x8, x12+ adc x9, x9, x13+ adds x6, x6, x6+ adcs x7, x7, x7+ adcs x8, x8, x8+ adcs x9, x9, x9+ adc x10, xzr, xzr+ adds x6, x6, x0+ adcs x7, x7, x1+ adcs x8, x8, x15+ adcs x9, x9, x16+ adc x10, x10, xzr+ lsl x12, x6, #32+ subs x13, x6, x12+ lsr x11, x6, #32+ sbc x6, x6, x11+ adds x7, x7, x12+ adcs x8, x8, x11+ adcs x9, x9, x13+ adcs x10, x10, x6+ adc x6, xzr, xzr+ lsl x12, x7, #32+ subs x13, x7, x12+ lsr x11, x7, #32+ sbc x7, x7, x11+ adds x8, x8, x12+ adcs x9, x9, x11+ adcs x10, x10, x13+ adcs x6, x6, x7+ adc x7, xzr, xzr+ mul x11, x4, x4+ adds x8, x8, x11+ mul x12, x5, x5+ umulh x11, x4, x4+ adcs x9, x9, x11+ adcs x10, x10, x12+ umulh x12, x5, x5+ adcs x6, x6, x12+ adc x7, x7, xzr+ mul x11, x4, x5+ umulh x12, x4, x5+ adds x11, x11, x11+ adcs x12, x12, x12+ adc x13, xzr, xzr+ adds x9, x9, x11+ adcs x10, x10, x12+ adcs x6, x6, x13+ adcs x7, x7, xzr+ mov x11, #0xffffffff+ adds x5, x8, #0x1+ sbcs x11, x9, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x10, xzr+ sbcs x13, x6, x13+ sbcs xzr, x7, xzr+ csel x8, x5, x8, cs+ csel x9, x11, x9, cs+ csel x10, x12, x10, cs+ csel x6, x13, x6, cs+ stp x8, x9, [sp]+ stp x10, x6, [sp, #16]+ ldp x3, x4, [x19, #64]+ ldp x5, x6, [x19, #80]+ ldp x7, x8, [x20, #32]+ ldp x9, x10, [x20, #48]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #32]+ stp x11, x12, [sp, #48]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #32]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #48]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #32]+ stp x3, x4, [sp, #48]+ ldp x3, x4, [sp]+ ldp x5, x6, [sp, #16]+ ldp x7, x8, [x20]+ ldp x9, x10, [x20, #16]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #64]+ stp x11, x12, [sp, #80]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #64]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #80]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #64]+ stp x3, x4, [sp, #80]+ ldp x3, x4, [sp]+ ldp x5, x6, [sp, #16]+ ldp x7, x8, [sp, #32]+ ldp x9, x10, [sp, #48]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #32]+ stp x11, x12, [sp, #48]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #32]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #48]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #32]+ stp x3, x4, [sp, #48]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [x19]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [x19, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #160]+ stp x7, x8, [sp, #176]+ ldp x5, x6, [sp, #32]+ ldp x4, x3, [x19, #32]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #48]+ ldp x4, x3, [x19, #48]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #32]+ stp x7, x8, [sp, #48]+ ldp x2, x3, [sp, #160]+ ldp x4, x5, [sp, #176]+ umull x15, w2, w2+ lsr x11, x2, #32+ umull x16, w11, w11+ umull x11, w2, w11+ adds x15, x15, x11, lsl #33+ lsr x11, x11, #31+ adc x16, x16, x11+ umull x0, w3, w3+ lsr x11, x3, #32+ umull x1, w11, w11+ umull x11, w3, w11+ mul x12, x2, x3+ umulh x13, x2, x3+ adds x0, x0, x11, lsl #33+ lsr x11, x11, #31+ adc x1, x1, x11+ adds x12, x12, x12+ adcs x13, x13, x13+ adc x1, x1, xzr+ adds x16, x16, x12+ adcs x0, x0, x13+ adc x1, x1, xzr+ lsl x12, x15, #32+ subs x13, x15, x12+ lsr x11, x15, #32+ sbc x15, x15, x11+ adds x16, x16, x12+ adcs x0, x0, x11+ adcs x1, x1, x13+ adc x15, x15, xzr+ lsl x12, x16, #32+ subs x13, x16, x12+ lsr x11, x16, #32+ sbc x16, x16, x11+ adds x0, x0, x12+ adcs x1, x1, x11+ adcs x15, x15, x13+ adc x16, x16, xzr+ mul x6, x2, x4+ mul x14, x3, x5+ umulh x8, x2, x4+ subs x10, x2, x3+ cneg x10, x10, cc+ csetm x13, cc+ subs x12, x5, x4+ cneg x12, x12, cc+ mul x11, x10, x12+ umulh x12, x10, x12+ cinv x13, x13, cc+ eor x11, x11, x13+ eor x12, x12, x13+ adds x7, x6, x8+ adc x8, x8, xzr+ umulh x9, x3, x5+ adds x7, x7, x14+ adcs x8, x8, x9+ adc x9, x9, xzr+ adds x8, x8, x14+ adc x9, x9, xzr+ cmn x13, #0x1+ adcs x7, x7, x11+ adcs x8, x8, x12+ adc x9, x9, x13+ adds x6, x6, x6+ adcs x7, x7, x7+ adcs x8, x8, x8+ adcs x9, x9, x9+ adc x10, xzr, xzr+ adds x6, x6, x0+ adcs x7, x7, x1+ adcs x8, x8, x15+ adcs x9, x9, x16+ adc x10, x10, xzr+ lsl x12, x6, #32+ subs x13, x6, x12+ lsr x11, x6, #32+ sbc x6, x6, x11+ adds x7, x7, x12+ adcs x8, x8, x11+ adcs x9, x9, x13+ adcs x10, x10, x6+ adc x6, xzr, xzr+ lsl x12, x7, #32+ subs x13, x7, x12+ lsr x11, x7, #32+ sbc x7, x7, x11+ adds x8, x8, x12+ adcs x9, x9, x11+ adcs x10, x10, x13+ adcs x6, x6, x7+ adc x7, xzr, xzr+ mul x11, x4, x4+ adds x8, x8, x11+ mul x12, x5, x5+ umulh x11, x4, x4+ adcs x9, x9, x11+ adcs x10, x10, x12+ umulh x12, x5, x5+ adcs x6, x6, x12+ adc x7, x7, xzr+ mul x11, x4, x5+ umulh x12, x4, x5+ adds x11, x11, x11+ adcs x12, x12, x12+ adc x13, xzr, xzr+ adds x9, x9, x11+ adcs x10, x10, x12+ adcs x6, x6, x13+ adcs x7, x7, xzr+ mov x11, #0xffffffff+ adds x5, x8, #0x1+ sbcs x11, x9, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x10, xzr+ sbcs x13, x6, x13+ sbcs xzr, x7, xzr+ csel x8, x5, x8, cs+ csel x9, x11, x9, cs+ csel x10, x12, x10, cs+ csel x6, x13, x6, cs+ stp x8, x9, [sp, #96]+ stp x10, x6, [sp, #112]+ ldp x2, x3, [sp, #32]+ ldp x4, x5, [sp, #48]+ umull x15, w2, w2+ lsr x11, x2, #32+ umull x16, w11, w11+ umull x11, w2, w11+ adds x15, x15, x11, lsl #33+ lsr x11, x11, #31+ adc x16, x16, x11+ umull x0, w3, w3+ lsr x11, x3, #32+ umull x1, w11, w11+ umull x11, w3, w11+ mul x12, x2, x3+ umulh x13, x2, x3+ adds x0, x0, x11, lsl #33+ lsr x11, x11, #31+ adc x1, x1, x11+ adds x12, x12, x12+ adcs x13, x13, x13+ adc x1, x1, xzr+ adds x16, x16, x12+ adcs x0, x0, x13+ adc x1, x1, xzr+ lsl x12, x15, #32+ subs x13, x15, x12+ lsr x11, x15, #32+ sbc x15, x15, x11+ adds x16, x16, x12+ adcs x0, x0, x11+ adcs x1, x1, x13+ adc x15, x15, xzr+ lsl x12, x16, #32+ subs x13, x16, x12+ lsr x11, x16, #32+ sbc x16, x16, x11+ adds x0, x0, x12+ adcs x1, x1, x11+ adcs x15, x15, x13+ adc x16, x16, xzr+ mul x6, x2, x4+ mul x14, x3, x5+ umulh x8, x2, x4+ subs x10, x2, x3+ cneg x10, x10, cc+ csetm x13, cc+ subs x12, x5, x4+ cneg x12, x12, cc+ mul x11, x10, x12+ umulh x12, x10, x12+ cinv x13, x13, cc+ eor x11, x11, x13+ eor x12, x12, x13+ adds x7, x6, x8+ adc x8, x8, xzr+ umulh x9, x3, x5+ adds x7, x7, x14+ adcs x8, x8, x9+ adc x9, x9, xzr+ adds x8, x8, x14+ adc x9, x9, xzr+ cmn x13, #0x1+ adcs x7, x7, x11+ adcs x8, x8, x12+ adc x9, x9, x13+ adds x6, x6, x6+ adcs x7, x7, x7+ adcs x8, x8, x8+ adcs x9, x9, x9+ adc x10, xzr, xzr+ adds x6, x6, x0+ adcs x7, x7, x1+ adcs x8, x8, x15+ adcs x9, x9, x16+ adc x10, x10, xzr+ lsl x12, x6, #32+ subs x13, x6, x12+ lsr x11, x6, #32+ sbc x6, x6, x11+ adds x7, x7, x12+ adcs x8, x8, x11+ adcs x9, x9, x13+ adcs x10, x10, x6+ adc x6, xzr, xzr+ lsl x12, x7, #32+ subs x13, x7, x12+ lsr x11, x7, #32+ sbc x7, x7, x11+ adds x8, x8, x12+ adcs x9, x9, x11+ adcs x10, x10, x13+ adcs x6, x6, x7+ adc x7, xzr, xzr+ mul x11, x4, x4+ adds x8, x8, x11+ mul x12, x5, x5+ umulh x11, x4, x4+ adcs x9, x9, x11+ adcs x10, x10, x12+ umulh x12, x5, x5+ adcs x6, x6, x12+ adc x7, x7, xzr+ mul x11, x4, x5+ umulh x12, x4, x5+ adds x11, x11, x11+ adcs x12, x12, x12+ adc x13, xzr, xzr+ adds x9, x9, x11+ adcs x10, x10, x12+ adcs x6, x6, x13+ adcs x7, x7, xzr+ mov x11, #0xffffffff+ adds x5, x8, #0x1+ sbcs x11, x9, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x10, xzr+ sbcs x13, x6, x13+ sbcs xzr, x7, xzr+ csel x8, x5, x8, cs+ csel x9, x11, x9, cs+ csel x10, x12, x10, cs+ csel x6, x13, x6, cs+ stp x8, x9, [sp]+ stp x10, x6, [sp, #16]+ ldp x3, x4, [sp, #96]+ ldp x5, x6, [sp, #112]+ ldp x7, x8, [x19]+ ldp x9, x10, [x19, #16]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #128]+ stp x11, x12, [sp, #144]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #128]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #144]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #128]+ stp x3, x4, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x5, x6, [sp, #112]+ ldp x7, x8, [sp, #64]+ ldp x9, x10, [sp, #80]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #64]+ stp x11, x12, [sp, #80]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #64]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #80]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #64]+ stp x3, x4, [sp, #80]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldp x3, x4, [sp, #160]+ ldp x5, x6, [sp, #176]+ ldp x7, x8, [x19, #64]+ ldp x9, x10, [x19, #80]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #160]+ stp x11, x12, [sp, #176]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #160]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #176]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #160]+ stp x3, x4, [sp, #176]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #64]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #80]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x5, x6, [sp, #112]+ ldp x7, x8, [x19, #32]+ ldp x9, x10, [x19, #48]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #96]+ stp x11, x12, [sp, #112]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #96]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #112]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #96]+ stp x3, x4, [sp, #112]+ ldp x3, x4, [sp, #32]+ ldp x5, x6, [sp, #48]+ ldp x7, x8, [sp, #128]+ ldp x9, x10, [sp, #144]+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x3, x4+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ stp x13, x14, [sp, #128]+ stp x11, x12, [sp, #144]+ mul x11, x5, x9+ mul x13, x6, x10+ umulh x12, x5, x9+ adds x16, x11, x13+ umulh x14, x6, x10+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x15, x5, x6+ cneg x15, x15, cc+ csetm x1, cc+ subs x0, x10, x9+ cneg x0, x0, cc+ mul x16, x15, x0+ umulh x0, x15, x0+ cinv x1, x1, cc+ eor x16, x16, x1+ eor x0, x0, x1+ cmn x1, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x1+ subs x3, x5, x3+ sbcs x4, x6, x4+ ngc x5, xzr+ cmn x5, #0x1+ eor x3, x3, x5+ adcs x3, x3, xzr+ eor x4, x4, x5+ adcs x4, x4, xzr+ subs x7, x7, x9+ sbcs x8, x8, x10+ ngc x9, xzr+ cmn x9, #0x1+ eor x7, x7, x9+ adcs x7, x7, xzr+ eor x8, x8, x9+ adcs x8, x8, xzr+ eor x10, x5, x9+ ldp x15, x1, [sp, #128]+ adds x15, x11, x15+ adcs x1, x12, x1+ ldp x5, x9, [sp, #144]+ adcs x5, x13, x5+ adcs x9, x14, x9+ adc x2, xzr, xzr+ mul x11, x3, x7+ mul x13, x4, x8+ umulh x12, x3, x7+ adds x16, x11, x13+ umulh x14, x4, x8+ adcs x0, x12, x14+ adcs x14, x14, xzr+ adds x12, x12, x16+ adcs x13, x13, x0+ adcs x14, x14, xzr+ subs x3, x3, x4+ cneg x3, x3, cc+ csetm x4, cc+ subs x0, x8, x7+ cneg x0, x0, cc+ mul x16, x3, x0+ umulh x0, x3, x0+ cinv x4, x4, cc+ eor x16, x16, x4+ eor x0, x0, x4+ cmn x4, #0x1+ adcs x12, x12, x16+ adcs x13, x13, x0+ adc x14, x14, x4+ cmn x10, #0x1+ eor x11, x11, x10+ adcs x11, x11, x15+ eor x12, x12, x10+ adcs x12, x12, x1+ eor x13, x13, x10+ adcs x13, x13, x5+ eor x14, x14, x10+ adcs x14, x14, x9+ adcs x3, x2, x10+ adcs x4, x10, xzr+ adc x10, x10, xzr+ adds x13, x13, x15+ adcs x14, x14, x1+ adcs x3, x3, x5+ adcs x4, x4, x9+ adc x10, x10, x2+ lsl x0, x11, #32+ subs x1, x11, x0+ lsr x16, x11, #32+ sbc x11, x11, x16+ adds x12, x12, x0+ adcs x13, x13, x16+ adcs x14, x14, x1+ adc x11, x11, xzr+ lsl x0, x12, #32+ subs x1, x12, x0+ lsr x16, x12, #32+ sbc x12, x12, x16+ adds x13, x13, x0+ adcs x14, x14, x16+ adcs x11, x11, x1+ adc x12, x12, xzr+ adds x3, x3, x11+ adcs x4, x4, x12+ adc x10, x10, xzr+ add x2, x10, #0x1+ lsl x16, x2, #32+ adds x4, x4, x16+ adc x10, x10, xzr+ neg x15, x2+ sub x16, x16, #0x1+ subs x13, x13, x15+ sbcs x14, x14, x16+ sbcs x3, x3, xzr+ sbcs x4, x4, x2+ sbcs x7, x10, x2+ adds x13, x13, x7+ mov x10, #0xffffffff+ and x10, x10, x7+ adcs x14, x14, x10+ adcs x3, x3, xzr+ mov x10, #0xffffffff00000001+ and x10, x10, x7+ adc x4, x4, x10+ stp x13, x14, [sp, #128]+ stp x3, x4, [sp, #144]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x0, x1, [x19, #64]+ ldp x2, x3, [x19, #80]+ orr x4, x0, x1+ orr x5, x2, x3+ orr x4, x4, x5+ cmp x4, xzr+ ldp x0, x1, [sp]+ ldp x12, x13, [x20]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x2, x3, [sp, #16]+ ldp x12, x13, [x20, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x4, x5, [sp, #128]+ ldp x12, x13, [x20, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x6, x7, [sp, #144]+ ldp x12, x13, [x20, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x8, x9, [sp, #160]+ mov x12, #0x1+ mov x13, #0xffffffff00000000+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x10, x11, [sp, #176]+ mov x12, #0xffffffffffffffff+ mov x13, #0xfffffffe+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ stp x0, x1, [x17]+ stp x2, x3, [x17, #16]+ stp x4, x5, [x17, #32]+ stp x6, x7, [x17, #48]+ stp x8, x9, [x17, #64]+ stp x10, x11, [x17, #80]+ CFI_INC_SP(192)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p256_scalarmulbase_alt.S view
@@ -0,0 +1,3057 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for precomputed point on NIST curve P-256+// Input scalar[4], blocksize, table[]; output res[8]+//+// extern void p256_scalarmulbase_alt+// (uint64_t res[static 8],+// const uint64_t scalar[static 4],+// uint64_t blocksize,+// const uint64_t *table);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, the input argument "table" is expected to be a table of+// multiples of the point P in Montgomery-affine form, with each block+// corresponding to "blocksize" bits of the scalar as follows, where+// B = 2^{blocksize-1} (e.g. B = 8 for blocksize = 4):+//+// For each i,j with blocksize * i <= 256 and 1 <= j <= B+// the multiple 2^{blocksize * i} * j * P is stored at+// tab[8 * (B * i + (j - 1))], considered as uint64_t pointers+// or tab + 64 * (B * i + (j - 1)) as byte pointers.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = blocksize, X3 = table+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmulbase_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmulbase_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmulbase_alt)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Safe copies of inputs and additional variables, with some aliasing++#define res x19+#define blocksize x20+#define table x21+#define i x22+#define bf x23+#define cf x24+#define j x25++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on "nacc", which is no longer needed at the end.+// Uppercase syntactic variants make x86_att version simpler to generate++#define rscalar sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define nacc sp, #(4*NUMSIZE)+#define tabent sp, #(7*NUMSIZE)++#define z2 sp, #(4*NUMSIZE)+#define z3 sp, #(5*NUMSIZE)++#define NSPACE 9*NUMSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p256_scalarmulbase_alt):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the input arguments except the scalar, since that gets absorbed+// immediately. The "table" value subsequently gets shifted up each iteration+// of the loop, while "res" and "blocksize" are static throughout.++ mov res, x0+ mov blocksize, x2+ mov table, x3++// Load the digits of group order n_256 = [x15;x14;x13;x12]++ movbig(x12, #0xf3b9, #0xcac2, #0xfc63, #0x2551)+ movbig(x13, #0xbce6, #0xfaad, #0xa717, #0x9e84)+ mov x14, #0xffffffffffffffff+ mov x15, #0xffffffff00000000++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256+// Store it to "rscalar" (reduced scalar)++ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]++ subs x6, x2, x12+ sbcs x7, x3, x13+ sbcs x8, x4, x14+ sbcs x9, x5, x15++ csel x2, x2, x6, cc+ csel x3, x3, x7, cc+ csel x4, x4, x8, cc+ csel x5, x5, x9, cc++ stp x2, x3, [rscalar]+ stp x4, x5, [rscalar+16]++// Initialize the accumulator to all zeros and the "carry flag" cf to 0++ stp xzr, xzr, [acc]+ stp xzr, xzr, [acc+16]+ stp xzr, xzr, [acc+32]+ stp xzr, xzr, [acc+48]+ stp xzr, xzr, [acc+64]+ stp xzr, xzr, [acc+80]+ mov cf, xzr++// Main loop over {i >= 0 | blocksize * i <= 256}. Note the non-strict+// inequality, to allow top carry for any choices of blocksize.++ mov i, xzr++Lp256_scalarmulbase_alt_loop:++// The next raw bitfield is bf = bitfield(blocksize * i,blocksize) + cf,+// adding in the deferred carry cf. We then shift the whole scalar right+// by blocksize so we can keep picking bitfield(0,blocksize).++ ldp x0, x1, [rscalar]+ ldp x2, x3, [rscalar+16]++ mov x4, #1+ lsl x4, x4, blocksize+ sub x4, x4, #1+ and x4, x4, x0+ add bf, x4, cf++ neg x8, blocksize++ lsl x5, x1, x8++ lsr x0, x0, blocksize+ orr x0, x0, x5++ lsl x6, x2, x8+ lsr x1, x1, blocksize+ orr x1, x1, x6++ lsl x7, x3, x8+ lsr x2, x2, blocksize+ orr x2, x2, x7++ lsr x3, x3, blocksize++ stp x0, x1, [rscalar]+ stp x2, x3, [rscalar+16]++// Now if bf <= B we just select entry j, unnegated and set cf = 0.+// If bf > B we set j = 2 * B - bf and negate the j'th entry, setting cf = 1.+// In either case we ultimately add bf, in the latter case with deferred+// carry as 2 * B - (2 * B - bf) = bf.++ mov x0, #1+ lsl x1, x0, blocksize+ lsr x0, x1, #1++ sub x2, x1, bf++ cmp x0, bf+ cset cf, cc+ csel j, x2, bf, cc++// Load table entry j - 1 for nonzero j in constant-time style.++ mov x16, #1+ lsl x16, x16, blocksize+ lsr x16, x16, #1+ mov x17, j++Lp256_scalarmulbase_alt_tabloop:+ ldp x8, x9, [table]+ ldp x10, x11, [table, #16]+ ldp x12, x13, [table, #32]+ ldp x14, x15, [table, #48]++ subs x17, x17, #1+ csel x0, x8, x0, eq+ csel x1, x9, x1, eq+ csel x2, x10, x2, eq+ csel x3, x11, x3, eq+ csel x4, x12, x4, eq+ csel x5, x13, x5, eq+ csel x6, x14, x6, eq+ csel x7, x15, x7, eq++ add table, table, #64++ sub x16, x16, #1+ cbnz x16, Lp256_scalarmulbase_alt_tabloop++// Before storing back, optionally negate the y coordinate of the table entry++ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]++ mov x0, 0xffffffffffffffff+ subs x0, x0, x4+ mov x1, 0x00000000ffffffff+ sbcs x1, x1, x5+ mov x3, 0xffffffff00000001+ sbcs x2, xzr, x6+ sbc x3, x3, x7++ cmp cf, xzr+ csel x4, x0, x4, ne+ csel x5, x1, x5, ne+ csel x6, x2, x6, ne+ csel x7, x3, x7, ne++ stp x4, x5, [tabent+32]+ stp x6, x7, [tabent+48]++// Add the adjusted table point to the accumulator++ add x0, nacc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp256_scalarmulbase_alt_local_p256_montjmixadd)++// However, only commit that update to the accumulator if j is nonzero,+// because the mixed addition function does not handle this case directly,+// and in any case we didn't choose the table entry appropriately.++ cmp j, xzr+ ldp x0, x1, [acc]+ ldp x12, x13, [nacc]+ csel x0, x12, x0, ne+ csel x1, x13, x1, ne++ ldp x2, x3, [acc+16]+ ldp x12, x13, [nacc+16]+ csel x2, x12, x2, ne+ csel x3, x13, x3, ne++ ldp x4, x5, [acc+32]+ ldp x12, x13, [nacc+32]+ csel x4, x12, x4, ne+ csel x5, x13, x5, ne++ ldp x6, x7, [acc+48]+ ldp x12, x13, [nacc+48]+ csel x6, x12, x6, ne+ csel x7, x13, x7, ne++ ldp x8, x9, [acc+64]+ ldp x12, x13, [nacc+64]+ csel x8, x12, x8, ne+ csel x9, x13, x9, ne++ ldp x10, x11, [acc+80]+ ldp x12, x13, [nacc+80]+ csel x10, x12, x10, ne+ csel x11, x13, x11, ne++ stp x0, x1, [acc]+ stp x2, x3, [acc+16]+ stp x4, x5, [acc+32]+ stp x6, x7, [acc+48]+ stp x8, x9, [acc+64]+ stp x10, x11, [acc+80]++// Loop while blocksize * i <= 256++ add i, i, #1+ mul x0, blocksize, i+ cmp x0, #257+ bcc Lp256_scalarmulbase_alt_loop++// That's the end of the main loop, and we just need to translate+// back from the Jacobian representation to affine. First of all,+// let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ add x0, z2+ add x1, acc+64+ CFI_BL(Lp256_scalarmulbase_alt_local_montsqr_p256)++ add x0, z3+ add x1, acc+64+ add x2, z2+ CFI_BL(Lp256_scalarmulbase_alt_local_montmul_p256)++ add x0, z2+ add x1, z3+ CFI_BL(Lp256_scalarmulbase_alt_local_demont_p256)++ add x0, z3+ add x1, z2+ CFI_BL(Lp256_scalarmulbase_alt_local_inv_p256)++ add x0, z2+ add x1, acc+64+ add x2, z3+ CFI_BL(Lp256_scalarmulbase_alt_local_montmul_p256)++// Convert back from Jacobian (X,Y,Z) |-> (X/Z^2, Y/Z^3)++ mov x0, res+ add x1, acc+ add x2, z2+ CFI_BL(Lp256_scalarmulbase_alt_local_montmul_p256)++ add x0, res, #32+ add x1, acc+32+ add x2, z3+ CFI_BL(Lp256_scalarmulbase_alt_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x25,x30)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmulbase_alt)++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_demont_p256)++Lp256_scalarmulbase_alt_local_demont_p256:+ CFI_START+ ldp x2, x3, [x1]+ ldp x4, x5, [x1, #16]+ lsl x7, x2, #32+ subs x8, x2, x7+ lsr x6, x2, #32+ sbc x2, x2, x6+ adds x3, x3, x7+ adcs x4, x4, x6+ adcs x5, x5, x8+ adc x2, x2, xzr+ lsl x7, x3, #32+ subs x8, x3, x7+ lsr x6, x3, #32+ sbc x3, x3, x6+ adds x4, x4, x7+ adcs x5, x5, x6+ adcs x2, x2, x8+ adc x3, x3, xzr+ lsl x7, x4, #32+ subs x8, x4, x7+ lsr x6, x4, #32+ sbc x4, x4, x6+ adds x5, x5, x7+ adcs x2, x2, x6+ adcs x3, x3, x8+ adc x4, x4, xzr+ lsl x7, x5, #32+ subs x8, x5, x7+ lsr x6, x5, #32+ sbc x5, x5, x6+ adds x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x8+ adc x5, x5, xzr+ stp x2, x3, [x0]+ stp x4, x5, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_demont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_inv_p256)++Lp256_scalarmulbase_alt_local_inv_p256:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(160)+ mov x20, x0+ mov x10, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x13, #0xffffffff00000001+ stp x10, x11, [sp]+ stp xzr, x13, [sp, #16]+ str xzr, [sp, #32]+ ldp x2, x3, [x1]+ subs x10, x2, x10+ sbcs x11, x3, x11+ ldp x4, x5, [x1, #16]+ sbcs x12, x4, xzr+ sbcs x13, x5, x13+ csel x2, x2, x10, cc+ csel x3, x3, x11, cc+ csel x4, x4, x12, cc+ csel x5, x5, x13, cc+ stp x2, x3, [sp, #48]+ stp x4, x5, [sp, #64]+ str xzr, [sp, #80]+ stp xzr, xzr, [sp, #96]+ stp xzr, xzr, [sp, #112]+ mov x10, #0x4000000000000+ stp x10, xzr, [sp, #128]+ stp xzr, xzr, [sp, #144]+ mov x21, #0xa+ mov x22, #0x1+ b Lp256_scalarmulbase_alt_inv_midloop+Lp256_scalarmulbase_alt_inv_loop:+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ and x0, x12, x16+ and x1, x13, x17+ add x19, x0, x1+ ldr x7, [sp]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #48]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x7, [sp, #8]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #56]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ adc x6, x6, x1+ extr x4, x2, x4, #59+ str x4, [sp]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ adc x4, x4, x1+ extr x5, x3, x5, #59+ str x5, [sp, #48]+ ldr x7, [sp, #16]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #64]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ adc x5, x5, x1+ extr x2, x6, x2, #59+ str x2, [sp, #8]+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ adc x2, x2, x1+ extr x3, x4, x3, #59+ str x3, [sp, #56]+ ldr x7, [sp, #24]+ eor x1, x7, x14+ ldr x23, [sp, #32]+ eor x3, x23, x14+ and x3, x3, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #72]+ eor x1, x8, x15+ ldr x24, [sp, #80]+ eor x0, x24, x15+ and x0, x0, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ extr x6, x5, x6, #59+ str x6, [sp, #16]+ extr x5, x3, x5, #59+ str x5, [sp, #24]+ asr x3, x3, #59+ str x3, [sp, #32]+ eor x1, x7, x16+ eor x5, x23, x16+ and x5, x5, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ eor x0, x24, x17+ and x0, x0, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ extr x4, x2, x4, #59+ str x4, [sp, #64]+ extr x2, x5, x2, #59+ str x2, [sp, #72]+ asr x5, x5, #59+ str x5, [sp, #80]+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x5, x19, x0+ adc x3, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x5, x5, x0+ str x5, [sp, #128]+ adc x3, x3, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x3, x3, x0+ adc x4, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x3, x3, x0+ str x3, [sp, #136]+ adc x4, x4, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ eor x1, x7, x16+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x4, x4, x0+ adc x2, xzr, x1+ eor x1, x8, x17+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x4, x4, x0+ str x4, [sp, #144]+ adc x2, x2, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x6, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x6, x6, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x6, x6, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x6, x6, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ stp x1, x6, [sp, #96]+ stp x5, x3, [sp, #112]+ eor x1, x7, x16+ and x5, x16, x12+ neg x5, x5+ mul x0, x1, x12+ umulh x1, x1, x12+ adds x2, x2, x0+ adc x5, x5, x1+ eor x1, x8, x17+ and x0, x17, x13+ sub x5, x5, x0+ mul x0, x1, x13+ umulh x1, x1, x13+ adds x2, x2, x0+ adc x5, x5, x1+ ldp x0, x1, [sp, #128]+ ldr x3, [sp, #144]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x3, x3, x11+ mov x10, #0x2000000000000000+ adcs x2, x2, x10+ mov x14, #0x1fffffffe0000000+ adc x5, x5, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x3, x3, x10+ adcs x2, x2, x14+ adcs x5, x5, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x3, x3, x11+ sbcs x2, x2, xzr+ sbc x5, x5, x10+ stp x1, x3, [sp, #128]+ stp x2, x5, [sp, #144]+Lp256_scalarmulbase_alt_inv_midloop:+ mov x1, x22+ ldr x2, [sp]+ ldr x3, [sp, #48]+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x8, x4, #0x100, lsl #12+ sbfx x8, x8, #21, #21+ mov x11, #0x100000+ add x11, x11, x11, lsl #21+ add x9, x4, x11+ asr x9, x9, #42+ add x10, x5, #0x100, lsl #12+ sbfx x10, x10, #21, #21+ add x11, x5, x11+ asr x11, x11, #42+ mul x6, x8, x2+ mul x7, x9, x3+ mul x2, x10, x2+ mul x3, x11, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #21, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #42+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #21, #21+ add x15, x5, x15+ asr x15, x15, #42+ mul x6, x12, x2+ mul x7, x13, x3+ mul x2, x14, x2+ mul x3, x15, x3+ add x4, x6, x7+ add x5, x2, x3+ asr x2, x4, #20+ asr x3, x5, #20+ and x4, x2, #0xfffff+ orr x4, x4, #0xfffffe0000000000+ and x5, x3, #0xfffff+ orr x5, x5, #0xc000000000000000+ tst x5, #0x1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ mul x2, x12, x8+ mul x3, x12, x9+ mul x6, x14, x8+ mul x7, x14, x9+ madd x8, x13, x10, x2+ madd x9, x13, x11, x3+ madd x16, x15, x10, x6+ madd x17, x15, x11, x7+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ tst x5, #0x2+ asr x5, x5, #1+ csel x6, x4, xzr, ne+ ccmp x1, xzr, #0x8, ne+ cneg x1, x1, ge+ cneg x6, x6, ge+ csel x4, x5, x4, ge+ add x5, x5, x6+ add x1, x1, #0x2+ asr x5, x5, #1+ add x12, x4, #0x100, lsl #12+ sbfx x12, x12, #22, #21+ mov x15, #0x100000+ add x15, x15, x15, lsl #21+ add x13, x4, x15+ asr x13, x13, #43+ add x14, x5, #0x100, lsl #12+ sbfx x14, x14, #22, #21+ add x15, x5, x15+ asr x15, x15, #43+ mneg x2, x12, x8+ mneg x3, x12, x9+ mneg x4, x14, x8+ mneg x5, x14, x9+ msub x10, x13, x16, x2+ msub x11, x13, x17, x3+ msub x12, x15, x16, x4+ msub x13, x15, x17, x5+ mov x22, x1+ subs x21, x21, #0x1+ bne Lp256_scalarmulbase_alt_inv_loop+ ldr x0, [sp]+ ldr x1, [sp, #48]+ mul x0, x0, x10+ madd x1, x1, x11, x0+ asr x0, x1, #63+ cmp x10, xzr+ csetm x14, mi+ cneg x10, x10, mi+ eor x14, x14, x0+ cmp x11, xzr+ csetm x15, mi+ cneg x11, x11, mi+ eor x15, x15, x0+ cmp x12, xzr+ csetm x16, mi+ cneg x12, x12, mi+ eor x16, x16, x0+ cmp x13, xzr+ csetm x17, mi+ cneg x13, x13, mi+ eor x17, x17, x0+ and x0, x10, x14+ and x1, x11, x15+ add x9, x0, x1+ ldr x7, [sp, #96]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x4, x9, x0+ adc x2, xzr, x1+ ldr x8, [sp, #128]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x4, x4, x0+ str x4, [sp, #96]+ adc x2, x2, x1+ ldr x7, [sp, #104]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x2, x2, x0+ adc x6, xzr, x1+ ldr x8, [sp, #136]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x2, x2, x0+ str x2, [sp, #104]+ adc x6, x6, x1+ ldr x7, [sp, #112]+ eor x1, x7, x14+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x6, x6, x0+ adc x5, xzr, x1+ ldr x8, [sp, #144]+ eor x1, x8, x15+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x6, x6, x0+ str x6, [sp, #112]+ adc x5, x5, x1+ ldr x7, [sp, #120]+ eor x1, x7, x14+ and x3, x14, x10+ neg x3, x3+ mul x0, x1, x10+ umulh x1, x1, x10+ adds x5, x5, x0+ adc x3, x3, x1+ ldr x8, [sp, #152]+ eor x1, x8, x15+ and x0, x15, x11+ sub x3, x3, x0+ mul x0, x1, x11+ umulh x1, x1, x11+ adds x5, x5, x0+ adc x3, x3, x1+ ldp x0, x1, [sp, #96]+ ldr x2, [sp, #112]+ mov x14, #0xe000000000000000+ adds x0, x0, x14+ sbcs x1, x1, xzr+ mov x11, #0x1fffffff+ adcs x2, x2, x11+ mov x10, #0x2000000000000000+ adcs x5, x5, x10+ mov x14, #0x1fffffffe0000000+ adc x3, x3, x14+ lsl x11, x0, #32+ subs x14, x0, x11+ lsr x10, x0, #32+ sbc x0, x0, x10+ adds x1, x1, x11+ adcs x2, x2, x10+ adcs x5, x5, x14+ adcs x3, x3, x0+ mov x14, #0xffffffffffffffff+ mov x11, #0xffffffff+ mov x10, #0xffffffff00000001+ csel x14, x14, xzr, cs+ csel x11, x11, xzr, cs+ csel x10, x10, xzr, cs+ subs x1, x1, x14+ sbcs x2, x2, x11+ sbcs x5, x5, xzr+ sbc x3, x3, x10+ mov x10, #0xffffffffffffffff+ subs x10, x1, x10+ mov x11, #0xffffffff+ sbcs x11, x2, x11+ mov x13, #0xffffffff00000001+ sbcs x12, x5, xzr+ sbcs x13, x3, x13+ csel x10, x1, x10, cc+ csel x11, x2, x11, cc+ csel x12, x5, x12, cc+ csel x13, x3, x13, cc+ stp x10, x11, [x20]+ stp x12, x13, [x20, #16]+ CFI_INC_SP(160)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_inv_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montmul_p256)++Lp256_scalarmulbase_alt_local_montmul_p256:+ CFI_START+ ldp x3, x4, [x1]+ ldp x7, x8, [x2]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x2, #16]+ mul x11, x3, x9+ umulh x15, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x16, x3, x10+ adcs x15, x15, x11+ adc x16, x16, xzr+ ldp x5, x6, [x1, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x15, x15, x11+ mul x11, x4, x10+ adcs x16, x16, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x15, x15, x11+ umulh x11, x4, x9+ adcs x16, x16, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x15, x15, x11+ mul x11, x5, x9+ adcs x16, x16, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x15, x15, x11+ umulh x11, x5, x8+ adcs x16, x16, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x15, x15, x11+ mul x11, x6, x8+ adcs x16, x16, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x15, x15, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x16, x16, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x15, x15, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x15, x15, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x15, lsl #32+ lsr x11, x15, #32+ adcs x13, x13, x11+ mul x11, x15, x10+ umulh x15, x15, x10+ adcs x14, x14, x11+ adc x15, x15, xzr+ adds x12, x12, x16+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x15, x15, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x16, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x15, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x16, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x15, x15, x5, cc+ stp x12, x13, [x0]+ stp x14, x15, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montmul_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montsqr_p256)++Lp256_scalarmulbase_alt_local_montsqr_p256:+ CFI_START+ ldp x2, x3, [x1]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x1, #16]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ mov x5, #0xffffffff00000001+ adds x9, x9, x8, lsl #32+ lsr x2, x8, #32+ adcs x10, x10, x2+ mul x2, x8, x5+ umulh x8, x8, x5+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x2, x9, #32+ adcs x11, x11, x2+ mul x2, x9, x5+ umulh x9, x9, x5+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x2, x10, #32+ adcs x8, x8, x2+ mul x2, x10, x5+ umulh x10, x10, x5+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x2, x11, #32+ adcs x9, x9, x2+ mul x2, x11, x5+ umulh x11, x11, x5+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [x0]+ stp x10, x11, [x0, #16]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montsqr_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_p256_montjmixadd)++Lp256_scalarmulbase_alt_local_p256_montjmixadd:+ CFI_START+ CFI_DEC_SP(192)+ mov x15, x0+ mov x16, x1+ mov x17, x2+ ldp x2, x3, [x16, #64]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x16, #80]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ mov x2, #0xffffffffffffffff+ csel x2, xzr, x2, cc+ mov x3, #0xffffffff+ csel x3, xzr, x3, cc+ mov x5, #0xffffffff00000001+ csel x5, xzr, x5, cc+ subs x8, x8, x2+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbc x11, x11, x5+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x3, x4, [x16, #64]+ ldp x7, x8, [x17, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x17, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [x16, #80]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #32]+ stp x14, x0, [sp, #48]+ ldp x3, x4, [sp]+ ldp x7, x8, [x17]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x17, #16]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #64]+ stp x14, x0, [sp, #80]+ ldp x3, x4, [sp]+ ldp x7, x8, [sp, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #16]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #32]+ stp x14, x0, [sp, #48]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [x16]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [x16, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #160]+ stp x7, x8, [sp, #176]+ ldp x5, x6, [sp, #32]+ ldp x4, x3, [x16, #32]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #48]+ ldp x4, x3, [x16, #48]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #32]+ stp x7, x8, [sp, #48]+ ldp x2, x3, [sp, #160]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #176]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ mov x2, #0xffffffffffffffff+ csel x2, xzr, x2, cc+ mov x3, #0xffffffff+ csel x3, xzr, x3, cc+ mov x5, #0xffffffff00000001+ csel x5, xzr, x5, cc+ subs x8, x8, x2+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbc x11, x11, x5+ stp x8, x9, [sp, #96]+ stp x10, x11, [sp, #112]+ ldp x2, x3, [sp, #32]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #48]+ mul x11, x2, x5+ umulh x12, x2, x5+ mul x6, x2, x4+ umulh x7, x2, x4+ adds x10, x10, x6+ adcs x11, x11, x7+ mul x6, x3, x4+ umulh x7, x3, x4+ adc x7, x7, xzr+ adds x11, x11, x6+ mul x13, x4, x5+ umulh x14, x4, x5+ adcs x12, x12, x7+ mul x6, x3, x5+ umulh x7, x3, x5+ adc x7, x7, xzr+ adds x12, x12, x6+ adcs x13, x13, x7+ adc x14, x14, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ cset x7, cs+ umulh x6, x2, x2+ mul x8, x2, x2+ adds x9, x9, x6+ mul x6, x3, x3+ adcs x10, x10, x6+ umulh x6, x3, x3+ adcs x11, x11, x6+ mul x6, x4, x4+ adcs x12, x12, x6+ umulh x6, x4, x4+ adcs x13, x13, x6+ mul x6, x5, x5+ adcs x14, x14, x6+ umulh x6, x5, x5+ adc x7, x7, x6+ adds x9, x9, x8, lsl #32+ lsr x3, x8, #32+ adcs x10, x10, x3+ mov x3, #0xffffffff00000001+ mul x2, x8, x3+ umulh x8, x8, x3+ adcs x11, x11, x2+ adc x8, x8, xzr+ adds x10, x10, x9, lsl #32+ lsr x3, x9, #32+ adcs x11, x11, x3+ mov x3, #0xffffffff00000001+ mul x2, x9, x3+ umulh x9, x9, x3+ adcs x8, x8, x2+ adc x9, x9, xzr+ adds x11, x11, x10, lsl #32+ lsr x3, x10, #32+ adcs x8, x8, x3+ mov x3, #0xffffffff00000001+ mul x2, x10, x3+ umulh x10, x10, x3+ adcs x9, x9, x2+ adc x10, x10, xzr+ adds x8, x8, x11, lsl #32+ lsr x3, x11, #32+ adcs x9, x9, x3+ mov x3, #0xffffffff00000001+ mul x2, x11, x3+ umulh x11, x11, x3+ adcs x10, x10, x2+ adc x11, x11, xzr+ adds x8, x8, x12+ adcs x9, x9, x13+ adcs x10, x10, x14+ adcs x11, x11, x7+ cset x2, cs+ mov x3, #0xffffffff+ mov x5, #0xffffffff00000001+ adds x12, x8, #0x1+ sbcs x13, x9, x3+ sbcs x14, x10, xzr+ sbcs x7, x11, x5+ sbcs xzr, x2, xzr+ csel x8, x8, x12, cc+ csel x9, x9, x13, cc+ csel x10, x10, x14, cc+ csel x11, x11, x7, cc+ stp x8, x9, [sp]+ stp x10, x11, [sp, #16]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [x16]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #16]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [sp, #64]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #80]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #64]+ stp x14, x0, [sp, #80]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #64]+ ldp x4, x3, [sp, #128]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #80]+ ldp x4, x3, [sp, #144]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #96]+ stp x7, x8, [sp, #112]+ ldp x3, x4, [sp, #160]+ ldp x7, x8, [x16, #64]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #80]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #176]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #160]+ stp x14, x0, [sp, #176]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #64]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #80]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x3, x4, [sp, #96]+ ldp x7, x8, [x16, #32]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [x16, #48]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #112]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #96]+ stp x14, x0, [sp, #112]+ ldp x3, x4, [sp, #32]+ ldp x7, x8, [sp, #128]+ mul x12, x3, x7+ umulh x13, x3, x7+ mul x11, x3, x8+ umulh x14, x3, x8+ adds x13, x13, x11+ ldp x9, x10, [sp, #144]+ mul x11, x3, x9+ umulh x0, x3, x9+ adcs x14, x14, x11+ mul x11, x3, x10+ umulh x1, x3, x10+ adcs x0, x0, x11+ adc x1, x1, xzr+ ldp x5, x6, [sp, #48]+ mul x11, x4, x7+ adds x13, x13, x11+ mul x11, x4, x8+ adcs x14, x14, x11+ mul x11, x4, x9+ adcs x0, x0, x11+ mul x11, x4, x10+ adcs x1, x1, x11+ umulh x3, x4, x10+ adc x3, x3, xzr+ umulh x11, x4, x7+ adds x14, x14, x11+ umulh x11, x4, x8+ adcs x0, x0, x11+ umulh x11, x4, x9+ adcs x1, x1, x11+ adc x3, x3, xzr+ mul x11, x5, x7+ adds x14, x14, x11+ mul x11, x5, x8+ adcs x0, x0, x11+ mul x11, x5, x9+ adcs x1, x1, x11+ mul x11, x5, x10+ adcs x3, x3, x11+ umulh x4, x5, x10+ adc x4, x4, xzr+ umulh x11, x5, x7+ adds x0, x0, x11+ umulh x11, x5, x8+ adcs x1, x1, x11+ umulh x11, x5, x9+ adcs x3, x3, x11+ adc x4, x4, xzr+ mul x11, x6, x7+ adds x0, x0, x11+ mul x11, x6, x8+ adcs x1, x1, x11+ mul x11, x6, x9+ adcs x3, x3, x11+ mul x11, x6, x10+ adcs x4, x4, x11+ umulh x5, x6, x10+ adc x5, x5, xzr+ mov x10, #0xffffffff00000001+ adds x13, x13, x12, lsl #32+ lsr x11, x12, #32+ adcs x14, x14, x11+ mul x11, x12, x10+ umulh x12, x12, x10+ adcs x0, x0, x11+ adc x12, x12, xzr+ umulh x11, x6, x7+ adds x1, x1, x11+ umulh x11, x6, x8+ adcs x3, x3, x11+ umulh x11, x6, x9+ adcs x4, x4, x11+ adc x5, x5, xzr+ adds x14, x14, x13, lsl #32+ lsr x11, x13, #32+ adcs x0, x0, x11+ mul x11, x13, x10+ umulh x13, x13, x10+ adcs x12, x12, x11+ adc x13, x13, xzr+ adds x0, x0, x14, lsl #32+ lsr x11, x14, #32+ adcs x12, x12, x11+ mul x11, x14, x10+ umulh x14, x14, x10+ adcs x13, x13, x11+ adc x14, x14, xzr+ adds x12, x12, x0, lsl #32+ lsr x11, x0, #32+ adcs x13, x13, x11+ mul x11, x0, x10+ umulh x0, x0, x10+ adcs x14, x14, x11+ adc x0, x0, xzr+ adds x12, x12, x1+ adcs x13, x13, x3+ adcs x14, x14, x4+ adcs x0, x0, x5+ cset x8, cs+ mov x11, #0xffffffff+ adds x1, x12, #0x1+ sbcs x3, x13, x11+ sbcs x4, x14, xzr+ sbcs x5, x0, x10+ sbcs xzr, x8, xzr+ csel x12, x12, x1, cc+ csel x13, x13, x3, cc+ csel x14, x14, x4, cc+ csel x0, x0, x5, cc+ stp x12, x13, [sp, #128]+ stp x14, x0, [sp, #144]+ ldp x5, x6, [sp, #128]+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #144]+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ csetm x3, cc+ adds x5, x5, x3+ mov x4, #0xffffffff+ and x4, x4, x3+ adcs x6, x6, x4+ adcs x7, x7, xzr+ mov x4, #0xffffffff00000001+ and x4, x4, x3+ adc x8, x8, x4+ stp x5, x6, [sp, #128]+ stp x7, x8, [sp, #144]+ ldp x0, x1, [x16, #64]+ ldp x2, x3, [x16, #80]+ orr x4, x0, x1+ orr x5, x2, x3+ orr x4, x4, x5+ cmp x4, xzr+ ldp x0, x1, [sp]+ ldp x12, x13, [x17]+ csel x0, x0, x12, ne+ csel x1, x1, x13, ne+ ldp x2, x3, [sp, #16]+ ldp x12, x13, [x17, #16]+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ ldp x4, x5, [sp, #128]+ ldp x12, x13, [x17, #32]+ csel x4, x4, x12, ne+ csel x5, x5, x13, ne+ ldp x6, x7, [sp, #144]+ ldp x12, x13, [x17, #48]+ csel x6, x6, x12, ne+ csel x7, x7, x13, ne+ ldp x8, x9, [sp, #160]+ mov x12, #0x1+ mov x13, #0xffffffff00000000+ csel x8, x8, x12, ne+ csel x9, x9, x13, ne+ ldp x10, x11, [sp, #176]+ mov x12, #0xffffffffffffffff+ mov x13, #0xfffffffe+ csel x10, x10, x12, ne+ csel x11, x11, x13, ne+ stp x0, x1, [x15]+ stp x2, x3, [x15, #16]+ stp x4, x5, [x15, #32]+ stp x6, x7, [x15, #48]+ stp x8, x9, [x15, #64]+ stp x10, x11, [x15, #80]+ CFI_INC_SP(192)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p384_montjscalarmul.S view
@@ -0,0 +1,10004 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery-Jacobian form scalar multiplication for P-384+// Input scalar[6], point[18]; output res[18]+//+// extern void p384_montjscalarmul+// (uint64_t res[static 18],+// const uint64_t scalar[static 6],+// const uint64_t point[static 18]);+//+// This function is a variant of its affine point version p384_scalarmul.+// Here, input and output points are assumed to be in Jacobian form with+// their coordinates in the Montgomery domain. Thus, if priming indicates+// Montgomery form, x' = (2^384 * x) mod p_384 etc., each point argument+// is a triple (x',y',z') representing the affine point (x/z^2,y/z^3) when+// z' is nonzero or the point at infinity (group identity) if z' = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-384, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_384) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p384_montjscalarmul)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p384_montjscalarmul)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p384_montjscalarmul)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 48+#define JACSIZE (3*NUMSIZE)++// Safe copies of input res and additional values in variables.++#define bf x22+#define sgn x23+#define j x24+#define res x25++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE++#define scalarb sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define tabent sp, #(4*NUMSIZE)++#define tab sp, #(7*NUMSIZE)++#define NSPACE 55*NUMSIZE++// Avoid using .rep for the sake of the BoringSSL/AWS-LC delocator,+// which doesn't accept repetitions, assembler macros etc.++#define selectblock(I) \+ cmp bf, #(1*I) __LF \+ ldp x20, x21, [x19] __LF \+ csel x0, x20, x0, eq __LF \+ csel x1, x21, x1, eq __LF \+ ldp x20, x21, [x19, #16] __LF \+ csel x2, x20, x2, eq __LF \+ csel x3, x21, x3, eq __LF \+ ldp x20, x21, [x19, #32] __LF \+ csel x4, x20, x4, eq __LF \+ csel x5, x21, x5, eq __LF \+ ldp x20, x21, [x19, #48] __LF \+ csel x6, x20, x6, eq __LF \+ csel x7, x21, x7, eq __LF \+ ldp x20, x21, [x19, #64] __LF \+ csel x8, x20, x8, eq __LF \+ csel x9, x21, x9, eq __LF \+ ldp x20, x21, [x19, #80] __LF \+ csel x10, x20, x10, eq __LF \+ csel x11, x21, x11, eq __LF \+ ldp x20, x21, [x19, #96] __LF \+ csel x12, x20, x12, eq __LF \+ csel x13, x21, x13, eq __LF \+ ldp x20, x21, [x19, #112] __LF \+ csel x14, x20, x14, eq __LF \+ csel x15, x21, x15, eq __LF \+ ldp x20, x21, [x19, #128] __LF \+ csel x16, x20, x16, eq __LF \+ csel x17, x21, x17, eq __LF \+ add x19, x19, #JACSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p384_montjscalarmul):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ mov res, x0++// Reduce the input scalar mod n_384, i.e. conditionally subtract n_384.+// Store it to "scalarb".++ ldp x3, x4, [x1]+ movbig(x15, #0xecec, #0x196a, #0xccc5, #0x2973)+ ldp x5, x6, [x1, #16]+ movbig(x16, #0x581a, #0x0db2, #0x48b0, #0xa77a)+ ldp x7, x8, [x1, #32]+ movbig(x17, #0xc763, #0x4d81, #0xf437, #0x2ddf)++ subs x9, x3, x15+ sbcs x10, x4, x16+ sbcs x11, x5, x17+ adcs x12, x6, xzr+ adcs x13, x7, xzr+ adcs x14, x8, xzr++ csel x3, x3, x9, cc+ csel x4, x4, x10, cc+ csel x5, x5, x11, cc+ csel x6, x6, x12, cc+ csel x7, x7, x13, cc+ csel x8, x8, x14, cc++ stp x3, x4, [scalarb]+ stp x5, x6, [scalarb+16]+ stp x7, x8, [scalarb+32]++// Set the tab[0] table entry to the input point = 1 * P++ ldp x10, x11, [x2]+ stp x10, x11, [tab]+ ldp x12, x13, [x2, #16]+ stp x12, x13, [tab+16]+ ldp x14, x15, [x2, #32]+ stp x14, x15, [tab+32]++ ldp x10, x11, [x2, #48]+ stp x10, x11, [tab+48]+ ldp x12, x13, [x2, #64]+ stp x12, x13, [tab+64]+ ldp x14, x15, [x2, #80]+ stp x14, x15, [tab+80]++ ldp x10, x11, [x2, #96]+ stp x10, x11, [tab+96]+ ldp x12, x13, [x2, #112]+ stp x12, x13, [tab+112]+ ldp x14, x15, [x2, #128]+ stp x14, x15, [tab+128]++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ add x0, tab+JACSIZE*1+ add x1, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, tab+JACSIZE*2+ add x1, tab+JACSIZE*1+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ add x0, tab+JACSIZE*3+ add x1, tab+JACSIZE*1+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, tab+JACSIZE*4+ add x1, tab+JACSIZE*3+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ add x0, tab+JACSIZE*5+ add x1, tab+JACSIZE*2+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, tab+JACSIZE*6+ add x1, tab+JACSIZE*5+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ add x0, tab+JACSIZE*7+ add x1, tab+JACSIZE*3+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, tab+JACSIZE*8+ add x1, tab+JACSIZE*7+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ add x0, tab+JACSIZE*9+ add x1, tab+JACSIZE*4+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, tab+JACSIZE*10+ add x1, tab+JACSIZE*9+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ add x0, tab+JACSIZE*11+ add x1, tab+JACSIZE*5+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, tab+JACSIZE*12+ add x1, tab+JACSIZE*11+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ add x0, tab+JACSIZE*13+ add x1, tab+JACSIZE*6+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, tab+JACSIZE*14+ add x1, tab+JACSIZE*13+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ add x0, tab+JACSIZE*15+ add x1, tab+JACSIZE*7+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically since none is a simple ARM load.+//+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x4210842108421084+// 0x8421084210842108+// 0x0842108421084210++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ movbig(x8, #0x1084, #0x2108, #0x4210, #0x8421)+ adds x0, x0, x8, lsr #1+ adcs x1, x1, x8+ lsl x8, x8, #1+ adcs x2, x2, x8+ lsl x8, x8, #1+ adcs x3, x3, x8+ lsl x8, x8, #1+ adcs x4, x4, x8+ lsr x8, x8, #4+ adcs x5, x5, x8+ cset x6, cs++// Record the top bitfield then shift the whole scalar left 4 bits+// to align the top of the next bitfield with the MSB (bits 379..383).++ extr bf, x6, x5, #60+ extr x5, x5, x4, #60+ extr x4, x4, x3, #60+ extr x3, x3, x2, #60+ extr x2, x2, x1, #60+ extr x1, x1, x0, #60+ lsl x0, x0, #4+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]++// Initialize the accumulator to the corresponding entry using constant-time+// lookup in the table. This top digit, uniquely, is not recoded so there is+// no sign adjustment to make.++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ mov x12, xzr+ mov x13, xzr+ mov x14, xzr+ mov x15, xzr+ mov x16, xzr+ mov x17, xzr++ add x19, tab++ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)++ stp x0, x1, [acc]+ stp x2, x3, [acc+16]+ stp x4, x5, [acc+32]+ stp x6, x7, [acc+48]+ stp x8, x9, [acc+64]+ stp x10, x11, [acc+80]+ stp x12, x13, [acc+96]+ stp x14, x15, [acc+112]+ stp x16, x17, [acc+128]++ mov j, #380++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++Lp384_montjscalarmul_mainloop:+ sub j, j, #5++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_p384_montjdouble)++// Choose the bitfield and adjust it to sign and magnitude++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ lsr bf, x5, #59+ extr x5, x5, x4, #59+ extr x4, x4, x3, #59+ extr x3, x3, x2, #59+ extr x2, x2, x1, #59+ extr x1, x1, x0, #59+ lsl x0, x0, #5+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]++ subs bf, bf, #16+ cset sgn, lo // sgn = sign of digit (1 = negative)+ cneg bf, bf, lo // bf = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ mov x12, xzr+ mov x13, xzr+ mov x14, xzr+ mov x15, xzr+ mov x16, xzr+ mov x17, xzr++ add x19, tab++ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_384 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).++ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]+ stp x4, x5, [tabent+32]++ stp x12, x13, [tabent+96]+ stp x14, x15, [tabent+112]+ stp x16, x17, [tabent+128]++ mov x0, #0x00000000ffffffff+ subs x0, x0, x6+ orr x12, x6, x7+ mov x1, #0xffffffff00000000+ sbcs x1, x1, x7+ orr x13, x8, x9+ mov x2, #0xfffffffffffffffe+ sbcs x2, x2, x8+ orr x14, x10, x11+ mov x5, #0xffffffffffffffff+ sbcs x3, x5, x9+ orr x12, x12, x13+ sbcs x4, x5, x10+ orr x12, x12, x14+ sbcs x5, x5, x11++ cmp sgn, xzr+ ccmp x12, xzr, #4, ne++ csel x6, x0, x6, ne+ csel x7, x1, x7, ne+ csel x8, x2, x8, ne+ csel x9, x3, x9, ne+ csel x10, x4, x10, ne+ csel x11, x5, x11, ne++ stp x6, x7, [tabent+48]+ stp x8, x9, [tabent+64]+ stp x10, x11, [tabent+80]++// Add to the accumulator++ add x0, acc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp384_montjscalarmul_p384_montjadd)++ cbnz j, Lp384_montjscalarmul_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ ldp x0, x1, [acc]+ stp x0, x1, [res]+ ldp x0, x1, [acc+16]+ stp x0, x1, [res, #16]+ ldp x0, x1, [acc+32]+ stp x0, x1, [res, #32]+ ldp x0, x1, [acc+48]+ stp x0, x1, [res, #48]+ ldp x0, x1, [acc+64]+ stp x0, x1, [res, #64]+ ldp x0, x1, [acc+80]+ stp x0, x1, [res, #80]+ ldp x0, x1, [acc+96]+ stp x0, x1, [res, #96]+ ldp x0, x1, [acc+112]+ stp x0, x1, [res, #112]+ ldp x0, x1, [acc+128]+ stp x0, x1, [res, #128]++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x25,x30)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p384_montjscalarmul)++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_p384_montjadd)++Lp384_montjscalarmul_p384_montjadd:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_PUSH1Z(x27)+ CFI_DEC_SP(384)+ mov x24, x0+ mov x25, x1+ mov x26, x2+ mov x0, sp+ ldr q1, [x25, #96]+ ldp x9, x2, [x25, #96]+ ldr q0, [x25, #96]+ ldp x4, x6, [x25, #112]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [x25, #128]+ xtn v30.2s, v0.2d+ ldr q1, [x25, #128]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [x25, #128]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [x0]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [x0, #16]+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [x0, #32]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [x0, #16]+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [x0]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [x0, #32]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [x0]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [x0, #16]+ adc x17, x14, xzr+ stp x2, x17, [x0, #32]+ ldr q1, [x26, #96]+ ldp x9, x2, [x26, #96]+ ldr q0, [x26, #96]+ ldp x4, x6, [x26, #112]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [x26, #128]+ xtn v30.2s, v0.2d+ ldr q1, [x26, #128]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [x26, #128]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [sp, #240]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [sp, #256]+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [sp, #272]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [sp, #256]+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [sp, #240]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [sp, #272]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [sp, #240]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [sp, #256]+ adc x17, x14, xzr+ stp x2, x17, [sp, #272]+ stp x23, x24, [sp, #0x150]+ ldr q3, [x26, #96]+ ldr q25, [x25, #48]+ ldp x13, x23, [x25, #48]+ ldp x3, x21, [x26, #96]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [x25, #80]+ ldp x8, x24, [x26, #112]+ subs x6, x3, x21+ ldr q0, [x26, #128]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [x25, #64]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [x25, #80]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [x26, #128]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #288]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #304]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #320]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #288]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #304]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #320]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #288]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #304]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #320]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #288]+ ldp x21, x12, [sp, #304]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #320]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #288]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #304]+ adc x12, x15, x23+ stp x21, x12, [sp, #320]+ ldr q3, [x25, #96]+ ldr q25, [x26, #48]+ ldp x13, x23, [x26, #48]+ ldp x3, x21, [x25, #96]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [x26, #80]+ ldp x8, x24, [x25, #112]+ subs x6, x3, x21+ ldr q0, [x25, #128]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [x26, #64]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [x26, #80]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [x25, #128]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #48]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #64]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #80]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #48]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #64]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #80]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #48]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #64]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #80]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #48]+ ldp x21, x12, [sp, #64]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #80]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #48]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #64]+ adc x12, x15, x23+ stp x21, x12, [sp, #80]+ mov x1, sp+ ldr q3, [x1]+ ldr q25, [x26]+ ldp x13, x23, [x26]+ ldp x3, x21, [x1]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [x26, #32]+ ldp x8, x24, [x1, #16]+ subs x6, x3, x21+ ldr q0, [x1, #32]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [x26, #16]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [x26, #32]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [x1, #32]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #96]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #112]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #128]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #96]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #112]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #128]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #96]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #112]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #128]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #96]+ ldp x21, x12, [sp, #112]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #128]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #96]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #112]+ adc x12, x15, x23+ stp x21, x12, [sp, #128]+ ldr q3, [sp, #240]+ ldr q25, [x25]+ ldp x13, x23, [x25]+ ldp x3, x21, [sp, #240]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [x25, #32]+ ldp x8, x24, [sp, #256]+ subs x6, x3, x21+ ldr q0, [sp, #272]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [x25, #16]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [x25, #32]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #272]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #192]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #208]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #224]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #192]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #208]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #224]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #192]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #208]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #224]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #192]+ ldp x21, x12, [sp, #208]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #224]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #192]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #208]+ adc x12, x15, x23+ stp x21, x12, [sp, #224]+ mov x1, sp+ ldr q3, [x1]+ ldr q25, [sp, #48]+ ldp x13, x23, [sp, #48]+ ldp x3, x21, [x1]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #80]+ ldp x8, x24, [x1, #16]+ subs x6, x3, x21+ ldr q0, [x1, #32]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #64]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #80]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [x1, #32]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #48]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #64]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #80]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #48]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #64]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #80]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #48]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #64]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #80]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #48]+ ldp x21, x12, [sp, #64]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #80]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #48]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #64]+ adc x12, x15, x23+ stp x21, x12, [sp, #80]+ ldr q3, [sp, #240]+ ldr q25, [sp, #288]+ ldp x13, x23, [sp, #288]+ ldp x3, x21, [sp, #240]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #320]+ ldp x8, x24, [sp, #256]+ subs x6, x3, x21+ ldr q0, [sp, #272]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #304]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #320]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #272]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #288]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #304]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #320]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #288]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #304]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #320]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #288]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #304]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #320]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #288]+ ldp x21, x12, [sp, #304]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #320]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x2, x24, x11+ stp x22, x5, [sp, #288]+ adcs x11, x13, x23+ adcs x12, x8, x23+ stp x2, x11, [sp, #304]+ adc x13, x15, x23+ stp x12, x13, [sp, #320]+ ldp x5, x6, [sp, #96]+ ldp x4, x3, [sp, #192]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #112]+ ldp x4, x3, [sp, #208]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #128]+ ldp x4, x3, [sp, #224]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ ldp x5, x6, [sp, #48]+ ldp x4, x3, [sp, #288]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #64]+ sbcs x7, x7, x2+ sbcs x8, x8, x11+ ldp x9, x10, [sp, #80]+ sbcs x9, x9, x12+ sbcs x10, x10, x13+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #48]+ stp x7, x8, [sp, #64]+ stp x9, x10, [sp, #80]+ ldr q1, [sp, #240]+ ldp x9, x2, [sp, #240]+ ldr q0, [sp, #240]+ ldp x4, x6, [sp, #256]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [sp, #272]+ xtn v30.2s, v0.2d+ ldr q1, [sp, #272]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [sp, #272]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [sp, #144]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [sp, #160]+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [sp, #176]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [sp, #160]+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [sp, #144]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [sp, #176]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [sp, #144]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [sp, #160]+ adc x17, x14, xzr+ stp x2, x17, [sp, #176]+ mov x0, sp+ ldr q1, [sp, #48]+ ldp x9, x2, [sp, #48]+ ldr q0, [sp, #48]+ ldp x4, x6, [sp, #64]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [sp, #80]+ xtn v30.2s, v0.2d+ ldr q1, [sp, #80]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [sp, #80]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [x0]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [x0, #16]+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [x0, #32]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [x0, #16]+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [x0]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [x0, #32]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [x0]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [x0, #16]+ adc x17, x14, xzr+ stp x2, x17, [x0, #32]+ ldr q3, [sp, #144]+ ldr q25, [sp, #192]+ ldp x13, x23, [sp, #192]+ ldp x3, x21, [sp, #144]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #224]+ ldp x8, x24, [sp, #160]+ subs x6, x3, x21+ ldr q0, [sp, #176]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #208]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #224]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #176]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #192]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #208]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #224]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #192]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #208]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #224]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #192]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #208]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #224]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #192]+ ldp x21, x12, [sp, #208]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #224]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #192]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #208]+ adc x12, x15, x23+ stp x21, x12, [sp, #224]+ ldr q3, [sp, #144]+ ldr q25, [sp, #96]+ ldp x13, x23, [sp, #96]+ ldp x3, x21, [sp, #144]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #128]+ ldp x8, x24, [sp, #160]+ subs x6, x3, x21+ ldr q0, [sp, #176]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #112]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #128]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #176]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #96]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #112]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #128]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #96]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #112]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #128]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #96]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #112]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #128]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #96]+ ldp x21, x12, [sp, #112]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #128]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x2, x24, x11+ stp x22, x5, [sp, #96]+ adcs x11, x13, x23+ adcs x12, x8, x23+ stp x2, x11, [sp, #112]+ adc x13, x15, x23+ stp x12, x13, [sp, #128]+ mov x0, sp+ mov x1, sp+ ldp x5, x6, [x1]+ ldp x4, x3, [sp, #192]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [sp, #208]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x1, #32]+ ldp x4, x3, [sp, #224]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [x0]+ stp x7, x8, [x0, #16]+ stp x9, x10, [x0, #32]+ ldp x5, x6, [sp, #96]+ ldp x4, x3, [sp, #192]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x4, x3, [sp, #208]+ sbcs x7, x2, x4+ sbcs x8, x11, x3+ ldp x4, x3, [sp, #224]+ sbcs x9, x12, x4+ sbcs x10, x13, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ ldr q3, [sp, #240]+ ldr q25, [x25, #96]+ ldp x13, x23, [x25, #96]+ ldp x3, x21, [sp, #240]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [x25, #128]+ ldp x8, x24, [sp, #256]+ subs x6, x3, x21+ ldr q0, [sp, #272]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [x25, #112]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [x25, #128]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #272]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #240]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #256]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #272]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #240]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #256]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #272]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #240]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #256]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #272]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #240]+ ldp x21, x12, [sp, #256]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #272]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #240]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #256]+ adc x12, x15, x23+ stp x21, x12, [sp, #272]+ mov x0, sp+ mov x1, sp+ ldp x5, x6, [x1]+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x1, #32]+ ldp x4, x3, [sp, #128]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x2, x5, x4+ eor x4, x4, x3+ adcs x11, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x4, x7, x4+ adcs x12, x8, x3+ adcs x13, x9, x3+ adc x3, x10, x3+ stp x2, x11, [x0]+ stp x4, x12, [x0, #16]+ stp x13, x3, [x0, #32]+ ldp x5, x6, [sp, #192]+ subs x5, x5, x2+ sbcs x6, x6, x11+ ldp x7, x8, [sp, #208]+ sbcs x7, x7, x4+ sbcs x8, x8, x12+ ldp x9, x10, [sp, #224]+ sbcs x9, x9, x13+ sbcs x10, x10, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #192]+ stp x7, x8, [sp, #208]+ stp x9, x10, [sp, #224]+ ldr q3, [sp, #144]+ ldr q25, [sp, #288]+ ldp x13, x23, [sp, #288]+ ldp x3, x21, [sp, #144]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #320]+ ldp x8, x24, [sp, #160]+ subs x6, x3, x21+ ldr q0, [sp, #176]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #304]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #320]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #176]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #144]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #160]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #176]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #144]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #160]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #176]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #144]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #160]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #176]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #144]+ ldp x21, x12, [sp, #160]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #176]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #144]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #160]+ adc x12, x15, x23+ stp x21, x12, [sp, #176]+ ldr q3, [sp, #240]+ ldr q25, [x26, #96]+ ldp x13, x23, [x26, #96]+ ldp x3, x21, [sp, #240]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [x26, #128]+ ldp x8, x24, [sp, #256]+ subs x6, x3, x21+ ldr q0, [sp, #272]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [x26, #112]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [x26, #128]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #272]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #240]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #256]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #272]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #240]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #256]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #272]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #240]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #256]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #272]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #240]+ ldp x21, x12, [sp, #256]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #272]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #240]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #256]+ adc x12, x15, x23+ stp x21, x12, [sp, #272]+ ldp x2, x27, [sp, #0x150]+ ldr q3, [sp, #48]+ ldr q25, [sp, #192]+ ldp x13, x23, [sp, #192]+ ldp x3, x21, [sp, #48]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #224]+ ldp x8, x24, [sp, #64]+ subs x6, x3, x21+ ldr q0, [sp, #80]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #208]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #224]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #80]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #192]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #208]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #224]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #192]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #208]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #224]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #192]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #208]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #224]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #192]+ ldp x21, x12, [sp, #208]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #224]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x2, x6, x20+ eor x3, x20, x23+ adcs x6, x7, x3+ adcs x7, x24, x11+ adcs x9, x13, x23+ adcs x10, x8, x23+ adc x11, x15, x23+ ldp x4, x3, [sp, #144]+ subs x5, x2, x4+ sbcs x6, x6, x3+ ldp x4, x3, [sp, #160]+ sbcs x7, x7, x4+ sbcs x8, x9, x3+ ldp x4, x3, [sp, #176]+ sbcs x9, x10, x4+ sbcs x10, x11, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x19, x5, x4+ eor x4, x4, x3+ adcs x24, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x7, x8, [sp, #208]+ stp x9, x10, [sp, #224]+ ldp x0, x1, [x25, #96]+ ldp x2, x3, [x25, #112]+ ldp x4, x5, [x25, #128]+ orr x20, x0, x1+ orr x21, x2, x3+ orr x22, x4, x5+ orr x20, x20, x21+ orr x20, x20, x22+ cmp x20, xzr+ cset x20, ne // ne = any+ ldp x6, x7, [x26, #96]+ ldp x8, x9, [x26, #112]+ ldp x10, x11, [x26, #128]+ orr x21, x6, x7+ orr x22, x8, x9+ orr x23, x10, x11+ orr x21, x21, x22+ orr x21, x21, x23+ cmp x21, xzr+ cset x21, ne // ne = any+ cmp x21, x20+ ldp x12, x13, [sp, #240]+ csel x12, x0, x12, cc // cc = lo, ul, last+ csel x13, x1, x13, cc // cc = lo, ul, last+ csel x12, x6, x12, hi // hi = pmore+ csel x13, x7, x13, hi // hi = pmore+ ldp x14, x15, [sp, #256]+ csel x14, x2, x14, cc // cc = lo, ul, last+ csel x15, x3, x15, cc // cc = lo, ul, last+ csel x14, x8, x14, hi // hi = pmore+ csel x15, x9, x15, hi // hi = pmore+ ldp x16, x17, [sp, #272]+ csel x16, x4, x16, cc // cc = lo, ul, last+ csel x17, x5, x17, cc // cc = lo, ul, last+ csel x16, x10, x16, hi // hi = pmore+ csel x17, x11, x17, hi // hi = pmore+ ldp x20, x21, [x25]+ ldp x0, x1, [sp]+ csel x0, x20, x0, cc // cc = lo, ul, last+ csel x1, x21, x1, cc // cc = lo, ul, last+ ldp x20, x21, [x26]+ csel x0, x20, x0, hi // hi = pmore+ csel x1, x21, x1, hi // hi = pmore+ ldp x20, x21, [x25, #16]+ ldp x2, x3, [sp, #16]+ csel x2, x20, x2, cc // cc = lo, ul, last+ csel x3, x21, x3, cc // cc = lo, ul, last+ ldp x20, x21, [x26, #16]+ csel x2, x20, x2, hi // hi = pmore+ csel x3, x21, x3, hi // hi = pmore+ ldp x20, x21, [x25, #32]+ ldp x4, x5, [sp, #32]+ csel x4, x20, x4, cc // cc = lo, ul, last+ csel x5, x21, x5, cc // cc = lo, ul, last+ ldp x20, x21, [x26, #32]+ csel x4, x20, x4, hi // hi = pmore+ csel x5, x21, x5, hi // hi = pmore+ ldp x20, x21, [x25, #48]+ csel x6, x20, x19, cc // cc = lo, ul, last+ csel x7, x21, x24, cc // cc = lo, ul, last+ ldp x20, x21, [x26, #48]+ csel x6, x20, x6, hi // hi = pmore+ csel x7, x21, x7, hi // hi = pmore+ ldp x20, x21, [x25, #64]+ ldp x8, x9, [sp, #208]+ csel x8, x20, x8, cc // cc = lo, ul, last+ csel x9, x21, x9, cc // cc = lo, ul, last+ ldp x20, x21, [x26, #64]+ csel x8, x20, x8, hi // hi = pmore+ csel x9, x21, x9, hi // hi = pmore+ ldp x20, x21, [x25, #80]+ ldp x10, x11, [sp, #224]+ csel x10, x20, x10, cc // cc = lo, ul, last+ csel x11, x21, x11, cc // cc = lo, ul, last+ ldp x20, x21, [x26, #80]+ csel x10, x20, x10, hi // hi = pmore+ csel x11, x21, x11, hi // hi = pmore+ stp x0, x1, [x27]+ stp x2, x3, [x27, #16]+ stp x4, x5, [x27, #32]+ stp x6, x7, [x27, #48]+ stp x8, x9, [x27, #64]+ stp x10, x11, [x27, #80]+ stp x12, x13, [x27, #96]+ stp x14, x15, [x27, #112]+ stp x16, x17, [x27, #128]+ CFI_INC_SP(384)+ CFI_POP1Z(x27)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_p384_montjadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_p384_montjdouble)++Lp384_montjscalarmul_p384_montjdouble:+ CFI_START+ CFI_DEC_SP(416)+ stp x19, x20, [sp, #336]+ stp x21, x22, [sp, #352]+ stp x23, x24, [sp, #368]+ stp x25, x26, [sp, #384]+ stp x27, xzr, [sp, #400]+ mov x25, x0+ mov x26, x1+ mov x0, sp+ ldr q1, [x26, #96]+ ldp x9, x2, [x26, #96]+ ldr q0, [x26, #96]+ ldp x4, x6, [x26, #112]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [x26, #128]+ xtn v30.2s, v0.2d+ ldr q1, [x26, #128]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [x26, #128]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [x0]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [x0, #16]+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [x0, #32]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [x0, #16]+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [x0]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [x0, #32]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [x0]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [x0, #16]+ adc x17, x14, xzr+ stp x2, x17, [x0, #32]+ ldr q1, [x26, #48]+ ldp x9, x2, [x26, #48]+ ldr q0, [x26, #48]+ ldp x4, x6, [x26, #64]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [x26, #80]+ xtn v30.2s, v0.2d+ ldr q1, [x26, #80]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [x26, #80]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [sp, #48]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [sp, #64]+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [sp, #80]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [sp, #64]+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [sp, #48]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [sp, #80]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [sp, #48]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [sp, #64]+ adc x17, x14, xzr+ stp x2, x17, [sp, #80]+ ldp x5, x6, [x26]+ ldp x4, x3, [sp]+ adds x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x26, #16]+ ldp x4, x3, [sp, #16]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x26, #32]+ ldp x4, x3, [sp, #32]+ adcs x9, x9, x4+ adcs x10, x10, x3+ csetm x3, cs // cs = hs, nlast+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ subs x5, x5, x4+ eor x4, x4, x3+ sbcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ sbcs x9, x9, x3+ sbc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ mov x2, sp+ ldp x5, x6, [x26]+ ldp x4, x3, [x2]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x26, #16]+ ldp x4, x3, [x2, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x26, #32]+ ldp x4, x3, [x2, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x13, x5, x4+ eor x4, x4, x3+ adcs x23, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x13, x23, [sp, #192]+ stp x7, x8, [sp, #208]+ stp x9, x10, [sp, #224]+ ldr q3, [sp, #240]+ ldr q25, [sp, #192]+ ldp x3, x21, [sp, #240]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #224]+ ldp x8, x24, [sp, #256]+ subs x6, x3, x21+ ldr q0, [sp, #272]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #208]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #224]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #272]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x16, x4, x16+ mov x4, v27.d[0]+ sbcs x11, x20, x11+ sbcs x20, x9, x12+ stp x16, x11, [sp, #96]+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #112]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #128]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ ldp x20, x9, [sp, #96]+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #112]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #128]+ adds x20, x22, x20+ mul x10, x13, x14+ adcs x11, x11, x9+ eor x9, x8, x21+ adcs x21, x19, x17+ stp x20, x11, [sp, #96]+ adcs x12, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ stp x21, x12, [sp, #112]+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #128]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #96]+ ldp x21, x12, [sp, #112]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #128]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x21+ eor x1, x22, x9+ adcs x24, x23, x12+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x21+ adcs x15, x17, x12+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #96]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #112]+ adc x12, x15, x23+ stp x21, x12, [sp, #128]+ ldp x5, x6, [x26, #48]+ ldp x4, x3, [x26, #96]+ adds x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x26, #64]+ ldp x4, x3, [x26, #112]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x26, #80]+ ldp x4, x3, [x26, #128]+ adcs x9, x9, x4+ adcs x10, x10, x3+ adc x3, xzr, xzr+ mov x4, #0xffffffff // #4294967295+ cmp x5, x4+ mov x4, #0xffffffff00000000 // #-4294967296+ sbcs xzr, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ sbcs xzr, x7, x4+ adcs xzr, x8, xzr+ adcs xzr, x9, xzr+ adcs xzr, x10, xzr+ adcs x3, x3, xzr+ csetm x3, ne // ne = any+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ subs x5, x5, x4+ eor x4, x4, x3+ sbcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ sbcs x9, x9, x3+ sbc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ ldr q1, [sp, #96]+ ldp x9, x2, [sp, #96]+ ldr q0, [sp, #96]+ ldp x4, x6, [sp, #112]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [sp, #128]+ xtn v30.2s, v0.2d+ ldr q1, [sp, #128]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [sp, #128]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x15, x3, x17+ sbcs x3, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [sp, #288]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ stp x15, x3, [sp, #304]+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [sp, #320]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ ldp x9, x17, [sp, #304]+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [sp, #288]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [sp, #320]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x9+ adcs x1, x1, x17+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [sp, #288]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [sp, #304]+ adc x17, x14, xzr+ stp x2, x17, [sp, #320]+ ldr q3, [x26]+ ldr q25, [sp, #48]+ ldp x13, x23, [sp, #48]+ ldp x3, x21, [x26]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #80]+ ldp x8, x24, [x26, #16]+ subs x6, x3, x21+ ldr q0, [x26, #32]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #64]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #80]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [x26, #32]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x26, x4, x16+ mov x4, v27.d[0]+ sbcs x27, x20, x11+ sbcs x20, x9, x12+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #160]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #176]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #160]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #176]+ adds x20, x22, x26+ mul x10, x13, x14+ adcs x11, x11, x27+ eor x9, x8, x21+ adcs x26, x19, x17+ stp x20, x11, [sp, #144]+ adcs x27, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #176]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #144]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #176]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x26+ eor x1, x22, x9+ adcs x24, x23, x27+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x26+ adcs x15, x17, x27+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #144]+ adcs x5, x13, x23+ adcs x21, x8, x23+ stp x14, x5, [sp, #160]+ adc x12, x15, x23+ stp x21, x12, [sp, #176]+ ldr q1, [sp, #240]+ ldp x9, x2, [sp, #240]+ ldr q0, [sp, #240]+ ldp x4, x6, [sp, #256]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [sp, #272]+ xtn v30.2s, v0.2d+ ldr q1, [sp, #272]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [sp, #272]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x19, x3, x17+ sbcs x20, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [sp, #192]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [sp, #224]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [sp, #192]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [sp, #224]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x19+ adcs x1, x1, x20+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x19, x13, x1+ and x13, x4, x9+ adcs x20, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [sp, #208]+ adc x17, x14, xzr+ stp x2, x17, [sp, #224]+ ldp x0, x1, [sp, #288]+ mov x6, #0xffffffff // #4294967295+ subs x6, x6, x0+ mov x7, #0xffffffff00000000 // #-4294967296+ sbcs x7, x7, x1+ ldp x0, x1, [sp, #304]+ mov x8, #0xfffffffffffffffe // #-2+ sbcs x8, x8, x0+ mov x13, #0xffffffffffffffff // #-1+ sbcs x9, x13, x1+ ldp x0, x1, [sp, #320]+ sbcs x10, x13, x0+ sbc x11, x13, x1+ mov x12, #0x9 // #9+ mul x0, x12, x6+ mul x1, x12, x7+ mul x2, x12, x8+ mul x3, x12, x9+ mul x4, x12, x10+ mul x5, x12, x11+ umulh x6, x12, x6+ umulh x7, x12, x7+ umulh x8, x12, x8+ umulh x9, x12, x9+ umulh x10, x12, x10+ umulh x12, x12, x11+ adds x1, x1, x6+ adcs x2, x2, x7+ adcs x3, x3, x8+ adcs x4, x4, x9+ adcs x5, x5, x10+ mov x6, #0x1 // #1+ adc x6, x12, x6+ ldp x8, x9, [sp, #144]+ ldp x10, x11, [sp, #160]+ ldp x12, x13, [sp, #176]+ mov x14, #0xc // #12+ mul x15, x14, x8+ umulh x8, x14, x8+ adds x0, x0, x15+ mul x15, x14, x9+ umulh x9, x14, x9+ adcs x1, x1, x15+ mul x15, x14, x10+ umulh x10, x14, x10+ adcs x2, x2, x15+ mul x15, x14, x11+ umulh x11, x14, x11+ adcs x3, x3, x15+ mul x15, x14, x12+ umulh x12, x14, x12+ adcs x4, x4, x15+ mul x15, x14, x13+ umulh x13, x14, x13+ adcs x5, x5, x15+ adc x6, x6, xzr+ adds x1, x1, x8+ adcs x2, x2, x9+ adcs x3, x3, x10+ adcs x4, x4, x11+ adcs x5, x5, x12+ adcs x6, x6, x13+ lsl x7, x6, #32+ subs x8, x6, x7+ sbc x7, x7, xzr+ adds x0, x0, x8+ adcs x1, x1, x7+ adcs x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ csetm x6, cc // cc = lo, ul, last+ mov x7, #0xffffffff // #4294967295+ and x7, x7, x6+ adds x0, x0, x7+ eor x7, x7, x6+ adcs x1, x1, x7+ mov x7, #0xfffffffffffffffe // #-2+ and x7, x7, x6+ adcs x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x6+ adc x5, x5, x6+ stp x0, x1, [sp, #288]+ stp x2, x3, [sp, #304]+ stp x4, x5, [sp, #320]+ mov x2, sp+ ldp x4, x3, [x2]+ subs x5, x19, x4+ sbcs x6, x20, x3+ ldp x7, x8, [sp, #208]+ ldp x4, x3, [x2, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #224]+ ldp x4, x3, [x2, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ ldr q1, [sp, #48]+ ldp x9, x2, [sp, #48]+ ldr q0, [sp, #48]+ ldp x4, x6, [sp, #64]+ rev64 v21.4s, v1.4s+ uzp2 v28.4s, v1.4s, v1.4s+ umulh x7, x9, x2+ xtn v17.2s, v1.2d+ mul v27.4s, v21.4s, v0.4s+ ldr q20, [sp, #80]+ xtn v30.2s, v0.2d+ ldr q1, [sp, #80]+ uzp2 v31.4s, v0.4s, v0.4s+ ldp x5, x10, [sp, #80]+ umulh x8, x9, x4+ uaddlp v3.2d, v27.4s+ umull v16.2d, v30.2s, v17.2s+ mul x16, x9, x4+ umull v27.2d, v30.2s, v28.2s+ shrn v0.2s, v20.2d, #32+ xtn v7.2s, v20.2d+ shl v20.2d, v3.2d, #32+ umull v3.2d, v31.2s, v28.2s+ mul x3, x2, x4+ umlal v20.2d, v30.2s, v17.2s+ umull v22.2d, v7.2s, v0.2s+ usra v27.2d, v16.2d, #32+ umulh x11, x2, x4+ movi v21.2d, #0xffffffff+ uzp2 v28.4s, v1.4s, v1.4s+ adds x15, x16, x7+ and v5.16b, v27.16b, v21.16b+ adcs x3, x3, x8+ usra v3.2d, v27.2d, #32+ dup v29.2d, x6+ adcs x16, x11, xzr+ mov x14, v20.d[0]+ umlal v5.2d, v31.2s, v17.2s+ mul x8, x9, x2+ mov x7, v20.d[1]+ shl v19.2d, v22.2d, #33+ xtn v25.2s, v29.2d+ rev64 v31.4s, v1.4s+ lsl x13, x14, #32+ uzp2 v6.4s, v29.4s, v29.4s+ umlal v19.2d, v7.2s, v7.2s+ usra v3.2d, v5.2d, #32+ adds x1, x8, x8+ umulh x8, x4, x4+ add x12, x13, x14+ mul v17.4s, v31.4s, v29.4s+ xtn v4.2s, v1.2d+ adcs x14, x15, x15+ lsr x13, x12, #32+ adcs x15, x3, x3+ umull v31.2d, v25.2s, v28.2s+ adcs x11, x16, x16+ umull v21.2d, v25.2s, v4.2s+ mov x17, v3.d[0]+ umull v18.2d, v6.2s, v28.2s+ adc x16, x8, xzr+ uaddlp v16.2d, v17.4s+ movi v1.2d, #0xffffffff+ subs x13, x13, x12+ usra v31.2d, v21.2d, #32+ sbc x8, x12, xzr+ adds x17, x17, x1+ mul x1, x4, x4+ shl v28.2d, v16.2d, #32+ mov x3, v3.d[1]+ adcs x14, x7, x14+ extr x7, x8, x13, #32+ adcs x13, x3, x15+ and v3.16b, v31.16b, v1.16b+ adcs x11, x1, x11+ lsr x1, x8, #32+ umlal v3.2d, v6.2s, v4.2s+ usra v18.2d, v31.2d, #32+ adc x3, x16, xzr+ adds x1, x1, x12+ umlal v28.2d, v25.2s, v4.2s+ adc x16, xzr, xzr+ subs x15, x17, x7+ sbcs x7, x14, x1+ lsl x1, x15, #32+ sbcs x16, x13, x16+ add x8, x1, x15+ usra v18.2d, v3.2d, #32+ sbcs x14, x11, xzr+ lsr x1, x8, #32+ sbcs x17, x3, xzr+ sbc x11, x12, xzr+ subs x13, x1, x8+ umulh x12, x4, x10+ sbc x1, x8, xzr+ extr x13, x1, x13, #32+ lsr x1, x1, #32+ adds x15, x1, x8+ adc x1, xzr, xzr+ subs x7, x7, x13+ sbcs x13, x16, x15+ lsl x3, x7, #32+ umulh x16, x2, x5+ sbcs x15, x14, x1+ add x7, x3, x7+ sbcs x3, x17, xzr+ lsr x1, x7, #32+ sbcs x14, x11, xzr+ sbc x11, x8, xzr+ subs x8, x1, x7+ sbc x1, x7, xzr+ extr x8, x1, x8, #32+ lsr x1, x1, #32+ adds x1, x1, x7+ adc x17, xzr, xzr+ subs x13, x13, x8+ umulh x8, x9, x6+ sbcs x1, x15, x1+ sbcs x19, x3, x17+ sbcs x20, x14, xzr+ mul x17, x2, x5+ sbcs x11, x11, xzr+ stp x13, x1, [sp, #192]+ sbc x14, x7, xzr+ mul x7, x4, x10+ subs x1, x9, x2+ csetm x15, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ stp x11, x14, [sp, #224]+ mul x14, x9, x6+ adds x17, x8, x17+ adcs x7, x16, x7+ adc x13, x12, xzr+ subs x12, x5, x6+ cneg x3, x12, cc // cc = lo, ul, last+ cinv x16, x15, cc // cc = lo, ul, last+ mul x8, x1, x3+ umulh x1, x1, x3+ eor x12, x8, x16+ adds x11, x17, x14+ adcs x3, x7, x17+ adcs x15, x13, x7+ adc x8, x13, xzr+ adds x3, x3, x14+ adcs x15, x15, x17+ adcs x17, x8, x7+ eor x1, x1, x16+ adc x13, x13, xzr+ subs x9, x9, x4+ csetm x8, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x4, x2, x4+ cneg x4, x4, cc // cc = lo, ul, last+ csetm x7, cc // cc = lo, ul, last+ subs x2, x10, x6+ cinv x8, x8, cc // cc = lo, ul, last+ cneg x2, x2, cc // cc = lo, ul, last+ cmn x16, #0x1+ adcs x11, x11, x12+ mul x12, x9, x2+ adcs x3, x3, x1+ adcs x15, x15, x16+ umulh x9, x9, x2+ adcs x17, x17, x16+ adc x13, x13, x16+ subs x1, x10, x5+ cinv x2, x7, cc // cc = lo, ul, last+ cneg x1, x1, cc // cc = lo, ul, last+ eor x9, x9, x8+ cmn x8, #0x1+ eor x7, x12, x8+ mul x12, x4, x1+ adcs x3, x3, x7+ adcs x7, x15, x9+ adcs x15, x17, x8+ umulh x4, x4, x1+ adc x8, x13, x8+ cmn x2, #0x1+ eor x1, x12, x2+ adcs x1, x7, x1+ ldp x7, x16, [sp, #192]+ eor x12, x4, x2+ adcs x4, x15, x12+ ldp x15, x12, [sp, #224]+ adc x8, x8, x2+ adds x13, x14, x14+ umulh x14, x5, x10+ adcs x2, x11, x11+ adcs x3, x3, x3+ adcs x1, x1, x1+ adcs x4, x4, x4+ adcs x11, x8, x8+ adc x8, xzr, xzr+ adds x13, x13, x7+ adcs x2, x2, x16+ mul x16, x5, x10+ adcs x3, x3, x19+ adcs x1, x1, x20+ umulh x5, x5, x5+ lsl x9, x13, #32+ add x9, x9, x13+ adcs x4, x4, x15+ mov x13, v28.d[1]+ adcs x15, x11, x12+ lsr x7, x9, #32+ adc x11, x8, xzr+ subs x7, x7, x9+ umulh x10, x10, x10+ sbc x17, x9, xzr+ extr x7, x17, x7, #32+ lsr x17, x17, #32+ adds x17, x17, x9+ adc x12, xzr, xzr+ subs x8, x2, x7+ sbcs x17, x3, x17+ lsl x7, x8, #32+ sbcs x2, x1, x12+ add x3, x7, x8+ sbcs x12, x4, xzr+ lsr x1, x3, #32+ sbcs x7, x15, xzr+ sbc x15, x9, xzr+ subs x1, x1, x3+ sbc x4, x3, xzr+ lsr x9, x4, #32+ extr x8, x4, x1, #32+ adds x9, x9, x3+ adc x4, xzr, xzr+ subs x1, x17, x8+ lsl x17, x1, #32+ sbcs x8, x2, x9+ sbcs x9, x12, x4+ add x17, x17, x1+ mov x1, v18.d[1]+ lsr x2, x17, #32+ sbcs x7, x7, xzr+ mov x12, v18.d[0]+ sbcs x15, x15, xzr+ sbc x3, x3, xzr+ subs x4, x2, x17+ sbc x2, x17, xzr+ adds x12, x13, x12+ adcs x16, x16, x1+ lsr x13, x2, #32+ extr x1, x2, x4, #32+ adc x2, x14, xzr+ adds x4, x13, x17+ mul x13, x6, x6+ adc x14, xzr, xzr+ subs x1, x8, x1+ sbcs x4, x9, x4+ mov x9, v28.d[0]+ sbcs x7, x7, x14+ sbcs x8, x15, xzr+ sbcs x3, x3, xzr+ sbc x14, x17, xzr+ adds x17, x9, x9+ adcs x12, x12, x12+ mov x15, v19.d[0]+ adcs x9, x16, x16+ umulh x6, x6, x6+ adcs x16, x2, x2+ adc x2, xzr, xzr+ adds x11, x11, x8+ adcs x3, x3, xzr+ adcs x14, x14, xzr+ adcs x8, xzr, xzr+ adds x13, x1, x13+ mov x1, v19.d[1]+ adcs x6, x4, x6+ mov x4, #0xffffffff // #4294967295+ adcs x15, x7, x15+ adcs x7, x11, x5+ adcs x1, x3, x1+ adcs x14, x14, x10+ adc x11, x8, xzr+ adds x6, x6, x17+ adcs x8, x15, x12+ adcs x3, x7, x9+ adcs x15, x1, x16+ mov x16, #0xffffffff00000001 // #-4294967295+ adcs x14, x14, x2+ mov x2, #0x1 // #1+ adc x17, x11, xzr+ cmn x13, x16+ adcs xzr, x6, x4+ adcs xzr, x8, x2+ adcs xzr, x3, xzr+ adcs xzr, x15, xzr+ adcs xzr, x14, xzr+ adc x1, x17, xzr+ neg x9, x1+ and x1, x16, x9+ adds x11, x13, x1+ and x13, x4, x9+ adcs x5, x6, x13+ and x1, x2, x9+ adcs x7, x8, x1+ stp x11, x5, [sp, #192]+ adcs x11, x3, xzr+ adcs x2, x15, xzr+ stp x7, x11, [sp, #208]+ adc x17, x14, xzr+ stp x2, x17, [sp, #224]+ ldp x5, x6, [sp, #240]+ ldp x4, x3, [sp, #48]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #256]+ ldp x4, x3, [sp, #64]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #272]+ ldp x4, x3, [sp, #80]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, cc // cc = lo, ul, last+ mov x4, #0xffffffff // #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #0xfffffffffffffffe // #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [x25, #96]+ stp x7, x8, [x25, #112]+ stp x9, x10, [x25, #128]+ ldr q3, [sp, #288]+ ldr q25, [sp, #96]+ ldp x13, x23, [sp, #96]+ ldp x3, x21, [sp, #288]+ rev64 v23.4s, v25.4s+ uzp1 v17.4s, v25.4s, v3.4s+ umulh x15, x3, x13+ mul v6.4s, v23.4s, v3.4s+ uzp1 v3.4s, v3.4s, v3.4s+ ldr q27, [sp, #128]+ ldp x8, x24, [sp, #304]+ subs x6, x3, x21+ ldr q0, [sp, #320]+ movi v23.2d, #0xffffffff+ csetm x10, cc // cc = lo, ul, last+ umulh x19, x21, x23+ rev64 v4.4s, v27.4s+ uzp2 v25.4s, v27.4s, v27.4s+ cneg x4, x6, cc // cc = lo, ul, last+ subs x7, x23, x13+ xtn v22.2s, v0.2d+ xtn v24.2s, v27.2d+ cneg x20, x7, cc // cc = lo, ul, last+ ldp x6, x14, [sp, #112]+ mul v27.4s, v4.4s, v0.4s+ uaddlp v20.2d, v6.4s+ cinv x5, x10, cc // cc = lo, ul, last+ mul x16, x4, x20+ uzp2 v6.4s, v0.4s, v0.4s+ umull v21.2d, v22.2s, v25.2s+ shl v0.2d, v20.2d, #32+ umlal v0.2d, v3.2s, v17.2s+ mul x22, x8, x6+ umull v1.2d, v6.2s, v25.2s+ subs x12, x3, x8+ umull v20.2d, v22.2s, v24.2s+ cneg x17, x12, cc // cc = lo, ul, last+ umulh x9, x8, x6+ mov x12, v0.d[1]+ eor x11, x16, x5+ mov x7, v0.d[0]+ csetm x10, cc // cc = lo, ul, last+ usra v21.2d, v20.2d, #32+ adds x15, x15, x12+ adcs x12, x19, x22+ umulh x20, x4, x20+ adc x19, x9, xzr+ usra v1.2d, v21.2d, #32+ adds x22, x15, x7+ and v26.16b, v21.16b, v23.16b+ adcs x16, x12, x15+ uaddlp v25.2d, v27.4s+ adcs x9, x19, x12+ umlal v26.2d, v6.2s, v24.2s+ adc x4, x19, xzr+ adds x16, x16, x7+ shl v27.2d, v25.2d, #32+ adcs x9, x9, x15+ adcs x4, x4, x12+ eor x12, x20, x5+ adc x15, x19, xzr+ subs x20, x6, x13+ cneg x20, x20, cc // cc = lo, ul, last+ cinv x10, x10, cc // cc = lo, ul, last+ cmn x5, #0x1+ mul x19, x17, x20+ adcs x11, x22, x11+ adcs x12, x16, x12+ adcs x9, x9, x5+ umulh x17, x17, x20+ adcs x22, x4, x5+ adc x5, x15, x5+ subs x16, x21, x8+ cneg x20, x16, cc // cc = lo, ul, last+ eor x19, x19, x10+ csetm x4, cc // cc = lo, ul, last+ subs x16, x6, x23+ cneg x16, x16, cc // cc = lo, ul, last+ umlal v27.2d, v22.2s, v24.2s+ mul x15, x20, x16+ cinv x4, x4, cc // cc = lo, ul, last+ cmn x10, #0x1+ usra v1.2d, v26.2d, #32+ adcs x19, x12, x19+ eor x17, x17, x10+ adcs x9, x9, x17+ adcs x22, x22, x10+ lsl x12, x7, #32+ umulh x20, x20, x16+ eor x16, x15, x4+ ldp x15, x17, [sp, #128]+ add x2, x12, x7+ adc x7, x5, x10+ ldp x5, x10, [sp, #320]+ lsr x1, x2, #32+ eor x12, x20, x4+ subs x1, x1, x2+ sbc x20, x2, xzr+ cmn x4, #0x1+ adcs x9, x9, x16+ extr x1, x20, x1, #32+ lsr x20, x20, #32+ adcs x22, x22, x12+ adc x16, x7, x4+ adds x12, x20, x2+ umulh x7, x24, x14+ adc x4, xzr, xzr+ subs x1, x11, x1+ sbcs x20, x19, x12+ sbcs x12, x9, x4+ lsl x9, x1, #32+ add x1, x9, x1+ sbcs x9, x22, xzr+ mul x22, x24, x14+ sbcs x16, x16, xzr+ lsr x4, x1, #32+ sbc x19, x2, xzr+ subs x4, x4, x1+ sbc x11, x1, xzr+ extr x2, x11, x4, #32+ lsr x4, x11, #32+ adds x4, x4, x1+ adc x11, xzr, xzr+ subs x2, x20, x2+ sbcs x4, x12, x4+ sbcs x20, x9, x11+ lsl x12, x2, #32+ add x2, x12, x2+ sbcs x9, x16, xzr+ lsr x11, x2, #32+ sbcs x19, x19, xzr+ sbc x1, x1, xzr+ subs x16, x11, x2+ sbc x12, x2, xzr+ extr x16, x12, x16, #32+ lsr x12, x12, #32+ adds x11, x12, x2+ adc x12, xzr, xzr+ subs x26, x4, x16+ mov x4, v27.d[0]+ sbcs x27, x20, x11+ sbcs x20, x9, x12+ sbcs x11, x19, xzr+ sbcs x9, x1, xzr+ stp x20, x11, [sp, #256]+ mov x1, v1.d[0]+ sbc x20, x2, xzr+ subs x12, x24, x5+ mov x11, v27.d[1]+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x2, cc // cc = lo, ul, last+ subs x19, x15, x14+ mov x12, v1.d[1]+ cinv x2, x2, cc // cc = lo, ul, last+ cneg x19, x19, cc // cc = lo, ul, last+ stp x9, x20, [sp, #272]+ mul x9, x16, x19+ adds x4, x7, x4+ adcs x11, x1, x11+ adc x1, x12, xzr+ adds x20, x4, x22+ umulh x19, x16, x19+ adcs x7, x11, x4+ eor x16, x9, x2+ adcs x9, x1, x11+ adc x12, x1, xzr+ adds x7, x7, x22+ adcs x4, x9, x4+ adcs x9, x12, x11+ adc x12, x1, xzr+ cmn x2, #0x1+ eor x1, x19, x2+ adcs x11, x20, x16+ adcs x19, x7, x1+ adcs x1, x4, x2+ adcs x20, x9, x2+ adc x2, x12, x2+ subs x12, x24, x10+ cneg x16, x12, cc // cc = lo, ul, last+ csetm x12, cc // cc = lo, ul, last+ subs x9, x17, x14+ cinv x12, x12, cc // cc = lo, ul, last+ cneg x9, x9, cc // cc = lo, ul, last+ subs x3, x24, x3+ sbcs x21, x5, x21+ mul x24, x16, x9+ sbcs x4, x10, x8+ ngc x8, xzr+ subs x10, x5, x10+ eor x5, x24, x12+ csetm x7, cc // cc = lo, ul, last+ cneg x24, x10, cc // cc = lo, ul, last+ subs x10, x17, x15+ cinv x7, x7, cc // cc = lo, ul, last+ cneg x10, x10, cc // cc = lo, ul, last+ subs x14, x13, x14+ sbcs x15, x23, x15+ eor x13, x21, x8+ mul x23, x24, x10+ sbcs x17, x6, x17+ eor x6, x3, x8+ ngc x21, xzr+ umulh x9, x16, x9+ cmn x8, #0x1+ eor x3, x23, x7+ adcs x23, x6, xzr+ adcs x13, x13, xzr+ eor x16, x4, x8+ adc x16, x16, xzr+ eor x4, x17, x21+ umulh x17, x24, x10+ cmn x21, #0x1+ eor x24, x14, x21+ eor x6, x15, x21+ adcs x15, x24, xzr+ adcs x14, x6, xzr+ adc x6, x4, xzr+ cmn x12, #0x1+ eor x4, x9, x12+ adcs x19, x19, x5+ umulh x5, x23, x15+ adcs x1, x1, x4+ adcs x10, x20, x12+ eor x4, x17, x7+ adc x2, x2, x12+ cmn x7, #0x1+ adcs x12, x1, x3+ ldp x17, x24, [sp, #256]+ mul x1, x16, x6+ adcs x3, x10, x4+ adc x2, x2, x7+ ldp x7, x4, [sp, #272]+ adds x20, x22, x26+ mul x10, x13, x14+ adcs x11, x11, x27+ eor x9, x8, x21+ adcs x26, x19, x17+ stp x20, x11, [sp, #240]+ adcs x27, x12, x24+ mul x8, x23, x15+ adcs x3, x3, x7+ adcs x12, x2, x4+ adc x19, xzr, xzr+ subs x21, x23, x16+ umulh x2, x16, x6+ stp x3, x12, [sp, #272]+ cneg x3, x21, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ umulh x11, x13, x14+ subs x21, x13, x16+ eor x7, x8, x9+ cneg x17, x21, cc // cc = lo, ul, last+ csetm x16, cc // cc = lo, ul, last+ subs x21, x6, x15+ cneg x22, x21, cc // cc = lo, ul, last+ cinv x21, x24, cc // cc = lo, ul, last+ subs x20, x23, x13+ umulh x12, x3, x22+ cneg x23, x20, cc // cc = lo, ul, last+ csetm x24, cc // cc = lo, ul, last+ subs x20, x14, x15+ cinv x24, x24, cc // cc = lo, ul, last+ mul x22, x3, x22+ cneg x3, x20, cc // cc = lo, ul, last+ subs x13, x6, x14+ cneg x20, x13, cc // cc = lo, ul, last+ cinv x15, x16, cc // cc = lo, ul, last+ adds x13, x5, x10+ mul x4, x23, x3+ adcs x11, x11, x1+ adc x14, x2, xzr+ adds x5, x13, x8+ adcs x16, x11, x13+ umulh x23, x23, x3+ adcs x3, x14, x11+ adc x1, x14, xzr+ adds x10, x16, x8+ adcs x6, x3, x13+ adcs x8, x1, x11+ umulh x13, x17, x20+ eor x1, x4, x24+ adc x4, x14, xzr+ cmn x24, #0x1+ adcs x1, x5, x1+ eor x16, x23, x24+ eor x11, x1, x9+ adcs x23, x10, x16+ eor x2, x22, x21+ adcs x3, x6, x24+ mul x14, x17, x20+ eor x17, x13, x15+ adcs x13, x8, x24+ adc x8, x4, x24+ cmn x21, #0x1+ adcs x6, x23, x2+ mov x16, #0xfffffffffffffffe // #-2+ eor x20, x12, x21+ adcs x20, x3, x20+ eor x23, x14, x15+ adcs x2, x13, x21+ adc x8, x8, x21+ cmn x15, #0x1+ ldp x5, x4, [sp, #240]+ adcs x22, x20, x23+ eor x23, x22, x9+ adcs x17, x2, x17+ adc x22, x8, x15+ cmn x9, #0x1+ adcs x15, x7, x5+ ldp x10, x14, [sp, #272]+ eor x1, x6, x9+ lsl x2, x15, #32+ adcs x8, x11, x4+ adcs x13, x1, x26+ eor x1, x22, x9+ adcs x24, x23, x27+ eor x11, x17, x9+ adcs x23, x11, x10+ adcs x7, x1, x14+ adcs x17, x9, x19+ adcs x20, x9, xzr+ add x1, x2, x15+ lsr x3, x1, #32+ adcs x11, x9, xzr+ adc x9, x9, xzr+ subs x3, x3, x1+ sbc x6, x1, xzr+ adds x24, x24, x5+ adcs x4, x23, x4+ extr x3, x6, x3, #32+ lsr x6, x6, #32+ adcs x21, x7, x26+ adcs x15, x17, x27+ adcs x7, x20, x10+ adcs x20, x11, x14+ mov x14, #0xffffffff // #4294967295+ adc x22, x9, x19+ adds x12, x6, x1+ adc x10, xzr, xzr+ subs x3, x8, x3+ sbcs x12, x13, x12+ lsl x9, x3, #32+ add x3, x9, x3+ sbcs x10, x24, x10+ sbcs x24, x4, xzr+ lsr x9, x3, #32+ sbcs x21, x21, xzr+ sbc x1, x1, xzr+ subs x9, x9, x3+ sbc x13, x3, xzr+ extr x9, x13, x9, #32+ lsr x13, x13, #32+ adds x13, x13, x3+ adc x6, xzr, xzr+ subs x12, x12, x9+ sbcs x17, x10, x13+ lsl x2, x12, #32+ sbcs x10, x24, x6+ add x9, x2, x12+ sbcs x6, x21, xzr+ lsr x5, x9, #32+ sbcs x21, x1, xzr+ sbc x13, x3, xzr+ subs x8, x5, x9+ sbc x19, x9, xzr+ lsr x12, x19, #32+ extr x3, x19, x8, #32+ adds x8, x12, x9+ adc x1, xzr, xzr+ subs x2, x17, x3+ sbcs x12, x10, x8+ sbcs x5, x6, x1+ sbcs x3, x21, xzr+ sbcs x19, x13, xzr+ sbc x24, x9, xzr+ adds x23, x15, x3+ adcs x8, x7, x19+ adcs x11, x20, x24+ adc x9, x22, xzr+ add x24, x9, #0x1+ lsl x7, x24, #32+ subs x21, x24, x7+ sbc x10, x7, xzr+ adds x6, x2, x21+ adcs x7, x12, x10+ adcs x24, x5, x24+ adcs x13, x23, xzr+ adcs x8, x8, xzr+ adcs x15, x11, xzr+ csetm x23, cc // cc = lo, ul, last+ and x11, x16, x23+ and x20, x14, x23+ adds x22, x6, x20+ eor x3, x20, x23+ adcs x5, x7, x3+ adcs x14, x24, x11+ stp x22, x5, [sp, #240]+ adcs x5, x13, x23+ adcs x12, x8, x23+ stp x14, x5, [sp, #256]+ adc x19, x15, x23+ ldp x1, x2, [sp, #144]+ ldp x3, x4, [sp, #160]+ ldp x5, x6, [sp, #176]+ lsl x0, x1, #2+ ldp x7, x8, [sp, #288]+ subs x0, x0, x7+ extr x1, x2, x1, #62+ sbcs x1, x1, x8+ ldp x7, x8, [sp, #304]+ extr x2, x3, x2, #62+ sbcs x2, x2, x7+ extr x3, x4, x3, #62+ sbcs x3, x3, x8+ extr x4, x5, x4, #62+ ldp x7, x8, [sp, #320]+ sbcs x4, x4, x7+ extr x5, x6, x5, #62+ sbcs x5, x5, x8+ lsr x6, x6, #62+ adc x6, x6, xzr+ lsl x7, x6, #32+ subs x8, x6, x7+ sbc x7, x7, xzr+ adds x0, x0, x8+ adcs x1, x1, x7+ adcs x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ csetm x8, cc // cc = lo, ul, last+ mov x9, #0xffffffff // #4294967295+ and x9, x9, x8+ adds x0, x0, x9+ eor x9, x9, x8+ adcs x1, x1, x9+ mov x9, #0xfffffffffffffffe // #-2+ and x9, x9, x8+ adcs x2, x2, x9+ adcs x3, x3, x8+ adcs x4, x4, x8+ adc x5, x5, x8+ stp x0, x1, [x25]+ stp x2, x3, [x25, #16]+ stp x4, x5, [x25, #32]+ ldp x0, x1, [sp, #192]+ mov x6, #0xffffffff // #4294967295+ subs x6, x6, x0+ mov x7, #0xffffffff00000000 // #-4294967296+ sbcs x7, x7, x1+ ldp x0, x1, [sp, #208]+ mov x8, #0xfffffffffffffffe // #-2+ sbcs x8, x8, x0+ mov x13, #0xffffffffffffffff // #-1+ sbcs x9, x13, x1+ ldp x0, x1, [sp, #224]+ sbcs x10, x13, x0+ sbc x11, x13, x1+ lsl x0, x6, #3+ extr x1, x7, x6, #61+ extr x2, x8, x7, #61+ extr x3, x9, x8, #61+ extr x4, x10, x9, #61+ extr x5, x11, x10, #61+ lsr x6, x11, #61+ add x6, x6, #0x1+ ldp x8, x9, [sp, #240]+ ldp x10, x11, [sp, #256]+ mov x14, #0x3 // #3+ mul x15, x14, x8+ umulh x8, x14, x8+ adds x0, x0, x15+ mul x15, x14, x9+ umulh x9, x14, x9+ adcs x1, x1, x15+ mul x15, x14, x10+ umulh x10, x14, x10+ adcs x2, x2, x15+ mul x15, x14, x11+ umulh x11, x14, x11+ adcs x3, x3, x15+ mul x15, x14, x12+ umulh x12, x14, x12+ adcs x4, x4, x15+ mul x15, x14, x19+ umulh x13, x14, x19+ adcs x5, x5, x15+ adc x6, x6, xzr+ adds x1, x1, x8+ adcs x2, x2, x9+ adcs x3, x3, x10+ adcs x4, x4, x11+ adcs x5, x5, x12+ adcs x6, x6, x13+ lsl x7, x6, #32+ subs x8, x6, x7+ sbc x7, x7, xzr+ adds x0, x0, x8+ adcs x1, x1, x7+ adcs x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ csetm x6, cc // cc = lo, ul, last+ mov x7, #0xffffffff // #4294967295+ and x7, x7, x6+ adds x0, x0, x7+ eor x7, x7, x6+ adcs x1, x1, x7+ mov x7, #0xfffffffffffffffe // #-2+ and x7, x7, x6+ adcs x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x6+ adc x5, x5, x6+ stp x0, x1, [x25, #48]+ stp x2, x3, [x25, #64]+ stp x4, x5, [x25, #80]+ ldp x19, x20, [sp, #336]+ ldp x21, x22, [sp, #352]+ ldp x23, x24, [sp, #368]+ ldp x25, x26, [sp, #384]+ ldp x27, xzr, [sp, #400]+ CFI_INC_SP(416)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_p384_montjdouble)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p384_montjscalarmul_alt.S view
@@ -0,0 +1,7155 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery-Jacobian form scalar multiplication for P-384+// Input scalar[6], point[18]; output res[18]+//+// extern void p384_montjscalarmul_alt+// (uint64_t res[static 18],+// const uint64_t scalar[static 6],+// const uint64_t point[static 18]);+//+// This function is a variant of its affine point version p384_scalarmul_alt.+// Here, input and output points are assumed to be in Jacobian form with+// their coordinates in the Montgomery domain. Thus, if priming indicates+// Montgomery form, x' = (2^384 * x) mod p_384 etc., each point argument+// is a triple (x',y',z') representing the affine point (x/z^2,y/z^3) when+// z' is nonzero or the point at infinity (group identity) if z' = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-384, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_384) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p384_montjscalarmul_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p384_montjscalarmul_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p384_montjscalarmul_alt)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 48+#define JACSIZE (3*NUMSIZE)++// Safe copies of input res and additional values in variables.++#define bf x22+#define sgn x23+#define j x24+#define res x25++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE++#define scalarb sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define tabent sp, #(4*NUMSIZE)++#define tab sp, #(7*NUMSIZE)++#define NSPACE 55*NUMSIZE++// Avoid using .rep for the sake of the BoringSSL/AWS-LC delocator,+// which doesn't accept repetitions, assembler macros etc.++#define selectblock(I) \+ cmp bf, #(1*I) __LF \+ ldp x20, x21, [x19] __LF \+ csel x0, x20, x0, eq __LF \+ csel x1, x21, x1, eq __LF \+ ldp x20, x21, [x19, #16] __LF \+ csel x2, x20, x2, eq __LF \+ csel x3, x21, x3, eq __LF \+ ldp x20, x21, [x19, #32] __LF \+ csel x4, x20, x4, eq __LF \+ csel x5, x21, x5, eq __LF \+ ldp x20, x21, [x19, #48] __LF \+ csel x6, x20, x6, eq __LF \+ csel x7, x21, x7, eq __LF \+ ldp x20, x21, [x19, #64] __LF \+ csel x8, x20, x8, eq __LF \+ csel x9, x21, x9, eq __LF \+ ldp x20, x21, [x19, #80] __LF \+ csel x10, x20, x10, eq __LF \+ csel x11, x21, x11, eq __LF \+ ldp x20, x21, [x19, #96] __LF \+ csel x12, x20, x12, eq __LF \+ csel x13, x21, x13, eq __LF \+ ldp x20, x21, [x19, #112] __LF \+ csel x14, x20, x14, eq __LF \+ csel x15, x21, x15, eq __LF \+ ldp x20, x21, [x19, #128] __LF \+ csel x16, x20, x16, eq __LF \+ csel x17, x21, x17, eq __LF \+ add x19, x19, #JACSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p384_montjscalarmul_alt):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ mov res, x0++// Reduce the input scalar mod n_384, i.e. conditionally subtract n_384.+// Store it to "scalarb".++ ldp x3, x4, [x1]+ movbig(x15, #0xecec, #0x196a, #0xccc5, #0x2973)+ ldp x5, x6, [x1, #16]+ movbig(x16, #0x581a, #0x0db2, #0x48b0, #0xa77a)+ ldp x7, x8, [x1, #32]+ movbig(x17, #0xc763, #0x4d81, #0xf437, #0x2ddf)++ subs x9, x3, x15+ sbcs x10, x4, x16+ sbcs x11, x5, x17+ adcs x12, x6, xzr+ adcs x13, x7, xzr+ adcs x14, x8, xzr++ csel x3, x3, x9, cc+ csel x4, x4, x10, cc+ csel x5, x5, x11, cc+ csel x6, x6, x12, cc+ csel x7, x7, x13, cc+ csel x8, x8, x14, cc++ stp x3, x4, [scalarb]+ stp x5, x6, [scalarb+16]+ stp x7, x8, [scalarb+32]++// Set the tab[0] table entry to the input point = 1 * P++ ldp x10, x11, [x2]+ stp x10, x11, [tab]+ ldp x12, x13, [x2, #16]+ stp x12, x13, [tab+16]+ ldp x14, x15, [x2, #32]+ stp x14, x15, [tab+32]++ ldp x10, x11, [x2, #48]+ stp x10, x11, [tab+48]+ ldp x12, x13, [x2, #64]+ stp x12, x13, [tab+64]+ ldp x14, x15, [x2, #80]+ stp x14, x15, [tab+80]++ ldp x10, x11, [x2, #96]+ stp x10, x11, [tab+96]+ ldp x12, x13, [x2, #112]+ stp x12, x13, [tab+112]+ ldp x14, x15, [x2, #128]+ stp x14, x15, [tab+128]++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ add x0, tab+JACSIZE*1+ add x1, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, tab+JACSIZE*2+ add x1, tab+JACSIZE*1+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ add x0, tab+JACSIZE*3+ add x1, tab+JACSIZE*1+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, tab+JACSIZE*4+ add x1, tab+JACSIZE*3+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ add x0, tab+JACSIZE*5+ add x1, tab+JACSIZE*2+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, tab+JACSIZE*6+ add x1, tab+JACSIZE*5+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ add x0, tab+JACSIZE*7+ add x1, tab+JACSIZE*3+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, tab+JACSIZE*8+ add x1, tab+JACSIZE*7+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ add x0, tab+JACSIZE*9+ add x1, tab+JACSIZE*4+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, tab+JACSIZE*10+ add x1, tab+JACSIZE*9+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ add x0, tab+JACSIZE*11+ add x1, tab+JACSIZE*5+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, tab+JACSIZE*12+ add x1, tab+JACSIZE*11+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ add x0, tab+JACSIZE*13+ add x1, tab+JACSIZE*6+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, tab+JACSIZE*14+ add x1, tab+JACSIZE*13+ add x2, tab+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ add x0, tab+JACSIZE*15+ add x1, tab+JACSIZE*7+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically since none is a simple ARM load.+//+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x4210842108421084+// 0x8421084210842108+// 0x0842108421084210++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ movbig(x8, #0x1084, #0x2108, #0x4210, #0x8421)+ adds x0, x0, x8, lsr #1+ adcs x1, x1, x8+ lsl x8, x8, #1+ adcs x2, x2, x8+ lsl x8, x8, #1+ adcs x3, x3, x8+ lsl x8, x8, #1+ adcs x4, x4, x8+ lsr x8, x8, #4+ adcs x5, x5, x8+ cset x6, cs++// Record the top bitfield then shift the whole scalar left 4 bits+// to align the top of the next bitfield with the MSB (bits 379..383).++ extr bf, x6, x5, #60+ extr x5, x5, x4, #60+ extr x4, x4, x3, #60+ extr x3, x3, x2, #60+ extr x2, x2, x1, #60+ extr x1, x1, x0, #60+ lsl x0, x0, #4+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]++// Initialize the accumulator to the corresponding entry using constant-time+// lookup in the table. This top digit, uniquely, is not recoded so there is+// no sign adjustment to make.++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ mov x12, xzr+ mov x13, xzr+ mov x14, xzr+ mov x15, xzr+ mov x16, xzr+ mov x17, xzr++ add x19, tab++ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)++ stp x0, x1, [acc]+ stp x2, x3, [acc+16]+ stp x4, x5, [acc+32]+ stp x6, x7, [acc+48]+ stp x8, x9, [acc+64]+ stp x10, x11, [acc+80]+ stp x12, x13, [acc+96]+ stp x14, x15, [acc+112]+ stp x16, x17, [acc+128]++ mov j, #380++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++Lp384_montjscalarmul_alt_mainloop:+ sub j, j, #5++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjdouble)++// Choose the bitfield and adjust it to sign and magnitude++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ lsr bf, x5, #59+ extr x5, x5, x4, #59+ extr x4, x4, x3, #59+ extr x3, x3, x2, #59+ extr x2, x2, x1, #59+ extr x1, x1, x0, #59+ lsl x0, x0, #5+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]++ subs bf, bf, #16+ cset sgn, lo // sgn = sign of digit (1 = negative)+ cneg bf, bf, lo // bf = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ mov x9, xzr+ mov x10, xzr+ mov x11, xzr+ mov x12, xzr+ mov x13, xzr+ mov x14, xzr+ mov x15, xzr+ mov x16, xzr+ mov x17, xzr++ add x19, tab++ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_384 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).++ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]+ stp x4, x5, [tabent+32]++ stp x12, x13, [tabent+96]+ stp x14, x15, [tabent+112]+ stp x16, x17, [tabent+128]++ mov x0, #0x00000000ffffffff+ subs x0, x0, x6+ orr x12, x6, x7+ mov x1, #0xffffffff00000000+ sbcs x1, x1, x7+ orr x13, x8, x9+ mov x2, #0xfffffffffffffffe+ sbcs x2, x2, x8+ orr x14, x10, x11+ mov x5, #0xffffffffffffffff+ sbcs x3, x5, x9+ orr x12, x12, x13+ sbcs x4, x5, x10+ orr x12, x12, x14+ sbcs x5, x5, x11++ cmp sgn, xzr+ ccmp x12, xzr, #4, ne++ csel x6, x0, x6, ne+ csel x7, x1, x7, ne+ csel x8, x2, x8, ne+ csel x9, x3, x9, ne+ csel x10, x4, x10, ne+ csel x11, x5, x11, ne++ stp x6, x7, [tabent+48]+ stp x8, x9, [tabent+64]+ stp x10, x11, [tabent+80]++// Add to the accumulator++ add x0, acc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp384_montjscalarmul_alt_p384_montjadd)++ cbnz j, Lp384_montjscalarmul_alt_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ ldp x0, x1, [acc]+ stp x0, x1, [res]+ ldp x0, x1, [acc+16]+ stp x0, x1, [res, #16]+ ldp x0, x1, [acc+32]+ stp x0, x1, [res, #32]+ ldp x0, x1, [acc+48]+ stp x0, x1, [res, #48]+ ldp x0, x1, [acc+64]+ stp x0, x1, [res, #64]+ ldp x0, x1, [acc+80]+ stp x0, x1, [res, #80]+ ldp x0, x1, [acc+96]+ stp x0, x1, [res, #96]+ ldp x0, x1, [acc+112]+ stp x0, x1, [res, #112]+ ldp x0, x1, [acc+128]+ stp x0, x1, [res, #128]++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x25,x30)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p384_montjscalarmul_alt)++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjadd)++Lp384_montjscalarmul_alt_p384_montjadd:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_DEC_SP(336)+ mov x24, x0+ mov x25, x1+ mov x26, x2+ ldp x2, x3, [x25, #96]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x25, #112]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [x25, #128]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ mov x14, #-4294967295+ mov x15, #4294967295+ csel x14, x14, xzr, hs+ csel x15, x15, xzr, hs+ cset x16, hs+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, xzr+ adcs x12, x12, xzr+ adc x13, x13, xzr+ stp x2, x9, [sp]+ stp x10, x11, [sp, #16]+ stp x12, x13, [sp, #32]+ ldp x2, x3, [x26, #96]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x26, #112]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [x26, #128]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ mov x14, #-4294967295+ mov x15, #4294967295+ csel x14, x14, xzr, hs+ csel x15, x15, xzr, hs+ cset x16, hs+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, xzr+ adcs x12, x12, xzr+ adc x13, x13, xzr+ stp x2, x9, [sp, #240]+ stp x10, x11, [sp, #256]+ stp x12, x13, [sp, #272]+ ldp x3, x4, [x26, #96]+ ldp x5, x6, [x25, #48]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [x25, #64]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [x25, #80]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [x26, #112]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [x26, #128]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #288]+ stp x14, x15, [sp, #304]+ stp x16, x17, [sp, #320]+ ldp x3, x4, [x25, #96]+ ldp x5, x6, [x26, #48]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [x26, #64]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [x26, #80]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [x25, #112]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [x25, #128]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #48]+ stp x14, x15, [sp, #64]+ stp x16, x17, [sp, #80]+ ldp x3, x4, [sp]+ ldp x5, x6, [x26]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [x26, #16]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [x26, #32]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #16]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #32]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #96]+ stp x14, x15, [sp, #112]+ stp x16, x17, [sp, #128]+ ldp x3, x4, [sp, #240]+ ldp x5, x6, [x25]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [x25, #16]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [x25, #32]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #256]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #272]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #192]+ stp x14, x15, [sp, #208]+ stp x16, x17, [sp, #224]+ ldp x3, x4, [sp]+ ldp x5, x6, [sp, #48]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #64]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #80]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #16]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #32]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #48]+ stp x14, x15, [sp, #64]+ stp x16, x17, [sp, #80]+ ldp x3, x4, [sp, #240]+ ldp x5, x6, [sp, #288]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #304]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #320]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #256]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #272]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #288]+ stp x14, x15, [sp, #304]+ stp x16, x17, [sp, #320]+ ldp x5, x6, [sp, #96]+ ldp x4, x3, [sp, #192]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #112]+ ldp x4, x3, [sp, #208]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #128]+ ldp x4, x3, [sp, #224]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ ldp x5, x6, [sp, #48]+ ldp x4, x3, [sp, #288]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #64]+ ldp x4, x3, [sp, #304]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #80]+ ldp x4, x3, [sp, #320]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #48]+ stp x7, x8, [sp, #64]+ stp x9, x10, [sp, #80]+ ldp x2, x3, [sp, #240]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #256]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [sp, #272]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ mov x14, #-4294967295+ mov x15, #4294967295+ csel x14, x14, xzr, hs+ csel x15, x15, xzr, hs+ cset x16, hs+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, xzr+ adcs x12, x12, xzr+ adc x13, x13, xzr+ stp x2, x9, [sp, #144]+ stp x10, x11, [sp, #160]+ stp x12, x13, [sp, #176]+ ldp x2, x3, [sp, #48]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #64]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [sp, #80]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ adc x6, xzr, xzr+ mov x8, #-4294967295+ adds x14, x2, x8+ mov x8, #4294967295+ adcs x15, x9, x8+ mov x8, #1+ adcs x16, x10, x8+ adcs x17, x11, xzr+ adcs x19, x12, xzr+ adcs x20, x13, xzr+ adcs x6, x6, xzr+ csel x2, x2, x14, eq+ csel x9, x9, x15, eq+ csel x10, x10, x16, eq+ csel x11, x11, x17, eq+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ stp x2, x9, [sp]+ stp x10, x11, [sp, #16]+ stp x12, x13, [sp, #32]+ ldp x3, x4, [sp, #144]+ ldp x5, x6, [sp, #192]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #208]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #224]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #160]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #176]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #192]+ stp x14, x15, [sp, #208]+ stp x16, x17, [sp, #224]+ ldp x3, x4, [sp, #144]+ ldp x5, x6, [sp, #96]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #112]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #128]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #160]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #176]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #96]+ stp x14, x15, [sp, #112]+ stp x16, x17, [sp, #128]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #192]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #208]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #32]+ ldp x4, x3, [sp, #224]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ stp x9, x10, [sp, #32]+ ldp x5, x6, [sp, #96]+ ldp x4, x3, [sp, #192]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #112]+ ldp x4, x3, [sp, #208]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #128]+ ldp x4, x3, [sp, #224]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ ldp x3, x4, [sp, #240]+ ldp x5, x6, [x25, #96]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [x25, #112]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [x25, #128]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #256]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #272]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #240]+ stp x14, x15, [sp, #256]+ stp x16, x17, [sp, #272]+ ldp x5, x6, [sp]+ ldp x4, x3, [sp, #96]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #16]+ ldp x4, x3, [sp, #112]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #32]+ ldp x4, x3, [sp, #128]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp]+ stp x7, x8, [sp, #16]+ stp x9, x10, [sp, #32]+ ldp x5, x6, [sp, #192]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #208]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #224]+ ldp x4, x3, [sp, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #192]+ stp x7, x8, [sp, #208]+ stp x9, x10, [sp, #224]+ ldp x3, x4, [sp, #144]+ ldp x5, x6, [sp, #288]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #304]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #320]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #160]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #176]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #144]+ stp x14, x15, [sp, #160]+ stp x16, x17, [sp, #176]+ ldp x3, x4, [sp, #240]+ ldp x5, x6, [x26, #96]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [x26, #112]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [x26, #128]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #256]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #272]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #240]+ stp x14, x15, [sp, #256]+ stp x16, x17, [sp, #272]+ ldp x3, x4, [sp, #48]+ ldp x5, x6, [sp, #192]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #208]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #224]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #64]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #80]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #192]+ stp x14, x15, [sp, #208]+ stp x16, x17, [sp, #224]+ ldp x5, x6, [sp, #192]+ ldp x4, x3, [sp, #144]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #208]+ ldp x4, x3, [sp, #160]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #224]+ ldp x4, x3, [sp, #176]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #192]+ stp x7, x8, [sp, #208]+ stp x9, x10, [sp, #224]+ ldp x0, x1, [x25, #96]+ ldp x2, x3, [x25, #112]+ ldp x4, x5, [x25, #128]+ orr x20, x0, x1+ orr x21, x2, x3+ orr x22, x4, x5+ orr x20, x20, x21+ orr x20, x20, x22+ cmp x20, xzr+ cset x20, ne+ ldp x6, x7, [x26, #96]+ ldp x8, x9, [x26, #112]+ ldp x10, x11, [x26, #128]+ orr x21, x6, x7+ orr x22, x8, x9+ orr x23, x10, x11+ orr x21, x21, x22+ orr x21, x21, x23+ cmp x21, xzr+ cset x21, ne+ cmp x21, x20+ ldp x12, x13, [sp, #240]+ csel x12, x0, x12, lo+ csel x13, x1, x13, lo+ csel x12, x6, x12, hi+ csel x13, x7, x13, hi+ ldp x14, x15, [sp, #256]+ csel x14, x2, x14, lo+ csel x15, x3, x15, lo+ csel x14, x8, x14, hi+ csel x15, x9, x15, hi+ ldp x16, x17, [sp, #272]+ csel x16, x4, x16, lo+ csel x17, x5, x17, lo+ csel x16, x10, x16, hi+ csel x17, x11, x17, hi+ ldp x20, x21, [x25]+ ldp x0, x1, [sp]+ csel x0, x20, x0, lo+ csel x1, x21, x1, lo+ ldp x20, x21, [x26]+ csel x0, x20, x0, hi+ csel x1, x21, x1, hi+ ldp x20, x21, [x25, #16]+ ldp x2, x3, [sp, #16]+ csel x2, x20, x2, lo+ csel x3, x21, x3, lo+ ldp x20, x21, [x26, #16]+ csel x2, x20, x2, hi+ csel x3, x21, x3, hi+ ldp x20, x21, [x25, #32]+ ldp x4, x5, [sp, #32]+ csel x4, x20, x4, lo+ csel x5, x21, x5, lo+ ldp x20, x21, [x26, #32]+ csel x4, x20, x4, hi+ csel x5, x21, x5, hi+ ldp x20, x21, [x25, #48]+ ldp x6, x7, [sp, #192]+ csel x6, x20, x6, lo+ csel x7, x21, x7, lo+ ldp x20, x21, [x26, #48]+ csel x6, x20, x6, hi+ csel x7, x21, x7, hi+ ldp x20, x21, [x25, #64]+ ldp x8, x9, [sp, #208]+ csel x8, x20, x8, lo+ csel x9, x21, x9, lo+ ldp x20, x21, [x26, #64]+ csel x8, x20, x8, hi+ csel x9, x21, x9, hi+ ldp x20, x21, [x25, #80]+ ldp x10, x11, [sp, #224]+ csel x10, x20, x10, lo+ csel x11, x21, x11, lo+ ldp x20, x21, [x26, #80]+ csel x10, x20, x10, hi+ csel x11, x21, x11, hi+ stp x0, x1, [x24]+ stp x2, x3, [x24, #16]+ stp x4, x5, [x24, #32]+ stp x6, x7, [x24, #48]+ stp x8, x9, [x24, #64]+ stp x10, x11, [x24, #80]+ stp x12, x13, [x24, #96]+ stp x14, x15, [x24, #112]+ stp x16, x17, [x24, #128]+ CFI_INC_SP(336)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjdouble)++Lp384_montjscalarmul_alt_p384_montjdouble:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_DEC_SP(336)+ mov x23, x0+ mov x24, x1+ ldp x2, x3, [x24, #96]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x24, #112]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [x24, #128]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ adc x6, xzr, xzr+ mov x8, #-4294967295+ adds x14, x2, x8+ mov x8, #4294967295+ adcs x15, x9, x8+ mov x8, #1+ adcs x16, x10, x8+ adcs x17, x11, xzr+ adcs x19, x12, xzr+ adcs x20, x13, xzr+ adcs x6, x6, xzr+ csel x2, x2, x14, eq+ csel x9, x9, x15, eq+ csel x10, x10, x16, eq+ csel x11, x11, x17, eq+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ stp x2, x9, [sp]+ stp x10, x11, [sp, #16]+ stp x12, x13, [sp, #32]+ ldp x2, x3, [x24, #48]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [x24, #64]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [x24, #80]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ adc x6, xzr, xzr+ mov x8, #-4294967295+ adds x14, x2, x8+ mov x8, #4294967295+ adcs x15, x9, x8+ mov x8, #1+ adcs x16, x10, x8+ adcs x17, x11, xzr+ adcs x19, x12, xzr+ adcs x20, x13, xzr+ adcs x6, x6, xzr+ csel x2, x2, x14, eq+ csel x9, x9, x15, eq+ csel x10, x10, x16, eq+ csel x11, x11, x17, eq+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ stp x2, x9, [sp, #48]+ stp x10, x11, [sp, #64]+ stp x12, x13, [sp, #80]+ ldp x5, x6, [x24]+ ldp x4, x3, [sp]+ adds x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x24, #16]+ ldp x4, x3, [sp, #16]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x24, #32]+ ldp x4, x3, [sp, #32]+ adcs x9, x9, x4+ adcs x10, x10, x3+ csetm x3, hs+ mov x4, #4294967295+ and x4, x4, x3+ subs x5, x5, x4+ eor x4, x4, x3+ sbcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ sbcs x9, x9, x3+ sbc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ ldp x5, x6, [x24]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x24, #16]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x24, #32]+ ldp x4, x3, [sp, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #192]+ stp x7, x8, [sp, #208]+ stp x9, x10, [sp, #224]+ ldp x3, x4, [sp, #240]+ ldp x5, x6, [sp, #192]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #208]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #224]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #256]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #272]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #96]+ stp x14, x15, [sp, #112]+ stp x16, x17, [sp, #128]+ ldp x5, x6, [x24, #48]+ ldp x4, x3, [x24, #96]+ adds x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x24, #64]+ ldp x4, x3, [x24, #112]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x24, #80]+ ldp x4, x3, [x24, #128]+ adcs x9, x9, x4+ adcs x10, x10, x3+ adc x3, xzr, xzr+ mov x4, #4294967295+ cmp x5, x4+ mov x4, #-4294967296+ sbcs xzr, x6, x4+ mov x4, #-2+ sbcs xzr, x7, x4+ adcs xzr, x8, xzr+ adcs xzr, x9, xzr+ adcs xzr, x10, xzr+ adcs x3, x3, xzr+ csetm x3, ne+ mov x4, #4294967295+ and x4, x4, x3+ subs x5, x5, x4+ eor x4, x4, x3+ sbcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ sbcs x9, x9, x3+ sbc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ ldp x2, x3, [sp, #96]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #112]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [sp, #128]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ adc x6, xzr, xzr+ mov x8, #-4294967295+ adds x14, x2, x8+ mov x8, #4294967295+ adcs x15, x9, x8+ mov x8, #1+ adcs x16, x10, x8+ adcs x17, x11, xzr+ adcs x19, x12, xzr+ adcs x20, x13, xzr+ adcs x6, x6, xzr+ csel x2, x2, x14, eq+ csel x9, x9, x15, eq+ csel x10, x10, x16, eq+ csel x11, x11, x17, eq+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ stp x2, x9, [sp, #288]+ stp x10, x11, [sp, #304]+ stp x12, x13, [sp, #320]+ ldp x3, x4, [x24]+ ldp x5, x6, [sp, #48]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #64]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #80]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [x24, #16]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [x24, #32]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #144]+ stp x14, x15, [sp, #160]+ stp x16, x17, [sp, #176]+ ldp x2, x3, [sp, #240]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #256]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [sp, #272]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ adc x6, xzr, xzr+ mov x8, #-4294967295+ adds x14, x2, x8+ mov x8, #4294967295+ adcs x15, x9, x8+ mov x8, #1+ adcs x16, x10, x8+ adcs x17, x11, xzr+ adcs x19, x12, xzr+ adcs x20, x13, xzr+ adcs x6, x6, xzr+ csel x2, x2, x14, eq+ csel x9, x9, x15, eq+ csel x10, x10, x16, eq+ csel x11, x11, x17, eq+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ stp x2, x9, [sp, #192]+ stp x10, x11, [sp, #208]+ stp x12, x13, [sp, #224]+ ldp x0, x1, [sp, #288]+ mov x6, #4294967295+ subs x6, x6, x0+ mov x7, #-4294967296+ sbcs x7, x7, x1+ ldp x0, x1, [sp, #304]+ mov x8, #-2+ sbcs x8, x8, x0+ mov x13, #-1+ sbcs x9, x13, x1+ ldp x0, x1, [sp, #320]+ sbcs x10, x13, x0+ sbc x11, x13, x1+ mov x12, #9+ mul x0, x12, x6+ mul x1, x12, x7+ mul x2, x12, x8+ mul x3, x12, x9+ mul x4, x12, x10+ mul x5, x12, x11+ umulh x6, x12, x6+ umulh x7, x12, x7+ umulh x8, x12, x8+ umulh x9, x12, x9+ umulh x10, x12, x10+ umulh x12, x12, x11+ adds x1, x1, x6+ adcs x2, x2, x7+ adcs x3, x3, x8+ adcs x4, x4, x9+ adcs x5, x5, x10+ mov x6, #1+ adc x6, x12, x6+ ldp x8, x9, [sp, #144]+ ldp x10, x11, [sp, #160]+ ldp x12, x13, [sp, #176]+ mov x14, #12+ mul x15, x14, x8+ umulh x8, x14, x8+ adds x0, x0, x15+ mul x15, x14, x9+ umulh x9, x14, x9+ adcs x1, x1, x15+ mul x15, x14, x10+ umulh x10, x14, x10+ adcs x2, x2, x15+ mul x15, x14, x11+ umulh x11, x14, x11+ adcs x3, x3, x15+ mul x15, x14, x12+ umulh x12, x14, x12+ adcs x4, x4, x15+ mul x15, x14, x13+ umulh x13, x14, x13+ adcs x5, x5, x15+ adc x6, x6, xzr+ adds x1, x1, x8+ adcs x2, x2, x9+ adcs x3, x3, x10+ adcs x4, x4, x11+ adcs x5, x5, x12+ adcs x6, x6, x13+ lsl x7, x6, #32+ subs x8, x6, x7+ sbc x7, x7, xzr+ adds x0, x0, x8+ adcs x1, x1, x7+ adcs x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ csetm x6, lo+ mov x7, #4294967295+ and x7, x7, x6+ adds x0, x0, x7+ eor x7, x7, x6+ adcs x1, x1, x7+ mov x7, #-2+ and x7, x7, x6+ adcs x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x6+ adc x5, x5, x6+ stp x0, x1, [sp, #288]+ stp x2, x3, [sp, #304]+ stp x4, x5, [sp, #320]+ ldp x5, x6, [sp, #192]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #208]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #224]+ ldp x4, x3, [sp, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [sp, #240]+ stp x7, x8, [sp, #256]+ stp x9, x10, [sp, #272]+ ldp x2, x3, [sp, #48]+ mul x9, x2, x3+ umulh x10, x2, x3+ ldp x4, x5, [sp, #64]+ mul x8, x2, x4+ adds x10, x10, x8+ mul x11, x2, x5+ mul x8, x3, x4+ adcs x11, x11, x8+ umulh x12, x2, x5+ mul x8, x3, x5+ adcs x12, x12, x8+ ldp x6, x7, [sp, #80]+ mul x13, x2, x7+ mul x8, x3, x6+ adcs x13, x13, x8+ umulh x14, x2, x7+ mul x8, x3, x7+ adcs x14, x14, x8+ mul x15, x5, x6+ adcs x15, x15, xzr+ umulh x16, x5, x6+ adc x16, x16, xzr+ umulh x8, x2, x4+ adds x11, x11, x8+ umulh x8, x3, x4+ adcs x12, x12, x8+ umulh x8, x3, x5+ adcs x13, x13, x8+ umulh x8, x3, x6+ adcs x14, x14, x8+ umulh x8, x3, x7+ adcs x15, x15, x8+ adc x16, x16, xzr+ mul x8, x2, x6+ adds x12, x12, x8+ mul x8, x4, x5+ adcs x13, x13, x8+ mul x8, x4, x6+ adcs x14, x14, x8+ mul x8, x4, x7+ adcs x15, x15, x8+ mul x8, x5, x7+ adcs x16, x16, x8+ mul x17, x6, x7+ adcs x17, x17, xzr+ umulh x19, x6, x7+ adc x19, x19, xzr+ umulh x8, x2, x6+ adds x13, x13, x8+ umulh x8, x4, x5+ adcs x14, x14, x8+ umulh x8, x4, x6+ adcs x15, x15, x8+ umulh x8, x4, x7+ adcs x16, x16, x8+ umulh x8, x5, x7+ adcs x17, x17, x8+ adc x19, x19, xzr+ adds x9, x9, x9+ adcs x10, x10, x10+ adcs x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ cset x20, hs+ umulh x8, x2, x2+ mul x2, x2, x2+ adds x9, x9, x8+ mul x8, x3, x3+ adcs x10, x10, x8+ umulh x8, x3, x3+ adcs x11, x11, x8+ mul x8, x4, x4+ adcs x12, x12, x8+ umulh x8, x4, x4+ adcs x13, x13, x8+ mul x8, x5, x5+ adcs x14, x14, x8+ umulh x8, x5, x5+ adcs x15, x15, x8+ mul x8, x6, x6+ adcs x16, x16, x8+ umulh x8, x6, x6+ adcs x17, x17, x8+ mul x8, x7, x7+ adcs x19, x19, x8+ umulh x8, x7, x7+ adc x20, x20, x8+ lsl x5, x2, #32+ add x2, x5, x2+ mov x5, #-4294967295+ umulh x5, x5, x2+ mov x4, #4294967295+ mul x3, x4, x2+ umulh x4, x4, x2+ adds x5, x5, x3+ adcs x4, x4, x2+ adc x3, xzr, xzr+ subs x9, x9, x5+ sbcs x10, x10, x4+ sbcs x11, x11, x3+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x2, x2, xzr+ lsl x5, x9, #32+ add x9, x5, x9+ mov x5, #-4294967295+ umulh x5, x5, x9+ mov x4, #4294967295+ mul x3, x4, x9+ umulh x4, x4, x9+ adds x5, x5, x3+ adcs x4, x4, x9+ adc x3, xzr, xzr+ subs x10, x10, x5+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ sbcs x13, x13, xzr+ sbcs x2, x2, xzr+ sbc x9, x9, xzr+ lsl x5, x10, #32+ add x10, x5, x10+ mov x5, #-4294967295+ umulh x5, x5, x10+ mov x4, #4294967295+ mul x3, x4, x10+ umulh x4, x4, x10+ adds x5, x5, x3+ adcs x4, x4, x10+ adc x3, xzr, xzr+ subs x11, x11, x5+ sbcs x12, x12, x4+ sbcs x13, x13, x3+ sbcs x2, x2, xzr+ sbcs x9, x9, xzr+ sbc x10, x10, xzr+ lsl x5, x11, #32+ add x11, x5, x11+ mov x5, #-4294967295+ umulh x5, x5, x11+ mov x4, #4294967295+ mul x3, x4, x11+ umulh x4, x4, x11+ adds x5, x5, x3+ adcs x4, x4, x11+ adc x3, xzr, xzr+ subs x12, x12, x5+ sbcs x13, x13, x4+ sbcs x2, x2, x3+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbc x11, x11, xzr+ lsl x5, x12, #32+ add x12, x5, x12+ mov x5, #-4294967295+ umulh x5, x5, x12+ mov x4, #4294967295+ mul x3, x4, x12+ umulh x4, x4, x12+ adds x5, x5, x3+ adcs x4, x4, x12+ adc x3, xzr, xzr+ subs x13, x13, x5+ sbcs x2, x2, x4+ sbcs x9, x9, x3+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbc x12, x12, xzr+ lsl x5, x13, #32+ add x13, x5, x13+ mov x5, #-4294967295+ umulh x5, x5, x13+ mov x4, #4294967295+ mul x3, x4, x13+ umulh x4, x4, x13+ adds x5, x5, x3+ adcs x4, x4, x13+ adc x3, xzr, xzr+ subs x2, x2, x5+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ adds x2, x2, x14+ adcs x9, x9, x15+ adcs x10, x10, x16+ adcs x11, x11, x17+ adcs x12, x12, x19+ adcs x13, x13, x20+ adc x6, xzr, xzr+ mov x8, #-4294967295+ adds x14, x2, x8+ mov x8, #4294967295+ adcs x15, x9, x8+ mov x8, #1+ adcs x16, x10, x8+ adcs x17, x11, xzr+ adcs x19, x12, xzr+ adcs x20, x13, xzr+ adcs x6, x6, xzr+ csel x2, x2, x14, eq+ csel x9, x9, x15, eq+ csel x10, x10, x16, eq+ csel x11, x11, x17, eq+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ stp x2, x9, [sp, #192]+ stp x10, x11, [sp, #208]+ stp x12, x13, [sp, #224]+ ldp x5, x6, [sp, #240]+ ldp x4, x3, [sp, #48]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #256]+ ldp x4, x3, [sp, #64]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #272]+ ldp x4, x3, [sp, #80]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ csetm x3, lo+ mov x4, #4294967295+ and x4, x4, x3+ adds x5, x5, x4+ eor x4, x4, x3+ adcs x6, x6, x4+ mov x4, #-2+ and x4, x4, x3+ adcs x7, x7, x4+ adcs x8, x8, x3+ adcs x9, x9, x3+ adc x10, x10, x3+ stp x5, x6, [x23, #96]+ stp x7, x8, [x23, #112]+ stp x9, x10, [x23, #128]+ ldp x3, x4, [sp, #288]+ ldp x5, x6, [sp, #96]+ mul x12, x3, x5+ umulh x13, x3, x5+ mul x11, x3, x6+ umulh x14, x3, x6+ adds x13, x13, x11+ ldp x7, x8, [sp, #112]+ mul x11, x3, x7+ umulh x15, x3, x7+ adcs x14, x14, x11+ mul x11, x3, x8+ umulh x16, x3, x8+ adcs x15, x15, x11+ ldp x9, x10, [sp, #128]+ mul x11, x3, x9+ umulh x17, x3, x9+ adcs x16, x16, x11+ mul x11, x3, x10+ umulh x19, x3, x10+ adcs x17, x17, x11+ adc x19, x19, xzr+ mul x11, x4, x5+ adds x13, x13, x11+ mul x11, x4, x6+ adcs x14, x14, x11+ mul x11, x4, x7+ adcs x15, x15, x11+ mul x11, x4, x8+ adcs x16, x16, x11+ mul x11, x4, x9+ adcs x17, x17, x11+ mul x11, x4, x10+ adcs x19, x19, x11+ cset x20, hs+ umulh x11, x4, x5+ adds x14, x14, x11+ umulh x11, x4, x6+ adcs x15, x15, x11+ umulh x11, x4, x7+ adcs x16, x16, x11+ umulh x11, x4, x8+ adcs x17, x17, x11+ umulh x11, x4, x9+ adcs x19, x19, x11+ umulh x11, x4, x10+ adc x20, x20, x11+ ldp x3, x4, [sp, #304]+ mul x11, x3, x5+ adds x14, x14, x11+ mul x11, x3, x6+ adcs x15, x15, x11+ mul x11, x3, x7+ adcs x16, x16, x11+ mul x11, x3, x8+ adcs x17, x17, x11+ mul x11, x3, x9+ adcs x19, x19, x11+ mul x11, x3, x10+ adcs x20, x20, x11+ cset x21, hs+ umulh x11, x3, x5+ adds x15, x15, x11+ umulh x11, x3, x6+ adcs x16, x16, x11+ umulh x11, x3, x7+ adcs x17, x17, x11+ umulh x11, x3, x8+ adcs x19, x19, x11+ umulh x11, x3, x9+ adcs x20, x20, x11+ umulh x11, x3, x10+ adc x21, x21, x11+ mul x11, x4, x5+ adds x15, x15, x11+ mul x11, x4, x6+ adcs x16, x16, x11+ mul x11, x4, x7+ adcs x17, x17, x11+ mul x11, x4, x8+ adcs x19, x19, x11+ mul x11, x4, x9+ adcs x20, x20, x11+ mul x11, x4, x10+ adcs x21, x21, x11+ cset x22, hs+ umulh x11, x4, x5+ adds x16, x16, x11+ umulh x11, x4, x6+ adcs x17, x17, x11+ umulh x11, x4, x7+ adcs x19, x19, x11+ umulh x11, x4, x8+ adcs x20, x20, x11+ umulh x11, x4, x9+ adcs x21, x21, x11+ umulh x11, x4, x10+ adc x22, x22, x11+ ldp x3, x4, [sp, #320]+ mul x11, x3, x5+ adds x16, x16, x11+ mul x11, x3, x6+ adcs x17, x17, x11+ mul x11, x3, x7+ adcs x19, x19, x11+ mul x11, x3, x8+ adcs x20, x20, x11+ mul x11, x3, x9+ adcs x21, x21, x11+ mul x11, x3, x10+ adcs x22, x22, x11+ cset x2, hs+ umulh x11, x3, x5+ adds x17, x17, x11+ umulh x11, x3, x6+ adcs x19, x19, x11+ umulh x11, x3, x7+ adcs x20, x20, x11+ umulh x11, x3, x8+ adcs x21, x21, x11+ umulh x11, x3, x9+ adcs x22, x22, x11+ umulh x11, x3, x10+ adc x2, x2, x11+ mul x11, x4, x5+ adds x17, x17, x11+ mul x11, x4, x6+ adcs x19, x19, x11+ mul x11, x4, x7+ adcs x20, x20, x11+ mul x11, x4, x8+ adcs x21, x21, x11+ mul x11, x4, x9+ adcs x22, x22, x11+ mul x11, x4, x10+ adcs x2, x2, x11+ cset x1, hs+ umulh x11, x4, x5+ adds x19, x19, x11+ umulh x11, x4, x6+ adcs x20, x20, x11+ umulh x11, x4, x7+ adcs x21, x21, x11+ umulh x11, x4, x8+ adcs x22, x22, x11+ umulh x11, x4, x9+ adcs x2, x2, x11+ umulh x11, x4, x10+ adc x1, x1, x11+ lsl x7, x12, #32+ add x12, x7, x12+ mov x7, #-4294967295+ umulh x7, x7, x12+ mov x6, #4294967295+ mul x5, x6, x12+ umulh x6, x6, x12+ adds x7, x7, x5+ adcs x6, x6, x12+ adc x5, xzr, xzr+ subs x13, x13, x7+ sbcs x14, x14, x6+ sbcs x15, x15, x5+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x12, x12, xzr+ lsl x7, x13, #32+ add x13, x7, x13+ mov x7, #-4294967295+ umulh x7, x7, x13+ mov x6, #4294967295+ mul x5, x6, x13+ umulh x6, x6, x13+ adds x7, x7, x5+ adcs x6, x6, x13+ adc x5, xzr, xzr+ subs x14, x14, x7+ sbcs x15, x15, x6+ sbcs x16, x16, x5+ sbcs x17, x17, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ lsl x7, x14, #32+ add x14, x7, x14+ mov x7, #-4294967295+ umulh x7, x7, x14+ mov x6, #4294967295+ mul x5, x6, x14+ umulh x6, x6, x14+ adds x7, x7, x5+ adcs x6, x6, x14+ adc x5, xzr, xzr+ subs x15, x15, x7+ sbcs x16, x16, x6+ sbcs x17, x17, x5+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ lsl x7, x15, #32+ add x15, x7, x15+ mov x7, #-4294967295+ umulh x7, x7, x15+ mov x6, #4294967295+ mul x5, x6, x15+ umulh x6, x6, x15+ adds x7, x7, x5+ adcs x6, x6, x15+ adc x5, xzr, xzr+ subs x16, x16, x7+ sbcs x17, x17, x6+ sbcs x12, x12, x5+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbc x15, x15, xzr+ lsl x7, x16, #32+ add x16, x7, x16+ mov x7, #-4294967295+ umulh x7, x7, x16+ mov x6, #4294967295+ mul x5, x6, x16+ umulh x6, x6, x16+ adds x7, x7, x5+ adcs x6, x6, x16+ adc x5, xzr, xzr+ subs x17, x17, x7+ sbcs x12, x12, x6+ sbcs x13, x13, x5+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbc x16, x16, xzr+ lsl x7, x17, #32+ add x17, x7, x17+ mov x7, #-4294967295+ umulh x7, x7, x17+ mov x6, #4294967295+ mul x5, x6, x17+ umulh x6, x6, x17+ adds x7, x7, x5+ adcs x6, x6, x17+ adc x5, xzr, xzr+ subs x12, x12, x7+ sbcs x13, x13, x6+ sbcs x14, x14, x5+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbc x17, x17, xzr+ adds x12, x12, x19+ adcs x13, x13, x20+ adcs x14, x14, x21+ adcs x15, x15, x22+ adcs x16, x16, x2+ adcs x17, x17, x1+ adc x10, xzr, xzr+ mov x11, #-4294967295+ adds x19, x12, x11+ mov x11, #4294967295+ adcs x20, x13, x11+ mov x11, #1+ adcs x21, x14, x11+ adcs x22, x15, xzr+ adcs x2, x16, xzr+ adcs x1, x17, xzr+ adcs x10, x10, xzr+ csel x12, x12, x19, eq+ csel x13, x13, x20, eq+ csel x14, x14, x21, eq+ csel x15, x15, x22, eq+ csel x16, x16, x2, eq+ csel x17, x17, x1, eq+ stp x12, x13, [sp, #240]+ stp x14, x15, [sp, #256]+ stp x16, x17, [sp, #272]+ ldp x1, x2, [sp, #144]+ ldp x3, x4, [sp, #160]+ ldp x5, x6, [sp, #176]+ lsl x0, x1, #2+ ldp x7, x8, [sp, #288]+ subs x0, x0, x7+ extr x1, x2, x1, #62+ sbcs x1, x1, x8+ ldp x7, x8, [sp, #304]+ extr x2, x3, x2, #62+ sbcs x2, x2, x7+ extr x3, x4, x3, #62+ sbcs x3, x3, x8+ extr x4, x5, x4, #62+ ldp x7, x8, [sp, #320]+ sbcs x4, x4, x7+ extr x5, x6, x5, #62+ sbcs x5, x5, x8+ lsr x6, x6, #62+ adc x6, x6, xzr+ lsl x7, x6, #32+ subs x8, x6, x7+ sbc x7, x7, xzr+ adds x0, x0, x8+ adcs x1, x1, x7+ adcs x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ csetm x8, lo+ mov x9, #4294967295+ and x9, x9, x8+ adds x0, x0, x9+ eor x9, x9, x8+ adcs x1, x1, x9+ mov x9, #-2+ and x9, x9, x8+ adcs x2, x2, x9+ adcs x3, x3, x8+ adcs x4, x4, x8+ adc x5, x5, x8+ stp x0, x1, [x23]+ stp x2, x3, [x23, #16]+ stp x4, x5, [x23, #32]+ ldp x0, x1, [sp, #192]+ mov x6, #4294967295+ subs x6, x6, x0+ mov x7, #-4294967296+ sbcs x7, x7, x1+ ldp x0, x1, [sp, #208]+ mov x8, #-2+ sbcs x8, x8, x0+ mov x13, #-1+ sbcs x9, x13, x1+ ldp x0, x1, [sp, #224]+ sbcs x10, x13, x0+ sbc x11, x13, x1+ lsl x0, x6, #3+ extr x1, x7, x6, #61+ extr x2, x8, x7, #61+ extr x3, x9, x8, #61+ extr x4, x10, x9, #61+ extr x5, x11, x10, #61+ lsr x6, x11, #61+ add x6, x6, #1+ ldp x8, x9, [sp, #240]+ ldp x10, x11, [sp, #256]+ ldp x12, x13, [sp, #272]+ mov x14, #3+ mul x15, x14, x8+ umulh x8, x14, x8+ adds x0, x0, x15+ mul x15, x14, x9+ umulh x9, x14, x9+ adcs x1, x1, x15+ mul x15, x14, x10+ umulh x10, x14, x10+ adcs x2, x2, x15+ mul x15, x14, x11+ umulh x11, x14, x11+ adcs x3, x3, x15+ mul x15, x14, x12+ umulh x12, x14, x12+ adcs x4, x4, x15+ mul x15, x14, x13+ umulh x13, x14, x13+ adcs x5, x5, x15+ adc x6, x6, xzr+ adds x1, x1, x8+ adcs x2, x2, x9+ adcs x3, x3, x10+ adcs x4, x4, x11+ adcs x5, x5, x12+ adcs x6, x6, x13+ lsl x7, x6, #32+ subs x8, x6, x7+ sbc x7, x7, xzr+ adds x0, x0, x8+ adcs x1, x1, x7+ adcs x2, x2, x6+ adcs x3, x3, xzr+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ csetm x6, lo+ mov x7, #4294967295+ and x7, x7, x6+ adds x0, x0, x7+ eor x7, x7, x6+ adcs x1, x1, x7+ mov x7, #-2+ and x7, x7, x6+ adcs x2, x2, x7+ adcs x3, x3, x6+ adcs x4, x4, x6+ adc x5, x5, x6+ stp x0, x1, [x23, #48]+ stp x2, x3, [x23, #64]+ stp x4, x5, [x23, #80]+ CFI_INC_SP(336)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjdouble)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p521_jscalarmul.S view
@@ -0,0 +1,2747 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Jacobian form scalar multiplication for P-521+// Input scalar[9], point[27]; output res[27]+//+// extern void p521_jscalarmul+// (uint64_t res[static 27],+// const uint64_t scalar[static 9],+// const uint64_t point[static 27]);+//+// This function is a variant of its affine point version p521_scalarmul.+// Here, input and output points are assumed to be in Jacobian form with+// a triple (x,y,z) representing the affine point (x/z^2,y/z^3) when+// z is nonzero or the point at infinity (group identity) if z = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-521, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_521) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p521_jscalarmul)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p521_jscalarmul)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p521_jscalarmul)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 72+#define JACSIZE (3*NUMSIZE)++// Safe copies of input res and additional values in variables.++#define tabup x15+#define bf x16+#define sgn x17+#define j x19+#define res x20++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE++#define scalarb sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define tabent sp, #(4*NUMSIZE)++#define tab sp, #(7*NUMSIZE)++// Round up to maintain stack alignment++#define NSPACE 3968++#define selectblock(I) \+ cmp bf, #(1*I) __LF \+ ldp x10, x11, [tabup] __LF \+ csel x0, x10, x0, eq __LF \+ csel x1, x11, x1, eq __LF \+ ldp x10, x11, [tabup, #16] __LF \+ csel x2, x10, x2, eq __LF \+ csel x3, x11, x3, eq __LF \+ ldp x10, x11, [tabup, #32] __LF \+ csel x4, x10, x4, eq __LF \+ csel x5, x11, x5, eq __LF \+ ldp x10, x11, [tabup, #48] __LF \+ csel x6, x10, x6, eq __LF \+ csel x7, x11, x7, eq __LF \+ ldr x10, [tabup, #64] __LF \+ csel x8, x10, x8, eq __LF \+ add tabup, tabup, #JACSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p521_jscalarmul):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ mov res, x0++// Reduce the input scalar mod n_521 and store it to "scalarb".++ mov x19, x2+ add x0, scalarb+ CFI_BL(Lp521_jscalarmul_bignum_mod_n521_9)+ mov x2, x19++// Set the tab[0] table entry to the input point = 1 * P, but also+// reduce all coordinates modulo p. In principle we assume reduction+// as a precondition, but this reduces the scope for surprise, e.g.+// making sure that any input with z = 0 is treated as zero, even+// if the other coordinates are not in fact reduced.++ add x0, tab+ mov x1, x19+ CFI_BL(Lp521_jscalarmul_bignum_mod_p521_9)++ add x0, tab+NUMSIZE+ add x1, x19, #NUMSIZE+ CFI_BL(Lp521_jscalarmul_bignum_mod_p521_9)++ add x0, tab+2*NUMSIZE+ add x1, x19, #(2*NUMSIZE)+ CFI_BL(Lp521_jscalarmul_bignum_mod_p521_9)++// If bit 520 of the scalar is set, then negate the scalar mod n_521,+// i.e. do scalar |-> n_521 - scalar, and also the point to compensate+// by negating its y coordinate. This further step is not needed by+// the indexing scheme (the top window is only a couple of bits either+// way), but is convenient to exclude a problem with the specific value+// scalar = n_521 - 18, where the last Jacobian addition is of the form+// (n_521 - 9) * P + -(9 * P) and hence is a degenerate doubling case.++ ldp x0, x1, [scalarb]+ movbig(x10, #0xbb6f, #0xb71e, #0x9138, #0x6409)+ subs x10, x10, x0+ movbig(x11, #0x3bb5, #0xc9b8, #0x899c, #0x47ae)+ sbcs x11, x11, x1+ ldp x2, x3, [scalarb+16]+ movbig(x12, #0x7fcc, #0x0148, #0xf709, #0xa5d0)+ sbcs x12, x12, x2+ movbig(x13, #0x5186, #0x8783, #0xbf2f, #0x966b)+ sbcs x13, x13, x3+ ldp x4, x5, [scalarb+32]+ mov x14, 0xfffffffffffffffa+ sbcs x14, x14, x4+ mov x15, 0xffffffffffffffff+ sbcs x15, x15, x5+ ldp x6, x7, [scalarb+48]+ mov x16, 0xffffffffffffffff+ sbcs x16, x16, x6+ mov x17, 0xffffffffffffffff+ sbcs x17, x17, x7+ ldr x8, [scalarb+64]+ mov x19, 0x00000000000001ff+ sbc x19, x19, x8+ tst x8, 0x100+ csetm x9, ne+ csel x0, x10, x0, ne+ csel x1, x11, x1, ne+ csel x2, x12, x2, ne+ csel x3, x13, x3, ne+ csel x4, x14, x4, ne+ csel x5, x15, x5, ne+ csel x6, x16, x6, ne+ csel x7, x17, x7, ne+ csel x8, x19, x8, ne+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]+ stp x6, x7, [scalarb+48]+ str x8, [scalarb+64]++ add tabup, tab+ ldp x0, x1, [tabup, #NUMSIZE]+ ldp x2, x3, [tabup, #NUMSIZE+16]+ ldp x4, x5, [tabup, #NUMSIZE+32]+ ldp x6, x7, [tabup, #NUMSIZE+48]+ ldr x8, [tabup, #NUMSIZE+64]+ orr x10, x0, x1+ orr x11, x2, x3+ orr x12, x4, x5+ orr x13, x6, x7+ orr x10, x10, x11+ orr x12, x12, x13+ orr x12, x12, x8+ orr x10, x10, x12+ cmp x10, xzr+ csel x9, x9, xzr, ne+ eor x0, x0, x9+ eor x1, x1, x9+ eor x2, x2, x9+ eor x3, x3, x9+ eor x4, x4, x9+ eor x5, x5, x9+ eor x6, x6, x9+ eor x7, x7, x9+ and x9, x9, #0x1FF+ eor x8, x8, x9+ stp x0, x1, [tabup, #NUMSIZE]+ stp x2, x3, [tabup, #NUMSIZE+16]+ stp x4, x5, [tabup, #NUMSIZE+32]+ stp x6, x7, [tabup, #NUMSIZE+48]+ str x8, [tabup, #NUMSIZE+64]++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ add x0, tab+JACSIZE*1+ add x1, tab+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, tab+JACSIZE*2+ add x1, tab+JACSIZE*1+ add x2, tab+ CFI_BL(Lp521_jscalarmul_jadd)++ add x0, tab+JACSIZE*3+ add x1, tab+JACSIZE*1+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, tab+JACSIZE*4+ add x1, tab+JACSIZE*3+ add x2, tab+ CFI_BL(Lp521_jscalarmul_jadd)++ add x0, tab+JACSIZE*5+ add x1, tab+JACSIZE*2+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, tab+JACSIZE*6+ add x1, tab+JACSIZE*5+ add x2, tab+ CFI_BL(Lp521_jscalarmul_jadd)++ add x0, tab+JACSIZE*7+ add x1, tab+JACSIZE*3+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, tab+JACSIZE*8+ add x1, tab+JACSIZE*7+ add x2, tab+ CFI_BL(Lp521_jscalarmul_jadd)++ add x0, tab+JACSIZE*9+ add x1, tab+JACSIZE*4+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, tab+JACSIZE*10+ add x1, tab+JACSIZE*9+ add x2, tab+ CFI_BL(Lp521_jscalarmul_jadd)++ add x0, tab+JACSIZE*11+ add x1, tab+JACSIZE*5+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, tab+JACSIZE*12+ add x1, tab+JACSIZE*11+ add x2, tab+ CFI_BL(Lp521_jscalarmul_jadd)++ add x0, tab+JACSIZE*13+ add x1, tab+JACSIZE*6+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, tab+JACSIZE*14+ add x1, tab+JACSIZE*13+ add x2, tab+ CFI_BL(Lp521_jscalarmul_jadd)++ add x0, tab+JACSIZE*15+ add x1, tab+JACSIZE*7+ CFI_BL(Lp521_jscalarmul_jdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically since none is a simple ARM load.+//+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x4210842108421084+// 0x8421084210842108+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x0000000000000084++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ ldp x6, x7, [scalarb+48]+ ldr x8, [scalarb+64]++ movbig(x10, #0x1084, #0x2108, #0x4210, #0x8421)+ adds x0, x0, x10, lsr #1+ adcs x1, x1, x10+ lsl x10, x10, #1+ adcs x2, x2, x10+ lsl x10, x10, #1+ adcs x3, x3, x10+ lsl x10, x10, #1+ adcs x4, x4, x10+ lsr x11, x10, #4+ adcs x5, x5, x11+ lsr x10, x10, #3+ adcs x6, x6, x10+ lsl x10, x10, #1+ adcs x7, x7, x10+ lsl x10, x10, #1+ and x10, x10, #0xFF+ adc x8, x8, x10++// Because of the initial reduction the top bitfield (>= bits 520) is <= 1,+// i.e. just a single bit. Record that in "bf", then shift the whole+// scalar left 56 bits to align the top of the next bitfield with the MSB+// (bits 571..575).++ lsr bf, x8, #8+ extr x8, x8, x7, #8+ extr x7, x7, x6, #8+ extr x6, x6, x5, #8+ extr x5, x5, x4, #8+ extr x4, x4, x3, #8+ extr x3, x3, x2, #8+ extr x2, x2, x1, #8+ extr x1, x1, x0, #8+ lsl x0, x0, #56+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]+ stp x6, x7, [scalarb+48]+ str x8, [scalarb+64]++// According to the top bit, initialize the accumulator to P or 0. This top+// digit, uniquely, is not recoded so there is no sign adjustment to make.+// We only really need to adjust the z coordinate to zero, but do all three.++ add tabup, tab+ cmp bf, xzr++ ldp x0, x1, [tabup]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc]+ ldp x0, x1, [tabup, #16]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+16]+ ldp x0, x1, [tabup, #32]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+32]+ ldp x0, x1, [tabup, #48]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+48]+ ldp x0, x1, [tabup, #64]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+64]+ ldp x0, x1, [tabup, #80]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+80]+ ldp x0, x1, [tabup, #96]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+96]+ ldp x0, x1, [tabup, #112]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+112]+ ldp x0, x1, [tabup, #128]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+128]+ ldp x0, x1, [tabup, #144]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+144]+ ldp x0, x1, [tabup, #160]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+160]+ ldp x0, x1, [tabup, #176]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+176]+ ldp x0, x1, [tabup, #192]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+192]+ ldr x0, [tabup, #208]+ csel x0, x0, xzr, ne+ str x0, [acc+208]++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++ mov j, #520++Lp521_jscalarmul_mainloop:+ sub j, j, #5++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_jdouble)++// Choose the bitfield and adjust it to sign and magnitude++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ ldp x6, x7, [scalarb+48]+ ldr x8, [scalarb+64]+ lsr bf, x8, #59+ extr x8, x8, x7, #59+ extr x7, x7, x6, #59+ extr x6, x6, x5, #59+ extr x5, x5, x4, #59+ extr x4, x4, x3, #59+ extr x3, x3, x2, #59+ extr x2, x2, x1, #59+ extr x1, x1, x0, #59+ lsl x0, x0, #5+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]+ stp x6, x7, [scalarb+48]+ str x8, [scalarb+64]++ subs bf, bf, #16+ csetm sgn, lo // sgn = sign of digit (1 = negative)+ cneg bf, bf, lo // bf = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ add tabup, tab+ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)+ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]+ stp x4, x5, [tabent+32]+ stp x6, x7, [tabent+48]+ str x8, [tabent+64]++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ add tabup, tab+2*NUMSIZE+ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)+ stp x0, x1, [tabent+2*NUMSIZE]+ stp x2, x3, [tabent+2*NUMSIZE+16]+ stp x4, x5, [tabent+2*NUMSIZE+32]+ stp x6, x7, [tabent+2*NUMSIZE+48]+ str x8, [tabent+2*NUMSIZE+64]++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ add tabup, tab+NUMSIZE+ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_521 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).++ orr x10, x0, x1+ orr x11, x2, x3+ orr x12, x4, x5+ orr x13, x6, x7+ orr x10, x10, x11+ orr x12, x12, x13+ orr x12, x12, x8+ orr x10, x10, x12+ cmp x10, xzr+ csel sgn, sgn, xzr, ne++ eor x0, x0, sgn+ eor x1, x1, sgn+ eor x2, x2, sgn+ eor x3, x3, sgn+ eor x4, x4, sgn+ eor x5, x5, sgn+ eor x6, x6, sgn+ eor x7, x7, sgn+ and sgn, sgn, #0x1FF+ eor x8, x8, sgn++ stp x0, x1, [tabent+NUMSIZE]+ stp x2, x3, [tabent+NUMSIZE+16]+ stp x4, x5, [tabent+NUMSIZE+32]+ stp x6, x7, [tabent+NUMSIZE+48]+ str x8, [tabent+NUMSIZE+64]++// Add to the accumulator++ add x0, acc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp521_jscalarmul_jadd)++ cbnz j, Lp521_jscalarmul_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ ldp x0, x1, [acc]+ stp x0, x1, [res]+ ldp x0, x1, [acc+16]+ stp x0, x1, [res, #16]+ ldp x0, x1, [acc+32]+ stp x0, x1, [res, #32]+ ldp x0, x1, [acc+48]+ stp x0, x1, [res, #48]+ ldp x0, x1, [acc+64]+ stp x0, x1, [res, #64]+ ldp x0, x1, [acc+80]+ stp x0, x1, [res, #80]+ ldp x0, x1, [acc+96]+ stp x0, x1, [res, #96]+ ldp x0, x1, [acc+112]+ stp x0, x1, [res, #112]+ ldp x0, x1, [acc+128]+ stp x0, x1, [res, #128]+ ldp x0, x1, [acc+144]+ stp x0, x1, [res, #144]+ ldp x0, x1, [acc+160]+ stp x0, x1, [res, #160]+ ldp x0, x1, [acc+176]+ stp x0, x1, [res, #176]+ ldp x0, x1, [acc+192]+ stp x0, x1, [res, #192]+ ldr x0, [acc+208]+ str x0, [res, #208]++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x21,x30)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p521_jscalarmul)++// Local copies of subroutines, complete clones at the moment except+// that we share multiplication and squaring between the point operations.++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_p521_9)++Lp521_jscalarmul_bignum_mod_p521_9:+ CFI_START+ ldr x12, [x1, #64]+ lsr x2, x12, #9+ cmp xzr, xzr+ ldp x4, x5, [x1]+ adcs xzr, x4, x2+ adcs xzr, x5, xzr+ ldp x6, x7, [x1, #16]+ and x3, x6, x7+ adcs xzr, x3, xzr+ ldp x8, x9, [x1, #32]+ and x3, x8, x9+ adcs xzr, x3, xzr+ ldp x10, x11, [x1, #48]+ and x3, x10, x11+ adcs xzr, x3, xzr+ orr x3, x12, #0xfffffffffffffe00+ adcs x3, x3, xzr+ adcs x4, x4, x2+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adcs x11, x11, xzr+ adc x12, x12, xzr+ and x12, x12, #0x1ff+ stp x4, x5, [x0]+ stp x6, x7, [x0, #16]+ stp x8, x9, [x0, #32]+ stp x10, x11, [x0, #48]+ str x12, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_p521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_n521_9)++Lp521_jscalarmul_bignum_mod_n521_9:+ CFI_START+ ldr x14, [x1, #64]+ lsr x15, x14, #9+ add x15, x15, #1+ mov x2, #39927+ movk x2, #28359, lsl #16+ movk x2, #18657, lsl #32+ movk x2, #17552, lsl #48+ mul x6, x2, x15+ mov x3, #47185+ movk x3, #30307, lsl #16+ movk x3, #13895, lsl #32+ movk x3, #50250, lsl #48+ mul x7, x3, x15+ mov x4, #23087+ movk x4, #2294, lsl #16+ movk x4, #65207, lsl #32+ movk x4, #32819, lsl #48+ mul x8, x4, x15+ mov x5, #27028+ movk x5, #16592, lsl #16+ movk x5, #30844, lsl #32+ movk x5, #44665, lsl #48+ mul x9, x5, x15+ lsl x10, x15, #2+ add x10, x10, x15+ umulh x13, x2, x15+ adds x7, x7, x13+ umulh x13, x3, x15+ adcs x8, x8, x13+ umulh x13, x4, x15+ adcs x9, x9, x13+ umulh x13, x5, x15+ adc x10, x10, x13+ ldp x12, x13, [x1]+ adds x6, x6, x12+ adcs x7, x7, x13+ ldp x12, x13, [x1, #16]+ adcs x8, x8, x12+ adcs x9, x9, x13+ ldp x13, x11, [x1, #32]+ adcs x10, x10, x13+ adcs x11, x11, xzr+ ldp x12, x13, [x1, #48]+ adcs x12, x12, xzr+ adcs x13, x13, xzr+ orr x14, x14, #0xfffffffffffffe00+ adcs x14, x14, xzr+ csetm x15, lo+ and x2, x2, x15+ subs x6, x6, x2+ and x3, x3, x15+ sbcs x7, x7, x3+ and x4, x4, x15+ sbcs x8, x8, x4+ and x5, x5, x15+ sbcs x9, x9, x5+ mov x2, #5+ and x2, x2, x15+ sbcs x10, x10, x2+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ and x14, x14, #0x1ff+ stp x6, x7, [x0]+ stp x8, x9, [x0, #16]+ stp x10, x11, [x0, #32]+ stp x12, x13, [x0, #48]+ str x14, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_n521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_jadd)++Lp521_jscalarmul_jadd:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_PUSH2(x27,x28)+ CFI_PUSH2(x29,x30)+ CFI_DEC_SP(576)+ mov x26, x0+ mov x27, x1+ mov x28, x2+ mov x0, sp+ add x1, x27, #0x90+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ add x0, sp, #0x168+ add x1, x28, #0x90+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ add x0, sp, #0x1f8+ add x1, x28, #0x90+ add x2, x27, #0x48+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x48+ add x1, x27, #0x90+ add x2, x28, #0x48+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x90+ mov x1, sp+ add x2, x28, #0x0+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x120+ add x1, sp, #0x168+ add x2, x27, #0x0+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x48+ mov x1, sp+ add x2, sp, #0x48+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x1f8+ add x1, sp, #0x168+ add x2, sp, #0x1f8+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x168+ add x1, sp, #0x90+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_sub_p521)+ add x0, sp, #0x48+ add x1, sp, #0x48+ add x2, sp, #0x1f8+ CFI_BL(Lp521_jscalarmul_sub_p521)+ add x0, sp, #0xd8+ add x1, sp, #0x168+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ mov x0, sp+ add x1, sp, #0x48+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ add x0, sp, #0x120+ add x1, sp, #0xd8+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x90+ add x1, sp, #0xd8+ add x2, sp, #0x90+ CFI_BL(Lp521_jscalarmul_mul_p521)+ mov x0, sp+ mov x1, sp+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_sub_p521)+ add x0, sp, #0xd8+ add x1, sp, #0x90+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_sub_p521)+ add x0, sp, #0x168+ add x1, sp, #0x168+ add x2, x27, #0x90+ CFI_BL(Lp521_jscalarmul_mul_p521)+ mov x0, sp+ mov x1, sp+ add x2, sp, #0x90+ CFI_BL(Lp521_jscalarmul_sub_p521)+ add x0, sp, #0x120+ add x1, sp, #0x120+ mov x2, sp+ CFI_BL(Lp521_jscalarmul_sub_p521)+ add x0, sp, #0xd8+ add x1, sp, #0xd8+ add x2, sp, #0x1f8+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x168+ add x1, sp, #0x168+ add x2, x28, #0x90+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x120+ add x1, sp, #0x48+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x120+ add x1, sp, #0x120+ add x2, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_sub_p521)+ ldp x0, x1, [x27, #144]+ ldp x2, x3, [x27, #160]+ ldp x4, x5, [x27, #176]+ ldp x6, x7, [x27, #192]+ ldr x8, [x27, #208]+ orr x20, x0, x1+ orr x21, x2, x3+ orr x22, x4, x5+ orr x23, x6, x7+ orr x20, x20, x21+ orr x22, x22, x23+ orr x20, x20, x8+ orr x20, x20, x22+ cmp x20, xzr+ cset x20, ne+ ldp x10, x11, [x28, #144]+ ldp x12, x13, [x28, #160]+ ldp x14, x15, [x28, #176]+ ldp x16, x17, [x28, #192]+ ldr x19, [x28, #208]+ orr x21, x10, x11+ orr x22, x12, x13+ orr x23, x14, x15+ orr x24, x16, x17+ orr x21, x21, x22+ orr x23, x23, x24+ orr x21, x21, x19+ orr x21, x21, x23+ csel x0, x0, x10, ne+ csel x1, x1, x11, ne+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ csel x4, x4, x14, ne+ csel x5, x5, x15, ne+ csel x6, x6, x16, ne+ csel x7, x7, x17, ne+ csel x8, x8, x19, ne+ cmp x21, xzr+ cset x21, ne+ cmp x21, x20+ ldp x10, x11, [sp, #360]+ ldp x12, x13, [sp, #376]+ ldp x14, x15, [sp, #392]+ ldp x16, x17, [sp, #408]+ ldr x19, [sp, #424]+ csel x0, x0, x10, ne+ csel x1, x1, x11, ne+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ csel x4, x4, x14, ne+ csel x5, x5, x15, ne+ csel x6, x6, x16, ne+ csel x7, x7, x17, ne+ csel x8, x8, x19, ne+ stp x0, x1, [sp, #360]+ stp x2, x3, [sp, #376]+ stp x4, x5, [sp, #392]+ stp x6, x7, [sp, #408]+ str x8, [sp, #424]+ ldp x20, x21, [x27]+ ldp x0, x1, [sp]+ csel x0, x20, x0, cc+ csel x1, x21, x1, cc+ ldp x20, x21, [x28]+ csel x0, x20, x0, hi+ csel x1, x21, x1, hi+ ldp x20, x21, [x27, #16]+ ldp x2, x3, [sp, #16]+ csel x2, x20, x2, cc+ csel x3, x21, x3, cc+ ldp x20, x21, [x28, #16]+ csel x2, x20, x2, hi+ csel x3, x21, x3, hi+ ldp x20, x21, [x27, #32]+ ldp x4, x5, [sp, #32]+ csel x4, x20, x4, cc+ csel x5, x21, x5, cc+ ldp x20, x21, [x28, #32]+ csel x4, x20, x4, hi+ csel x5, x21, x5, hi+ ldp x20, x21, [x27, #48]+ ldp x6, x7, [sp, #48]+ csel x6, x20, x6, cc+ csel x7, x21, x7, cc+ ldp x20, x21, [x28, #48]+ csel x6, x20, x6, hi+ csel x7, x21, x7, hi+ ldr x20, [x27, #64]+ ldr x8, [sp, #64]+ csel x8, x20, x8, cc+ ldr x21, [x28, #64]+ csel x8, x21, x8, hi+ ldp x20, x21, [x27, #72]+ ldp x10, x11, [sp, #288]+ csel x10, x20, x10, cc+ csel x11, x21, x11, cc+ ldp x20, x21, [x28, #72]+ csel x10, x20, x10, hi+ csel x11, x21, x11, hi+ ldp x20, x21, [x27, #88]+ ldp x12, x13, [sp, #304]+ csel x12, x20, x12, cc+ csel x13, x21, x13, cc+ ldp x20, x21, [x28, #88]+ csel x12, x20, x12, hi+ csel x13, x21, x13, hi+ ldp x20, x21, [x27, #104]+ ldp x14, x15, [sp, #320]+ csel x14, x20, x14, cc+ csel x15, x21, x15, cc+ ldp x20, x21, [x28, #104]+ csel x14, x20, x14, hi+ csel x15, x21, x15, hi+ ldp x20, x21, [x27, #120]+ ldp x16, x17, [sp, #336]+ csel x16, x20, x16, cc+ csel x17, x21, x17, cc+ ldp x20, x21, [x28, #120]+ csel x16, x20, x16, hi+ csel x17, x21, x17, hi+ ldr x20, [x27, #136]+ ldr x19, [sp, #352]+ csel x19, x20, x19, cc+ ldr x21, [x28, #136]+ csel x19, x21, x19, hi+ stp x0, x1, [x26]+ stp x2, x3, [x26, #16]+ stp x4, x5, [x26, #32]+ stp x6, x7, [x26, #48]+ str x8, [x26, #64]+ ldp x0, x1, [sp, #360]+ ldp x2, x3, [sp, #376]+ ldp x4, x5, [sp, #392]+ ldp x6, x7, [sp, #408]+ ldr x8, [sp, #424]+ stp x10, x11, [x26, #72]+ stp x12, x13, [x26, #88]+ stp x14, x15, [x26, #104]+ stp x16, x17, [x26, #120]+ str x19, [x26, #136]+ stp x0, x1, [x26, #144]+ stp x2, x3, [x26, #160]+ stp x4, x5, [x26, #176]+ stp x6, x7, [x26, #192]+ str x8, [x26, #208]+ CFI_INC_SP(576)+ CFI_POP2(x29,x30)+ CFI_POP2(x27,x28)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_jadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_jdouble)++Lp521_jscalarmul_jdouble:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_PUSH2(x27,x28)+ CFI_PUSH2(x29,x30)+ CFI_DEC_SP(512)+ mov x26, x0+ mov x27, x1+ mov x0, sp+ add x1, x27, #0x90+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ add x0, sp, #0x48+ add x1, x27, #0x48+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ ldp x5, x6, [x27]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x27, #16]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x27, #32]+ ldp x4, x3, [sp, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [x27, #48]+ ldp x4, x3, [sp, #48]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [x27, #64]+ ldr x4, [sp, #64]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [sp, #216]+ stp x7, x8, [sp, #232]+ stp x9, x10, [sp, #248]+ stp x11, x12, [sp, #264]+ str x13, [sp, #280]+ cmp xzr, xzr+ ldp x5, x6, [x27]+ ldp x4, x3, [sp]+ adcs x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x27, #16]+ ldp x4, x3, [sp, #16]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x27, #32]+ ldp x4, x3, [sp, #32]+ adcs x9, x9, x4+ adcs x10, x10, x3+ ldp x11, x12, [x27, #48]+ ldp x4, x3, [sp, #48]+ adcs x11, x11, x4+ adcs x12, x12, x3+ ldr x13, [x27, #64]+ ldr x4, [sp, #64]+ adc x13, x13, x4+ subs x4, x13, #0x200+ csetm x4, cs+ sbcs x5, x5, xzr+ and x4, x4, #0x200+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, x4+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ stp x11, x12, [sp, #192]+ str x13, [sp, #208]+ add x0, sp, #0xd8+ add x1, sp, #0x90+ add x2, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_mul_p521)+ cmp xzr, xzr+ ldp x5, x6, [x27, #72]+ ldp x4, x3, [x27, #144]+ adcs x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x27, #88]+ ldp x4, x3, [x27, #160]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x27, #104]+ ldp x4, x3, [x27, #176]+ adcs x9, x9, x4+ adcs x10, x10, x3+ ldp x11, x12, [x27, #120]+ ldp x4, x3, [x27, #192]+ adcs x11, x11, x4+ adcs x12, x12, x3+ ldr x13, [x27, #136]+ ldr x4, [x27, #208]+ adc x13, x13, x4+ subs x4, x13, #0x200+ csetm x4, cs+ sbcs x5, x5, xzr+ and x4, x4, #0x200+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, x4+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ stp x11, x12, [sp, #192]+ str x13, [sp, #208]+ add x0, sp, #0x120+ add x1, x27, #0x0+ add x2, sp, #0x48+ CFI_BL(Lp521_jscalarmul_mul_p521)+ add x0, sp, #0x168+ add x1, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ add x0, sp, #0x90+ add x1, sp, #0x90+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ ldp x6, x7, [sp, #288]+ mov x1, #0xc+ mul x3, x1, x6+ mul x4, x1, x7+ umulh x6, x1, x6+ adds x4, x4, x6+ umulh x7, x1, x7+ ldp x8, x9, [sp, #304]+ mul x5, x1, x8+ mul x6, x1, x9+ umulh x8, x1, x8+ adcs x5, x5, x7+ umulh x9, x1, x9+ adcs x6, x6, x8+ ldp x10, x11, [sp, #320]+ mul x7, x1, x10+ mul x8, x1, x11+ umulh x10, x1, x10+ adcs x7, x7, x9+ umulh x11, x1, x11+ adcs x8, x8, x10+ ldp x12, x13, [sp, #336]+ mul x9, x1, x12+ mul x10, x1, x13+ umulh x12, x1, x12+ adcs x9, x9, x11+ umulh x13, x1, x13+ adcs x10, x10, x12+ ldr x14, [sp, #352]+ mul x11, x1, x14+ adc x11, x11, x13+ mov x1, #0x9+ ldp x20, x21, [sp, #360]+ mvn x20, x20+ mul x0, x1, x20+ umulh x20, x1, x20+ adds x3, x3, x0+ mvn x21, x21+ mul x0, x1, x21+ umulh x21, x1, x21+ adcs x4, x4, x0+ ldp x22, x23, [sp, #376]+ mvn x22, x22+ mul x0, x1, x22+ umulh x22, x1, x22+ adcs x5, x5, x0+ mvn x23, x23+ mul x0, x1, x23+ umulh x23, x1, x23+ adcs x6, x6, x0+ ldp x17, x19, [sp, #392]+ mvn x17, x17+ mul x0, x1, x17+ umulh x17, x1, x17+ adcs x7, x7, x0+ mvn x19, x19+ mul x0, x1, x19+ umulh x19, x1, x19+ adcs x8, x8, x0+ ldp x2, x16, [sp, #408]+ mvn x2, x2+ mul x0, x1, x2+ umulh x2, x1, x2+ adcs x9, x9, x0+ mvn x16, x16+ mul x0, x1, x16+ umulh x16, x1, x16+ adcs x10, x10, x0+ ldr x0, [sp, #424]+ eor x0, x0, #0x1ff+ mul x0, x1, x0+ adc x11, x11, x0+ adds x4, x4, x20+ adcs x5, x5, x21+ and x15, x4, x5+ adcs x6, x6, x22+ and x15, x15, x6+ adcs x7, x7, x23+ and x15, x15, x7+ adcs x8, x8, x17+ and x15, x15, x8+ adcs x9, x9, x19+ and x15, x15, x9+ adcs x10, x10, x2+ and x15, x15, x10+ adc x11, x11, x16+ lsr x12, x11, #9+ orr x11, x11, #0xfffffffffffffe00+ cmp xzr, xzr+ adcs xzr, x3, x12+ adcs xzr, x15, xzr+ adcs xzr, x11, xzr+ adcs x3, x3, x12+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adc x11, x11, xzr+ and x11, x11, #0x1ff+ stp x3, x4, [sp, #360]+ stp x5, x6, [sp, #376]+ stp x7, x8, [sp, #392]+ stp x9, x10, [sp, #408]+ str x11, [sp, #424]+ ldp x5, x6, [sp, #144]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #160]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #176]+ ldp x4, x3, [sp, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [sp, #192]+ ldp x4, x3, [sp, #48]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [sp, #208]+ ldr x4, [sp, #64]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ stp x11, x12, [sp, #192]+ str x13, [sp, #208]+ mov x0, sp+ add x1, sp, #0x48+ CFI_BL(Lp521_jscalarmul_sqr_p521)+ add x0, sp, #0xd8+ add x1, sp, #0x168+ add x2, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_mul_p521)+ ldp x5, x6, [sp, #144]+ ldp x4, x3, [sp, #72]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #160]+ ldp x4, x3, [sp, #88]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #176]+ ldp x4, x3, [sp, #104]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [sp, #192]+ ldp x4, x3, [sp, #120]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [sp, #208]+ ldr x4, [sp, #136]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [x26, #144]+ stp x7, x8, [x26, #160]+ stp x9, x10, [x26, #176]+ stp x11, x12, [x26, #192]+ str x13, [x26, #208]+ ldp x6, x7, [sp, #288]+ lsl x3, x6, #2+ extr x4, x7, x6, #62+ ldp x8, x9, [sp, #304]+ extr x5, x8, x7, #62+ extr x6, x9, x8, #62+ ldp x10, x11, [sp, #320]+ extr x7, x10, x9, #62+ extr x8, x11, x10, #62+ ldp x12, x13, [sp, #336]+ extr x9, x12, x11, #62+ extr x10, x13, x12, #62+ ldr x14, [sp, #352]+ extr x11, x14, x13, #62+ ldp x0, x1, [sp, #360]+ mvn x0, x0+ adds x3, x3, x0+ sbcs x4, x4, x1+ ldp x0, x1, [sp, #376]+ sbcs x5, x5, x0+ and x15, x4, x5+ sbcs x6, x6, x1+ and x15, x15, x6+ ldp x0, x1, [sp, #392]+ sbcs x7, x7, x0+ and x15, x15, x7+ sbcs x8, x8, x1+ and x15, x15, x8+ ldp x0, x1, [sp, #408]+ sbcs x9, x9, x0+ and x15, x15, x9+ sbcs x10, x10, x1+ and x15, x15, x10+ ldr x0, [sp, #424]+ eor x0, x0, #0x1ff+ adc x11, x11, x0+ lsr x12, x11, #9+ orr x11, x11, #0xfffffffffffffe00+ cmp xzr, xzr+ adcs xzr, x3, x12+ adcs xzr, x15, xzr+ adcs xzr, x11, xzr+ adcs x3, x3, x12+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adc x11, x11, xzr+ and x11, x11, #0x1ff+ stp x3, x4, [x26]+ stp x5, x6, [x26, #16]+ stp x7, x8, [x26, #32]+ stp x9, x10, [x26, #48]+ str x11, [x26, #64]+ ldp x6, x7, [sp, #216]+ lsl x3, x6, #1+ adds x3, x3, x6+ extr x4, x7, x6, #63+ adcs x4, x4, x7+ ldp x8, x9, [sp, #232]+ extr x5, x8, x7, #63+ adcs x5, x5, x8+ extr x6, x9, x8, #63+ adcs x6, x6, x9+ ldp x10, x11, [sp, #248]+ extr x7, x10, x9, #63+ adcs x7, x7, x10+ extr x8, x11, x10, #63+ adcs x8, x8, x11+ ldp x12, x13, [sp, #264]+ extr x9, x12, x11, #63+ adcs x9, x9, x12+ extr x10, x13, x12, #63+ adcs x10, x10, x13+ ldr x14, [sp, #280]+ extr x11, x14, x13, #63+ adc x11, x11, x14+ ldp x20, x21, [sp]+ mvn x20, x20+ lsl x0, x20, #3+ adds x3, x3, x0+ mvn x21, x21+ extr x0, x21, x20, #61+ adcs x4, x4, x0+ ldp x22, x23, [sp, #16]+ mvn x22, x22+ extr x0, x22, x21, #61+ adcs x5, x5, x0+ and x15, x4, x5+ mvn x23, x23+ extr x0, x23, x22, #61+ adcs x6, x6, x0+ and x15, x15, x6+ ldp x20, x21, [sp, #32]+ mvn x20, x20+ extr x0, x20, x23, #61+ adcs x7, x7, x0+ and x15, x15, x7+ mvn x21, x21+ extr x0, x21, x20, #61+ adcs x8, x8, x0+ and x15, x15, x8+ ldp x22, x23, [sp, #48]+ mvn x22, x22+ extr x0, x22, x21, #61+ adcs x9, x9, x0+ and x15, x15, x9+ mvn x23, x23+ extr x0, x23, x22, #61+ adcs x10, x10, x0+ and x15, x15, x10+ ldr x0, [sp, #64]+ eor x0, x0, #0x1ff+ extr x0, x0, x23, #61+ adc x11, x11, x0+ lsr x12, x11, #9+ orr x11, x11, #0xfffffffffffffe00+ cmp xzr, xzr+ adcs xzr, x3, x12+ adcs xzr, x15, xzr+ adcs xzr, x11, xzr+ adcs x3, x3, x12+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adc x11, x11, xzr+ and x11, x11, #0x1ff+ stp x3, x4, [x26, #72]+ stp x5, x6, [x26, #88]+ stp x7, x8, [x26, #104]+ stp x9, x10, [x26, #120]+ str x11, [x26, #136]+ CFI_INC_SP(512)+ CFI_POP2(x29,x30)+ CFI_POP2(x27,x28)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_jdouble)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_mul_p521)++Lp521_jscalarmul_mul_p521:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_DEC_SP(80)+ ldr q6, [x2]+ ldp x10, x17, [x1, #16]+ ldr q4, [x1]+ ldr q16, [x2, #32]+ ldp x5, x20, [x2, #16]+ ldr q2, [x1, #32]+ movi v31.2D, #0x00000000ffffffff+ uzp2 v17.4S, v6.4S, v6.4S+ rev64 v7.4S, v6.4S+ ldp x15, x21, [x1]+ xtn v25.2S, v6.2D+ xtn v22.2S, v4.2D+ subs x14, x10, x17+ mul v7.4S, v7.4S, v4.4S+ csetm x8, cc+ rev64 v3.4S, v16.4S+ xtn v1.2S, v16.2D+ ldp x13, x16, [x2]+ mul x26, x10, x5+ uzp2 v16.4S, v16.4S, v16.4S+ uaddlp v26.2D, v7.4S+ cneg x4, x14, cc+ subs x24, x15, x21+ xtn v5.2S, v2.2D+ mul v28.4S, v3.4S, v2.4S+ shl v26.2D, v26.2D, #32+ mul x22, x17, x20+ umull v20.2D, v22.2S, v25.2S+ uzp2 v6.4S, v4.4S, v4.4S+ umull v18.2D, v22.2S, v17.2S+ uzp2 v4.4S, v2.4S, v2.4S+ cneg x14, x24, cc+ csetm x7, cc+ umulh x11, x17, x20+ usra v18.2D, v20.2D, #32+ uaddlp v7.2D, v28.4S+ subs x19, x16, x13+ umlal v26.2D, v22.2S, v25.2S+ cneg x19, x19, cc+ shl v28.2D, v7.2D, #32+ umull v7.2D, v5.2S, v1.2S+ umull v30.2D, v5.2S, v16.2S+ cinv x6, x7, cc+ mul x25, x14, x19+ umlal v28.2D, v5.2S, v1.2S+ umull v21.2D, v6.2S, v17.2S+ umulh x14, x14, x19+ usra v30.2D, v7.2D, #32+ subs x9, x20, x5+ and v29.16B, v18.16B, v31.16B+ cinv x23, x8, cc+ mov x8, v26.d[1]+ cneg x12, x9, cc+ usra v21.2D, v18.2D, #32+ umlal v29.2D, v6.2S, v25.2S+ mul x24, x4, x12+ umull v18.2D, v4.2S, v16.2S+ movi v25.2D, #0x00000000ffffffff+ eor x9, x14, x6+ and v7.16B, v30.16B, v25.16B+ usra v21.2D, v29.2D, #32+ umulh x7, x10, x5+ usra v18.2D, v30.2D, #32+ umlal v7.2D, v4.2S, v1.2S+ mov x19, v21.d[0]+ umulh x3, x4, x12+ mov x14, v21.d[1]+ usra v18.2D, v7.2D, #32+ adds x4, x8, x19+ mov x8, v26.d[0]+ adcs x19, x26, x14+ adcs x14, x22, x7+ adc x12, x11, xzr+ adds x11, x4, x8+ adcs x26, x19, x4+ adcs x22, x14, x19+ eor x4, x24, x23+ adcs x14, x12, x14+ eor x7, x25, x6+ adc x25, xzr, x12+ eor x19, x3, x23+ adds x3, x26, x8+ adcs x24, x22, x11+ adcs x12, x14, x26+ adcs x22, x25, x22+ adcs x26, xzr, x14+ adc x14, xzr, x25+ cmn x23, #0x1+ adcs x22, x22, x4+ adcs x19, x26, x19+ adc x25, x14, x23+ subs x14, x21, x17+ cneg x23, x14, cc+ csetm x26, cc+ subs x4, x20, x16+ cneg x14, x4, cc+ cinv x4, x26, cc+ cmn x6, #0x1+ adcs x11, x11, x7+ mul x7, x23, x14+ adcs x9, x3, x9+ adcs x26, x24, x6+ umulh x3, x23, x14+ adcs x14, x12, x6+ adcs x22, x22, x6+ adcs x12, x19, x6+ extr x24, x11, x8, #55+ adc x6, x25, x6+ subs x19, x15, x17+ csetm x17, cc+ cneg x23, x19, cc+ subs x19, x20, x13+ lsl x25, x8, #9+ eor x8, x7, x4+ cneg x20, x19, cc+ umulh x7, x23, x20+ cinv x19, x17, cc+ subs x17, x15, x10+ csetm x15, cc+ stp x25, x24, [sp, #32]+ cneg x24, x17, cc+ mul x20, x23, x20+ subs x25, x5, x13+ cneg x13, x25, cc+ cinv x15, x15, cc+ mul x25, x24, x13+ subs x21, x21, x10+ csetm x23, cc+ cneg x17, x21, cc+ subs x21, x5, x16+ umulh x13, x24, x13+ cinv x10, x23, cc+ cneg x23, x21, cc+ cmn x4, #0x1+ adcs x14, x14, x8+ eor x21, x3, x4+ adcs x21, x22, x21+ eor x5, x20, x19+ adcs x24, x12, x4+ mul x12, x17, x23+ eor x8, x25, x15+ adc x25, x6, x4+ cmn x15, #0x1+ adcs x6, x9, x8+ ldp x20, x8, [x2, #48]+ eor x9, x13, x15+ adcs x4, x26, x9+ umulh x26, x17, x23+ ldp x17, x13, [x1, #48]+ adcs x9, x14, x15+ adcs x16, x21, x15+ adcs x14, x24, x15+ eor x21, x7, x19+ mul x23, x17, x20+ adc x24, x25, x15+ cmn x19, #0x1+ adcs x7, x4, x5+ adcs x9, x9, x21+ umulh x3, x13, x8+ adcs x16, x16, x19+ adcs x22, x14, x19+ eor x5, x12, x10+ adc x12, x24, x19+ cmn x10, #0x1+ adcs x19, x7, x5+ eor x14, x26, x10+ mov x7, v28.d[1]+ adcs x24, x9, x14+ extr x4, x19, x6, #55+ umulh x15, x17, x20+ mov x14, v18.d[1]+ lsr x9, x19, #55+ adcs x5, x16, x10+ mov x16, v18.d[0]+ adcs x19, x22, x10+ str x9, [sp, #64]+ extr x25, x6, x11, #55+ adc x21, x12, x10+ subs x26, x17, x13+ stp x25, x4, [sp, #48]+ stp x19, x21, [sp, #16]+ csetm x6, cc+ cneg x4, x26, cc+ mul x19, x13, x8+ subs x11, x8, x20+ stp x24, x5, [sp]+ ldp x21, x10, [x1, #32]+ cinv x12, x6, cc+ cneg x6, x11, cc+ mov x9, v28.d[0]+ umulh x25, x4, x6+ adds x22, x7, x16+ ldp x16, x5, [x2, #32]+ adcs x14, x23, x14+ adcs x11, x19, x15+ adc x24, x3, xzr+ adds x3, x22, x9+ adcs x15, x14, x22+ mul x22, x4, x6+ adcs x6, x11, x14+ adcs x4, x24, x11+ eor x14, x25, x12+ adc x26, xzr, x24+ subs x7, x21, x10+ csetm x23, cc+ cneg x19, x7, cc+ subs x24, x5, x16+ cneg x11, x24, cc+ cinv x7, x23, cc+ adds x25, x15, x9+ eor x23, x22, x12+ adcs x22, x6, x3+ mul x24, x19, x11+ adcs x15, x4, x15+ adcs x6, x26, x6+ umulh x19, x19, x11+ adcs x11, xzr, x4+ adc x26, xzr, x26+ cmn x12, #0x1+ adcs x4, x6, x23+ eor x6, x24, x7+ adcs x14, x11, x14+ adc x26, x26, x12+ subs x11, x10, x13+ cneg x12, x11, cc+ csetm x11, cc+ eor x19, x19, x7+ subs x24, x8, x5+ cinv x11, x11, cc+ cneg x24, x24, cc+ cmn x7, #0x1+ adcs x3, x3, x6+ mul x23, x12, x24+ adcs x25, x25, x19+ adcs x6, x22, x7+ umulh x19, x12, x24+ adcs x22, x15, x7+ adcs x12, x4, x7+ eor x24, x23, x11+ adcs x4, x14, x7+ adc x26, x26, x7+ eor x19, x19, x11+ subs x14, x21, x17+ cneg x7, x14, cc+ csetm x14, cc+ subs x23, x20, x16+ cinv x14, x14, cc+ cneg x23, x23, cc+ cmn x11, #0x1+ adcs x22, x22, x24+ mul x24, x7, x23+ adcs x15, x12, x19+ adcs x4, x4, x11+ adc x19, x26, x11+ umulh x26, x7, x23+ subs x7, x21, x13+ eor x11, x24, x14+ cneg x23, x7, cc+ csetm x12, cc+ subs x7, x8, x16+ cneg x7, x7, cc+ cinv x12, x12, cc+ cmn x14, #0x1+ eor x26, x26, x14+ adcs x11, x25, x11+ mul x25, x23, x7+ adcs x26, x6, x26+ adcs x6, x22, x14+ adcs x24, x15, x14+ umulh x23, x23, x7+ adcs x4, x4, x14+ adc x22, x19, x14+ eor x14, x25, x12+ eor x7, x23, x12+ cmn x12, #0x1+ adcs x14, x26, x14+ ldp x19, x25, [x2]+ ldp x15, x23, [x2, #16]+ adcs x26, x6, x7+ adcs x24, x24, x12+ adcs x7, x4, x12+ adc x4, x22, x12+ subs x19, x19, x16+ ldp x16, x22, [x1]+ sbcs x6, x25, x5+ ldp x12, x25, [x1, #16]+ sbcs x15, x15, x20+ sbcs x8, x23, x8+ csetm x23, cc+ subs x21, x21, x16+ eor x16, x19, x23+ sbcs x19, x10, x22+ eor x22, x6, x23+ eor x8, x8, x23+ sbcs x6, x17, x12+ sbcs x13, x13, x25+ csetm x12, cc+ subs x10, x10, x17+ cneg x17, x10, cc+ csetm x25, cc+ subs x5, x20, x5+ eor x10, x19, x12+ cneg x19, x5, cc+ eor x20, x15, x23+ eor x21, x21, x12+ cinv x15, x25, cc+ mul x25, x17, x19+ subs x16, x16, x23+ sbcs x5, x22, x23+ eor x6, x6, x12+ sbcs x20, x20, x23+ eor x22, x13, x12+ sbc x8, x8, x23+ subs x21, x21, x12+ umulh x19, x17, x19+ sbcs x10, x10, x12+ sbcs x17, x6, x12+ eor x6, x19, x15+ eor x19, x25, x15+ umulh x25, x17, x20+ sbc x13, x22, x12+ cmn x15, #0x1+ adcs x22, x14, x19+ adcs x19, x26, x6+ ldp x6, x26, [sp]+ adcs x14, x24, x15+ umulh x24, x21, x16+ adcs x7, x7, x15+ adc x15, x4, x15+ adds x4, x9, x6+ eor x9, x23, x12+ adcs x12, x3, x26+ stp x4, x12, [sp]+ ldp x4, x26, [sp, #16]+ umulh x12, x10, x5+ ldp x6, x23, [sp, #32]+ adcs x3, x11, x4+ mul x4, x13, x8+ adcs x26, x22, x26+ ldp x22, x11, [sp, #48]+ adcs x6, x19, x6+ stp x3, x26, [sp, #16]+ mul x26, x10, x5+ adcs x14, x14, x23+ stp x6, x14, [sp, #32]+ ldr x6, [sp, #64]+ adcs x22, x7, x22+ adcs x14, x15, x11+ mul x11, x17, x20+ adc x19, x6, xzr+ stp x22, x14, [sp, #48]+ adds x14, x26, x24+ str x19, [sp, #64]+ umulh x19, x13, x8+ adcs x7, x11, x12+ adcs x22, x4, x25+ mul x6, x21, x16+ adc x19, x19, xzr+ subs x11, x17, x13+ cneg x12, x11, cc+ csetm x11, cc+ subs x24, x8, x20+ cinv x11, x11, cc+ cneg x24, x24, cc+ adds x4, x14, x6+ adcs x14, x7, x14+ mul x3, x12, x24+ adcs x7, x22, x7+ adcs x22, x19, x22+ umulh x12, x12, x24+ adc x24, xzr, x19+ adds x19, x14, x6+ eor x3, x3, x11+ adcs x26, x7, x4+ adcs x14, x22, x14+ adcs x25, x24, x7+ adcs x23, xzr, x22+ eor x7, x12, x11+ adc x12, xzr, x24+ subs x22, x21, x10+ cneg x24, x22, cc+ csetm x22, cc+ subs x15, x5, x16+ cinv x22, x22, cc+ cneg x15, x15, cc+ cmn x11, #0x1+ adcs x3, x25, x3+ mul x25, x24, x15+ adcs x23, x23, x7+ adc x11, x12, x11+ subs x7, x10, x13+ umulh x15, x24, x15+ cneg x12, x7, cc+ csetm x7, cc+ eor x24, x25, x22+ eor x25, x15, x22+ cmn x22, #0x1+ adcs x24, x4, x24+ adcs x19, x19, x25+ adcs x15, x26, x22+ adcs x4, x14, x22+ adcs x26, x3, x22+ adcs x25, x23, x22+ adc x23, x11, x22+ subs x14, x21, x17+ cneg x3, x14, cc+ csetm x11, cc+ subs x14, x8, x5+ cneg x14, x14, cc+ cinv x7, x7, cc+ subs x13, x21, x13+ cneg x21, x13, cc+ csetm x13, cc+ mul x22, x12, x14+ subs x8, x8, x16+ cinv x13, x13, cc+ umulh x14, x12, x14+ cneg x12, x8, cc+ subs x8, x20, x16+ cneg x8, x8, cc+ cinv x16, x11, cc+ eor x22, x22, x7+ cmn x7, #0x1+ eor x14, x14, x7+ adcs x4, x4, x22+ mul x11, x3, x8+ adcs x22, x26, x14+ adcs x14, x25, x7+ eor x25, x24, x9+ adc x26, x23, x7+ umulh x7, x3, x8+ subs x17, x10, x17+ cneg x24, x17, cc+ eor x3, x11, x16+ csetm x11, cc+ subs x20, x20, x5+ cneg x5, x20, cc+ cinv x11, x11, cc+ cmn x16, #0x1+ mul x17, x21, x12+ eor x8, x7, x16+ adcs x10, x19, x3+ and x19, x9, #0x1ff+ adcs x20, x15, x8+ umulh x15, x21, x12+ eor x12, x10, x9+ eor x8, x6, x9+ adcs x6, x4, x16+ adcs x4, x22, x16+ adcs x21, x14, x16+ adc x7, x26, x16+ mul x10, x24, x5+ cmn x13, #0x1+ ldp x3, x14, [x1]+ eor x17, x17, x13+ umulh x5, x24, x5+ adcs x20, x20, x17+ eor x17, x15, x13+ adcs x16, x6, x17+ eor x22, x10, x11+ adcs x23, x4, x13+ extr x10, x14, x3, #52+ and x26, x3, #0xfffffffffffff+ adcs x24, x21, x13+ and x15, x10, #0xfffffffffffff+ adc x6, x7, x13+ cmn x11, #0x1+ adcs x17, x20, x22+ eor x4, x5, x11+ ldp x21, x10, [sp]+ adcs x7, x16, x4+ eor x16, x17, x9+ eor x13, x7, x9+ ldp x3, x17, [sp, #16]+ adcs x7, x23, x11+ eor x23, x7, x9+ ldp x5, x22, [sp, #32]+ adcs x7, x24, x11+ adc x24, x6, x11+ ldr x6, [x2, #64]+ adds x20, x8, x21+ lsl x11, x20, #9+ eor x4, x7, x9+ orr x7, x11, x19+ eor x8, x24, x9+ adcs x11, x25, x10+ mul x26, x6, x26+ ldp x19, x24, [sp, #48]+ adcs x12, x12, x3+ adcs x16, x16, x17+ adcs x9, x13, x5+ ldr x25, [sp, #64]+ extr x20, x11, x20, #55+ adcs x13, x23, x22+ adcs x4, x4, x19+ extr x23, x12, x11, #55+ adcs x8, x8, x24+ adc x11, x25, xzr+ adds x21, x9, x21+ extr x9, x16, x12, #55+ lsr x12, x16, #55+ adcs x10, x13, x10+ mul x15, x6, x15+ adcs x13, x4, x3+ ldp x16, x4, [x2]+ ldr x3, [x1, #64]+ adcs x17, x8, x17+ adcs x5, x5, x7+ adcs x20, x22, x20+ adcs x8, x19, x23+ and x22, x16, #0xfffffffffffff+ ldp x19, x7, [x1, #16]+ adcs x9, x24, x9+ extr x24, x4, x16, #52+ adc x16, x12, x25+ mul x22, x3, x22+ and x25, x24, #0xfffffffffffff+ extr x14, x19, x14, #40+ and x12, x14, #0xfffffffffffff+ extr x23, x7, x19, #28+ ldp x19, x24, [x2, #16]+ mul x14, x3, x25+ and x23, x23, #0xfffffffffffff+ add x22, x26, x22+ lsl x11, x11, #48+ lsr x26, x22, #52+ lsl x25, x22, #12+ mul x22, x6, x12+ extr x12, x19, x4, #40+ add x4, x15, x14+ mul x15, x6, x23+ add x4, x4, x26+ extr x23, x24, x19, #28+ ldp x14, x19, [x1, #32]+ and x26, x12, #0xfffffffffffff+ extr x12, x4, x25, #12+ and x25, x23, #0xfffffffffffff+ adds x21, x21, x12+ mul x12, x3, x26+ extr x23, x14, x7, #16+ and x23, x23, #0xfffffffffffff+ mul x7, x3, x25+ ldp x25, x26, [x2, #32]+ add x12, x22, x12+ extr x22, x19, x14, #56+ mul x23, x6, x23+ lsr x14, x14, #4+ extr x24, x25, x24, #16+ add x7, x15, x7+ and x15, x24, #0xfffffffffffff+ and x22, x22, #0xfffffffffffff+ lsr x24, x4, #52+ mul x15, x3, x15+ and x14, x14, #0xfffffffffffff+ add x12, x12, x24+ lsl x24, x4, #12+ lsr x4, x12, #52+ extr x24, x12, x24, #24+ adcs x10, x10, x24+ lsl x24, x12, #12+ add x12, x7, x4+ mul x22, x6, x22+ add x4, x23, x15+ extr x7, x12, x24, #36+ adcs x13, x13, x7+ lsl x15, x12, #12+ add x7, x4, x11+ lsr x24, x12, #52+ ldp x23, x11, [x2, #48]+ add x4, x7, x24+ mul x12, x6, x14+ extr x7, x26, x25, #56+ extr x14, x4, x15, #48+ and x2, x7, #0xfffffffffffff+ extr x24, x11, x23, #32+ ldp x15, x7, [x1, #48]+ and x1, x24, #0xfffffffffffff+ lsr x24, x4, #52+ mul x2, x3, x2+ extr x26, x23, x26, #44+ lsr x23, x25, #4+ and x23, x23, #0xfffffffffffff+ and x25, x26, #0xfffffffffffff+ extr x26, x7, x15, #32+ extr x19, x15, x19, #44+ mul x23, x3, x23+ and x15, x26, #0xfffffffffffff+ lsl x26, x4, #12+ and x4, x19, #0xfffffffffffff+ lsr x11, x11, #20+ mul x19, x6, x4+ adcs x17, x17, x14+ add x14, x22, x2+ add x22, x12, x23+ lsr x7, x7, #20+ add x22, x22, x24+ extr x2, x22, x26, #60+ mul x24, x3, x25+ lsr x22, x22, #52+ add x14, x14, x22+ lsl x22, x2, #8+ extr x22, x14, x22, #8+ lsl x2, x14, #12+ mul x1, x3, x1+ adcs x12, x5, x22+ mul x5, x6, x15+ and x26, x10, x13+ and x4, x26, x17+ add x23, x19, x24+ lsr x14, x14, #52+ mul x22, x3, x11+ add x11, x23, x14+ extr x25, x11, x2, #20+ lsl x19, x11, #12+ adcs x25, x20, x25+ and x14, x4, x12+ add x1, x5, x1+ and x14, x14, x25+ mul x15, x6, x7+ add x26, x15, x22+ mul x6, x6, x3+ lsr x22, x11, #52+ add x4, x1, x22+ lsr x1, x4, #52+ extr x3, x4, x19, #32+ lsl x15, x4, #12+ add x7, x26, x1+ adcs x23, x8, x3+ extr x20, x7, x15, #44+ and x3, x14, x23+ lsr x19, x7, #44+ adcs x7, x9, x20+ add x11, x6, x19+ adc x4, x16, x11+ lsr x14, x4, #9+ cmp xzr, xzr+ and x15, x3, x7+ orr x3, x4, #0xfffffffffffffe00+ adcs xzr, x21, x14+ adcs xzr, x15, xzr+ adcs xzr, x3, xzr+ adcs x11, x21, x14+ and x14, x11, #0x1ff+ adcs x1, x10, xzr+ extr x10, x1, x11, #9+ str x14, [x0, #64]+ adcs x14, x13, xzr+ extr x11, x14, x1, #9+ adcs x1, x17, xzr+ extr x4, x1, x14, #9+ stp x10, x11, [x0]+ adcs x11, x12, xzr+ extr x14, x11, x1, #9+ adcs x10, x25, xzr+ extr x11, x10, x11, #9+ stp x4, x14, [x0, #16]+ adcs x14, x23, xzr+ extr x10, x14, x10, #9+ adcs x1, x7, xzr+ stp x11, x10, [x0, #32]+ extr x14, x1, x14, #9+ adc x10, x3, xzr+ extr x26, x10, x1, #9+ stp x14, x26, [x0, #48]+ CFI_INC_SP(80)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_mul_p521)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_sqr_p521)++Lp521_jscalarmul_sqr_p521:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ ldr q23, [x1, #32]+ ldp x9, x2, [x1, #32]+ ldr q16, [x1, #32]+ ldr q20, [x1, #48]+ ldp x6, x13, [x1, #48]+ rev64 v2.4S, v23.4S+ mul x14, x9, x2+ ldr q31, [x1, #48]+ subs x22, x9, x2+ uzp2 v26.4S, v23.4S, v23.4S+ mul v30.4S, v2.4S, v16.4S+ xtn v0.2S, v20.2D+ csetm x12, cc+ xtn v21.2S, v16.2D+ xtn v23.2S, v23.2D+ umulh x10, x9, x6+ rev64 v27.4S, v31.4S+ umull v2.2D, v21.2S, v26.2S+ cneg x23, x22, cc+ uaddlp v25.2D, v30.4S+ umull v18.2D, v21.2S, v23.2S+ mul x22, x9, x6+ mul v6.4S, v27.4S, v20.4S+ uzp2 v17.4S, v20.4S, v20.4S+ shl v20.2D, v25.2D, #32+ uzp2 v27.4S, v31.4S, v31.4S+ mul x16, x2, x13+ umlal v20.2D, v21.2S, v23.2S+ usra v2.2D, v18.2D, #32+ adds x8, x22, x10+ umull v25.2D, v17.2S, v27.2S+ xtn v31.2S, v31.2D+ movi v1.2D, #0xffffffff+ adc x3, x10, xzr+ umulh x21, x2, x13+ uzp2 v21.4S, v16.4S, v16.4S+ umull v18.2D, v0.2S, v27.2S+ subs x19, x13, x6+ and v7.16B, v2.16B, v1.16B+ umull v27.2D, v0.2S, v31.2S+ cneg x20, x19, cc+ movi v30.2D, #0xffffffff+ umull v16.2D, v21.2S, v26.2S+ umlal v7.2D, v21.2S, v23.2S+ mul x19, x23, x20+ cinv x7, x12, cc+ uaddlp v6.2D, v6.4S+ eor x12, x19, x7+ adds x11, x8, x16+ umulh x10, x23, x20+ ldr q1, [x1]+ usra v16.2D, v2.2D, #32+ adcs x19, x3, x21+ shl v2.2D, v6.2D, #32+ adc x20, x21, xzr+ adds x17, x19, x16+ usra v18.2D, v27.2D, #32+ adc x19, x20, xzr+ cmn x7, #0x1+ umlal v2.2D, v0.2S, v31.2S+ umulh x16, x9, x2+ adcs x8, x11, x12+ usra v16.2D, v7.2D, #32+ ldr x12, [x1, #64]+ eor x20, x10, x7+ umulh x10, x6, x13+ mov x23, v2.d[0]+ mov x3, v2.d[1]+ adcs x21, x17, x20+ usra v25.2D, v18.2D, #32+ and v23.16B, v18.16B, v30.16B+ adc x7, x19, x7+ adds x22, x22, x22+ ldr q7, [x1, #16]+ adcs x17, x8, x8+ umlal v23.2D, v17.2S, v31.2S+ mov x19, v16.d[0]+ mul x11, x12, x12+ ldr q4, [x1]+ usra v25.2D, v23.2D, #32+ add x5, x12, x12+ adcs x15, x21, x21+ ldr q28, [x1]+ mov x12, v20.d[1]+ adcs x24, x7, x7+ mov x21, v16.d[1]+ adc x4, xzr, xzr+ adds x19, x19, x14+ ldr q18, [x1, #16]+ xtn v26.2S, v1.2D+ adcs x8, x12, x16+ adc x21, x21, xzr+ adds x7, x19, x14+ xtn v23.2S, v7.2D+ rev64 v21.4S, v28.4S+ adcs x12, x8, x16+ ldp x20, x19, [x1]+ mov x16, v25.d[1]+ xtn v22.2S, v28.2D+ adc x14, x21, xzr+ adds x8, x22, x12+ uzp2 v24.4S, v28.4S, v28.4S+ rev64 v28.4S, v18.4S+ mul x12, x6, x13+ mul v16.4S, v21.4S, v1.4S+ shrn v31.2S, v7.2D, #32+ adcs x22, x17, x14+ mov x14, v25.d[0]+ and x21, x20, #0xfffffffffffff+ umull v17.2D, v26.2S, v24.2S+ ldr q2, [x1, #32]+ adcs x17, x15, xzr+ ldr q30, [x1, #48]+ umull v7.2D, v26.2S, v22.2S+ adcs x15, x24, xzr+ ldr q0, [x1, #16]+ movi v6.2D, #0xffffffff+ adc x4, x4, xzr+ adds x14, x14, x12+ uzp1 v27.4S, v18.4S, v4.4S+ uzp2 v19.4S, v1.4S, v1.4S+ adcs x24, x3, x10+ mul x3, x5, x21+ umull v29.2D, v23.2S, v31.2S+ ldr q5, [x1]+ adc x21, x16, xzr+ adds x16, x14, x12+ extr x12, x19, x20, #52+ umull v18.2D, v19.2S, v24.2S+ adcs x24, x24, x10+ and x10, x12, #0xfffffffffffff+ ldp x14, x12, [x1, #16]+ usra v17.2D, v7.2D, #32+ adc x21, x21, xzr+ adds x23, x23, x17+ mul x17, x5, x10+ shl v21.2D, v29.2D, #33+ lsl x10, x3, #12+ lsr x1, x3, #52+ rev64 v29.4S, v2.4S+ uaddlp v25.2D, v16.4S+ add x17, x17, x1+ adcs x16, x16, x15+ extr x3, x14, x19, #40+ mov x15, v20.d[0]+ extr x10, x17, x10, #12+ and x3, x3, #0xfffffffffffff+ shl v3.2D, v25.2D, #32+ and v6.16B, v17.16B, v6.16B+ mul x1, x5, x3+ usra v18.2D, v17.2D, #32+ adcs x3, x24, x4+ extr x4, x12, x14, #28+ umlal v6.2D, v19.2S, v22.2S+ xtn v20.2S, v2.2D+ umlal v3.2D, v26.2S, v22.2S+ movi v26.2D, #0xffffffff+ lsr x24, x17, #52+ and x4, x4, #0xfffffffffffff+ uzp2 v19.4S, v2.4S, v2.4S+ add x1, x1, x24+ mul x24, x5, x4+ lsl x4, x17, #12+ xtn v24.2S, v5.2D+ extr x17, x1, x4, #24+ adc x21, x21, xzr+ umlal v21.2D, v23.2S, v23.2S+ adds x4, x15, x10+ lsl x10, x1, #12+ adcs x15, x7, x17+ mul v23.4S, v28.4S, v4.4S+ and x7, x4, #0x1ff+ lsr x17, x1, #52+ umulh x1, x19, x12+ uzp2 v17.4S, v5.4S, v5.4S+ extr x4, x15, x4, #9+ add x24, x24, x17+ mul v29.4S, v29.4S, v5.4S+ extr x17, x24, x10, #36+ extr x10, x9, x12, #16+ uzp1 v28.4S, v4.4S, v4.4S+ adcs x17, x8, x17+ and x8, x10, #0xfffffffffffff+ umull v16.2D, v24.2S, v20.2S+ extr x10, x17, x15, #9+ mul x15, x5, x8+ stp x4, x10, [x0]+ lsl x4, x24, #12+ lsr x8, x9, #4+ uaddlp v4.2D, v23.4S+ and x8, x8, #0xfffffffffffff+ umull v23.2D, v24.2S, v19.2S+ mul x8, x5, x8+ extr x10, x2, x9, #56+ lsr x24, x24, #52+ and x10, x10, #0xfffffffffffff+ add x15, x15, x24+ extr x4, x15, x4, #48+ mul x24, x5, x10+ lsr x10, x15, #52+ usra v23.2D, v16.2D, #32+ add x10, x8, x10+ shl v4.2D, v4.2D, #32+ adcs x22, x22, x4+ extr x4, x6, x2, #44+ lsl x15, x15, #12+ lsr x8, x10, #52+ extr x15, x10, x15, #60+ and x10, x4, #0xfffffffffffff+ umlal v4.2D, v28.2S, v27.2S+ add x8, x24, x8+ extr x4, x13, x6, #32+ mul x24, x5, x10+ uzp2 v16.4S, v30.4S, v30.4S+ lsl x10, x15, #8+ rev64 v28.4S, v30.4S+ and x15, x4, #0xfffffffffffff+ extr x4, x8, x10, #8+ mul x10, x5, x15+ lsl x15, x8, #12+ adcs x23, x23, x4+ lsr x4, x8, #52+ lsr x8, x13, #20+ add x4, x24, x4+ mul x8, x5, x8+ lsr x24, x4, #52+ extr x15, x4, x15, #20+ lsl x4, x4, #12+ add x10, x10, x24+ adcs x15, x16, x15+ extr x4, x10, x4, #32+ umulh x5, x20, x14+ adcs x3, x3, x4+ usra v18.2D, v6.2D, #32+ lsl x16, x10, #12+ extr x24, x15, x23, #9+ lsr x10, x10, #52+ uzp2 v27.4S, v0.4S, v0.4S+ add x8, x8, x10+ extr x10, x3, x15, #9+ extr x4, x22, x17, #9+ and v25.16B, v23.16B, v26.16B+ lsr x17, x8, #44+ extr x15, x8, x16, #44+ extr x16, x23, x22, #9+ xtn v7.2S, v30.2D+ mov x8, v4.d[0]+ stp x24, x10, [x0, #32]+ uaddlp v30.2D, v29.4S+ stp x4, x16, [x0, #16]+ umulh x24, x20, x19+ adcs x15, x21, x15+ adc x16, x11, x17+ subs x11, x20, x19+ xtn v5.2S, v0.2D+ csetm x17, cc+ extr x3, x15, x3, #9+ mov x22, v4.d[1]+ cneg x21, x11, cc+ subs x10, x12, x14+ mul v31.4S, v28.4S, v0.4S+ cneg x10, x10, cc+ cinv x11, x17, cc+ shl v4.2D, v30.2D, #32+ umull v28.2D, v5.2S, v16.2S+ extr x23, x16, x15, #9+ adds x4, x8, x5+ mul x17, x21, x10+ umull v22.2D, v5.2S, v7.2S+ adc x15, x5, xzr+ adds x4, x4, x22+ uaddlp v2.2D, v31.4S+ lsr x5, x16, #9+ adcs x16, x15, x1+ mov x15, v18.d[0]+ adc x1, x1, xzr+ umulh x10, x21, x10+ adds x22, x16, x22+ umlal v4.2D, v24.2S, v20.2S+ umull v30.2D, v27.2S, v16.2S+ stp x3, x23, [x0, #48]+ add x3, x7, x5+ adc x16, x1, xzr+ usra v28.2D, v22.2D, #32+ mul x23, x20, x19+ eor x1, x17, x11+ cmn x11, #0x1+ mov x17, v18.d[1]+ umull v18.2D, v17.2S, v19.2S+ adcs x7, x4, x1+ eor x1, x10, x11+ umlal v25.2D, v17.2S, v20.2S+ movi v16.2D, #0xffffffff+ adcs x22, x22, x1+ usra v18.2D, v23.2D, #32+ umulh x4, x14, x14+ adc x1, x16, x11+ adds x10, x8, x8+ shl v23.2D, v2.2D, #32+ str x3, [x0, #64]+ adcs x5, x7, x7+ and v16.16B, v28.16B, v16.16B+ usra v30.2D, v28.2D, #32+ adcs x7, x22, x22+ mov x21, v3.d[1]+ adcs x11, x1, x1+ umlal v16.2D, v27.2S, v7.2S+ adc x22, xzr, xzr+ adds x16, x15, x23+ mul x8, x14, x12+ umlal v23.2D, v5.2S, v7.2S+ usra v18.2D, v25.2D, #32+ umulh x15, x14, x12+ adcs x21, x21, x24+ usra v30.2D, v16.2D, #32+ adc x1, x17, xzr+ adds x3, x16, x23+ adcs x21, x21, x24+ adc x1, x1, xzr+ adds x24, x10, x21+ umulh x21, x12, x12+ adcs x16, x5, x1+ adcs x10, x7, xzr+ mov x17, v21.d[1]+ adcs x23, x11, xzr+ adc x5, x22, xzr+ adds x1, x4, x8+ adcs x22, x17, x15+ ldp x17, x4, [x0]+ mov x11, v21.d[0]+ adc x21, x21, xzr+ adds x1, x1, x8+ adcs x15, x22, x15+ adc x8, x21, xzr+ adds x22, x11, x10+ mov x21, v3.d[0]+ adcs x11, x1, x23+ ldp x1, x10, [x0, #16]+ adcs x15, x15, x5+ adc x7, x8, xzr+ adds x8, x17, x21+ mov x23, v4.d[1]+ ldp x5, x21, [x0, #32]+ adcs x17, x4, x3+ ldr x4, [x0, #64]+ mov x3, v18.d[0]+ adcs x24, x1, x24+ stp x8, x17, [x0]+ adcs x17, x10, x16+ ldp x1, x16, [x0, #48]+ adcs x5, x5, x22+ adcs x8, x21, x11+ stp x5, x8, [x0, #32]+ adcs x1, x1, x15+ mov x15, v23.d[1]+ adcs x21, x16, x7+ stp x1, x21, [x0, #48]+ adc x10, x4, xzr+ subs x7, x14, x12+ mov x16, v18.d[1]+ cneg x5, x7, cc+ csetm x4, cc+ subs x11, x13, x6+ mov x8, v23.d[0]+ cneg x7, x11, cc+ cinv x21, x4, cc+ mov x11, v30.d[0]+ adds x4, x23, x3+ mul x22, x5, x7+ mov x23, v30.d[1]+ adcs x8, x8, x16+ adcs x16, x15, x11+ adc x11, x23, xzr+ umulh x3, x5, x7+ stp x24, x17, [x0, #16]+ mov x5, v4.d[0]+ subs x15, x20, x19+ cneg x7, x15, cc+ str x10, [x0, #64]+ csetm x1, cc+ subs x24, x2, x9+ cneg x17, x24, cc+ cinv x15, x1, cc+ adds x23, x4, x5+ umulh x1, x7, x17+ adcs x24, x8, x4+ adcs x10, x16, x8+ eor x8, x22, x21+ adcs x16, x11, x16+ mul x22, x7, x17+ eor x17, x1, x15+ adc x1, xzr, x11+ adds x11, x24, x5+ eor x7, x3, x21+ adcs x3, x10, x23+ adcs x24, x16, x24+ adcs x4, x1, x10+ eor x10, x22, x15+ adcs x16, xzr, x16+ adc x1, xzr, x1+ cmn x21, #0x1+ adcs x8, x4, x8+ adcs x22, x16, x7+ adc x7, x1, x21+ subs x21, x19, x12+ csetm x4, cc+ cneg x1, x21, cc+ subs x21, x13, x2+ cinv x16, x4, cc+ cneg x4, x21, cc+ cmn x15, #0x1+ adcs x21, x23, x10+ mul x23, x1, x4+ adcs x11, x11, x17+ adcs x3, x3, x15+ umulh x1, x1, x4+ adcs x24, x24, x15+ adcs x8, x8, x15+ adcs x22, x22, x15+ eor x17, x23, x16+ adc x15, x7, x15+ subs x7, x20, x14+ cneg x7, x7, cc+ csetm x4, cc+ subs x10, x20, x12+ cneg x23, x10, cc+ csetm x10, cc+ subs x12, x6, x9+ cinv x20, x4, cc+ cneg x12, x12, cc+ cmn x16, #0x1+ eor x1, x1, x16+ adcs x17, x24, x17+ mul x4, x7, x12+ adcs x8, x8, x1+ umulh x1, x7, x12+ adcs x24, x22, x16+ adc x7, x15, x16+ subs x12, x13, x9+ cneg x12, x12, cc+ cinv x13, x10, cc+ subs x19, x19, x14+ mul x9, x23, x12+ cneg x19, x19, cc+ csetm x10, cc+ eor x16, x1, x20+ subs x22, x6, x2+ umulh x12, x23, x12+ eor x1, x4, x20+ cinv x4, x10, cc+ cneg x22, x22, cc+ cmn x20, #0x1+ adcs x15, x11, x1+ eor x6, x12, x13+ adcs x10, x3, x16+ adcs x17, x17, x20+ eor x23, x9, x13+ adcs x2, x8, x20+ mul x11, x19, x22+ adcs x24, x24, x20+ adc x7, x7, x20+ cmn x13, #0x1+ adcs x3, x10, x23+ umulh x22, x19, x22+ adcs x17, x17, x6+ eor x12, x22, x4+ extr x22, x15, x21, #63+ adcs x8, x2, x13+ extr x21, x21, x5, #63+ ldp x16, x23, [x0]+ adcs x20, x24, x13+ eor x1, x11, x4+ adc x6, x7, x13+ cmn x4, #0x1+ ldp x2, x7, [x0, #16]+ adcs x1, x3, x1+ extr x19, x1, x15, #63+ adcs x14, x17, x12+ extr x1, x14, x1, #63+ lsl x17, x5, #1+ adcs x8, x8, x4+ extr x12, x8, x14, #8+ ldp x15, x11, [x0, #32]+ adcs x9, x20, x4+ adc x3, x6, x4+ adds x16, x12, x16+ extr x6, x9, x8, #8+ ldp x14, x12, [x0, #48]+ extr x8, x3, x9, #8+ adcs x20, x6, x23+ ldr x24, [x0, #64]+ lsr x6, x3, #8+ adcs x8, x8, x2+ and x2, x1, #0x1ff+ and x1, x20, x8+ adcs x4, x6, x7+ adcs x3, x17, x15+ and x1, x1, x4+ adcs x9, x21, x11+ and x1, x1, x3+ adcs x6, x22, x14+ and x1, x1, x9+ and x21, x1, x6+ adcs x14, x19, x12+ adc x1, x24, x2+ cmp xzr, xzr+ orr x12, x1, #0xfffffffffffffe00+ lsr x1, x1, #9+ adcs xzr, x16, x1+ and x21, x21, x14+ adcs xzr, x21, xzr+ adcs xzr, x12, xzr+ adcs x21, x16, x1+ adcs x1, x20, xzr+ adcs x19, x8, xzr+ stp x21, x1, [x0]+ adcs x1, x4, xzr+ adcs x21, x3, xzr+ stp x19, x1, [x0, #16]+ adcs x1, x9, xzr+ stp x21, x1, [x0, #32]+ adcs x21, x6, xzr+ adcs x1, x14, xzr+ stp x21, x1, [x0, #48]+ adc x1, x12, xzr+ and x1, x1, #0x1ff+ str x1, [x0, #64]+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_sqr_p521)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_sub_p521)++Lp521_jscalarmul_sub_p521:+ CFI_START+ ldp x5, x6, [x1]+ ldp x4, x3, [x2]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [x2, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x1, #32]+ ldp x4, x3, [x2, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [x1, #48]+ ldp x4, x3, [x2, #48]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [x1, #64]+ ldr x4, [x2, #64]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [x0]+ stp x7, x8, [x0, #16]+ stp x9, x10, [x0, #32]+ stp x11, x12, [x0, #48]+ str x13, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_sub_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/arm/p521_jscalarmul_alt.S view
@@ -0,0 +1,2143 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Jacobian form scalar multiplication for P-521+// Input scalar[9], point[27]; output res[27]+//+// extern void p521_jscalarmul_alt+// (uint64_t res[static 27],+// const uint64_t scalar[static 9],+// const uint64_t point[static 27]);+//+// This function is a variant of its affine point version p521_scalarmul.+// Here, input and output points are assumed to be in Jacobian form with+// a triple (x,y,z) representing the affine point (x/z^2,y/z^3) when+// z is nonzero or the point at infinity (group identity) if z = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-521, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_521) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard ARM ABI: X0 = res, X1 = scalar, X2 = point+// ----------------------------------------------------------------------------+++#include "_internal_s2n_bignum_arm.h"++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p521_jscalarmul_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p521_jscalarmul_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p521_jscalarmul_alt)+++ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 72+#define JACSIZE (3*NUMSIZE)++// Safe copies of input res and additional values in variables.++#define tabup x15+#define bf x16+#define sgn x17+#define j x19+#define res x20++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE++#define scalarb sp, #(0*NUMSIZE)+#define acc sp, #(1*NUMSIZE)+#define tabent sp, #(4*NUMSIZE)++#define tab sp, #(7*NUMSIZE)++// Round up to maintain stack alignment++#define NSPACE 3968++#define selectblock(I) \+ cmp bf, #(1*I) __LF \+ ldp x10, x11, [tabup] __LF \+ csel x0, x10, x0, eq __LF \+ csel x1, x11, x1, eq __LF \+ ldp x10, x11, [tabup, #16] __LF \+ csel x2, x10, x2, eq __LF \+ csel x3, x11, x3, eq __LF \+ ldp x10, x11, [tabup, #32] __LF \+ csel x4, x10, x4, eq __LF \+ csel x5, x11, x5, eq __LF \+ ldp x10, x11, [tabup, #48] __LF \+ csel x6, x10, x6, eq __LF \+ csel x7, x11, x7, eq __LF \+ ldr x10, [tabup, #64] __LF \+ csel x8, x10, x8, eq __LF \+ add tabup, tabup, #JACSIZE++// Loading large constants++#define movbig(nn,n3,n2,n1,n0) \+ movz nn, n0 __LF \+ movk nn, n1, lsl #16 __LF \+ movk nn, n2, lsl #32 __LF \+ movk nn, n3, lsl #48++S2N_BN_SYMBOL(p521_jscalarmul_alt):+ CFI_START++ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x30)+ CFI_DEC_SP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ mov res, x0++// Reduce the input scalar mod n_521 and store it to "scalarb".++ mov x19, x2+ add x0, scalarb+ CFI_BL(Lp521_jscalarmul_alt_bignum_mod_n521_9)+ mov x2, x19++// Set the tab[0] table entry to the input point = 1 * P, but also+// reduce all coordinates modulo p. In principle we assume reduction+// as a precondition, but this reduces the scope for surprise, e.g.+// making sure that any input with z = 0 is treated as zero, even+// if the other coordinates are not in fact reduced.++ add x0, tab+ mov x1, x19+ CFI_BL(Lp521_jscalarmul_alt_bignum_mod_p521_9)++ add x0, tab+NUMSIZE+ add x1, x19, #NUMSIZE+ CFI_BL(Lp521_jscalarmul_alt_bignum_mod_p521_9)++ add x0, tab+2*NUMSIZE+ add x1, x19, #(2*NUMSIZE)+ CFI_BL(Lp521_jscalarmul_alt_bignum_mod_p521_9)++// If bit 520 of the scalar is set, then negate the scalar mod n_521,+// i.e. do scalar |-> n_521 - scalar, and also the point to compensate+// by negating its y coordinate. This further step is not needed by+// the indexing scheme (the top window is only a couple of bits either+// way), but is convenient to exclude a problem with the specific value+// scalar = n_521 - 18, where the last Jacobian addition is of the form+// (n_521 - 9) * P + -(9 * P) and hence is a degenerate doubling case.++ ldp x0, x1, [scalarb]+ movbig(x10, #0xbb6f, #0xb71e, #0x9138, #0x6409)+ subs x10, x10, x0+ movbig(x11, #0x3bb5, #0xc9b8, #0x899c, #0x47ae)+ sbcs x11, x11, x1+ ldp x2, x3, [scalarb+16]+ movbig(x12, #0x7fcc, #0x0148, #0xf709, #0xa5d0)+ sbcs x12, x12, x2+ movbig(x13, #0x5186, #0x8783, #0xbf2f, #0x966b)+ sbcs x13, x13, x3+ ldp x4, x5, [scalarb+32]+ mov x14, 0xfffffffffffffffa+ sbcs x14, x14, x4+ mov x15, 0xffffffffffffffff+ sbcs x15, x15, x5+ ldp x6, x7, [scalarb+48]+ mov x16, 0xffffffffffffffff+ sbcs x16, x16, x6+ mov x17, 0xffffffffffffffff+ sbcs x17, x17, x7+ ldr x8, [scalarb+64]+ mov x19, 0x00000000000001ff+ sbc x19, x19, x8+ tst x8, 0x100+ csetm x9, ne+ csel x0, x10, x0, ne+ csel x1, x11, x1, ne+ csel x2, x12, x2, ne+ csel x3, x13, x3, ne+ csel x4, x14, x4, ne+ csel x5, x15, x5, ne+ csel x6, x16, x6, ne+ csel x7, x17, x7, ne+ csel x8, x19, x8, ne+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]+ stp x6, x7, [scalarb+48]+ str x8, [scalarb+64]++ add tabup, tab+ ldp x0, x1, [tabup, #NUMSIZE]+ ldp x2, x3, [tabup, #NUMSIZE+16]+ ldp x4, x5, [tabup, #NUMSIZE+32]+ ldp x6, x7, [tabup, #NUMSIZE+48]+ ldr x8, [tabup, #NUMSIZE+64]+ orr x10, x0, x1+ orr x11, x2, x3+ orr x12, x4, x5+ orr x13, x6, x7+ orr x10, x10, x11+ orr x12, x12, x13+ orr x12, x12, x8+ orr x10, x10, x12+ cmp x10, xzr+ csel x9, x9, xzr, ne+ eor x0, x0, x9+ eor x1, x1, x9+ eor x2, x2, x9+ eor x3, x3, x9+ eor x4, x4, x9+ eor x5, x5, x9+ eor x6, x6, x9+ eor x7, x7, x9+ and x9, x9, #0x1FF+ eor x8, x8, x9+ stp x0, x1, [tabup, #NUMSIZE]+ stp x2, x3, [tabup, #NUMSIZE+16]+ stp x4, x5, [tabup, #NUMSIZE+32]+ stp x6, x7, [tabup, #NUMSIZE+48]+ str x8, [tabup, #NUMSIZE+64]++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ add x0, tab+JACSIZE*1+ add x1, tab+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, tab+JACSIZE*2+ add x1, tab+JACSIZE*1+ add x2, tab+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ add x0, tab+JACSIZE*3+ add x1, tab+JACSIZE*1+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, tab+JACSIZE*4+ add x1, tab+JACSIZE*3+ add x2, tab+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ add x0, tab+JACSIZE*5+ add x1, tab+JACSIZE*2+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, tab+JACSIZE*6+ add x1, tab+JACSIZE*5+ add x2, tab+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ add x0, tab+JACSIZE*7+ add x1, tab+JACSIZE*3+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, tab+JACSIZE*8+ add x1, tab+JACSIZE*7+ add x2, tab+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ add x0, tab+JACSIZE*9+ add x1, tab+JACSIZE*4+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, tab+JACSIZE*10+ add x1, tab+JACSIZE*9+ add x2, tab+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ add x0, tab+JACSIZE*11+ add x1, tab+JACSIZE*5+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, tab+JACSIZE*12+ add x1, tab+JACSIZE*11+ add x2, tab+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ add x0, tab+JACSIZE*13+ add x1, tab+JACSIZE*6+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, tab+JACSIZE*14+ add x1, tab+JACSIZE*13+ add x2, tab+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ add x0, tab+JACSIZE*15+ add x1, tab+JACSIZE*7+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically since none is a simple ARM load.+//+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x4210842108421084+// 0x8421084210842108+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x0000000000000084++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ ldp x6, x7, [scalarb+48]+ ldr x8, [scalarb+64]++ movbig(x10, #0x1084, #0x2108, #0x4210, #0x8421)+ adds x0, x0, x10, lsr #1+ adcs x1, x1, x10+ lsl x10, x10, #1+ adcs x2, x2, x10+ lsl x10, x10, #1+ adcs x3, x3, x10+ lsl x10, x10, #1+ adcs x4, x4, x10+ lsr x11, x10, #4+ adcs x5, x5, x11+ lsr x10, x10, #3+ adcs x6, x6, x10+ lsl x10, x10, #1+ adcs x7, x7, x10+ lsl x10, x10, #1+ and x10, x10, #0xFF+ adc x8, x8, x10++// Because of the initial reduction the top bitfield (>= bits 520) is <= 1,+// i.e. just a single bit. Record that in "bf", then shift the whole+// scalar left 56 bits to align the top of the next bitfield with the MSB+// (bits 571..575).++ lsr bf, x8, #8+ extr x8, x8, x7, #8+ extr x7, x7, x6, #8+ extr x6, x6, x5, #8+ extr x5, x5, x4, #8+ extr x4, x4, x3, #8+ extr x3, x3, x2, #8+ extr x2, x2, x1, #8+ extr x1, x1, x0, #8+ lsl x0, x0, #56+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]+ stp x6, x7, [scalarb+48]+ str x8, [scalarb+64]++// According to the top bit, initialize the accumulator to P or 0. This top+// digit, uniquely, is not recoded so there is no sign adjustment to make.+// We only really need to adjust the z coordinate to zero, but do all three.++ add tabup, tab+ cmp bf, xzr++ ldp x0, x1, [tabup]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc]+ ldp x0, x1, [tabup, #16]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+16]+ ldp x0, x1, [tabup, #32]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+32]+ ldp x0, x1, [tabup, #48]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+48]+ ldp x0, x1, [tabup, #64]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+64]+ ldp x0, x1, [tabup, #80]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+80]+ ldp x0, x1, [tabup, #96]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+96]+ ldp x0, x1, [tabup, #112]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+112]+ ldp x0, x1, [tabup, #128]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+128]+ ldp x0, x1, [tabup, #144]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+144]+ ldp x0, x1, [tabup, #160]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+160]+ ldp x0, x1, [tabup, #176]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+176]+ ldp x0, x1, [tabup, #192]+ csel x0, x0, xzr, ne+ csel x1, x1, xzr, ne+ stp x0, x1, [acc+192]+ ldr x0, [tabup, #208]+ csel x0, x0, xzr, ne+ str x0, [acc+208]++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++ mov j, #520++Lp521_jscalarmul_alt_mainloop:+ sub j, j, #5++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++ add x0, acc+ add x1, acc+ CFI_BL(Lp521_jscalarmul_alt_jdouble)++// Choose the bitfield and adjust it to sign and magnitude++ ldp x0, x1, [scalarb]+ ldp x2, x3, [scalarb+16]+ ldp x4, x5, [scalarb+32]+ ldp x6, x7, [scalarb+48]+ ldr x8, [scalarb+64]+ lsr bf, x8, #59+ extr x8, x8, x7, #59+ extr x7, x7, x6, #59+ extr x6, x6, x5, #59+ extr x5, x5, x4, #59+ extr x4, x4, x3, #59+ extr x3, x3, x2, #59+ extr x2, x2, x1, #59+ extr x1, x1, x0, #59+ lsl x0, x0, #5+ stp x0, x1, [scalarb]+ stp x2, x3, [scalarb+16]+ stp x4, x5, [scalarb+32]+ stp x6, x7, [scalarb+48]+ str x8, [scalarb+64]++ subs bf, bf, #16+ csetm sgn, lo // sgn = sign of digit (1 = negative)+ cneg bf, bf, lo // bf = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ add tabup, tab+ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)+ stp x0, x1, [tabent]+ stp x2, x3, [tabent+16]+ stp x4, x5, [tabent+32]+ stp x6, x7, [tabent+48]+ str x8, [tabent+64]++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ add tabup, tab+2*NUMSIZE+ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)+ stp x0, x1, [tabent+2*NUMSIZE]+ stp x2, x3, [tabent+2*NUMSIZE+16]+ stp x4, x5, [tabent+2*NUMSIZE+32]+ stp x6, x7, [tabent+2*NUMSIZE+48]+ str x8, [tabent+2*NUMSIZE+64]++ mov x0, xzr+ mov x1, xzr+ mov x2, xzr+ mov x3, xzr+ mov x4, xzr+ mov x5, xzr+ mov x6, xzr+ mov x7, xzr+ mov x8, xzr+ add tabup, tab+NUMSIZE+ selectblock(1)+ selectblock(2)+ selectblock(3)+ selectblock(4)+ selectblock(5)+ selectblock(6)+ selectblock(7)+ selectblock(8)+ selectblock(9)+ selectblock(10)+ selectblock(11)+ selectblock(12)+ selectblock(13)+ selectblock(14)+ selectblock(15)+ selectblock(16)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_521 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).++ orr x10, x0, x1+ orr x11, x2, x3+ orr x12, x4, x5+ orr x13, x6, x7+ orr x10, x10, x11+ orr x12, x12, x13+ orr x12, x12, x8+ orr x10, x10, x12+ cmp x10, xzr+ csel sgn, sgn, xzr, ne++ eor x0, x0, sgn+ eor x1, x1, sgn+ eor x2, x2, sgn+ eor x3, x3, sgn+ eor x4, x4, sgn+ eor x5, x5, sgn+ eor x6, x6, sgn+ eor x7, x7, sgn+ and sgn, sgn, #0x1FF+ eor x8, x8, sgn++ stp x0, x1, [tabent+NUMSIZE]+ stp x2, x3, [tabent+NUMSIZE+16]+ stp x4, x5, [tabent+NUMSIZE+32]+ stp x6, x7, [tabent+NUMSIZE+48]+ str x8, [tabent+NUMSIZE+64]++// Add to the accumulator++ add x0, acc+ add x1, acc+ add x2, tabent+ CFI_BL(Lp521_jscalarmul_alt_jadd)++ cbnz j, Lp521_jscalarmul_alt_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ ldp x0, x1, [acc]+ stp x0, x1, [res]+ ldp x0, x1, [acc+16]+ stp x0, x1, [res, #16]+ ldp x0, x1, [acc+32]+ stp x0, x1, [res, #32]+ ldp x0, x1, [acc+48]+ stp x0, x1, [res, #48]+ ldp x0, x1, [acc+64]+ stp x0, x1, [res, #64]+ ldp x0, x1, [acc+80]+ stp x0, x1, [res, #80]+ ldp x0, x1, [acc+96]+ stp x0, x1, [res, #96]+ ldp x0, x1, [acc+112]+ stp x0, x1, [res, #112]+ ldp x0, x1, [acc+128]+ stp x0, x1, [res, #128]+ ldp x0, x1, [acc+144]+ stp x0, x1, [res, #144]+ ldp x0, x1, [acc+160]+ stp x0, x1, [res, #160]+ ldp x0, x1, [acc+176]+ stp x0, x1, [res, #176]+ ldp x0, x1, [acc+192]+ stp x0, x1, [res, #192]+ ldr x0, [acc+208]+ str x0, [res, #208]++// Restore stack and registers and return++ CFI_INC_SP(NSPACE)+ CFI_POP2(x21,x30)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p521_jscalarmul_alt)++// Local copies of subroutines, complete clones at the moment except+// that we share multiplication and squaring between the point operations.++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_p521_9)++Lp521_jscalarmul_alt_bignum_mod_p521_9:+ CFI_START+ ldr x12, [x1, #64]+ lsr x2, x12, #9+ cmp xzr, xzr+ ldp x4, x5, [x1]+ adcs xzr, x4, x2+ adcs xzr, x5, xzr+ ldp x6, x7, [x1, #16]+ and x3, x6, x7+ adcs xzr, x3, xzr+ ldp x8, x9, [x1, #32]+ and x3, x8, x9+ adcs xzr, x3, xzr+ ldp x10, x11, [x1, #48]+ and x3, x10, x11+ adcs xzr, x3, xzr+ orr x3, x12, #0xfffffffffffffe00+ adcs x3, x3, xzr+ adcs x4, x4, x2+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adcs x11, x11, xzr+ adc x12, x12, xzr+ and x12, x12, #0x1ff+ stp x4, x5, [x0]+ stp x6, x7, [x0, #16]+ stp x8, x9, [x0, #32]+ stp x10, x11, [x0, #48]+ str x12, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_p521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_n521_9)++Lp521_jscalarmul_alt_bignum_mod_n521_9:+ CFI_START+ ldr x14, [x1, #64]+ lsr x15, x14, #9+ add x15, x15, #1+ mov x2, #39927+ movk x2, #28359, lsl #16+ movk x2, #18657, lsl #32+ movk x2, #17552, lsl #48+ mul x6, x2, x15+ mov x3, #47185+ movk x3, #30307, lsl #16+ movk x3, #13895, lsl #32+ movk x3, #50250, lsl #48+ mul x7, x3, x15+ mov x4, #23087+ movk x4, #2294, lsl #16+ movk x4, #65207, lsl #32+ movk x4, #32819, lsl #48+ mul x8, x4, x15+ mov x5, #27028+ movk x5, #16592, lsl #16+ movk x5, #30844, lsl #32+ movk x5, #44665, lsl #48+ mul x9, x5, x15+ lsl x10, x15, #2+ add x10, x10, x15+ umulh x13, x2, x15+ adds x7, x7, x13+ umulh x13, x3, x15+ adcs x8, x8, x13+ umulh x13, x4, x15+ adcs x9, x9, x13+ umulh x13, x5, x15+ adc x10, x10, x13+ ldp x12, x13, [x1]+ adds x6, x6, x12+ adcs x7, x7, x13+ ldp x12, x13, [x1, #16]+ adcs x8, x8, x12+ adcs x9, x9, x13+ ldp x13, x11, [x1, #32]+ adcs x10, x10, x13+ adcs x11, x11, xzr+ ldp x12, x13, [x1, #48]+ adcs x12, x12, xzr+ adcs x13, x13, xzr+ orr x14, x14, #0xfffffffffffffe00+ adcs x14, x14, xzr+ csetm x15, lo+ and x2, x2, x15+ subs x6, x6, x2+ and x3, x3, x15+ sbcs x7, x7, x3+ and x4, x4, x15+ sbcs x8, x8, x4+ and x5, x5, x15+ sbcs x9, x9, x5+ mov x2, #5+ and x2, x2, x15+ sbcs x10, x10, x2+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbc x14, x14, xzr+ and x14, x14, #0x1ff+ stp x6, x7, [x0]+ stp x8, x9, [x0, #16]+ stp x10, x11, [x0, #32]+ stp x12, x13, [x0, #48]+ str x14, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_n521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_jadd)++Lp521_jscalarmul_alt_jadd:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_PUSH2(x27,x28)+ CFI_PUSH2(x29,x30)+ CFI_DEC_SP(576)+ mov x27, x0+ mov x28, x1+ mov x29, x2+ mov x0, sp+ add x1, x28, #0x90+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ add x0, sp, #0x168+ add x1, x29, #0x90+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ add x0, sp, #0x1f8+ add x1, x29, #0x90+ add x2, x28, #0x48+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x48+ add x1, x28, #0x90+ add x2, x29, #0x48+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x90+ mov x1, sp+ add x2, x29, #0x0+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x120+ add x1, sp, #0x168+ add x2, x28, #0x0+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x48+ mov x1, sp+ add x2, sp, #0x48+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x1f8+ add x1, sp, #0x168+ add x2, sp, #0x1f8+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x168+ add x1, sp, #0x90+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_alt_sub_p521)+ add x0, sp, #0x48+ add x1, sp, #0x48+ add x2, sp, #0x1f8+ CFI_BL(Lp521_jscalarmul_alt_sub_p521)+ add x0, sp, #0xd8+ add x1, sp, #0x168+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ mov x0, sp+ add x1, sp, #0x48+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ add x0, sp, #0x120+ add x1, sp, #0xd8+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x90+ add x1, sp, #0xd8+ add x2, sp, #0x90+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ mov x0, sp+ mov x1, sp+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_alt_sub_p521)+ add x0, sp, #0xd8+ add x1, sp, #0x90+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_alt_sub_p521)+ add x0, sp, #0x168+ add x1, sp, #0x168+ add x2, x28, #0x90+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ mov x0, sp+ mov x1, sp+ add x2, sp, #0x90+ CFI_BL(Lp521_jscalarmul_alt_sub_p521)+ add x0, sp, #0x120+ add x1, sp, #0x120+ mov x2, sp+ CFI_BL(Lp521_jscalarmul_alt_sub_p521)+ add x0, sp, #0xd8+ add x1, sp, #0xd8+ add x2, sp, #0x1f8+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x168+ add x1, sp, #0x168+ add x2, x29, #0x90+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x120+ add x1, sp, #0x48+ add x2, sp, #0x120+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x120+ add x1, sp, #0x120+ add x2, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_alt_sub_p521)+ ldp x0, x1, [x28, #144]+ ldp x2, x3, [x28, #160]+ ldp x4, x5, [x28, #176]+ ldp x6, x7, [x28, #192]+ ldr x8, [x28, #208]+ orr x20, x0, x1+ orr x21, x2, x3+ orr x22, x4, x5+ orr x23, x6, x7+ orr x20, x20, x21+ orr x22, x22, x23+ orr x20, x20, x8+ orr x20, x20, x22+ cmp x20, xzr+ cset x20, ne+ ldp x10, x11, [x29, #144]+ ldp x12, x13, [x29, #160]+ ldp x14, x15, [x29, #176]+ ldp x16, x17, [x29, #192]+ ldr x19, [x29, #208]+ orr x21, x10, x11+ orr x22, x12, x13+ orr x23, x14, x15+ orr x24, x16, x17+ orr x21, x21, x22+ orr x23, x23, x24+ orr x21, x21, x19+ orr x21, x21, x23+ csel x0, x0, x10, ne+ csel x1, x1, x11, ne+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ csel x4, x4, x14, ne+ csel x5, x5, x15, ne+ csel x6, x6, x16, ne+ csel x7, x7, x17, ne+ csel x8, x8, x19, ne+ cmp x21, xzr+ cset x21, ne+ cmp x21, x20+ ldp x10, x11, [sp, #360]+ ldp x12, x13, [sp, #376]+ ldp x14, x15, [sp, #392]+ ldp x16, x17, [sp, #408]+ ldr x19, [sp, #424]+ csel x0, x0, x10, ne+ csel x1, x1, x11, ne+ csel x2, x2, x12, ne+ csel x3, x3, x13, ne+ csel x4, x4, x14, ne+ csel x5, x5, x15, ne+ csel x6, x6, x16, ne+ csel x7, x7, x17, ne+ csel x8, x8, x19, ne+ stp x0, x1, [sp, #360]+ stp x2, x3, [sp, #376]+ stp x4, x5, [sp, #392]+ stp x6, x7, [sp, #408]+ str x8, [sp, #424]+ ldp x20, x21, [x28]+ ldp x0, x1, [sp]+ csel x0, x20, x0, cc+ csel x1, x21, x1, cc+ ldp x20, x21, [x29]+ csel x0, x20, x0, hi+ csel x1, x21, x1, hi+ ldp x20, x21, [x28, #16]+ ldp x2, x3, [sp, #16]+ csel x2, x20, x2, cc+ csel x3, x21, x3, cc+ ldp x20, x21, [x29, #16]+ csel x2, x20, x2, hi+ csel x3, x21, x3, hi+ ldp x20, x21, [x28, #32]+ ldp x4, x5, [sp, #32]+ csel x4, x20, x4, cc+ csel x5, x21, x5, cc+ ldp x20, x21, [x29, #32]+ csel x4, x20, x4, hi+ csel x5, x21, x5, hi+ ldp x20, x21, [x28, #48]+ ldp x6, x7, [sp, #48]+ csel x6, x20, x6, cc+ csel x7, x21, x7, cc+ ldp x20, x21, [x29, #48]+ csel x6, x20, x6, hi+ csel x7, x21, x7, hi+ ldr x20, [x28, #64]+ ldr x8, [sp, #64]+ csel x8, x20, x8, cc+ ldr x21, [x29, #64]+ csel x8, x21, x8, hi+ ldp x20, x21, [x28, #72]+ ldp x10, x11, [sp, #288]+ csel x10, x20, x10, cc+ csel x11, x21, x11, cc+ ldp x20, x21, [x29, #72]+ csel x10, x20, x10, hi+ csel x11, x21, x11, hi+ ldp x20, x21, [x28, #88]+ ldp x12, x13, [sp, #304]+ csel x12, x20, x12, cc+ csel x13, x21, x13, cc+ ldp x20, x21, [x29, #88]+ csel x12, x20, x12, hi+ csel x13, x21, x13, hi+ ldp x20, x21, [x28, #104]+ ldp x14, x15, [sp, #320]+ csel x14, x20, x14, cc+ csel x15, x21, x15, cc+ ldp x20, x21, [x29, #104]+ csel x14, x20, x14, hi+ csel x15, x21, x15, hi+ ldp x20, x21, [x28, #120]+ ldp x16, x17, [sp, #336]+ csel x16, x20, x16, cc+ csel x17, x21, x17, cc+ ldp x20, x21, [x29, #120]+ csel x16, x20, x16, hi+ csel x17, x21, x17, hi+ ldr x20, [x28, #136]+ ldr x19, [sp, #352]+ csel x19, x20, x19, cc+ ldr x21, [x29, #136]+ csel x19, x21, x19, hi+ stp x0, x1, [x27]+ stp x2, x3, [x27, #16]+ stp x4, x5, [x27, #32]+ stp x6, x7, [x27, #48]+ str x8, [x27, #64]+ ldp x0, x1, [sp, #360]+ ldp x2, x3, [sp, #376]+ ldp x4, x5, [sp, #392]+ ldp x6, x7, [sp, #408]+ ldr x8, [sp, #424]+ stp x10, x11, [x27, #72]+ stp x12, x13, [x27, #88]+ stp x14, x15, [x27, #104]+ stp x16, x17, [x27, #120]+ str x19, [x27, #136]+ stp x0, x1, [x27, #144]+ stp x2, x3, [x27, #160]+ stp x4, x5, [x27, #176]+ stp x6, x7, [x27, #192]+ str x8, [x27, #208]+ CFI_INC_SP(576)+ CFI_POP2(x29,x30)+ CFI_POP2(x27,x28)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_jadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_jdouble)++Lp521_jscalarmul_alt_jdouble:+ CFI_START+ CFI_PUSH2(x19,x20)+ CFI_PUSH2(x21,x22)+ CFI_PUSH2(x23,x24)+ CFI_PUSH2(x25,x26)+ CFI_PUSH2(x27,x28)+ CFI_PUSH2(x29,x30)+ CFI_DEC_SP(512)+ mov x27, x0+ mov x28, x1+ mov x0, sp+ add x1, x28, #0x90+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ add x0, sp, #0x48+ add x1, x28, #0x48+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ ldp x5, x6, [x28]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x28, #16]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x28, #32]+ ldp x4, x3, [sp, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [x28, #48]+ ldp x4, x3, [sp, #48]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [x28, #64]+ ldr x4, [sp, #64]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [sp, #216]+ stp x7, x8, [sp, #232]+ stp x9, x10, [sp, #248]+ stp x11, x12, [sp, #264]+ str x13, [sp, #280]+ cmp xzr, xzr+ ldp x5, x6, [x28]+ ldp x4, x3, [sp]+ adcs x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x28, #16]+ ldp x4, x3, [sp, #16]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x28, #32]+ ldp x4, x3, [sp, #32]+ adcs x9, x9, x4+ adcs x10, x10, x3+ ldp x11, x12, [x28, #48]+ ldp x4, x3, [sp, #48]+ adcs x11, x11, x4+ adcs x12, x12, x3+ ldr x13, [x28, #64]+ ldr x4, [sp, #64]+ adc x13, x13, x4+ subs x4, x13, #0x200+ csetm x4, cs+ sbcs x5, x5, xzr+ and x4, x4, #0x200+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, x4+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ stp x11, x12, [sp, #192]+ str x13, [sp, #208]+ add x0, sp, #0xd8+ add x1, sp, #0x90+ add x2, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ cmp xzr, xzr+ ldp x5, x6, [x28, #72]+ ldp x4, x3, [x28, #144]+ adcs x5, x5, x4+ adcs x6, x6, x3+ ldp x7, x8, [x28, #88]+ ldp x4, x3, [x28, #160]+ adcs x7, x7, x4+ adcs x8, x8, x3+ ldp x9, x10, [x28, #104]+ ldp x4, x3, [x28, #176]+ adcs x9, x9, x4+ adcs x10, x10, x3+ ldp x11, x12, [x28, #120]+ ldp x4, x3, [x28, #192]+ adcs x11, x11, x4+ adcs x12, x12, x3+ ldr x13, [x28, #136]+ ldr x4, [x28, #208]+ adc x13, x13, x4+ subs x4, x13, #0x200+ csetm x4, cs+ sbcs x5, x5, xzr+ and x4, x4, #0x200+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, x4+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ stp x11, x12, [sp, #192]+ str x13, [sp, #208]+ add x0, sp, #0x120+ add x1, x28, #0x0+ add x2, sp, #0x48+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ add x0, sp, #0x168+ add x1, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ add x0, sp, #0x90+ add x1, sp, #0x90+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ ldp x6, x7, [sp, #288]+ mov x1, #0xc+ mul x3, x1, x6+ mul x4, x1, x7+ umulh x6, x1, x6+ adds x4, x4, x6+ umulh x7, x1, x7+ ldp x8, x9, [sp, #304]+ mul x5, x1, x8+ mul x6, x1, x9+ umulh x8, x1, x8+ adcs x5, x5, x7+ umulh x9, x1, x9+ adcs x6, x6, x8+ ldp x10, x11, [sp, #320]+ mul x7, x1, x10+ mul x8, x1, x11+ umulh x10, x1, x10+ adcs x7, x7, x9+ umulh x11, x1, x11+ adcs x8, x8, x10+ ldp x12, x13, [sp, #336]+ mul x9, x1, x12+ mul x10, x1, x13+ umulh x12, x1, x12+ adcs x9, x9, x11+ umulh x13, x1, x13+ adcs x10, x10, x12+ ldr x14, [sp, #352]+ mul x11, x1, x14+ adc x11, x11, x13+ mov x1, #0x9+ ldp x20, x21, [sp, #360]+ mvn x20, x20+ mul x0, x1, x20+ umulh x20, x1, x20+ adds x3, x3, x0+ mvn x21, x21+ mul x0, x1, x21+ umulh x21, x1, x21+ adcs x4, x4, x0+ ldp x22, x23, [sp, #376]+ mvn x22, x22+ mul x0, x1, x22+ umulh x22, x1, x22+ adcs x5, x5, x0+ mvn x23, x23+ mul x0, x1, x23+ umulh x23, x1, x23+ adcs x6, x6, x0+ ldp x17, x19, [sp, #392]+ mvn x17, x17+ mul x0, x1, x17+ umulh x17, x1, x17+ adcs x7, x7, x0+ mvn x19, x19+ mul x0, x1, x19+ umulh x19, x1, x19+ adcs x8, x8, x0+ ldp x2, x16, [sp, #408]+ mvn x2, x2+ mul x0, x1, x2+ umulh x2, x1, x2+ adcs x9, x9, x0+ mvn x16, x16+ mul x0, x1, x16+ umulh x16, x1, x16+ adcs x10, x10, x0+ ldr x0, [sp, #424]+ eor x0, x0, #0x1ff+ mul x0, x1, x0+ adc x11, x11, x0+ adds x4, x4, x20+ adcs x5, x5, x21+ and x15, x4, x5+ adcs x6, x6, x22+ and x15, x15, x6+ adcs x7, x7, x23+ and x15, x15, x7+ adcs x8, x8, x17+ and x15, x15, x8+ adcs x9, x9, x19+ and x15, x15, x9+ adcs x10, x10, x2+ and x15, x15, x10+ adc x11, x11, x16+ lsr x12, x11, #9+ orr x11, x11, #0xfffffffffffffe00+ cmp xzr, xzr+ adcs xzr, x3, x12+ adcs xzr, x15, xzr+ adcs xzr, x11, xzr+ adcs x3, x3, x12+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adc x11, x11, xzr+ and x11, x11, #0x1ff+ stp x3, x4, [sp, #360]+ stp x5, x6, [sp, #376]+ stp x7, x8, [sp, #392]+ stp x9, x10, [sp, #408]+ str x11, [sp, #424]+ ldp x5, x6, [sp, #144]+ ldp x4, x3, [sp]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #160]+ ldp x4, x3, [sp, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #176]+ ldp x4, x3, [sp, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [sp, #192]+ ldp x4, x3, [sp, #48]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [sp, #208]+ ldr x4, [sp, #64]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [sp, #144]+ stp x7, x8, [sp, #160]+ stp x9, x10, [sp, #176]+ stp x11, x12, [sp, #192]+ str x13, [sp, #208]+ mov x0, sp+ add x1, sp, #0x48+ CFI_BL(Lp521_jscalarmul_alt_sqr_p521)+ add x0, sp, #0xd8+ add x1, sp, #0x168+ add x2, sp, #0xd8+ CFI_BL(Lp521_jscalarmul_alt_mul_p521)+ ldp x5, x6, [sp, #144]+ ldp x4, x3, [sp, #72]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [sp, #160]+ ldp x4, x3, [sp, #88]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [sp, #176]+ ldp x4, x3, [sp, #104]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [sp, #192]+ ldp x4, x3, [sp, #120]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [sp, #208]+ ldr x4, [sp, #136]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [x27, #144]+ stp x7, x8, [x27, #160]+ stp x9, x10, [x27, #176]+ stp x11, x12, [x27, #192]+ str x13, [x27, #208]+ ldp x6, x7, [sp, #288]+ lsl x3, x6, #2+ extr x4, x7, x6, #62+ ldp x8, x9, [sp, #304]+ extr x5, x8, x7, #62+ extr x6, x9, x8, #62+ ldp x10, x11, [sp, #320]+ extr x7, x10, x9, #62+ extr x8, x11, x10, #62+ ldp x12, x13, [sp, #336]+ extr x9, x12, x11, #62+ extr x10, x13, x12, #62+ ldr x14, [sp, #352]+ extr x11, x14, x13, #62+ ldp x0, x1, [sp, #360]+ mvn x0, x0+ adds x3, x3, x0+ sbcs x4, x4, x1+ ldp x0, x1, [sp, #376]+ sbcs x5, x5, x0+ and x15, x4, x5+ sbcs x6, x6, x1+ and x15, x15, x6+ ldp x0, x1, [sp, #392]+ sbcs x7, x7, x0+ and x15, x15, x7+ sbcs x8, x8, x1+ and x15, x15, x8+ ldp x0, x1, [sp, #408]+ sbcs x9, x9, x0+ and x15, x15, x9+ sbcs x10, x10, x1+ and x15, x15, x10+ ldr x0, [sp, #424]+ eor x0, x0, #0x1ff+ adc x11, x11, x0+ lsr x12, x11, #9+ orr x11, x11, #0xfffffffffffffe00+ cmp xzr, xzr+ adcs xzr, x3, x12+ adcs xzr, x15, xzr+ adcs xzr, x11, xzr+ adcs x3, x3, x12+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adc x11, x11, xzr+ and x11, x11, #0x1ff+ stp x3, x4, [x27]+ stp x5, x6, [x27, #16]+ stp x7, x8, [x27, #32]+ stp x9, x10, [x27, #48]+ str x11, [x27, #64]+ ldp x6, x7, [sp, #216]+ lsl x3, x6, #1+ adds x3, x3, x6+ extr x4, x7, x6, #63+ adcs x4, x4, x7+ ldp x8, x9, [sp, #232]+ extr x5, x8, x7, #63+ adcs x5, x5, x8+ extr x6, x9, x8, #63+ adcs x6, x6, x9+ ldp x10, x11, [sp, #248]+ extr x7, x10, x9, #63+ adcs x7, x7, x10+ extr x8, x11, x10, #63+ adcs x8, x8, x11+ ldp x12, x13, [sp, #264]+ extr x9, x12, x11, #63+ adcs x9, x9, x12+ extr x10, x13, x12, #63+ adcs x10, x10, x13+ ldr x14, [sp, #280]+ extr x11, x14, x13, #63+ adc x11, x11, x14+ ldp x20, x21, [sp]+ mvn x20, x20+ lsl x0, x20, #3+ adds x3, x3, x0+ mvn x21, x21+ extr x0, x21, x20, #61+ adcs x4, x4, x0+ ldp x22, x23, [sp, #16]+ mvn x22, x22+ extr x0, x22, x21, #61+ adcs x5, x5, x0+ and x15, x4, x5+ mvn x23, x23+ extr x0, x23, x22, #61+ adcs x6, x6, x0+ and x15, x15, x6+ ldp x20, x21, [sp, #32]+ mvn x20, x20+ extr x0, x20, x23, #61+ adcs x7, x7, x0+ and x15, x15, x7+ mvn x21, x21+ extr x0, x21, x20, #61+ adcs x8, x8, x0+ and x15, x15, x8+ ldp x22, x23, [sp, #48]+ mvn x22, x22+ extr x0, x22, x21, #61+ adcs x9, x9, x0+ and x15, x15, x9+ mvn x23, x23+ extr x0, x23, x22, #61+ adcs x10, x10, x0+ and x15, x15, x10+ ldr x0, [sp, #64]+ eor x0, x0, #0x1ff+ extr x0, x0, x23, #61+ adc x11, x11, x0+ lsr x12, x11, #9+ orr x11, x11, #0xfffffffffffffe00+ cmp xzr, xzr+ adcs xzr, x3, x12+ adcs xzr, x15, xzr+ adcs xzr, x11, xzr+ adcs x3, x3, x12+ adcs x4, x4, xzr+ adcs x5, x5, xzr+ adcs x6, x6, xzr+ adcs x7, x7, xzr+ adcs x8, x8, xzr+ adcs x9, x9, xzr+ adcs x10, x10, xzr+ adc x11, x11, xzr+ and x11, x11, #0x1ff+ stp x3, x4, [x27, #72]+ stp x5, x6, [x27, #88]+ stp x7, x8, [x27, #104]+ stp x9, x10, [x27, #120]+ str x11, [x27, #136]+ CFI_INC_SP(512)+ CFI_POP2(x29,x30)+ CFI_POP2(x27,x28)+ CFI_POP2(x25,x26)+ CFI_POP2(x23,x24)+ CFI_POP2(x21,x22)+ CFI_POP2(x19,x20)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_jdouble)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_mul_p521)++Lp521_jscalarmul_alt_mul_p521:+ CFI_START+ ldp x3, x4, [x1]+ ldp x5, x6, [x2]+ mul x15, x3, x5+ umulh x16, x3, x5+ mul x14, x3, x6+ umulh x17, x3, x6+ adds x16, x16, x14+ ldp x7, x8, [x2, #16]+ mul x14, x3, x7+ umulh x19, x3, x7+ adcs x17, x17, x14+ mul x14, x3, x8+ umulh x20, x3, x8+ adcs x19, x19, x14+ ldp x9, x10, [x2, #32]+ mul x14, x3, x9+ umulh x21, x3, x9+ adcs x20, x20, x14+ mul x14, x3, x10+ umulh x22, x3, x10+ adcs x21, x21, x14+ ldp x11, x12, [x2, #48]+ mul x14, x3, x11+ umulh x23, x3, x11+ adcs x22, x22, x14+ ldr x13, [x2, #64]+ mul x14, x3, x12+ umulh x24, x3, x12+ adcs x23, x23, x14+ mul x14, x3, x13+ umulh x25, x3, x13+ adcs x24, x24, x14+ adc x25, x25, xzr+ mul x14, x4, x5+ adds x16, x16, x14+ mul x14, x4, x6+ adcs x17, x17, x14+ mul x14, x4, x7+ adcs x19, x19, x14+ mul x14, x4, x8+ adcs x20, x20, x14+ mul x14, x4, x9+ adcs x21, x21, x14+ mul x14, x4, x10+ adcs x22, x22, x14+ mul x14, x4, x11+ adcs x23, x23, x14+ mul x14, x4, x12+ adcs x24, x24, x14+ mul x14, x4, x13+ adcs x25, x25, x14+ cset x26, cs+ umulh x14, x4, x5+ adds x17, x17, x14+ umulh x14, x4, x6+ adcs x19, x19, x14+ umulh x14, x4, x7+ adcs x20, x20, x14+ umulh x14, x4, x8+ adcs x21, x21, x14+ umulh x14, x4, x9+ adcs x22, x22, x14+ umulh x14, x4, x10+ adcs x23, x23, x14+ umulh x14, x4, x11+ adcs x24, x24, x14+ umulh x14, x4, x12+ adcs x25, x25, x14+ umulh x14, x4, x13+ adc x26, x26, x14+ stp x15, x16, [sp, #432]+ ldp x3, x4, [x1, #16]+ mul x14, x3, x5+ adds x17, x17, x14+ mul x14, x3, x6+ adcs x19, x19, x14+ mul x14, x3, x7+ adcs x20, x20, x14+ mul x14, x3, x8+ adcs x21, x21, x14+ mul x14, x3, x9+ adcs x22, x22, x14+ mul x14, x3, x10+ adcs x23, x23, x14+ mul x14, x3, x11+ adcs x24, x24, x14+ mul x14, x3, x12+ adcs x25, x25, x14+ mul x14, x3, x13+ adcs x26, x26, x14+ cset x15, cs+ umulh x14, x3, x5+ adds x19, x19, x14+ umulh x14, x3, x6+ adcs x20, x20, x14+ umulh x14, x3, x7+ adcs x21, x21, x14+ umulh x14, x3, x8+ adcs x22, x22, x14+ umulh x14, x3, x9+ adcs x23, x23, x14+ umulh x14, x3, x10+ adcs x24, x24, x14+ umulh x14, x3, x11+ adcs x25, x25, x14+ umulh x14, x3, x12+ adcs x26, x26, x14+ umulh x14, x3, x13+ adc x15, x15, x14+ mul x14, x4, x5+ adds x19, x19, x14+ mul x14, x4, x6+ adcs x20, x20, x14+ mul x14, x4, x7+ adcs x21, x21, x14+ mul x14, x4, x8+ adcs x22, x22, x14+ mul x14, x4, x9+ adcs x23, x23, x14+ mul x14, x4, x10+ adcs x24, x24, x14+ mul x14, x4, x11+ adcs x25, x25, x14+ mul x14, x4, x12+ adcs x26, x26, x14+ mul x14, x4, x13+ adcs x15, x15, x14+ cset x16, cs+ umulh x14, x4, x5+ adds x20, x20, x14+ umulh x14, x4, x6+ adcs x21, x21, x14+ umulh x14, x4, x7+ adcs x22, x22, x14+ umulh x14, x4, x8+ adcs x23, x23, x14+ umulh x14, x4, x9+ adcs x24, x24, x14+ umulh x14, x4, x10+ adcs x25, x25, x14+ umulh x14, x4, x11+ adcs x26, x26, x14+ umulh x14, x4, x12+ adcs x15, x15, x14+ umulh x14, x4, x13+ adc x16, x16, x14+ stp x17, x19, [sp, #448]+ ldp x3, x4, [x1, #32]+ mul x14, x3, x5+ adds x20, x20, x14+ mul x14, x3, x6+ adcs x21, x21, x14+ mul x14, x3, x7+ adcs x22, x22, x14+ mul x14, x3, x8+ adcs x23, x23, x14+ mul x14, x3, x9+ adcs x24, x24, x14+ mul x14, x3, x10+ adcs x25, x25, x14+ mul x14, x3, x11+ adcs x26, x26, x14+ mul x14, x3, x12+ adcs x15, x15, x14+ mul x14, x3, x13+ adcs x16, x16, x14+ cset x17, cs+ umulh x14, x3, x5+ adds x21, x21, x14+ umulh x14, x3, x6+ adcs x22, x22, x14+ umulh x14, x3, x7+ adcs x23, x23, x14+ umulh x14, x3, x8+ adcs x24, x24, x14+ umulh x14, x3, x9+ adcs x25, x25, x14+ umulh x14, x3, x10+ adcs x26, x26, x14+ umulh x14, x3, x11+ adcs x15, x15, x14+ umulh x14, x3, x12+ adcs x16, x16, x14+ umulh x14, x3, x13+ adc x17, x17, x14+ mul x14, x4, x5+ adds x21, x21, x14+ mul x14, x4, x6+ adcs x22, x22, x14+ mul x14, x4, x7+ adcs x23, x23, x14+ mul x14, x4, x8+ adcs x24, x24, x14+ mul x14, x4, x9+ adcs x25, x25, x14+ mul x14, x4, x10+ adcs x26, x26, x14+ mul x14, x4, x11+ adcs x15, x15, x14+ mul x14, x4, x12+ adcs x16, x16, x14+ mul x14, x4, x13+ adcs x17, x17, x14+ cset x19, cs+ umulh x14, x4, x5+ adds x22, x22, x14+ umulh x14, x4, x6+ adcs x23, x23, x14+ umulh x14, x4, x7+ adcs x24, x24, x14+ umulh x14, x4, x8+ adcs x25, x25, x14+ umulh x14, x4, x9+ adcs x26, x26, x14+ umulh x14, x4, x10+ adcs x15, x15, x14+ umulh x14, x4, x11+ adcs x16, x16, x14+ umulh x14, x4, x12+ adcs x17, x17, x14+ umulh x14, x4, x13+ adc x19, x19, x14+ stp x20, x21, [sp, #464]+ ldp x3, x4, [x1, #48]+ mul x14, x3, x5+ adds x22, x22, x14+ mul x14, x3, x6+ adcs x23, x23, x14+ mul x14, x3, x7+ adcs x24, x24, x14+ mul x14, x3, x8+ adcs x25, x25, x14+ mul x14, x3, x9+ adcs x26, x26, x14+ mul x14, x3, x10+ adcs x15, x15, x14+ mul x14, x3, x11+ adcs x16, x16, x14+ mul x14, x3, x12+ adcs x17, x17, x14+ mul x14, x3, x13+ adcs x19, x19, x14+ cset x20, cs+ umulh x14, x3, x5+ adds x23, x23, x14+ umulh x14, x3, x6+ adcs x24, x24, x14+ umulh x14, x3, x7+ adcs x25, x25, x14+ umulh x14, x3, x8+ adcs x26, x26, x14+ umulh x14, x3, x9+ adcs x15, x15, x14+ umulh x14, x3, x10+ adcs x16, x16, x14+ umulh x14, x3, x11+ adcs x17, x17, x14+ umulh x14, x3, x12+ adcs x19, x19, x14+ umulh x14, x3, x13+ adc x20, x20, x14+ mul x14, x4, x5+ adds x23, x23, x14+ mul x14, x4, x6+ adcs x24, x24, x14+ mul x14, x4, x7+ adcs x25, x25, x14+ mul x14, x4, x8+ adcs x26, x26, x14+ mul x14, x4, x9+ adcs x15, x15, x14+ mul x14, x4, x10+ adcs x16, x16, x14+ mul x14, x4, x11+ adcs x17, x17, x14+ mul x14, x4, x12+ adcs x19, x19, x14+ mul x14, x4, x13+ adcs x20, x20, x14+ cset x21, cs+ umulh x14, x4, x5+ adds x24, x24, x14+ umulh x14, x4, x6+ adcs x25, x25, x14+ umulh x14, x4, x7+ adcs x26, x26, x14+ umulh x14, x4, x8+ adcs x15, x15, x14+ umulh x14, x4, x9+ adcs x16, x16, x14+ umulh x14, x4, x10+ adcs x17, x17, x14+ umulh x14, x4, x11+ adcs x19, x19, x14+ umulh x14, x4, x12+ adcs x20, x20, x14+ umulh x14, x4, x13+ adc x21, x21, x14+ stp x22, x23, [sp, #480]+ ldr x3, [x1, #64]+ mul x14, x3, x5+ adds x24, x24, x14+ mul x14, x3, x6+ adcs x25, x25, x14+ mul x14, x3, x7+ adcs x26, x26, x14+ mul x14, x3, x8+ adcs x15, x15, x14+ mul x14, x3, x9+ adcs x16, x16, x14+ mul x14, x3, x10+ adcs x17, x17, x14+ mul x14, x3, x11+ adcs x19, x19, x14+ mul x14, x3, x12+ adcs x20, x20, x14+ mul x14, x3, x13+ adc x21, x21, x14+ umulh x14, x3, x5+ adds x25, x25, x14+ umulh x14, x3, x6+ adcs x26, x26, x14+ umulh x14, x3, x7+ adcs x15, x15, x14+ umulh x14, x3, x8+ adcs x16, x16, x14+ umulh x14, x3, x9+ adcs x17, x17, x14+ umulh x14, x3, x10+ adcs x19, x19, x14+ umulh x14, x3, x11+ adcs x20, x20, x14+ umulh x14, x3, x12+ adc x21, x21, x14+ cmp xzr, xzr+ ldp x5, x6, [sp, #432]+ extr x14, x25, x24, #9+ adcs x5, x5, x14+ extr x14, x26, x25, #9+ adcs x6, x6, x14+ ldp x7, x8, [sp, #448]+ extr x14, x15, x26, #9+ adcs x7, x7, x14+ extr x14, x16, x15, #9+ adcs x8, x8, x14+ ldp x9, x10, [sp, #464]+ extr x14, x17, x16, #9+ adcs x9, x9, x14+ extr x14, x19, x17, #9+ adcs x10, x10, x14+ ldp x11, x12, [sp, #480]+ extr x14, x20, x19, #9+ adcs x11, x11, x14+ extr x14, x21, x20, #9+ adcs x12, x12, x14+ orr x13, x24, #0xfffffffffffffe00+ lsr x14, x21, #9+ adcs x13, x13, x14+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbc x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [x0]+ stp x7, x8, [x0, #16]+ stp x9, x10, [x0, #32]+ stp x11, x12, [x0, #48]+ str x13, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_mul_p521)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_sqr_p521)++Lp521_jscalarmul_alt_sqr_p521:+ CFI_START+ ldp x2, x3, [x1]+ mul x11, x2, x3+ umulh x12, x2, x3+ ldp x4, x5, [x1, #16]+ mul x10, x2, x4+ umulh x13, x2, x4+ adds x12, x12, x10+ ldp x6, x7, [x1, #32]+ mul x10, x2, x5+ umulh x14, x2, x5+ adcs x13, x13, x10+ ldp x8, x9, [x1, #48]+ mul x10, x2, x6+ umulh x15, x2, x6+ adcs x14, x14, x10+ mul x10, x2, x7+ umulh x16, x2, x7+ adcs x15, x15, x10+ mul x10, x2, x8+ umulh x17, x2, x8+ adcs x16, x16, x10+ mul x10, x2, x9+ umulh x19, x2, x9+ adcs x17, x17, x10+ adc x19, x19, xzr+ mul x10, x3, x4+ adds x13, x13, x10+ mul x10, x3, x5+ adcs x14, x14, x10+ mul x10, x3, x6+ adcs x15, x15, x10+ mul x10, x3, x7+ adcs x16, x16, x10+ mul x10, x3, x8+ adcs x17, x17, x10+ mul x10, x3, x9+ adcs x19, x19, x10+ cset x20, cs+ umulh x10, x3, x4+ adds x14, x14, x10+ umulh x10, x3, x5+ adcs x15, x15, x10+ umulh x10, x3, x6+ adcs x16, x16, x10+ umulh x10, x3, x7+ adcs x17, x17, x10+ umulh x10, x3, x8+ adcs x19, x19, x10+ umulh x10, x3, x9+ adc x20, x20, x10+ mul x10, x6, x7+ umulh x21, x6, x7+ adds x20, x20, x10+ adc x21, x21, xzr+ mul x10, x4, x5+ adds x15, x15, x10+ mul x10, x4, x6+ adcs x16, x16, x10+ mul x10, x4, x7+ adcs x17, x17, x10+ mul x10, x4, x8+ adcs x19, x19, x10+ mul x10, x4, x9+ adcs x20, x20, x10+ mul x10, x6, x8+ adcs x21, x21, x10+ cset x22, cs+ umulh x10, x4, x5+ adds x16, x16, x10+ umulh x10, x4, x6+ adcs x17, x17, x10+ umulh x10, x4, x7+ adcs x19, x19, x10+ umulh x10, x4, x8+ adcs x20, x20, x10+ umulh x10, x4, x9+ adcs x21, x21, x10+ umulh x10, x6, x8+ adc x22, x22, x10+ mul x10, x7, x8+ umulh x23, x7, x8+ adds x22, x22, x10+ adc x23, x23, xzr+ mul x10, x5, x6+ adds x17, x17, x10+ mul x10, x5, x7+ adcs x19, x19, x10+ mul x10, x5, x8+ adcs x20, x20, x10+ mul x10, x5, x9+ adcs x21, x21, x10+ mul x10, x6, x9+ adcs x22, x22, x10+ mul x10, x7, x9+ adcs x23, x23, x10+ cset x24, cs+ umulh x10, x5, x6+ adds x19, x19, x10+ umulh x10, x5, x7+ adcs x20, x20, x10+ umulh x10, x5, x8+ adcs x21, x21, x10+ umulh x10, x5, x9+ adcs x22, x22, x10+ umulh x10, x6, x9+ adcs x23, x23, x10+ umulh x10, x7, x9+ adc x24, x24, x10+ mul x10, x8, x9+ umulh x25, x8, x9+ adds x24, x24, x10+ adc x25, x25, xzr+ adds x11, x11, x11+ adcs x12, x12, x12+ adcs x13, x13, x13+ adcs x14, x14, x14+ adcs x15, x15, x15+ adcs x16, x16, x16+ adcs x17, x17, x17+ adcs x19, x19, x19+ adcs x20, x20, x20+ adcs x21, x21, x21+ adcs x22, x22, x22+ adcs x23, x23, x23+ adcs x24, x24, x24+ adcs x25, x25, x25+ cset x26, cs+ umulh x10, x2, x2+ adds x11, x11, x10+ mul x10, x3, x3+ adcs x12, x12, x10+ umulh x10, x3, x3+ adcs x13, x13, x10+ mul x10, x4, x4+ adcs x14, x14, x10+ umulh x10, x4, x4+ adcs x15, x15, x10+ mul x10, x5, x5+ adcs x16, x16, x10+ umulh x10, x5, x5+ adcs x17, x17, x10+ mul x10, x6, x6+ adcs x19, x19, x10+ umulh x10, x6, x6+ adcs x20, x20, x10+ mul x10, x7, x7+ adcs x21, x21, x10+ umulh x10, x7, x7+ adcs x22, x22, x10+ mul x10, x8, x8+ adcs x23, x23, x10+ umulh x10, x8, x8+ adcs x24, x24, x10+ mul x10, x9, x9+ adcs x25, x25, x10+ umulh x10, x9, x9+ adc x26, x26, x10+ ldr x1, [x1, #64]+ add x1, x1, x1+ mul x10, x1, x2+ adds x19, x19, x10+ umulh x10, x1, x2+ adcs x20, x20, x10+ mul x10, x1, x4+ adcs x21, x21, x10+ umulh x10, x1, x4+ adcs x22, x22, x10+ mul x10, x1, x6+ adcs x23, x23, x10+ umulh x10, x1, x6+ adcs x24, x24, x10+ mul x10, x1, x8+ adcs x25, x25, x10+ umulh x10, x1, x8+ adcs x26, x26, x10+ lsr x4, x1, #1+ mul x4, x4, x4+ adc x4, x4, xzr+ mul x10, x1, x3+ adds x20, x20, x10+ umulh x10, x1, x3+ adcs x21, x21, x10+ mul x10, x1, x5+ adcs x22, x22, x10+ umulh x10, x1, x5+ adcs x23, x23, x10+ mul x10, x1, x7+ adcs x24, x24, x10+ umulh x10, x1, x7+ adcs x25, x25, x10+ mul x10, x1, x9+ adcs x26, x26, x10+ umulh x10, x1, x9+ adc x4, x4, x10+ mul x2, x2, x2+ cmp xzr, xzr+ extr x10, x20, x19, #9+ adcs x2, x2, x10+ extr x10, x21, x20, #9+ adcs x11, x11, x10+ extr x10, x22, x21, #9+ adcs x12, x12, x10+ extr x10, x23, x22, #9+ adcs x13, x13, x10+ extr x10, x24, x23, #9+ adcs x14, x14, x10+ extr x10, x25, x24, #9+ adcs x15, x15, x10+ extr x10, x26, x25, #9+ adcs x16, x16, x10+ extr x10, x4, x26, #9+ adcs x17, x17, x10+ orr x19, x19, #0xfffffffffffffe00+ lsr x10, x4, #9+ adcs x19, x19, x10+ sbcs x2, x2, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ sbcs x14, x14, xzr+ sbcs x15, x15, xzr+ sbcs x16, x16, xzr+ sbcs x17, x17, xzr+ sbc x19, x19, xzr+ and x19, x19, #0x1ff+ stp x2, x11, [x0]+ stp x12, x13, [x0, #16]+ stp x14, x15, [x0, #32]+ stp x16, x17, [x0, #48]+ str x19, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_sqr_p521)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_sub_p521)++Lp521_jscalarmul_alt_sub_p521:+ CFI_START+ ldp x5, x6, [x1]+ ldp x4, x3, [x2]+ subs x5, x5, x4+ sbcs x6, x6, x3+ ldp x7, x8, [x1, #16]+ ldp x4, x3, [x2, #16]+ sbcs x7, x7, x4+ sbcs x8, x8, x3+ ldp x9, x10, [x1, #32]+ ldp x4, x3, [x2, #32]+ sbcs x9, x9, x4+ sbcs x10, x10, x3+ ldp x11, x12, [x1, #48]+ ldp x4, x3, [x2, #48]+ sbcs x11, x11, x4+ sbcs x12, x12, x3+ ldr x13, [x1, #64]+ ldr x4, [x2, #64]+ sbcs x13, x13, x4+ sbcs x5, x5, xzr+ sbcs x6, x6, xzr+ sbcs x7, x7, xzr+ sbcs x8, x8, xzr+ sbcs x9, x9, xzr+ sbcs x10, x10, xzr+ sbcs x11, x11, xzr+ sbcs x12, x12, xzr+ sbcs x13, x13, xzr+ and x13, x13, #0x1ff+ stp x5, x6, [x0]+ stp x7, x8, [x0, #16]+ stp x9, x10, [x0, #32]+ stp x11, x12, [x0, #48]+ str x13, [x0, #64]+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_sub_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/import.sh view
@@ -0,0 +1,112 @@+#!/bin/sh+# Re-import the vendored parts of AWS's s2n-bignum.+#+# Only the files crypton calls are kept, and they are kept unmodified -- the+# dispatch that chooses between the two variants of each is in+# cbits/p256/p256_s2n.c, not in here. Run this from cbits/s2n:+#+# ./import.sh [commit]+#+# and commit the result together with the COMMIT line it writes, so that the+# tree always says which upstream revision it holds.+set -eu++REPO=https://github.com/awslabs/s2n-bignum+REV=${1:-main}+HERE=$(cd "$(dirname "$0")" && pwd)+TMP=$(mktemp -d)+trap 'rm -rf "$TMP"' EXIT++git clone -q "$REPO" "$TMP/s2n"+git -C "$TMP/s2n" checkout -q "$REV"++# The headers every vendored file includes.+for h in _internal_s2n_bignum_arm.h _internal_s2n_bignum_x86_att.h; do+ cp "$TMP/s2n/include/$h" "$HERE/include/$h"+done+cp "$TMP/s2n/LICENSE" "$HERE/LICENSE"++# Both variants of each routine are taken, since which one is faster is not+# the same question on the two architectures -- see README.md. Where the+# upstream tree has no separate _alt file the plain one defines both symbols,+# so "copy it if it is there" gets the right set either way.+# x86-64 only, for the things AArch64 does not want -- see README.md.+take_x86() {+ dir=$1+ name=$2+ cp "$TMP/s2n/x86_att/$dir/$name.S" "$HERE/x86_att/$name.S"+}++take() {+ curve=$1+ name=$2+ for arch in arm x86_att; do+ for v in "" _alt; do+ src="$TMP/s2n/$arch/$curve/$name$v.S"+ if [ -f "$src" ]; then+ cp "$src" "$HERE/$arch/$name$v.S"+ fi+ done+ done+}++# P-256: variable-point scalar multiplication, affine in and out, and the+# fixed-base one, which reads a table of its own that+# cbits/p256/gen_base_table.py builds.+take p256 p256_scalarmul+take p256 p256_scalarmulbase++# The Jacobian point operations, which ECDSA verification walks itself: it+# multiplies two scalars at once, in variable time, which is allowed there+# because everything it touches is public. See cbits/p256/p256_verify.c.+take p256 p256_montjadd+take p256 p256_montjdouble+take p256 p256_montjmixadd+take p256 bignum_tomont_p256+take p256 bignum_demont_p256+take p256 bignum_neg_p256++# P-384 and P-521 have no affine wrapper upstream, so the Montgomery and+# Jacobian conversions are built here out of these; the glue is in+# cbits/crypton_ecc_s2n.c.+take p384 p384_montjscalarmul+take p384 bignum_tomont_p384+take p384 bignum_deamont_p384+take p384 bignum_montmul_p384+take p384 bignum_montsqr_p384+take p384 bignum_montinv_p384++take p521 p521_jscalarmul+take p521 bignum_mul_p521+take p521 bignum_sqr_p521+take p521 bignum_inv_p521++# X25519, both the general one and the fixed-base one that a key is+# generated with. The word form, which both architectures have, rather than+# the byte form that only AArch64 has: they measure the same and this way+# there is one code path.+take curve25519 curve25519_x25519+take curve25519 curve25519_x25519base++# Ed25519's base point multiplication, which signing does twice -- once for+# the nonce's point and once for the public key it derives from the secret+# key every time -- and the encoding of the result, which has one form.+take curve25519 edwards25519_scalarmulbase+take curve25519 edwards25519_encode++# Inversion modulo an odd number of any size, which is what ECDSA does once+# per signature and once per verification. It uses no instruction beyond+# the base architecture, so there is one of it and no run-time question.+take generic bignum_modinv++# Modular exponentiation at RSA sizes. Only x86-64: on AArch64 crypton's C+# is the faster of the two, measured, so nothing is taken for it. The+# Karatsuba multiplications and the reduction all want ADX.+take_x86 fastmul bignum_kmul_16_32+take_x86 fastmul bignum_ksqr_16_32+take_x86 fastmul bignum_kmul_32_64+take_x86 fastmul bignum_ksqr_32_64+take_x86 fastmul bignum_emontredc_8n++git -C "$TMP/s2n" rev-parse HEAD > "$HERE/COMMIT"+echo "imported $(cat "$HERE/COMMIT")"
+ cbits/s2n/include/_internal_s2n_bignum_arm.h view
@@ -0,0 +1,103 @@+#ifdef __APPLE__+# define S2N_BN_SYMBOL(NAME) _##NAME+# if defined(__AARCH64EL__) || defined(__ARMEL__)+# define __LF %%+# else+# define __LF ;+# endif+#else+# define S2N_BN_SYMBOL(name) name+# define __LF ;+#endif++#define S2N_BN_SYM_VISIBILITY_DIRECTIVE(name) .globl S2N_BN_SYMBOL(name)++#ifdef S2N_BN_HIDE_SYMBOLS+# ifdef __APPLE__+# define S2N_BN_SYM_PRIVACY_DIRECTIVE(name) .private_extern S2N_BN_SYMBOL(name)+# else+# define S2N_BN_SYM_PRIVACY_DIRECTIVE(name) .hidden S2N_BN_SYMBOL(name)+# endif+#else+# define S2N_BN_SYM_PRIVACY_DIRECTIVE(name) /* NO-OP: S2N_BN_SYM_PRIVACY_DIRECTIVE */+#endif++#ifdef __APPLE__+# define S2N_BN_FUNCTION_TYPE_DIRECTIVE(name) /* Not used in Mach-O */+#else+# define S2N_BN_FUNCTION_TYPE_DIRECTIVE(name) .type name, %function+#endif++#ifdef __APPLE__+# define S2N_BN_SIZE_DIRECTIVE(name) /* Not used in Mach-O */+#else+# define S2N_BN_SIZE_DIRECTIVE(name) .size S2N_BN_SYMBOL(name), .-S2N_BN_SYMBOL(name)+#endif++// Enable branch target identification (BTI) support unless explicitly disabled+// with -DNO_IBT, mirroring the x86 _CET_ENDBR machinery. AARCH64_VALID_CALL_TARGET+// is emitted at each entry point unconditionally by default, since BTI 'c' is in+// the hint space and so behaves as a NOP on all pre-Armv8.5-A processors. The name+// matches AWS-LC's macro, whose definition we defer to if already present, just as+// the x86 side defers to <cet.h>. Unlike CET, BTI also needs a .note.gnu.property+// section: it has GNU_PROPERTY_AARCH64_FEATURE_1_AND semantics, so one object+// without the note silently disables BTI program-wide, hence emitting it here.++#if NO_IBT+# if defined(AARCH64_VALID_CALL_TARGET)+# error "The s2n-bignum build option NO_IBT was configured, but AARCH64_VALID_CALL_TARGET is defined in this compilation unit. That is weird, so failing the build."+# endif+# define AARCH64_VALID_CALL_TARGET+#elif !defined(AARCH64_VALID_CALL_TARGET)+# define AARCH64_VALID_CALL_TARGET hint #34 /* BTI c */+# ifndef __APPLE__+ .pushsection .note.gnu.property, "a"+ .balign 8+ .long 4 /* n_namesz: sizeof "GNU\0" */+ .long 0x10 /* n_descsz: 16 bytes of property data */+ .long 0x5 /* n_type: NT_GNU_PROPERTY_TYPE_0 */+ .asciz "GNU"+ .long 0xc0000000 /* pr_type: GNU_PROPERTY_AARCH64_FEATURE_1_AND */+ .long 4 /* pr_datasz: 4 bytes */+ .long 1 /* pr_data: GNU_PROPERTY_AARCH64_FEATURE_1_BTI */+ .long 0 /* pad to 8-byte alignment */+ .popsection+# endif+#endif++// Variants of instructions including CFI (call frame information) annotations++#define CFI_START .cfi_startproc+#define CFI_RET ret __LF .cfi_endproc++#define CFI_BL(target) bl target++#define CFI_PUSH2(lo,hi) stp lo, hi, [sp, #-16]! __LF .cfi_adjust_cfa_offset 16 __LF .cfi_rel_offset lo, 0 __LF .cfi_rel_offset hi, 8+#define CFI_PUSH1Z(reg) stp reg, xzr, [sp, #-16]! __LF .cfi_adjust_cfa_offset 16 __LF .cfi_rel_offset reg, 0++#define CFI_POP2(lo,hi) ldp lo, hi, [sp], #16 __LF .cfi_adjust_cfa_offset -16 __LF .cfi_restore lo __LF .cfi_restore hi+#define CFI_POP1Z(reg) ldp reg, xzr, [sp], #16 __LF .cfi_adjust_cfa_offset -16 __LF .cfi_restore reg++#define CFI_STACKSAVE2(lo,hi,offset) stp lo, hi, [sp, #(offset)] __LF .cfi_rel_offset lo, offset __LF .cfi_rel_offset hi, offset+8++// This is an alternative to CFI_STACKSAVE2 to work around delocator problems+// in the AWS-LC FIPS build, avoiding certain composite expressions. It is+// expected that offset8 = offset+8 as in an invocation of CFI_STACKSAVE2.+// Likewise the (offset+0) oddities in the following macros are driven by+// delocator problems.++#define CFI_STACKSAVE2X(lo,hi,offset,offset8) stp lo, hi, [sp, #(offset+0)] __LF .cfi_rel_offset lo, offset __LF .cfi_rel_offset hi, offset8++#define CFI_STACKSAVE1Z(reg,offset) stp reg, xzr, [sp, #(offset+0)] __LF .cfi_rel_offset reg, offset++#define CFI_STACKLOAD2(lo,hi,offset) ldp lo, hi, [sp, #(offset+0)] __LF .cfi_restore lo __LF .cfi_restore hi+#define CFI_STACKLOAD1Z(reg,offset) ldp reg, xzr, [sp, #(offset+0)] __LF .cfi_restore reg++// It would be better to use -(offset) not -offset, but again there seem+// to be delocator issues. We adopt a discipline of not using dangerous+// composite expressions in this macro, e.g. parenthesizing the argument+// or just using numeric constants or products where the association is+// not a problem.++#define CFI_INC_SP(offset) add sp, sp, #(offset+0) __LF .cfi_adjust_cfa_offset -offset+#define CFI_DEC_SP(offset) sub sp, sp, #(offset+0) __LF .cfi_adjust_cfa_offset offset
+ cbits/s2n/include/_internal_s2n_bignum_x86_att.h view
@@ -0,0 +1,68 @@+#ifdef __APPLE__+# define S2N_BN_SYMBOL(NAME) _##NAME+#else+# define S2N_BN_SYMBOL(name) name+#endif++#define S2N_BN_SYM_VISIBILITY_DIRECTIVE(name) .globl S2N_BN_SYMBOL(name)++#ifdef S2N_BN_HIDE_SYMBOLS+# ifdef __APPLE__+# define S2N_BN_SYM_PRIVACY_DIRECTIVE(name) .private_extern S2N_BN_SYMBOL(name)+# else+# define S2N_BN_SYM_PRIVACY_DIRECTIVE(name) .hidden S2N_BN_SYMBOL(name)+# endif+#else+# define S2N_BN_SYM_PRIVACY_DIRECTIVE(name) /* NO-OP: S2N_BN_SYM_PRIVACY_DIRECTIVE */+#endif++#ifdef __APPLE__+# define S2N_BN_FUNCTION_TYPE_DIRECTIVE(name) /* Not used in Mach-O */+#else+# define S2N_BN_FUNCTION_TYPE_DIRECTIVE(name) .type name, %function+#endif++#ifdef __APPLE__+# define S2N_BN_SIZE_DIRECTIVE(name) /* Not used in Mach-O */+#else+# define S2N_BN_SIZE_DIRECTIVE(name) .size S2N_BN_SYMBOL(name), .-S2N_BN_SYMBOL(name)+#endif++// Enable indirect branch tracking support unless explicitly disabled+// with -DNO_IBT. If the platform supports CET, simply inherit this from+// the usual header. Otherwise manually define _CET_ENDBR, used at each+// x86 entry point, to be the ENDBR64 instruction, with an explicit byte+// sequence for compilers/assemblers that don't know about it. Note that+// it is safe to use ENDBR64 on all platforms, since the encoding is by+// design interpreted as a NOP on all pre-CET x86_64 processors. The only+// downside is a small increase in code size and potentially a modest+// slowdown from executing one more instruction.++#if NO_IBT+# if defined(_CET_ENDBR)+# error "The s2n-bignum build option NO_IBT was configured, but _CET_ENDBR is defined in this compilation unit. That is weird, so failing the build."+# endif+# define _CET_ENDBR+#elif defined(__CET__)+# include <cet.h>+#elif !defined(_CET_ENDBR)+# define _CET_ENDBR .byte 0xf3,0x0f,0x1e,0xfa+#endif++// Variants of instructions including CFI (call frame information) annotations++#define CFI_START .cfi_startproc+#define CFI_RET retq ; .cfi_endproc++#define CFI_CALL(target) callq target++#define CFI_PUSH(reg) pushq reg ; .cfi_adjust_cfa_offset 8 ; .cfi_rel_offset reg, 0+#define CFI_POP(reg) popq reg ; .cfi_adjust_cfa_offset -8 ; .cfi_restore reg++#define CFI_INC_RSP(offset) addq $offset, %rsp ; .cfi_adjust_cfa_offset -offset+#define CFI_DEC_RSP(offset) subq $offset, %rsp ; .cfi_adjust_cfa_offset offset++#define CFI_STACKSAVE(reg,offset) mov reg, offset(%rsp) ; .cfi_rel_offset reg, offset+#define CFI_STACKLOAD(reg,offset) mov offset(%rsp), reg ; .cfi_restore reg+#define CFI_STACKSAVEU(reg,offset) movups reg, offset(%rsp) ; .cfi_rel_offset reg, offset+#define CFI_STACKLOADU(reg,offset) movups offset(%rsp), reg ; .cfi_restore reg
+ cbits/s2n/x86_att/bignum_deamont_p384.S view
@@ -0,0 +1,184 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert from almost-Montgomery form, z := (x / 2^384) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_deamont_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Convert a 6-digit bignum x out of its (optionally almost) Montgomery form,+// "almost" meaning any 6-digit input will work, with no range restriction.+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_deamont_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_deamont_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_deamont_p384)+ .text++#define z %rdi+#define x %rsi++// Additional temps in the correction phase++#define u %rax+#define v %rcx+#define w %rdx++#define vshort %ecx++// Core one-step "short" Montgomery reduction macro. Takes input in+// [d5;d4;d3;d2;d1;d0] and returns result in [d6;d5;d4;d3;d2;d1],+// adding to the existing contents of [d5;d4;d3;d2;d1;d0]. This+// is intended only for 6-word inputs as in mapping out of Montgomery,+// not for the general case of Montgomery multiplication. It is fine+// for d6 to be the same register as d0.+//+// Parms: montreds(d6,d5,d4,d3,d2,d1,d0)+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64++#define montreds(d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rdx ; \+ shlq $32, %rdx ; \+ addq d0, %rdx ; \+/* Construct [%rsi;%rcx;%rax;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 */ \+/* as a temp. */ \+ xorq %rsi, %rsi ; \+ movq $0xffffffff00000001, %rax ; \+ mulxq %rax, %rcx, %rax ; \+ movl $0x00000000ffffffff, %ecx ; \+ mulxq %rcx, d0, %rcx ; \+ adcq d0, %rax ; \+ adcq %rdx, %rcx ; \+ adcq $0, %rsi ; \+/* Now subtract that and add 2^384 * w */ \+ subq %rax, d1 ; \+ sbbq %rcx, d2 ; \+ sbbq %rsi, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ movq %rdx, d6 ; \+ sbbq $0, d6++S2N_BN_SYMBOL(bignum_deamont_p384):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save more registers to play with++ CFI_PUSH(%r12)+ CFI_PUSH(%r13)++// Set up an initial window [%r13,%r12,%r11,%r10,%r9,%r8] = x++ movq (x), %r8+ movq 8(x), %r9+ movq 16(x), %r10+ movq 24(x), %r11+ movq 32(x), %r12+ movq 40(x), %r13++// Montgomery reduce window 0++ montreds(%r8,%r13,%r12,%r11,%r10,%r9,%r8)++// Montgomery reduce window 1++ montreds(%r9,%r8,%r13,%r12,%r11,%r10,%r9)++// Montgomery reduce window 2++ montreds(%r10,%r9,%r8,%r13,%r12,%r11,%r10)++// Montgomery reduce window 3++ montreds(%r11,%r10,%r9,%r8,%r13,%r12,%r11)++// Montgomery reduce window 4++ montreds(%r12,%r11,%r10,%r9,%r8,%r13,%r12)++// Montgomery reduce window 5++ montreds(%r13,%r12,%r11,%r10,%r9,%r8,%r13)++// Do a test addition of dd = [%r13;%r12;%r11;%r10;%r9;%r8] and+// 2^384 - p_384 = [0;0;0;1;v;u], hence setting CF iff+// dd + (2^384 - p_384) >= 2^384, hence iff dd >= p_384.++ movq $0xffffffff00000001, u+ movl $0x00000000ffffffff, vshort++ movq %r8, w+ addq u, w+ movq %r9, w+ adcq v, w+ movq %r10, w+ adcq $1, w+ movq %r11, w+ adcq $0, w+ movq %r12, w+ adcq $0, w+ movq %r13, w+ adcq $0, w++// Convert CF to a bitmask in w++ sbbq w, w++// Masked addition of 2^384 - p_384, hence subtraction of p_384++ andq w, u+ andq w, v+ andq $1, w++ addq u, %r8+ adcq v, %r9+ adcq w, %r10+ adcq $0, %r11+ adcq $0, %r12+ adcq $0, %r13++// Write back the result++ movq %r8, (z)+ movq %r9, 8(z)+ movq %r10, 16(z)+ movq %r11, 24(z)+ movq %r12, 32(z)+ movq %r13, 40(z)++// Restore registers and return++ CFI_POP(%r13)+ CFI_POP(%r12)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_deamont_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_deamont_p384_alt.S view
@@ -0,0 +1,184 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert from almost-Montgomery form, z := (x / 2^384) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_deamont_p384_alt(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Convert a 6-digit bignum x out of its (optionally almost) Montgomery form,+// "almost" meaning any 6-digit input will work, with no range restriction.+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_deamont_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_deamont_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_deamont_p384_alt)+ .text++#define z %rdi+#define x %rsi++// Additional temps in the correction phase++#define u %rax+#define v %rcx+#define w %rdx++#define vshort %ecx++// Core one-step "short" Montgomery reduction macro. Takes input in+// [d5;d4;d3;d2;d1;d0] and returns result in [d6;d5;d4;d3;d2;d1],+// adding to the existing [d5;d4;d3;d2;d1] and re-using d0 as a+// temporary internally, as well as %rax, %rcx and %rdx.+// It is OK for d6 and d0 to be the same register (they often are)+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+//+// montreds(d6,d5,d4,d3,d2,d1,d0)++#define montreds(d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rcx ; \+ shlq $32, %rcx ; \+ addq d0, %rcx ; \+/* Construct [%rax;%rdx;d0;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 */ \+/* and %rcx as temps. */ \+ movq $0xffffffff00000001, %rax ; \+ mulq %rcx; \+ movq %rdx, d0 ; \+ movq $0x00000000ffffffff, %rax ; \+ mulq %rcx; \+ addq %rax, d0 ; \+ movl $0, %eax ; \+ adcq %rcx, %rdx ; \+ adcl %eax, %eax ; \+/* Now subtract that and add 2^384 * w */ \+ subq d0, d1 ; \+ sbbq %rdx, d2 ; \+ sbbq %rax, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ movq %rcx, d6 ; \+ sbbq $0, d6++S2N_BN_SYMBOL(bignum_deamont_p384_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save more registers to play with++ CFI_PUSH(%r12)+ CFI_PUSH(%r13)++// Set up an initial window [%r13,%r12,%r11,%r10,%r9,%r8] = x++ movq (x), %r8+ movq 8(x), %r9+ movq 16(x), %r10+ movq 24(x), %r11+ movq 32(x), %r12+ movq 40(x), %r13++// Montgomery reduce window 0++ montreds(%r8,%r13,%r12,%r11,%r10,%r9,%r8)++// Montgomery reduce window 1++ montreds(%r9,%r8,%r13,%r12,%r11,%r10,%r9)++// Montgomery reduce window 2++ montreds(%r10,%r9,%r8,%r13,%r12,%r11,%r10)++// Montgomery reduce window 3++ montreds(%r11,%r10,%r9,%r8,%r13,%r12,%r11)++// Montgomery reduce window 4++ montreds(%r12,%r11,%r10,%r9,%r8,%r13,%r12)++// Montgomery reduce window 5++ montreds(%r13,%r12,%r11,%r10,%r9,%r8,%r13)++// Do a test addition of dd = [%r13;%r12;%r11;%r10;%r9;%r8] and+// 2^384 - p_384 = [0;0;0;1;v;u], hence setting CF iff+// dd + (2^384 - p_384) >= 2^384, hence iff dd >= p_384.++ movq $0xffffffff00000001, u+ movl $0x00000000ffffffff, vshort++ movq %r8, w+ addq u, w+ movq %r9, w+ adcq v, w+ movq %r10, w+ adcq $1, w+ movq %r11, w+ adcq $0, w+ movq %r12, w+ adcq $0, w+ movq %r13, w+ adcq $0, w++// Convert CF to a bitmask in w++ sbbq w, w++// Masked addition of 2^384 - p_384, hence subtraction of p_384++ andq w, u+ andq w, v+ andq $1, w++ addq u, %r8+ adcq v, %r9+ adcq w, %r10+ adcq $0, %r11+ adcq $0, %r12+ adcq $0, %r13++// Write back the result++ movq %r8, (z)+ movq %r9, 8(z)+ movq %r10, 16(z)+ movq %r11, 24(z)+ movq %r12, 32(z)+ movq %r13, 40(z)++// Restore registers and return++ CFI_POP(%r13)+ CFI_POP(%r12)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_deamont_p384_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_demont_p256.S view
@@ -0,0 +1,116 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert from Montgomery form z := (x / 2^256) mod p_256, assuming x reduced+// Input x[4]; output z[4]+//+// extern void bignum_demont_p256(uint64_t z[static 4],+// const uint64_t x[static 4]);+//+// This assumes the input is < p_256 for correctness. If this is not the case,+// use the variant "bignum_deamont_p256" instead.+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_demont_p256)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_demont_p256)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_demont_p256)+ .text++#define z %rdi+#define x %rsi++// Add %rdx * m into a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rcx as temporaries++#define mulpadd(high,low,m) \+ mulxq m, %rax, %rcx ; \+ adcxq %rax, low ; \+ adoxq %rcx, high++S2N_BN_SYMBOL(bignum_demont_p256):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save one more register to play with++ CFI_PUSH(%rbx)++// Set up an initial 4-word window [%r11,%r10,%r9,%r8] = x++ movq (x), %r8+ movq 8(x), %r9+ movq 16(x), %r10+ movq 24(x), %r11++// Fill in two zeros to the left++ xorq %rbx, %rbx+ xorq %rsi, %rsi++// Montgomery reduce windows 0 and 1 together++ movq $0x0000000100000000, %rdx+ mulpadd(%r10,%r9,%r8)+ mulpadd(%r11,%r10,%r9)+ movq $0xffffffff00000001, %rdx+ mulpadd(%rbx,%r11,%r8)+ mulpadd(%rsi,%rbx,%r9)+ movl $0, %r8d+ adcxq %r8, %rsi++// Append just one more leading zero (by the above %r8 = 0 already).++ xorq %r9, %r9++// Montgomery reduce windows 2 and 3 together++ movq $0x0000000100000000, %rdx+ mulpadd(%rbx,%r11,%r10)+ mulpadd(%rsi,%rbx,%r11)+ movq $0xffffffff00000001, %rdx+ mulpadd(%r8,%rsi,%r10)+ mulpadd(%r9,%r8,%r11)+ movl $0, %r10d+ adcxq %r10, %r9++// Since the input was assumed reduced modulo, i.e. < p, we actually know that+// 2^256 * [carries; %r9;%r8;%rsi;%rbx] is <= (p - 1) + (2^256 - 1) p+// and hence [carries; %r9;%r8;%rsi;%rbx] < p. This means in fact carries = 0+// and [%r9;%r8;%rsi;%rbx] is already our answer, without further correction.+// Write that back.++ movq %rbx, (z)+ movq %rsi, 8(z)+ movq %r8, 16(z)+ movq %r9, 24(z)++// Restore saved register and return++ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_demont_p256)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_demont_p256_alt.S view
@@ -0,0 +1,134 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert from Montgomery form z := (x / 2^256) mod p_256, assuming x reduced+// Input x[4]; output z[4]+//+// extern void bignum_demont_p256_alt(uint64_t z[static 4],+// const uint64_t x[static 4]);+//+// This assumes the input is < p_256 for correctness. If this is not the case,+// use the variant "bignum_deamont_p256" instead.+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_demont_p256_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_demont_p256_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_demont_p256_alt)+ .text++#define z %rdi+#define x %rsi++// Add %rdx * m into a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rcx as temporaries++#define mulpado(high,low,m) \+ mulxq m, %rax, %rcx ; \+ adcxq %rax, low ; \+ adoxq %rcx, high++// Add %rcx * m into a register-pair (high,low) maintaining consistent+// carry-catching with carry (negated, as bitmask) and using %rax and %rdx+// as temporaries++#define mulpadd(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rcx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// Initial version assuming no carry-in++#define mulpadi(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rcx; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// Version with no carry in or out++#define mulpadn(high,low,m) \+ movq m, %rax ; \+ mulq %rcx; \+ addq %rax, low ; \+ adcq %rdx, high++S2N_BN_SYMBOL(bignum_demont_p256_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Set up an initial 4-word window [%r11,%r10,%r9,%r8] = x++ movq (x), %r8+ movq 8(x), %r9+ movq 16(x), %r10+ movq 24(x), %r11++// Load constant 2^32; %rcx toggles between this and (1 - %rcx) below++ movq $0x0000000100000000, %rcx++// Montgomery reduce windows 0 and 1 together as [%r8;%rsi;%r11;%r10]++ mulpadi(%rsi,%r10,%r9,%r8)+ mulpadd(%rsi,%r11,%r10,%r9)+ negq %rcx+ negq %rsi+ incq %rcx+ mulpadi(%r8,%rsi,%r11,%r8)+ negq %r8+ mulpadn(%r8,%rsi,%r9)++// Montgomery reduce windows 2 and 3 together as [%r10;%r9;%r8;%rsi]++ negq %rcx+ incq %rcx+ mulpadi(%r9,%rsi,%r11,%r10)+ mulpadd(%r9,%r8,%rsi,%r11)+ negq %rcx+ negq %r9+ incq %rcx+ mulpadi(%r10,%r9,%r8,%r10)+ negq %r10+ mulpadn(%r10,%r9,%r11)++// Since the input was assumed reduced modulo, i.e. < p, we actually know that+// 2^256 * [carries; %r10;%r9;%r8;%rsi] is <= (p - 1) + (2^256 - 1) p+// and hence [carries; %r10;%r9;%r8;%rsi] < p. This means in fact carries = 0+// and [%r10;%r9;%r8;%rsi] is already our answer, without further correction.+// Write that back.++ movq %rsi, (z)+ movq %r8, 8(z)+ movq %r9, 16(z)+ movq %r10, 24(z)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_demont_p256_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_emontredc_8n.S view
@@ -0,0 +1,427 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Extended Montgomery reduce in 8-digit blocks, results in input-output buffer+// Inputs z[2*k], m[k], w; outputs function return (extra result bit) and z[2*k]+//+// extern uint64_t bignum_emontredc_8n(uint64_t k, uint64_t *z, const uint64_t *m,+// uint64_t w);+//+// Functionally equivalent to bignum_emontredc (see that file for more detail).+// But in general assumes that the input k is a multiple of 8.+//+// Standard x86-64 ABI: RDI = k, RSI = z, RDX = m, RCX = w, returns RAX+// Microsoft x64 ABI: RCX = k, RDX = z, R8 = m, R9 = w, returns RAX+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_emontredc_8n)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_emontredc_8n)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_emontredc_8n)+ .text+ .balign 32++// Original input parameters are here++#define z %rsi+#define w %rcx++// This is copied in early once we stash away k++#define m %rdi++// A variable z pointer++#define zz %rbp++// Stack-based variables++#define carry (%rsp)+#define innercount 8(%rsp)+#define outercount 16(%rsp)+#define k8m1 24(%rsp)++// -----------------------------------------------------------------------------+// Standard macros as used in pure multiplier arrays+// -----------------------------------------------------------------------------++// mulpadd i, j adds z[i] * rdx (now assumed = m[j]) into the window at i+j++.macro mulpadd arg1,arg2+ mulxq 8*\arg1(z), %rax, %rbx+.if ((\arg1 + \arg2) % 8 == 0)+ adcxq %rax, %r8+ adoxq %rbx, %r9+.elseif ((\arg1 + \arg2) % 8 == 1)+ adcxq %rax, %r9+ adoxq %rbx, %r10+.elseif ((\arg1 + \arg2) % 8 == 2)+ adcxq %rax, %r10+ adoxq %rbx, %r11+.elseif ((\arg1 + \arg2) % 8 == 3)+ adcxq %rax, %r11+ adoxq %rbx, %r12+.elseif ((\arg1 + \arg2) % 8 == 4)+ adcxq %rax, %r12+ adoxq %rbx, %r13+.elseif ((\arg1 + \arg2) % 8 == 5)+ adcxq %rax, %r13+ adoxq %rbx, %r14+.elseif ((\arg1 + \arg2) % 8 == 6)+ adcxq %rax, %r14+ adoxq %rbx, %r15+.elseif ((\arg1 + \arg2) % 8 == 7)+ adcxq %rax, %r15+ adoxq %rbx, %r8+.endif++.endm++// addrow i adds z[i] + zz[0..7] * m[j] into the window++.macro addrow arg1+ movq 8*\arg1(m), %rdx+ xorl %eax, %eax // Get a known flag state++.if (\arg1 % 8 == 0)+ adoxq 8*\arg1(zz), %r8+.elseif (\arg1 % 8 == 1)+ adoxq 8*\arg1(zz), %r9+.elseif (\arg1 % 8 == 2)+ adoxq 8*\arg1(zz), %r10+.elseif (\arg1 % 8 == 3)+ adoxq 8*\arg1(zz), %r11+.elseif (\arg1 % 8 == 4)+ adoxq 8*\arg1(zz), %r12+.elseif (\arg1 % 8 == 5)+ adoxq 8*\arg1(zz), %r13+.elseif (\arg1 % 8 == 6)+ adoxq 8*\arg1(zz), %r14+.elseif (\arg1 % 8 == 7)+ adoxq 8*\arg1(zz), %r15+.endif++ mulpadd 0, \arg1++.if (\arg1 % 8 == 0)+ movq %r8, 8*\arg1(zz)+ movl $0, %r8d+.elseif (\arg1 % 8 == 1)+ movq %r9, 8*\arg1(zz)+ movl $0, %r9d+.elseif (\arg1 % 8 == 2)+ movq %r10, 8*\arg1(zz)+ movl $0, %r10d+.elseif (\arg1 % 8 == 3)+ movq %r11, 8*\arg1(zz)+ movl $0, %r11d+.elseif (\arg1 % 8 == 4)+ movq %r12, 8*\arg1(zz)+ movl $0, %r12d+.elseif (\arg1 % 8 == 5)+ movq %r13, 8*\arg1(zz)+ movl $0, %r13d+.elseif (\arg1 % 8 == 6)+ movq %r14, 8*\arg1(zz)+ movl $0, %r14d+.elseif (\arg1 % 8 == 7)+ movq %r15, 8*\arg1(zz)+ movl $0, %r15d+.endif++ mulpadd 1, \arg1+ mulpadd 2, \arg1+ mulpadd 3, \arg1+ mulpadd 4, \arg1+ mulpadd 5, \arg1+ mulpadd 6, \arg1+ mulpadd 7, \arg1++.if (\arg1 % 8 == 0)+ adcq $0, %r8+.elseif (\arg1 % 8 == 1)+ adcq $0, %r9+.elseif (\arg1 % 8 == 2)+ adcq $0, %r10+.elseif (\arg1 % 8 == 3)+ adcq $0, %r11+.elseif (\arg1 % 8 == 4)+ adcq $0, %r12+.elseif (\arg1 % 8 == 5)+ adcq $0, %r13+.elseif (\arg1 % 8 == 6)+ adcq $0, %r14+.elseif (\arg1 % 8 == 7)+ adcq $0, %r15+.endif+++.endm++// -----------------------------------------------------------------------------+// Anti-matter versions with z and m switched, and also not writing back the z+// words, but the inverses instead, *and* also adding in the z[0..7] at the+// beginning. The aim is to use this in Montgomery where we discover z[j]+// entries as we go along.+// -----------------------------------------------------------------------------++.macro mulpadda arg1,arg2+ mulxq 8*\arg1(m), %rax, %rbx+.if ((\arg1 + \arg2) % 8 == 0)+ adcxq %rax, %r8+ adoxq %rbx, %r9+.elseif ((\arg1 + \arg2) % 8 == 1)+ adcxq %rax, %r9+ adoxq %rbx, %r10+.elseif ((\arg1 + \arg2) % 8 == 2)+ adcxq %rax, %r10+ adoxq %rbx, %r11+.elseif ((\arg1 + \arg2) % 8 == 3)+ adcxq %rax, %r11+ adoxq %rbx, %r12+.elseif ((\arg1 + \arg2) % 8 == 4)+ adcxq %rax, %r12+ adoxq %rbx, %r13+.elseif ((\arg1 + \arg2) % 8 == 5)+ adcxq %rax, %r13+ adoxq %rbx, %r14+.elseif ((\arg1 + \arg2) % 8 == 6)+ adcxq %rax, %r14+ adoxq %rbx, %r15+.elseif ((\arg1 + \arg2) % 8 == 7)+ adcxq %rax, %r15+ adoxq %rbx, %r8+.endif++.endm++.macro adurowa arg1+ movq w, %rdx // Get the word-level modular inverse+ xorl %eax, %eax // Get a known flag state+.if (\arg1 % 8 == 0)+ mulxq %r8, %rdx, %rax+.elseif (\arg1 % 8 == 1)+ mulxq %r9, %rdx, %rax+.elseif (\arg1 % 8 == 2)+ mulxq %r10, %rdx, %rax+.elseif (\arg1 % 8 == 3)+ mulxq %r11, %rdx, %rax+.elseif (\arg1 % 8 == 4)+ mulxq %r12, %rdx, %rax+.elseif (\arg1 % 8 == 5)+ mulxq %r13, %rdx, %rax+.elseif (\arg1 % 8 == 6)+ mulxq %r14, %rdx, %rax+.elseif (\arg1 % 8 == 7)+ mulxq %r15, %rdx, %rax+.endif++ movq %rdx, 8*\arg1(z) // Store multiplier word++ mulpadda 0, \arg1++ // Note that the bottom reg of the window is zero by construction+ // So it's safe just to use "mulpadda 7" here++ mulpadda 1, \arg1+ mulpadda 2, \arg1+ mulpadda 3, \arg1+ mulpadda 4, \arg1+ mulpadda 5, \arg1+ mulpadda 6, \arg1+ mulpadda 7, \arg1 // window lowest = 0 beforehand by construction++.if (\arg1 % 8 == 0)+ adcq $0, %r8+.elseif (\arg1 % 8 == 1)+ adcq $0, %r9+.elseif (\arg1 % 8 == 2)+ adcq $0, %r10+.elseif (\arg1 % 8 == 3)+ adcq $0, %r11+.elseif (\arg1 % 8 == 4)+ adcq $0, %r12+.elseif (\arg1 % 8 == 5)+ adcq $0, %r13+.elseif (\arg1 % 8 == 6)+ adcq $0, %r14+.elseif (\arg1 % 8 == 7)+ adcq $0, %r15+.endif++.endm++.macro adurowza+ movq w, %rdx // Get the word-level modular inverse+ xorl %eax, %eax // Get a known flag state++ movq (z), %r8 // %r8 = zeroth word+ mulxq %r8, %rdx, %rax // Compute multiplier word+ movq %rdx, (z) // Store multiplier word+ movq 8(z), %r9++ mulpadda 0, 0+ movq 16(z), %r10+ mulpadda 1, 0+ movq 24(z), %r11+ mulpadda 2, 0+ movq 32(z), %r12+ mulpadda 3, 0+ movq 40(z), %r13+ mulpadda 4, 0+ movq 48(z), %r14+ mulpadda 5, 0+ movq 56(z), %r15+ mulpadda 6, 0+ mulpadda 7, 0 // r8 = 0 beforehand by construction+ adcq $0, %r8+.endm++// -----------------------------------------------------------------------------+// Hybrid top, doing an 8 block specially then multiple additional 8 blocks+// -----------------------------------------------------------------------------++// Multiply-add: z := z + x[i...i+7] * m++.macro addrows++ adurowza+ adurowa 1+ adurowa 2+ adurowa 3+ adurowa 4+ adurowa 5+ adurowa 6+ adurowa 7++ movq z, zz++ movq k8m1, %rax+ testq %rax, %rax+ jz Lbignum_emontredc_8n_innerend+ movq %rax, innercount+Lbignum_emontredc_8n_innerloop:+ addq $64, zz+ addq $64, m+ addrow 0+ addrow 1+ addrow 2+ addrow 3+ addrow 4+ addrow 5+ addrow 6+ addrow 7+ subq $64, innercount+ jnz Lbignum_emontredc_8n_innerloop++ movq k8m1, %rax+Lbignum_emontredc_8n_innerend:+ subq %rax, m++ movq carry, %rbx+ negq %rbx+ adcq %r8, 64(z,%rax,1)+ adcq %r9, 72(z,%rax,1)+ adcq %r10, 80(z,%rax,1)+ adcq %r11, 88(z,%rax,1)+ adcq %r12, 96(z,%rax,1)+ adcq %r13, 104(z,%rax,1)+ adcq %r14, 112(z,%rax,1)+ adcq %r15, 120(z,%rax,1)+ movl $0, %eax+ adcq $0, %rax+ movq %rax, carry+.endm++// -----------------------------------------------------------------------------+// Main code.+// -----------------------------------------------------------------------------++S2N_BN_SYMBOL(bignum_emontredc_8n):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ movq %r9, %rcx+#endif++// Save more registers to play with++ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Pre-initialize the return value to 0 just in case of early exit below++ xorl %eax, %eax++// Divide the input k by 8, and push k8m1 = (k/8 - 1)<<6 which is used as+// the scaled inner loop counter / pointer adjustment repeatedly. Also push+// k/8 itself which is here initializing the outer loop count.++ shrq $3, %rdi+ jz Lbignum_emontredc_8n_end++ leaq -1(%rdi), %rbx+ shlq $6, %rbx+ CFI_PUSH(%rbx)+ CFI_PUSH(%rdi)++// Make space for two more variables, and set between-stages carry to 0++ CFI_DEC_RSP(16)+ movq $0, carry++// Copy m into its main home++ movq %rdx, m++// Now just systematically add in the rows++Lbignum_emontredc_8n_outerloop:+ addrows+ addq $64, z+ subq $1, outercount+ jnz Lbignum_emontredc_8n_outerloop++// Pop the carry-out "p", which was stored at [%rsp], put in %rax for return++ CFI_POP(%rax)++// Adjust the stack++ CFI_INC_RSP(24)++// Reset of epilog++Lbignum_emontredc_8n_end:++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_POP(%rbp)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_emontredc_8n)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_inv_p521.S view
@@ -0,0 +1,2093 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Modular inverse modulo p_521 = 2^521 - 1+// Input x[9]; output z[9]+//+// extern void bignum_inv_p521(uint64_t z[static 9],const uint64_t x[static 9]);+//+// Assuming the 9-digit input x is coprime to p_521, i.e. is not divisible+// by it, returns z < p_521 such that x * z == 1 (mod p_521). Note that+// x does not need to be reduced modulo p_521, but the output always is.+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_inv_p521)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_inv_p521)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_inv_p521)+ .text+ .balign 32++// Size in bytes of a 64-bit word++#define N 8++// Pointer-offset pairs for temporaries on stack++#define f 0(%rsp)+#define g (9*N)(%rsp)+#define u (18*N)(%rsp)+#define v (27*N)(%rsp)+#define tmp (36*N)(%rsp)+#define tmp2 (37*N)(%rsp)+#define i (38*N)(%rsp)+#define d (39*N)(%rsp)++#define mat (40*N)(%rsp)++// Backup for the input pointer++#define res (44*N)(%rsp)++// Total size to reserve on the stack++#define NSPACE 45*N++// Syntactic variants to make x86_att version simpler to generate++#define F 0+#define G (9*N)+#define U (18*N)+#define V (27*N)+#define MAT (40*N)++#define ff (%rsp)+#define gg (9*N)(%rsp)++// Very similar to a subroutine call to the s2n-bignum word_divstep59.+// But different in register usage and returning the final matrix as+//+// [ %r8 %r10]+// [ %r12 %r14]+//+// and also returning the matrix still negated (which doesn't matter)++#define divstep59(din,fin,gin) \+ movq din, %rsi ; \+ movq fin, %rdx ; \+ movq gin, %rcx ; \+ movq %rdx, %rbx ; \+ andq $0xfffff, %rbx ; \+ movabsq $0xfffffe0000000000, %rax ; \+ orq %rax, %rbx ; \+ andq $0xfffff, %rcx ; \+ movabsq $0xc000000000000000, %rax ; \+ orq %rax, %rcx ; \+ movq $0xfffffffffffffffe, %rax ; \+ xorl %ebp, %ebp ; \+ movl $0x2, %edx ; \+ movq %rbx, %rdi ; \+ movq %rax, %r8 ; \+ testq %rsi, %rsi ; \+ cmovs %rbp, %r8 ; \+ testq $0x1, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ sarq $1, %rcx ; \+ movl $0x100000, %eax ; \+ leaq (%rbx,%rax), %rdx ; \+ leaq (%rcx,%rax), %rdi ; \+ shlq $0x16, %rdx ; \+ shlq $0x16, %rdi ; \+ sarq $0x2b, %rdx ; \+ sarq $0x2b, %rdi ; \+ movabsq $0x20000100000, %rax ; \+ leaq (%rbx,%rax), %rbx ; \+ leaq (%rcx,%rax), %rcx ; \+ sarq $0x2a, %rbx ; \+ sarq $0x2a, %rcx ; \+ movq %rdx, MAT(%rsp) ; \+ movq %rbx, MAT+0x8(%rsp) ; \+ movq %rdi, MAT+0x10(%rsp) ; \+ movq %rcx, MAT+0x18(%rsp) ; \+ movq fin, %r12 ; \+ imulq %r12, %rdi ; \+ imulq %rdx, %r12 ; \+ movq gin, %r13 ; \+ imulq %r13, %rbx ; \+ imulq %rcx, %r13 ; \+ addq %rbx, %r12 ; \+ addq %rdi, %r13 ; \+ sarq $0x14, %r12 ; \+ sarq $0x14, %r13 ; \+ movq %r12, %rbx ; \+ andq $0xfffff, %rbx ; \+ movabsq $0xfffffe0000000000, %rax ; \+ orq %rax, %rbx ; \+ movq %r13, %rcx ; \+ andq $0xfffff, %rcx ; \+ movabsq $0xc000000000000000, %rax ; \+ orq %rax, %rcx ; \+ movq $0xfffffffffffffffe, %rax ; \+ movl $0x2, %edx ; \+ movq %rbx, %rdi ; \+ movq %rax, %r8 ; \+ testq %rsi, %rsi ; \+ cmovs %rbp, %r8 ; \+ testq $0x1, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ sarq $1, %rcx ; \+ movl $0x100000, %eax ; \+ leaq (%rbx,%rax), %r8 ; \+ leaq (%rcx,%rax), %r10 ; \+ shlq $0x16, %r8 ; \+ shlq $0x16, %r10 ; \+ sarq $0x2b, %r8 ; \+ sarq $0x2b, %r10 ; \+ movabsq $0x20000100000, %rax ; \+ leaq (%rbx,%rax), %r15 ; \+ leaq (%rcx,%rax), %r11 ; \+ sarq $0x2a, %r15 ; \+ sarq $0x2a, %r11 ; \+ movq %r13, %rbx ; \+ movq %r12, %rcx ; \+ imulq %r8, %r12 ; \+ imulq %r15, %rbx ; \+ addq %rbx, %r12 ; \+ imulq %r11, %r13 ; \+ imulq %r10, %rcx ; \+ addq %rcx, %r13 ; \+ sarq $0x14, %r12 ; \+ sarq $0x14, %r13 ; \+ movq %r12, %rbx ; \+ andq $0xfffff, %rbx ; \+ movabsq $0xfffffe0000000000, %rax ; \+ orq %rax, %rbx ; \+ movq %r13, %rcx ; \+ andq $0xfffff, %rcx ; \+ movabsq $0xc000000000000000, %rax ; \+ orq %rax, %rcx ; \+ movq MAT(%rsp), %rax ; \+ imulq %r8, %rax ; \+ movq MAT+0x10(%rsp), %rdx ; \+ imulq %r15, %rdx ; \+ imulq MAT+0x8(%rsp), %r8 ; \+ imulq MAT+0x18(%rsp), %r15 ; \+ addq %r8, %r15 ; \+ leaq (%rax,%rdx), %r9 ; \+ movq MAT(%rsp), %rax ; \+ imulq %r10, %rax ; \+ movq MAT+0x10(%rsp), %rdx ; \+ imulq %r11, %rdx ; \+ imulq MAT+0x8(%rsp), %r10 ; \+ imulq MAT+0x18(%rsp), %r11 ; \+ addq %r10, %r11 ; \+ leaq (%rax,%rdx), %r13 ; \+ movq $0xfffffffffffffffe, %rax ; \+ movl $0x2, %edx ; \+ movq %rbx, %rdi ; \+ movq %rax, %r8 ; \+ testq %rsi, %rsi ; \+ cmovs %rbp, %r8 ; \+ testq $0x1, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ sarq $1, %rcx ; \+ movl $0x100000, %eax ; \+ leaq (%rbx,%rax), %r8 ; \+ leaq (%rcx,%rax), %r12 ; \+ shlq $0x15, %r8 ; \+ shlq $0x15, %r12 ; \+ sarq $0x2b, %r8 ; \+ sarq $0x2b, %r12 ; \+ movabsq $0x20000100000, %rax ; \+ leaq (%rbx,%rax), %r10 ; \+ leaq (%rcx,%rax), %r14 ; \+ sarq $0x2b, %r10 ; \+ sarq $0x2b, %r14 ; \+ movq %r9, %rax ; \+ imulq %r8, %rax ; \+ movq %r13, %rdx ; \+ imulq %r10, %rdx ; \+ imulq %r15, %r8 ; \+ imulq %r11, %r10 ; \+ addq %r8, %r10 ; \+ leaq (%rax,%rdx), %r8 ; \+ movq %r9, %rax ; \+ imulq %r12, %rax ; \+ movq %r13, %rdx ; \+ imulq %r14, %rdx ; \+ imulq %r15, %r12 ; \+ imulq %r11, %r14 ; \+ addq %r12, %r14 ; \+ leaq (%rax,%rdx), %r12++S2N_BN_SYMBOL(bignum_inv_p521):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save registers and make room for temporaries++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++// Save the return pointer for the end so we can overwrite %rdi later++ movq %rdi, res++// Copy the prime p_521 = 2^521 - 1 into the f variable++ xorl %eax, %eax+ notq %rax+ movq %rax, F(%rsp)+ movq %rax, F+8(%rsp)+ movq %rax, F+16(%rsp)+ movq %rax, F+24(%rsp)+ movq %rax, F+32(%rsp)+ movq %rax, F+40(%rsp)+ movq %rax, F+48(%rsp)+ movq %rax, F+56(%rsp)+ movl $0x1FF, %eax+ movq %rax, F+64(%rsp)++// Copy the input into the g variable, but reduce it strictly mod p_521+// so that g <= f as assumed in the bound proof. This code fragment is+// very similar to bignum_mod_p521_9.++ movq 64(%rsi), %r8+ movl $0x1FF, %ebx+ andq %r8, %rbx+ shrq $9, %r8++ stc+ adcq (%rsi), %r8+ movq 8(%rsi), %r9+ adcq $0, %r9+ movq 16(%rsi), %r10+ adcq $0, %r10+ movq 24(%rsi), %r11+ adcq $0, %r11+ movq 32(%rsi), %r12+ adcq $0, %r12+ movq 40(%rsi), %r13+ adcq $0, %r13+ movq 48(%rsi), %r14+ adcq $0, %r14+ movq 56(%rsi), %r15+ adcq $0, %r15+ adcq $0, %rbx++ cmpq $512, %rbx++ sbbq $0, %r8+ movq %r8, G(%rsp)+ sbbq $0, %r9+ movq %r9, G+8(%rsp)+ sbbq $0, %r10+ movq %r10, G+16(%rsp)+ sbbq $0, %r11+ movq %r11, G+24(%rsp)+ sbbq $0, %r12+ movq %r12, G+32(%rsp)+ sbbq $0, %r13+ movq %r13, G+40(%rsp)+ sbbq $0, %r14+ movq %r14, G+48(%rsp)+ sbbq $0, %r15+ movq %r15, G+56(%rsp)+ sbbq $0, %rbx+ andq $0x1FF, %rbx+ movq %rbx, G+64(%rsp)++// Also maintain weakly reduced < 2*p_521 vector [u,v] such that+// [f,g] == x * 2^{1239-59*i} * [u,v] (mod p_521)+// starting with [p_521,x] == x * 2^{1239-59*0} * [0,2^-1239] (mod p_521)+// Note that because (2^{a+521} == 2^a) (mod p_521) we simply have+// (2^-1239 == 2^324) (mod p_521) so the constant initializer is simple.+//+// Based on the standard divstep bound, for inputs <= 2^b we need at least+// n >= (9437 * b + 1) / 4096. Since b is 521, that means 1201 iterations.+// Since we package divstep in multiples of 59 bits, we do 21 blocks of 59+// making *1239* total. (With a bit more effort we could avoid the full 59+// divsteps and use a shorter tail computation, but we keep it simple.)+// Hence, after the 21st iteration we have [f,g] == x * [u,v] and since+// |f| = 1 we get the modular inverse from u by flipping its sign with f.++ xorl %eax, %eax+ movq %rax, U(%rsp)+ movq %rax, U+8(%rsp)+ movq %rax, U+16(%rsp)+ movq %rax, U+24(%rsp)+ movq %rax, U+32(%rsp)+ movq %rax, U+40(%rsp)+ movq %rax, U+48(%rsp)+ movq %rax, U+56(%rsp)+ movq %rax, U+64(%rsp)++ movl $16, %ebx+ movq %rax, V(%rsp)+ movq %rax, V+8(%rsp)+ movq %rax, V+16(%rsp)+ movq %rax, V+24(%rsp)+ movq %rax, V+32(%rsp)+ movq %rbx, V+40(%rsp)+ movq %rax, V+48(%rsp)+ movq %rax, V+56(%rsp)+ movq %rax, V+64(%rsp)++// Start of main loop. We jump into the middle so that the divstep+// portion is common to the special 21st iteration after a uniform+// first 20.++ movq $21, i+ movq $1, d+ jmp Lbignum_inv_p521_midloop++Lbignum_inv_p521_loop:++// Separate out the matrix into sign-magnitude pairs++ movq %r8, %r9+ sarq $63, %r9+ xorq %r9, %r8+ subq %r9, %r8++ movq %r10, %r11+ sarq $63, %r11+ xorq %r11, %r10+ subq %r11, %r10++ movq %r12, %r13+ sarq $63, %r13+ xorq %r13, %r12+ subq %r13, %r12++ movq %r14, %r15+ sarq $63, %r15+ xorq %r15, %r14+ subq %r15, %r14++// Adjust the initial values to allow for complement instead of negation+// This initial offset is the same for [f,g] and [u,v] compositions.+// Save it in temporary storage for the [u,v] part and do [f,g] first.++ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, tmp++ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, tmp2++// Now the computation of the updated f and g values. This maintains a+// 2-word carry between stages so we can conveniently insert the shift+// right by 59 before storing back, and not overwrite digits we need+// again of the old f and g values.+//+// Digit 0 of [f,g]++ xorl %ebx, %ebx+ movq F(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq G(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq F(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq G(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp++// Digit 1 of [f,g]++ xorl %ecx, %ecx+ movq F+N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq G+N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $59, %rbx, %rdi+ movq %rdi, F(%rsp)++ xorl %edi, %edi+ movq F+N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq G+N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $59, %rbp, %rsi+ movq %rsi, G(%rsp)++// Digit 2 of [f,g]++ xorl %esi, %esi+ movq F+2*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq G+2*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $59, %rcx, %rbx+ movq %rbx, F+N(%rsp)++ xorl %ebx, %ebx+ movq F+2*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq G+2*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $59, %rdi, %rbp+ movq %rbp, G+N(%rsp)++// Digit 3 of [f,g]++ xorl %ebp, %ebp+ movq F+3*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq G+3*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $59, %rsi, %rcx+ movq %rcx, F+2*N(%rsp)++ xorl %ecx, %ecx+ movq F+3*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq G+3*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $59, %rbx, %rdi+ movq %rdi, G+2*N(%rsp)++// Digit 4 of [f,g]++ xorl %edi, %edi+ movq F+4*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq G+4*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $59, %rbp, %rsi+ movq %rsi, F+3*N(%rsp)++ xorl %esi, %esi+ movq F+4*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq G+4*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $59, %rcx, %rbx+ movq %rbx, G+3*N(%rsp)++// Digit 5 of [f,g]++ xorl %ebx, %ebx+ movq F+5*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq G+5*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $59, %rdi, %rbp+ movq %rbp, F+4*N(%rsp)++ xorl %ebp, %ebp+ movq F+5*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq G+5*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $59, %rsi, %rcx+ movq %rcx, G+4*N(%rsp)++// Digit 6 of [f,g]++ xorl %ecx, %ecx+ movq F+6*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq G+6*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $59, %rbx, %rdi+ movq %rdi, F+5*N(%rsp)++ xorl %edi, %edi+ movq F+6*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq G+6*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $59, %rbp, %rsi+ movq %rsi, G+5*N(%rsp)++// Digit 7 of [f,g]++ xorl %esi, %esi+ movq F+7*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq G+7*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $59, %rcx, %rbx+ movq %rbx, F+6*N(%rsp)++ xorl %ebx, %ebx+ movq F+7*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq G+7*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $59, %rdi, %rbp+ movq %rbp, G+6*N(%rsp)++// Digits 8 and 9 of [f,g]++ movq F+8*N(%rsp), %rax+ xorq %r9, %rax+ movq %rax, %rbp+ sarq $63, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq G+8*N(%rsp), %rax+ xorq %r11, %rax+ movq %rax, %rdx+ sarq $63, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $59, %rsi, %rcx+ movq %rcx, F+7*N(%rsp)+ shrdq $59, %rbp, %rsi++ movq F+8*N(%rsp), %rax+ movq %rsi, F+8*N(%rsp)++ xorq %r13, %rax+ movq %rax, %rsi+ sarq $63, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq G+8*N(%rsp), %rax+ xorq %r15, %rax+ movq %rax, %rdx+ sarq $63, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $59, %rbx, %rdi+ movq %rdi, G+7*N(%rsp)+ shrdq $59, %rsi, %rbx+ movq %rbx, G+8*N(%rsp)++// Get the initial carries back from storage and do the [u,v] accumulation++ movq tmp, %rbx+ movq tmp2, %rbp++// Digit 0 of [u,v]++ xorl %ecx, %ecx+ movq U(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx++ xorl %esi, %esi+ movq U(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, U(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq V(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, V(%rsp)++// Digit 1 of [u,v]++ xorl %ebx, %ebx+ movq U+N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq U+N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, U+N(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq V+N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, V+N(%rsp)++// Digit 2 of [u,v]++ xorl %ecx, %ecx+ movq U+2*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+2*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx++ xorl %esi, %esi+ movq U+2*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, U+2*N(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq V+2*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, V+2*N(%rsp)++// Digit 3 of [u,v]++ xorl %ebx, %ebx+ movq U+3*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+3*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq U+3*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, U+3*N(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq V+3*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, V+3*N(%rsp)++// Digit 4 of [u,v]++ xorl %ecx, %ecx+ movq U+4*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+4*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx++ xorl %esi, %esi+ movq U+4*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, U+4*N(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq V+4*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, V+4*N(%rsp)++// Digit 5 of [u,v]++ xorl %ebx, %ebx+ movq U+5*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+5*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq U+5*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, U+5*N(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq V+5*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, V+5*N(%rsp)++// Digit 6 of [u,v]++ xorl %ecx, %ecx+ movq U+6*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+6*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx++ xorl %esi, %esi+ movq U+6*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, U+6*N(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq V+6*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, V+6*N(%rsp)++// Digit 7 of [u,v]++ xorl %ebx, %ebx+ movq U+7*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+7*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq U+7*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, U+7*N(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq V+7*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, V+7*N(%rsp)++// Digits 8 and 9 of u (top is unsigned)++ movq U+8*N(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rcx+ andq %r8, %rcx+ negq %rcx+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+8*N(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rcx+ mulq %r10+ addq %rax, %rbx+ adcq %rcx, %rdx++// Modular reduction of u++ movq %rdx, %rax+ shldq $55, %rbx, %rdx+ sarq $63, %rax+ addq %rax, %rdx+ movq %rdx, %rax+ shlq $9, %rdx+ subq %rdx, %rbx+ movq %rax, %rdx+ sarq $63, %rax+ movq U(%rsp), %rcx+ addq %rdx, %rcx+ movq %rcx, U(%rsp)+ movq U+N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+N(%rsp)+ movq U+2*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+2*N(%rsp)+ movq U+3*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+3*N(%rsp)+ movq U+4*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+4*N(%rsp)+ movq U+5*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+5*N(%rsp)+ movq U+6*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+6*N(%rsp)+ movq U+7*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+7*N(%rsp)+ adcq %rax, %rbx++// Preload for last use of old u digit 8++ movq U+8*N(%rsp), %rax+ movq %rbx, U+8*N(%rsp)++// Digits 8 and 9 of v (top is unsigned)++ xorq %r13, %rax+ movq %r13, %rbx+ andq %r12, %rbx+ negq %rbx+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rbx+ movq V+8*N(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rbx+ mulq %r14+ addq %rax, %rbp+ adcq %rbx, %rdx++// Modular reduction of v++ movq %rdx, %rax+ shldq $55, %rbp, %rdx+ sarq $63, %rax+ addq %rax, %rdx+ movq %rdx, %rax+ shlq $9, %rdx+ subq %rdx, %rbp+ movq %rax, %rdx+ sarq $63, %rax+ movq V(%rsp), %rcx+ addq %rdx, %rcx+ movq %rcx, V(%rsp)+ movq V+N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, V+N(%rsp)+ movq V+2*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, V+2*N(%rsp)+ movq V+3*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, V+3*N(%rsp)+ movq V+4*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, V+4*N(%rsp)+ movq V+5*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, V+5*N(%rsp)+ movq V+6*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, V+6*N(%rsp)+ movq V+7*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, V+7*N(%rsp)+ adcq %rax, %rbp+ movq %rbp, V+8*N(%rsp)++Lbignum_inv_p521_midloop:++ divstep59(d,ff,gg)+ movq %rsi, d++// Next iteration++ decq i+ jnz Lbignum_inv_p521_loop++// The 21st and last iteration does not need anything except the+// u value and the sign of f; the latter can be obtained from the+// lowest word of f. So it's done differently from the main loop.+// Find the sign of the new f. For this we just need one digit+// since we know (for in-scope cases) that f is either +1 or -1.+// We don't explicitly shift right by 59 either, but looking at+// bit 63 (or any bit >= 60) of the unshifted result is enough+// to distinguish -1 from +1; this is then made into a mask.++ movq F(%rsp), %rax+ movq G(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $63, %rax++// Now separate out the matrix into sign-magnitude pairs+// and adjust each one based on the sign of f.+//+// Note that at this point we expect |f|=1 and we got its+// sign above, so then since [f,0] == x * [u,v] (mod p_521)+// we want to flip the sign of u according to that of f.++ movq %r8, %r9+ sarq $63, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9++ movq %r10, %r11+ sarq $63, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11++ movq %r12, %r13+ sarq $63, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13++ movq %r14, %r15+ sarq $63, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15++// Adjust the initial value to allow for complement instead of negation++ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rbx+ andq %r11, %rbx+ addq %rax, %rbx++// Digit 0 of u++ xorl %ecx, %ecx+ movq U(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ movq %rbx, U(%rsp)+ adcq %rdx, %rcx++// Digit 1 of u++ xorl %ebx, %ebx+ movq U+N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ movq %rcx, U+N(%rsp)+ adcq %rdx, %rbx++// Digit 2 of u++ xorl %ecx, %ecx+ movq U+2*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+2*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ movq %rbx, U+2*N(%rsp)+ adcq %rdx, %rcx++// Digit 3 of u++ xorl %ebx, %ebx+ movq U+3*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+3*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ movq %rcx, U+3*N(%rsp)+ adcq %rdx, %rbx++// Digit 4 of u++ xorl %ecx, %ecx+ movq U+4*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+4*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ movq %rbx, U+4*N(%rsp)+ adcq %rdx, %rcx++// Digit 5 of u++ xorl %ebx, %ebx+ movq U+5*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+5*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ movq %rcx, U+5*N(%rsp)+ adcq %rdx, %rbx++// Digit 6 of u++ xorl %ecx, %ecx+ movq U+6*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+6*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ movq %rbx, U+6*N(%rsp)+ adcq %rdx, %rcx++// Digit 7 of u++ xorl %ebx, %ebx+ movq U+7*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+7*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ movq %rcx, U+7*N(%rsp)+ adcq %rdx, %rbx++// Digits 8 and 9 of u (top is unsigned)++ movq U+8*N(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rcx+ andq %r8, %rcx+ negq %rcx+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+8*N(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rcx+ mulq %r10+ addq %rax, %rbx+ adcq %rcx, %rdx++// Modular reduction of u++ movq %rdx, %rax+ shldq $55, %rbx, %rdx+ sarq $63, %rax+ addq %rax, %rdx+ movq %rdx, %rax+ shlq $9, %rdx+ subq %rdx, %rbx+ movq %rax, %rdx+ sarq $63, %rax+ movq U(%rsp), %rcx+ addq %rdx, %rcx+ movq %rcx, U(%rsp)+ movq U+N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+N(%rsp)+ movq U+2*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+2*N(%rsp)+ movq U+3*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+3*N(%rsp)+ movq U+4*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+4*N(%rsp)+ movq U+5*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+5*N(%rsp)+ movq U+6*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+6*N(%rsp)+ movq U+7*N(%rsp), %rcx+ adcq %rax, %rcx+ movq %rcx, U+7*N(%rsp)+ adcq %rax, %rbx+ movq %rbx, U+8*N(%rsp)++// Further strict reduction ready for the output, which just means+// a conditional subtraction of p_521++ xorl %eax, %eax+ notq %rax+ movq U(%rsp), %r8+ subq %rax, %r8+ movq U+N(%rsp), %r9+ sbbq %rax, %r9+ movq U+2*N(%rsp), %r10+ sbbq %rax, %r10+ movq U+3*N(%rsp), %r11+ sbbq %rax, %r11+ movq U+4*N(%rsp), %r12+ sbbq %rax, %r12+ movq U+5*N(%rsp), %r13+ sbbq %rax, %r13+ movq U+6*N(%rsp), %r14+ sbbq %rax, %r14+ movq U+7*N(%rsp), %r15+ sbbq %rax, %r15+ movl $0x1FF, %eax+ movq U+8*N(%rsp), %rbp+ sbbq %rax, %rbp++ cmovcq U(%rsp), %r8+ cmovcq U+N(%rsp), %r9+ cmovcq U+2*N(%rsp), %r10+ cmovcq U+3*N(%rsp), %r11+ cmovcq U+4*N(%rsp), %r12+ cmovcq U+5*N(%rsp), %r13+ cmovcq U+6*N(%rsp), %r14+ cmovcq U+7*N(%rsp), %r15+ cmovcq U+8*N(%rsp), %rbp++// Store it back to the final output++ movq res, %rdi+ movq %r8, (%rdi)+ movq %r9, N(%rdi)+ movq %r10, 2*N(%rdi)+ movq %r11, 3*N(%rdi)+ movq %r12, 4*N(%rdi)+ movq %r13, 5*N(%rdi)+ movq %r14, 6*N(%rdi)+ movq %r15, 7*N(%rdi)+ movq %rbp, 8*N(%rdi)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_inv_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/bignum_kmul_16_32.S view
@@ -0,0 +1,513 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Multiply z := x * y+// Inputs x[16], y[16]; output z[32]; temporary buffer t[>=32]+//+// extern void bignum_kmul_16_32(uint64_t z[static 32],+// const uint64_t x[static 16],+// const uint64_t y[static 16],+// uint64_t t[static 32]);+//+// In this x86 code the final temporary space argument t is unused, but+// it is retained in the prototype above for API consistency with ARM.+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = y, RCX = t+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = y, R9 = t+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_kmul_16_32)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_kmul_16_32)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_kmul_16_32)+ .text++// These parameters are kept where they come in++#define z %rdi+#define x %rsi++// This one gets moved to free up %rdx for muls++#define y %rcx++// Often used for zero++#define zero %rbp+#define zeroe %ebp++// mulpadd i, j adds x[i] * rdx (now assumed = y[j]) into the window at i+j++.macro mulpadd arg1,arg2+ mulxq 8*\arg1(x), %rax, %rbx+.if ((\arg1 + \arg2) % 8 == 0)+ adcxq %rax, %r8+ adoxq %rbx, %r9+.elseif ((\arg1 + \arg2) % 8 == 1)+ adcxq %rax, %r9+ adoxq %rbx, %r10+.elseif ((\arg1 + \arg2) % 8 == 2)+ adcxq %rax, %r10+ adoxq %rbx, %r11+.elseif ((\arg1 + \arg2) % 8 == 3)+ adcxq %rax, %r11+ adoxq %rbx, %r12+.elseif ((\arg1 + \arg2) % 8 == 4)+ adcxq %rax, %r12+ adoxq %rbx, %r13+.elseif ((\arg1 + \arg2) % 8 == 5)+ adcxq %rax, %r13+ adoxq %rbx, %r14+.elseif ((\arg1 + \arg2) % 8 == 6)+ adcxq %rax, %r14+ adoxq %rbx, %r15+.elseif ((\arg1 + \arg2) % 8 == 7)+ adcxq %rax, %r15+ adoxq %rbx, %r8+.endif++.endm++// mulpade i, j adds x[i] * rdx (now assumed = y[j]) into the window at i+j+// but re-creates the top word assuming nothing to add there++.macro mulpade arg1,arg2+.if ((\arg1 + \arg2) % 8 == 0)+ mulxq 8*\arg1(x), %rax, %r9+ adcxq %rax, %r8+ adoxq zero, %r9+.elseif ((\arg1 + \arg2) % 8 == 1)+ mulxq 8*\arg1(x), %rax, %r10+ adcxq %rax, %r9+ adoxq zero, %r10+.elseif ((\arg1 + \arg2) % 8 == 2)+ mulxq 8*\arg1(x), %rax, %r11+ adcxq %rax, %r10+ adoxq zero, %r11+.elseif ((\arg1 + \arg2) % 8 == 3)+ mulxq 8*\arg1(x), %rax, %r12+ adcxq %rax, %r11+ adoxq zero, %r12+.elseif ((\arg1 + \arg2) % 8 == 4)+ mulxq 8*\arg1(x), %rax, %r13+ adcxq %rax, %r12+ adoxq zero, %r13+.elseif ((\arg1 + \arg2) % 8 == 5)+ mulxq 8*\arg1(x), %rax, %r14+ adcxq %rax, %r13+ adoxq zero, %r14+.elseif ((\arg1 + \arg2) % 8 == 6)+ mulxq 8*\arg1(x), %rax, %r15+ adcxq %rax, %r14+ adoxq zero, %r15+.elseif ((\arg1 + \arg2) % 8 == 7)+ mulxq 8*\arg1(x), %rax, %r8+ adcxq %rax, %r15+ adoxq zero, %r8+.endif++.endm++// addrow i adds z[i] + x[0..7] * y[i] into the window++.macro addrow arg1+ movq 8*\arg1(y), %rdx+ xorl zeroe, zeroe++.if (\arg1 % 8 == 0)+ adoxq 8*\arg1(z), %r8+.elseif (\arg1 % 8 == 1)+ adoxq 8*\arg1(z), %r9+.elseif (\arg1 % 8 == 2)+ adoxq 8*\arg1(z), %r10+.elseif (\arg1 % 8 == 3)+ adoxq 8*\arg1(z), %r11+.elseif (\arg1 % 8 == 4)+ adoxq 8*\arg1(z), %r12+.elseif (\arg1 % 8 == 5)+ adoxq 8*\arg1(z), %r13+.elseif (\arg1 % 8 == 6)+ adoxq 8*\arg1(z), %r14+.elseif (\arg1 % 8 == 7)+ adoxq 8*\arg1(z), %r15+.endif++ mulpadd 0, \arg1++.if (\arg1 % 8 == 0)+ movq %r8, 8*\arg1(z)+.elseif (\arg1 % 8 == 1)+ movq %r9, 8*\arg1(z)+.elseif (\arg1 % 8 == 2)+ movq %r10, 8*\arg1(z)+.elseif (\arg1 % 8 == 3)+ movq %r11, 8*\arg1(z)+.elseif (\arg1 % 8 == 4)+ movq %r12, 8*\arg1(z)+.elseif (\arg1 % 8 == 5)+ movq %r13, 8*\arg1(z)+.elseif (\arg1 % 8 == 6)+ movq %r14, 8*\arg1(z)+.elseif (\arg1 % 8 == 7)+ movq %r15, 8*\arg1(z)+.endif++ mulpadd 1, \arg1+ mulpadd 2, \arg1+ mulpadd 3, \arg1+ mulpadd 4, \arg1+ mulpadd 5, \arg1+ mulpadd 6, \arg1+ mulpade 7, \arg1++.if (\arg1 % 8 == 0)+ adcq zero, %r8+.elseif (\arg1 % 8 == 1)+ adcq zero, %r9+.elseif (\arg1 % 8 == 2)+ adcq zero, %r10+.elseif (\arg1 % 8 == 3)+ adcq zero, %r11+.elseif (\arg1 % 8 == 4)+ adcq zero, %r12+.elseif (\arg1 % 8 == 5)+ adcq zero, %r13+.elseif (\arg1 % 8 == 6)+ adcq zero, %r14+.elseif (\arg1 % 8 == 7)+ adcq zero, %r15+.endif++.endm++// Special zero version of addrow, setting up the window from scratch++.macro addrowz+ movq (y), %rdx+ xorl zeroe, zeroe++ mulxq (x), %rax, %r9+ adcq %rax, (z)++ mulxq 8(x), %rax, %r10+ adcq %rax, %r9++ mulxq 16(x), %rax, %r11+ adcq %rax, %r10++ mulxq 24(x), %rax, %r12+ adcq %rax, %r11++ mulxq 32(x), %rax, %r13+ adcq %rax, %r12++ mulxq 40(x), %rax, %r14+ adcq %rax, %r13++ mulxq 48(x), %rax, %r15+ adcq %rax, %r14++ mulxq 56(x), %rax, %r8+ adcq %rax, %r15++ adcq zero, %r8+.endm++// This is a variant where we add the initial z[0..7] at the outset.+// This makes the initialization process a bit less wasteful. By doing+// a block of 8 we get the same effect except that we add z[0..7]+//+// adurow i adds 2^{7*64} * z[i+7] + x[0..7] * y[i] into the window++.macro adurow arg1+ movq 8*\arg1(y), %rdx+ xorl zeroe, zeroe++ mulpadd 0, \arg1++.if (\arg1 % 8 == 0)+ movq %r8, 8*\arg1(z)+.elseif (\arg1 % 8 == 1)+ movq %r9, 8*\arg1(z)+.elseif (\arg1 % 8 == 2)+ movq %r10, 8*\arg1(z)+.elseif (\arg1 % 8 == 3)+ movq %r11, 8*\arg1(z)+.elseif (\arg1 % 8 == 4)+ movq %r12, 8*\arg1(z)+.elseif (\arg1 % 8 == 5)+ movq %r13, 8*\arg1(z)+.elseif (\arg1 % 8 == 6)+ movq %r14, 8*\arg1(z)+.elseif (\arg1 % 8 == 7)+ movq %r15, 8*\arg1(z)+.endif++ mulpadd 1, \arg1+ mulpadd 2, \arg1+ mulpadd 3, \arg1+ mulpadd 4, \arg1+ mulpadd 5, \arg1+ mulpadd 6, \arg1+ mulpade 7, \arg1++.if (\arg1 % 8 == 0)+ adcq zero, %r8+.elseif (\arg1 % 8 == 1)+ adcq zero, %r9+.elseif (\arg1 % 8 == 2)+ adcq zero, %r10+.elseif (\arg1 % 8 == 3)+ adcq zero, %r11+.elseif (\arg1 % 8 == 4)+ adcq zero, %r12+.elseif (\arg1 % 8 == 5)+ adcq zero, %r13+.elseif (\arg1 % 8 == 6)+ adcq zero, %r14+.elseif (\arg1 % 8 == 7)+ adcq zero, %r15+.endif++.endm++// Special "adurow 0" case to do first stage++.macro adurowz+ movq (y), %rdx+ xorl zeroe, zeroe++ movq (z), %r8+ movq 8(z), %r9++ mulpadd 0, 0+ movq %r8, (z)++ movq 16(z), %r10+ mulpadd 1, 0+ movq 24(z), %r11+ mulpadd 2, 0+ movq 32(z), %r12+ mulpadd 3, 0+ movq 40(z), %r13+ mulpadd 4, 0+ movq 48(z), %r14+ mulpadd 5, 0+ movq 56(z), %r15+ mulpadd 6, 0++ mulxq 56(x), %rax, %r8+ adcxq %rax, %r15+ adoxq zero, %r8+ adcxq zero, %r8+.endm++// Multiply-add: z := z + x[0..7] * y++.macro addrows+ adurowz+ adurow 1+ adurow 2+ adurow 3+ adurow 4+ adurow 5+ adurow 6+ adurow 7+ addrow 8+ addrow 9+ addrow 10+ addrow 11+ addrow 12+ addrow 13+ addrow 14+ addrow 15++ movq %r8, 128(z)+ movq %r9, 136(z)+ movq %r10, 144(z)+ movq %r11, 152(z)+ movq %r12, 160(z)+ movq %r13, 168(z)+ movq %r14, 176(z)+ movq %r15, 184(z)++.endm++// mulrow i adds x[0..7] * y[i] into the window+// just like addrow but no addition of z[i]++.macro mulrow arg1+ movq 8*\arg1(y), %rdx+ xorl zeroe, zeroe++ mulpadd 0, \arg1++.if (\arg1 % 8 == 0)+ movq %r8, 8*\arg1(z)+.elseif (\arg1 % 8 == 1)+ movq %r9, 8*\arg1(z)+.elseif (\arg1 % 8 == 2)+ movq %r10, 8*\arg1(z)+.elseif (\arg1 % 8 == 3)+ movq %r11, 8*\arg1(z)+.elseif (\arg1 % 8 == 4)+ movq %r12, 8*\arg1(z)+.elseif (\arg1 % 8 == 5)+ movq %r13, 8*\arg1(z)+.elseif (\arg1 % 8 == 6)+ movq %r14, 8*\arg1(z)+.elseif (\arg1 % 8 == 7)+ movq %r15, 8*\arg1(z)+.endif++ mulpadd 1, \arg1+ mulpadd 2, \arg1+ mulpadd 3, \arg1+ mulpadd 4, \arg1+ mulpadd 5, \arg1+ mulpadd 6, \arg1+ mulpade 7, \arg1++.if (\arg1 % 8 == 0)+ adcq zero, %r8+.elseif (\arg1 % 8 == 1)+ adcq zero, %r9+.elseif (\arg1 % 8 == 2)+ adcq zero, %r10+.elseif (\arg1 % 8 == 3)+ adcq zero, %r11+.elseif (\arg1 % 8 == 4)+ adcq zero, %r12+.elseif (\arg1 % 8 == 5)+ adcq zero, %r13+.elseif (\arg1 % 8 == 6)+ adcq zero, %r14+.elseif (\arg1 % 8 == 7)+ adcq zero, %r15+.endif+++.endm++// Special zero version of mulrow, setting up the window from scratch++.macro mulrowz+ movq (y), %rdx+ xorl zeroe, zeroe++ mulxq (x), %rax, %r9+ movq %rax, (z)++ mulxq 8(x), %rax, %r10+ adcxq %rax, %r9++ mulxq 16(x), %rax, %r11+ adcxq %rax, %r10++ mulxq 24(x), %rax, %r12+ adcxq %rax, %r11++ mulxq 32(x), %rax, %r13+ adcxq %rax, %r12++ mulxq 40(x), %rax, %r14+ adcxq %rax, %r13++ mulxq 48(x), %rax, %r15+ adcxq %rax, %r14++ mulxq 56(x), %rax, %r8+ adcxq %rax, %r15++ adcq zero, %r8+.endm++// Multiply-add: z := x[0..7] * y plus window++.macro mulrows+ mulrowz+ mulrow 1+ mulrow 2+ mulrow 3+ mulrow 4+ mulrow 5+ mulrow 6+ mulrow 7++ mulrow 8+ mulrow 9+ mulrow 10+ mulrow 11+ mulrow 12+ mulrow 13+ mulrow 14+ mulrow 15++ movq %r8, 128(z)+ movq %r9, 136(z)+ movq %r10, 144(z)+ movq %r11, 152(z)+ movq %r12, 160(z)+ movq %r13, 168(z)+ movq %r14, 176(z)+ movq %r15, 184(z)++.endm+++S2N_BN_SYMBOL(bignum_kmul_16_32):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save more registers to play with++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Move y into its permanent home, freeing up %rdx for its special role in muls++ movq %rdx, y++// Do the zeroth row as a pure product then the next as multiply-add++ mulrows++ addq $64, z+ addq $64, x+ addrows++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_kmul_16_32)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_kmul_32_64.S view
@@ -0,0 +1,1161 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Multiply z := x * y+// Inputs x[32], y[32]; output z[64]; temporary buffer t[>=96]+//+// extern void bignum_kmul_32_64(uint64_t z[static 64],+// const uint64_t x[static 32],+// const uint64_t y[static 32],+// uint64_t t[static 96]);+//+// This is a Karatsuba-style function multiplying half-sized results+// internally and using temporary buffer t for intermediate results. The size+// of 96 is an overstatement for compatibility with the ARM version; it+// actually only uses 65 elements of t (64 + 1 for a stashed sign).+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = y, RCX = t+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = y, R9 = t+// -----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_kmul_32_64)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_kmul_32_64)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_kmul_32_64)+++ .text++#define K 16++#define z %rdi+#define x %rsi+#define y %rcx++#define s %r9++// We re-use the y variable to point at t later on, when this seems clearer++#define t %rcx++S2N_BN_SYMBOL(bignum_kmul_32_64):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ movq %r9, %rcx+#endif++// Save callee-saved registers and also push t onto the stack; we'll+// use this space to back up both t and later z. Then move the y variable+// into its longer-term home for the first few stages.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_PUSH(%rcx)+ movq %rdx, y++// Multiply the low halves++ CFI_CALL(Lbignum_kmul_32_64_local_bignum_kmul_16_32)++// Multiply the high halves++ leaq 16*K-0x40(%rdi), %rdi+ leaq 8*K-0x40(%rsi), %rsi+ leaq 8*K(%rcx), %rcx+ CFI_CALL(Lbignum_kmul_32_64_local_bignum_kmul_16_32)++// Establish %r8 as the t pointer and use the cell to back up z now++ movq (%rsp), %r8+ subq $16*K+0x40, %rdi+ movq %rdi, (%rsp)++// Form |x_lo - x_hi| starting at t++ movq -8*K-0x40(%rsi), %rax+ subq -8*K-0x40+8*K(%rsi), %rax+ movq %rax, (%r8)+ .set I, 1+ .rep K-1+ movq -8*K-0x40+8*I(%rsi), %rax+ sbbq -8*K-0x40+8*K+8*I(%rsi), %rax+ movq %rax, 8*I(%r8)+ .set I, (I+1)+ .endr++ movl $0, %ebx+ sbbq s, s // Maintain CF, set ZF for cmovs, record sign++ .set I, 0+ .rep K+ movq 8*I(%r8), %rdx+ movq %rdx, %rax+ notq %rdx+ cmovzq %rax, %rdx+ adcxq %rbx, %rdx+ movq %rdx, 8*I(%r8)+ .set I, (I+1)+ .endr++// Form |y_hi - y_lo| (note opposite order) starting at t[K]++ movq -8*K+8*K(%rcx), %rax+ subq -8*K(%rcx), %rax+ movq %rax, 8*K(%r8)+ .set I, 1+ .rep K-1+ movq -8*K+8*K+8*I(%rcx), %rax+ sbbq -8*K+8*I(%rcx), %rax+ movq %rax, 8*K+8*I(%r8)+ .set I, (I+1)+ .endr++ movl $0, %ebx+ sbbq %rbp, %rbp // Maintain CF, set ZF for cmovs++ .set I, 0+ .rep K+ movq 8*K+8*I(%r8), %rdx+ movq %rdx, %rax+ notq %rdx+ cmovzq %rax, %rdx+ adcxq %rbx, %rdx+ movq %rdx, 8*K+8*I(%r8)+ .set I, (I+1)+ .endr++// Stash the final sign with which to add things at t[4*K]++ xorq %rbp, s+ movq s, 32*K(%r8)++// Multiply the absolute differences, putting the result at t[2*K]+// This has the side-effect of putting t in the "right" register %rcx+// so after the load of z, we have both z and t pointers straight.++ movq %r8, %rcx+ leaq 8*K(%r8), %rsi+ leaq 16*K(%r8), %rdi+ CFI_CALL(Lbignum_kmul_32_64_local_bignum_kmul_16_32)+ movq (%rsp), z++// Compose the middle parts [2,1] + [1,0] + [3,2], saving carry in %rbx.+// Put the sum at t, overwriting the absolute differences we no longer need.++ xorl %ebx, %ebx+ .set I, 0+ .rep 2*K+ movq 8*K+8*I(z), %rax+ adcxq 8*I(z), %rax+ adoxq 16*K+8*I(z), %rax+ movq %rax, 8*I(t)+ .set I, (I+1)+ .endr+ adoxq %rbx, %rbx+ adcq $0, %rbx++// Sign-aware addition or subtraction of the complicated term.+// We double-negate it to set CF/ZF while not spoiling its+// actual form: note that we eventually adcx to it below.++ movq 32*K(t), s+ negq s+ negq s++ .set I, 0+ .rep 2*K+ movq 16*K+8*I(t), %rdx+ movq %rdx, %rax+ notq %rdx+ cmovzq %rax, %rdx+ adcxq 8*I(t), %rdx+ movq %rdx, 8*K+8*I(z)+ .set I, (I+1)+ .endr++// Bump the accumulated carry. This must end up >= 0 because it's the top+// word of a value of the form ... + h * h' + l * l' - (h - l) * (h' - l') >= 0++ adcxq s, %rbx++// Finally propagate the carry to the top part++ xorl %eax, %eax+ addq %rbx, 24*K(z)+ .set I, 1+ .rep K-1+ adcq %rax, 24*K+8*I(z)+ .set I, (I+1)+ .endr++// Restore and return. The first pop is not needed for the ABI but+// we need to adjust the stack anyway so it seems reasonable.++ CFI_POP(%rcx)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++// Local copy of half-length subroutine. This has a slightly different+// interface, expecting y argument in %rcx directly, and not doing any+// save-restore of the other registers. It naturally moves z and x on by+// 0x40, which we compensate for when it is called by adjusting offsets.++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lbignum_kmul_32_64_local_bignum_kmul_16_32)++Lbignum_kmul_32_64_local_bignum_kmul_16_32:+ CFI_START+ movq (%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %r9+ movq %rax, (%rdi)+ mulxq 0x8(%rsi), %rax, %r10+ adcxq %rax, %r9+ mulxq 0x10(%rsi), %rax, %r11+ adcxq %rax, %r10+ mulxq 0x18(%rsi), %rax, %r12+ adcxq %rax, %r11+ mulxq 0x20(%rsi), %rax, %r13+ adcxq %rax, %r12+ mulxq 0x28(%rsi), %rax, %r14+ adcxq %rax, %r13+ mulxq 0x30(%rsi), %rax, %r15+ adcxq %rax, %r14+ mulxq 0x38(%rsi), %rax, %r8+ adcxq %rax, %r15+ adcq %rbp, %r8+ movq 0x8(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x8(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(%rsi), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ adcq %rbp, %r9+ movq 0x10(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x10(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(%rsi), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcq %rbp, %r10+ movq 0x18(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x18(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(%rsi), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ adcq %rbp, %r11+ movq 0x20(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x20(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsi), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcq %rbp, %r12+ movq 0x28(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x28(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsi), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ adcq %rbp, %r13+ movq 0x30(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x30(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(%rsi), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ movq 0x38(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x38(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(%rsi), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ adcq %rbp, %r15+ movq 0x40(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ movq %r8, 0x40(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x38(%rsi), %rax, %r8+ adcxq %rax, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movq 0x48(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x48(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(%rsi), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ adcq %rbp, %r9+ movq 0x50(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x50(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(%rsi), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcq %rbp, %r10+ movq 0x58(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x58(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(%rsi), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ adcq %rbp, %r11+ movq 0x60(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x60(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsi), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcq %rbp, %r12+ movq 0x68(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x68(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsi), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ adcq %rbp, %r13+ movq 0x70(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x70(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(%rsi), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ movq 0x78(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x78(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(%rsi), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ adcq %rbp, %r15+ movq %r8, 0x80(%rdi)+ movq %r9, 0x88(%rdi)+ movq %r10, 0x90(%rdi)+ movq %r11, 0x98(%rdi)+ movq %r12, 0xa0(%rdi)+ movq %r13, 0xa8(%rdi)+ movq %r14, 0xb0(%rdi)+ movq %r15, 0xb8(%rdi)+ addq $0x40, %rdi+ addq $0x40, %rsi+ movq (%rcx), %rdx+ xorl %ebp, %ebp+ movq (%rdi), %r8+ movq 0x8(%rdi), %r9+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ movq %r8, (%rdi)+ movq 0x10(%rdi), %r10+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq 0x18(%rdi), %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq 0x20(%rdi), %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x28(%rdi), %r13+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x30(%rdi), %r14+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq 0x38(%rdi), %r15+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x38(%rsi), %rax, %r8+ adcxq %rax, %r15+ adoxq %rbp, %r8+ adcxq %rbp, %r8+ movq 0x8(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x8(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(%rsi), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ adcq %rbp, %r9+ movq 0x10(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x10(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(%rsi), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcq %rbp, %r10+ movq 0x18(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x18(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(%rsi), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ adcq %rbp, %r11+ movq 0x20(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x20(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsi), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcq %rbp, %r12+ movq 0x28(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x28(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsi), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ adcq %rbp, %r13+ movq 0x30(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x30(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(%rsi), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ movq 0x38(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x38(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(%rsi), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ adcq %rbp, %r15+ movq 0x40(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x40(%rdi), %r8+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ movq %r8, 0x40(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x38(%rsi), %rax, %r8+ adcxq %rax, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movq 0x48(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x48(%rdi), %r9+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x48(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(%rsi), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ adcq %rbp, %r9+ movq 0x50(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x50(%rdi), %r10+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x50(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(%rsi), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcq %rbp, %r10+ movq 0x58(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x58(%rdi), %r11+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x58(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(%rsi), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ adcq %rbp, %r11+ movq 0x60(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x60(%rdi), %r12+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x60(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsi), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcq %rbp, %r12+ movq 0x68(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x68(%rdi), %r13+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x68(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsi), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ adcq %rbp, %r13+ movq 0x70(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x70(%rdi), %r14+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x70(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(%rsi), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ movq 0x78(%rcx), %rdx+ xorl %ebp, %ebp+ adoxq 0x78(%rdi), %r15+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x78(%rdi)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(%rsi), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ adcq %rbp, %r15+ movq %r8, 0x80(%rdi)+ movq %r9, 0x88(%rdi)+ movq %r10, 0x90(%rdi)+ movq %r11, 0x98(%rdi)+ movq %r12, 0xa0(%rdi)+ movq %r13, 0xa8(%rdi)+ movq %r14, 0xb0(%rdi)+ movq %r15, 0xb8(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lbignum_kmul_32_64_local_bignum_kmul_16_32)++S2N_BN_SIZE_DIRECTIVE(bignum_kmul_32_64)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_ksqr_16_32.S view
@@ -0,0 +1,545 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Square, z := x^2+// Input x[16]; output z[32]; temporary buffer t[>=24]+//+// extern void bignum_ksqr_16_32(uint64_t z[static 32],+// const uint64_t x[static 16],+// uint64_t t[static 24]);+//+// In this x86 code the final temporary space argument t is unused, but+// it is retained in the prototype above for API consistency with ARM.+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = t+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = t+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_ksqr_16_32)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_ksqr_16_32)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_ksqr_16_32)+ .text++#define z %rdi+#define x %rsi++// A zero register++#define zero %rbp+#define zeroe %ebp++// ------------------------------------------------------------------------+// mulpadd i, j adds rdx * x[i] into the window at the i+j point+// ------------------------------------------------------------------------++.macro mulpadd arg1,arg2+ mulxq 8*\arg1(x), %rax, %rcx+.if ((\arg1 + \arg2) % 8 == 0)+ adcxq %rax, %r8+ adoxq %rcx, %r9+.elseif ((\arg1 + \arg2) % 8 == 1)+ adcxq %rax, %r9+ adoxq %rcx, %r10+.elseif ((\arg1 + \arg2) % 8 == 2)+ adcxq %rax, %r10+ adoxq %rcx, %r11+.elseif ((\arg1 + \arg2) % 8 == 3)+ adcxq %rax, %r11+ adoxq %rcx, %r12+.elseif ((\arg1 + \arg2) % 8 == 4)+ adcxq %rax, %r12+ adoxq %rcx, %r13+.elseif ((\arg1 + \arg2) % 8 == 5)+ adcxq %rax, %r13+ adoxq %rcx, %r14+.elseif ((\arg1 + \arg2) % 8 == 6)+ adcxq %rax, %r14+ adoxq %rcx, %r15+.elseif ((\arg1 + \arg2) % 8 == 7)+ adcxq %rax, %r15+ adoxq %rcx, %r8+.endif++.endm++// ------------------------------------------------------------------------+// mulpade i, j adds rdx * x[i] into the window at i+j+// but re-creates the top word assuming nothing to add there+// ------------------------------------------------------------------------++.macro mulpade arg1,arg2+.if ((\arg1 + \arg2) % 8 == 0)+ mulxq 8*\arg1(x), %rax, %r9+ adcxq %rax, %r8+ adoxq zero, %r9+.elseif ((\arg1 + \arg2) % 8 == 1)+ mulxq 8*\arg1(x), %rax, %r10+ adcxq %rax, %r9+ adoxq zero, %r10+.elseif ((\arg1 + \arg2) % 8 == 2)+ mulxq 8*\arg1(x), %rax, %r11+ adcxq %rax, %r10+ adoxq zero, %r11+.elseif ((\arg1 + \arg2) % 8 == 3)+ mulxq 8*\arg1(x), %rax, %r12+ adcxq %rax, %r11+ adoxq zero, %r12+.elseif ((\arg1 + \arg2) % 8 == 4)+ mulxq 8*\arg1(x), %rax, %r13+ adcxq %rax, %r12+ adoxq zero, %r13+.elseif ((\arg1 + \arg2) % 8 == 5)+ mulxq 8*\arg1(x), %rax, %r14+ adcxq %rax, %r13+ adoxq zero, %r14+.elseif ((\arg1 + \arg2) % 8 == 6)+ mulxq 8*\arg1(x), %rax, %r15+ adcxq %rax, %r14+ adoxq zero, %r15+.elseif ((\arg1 + \arg2) % 8 == 7)+ mulxq 8*\arg1(x), %rax, %r8+ adcxq %rax, %r15+ adoxq zero, %r8+.endif++.endm++// ------------------------------------------------------------------------+// addrow i,j adds z[i+j] + x[i..i+7] * x[j] into the window+// ------------------------------------------------------------------------++.macro addrow arg1,arg2+ movq 8*\arg2(x), %rdx+ xorl zeroe, zeroe // Get a known flag state and give a zero reg++.if ((\arg1 + \arg2) % 8 == 0)+ adoxq 8*(\arg1+\arg2)(z), %r8+.elseif ((\arg1 + \arg2) % 8 == 1)+ adoxq 8*(\arg1+\arg2)(z), %r9+.elseif ((\arg1 + \arg2) % 8 == 2)+ adoxq 8*(\arg1+\arg2)(z), %r10+.elseif ((\arg1 + \arg2) % 8 == 3)+ adoxq 8*(\arg1+\arg2)(z), %r11+.elseif ((\arg1 + \arg2) % 8 == 4)+ adoxq 8*(\arg1+\arg2)(z), %r12+.elseif ((\arg1 + \arg2) % 8 == 5)+ adoxq 8*(\arg1+\arg2)(z), %r13+.elseif ((\arg1 + \arg2) % 8 == 6)+ adoxq 8*(\arg1+\arg2)(z), %r14+.elseif ((\arg1 + \arg2) % 8 == 7)+ adoxq 8*(\arg1+\arg2)(z), %r15+.endif++ mulpadd \arg1, \arg2++.if ((\arg1 + \arg2) % 8 == 0)+ movq %r8, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 1)+ movq %r9, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 2)+ movq %r10, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 3)+ movq %r11, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 4)+ movq %r12, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 5)+ movq %r13, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 6)+ movq %r14, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 7)+ movq %r15, 8*(\arg1+\arg2)(z)+.endif++ mulpadd (\arg1+1), \arg2+ mulpadd (\arg1+2), \arg2+ mulpadd (\arg1+3), \arg2+ mulpadd (\arg1+4), \arg2+ mulpadd (\arg1+5), \arg2+ mulpade (\arg1+6), \arg2+ mulpade (\arg1+7), \arg2++.if ((\arg1 + \arg2) % 8 == 0)+ adcxq zero, %r8+.elseif ((\arg1 + \arg2) % 8 == 1)+ adcxq zero, %r9+.elseif ((\arg1 + \arg2) % 8 == 2)+ adcxq zero, %r10+.elseif ((\arg1 + \arg2) % 8 == 3)+ adcxq zero, %r11+.elseif ((\arg1 + \arg2) % 8 == 4)+ adcxq zero, %r12+.elseif ((\arg1 + \arg2) % 8 == 5)+ adcxq zero, %r13+.elseif ((\arg1 + \arg2) % 8 == 6)+ adcxq zero, %r14+.elseif ((\arg1 + \arg2) % 8 == 7)+ adcxq zero, %r15+.endif+++.endm+++// ------------------------------------------------------------------------+// Adds off-diagonal part of x[i..i+7]^2 into the window, writes 0..7 back+// ------------------------------------------------------------------------++.macro sqr arg1++ xorl zeroe, zeroe++// Set up the initial window++ movq 16*\arg1+8(z), %r9+ movq 16*\arg1+16(z), %r10+ movq 16*\arg1+24(z), %r11+ movq 16*\arg1+32(z), %r12+ movq 16*\arg1+40(z), %r13+ movq 16*\arg1+48(z), %r14+ movq 16*\arg1+56(z), %r15++// Add in the first diagonal [%r8..%r10] + 2 wb = 10 + 20 + 30 + 40 + 50 + 60 + 70++ movq 8*\arg1(x), %rdx+ mulpadd (\arg1+1), (\arg1+0)+ movq %r9, 16*\arg1+8(z)+ mulpadd (\arg1+2), (\arg1+0)+ movq %r10, 16*\arg1+16(z)+ mulpadd (\arg1+3), (\arg1+0)+ mulpadd (\arg1+4), (\arg1+0)+ mulpadd (\arg1+5), (\arg1+0)+ mulpadd (\arg1+6), (\arg1+0)+ mulpade (\arg1+7), (\arg1+0)+ adcxq zero, %r8++// Add in the next diagonal = 21 + 31 + 41 + 51 + 61 + 71 + 54++ xorl zeroe, zeroe+ movq 8*\arg1+8(x), %rdx+ mulpadd (\arg1+2), (\arg1+1)+ movq %r11, 16*\arg1+24(z)+ mulpadd (\arg1+3), (\arg1+1)+ movq %r12, 16*\arg1+32(z)+ mulpadd (\arg1+4), (\arg1+1)+ mulpadd (\arg1+5), (\arg1+1)+ mulpadd (\arg1+6), (\arg1+1)+ mulpade (\arg1+7), (\arg1+1)+ movq 8*\arg1+32(x), %rdx+ mulpade (\arg1+5), (\arg1+4)+ adcxq zero, %r10++// And the next one = 32 + 42 + 52 + 62 + 72 + 64 + 65++ xorl zeroe, zeroe+ movq 8*\arg1+16(x), %rdx+ mulpadd (\arg1+3), (\arg1+2)+ movq %r13, 16*\arg1+40(z)+ mulpadd (\arg1+4), (\arg1+2)+ movq %r14, 16*\arg1+48(z)+ mulpadd (\arg1+5), (\arg1+2)+ mulpadd (\arg1+6), (\arg1+2)+ mulpadd (\arg1+7), (\arg1+2)+ movq 8*\arg1+48(x), %rdx+ mulpade (\arg1+4), (\arg1+6)+ mulpade (\arg1+5), (\arg1+6)+ adcxq zero, %r12++// And the final one = 43 + 53 + 63 + 73 + 74 + 75 + 76++ xorl zeroe, zeroe+ movq 8*\arg1+24(x), %rdx+ mulpadd (\arg1+4), (\arg1+3)+ movq %r15, 16*\arg1+56(z)+ mulpadd (\arg1+5), (\arg1+3)+ mulpadd (\arg1+6), (\arg1+3)+ mulpadd (\arg1+7), (\arg1+3)+ movq 8*\arg1+56(x), %rdx+ mulpadd (\arg1+4), (\arg1+7)+ mulpade (\arg1+5), (\arg1+7)+ mulpade (\arg1+6), (\arg1+7)+ adcxq zero, %r14+.endm++// ------------------------------------------------------------------------+// Multiply-add: z := z + x[i...i+7] * x+// ------------------------------------------------------------------------++.macro addrows arg1++ sqr \arg1++ .set I, (\arg1+8)+.rep (8-\arg1)+ addrow \arg1, I+ .set I, (I+1)+.endr++ movq %r8, 8*(16+\arg1)(z)+ movq %r9, 8*(17+\arg1)(z)+ movq %r10, 8*(18+\arg1)(z)+ movq %r11, 8*(19+\arg1)(z)+ movq %r12, 8*(20+\arg1)(z)+ movq %r13, 8*(21+\arg1)(z)+ movq %r14, 8*(22+\arg1)(z)+.endm+++// ------------------------------------------------------------------------+// mulrow i,j adds x[i..i+7] * x[j] into the window+// just like addrow but no addition of z[i+j]+// ------------------------------------------------------------------------++.macro mulrow arg1,arg2+ movq 8*\arg2(x), %rdx+ xorl zeroe, zeroe // Get a known flag state and give a zero reg++ mulpadd \arg1, \arg2++.if ((\arg1 + \arg2) % 8 == 0)+ movq %r8, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 1)+ movq %r9, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 2)+ movq %r10, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 3)+ movq %r11, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 4)+ movq %r12, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 5)+ movq %r13, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 6)+ movq %r14, 8*(\arg1+\arg2)(z)+.elseif ((\arg1 + \arg2) % 8 == 7)+ movq %r15, 8*(\arg1+\arg2)(z)+.endif++ mulpadd (\arg1+1), \arg2+ mulpadd (\arg1+2), \arg2+ mulpadd (\arg1+3), \arg2+ mulpadd (\arg1+4), \arg2+ mulpadd (\arg1+5), \arg2+.if ((\arg1 + \arg2) % 8 == 0)+ mulpade (\arg1+6), \arg2+.else+ mulpadd (\arg1+6), \arg2+.endif++ mulpade (\arg1+7), \arg2++.if ((\arg1 + \arg2) % 8 == 0)+ adcxq zero, %r8+.elseif ((\arg1 + \arg2) % 8 == 1)+ adcxq zero, %r9+.elseif ((\arg1 + \arg2) % 8 == 2)+ adcxq zero, %r10+.elseif ((\arg1 + \arg2) % 8 == 3)+ adcxq zero, %r11+.elseif ((\arg1 + \arg2) % 8 == 4)+ adcxq zero, %r12+.elseif ((\arg1 + \arg2) % 8 == 5)+ adcxq zero, %r13+.elseif ((\arg1 + \arg2) % 8 == 6)+ adcxq zero, %r14+.elseif ((\arg1 + \arg2) % 8 == 7)+ adcxq zero, %r15+.endif+++.endm++// ------------------------------------------------------------------------+// Compute off-diagonal part of x[0..7]^2, write back 1..7 elements and+// set up the high part in the standard register window. DOES NOT WRITE z[0]!+// ------------------------------------------------------------------------++.macro sqrz++ xorl zeroe, zeroe++// Set initial window [%r8..%r10] + 2 wb = 10 + 20 + 30 + 40 + 50 + 60 + 70++ movq (x), %rdx+ mulxq 8(x), %r9, %rax+ movq %r9, 8(z)+ mulxq 16(x), %r10, %rcx+ adcxq %rax, %r10+ movq %r10, 16(z)+ mulxq 24(x), %r11, %rax+ adcxq %rcx, %r11+ mulxq 32(x), %r12, %rcx+ adcxq %rax, %r12+ mulxq 40(x), %r13, %rax+ adcxq %rcx, %r13+ mulxq 48(x), %r14, %rcx+ adcxq %rax, %r14+ mulxq 56(x), %r15, %r8+ adcxq %rcx, %r15+ adcxq zero, %r8++// Add in the next diagonal = 21 + 31 + 41 + 51 + 61 + 71 + 54++ xorl zeroe, zeroe+ movq 8(x), %rdx+ mulpadd 2, 1+ movq %r11, 24(z)+ mulpadd 3, 1+ movq %r12, 32(z)+ mulpadd 4, 1+ mulpadd 5, 1+ mulpadd 6, 1+ mulpade 7, 1+ movq 32(x), %rdx+ mulpade 5, 4+ adcxq zero, %r10++// And the next one = 32 + 42 + 52 + 62 + 72 + 64 + 65++ xorl zeroe, zeroe+ movq 16(x), %rdx+ mulpadd 3, 2+ movq %r13, 40(z)+ mulpadd 4, 2+ movq %r14, 48(z)+ mulpadd 5, 2+ mulpadd 6, 2+ mulpadd 7, 2+ movq 48(x), %rdx+ mulpade 4, 6+ mulpade 5, 6+ adcxq zero, %r12++// And the final one = 43 + 53 + 63 + 73 + 74 + 75 + 76++ xorl zeroe, zeroe+ movq 24(x), %rdx+ mulpadd 4, 3+ movq %r15, 56(z)+ mulpadd 5, 3+ mulpadd 6, 3+ mulpadd 7, 3+ movq 56(x), %rdx+ mulpadd 4, 7+ mulpade 5, 7+ mulpade 6, 7+ adcxq zero, %r14+.endm++// ------------------------------------------------------------------------+// Multiply-add: z := x[0...7] * x off-diagonal elements+// ------------------------------------------------------------------------++.macro mulrows+ sqrz++ .set I, 8+.rep 8+ mulrow 0, I+ .set I, (I+1)+.endr++ movq %r8, 128(z)+ movq %r9, 136(z)+ movq %r10, 144(z)+ movq %r11, 152(z)+ movq %r12, 160(z)+ movq %r13, 168(z)+ movq %r14, 176(z)+ movq %r15, 184(z)+.endm++// ------------------------------------------------------------------------+// The actual code+// ------------------------------------------------------------------------++++S2N_BN_SYMBOL(bignum_ksqr_16_32):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save more registers to play with++ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Now just systematically add in the rows to get all off-diagonal elements++ mulrows+ addrows 8++// Double and add the diagonal elements. Note that z[0] was never written above++ xorl zeroe, zeroe+ movq (x), %rdx+ mulxq %rdx, %rax, %rcx+ movq %rax, (z)++ movq 8(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rcx, %rdx+ movq %rdx, 8(z)++ .set I, 1+.rep 14+ movq 8*I(x), %rdx+ mulxq %rdx, %rax, %rcx++ movq 8*(2*I)(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 8*(2*I)(z)++ movq 8*(2*I+1)(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rcx, %rdx+ movq %rdx, 8*(2*I+1)(z)+ .set I, (I+1)+.endr++ movq 8*I(x), %rdx+ mulxq %rdx, %rax, %rcx++ movq 8*(2*I)(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 8*(2*I)(z)++ adcxq zero, %rcx+ adoxq zero, %rcx+ movq %rcx, 8*(2*I+1)(z)+ .set I, (I+1)+++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_ksqr_16_32)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_ksqr_32_64.S view
@@ -0,0 +1,809 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Square, z := x^2+// Input x[32]; output z[64]; temporary buffer t[>=72]+//+// extern void bignum_ksqr_32_64(uint64_t z[static 64],+// const uint64_t x[static 32],+// uint64_t t[static 72]);+//+// This is a Karatsuba-style function squaring half-sized results+// and using temporary buffer t for intermediate results. The size of 72+// is an overstatement for compatibility with the ARM version; it actually+// only uses 65 elements of t (64 + 1 for a suspended carry).+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = t+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = t+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_ksqr_32_64)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_ksqr_32_64)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_ksqr_32_64)++ .text++#define K 16++#define z %rdi+#define x %rsi+#define t %rcx++S2N_BN_SYMBOL(bignum_ksqr_32_64):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save callee-preserved registers once and for all at the outset+// Later we further reshuffle the input arguments to avoid extra saves++ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Move the temp space pointer since we need %rdx for multiplications++ movq %rdx, t++// Square the low half++ CFI_CALL(Lbignum_ksqr_32_64_local_bignum_sqr_16_32)++// Square the high half; from here on x and z are modified++ leaq 8*K(x), x // input at x+8*K+ leaq 16*K(z), z // result at z+16*K+ CFI_CALL(Lbignum_ksqr_32_64_local_bignum_sqr_16_32)++// Form |x_lo - x_hi|, stored at t++ movq -8*K(x), %rax+ subq (x), %rax+ movq %rax, (t)+ .set I, 1+ .rep K-1+ movq -8*K+8*I(x), %rax+ sbbq 8*I(x), %rax+ movq %rax, 8*I(t)+ .set I, (I+1)+ .endr++ movl $0, %ebx+ sbbq %rax, %rax // Maintain CF, set ZF for cmovs++ .set I, 0+ .rep K+ movq 8*I(t), %rdx+ movq %rdx, %rax+ notq %rdx+ adcxq %rbx, %rdx+ cmovzq %rax, %rdx+ movq %rdx, 8*I(t)+ .set I, (I+1)+ .endr++// Compose the middle parts [2,1] + [1,0] + [3,2]+// Put the low half of this at t[K] and the top half in place at z[2*K]; a+// fully in-place version is awkward with the otherwise beneficial double+// carry chain. Stash the carry suspended from the 3k position at the end of+// the temp buffer t[4*K].++ xorl %edx, %edx+ .set I, 0+ .rep K+ movq -16*K+8*K+8*I(z), %rax+ adcxq -16*K+8*I(z), %rax+ adoxq -16*K+16*K+8*I(z), %rax+ movq %rax, 8*K+8*I(t)+ .set I, (I+1)+ .endr++ .rep K+ movq -16*K+8*K+8*I(z), %rax+ adcxq -16*K+8*I(z), %rax+ adoxq -16*K+16*K+8*I(z), %rax+ movq %rax, -16*K+8*K+8*I(z)+ .set I, (I+1)+ .endr++ adoxq %rdx, %rdx+ adcq $0, %rdx+ movq %rdx, 32*K(t)++// Square the absolute difference, putting the result M at t[2*K].+// This involves another shuffle so now t' = z_orig and x' = t_orig+// while z' points within the temp buffer to the product M itself++ movq t, x+ leaq -16*K(z), t+ leaq 16*K(x), z+ CFI_CALL(Lbignum_ksqr_32_64_local_bignum_sqr_16_32)++// Subtract M, pausing at the 3k position to bump down accumulated carry.+// The carry cannot go negative since it's the top word of a value+// of the form ... + h^2 + l^2 - (h - l)^2 >= 0++ movq 8*K(x), %rax+ subq (z), %rax+ movq %rax, 8*K(t)++ .set I, 1++ .rep (K-1)+ movq 8*K+8*I(x), %rax+ sbbq 8*I(z), %rax+ movq %rax, 8*K+8*I(t)+ .set I, (I+1)+ .endr++ .rep K+ movq 8*K+8*I(t), %rax+ sbbq 8*I(z), %rax+ movq %rax, 8*K+8*I(t)+ .set I, (I+1)+ .endr++ movq 32*K(x), %rdx+ sbbq $0, %rdx++// Finally propagate the carry to the top quarter++ xorl %eax, %eax+ addq %rdx, 24*K(t)+ .set I, 1+ .rep K-1+ adcq %rax, 24*K+8*I(t)+ .set I, (I+1)+ .endr++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_POP(%rbp)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++// Local copy of the half-length subroutine++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lbignum_ksqr_32_64_local_bignum_sqr_16_32)++Lbignum_ksqr_32_64_local_bignum_sqr_16_32:+ CFI_START+ xorl %ebp, %ebp+ movq (x), %rdx+ mulxq 0x8(x), %r9, %rax+ movq %r9, 0x8(z)+ mulxq 0x10(x), %r10, %rbx+ adcxq %rax, %r10+ movq %r10, 0x10(z)+ mulxq 0x18(x), %r11, %rax+ adcxq %rbx, %r11+ mulxq 0x20(x), %r12, %rbx+ adcxq %rax, %r12+ mulxq 0x28(x), %r13, %rax+ adcxq %rbx, %r13+ mulxq 0x30(x), %r14, %rbx+ adcxq %rax, %r14+ mulxq 0x38(x), %r15, %r8+ adcxq %rbx, %r15+ adcxq %rbp, %r8+ xorl %ebp, %ebp+ movq 0x8(x), %rdx+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x18(z)+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x20(z)+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(x), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ movq 0x20(x), %rdx+ mulxq 0x28(x), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcxq %rbp, %r10+ xorl %ebp, %ebp+ movq 0x10(x), %rdx+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x28(z)+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x30(z)+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq 0x30(x), %rdx+ mulxq 0x20(x), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ mulxq 0x28(x), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcxq %rbp, %r12+ xorl %ebp, %ebp+ movq 0x18(x), %rdx+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x38(z)+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq 0x38(x), %rdx+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(x), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ mulxq 0x30(x), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcxq %rbp, %r14+ movq 0x40(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ movq %r8, 0x40(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x30(x), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ mulxq 0x38(x), %rax, %r8+ adcxq %rax, %r15+ adoxq %rbp, %r8+ adcxq %rbp, %r8+ movq 0x48(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x48(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(x), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ movq 0x50(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x50(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(x), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcxq %rbp, %r10+ movq 0x58(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x58(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(x), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ adcxq %rbp, %r11+ movq 0x60(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x60(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(x), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcxq %rbp, %r12+ movq 0x68(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x68(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(x), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ adcxq %rbp, %r13+ movq 0x70(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x70(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(x), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcxq %rbp, %r14+ movq 0x78(x), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x78(z)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(x), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ adcxq %rbp, %r15+ movq %r8, 0x80(z)+ movq %r9, 0x88(z)+ movq %r10, 0x90(z)+ movq %r11, 0x98(z)+ movq %r12, 0xa0(z)+ movq %r13, 0xa8(z)+ movq %r14, 0xb0(z)+ movq %r15, 0xb8(z)+ xorl %ebp, %ebp+ movq 0x88(z), %r9+ movq 0x90(z), %r10+ movq 0x98(z), %r11+ movq 0xa0(z), %r12+ movq 0xa8(z), %r13+ movq 0xb0(z), %r14+ movq 0xb8(z), %r15+ movq 0x40(x), %rdx+ mulxq 0x48(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x88(z)+ mulxq 0x50(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x90(z)+ mulxq 0x58(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x60(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x68(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x70(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x78(x), %rax, %r8+ adcxq %rax, %r15+ adoxq %rbp, %r8+ adcxq %rbp, %r8+ xorl %ebp, %ebp+ movq 0x48(x), %rdx+ mulxq 0x50(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x98(z)+ mulxq 0x58(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0xa0(z)+ mulxq 0x60(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x68(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x70(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x78(x), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ movq 0x60(x), %rdx+ mulxq 0x68(x), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcxq %rbp, %r10+ xorl %ebp, %ebp+ movq 0x50(x), %rdx+ mulxq 0x58(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0xa8(z)+ mulxq 0x60(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0xb0(z)+ mulxq 0x68(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x70(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x78(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq 0x70(x), %rdx+ mulxq 0x60(x), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ mulxq 0x68(x), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcxq %rbp, %r12+ xorl %ebp, %ebp+ movq 0x58(x), %rdx+ mulxq 0x60(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0xb8(z)+ mulxq 0x68(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x70(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x78(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq 0x78(x), %rdx+ mulxq 0x60(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(x), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ mulxq 0x70(x), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcxq %rbp, %r14+ movq %r8, 0xc0(z)+ movq %r9, 0xc8(z)+ movq %r10, 0xd0(z)+ movq %r11, 0xd8(z)+ movq %r12, 0xe0(z)+ movq %r13, 0xe8(z)+ movq %r14, 0xf0(z)+ xorl %ebp, %ebp+ movq (x), %rdx+ mulxq %rdx, %rax, %rbx+ movq %rax, (z)+ movq 0x8(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x8(z)+ movq 0x8(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x10(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x10(z)+ movq 0x18(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x18(z)+ movq 0x10(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x20(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x20(z)+ movq 0x28(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x28(z)+ movq 0x18(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x30(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x30(z)+ movq 0x38(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x38(z)+ movq 0x20(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x40(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x40(z)+ movq 0x48(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x48(z)+ movq 0x28(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x50(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x50(z)+ movq 0x58(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x58(z)+ movq 0x30(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x60(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x60(z)+ movq 0x68(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x68(z)+ movq 0x38(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x70(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x70(z)+ movq 0x78(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x78(z)+ movq 0x40(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x80(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x80(z)+ movq 0x88(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x88(z)+ movq 0x48(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0x90(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0x90(z)+ movq 0x98(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0x98(z)+ movq 0x50(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0xa0(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0xa0(z)+ movq 0xa8(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0xa8(z)+ movq 0x58(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0xb0(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0xb0(z)+ movq 0xb8(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0xb8(z)+ movq 0x60(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0xc0(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0xc0(z)+ movq 0xc8(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0xc8(z)+ movq 0x68(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0xd0(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0xd0(z)+ movq 0xd8(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0xd8(z)+ movq 0x70(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0xe0(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0xe0(z)+ movq 0xe8(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rbx, %rdx+ movq %rdx, 0xe8(z)+ movq 0x78(x), %rdx+ mulxq %rdx, %rax, %rbx+ movq 0xf0(z), %rdx+ adcxq %rdx, %rdx+ adoxq %rax, %rdx+ movq %rdx, 0xf0(z)+ adcxq %rbp, %rbx+ adoxq %rbp, %rbx+ movq %rbx, 0xf8(z)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lbignum_ksqr_32_64_local_bignum_sqr_16_32)++S2N_BN_SIZE_DIRECTIVE(bignum_ksqr_32_64)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_modinv.S view
@@ -0,0 +1,714 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Invert modulo m, z = (1/a) mod b, assuming b is an odd number > 1, coprime a+// Inputs a[k], b[k]; output z[k]; temporary buffer t[>=3*k]+//+// extern void bignum_modinv(uint64_t k, uint64_t *z, const uint64_t *a,+// const uint64_t *b, uint64_t *t);+//+// k-digit (digit=64 bits) "z := a^-1 mod b" (modular inverse of a modulo b)+// using t as a temporary buffer (t at least 3*k words = 24*k bytes), and+// assuming that a and b are coprime *and* that b is an odd number > 1.+//+// Standard x86-64 ABI: RDI = k, RSI = z, RDX = a, RCX = b, R8 = t+// Microsoft x64 ABI: RCX = k, RDX = z, R8 = a, R9 = b, [RSP+40] = t+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_modinv)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_modinv)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_modinv)+ .text+ .balign 32++// We get CHUNKSIZE bits per outer iteration, 64 minus a few for proxy errors++#define CHUNKSIZE 58++// These variables are so fundamental we keep them consistently in registers.+// k actually stays where it was at the beginning, while l gets set up later++#define k %rdi+#define l %r13++// These are kept on the stack since there aren't enough registers++#define mat_mm (%rsp)+#define mat_mn 8(%rsp)+#define mat_nm 16(%rsp)+#define mat_nn 24(%rsp)+#define t 32(%rsp)+// Modular inverse+#define v 40(%rsp)+// We reconstruct n as m + 8*k as needed+#define m 48(%rsp)+#define w 56(%rsp)+#define z 64(%rsp)+// Original b pointer, not b the temp+#define bm 72(%rsp)++#define STACKVARSIZE 80++// These get set to m/n or w/z during the cross-multiplications etc.+// Otherwise they can be used as additional temporaries++#define p1 %r8+#define p2 %r15++// These are shorthands for common temporary registers++#define a %rax+#define b %rbx+#define c %rcx+#define d %rdx+#define i %r9++// Temporaries for the top proxy selection part++#define c1 %r10+#define c2 %r11+#define h1 %r12+#define h2 %rbp+#define l1 %r14+#define l2 %rsi++// Re-use for the actual proxies; m_hi = h1 and n_hi = h2 are assumed++#define m_hi %r12+#define n_hi %rbp+#define m_lo %r14+#define n_lo %rsi++// Re-use for the matrix entries in the inner loop, though they+// get spilled to the corresponding memory locations mat_...++#define m_m %r10+#define m_n %r11+#define n_m %rcx+#define n_n %rdx++#define ashort %eax+#define ishort %r9d+#define m_mshort %r10d+#define m_nshort %r11d+#define n_mshort %ecx+#define n_nshort %edx++S2N_BN_SYMBOL(bignum_modinv):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ movq %r9, %rcx+ movq 56(%rsp), %r8+#endif++// Save all required registers and make room on stack for all the above vars++ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(STACKVARSIZE)++// If k = 0 then do nothing (this is out of scope anyway)++ testq k, k+ jz Lbignum_modinv_end++// Set up the additional two buffers m and n beyond w in temp space+// and record all pointers m, n, w and z in stack-based variables++ movq %rsi, z+ movq %r8, w+ movq %rcx, bm+ leaq (%r8,k,8), %r10+ movq %r10, m+ leaq (%r10,k,8), p2++// Initialize the main buffers with their starting values:+// m = a, n = b, w = b (to be tweaked to b - 1) and z = 0++ xorq %r11, %r11+ xorq i, i+Lbignum_modinv_copyloop:+ movq (%rdx,i,8), a+ movq (%rcx,i,8), b+ movq a, (%r10,i,8)+ movq b, (p2,i,8)+ movq b, (%r8,i,8)+ movq %r11, (%rsi,i,8)+ incq i+ cmpq k, i+ jc Lbignum_modinv_copyloop++// Tweak down w to b - 1 (this crude approach is safe as b needs to be odd+// for it to be in scope). We have then established the congruence invariant:+//+// a * w == -m (mod b)+// a * z == n (mod b)+//+// This, with the bounds w <= b and z <= b, is maintained round the outer loop++ movq (%r8), a+ movq a, b+ decq b+ movq b, (%r8)++// Compute v = negated modular inverse of b mod 2^64, reusing a from above+// This is used for Montgomery reduction operations each time round the loop++ movq a, h2+ movq a, h1+ shlq $2, h2+ subq h2, h1+ xorq $2, h1++ movq h1, h2+ imulq a, h2+ movl $2, ashort+ addq h2, a+ addq $1, h2++ imulq a, h1++ imulq h2, h2+ movl $1, ashort+ addq h2, a+ imulq a, h1++ imulq h2, h2+ movl $1, ashort+ addq h2, a+ imulq a, h1++ imulq h2, h2+ movl $1, ashort+ addq h2, a+ imulq a, h1++ movq h1, v++// Set up the outer loop count of 128 * k+// The invariant is that m * n < 2^t at all times.++ movq k, a+ shlq $7, a+ movq a, t++// Start of the main outer loop iterated t / CHUNKSIZE times++Lbignum_modinv_outerloop:++// We need only bother with sharper l = min k (ceil(t/64)) digits+// for the computations on m and n (but we still need k for w and z).+// Either both m and n fit in l digits, or m has become zero and so+// nothing happens in the loop anyway and this makes no difference.++ movq t, l+ addq $63, l+ shrq $6, l+ cmpq k, l+ cmovncq k, l++// Select upper and lower proxies for both m and n to drive the inner+// loop. The lower proxies are simply the lowest digits themselves,+// m_lo = m[0] and n_lo = n[0], while the upper proxies are bitfields+// of the two inputs selected so their top bit (63) aligns with the+// most significant bit of *either* of the two inputs.++ xorq h1, h1 // Previous high and low for m+ xorq l1, l1+ xorq h2, h2 // Previous high and low for n+ xorq l2, l2+ xorq c2, c2 // Mask flag: previous word of one was nonzero+ // and in this case h1 and h2 are those words++ movq m, p1+ leaq (p1,k,8), p2+ xorq i, i+Lbignum_modinv_toploop:+ movq (p1,i,8), b+ movq (p2,i,8), c+ movq c2, c1+ andq h1, c1+ andq h2, c2+ movq b, a+ orq c, a+ negq a+ cmovcq c1, l1+ cmovcq c2, l2+ cmovcq b, h1+ cmovcq c, h2+ sbbq c2, c2+ incq i+ cmpq l, i+ jc Lbignum_modinv_toploop++ movq h1, a+ orq h2, a+ bsrq a, c+ xorq $63, c+ shldq %cl, l1, h1+ shldq %cl, l2, h2++// m_lo = m[0], n_lo = n[0];++ movq (p1), %rax+ movq %rax, m_lo++ movq (p2), %rax+ movq %rax, n_lo++// Now the inner loop, with i as loop counter from CHUNKSIZE down.+// This records a matrix of updates to apply to the initial+// values of m and n with, at stage j:+//+// sgn * m' = (m_m * m - m_n * n) / 2^j+// -sgn * n' = (n_m * m - n_n * n) / 2^j+//+// where "sgn" is either +1 or -1, and we lose track of which except+// that both instance above are the same. This throwing away the sign+// costs nothing (since we have to correct in general anyway because+// of the proxied comparison) and makes things a bit simpler. But it+// is simply the parity of the number of times the first condition,+// used as the swapping criterion, fires in this loop.++ movl $1, m_mshort+ movl $0, m_nshort+ movl $0, n_mshort+ movl $1, n_nshort+ movl $CHUNKSIZE, ishort++// Stash more variables over the inner loop to free up regs++ movq k, mat_mn+ movq l, mat_nm+ movq p1, mat_mm+ movq p2, mat_nn++// Conceptually in the inner loop we follow these steps:+//+// * If m_lo is odd and m_hi < n_hi, then swap the four pairs+// (m_hi,n_hi); (m_lo,n_lo); (m_m,n_m); (m_n,n_n)+//+// * Now, if m_lo is odd (old or new, doesn't matter as initial n_lo is odd)+// m_hi := m_hi - n_hi, m_lo := m_lo - n_lo+// m_m := m_m + n_m, m_n := m_n + n_n+//+// * Halve and double them+// m_hi := m_hi / 2, m_lo := m_lo / 2+// n_m := n_m * 2, n_n := n_n * 2+//+// The actual computation computes updates before actually swapping and+// then corrects as needed.++Lbignum_modinv_innerloop:++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorq p1, p1+ xorq p2, p2+ btq $0, m_lo++ cmovcq n_hi, %rax+ cmovcq n_lo, %rbx+ cmovcq n_m, p1+ cmovcq n_n, p2++ movq m_lo, l+ subq %rbx, m_lo+ subq l, %rbx+ movq m_hi, k+ subq %rax, k+ cmovcq m_hi, n_hi+ leaq -1(k), m_hi+ cmovcq %rbx, m_lo+ cmovcq l, n_lo+ notq m_hi+ cmovcq m_m, n_m+ cmovcq m_n, n_n+ cmovncq k, m_hi++ shrq $1, m_lo+ addq p1, m_m+ addq p2, m_n+ shrq $1, m_hi+ addq n_m, n_m+ addq n_n, n_n++// End of the inner for-loop++ decq i+ jnz Lbignum_modinv_innerloop++// Unstash the temporary variables++ movq mat_mn, k+ movq mat_nm, l+ movq mat_mm, p1+ movq mat_nn, p2++// Put the matrix entries in memory since we're out of registers+// We pull them out repeatedly in the next loop++ movq m_m, mat_mm+ movq m_n, mat_mn+ movq n_m, mat_nm+ movq n_n, mat_nn++// Apply the update to w and z, using addition in this case, and also take+// the chance to shift an additional 6 = 64-CHUNKSIZE bits to be ready for a+// Montgomery multiplication. Because we know that m_m + m_n <= 2^58 and+// w, z <= b < 2^{64k}, we know that both of these fit in k+1 words.+// We do this before the m-n update to allow us to play with c1 and c2 here.+//+// l1::w = 2^6 * (m_m * w + m_n * z)+// l2::z = 2^6 * (n_m * w + n_n * z)+//+// with c1 and c2 recording previous words for the shifting part++ movq w, p1+ movq z, p2+ xorq l1, l1+ xorq l2, l2+ xorq c1, c1+ xorq c2, c2+ xorq i, i+Lbignum_modinv_congloop:++ movq (p1,i,8), c+ movq mat_mm, a+ mulq c+ addq a, l1+ adcq $0, d+ movq d, h1 // Now h1::l1 := m_m * w + l1_in++ movq mat_nm, a+ mulq c+ addq a, l2+ adcq $0, d+ movq d, h2 // Now h2::l2 := n_m * w + l2_in++ movq (p2,i,8), c+ movq mat_mn, a+ mulq c+ addq a, l1+ adcq d, h1 // h1::l1 := m_m * w + m_n * z + l1_in+ shrdq $CHUNKSIZE, l1, c1+ movq c1, (p1,i,8)+ movq l1, c1+ movq h1, l1++ movq mat_nn, a+ mulq c+ addq a, l2+ adcq d, h2 // h2::l2 := n_m * w + n_n * z + l2_in+ shrdq $CHUNKSIZE, l2, c2+ movq c2, (p2,i,8)+ movq l2, c2+ movq h2, l2++ incq i+ cmpq k, i+ jc Lbignum_modinv_congloop++ shldq $64-CHUNKSIZE, c1, l1+ shldq $64-CHUNKSIZE, c2, l2++// Do a Montgomery reduction of l1::w++ movq bm, p2++ movq (p1), b+ movq v, h1+ imulq b, h1+ movq (p2), a+ mulq h1+ addq b, a // Will be zero but want the carry+ movq %rdx, c1+ movl $1, ishort+ movq k, c+ decq c+ jz Lbignum_modinv_wmontend++Lbignum_modinv_wmontloop:+ adcq (p1,i,8), c1+ sbbq b, b+ movq (p2,i,8), a+ mulq h1+ subq b, %rdx+ addq c1, a+ movq a, -8(p1,i,8)+ movq %rdx, c1+ incq i+ decq c+ jnz Lbignum_modinv_wmontloop++Lbignum_modinv_wmontend:+ adcq l1, c1+ movq c1, -8(p1,k,8)+ sbbq c1, c1+ negq c1++ movq k, c+ xorq i, i+Lbignum_modinv_wcmploop:+ movq (p1,i,8), a+ sbbq (p2,i,8), a+ incq i+ decq c+ jnz Lbignum_modinv_wcmploop+ sbbq $0, c1+ sbbq c1, c1+ notq c1++ xorq c, c+ xorq i, i+Lbignum_modinv_wcorrloop:+ movq (p1,i,8), a+ movq (p2,i,8), b+ andq c1, b+ negq c+ sbbq b, a+ sbbq c, c+ movq a, (p1,i,8)+ incq i+ cmpq k, i+ jc Lbignum_modinv_wcorrloop++// Do a Montgomery reduction of l2::z++ movq z, p1++ movq (p1), b+ movq v, h2+ imulq b, h2+ movq (p2), a+ mulq h2+ addq b, a // Will be zero but want the carry+ movq %rdx, c2+ movl $1, ishort+ movq k, c+ decq c+ jz Lbignum_modinv_zmontend++Lbignum_modinv_zmontloop:+ adcq (p1,i,8), c2+ sbbq b, b+ movq (p2,i,8), a+ mulq h2+ subq b, %rdx+ addq c2, a+ movq a, -8(p1,i,8)+ movq %rdx, c2+ incq i+ decq c+ jnz Lbignum_modinv_zmontloop++Lbignum_modinv_zmontend:+ adcq l2, c2+ movq c2, -8(p1,k,8)+ sbbq c2, c2+ negq c2++ movq k, c+ xorq i, i+Lbignum_modinv_zcmploop:+ movq (p1,i,8), a+ sbbq (p2,i,8), a+ incq i+ decq c+ jnz Lbignum_modinv_zcmploop+ sbbq $0, c2+ sbbq c2, c2+ notq c2++ xorq c, c+ xorq i, i+Lbignum_modinv_zcorrloop:+ movq (p1,i,8), a+ movq (p2,i,8), b+ andq c2, b+ negq c+ sbbq b, a+ sbbq c, c+ movq a, (p1,i,8)+ incq i+ cmpq k, i+ jc Lbignum_modinv_zcorrloop++// Now actually compute the updates to m and n corresponding to the matrix,+// and correct the signs if they have gone negative. First we compute the+// (k+1)-sized updates with the following invariant (here h1 and h2 are in+// fact carry bitmasks, either 0 or -1):+//+// h1::l1::m = m_m * m - m_n * n+// h2::l2::n = n_m * m - n_n * n++ movq m, p1+ leaq (p1,k,8), p2+ xorq i, i+ xorq h1, h1+ xorq l1, l1+ xorq h2, h2+ xorq l2, l2+Lbignum_modinv_crossloop:++ movq (p1,i,8), c+ movq mat_mm, a+ mulq c+ addq a, l1+ adcq $0, d+ movq d, c1 // Now c1::l1 is +ve part 1++ movq mat_nm, a+ mulq c+ addq a, l2+ adcq $0, d+ movq d, c2 // Now c2::l2 is +ve part 2++ movq (p2,i,8), c+ movq mat_mn, a+ mulq c+ subq h1, d // Now d::a is -ve part 1++ subq a, l1+ sbbq d, c1+ sbbq h1, h1+ movq l1, (p1,i,8)+ movq c1, l1++ movq mat_nn, a+ mulq c+ subq h2, d // Now d::a is -ve part 2++ subq a, l2+ sbbq d, c2+ sbbq h2, h2+ movq l2, (p2,i,8)+ movq c2, l2++ incq i+ cmpq l, i+ jc Lbignum_modinv_crossloop++// Now fix the signs of m and n if they have gone negative++ xorq i, i+ movq h1, c1 // carry-in coded up as well+ movq h2, c2 // carry-in coded up as well+ xorq h1, l1 // for the Lbignum_modinv_end digit+ xorq h2, l2 // for the Lbignum_modinv_end digit+Lbignum_modinv_optnegloop:+ movq (p1,i,8), a+ xorq h1, a+ negq c1+ adcq $0, a+ sbbq c1, c1+ movq a, (p1,i,8)+ movq (p2,i,8), a+ xorq h2, a+ negq c2+ adcq $0, a+ sbbq c2, c2+ movq a, (p2,i,8)+ incq i+ cmpq l, i+ jc Lbignum_modinv_optnegloop+ subq c1, l1+ subq c2, l2++// Now shift them right CHUNKSIZE bits++ movq l, i+Lbignum_modinv_shiftloop:+ movq -8(p1,i,8), a+ movq a, c1+ shrdq $CHUNKSIZE, l1, a+ movq a, -8(p1,i,8)+ movq c1, l1+ movq -8(p2,i,8), a+ movq a, c2+ shrdq $CHUNKSIZE, l2, a+ movq a, -8(p2,i,8)+ movq c2, l2+ decq i+ jnz Lbignum_modinv_shiftloop++// Finally, use the signs h1 and h2 to do optional modular negations of+// w and z respectively, flipping h2 to make signs work. We don't make+// any checks for zero values, but we certainly retain w <= b and z <= b.+// This is enough for the Montgomery step in the next iteration to give+// strict reduction w < b amd z < b, and anyway when we terminate we+// could not have z = b since it violates the coprimality assumption for+// in-scope cases.++ notq h2+ movq bm, c+ movq w, p1+ movq z, p2+ movq h1, c1+ movq h2, c2+ xorq i, i+Lbignum_modinv_fliploop:+ movq h2, d+ movq (c,i,8), a+ andq a, d+ andq h1, a+ movq (p1,i,8), b+ xorq h1, b+ negq c1+ adcq b, a+ sbbq c1, c1+ movq a, (p1,i,8)+ movq (p2,i,8), b+ xorq h2, b+ negq c2+ adcq b, d+ sbbq c2, c2+ movq d, (p2,i,8)+ incq i+ cmpq k, i+ jc Lbignum_modinv_fliploop++// End of main loop. We can stop if t' <= 0 since then m * n < 2^0, which+// since n is odd and m and n are coprime (in the in-scope cases) means+// m = 0, n = 1 and hence from the congruence invariant a * z == 1 (mod b).+// Moreover we do in fact need to maintain strictly t > 0 in the main loop,+// or the computation of the optimized digit bound l could collapse to 0.++ subq $CHUNKSIZE, t+ jnbe Lbignum_modinv_outerloop++Lbignum_modinv_end:+ CFI_INC_RSP(STACKVARSIZE)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_POP(%rbp)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_modinv)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_montinv_p384.S view
@@ -0,0 +1,1834 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery inverse modulo p_384 = 2^384 - 2^128 - 2^96 + 2^32 - 1+// Input x[6]; output z[6]+//+// extern void bignum_montinv_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// If the 6-digit input x is coprime to p_384, i.e. is not divisible+// by it, returns z < p_384 such that x * z == 2^768 (mod p_384). This+// is effectively "Montgomery inverse" because if we consider x and z as+// Montgomery forms of X and Z, i.e. x == 2^384 * X and z == 2^384 * Z+// (both mod p_384) then X * Z == 1 (mod p_384). That is, this function+// gives the analog of the modular inverse bignum_inv_p384 but with both+// input and output in the Montgomery domain. Note that x does not need+// to be reduced modulo p_384, but the output always is. If the input+// is divisible (i.e. is 0 or p_384), then there can be no solution to+// the congruence x * z == 2^768 (mod p_384), and z = 0 is returned.+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montinv_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montinv_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montinv_p384)+ .text+ .balign 32++// Size in bytes of a 64-bit word++#define N 8++// Pointer-offset pairs for temporaries on stack+// The u and v variables are 6 words each as expected, but the f and g+// variables are 8 words each -- they need to have at least one extra+// word for a sign word, and to preserve alignment we "round up" to 8.+// In fact, we currently keep an extra word in u and v as well.++#define f 0(%rsp)+#define g (8*N)(%rsp)+#define u (16*N)(%rsp)+#define v (24*N)(%rsp)+#define tmp (32*N)(%rsp)+#define tmp2 (33*N)(%rsp)+#define i (34*N)(%rsp)+#define d (35*N)(%rsp)++#define mat (36*N)(%rsp)++// Backup for the input pointer++#define res (40*N)(%rsp)++// Total size to reserve on the stack++#define NSPACE 42*N++// Syntactic variants to make x86_att version simpler to generate++#define F 0+#define G (8*N)+#define U (16*N)+#define V (24*N)+#define MAT (36*N)++#define ff (%rsp)+#define gg (8*N)(%rsp)++// ---------------------------------------------------------------------------+// Core signed almost-Montgomery reduction macro from P[6..0] to P[5..0].+// ---------------------------------------------------------------------------++#define amontred(P) \+/* We only know the input is -2^444 < x < 2^444. To do traditional */ \+/* unsigned Montgomery reduction, start by adding 2^61 * p_384. */ \+ movq $0xe000000000000000, %r8 ; \+ xorl %eax, %eax ; \+ addq P, %r8 ; \+ movq $0x000000001fffffff, %r9 ; \+ leaq -1(%rax), %rax ; \+ adcq N+P, %r9 ; \+ movq $0xdfffffffe0000000, %r10 ; \+ adcq 2*N+P, %r10 ; \+ movq 3*N+P, %r11 ; \+ adcq %rax, %r11 ; \+ movq 4*N+P, %r12 ; \+ adcq %rax, %r12 ; \+ movq 5*N+P, %r13 ; \+ adcq %rax, %r13 ; \+ movq $0x1fffffffffffffff, %r14 ; \+ adcq 6*N+P, %r14 ; \+/* Correction multiplier is %rbx = w = [d0 + (d0<<32)] mod 2^64 */ \+ movq %r8, %rbx ; \+ shlq $32, %rbx ; \+ addq %r8, %rbx ; \+/* Construct [%rbp;%rdx;%rax;-] = (2^384 - p_384) * w */ \+/* We know lowest word will cancel so can re-use %r8 as a temp */ \+ xorl %ebp, %ebp ; \+ movq $0xffffffff00000001, %rax ; \+ mulq %rbx; \+ movq %rdx, %r8 ; \+ movq $0x00000000ffffffff, %rax ; \+ mulq %rbx; \+ addq %r8, %rax ; \+ adcq %rbx, %rdx ; \+ adcl %ebp, %ebp ; \+/* Now subtract that and add 2^384 * w, catching carry in %rax */ \+ subq %rax, %r9 ; \+ sbbq %rdx, %r10 ; \+ sbbq %rbp, %r11 ; \+ sbbq $0, %r12 ; \+ sbbq $0, %r13 ; \+ sbbq $0, %r14 ; \+ sbbq %rax, %rax ; \+ addq %rbx, %r14 ; \+ adcq $0, %rax ; \+/* Now if top is nonzero we subtract p_384 (almost-Montgomery) */ \+ negq %rax; \+ movq $0x00000000ffffffff, %rbx ; \+ andq %rax, %rbx ; \+ movq $0xffffffff00000000, %rcx ; \+ andq %rax, %rcx ; \+ movq $0xfffffffffffffffe, %rdx ; \+ andq %rax, %rdx ; \+ subq %rbx, %r9 ; \+ movq %r9, P ; \+ sbbq %rcx, %r10 ; \+ movq %r10, N+P ; \+ sbbq %rdx, %r11 ; \+ movq %r11, 2*N+P ; \+ sbbq %rax, %r12 ; \+ movq %r12, 3*N+P ; \+ sbbq %rax, %r13 ; \+ movq %r13, 4*N+P ; \+ sbbq %rax, %r14 ; \+ movq %r14, 5*N+P++// Very similar to a subroutine call to the s2n-bignum word_divstep59.+// But different in register usage and returning the final matrix as+//+// [ %r8 %r10]+// [ %r12 %r14]+//+// and also returning the matrix still negated (which doesn't matter)++#define divstep59(din,fin,gin) \+ movq din, %rsi ; \+ movq fin, %rdx ; \+ movq gin, %rcx ; \+ movq %rdx, %rbx ; \+ andq $0xfffff, %rbx ; \+ movabsq $0xfffffe0000000000, %rax ; \+ orq %rax, %rbx ; \+ andq $0xfffff, %rcx ; \+ movabsq $0xc000000000000000, %rax ; \+ orq %rax, %rcx ; \+ movq $0xfffffffffffffffe, %rax ; \+ xorl %ebp, %ebp ; \+ movl $0x2, %edx ; \+ movq %rbx, %rdi ; \+ movq %rax, %r8 ; \+ testq %rsi, %rsi ; \+ cmovs %rbp, %r8 ; \+ testq $0x1, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ sarq $1, %rcx ; \+ movl $0x100000, %eax ; \+ leaq (%rbx,%rax), %rdx ; \+ leaq (%rcx,%rax), %rdi ; \+ shlq $0x16, %rdx ; \+ shlq $0x16, %rdi ; \+ sarq $0x2b, %rdx ; \+ sarq $0x2b, %rdi ; \+ movabsq $0x20000100000, %rax ; \+ leaq (%rbx,%rax), %rbx ; \+ leaq (%rcx,%rax), %rcx ; \+ sarq $0x2a, %rbx ; \+ sarq $0x2a, %rcx ; \+ movq %rdx, MAT(%rsp) ; \+ movq %rbx, MAT+0x8(%rsp) ; \+ movq %rdi, MAT+0x10(%rsp) ; \+ movq %rcx, MAT+0x18(%rsp) ; \+ movq fin, %r12 ; \+ imulq %r12, %rdi ; \+ imulq %rdx, %r12 ; \+ movq gin, %r13 ; \+ imulq %r13, %rbx ; \+ imulq %rcx, %r13 ; \+ addq %rbx, %r12 ; \+ addq %rdi, %r13 ; \+ sarq $0x14, %r12 ; \+ sarq $0x14, %r13 ; \+ movq %r12, %rbx ; \+ andq $0xfffff, %rbx ; \+ movabsq $0xfffffe0000000000, %rax ; \+ orq %rax, %rbx ; \+ movq %r13, %rcx ; \+ andq $0xfffff, %rcx ; \+ movabsq $0xc000000000000000, %rax ; \+ orq %rax, %rcx ; \+ movq $0xfffffffffffffffe, %rax ; \+ movl $0x2, %edx ; \+ movq %rbx, %rdi ; \+ movq %rax, %r8 ; \+ testq %rsi, %rsi ; \+ cmovs %rbp, %r8 ; \+ testq $0x1, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ sarq $1, %rcx ; \+ movl $0x100000, %eax ; \+ leaq (%rbx,%rax), %r8 ; \+ leaq (%rcx,%rax), %r10 ; \+ shlq $0x16, %r8 ; \+ shlq $0x16, %r10 ; \+ sarq $0x2b, %r8 ; \+ sarq $0x2b, %r10 ; \+ movabsq $0x20000100000, %rax ; \+ leaq (%rbx,%rax), %r15 ; \+ leaq (%rcx,%rax), %r11 ; \+ sarq $0x2a, %r15 ; \+ sarq $0x2a, %r11 ; \+ movq %r13, %rbx ; \+ movq %r12, %rcx ; \+ imulq %r8, %r12 ; \+ imulq %r15, %rbx ; \+ addq %rbx, %r12 ; \+ imulq %r11, %r13 ; \+ imulq %r10, %rcx ; \+ addq %rcx, %r13 ; \+ sarq $0x14, %r12 ; \+ sarq $0x14, %r13 ; \+ movq %r12, %rbx ; \+ andq $0xfffff, %rbx ; \+ movabsq $0xfffffe0000000000, %rax ; \+ orq %rax, %rbx ; \+ movq %r13, %rcx ; \+ andq $0xfffff, %rcx ; \+ movabsq $0xc000000000000000, %rax ; \+ orq %rax, %rcx ; \+ movq MAT(%rsp), %rax ; \+ imulq %r8, %rax ; \+ movq MAT+0x10(%rsp), %rdx ; \+ imulq %r15, %rdx ; \+ imulq MAT+0x8(%rsp), %r8 ; \+ imulq MAT+0x18(%rsp), %r15 ; \+ addq %r8, %r15 ; \+ leaq (%rax,%rdx), %r9 ; \+ movq MAT(%rsp), %rax ; \+ imulq %r10, %rax ; \+ movq MAT+0x10(%rsp), %rdx ; \+ imulq %r11, %rdx ; \+ imulq MAT+0x8(%rsp), %r10 ; \+ imulq MAT+0x18(%rsp), %r11 ; \+ addq %r10, %r11 ; \+ leaq (%rax,%rdx), %r13 ; \+ movq $0xfffffffffffffffe, %rax ; \+ movl $0x2, %edx ; \+ movq %rbx, %rdi ; \+ movq %rax, %r8 ; \+ testq %rsi, %rsi ; \+ cmovs %rbp, %r8 ; \+ testq $0x1, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ cmovs %rbp, %r8 ; \+ movq %rbx, %rdi ; \+ testq %rdx, %rcx ; \+ cmoveq %rbp, %r8 ; \+ cmoveq %rbp, %rdi ; \+ sarq $1, %rcx ; \+ xorq %r8, %rdi ; \+ xorq %r8, %rsi ; \+ btq $0x3f, %r8 ; \+ cmovbq %rcx, %rbx ; \+ movq %rax, %r8 ; \+ subq %rax, %rsi ; \+ leaq (%rcx,%rdi), %rcx ; \+ sarq $1, %rcx ; \+ movl $0x100000, %eax ; \+ leaq (%rbx,%rax), %r8 ; \+ leaq (%rcx,%rax), %r12 ; \+ shlq $0x15, %r8 ; \+ shlq $0x15, %r12 ; \+ sarq $0x2b, %r8 ; \+ sarq $0x2b, %r12 ; \+ movabsq $0x20000100000, %rax ; \+ leaq (%rbx,%rax), %r10 ; \+ leaq (%rcx,%rax), %r14 ; \+ sarq $0x2b, %r10 ; \+ sarq $0x2b, %r14 ; \+ movq %r9, %rax ; \+ imulq %r8, %rax ; \+ movq %r13, %rdx ; \+ imulq %r10, %rdx ; \+ imulq %r15, %r8 ; \+ imulq %r11, %r10 ; \+ addq %r8, %r10 ; \+ leaq (%rax,%rdx), %r8 ; \+ movq %r9, %rax ; \+ imulq %r12, %rax ; \+ movq %r13, %rdx ; \+ imulq %r14, %rdx ; \+ imulq %r15, %r12 ; \+ imulq %r11, %r14 ; \+ addq %r12, %r14 ; \+ leaq (%rax,%rdx), %r12++S2N_BN_SYMBOL(bignum_montinv_p384):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save registers and make room for temporaries++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++// Save the return pointer for the end so we can overwrite %rdi later++ movq %rdi, res++// Copy the constant p_384 into f including the 7th zero digit++ movl $0xffffffff, %eax+ movq %rax, F(%rsp)+ movq %rax, %rbx+ notq %rbx+ movq %rbx, F+N(%rsp)+ xorl %ebp, %ebp+ leaq -2(%rbp), %rcx+ movq %rcx, F+2*N(%rsp)+ leaq -1(%rbp), %rdx+ movq %rdx, F+3*N(%rsp)+ movq %rdx, F+4*N(%rsp)+ movq %rdx, F+5*N(%rsp)+ movq %rbp, F+6*N(%rsp)++// Copy input but to g, reduced mod p_384 so that g <= f as assumed+// in the divstep bound proof.++ movq (%rsi), %r8+ subq %rax, %r8+ movq N(%rsi), %r9+ sbbq %rbx, %r9+ movq 2*N(%rsi), %r10+ sbbq %rcx, %r10+ movq 3*N(%rsi), %r11+ sbbq %rdx, %r11+ movq 4*N(%rsi), %r12+ sbbq %rdx, %r12+ movq 5*N(%rsi), %r13+ sbbq %rdx, %r13++ cmovcq (%rsi), %r8+ cmovcq N(%rsi), %r9+ cmovcq 2*N(%rsi), %r10+ cmovcq 3*N(%rsi), %r11+ cmovcq 4*N(%rsi), %r12+ cmovcq 5*N(%rsi), %r13++ movq %r8, G(%rsp)+ movq %r9, G+N(%rsp)+ movq %r10, G+2*N(%rsp)+ movq %r11, G+3*N(%rsp)+ movq %r12, G+4*N(%rsp)+ movq %r13, G+5*N(%rsp)+ movq %rbp, G+6*N(%rsp)++// Also maintain reduced < 2^384 vector [u,v] such that+// [f,g] == x * 2^{5*i-843} * [u,v] (mod p_384)+// starting with [p_384,x] == x * 2^{5*0-843} * [0,2^843] (mod p_384)+// The weird-looking 5*i modifications come in because we are doing+// 64-bit word-sized Montgomery reductions at each stage, which is+// 5 bits more than the 59-bit requirement to keep things stable.+// After the 15th and last iteration and sign adjustment, when+// f == 1 for in-scope cases, we have x * 2^{75-843} * u == 1, i.e.+// x * u == 2^768 as required.++ xorl %eax, %eax+ movq %rax, U(%rsp)+ movq %rax, U+N(%rsp)+ movq %rax, U+2*N(%rsp)+ movq %rax, U+3*N(%rsp)+ movq %rax, U+4*N(%rsp)+ movq %rax, U+5*N(%rsp)++// The starting constant 2^843 mod p_384 is+// 0x0000000000000800:00001000000007ff:fffff00000000000+// :00001000000007ff:fffff00000000800:0000000000000000+// where colons separate 64-bit subwords, least significant at the right.+// These are constructed dynamically to reduce large constant loads.++ movq %rax, V(%rsp)+ movq $0xfffff00000000800, %rcx+ movq %rcx, V+N(%rsp)+ movq $0x00001000000007ff, %rdx+ movq %rdx, V+2*N(%rsp)+ btr $11, %rcx+ movq %rcx, V+3*N(%rsp)+ movq %rdx, V+4*N(%rsp)+ bts $11, %rax+ movq %rax, V+5*N(%rsp)++// Start of main loop. We jump into the middle so that the divstep+// portion is common to the special fifteenth iteration after a uniform+// first 14.++ movq $15, i+ movq $1, d+ jmp Lbignum_montinv_p384_midloop++Lbignum_montinv_p384_loop:++// Separate out the matrix into sign-magnitude pairs++ movq %r8, %r9+ sarq $63, %r9+ xorq %r9, %r8+ subq %r9, %r8++ movq %r10, %r11+ sarq $63, %r11+ xorq %r11, %r10+ subq %r11, %r10++ movq %r12, %r13+ sarq $63, %r13+ xorq %r13, %r12+ subq %r13, %r12++ movq %r14, %r15+ sarq $63, %r15+ xorq %r15, %r14+ subq %r15, %r14++// Adjust the initial values to allow for complement instead of negation+// This initial offset is the same for [f,g] and [u,v] compositions.+// Save it in temporary storage for the [u,v] part and do [f,g] first.++ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, tmp++ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, tmp2++// Now the computation of the updated f and g values. This maintains a+// 2-word carry between stages so we can conveniently insert the shift+// right by 59 before storing back, and not overwrite digits we need+// again of the old f and g values.+//+// Digit 0 of [f,g]++ xorl %ebx, %ebx+ movq F(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq G(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq F(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq G(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp++// Digit 1 of [f,g]++ xorl %ecx, %ecx+ movq F+N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq G+N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $59, %rbx, %rdi+ movq %rdi, F(%rsp)++ xorl %edi, %edi+ movq F+N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq G+N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $59, %rbp, %rsi+ movq %rsi, G(%rsp)++// Digit 2 of [f,g]++ xorl %esi, %esi+ movq F+2*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq G+2*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $59, %rcx, %rbx+ movq %rbx, F+N(%rsp)++ xorl %ebx, %ebx+ movq F+2*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq G+2*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $59, %rdi, %rbp+ movq %rbp, G+N(%rsp)++// Digit 3 of [f,g]++ xorl %ebp, %ebp+ movq F+3*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq G+3*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $59, %rsi, %rcx+ movq %rcx, F+2*N(%rsp)++ xorl %ecx, %ecx+ movq F+3*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq G+3*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $59, %rbx, %rdi+ movq %rdi, G+2*N(%rsp)++// Digit 4 of [f,g]++ xorl %edi, %edi+ movq F+4*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq G+4*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $59, %rbp, %rsi+ movq %rsi, F+3*N(%rsp)++ xorl %esi, %esi+ movq F+4*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq G+4*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $59, %rcx, %rbx+ movq %rbx, G+3*N(%rsp)++// Digits 5 and 6 of [f,g]++ movq F+5*N(%rsp), %rax+ xorq %r9, %rax+ movq F+6*N(%rsp), %rbx+ xorq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq G+5*N(%rsp), %rax+ xorq %r11, %rax+ movq G+6*N(%rsp), %rdx+ xorq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $59, %rdi, %rbp+ movq %rbp, F+4*N(%rsp)+ shrdq $59, %rbx, %rdi+ sarq $59, %rbx++ movq F+5*N(%rsp), %rax+ movq %rdi, F+5*N(%rsp)++ movq F+6*N(%rsp), %rdi+ movq %rbx, F+6*N(%rsp)++ xorq %r13, %rax+ xorq %r13, %rdi+ andq %r12, %rdi+ negq %rdi+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rdi+ movq G+5*N(%rsp), %rax+ xorq %r15, %rax+ movq G+6*N(%rsp), %rdx+ xorq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rdi+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rdi+ shrdq $59, %rsi, %rcx+ movq %rcx, G+4*N(%rsp)+ shrdq $59, %rdi, %rsi+ movq %rsi, G+5*N(%rsp)+ sarq $59, %rdi+ movq %rdi, G+6*N(%rsp)++// Get the initial carries back from storage and do the [u,v] accumulation++ movq tmp, %rbx+ movq tmp2, %rbp++// Digit 0 of [u,v]++ xorl %ecx, %ecx+ movq U(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx++ xorl %esi, %esi+ movq U(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, U(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq V(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, V(%rsp)++// Digit 1 of [u,v]++ xorl %ebx, %ebx+ movq U+N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq U+N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, U+N(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq V+N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, V+N(%rsp)++// Digit 2 of [u,v]++ xorl %ecx, %ecx+ movq U+2*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+2*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx++ xorl %esi, %esi+ movq U+2*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, U+2*N(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq V+2*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, V+2*N(%rsp)++// Digit 3 of [u,v]++ xorl %ebx, %ebx+ movq U+3*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+3*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx++ xorl %ebp, %ebp+ movq U+3*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, U+3*N(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq V+3*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, V+3*N(%rsp)++// Digit 4 of [u,v]++ xorl %ecx, %ecx+ movq U+4*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq V+4*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx++ xorl %esi, %esi+ movq U+4*N(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, U+4*N(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq V+4*N(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, V+4*N(%rsp)++// Digits 5 and 6 of u (top is unsigned)++ movq U+5*N(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq V+5*N(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx++// Preload for last use of old u digit 3++ movq U+5*N(%rsp), %rax+ movq %rcx, U+5*N(%rsp)+ movq %rdx, U+6*N(%rsp)++// Digits 5 and 6 of v (top is unsigned)++ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq V+5*N(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rsi, V+5*N(%rsp)+ movq %rdx, V+6*N(%rsp)++// Montgomery reduction of u++ amontred(u)++// Montgomery reduction of v++ amontred(v)++Lbignum_montinv_p384_midloop:++ divstep59(d,ff,gg)+ movq %rsi, d++// Next iteration++ decq i+ jnz Lbignum_montinv_p384_loop++// The 15th and last iteration does not need anything except the+// u value and the sign of f; the latter can be obtained from the+// lowest word of f. So it's done differently from the main loop.+// Find the sign of the new f. For this we just need one digit+// since we know (for in-scope cases) that f is either +1 or -1.+// We don't explicitly shift right by 59 either, but looking at+// bit 63 (or any bit >= 60) of the unshifted result is enough+// to distinguish -1 from +1; this is then made into a mask.++ movq F(%rsp), %rax+ movq G(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $63, %rax++// Now separate out the matrix into sign-magnitude pairs+// and adjust each one based on the sign of f.+//+// Note that at this point we expect |f|=1 and we got its+// sign above, so then since [f,0] == x * 2^{-768} [u,v] (mod p_384)+// we want to flip the sign of u according to that of f.++ movq %r8, %r9+ sarq $63, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9++ movq %r10, %r11+ sarq $63, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11++ movq %r12, %r13+ sarq $63, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13++ movq %r14, %r15+ sarq $63, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15++// Adjust the initial value to allow for complement instead of negation++ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12++// Digit 0 of [u]++ xorl %r13d, %r13d+ movq U(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq V(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ movq %r12, U(%rsp)+ adcq %rdx, %r13++// Digit 1 of [u]++ xorl %r14d, %r14d+ movq U+N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq V+N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ movq %r13, U+N(%rsp)+ adcq %rdx, %r14++// Digit 2 of [u]++ xorl %r15d, %r15d+ movq U+2*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq V+2*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ movq %r14, U+2*N(%rsp)+ adcq %rdx, %r15++// Digit 3 of [u]++ xorl %r14d, %r14d+ movq U+3*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r14+ movq V+3*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r15+ movq %r15, U+3*N(%rsp)+ adcq %rdx, %r14++// Digit 4 of [u]++ xorl %r15d, %r15d+ movq U+4*N(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq V+4*N(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ movq %r14, U+4*N(%rsp)+ adcq %rdx, %r15++// Digits 5 and 6 of u (top is unsigned)++ movq U+5*N(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq V+5*N(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ movq %r15, U+5*N(%rsp)+ adcq %rdx, %r9+ movq %r9, U+6*N(%rsp)++// Montgomery reduce u++ amontred(u)++// Perform final strict reduction mod p_384 and copy to output++ movl $0xffffffff, %eax+ movq %rax, %rbx+ notq %rbx+ xorl %ebp, %ebp+ leaq -2(%rbp), %rcx+ leaq -1(%rbp), %rdx++ movq U(%rsp), %r8+ subq %rax, %r8+ movq U+N(%rsp), %r9+ sbbq %rbx, %r9+ movq U+2*N(%rsp), %r10+ sbbq %rcx, %r10+ movq U+3*N(%rsp), %r11+ sbbq %rdx, %r11+ movq U+4*N(%rsp), %r12+ sbbq %rdx, %r12+ movq U+5*N(%rsp), %r13+ sbbq %rdx, %r13++ cmovcq U(%rsp), %r8+ cmovcq U+N(%rsp), %r9+ cmovcq U+2*N(%rsp), %r10+ cmovcq U+3*N(%rsp), %r11+ cmovcq U+4*N(%rsp), %r12+ cmovcq U+5*N(%rsp), %r13++ movq res, %rdi+ movq %r8, (%rdi)+ movq %r9, N(%rdi)+ movq %r10, 2*N(%rdi)+ movq %r11, 3*N(%rdi)+ movq %r12, 4*N(%rdi)+ movq %r13, 5*N(%rdi)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montinv_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/bignum_montmul_p384.S view
@@ -0,0 +1,291 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery multiply, z := (x * y / 2^384) mod p_384+// Inputs x[6], y[6]; output z[6]+//+// extern void bignum_montmul_p384(uint64_t z[static 6],+// const uint64_t x[static 6],+// const uint64_t y[static 6]);+//+// Does z := (2^{-384} * x * y) mod p_384, assuming that the inputs x and y+// satisfy x * y <= 2^384 * p_384 (in particular this is true if we are in+// the "usual" case x < p_384 and y < p_384).+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = y+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = y+// -----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montmul_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montmul_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montmul_p384)+ .text++#define z %rdi+#define x %rsi++// We move the y argument here so we can use %rdx for multipliers++#define y %rcx++// Some temp registers for the last correction stage++#define d %rax+#define u %rdx+#define v %rcx+#define w %rbx++// Add %rdx * m into a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rbx as temporaries++#define mulpadd(high,low,m) \+ mulxq m, %rax, %rbx ; \+ adcxq %rax, low ; \+ adoxq %rbx, high++// Core one-step Montgomery reduction macro. Takes input in+// [d7;d6;d5;d4;d3;d2;d1;d0] and returns result in [d7;d6;d5;d4;d3;d2;d1],+// adding to the existing contents, re-using d0 as a temporary internally+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+//+// montredc(d7,d6,d5,d4,d3,d2,d1,d0)+//+// This particular variant, with its mix of addition and subtraction+// at the top, is not intended to maintain a coherent carry or borrow out.+// It is assumed the final result would fit in [d7;d6;d5;d4;d3;d2;d1].+// which is always the case here as the top word is even always in {0,1}++#define montredc(d7,d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rdx ; \+ shlq $32, %rdx ; \+ addq d0, %rdx ; \+/* Construct [%rbp;%rbx;%rax;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 as a temp */ \+ xorl %ebp, %ebp ; \+ movq $0xffffffff00000001, %rax ; \+ mulxq %rax, %rbx, %rax ; \+ movl $0x00000000ffffffff, %ebx ; \+ mulxq %rbx, d0, %rbx ; \+ adcq d0, %rax ; \+ adcq %rdx, %rbx ; \+ adcl %ebp, %ebp ; \+/* Now subtract that and add 2^384 * w */ \+ subq %rax, d1 ; \+ sbbq %rbx, d2 ; \+ sbbq %rbp, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ sbbq $0, %rdx ; \+ addq %rdx, d6 ; \+ adcq $0, d7++S2N_BN_SYMBOL(bignum_montmul_p384):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save more registers to play with++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Copy y into a safe register to start with++ movq %rdx, y++// Do row 0 computation, which is a bit different:+// set up initial window [%r14,%r13,%r12,%r11,%r10,%r9,%r8] = y[0] * x+// Unlike later, we only need a single carry chain++ movq (y), %rdx+ xorl %r15d, %r15d+ mulxq (x), %r8, %r9+ mulxq 8(x), %rbx, %r10+ addq %rbx, %r9+ mulxq 16(x), %rbx, %r11+ adcq %rbx, %r10+ mulxq 24(x), %rbx, %r12+ adcq %rbx, %r11+ mulxq 32(x), %rbx, %r13+ adcq %rbx, %r12+ mulxq 40(x), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14++// Montgomery reduce the zeroth window++ montredc(%r15, %r14,%r13,%r12,%r11,%r10,%r9,%r8)++// Add row 1++ movq 8(y), %rdx+ xorl %r8d, %r8d+ mulpadd(%r10,%r9,(x))+ mulpadd(%r11,%r10, 8(x))+ mulpadd(%r12,%r11,16(x))+ mulpadd(%r13,%r12,24(x))+ mulpadd(%r14,%r13,32(x))+ adoxq %r8, %r15+ mulxq 40(x), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8++// Montgomery reduce window 1++ montredc(%r8, %r15,%r14,%r13,%r12,%r11,%r10,%r9)++// Add row 2++ movq 16(y), %rdx+ xorl %r9d, %r9d+ mulpadd(%r11,%r10,(x))+ mulpadd(%r12,%r11,8(x))+ mulpadd(%r13,%r12,16(x))+ mulpadd(%r14,%r13,24(x))+ mulpadd(%r15,%r14,32(x))+ adoxq %r9, %r8+ mulxq 40(x), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9++// Montgomery reduce window 2++ montredc(%r9, %r8,%r15,%r14,%r13,%r12,%r11,%r10)++// Add row 3++ movq 24(y), %rdx+ xorl %r10d, %r10d+ mulpadd(%r12,%r11,(x))+ mulpadd(%r13,%r12,8(x))+ mulpadd(%r14,%r13,16(x))+ mulpadd(%r15,%r14,24(x))+ mulpadd(%r8,%r15,32(x))+ adoxq %r10, %r9+ mulxq 40(x), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10++// Montgomery reduce window 3++ montredc(%r10, %r9,%r8,%r15,%r14,%r13,%r12,%r11)++// Add row 4++ movq 32(y), %rdx+ xorl %r11d, %r11d+ mulpadd(%r13,%r12,(x))+ mulpadd(%r14,%r13,8(x))+ mulpadd(%r15,%r14,16(x))+ mulpadd(%r8,%r15,24(x))+ mulpadd(%r9,%r8,32(x))+ adoxq %r11, %r10+ mulxq 40(x), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11++// Montgomery reduce window 4++ montredc(%r11, %r10,%r9,%r8,%r15,%r14,%r13,%r12)++// Add row 5++ movq 40(y), %rdx+ xorl %r12d, %r12d+ mulpadd(%r14,%r13,(x))+ mulpadd(%r15,%r14,8(x))+ mulpadd(%r8,%r15,16(x))+ mulpadd(%r9,%r8,24(x))+ mulpadd(%r10,%r9,32(x))+ adoxq %r12, %r11+ mulxq 40(x), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12++// Montgomery reduce window 5++ montredc(%r12, %r11,%r10,%r9,%r8,%r15,%r14,%r13)++// We now have a pre-reduced 7-word form z = [%r12; %r11;%r10;%r9;%r8;%r15;%r14]+// Next, accumulate in different registers z - p_384, or more precisely+//+// [%r12; %r13;%rbp;%rdx;%rcx;%rbx;%rax] = z + (2^384 - p_384)++ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d++ movq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0x00000000ffffffff, %ebx+ adcq %r15, %rbx+ movl $0x0000000000000001, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0, %r12++// ~ZF <=> %r12 >= 1 <=> z + (2^384 - p_384) >= 2^384 <=> z >= p_384, which+// determines whether to use the further reduced argument or the original z.++ cmovnzq %rax, %r14+ cmovnzq %rbx, %r15+ cmovnzq %rcx, %r8+ cmovnzq %rdx, %r9+ cmovnzq %rbp, %r10+ cmovnzq %r13, %r11++// Write back the result++ movq %r14, (z)+ movq %r15, 8(z)+ movq %r8, 16(z)+ movq %r9, 24(z)+ movq %r10, 32(z)+ movq %r11, 40(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montmul_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_montmul_p384_alt.S view
@@ -0,0 +1,316 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery multiply, z := (x * y / 2^384) mod p_384+// Inputs x[6], y[6]; output z[6]+//+// extern void bignum_montmul_p384_alt(uint64_t z[static 6],+// const uint64_t x[static 6],+// const uint64_t y[static 6]);+//+// Does z := (2^{-384} * x * y) mod p_384, assuming that the inputs x and y+// satisfy x * y <= 2^384 * p_384 (in particular this is true if we are in+// the "usual" case x < p_384 and y < p_384).+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = y+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = y+// -----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montmul_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montmul_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montmul_p384_alt)+ .text++#define z %rdi+#define x %rsi++// We move the y argument here so we can use %rdx for multipliers++#define y %rcx++// Some temp registers for the last correction stage++#define d %rax+#define u %rdx+#define v %rcx+#define w %rbx++// Add %rbx * m into a register-pair (high,low) maintaining consistent+// carry-catching with carry (negated, as bitmask) and using %rax and %rdx+// as temporaries++#define mulpadd(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// Initial version assuming no carry-in++#define mulpadi(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// End version not catching the top carry-out++#define mulpade(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high++// Core one-step Montgomery reduction macro. Takes input in+// [d7;d6;d5;d4;d3;d2;d1;d0] and returns result in [d7;d6;d5;d4;d3;d2;d1],+// adding to the existing contents, re-using d0 as a temporary internally+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+//+// montredc(d7,d6,d5,d4,d3,d2,d1,d0)+//+// This particular variant, with its mix of addition and subtraction+// at the top, is not intended to maintain a coherent carry or borrow out.+// It is assumed the final result would fit in [d7;d6;d5;d4;d3;d2;d1].+// which is always the case here as the top word is even always in {0,1}++#define montredc(d7,d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rbx ; \+ shlq $32, %rbx ; \+ addq d0, %rbx ; \+/* Construct [%rbp;%rdx;%rax;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 as a temp */ \+ xorl %ebp, %ebp ; \+ movq $0xffffffff00000001, %rax ; \+ mulq %rbx; \+ movq %rdx, d0 ; \+ movq $0x00000000ffffffff, %rax ; \+ mulq %rbx; \+ addq d0, %rax ; \+ adcq %rbx, %rdx ; \+ adcl %ebp, %ebp ; \+/* Now subtract that and add 2^384 * w */ \+ subq %rax, d1 ; \+ sbbq %rdx, d2 ; \+ sbbq %rbp, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ sbbq $0, %rbx ; \+ addq %rbx, d6 ; \+ adcq $0, d7++S2N_BN_SYMBOL(bignum_montmul_p384_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save more registers to play with++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Copy y into a safe register to start with++ movq %rdx, y++// Do row 0 computation, which is a bit different:+// set up initial window [%r14,%r13,%r12,%r11,%r10,%r9,%r8] = y[0] * x+// Unlike later, we only need a single carry chain++ movq (y), %rbx+ movq (x), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9++ movq 8(x), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10++ movq 16(x), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11++ movq 24(x), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12++ movq 32(x), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13++ movq 40(x), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14++ xorl %r15d, %r15d++// Montgomery reduce the zeroth window++ montredc(%r15, %r14,%r13,%r12,%r11,%r10,%r9,%r8)++// Add row 1++ movq 8(y), %rbx+ mulpadi(%r8,%r10,%r9,(x))+ mulpadd(%r8,%r11,%r10,8(x))+ mulpadd(%r8,%r12,%r11,16(x))+ mulpadd(%r8,%r13,%r12,24(x))+ mulpadd(%r8,%r14,%r13,32(x))+ mulpadd(%r8,%r15,%r14,40(x))+ negq %r8++// Montgomery reduce window 1++ montredc(%r8, %r15,%r14,%r13,%r12,%r11,%r10,%r9)++// Add row 2++ movq 16(y), %rbx+ mulpadi(%r9,%r11,%r10,(x))+ mulpadd(%r9,%r12,%r11,8(x))+ mulpadd(%r9,%r13,%r12,16(x))+ mulpadd(%r9,%r14,%r13,24(x))+ mulpadd(%r9,%r15,%r14,32(x))+ mulpadd(%r9,%r8,%r15,40(x))+ negq %r9++// Montgomery reduce window 2++ montredc(%r9, %r8,%r15,%r14,%r13,%r12,%r11,%r10)++// Add row 3++ movq 24(y), %rbx+ mulpadi(%r10,%r12,%r11,(x))+ mulpadd(%r10,%r13,%r12,8(x))+ mulpadd(%r10,%r14,%r13,16(x))+ mulpadd(%r10,%r15,%r14,24(x))+ mulpadd(%r10,%r8,%r15,32(x))+ mulpadd(%r10,%r9,%r8,40(x))+ negq %r10++// Montgomery reduce window 3++ montredc(%r10, %r9,%r8,%r15,%r14,%r13,%r12,%r11)++// Add row 4++ movq 32(y), %rbx+ mulpadi(%r11,%r13,%r12,(x))+ mulpadd(%r11,%r14,%r13,8(x))+ mulpadd(%r11,%r15,%r14,16(x))+ mulpadd(%r11,%r8,%r15,24(x))+ mulpadd(%r11,%r9,%r8,32(x))+ mulpadd(%r11,%r10,%r9,40(x))+ negq %r11++// Montgomery reduce window 4++ montredc(%r11, %r10,%r9,%r8,%r15,%r14,%r13,%r12)++// Add row 5++ movq 40(y), %rbx+ mulpadi(%r12,%r14,%r13,(x))+ mulpadd(%r12,%r15,%r14,8(x))+ mulpadd(%r12,%r8,%r15,16(x))+ mulpadd(%r12,%r9,%r8,24(x))+ mulpadd(%r12,%r10,%r9,32(x))+ mulpadd(%r12,%r11,%r10,40(x))+ negq %r12++// Montgomery reduce window 5++ montredc(%r12, %r11,%r10,%r9,%r8,%r15,%r14,%r13)++// We now have a pre-reduced 7-word form z = [%r12; %r11;%r10;%r9;%r8;%r15;%r14]+// Next, accumulate in different registers z - p_384, or more precisely+//+// [%r12; %r13;%rbp;%rdx;%rcx;%rbx;%rax] = z + (2^384 - p_384)++ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d++ movq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0x00000000ffffffff, %ebx+ adcq %r15, %rbx+ movl $0x0000000000000001, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0, %r12++// ~ZF <=> %r12 >= 1 <=> z + (2^384 - p_384) >= 2^384 <=> z >= p_384, which+// determines whether to use the further reduced argument or the original z.++ cmovnzq %rax, %r14+ cmovnzq %rbx, %r15+ cmovnzq %rcx, %r8+ cmovnzq %rdx, %r9+ cmovnzq %rbp, %r10+ cmovnzq %r13, %r11++// Write back the result++ movq %r14, (z)+ movq %r15, 8(z)+ movq %r8, 16(z)+ movq %r9, 24(z)+ movq %r10, 32(z)+ movq %r11, 40(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montmul_p384_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_montsqr_p384.S view
@@ -0,0 +1,294 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery square, z := (x^2 / 2^384) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_montsqr_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Does z := (x^2 / 2^384) mod p_384, assuming x^2 <= 2^384 * p_384, which is+// guaranteed in particular if x < p_384 initially (the "intended" case).+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montsqr_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montsqr_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montsqr_p384)+ .text++#define z %rdi+#define x %rsi++// Some temp registers for the last correction stage++#define d %rax+#define u %rdx+#define v %r10+#define w %r11++// A zero register, very often++#define zero %rbp+#define zeroe %ebp++// Add %rdx * m into a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rbx as temporaries++#define mulpadd(high,low,m) \+ mulxq m, %rax, %rbx ; \+ adcxq %rax, low ; \+ adoxq %rbx, high++// Core one-step "short" Montgomery reduction macro. Takes input in+// [d5;d4;d3;d2;d1;d0] and returns result in [d6;d5;d4;d3;d2;d1],+// adding to the existing [d5;d4;d3;d2;d1] and re-using d0 as a+// temporary internally, as well as %rax, %rbx and %rdx.+// It is OK for d6 and d0 to be the same register (they often are)+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+//+// montreds(d6,d5,d4,d3,d2,d1,d0)++#define montreds(d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rdx ; \+ shlq $32, %rdx ; \+ addq d0, %rdx ; \+/* Construct [%rbx;d0;%rax;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 */ \+/* and %rbx as temps. */ \+ movq $0xffffffff00000001, %rax ; \+ mulxq %rax, d0, %rax ; \+ movl $0x00000000ffffffff, %ebx ; \+ mulxq %rbx, %rbx, d0 ; \+ addq %rbx, %rax ; \+ adcq %rdx, d0 ; \+ movl $0, %ebx ; \+ adcq %rbx, %rbx ; \+/* Now subtract that and add 2^384 * w */ \+ subq %rax, d1 ; \+ sbbq d0, d2 ; \+ sbbq %rbx, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ movq %rdx, d6 ; \+ sbbq $0, d6++S2N_BN_SYMBOL(bignum_montsqr_p384):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save more registers to play with++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Set up an initial window [%rcx;%r15;...%r9] = [34;05;03;01]+// Note that we are using %rcx as the first step past the rotating window++ movq (x), %rdx+ mulxq 8(x), %r9, %r10+ mulxq 24(x), %r11, %r12+ mulxq 40(x), %r13, %r14+ movq 24(x), %rdx+ mulxq 32(x), %r15, %rcx++// Clear our zero register, and also initialize the flags for the carry chain++ xorl zeroe, zeroe++// Chain in the addition of 02 + 12 + 13 + 14 + 15 to that window+// (no carry-out possible)++ movq 16(x), %rdx+ mulpadd(%r11,%r10,(x))+ mulpadd(%r12,%r11,8(x))+ movq 8(x), %rdx+ mulpadd(%r13,%r12,24(x))+ mulpadd(%r14,%r13,32(x))+ mulpadd(%r15,%r14,40(x))+ adcxq zero, %r15+ adoxq zero, %rcx+ adcq zero, %rcx++// Again zero out the flags. Actually they are already cleared but it may+// help decouple these in the OOO engine not to wait for the chain above++ xorl zeroe, zeroe++// Now chain in the 04 + 23 + 24 + 25 + 35 + 45 terms+// We are running out of registers in our rotating window, so we start+// using %rbx (and hence need care with using mulpadd after this). Thus+// our result so far is in [%rbp;%rbx;%rcx;%r15;...%r9]++ movq 32(x), %rdx+ mulpadd(%r13,%r12,(x))+ movq 16(x), %rdx+ mulpadd(%r14,%r13,24(x))+ mulpadd(%r15,%r14,32(x))+ mulxq 40(x), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx++// First set up the last couple of spots in our window, [%rbp;%rbx] = 45+// then add the last other term 35++ movq 40(x), %rdx+ mulxq 32(x), %rbx, %rbp+ mulxq 24(x), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp++// Just for a clear fresh start for the flags; we don't use the zero++ xorq %rax, %rax++// Double and add to the 00 + 11 + 22 + 33 + 44 + 55 terms+// For one glorious moment the entire squaring result is all in the+// register file as [%rsi;%rbp;%rbx;%rcx;%r15;...;%r8]+// (since we've now finished with x we can re-use %rsi)++ movq (x), %rdx+ mulxq (x), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 8(x), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 16(x), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 24(x), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 32(x), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 40(x), %rdx+ mulxq %rdx, %rax, %rsi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0, %eax+ adcxq %rax, %rsi+ adoxq %rax, %rsi++// We need just *one* more register as a temp for the Montgomery steps.+// Since we are writing to the z buffer anyway, make use of that to stash %rbx.++ movq %rbx, (z)++// Montgomery reduce the %r13,...,%r8 window 6 times++ montreds(%r8,%r13,%r12,%r11,%r10,%r9,%r8)+ montreds(%r9,%r8,%r13,%r12,%r11,%r10,%r9)+ montreds(%r10,%r9,%r8,%r13,%r12,%r11,%r10)+ montreds(%r11,%r10,%r9,%r8,%r13,%r12,%r11)+ montreds(%r12,%r11,%r10,%r9,%r8,%r13,%r12)+ montreds(%r13,%r12,%r11,%r10,%r9,%r8,%r13)++// Now we can safely restore %rbx before accumulating++ movq (z), %rbx++ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0, %r8d+ adcq %r8, %r8++// We now have a pre-reduced 7-word form z = [%r8; %rsi;%rbp;%rbx;%rcx;%r15;%r14]+// Next, accumulate in different registers z - p_384, or more precisely+//+// [%r8; %r13;%r12;%r11;%r10;%r9;%rax] = z + (2^384 - p_384)++ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0x00000000ffffffff, %r9d+ adcq %r15, %r9+ movl $0x0000000000000001, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rsi, %r13+ adcq $0, %r8++// ~ZF <=> %r12 >= 1 <=> z + (2^384 - p_384) >= 2^384 <=> z >= p_384, which+// determines whether to use the further reduced argument or the original z.++ cmovnzq %rax, %r14+ cmovnzq %r9, %r15+ cmovnzq %r10, %rcx+ cmovnzq %r11, %rbx+ cmovnzq %r12, %rbp+ cmovnzq %r13, %rsi++// Write back the result++ movq %r14, (z)+ movq %r15, 8(z)+ movq %rcx, 16(z)+ movq %rbx, 24(z)+ movq %rbp, 32(z)+ movq %rsi, 40(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montsqr_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_montsqr_p384_alt.S view
@@ -0,0 +1,339 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery square, z := (x^2 / 2^384) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_montsqr_p384_alt(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Does z := (x^2 / 2^384) mod p_384, assuming x^2 <= 2^384 * p_384, which is+// guaranteed in particular if x < p_384 initially (the "intended" case).+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_montsqr_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_montsqr_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_montsqr_p384_alt)+ .text++#define z %rdi+#define x %rsi++// Some temp registers for the last correction stage++#define d %rax+#define u %rdx+#define v %r10+#define w %r11++// A zero register, very often++#define zero %rbp+#define zeroe %ebp++// Add %rbx * m into a register-pair (high,low) maintaining consistent+// carry-catching with carry (negated, as bitmask) and using %rax and %rdx+// as temporaries++#define mulpadd(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// Initial version assuming no carry-in++#define mulpadi(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// End version not catching the top carry-out++#define mulpade(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high++// Core one-step "short" Montgomery reduction macro. Takes input in+// [d5;d4;d3;d2;d1;d0] and returns result in [d6;d5;d4;d3;d2;d1],+// adding to the existing [d5;d4;d3;d2;d1] and re-using d0 as a+// temporary internally, as well as %rax, %rbx and %rdx.+// It is OK for d6 and d0 to be the same register (they often are)+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+//+// montreds(d6,d5,d4,d3,d2,d1,d0)++#define montreds(d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rbx ; \+ shlq $32, %rbx ; \+ addq d0, %rbx ; \+/* Construct [%rax;%rdx;d0;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 */ \+/* and %rbx as temps. */ \+ movq $0xffffffff00000001, %rax ; \+ mulq %rbx; \+ movq %rdx, d0 ; \+ movq $0x00000000ffffffff, %rax ; \+ mulq %rbx; \+ addq %rax, d0 ; \+ movl $0, %eax ; \+ adcq %rbx, %rdx ; \+ adcl %eax, %eax ; \+/* Now subtract that and add 2^384 * w */ \+ subq d0, d1 ; \+ sbbq %rdx, d2 ; \+ sbbq %rax, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ movq %rbx, d6 ; \+ sbbq $0, d6++S2N_BN_SYMBOL(bignum_montsqr_p384_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save more registers to play with++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Set up an initial window [%rcx;%r15;...%r9] = [34;05;03;01]+// Note that we are using %rcx as the first step past the rotating window++ movq (x), %rbx+ movq 8(x), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10++ movq 24(x), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12++ movq 40(x), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14++ movq 24(x), %rax+ mulq 32(x)+ movq %rax, %r15+ movq %rdx, %rcx++// Chain in the addition of 02 + 12 + 13 + 14 + 15 to that window+// (no carry-out possible)++ movq 16(x), %rbx+ mulpadi(%rbp,%r11,%r10,(x))+ mulpadd(%rbp,%r12,%r11,8(x))+ movq 8(x), %rbx+ mulpadd(%rbp,%r13,%r12,24(x))+ mulpadd(%rbp,%r14,%r13,32(x))+ mulpade(%rbp,%r15,%r14,40(x))+ adcq $0, %rcx++// Now chain in the 04 + 23 + 24 + 25 + 35 + 45 terms+// We are running out of registers in our rotating window, so we start+// using %rbx (and hence need care with using mulpadd after this). Thus+// our result so far is in [%rbp;%rbx;%rcx;%r15;...%r9]++ movq 32(x), %rbx+ mulpadi(%rbp,%r13,%r12,(x))+ movq 16(x), %rbx+ mulpadd(%rbp,%r14,%r13,24(x))+ mulpadd(%rbp,%r15,%r14,32(x))+ mulpadd(%rbp,%rcx,%r15,40(x))++ xorl %ebx, %ebx+ movq 24(x), %rax+ mulq 40(x)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 32(x), %rax+ mulq 40(x)+ addq %rax, %rbx+ adcq %rdx, %rbp++// Double the window as [%r8;%rbp;%rbx;%rcx;%r15;...%r9]++ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d++// Add the doubled window to the 00 + 11 + 22 + 33 + 44 + 55 terms+// For one glorious moment the entire squaring result is all in the+// register file as [%rsi;%rbp;%rbx;%rcx;%r15;...;%r8]+// (since we've now finished with x we can re-use %rsi). But since+// we are so close to running out of registers, we do a bit of+// reshuffling and temporary storage in the output buffer.++ movq (x), %rax+ mulq %rax+ movq %r8, (z)+ movq %rax, %r8+ movq 8(x), %rax+ movq %rbp, 8(z)+ addq %rdx, %r9+ sbbq %rbp, %rbp++ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp++ movq 16(x), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp++ movq 24(x), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp++ movq 32(x), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp++ movq 40(x), %rax+ mulq %rax+ negq %rbp+ adcq 8(z), %rax+ adcq (z), %rdx+ movq %rax, %rbp+ movq %rdx, %rsi++// We need just *one* more register as a temp for the Montgomery steps.+// Since we are writing to the z buffer anyway, make use of that again+// to stash %rbx.++ movq %rbx, (z)++// Montgomery reduce the %r13,...,%r8 window 6 times++ montreds(%r8,%r13,%r12,%r11,%r10,%r9,%r8)+ montreds(%r9,%r8,%r13,%r12,%r11,%r10,%r9)+ montreds(%r10,%r9,%r8,%r13,%r12,%r11,%r10)+ montreds(%r11,%r10,%r9,%r8,%r13,%r12,%r11)+ montreds(%r12,%r11,%r10,%r9,%r8,%r13,%r12)+ montreds(%r13,%r12,%r11,%r10,%r9,%r8,%r13)++// Now we can safely restore %rbx before accumulating++ movq (z), %rbx++ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0, %r8d+ adcq %r8, %r8++// We now have a pre-reduced 7-word form z = [%r8; %rsi;%rbp;%rbx;%rcx;%r15;%r14]+// Next, accumulate in different registers z - p_384, or more precisely+//+// [%r8; %r13;%r12;%r11;%r10;%r9;%rax] = z + (2^384 - p_384)++ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0x00000000ffffffff, %r9d+ adcq %r15, %r9+ movl $0x0000000000000001, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rsi, %r13+ adcq $0, %r8++// ~ZF <=> %r12 >= 1 <=> z + (2^384 - p_384) >= 2^384 <=> z >= p_384, which+// determines whether to use the further reduced argument or the original z.++ cmovnzq %rax, %r14+ cmovnzq %r9, %r15+ cmovnzq %r10, %rcx+ cmovnzq %r11, %rbx+ cmovnzq %r12, %rbp+ cmovnzq %r13, %rsi++// Write back the result++ movq %r14, (z)+ movq %r15, 8(z)+ movq %rcx, 16(z)+ movq %rbx, 24(z)+ movq %rbp, 32(z)+ movq %rsi, 40(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_montsqr_p384_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_mul_p521.S view
@@ -0,0 +1,394 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Multiply modulo p_521, z := (x * y) mod p_521, assuming x and y reduced+// Inputs x[9], y[9]; output z[9]+//+// extern void bignum_mul_p521(uint64_t z[static 9], const uint64_t x[static 9],+// const uint64_t y[static 9]);+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = y+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = y+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_mul_p521)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_mul_p521)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_mul_p521)+ .text++#define z %rdi+#define x %rsi++// Copied in++#define y %rcx++// mulpadd (high,low,x) adds rdx * x to a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rbx as temporaries.++#define mulpadd(high,low,x) \+ mulxq x, %rax, %rbx ; \+ adcxq %rax, low ; \+ adoxq %rbx, high++S2N_BN_SYMBOL(bignum_mul_p521):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save more registers to play with and make temporary space on stack++ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(64)++// Copy y into a safe register to start with++ movq %rdx, y++// Clone of the main body of bignum_8_16, writing back the low 8 words to+// the temporary buffer on the stack and keeping the top half in %r15,...,%r8++ xorl %ebp, %ebp+ movq (y), %rdx+ mulxq (x), %r8, %r9+ movq %r8, (%rsp)+ mulxq 0x8(x), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(x), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(x), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x20(x), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x28(x), %rbx, %r14+ adcq %rbx, %r13+ mulxq 0x30(x), %rbx, %r15+ adcq %rbx, %r14+ mulxq 0x38(x), %rbx, %r8+ adcq %rbx, %r15+ adcq %rbp, %r8+ movq 0x8(y), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x8(%rsp)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(x), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ adcq %rbp, %r9+ movq 0x10(y), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x10(%rsp)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(x), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcq %rbp, %r10+ movq 0x18(y), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x18(%rsp)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(x), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ adcq %rbp, %r11+ movq 0x20(y), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x20(%rsp)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(x), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcq %rbp, %r12+ movq 0x28(y), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x28(%rsp)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(x), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ adcq %rbp, %r13+ movq 0x30(y), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x30(%rsp)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(x), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ movq 0x38(y), %rdx+ xorl %ebp, %ebp+ mulxq (x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x38(%rsp)+ mulxq 0x8(x), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x10(x), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x18(x), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x20(x), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(x), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(x), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(x), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ adcq %rbp, %r15++// Accumulate x[8] * y[0..7], extending the window to %rbp,%r15,...,%r8++ movq 64(x), %rdx+ xorl %ebp, %ebp+ mulpadd(%r9,%r8,(y))+ mulpadd(%r10,%r9,8(y))+ mulpadd(%r11,%r10,16(y))+ mulpadd(%r12,%r11,24(y))+ mulpadd(%r13,%r12,32(y))+ mulpadd(%r14,%r13,40(y))+ mulpadd(%r15,%r14,48(y))+ mulxq 56(y), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbp, %rbx+ adcq %rbx, %rbp++// Accumulate y[8] * x[0..8] within this extended window %rbp,%r15,...,%r8++ movq 64(y), %rdx+ xorl %eax, %eax+ mulpadd(%r9,%r8,(x))+ mulpadd(%r10,%r9,8(x))+ mulpadd(%r11,%r10,16(x))+ mulpadd(%r12,%r11,24(x))+ mulpadd(%r13,%r12,32(x))+ mulpadd(%r14,%r13,40(x))+ mulpadd(%r15,%r14,48(x))+ mulxq 56(x), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %rbp+ mulxq 64(x), %rax, %rbx+ adcq %rax, %rbp++// Rotate the upper portion right 9 bits since 2^512 == 2^-9 (mod p_521)+// Let rotated result %rbp,%r15,%r14,...,%r8 be h (high) and %rsp[0..7] be l (low)++ movq %r8, %rax+ andq $0x1FF, %rax+ shrdq $9, %r9, %r8+ shrdq $9, %r10, %r9+ shrdq $9, %r11, %r10+ shrdq $9, %r12, %r11+ shrdq $9, %r13, %r12+ shrdq $9, %r14, %r13+ shrdq $9, %r15, %r14+ shrdq $9, %rbp, %r15+ shrq $9, %rbp+ addq %rax, %rbp++// Force carry-in then add to get s = h + l + 1+// but actually add all 1s in the top 53 bits to get simple carry out++ stc+ adcq (%rsp), %r8+ adcq 8(%rsp), %r9+ adcq 16(%rsp), %r10+ adcq 24(%rsp), %r11+ adcq 32(%rsp), %r12+ adcq 40(%rsp), %r13+ adcq 48(%rsp), %r14+ adcq 56(%rsp), %r15+ adcq $~0x1FF, %rbp++// Now CF is set <=> h + l + 1 >= 2^521 <=> h + l >= p_521,+// in which case the lower 521 bits are already right. Otherwise if+// CF is clear, we want to subtract 1. Hence subtract the complement+// of the carry flag then mask the top word, which scrubs the+// padding in either case. Write digits back as they are created.++ cmc+ sbbq $0, %r8+ movq %r8, (z)+ sbbq $0, %r9+ movq %r9, 8(z)+ sbbq $0, %r10+ movq %r10, 16(z)+ sbbq $0, %r11+ movq %r11, 24(z)+ sbbq $0, %r12+ movq %r12, 32(z)+ sbbq $0, %r13+ movq %r13, 40(z)+ sbbq $0, %r14+ movq %r14, 48(z)+ sbbq $0, %r15+ movq %r15, 56(z)+ sbbq $0, %rbp+ andq $0x1FF, %rbp+ movq %rbp, 64(z)++// Restore registers and return++ CFI_INC_RSP(64)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_POP(%rbp)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_mul_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_mul_p521_alt.S view
@@ -0,0 +1,321 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Multiply modulo p_521, z := (x * y) mod p_521, assuming x and y reduced+// Inputs x[9], y[9]; output z[9]+//+// extern void bignum_mul_p521_alt(uint64_t z[static 9],+// const uint64_t x[static 9],+// const uint64_t y[static 9]);+//+// Standard x86-64 ABI: RDI = z, RSI = x, RDX = y+// Microsoft x64 ABI: RCX = z, RDX = x, R8 = y+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_mul_p521_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_mul_p521_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_mul_p521_alt)+ .text++#define z %rdi+#define x %rsi++// This is moved from %rdx to free it for muls++#define y %rcx++// Macro for the key "multiply and add to (c,h,l)" step++#define combadd(c,h,l,numa,numb) \+ movq numa, %rax ; \+ mulq numb; \+ addq %rax, l ; \+ adcq %rdx, h ; \+ adcq $0, c++// A minutely shorter form for when c = 0 initially++#define combadz(c,h,l,numa,numb) \+ movq numa, %rax ; \+ mulq numb; \+ addq %rax, l ; \+ adcq %rdx, h ; \+ adcq c, c++// A short form where we don't expect a top carry++#define combads(h,l,numa,numb) \+ movq numa, %rax ; \+ mulq numb; \+ addq %rax, l ; \+ adcq %rdx, h++S2N_BN_SYMBOL(bignum_mul_p521_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Make more registers available and make temporary space on stack++ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(72)++// Copy y into a safe register to start with++ movq %rdx, y++// Start doing a conventional columnwise multiplication,+// temporarily storing the lower 9 digits to the stack.+// Start with result term 0++ movq (x), %rax+ mulq (y)++ movq %rax, (%rsp)+ movq %rdx, %r9+ xorq %r10, %r10++// Result term 1++ xorq %r11, %r11+ combads(%r10,%r9,(x),8(y))+ combadz(%r11,%r10,%r9,8(x),(y))+ movq %r9, 8(%rsp)++// Result term 2++ xorq %r12, %r12+ combadz(%r12,%r11,%r10,(x),16(y))+ combadd(%r12,%r11,%r10,8(x),8(y))+ combadd(%r12,%r11,%r10,16(x),(y))+ movq %r10, 16(%rsp)++// Result term 3++ xorq %r13, %r13+ combadz(%r13,%r12,%r11,(x),24(y))+ combadd(%r13,%r12,%r11,8(x),16(y))+ combadd(%r13,%r12,%r11,16(x),8(y))+ combadd(%r13,%r12,%r11,24(x),(y))+ movq %r11, 24(%rsp)++// Result term 4++ xorq %r14, %r14+ combadz(%r14,%r13,%r12,(x),32(y))+ combadd(%r14,%r13,%r12,8(x),24(y))+ combadd(%r14,%r13,%r12,16(x),16(y))+ combadd(%r14,%r13,%r12,24(x),8(y))+ combadd(%r14,%r13,%r12,32(x),(y))+ movq %r12, 32(%rsp)++// Result term 5++ xorq %r15, %r15+ combadz(%r15,%r14,%r13,(x),40(y))+ combadd(%r15,%r14,%r13,8(x),32(y))+ combadd(%r15,%r14,%r13,16(x),24(y))+ combadd(%r15,%r14,%r13,24(x),16(y))+ combadd(%r15,%r14,%r13,32(x),8(y))+ combadd(%r15,%r14,%r13,40(x),(y))+ movq %r13, 40(%rsp)++// Result term 6++ xorq %r8, %r8+ combadz(%r8,%r15,%r14,(x),48(y))+ combadd(%r8,%r15,%r14,8(x),40(y))+ combadd(%r8,%r15,%r14,16(x),32(y))+ combadd(%r8,%r15,%r14,24(x),24(y))+ combadd(%r8,%r15,%r14,32(x),16(y))+ combadd(%r8,%r15,%r14,40(x),8(y))+ combadd(%r8,%r15,%r14,48(x),(y))+ movq %r14, 48(%rsp)++// Result term 7++ xorq %r9, %r9+ combadz(%r9,%r8,%r15,(x),56(y))+ combadd(%r9,%r8,%r15,8(x),48(y))+ combadd(%r9,%r8,%r15,16(x),40(y))+ combadd(%r9,%r8,%r15,24(x),32(y))+ combadd(%r9,%r8,%r15,32(x),24(y))+ combadd(%r9,%r8,%r15,40(x),16(y))+ combadd(%r9,%r8,%r15,48(x),8(y))+ combadd(%r9,%r8,%r15,56(x),(y))+ movq %r15, 56(%rsp)++// Result term 8++ xorq %r10, %r10+ combadz(%r10,%r9,%r8,(x),64(y))+ combadd(%r10,%r9,%r8,8(x),56(y))+ combadd(%r10,%r9,%r8,16(x),48(y))+ combadd(%r10,%r9,%r8,24(x),40(y))+ combadd(%r10,%r9,%r8,32(x),32(y))+ combadd(%r10,%r9,%r8,40(x),24(y))+ combadd(%r10,%r9,%r8,48(x),16(y))+ combadd(%r10,%r9,%r8,56(x),8(y))+ combadd(%r10,%r9,%r8,64(x),(y))+ movq %r8, 64(%rsp)++// At this point we suspend writing back results and collect them+// in a register window. Next is result term 9++ xorq %r11, %r11+ combadz(%r11,%r10,%r9,8(x),64(y))+ combadd(%r11,%r10,%r9,16(x),56(y))+ combadd(%r11,%r10,%r9,24(x),48(y))+ combadd(%r11,%r10,%r9,32(x),40(y))+ combadd(%r11,%r10,%r9,40(x),32(y))+ combadd(%r11,%r10,%r9,48(x),24(y))+ combadd(%r11,%r10,%r9,56(x),16(y))+ combadd(%r11,%r10,%r9,64(x),8(y))++// Result term 10++ xorq %r12, %r12+ combadz(%r12,%r11,%r10,16(x),64(y))+ combadd(%r12,%r11,%r10,24(x),56(y))+ combadd(%r12,%r11,%r10,32(x),48(y))+ combadd(%r12,%r11,%r10,40(x),40(y))+ combadd(%r12,%r11,%r10,48(x),32(y))+ combadd(%r12,%r11,%r10,56(x),24(y))+ combadd(%r12,%r11,%r10,64(x),16(y))++// Result term 11++ xorq %r13, %r13+ combadz(%r13,%r12,%r11,24(x),64(y))+ combadd(%r13,%r12,%r11,32(x),56(y))+ combadd(%r13,%r12,%r11,40(x),48(y))+ combadd(%r13,%r12,%r11,48(x),40(y))+ combadd(%r13,%r12,%r11,56(x),32(y))+ combadd(%r13,%r12,%r11,64(x),24(y))++// Result term 12++ xorq %r14, %r14+ combadz(%r14,%r13,%r12,32(x),64(y))+ combadd(%r14,%r13,%r12,40(x),56(y))+ combadd(%r14,%r13,%r12,48(x),48(y))+ combadd(%r14,%r13,%r12,56(x),40(y))+ combadd(%r14,%r13,%r12,64(x),32(y))++// Result term 13++ xorq %r15, %r15+ combadz(%r15,%r14,%r13,40(x),64(y))+ combadd(%r15,%r14,%r13,48(x),56(y))+ combadd(%r15,%r14,%r13,56(x),48(y))+ combadd(%r15,%r14,%r13,64(x),40(y))++// Result term 14++ xorq %r8, %r8+ combadz(%r8,%r15,%r14,48(x),64(y))+ combadd(%r8,%r15,%r14,56(x),56(y))+ combadd(%r8,%r15,%r14,64(x),48(y))++// Result term 15++ combads(%r8,%r15,56(x),64(y))+ combads(%r8,%r15,64(x),56(y))++// Result term 16++ movq 64(x), %rax+ imulq 64(y), %rax+ addq %r8, %rax++// Now the upper portion is [%rax;%r15;%r14;%r13;%r12;%r11;%r10;%r9;[%rsp+64]].+// Rotate the upper portion right 9 bits since 2^512 == 2^-9 (mod p_521)+// Let rotated result %rdx,%r15,%r14,...,%r8 be h (high) and %rsp[0..7] be l (low)++ movq 64(%rsp), %r8+ movq %r8, %rdx+ andq $0x1FF, %rdx+ shrdq $9, %r9, %r8+ shrdq $9, %r10, %r9+ shrdq $9, %r11, %r10+ shrdq $9, %r12, %r11+ shrdq $9, %r13, %r12+ shrdq $9, %r14, %r13+ shrdq $9, %r15, %r14+ shrdq $9, %rax, %r15+ shrq $9, %rax+ addq %rax, %rdx++// Force carry-in then add to get s = h + l + 1+// but actually add all 1s in the top 53 bits to get simple carry out++ stc+ adcq (%rsp), %r8+ adcq 8(%rsp), %r9+ adcq 16(%rsp), %r10+ adcq 24(%rsp), %r11+ adcq 32(%rsp), %r12+ adcq 40(%rsp), %r13+ adcq 48(%rsp), %r14+ adcq 56(%rsp), %r15+ adcq $~0x1FF, %rdx++// Now CF is set <=> h + l + 1 >= 2^521 <=> h + l >= p_521,+// in which case the lower 521 bits are already right. Otherwise if+// CF is clear, we want to subtract 1. Hence subtract the complement+// of the carry flag then mask the top word, which scrubs the+// padding in either case. Write digits back as they are created.++ cmc+ sbbq $0, %r8+ movq %r8, (z)+ sbbq $0, %r9+ movq %r9, 8(z)+ sbbq $0, %r10+ movq %r10, 16(z)+ sbbq $0, %r11+ movq %r11, 24(z)+ sbbq $0, %r12+ movq %r12, 32(z)+ sbbq $0, %r13+ movq %r13, 40(z)+ sbbq $0, %r14+ movq %r14, 48(z)+ sbbq $0, %r15+ movq %r15, 56(z)+ sbbq $0, %rdx+ andq $0x1FF, %rdx+ movq %rdx, 64(z)++// Restore registers and return++ CFI_INC_RSP(72)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_mul_p521_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_neg_p256.S view
@@ -0,0 +1,97 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Negate modulo p_256, z := (-x) mod p_256, assuming x reduced+// Input x[4]; output z[4]+//+// extern void bignum_neg_p256(uint64_t z[static 4], const uint64_t x[static 4]);+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_neg_p256)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_neg_p256)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_neg_p256)+ .text++#define z %rdi+#define x %rsi++#define q %rdx++#define d0 %rax+#define d1 %rcx+#define d2 %r8+#define d3 %r9++#define n1 %r10+#define n3 %r11++#define d0short %eax+#define n1short %r10d++S2N_BN_SYMBOL(bignum_neg_p256):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Load the input digits as [d3;d2;d1;d0] and also set a bitmask q+// for the input being nonzero, so that we avoid doing -0 = p_256+// and hence maintain strict modular reduction++ movq (x), d0+ movq 8(x), d1+ movq d0, n1+ orq d1, n1+ movq 16(x), d2+ movq 24(x), d3+ movq d2, n3+ orq d3, n3+ orq n1, n3+ negq n3+ sbbq q, q++// Load the non-trivial words of p_256 = [n3;0;n1;-1] and mask them with q++ movl $0x00000000ffffffff, n1short+ movq $0xffffffff00000001, n3+ andq q, n1+ andq q, n3++// Do the subtraction, getting it as [n3;d0;n1;q] to avoid moves++ subq d0, q+ movl $0, d0short+ sbbq d1, n1+ sbbq d2, d0+ sbbq d3, n3++// Write back++ movq q, (z)+ movq n1, 8(z)+ movq d0, 16(z)+ movq n3, 24(z)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_neg_p256)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_sqr_p521.S view
@@ -0,0 +1,302 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Square modulo p_521, z := (x^2) mod p_521, assuming x reduced+// Input x[9]; output z[9]+//+// extern void bignum_sqr_p521(uint64_t z[static 9], const uint64_t x[static 9]);+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_sqr_p521)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_sqr_p521)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_sqr_p521)+ .text++#define z %rdi+#define x %rsi++// A zero register++#define zero %rbp+#define zeroe %ebp++// mulpadd(high,low,i) adds %rdx * x[i] to a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rcx as temporaries.++#define mulpadd(high,low,I) \+ mulxq I(x), %rax, %rcx ; \+ adcxq %rax, low ; \+ adoxq %rcx, high++// mulpade(high,low,i) adds %rdx * x[i] to a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax as a temporary, assuming high created from scratch+// and that zero has value zero.++#define mulpade(high,low,I) \+ mulxq I(x), %rax, high ; \+ adcxq %rax, low ; \+ adoxq zero, high++S2N_BN_SYMBOL(bignum_sqr_p521):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save more registers to play with and make temporary space on stack++ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(64)++// Do a basic 8x8 squaring stashing in %rsp[0..7] but keeping the+// top half in the usual rotating register window %r15,...,%r8. Except+// for the lack of full writeback this is the same as bignum_sqr_8_16.++ xorl zeroe, zeroe++ movq (x), %rdx+ mulxq 8(x), %r9, %rax+ movq %r9, 8(%rsp)+ mulxq 16(x), %r10, %rcx+ adcxq %rax, %r10+ movq %r10, 16(%rsp)+ mulxq 24(x), %r11, %rax+ adcxq %rcx, %r11+ mulxq 32(x), %r12, %rcx+ adcxq %rax, %r12+ mulxq 40(x), %r13, %rax+ adcxq %rcx, %r13+ mulxq 48(x), %r14, %rcx+ adcxq %rax, %r14+ mulxq 56(x), %r15, %r8+ adcxq %rcx, %r15+ adcxq zero, %r8++ xorl zeroe, zeroe+ movq 8(x), %rdx+ mulpadd(%r12,%r11,16)+ movq %r11, 24(%rsp)+ mulpadd(%r13,%r12,24)+ movq %r12, 32(%rsp)+ mulpadd(%r14,%r13,32)+ mulpadd(%r15,%r14,40)+ mulpadd(%r8,%r15,48)+ mulpade(%r9,%r8,56)+ movq 32(x), %rdx+ mulpade(%r10,%r9,40)+ adcxq zero, %r10++ xorl zeroe, zeroe+ movq 16(x), %rdx+ mulpadd(%r14,%r13,24)+ movq %r13, 40(%rsp)+ mulpadd(%r15,%r14,32)+ movq %r14, 48(%rsp)+ mulpadd(%r8,%r15,40)+ mulpadd(%r9,%r8,48)+ mulpadd(%r10,%r9,56)+ movq 48(x), %rdx+ mulpade(%r11,%r10,32)+ mulpade(%r12,%r11,40)+ adcxq zero, %r12++ xorl zeroe, zeroe+ movq 24(x), %rdx+ mulpadd(%r8,%r15,32)+ movq %r15, 56(%rsp)+ mulpadd(%r9,%r8,40)+ mulpadd(%r10,%r9,48)+ mulpadd(%r11,%r10,56)+ movq 56(x), %rdx+ mulpadd(%r12,%r11,32)+ mulpade(%r13,%r12,40)+ mulpade(%r14,%r13,48)+ adcxq zero, %r14++ xorl zeroe, zeroe+ movq (x), %rdx+ mulxq %rdx, %rax, %rcx+ movq %rax, (%rsp)+ movq 8(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 8(%rsp)++ movq 16(%rsp), %rax+ movq 8(x), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %rax, %rax+ adoxq %rdx, %rax+ movq %rax, 16(%rsp)+ movq 24(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 24(%rsp)++ movq 32(%rsp), %rax+ movq 16(x), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %rax, %rax+ adoxq %rdx, %rax+ movq %rax, 32(%rsp)+ movq 40(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 40(%rsp)++ movq 48(%rsp), %rax+ movq 24(x), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %rax, %rax+ adoxq %rdx, %rax+ movq %rax, 48(%rsp)+ movq 56(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 56(%rsp)++ movq 32(x), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %r8, %r8+ adoxq %rdx, %r8+ adcxq %r9, %r9+ adoxq %rcx, %r9++ movq 40(x), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %r10, %r10+ adoxq %rdx, %r10+ adcxq %r11, %r11+ adoxq %rcx, %r11++ movq 48(x), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %r12, %r12+ adoxq %rdx, %r12+ adcxq %r13, %r13+ adoxq %rcx, %r13++ movq 56(x), %rdx+ mulxq %rdx, %rdx, %r15+ adcxq %r14, %r14+ adoxq %rdx, %r14+ adcxq zero, %r15+ adoxq zero, %r15++// Augment the high part with the contribution from the top little word C.+// If we write the input as 2^512 * C + x then we are otherwise just doing+// x^2, so we need to add to the high part 2^512 * C^2 + (2 * C) * x.+// The initial doubling add of C also clears the CF and OF flags as desired.+// We extend the window now to the 9-element %rbp,%r15,%r14,...,%r8.++ movq 64(x), %rdx+ movq %rdx, %rbp+ imulq %rbp, %rbp+ addq %rdx, %rdx+ mulpadd(%r9,%r8,0)+ mulpadd(%r10,%r9,8)+ mulpadd(%r11,%r10,16)+ mulpadd(%r12,%r11,24)+ mulpadd(%r13,%r12,32)+ mulpadd(%r14,%r13,40)+ mulpadd(%r15,%r14,48)+ mulxq 56(x), %rax, %rcx+ adcxq %rax, %r15+ adoxq %rcx, %rbp+ adcq $0, %rbp++// Rotate the upper portion right 9 bits since 2^512 == 2^-9 (mod p_521)+// Let rotated result %rbp,%r15,%r14,...,%r8 be h (high) and %rsp[0..7] be l (low)++ movq %r8, %rax+ andq $0x1FF, %rax+ shrdq $9, %r9, %r8+ shrdq $9, %r10, %r9+ shrdq $9, %r11, %r10+ shrdq $9, %r12, %r11+ shrdq $9, %r13, %r12+ shrdq $9, %r14, %r13+ shrdq $9, %r15, %r14+ shrdq $9, %rbp, %r15+ shrq $9, %rbp+ addq %rax, %rbp++// Force carry-in then add to get s = h + l + 1+// but actually add all 1s in the top 53 bits to get simple carry out++ stc+ adcq (%rsp), %r8+ adcq 8(%rsp), %r9+ adcq 16(%rsp), %r10+ adcq 24(%rsp), %r11+ adcq 32(%rsp), %r12+ adcq 40(%rsp), %r13+ adcq 48(%rsp), %r14+ adcq 56(%rsp), %r15+ adcq $~0x1FF, %rbp++// Now CF is set <=> h + l + 1 >= 2^521 <=> h + l >= p_521,+// in which case the lower 521 bits are already right. Otherwise if+// CF is clear, we want to subtract 1. Hence subtract the complement+// of the carry flag then mask the top word, which scrubs the+// padding in either case. Write digits back as they are created.++ cmc+ sbbq $0, %r8+ movq %r8, (z)+ sbbq $0, %r9+ movq %r9, 8(z)+ sbbq $0, %r10+ movq %r10, 16(z)+ sbbq $0, %r11+ movq %r11, 24(z)+ sbbq $0, %r12+ movq %r12, 32(z)+ sbbq $0, %r13+ movq %r13, 40(z)+ sbbq $0, %r14+ movq %r14, 48(z)+ sbbq $0, %r15+ movq %r15, 56(z)+ sbbq $0, %rbp+ andq $0x1FF, %rbp+ movq %rbp, 64(z)++// Restore registers and return++ CFI_INC_RSP(64)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_sqr_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_sqr_p521_alt.S view
@@ -0,0 +1,315 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Square modulo p_521, z := (x^2) mod p_521, assuming x reduced+// Input x[9]; output z[9]+//+// extern void bignum_sqr_p521_alt(uint64_t z[static 9],+// const uint64_t x[static 9]);+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_sqr_p521_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_sqr_p521_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_sqr_p521_alt)+ .text++// Input arguments++#define z %rdi+#define x %rsi++// Macro for the key "multiply and add to (c,h,l)" step++#define combadd(c,h,l,numa,numb) \+ movq numa, %rax ; \+ mulq numb; \+ addq %rax, l ; \+ adcq %rdx, h ; \+ adcq $0, c++// Set up initial window (c,h,l) = numa * numb++#define combaddz(c,h,l,numa,numb) \+ movq numa, %rax ; \+ mulq numb; \+ xorq c, c ; \+ movq %rax, l ; \+ movq %rdx, h++// Doubling step (c,h,l) = 2 * (c,hh,ll) + (0,h,l)++#define doubladd(c,h,l,hh,ll) \+ addq ll, ll ; \+ adcq hh, hh ; \+ adcq c, c ; \+ addq ll, l ; \+ adcq hh, h ; \+ adcq $0, c++// Square term incorporation (c,h,l) += numba^2++#define combadd1(c,h,l,numa) \+ movq numa, %rax ; \+ mulq %rax; \+ addq %rax, l ; \+ adcq %rdx, h ; \+ adcq $0, c++// A short form where we don't expect a top carry++#define combads(h,l,numa) \+ movq numa, %rax ; \+ mulq %rax; \+ addq %rax, l ; \+ adcq %rdx, h++// A version doubling directly before adding, for single non-square terms++#define combadd2(c,h,l,numa,numb) \+ movq numa, %rax ; \+ mulq numb; \+ addq %rax, %rax ; \+ adcq %rdx, %rdx ; \+ adcq $0, c ; \+ addq %rax, l ; \+ adcq %rdx, h ; \+ adcq $0, c++S2N_BN_SYMBOL(bignum_sqr_p521_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Make more registers available and make temporary space on stack++ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(72)++// Start doing a conventional columnwise squaring,+// temporarily storing the lower 9 digits on the stack.+// Start with result term 0++ movq (x), %rax+ mulq %rax++ movq %rax, (%rsp)+ movq %rdx, %r9+ xorq %r10, %r10++// Result term 1++ xorq %r11, %r11+ combadd2(%r11,%r10,%r9,(x),8(x))+ movq %r9, 8(%rsp)++// Result term 2++ xorq %r12, %r12+ combadd1(%r12,%r11,%r10,8(x))+ combadd2(%r12,%r11,%r10,(x),16(x))+ movq %r10, 16(%rsp)++// Result term 3++ combaddz(%r13,%rcx,%rbx,(x),24(x))+ combadd(%r13,%rcx,%rbx,8(x),16(x))+ doubladd(%r13,%r12,%r11,%rcx,%rbx)+ movq %r11, 24(%rsp)++// Result term 4++ combaddz(%r14,%rcx,%rbx,(x),32(x))+ combadd(%r14,%rcx,%rbx,8(x),24(x))+ doubladd(%r14,%r13,%r12,%rcx,%rbx)+ combadd1(%r14,%r13,%r12,16(x))+ movq %r12, 32(%rsp)++// Result term 5++ combaddz(%r15,%rcx,%rbx,(x),40(x))+ combadd(%r15,%rcx,%rbx,8(x),32(x))+ combadd(%r15,%rcx,%rbx,16(x),24(x))+ doubladd(%r15,%r14,%r13,%rcx,%rbx)+ movq %r13, 40(%rsp)++// Result term 6++ combaddz(%r8,%rcx,%rbx,(x),48(x))+ combadd(%r8,%rcx,%rbx,8(x),40(x))+ combadd(%r8,%rcx,%rbx,16(x),32(x))+ doubladd(%r8,%r15,%r14,%rcx,%rbx)+ combadd1(%r8,%r15,%r14,24(x))+ movq %r14, 48(%rsp)++// Result term 7++ combaddz(%r9,%rcx,%rbx,(x),56(x))+ combadd(%r9,%rcx,%rbx,8(x),48(x))+ combadd(%r9,%rcx,%rbx,16(x),40(x))+ combadd(%r9,%rcx,%rbx,24(x),32(x))+ doubladd(%r9,%r8,%r15,%rcx,%rbx)+ movq %r15, 56(%rsp)++// Result term 8++ combaddz(%r10,%rcx,%rbx,(x),64(x))+ combadd(%r10,%rcx,%rbx,8(x),56(x))+ combadd(%r10,%rcx,%rbx,16(x),48(x))+ combadd(%r10,%rcx,%rbx,24(x),40(x))+ doubladd(%r10,%r9,%r8,%rcx,%rbx)+ combadd1(%r10,%r9,%r8,32(x))+ movq %r8, 64(%rsp)++// We now stop writing back and keep remaining results in a register window.+// Continue with result term 9++ combaddz(%r11,%rcx,%rbx,8(x),64(x))+ combadd(%r11,%rcx,%rbx,16(x),56(x))+ combadd(%r11,%rcx,%rbx,24(x),48(x))+ combadd(%r11,%rcx,%rbx,32(x),40(x))+ doubladd(%r11,%r10,%r9,%rcx,%rbx)++// Result term 10++ combaddz(%r12,%rcx,%rbx,16(x),64(x))+ combadd(%r12,%rcx,%rbx,24(x),56(x))+ combadd(%r12,%rcx,%rbx,32(x),48(x))+ doubladd(%r12,%r11,%r10,%rcx,%rbx)+ combadd1(%r12,%r11,%r10,40(x))++// Result term 11++ combaddz(%r13,%rcx,%rbx,24(x),64(x))+ combadd(%r13,%rcx,%rbx,32(x),56(x))+ combadd(%r13,%rcx,%rbx,40(x),48(x))+ doubladd(%r13,%r12,%r11,%rcx,%rbx)++// Result term 12++ combaddz(%r14,%rcx,%rbx,32(x),64(x))+ combadd(%r14,%rcx,%rbx,40(x),56(x))+ doubladd(%r14,%r13,%r12,%rcx,%rbx)+ combadd1(%r14,%r13,%r12,48(x))++// Result term 13++ combaddz(%r15,%rcx,%rbx,40(x),64(x))+ combadd(%r15,%rcx,%rbx,48(x),56(x))+ doubladd(%r15,%r14,%r13,%rcx,%rbx);++// Result term 14++ xorq %r8, %r8+ combadd1(%r8,%r15,%r14,56(x))+ combadd2(%r8,%r15,%r14,48(x),64(x))++// Result term 15++ movq 56(x), %rax+ mulq 64(x)+ addq %rax, %rax+ adcq %rdx, %rdx+ addq %rax, %r15+ adcq %rdx, %r8++// Result term 16++ movq 64(x), %rax+ imulq %rax, %rax+ addq %r8, %rax++// Now the upper portion is [%rax;%r15;%r14;%r13;%r12;%r11;%r10;%r9;[%rsp+64]].+// Rotate the upper portion right 9 bits since 2^512 == 2^-9 (mod p_521)+// Let rotated result %rdx,%r15,%r14,...,%r8 be h (high) and %rsp[0..7] be l (low)++ movq 64(%rsp), %r8+ movq %r8, %rdx+ andq $0x1FF, %rdx+ shrdq $9, %r9, %r8+ shrdq $9, %r10, %r9+ shrdq $9, %r11, %r10+ shrdq $9, %r12, %r11+ shrdq $9, %r13, %r12+ shrdq $9, %r14, %r13+ shrdq $9, %r15, %r14+ shrdq $9, %rax, %r15+ shrq $9, %rax+ addq %rax, %rdx++// Force carry-in then add to get s = h + l + 1+// but actually add all 1s in the top 53 bits to get simple carry out++ stc+ adcq (%rsp), %r8+ adcq 8(%rsp), %r9+ adcq 16(%rsp), %r10+ adcq 24(%rsp), %r11+ adcq 32(%rsp), %r12+ adcq 40(%rsp), %r13+ adcq 48(%rsp), %r14+ adcq 56(%rsp), %r15+ adcq $~0x1FF, %rdx++// Now CF is set <=> h + l + 1 >= 2^521 <=> h + l >= p_521,+// in which case the lower 521 bits are already right. Otherwise if+// CF is clear, we want to subtract 1. Hence subtract the complement+// of the carry flag then mask the top word, which scrubs the+// padding in either case. Write digits back as they are created.++ cmc+ sbbq $0, %r8+ movq %r8, (z)+ sbbq $0, %r9+ movq %r9, 8(z)+ sbbq $0, %r10+ movq %r10, 16(z)+ sbbq $0, %r11+ movq %r11, 24(z)+ sbbq $0, %r12+ movq %r12, 32(z)+ sbbq $0, %r13+ movq %r13, 40(z)+ sbbq $0, %r14+ movq %r14, 48(z)+ sbbq $0, %r15+ movq %r15, 56(z)+ sbbq $0, %rdx+ andq $0x1FF, %rdx+ movq %rdx, 64(z)++// Restore registers and return++ CFI_INC_RSP(72)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_sqr_p521_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_tomont_p256.S view
@@ -0,0 +1,195 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert to Montgomery form z := (2^256 * x) mod p_256+// Input x[4]; output z[4]+//+// extern void bignum_tomont_p256(uint64_t z[static 4],+// const uint64_t x[static 4]);+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p256)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p256)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p256)+ .text++#define z %rdi+#define x %rsi++// Some temp registers for the last correction stage++#define d %rax+#define u %rdx+#define v %rcx++#define dshort %eax+#define ushort %edx++// Add %rdx * m into a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rbx as temporaries++#define mulpadd(high,low,m) \+ mulxq m, %rax, %rcx ; \+ adcxq %rax, low ; \+ adoxq %rcx, high++S2N_BN_SYMBOL(bignum_tomont_p256):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// We are essentially just doing a Montgomery multiplication of x and the+// precomputed constant y = 2^512 mod p, so the code is almost the same+// modulo a few registers and the change from loading y[i] to using constants.+// Because there is no y pointer to keep, we use one register less.++ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Do row 0 computation, which is a bit different:+// set up initial window [%r12,%r11,%r10,%r9,%r8] = y[0] * x+// Unlike later, we only need a single carry chain++ xorq %r13, %r13+ movl $0x0000000000000003, %edx+ mulxq (x), %r8, %r9+ mulxq 8(x), %rcx, %r10+ adcxq %rcx, %r9+ mulxq 16(x), %rcx, %r11+ adcxq %rcx, %r10+ mulxq 24(x), %rcx, %r12+ adcxq %rcx, %r11+ adcxq %r13, %r12++// Add row 1++ movq $0xfffffffbffffffff, %rdx+ xorq %r14, %r14+ mulpadd(%r10,%r9,(x))+ mulpadd(%r11,%r10,8(x))+ mulpadd(%r12,%r11,16(x))+ mulpadd(%r13,%r12,24(x))+ adcq %r14, %r13++// Montgomery reduce windows 0 and 1 together++ xorq %r15, %r15+ movq $0x0000000100000000, %rdx+ mulpadd(%r10,%r9,%r8)+ mulpadd(%r11,%r10,%r9)+ movq $0xffffffff00000001, %rdx+ mulpadd(%r12,%r11,%r8)+ mulpadd(%r13,%r12,%r9)+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcxq %r15, %r14++// Add row 2++ movq $0xfffffffffffffffe, %rdx+ xorq %r8, %r8+ mulpadd(%r11,%r10,(x))+ mulpadd(%r12,%r11,8(x))+ mulpadd(%r13,%r12,16(x))+ mulpadd(%r14,%r13,24(x))+ adcxq %r8, %r14+ adoxq %r8, %r15+ adcxq %r8, %r15++// Add row 3++ movq $0x00000004fffffffd, %rdx+ xorq %r9, %r9+ mulpadd(%r12,%r11,(x))+ mulpadd(%r13,%r12,8(x))+ mulpadd(%r14,%r13,16(x))+ mulpadd(%r15,%r14,24(x))+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcxq %r9, %r8++// Montgomery reduce windows 2 and 3 together++ xorq %r9, %r9+ movq $0x0000000100000000, %rdx+ mulpadd(%r12,%r11,%r10)+ mulpadd(%r13,%r12,%r11)+ movq $0xffffffff00000001, %rdx+ mulpadd(%r14,%r13,%r10)+ mulpadd(%r15,%r14,%r11)+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcxq %r9, %r8++// We now have a pre-reduced 5-word form [%r8; %r15;%r14;%r13;%r12]+// Load non-trivial digits of p_256 = [v; 0; u; -1]++ movl $0x00000000ffffffff, ushort+ movq $0xffffffff00000001, v++// Now do the subtraction (0,p_256-1) - (%r8,%r15,%r14,%r13,%r12) to get the carry++ movq $-2, d+ subq %r12, d+ movq u, d+ sbbq %r13, d+ movl $0, dshort+ sbbq %r14, d+ movq v, d+ sbbq %r15, d++// This last comparison in the chain will actually even set the mask+// for us, so we don't need to separately create it from the carry.+// This means p_256 - 1 < (c,d1,d0,d5,d4), i.e. we are so far >= p_256++ movl $0, dshort+ sbbq %r8, d+ andq d, u+ andq d, v++// Do a masked subtraction of p_256 and write back++ subq d, %r12+ sbbq u, %r13+ sbbq $0, %r14+ sbbq v, %r15++ movq %r12, (z)+ movq %r13, 8(z)+ movq %r14, 16(z)+ movq %r15, 24(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_tomont_p256)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_tomont_p256_alt.S view
@@ -0,0 +1,203 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert to Montgomery form z := (2^256 * x) mod p_256+// Input x[4]; output z[4]+//+// extern void bignum_tomont_p256_alt(uint64_t z[static 4],+// const uint64_t x[static 4]);+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p256_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p256_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p256_alt)+ .text++#define z %rdi+#define x %rsi++// Add %rcx * m into a register-pair (high,low) maintaining consistent+// carry-catching with carry (negated, as bitmask) and using %rax and %rdx+// as temporaries++#define mulpadd(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rcx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// Initial version assuming no carry-in++#define mulpadi(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rcx; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// End version not catching the top carry-out++#define mulpade(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rcx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high++S2N_BN_SYMBOL(bignum_tomont_p256_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save more registers to play with++ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Do row 0 computation, which is a bit different:+// set up initial window [%r12,%r11,%r10,%r9,%r8] = y[0] * x+// Unlike later, we only need a single carry chain++ movl $0x0000000000000003, %ecx+ movq (x), %rax+ mulq %rcx+ movq %rax, %r8+ movq %rdx, %r9++ movq 8(x), %rax+ mulq %rcx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10++ movq 16(x), %rax+ mulq %rcx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11++ movq 24(x), %rax+ mulq %rcx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12++// Add row 1++ movq $0xfffffffbffffffff, %rcx+ xorl %r13d, %r13d+ mulpadi(%r14,%r10,%r9,(x))+ mulpadd(%r14,%r11,%r10,8(x))+ mulpadd(%r14,%r12,%r11,16(x))+ mulpade(%r14,%r13,%r12,24(x))++// Montgomery reduce windows 0 and 1 together++ xorl %r14d, %r14d+ movq $0x0000000100000000, %rcx+ mulpadi(%r15,%r10,%r9,%r8)+ mulpadd(%r15,%r11,%r10,%r9)+ notq %rcx+ leaq 2(%rcx), %rcx+ mulpadd(%r15,%r12,%r11,%r8)+ mulpade(%r15,%r13,%r12,%r9)+ adcq %r14, %r14++// Add row 2++ movq $0xfffffffffffffffe, %rcx+ xorl %r15d, %r15d+ mulpadi(%r8,%r11,%r10,(x))+ mulpadd(%r8,%r12,%r11,8(x))+ mulpadd(%r8,%r13,%r12,16(x))+ mulpade(%r8,%r14,%r13,24(x))+ adcq %r15, %r15++// Add row 3++ movq $0x00000004fffffffd, %rcx+ xorl %r8d, %r8d+ mulpadi(%r9,%r12,%r11,(x))+ mulpadd(%r9,%r13,%r12,8(x))+ mulpadd(%r9,%r14,%r13,16(x))+ mulpade(%r9,%r15,%r14,24(x))+ adcq %r8, %r8++// Montgomery reduce windows 2 and 3 together++ movq $0x0000000100000000, %rcx+ mulpadi(%r9,%r12,%r11,%r10)+ mulpadd(%r9,%r13,%r12,%r11)+ notq %rcx+ leaq 2(%rcx), %rcx+ mulpadd(%r9,%r14,%r13,%r10)+ mulpadd(%r9,%r15,%r14,%r11)+ subq %r9, %r8++// We now have a pre-reduced 5-word form [%r8; %r15;%r14;%r13;%r12]+// Load [%rax;%r11;%r9;%rcx;%rdx] = 2^320 - p_256, re-using earlier numbers a bit+// Do [%rax;%r11;%r9;%rcx;%rdx] = [%r8;%r15;%r14;%r13;%r12] + (2^320 - p_256)++ xorl %edx, %edx+ leaq -1(%rdx), %r9+ incq %rdx+ addq %r12, %rdx+ decq %rcx+ adcq %r13, %rcx+ movq %r9, %rax+ adcq %r14, %r9+ movl $0x00000000fffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax++// Now carry is set if r + (2^320 - p_256) >= 2^320, i.e. r >= p_256+// where r is the pre-reduced form. So conditionally select the+// output accordingly.++ cmovcq %rdx, %r12+ cmovcq %rcx, %r13+ cmovcq %r9, %r14+ cmovcq %r11, %r15++// Write back reduced value++ movq %r12, (z)+ movq %r13, 8(z)+ movq %r14, 16(z)+ movq %r15, 24(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_tomont_p256_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_tomont_p384.S view
@@ -0,0 +1,295 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert to Montgomery form z := (2^384 * x) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_tomont_p384(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p384)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p384)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p384)+ .text++#define z %rdi+#define x %rsi++// Fairly consistently used as a zero register++#define zero %rbp++// Some temp registers for the last correction stage++#define d %rax+#define u %rdx+#define v %rcx+#define w %rsi++#define vshort %ecx+#define wshort %esi++// Add %rdx * m into a register-pair (high,low)+// maintaining consistent double-carrying with adcx and adox,+// using %rax and %rcx as temporaries++#define mulpadd(high,low,m) \+ mulxq m, %rax, %rcx ; \+ adcxq %rax, low ; \+ adoxq %rcx, high++// Core one-step Montgomery reduction macro. Takes input in+// [d7;d6;d5;d4;d3;d2;d1;d0] and returns result in [d7;d6;d5;d4;d3;d2;d1],+// adding to the existing contents, re-using d0 as a temporary internally+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+//+// montredc(d7,d6,d5,d4,d3,d2,d1,d0)+//+// This particular variant, with its mix of addition and subtraction+// at the top, is not intended to maintain a coherent carry or borrow out.+// It is assumed the final result would fit in [d7;d6;d5;d4;d3;d2;d1].+// which is always the case here as the top word is even always in {0,1}++#define montredc(d7,d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rdx ; \+ shlq $32, %rdx ; \+ addq d0, %rdx ; \+/* Construct [%rbp;%rcx;%rax;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 as a temp */ \+ xorl %ebp, %ebp ; \+ movq $0xffffffff00000001, %rax ; \+ mulxq %rax, %rcx, %rax ; \+ movl $0x00000000ffffffff, %ecx ; \+ mulxq %rcx, d0, %rcx ; \+ adcq d0, %rax ; \+ adcq %rdx, %rcx ; \+ adcl %ebp, %ebp ; \+/* Now subtract that and add 2^384 * w */ \+ subq %rax, d1 ; \+ sbbq %rcx, d2 ; \+ sbbq %rbp, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ sbbq $0, %rdx ; \+ addq %rdx, d6 ; \+ adcq $0, d7++S2N_BN_SYMBOL(bignum_tomont_p384):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// We are essentially just doing a Montgomery multiplication of x and the+// precomputed constant y = 2^768 mod p, so the code is almost the same+// modulo a few registers and the change from loading y[i] to using constants,+// plus the easy digits y[4] = 1 and y[5] = 0 being treated specially.+// Because there is no y pointer to keep, we use one register less.++ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Do row 0 computation, which is a bit different:+// set up initial window [%r14,%r13,%r12,%r11,%r10,%r9,%r8] = y[0] * x+// Unlike later, we only need a single carry chain++ movq $0xfffffffe00000001, %rdx+ mulxq (x), %r8, %r9+ mulxq 8(x), %rcx, %r10+ addq %rcx, %r9+ mulxq 16(x), %rcx, %r11+ adcq %rcx, %r10+ mulxq 24(x), %rcx, %r12+ adcq %rcx, %r11+ mulxq 32(x), %rcx, %r13+ adcq %rcx, %r12+ mulxq 40(x), %rcx, %r14+ adcq %rcx, %r13+ adcq $0, %r14++// Montgomery reduce the zeroth window++ xorq %r15, %r15+ montredc(%r15, %r14,%r13,%r12,%r11,%r10,%r9,%r8)++// Add row 1++ xorq zero, zero+ movq $0x0000000200000000, %rdx+ xorq %r8, %r8+ mulpadd(%r10,%r9,(x))+ mulpadd(%r11,%r10,8(x))+ mulpadd(%r12,%r11,16(x))+ mulpadd(%r13,%r12,24(x))+ mulpadd(%r14,%r13,32(x))+ mulpadd(%r15,%r14,40(x))+ adcxq zero, %r15+ adoxq zero, %r8+ adcxq zero, %r8++// Montgomery reduce window 1++ montredc(%r8, %r15,%r14,%r13,%r12,%r11,%r10,%r9)++// Add row 2++ xorq zero, zero+ movq $0xfffffffe00000000, %rdx+ xorq %r9, %r9+ mulpadd(%r11,%r10,(x))+ mulpadd(%r12,%r11,8(x))+ mulpadd(%r13,%r12,16(x))+ mulpadd(%r14,%r13,24(x))+ mulpadd(%r15,%r14,32(x))+ mulpadd(%r8,%r15,40(x))+ adcxq zero, %r8+ adoxq zero, %r9+ adcxq zero, %r9++// Montgomery reduce window 2++ montredc(%r9, %r8,%r15,%r14,%r13,%r12,%r11,%r10)++// Add row 3++ xorq zero, zero+ movq $0x0000000200000000, %rdx+ xorq %r10, %r10+ mulpadd(%r12,%r11,(x))+ mulpadd(%r13,%r12,8(x))+ mulpadd(%r14,%r13,16(x))+ mulpadd(%r15,%r14,24(x))+ mulpadd(%r8,%r15,32(x))+ mulpadd(%r9,%r8,40(x))+ adcxq zero, %r9+ adoxq zero, %r10+ adcxq zero, %r10++// Montgomery reduce window 3++ montredc(%r10, %r9,%r8,%r15,%r14,%r13,%r12,%r11)++// Add row 4. The multiplier y[4] = 1, so we just add x to the window+// while extending it with one more digit, initially this carry++ xorq %r11, %r11+ addq (x), %r12+ adcq 8(x), %r13+ adcq 16(x), %r14+ adcq 24(x), %r15+ adcq 32(x), %r8+ adcq 40(x), %r9+ adcq $0, %r10+ adcq $0, %r11++// Montgomery reduce window 4++ montredc(%r11, %r10,%r9,%r8,%r15,%r14,%r13,%r12)++// Add row 5, The multiplier y[5] = 0, so this is trivial: all we do is+// bring down another zero digit into the window.++ xorq %r12, %r12++// Montgomery reduce window 5++ montredc(%r12, %r11,%r10,%r9,%r8,%r15,%r14,%r13)++// We now have a pre-reduced 7-word form [%r12;%r11;%r10;%r9;%r8;%r15;%r14]++// We know, writing B = 2^{6*64} that the full implicit result is+// B^2 c <= z + (B - 1) * p < B * p + (B - 1) * p < 2 * B * p,+// so the top half is certainly < 2 * p. If c = 1 already, we know+// subtracting p will give the reduced modulus. But now we do a+// comparison to catch cases where the residue is >= p.+// First set [0;0;0;w;v;u] = 2^384 - p_384++ movq $0xffffffff00000001, u+ movl $0x00000000ffffffff, vshort+ movl $0x0000000000000001, wshort++// Let dd = [%r11;%r10;%r9;%r8;%r15;%r14] be the topless 6-word intermediate result.+// Set CF if the addition dd + (2^384 - p_384) >= 2^384, hence iff dd >= p_384.++ movq %r14, d+ addq u, d+ movq %r15, d+ adcq v, d+ movq %r8, d+ adcq w, d+ movq %r9, d+ adcq $0, d+ movq %r10, d+ adcq $0, d+ movq %r11, d+ adcq $0, d++// Now just add this new carry into the existing %r12. It's easy to see they+// can't both be 1 by our range assumptions, so this gives us a {0,1} flag++ adcq $0, %r12++// Now convert it into a bitmask++ negq %r12++// Masked addition of 2^384 - p_384, hence subtraction of p_384++ andq %r12, u+ andq %r12, v+ andq %r12, w++ addq u, %r14+ adcq v, %r15+ adcq w, %r8+ adcq $0, %r9+ adcq $0, %r10+ adcq $0, %r11++// Write back the result++ movq %r14, (z)+ movq %r15, 8(z)+ movq %r8, 16(z)+ movq %r9, 24(z)+ movq %r10, 32(z)+ movq %r11, 40(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_tomont_p384)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/bignum_tomont_p384_alt.S view
@@ -0,0 +1,324 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Convert to Montgomery form z := (2^384 * x) mod p_384+// Input x[6]; output z[6]+//+// extern void bignum_tomont_p384_alt(uint64_t z[static 6],+// const uint64_t x[static 6]);+//+// Standard x86-64 ABI: RDI = z, RSI = x+// Microsoft x64 ABI: RCX = z, RDX = x+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(bignum_tomont_p384_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(bignum_tomont_p384_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(bignum_tomont_p384_alt)+ .text++#define z %rdi+#define x %rsi++// Some temp registers for the last correction stage++#define d %rax+#define u %rdx+#define v %rcx+#define w %rsi++#define vshort %ecx+#define wshort %esi++// Add %rbx * m into a register-pair (high,low) maintaining consistent+// carry-catching with carry (negated, as bitmask) and using %rax and %rdx+// as temporaries++#define mulpadd(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// Initial version assuming no carry-in++#define mulpadi(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ addq %rax, low ; \+ adcq %rdx, high ; \+ sbbq carry, carry++// End version not catching the top carry-out++#define mulpade(carry,high,low,m) \+ movq m, %rax ; \+ mulq %rbx; \+ subq carry, %rdx ; \+ addq %rax, low ; \+ adcq %rdx, high++// Core one-step Montgomery reduction macro. Takes input in+// [d7;d6;d5;d4;d3;d2;d1;d0] and returns result in [d7;d6;d5;d4;d3;d2;d1],+// adding to the existing contents, re-using d0 as a temporary internally+//+// We want to add (2^384 - 2^128 - 2^96 + 2^32 - 1) * w+// where w = [d0 + (d0<<32)] mod 2^64+//+// montredc(d7,d6,d5,d4,d3,d2,d1,d0)+//+// This particular variant, with its mix of addition and subtraction+// at the top, is not intended to maintain a coherent carry or borrow out.+// It is assumed the final result would fit in [d7;d6;d5;d4;d3;d2;d1].+// which is always the case here as the top word is even always in {0,1}++#define montredc(d7,d6,d5,d4,d3,d2,d1,d0) \+/* Our correction multiplier is w = [d0 + (d0<<32)] mod 2^64 */ \+ movq d0, %rbx ; \+ shlq $32, %rbx ; \+ addq d0, %rbx ; \+/* Construct [%rcx;%rdx;%rax;-] = (2^384 - p_384) * w */ \+/* We know the lowest word will cancel so we can re-use d0 as a temp */ \+ xorl %ecx, %ecx ; \+ movq $0xffffffff00000001, %rax ; \+ mulq %rbx; \+ movq %rdx, d0 ; \+ movq $0x00000000ffffffff, %rax ; \+ mulq %rbx; \+ addq d0, %rax ; \+ adcq %rbx, %rdx ; \+ adcl %ecx, %ecx ; \+/* Now subtract that and add 2^384 * w */ \+ subq %rax, d1 ; \+ sbbq %rdx, d2 ; \+ sbbq %rcx, d3 ; \+ sbbq $0, d4 ; \+ sbbq $0, d5 ; \+ sbbq $0, %rbx ; \+ addq %rbx, d6 ; \+ adcq $0, d7++S2N_BN_SYMBOL(bignum_tomont_p384_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// We are essentially just doing a Montgomery multiplication of x and the+// precomputed constant y = 2^768 mod p, so the code is almost the same+// modulo a few registers and the change from loading y[i] to using constants,+// plus the easy digits y[4] = 1 and y[5] = 0 being treated specially.+// Because there is no y pointer to keep, we use one register less.++ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++// Do row 0 computation, which is a bit different:+// set up initial window [%r14,%r13,%r12,%r11,%r10,%r9,%r8] = y[0] * x+// Unlike later, we only need a single carry chain++ movq $0xfffffffe00000001, %rbx+ movq (x), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9++ movq 8(x), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10++ movq 16(x), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11++ movq 24(x), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12++ movq 32(x), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13++ movq 40(x), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14++ xorl %r15d, %r15d++// Montgomery reduce the zeroth window++ montredc(%r15, %r14,%r13,%r12,%r11,%r10,%r9,%r8)++// Add row 1++ movq $0x0000000200000000, %rbx+ mulpadi(%r8,%r10,%r9,(x))+ mulpadd(%r8,%r11,%r10,8(x))+ mulpadd(%r8,%r12,%r11,16(x))+ mulpadd(%r8,%r13,%r12,24(x))+ mulpadd(%r8,%r14,%r13,32(x))+ mulpadd(%r8,%r15,%r14,40(x))+ negq %r8++// Montgomery reduce window 1++ montredc(%r8, %r15,%r14,%r13,%r12,%r11,%r10,%r9)++// Add row 2++ movq $0xfffffffe00000000, %rbx+ mulpadi(%r9,%r11,%r10,(x))+ mulpadd(%r9,%r12,%r11,8(x))+ mulpadd(%r9,%r13,%r12,16(x))+ mulpadd(%r9,%r14,%r13,24(x))+ mulpadd(%r9,%r15,%r14,32(x))+ mulpadd(%r9,%r8,%r15,40(x))+ negq %r9++// Montgomery reduce window 2++ montredc(%r9, %r8,%r15,%r14,%r13,%r12,%r11,%r10)++// Add row 3++ movq $0x0000000200000000, %rbx+ mulpadi(%r10,%r12,%r11,(x))+ mulpadd(%r10,%r13,%r12,8(x))+ mulpadd(%r10,%r14,%r13,16(x))+ mulpadd(%r10,%r15,%r14,24(x))+ mulpadd(%r10,%r8,%r15,32(x))+ mulpadd(%r10,%r9,%r8,40(x))+ negq %r10++// Montgomery reduce window 3++ montredc(%r10, %r9,%r8,%r15,%r14,%r13,%r12,%r11)++// Add row 4. The multiplier y[4] = 1, so we just add x to the window+// while extending it with one more digit, initially this carry++ xorq %r11, %r11+ addq (x), %r12+ adcq 8(x), %r13+ adcq 16(x), %r14+ adcq 24(x), %r15+ adcq 32(x), %r8+ adcq 40(x), %r9+ adcq %r11, %r10+ adcq %r11, %r11++// Montgomery reduce window 4++ montredc(%r11, %r10,%r9,%r8,%r15,%r14,%r13,%r12)++// Add row 5, The multiplier y[5] = 0, so this is trivial: all we do is+// bring down another zero digit into the window.++ xorq %r12, %r12++// Montgomery reduce window 5++ montredc(%r12, %r11,%r10,%r9,%r8,%r15,%r14,%r13)++// We now have a pre-reduced 7-word form [%r12;%r11;%r10;%r9;%r8;%r15;%r14]++// We know, writing B = 2^{6*64} that the full implicit result is+// B^2 c <= z + (B - 1) * p < B * p + (B - 1) * p < 2 * B * p,+// so the top half is certainly < 2 * p. If c = 1 already, we know+// subtracting p will give the reduced modulus. But now we do a+// comparison to catch cases where the residue is >= p.+// First set [0;0;0;w;v;u] = 2^384 - p_384++ movq $0xffffffff00000001, u+ movl $0x00000000ffffffff, vshort+ movl $0x0000000000000001, wshort++// Let dd = [%r11;%r10;%r9;%r8;%r15;%r14] be the topless 6-word intermediate result.+// Set CF if the addition dd + (2^384 - p_384) >= 2^384, hence iff dd >= p_384.++ movq %r14, d+ addq u, d+ movq %r15, d+ adcq v, d+ movq %r8, d+ adcq w, d+ movq %r9, d+ adcq $0, d+ movq %r10, d+ adcq $0, d+ movq %r11, d+ adcq $0, d++// Now just add this new carry into the existing %r12. It's easy to see they+// can't both be 1 by our range assumptions, so this gives us a {0,1} flag++ adcq $0, %r12++// Now convert it into a bitmask++ negq %r12++// Masked addition of 2^384 - p_384, hence subtraction of p_384++ andq %r12, u+ andq %r12, v+ andq %r12, w++ addq u, %r14+ adcq v, %r15+ adcq w, %r8+ adcq $0, %r9+ adcq $0, %r10+ adcq $0, %r11++// Write back the result++ movq %r14, (z)+ movq %r15, 8(z)+ movq %r8, 16(z)+ movq %r9, 24(z)+ movq %r10, 32(z)+ movq %r11, 40(z)++// Restore registers and return++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(bignum_tomont_p384_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/curve25519_x25519.S view
@@ -0,0 +1,2189 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// The x25519 function for curve25519+// Inputs scalar[4], point[4]; output res[4]+//+// extern void curve25519_x25519+// (uint64_t res[static 4],const uint64_t scalar[static 4],+// const uint64_t point[static 4]);+//+// The function has a second prototype considering the arguments as arrays+// of bytes rather than 64-bit words. The underlying code is the same, since+// the x86 platform is little-endian.+//+// extern void curve25519_x25519_byte+// (uint8_t res[static 32],const uint8_t scalar[static 32],+// const uint8_t point[static 32]);+//+// Given a scalar n and the X coordinate of an input point P = (X,Y) on+// curve25519 (Y can live in any extension field of characteristic 2^255-19),+// this returns the X coordinate of n * P = (X, Y), or 0 when n * P is the+// point at infinity. Both n and X inputs are first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748);+// in particular the lower three bits of n are set to zero. Does not implement+// the zero-check specified in Section 6.1.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519_byte)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519_byte)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519_byte)+ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Stable homes for the input result argument during the whole body+// and other variables that are only needed prior to the modular inverse.++#define res 12*NUMSIZE(%rsp)+#define i 12*NUMSIZE+8(%rsp)+#define swap 12*NUMSIZE+16(%rsp)++// Pointers to result x coord to be written, assuming the base "res"+// has been loaded into %rbp++#define resx 0(%rbp)++// Pointer-offset pairs for temporaries on stack with some aliasing.+// Both dmsn and dnsm need space for >= 5 digits, and we allocate 8++#define scalar (0*NUMSIZE)(%rsp)++#define pointx (1*NUMSIZE)(%rsp)++#define dm (2*NUMSIZE)(%rsp)++#define zm (3*NUMSIZE)(%rsp)+#define sm (3*NUMSIZE)(%rsp)+#define dpro (3*NUMSIZE)(%rsp)++#define sn (4*NUMSIZE)(%rsp)++#define dn (5*NUMSIZE)(%rsp)+#define e (5*NUMSIZE)(%rsp)++#define dmsn (6*NUMSIZE)(%rsp)+#define p (6*NUMSIZE)(%rsp)+#define zn (7*NUMSIZE)(%rsp)++#define xm (8*NUMSIZE)(%rsp)+#define dnsm (8*NUMSIZE)(%rsp)+#define spro (8*NUMSIZE)(%rsp)++#define xn (10*NUMSIZE)(%rsp)+#define s (10*NUMSIZE)(%rsp)++#define d (11*NUMSIZE)(%rsp)++// Total size to reserve on the stack+// This includes space for the 3 other variables above+// and rounds up to a multiple of 32++#define NSPACE 13*NUMSIZE++// Macro wrapping up the basic field operation bignum_mul_p25519, only+// trivially different from a pure function call to that subroutine.++#define mul_p25519(P0,P1,P2) \+ xorl %edi, %edi ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rax, %r10 ; \+ addq %rax, %r9 ; \+ mulxq 0x10+P1, %rax, %r11 ; \+ adcq %rax, %r10 ; \+ mulxq 0x18+P1, %rax, %r12 ; \+ adcq %rax, %r11 ; \+ adcq %rdi, %r12 ; \+ xorl %edi, %edi ; \+ movq 0x8+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %r13 ; \+ adcxq %rax, %r12 ; \+ adoxq %rdi, %r13 ; \+ adcxq %rdi, %r13 ; \+ xorl %edi, %edi ; \+ movq 0x10+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x18+P1, %rax, %r14 ; \+ adcxq %rax, %r13 ; \+ adoxq %rdi, %r14 ; \+ adcxq %rdi, %r14 ; \+ xorl %edi, %edi ; \+ movq 0x18+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq 0x18+P1, %rax, %r15 ; \+ adcxq %rax, %r14 ; \+ adoxq %rdi, %r15 ; \+ adcxq %rdi, %r15 ; \+ movl $0x26, %edx ; \+ xorl %edi, %edi ; \+ mulxq %r12, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq %r13, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r14, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rdi, %r12 ; \+ adcxq %rdi, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ movl $0x13, %edx ; \+ incq %r12; \+ bts $63, %r11 ; \+ mulxq %r12, %rax, %rbx ; \+ addq %rax, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rdi, %r10 ; \+ adcq %rdi, %r11 ; \+ sbbq %rax, %rax ; \+ notq %rax; \+ andq %rdx, %rax ; \+ subq %rax, %r8 ; \+ sbbq %rdi, %r9 ; \+ sbbq %rdi, %r10 ; \+ sbbq %rdi, %r11 ; \+ btr $63, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ xorl %ecx, %ecx ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rax, %r10 ; \+ addq %rax, %r9 ; \+ mulxq 0x10+P1, %rax, %r11 ; \+ adcq %rax, %r10 ; \+ mulxq 0x18+P1, %rax, %r12 ; \+ adcq %rax, %r11 ; \+ adcq %rcx, %r12 ; \+ xorl %ecx, %ecx ; \+ movq 0x8+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %r13 ; \+ adcxq %rax, %r12 ; \+ adoxq %rcx, %r13 ; \+ adcxq %rcx, %r13 ; \+ xorl %ecx, %ecx ; \+ movq 0x10+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x18+P1, %rax, %r14 ; \+ adcxq %rax, %r13 ; \+ adoxq %rcx, %r14 ; \+ adcxq %rcx, %r14 ; \+ xorl %ecx, %ecx ; \+ movq 0x18+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq 0x18+P1, %rax, %r15 ; \+ adcxq %rax, %r14 ; \+ adoxq %rcx, %r15 ; \+ adcxq %rcx, %r15 ; \+ movl $0x26, %edx ; \+ xorl %ecx, %ecx ; \+ mulxq %r12, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq %r13, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r14, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rcx, %r12 ; \+ adcxq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Multiplication just giving a 5-digit result (actually < 39 * p_25519)+// by not doing anything beyond the first stage of reduction++#define mul_5(P0,P1,P2) \+ xorl %edi, %edi ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rax, %r10 ; \+ addq %rax, %r9 ; \+ mulxq 0x10+P1, %rax, %r11 ; \+ adcq %rax, %r10 ; \+ mulxq 0x18+P1, %rax, %r12 ; \+ adcq %rax, %r11 ; \+ adcq %rdi, %r12 ; \+ xorl %edi, %edi ; \+ movq 0x8+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %r13 ; \+ adcxq %rax, %r12 ; \+ adoxq %rdi, %r13 ; \+ adcxq %rdi, %r13 ; \+ xorl %edi, %edi ; \+ movq 0x10+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x18+P1, %rax, %r14 ; \+ adcxq %rax, %r13 ; \+ adoxq %rdi, %r14 ; \+ adcxq %rdi, %r14 ; \+ xorl %edi, %edi ; \+ movq 0x18+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq 0x18+P1, %rax, %r15 ; \+ adcxq %rax, %r14 ; \+ adoxq %rdi, %r15 ; \+ adcxq %rdi, %r15 ; \+ movl $0x26, %edx ; \+ xorl %edi, %edi ; \+ mulxq %r12, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq %r13, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r14, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rdi, %r12 ; \+ adcxq %rdi, %r12 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0 ; \+ movq %r12, 0x20+P0++// Squaring just giving a result < 2 * p_25519, which is done by+// basically skipping the +1 in the quotient estimate and the final+// optional correction.++#define sqr_4(P0,P1) \+ movq P1, %rdx ; \+ mulxq %rdx, %r8, %r15 ; \+ mulxq 0x8+P1, %r9, %r10 ; \+ mulxq 0x18+P1, %r11, %r12 ; \+ movq 0x10+P1, %rdx ; \+ mulxq 0x18+P1, %r13, %r14 ; \+ xorl %ebx, %ebx ; \+ mulxq P1, %rax, %rcx ; \+ adcxq %rax, %r10 ; \+ adoxq %rcx, %r11 ; \+ mulxq 0x8+P1, %rax, %rcx ; \+ adcxq %rax, %r11 ; \+ adoxq %rcx, %r12 ; \+ movq 0x18+P1, %rdx ; \+ mulxq 0x8+P1, %rax, %rcx ; \+ adcxq %rax, %r12 ; \+ adoxq %rcx, %r13 ; \+ adcxq %rbx, %r13 ; \+ adoxq %rbx, %r14 ; \+ adcq %rbx, %r14 ; \+ xorl %ebx, %ebx ; \+ adcxq %r9, %r9 ; \+ adoxq %r15, %r9 ; \+ movq 0x8+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r10, %r10 ; \+ adoxq %rax, %r10 ; \+ adcxq %r11, %r11 ; \+ adoxq %rdx, %r11 ; \+ movq 0x10+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r12, %r12 ; \+ adoxq %rax, %r12 ; \+ adcxq %r13, %r13 ; \+ adoxq %rdx, %r13 ; \+ movq 0x18+P1, %rdx ; \+ mulxq %rdx, %rax, %r15 ; \+ adcxq %r14, %r14 ; \+ adoxq %rax, %r14 ; \+ adcxq %rbx, %r15 ; \+ adoxq %rbx, %r15 ; \+ movl $0x26, %edx ; \+ xorl %ebx, %ebx ; \+ mulxq %r12, %rax, %rcx ; \+ adcxq %rax, %r8 ; \+ adoxq %rcx, %r9 ; \+ mulxq %r13, %rax, %rcx ; \+ adcxq %rax, %r9 ; \+ adoxq %rcx, %r10 ; \+ mulxq %r14, %rax, %rcx ; \+ adcxq %rax, %r10 ; \+ adoxq %rcx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ adcxq %rbx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rbx, %r10 ; \+ adcq %rbx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Add 5-digit inputs and normalize to 4 digits++#define add5_4(P0,P1,P2) \+ movq P1, %r8 ; \+ addq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ adcq 8+P2, %r9 ; \+ movq 16+P1, %r10 ; \+ adcq 16+P2, %r10 ; \+ movq 24+P1, %r11 ; \+ adcq 24+P2, %r11 ; \+ movq 32+P1, %r12 ; \+ adcq 32+P2, %r12 ; \+ xorl %ebx, %ebx ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rbx, %r10 ; \+ adcq %rbx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular addition with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq P2, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq 0x8+P2, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq 0x10+P2, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq 0x18+P2, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ebx, %ebx ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movl $38, %ecx ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %rax ; \+ sbbq 24+P2, %rax ; \+ cmovncq %rbx, %rcx ; \+ subq %rcx, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %rax ; \+ movq %r8, P0 ; \+ movq %r9, 8+P0 ; \+ movq %r10, 16+P0 ; \+ movq %rax, 24+P0++// 5-digit subtraction with upward bias to make it positive, adding+// 1000 * (2^255 - 19) = 2^256 * 500 - 19000, then normalizing to 4 digits++#define sub5_4(P0,P1,P2) \+ movq P1, %r8 ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %r11 ; \+ sbbq 24+P2, %r11 ; \+ movq 32+P1, %r12 ; \+ sbbq 32+P2, %r12 ; \+ xorl %ebx, %ebx ; \+ subq $19000, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %r11 ; \+ sbbq %rbx, %r12 ; \+ addq $500, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rbx, %r10 ; \+ adcq %rbx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Combined z = c * x + y with reduction only < 2 * p_25519+// It is assumed that 19 * (c * x + y) < 2^60 * 2^256 so we+// don't need a high mul in the final part.++#define cmadd_4(P0,C1,P2,P3) \+ movq P3, %r8 ; \+ movq 8+P3, %r9 ; \+ movq 16+P3, %r10 ; \+ movq 24+P3, %r11 ; \+ xorl %edi, %edi ; \+ movq $C1, %rdx ; \+ mulxq P2, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq 8+P2, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 16+P2, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 24+P2, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rdi, %rbx ; \+ adcxq %rdi, %rbx ; \+ shldq $0x1, %r11, %rbx ; \+ btr $63, %r11 ; \+ movl $0x13, %edx ; \+ imulq %rdx, %rbx ; \+ addq %rbx, %r8 ; \+ adcq %rdi, %r9 ; \+ adcq %rdi, %r10 ; \+ adcq %rdi, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Multiplex: z := if NZ then x else y++#define mux_4(P0,P1,P2) \+ movq P1, %rax ; \+ movq P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, P0 ; \+ movq 8+P1, %rax ; \+ movq 8+P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, 8+P0 ; \+ movq 16+P1, %rax ; \+ movq 16+P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, 16+P0 ; \+ movq 24+P1, %rax ; \+ movq 24+P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, 24+P0++S2N_BN_SYMBOL(curve25519_x25519):+S2N_BN_SYMBOL(curve25519_x25519_byte):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save registers, make room for temps, preserve input arguments.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(NSPACE)++// Move the output pointer to a stable place++ movq %rdi, res++// Copy the inputs to the local variables with minimal mangling:+//+// - The scalar is in principle turned into 01xxx...xxx000 but+// in the structure below the special handling of these bits is+// explicit in the main computation; the scalar is just copied.+//+// - The point x coord is reduced mod 2^255 by masking off the+// top bit. In the main loop we only need reduction < 2 * p_25519.++ movq (%rsi), %rax+ movq %rax, (%rsp)+ movq 8(%rsi), %rax+ movq %rax, 8(%rsp)+ movq 16(%rsi), %rax+ movq %rax, 16(%rsp)+ movq 24(%rsi), %rax+ movq %rax, 24(%rsp)++ movq (%rdx), %r8+ movq 8(%rdx), %r9+ movq 16(%rdx), %r10+ movq 24(%rdx), %r11+ btr $63, %r11+ movq %r8, 32(%rsp)+ movq %r9, 40(%rsp)+ movq %r10, 48(%rsp)+ movq %r11, 56(%rsp)++// Initialize with explicit doubling in order to handle set bit 254.+// Set swap = 1 and (xm,zm) = (x,1) then double as (xn,zn) = 2 * (x,1).+// We use the fact that the point x coordinate is still in registers.+// Since zm = 1 we could do the doubling with an operation count of+// 2 * S + M instead of 2 * S + 2 * M, but it doesn't seem worth+// the slight complication arising from a different linear combination.++ movl $1, %eax+ movq %rax, swap+ movq %r8, 256(%rsp)+ movq %rax, 96(%rsp)+ xorl %eax, %eax+ movq %r9, 264(%rsp)+ movq %rax, 104(%rsp)+ movq %r10, 272(%rsp)+ movq %rax, 112(%rsp)+ movq %r11, 280(%rsp)+ movq %rax, 120(%rsp)++ sub_twice4(d,xm,zm)+ add_twice4(s,xm,zm)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++// The main loop over unmodified bits from i = 253, ..., i = 3 (inclusive).+// This is a classic Montgomery ladder, with the main coordinates only+// reduced mod 2 * p_25519, some intermediate results even more loosely.++ movl $253, %eax+ movq %rax, i++Lcurve25519_x25519_scalarloop:++// sm = xm + zm; sn = xn + zn; dm = xm - zm; dn = xn - zn++ sub_twice4(dm,xm,zm)+ add_twice4(sn,xn,zn)+ sub_twice4(dn,xn,zn)+ add_twice4(sm,xm,zm)++// DOUBLING: mux d = xt - zt and s = xt + zt for appropriate choice of (xt,zt)++ movq i, %rdx+ movq %rdx, %rcx+ shrq $6, %rdx+ movq (%rsp,%rdx,8), %rdx+ shrq %cl, %rdx+ andq $1, %rdx+ cmpq swap, %rdx+ movq %rdx, swap+ mux_4(d,dm,dn)+ mux_4(s,sm,sn)++// ADDING: dmsn = dm * sn; dnsm = sm * dn++ mul_5(dnsm,sm,dn)+ mul_5(dmsn,sn,dm)++// DOUBLING: d = (xt - zt)^2++ sqr_4(d,d)++// ADDING: dpro = (dmsn - dnsm)^2, spro = (dmsn + dnsm)^2+// DOUBLING: s = (xt + zt)^2++ sub5_4(dpro,dmsn,dnsm)+ add5_4(spro,dmsn,dnsm)+ sqr_4(s,s)+ sqr_4(dpro,dpro)++// DOUBLING: p = 4 * xt * zt = s - d++ sub_twice4(p,s,d)++// ADDING: xm' = (dmsn + dnsm)^2++ sqr_4(xm,spro)++// DOUBLING: e = 121666 * p + d++ cmadd_4(e,0x1db42,p,d)++// DOUBLING: xn' = (xt + zt)^2 * (xt - zt)^2 = s * d++ mul_4(xn,s,d)++// DOUBLING: zn' = (4 * xt * zt) * ((xt - zt)^2 + 121666 * (4 * xt * zt))+// = p * (d + 121666 * p)++ mul_4(zn,p,e)++// ADDING: zm' = x * (dmsn - dnsm)^2++ mul_4(zm,dpro,pointx)++// Loop down as far as 3 (inclusive)++ movq i, %rax+ subq $1, %rax+ movq %rax, i+ cmpq $3, %rax+ jnc Lcurve25519_x25519_scalarloop++// Multiplex directly into (xn,zn) then do three pure doubling steps;+// this accounts for the implicit zeroing of the three lowest bits+// of the scalar.++ movq swap, %rdx+ testq %rdx, %rdx+ mux_4(xn,xm,xn)+ mux_4(zn,zm,zn)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++// The projective result of the scalar multiplication is now (xn,zn).+// Prepare to call the modular inverse function to get zn' = 1/zn++ leaq 224(%rsp), %rdi+ leaq 224(%rsp), %rsi++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "x86/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 208 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, xn and zn.++ movq %rdi, 0xc0(%rsp)+ xorl %eax, %eax+ leaq -0x13(%rax), %rcx+ notq %rax+ movq %rcx, (%rsp)+ movq %rax, 0x8(%rsp)+ movq %rax, 0x10(%rsp)+ btr $0x3f, %rax+ movq %rax, 0x18(%rsp)+ movq (%rsi), %rdx+ movq 0x8(%rsi), %rcx+ movq 0x10(%rsi), %r8+ movq 0x18(%rsi), %r9+ movl $0x1, %eax+ xorl %r10d, %r10d+ bts $0x3f, %r9+ adcq %r10, %rax+ imulq $0x13, %rax, %rax+ addq %rax, %rdx+ adcq %r10, %rcx+ adcq %r10, %r8+ adcq %r10, %r9+ movl $0x13, %eax+ cmovbq %r10, %rax+ subq %rax, %rdx+ sbbq %r10, %rcx+ sbbq %r10, %r8+ sbbq %r10, %r9+ btr $0x3f, %r9+ movq %rdx, 0x20(%rsp)+ movq %rcx, 0x28(%rsp)+ movq %r8, 0x30(%rsp)+ movq %r9, 0x38(%rsp)+ xorl %eax, %eax+ movq %rax, 0x40(%rsp)+ movq %rax, 0x48(%rsp)+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movabsq $0xa0f99e2375022099, %rax+ movq %rax, 0x60(%rsp)+ movabsq $0xa8c68f3f1d132595, %rax+ movq %rax, 0x68(%rsp)+ movabsq $0x6c6c893805ac5242, %rax+ movq %rax, 0x70(%rsp)+ movabsq $0x276508b241770615, %rax+ movq %rax, 0x78(%rsp)+ movq $0xa, 0x90(%rsp)+ movq $0x1, 0x98(%rsp)+ jmp Lcurve25519_x25519_midloop+Lcurve25519_x25519_inverseloop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0x80(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0x88(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x20(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x20(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x20(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x28(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq %rax, %rbp+ sarq $0x3f, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ xorq %r13, %rax+ movq %rax, %rsi+ sarq $0x3f, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x30(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x38(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x88(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x40(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x40(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x60(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x60(%rsp)+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x48(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x48(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x68(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x68(%rsp)+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x70(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x70(%rsp)+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq %rdx, %rbx+ shldq $0x1, %rcx, %rdx+ sarq $0x3f, %rbx+ addq %rbx, %rdx+ movl $0x13, %eax+ imulq %rdx+ movq 0x40(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x40(%rsp)+ movq 0x48(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x48(%rsp)+ movq 0x50(%rsp), %r8+ adcq %rbx, %r8+ movq %r8, 0x50(%rsp)+ adcq %rbx, %rcx+ shlq $0x3f, %rax+ addq %rax, %rcx+ movq 0x58(%rsp), %rax+ movq %rcx, 0x58(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rdx, %rcx+ shldq $0x1, %rsi, %rdx+ sarq $0x3f, %rcx+ movl $0x13, %eax+ addq %rcx, %rdx+ imulq %rdx+ movq 0x60(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x60(%rsp)+ movq 0x68(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x68(%rsp)+ movq 0x70(%rsp), %r8+ adcq %rcx, %r8+ movq %r8, 0x70(%rsp)+ adcq %rcx, %rsi+ shlq $0x3f, %rax+ addq %rax, %rsi+ movq %rsi, 0x78(%rsp)+Lcurve25519_x25519_midloop:+ movq 0x98(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x20(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rdi, 0xb0(%rsp)+ movq %rcx, 0xb8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x20(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xa0(%rsp), %rax+ imulq %r8, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xa8(%rsp), %r8+ imulq 0xb8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xa0(%rsp), %rax+ imulq %r10, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xa8(%rsp), %r10+ imulq 0xb8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0x98(%rsp)+ decq 0x90(%rsp)+ jne Lcurve25519_x25519_inverseloop+ movq (%rsp), %rax+ movq 0x20(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r9, %rax+ shldq $0x1, %r15, %rax+ sarq $0x3f, %r9+ movl $0x13, %ebx+ leaq 0x1(%rax,%r9,1), %rax+ imulq %rbx+ xorl %ebp, %ebp+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r9, %r14+ adcq %r9, %r15+ shlq $0x3f, %rax+ addq %rax, %r15+ cmovns %rbp, %rbx+ subq %rbx, %r12+ sbbq %rbp, %r13+ sbbq %rbp, %r14+ sbbq %rbp, %r15+ btr $0x3f, %r15+ movq 0xc0(%rsp), %rdi+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)++// Now the result is xn * (1/zn), fully reduced modulo p.+// Note that in the degenerate case zn = 0 (mod p_25519), the+// modular inverse code above will produce 1/zn = 0, giving+// the correct overall X25519 result of zero for the point at+// infinity.++ movq res, %rbp+ mul_p25519(resx,xn,zn)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519)+S2N_BN_SIZE_DIRECTIVE(curve25519_x25519_byte)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/curve25519_x25519_alt.S view
@@ -0,0 +1,2350 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// The x25519 function for curve25519+// Inputs scalar[4], point[4]; output res[4]+//+// extern void curve25519_x25519_alt+// (uint64_t res[static 4],const uint64_t scalar[static 4],+// const uint64_t point[static 4]);+//+// The function has a second prototype considering the arguments as arrays+// of bytes rather than 64-bit words. The underlying code is the same, since+// the x86 platform is little-endian.+//+// extern void curve25519_x25519_byte_alt+// (uint8_t res[static 32],const uint8_t scalar[static 32],+// const uint8_t point[static 32]);+//+// Given a scalar n and the X coordinate of an input point P = (X,Y) on+// curve25519 (Y can live in any extension field of characteristic 2^255-19),+// this returns the X coordinate of n * P = (X, Y), or 0 when n * P is the+// point at infinity. Both n and X inputs are first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748);+// in particular the lower three bits of n are set to zero. Does not implement+// the zero-check specified in Section 6.1.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519_alt)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519_byte_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519_byte_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519_byte_alt)+ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Stable homes for the input result argument during the whole body+// and other variables that are only needed prior to the modular inverse.++#define res 12*NUMSIZE(%rsp)+#define i 12*NUMSIZE+8(%rsp)+#define swap 12*NUMSIZE+16(%rsp)++// Pointers to result x coord to be written, assuming the base "res"+// has been loaded into %rbp++#define resx 0(%rbp)++// Pointer-offset pairs for temporaries on stack with some aliasing.+// Both dmsn and dnsm need space for >= 5 digits, and we allocate 8++#define scalar (0*NUMSIZE)(%rsp)++#define pointx (1*NUMSIZE)(%rsp)++#define dm (2*NUMSIZE)(%rsp)++#define zm (3*NUMSIZE)(%rsp)+#define sm (3*NUMSIZE)(%rsp)+#define dpro (3*NUMSIZE)(%rsp)++#define sn (4*NUMSIZE)(%rsp)++#define dn (5*NUMSIZE)(%rsp)+#define e (5*NUMSIZE)(%rsp)++#define dmsn (6*NUMSIZE)(%rsp)+#define p (6*NUMSIZE)(%rsp)+#define zn (7*NUMSIZE)(%rsp)++#define xm (8*NUMSIZE)(%rsp)+#define dnsm (8*NUMSIZE)(%rsp)+#define spro (8*NUMSIZE)(%rsp)++#define xn (10*NUMSIZE)(%rsp)+#define s (10*NUMSIZE)(%rsp)++#define d (11*NUMSIZE)(%rsp)++// Total size to reserve on the stack+// This includes space for the 3 other variables above+// and rounds up to a multiple of 32++#define NSPACE 13*NUMSIZE++// Macro wrapping up the basic field operation bignum_mul_p25519_alt, only+// trivially different from a pure function call to that subroutine.++#define mul_p25519(P0,P1,P2) \+ movq P1, %rax ; \+ mulq P2; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x8+P1, %rax ; \+ mulq P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq 0x10+P1, %rax ; \+ mulq P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq %r13, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x18+P1, %rax ; \+ mulq P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %esi ; \+ movq %r12, %rax ; \+ mulq %rsi; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ leaq 0x1(%r12), %rax ; \+ movl $0x13, %esi ; \+ bts $63, %r11 ; \+ imulq %rsi, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ sbbq %rax, %rax ; \+ notq %rax; \+ andq %rsi, %rax ; \+ subq %rax, %r8 ; \+ sbbq %rcx, %r9 ; \+ sbbq %rcx, %r10 ; \+ sbbq %rcx, %r11 ; \+ btr $63, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ movq P1, %rax ; \+ mulq P2; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x8+P1, %rax ; \+ mulq P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq 0x10+P1, %rax ; \+ mulq P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq %r13, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x18+P1, %rax ; \+ mulq P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %esi ; \+ movq %r12, %rax ; \+ mulq %rsi; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Multiplication just giving a 5-digit result (actually < 39 * p_25519)+// by not doing anything beyond the first stage of reduction++#define mul_5(P0,P1,P2) \+ movq P1, %rax ; \+ mulq P2; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x8+P1, %rax ; \+ mulq P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq 0x10+P1, %rax ; \+ mulq P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq %r13, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x18+P1, %rax ; \+ mulq P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %esi ; \+ movq %r12, %rax ; \+ mulq %rsi; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0 ; \+ movq %r12, 0x20+P0++// Squaring just giving a result < 2 * p_25519, which is done by+// basically skipping the +1 in the quotient estimate and the final+// optional correction.++#define sqr_4(P0,P1) \+ movq P1, %rax ; \+ mulq %rax; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P1; \+ addq %rax, %rax ; \+ adcq %rdx, %rdx ; \+ adcq $0x0, %r11 ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq %rax; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P1; \+ addq %rax, %rax ; \+ adcq %rdx, %rdx ; \+ adcq $0x0, %r12 ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P1; \+ addq %rax, %rax ; \+ adcq %rdx, %rdx ; \+ adcq $0x0, %r13 ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P1; \+ addq %rax, %rax ; \+ adcq %rdx, %rdx ; \+ adcq $0x0, %r13 ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P1; \+ addq %rax, %rax ; \+ adcq %rdx, %rdx ; \+ adcq $0x0, %r14 ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq %rax; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P1; \+ addq %rax, %rax ; \+ adcq %rdx, %rdx ; \+ adcq $0x0, %r15 ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq %rax; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %esi ; \+ movq %r12, %rax ; \+ mulq %rsi; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Add 5-digit inputs and normalize to 4 digits++#define add5_4(P0,P1,P2) \+ movq P1, %r8 ; \+ addq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ adcq 8+P2, %r9 ; \+ movq 16+P1, %r10 ; \+ adcq 16+P2, %r10 ; \+ movq 24+P1, %r11 ; \+ adcq 24+P2, %r11 ; \+ movq 32+P1, %r12 ; \+ adcq 32+P2, %r12 ; \+ xorl %ebx, %ebx ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rbx, %r10 ; \+ adcq %rbx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular addition with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq P2, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq 0x8+P2, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq 0x10+P2, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq 0x18+P2, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ebx, %ebx ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movl $38, %ecx ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %rax ; \+ sbbq 24+P2, %rax ; \+ cmovncq %rbx, %rcx ; \+ subq %rcx, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %rax ; \+ movq %r8, P0 ; \+ movq %r9, 8+P0 ; \+ movq %r10, 16+P0 ; \+ movq %rax, 24+P0++// 5-digit subtraction with upward bias to make it positive, adding+// 1000 * (2^255 - 19) = 2^256 * 500 - 19000, then normalizing to 4 digits++#define sub5_4(P0,P1,P2) \+ movq P1, %r8 ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %r11 ; \+ sbbq 24+P2, %r11 ; \+ movq 32+P1, %r12 ; \+ sbbq 32+P2, %r12 ; \+ xorl %ebx, %ebx ; \+ subq $19000, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %r11 ; \+ sbbq %rbx, %r12 ; \+ addq $500, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rbx, %r10 ; \+ adcq %rbx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Combined z = c * x + y with reduction only < 2 * p_25519+// It is assumed that 19 * (c * x + y) < 2^60 * 2^256 so we+// don't need a high mul in the final part.++#define cmadd_4(P0,C1,P2,P3) \+ movq $C1, %rsi ; \+ movq P2, %rax ; \+ mulq %rsi; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ movq 0x8+P2, %rax ; \+ xorq %r10, %r10 ; \+ mulq %rsi; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x10+P2, %rax ; \+ mulq %rsi; \+ addq %rax, %r10 ; \+ adcq $0x0, %rdx ; \+ movq 0x18+P2, %rax ; \+ movq %rdx, %r11 ; \+ mulq %rsi; \+ xorl %esi, %esi ; \+ addq %rax, %r11 ; \+ adcq %rsi, %rdx ; \+ addq P3, %r8 ; \+ adcq 0x8+P3, %r9 ; \+ adcq 0x10+P3, %r10 ; \+ adcq 0x18+P3, %r11 ; \+ adcq %rsi, %rdx ; \+ shldq $0x1, %r11, %rdx ; \+ btr $63, %r11 ; \+ movl $0x13, %ebx ; \+ imulq %rbx, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rsi, %r9 ; \+ adcq %rsi, %r10 ; \+ adcq %rsi, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Multiplex: z := if NZ then x else y++#define mux_4(P0,P1,P2) \+ movq P1, %rax ; \+ movq P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, P0 ; \+ movq 8+P1, %rax ; \+ movq 8+P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, 8+P0 ; \+ movq 16+P1, %rax ; \+ movq 16+P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, 16+P0 ; \+ movq 24+P1, %rax ; \+ movq 24+P2, %rcx ; \+ cmovzq %rcx, %rax ; \+ movq %rax, 24+P0++S2N_BN_SYMBOL(curve25519_x25519_alt):+S2N_BN_SYMBOL(curve25519_x25519_byte_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save registers, make room for temps, preserve input arguments.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(NSPACE)++// Move the output pointer to a stable place++ movq %rdi, res++// Copy the inputs to the local variables with minimal mangling:+//+// - The scalar is in principle turned into 01xxx...xxx000 but+// in the structure below the special handling of these bits is+// explicit in the main computation; the scalar is just copied.+//+// - The point x coord is reduced mod 2^255 by masking off the+// top bit. In the main loop we only need reduction < 2 * p_25519.++ movq (%rsi), %rax+ movq %rax, (%rsp)+ movq 8(%rsi), %rax+ movq %rax, 8(%rsp)+ movq 16(%rsi), %rax+ movq %rax, 16(%rsp)+ movq 24(%rsi), %rax+ movq %rax, 24(%rsp)++ movq (%rdx), %r8+ movq 8(%rdx), %r9+ movq 16(%rdx), %r10+ movq 24(%rdx), %r11+ btr $63, %r11+ movq %r8, 32(%rsp)+ movq %r9, 40(%rsp)+ movq %r10, 48(%rsp)+ movq %r11, 56(%rsp)++// Initialize with explicit doubling in order to handle set bit 254.+// Set swap = 1 and (xm,zm) = (x,1) then double as (xn,zn) = 2 * (x,1).+// We use the fact that the point x coordinate is still in registers.+// Since zm = 1 we could do the doubling with an operation count of+// 2 * S + M instead of 2 * S + 2 * M, but it doesn't seem worth+// the slight complication arising from a different linear combination.++ movl $1, %eax+ movq %rax, swap+ movq %r8, 256(%rsp)+ movq %rax, 96(%rsp)+ xorl %eax, %eax+ movq %r9, 264(%rsp)+ movq %rax, 104(%rsp)+ movq %r10, 272(%rsp)+ movq %rax, 112(%rsp)+ movq %r11, 280(%rsp)+ movq %rax, 120(%rsp)++ sub_twice4(d,xm,zm)+ add_twice4(s,xm,zm)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++// The main loop over unmodified bits from i = 253, ..., i = 3 (inclusive).+// This is a classic Montgomery ladder, with the main coordinates only+// reduced mod 2 * p_25519, some intermediate results even more loosely.++ movl $253, %eax+ movq %rax, i++Lcurve25519_x25519_alt_scalarloop:++// sm = xm + zm; sn = xn + zn; dm = xm - zm; dn = xn - zn++ sub_twice4(dm,xm,zm)+ add_twice4(sn,xn,zn)+ sub_twice4(dn,xn,zn)+ add_twice4(sm,xm,zm)++// DOUBLING: mux d = xt - zt and s = xt + zt for appropriate choice of (xt,zt)++ movq i, %rdx+ movq %rdx, %rcx+ shrq $6, %rdx+ movq (%rsp,%rdx,8), %rdx+ shrq %cl, %rdx+ andq $1, %rdx+ cmpq swap, %rdx+ movq %rdx, swap+ mux_4(d,dm,dn)+ mux_4(s,sm,sn)++// ADDING: dmsn = dm * sn; dnsm = sm * dn++ mul_5(dnsm,sm,dn)+ mul_5(dmsn,sn,dm)++// DOUBLING: d = (xt - zt)^2++ sqr_4(d,d)++// ADDING: dpro = (dmsn - dnsm)^2, spro = (dmsn + dnsm)^2+// DOUBLING: s = (xt + zt)^2++ sub5_4(dpro,dmsn,dnsm)+ add5_4(spro,dmsn,dnsm)+ sqr_4(s,s)+ sqr_4(dpro,dpro)++// DOUBLING: p = 4 * xt * zt = s - d++ sub_twice4(p,s,d)++// ADDING: xm' = (dmsn + dnsm)^2++ sqr_4(xm,spro)++// DOUBLING: e = 121666 * p + d++ cmadd_4(e,0x1db42,p,d)++// DOUBLING: xn' = (xt + zt)^2 * (xt - zt)^2 = s * d++ mul_4(xn,s,d)++// DOUBLING: zn' = (4 * xt * zt) * ((xt - zt)^2 + 121666 * (4 * xt * zt))+// = p * (d + 121666 * p)++ mul_4(zn,p,e)++// ADDING: zm' = x * (dmsn - dnsm)^2++ mul_4(zm,dpro,pointx)++// Loop down as far as 3 (inclusive)++ movq i, %rax+ subq $1, %rax+ movq %rax, i+ cmpq $3, %rax+ jnc Lcurve25519_x25519_alt_scalarloop++// Multiplex directly into (xn,zn) then do three pure doubling steps;+// this accounts for the implicit zeroing of the three lowest bits+// of the scalar.++ movq swap, %rdx+ testq %rdx, %rdx+ mux_4(xn,xm,xn)+ mux_4(zn,zm,zn)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++ sub_twice4(d,xn,zn)+ add_twice4(s,xn,zn)+ sqr_4(d,d)+ sqr_4(s,s)+ sub_twice4(p,s,d)+ cmadd_4(e,0x1db42,p,d)+ mul_4(xn,s,d)+ mul_4(zn,p,e)++// The projective result of the scalar multiplication is now (xn,zn).+// Prepare to call the modular inverse function to get zn' = 1/zn++ leaq 224(%rsp), %rdi+ leaq 224(%rsp), %rsi++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "x86/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 208 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, xn and zn.++ movq %rdi, 0xc0(%rsp)+ xorl %eax, %eax+ leaq -0x13(%rax), %rcx+ notq %rax+ movq %rcx, (%rsp)+ movq %rax, 0x8(%rsp)+ movq %rax, 0x10(%rsp)+ btr $0x3f, %rax+ movq %rax, 0x18(%rsp)+ movq (%rsi), %rdx+ movq 0x8(%rsi), %rcx+ movq 0x10(%rsi), %r8+ movq 0x18(%rsi), %r9+ movl $0x1, %eax+ xorl %r10d, %r10d+ bts $0x3f, %r9+ adcq %r10, %rax+ imulq $0x13, %rax, %rax+ addq %rax, %rdx+ adcq %r10, %rcx+ adcq %r10, %r8+ adcq %r10, %r9+ movl $0x13, %eax+ cmovbq %r10, %rax+ subq %rax, %rdx+ sbbq %r10, %rcx+ sbbq %r10, %r8+ sbbq %r10, %r9+ btr $0x3f, %r9+ movq %rdx, 0x20(%rsp)+ movq %rcx, 0x28(%rsp)+ movq %r8, 0x30(%rsp)+ movq %r9, 0x38(%rsp)+ xorl %eax, %eax+ movq %rax, 0x40(%rsp)+ movq %rax, 0x48(%rsp)+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movabsq $0xa0f99e2375022099, %rax+ movq %rax, 0x60(%rsp)+ movabsq $0xa8c68f3f1d132595, %rax+ movq %rax, 0x68(%rsp)+ movabsq $0x6c6c893805ac5242, %rax+ movq %rax, 0x70(%rsp)+ movabsq $0x276508b241770615, %rax+ movq %rax, 0x78(%rsp)+ movq $0xa, 0x90(%rsp)+ movq $0x1, 0x98(%rsp)+ jmp Lcurve25519_x25519_alt_midloop+Lcurve25519_x25519_alt_inverseloop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0x80(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0x88(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x20(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x20(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x20(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x28(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq %rax, %rbp+ sarq $0x3f, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ xorq %r13, %rax+ movq %rax, %rsi+ sarq $0x3f, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x30(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x38(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x88(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x40(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x40(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x60(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x60(%rsp)+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x48(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x48(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x68(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x68(%rsp)+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x70(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x70(%rsp)+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq %rdx, %rbx+ shldq $0x1, %rcx, %rdx+ sarq $0x3f, %rbx+ addq %rbx, %rdx+ movl $0x13, %eax+ imulq %rdx+ movq 0x40(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x40(%rsp)+ movq 0x48(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x48(%rsp)+ movq 0x50(%rsp), %r8+ adcq %rbx, %r8+ movq %r8, 0x50(%rsp)+ adcq %rbx, %rcx+ shlq $0x3f, %rax+ addq %rax, %rcx+ movq 0x58(%rsp), %rax+ movq %rcx, 0x58(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rdx, %rcx+ shldq $0x1, %rsi, %rdx+ sarq $0x3f, %rcx+ movl $0x13, %eax+ addq %rcx, %rdx+ imulq %rdx+ movq 0x60(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x60(%rsp)+ movq 0x68(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x68(%rsp)+ movq 0x70(%rsp), %r8+ adcq %rcx, %r8+ movq %r8, 0x70(%rsp)+ adcq %rcx, %rsi+ shlq $0x3f, %rax+ addq %rax, %rsi+ movq %rsi, 0x78(%rsp)+Lcurve25519_x25519_alt_midloop:+ movq 0x98(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x20(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rdi, 0xb0(%rsp)+ movq %rcx, 0xb8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x20(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xa0(%rsp), %rax+ imulq %r8, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xa8(%rsp), %r8+ imulq 0xb8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xa0(%rsp), %rax+ imulq %r10, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xa8(%rsp), %r10+ imulq 0xb8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0x98(%rsp)+ decq 0x90(%rsp)+ jne Lcurve25519_x25519_alt_inverseloop+ movq (%rsp), %rax+ movq 0x20(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r9, %rax+ shldq $0x1, %r15, %rax+ sarq $0x3f, %r9+ movl $0x13, %ebx+ leaq 0x1(%rax,%r9,1), %rax+ imulq %rbx+ xorl %ebp, %ebp+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r9, %r14+ adcq %r9, %r15+ shlq $0x3f, %rax+ addq %rax, %r15+ cmovns %rbp, %rbx+ subq %rbx, %r12+ sbbq %rbp, %r13+ sbbq %rbp, %r14+ sbbq %rbp, %r15+ btr $0x3f, %r15+ movq 0xc0(%rsp), %rdi+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)++// Now the result is xn * (1/zn), fully reduced modulo p.+// Note that in the degenerate case zn = 0 (mod p_25519), the+// modular inverse code above will produce 1/zn = 0, giving+// the correct overall X25519 result of zero for the point at+// infinity.++ movq res, %rbp+ mul_p25519(resx,xn,zn)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519_alt)+S2N_BN_SIZE_DIRECTIVE(curve25519_x25519_byte_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/curve25519_x25519base.S view
@@ -0,0 +1,9890 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// The x25519 function for curve25519 on base element 9+// Input scalar[4]; output res[4]+//+// extern void curve25519_x25519base+// (uint64_t res[static 4], const uint64_t scalar[static 4]);+//+// The function has a second prototype considering the arguments as arrays+// of bytes rather than 64-bit words. The underlying code is the same, since+// the x86 platform is little-endian.+//+// extern void curve25519_x25519base_byte+// (uint8_t res[static 32],const uint8_t scalar[static 32]);+//+// Given a scalar n, returns the X coordinate of n * G where G = (9,...) is+// the standard generator. The scalar is first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748).+//+// Standard x86-64 ABI: RDI = res, RSI = scalar+// Microsoft x64 ABI: RCX = res, RDX = scalar+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519base)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519base)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519base)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519base_byte)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519base_byte)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519base_byte)++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for result and temporaries on stack with some aliasing.+// The result "resx" assumes the "res" pointer has been preloaded into %rbp.++#define resx (0*NUMSIZE)(%rbp)++#define scalar (0*NUMSIZE)(%rsp)++#define tabent (1*NUMSIZE)(%rsp)+#define ymx_2 (1*NUMSIZE)(%rsp)+#define xpy_2 (2*NUMSIZE)(%rsp)+#define kxy_2 (3*NUMSIZE)(%rsp)++#define acc (4*NUMSIZE)(%rsp)+#define x_1 (4*NUMSIZE)(%rsp)+#define y_1 (5*NUMSIZE)(%rsp)+#define z_1 (6*NUMSIZE)(%rsp)+#define w_1 (7*NUMSIZE)(%rsp)+#define x_3 (4*NUMSIZE)(%rsp)+#define y_3 (5*NUMSIZE)(%rsp)+#define z_3 (6*NUMSIZE)(%rsp)+#define w_3 (7*NUMSIZE)(%rsp)++#define tmpspace (8*NUMSIZE)(%rsp)+#define t0 (8*NUMSIZE)(%rsp)+#define t1 (9*NUMSIZE)(%rsp)+#define t2 (10*NUMSIZE)(%rsp)+#define t3 (11*NUMSIZE)(%rsp)+#define t4 (12*NUMSIZE)(%rsp)+#define t5 (13*NUMSIZE)(%rsp)++// Stable homes for the input result pointer, and other variables++#define res 14*NUMSIZE(%rsp)++#define i 14*NUMSIZE+8(%rsp)++#define bias 14*NUMSIZE+16(%rsp)++#define bf 14*NUMSIZE+24(%rsp)+#define ix 14*NUMSIZE+24(%rsp)++#define tab 15*NUMSIZE(%rsp)++// Total size to reserve on the stack++#define NSPACE 488++// Macro wrapping up the basic field multiplication, only trivially+// different from a pure function call to bignum_mul_p25519.++#define mul_p25519(P0,P1,P2) \+ xorl %esi, %esi ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rax, %r10 ; \+ addq %rax, %r9 ; \+ mulxq 0x10+P1, %rax, %r11 ; \+ adcq %rax, %r10 ; \+ mulxq 0x18+P1, %rax, %r12 ; \+ adcq %rax, %r11 ; \+ adcq %rsi, %r12 ; \+ xorl %esi, %esi ; \+ movq 0x8+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %r13 ; \+ adcxq %rax, %r12 ; \+ adoxq %rsi, %r13 ; \+ adcxq %rsi, %r13 ; \+ xorl %esi, %esi ; \+ movq 0x10+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x18+P1, %rax, %r14 ; \+ adcxq %rax, %r13 ; \+ adoxq %rsi, %r14 ; \+ adcxq %rsi, %r14 ; \+ xorl %esi, %esi ; \+ movq 0x18+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq 0x18+P1, %rax, %r15 ; \+ adcxq %rax, %r14 ; \+ adoxq %rsi, %r15 ; \+ adcxq %rsi, %r15 ; \+ movl $0x26, %edx ; \+ xorl %esi, %esi ; \+ mulxq %r12, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq %r13, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r14, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rsi, %r12 ; \+ adcxq %rsi, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ movl $0x13, %edx ; \+ incq %r12; \+ bts $63, %r11 ; \+ mulxq %r12, %rax, %rbx ; \+ addq %rax, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rsi, %r10 ; \+ adcq %rsi, %r11 ; \+ sbbq %rax, %rax ; \+ notq %rax; \+ andq %rdx, %rax ; \+ subq %rax, %r8 ; \+ sbbq %rsi, %r9 ; \+ sbbq %rsi, %r10 ; \+ sbbq %rsi, %r11 ; \+ btr $63, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ xorl %ecx, %ecx ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rax, %r10 ; \+ addq %rax, %r9 ; \+ mulxq 0x10+P1, %rax, %r11 ; \+ adcq %rax, %r10 ; \+ mulxq 0x18+P1, %rax, %r12 ; \+ adcq %rax, %r11 ; \+ adcq %rcx, %r12 ; \+ xorl %ecx, %ecx ; \+ movq 0x8+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %r13 ; \+ adcxq %rax, %r12 ; \+ adoxq %rcx, %r13 ; \+ adcxq %rcx, %r13 ; \+ xorl %ecx, %ecx ; \+ movq 0x10+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x18+P1, %rax, %r14 ; \+ adcxq %rax, %r13 ; \+ adoxq %rcx, %r14 ; \+ adcxq %rcx, %r14 ; \+ xorl %ecx, %ecx ; \+ movq 0x18+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq 0x18+P1, %rax, %r15 ; \+ adcxq %rax, %r14 ; \+ adoxq %rcx, %r15 ; \+ adcxq %rcx, %r15 ; \+ movl $0x26, %edx ; \+ xorl %ecx, %ecx ; \+ mulxq %r12, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq %r13, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r14, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rcx, %r12 ; \+ adcxq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ebx, %ebx ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movl $38, %ecx ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %rax ; \+ sbbq 24+P2, %rax ; \+ cmovncq %rbx, %rcx ; \+ subq %rcx, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %rax ; \+ movq %r8, P0 ; \+ movq %r9, 8+P0 ; \+ movq %r10, 16+P0 ; \+ movq %rax, 24+P0++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq P2, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq 0x8+P2, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq 0x10+P2, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq 0x18+P2, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++#define double_twice4(P0,P1) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq %r8, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq %r9, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq %r10, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq %r11, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++S2N_BN_SYMBOL(curve25519_x25519base):+S2N_BN_SYMBOL(curve25519_x25519base_byte):+ CFI_START+ _CET_ENDBR++// In this case the Windows form literally makes a subroutine call.+// This avoids hassle arising from keeping code and data together.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ CFI_CALL(Lcurve25519_x25519base_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519base)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lcurve25519_x25519base_standard)++Lcurve25519_x25519base_standard:+ CFI_START+#endif++// Save registers, make room for temps, preserve input arguments.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(NSPACE)++// Move the output pointer to a stable place++ movq %rdi, res++// Copy the input scalar to its local variable while mangling it.+// In principle the mangling is into 01xxx...xxx000, but actually+// we only clear the top two bits so 00xxx...xxxxxx. The additional+// 2^254 * G is taken care of by the starting value for the addition+// chain below, while we never look at the three low bits at all.++ movq (%rsi), %rax+ movq %rax, (%rsp)+ movq 8(%rsi), %rax+ movq %rax, 8(%rsp)+ movq 16(%rsi), %rax+ movq %rax, 16(%rsp)+ movq $0x3fffffffffffffff, %rax+ andq 24(%rsi), %rax+ movq %rax, 24(%rsp)++// The main part of the computation is on the edwards25519 curve in+// extended-projective coordinates (X,Y,Z,T), representing a point+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// Only at the very end do we translate back to curve25519. So G+// below means the generator within edwards25519 corresponding to+// (9,...) for curve25519, via the standard isomorphism.+//+// Initialize accumulator "acc" to either (2^254 + 8) * G or just 2^254 * G+// depending on bit 3 of the scalar, the only nonzero bit of the bottom 4.+// Thus, we have effectively dealt with bits 0, 1, 2, 3, 254 and 255.++ movq (%rsp), %rax+ andq $8, %rax++ leaq S2N_BN_SYMBOL(curve25519_x25519base_constant)(%rip), %r10+ leaq 8*12(%r10), %r11++ movq (%r10), %rax+ movq (%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*16(%rsp)++ movq 8*1(%r10), %rax+ movq 8*1(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*17(%rsp)++ movq 8*2(%r10), %rax+ movq 8*2(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*18(%rsp)++ movq 8*3(%r10), %rax+ movq 8*3(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*19(%rsp)++ movq 8*4(%r10), %rax+ movq 8*4(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*20(%rsp)++ movq 8*5(%r10), %rax+ movq 8*5(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*21(%rsp)++ movq 8*6(%r10), %rax+ movq 8*6(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*22(%rsp)++ movq 8*7(%r10), %rax+ movq 8*7(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*23(%rsp)++ movl $1, %eax+ movq %rax, 8*24(%rsp)+ movl $0, %eax+ movq %rax, 8*25(%rsp)+ movq %rax, 8*26(%rsp)+ movq %rax, 8*27(%rsp)++ movq 8*8(%r10), %rax+ movq 8*8(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*28(%rsp)++ movq 8*9(%r10), %rax+ movq 8*9(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*29(%rsp)++ movq 8*10(%r10), %rax+ movq 8*10(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*30(%rsp)++ movq 8*11(%r10), %rax+ movq 8*11(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*31(%rsp)++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 4 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * G at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * G = (16 * (h + 1) - (16 - l)) * G is used+// when l >= 9. Note that we can't have any bias left over at the+// end because of the clearing of bit 255 of the scalar, meaning the+// l >= 9 case cannot arise on the last iteration.++ movq $4, i+ leaq 8*24(%r10), %rax+ movq %rax, tab+ movq $0, bias++// Start of the main loop, repeated 63 times for i = 4, 8, ..., 252++Lcurve25519_x25519base_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ movq i, %rax+ movq %rax, %rcx+ shrq $6, %rax+ movq (%rsp,%rax,8), %rax // Exploiting scalar = sp exactly+ shrq %cl, %rax+ andq $15, %rax+ addq bias, %rax+ movq %rax, bf++ cmpq $9, bf+ sbbq %rax, %rax+ incq %rax+ movq %rax, bias++ movq $16, %rdi+ subq bf, %rdi+ cmpq $0, bias+ cmovzq bf, %rdi+ movq %rdi, ix++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ movl $1, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ movl $1, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ movq tab, %rbp++ cmpq $1, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $2, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $3, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $4, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $5, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $6, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $7, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $8, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15++ addq $96, %rbp+ movq %rbp, tab++// We now have the triple from the table in registers as follows+//+// [%rdx;%rcx;%rbx;%rax] = y - x+// [%r11;%r10;%r9;%r8] = x + y+// [%r15;%r14;%r13;%r12] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmpq $0, bias++ movq %rax, %rsi+ cmovnzq %r8, %rsi+ cmovnzq %rax, %r8+ movq %rsi, 32(%rsp)+ movq %r8, 64(%rsp)++ movq %rbx, %rsi+ cmovnzq %r9, %rsi+ cmovnzq %rbx, %r9+ movq %rsi, 40(%rsp)+ movq %r9, 72(%rsp)++ movq %rcx, %rsi+ cmovnzq %r10, %rsi+ cmovnzq %rcx, %r10+ movq %rsi, 48(%rsp)+ movq %r10, 80(%rsp)++ movq %rdx, %rsi+ cmovnzq %r11, %rsi+ cmovnzq %rdx, %r11+ movq %rsi, 56(%rsp)+ movq %r11, 88(%rsp)++ movq $-19, %rax+ movq $-1, %rbx+ movq $-1, %rcx+ movq $0x7fffffffffffffff, %rdx+ subq %r12, %rax+ sbbq %r13, %rbx+ sbbq %r14, %rcx+ sbbq %r15, %rdx++ movq ix, %r8+ movq bias, %r9+ testq %r8, %r8+ cmovzq %r8, %r9+ testq %r9, %r9++ cmovzq %r12, %rax+ cmovzq %r13, %rbx+ cmovzq %r14, %rcx+ cmovzq %r15, %rdx+ movq %rax, 96(%rsp)+ movq %rbx, 104(%rsp)+ movq %rcx, 112(%rsp)+ movq %rdx, 120(%rsp)++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ addq $4, i+ cmpq $256, i+ jc Lcurve25519_x25519base_scalarloop++// Now we need to translate from Edwards curve edwards25519 back+// to the Montgomery form curve25519. The mapping in the affine+// representations is+//+// (x,y) |-> ((1 + y) / (1 - y), c * (1 + y) / ((1 - y) * x))+//+// For x25519, we only need the x coordinate, and we compute this as+//+// (1 + y) / (1 - y) = (x + x * y) / (x - x * y)+// = (X/Z + T/Z) / (X/Z - T/Z)+// = (X + T) / (X - T)+// = (X + T) * inverse(X - T)+//+// We could equally well use (Z + Y) / (Z - Y), but the above has the+// same cost, and it more explicitly forces zero output whenever X = 0,+// regardless of how the modular inverse behaves on zero inputs. In+// the present setting (base point 9, mangled scalar) that doesn't+// really matter anyway since X = 0 never arises, but it seems a+// little bit tidier. Note that both Edwards point (0,1) which maps to+// the Montgomery point at infinity, and Edwards (0,-1) which maps to+// Montgomery (0,0) [this is the 2-torsion point] are both by definition+// mapped to 0 by the X coordinate mapping used to define curve25519.+//+// First the addition and subtraction:++ add_twice4(t1,x_3,w_3)+ sub_twice4(t2,x_3,w_3)++// Prepare to call the modular inverse function to get t0 = 1/t2+// Note that this works for the weakly normalized z_3 equally well.+// The non-coprime case z_3 == 0 (mod p_25519) cannot arise anyway.++ leaq 256(%rsp), %rdi+ leaq 320(%rsp), %rsi++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "x86/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 208 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, t0, t1, t2.++ movq %rdi, 0xc0(%rsp)+ xorl %eax, %eax+ leaq -0x13(%rax), %rcx+ notq %rax+ movq %rcx, (%rsp)+ movq %rax, 0x8(%rsp)+ movq %rax, 0x10(%rsp)+ btr $0x3f, %rax+ movq %rax, 0x18(%rsp)+ movq (%rsi), %rdx+ movq 0x8(%rsi), %rcx+ movq 0x10(%rsi), %r8+ movq 0x18(%rsi), %r9+ movl $0x1, %eax+ xorl %r10d, %r10d+ bts $0x3f, %r9+ adcq %r10, %rax+ imulq $0x13, %rax, %rax+ addq %rax, %rdx+ adcq %r10, %rcx+ adcq %r10, %r8+ adcq %r10, %r9+ movl $0x13, %eax+ cmovbq %r10, %rax+ subq %rax, %rdx+ sbbq %r10, %rcx+ sbbq %r10, %r8+ sbbq %r10, %r9+ btr $0x3f, %r9+ movq %rdx, 0x20(%rsp)+ movq %rcx, 0x28(%rsp)+ movq %r8, 0x30(%rsp)+ movq %r9, 0x38(%rsp)+ xorl %eax, %eax+ movq %rax, 0x40(%rsp)+ movq %rax, 0x48(%rsp)+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movabsq $0xa0f99e2375022099, %rax+ movq %rax, 0x60(%rsp)+ movabsq $0xa8c68f3f1d132595, %rax+ movq %rax, 0x68(%rsp)+ movabsq $0x6c6c893805ac5242, %rax+ movq %rax, 0x70(%rsp)+ movabsq $0x276508b241770615, %rax+ movq %rax, 0x78(%rsp)+ movq $0xa, 0x90(%rsp)+ movq $0x1, 0x98(%rsp)+ jmp Lcurve25519_x25519base_midloop+Lcurve25519_x25519base_inverseloop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0x80(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0x88(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x20(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x20(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x20(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x28(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq %rax, %rbp+ sarq $0x3f, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ xorq %r13, %rax+ movq %rax, %rsi+ sarq $0x3f, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x30(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x38(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x88(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x40(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x40(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x60(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x60(%rsp)+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x48(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x48(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x68(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x68(%rsp)+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x70(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x70(%rsp)+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq %rdx, %rbx+ shldq $0x1, %rcx, %rdx+ sarq $0x3f, %rbx+ addq %rbx, %rdx+ movl $0x13, %eax+ imulq %rdx+ movq 0x40(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x40(%rsp)+ movq 0x48(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x48(%rsp)+ movq 0x50(%rsp), %r8+ adcq %rbx, %r8+ movq %r8, 0x50(%rsp)+ adcq %rbx, %rcx+ shlq $0x3f, %rax+ addq %rax, %rcx+ movq 0x58(%rsp), %rax+ movq %rcx, 0x58(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rdx, %rcx+ shldq $0x1, %rsi, %rdx+ sarq $0x3f, %rcx+ movl $0x13, %eax+ addq %rcx, %rdx+ imulq %rdx+ movq 0x60(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x60(%rsp)+ movq 0x68(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x68(%rsp)+ movq 0x70(%rsp), %r8+ adcq %rcx, %r8+ movq %r8, 0x70(%rsp)+ adcq %rcx, %rsi+ shlq $0x3f, %rax+ addq %rax, %rsi+ movq %rsi, 0x78(%rsp)+Lcurve25519_x25519base_midloop:+ movq 0x98(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x20(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rdi, 0xb0(%rsp)+ movq %rcx, 0xb8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x20(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xa0(%rsp), %rax+ imulq %r8, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xa8(%rsp), %r8+ imulq 0xb8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xa0(%rsp), %rax+ imulq %r10, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xa8(%rsp), %r10+ imulq 0xb8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0x98(%rsp)+ decq 0x90(%rsp)+ jne Lcurve25519_x25519base_inverseloop+ movq (%rsp), %rax+ movq 0x20(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r9, %rax+ shldq $0x1, %r15, %rax+ sarq $0x3f, %r9+ movl $0x13, %ebx+ leaq 0x1(%rax,%r9,1), %rax+ imulq %rbx+ xorl %ebp, %ebp+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r9, %r14+ adcq %r9, %r15+ shlq $0x3f, %rax+ addq %rax, %r15+ cmovns %rbp, %rbx+ subq %rbx, %r12+ sbbq %rbp, %r13+ sbbq %rbp, %r14+ sbbq %rbp, %r15+ btr $0x3f, %r15+ movq 0xc0(%rsp), %rdi+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)++// The final result is (X + T) / (X - T)+// This is the only operation in the whole computation that+// fully reduces modulo p_25519 since now we want the canonical+// answer as output.++ movq res, %rbp+ mul_p25519(resx,t1,t0)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lcurve25519_x25519base_standard)+#else+S2N_BN_SIZE_DIRECTIVE(curve25519_x25519base)+#endif++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(curve25519_x25519base_constant), %object+.size S2N_BN_SYMBOL(curve25519_x25519base_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(curve25519_x25519base_constant):++// 2^254 * G and (2^254 + 8) * G in extended-projective coordinates+// but with z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x251037f7cf4e861d+ .quad 0x10ede0fb19fb128f+ .quad 0x96c033b175f5e2c8+ .quad 0x055f070d6c15fb0d++ .quad 0x7c52af2c97473e69+ .quad 0x022f82391bad8378+ .quad 0x9991e1b02adb476f+ .quad 0x511144a03a99b855++ .quad 0x5fafc3b88ff2e4ae+ .quad 0x855e4ff0de1230ff+ .quad 0x72e302a348492870+ .quad 0x1253c19e53dbe1bc+++ .quad 0x331d086e0d9abcaa+ .quad 0x1e23c96d311a10c9+ .quad 0x96d0f95e58c13478+ .quad 0x2f72f7384fcfcc59++ .quad 0x39a6cd1cfd7d87c9+ .quad 0x9867a0abd8ae153a+ .quad 0xa49d2a5f35986745+ .quad 0x57012940cdfe82e1++ .quad 0x5046a6532ec5544a+ .quad 0x6d674004739ff6c9+ .quad 0x9bbaa44b234a70e3+ .quad 0x5e6d8901138cf386++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^4 * 1 * G++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * G++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * G++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * G++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * G++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * G++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * G++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * G++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * G++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * G++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * G++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * G++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * G++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * G++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * G++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * G++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * G++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * G++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * G++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * G++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * G++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * G++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * G++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * G++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * G++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * G++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * G++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * G++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * G++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * G++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * G++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * G++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * G++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * G++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * G++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * G++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * G++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * G++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * G++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * G++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * G++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * G++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * G++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * G++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * G++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * G++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * G++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * G++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * G++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * G++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * G++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * G++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * G++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * G++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * G++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * G++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * G++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * G++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * G++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * G++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * G++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * G++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * G++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * G++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * G++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * G++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * G++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * G++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * G++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * G++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * G++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * G++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * G++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * G++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * G++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * G++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * G++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * G++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * G++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * G++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * G++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * G++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * G++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * G++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * G++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * G++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * G++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * G++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * G++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * G++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * G++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * G++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * G++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * G++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * G++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * G++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * G++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * G++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * G++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * G++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * G++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * G++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * G++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * G++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * G++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * G++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * G++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * G++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * G++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * G++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * G++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * G++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * G++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * G++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * G++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * G++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * G++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * G++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * G++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * G++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * G++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * G++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * G++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * G++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * G++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * G++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * G++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * G++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * G++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * G++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * G++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * G++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * G++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * G++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * G++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * G++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * G++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * G++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * G++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * G++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * G++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * G++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * G++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * G++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * G++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * G++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * G++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * G++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * G++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * G++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * G++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * G++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * G++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * G++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * G++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * G++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * G++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * G++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * G++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * G++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * G++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * G++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * G++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * G++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * G++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * G++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * G++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * G++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * G++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * G++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * G++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * G++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * G++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * G++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * G++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * G++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * G++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * G++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * G++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * G++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * G++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * G++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * G++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * G++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * G++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * G++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * G++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * G++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * G++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * G++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * G++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * G++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * G++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * G++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * G++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * G++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * G++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * G++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * G++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * G++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * G++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * G++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * G++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * G++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * G++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * G++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * G++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * G++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * G++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * G++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * G++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * G++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * G++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * G++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * G++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * G++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * G++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * G++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * G++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * G++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * G++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * G++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * G++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * G++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * G++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * G++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * G++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * G++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * G++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * G++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * G++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * G++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * G++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * G++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * G++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * G++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * G++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * G++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * G++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * G++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * G++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * G++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * G++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * G++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * G++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * G++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * G++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * G++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * G++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * G++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * G++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * G++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * G++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * G++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * G++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * G++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * G++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * G++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * G++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * G++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * G++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * G++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * G++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * G++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * G++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * G++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * G++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * G++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * G++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * G++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * G++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * G++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * G++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * G++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * G++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * G++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * G++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * G++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * G++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * G++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * G++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * G++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * G++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * G++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * G++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * G++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * G++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * G++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * G++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * G++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * G++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * G++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * G++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * G++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * G++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * G++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * G++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * G++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * G++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * G++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * G++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * G++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * G++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * G++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * G++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * G++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * G++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * G++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * G++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * G++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * G++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * G++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * G++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * G++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * G++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * G++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * G++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * G++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * G++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * G++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * G++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * G++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * G++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * G++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * G++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * G++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * G++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * G++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * G++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * G++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * G++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * G++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * G++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * G++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * G++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * G++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * G++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * G++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * G++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * G++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * G++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * G++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * G++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * G++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * G++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * G++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * G++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * G++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * G++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * G++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * G++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * G++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * G++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * G++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * G++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * G++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * G++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * G++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * G++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * G++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * G++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * G++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * G++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * G++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * G++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * G++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * G++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * G++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * G++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * G++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * G++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * G++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * G++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * G++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * G++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * G++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * G++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * G++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * G++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * G++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * G++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * G++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * G++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * G++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * G++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * G++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * G++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * G++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * G++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * G++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * G++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * G++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * G++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * G++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * G++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * G++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * G++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * G++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * G++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * G++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * G++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * G++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * G++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * G++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * G++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * G++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * G++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * G++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * G++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * G++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * G++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * G++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * G++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * G++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * G++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * G++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * G++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * G++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * G++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * G++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * G++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * G++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * G++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * G++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * G++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * G++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * G++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * G++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * G++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * G++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * G++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * G++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * G++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * G++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * G++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * G++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * G++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * G++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * G++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * G++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * G++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * G++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * G++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * G++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * G++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * G++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * G++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * G++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * G++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * G++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * G++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * G++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * G++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * G++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * G++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * G++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * G++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * G++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * G++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * G++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * G++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * G++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * G++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * G++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * G++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * G++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * G++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * G++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * G++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * G++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * G++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * G++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * G++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * G++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * G++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * G++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * G++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * G++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * G++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * G++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * G++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * G++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * G++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * G++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * G++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * G++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * G++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * G++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * G++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * G++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * G++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * G++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * G++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * G++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * G++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * G++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f++ // 2^252 * 1 * G++ .quad 0xb1507ca1ab1c6eb9+ .quad 0xbd448f3e16b687b3+ .quad 0x3455fb7f2c7a91ab+ .quad 0x7579229e2f2adec1+ .quad 0x6ab5dcb85b1c16b7+ .quad 0x94c0fce83c7b27a5+ .quad 0xa4b11c1a735517be+ .quad 0x499238d0ba0eafaa+ .quad 0xecf46e527aba8b57+ .quad 0x15a08c478bd1647b+ .quad 0x7af1c6a65f706fef+ .quad 0x6345fa78f03a30d5++ // 2^252 * 2 * G++ .quad 0xdf02f95f1015e7a1+ .quad 0x790ec41da9b40263+ .quad 0x4d3a0ea133ea1107+ .quad 0x54f70be7e33af8c9+ .quad 0x93d3cbe9bdd8f0a4+ .quad 0xdb152c1bfd177302+ .quad 0x7dbddc6d7f17a875+ .quad 0x3e1a71cc8f426efe+ .quad 0xc83ca3e390babd62+ .quad 0x80ede3670291c833+ .quad 0xc88038ccd37900c4+ .quad 0x2c5fc0231ec31fa1++ // 2^252 * 3 * G++ .quad 0xfeba911717038b4f+ .quad 0xe5123721c9deef81+ .quad 0x1c97e4e75d0d8834+ .quad 0x68afae7a23dc3bc6+ .quad 0xc422e4d102456e65+ .quad 0x87414ac1cad47b91+ .quad 0x1592e2bba2b6ffdd+ .quad 0x75d9d2bff5c2100f+ .quad 0x5bd9b4763626e81c+ .quad 0x89966936bca02edd+ .quad 0x0a41193d61f077b3+ .quad 0x3097a24200ce5471++ // 2^252 * 4 * G++ .quad 0x57427734c7f8b84c+ .quad 0xf141a13e01b270e9+ .quad 0x02d1adfeb4e564a6+ .quad 0x4bb23d92ce83bd48+ .quad 0xa162e7246695c486+ .quad 0x131d633435a89607+ .quad 0x30521561a0d12a37+ .quad 0x56704bada6afb363+ .quad 0xaf6c4aa752f912b9+ .quad 0x5e665f6cd86770c8+ .quad 0x4c35ac83a3c8cd58+ .quad 0x2b7a29c010a58a7e++ // 2^252 * 5 * G++ .quad 0xc4007f77d0c1cec3+ .quad 0x8d1020b6bac492f8+ .quad 0x32ec29d57e69daaf+ .quad 0x599408759d95fce0+ .quad 0x33810a23bf00086e+ .quad 0xafce925ee736ff7c+ .quad 0x3d60e670e24922d4+ .quad 0x11ce9e714f96061b+ .quad 0x219ef713d815bac1+ .quad 0xf141465d485be25c+ .quad 0x6d5447cc4e513c51+ .quad 0x174926be5ef44393++ // 2^252 * 6 * G++ .quad 0xb5deb2f9fc5bd5bb+ .quad 0x92daa72ae1d810e1+ .quad 0xafc4cfdcb72a1c59+ .quad 0x497d78813fc22a24+ .quad 0x3ef5d41593ea022e+ .quad 0x5cbcc1a20ed0eed6+ .quad 0x8fd24ecf07382c8c+ .quad 0x6fa42ead06d8e1ad+ .quad 0xe276824a1f73371f+ .quad 0x7f7cf01c4f5b6736+ .quad 0x7e201fe304fa46e7+ .quad 0x785a36a357808c96++ // 2^252 * 7 * G++ .quad 0x825fbdfd63014d2b+ .quad 0xc852369c6ca7578b+ .quad 0x5b2fcd285c0b5df0+ .quad 0x12ab214c58048c8f+ .quad 0x070442985d517bc3+ .quad 0x6acd56c7ae653678+ .quad 0x00a27983985a7763+ .quad 0x5167effae512662b+ .quad 0xbd4ea9e10f53c4b6+ .quad 0x1673dc5f8ac91a14+ .quad 0xa8f81a4e2acc1aba+ .quad 0x33a92a7924332a25++ // 2^252 * 8 * G++ .quad 0x9dd1f49927996c02+ .quad 0x0cb3b058e04d1752+ .quad 0x1f7e88967fd02c3e+ .quad 0x2f964268cb8b3eb1+ .quad 0x7ba95ba0218f2ada+ .quad 0xcff42287330fb9ca+ .quad 0xdada496d56c6d907+ .quad 0x5380c296f4beee54+ .quad 0x9d4f270466898d0a+ .quad 0x3d0987990aff3f7a+ .quad 0xd09ef36267daba45+ .quad 0x7761455e7b1c669c
+ cbits/s2n/x86_att/curve25519_x25519base_alt.S view
@@ -0,0 +1,9965 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// The x25519 function for curve25519 on base element 9+// Input scalar[4]; output res[4]+//+// extern void curve25519_x25519base_alt+// (uint64_t res[static 4],const uint64_t scalar[static 4]);+//+// The function has a second prototype considering the arguments as arrays+// of bytes rather than 64-bit words. The underlying code is the same, since+// the x86 platform is little-endian.+//+// extern void curve25519_x25519base_byte_alt+// (uint8_t res[static 32],const uint8_t scalar[static 32]);+//+// Given a scalar n, returns the X coordinate of n * G where G = (9,...) is+// the standard generator. The scalar is first slightly modified/mangled+// as specified in the relevant RFC (https://www.rfc-editor.org/rfc/rfc7748).+//+// Standard x86-64 ABI: RDI = res, RSI = scalar+// Microsoft x64 ABI: RCX = res, RDX = scalar+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519base_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519base_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519base_alt)+ S2N_BN_SYM_VISIBILITY_DIRECTIVE(curve25519_x25519base_byte_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(curve25519_x25519base_byte_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(curve25519_x25519base_byte_alt)++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for result and temporaries on stack with some aliasing.+// The result "resx" assumes the "res" pointer has been preloaded into %rbp.++#define resx (0*NUMSIZE)(%rbp)++#define scalar (0*NUMSIZE)(%rsp)++#define tabent (1*NUMSIZE)(%rsp)+#define ymx_2 (1*NUMSIZE)(%rsp)+#define xpy_2 (2*NUMSIZE)(%rsp)+#define kxy_2 (3*NUMSIZE)(%rsp)++#define acc (4*NUMSIZE)(%rsp)+#define x_1 (4*NUMSIZE)(%rsp)+#define y_1 (5*NUMSIZE)(%rsp)+#define z_1 (6*NUMSIZE)(%rsp)+#define w_1 (7*NUMSIZE)(%rsp)+#define x_3 (4*NUMSIZE)(%rsp)+#define y_3 (5*NUMSIZE)(%rsp)+#define z_3 (6*NUMSIZE)(%rsp)+#define w_3 (7*NUMSIZE)(%rsp)++#define tmpspace (8*NUMSIZE)(%rsp)+#define t0 (8*NUMSIZE)(%rsp)+#define t1 (9*NUMSIZE)(%rsp)+#define t2 (10*NUMSIZE)(%rsp)+#define t3 (11*NUMSIZE)(%rsp)+#define t4 (12*NUMSIZE)(%rsp)+#define t5 (13*NUMSIZE)(%rsp)++// Stable homes for the input result pointer, and other variables++#define res 14*NUMSIZE(%rsp)++#define i 14*NUMSIZE+8(%rsp)++#define bias 14*NUMSIZE+16(%rsp)++#define bf 14*NUMSIZE+24(%rsp)+#define ix 14*NUMSIZE+24(%rsp)++#define tab 15*NUMSIZE(%rsp)++// Total size to reserve on the stack++#define NSPACE 488++// Macro wrapping up the basic field multiplication, only trivially+// different from a pure function call to bignum_mul_p25519_alt.++#define mul_p25519(P0,P1,P2) \+ movq P1, %rax ; \+ mulq P2; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x8+P1, %rax ; \+ mulq P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq 0x10+P1, %rax ; \+ mulq P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq %r13, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x18+P1, %rax ; \+ mulq P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %esi ; \+ movq %r12, %rax ; \+ mulq %rsi; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ leaq 0x1(%r12), %rax ; \+ movl $0x13, %esi ; \+ bts $63, %r11 ; \+ imulq %rsi, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ sbbq %rax, %rax ; \+ notq %rax; \+ andq %rsi, %rax ; \+ subq %rax, %r8 ; \+ sbbq %rcx, %r9 ; \+ sbbq %rcx, %r10 ; \+ sbbq %rcx, %r11 ; \+ btr $63, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ movq P1, %rax ; \+ mulq P2; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x8+P1, %rax ; \+ mulq P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq 0x10+P1, %rax ; \+ mulq P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq %r13, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x18+P1, %rax ; \+ mulq P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %ebx ; \+ movq %r12, %rax ; \+ mulq %rbx; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ebx, %ebx ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movl $38, %ecx ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %rax ; \+ sbbq 24+P2, %rax ; \+ cmovncq %rbx, %rcx ; \+ subq %rcx, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %rax ; \+ movq %r8, P0 ; \+ movq %r9, 8+P0 ; \+ movq %r10, 16+P0 ; \+ movq %rax, 24+P0++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq P2, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq 0x8+P2, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq 0x10+P2, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq 0x18+P2, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++#define double_twice4(P0,P1) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq %r8, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq %r9, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq %r10, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq %r11, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++S2N_BN_SYMBOL(curve25519_x25519base_alt):+S2N_BN_SYMBOL(curve25519_x25519base_byte_alt):+ CFI_START+ _CET_ENDBR++// In this case the Windows form literally makes a subroutine call.+// This avoids hassle arising from keeping code and data together.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ CFI_CALL(Lcurve25519_x25519base_alt_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(curve25519_x25519base_alt)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lcurve25519_x25519base_alt_standard)++Lcurve25519_x25519base_alt_standard:+ CFI_START+#endif++// Save registers, make room for temps, preserve input arguments.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(NSPACE)++// Move the output pointer to a stable place++ movq %rdi, res++// Copy the input scalar to its local variable while mangling it.+// In principle the mangling is into 01xxx...xxx000, but actually+// we only clear the top two bits so 00xxx...xxxxxx. The additional+// 2^254 * G is taken care of by the starting value for the addition+// chain below, while we never look at the three low bits at all.++ movq (%rsi), %rax+ movq %rax, (%rsp)+ movq 8(%rsi), %rax+ movq %rax, 8(%rsp)+ movq 16(%rsi), %rax+ movq %rax, 16(%rsp)+ movq $0x3fffffffffffffff, %rax+ andq 24(%rsi), %rax+ movq %rax, 24(%rsp)++// The main part of the computation is on the edwards25519 curve in+// extended-projective coordinates (X,Y,Z,T), representing a point+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// Only at the very end do we translate back to curve25519. So G+// below means the generator within edwards25519 corresponding to+// (9,...) for curve25519, via the standard isomorphism.+//+// Initialize accumulator "acc" to either (2^254 + 8) * G or just 2^254 * G+// depending on bit 3 of the scalar, the only nonzero bit of the bottom 4.+// Thus, we have effectively dealt with bits 0, 1, 2, 3, 254 and 255.++ movq (%rsp), %rax+ andq $8, %rax++ leaq S2N_BN_SYMBOL(curve25519_x25519base_alt_constant)(%rip), %r10+ leaq 8*12(%r10), %r11++ movq (%r10), %rax+ movq (%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*16(%rsp)++ movq 8*1(%r10), %rax+ movq 8*1(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*17(%rsp)++ movq 8*2(%r10), %rax+ movq 8*2(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*18(%rsp)++ movq 8*3(%r10), %rax+ movq 8*3(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*19(%rsp)++ movq 8*4(%r10), %rax+ movq 8*4(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*20(%rsp)++ movq 8*5(%r10), %rax+ movq 8*5(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*21(%rsp)++ movq 8*6(%r10), %rax+ movq 8*6(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*22(%rsp)++ movq 8*7(%r10), %rax+ movq 8*7(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*23(%rsp)++ movl $1, %eax+ movq %rax, 8*24(%rsp)+ movl $0, %eax+ movq %rax, 8*25(%rsp)+ movq %rax, 8*26(%rsp)+ movq %rax, 8*27(%rsp)++ movq 8*8(%r10), %rax+ movq 8*8(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*28(%rsp)++ movq 8*9(%r10), %rax+ movq 8*9(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*29(%rsp)++ movq 8*10(%r10), %rax+ movq 8*10(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*30(%rsp)++ movq 8*11(%r10), %rax+ movq 8*11(%r11), %rcx+ cmovnzq %rcx, %rax+ movq %rax, 8*31(%rsp)++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 4 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * G at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * G = (16 * (h + 1) - (16 - l)) * G is used+// when l >= 9. Note that we can't have any bias left over at the+// end because of the clearing of bit 255 of the scalar, meaning the+// l >= 9 case cannot arise on the last iteration.++ movq $4, i+ leaq 8*24(%r10), %rax+ movq %rax, tab+ movq $0, bias++// Start of the main loop, repeated 63 times for i = 4, 8, ..., 252++Lcurve25519_x25519base_alt_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ movq i, %rax+ movq %rax, %rcx+ shrq $6, %rax+ movq (%rsp,%rax,8), %rax // Exploiting scalar = sp exactly+ shrq %cl, %rax+ andq $15, %rax+ addq bias, %rax+ movq %rax, bf++ cmpq $9, bf+ sbbq %rax, %rax+ incq %rax+ movq %rax, bias++ movq $16, %rdi+ subq bf, %rdi+ cmpq $0, bias+ cmovzq bf, %rdi+ movq %rdi, ix++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ movl $1, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ movl $1, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ movq tab, %rbp++ cmpq $1, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $2, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $3, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $4, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $5, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $6, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $7, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $8, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15++ addq $96, %rbp+ movq %rbp, tab++// We now have the triple from the table in registers as follows+//+// [%rdx;%rcx;%rbx;%rax] = y - x+// [%r11;%r10;%r9;%r8] = x + y+// [%r15;%r14;%r13;%r12] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmpq $0, bias++ movq %rax, %rsi+ cmovnzq %r8, %rsi+ cmovnzq %rax, %r8+ movq %rsi, 32(%rsp)+ movq %r8, 64(%rsp)++ movq %rbx, %rsi+ cmovnzq %r9, %rsi+ cmovnzq %rbx, %r9+ movq %rsi, 40(%rsp)+ movq %r9, 72(%rsp)++ movq %rcx, %rsi+ cmovnzq %r10, %rsi+ cmovnzq %rcx, %r10+ movq %rsi, 48(%rsp)+ movq %r10, 80(%rsp)++ movq %rdx, %rsi+ cmovnzq %r11, %rsi+ cmovnzq %rdx, %r11+ movq %rsi, 56(%rsp)+ movq %r11, 88(%rsp)++ movq $-19, %rax+ movq $-1, %rbx+ movq $-1, %rcx+ movq $0x7fffffffffffffff, %rdx+ subq %r12, %rax+ sbbq %r13, %rbx+ sbbq %r14, %rcx+ sbbq %r15, %rdx++ movq ix, %r8+ movq bias, %r9+ testq %r8, %r8+ cmovzq %r8, %r9+ testq %r9, %r9++ cmovzq %r12, %rax+ cmovzq %r13, %rbx+ cmovzq %r14, %rcx+ cmovzq %r15, %rdx+ movq %rax, 96(%rsp)+ movq %rbx, 104(%rsp)+ movq %rcx, 112(%rsp)+ movq %rdx, 120(%rsp)++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd_alt(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ addq $4, i+ cmpq $256, i+ jc Lcurve25519_x25519base_alt_scalarloop++// Now we need to translate from Edwards curve edwards25519 back+// to the Montgomery form curve25519. The mapping in the affine+// representations is+//+// (x,y) |-> ((1 + y) / (1 - y), c * (1 + y) / ((1 - y) * x))+//+// For x25519, we only need the x coordinate, and we compute this as+//+// (1 + y) / (1 - y) = (x + x * y) / (x - x * y)+// = (X/Z + T/Z) / (X/Z - T/Z)+// = (X + T) / (X - T)+// = (X + T) * inverse(X - T)+//+// We could equally well use (Z + Y) / (Z - Y), but the above has the+// same cost, and it more explicitly forces zero output whenever X = 0,+// regardless of how the modular inverse behaves on zero inputs. In+// the present setting (base point 9, mangled scalar) that doesn't+// really matter anyway since X = 0 never arises, but it seems a+// little bit tidier. Note that both Edwards point (0,1) which maps to+// the Montgomery point at infinity, and Edwards (0,-1) which maps to+// Montgomery (0,0) [this is the 2-torsion point] are both by definition+// mapped to 0 by the X coordinate mapping used to define curve25519.+//+// First the addition and subtraction:++ add_twice4(t1,x_3,w_3)+ sub_twice4(t2,x_3,w_3)++// Prepare to call the modular inverse function to get t0 = 1/t2+// Note that this works for the weakly normalized z_3 equally well.+// The non-coprime case z_3 == 0 (mod p_25519) cannot arise anyway.++ leaq 256(%rsp), %rdi+ leaq 320(%rsp), %rsi++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "x86/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 208 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, t0, t1, t2.++ movq %rdi, 0xc0(%rsp)+ xorl %eax, %eax+ leaq -0x13(%rax), %rcx+ notq %rax+ movq %rcx, (%rsp)+ movq %rax, 0x8(%rsp)+ movq %rax, 0x10(%rsp)+ btr $0x3f, %rax+ movq %rax, 0x18(%rsp)+ movq (%rsi), %rdx+ movq 0x8(%rsi), %rcx+ movq 0x10(%rsi), %r8+ movq 0x18(%rsi), %r9+ movl $0x1, %eax+ xorl %r10d, %r10d+ bts $0x3f, %r9+ adcq %r10, %rax+ imulq $0x13, %rax, %rax+ addq %rax, %rdx+ adcq %r10, %rcx+ adcq %r10, %r8+ adcq %r10, %r9+ movl $0x13, %eax+ cmovbq %r10, %rax+ subq %rax, %rdx+ sbbq %r10, %rcx+ sbbq %r10, %r8+ sbbq %r10, %r9+ btr $0x3f, %r9+ movq %rdx, 0x20(%rsp)+ movq %rcx, 0x28(%rsp)+ movq %r8, 0x30(%rsp)+ movq %r9, 0x38(%rsp)+ xorl %eax, %eax+ movq %rax, 0x40(%rsp)+ movq %rax, 0x48(%rsp)+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movabsq $0xa0f99e2375022099, %rax+ movq %rax, 0x60(%rsp)+ movabsq $0xa8c68f3f1d132595, %rax+ movq %rax, 0x68(%rsp)+ movabsq $0x6c6c893805ac5242, %rax+ movq %rax, 0x70(%rsp)+ movabsq $0x276508b241770615, %rax+ movq %rax, 0x78(%rsp)+ movq $0xa, 0x90(%rsp)+ movq $0x1, 0x98(%rsp)+ jmp Lcurve25519_x25519base_alt_midloop+Lcurve25519_x25519base_alt_inverseloop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0x80(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0x88(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x20(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x20(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x20(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x28(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq %rax, %rbp+ sarq $0x3f, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ xorq %r13, %rax+ movq %rax, %rsi+ sarq $0x3f, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x30(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x38(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x88(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x40(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x40(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x60(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x60(%rsp)+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x48(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x48(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x68(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x68(%rsp)+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x70(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x70(%rsp)+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq %rdx, %rbx+ shldq $0x1, %rcx, %rdx+ sarq $0x3f, %rbx+ addq %rbx, %rdx+ movl $0x13, %eax+ imulq %rdx+ movq 0x40(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x40(%rsp)+ movq 0x48(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x48(%rsp)+ movq 0x50(%rsp), %r8+ adcq %rbx, %r8+ movq %r8, 0x50(%rsp)+ adcq %rbx, %rcx+ shlq $0x3f, %rax+ addq %rax, %rcx+ movq 0x58(%rsp), %rax+ movq %rcx, 0x58(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rdx, %rcx+ shldq $0x1, %rsi, %rdx+ sarq $0x3f, %rcx+ movl $0x13, %eax+ addq %rcx, %rdx+ imulq %rdx+ movq 0x60(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x60(%rsp)+ movq 0x68(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x68(%rsp)+ movq 0x70(%rsp), %r8+ adcq %rcx, %r8+ movq %r8, 0x70(%rsp)+ adcq %rcx, %rsi+ shlq $0x3f, %rax+ addq %rax, %rsi+ movq %rsi, 0x78(%rsp)+Lcurve25519_x25519base_alt_midloop:+ movq 0x98(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x20(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rdi, 0xb0(%rsp)+ movq %rcx, 0xb8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x20(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xa0(%rsp), %rax+ imulq %r8, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xa8(%rsp), %r8+ imulq 0xb8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xa0(%rsp), %rax+ imulq %r10, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xa8(%rsp), %r10+ imulq 0xb8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0x98(%rsp)+ decq 0x90(%rsp)+ jne Lcurve25519_x25519base_alt_inverseloop+ movq (%rsp), %rax+ movq 0x20(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r9, %rax+ shldq $0x1, %r15, %rax+ sarq $0x3f, %r9+ movl $0x13, %ebx+ leaq 0x1(%rax,%r9,1), %rax+ imulq %rbx+ xorl %ebp, %ebp+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r9, %r14+ adcq %r9, %r15+ shlq $0x3f, %rax+ addq %rax, %r15+ cmovns %rbp, %rbx+ subq %rbx, %r12+ sbbq %rbp, %r13+ sbbq %rbp, %r14+ sbbq %rbp, %r15+ btr $0x3f, %r15+ movq 0xc0(%rsp), %rdi+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)++// The final result is (X + T) / (X - T)+// This is the only operation in the whole computation that+// fully reduces modulo p_25519 since now we want the canonical+// answer as output.++ movq res, %rbp+ mul_p25519(resx,t1,t0)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lcurve25519_x25519base_alt_standard)+#else+S2N_BN_SIZE_DIRECTIVE(curve25519_x25519base_alt)+#endif++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(curve25519_x25519base_alt_constant), %object+.size S2N_BN_SYMBOL(curve25519_x25519base_alt_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(curve25519_x25519base_alt_constant):++// 2^254 * G and (2^254 + 8) * G in extended-projective coordinates+// but with z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x251037f7cf4e861d+ .quad 0x10ede0fb19fb128f+ .quad 0x96c033b175f5e2c8+ .quad 0x055f070d6c15fb0d++ .quad 0x7c52af2c97473e69+ .quad 0x022f82391bad8378+ .quad 0x9991e1b02adb476f+ .quad 0x511144a03a99b855++ .quad 0x5fafc3b88ff2e4ae+ .quad 0x855e4ff0de1230ff+ .quad 0x72e302a348492870+ .quad 0x1253c19e53dbe1bc++ .quad 0x331d086e0d9abcaa+ .quad 0x1e23c96d311a10c9+ .quad 0x96d0f95e58c13478+ .quad 0x2f72f7384fcfcc59++ .quad 0x39a6cd1cfd7d87c9+ .quad 0x9867a0abd8ae153a+ .quad 0xa49d2a5f35986745+ .quad 0x57012940cdfe82e1++ .quad 0x5046a6532ec5544a+ .quad 0x6d674004739ff6c9+ .quad 0x9bbaa44b234a70e3+ .quad 0x5e6d8901138cf386++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^4 * 1 * G++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * G++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * G++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * G++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * G++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * G++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * G++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * G++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * G++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * G++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * G++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * G++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * G++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * G++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * G++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * G++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * G++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * G++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * G++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * G++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * G++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * G++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * G++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * G++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * G++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * G++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * G++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * G++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * G++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * G++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * G++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * G++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * G++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * G++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * G++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * G++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * G++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * G++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * G++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * G++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * G++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * G++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * G++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * G++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * G++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * G++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * G++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * G++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * G++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * G++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * G++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * G++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * G++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * G++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * G++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * G++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * G++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * G++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * G++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * G++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * G++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * G++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * G++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * G++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * G++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * G++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * G++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * G++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * G++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * G++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * G++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * G++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * G++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * G++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * G++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * G++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * G++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * G++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * G++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * G++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * G++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * G++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * G++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * G++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * G++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * G++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * G++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * G++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * G++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * G++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * G++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * G++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * G++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * G++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * G++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * G++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * G++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * G++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * G++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * G++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * G++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * G++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * G++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * G++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * G++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * G++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * G++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * G++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * G++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * G++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * G++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * G++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * G++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * G++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * G++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * G++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * G++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * G++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * G++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * G++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * G++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * G++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * G++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * G++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * G++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * G++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * G++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * G++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * G++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * G++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * G++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * G++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * G++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * G++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * G++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * G++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * G++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * G++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * G++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * G++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * G++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * G++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * G++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * G++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * G++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * G++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * G++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * G++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * G++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * G++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * G++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * G++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * G++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * G++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * G++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * G++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * G++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * G++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * G++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * G++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * G++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * G++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * G++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * G++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * G++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * G++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * G++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * G++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * G++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * G++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * G++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * G++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * G++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * G++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * G++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * G++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * G++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * G++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * G++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * G++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * G++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * G++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * G++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * G++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * G++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * G++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * G++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * G++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * G++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * G++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * G++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * G++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * G++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * G++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * G++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * G++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * G++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * G++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * G++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * G++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * G++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * G++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * G++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * G++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * G++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * G++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * G++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * G++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * G++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * G++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * G++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * G++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * G++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * G++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * G++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * G++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * G++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * G++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * G++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * G++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * G++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * G++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * G++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * G++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * G++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * G++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * G++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * G++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * G++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * G++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * G++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * G++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * G++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * G++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * G++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * G++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * G++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * G++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * G++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * G++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * G++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * G++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * G++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * G++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * G++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * G++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * G++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * G++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * G++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * G++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * G++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * G++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * G++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * G++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * G++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * G++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * G++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * G++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * G++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * G++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * G++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * G++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * G++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * G++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * G++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * G++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * G++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * G++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * G++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * G++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * G++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * G++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * G++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * G++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * G++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * G++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * G++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * G++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * G++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * G++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * G++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * G++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * G++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * G++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * G++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * G++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * G++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * G++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * G++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * G++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * G++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * G++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * G++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * G++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * G++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * G++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * G++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * G++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * G++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * G++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * G++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * G++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * G++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * G++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * G++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * G++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * G++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * G++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * G++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * G++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * G++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * G++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * G++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * G++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * G++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * G++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * G++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * G++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * G++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * G++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * G++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * G++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * G++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * G++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * G++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * G++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * G++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * G++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * G++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * G++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * G++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * G++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * G++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * G++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * G++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * G++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * G++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * G++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * G++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * G++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * G++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * G++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * G++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * G++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * G++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * G++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * G++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * G++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * G++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * G++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * G++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * G++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * G++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * G++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * G++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * G++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * G++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * G++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * G++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * G++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * G++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * G++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * G++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * G++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * G++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * G++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * G++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * G++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * G++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * G++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * G++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * G++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * G++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * G++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * G++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * G++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * G++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * G++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * G++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * G++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * G++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * G++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * G++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * G++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * G++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * G++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * G++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * G++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * G++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * G++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * G++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * G++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * G++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * G++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * G++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * G++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * G++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * G++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * G++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * G++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * G++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * G++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * G++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * G++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * G++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * G++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * G++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * G++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * G++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * G++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * G++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * G++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * G++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * G++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * G++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * G++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * G++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * G++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * G++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * G++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * G++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * G++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * G++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * G++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * G++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * G++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * G++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * G++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * G++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * G++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * G++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * G++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * G++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * G++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * G++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * G++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * G++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * G++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * G++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * G++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * G++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * G++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * G++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * G++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * G++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * G++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * G++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * G++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * G++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * G++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * G++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * G++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * G++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * G++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * G++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * G++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * G++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * G++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * G++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * G++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * G++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * G++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * G++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * G++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * G++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * G++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * G++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * G++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * G++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * G++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * G++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * G++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * G++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * G++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * G++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * G++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * G++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * G++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * G++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * G++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * G++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * G++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * G++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * G++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * G++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * G++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * G++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * G++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * G++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * G++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * G++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * G++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * G++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * G++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * G++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * G++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f++ // 2^252 * 1 * G++ .quad 0xb1507ca1ab1c6eb9+ .quad 0xbd448f3e16b687b3+ .quad 0x3455fb7f2c7a91ab+ .quad 0x7579229e2f2adec1+ .quad 0x6ab5dcb85b1c16b7+ .quad 0x94c0fce83c7b27a5+ .quad 0xa4b11c1a735517be+ .quad 0x499238d0ba0eafaa+ .quad 0xecf46e527aba8b57+ .quad 0x15a08c478bd1647b+ .quad 0x7af1c6a65f706fef+ .quad 0x6345fa78f03a30d5++ // 2^252 * 2 * G++ .quad 0xdf02f95f1015e7a1+ .quad 0x790ec41da9b40263+ .quad 0x4d3a0ea133ea1107+ .quad 0x54f70be7e33af8c9+ .quad 0x93d3cbe9bdd8f0a4+ .quad 0xdb152c1bfd177302+ .quad 0x7dbddc6d7f17a875+ .quad 0x3e1a71cc8f426efe+ .quad 0xc83ca3e390babd62+ .quad 0x80ede3670291c833+ .quad 0xc88038ccd37900c4+ .quad 0x2c5fc0231ec31fa1++ // 2^252 * 3 * G++ .quad 0xfeba911717038b4f+ .quad 0xe5123721c9deef81+ .quad 0x1c97e4e75d0d8834+ .quad 0x68afae7a23dc3bc6+ .quad 0xc422e4d102456e65+ .quad 0x87414ac1cad47b91+ .quad 0x1592e2bba2b6ffdd+ .quad 0x75d9d2bff5c2100f+ .quad 0x5bd9b4763626e81c+ .quad 0x89966936bca02edd+ .quad 0x0a41193d61f077b3+ .quad 0x3097a24200ce5471++ // 2^252 * 4 * G++ .quad 0x57427734c7f8b84c+ .quad 0xf141a13e01b270e9+ .quad 0x02d1adfeb4e564a6+ .quad 0x4bb23d92ce83bd48+ .quad 0xa162e7246695c486+ .quad 0x131d633435a89607+ .quad 0x30521561a0d12a37+ .quad 0x56704bada6afb363+ .quad 0xaf6c4aa752f912b9+ .quad 0x5e665f6cd86770c8+ .quad 0x4c35ac83a3c8cd58+ .quad 0x2b7a29c010a58a7e++ // 2^252 * 5 * G++ .quad 0xc4007f77d0c1cec3+ .quad 0x8d1020b6bac492f8+ .quad 0x32ec29d57e69daaf+ .quad 0x599408759d95fce0+ .quad 0x33810a23bf00086e+ .quad 0xafce925ee736ff7c+ .quad 0x3d60e670e24922d4+ .quad 0x11ce9e714f96061b+ .quad 0x219ef713d815bac1+ .quad 0xf141465d485be25c+ .quad 0x6d5447cc4e513c51+ .quad 0x174926be5ef44393++ // 2^252 * 6 * G++ .quad 0xb5deb2f9fc5bd5bb+ .quad 0x92daa72ae1d810e1+ .quad 0xafc4cfdcb72a1c59+ .quad 0x497d78813fc22a24+ .quad 0x3ef5d41593ea022e+ .quad 0x5cbcc1a20ed0eed6+ .quad 0x8fd24ecf07382c8c+ .quad 0x6fa42ead06d8e1ad+ .quad 0xe276824a1f73371f+ .quad 0x7f7cf01c4f5b6736+ .quad 0x7e201fe304fa46e7+ .quad 0x785a36a357808c96++ // 2^252 * 7 * G++ .quad 0x825fbdfd63014d2b+ .quad 0xc852369c6ca7578b+ .quad 0x5b2fcd285c0b5df0+ .quad 0x12ab214c58048c8f+ .quad 0x070442985d517bc3+ .quad 0x6acd56c7ae653678+ .quad 0x00a27983985a7763+ .quad 0x5167effae512662b+ .quad 0xbd4ea9e10f53c4b6+ .quad 0x1673dc5f8ac91a14+ .quad 0xa8f81a4e2acc1aba+ .quad 0x33a92a7924332a25++ // 2^252 * 8 * G++ .quad 0x9dd1f49927996c02+ .quad 0x0cb3b058e04d1752+ .quad 0x1f7e88967fd02c3e+ .quad 0x2f964268cb8b3eb1+ .quad 0x7ba95ba0218f2ada+ .quad 0xcff42287330fb9ca+ .quad 0xdada496d56c6d907+ .quad 0x5380c296f4beee54+ .quad 0x9d4f270466898d0a+ .quad 0x3d0987990aff3f7a+ .quad 0xd09ef36267daba45+ .quad 0x7761455e7b1c669c
+ cbits/s2n/x86_att/edwards25519_encode.S view
@@ -0,0 +1,86 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Encode edwards25519 point into compressed form as 256-bit number+// Input p[8]; output z[32] (bytes)+//+// extern void edwards25519_encode(uint8_t z[static 32],+// const uint64_t p[static 8]);+//+// This assumes that the input buffer p points to a pair of 256-bit+// numbers x (at p) and y (at p+4) representing a point (x,y) on the+// edwards25519 curve. It is assumed that both x and y are < p_25519+// but there is no checking of this, nor of the fact that (x,y) is+// in fact on the curve.+//+// The output in z is a little-endian array of bytes corresponding to+// the standard compressed encoding of a point as 2^255 * x_0 + y+// where x_0 is the least significant bit of x.+// See "https://datatracker.ietf.org/doc/html/rfc8032#section-5.1.2"+// In this implementation, y is simply truncated to 255 bits, but if+// it is reduced mod p_25519 as expected this does not affect values.+//+// Standard x86-64 ABI: RDI = z, RSI = p+// Microsoft x64 ABI: RCX = z, RDX = p+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(edwards25519_encode)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(edwards25519_encode)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(edwards25519_encode)+ .text++#define z %rdi+#define p %rsi+#define y0 %rax+#define y1 %rcx+#define y2 %rdx+#define y3 %r8+#define xb %r9++S2N_BN_SYMBOL(edwards25519_encode):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Load lowest word of x coordinate in xb and full y as [y3;y2;y1;y0].++ movq (p), xb+ movq 32(p), y0+ movq 40(p), y1+ movq 48(p), y2+ movq 56(p), y3++// Compute the encoded form, making the LSB of x the MSB of the encoding++ btr $63, y3+ shlq $63, xb+ orq xb, y3++// Store back (by the word, since x86 is little-endian anyway)++ movq y0, (z)+ movq y1, 8(z)+ movq y2, 16(z)+ movq y3, 24(z)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(edwards25519_encode)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack,"",%progbits+#endif
+ cbits/s2n/x86_att/edwards25519_scalarmulbase.S view
@@ -0,0 +1,9926 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for the edwards25519 standard basepoint+// Input scalar[4]; output res[8]+//+// extern void edwards25519_scalarmulbase+// (uint64_t res[static 8],const uint64_t scalar[static 4]);+//+// Given a scalar n, returns point (X,Y) = n * B where B = (...,4/5) is+// the standard basepoint for the edwards25519 (Ed25519) curve.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar+// Microsoft x64 ABI: RCX = res, RDX = scalar+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(edwards25519_scalarmulbase)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(edwards25519_scalarmulbase)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(edwards25519_scalarmulbase)++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for result and temporaries on stack with some aliasing.+// The result "resx" assumes the "res" pointer has been preloaded into %rbp.++#define resx (0*NUMSIZE)(%rbp)+#define resy (1*NUMSIZE)(%rbp)++#define scalar (0*NUMSIZE)(%rsp)++#define tabent (1*NUMSIZE)(%rsp)+#define ymx_2 (1*NUMSIZE)(%rsp)+#define xpy_2 (2*NUMSIZE)(%rsp)+#define kxy_2 (3*NUMSIZE)(%rsp)++#define t0 (4*NUMSIZE)(%rsp)+#define t1 (5*NUMSIZE)(%rsp)+#define t2 (6*NUMSIZE)(%rsp)+#define t3 (7*NUMSIZE)(%rsp)+#define t4 (8*NUMSIZE)(%rsp)+#define t5 (9*NUMSIZE)(%rsp)++#define acc (10*NUMSIZE)(%rsp)+#define x_1 (10*NUMSIZE)(%rsp)+#define y_1 (11*NUMSIZE)(%rsp)+#define z_1 (12*NUMSIZE)(%rsp)+#define w_1 (13*NUMSIZE)(%rsp)+#define x_3 (10*NUMSIZE)(%rsp)+#define y_3 (11*NUMSIZE)(%rsp)+#define z_3 (12*NUMSIZE)(%rsp)+#define w_3 (13*NUMSIZE)(%rsp)++// Stable homes for the input result pointer, and other variables++#define res 14*NUMSIZE(%rsp)++#define i 14*NUMSIZE+8(%rsp)++#define bias 14*NUMSIZE+16(%rsp)++#define bf 14*NUMSIZE+24(%rsp)+#define ix 14*NUMSIZE+24(%rsp)++#define tab 15*NUMSIZE(%rsp)++// Total size to reserve on the stack++#define NSPACE 488++// Syntactic variants to make x86_att version simpler to generate++#define SCALAR 0+#define TABENT (1*NUMSIZE)+#define ACC (10*NUMSIZE)+#define X3 (10*NUMSIZE)+#define Z3 (12*NUMSIZE)+#define W3 (13*NUMSIZE)++// Macro wrapping up the basic field multiplication, only trivially+// different from a pure function call to bignum_mul_p25519.++#define mul_p25519(P0,P1,P2) \+ xorl %esi, %esi ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rax, %r10 ; \+ addq %rax, %r9 ; \+ mulxq 0x10+P1, %rax, %r11 ; \+ adcq %rax, %r10 ; \+ mulxq 0x18+P1, %rax, %r12 ; \+ adcq %rax, %r11 ; \+ adcq %rsi, %r12 ; \+ xorl %esi, %esi ; \+ movq 0x8+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %r13 ; \+ adcxq %rax, %r12 ; \+ adoxq %rsi, %r13 ; \+ adcxq %rsi, %r13 ; \+ xorl %esi, %esi ; \+ movq 0x10+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x18+P1, %rax, %r14 ; \+ adcxq %rax, %r13 ; \+ adoxq %rsi, %r14 ; \+ adcxq %rsi, %r14 ; \+ xorl %esi, %esi ; \+ movq 0x18+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq 0x18+P1, %rax, %r15 ; \+ adcxq %rax, %r14 ; \+ adoxq %rsi, %r15 ; \+ adcxq %rsi, %r15 ; \+ movl $0x26, %edx ; \+ xorl %esi, %esi ; \+ mulxq %r12, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq %r13, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r14, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rsi, %r12 ; \+ adcxq %rsi, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ movl $0x13, %edx ; \+ incq %r12; \+ bts $63, %r11 ; \+ mulxq %r12, %rax, %rbx ; \+ addq %rax, %r8 ; \+ adcq %rbx, %r9 ; \+ adcq %rsi, %r10 ; \+ adcq %rsi, %r11 ; \+ sbbq %rax, %rax ; \+ notq %rax; \+ andq %rdx, %rax ; \+ subq %rax, %r8 ; \+ sbbq %rsi, %r9 ; \+ sbbq %rsi, %r10 ; \+ sbbq %rsi, %r11 ; \+ btr $63, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ xorl %ecx, %ecx ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rax, %r10 ; \+ addq %rax, %r9 ; \+ mulxq 0x10+P1, %rax, %r11 ; \+ adcq %rax, %r10 ; \+ mulxq 0x18+P1, %rax, %r12 ; \+ adcq %rax, %r11 ; \+ adcq %rcx, %r12 ; \+ xorl %ecx, %ecx ; \+ movq 0x8+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %r13 ; \+ adcxq %rax, %r12 ; \+ adoxq %rcx, %r13 ; \+ adcxq %rcx, %r13 ; \+ xorl %ecx, %ecx ; \+ movq 0x10+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x18+P1, %rax, %r14 ; \+ adcxq %rax, %r13 ; \+ adoxq %rcx, %r14 ; \+ adcxq %rcx, %r14 ; \+ xorl %ecx, %ecx ; \+ movq 0x18+P2, %rdx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq 0x18+P1, %rax, %r15 ; \+ adcxq %rax, %r14 ; \+ adoxq %rcx, %r15 ; \+ adcxq %rcx, %r15 ; \+ movl $0x26, %edx ; \+ xorl %ecx, %ecx ; \+ mulxq %r12, %rax, %rbx ; \+ adcxq %rax, %r8 ; \+ adoxq %rbx, %r9 ; \+ mulxq %r13, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r14, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq %r15, %rax, %r12 ; \+ adcxq %rax, %r11 ; \+ adoxq %rcx, %r12 ; \+ adcxq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ebx, %ebx ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movl $38, %ecx ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %rax ; \+ sbbq 24+P2, %rax ; \+ cmovncq %rbx, %rcx ; \+ subq %rcx, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %rax ; \+ movq %r8, P0 ; \+ movq %r9, 8+P0 ; \+ movq %r10, 16+P0 ; \+ movq %rax, 24+P0++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq P2, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq 0x8+P2, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq 0x10+P2, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq 0x18+P2, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++#define double_twice4(P0,P1) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq %r8, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq %r9, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq %r10, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq %r11, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++S2N_BN_SYMBOL(edwards25519_scalarmulbase):+ CFI_START+ _CET_ENDBR++// In this case the Windows form literally makes a subroutine call.+// This avoids hassle arising from keeping code and data together.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ CFI_CALL(Ledwards25519_scalarmulbase_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(edwards25519_scalarmulbase)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Ledwards25519_scalarmulbase_standard)++Ledwards25519_scalarmulbase_standard:+ CFI_START+#endif++// Save registers, make room for temps, preserve input arguments.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(NSPACE)++// Move the output pointer to a stable place++ movq %rdi, res++// Copy the input scalar x to its local variable while reducing it+// modulo 2^252 + m where m = 27742317777372353535851937790883648493;+// this is the order of the basepoint so this doesn't change the result.+// First do q = floor(x/2^252) and x' = x - q * (2^252 + m), which gives+// an initial result -15 * m <= x' < 2^252++ movq (%rsi), %r8+ movq 8(%rsi), %r9+ movq 16(%rsi), %r10+ movq 24(%rsi), %r11++ movq %r11, %rcx+ shrq $60, %rcx++ movq $0x5812631a5cf5d3ed, %rax+ mulq %rcx+ movq %rax, %r12+ movq %rdx, %r13+ movq $0x14def9dea2f79cd6, %rax+ mulq %rcx+ addq %rax, %r13+ adcq $0, %rdx+ shlq $60, %rcx++ subq %r12, %r8+ sbbq %r13, %r9+ sbbq %rdx, %r10+ sbbq %rcx, %r11++// If x' < 0 then just directly negate it; this makes sure the+// reduced argument is strictly 0 <= x' < 2^252, but now we need+// to record (done via bit 255 of the reduced scalar, which is+// ignored in the main loop) when we negated so we can flip+// the end result to compensate.++ sbbq %rax, %rax++ xorq %rax, %r8+ xorq %rax, %r9+ xorq %rax, %r10+ xorq %rax, %r11++ negq %rax+ adcq $0, %r8+ adcq $0, %r9+ adcq $0, %r10+ adcq $0, %r11++ shlq $63, %rax+ orq %rax, %r11++// And before we store the scalar, test and reset bit 251 to+// initialize the main loop just below.++ movq %r8, SCALAR(%rsp)+ movq %r9, SCALAR+8(%rsp)+ movq %r10, SCALAR+16(%rsp)+ btr $59, %r11+ movq %r11, SCALAR+24(%rsp)++// The main part of the computation is in extended-projective coordinates+// (X,Y,Z,T), representing an affine point on the edwards25519 curve+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// In comments B means the standard basepoint (x,4/5) =+// (0x216....f25d51a,0x6666..666658).+//+// Initialize accumulator "acc" to either 0 or 2^251 * B depending on+// bit 251 of the (reduced) scalar. That leaves bits 0..250 to handle.++ leaq S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant)(%rip), %r10+ leaq 8*12(%r10), %r11++ movq (%r10), %rax+ movq (%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC(%rsp)++ movq 8*1(%r10), %rax+ movq 8*1(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+8(%rsp)++ movq 8*2(%r10), %rax+ movq 8*2(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+16(%rsp)++ movq 8*3(%r10), %rax+ movq 8*3(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+24(%rsp)++ movq 8*4(%r10), %rax+ movq 8*4(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+32(%rsp)++ movq 8*5(%r10), %rax+ movq 8*5(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+40(%rsp)++ movq 8*6(%r10), %rax+ movq 8*6(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+48(%rsp)++ movq 8*7(%r10), %rax+ movq 8*7(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+56(%rsp)++ movl $1, %eax+ movq %rax, ACC+64(%rsp)+ movl $0, %eax+ movq %rax, ACC+72(%rsp)+ movq %rax, ACC+80(%rsp)+ movq %rax, ACC+88(%rsp)++ movq 8*8(%r10), %rax+ movq 8*8(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+96(%rsp)++ movq 8*9(%r10), %rax+ movq 8*9(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+104(%rsp)++ movq 8*10(%r10), %rax+ movq 8*10(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+112(%rsp)++ movq 8*11(%r10), %rax+ movq 8*11(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+120(%rsp)++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 0 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * B at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * B = (16 * (h + 1) - (16 - l)) * B is used+// when l >= 9. Note that we can't have any bias left over at the+// end because we made sure bit 251 is clear in the reduced scalar.++ movq $0, i+ leaq 8*24(%r10), %rax+ movq %rax, tab+ movq $0, bias++// Start of the main loop, repeated 63 times for i = 4, 8, ..., 252++Ledwards25519_scalarmulbase_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ movq i, %rax+ movq %rax, %rcx+ shrq $6, %rax+ movq (%rsp,%rax,8), %rax // Exploiting scalar = sp exactly+ shrq %cl, %rax+ andq $15, %rax+ addq bias, %rax+ movq %rax, bf++ cmpq $9, bf+ sbbq %rax, %rax+ incq %rax+ movq %rax, bias++ movq $16, %rdi+ subq bf, %rdi+ cmpq $0, bias+ cmovzq bf, %rdi+ movq %rdi, ix++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ movl $1, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ movl $1, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ movq tab, %rbp++ cmpq $1, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $2, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $3, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $4, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $5, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $6, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $7, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $8, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15++ addq $96, %rbp+ movq %rbp, tab++// We now have the triple from the table in registers as follows+//+// [%rdx;%rcx;%rbx;%rax] = y - x+// [%r11;%r10;%r9;%r8] = x + y+// [%r15;%r14;%r13;%r12] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmpq $0, bias++ movq %rax, %rsi+ cmovnzq %r8, %rsi+ cmovnzq %rax, %r8+ movq %rsi, TABENT(%rsp)+ movq %r8, TABENT+32(%rsp)++ movq %rbx, %rsi+ cmovnzq %r9, %rsi+ cmovnzq %rbx, %r9+ movq %rsi, TABENT+8(%rsp)+ movq %r9, TABENT+40(%rsp)++ movq %rcx, %rsi+ cmovnzq %r10, %rsi+ cmovnzq %rcx, %r10+ movq %rsi, TABENT+16(%rsp)+ movq %r10, TABENT+48(%rsp)++ movq %rdx, %rsi+ cmovnzq %r11, %rsi+ cmovnzq %rdx, %r11+ movq %rsi, TABENT+24(%rsp)+ movq %r11, TABENT+56(%rsp)++ movq $-19, %rax+ movq $-1, %rbx+ movq $-1, %rcx+ movq $0x7fffffffffffffff, %rdx+ subq %r12, %rax+ sbbq %r13, %rbx+ sbbq %r14, %rcx+ sbbq %r15, %rdx++ movq ix, %r8+ movq bias, %r9+ testq %r8, %r8+ cmovzq %r8, %r9+ testq %r9, %r9++ cmovzq %r12, %rax+ cmovzq %r13, %rbx+ cmovzq %r14, %rcx+ cmovzq %r15, %rdx+ movq %rax, TABENT+64(%rsp)+ movq %rbx, TABENT+72(%rsp)+ movq %rcx, TABENT+80(%rsp)+ movq %rdx, TABENT+88(%rsp)++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ addq $4, i+ cmpq $252, i+ jc Ledwards25519_scalarmulbase_scalarloop++// Insert the optional negation of the projective X coordinate, and+// so by extension the final affine x coordinate x = X/Z and thus+// the point P = (x,y). We only know X < 2 * p_25519, so we do the+// negation as 2 * p_25519 - X to keep it nonnegative. From this+// point on we don't need any normalization of the coordinates+// except for making sure that they fit in 4 digits.++ movq X3(%rsp), %r8+ movq X3+8(%rsp), %r9+ movq X3+16(%rsp), %r10+ movq X3+24(%rsp), %r11+ movq $0xffffffffffffffda, %r12+ subq %r8, %r12+ movq $0xffffffffffffffff, %r13+ sbbq %r9, %r13+ movq $0xffffffffffffffff, %r14+ sbbq %r10, %r14+ movq $0xffffffffffffffff, %r15+ sbbq %r11, %r15+ movq SCALAR+24(%rsp), %rax+ btq $63, %rax+ cmovcq %r12, %r8+ cmovcq %r13, %r9+ cmovcq %r14, %r10+ cmovcq %r15, %r11+ movq %r8, X3(%rsp)+ movq %r9, X3+8(%rsp)+ movq %r10, X3+16(%rsp)+ movq %r11, X3+24(%rsp)++// Now we need to map out of the extended-projective representation+// (X,Y,Z,W) back to the affine form (x,y) = (X/Z,Y/Z). This means+// first calling the modular inverse to get w_3 = 1/z_3.++ leaq W3(%rsp), %rdi+ leaq Z3(%rsp), %rsi++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "x86/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 208 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, x_3, y_3,+// z_3 and w_3.++ movq %rdi, 0xc0(%rsp)+ xorl %eax, %eax+ leaq -0x13(%rax), %rcx+ notq %rax+ movq %rcx, (%rsp)+ movq %rax, 0x8(%rsp)+ movq %rax, 0x10(%rsp)+ btr $0x3f, %rax+ movq %rax, 0x18(%rsp)+ movq (%rsi), %rdx+ movq 0x8(%rsi), %rcx+ movq 0x10(%rsi), %r8+ movq 0x18(%rsi), %r9+ movl $0x1, %eax+ xorl %r10d, %r10d+ bts $0x3f, %r9+ adcq %r10, %rax+ imulq $0x13, %rax, %rax+ addq %rax, %rdx+ adcq %r10, %rcx+ adcq %r10, %r8+ adcq %r10, %r9+ movl $0x13, %eax+ cmovbq %r10, %rax+ subq %rax, %rdx+ sbbq %r10, %rcx+ sbbq %r10, %r8+ sbbq %r10, %r9+ btr $0x3f, %r9+ movq %rdx, 0x20(%rsp)+ movq %rcx, 0x28(%rsp)+ movq %r8, 0x30(%rsp)+ movq %r9, 0x38(%rsp)+ xorl %eax, %eax+ movq %rax, 0x40(%rsp)+ movq %rax, 0x48(%rsp)+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movabsq $0xa0f99e2375022099, %rax+ movq %rax, 0x60(%rsp)+ movabsq $0xa8c68f3f1d132595, %rax+ movq %rax, 0x68(%rsp)+ movabsq $0x6c6c893805ac5242, %rax+ movq %rax, 0x70(%rsp)+ movabsq $0x276508b241770615, %rax+ movq %rax, 0x78(%rsp)+ movq $0xa, 0x90(%rsp)+ movq $0x1, 0x98(%rsp)+ jmp Ledwards25519_scalarmulbase_midloop+Ledwards25519_scalarmulbase_inverseloop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0x80(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0x88(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x20(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x20(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x20(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x28(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq %rax, %rbp+ sarq $0x3f, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ xorq %r13, %rax+ movq %rax, %rsi+ sarq $0x3f, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x30(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x38(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x88(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x40(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x40(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x60(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x60(%rsp)+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x48(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x48(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x68(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x68(%rsp)+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x70(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x70(%rsp)+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq %rdx, %rbx+ shldq $0x1, %rcx, %rdx+ sarq $0x3f, %rbx+ addq %rbx, %rdx+ movl $0x13, %eax+ imulq %rdx+ movq 0x40(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x40(%rsp)+ movq 0x48(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x48(%rsp)+ movq 0x50(%rsp), %r8+ adcq %rbx, %r8+ movq %r8, 0x50(%rsp)+ adcq %rbx, %rcx+ shlq $0x3f, %rax+ addq %rax, %rcx+ movq 0x58(%rsp), %rax+ movq %rcx, 0x58(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rdx, %rcx+ shldq $0x1, %rsi, %rdx+ sarq $0x3f, %rcx+ movl $0x13, %eax+ addq %rcx, %rdx+ imulq %rdx+ movq 0x60(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x60(%rsp)+ movq 0x68(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x68(%rsp)+ movq 0x70(%rsp), %r8+ adcq %rcx, %r8+ movq %r8, 0x70(%rsp)+ adcq %rcx, %rsi+ shlq $0x3f, %rax+ addq %rax, %rsi+ movq %rsi, 0x78(%rsp)+Ledwards25519_scalarmulbase_midloop:+ movq 0x98(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x20(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rdi, 0xb0(%rsp)+ movq %rcx, 0xb8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x20(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xa0(%rsp), %rax+ imulq %r8, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xa8(%rsp), %r8+ imulq 0xb8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xa0(%rsp), %rax+ imulq %r10, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xa8(%rsp), %r10+ imulq 0xb8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0x98(%rsp)+ decq 0x90(%rsp)+ jne Ledwards25519_scalarmulbase_inverseloop+ movq (%rsp), %rax+ movq 0x20(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r9, %rax+ shldq $0x1, %r15, %rax+ sarq $0x3f, %r9+ movl $0x13, %ebx+ leaq 0x1(%rax,%r9,1), %rax+ imulq %rbx+ xorl %ebp, %ebp+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r9, %r14+ adcq %r9, %r15+ shlq $0x3f, %rax+ addq %rax, %r15+ cmovns %rbp, %rbx+ subq %rbx, %r12+ sbbq %rbp, %r13+ sbbq %rbp, %r14+ sbbq %rbp, %r15+ btr $0x3f, %r15+ movq 0xc0(%rsp), %rdi+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)++// The final result is x = X * inv(Z), y = Y * inv(Z).+// These are the only operations in the whole computation that+// fully reduce modulo p_25519 since now we want the canonical+// answer as output.++ movq res, %rbp+ mul_p25519(resx,x_3,w_3)+ mul_p25519(resy,y_3,w_3)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Ledwards25519_scalarmulbase_standard)+#else+S2N_BN_SIZE_DIRECTIVE(edwards25519_scalarmulbase)+#endif++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant), %object+.size S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(edwards25519_scalarmulbase_constant):++// 0 * B = 0 and 2^251 * B in extended-projective coordinates+// but with Z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x0000000000000001+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x525f946d7c7220e7+ .quad 0x4636b0b2f1e35444+ .quad 0x796e9d70e892ae0f+ .quad 0x03dec05fa937adb1+ .quad 0x6d1c271cc6375515+ .quad 0x462588c4a4ca4f14+ .quad 0x691129fee55afc39+ .quad 0x15949f784d8472f5+ .quad 0xbd89e510afad0049+ .quad 0x4d1f08c073b9860e+ .quad 0x07716e8b2d00af9d+ .quad 0x70d685f68f859714++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^0 * 1 * G++ .quad 0x9d103905d740913e+ .quad 0xfd399f05d140beb3+ .quad 0xa5c18434688f8a09+ .quad 0x44fd2f9298f81267+ .quad 0x2fbc93c6f58c3b85+ .quad 0xcf932dc6fb8c0e19+ .quad 0x270b4898643d42c2+ .quad 0x07cf9d3a33d4ba65+ .quad 0xabc91205877aaa68+ .quad 0x26d9e823ccaac49e+ .quad 0x5a1b7dcbdd43598c+ .quad 0x6f117b689f0c65a8++ // 2^0 * 2 * G++ .quad 0x8a99a56042b4d5a8+ .quad 0x8f2b810c4e60acf6+ .quad 0xe09e236bb16e37aa+ .quad 0x6bb595a669c92555+ .quad 0x9224e7fc933c71d7+ .quad 0x9f469d967a0ff5b5+ .quad 0x5aa69a65e1d60702+ .quad 0x590c063fa87d2e2e+ .quad 0x43faa8b3a59b7a5f+ .quad 0x36c16bdd5d9acf78+ .quad 0x500fa0840b3d6a31+ .quad 0x701af5b13ea50b73++ // 2^0 * 3 * G++ .quad 0x56611fe8a4fcd265+ .quad 0x3bd353fde5c1ba7d+ .quad 0x8131f31a214bd6bd+ .quad 0x2ab91587555bda62+ .quad 0xaf25b0a84cee9730+ .quad 0x025a8430e8864b8a+ .quad 0xc11b50029f016732+ .quad 0x7a164e1b9a80f8f4+ .quad 0x14ae933f0dd0d889+ .quad 0x589423221c35da62+ .quad 0xd170e5458cf2db4c+ .quad 0x5a2826af12b9b4c6++ // 2^0 * 4 * G++ .quad 0x95fe050a056818bf+ .quad 0x327e89715660faa9+ .quad 0xc3e8e3cd06a05073+ .quad 0x27933f4c7445a49a+ .quad 0x287351b98efc099f+ .quad 0x6765c6f47dfd2538+ .quad 0xca348d3dfb0a9265+ .quad 0x680e910321e58727+ .quad 0x5a13fbe9c476ff09+ .quad 0x6e9e39457b5cc172+ .quad 0x5ddbdcf9102b4494+ .quad 0x7f9d0cbf63553e2b++ // 2^0 * 5 * G++ .quad 0x7f9182c3a447d6ba+ .quad 0xd50014d14b2729b7+ .quad 0xe33cf11cb864a087+ .quad 0x154a7e73eb1b55f3+ .quad 0xa212bc4408a5bb33+ .quad 0x8d5048c3c75eed02+ .quad 0xdd1beb0c5abfec44+ .quad 0x2945ccf146e206eb+ .quad 0xbcbbdbf1812a8285+ .quad 0x270e0807d0bdd1fc+ .quad 0xb41b670b1bbda72d+ .quad 0x43aabe696b3bb69a++ // 2^0 * 6 * G++ .quad 0x499806b67b7d8ca4+ .quad 0x575be28427d22739+ .quad 0xbb085ce7204553b9+ .quad 0x38b64c41ae417884+ .quad 0x3a0ceeeb77157131+ .quad 0x9b27158900c8af88+ .quad 0x8065b668da59a736+ .quad 0x51e57bb6a2cc38bd+ .quad 0x85ac326702ea4b71+ .quad 0xbe70e00341a1bb01+ .quad 0x53e4a24b083bc144+ .quad 0x10b8e91a9f0d61e3++ // 2^0 * 7 * G++ .quad 0xba6f2c9aaa3221b1+ .quad 0x6ca021533bba23a7+ .quad 0x9dea764f92192c3a+ .quad 0x1d6edd5d2e5317e0+ .quad 0x6b1a5cd0944ea3bf+ .quad 0x7470353ab39dc0d2+ .quad 0x71b2528228542e49+ .quad 0x461bea69283c927e+ .quad 0xf1836dc801b8b3a2+ .quad 0xb3035f47053ea49a+ .quad 0x529c41ba5877adf3+ .quad 0x7a9fbb1c6a0f90a7++ // 2^0 * 8 * G++ .quad 0xe2a75dedf39234d9+ .quad 0x963d7680e1b558f9+ .quad 0x2c2741ac6e3c23fb+ .quad 0x3a9024a1320e01c3+ .quad 0x59b7596604dd3e8f+ .quad 0x6cb30377e288702c+ .quad 0xb1339c665ed9c323+ .quad 0x0915e76061bce52f+ .quad 0xe7c1f5d9c9a2911a+ .quad 0xb8a371788bcca7d7+ .quad 0x636412190eb62a32+ .quad 0x26907c5c2ecc4e95++ // 2^4 * 1 * G++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * G++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * G++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * G++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * G++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * G++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * G++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * G++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * G++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * G++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * G++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * G++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * G++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * G++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * G++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * G++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * G++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * G++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * G++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * G++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * G++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * G++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * G++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * G++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * G++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * G++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * G++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * G++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * G++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * G++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * G++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * G++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * G++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * G++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * G++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * G++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * G++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * G++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * G++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * G++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * G++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * G++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * G++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * G++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * G++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * G++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * G++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * G++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * G++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * G++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * G++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * G++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * G++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * G++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * G++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * G++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * G++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * G++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * G++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * G++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * G++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * G++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * G++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * G++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * G++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * G++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * G++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * G++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * G++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * G++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * G++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * G++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * G++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * G++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * G++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * G++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * G++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * G++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * G++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * G++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * G++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * G++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * G++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * G++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * G++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * G++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * G++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * G++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * G++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * G++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * G++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * G++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * G++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * G++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * G++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * G++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * G++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * G++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * G++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * G++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * G++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * G++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * G++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * G++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * G++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * G++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * G++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * G++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * G++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * G++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * G++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * G++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * G++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * G++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * G++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * G++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * G++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * G++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * G++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * G++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * G++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * G++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * G++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * G++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * G++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * G++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * G++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * G++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * G++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * G++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * G++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * G++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * G++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * G++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * G++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * G++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * G++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * G++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * G++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * G++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * G++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * G++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * G++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * G++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * G++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * G++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * G++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * G++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * G++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * G++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * G++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * G++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * G++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * G++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * G++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * G++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * G++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * G++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * G++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * G++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * G++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * G++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * G++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * G++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * G++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * G++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * G++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * G++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * G++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * G++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * G++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * G++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * G++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * G++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * G++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * G++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * G++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * G++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * G++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * G++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * G++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * G++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * G++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * G++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * G++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * G++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * G++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * G++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * G++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * G++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * G++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * G++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * G++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * G++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * G++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * G++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * G++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * G++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * G++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * G++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * G++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * G++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * G++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * G++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * G++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * G++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * G++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * G++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * G++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * G++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * G++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * G++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * G++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * G++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * G++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * G++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * G++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * G++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * G++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * G++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * G++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * G++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * G++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * G++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * G++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * G++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * G++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * G++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * G++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * G++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * G++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * G++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * G++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * G++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * G++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * G++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * G++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * G++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * G++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * G++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * G++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * G++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * G++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * G++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * G++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * G++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * G++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * G++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * G++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * G++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * G++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * G++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * G++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * G++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * G++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * G++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * G++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * G++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * G++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * G++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * G++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * G++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * G++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * G++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * G++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * G++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * G++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * G++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * G++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * G++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * G++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * G++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * G++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * G++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * G++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * G++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * G++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * G++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * G++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * G++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * G++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * G++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * G++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * G++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * G++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * G++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * G++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * G++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * G++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * G++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * G++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * G++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * G++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * G++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * G++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * G++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * G++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * G++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * G++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * G++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * G++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * G++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * G++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * G++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * G++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * G++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * G++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * G++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * G++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * G++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * G++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * G++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * G++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * G++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * G++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * G++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * G++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * G++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * G++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * G++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * G++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * G++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * G++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * G++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * G++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * G++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * G++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * G++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * G++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * G++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * G++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * G++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * G++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * G++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * G++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * G++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * G++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * G++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * G++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * G++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * G++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * G++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * G++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * G++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * G++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * G++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * G++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * G++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * G++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * G++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * G++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * G++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * G++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * G++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * G++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * G++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * G++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * G++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * G++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * G++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * G++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * G++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * G++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * G++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * G++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * G++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * G++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * G++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * G++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * G++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * G++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * G++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * G++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * G++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * G++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * G++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * G++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * G++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * G++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * G++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * G++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * G++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * G++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * G++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * G++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * G++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * G++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * G++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * G++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * G++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * G++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * G++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * G++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * G++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * G++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * G++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * G++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * G++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * G++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * G++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * G++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * G++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * G++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * G++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * G++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * G++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * G++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * G++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * G++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * G++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * G++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * G++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * G++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * G++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * G++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * G++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * G++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * G++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * G++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * G++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * G++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * G++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * G++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * G++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * G++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * G++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * G++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * G++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * G++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * G++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * G++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * G++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * G++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * G++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * G++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * G++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * G++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * G++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * G++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * G++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * G++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * G++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * G++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * G++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * G++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * G++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * G++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * G++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * G++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * G++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * G++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * G++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * G++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * G++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * G++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * G++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * G++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * G++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * G++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * G++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * G++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * G++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * G++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * G++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * G++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * G++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * G++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * G++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * G++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * G++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * G++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * G++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * G++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * G++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * G++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * G++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * G++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * G++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * G++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * G++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * G++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * G++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * G++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * G++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * G++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * G++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * G++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * G++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * G++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * G++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * G++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * G++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * G++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * G++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * G++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * G++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f
+ cbits/s2n/x86_att/edwards25519_scalarmulbase_alt.S view
@@ -0,0 +1,10002 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for the edwards25519 standard basepoint+// Input scalar[4]; output res[8]+//+// extern void edwards25519_scalarmulbase_alt+// (uint64_t res[static 8],const uint64_t scalar[static 4]);+//+// Given a scalar n, returns point (X,Y) = n * B where B = (...,4/5) is+// the standard basepoint for the edwards25519 (Ed25519) curve.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar+// Microsoft x64 ABI: RCX = res, RDX = scalar+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(edwards25519_scalarmulbase_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(edwards25519_scalarmulbase_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(edwards25519_scalarmulbase_alt)++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for result and temporaries on stack with some aliasing.+// The result "resx" assumes the "res" pointer has been preloaded into %rbp.++#define resx (0*NUMSIZE)(%rbp)+#define resy (1*NUMSIZE)(%rbp)++#define scalar (0*NUMSIZE)(%rsp)++#define tabent (1*NUMSIZE)(%rsp)+#define ymx_2 (1*NUMSIZE)(%rsp)+#define xpy_2 (2*NUMSIZE)(%rsp)+#define kxy_2 (3*NUMSIZE)(%rsp)++#define t0 (4*NUMSIZE)(%rsp)+#define t1 (5*NUMSIZE)(%rsp)+#define t2 (6*NUMSIZE)(%rsp)+#define t3 (7*NUMSIZE)(%rsp)+#define t4 (8*NUMSIZE)(%rsp)+#define t5 (9*NUMSIZE)(%rsp)++#define acc (10*NUMSIZE)(%rsp)+#define x_1 (10*NUMSIZE)(%rsp)+#define y_1 (11*NUMSIZE)(%rsp)+#define z_1 (12*NUMSIZE)(%rsp)+#define w_1 (13*NUMSIZE)(%rsp)+#define x_3 (10*NUMSIZE)(%rsp)+#define y_3 (11*NUMSIZE)(%rsp)+#define z_3 (12*NUMSIZE)(%rsp)+#define w_3 (13*NUMSIZE)(%rsp)++// Stable homes for the input result pointer, and other variables++#define res 14*NUMSIZE(%rsp)++#define i 14*NUMSIZE+8(%rsp)++#define bias 14*NUMSIZE+16(%rsp)++#define bf 14*NUMSIZE+24(%rsp)+#define ix 14*NUMSIZE+24(%rsp)++#define tab 15*NUMSIZE(%rsp)++// Total size to reserve on the stack++#define NSPACE 488++// Syntactic variants to make x86_att version simpler to generate++#define SCALAR 0+#define TABENT (1*NUMSIZE)+#define ACC (10*NUMSIZE)+#define X3 (10*NUMSIZE)+#define Z3 (12*NUMSIZE)+#define W3 (13*NUMSIZE)++// Macro wrapping up the basic field multiplication, only trivially+// different from a pure function call to bignum_mul_p25519_alt.++#define mul_p25519(P0,P1,P2) \+ movq P1, %rax ; \+ mulq P2; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x8+P1, %rax ; \+ mulq P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq 0x10+P1, %rax ; \+ mulq P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq %r13, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x18+P1, %rax ; \+ mulq P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %esi ; \+ movq %r12, %rax ; \+ mulq %rsi; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rsi; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ leaq 0x1(%r12), %rax ; \+ movl $0x13, %esi ; \+ bts $63, %r11 ; \+ imulq %rsi, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ sbbq %rax, %rax ; \+ notq %rax; \+ andq %rsi, %rax ; \+ subq %rax, %r8 ; \+ sbbq %rcx, %r9 ; \+ sbbq %rcx, %r10 ; \+ sbbq %rcx, %r11 ; \+ btr $63, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// A version of multiplication that only guarantees output < 2 * p_25519.+// This basically skips the +1 and final correction in quotient estimation.++#define mul_4(P0,P1,P2) \+ movq P1, %rax ; \+ mulq P2; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ xorq %r10, %r10 ; \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x8+P1, %rax ; \+ mulq P2; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ adcq $0x0, %r11 ; \+ xorq %r12, %r12 ; \+ movq P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq %r12, %r12 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ movq 0x10+P1, %rax ; \+ mulq P2; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ adcq $0x0, %r12 ; \+ xorq %r13, %r13 ; \+ movq P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq %r13, %r13 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ movq 0x18+P1, %rax ; \+ mulq P2; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ adcq $0x0, %r13 ; \+ xorq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x8+P2; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x10+P2; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq $0x0, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq 0x18+P2; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ movl $0x26, %ebx ; \+ movq %r12, %rax ; \+ mulq %rbx; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rcx, %rcx ; \+ movq %r13, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r14, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq %r15, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ xorq %rcx, %rcx ; \+ addq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ adcq %rcx, %r12 ; \+ shldq $0x1, %r11, %r12 ; \+ btr $0x3f, %r11 ; \+ movl $0x13, %edx ; \+ imulq %r12, %rdx ; \+ addq %rdx, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++// Modular subtraction with double modulus 2 * p_25519 = 2^256 - 38++#define sub_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ebx, %ebx ; \+ subq P2, %r8 ; \+ movq 8+P1, %r9 ; \+ sbbq 8+P2, %r9 ; \+ movl $38, %ecx ; \+ movq 16+P1, %r10 ; \+ sbbq 16+P2, %r10 ; \+ movq 24+P1, %rax ; \+ sbbq 24+P2, %rax ; \+ cmovncq %rbx, %rcx ; \+ subq %rcx, %r8 ; \+ sbbq %rbx, %r9 ; \+ sbbq %rbx, %r10 ; \+ sbbq %rbx, %rax ; \+ movq %r8, P0 ; \+ movq %r9, 8+P0 ; \+ movq %r10, 16+P0 ; \+ movq %rax, 24+P0++// Modular addition and doubling with double modulus 2 * p_25519 = 2^256 - 38.+// This only ensures that the result fits in 4 digits, not that it is reduced+// even w.r.t. double modulus. The result is always correct modulo provided+// the sum of the inputs is < 2^256 + 2^256 - 38, so in particular provided+// at least one of them is reduced double modulo.++#define add_twice4(P0,P1,P2) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq P2, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq 0x8+P2, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq 0x10+P2, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq 0x18+P2, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++#define double_twice4(P0,P1) \+ movq P1, %r8 ; \+ xorl %ecx, %ecx ; \+ addq %r8, %r8 ; \+ movq 0x8+P1, %r9 ; \+ adcq %r9, %r9 ; \+ movq 0x10+P1, %r10 ; \+ adcq %r10, %r10 ; \+ movq 0x18+P1, %r11 ; \+ adcq %r11, %r11 ; \+ movl $38, %eax ; \+ cmovncq %rcx, %rax ; \+ addq %rax, %r8 ; \+ adcq %rcx, %r9 ; \+ adcq %rcx, %r10 ; \+ adcq %rcx, %r11 ; \+ movq %r8, P0 ; \+ movq %r9, 0x8+P0 ; \+ movq %r10, 0x10+P0 ; \+ movq %r11, 0x18+P0++S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt):+ CFI_START+ _CET_ENDBR++// In this case the Windows form literally makes a subroutine call.+// This avoids hassle arising from keeping code and data together.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ CFI_CALL(Ledwards25519_scalarmulbase_alt_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(edwards25519_scalarmulbase_alt)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Ledwards25519_scalarmulbase_alt_standard)++Ledwards25519_scalarmulbase_alt_standard:+ CFI_START+#endif++// Save registers, make room for temps, preserve input arguments.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(NSPACE)++// Move the output pointer to a stable place++ movq %rdi, res++// Copy the input scalar x to its local variable while reducing it+// modulo 2^252 + m where m = 27742317777372353535851937790883648493;+// this is the order of the basepoint so this doesn't change the result.+// First do q = floor(x/2^252) and x' = x - q * (2^252 + m), which gives+// an initial result -15 * m <= x' < 2^252++ movq (%rsi), %r8+ movq 8(%rsi), %r9+ movq 16(%rsi), %r10+ movq 24(%rsi), %r11++ movq %r11, %rcx+ shrq $60, %rcx++ movq $0x5812631a5cf5d3ed, %rax+ mulq %rcx+ movq %rax, %r12+ movq %rdx, %r13+ movq $0x14def9dea2f79cd6, %rax+ mulq %rcx+ addq %rax, %r13+ adcq $0, %rdx+ shlq $60, %rcx++ subq %r12, %r8+ sbbq %r13, %r9+ sbbq %rdx, %r10+ sbbq %rcx, %r11++// If x' < 0 then just directly negate it; this makes sure the+// reduced argument is strictly 0 <= x' < 2^252, but now we need+// to record (done via bit 255 of the reduced scalar, which is+// ignored in the main loop) when we negated so we can flip+// the end result to compensate.++ sbbq %rax, %rax++ xorq %rax, %r8+ xorq %rax, %r9+ xorq %rax, %r10+ xorq %rax, %r11++ negq %rax+ adcq $0, %r8+ adcq $0, %r9+ adcq $0, %r10+ adcq $0, %r11++ shlq $63, %rax+ orq %rax, %r11++// And before we store the scalar, test and reset bit 251 to+// initialize the main loop just below.++ movq %r8, SCALAR(%rsp)+ movq %r9, SCALAR+8(%rsp)+ movq %r10, SCALAR+16(%rsp)+ btr $59, %r11+ movq %r11, SCALAR+24(%rsp)++// The main part of the computation is in extended-projective coordinates+// (X,Y,Z,T), representing an affine point on the edwards25519 curve+// (x,y) via x = X/Z, y = Y/Z and x * y = T/Z (so X * Y = T * Z).+// In comments B means the standard basepoint (x,4/5) =+// (0x216....f25d51a,0x6666..666658).+//+// Initialize accumulator "acc" to either 0 or 2^251 * B depending on+// bit 251 of the (reduced) scalar. That leaves bits 0..250 to handle.++ leaq S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant)(%rip), %r10+ leaq 8*12(%r10), %r11++ movq (%r10), %rax+ movq (%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC(%rsp)++ movq 8*1(%r10), %rax+ movq 8*1(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+8(%rsp)++ movq 8*2(%r10), %rax+ movq 8*2(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+16(%rsp)++ movq 8*3(%r10), %rax+ movq 8*3(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+24(%rsp)++ movq 8*4(%r10), %rax+ movq 8*4(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+32(%rsp)++ movq 8*5(%r10), %rax+ movq 8*5(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+40(%rsp)++ movq 8*6(%r10), %rax+ movq 8*6(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+48(%rsp)++ movq 8*7(%r10), %rax+ movq 8*7(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+56(%rsp)++ movl $1, %eax+ movq %rax, ACC+64(%rsp)+ movl $0, %eax+ movq %rax, ACC+72(%rsp)+ movq %rax, ACC+80(%rsp)+ movq %rax, ACC+88(%rsp)++ movq 8*8(%r10), %rax+ movq 8*8(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+96(%rsp)++ movq 8*9(%r10), %rax+ movq 8*9(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+104(%rsp)++ movq 8*10(%r10), %rax+ movq 8*10(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+112(%rsp)++ movq 8*11(%r10), %rax+ movq 8*11(%r11), %rcx+ cmovcq %rcx, %rax+ movq %rax, ACC+120(%rsp)++// The counter "i" tracks the bit position for which the scalar has+// already been absorbed, starting at 0 and going up in chunks of 4.+//+// The pointer "tab" points at the current block of the table for+// multiples (2^i * j) * B at the current bit position i; 1 <= j <= 8.+//+// The bias is always either 0 and 1 and needs to be added to the+// partially processed scalar implicitly. This is used to absorb 4 bits+// of scalar per iteration from 3-bit table indexing by exploiting+// negation: (16 * h + l) * B = (16 * (h + 1) - (16 - l)) * B is used+// when l >= 9. Note that we can't have any bias left over at the+// end because we made sure bit 251 is clear in the reduced scalar.++ movq $0, i+ leaq 8*24(%r10), %rax+ movq %rax, tab+ movq $0, bias++// Start of the main loop, repeated 63 times for i = 4, 8, ..., 252++Ledwards25519_scalarmulbase_alt_scalarloop:++// Look at the next 4-bit field "bf", adding the previous bias as well.+// Choose the table index "ix" as bf when bf <= 8 and 16 - bf for bf >= 9,+// setting the bias to 1 for the next iteration in the latter case.++ movq i, %rax+ movq %rax, %rcx+ shrq $6, %rax+ movq (%rsp,%rax,8), %rax // Exploiting scalar = sp exactly+ shrq %cl, %rax+ andq $15, %rax+ addq bias, %rax+ movq %rax, bf++ cmpq $9, bf+ sbbq %rax, %rax+ incq %rax+ movq %rax, bias++ movq $16, %rdi+ subq bf, %rdi+ cmpq $0, bias+ cmovzq bf, %rdi+ movq %rdi, ix++// Perform constant-time lookup in the table to get element number "ix".+// The table entry for the affine point (x,y) is actually a triple+// (y - x,x + y,2 * d * x * y) to precompute parts of the addition.+// Note that "ix" can be 0, so we set up the appropriate identity first.++ movl $1, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ movl $1, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ movq tab, %rbp++ cmpq $1, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $2, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $3, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $4, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $5, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $6, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $7, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15+ addq $96, %rbp++ cmpq $8, ix+ movq (%rbp), %rsi+ cmovzq %rsi, %rax+ movq 8(%rbp), %rsi+ cmovzq %rsi, %rbx+ movq 16(%rbp), %rsi+ cmovzq %rsi, %rcx+ movq 24(%rbp), %rsi+ cmovzq %rsi, %rdx+ movq 32(%rbp), %rsi+ cmovzq %rsi, %r8+ movq 40(%rbp), %rsi+ cmovzq %rsi, %r9+ movq 48(%rbp), %rsi+ cmovzq %rsi, %r10+ movq 56(%rbp), %rsi+ cmovzq %rsi, %r11+ movq 64(%rbp), %rsi+ cmovzq %rsi, %r12+ movq 72(%rbp), %rsi+ cmovzq %rsi, %r13+ movq 80(%rbp), %rsi+ cmovzq %rsi, %r14+ movq 88(%rbp), %rsi+ cmovzq %rsi, %r15++ addq $96, %rbp+ movq %rbp, tab++// We now have the triple from the table in registers as follows+//+// [%rdx;%rcx;%rbx;%rax] = y - x+// [%r11;%r10;%r9;%r8] = x + y+// [%r15;%r14;%r13;%r12] = 2 * d * x * y+//+// In case bias = 1 we need to negate this. For Edwards curves+// -(x,y) = (-x,y), i.e. we need to negate the x coordinate.+// In this processed encoding, that amounts to swapping the+// first two fields and negating the third.+//+// The optional negation here also pretends bias = 0 whenever+// ix = 0 so that it doesn't need to handle the case of zero+// inputs, since no non-trivial table entries are zero. Note+// that in the zero case the whole negation is trivial, and+// so indeed is the swapping.++ cmpq $0, bias++ movq %rax, %rsi+ cmovnzq %r8, %rsi+ cmovnzq %rax, %r8+ movq %rsi, TABENT(%rsp)+ movq %r8, TABENT+32(%rsp)++ movq %rbx, %rsi+ cmovnzq %r9, %rsi+ cmovnzq %rbx, %r9+ movq %rsi, TABENT+8(%rsp)+ movq %r9, TABENT+40(%rsp)++ movq %rcx, %rsi+ cmovnzq %r10, %rsi+ cmovnzq %rcx, %r10+ movq %rsi, TABENT+16(%rsp)+ movq %r10, TABENT+48(%rsp)++ movq %rdx, %rsi+ cmovnzq %r11, %rsi+ cmovnzq %rdx, %r11+ movq %rsi, TABENT+24(%rsp)+ movq %r11, TABENT+56(%rsp)++ movq $-19, %rax+ movq $-1, %rbx+ movq $-1, %rcx+ movq $0x7fffffffffffffff, %rdx+ subq %r12, %rax+ sbbq %r13, %rbx+ sbbq %r14, %rcx+ sbbq %r15, %rdx++ movq ix, %r8+ movq bias, %r9+ testq %r8, %r8+ cmovzq %r8, %r9+ testq %r9, %r9++ cmovzq %r12, %rax+ cmovzq %r13, %rbx+ cmovzq %r14, %rcx+ cmovzq %r15, %rdx+ movq %rax, TABENT+64(%rsp)+ movq %rbx, TABENT+72(%rsp)+ movq %rcx, TABENT+80(%rsp)+ movq %rdx, TABENT+88(%rsp)++// Extended-projective and precomputed mixed addition.+// This is effectively the same as calling the standalone+// function edwards25519_pepadd(acc,acc,tabent), but we+// only retain slightly weaker normalization < 2 * p_25519+// throughout the inner loop, so the computation is+// slightly different, and faster overall.++ double_twice4(t0,z_1)+ sub_twice4(t1,y_1,x_1)+ add_twice4(t2,y_1,x_1)+ mul_4(t3,w_1,kxy_2)+ mul_4(t1,t1,ymx_2)+ mul_4(t2,t2,xpy_2)+ sub_twice4(t4,t0,t3)+ add_twice4(t0,t0,t3)+ sub_twice4(t5,t2,t1)+ add_twice4(t1,t2,t1)+ mul_4(z_3,t4,t0)+ mul_4(x_3,t5,t4)+ mul_4(y_3,t0,t1)+ mul_4(w_3,t5,t1)++// End of the main loop; move on by 4 bits.++ addq $4, i+ cmpq $252, i+ jc Ledwards25519_scalarmulbase_alt_scalarloop++// Insert the optional negation of the projective X coordinate, and+// so by extension the final affine x coordinate x = X/Z and thus+// the point P = (x,y). We only know X < 2 * p_25519, so we do the+// negation as 2 * p_25519 - X to keep it nonnegative. From this+// point on we don't need any normalization of the coordinates+// except for making sure that they fit in 4 digits.++ movq X3(%rsp), %r8+ movq X3+8(%rsp), %r9+ movq X3+16(%rsp), %r10+ movq X3+24(%rsp), %r11+ movq $0xffffffffffffffda, %r12+ subq %r8, %r12+ movq $0xffffffffffffffff, %r13+ sbbq %r9, %r13+ movq $0xffffffffffffffff, %r14+ sbbq %r10, %r14+ movq $0xffffffffffffffff, %r15+ sbbq %r11, %r15+ movq SCALAR+24(%rsp), %rax+ btq $63, %rax+ cmovcq %r12, %r8+ cmovcq %r13, %r9+ cmovcq %r14, %r10+ cmovcq %r15, %r11+ movq %r8, X3(%rsp)+ movq %r9, X3+8(%rsp)+ movq %r10, X3+16(%rsp)+ movq %r11, X3+24(%rsp)++// Now we need to map out of the extended-projective representation+// (X,Y,Z,W) back to the affine form (x,y) = (X/Z,Y/Z). This means+// first calling the modular inverse to get w_3 = 1/z_3.++ leaq W3(%rsp), %rdi+ leaq Z3(%rsp), %rsi++// Inline copy of bignum_inv_p25519, identical except for stripping out+// the prologue and epilogue saving and restoring registers and making+// and reclaiming room on the stack. For more details and explanations see+// "x86/curve25519/bignum_inv_p25519.S". Note that the stack it uses for+// its own temporaries is 208 bytes, so it has no effect on variables+// that are needed in the rest of our computation here: res, x_3, y_3,+// z_3 and w_3.++ movq %rdi, 0xc0(%rsp)+ xorl %eax, %eax+ leaq -0x13(%rax), %rcx+ notq %rax+ movq %rcx, (%rsp)+ movq %rax, 0x8(%rsp)+ movq %rax, 0x10(%rsp)+ btr $0x3f, %rax+ movq %rax, 0x18(%rsp)+ movq (%rsi), %rdx+ movq 0x8(%rsi), %rcx+ movq 0x10(%rsi), %r8+ movq 0x18(%rsi), %r9+ movl $0x1, %eax+ xorl %r10d, %r10d+ bts $0x3f, %r9+ adcq %r10, %rax+ imulq $0x13, %rax, %rax+ addq %rax, %rdx+ adcq %r10, %rcx+ adcq %r10, %r8+ adcq %r10, %r9+ movl $0x13, %eax+ cmovbq %r10, %rax+ subq %rax, %rdx+ sbbq %r10, %rcx+ sbbq %r10, %r8+ sbbq %r10, %r9+ btr $0x3f, %r9+ movq %rdx, 0x20(%rsp)+ movq %rcx, 0x28(%rsp)+ movq %r8, 0x30(%rsp)+ movq %r9, 0x38(%rsp)+ xorl %eax, %eax+ movq %rax, 0x40(%rsp)+ movq %rax, 0x48(%rsp)+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movabsq $0xa0f99e2375022099, %rax+ movq %rax, 0x60(%rsp)+ movabsq $0xa8c68f3f1d132595, %rax+ movq %rax, 0x68(%rsp)+ movabsq $0x6c6c893805ac5242, %rax+ movq %rax, 0x70(%rsp)+ movabsq $0x276508b241770615, %rax+ movq %rax, 0x78(%rsp)+ movq $0xa, 0x90(%rsp)+ movq $0x1, 0x98(%rsp)+ jmp Ledwards25519_scalarmulbase_alt_midloop+Ledwards25519_scalarmulbase_alt_inverseloop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0x80(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0x88(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x20(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x20(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x20(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x28(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq %rax, %rbp+ sarq $0x3f, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ xorq %r13, %rax+ movq %rax, %rsi+ sarq $0x3f, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ movq %rax, %rdx+ sarq $0x3f, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x30(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x38(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x88(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x40(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x40(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x60(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x60(%rsp)+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x48(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x48(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x68(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x68(%rsp)+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x70(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x70(%rsp)+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq %rdx, %rbx+ shldq $0x1, %rcx, %rdx+ sarq $0x3f, %rbx+ addq %rbx, %rdx+ movl $0x13, %eax+ imulq %rdx+ movq 0x40(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x40(%rsp)+ movq 0x48(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x48(%rsp)+ movq 0x50(%rsp), %r8+ adcq %rbx, %r8+ movq %r8, 0x50(%rsp)+ adcq %rbx, %rcx+ shlq $0x3f, %rax+ addq %rax, %rcx+ movq 0x58(%rsp), %rax+ movq %rcx, 0x58(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rdx, %rcx+ shldq $0x1, %rsi, %rdx+ sarq $0x3f, %rcx+ movl $0x13, %eax+ addq %rcx, %rdx+ imulq %rdx+ movq 0x60(%rsp), %r8+ addq %rax, %r8+ movq %r8, 0x60(%rsp)+ movq 0x68(%rsp), %r8+ adcq %rdx, %r8+ movq %r8, 0x68(%rsp)+ movq 0x70(%rsp), %r8+ adcq %rcx, %r8+ movq %r8, 0x70(%rsp)+ adcq %rcx, %rsi+ shlq $0x3f, %rax+ addq %rax, %rsi+ movq %rsi, 0x78(%rsp)+Ledwards25519_scalarmulbase_alt_midloop:+ movq 0x98(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x20(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rdi, 0xb0(%rsp)+ movq %rcx, 0xb8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x20(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xa0(%rsp), %rax+ imulq %r8, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xa8(%rsp), %r8+ imulq 0xb8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xa0(%rsp), %rax+ imulq %r10, %rax+ movq 0xb0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xa8(%rsp), %r10+ imulq 0xb8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0x98(%rsp)+ decq 0x90(%rsp)+ jne Ledwards25519_scalarmulbase_alt_inverseloop+ movq (%rsp), %rax+ movq 0x20(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x60(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x48(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x68(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x70(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r9, %rax+ shldq $0x1, %r15, %rax+ sarq $0x3f, %r9+ movl $0x13, %ebx+ leaq 0x1(%rax,%r9,1), %rax+ imulq %rbx+ xorl %ebp, %ebp+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r9, %r14+ adcq %r9, %r15+ shlq $0x3f, %rax+ addq %rax, %r15+ cmovns %rbp, %rbx+ subq %rbx, %r12+ sbbq %rbp, %r13+ sbbq %rbp, %r14+ sbbq %rbp, %r15+ btr $0x3f, %r15+ movq 0xc0(%rsp), %rdi+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)++// The final result is x = X * inv(Z), y = Y * inv(Z).+// These are the only operations in the whole computation that+// fully reduce modulo p_25519 since now we want the canonical+// answer as output.++ movq res, %rbp+ mul_p25519(resx,x_3,w_3)+ mul_p25519(resy,y_3,w_3)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)++ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Ledwards25519_scalarmulbase_alt_standard)+#else+S2N_BN_SIZE_DIRECTIVE(edwards25519_scalarmulbase_alt)+#endif++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif++// ****************************************************************************+// The precomputed data (all read-only).+// ****************************************************************************++#if defined(__ELF__)+.section .rodata+.type S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant), %object+.size S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant), 48576+#elif defined(__APPLE__)+.const_data+#endif++S2N_BN_SYMBOL(edwards25519_scalarmulbase_alt_constant):++// 0 * B = 0 and 2^251 * B in extended-projective coordinates+// but with Z = 1 assumed and hence left out, so they are (X,Y,T) only.++ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x0000000000000001+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000+ .quad 0x0000000000000000++ .quad 0x525f946d7c7220e7+ .quad 0x4636b0b2f1e35444+ .quad 0x796e9d70e892ae0f+ .quad 0x03dec05fa937adb1+ .quad 0x6d1c271cc6375515+ .quad 0x462588c4a4ca4f14+ .quad 0x691129fee55afc39+ .quad 0x15949f784d8472f5+ .quad 0xbd89e510afad0049+ .quad 0x4d1f08c073b9860e+ .quad 0x07716e8b2d00af9d+ .quad 0x70d685f68f859714++// Precomputed table of multiples of generator for edwards25519+// all in precomputed extended-projective (y-x,x+y,2*d*x*y) triples.++ // 2^0 * 1 * G++ .quad 0x9d103905d740913e+ .quad 0xfd399f05d140beb3+ .quad 0xa5c18434688f8a09+ .quad 0x44fd2f9298f81267+ .quad 0x2fbc93c6f58c3b85+ .quad 0xcf932dc6fb8c0e19+ .quad 0x270b4898643d42c2+ .quad 0x07cf9d3a33d4ba65+ .quad 0xabc91205877aaa68+ .quad 0x26d9e823ccaac49e+ .quad 0x5a1b7dcbdd43598c+ .quad 0x6f117b689f0c65a8++ // 2^0 * 2 * G++ .quad 0x8a99a56042b4d5a8+ .quad 0x8f2b810c4e60acf6+ .quad 0xe09e236bb16e37aa+ .quad 0x6bb595a669c92555+ .quad 0x9224e7fc933c71d7+ .quad 0x9f469d967a0ff5b5+ .quad 0x5aa69a65e1d60702+ .quad 0x590c063fa87d2e2e+ .quad 0x43faa8b3a59b7a5f+ .quad 0x36c16bdd5d9acf78+ .quad 0x500fa0840b3d6a31+ .quad 0x701af5b13ea50b73++ // 2^0 * 3 * G++ .quad 0x56611fe8a4fcd265+ .quad 0x3bd353fde5c1ba7d+ .quad 0x8131f31a214bd6bd+ .quad 0x2ab91587555bda62+ .quad 0xaf25b0a84cee9730+ .quad 0x025a8430e8864b8a+ .quad 0xc11b50029f016732+ .quad 0x7a164e1b9a80f8f4+ .quad 0x14ae933f0dd0d889+ .quad 0x589423221c35da62+ .quad 0xd170e5458cf2db4c+ .quad 0x5a2826af12b9b4c6++ // 2^0 * 4 * G++ .quad 0x95fe050a056818bf+ .quad 0x327e89715660faa9+ .quad 0xc3e8e3cd06a05073+ .quad 0x27933f4c7445a49a+ .quad 0x287351b98efc099f+ .quad 0x6765c6f47dfd2538+ .quad 0xca348d3dfb0a9265+ .quad 0x680e910321e58727+ .quad 0x5a13fbe9c476ff09+ .quad 0x6e9e39457b5cc172+ .quad 0x5ddbdcf9102b4494+ .quad 0x7f9d0cbf63553e2b++ // 2^0 * 5 * G++ .quad 0x7f9182c3a447d6ba+ .quad 0xd50014d14b2729b7+ .quad 0xe33cf11cb864a087+ .quad 0x154a7e73eb1b55f3+ .quad 0xa212bc4408a5bb33+ .quad 0x8d5048c3c75eed02+ .quad 0xdd1beb0c5abfec44+ .quad 0x2945ccf146e206eb+ .quad 0xbcbbdbf1812a8285+ .quad 0x270e0807d0bdd1fc+ .quad 0xb41b670b1bbda72d+ .quad 0x43aabe696b3bb69a++ // 2^0 * 6 * G++ .quad 0x499806b67b7d8ca4+ .quad 0x575be28427d22739+ .quad 0xbb085ce7204553b9+ .quad 0x38b64c41ae417884+ .quad 0x3a0ceeeb77157131+ .quad 0x9b27158900c8af88+ .quad 0x8065b668da59a736+ .quad 0x51e57bb6a2cc38bd+ .quad 0x85ac326702ea4b71+ .quad 0xbe70e00341a1bb01+ .quad 0x53e4a24b083bc144+ .quad 0x10b8e91a9f0d61e3++ // 2^0 * 7 * G++ .quad 0xba6f2c9aaa3221b1+ .quad 0x6ca021533bba23a7+ .quad 0x9dea764f92192c3a+ .quad 0x1d6edd5d2e5317e0+ .quad 0x6b1a5cd0944ea3bf+ .quad 0x7470353ab39dc0d2+ .quad 0x71b2528228542e49+ .quad 0x461bea69283c927e+ .quad 0xf1836dc801b8b3a2+ .quad 0xb3035f47053ea49a+ .quad 0x529c41ba5877adf3+ .quad 0x7a9fbb1c6a0f90a7++ // 2^0 * 8 * G++ .quad 0xe2a75dedf39234d9+ .quad 0x963d7680e1b558f9+ .quad 0x2c2741ac6e3c23fb+ .quad 0x3a9024a1320e01c3+ .quad 0x59b7596604dd3e8f+ .quad 0x6cb30377e288702c+ .quad 0xb1339c665ed9c323+ .quad 0x0915e76061bce52f+ .quad 0xe7c1f5d9c9a2911a+ .quad 0xb8a371788bcca7d7+ .quad 0x636412190eb62a32+ .quad 0x26907c5c2ecc4e95++ // 2^4 * 1 * G++ .quad 0x7ec851ca553e2df3+ .quad 0xa71284cba64878b3+ .quad 0xe6b5e4193288d1e7+ .quad 0x4cf210ec5a9a8883+ .quad 0x322d04a52d9021f6+ .quad 0xb9c19f3375c6bf9c+ .quad 0x587a3a4342d20b09+ .quad 0x143b1cf8aa64fe61+ .quad 0x9f867c7d968acaab+ .quad 0x5f54258e27092729+ .quad 0xd0a7d34bea180975+ .quad 0x21b546a3374126e1++ // 2^4 * 2 * G++ .quad 0xa94ff858a2888343+ .quad 0xce0ed4565313ed3c+ .quad 0xf55c3dcfb5bf34fa+ .quad 0x0a653ca5c9eab371+ .quad 0x490a7a45d185218f+ .quad 0x9a15377846049335+ .quad 0x0060ea09cc31e1f6+ .quad 0x7e041577f86ee965+ .quad 0x66b2a496ce5b67f3+ .quad 0xff5492d8bd569796+ .quad 0x503cec294a592cd0+ .quad 0x566943650813acb2++ // 2^4 * 3 * G++ .quad 0xb818db0c26620798+ .quad 0x5d5c31d9606e354a+ .quad 0x0982fa4f00a8cdc7+ .quad 0x17e12bcd4653e2d4+ .quad 0x5672f9eb1dabb69d+ .quad 0xba70b535afe853fc+ .quad 0x47ac0f752796d66d+ .quad 0x32a5351794117275+ .quad 0xd3a644a6df648437+ .quad 0x703b6559880fbfdd+ .quad 0xcb852540ad3a1aa5+ .quad 0x0900b3f78e4c6468++ // 2^4 * 4 * G++ .quad 0x0a851b9f679d651b+ .quad 0xe108cb61033342f2+ .quad 0xd601f57fe88b30a3+ .quad 0x371f3acaed2dd714+ .quad 0xed280fbec816ad31+ .quad 0x52d9595bd8e6efe3+ .quad 0x0fe71772f6c623f5+ .quad 0x4314030b051e293c+ .quad 0xd560005efbf0bcad+ .quad 0x8eb70f2ed1870c5e+ .quad 0x201f9033d084e6a0+ .quad 0x4c3a5ae1ce7b6670++ // 2^4 * 5 * G++ .quad 0x4138a434dcb8fa95+ .quad 0x870cf67d6c96840b+ .quad 0xde388574297be82c+ .quad 0x7c814db27262a55a+ .quad 0xbaf875e4c93da0dd+ .quad 0xb93282a771b9294d+ .quad 0x80d63fb7f4c6c460+ .quad 0x6de9c73dea66c181+ .quad 0x478904d5a04df8f2+ .quad 0xfafbae4ab10142d3+ .quad 0xf6c8ac63555d0998+ .quad 0x5aac4a412f90b104++ // 2^4 * 6 * G++ .quad 0xc64f326b3ac92908+ .quad 0x5551b282e663e1e0+ .quad 0x476b35f54a1a4b83+ .quad 0x1b9da3fe189f68c2+ .quad 0x603a0d0abd7f5134+ .quad 0x8089c932e1d3ae46+ .quad 0xdf2591398798bd63+ .quad 0x1c145cd274ba0235+ .quad 0x32e8386475f3d743+ .quad 0x365b8baf6ae5d9ef+ .quad 0x825238b6385b681e+ .quad 0x234929c1167d65e1++ // 2^4 * 7 * G++ .quad 0x984decaba077ade8+ .quad 0x383f77ad19eb389d+ .quad 0xc7ec6b7e2954d794+ .quad 0x59c77b3aeb7c3a7a+ .quad 0x48145cc21d099fcf+ .quad 0x4535c192cc28d7e5+ .quad 0x80e7c1e548247e01+ .quad 0x4a5f28743b2973ee+ .quad 0xd3add725225ccf62+ .quad 0x911a3381b2152c5d+ .quad 0xd8b39fad5b08f87d+ .quad 0x6f05606b4799fe3b++ // 2^4 * 8 * G++ .quad 0x9ffe9e92177ba962+ .quad 0x98aee71d0de5cae1+ .quad 0x3ff4ae942d831044+ .quad 0x714de12e58533ac8+ .quad 0x5b433149f91b6483+ .quad 0xadb5dc655a2cbf62+ .quad 0x87fa8412632827b3+ .quad 0x60895e91ab49f8d8+ .quad 0xe9ecf2ed0cf86c18+ .quad 0xb46d06120735dfd4+ .quad 0xbc9da09804b96be7+ .quad 0x73e2e62fd96dc26b++ // 2^8 * 1 * G++ .quad 0xed5b635449aa515e+ .quad 0xa865c49f0bc6823a+ .quad 0x850c1fe95b42d1c4+ .quad 0x30d76d6f03d315b9+ .quad 0x2eccdd0e632f9c1d+ .quad 0x51d0b69676893115+ .quad 0x52dfb76ba8637a58+ .quad 0x6dd37d49a00eef39+ .quad 0x6c4444172106e4c7+ .quad 0xfb53d680928d7f69+ .quad 0xb4739ea4694d3f26+ .quad 0x10c697112e864bb0++ // 2^8 * 2 * G++ .quad 0x6493c4277dbe5fde+ .quad 0x265d4fad19ad7ea2+ .quad 0x0e00dfc846304590+ .quad 0x25e61cabed66fe09+ .quad 0x0ca62aa08358c805+ .quad 0x6a3d4ae37a204247+ .quad 0x7464d3a63b11eddc+ .quad 0x03bf9baf550806ef+ .quad 0x3f13e128cc586604+ .quad 0x6f5873ecb459747e+ .quad 0xa0b63dedcc1268f5+ .quad 0x566d78634586e22c++ // 2^8 * 3 * G++ .quad 0x1637a49f9cc10834+ .quad 0xbc8e56d5a89bc451+ .quad 0x1cb5ec0f7f7fd2db+ .quad 0x33975bca5ecc35d9+ .quad 0xa1054285c65a2fd0+ .quad 0x6c64112af31667c3+ .quad 0x680ae240731aee58+ .quad 0x14fba5f34793b22a+ .quad 0x3cd746166985f7d4+ .quad 0x593e5e84c9c80057+ .quad 0x2fc3f2b67b61131e+ .quad 0x14829cea83fc526c++ // 2^8 * 4 * G++ .quad 0xff437b8497dd95c2+ .quad 0x6c744e30aa4eb5a7+ .quad 0x9e0c5d613c85e88b+ .quad 0x2fd9c71e5f758173+ .quad 0x21e70b2f4e71ecb8+ .quad 0xe656ddb940a477e3+ .quad 0xbf6556cece1d4f80+ .quad 0x05fc3bc4535d7b7e+ .quad 0x24b8b3ae52afdedd+ .quad 0x3495638ced3b30cf+ .quad 0x33a4bc83a9be8195+ .quad 0x373767475c651f04++ // 2^8 * 5 * G++ .quad 0x2fba99fd40d1add9+ .quad 0xb307166f96f4d027+ .quad 0x4363f05215f03bae+ .quad 0x1fbea56c3b18f999+ .quad 0x634095cb14246590+ .quad 0xef12144016c15535+ .quad 0x9e38140c8910bc60+ .quad 0x6bf5905730907c8c+ .quad 0x0fa778f1e1415b8a+ .quad 0x06409ff7bac3a77e+ .quad 0x6f52d7b89aa29a50+ .quad 0x02521cf67a635a56++ // 2^8 * 6 * G++ .quad 0x513fee0b0a9d5294+ .quad 0x8f98e75c0fdf5a66+ .quad 0xd4618688bfe107ce+ .quad 0x3fa00a7e71382ced+ .quad 0xb1146720772f5ee4+ .quad 0xe8f894b196079ace+ .quad 0x4af8224d00ac824a+ .quad 0x001753d9f7cd6cc4+ .quad 0x3c69232d963ddb34+ .quad 0x1dde87dab4973858+ .quad 0xaad7d1f9a091f285+ .quad 0x12b5fe2fa048edb6++ // 2^8 * 7 * G++ .quad 0x71f0fbc496fce34d+ .quad 0x73b9826badf35bed+ .quad 0xd2047261ff28c561+ .quad 0x749b76f96fb1206f+ .quad 0xdf2b7c26ad6f1e92+ .quad 0x4b66d323504b8913+ .quad 0x8c409dc0751c8bc3+ .quad 0x6f7e93c20796c7b8+ .quad 0x1f5af604aea6ae05+ .quad 0xc12351f1bee49c99+ .quad 0x61a808b5eeff6b66+ .quad 0x0fcec10f01e02151++ // 2^8 * 8 * G++ .quad 0x644d58a649fe1e44+ .quad 0x21fcaea231ad777e+ .quad 0x02441c5a887fd0d2+ .quad 0x4901aa7183c511f3+ .quad 0x3df2d29dc4244e45+ .quad 0x2b020e7493d8de0a+ .quad 0x6cc8067e820c214d+ .quad 0x413779166feab90a+ .quad 0x08b1b7548c1af8f0+ .quad 0xce0f7a7c246299b4+ .quad 0xf760b0f91e06d939+ .quad 0x41bb887b726d1213++ // 2^12 * 1 * G++ .quad 0x9267806c567c49d8+ .quad 0x066d04ccca791e6a+ .quad 0xa69f5645e3cc394b+ .quad 0x5c95b686a0788cd2+ .quad 0x97d980e0aa39f7d2+ .quad 0x35d0384252c6b51c+ .quad 0x7d43f49307cd55aa+ .quad 0x56bd36cfb78ac362+ .quad 0x2ac519c10d14a954+ .quad 0xeaf474b494b5fa90+ .quad 0xe6af8382a9f87a5a+ .quad 0x0dea6db1879be094++ // 2^12 * 2 * G++ .quad 0xaa66bf547344e5ab+ .quad 0xda1258888f1b4309+ .quad 0x5e87d2b3fd564b2f+ .quad 0x5b2c78885483b1dd+ .quad 0x15baeb74d6a8797a+ .quad 0x7ef55cf1fac41732+ .quad 0x29001f5a3c8b05c5+ .quad 0x0ad7cc8752eaccfb+ .quad 0x52151362793408cf+ .quad 0xeb0f170319963d94+ .quad 0xa833b2fa883d9466+ .quad 0x093a7fa775003c78++ // 2^12 * 3 * G++ .quad 0xe5107de63a16d7be+ .quad 0xa377ffdc9af332cf+ .quad 0x70d5bf18440b677f+ .quad 0x6a252b19a4a31403+ .quad 0xb8e9604460a91286+ .quad 0x7f3fd8047778d3de+ .quad 0x67d01e31bf8a5e2d+ .quad 0x7b038a06c27b653e+ .quad 0x9ed919d5d36990f3+ .quad 0x5213aebbdb4eb9f2+ .quad 0xc708ea054cb99135+ .quad 0x58ded57f72260e56++ // 2^12 * 4 * G++ .quad 0x78e79dade9413d77+ .quad 0xf257f9d59729e67d+ .quad 0x59db910ee37aa7e6+ .quad 0x6aa11b5bbb9e039c+ .quad 0xda6d53265b0fd48b+ .quad 0x8960823193bfa988+ .quad 0xd78ac93261d57e28+ .quad 0x79f2942d3a5c8143+ .quad 0x97da2f25b6c88de9+ .quad 0x251ba7eaacf20169+ .quad 0x09b44f87ef4eb4e4+ .quad 0x7d90ab1bbc6a7da5++ // 2^12 * 5 * G++ .quad 0x9acca683a7016bfe+ .quad 0x90505f4df2c50b6d+ .quad 0x6b610d5fcce435aa+ .quad 0x19a10d446198ff96+ .quad 0x1a07a3f496b3c397+ .quad 0x11ceaa188f4e2532+ .quad 0x7d9498d5a7751bf0+ .quad 0x19ed161f508dd8a0+ .quad 0x560a2cd687dce6ca+ .quad 0x7f3568c48664cf4d+ .quad 0x8741e95222803a38+ .quad 0x483bdab1595653fc++ // 2^12 * 6 * G++ .quad 0xfa780f148734fa49+ .quad 0x106f0b70360534e0+ .quad 0x2210776fe3e307bd+ .quad 0x3286c109dde6a0fe+ .quad 0xd6cf4d0ab4da80f6+ .quad 0x82483e45f8307fe0+ .quad 0x05005269ae6f9da4+ .quad 0x1c7052909cf7877a+ .quad 0x32ee7de2874e98d4+ .quad 0x14c362e9b97e0c60+ .quad 0x5781dcde6a60a38a+ .quad 0x217dd5eaaa7aa840++ // 2^12 * 7 * G++ .quad 0x9db7c4d0248e1eb0+ .quad 0xe07697e14d74bf52+ .quad 0x1e6a9b173c562354+ .quad 0x7fa7c21f795a4965+ .quad 0x8bdf1fb9be8c0ec8+ .quad 0x00bae7f8e30a0282+ .quad 0x4963991dad6c4f6c+ .quad 0x07058a6e5df6f60a+ .quad 0xe9eb02c4db31f67f+ .quad 0xed25fd8910bcfb2b+ .quad 0x46c8131f5c5cddb4+ .quad 0x33b21c13a0cb9bce++ // 2^12 * 8 * G++ .quad 0x360692f8087d8e31+ .quad 0xf4dcc637d27163f7+ .quad 0x25a4e62065ea5963+ .quad 0x659bf72e5ac160d9+ .quad 0x9aafb9b05ee38c5b+ .quad 0xbf9d2d4e071a13c7+ .quad 0x8eee6e6de933290a+ .quad 0x1c3bab17ae109717+ .quad 0x1c9ab216c7cab7b0+ .quad 0x7d65d37407bbc3cc+ .quad 0x52744750504a58d5+ .quad 0x09f2606b131a2990++ // 2^16 * 1 * G++ .quad 0x40e87d44744346be+ .quad 0x1d48dad415b52b25+ .quad 0x7c3a8a18a13b603e+ .quad 0x4eb728c12fcdbdf7+ .quad 0x7e234c597c6691ae+ .quad 0x64889d3d0a85b4c8+ .quad 0xdae2c90c354afae7+ .quad 0x0a871e070c6a9e1d+ .quad 0x3301b5994bbc8989+ .quad 0x736bae3a5bdd4260+ .quad 0x0d61ade219d59e3c+ .quad 0x3ee7300f2685d464++ // 2^16 * 2 * G++ .quad 0xf5d255e49e7dd6b7+ .quad 0x8016115c610b1eac+ .quad 0x3c99975d92e187ca+ .quad 0x13815762979125c2+ .quad 0x43fa7947841e7518+ .quad 0xe5c6fa59639c46d7+ .quad 0xa1065e1de3052b74+ .quad 0x7d47c6a2cfb89030+ .quad 0x3fdad0148ef0d6e0+ .quad 0x9d3e749a91546f3c+ .quad 0x71ec621026bb8157+ .quad 0x148cf58d34c9ec80++ // 2^16 * 3 * G++ .quad 0x46a492f67934f027+ .quad 0x469984bef6840aa9+ .quad 0x5ca1bc2a89611854+ .quad 0x3ff2fa1ebd5dbbd4+ .quad 0xe2572f7d9ae4756d+ .quad 0x56c345bb88f3487f+ .quad 0x9fd10b6d6960a88d+ .quad 0x278febad4eaea1b9+ .quad 0xb1aa681f8c933966+ .quad 0x8c21949c20290c98+ .quad 0x39115291219d3c52+ .quad 0x4104dd02fe9c677b++ // 2^16 * 4 * G++ .quad 0x72b2bf5e1124422a+ .quad 0xa1fa0c3398a33ab5+ .quad 0x94cb6101fa52b666+ .quad 0x2c863b00afaf53d5+ .quad 0x81214e06db096ab8+ .quad 0x21a8b6c90ce44f35+ .quad 0x6524c12a409e2af5+ .quad 0x0165b5a48efca481+ .quad 0xf190a474a0846a76+ .quad 0x12eff984cd2f7cc0+ .quad 0x695e290658aa2b8f+ .quad 0x591b67d9bffec8b8++ // 2^16 * 5 * G++ .quad 0x312f0d1c80b49bfa+ .quad 0x5979515eabf3ec8a+ .quad 0x727033c09ef01c88+ .quad 0x3de02ec7ca8f7bcb+ .quad 0x99b9b3719f18b55d+ .quad 0xe465e5faa18c641e+ .quad 0x61081136c29f05ed+ .quad 0x489b4f867030128b+ .quad 0xd232102d3aeb92ef+ .quad 0xe16253b46116a861+ .quad 0x3d7eabe7190baa24+ .quad 0x49f5fbba496cbebf++ // 2^16 * 6 * G++ .quad 0x30949a108a5bcfd4+ .quad 0xdc40dd70bc6473eb+ .quad 0x92c294c1307c0d1c+ .quad 0x5604a86dcbfa6e74+ .quad 0x155d628c1e9c572e+ .quad 0x8a4d86acc5884741+ .quad 0x91a352f6515763eb+ .quad 0x06a1a6c28867515b+ .quad 0x7288d1d47c1764b6+ .quad 0x72541140e0418b51+ .quad 0x9f031a6018acf6d1+ .quad 0x20989e89fe2742c6++ // 2^16 * 7 * G++ .quad 0x499777fd3a2dcc7f+ .quad 0x32857c2ca54fd892+ .quad 0xa279d864d207e3a0+ .quad 0x0403ed1d0ca67e29+ .quad 0x1674278b85eaec2e+ .quad 0x5621dc077acb2bdf+ .quad 0x640a4c1661cbf45a+ .quad 0x730b9950f70595d3+ .quad 0xc94b2d35874ec552+ .quad 0xc5e6c8cf98246f8d+ .quad 0xf7cb46fa16c035ce+ .quad 0x5bd7454308303dcc++ // 2^16 * 8 * G++ .quad 0x7f9ad19528b24cc2+ .quad 0x7f6b54656335c181+ .quad 0x66b8b66e4fc07236+ .quad 0x133a78007380ad83+ .quad 0x85c4932115e7792a+ .quad 0xc64c89a2bdcdddc9+ .quad 0x9d1e3da8ada3d762+ .quad 0x5bb7db123067f82c+ .quad 0x0961f467c6ca62be+ .quad 0x04ec21d6211952ee+ .quad 0x182360779bd54770+ .quad 0x740dca6d58f0e0d2++ // 2^20 * 1 * G++ .quad 0x50b70bf5d3f0af0b+ .quad 0x4feaf48ae32e71f7+ .quad 0x60e84ed3a55bbd34+ .quad 0x00ed489b3f50d1ed+ .quad 0x3906c72aed261ae5+ .quad 0x9ab68fd988e100f7+ .quad 0xf5e9059af3360197+ .quad 0x0e53dc78bf2b6d47+ .quad 0xb90829bf7971877a+ .quad 0x5e4444636d17e631+ .quad 0x4d05c52e18276893+ .quad 0x27632d9a5a4a4af5++ // 2^20 * 2 * G++ .quad 0xd11ff05154b260ce+ .quad 0xd86dc38e72f95270+ .quad 0x601fcd0d267cc138+ .quad 0x2b67916429e90ccd+ .quad 0xa98285d187eaffdb+ .quad 0xa5b4fbbbd8d0a864+ .quad 0xb658f27f022663f7+ .quad 0x3bbc2b22d99ce282+ .quad 0xb917c952583c0a58+ .quad 0x653ff9b80fe4c6f3+ .quad 0x9b0da7d7bcdf3c0c+ .quad 0x43a0eeb6ab54d60e++ // 2^20 * 3 * G++ .quad 0x396966a46d4a5487+ .quad 0xf811a18aac2bb3ba+ .quad 0x66e4685b5628b26b+ .quad 0x70a477029d929b92+ .quad 0x3ac6322357875fe8+ .quad 0xd9d4f4ecf5fbcb8f+ .quad 0x8dee8493382bb620+ .quad 0x50c5eaa14c799fdc+ .quad 0xdd0edc8bd6f2fb3c+ .quad 0x54c63aa79cc7b7a0+ .quad 0xae0b032b2c8d9f1a+ .quad 0x6f9ce107602967fb++ // 2^20 * 4 * G++ .quad 0xad1054b1cde1c22a+ .quad 0xc4a8e90248eb32df+ .quad 0x5f3e7b33accdc0ea+ .quad 0x72364713fc79963e+ .quad 0x139693063520e0b5+ .quad 0x437fcf7c88ea03fe+ .quad 0xf7d4c40bd3c959bc+ .quad 0x699154d1f893ded9+ .quad 0x315d5c75b4b27526+ .quad 0xcccb842d0236daa5+ .quad 0x22f0c8a3345fee8e+ .quad 0x73975a617d39dbed++ // 2^20 * 5 * G++ .quad 0xe4024df96375da10+ .quad 0x78d3251a1830c870+ .quad 0x902b1948658cd91c+ .quad 0x7e18b10b29b7438a+ .quad 0x6f37f392f4433e46+ .quad 0x0e19b9a11f566b18+ .quad 0x220fb78a1fd1d662+ .quad 0x362a4258a381c94d+ .quad 0x9071d9132b6beb2f+ .quad 0x0f26e9ad28418247+ .quad 0xeab91ec9bdec925d+ .quad 0x4be65bc8f48af2de++ // 2^20 * 6 * G++ .quad 0x78487feba36e7028+ .quad 0x5f3f13001dd8ce34+ .quad 0x934fb12d4b30c489+ .quad 0x056c244d397f0a2b+ .quad 0x1d50fba257c26234+ .quad 0x7bd4823adeb0678b+ .quad 0xc2b0dc6ea6538af5+ .quad 0x5665eec6351da73e+ .quad 0xdb3ee00943bfb210+ .quad 0x4972018720800ac2+ .quad 0x26ab5d6173bd8667+ .quad 0x20b209c2ab204938++ // 2^20 * 7 * G++ .quad 0x549e342ac07fb34b+ .quad 0x02d8220821373d93+ .quad 0xbc262d70acd1f567+ .quad 0x7a92c9fdfbcac784+ .quad 0x1fcca94516bd3289+ .quad 0x448d65aa41420428+ .quad 0x59c3b7b216a55d62+ .quad 0x49992cc64e612cd8+ .quad 0x65bd1bea70f801de+ .quad 0x1befb7c0fe49e28a+ .quad 0xa86306cdb1b2ae4a+ .quad 0x3b7ac0cd265c2a09++ // 2^20 * 8 * G++ .quad 0x822bee438c01bcec+ .quad 0x530cb525c0fbc73b+ .quad 0x48519034c1953fe9+ .quad 0x265cc261e09a0f5b+ .quad 0xf0d54e4f22ed39a7+ .quad 0xa2aae91e5608150a+ .quad 0xf421b2e9eddae875+ .quad 0x31bc531d6b7de992+ .quad 0xdf3d134da980f971+ .quad 0x7a4fb8d1221a22a7+ .quad 0x3df7d42035aad6d8+ .quad 0x2a14edcc6a1a125e++ // 2^24 * 1 * G++ .quad 0xdf48ee0752cfce4e+ .quad 0xc3fffaf306ec08b7+ .quad 0x05710b2ab95459c4+ .quad 0x161d25fa963ea38d+ .quad 0x231a8c570478433c+ .quad 0xb7b5270ec281439d+ .quad 0xdbaa99eae3d9079f+ .quad 0x2c03f5256c2b03d9+ .quad 0x790f18757b53a47d+ .quad 0x307b0130cf0c5879+ .quad 0x31903d77257ef7f9+ .quad 0x699468bdbd96bbaf++ // 2^24 * 2 * G++ .quad 0xbd1f2f46f4dafecf+ .quad 0x7cef0114a47fd6f7+ .quad 0xd31ffdda4a47b37f+ .quad 0x525219a473905785+ .quad 0xd8dd3de66aa91948+ .quad 0x485064c22fc0d2cc+ .quad 0x9b48246634fdea2f+ .quad 0x293e1c4e6c4a2e3a+ .quad 0x376e134b925112e1+ .quad 0x703778b5dca15da0+ .quad 0xb04589af461c3111+ .quad 0x5b605c447f032823++ // 2^24 * 3 * G++ .quad 0xb965805920c47c89+ .quad 0xe7f0100c923b8fcc+ .quad 0x0001256502e2ef77+ .quad 0x24a76dcea8aeb3ee+ .quad 0x3be9fec6f0e7f04c+ .quad 0x866a579e75e34962+ .quad 0x5542ef161e1de61a+ .quad 0x2f12fef4cc5abdd5+ .quad 0x0a4522b2dfc0c740+ .quad 0x10d06e7f40c9a407+ .quad 0xc6cf144178cff668+ .quad 0x5e607b2518a43790++ // 2^24 * 4 * G++ .quad 0x58b31d8f6cdf1818+ .quad 0x35cfa74fc36258a2+ .quad 0xe1b3ff4f66e61d6e+ .quad 0x5067acab6ccdd5f7+ .quad 0xa02c431ca596cf14+ .quad 0xe3c42d40aed3e400+ .quad 0xd24526802e0f26db+ .quad 0x201f33139e457068+ .quad 0xfd527f6b08039d51+ .quad 0x18b14964017c0006+ .quad 0xd5220eb02e25a4a8+ .quad 0x397cba8862460375++ // 2^24 * 5 * G++ .quad 0x30c13093f05959b2+ .quad 0xe23aa18de9a97976+ .quad 0x222fd491721d5e26+ .quad 0x2339d320766e6c3a+ .quad 0x7815c3fbc81379e7+ .quad 0xa6619420dde12af1+ .quad 0xffa9c0f885a8fdd5+ .quad 0x771b4022c1e1c252+ .quad 0xd87dd986513a2fa7+ .quad 0xf5ac9b71f9d4cf08+ .quad 0xd06bc31b1ea283b3+ .quad 0x331a189219971a76++ // 2^24 * 6 * G++ .quad 0xf5166f45fb4f80c6+ .quad 0x9c36c7de61c775cf+ .quad 0xe3d4e81b9041d91c+ .quad 0x31167c6b83bdfe21+ .quad 0x26512f3a9d7572af+ .quad 0x5bcbe28868074a9e+ .quad 0x84edc1c11180f7c4+ .quad 0x1ac9619ff649a67b+ .quad 0xf22b3842524b1068+ .quad 0x5068343bee9ce987+ .quad 0xfc9d71844a6250c8+ .quad 0x612436341f08b111++ // 2^24 * 7 * G++ .quad 0xd99d41db874e898d+ .quad 0x09fea5f16c07dc20+ .quad 0x793d2c67d00f9bbc+ .quad 0x46ebe2309e5eff40+ .quad 0x8b6349e31a2d2638+ .quad 0x9ddfb7009bd3fd35+ .quad 0x7f8bf1b8a3a06ba4+ .quad 0x1522aa3178d90445+ .quad 0x2c382f5369614938+ .quad 0xdafe409ab72d6d10+ .quad 0xe8c83391b646f227+ .quad 0x45fe70f50524306c++ // 2^24 * 8 * G++ .quad 0xda4875a6960c0b8c+ .quad 0x5b68d076ef0e2f20+ .quad 0x07fb51cf3d0b8fd4+ .quad 0x428d1623a0e392d4+ .quad 0x62f24920c8951491+ .quad 0x05f007c83f630ca2+ .quad 0x6fbb45d2f5c9d4b8+ .quad 0x16619f6db57a2245+ .quad 0x084f4a4401a308fd+ .quad 0xa82219c376a5caac+ .quad 0xdeb8de4643d1bc7d+ .quad 0x1d81592d60bd38c6++ // 2^28 * 1 * G++ .quad 0xd833d7beec2a4c38+ .quad 0x2c9162830acc20ed+ .quad 0xe93a47aa92df7581+ .quad 0x702d67a3333c4a81+ .quad 0x3a4a369a2f89c8a1+ .quad 0x63137a1d7c8de80d+ .quad 0xbcac008a78eda015+ .quad 0x2cb8b3a5b483b03f+ .quad 0x36e417cbcb1b90a1+ .quad 0x33b3ddaa7f11794e+ .quad 0x3f510808885bc607+ .quad 0x24141dc0e6a8020d++ // 2^28 * 2 * G++ .quad 0x59f73c773fefee9d+ .quad 0xb3f1ef89c1cf989d+ .quad 0xe35dfb42e02e545f+ .quad 0x5766120b47a1b47c+ .quad 0x91925dccbd83157d+ .quad 0x3ca1205322cc8094+ .quad 0x28e57f183f90d6e4+ .quad 0x1a4714cede2e767b+ .quad 0xdb20ba0fb8b6b7ff+ .quad 0xb732c3b677511fa1+ .quad 0xa92b51c099f02d89+ .quad 0x4f3875ad489ca5f1++ // 2^28 * 3 * G++ .quad 0xc7fc762f4932ab22+ .quad 0x7ac0edf72f4c3c1b+ .quad 0x5f6b55aa9aa895e8+ .quad 0x3680274dad0a0081+ .quad 0x79ed13f6ee73eec0+ .quad 0xa5c6526d69110bb1+ .quad 0xe48928c38603860c+ .quad 0x722a1446fd7059f5+ .quad 0xd0959fe9a8cf8819+ .quad 0xd0a995508475a99c+ .quad 0x6eac173320b09cc5+ .quad 0x628ecf04331b1095++ // 2^28 * 4 * G++ .quad 0x98bcb118a9d0ddbc+ .quad 0xee449e3408b4802b+ .quad 0x87089226b8a6b104+ .quad 0x685f349a45c7915d+ .quad 0x9b41acf85c74ccf1+ .quad 0xb673318108265251+ .quad 0x99c92aed11adb147+ .quad 0x7a47d70d34ecb40f+ .quad 0x60a0c4cbcc43a4f5+ .quad 0x775c66ca3677bea9+ .quad 0xa17aa1752ff8f5ed+ .quad 0x11ded9020e01fdc0++ // 2^28 * 5 * G++ .quad 0x890e7809caefe704+ .quad 0x8728296de30e8c6c+ .quad 0x4c5cd2a392aeb1c9+ .quad 0x194263d15771531f+ .quad 0x471f95b03bea93b7+ .quad 0x0552d7d43313abd3+ .quad 0xbd9370e2e17e3f7b+ .quad 0x7b120f1db20e5bec+ .quad 0x17d2fb3d86502d7a+ .quad 0xb564d84450a69352+ .quad 0x7da962c8a60ed75d+ .quad 0x00d0f85b318736aa++ // 2^28 * 6 * G++ .quad 0x978b142e777c84fd+ .quad 0xf402644705a8c062+ .quad 0xa67ad51be7e612c7+ .quad 0x2f7b459698dd6a33+ .quad 0xa6753c1efd7621c1+ .quad 0x69c0b4a7445671f5+ .quad 0x971f527405b23c11+ .quad 0x387bc74851a8c7cd+ .quad 0x81894b4d4a52a9a8+ .quad 0xadd93e12f6b8832f+ .quad 0x184d8548b61bd638+ .quad 0x3f1c62dbd6c9f6cd++ // 2^28 * 7 * G++ .quad 0x2e8f1f0091910c1f+ .quad 0xa4df4fe0bff2e12c+ .quad 0x60c6560aee927438+ .quad 0x6338283facefc8fa+ .quad 0x3fad3e40148f693d+ .quad 0x052656e194eb9a72+ .quad 0x2f4dcbfd184f4e2f+ .quad 0x406f8db1c482e18b+ .quad 0x9e630d2c7f191ee4+ .quad 0x4fbf8301bc3ff670+ .quad 0x787d8e4e7afb73c4+ .quad 0x50d83d5be8f58fa5++ // 2^28 * 8 * G++ .quad 0x85683916c11a1897+ .quad 0x2d69a4efe506d008+ .quad 0x39af1378f664bd01+ .quad 0x65942131361517c6+ .quad 0xc0accf90b4d3b66d+ .quad 0xa7059de561732e60+ .quad 0x033d1f7870c6b0ba+ .quad 0x584161cd26d946e4+ .quad 0xbbf2b1a072d27ca2+ .quad 0xbf393c59fbdec704+ .quad 0xe98dbbcee262b81e+ .quad 0x02eebd0b3029b589++ // 2^32 * 1 * G++ .quad 0x61368756a60dac5f+ .quad 0x17e02f6aebabdc57+ .quad 0x7f193f2d4cce0f7d+ .quad 0x20234a7789ecdcf0+ .quad 0x8765b69f7b85c5e8+ .quad 0x6ff0678bd168bab2+ .quad 0x3a70e77c1d330f9b+ .quad 0x3a5f6d51b0af8e7c+ .quad 0x76d20db67178b252+ .quad 0x071c34f9d51ed160+ .quad 0xf62a4a20b3e41170+ .quad 0x7cd682353cffe366++ // 2^32 * 2 * G++ .quad 0x0be1a45bd887fab6+ .quad 0x2a846a32ba403b6e+ .quad 0xd9921012e96e6000+ .quad 0x2838c8863bdc0943+ .quad 0xa665cd6068acf4f3+ .quad 0x42d92d183cd7e3d3+ .quad 0x5759389d336025d9+ .quad 0x3ef0253b2b2cd8ff+ .quad 0xd16bb0cf4a465030+ .quad 0xfa496b4115c577ab+ .quad 0x82cfae8af4ab419d+ .quad 0x21dcb8a606a82812++ // 2^32 * 3 * G++ .quad 0x5c6004468c9d9fc8+ .quad 0x2540096ed42aa3cb+ .quad 0x125b4d4c12ee2f9c+ .quad 0x0bc3d08194a31dab+ .quad 0x9a8d00fabe7731ba+ .quad 0x8203607e629e1889+ .quad 0xb2cc023743f3d97f+ .quad 0x5d840dbf6c6f678b+ .quad 0x706e380d309fe18b+ .quad 0x6eb02da6b9e165c7+ .quad 0x57bbba997dae20ab+ .quad 0x3a4276232ac196dd++ // 2^32 * 4 * G++ .quad 0x4b42432c8a7084fa+ .quad 0x898a19e3dfb9e545+ .quad 0xbe9f00219c58e45d+ .quad 0x1ff177cea16debd1+ .quad 0x3bf8c172db447ecb+ .quad 0x5fcfc41fc6282dbd+ .quad 0x80acffc075aa15fe+ .quad 0x0770c9e824e1a9f9+ .quad 0xcf61d99a45b5b5fd+ .quad 0x860984e91b3a7924+ .quad 0xe7300919303e3e89+ .quad 0x39f264fd41500b1e++ // 2^32 * 5 * G++ .quad 0xa7ad3417dbe7e29c+ .quad 0xbd94376a2b9c139c+ .quad 0xa0e91b8e93597ba9+ .quad 0x1712d73468889840+ .quad 0xd19b4aabfe097be1+ .quad 0xa46dfce1dfe01929+ .quad 0xc3c908942ca6f1ff+ .quad 0x65c621272c35f14e+ .quad 0xe72b89f8ce3193dd+ .quad 0x4d103356a125c0bb+ .quad 0x0419a93d2e1cfe83+ .quad 0x22f9800ab19ce272++ // 2^32 * 6 * G++ .quad 0x605a368a3e9ef8cb+ .quad 0xe3e9c022a5504715+ .quad 0x553d48b05f24248f+ .quad 0x13f416cd647626e5+ .quad 0x42029fdd9a6efdac+ .quad 0xb912cebe34a54941+ .quad 0x640f64b987bdf37b+ .quad 0x4171a4d38598cab4+ .quad 0xfa2758aa99c94c8c+ .quad 0x23006f6fb000b807+ .quad 0xfbd291ddadda5392+ .quad 0x508214fa574bd1ab++ // 2^32 * 7 * G++ .quad 0xc20269153ed6fe4b+ .quad 0xa65a6739511d77c4+ .quad 0xcbde26462c14af94+ .quad 0x22f960ec6faba74b+ .quad 0x461a15bb53d003d6+ .quad 0xb2102888bcf3c965+ .quad 0x27c576756c683a5a+ .quad 0x3a7758a4c86cb447+ .quad 0x548111f693ae5076+ .quad 0x1dae21df1dfd54a6+ .quad 0x12248c90f3115e65+ .quad 0x5d9fd15f8de7f494++ // 2^32 * 8 * G++ .quad 0x031408d36d63727f+ .quad 0x6a379aefd7c7b533+ .quad 0xa9e18fc5ccaee24b+ .quad 0x332f35914f8fbed3+ .quad 0x3f244d2aeed7521e+ .quad 0x8e3a9028432e9615+ .quad 0xe164ba772e9c16d4+ .quad 0x3bc187fa47eb98d8+ .quad 0x6d470115ea86c20c+ .quad 0x998ab7cb6c46d125+ .quad 0xd77832b53a660188+ .quad 0x450d81ce906fba03++ // 2^36 * 1 * G++ .quad 0xf8ae4d2ad8453902+ .quad 0x7018058ee8db2d1d+ .quad 0xaab3995fc7d2c11e+ .quad 0x53b16d2324ccca79+ .quad 0x23264d66b2cae0b5+ .quad 0x7dbaed33ebca6576+ .quad 0x030ebed6f0d24ac8+ .quad 0x2a887f78f7635510+ .quad 0x2a23b9e75c012d4f+ .quad 0x0c974651cae1f2ea+ .quad 0x2fb63273675d70ca+ .quad 0x0ba7250b864403f5++ // 2^36 * 2 * G++ .quad 0xbb0d18fd029c6421+ .quad 0xbc2d142189298f02+ .quad 0x8347f8e68b250e96+ .quad 0x7b9f2fe8032d71c9+ .quad 0xdd63589386f86d9c+ .quad 0x61699176e13a85a4+ .quad 0x2e5111954eaa7d57+ .quad 0x32c21b57fb60bdfb+ .quad 0xd87823cd319e0780+ .quad 0xefc4cfc1897775c5+ .quad 0x4854fb129a0ab3f7+ .quad 0x12c49d417238c371++ // 2^36 * 3 * G++ .quad 0x0950b533ffe83769+ .quad 0x21861c1d8e1d6bd1+ .quad 0xf022d8381302e510+ .quad 0x2509200c6391cab4+ .quad 0x09b3a01783799542+ .quad 0x626dd08faad5ee3f+ .quad 0xba00bceeeb70149f+ .quad 0x1421b246a0a444c9+ .quad 0x4aa43a8e8c24a7c7+ .quad 0x04c1f540d8f05ef5+ .quad 0xadba5e0c0b3eb9dc+ .quad 0x2ab5504448a49ce3++ // 2^36 * 4 * G++ .quad 0x2ed227266f0f5dec+ .quad 0x9824ee415ed50824+ .quad 0x807bec7c9468d415+ .quad 0x7093bae1b521e23f+ .quad 0xdc07ac631c5d3afa+ .quad 0x58615171f9df8c6c+ .quad 0x72a079d89d73e2b0+ .quad 0x7301f4ceb4eae15d+ .quad 0x6409e759d6722c41+ .quad 0xa674e1cf72bf729b+ .quad 0xbc0a24eb3c21e569+ .quad 0x390167d24ebacb23++ // 2^36 * 5 * G++ .quad 0x27f58e3bba353f1c+ .quad 0x4c47764dbf6a4361+ .quad 0xafbbc4e56e562650+ .quad 0x07db2ee6aae1a45d+ .quad 0xd7bb054ba2f2120b+ .quad 0xe2b9ceaeb10589b7+ .quad 0x3fe8bac8f3c0edbe+ .quad 0x4cbd40767112cb69+ .quad 0x0b603cc029c58176+ .quad 0x5988e3825cb15d61+ .quad 0x2bb61413dcf0ad8d+ .quad 0x7b8eec6c74183287++ // 2^36 * 6 * G++ .quad 0xe4ca40782cd27cb0+ .quad 0xdaf9c323fbe967bd+ .quad 0xb29bd34a8ad41e9e+ .quad 0x72810497626ede4d+ .quad 0x32fee570fc386b73+ .quad 0xda8b0141da3a8cc7+ .quad 0x975ffd0ac8968359+ .quad 0x6ee809a1b132a855+ .quad 0x9444bb31fcfd863a+ .quad 0x2fe3690a3e4e48c5+ .quad 0xdc29c867d088fa25+ .quad 0x13bd1e38d173292e++ // 2^36 * 7 * G++ .quad 0xd32b4cd8696149b5+ .quad 0xe55937d781d8aab7+ .quad 0x0bcb2127ae122b94+ .quad 0x41e86fcfb14099b0+ .quad 0x223fb5cf1dfac521+ .quad 0x325c25316f554450+ .quad 0x030b98d7659177ac+ .quad 0x1ed018b64f88a4bd+ .quad 0x3630dfa1b802a6b0+ .quad 0x880f874742ad3bd5+ .quad 0x0af90d6ceec5a4d4+ .quad 0x746a247a37cdc5d9++ // 2^36 * 8 * G++ .quad 0xd531b8bd2b7b9af6+ .quad 0x5005093537fc5b51+ .quad 0x232fcf25c593546d+ .quad 0x20a365142bb40f49+ .quad 0x6eccd85278d941ed+ .quad 0x2254ae83d22f7843+ .quad 0xc522d02e7bbfcdb7+ .quad 0x681e3351bff0e4e2+ .quad 0x8b64b59d83034f45+ .quad 0x2f8b71f21fa20efb+ .quad 0x69249495ba6550e4+ .quad 0x539ef98e45d5472b++ // 2^40 * 1 * G++ .quad 0x6e7bb6a1a6205275+ .quad 0xaa4f21d7413c8e83+ .quad 0x6f56d155e88f5cb2+ .quad 0x2de25d4ba6345be1+ .quad 0xd074d8961cae743f+ .quad 0xf86d18f5ee1c63ed+ .quad 0x97bdc55be7f4ed29+ .quad 0x4cbad279663ab108+ .quad 0x80d19024a0d71fcd+ .quad 0xc525c20afb288af8+ .quad 0xb1a3974b5f3a6419+ .quad 0x7d7fbcefe2007233++ // 2^40 * 2 * G++ .quad 0xfaef1e6a266b2801+ .quad 0x866c68c4d5739f16+ .quad 0xf68a2fbc1b03762c+ .quad 0x5975435e87b75a8d+ .quad 0xcd7c5dc5f3c29094+ .quad 0xc781a29a2a9105ab+ .quad 0x80c61d36421c3058+ .quad 0x4f9cd196dcd8d4d7+ .quad 0x199297d86a7b3768+ .quad 0xd0d058241ad17a63+ .quad 0xba029cad5c1c0c17+ .quad 0x7ccdd084387a0307++ // 2^40 * 3 * G++ .quad 0xdca6422c6d260417+ .quad 0xae153d50948240bd+ .quad 0xa9c0c1b4fb68c677+ .quad 0x428bd0ed61d0cf53+ .quad 0x9b0c84186760cc93+ .quad 0xcdae007a1ab32a99+ .quad 0xa88dec86620bda18+ .quad 0x3593ca848190ca44+ .quad 0x9213189a5e849aa7+ .quad 0xd4d8c33565d8facd+ .quad 0x8c52545b53fdbbd1+ .quad 0x27398308da2d63e6++ // 2^40 * 4 * G++ .quad 0x42c38d28435ed413+ .quad 0xbd50f3603278ccc9+ .quad 0xbb07ab1a79da03ef+ .quad 0x269597aebe8c3355+ .quad 0xb9a10e4c0a702453+ .quad 0x0fa25866d57d1bde+ .quad 0xffb9d9b5cd27daf7+ .quad 0x572c2945492c33fd+ .quad 0xc77fc745d6cd30be+ .quad 0xe4dfe8d3e3baaefb+ .quad 0xa22c8830aa5dda0c+ .quad 0x7f985498c05bca80++ // 2^40 * 5 * G++ .quad 0x3849ce889f0be117+ .quad 0x8005ad1b7b54a288+ .quad 0x3da3c39f23fc921c+ .quad 0x76c2ec470a31f304+ .quad 0xd35615520fbf6363+ .quad 0x08045a45cf4dfba6+ .quad 0xeec24fbc873fa0c2+ .quad 0x30f2653cd69b12e7+ .quad 0x8a08c938aac10c85+ .quad 0x46179b60db276bcb+ .quad 0xa920c01e0e6fac70+ .quad 0x2f1273f1596473da++ // 2^40 * 6 * G++ .quad 0x4739fc7c8ae01e11+ .quad 0xfd5274904a6aab9f+ .quad 0x41d98a8287728f2e+ .quad 0x5d9e572ad85b69f2+ .quad 0x30488bd755a70bc0+ .quad 0x06d6b5a4f1d442e7+ .quad 0xead1a69ebc596162+ .quad 0x38ac1997edc5f784+ .quad 0x0666b517a751b13b+ .quad 0x747d06867e9b858c+ .quad 0xacacc011454dde49+ .quad 0x22dfcd9cbfe9e69c++ // 2^40 * 7 * G++ .quad 0x8ddbd2e0c30d0cd9+ .quad 0xad8e665facbb4333+ .quad 0x8f6b258c322a961f+ .quad 0x6b2916c05448c1c7+ .quad 0x56ec59b4103be0a1+ .quad 0x2ee3baecd259f969+ .quad 0x797cb29413f5cd32+ .quad 0x0fe9877824cde472+ .quad 0x7edb34d10aba913b+ .quad 0x4ea3cd822e6dac0e+ .quad 0x66083dff6578f815+ .quad 0x4c303f307ff00a17++ // 2^40 * 8 * G++ .quad 0xd30a3bd617b28c85+ .quad 0xc5d377b739773bea+ .quad 0xc6c6e78c1e6a5cbf+ .quad 0x0d61b8f78b2ab7c4+ .quad 0x29fc03580dd94500+ .quad 0xecd27aa46fbbec93+ .quad 0x130a155fc2e2a7f8+ .quad 0x416b151ab706a1d5+ .quad 0x56a8d7efe9c136b0+ .quad 0xbd07e5cd58e44b20+ .quad 0xafe62fda1b57e0ab+ .quad 0x191a2af74277e8d2++ // 2^44 * 1 * G++ .quad 0xd550095bab6f4985+ .quad 0x04f4cd5b4fbfaf1a+ .quad 0x9d8e2ed12a0c7540+ .quad 0x2bc24e04b2212286+ .quad 0x09d4b60b2fe09a14+ .quad 0xc384f0afdbb1747e+ .quad 0x58e2ea8978b5fd6e+ .quad 0x519ef577b5e09b0a+ .quad 0x1863d7d91124cca9+ .quad 0x7ac08145b88a708e+ .quad 0x2bcd7309857031f5+ .quad 0x62337a6e8ab8fae5++ // 2^44 * 2 * G++ .quad 0x4bcef17f06ffca16+ .quad 0xde06e1db692ae16a+ .quad 0x0753702d614f42b0+ .quad 0x5f6041b45b9212d0+ .quad 0xd1ab324e1b3a1273+ .quad 0x18947cf181055340+ .quad 0x3b5d9567a98c196e+ .quad 0x7fa00425802e1e68+ .quad 0x7d531574028c2705+ .quad 0x80317d69db0d75fe+ .quad 0x30fface8ef8c8ddd+ .quad 0x7e9de97bb6c3e998++ // 2^44 * 3 * G++ .quad 0x1558967b9e6585a3+ .quad 0x97c99ce098e98b92+ .quad 0x10af149b6eb3adad+ .quad 0x42181fe8f4d38cfa+ .quad 0xf004be62a24d40dd+ .quad 0xba0659910452d41f+ .quad 0x81c45ee162a44234+ .quad 0x4cb829d8a22266ef+ .quad 0x1dbcaa8407b86681+ .quad 0x081f001e8b26753b+ .quad 0x3cd7ce6a84048e81+ .quad 0x78af11633f25f22c++ // 2^44 * 4 * G++ .quad 0x8416ebd40b50babc+ .quad 0x1508722628208bee+ .quad 0xa3148fafb9c1c36d+ .quad 0x0d07daacd32d7d5d+ .quad 0x3241c00e7d65318c+ .quad 0xe6bee5dcd0e86de7+ .quad 0x118b2dc2fbc08c26+ .quad 0x680d04a7fc603dc3+ .quad 0xf9c2414a695aa3eb+ .quad 0xdaa42c4c05a68f21+ .quad 0x7c6c23987f93963e+ .quad 0x210e8cd30c3954e3++ // 2^44 * 5 * G++ .quad 0xac4201f210a71c06+ .quad 0x6a65e0aef3bfb021+ .quad 0xbc42c35c393632f7+ .quad 0x56ea8db1865f0742+ .quad 0x2b50f16137fe6c26+ .quad 0xe102bcd856e404d8+ .quad 0x12b0f1414c561f6b+ .quad 0x51b17bc8d028ec91+ .quad 0xfff5fb4bcf535119+ .quad 0xf4989d79df1108a0+ .quad 0xbdfcea659a3ba325+ .quad 0x18a11f1174d1a6f2++ // 2^44 * 6 * G++ .quad 0x407375ab3f6bba29+ .quad 0x9ec3b6d8991e482e+ .quad 0x99c80e82e55f92e9+ .quad 0x307c13b6fb0c0ae1+ .quad 0xfbd63cdad27a5f2c+ .quad 0xf00fc4bc8aa106d7+ .quad 0x53fb5c1a8e64a430+ .quad 0x04eaabe50c1a2e85+ .quad 0x24751021cb8ab5e7+ .quad 0xfc2344495c5010eb+ .quad 0x5f1e717b4e5610a1+ .quad 0x44da5f18c2710cd5++ // 2^44 * 7 * G++ .quad 0x033cc55ff1b82eb5+ .quad 0xb15ae36d411cae52+ .quad 0xba40b6198ffbacd3+ .quad 0x768edce1532e861f+ .quad 0x9156fe6b89d8eacc+ .quad 0xe6b79451e23126a1+ .quad 0xbd7463d93944eb4e+ .quad 0x726373f6767203ae+ .quad 0xe305ca72eb7ef68a+ .quad 0x662cf31f70eadb23+ .quad 0x18f026fdb4c45b68+ .quad 0x513b5384b5d2ecbd++ // 2^44 * 8 * G++ .quad 0x46d46280c729989e+ .quad 0x4b93fbd05368a5dd+ .quad 0x63df3f81d1765a89+ .quad 0x34cebd64b9a0a223+ .quad 0x5e2702878af34ceb+ .quad 0x900b0409b946d6ae+ .quad 0x6512ebf7dabd8512+ .quad 0x61d9b76988258f81+ .quad 0xa6c5a71349b7d94b+ .quad 0xa3f3d15823eb9446+ .quad 0x0416fbd277484834+ .quad 0x69d45e6f2c70812f++ // 2^48 * 1 * G++ .quad 0xce16f74bc53c1431+ .quad 0x2b9725ce2072edde+ .quad 0xb8b9c36fb5b23ee7+ .quad 0x7e2e0e450b5cc908+ .quad 0x9fe62b434f460efb+ .quad 0xded303d4a63607d6+ .quad 0xf052210eb7a0da24+ .quad 0x237e7dbe00545b93+ .quad 0x013575ed6701b430+ .quad 0x231094e69f0bfd10+ .quad 0x75320f1583e47f22+ .quad 0x71afa699b11155e3++ // 2^48 * 2 * G++ .quad 0x65ce6f9b3953b61d+ .quad 0xc65839eaafa141e6+ .quad 0x0f435ffda9f759fe+ .quad 0x021142e9c2b1c28e+ .quad 0xea423c1c473b50d6+ .quad 0x51e87a1f3b38ef10+ .quad 0x9b84bf5fb2c9be95+ .quad 0x00731fbc78f89a1c+ .quad 0xe430c71848f81880+ .quad 0xbf960c225ecec119+ .quad 0xb6dae0836bba15e3+ .quad 0x4c4d6f3347e15808++ // 2^48 * 3 * G++ .quad 0x18f7eccfc17d1fc9+ .quad 0x6c75f5a651403c14+ .quad 0xdbde712bf7ee0cdf+ .quad 0x193fddaaa7e47a22+ .quad 0x2f0cddfc988f1970+ .quad 0x6b916227b0b9f51b+ .quad 0x6ec7b6c4779176be+ .quad 0x38bf9500a88f9fa8+ .quad 0x1fd2c93c37e8876f+ .quad 0xa2f61e5a18d1462c+ .quad 0x5080f58239241276+ .quad 0x6a6fb99ebf0d4969++ // 2^48 * 4 * G++ .quad 0x6a46c1bb560855eb+ .quad 0x2416bb38f893f09d+ .quad 0xd71d11378f71acc1+ .quad 0x75f76914a31896ea+ .quad 0xeeb122b5b6e423c6+ .quad 0x939d7010f286ff8e+ .quad 0x90a92a831dcf5d8c+ .quad 0x136fda9f42c5eb10+ .quad 0xf94cdfb1a305bdd1+ .quad 0x0f364b9d9ff82c08+ .quad 0x2a87d8a5c3bb588a+ .quad 0x022183510be8dcba++ // 2^48 * 5 * G++ .quad 0x4af766385ead2d14+ .quad 0xa08ed880ca7c5830+ .quad 0x0d13a6e610211e3d+ .quad 0x6a071ce17b806c03+ .quad 0x9d5a710143307a7f+ .quad 0xb063de9ec47da45f+ .quad 0x22bbfe52be927ad3+ .quad 0x1387c441fd40426c+ .quad 0xb5d3c3d187978af8+ .quad 0x722b5a3d7f0e4413+ .quad 0x0d7b4848bb477ca0+ .quad 0x3171b26aaf1edc92++ // 2^48 * 6 * G++ .quad 0xa92f319097564ca8+ .quad 0xff7bb84c2275e119+ .quad 0x4f55fe37a4875150+ .quad 0x221fd4873cf0835a+ .quad 0xa60db7d8b28a47d1+ .quad 0xa6bf14d61770a4f1+ .quad 0xd4a1f89353ddbd58+ .quad 0x6c514a63344243e9+ .quad 0x2322204f3a156341+ .quad 0xfb73e0e9ba0a032d+ .quad 0xfce0dd4c410f030e+ .quad 0x48daa596fb924aaa++ // 2^48 * 7 * G++ .quad 0x6eca8e665ca59cc7+ .quad 0xa847254b2e38aca0+ .quad 0x31afc708d21e17ce+ .quad 0x676dd6fccad84af7+ .quad 0x14f61d5dc84c9793+ .quad 0x9941f9e3ef418206+ .quad 0xcdf5b88f346277ac+ .quad 0x58c837fa0e8a79a9+ .quad 0x0cf9688596fc9058+ .quad 0x1ddcbbf37b56a01b+ .quad 0xdcc2e77d4935d66a+ .quad 0x1c4f73f2c6a57f0a++ // 2^48 * 8 * G++ .quad 0x0e7a4fbd305fa0bb+ .quad 0x829d4ce054c663ad+ .quad 0xf421c3832fe33848+ .quad 0x795ac80d1bf64c42+ .quad 0xb36e706efc7c3484+ .quad 0x73dfc9b4c3c1cf61+ .quad 0xeb1d79c9781cc7e5+ .quad 0x70459adb7daf675c+ .quad 0x1b91db4991b42bb3+ .quad 0x572696234b02dcca+ .quad 0x9fdf9ee51f8c78dc+ .quad 0x5fe162848ce21fd3++ // 2^52 * 1 * G++ .quad 0xe2790aae4d077c41+ .quad 0x8b938270db7469a3+ .quad 0x6eb632dc8abd16a2+ .quad 0x720814ecaa064b72+ .quad 0x315c29c795115389+ .quad 0xd7e0e507862f74ce+ .quad 0x0c4a762185927432+ .quad 0x72de6c984a25a1e4+ .quad 0xae9ab553bf6aa310+ .quad 0x050a50a9806d6e1b+ .quad 0x92bb7403adff5139+ .quad 0x0394d27645be618b++ // 2^52 * 2 * G++ .quad 0x4d572251857eedf4+ .quad 0xe3724edde19e93c5+ .quad 0x8a71420e0b797035+ .quad 0x3b3c833687abe743+ .quad 0xf5396425b23545a4+ .quad 0x15a7a27e98fbb296+ .quad 0xab6c52bc636fdd86+ .quad 0x79d995a8419334ee+ .quad 0xcd8a8ea61195dd75+ .quad 0xa504d8a81dd9a82f+ .quad 0x540dca81a35879b6+ .quad 0x60dd16a379c86a8a++ // 2^52 * 3 * G++ .quad 0x35a2c8487381e559+ .quad 0x596ffea6d78082cb+ .quad 0xcb9771ebdba7b653+ .quad 0x5a08b5019b4da685+ .quad 0x3501d6f8153e47b8+ .quad 0xb7a9675414a2f60c+ .quad 0x112ee8b6455d9523+ .quad 0x4e62a3c18112ea8a+ .quad 0xc8d4ac04516ab786+ .quad 0x595af3215295b23d+ .quad 0xd6edd234db0230c1+ .quad 0x0929efe8825b41cc++ // 2^52 * 4 * G++ .quad 0x5f0601d1cbd0f2d3+ .quad 0x736e412f6132bb7f+ .quad 0x83604432238dde87+ .quad 0x1e3a5272f5c0753c+ .quad 0x8b3172b7ad56651d+ .quad 0x01581b7a3fabd717+ .quad 0x2dc94df6424df6e4+ .quad 0x30376e5d2c29284f+ .quad 0xd2918da78159a59c+ .quad 0x6bdc1cd93f0713f3+ .quad 0x565f7a934acd6590+ .quad 0x53daacec4cb4c128++ // 2^52 * 5 * G++ .quad 0x4ca73bd79cc8a7d6+ .quad 0x4d4a738f47e9a9b2+ .quad 0xf4cbf12942f5fe00+ .quad 0x01a13ff9bdbf0752+ .quad 0x99852bc3852cfdb0+ .quad 0x2cc12e9559d6ed0b+ .quad 0x70f9e2bf9b5ac27b+ .quad 0x4f3b8c117959ae99+ .quad 0x55b6c9c82ff26412+ .quad 0x1ac4a8c91fb667a8+ .quad 0xd527bfcfeb778bf2+ .quad 0x303337da7012a3be++ // 2^52 * 6 * G++ .quad 0x955422228c1c9d7c+ .quad 0x01fac1371a9b340f+ .quad 0x7e8d9177925b48d7+ .quad 0x53f8ad5661b3e31b+ .quad 0x976d3ccbfad2fdd1+ .quad 0xcb88839737a640a8+ .quad 0x2ff00c1d6734cb25+ .quad 0x269ff4dc789c2d2b+ .quad 0x0c003fbdc08d678d+ .quad 0x4d982fa37ead2b17+ .quad 0xc07e6bcdb2e582f1+ .quad 0x296c7291df412a44++ // 2^52 * 7 * G++ .quad 0x7903de2b33daf397+ .quad 0xd0ff0619c9a624b3+ .quad 0x8a1d252b555b3e18+ .quad 0x2b6d581c52e0b7c0+ .quad 0xdfb23205dab8b59e+ .quad 0x465aeaa0c8092250+ .quad 0xd133c1189a725d18+ .quad 0x2327370261f117d1+ .quad 0x3d0543d3623e7986+ .quad 0x679414c2c278a354+ .quad 0xae43f0cc726196f6+ .quad 0x7836c41f8245eaba++ // 2^52 * 8 * G++ .quad 0xe7a254db49e95a81+ .quad 0x5192d5d008b0ad73+ .quad 0x4d20e5b1d00afc07+ .quad 0x5d55f8012cf25f38+ .quad 0xca651e848011937c+ .quad 0xc6b0c46e6ef41a28+ .quad 0xb7021ba75f3f8d52+ .quad 0x119dff99ead7b9fd+ .quad 0x43eadfcbf4b31d4d+ .quad 0xc6503f7411148892+ .quad 0xfeee68c5060d3b17+ .quad 0x329293b3dd4a0ac8++ // 2^56 * 1 * G++ .quad 0x4e59214fe194961a+ .quad 0x49be7dc70d71cd4f+ .quad 0x9300cfd23b50f22d+ .quad 0x4789d446fc917232+ .quad 0x2879852d5d7cb208+ .quad 0xb8dedd70687df2e7+ .quad 0xdc0bffab21687891+ .quad 0x2b44c043677daa35+ .quad 0x1a1c87ab074eb78e+ .quad 0xfac6d18e99daf467+ .quad 0x3eacbbcd484f9067+ .quad 0x60c52eef2bb9a4e4++ // 2^56 * 2 * G++ .quad 0x0b5d89bc3bfd8bf1+ .quad 0xb06b9237c9f3551a+ .quad 0x0e4c16b0d53028f5+ .quad 0x10bc9c312ccfcaab+ .quad 0x702bc5c27cae6d11+ .quad 0x44c7699b54a48cab+ .quad 0xefbc4056ba492eb2+ .quad 0x70d77248d9b6676d+ .quad 0xaa8ae84b3ec2a05b+ .quad 0x98699ef4ed1781e0+ .quad 0x794513e4708e85d1+ .quad 0x63755bd3a976f413++ // 2^56 * 3 * G++ .quad 0xb55fa03e2ad10853+ .quad 0x356f75909ee63569+ .quad 0x9ff9f1fdbe69b890+ .quad 0x0d8cc1c48bc16f84+ .quad 0x3dc7101897f1acb7+ .quad 0x5dda7d5ec165bbd8+ .quad 0x508e5b9c0fa1020f+ .quad 0x2763751737c52a56+ .quad 0x029402d36eb419a9+ .quad 0xf0b44e7e77b460a5+ .quad 0xcfa86230d43c4956+ .quad 0x70c2dd8a7ad166e7++ // 2^56 * 4 * G++ .quad 0x656194509f6fec0e+ .quad 0xee2e7ea946c6518d+ .quad 0x9733c1f367e09b5c+ .quad 0x2e0fac6363948495+ .quad 0x91d4967db8ed7e13+ .quad 0x74252f0ad776817a+ .quad 0xe40982e00d852564+ .quad 0x32b8613816a53ce5+ .quad 0x79e7f7bee448cd64+ .quad 0x6ac83a67087886d0+ .quad 0xf89fd4d9a0e4db2e+ .quad 0x4179215c735a4f41++ // 2^56 * 5 * G++ .quad 0x8c7094e7d7dced2a+ .quad 0x97fb8ac347d39c70+ .quad 0xe13be033a906d902+ .quad 0x700344a30cd99d76+ .quad 0xe4ae33b9286bcd34+ .quad 0xb7ef7eb6559dd6dc+ .quad 0x278b141fb3d38e1f+ .quad 0x31fa85662241c286+ .quad 0xaf826c422e3622f4+ .quad 0xc12029879833502d+ .quad 0x9bc1b7e12b389123+ .quad 0x24bb2312a9952489++ // 2^56 * 6 * G++ .quad 0xb1a8ed1732de67c3+ .quad 0x3cb49418461b4948+ .quad 0x8ebd434376cfbcd2+ .quad 0x0fee3e871e188008+ .quad 0x41f80c2af5f85c6b+ .quad 0x687284c304fa6794+ .quad 0x8945df99a3ba1bad+ .quad 0x0d1d2af9ffeb5d16+ .quad 0xa9da8aa132621edf+ .quad 0x30b822a159226579+ .quad 0x4004197ba79ac193+ .quad 0x16acd79718531d76++ // 2^56 * 7 * G++ .quad 0x72df72af2d9b1d3d+ .quad 0x63462a36a432245a+ .quad 0x3ecea07916b39637+ .quad 0x123e0ef6b9302309+ .quad 0xc959c6c57887b6ad+ .quad 0x94e19ead5f90feba+ .quad 0x16e24e62a342f504+ .quad 0x164ed34b18161700+ .quad 0x487ed94c192fe69a+ .quad 0x61ae2cea3a911513+ .quad 0x877bf6d3b9a4de27+ .quad 0x78da0fc61073f3eb++ // 2^56 * 8 * G++ .quad 0x5bf15d28e52bc66a+ .quad 0x2c47e31870f01a8e+ .quad 0x2419afbc06c28bdd+ .quad 0x2d25deeb256b173a+ .quad 0xa29f80f1680c3a94+ .quad 0x71f77e151ae9e7e6+ .quad 0x1100f15848017973+ .quad 0x054aa4b316b38ddd+ .quad 0xdfc8468d19267cb8+ .quad 0x0b28789c66e54daf+ .quad 0x2aeb1d2a666eec17+ .quad 0x134610a6ab7da760++ // 2^60 * 1 * G++ .quad 0xcaf55ec27c59b23f+ .quad 0x99aeed3e154d04f2+ .quad 0x68441d72e14141f4+ .quad 0x140345133932a0a2+ .quad 0xd91430e0dc028c3c+ .quad 0x0eb955a85217c771+ .quad 0x4b09e1ed2c99a1fa+ .quad 0x42881af2bd6a743c+ .quad 0x7bfec69aab5cad3d+ .quad 0xc23e8cd34cb2cfad+ .quad 0x685dd14bfb37d6a2+ .quad 0x0ad6d64415677a18++ // 2^60 * 2 * G++ .quad 0x781a439e417becb5+ .quad 0x4ac5938cd10e0266+ .quad 0x5da385110692ac24+ .quad 0x11b065a2ade31233+ .quad 0x7914892847927e9f+ .quad 0x33dad6ef370aa877+ .quad 0x1f8f24fa11122703+ .quad 0x5265ac2f2adf9592+ .quad 0x405fdd309afcb346+ .quad 0xd9723d4428e63f54+ .quad 0x94c01df05f65aaae+ .quad 0x43e4dc3ae14c0809++ // 2^60 * 3 * G++ .quad 0xbc12c7f1a938a517+ .quad 0x473028ab3180b2e1+ .quad 0x3f78571efbcd254a+ .quad 0x74e534426ff6f90f+ .quad 0xea6f7ac3adc2c6a3+ .quad 0xd0e928f6e9717c94+ .quad 0xe2d379ead645eaf5+ .quad 0x46dd8785c51ffbbe+ .quad 0x709801be375c8898+ .quad 0x4b06dab5e3fd8348+ .quad 0x75880ced27230714+ .quad 0x2b09468fdd2f4c42++ // 2^60 * 4 * G++ .quad 0x97c749eeb701cb96+ .quad 0x83f438d4b6a369c3+ .quad 0x62962b8b9a402cd9+ .quad 0x6976c7509888df7b+ .quad 0x5b97946582ffa02a+ .quad 0xda096a51fea8f549+ .quad 0xa06351375f77af9b+ .quad 0x1bcfde61201d1e76+ .quad 0x4a4a5490246a59a2+ .quad 0xd63ebddee87fdd90+ .quad 0xd9437c670d2371fa+ .quad 0x69e87308d30f8ed6++ // 2^60 * 5 * G++ .quad 0x435a8bb15656beb0+ .quad 0xf8fac9ba4f4d5bca+ .quad 0xb9b278c41548c075+ .quad 0x3eb0ef76e892b622+ .quad 0x0f80bf028bc80303+ .quad 0x6aae16b37a18cefb+ .quad 0xdd47ea47d72cd6a3+ .quad 0x61943588f4ed39aa+ .quad 0xd26e5c3e91039f85+ .quad 0xc0e9e77df6f33aa9+ .quad 0xe8968c5570066a93+ .quad 0x3c34d1881faaaddd++ // 2^60 * 6 * G++ .quad 0x3f9d2b5ea09f9ec0+ .quad 0x1dab3b6fb623a890+ .quad 0xa09ba3ea72d926c4+ .quad 0x374193513fd8b36d+ .quad 0xbd5b0b8f2fffe0d9+ .quad 0x6aa254103ed24fb9+ .quad 0x2ac7d7bcb26821c4+ .quad 0x605b394b60dca36a+ .quad 0xb4e856e45a9d1ed2+ .quad 0xefe848766c97a9a2+ .quad 0xb104cf641e5eee7d+ .quad 0x2f50b81c88a71c8f++ // 2^60 * 7 * G++ .quad 0x31723c61fc6811bb+ .quad 0x9cb450486211800f+ .quad 0x768933d347995753+ .quad 0x3491a53502752fcd+ .quad 0x2b552ca0a7da522a+ .quad 0x3230b336449b0250+ .quad 0xf2c4c5bca4b99fb9+ .quad 0x7b2c674958074a22+ .quad 0xd55165883ed28cdf+ .quad 0x12d84fd2d362de39+ .quad 0x0a874ad3e3378e4f+ .quad 0x000d2b1f7c763e74++ // 2^60 * 8 * G++ .quad 0x3d420811d06d4a67+ .quad 0xbefc048590e0ffe3+ .quad 0xf870c6b7bd487bde+ .quad 0x6e2a7316319afa28+ .quad 0x9624778c3e94a8ab+ .quad 0x0ad6f3cee9a78bec+ .quad 0x948ac7810d743c4f+ .quad 0x76627935aaecfccc+ .quad 0x56a8ac24d6d59a9f+ .quad 0xc8db753e3096f006+ .quad 0x477f41e68f4c5299+ .quad 0x588d851cf6c86114++ // 2^64 * 1 * G++ .quad 0x51138ec78df6b0fe+ .quad 0x5397da89e575f51b+ .quad 0x09207a1d717af1b9+ .quad 0x2102fdba2b20d650+ .quad 0xcd2a65e777d1f515+ .quad 0x548991878faa60f1+ .quad 0xb1b73bbcdabc06e5+ .quad 0x654878cba97cc9fb+ .quad 0x969ee405055ce6a1+ .quad 0x36bca7681251ad29+ .quad 0x3a1af517aa7da415+ .quad 0x0ad725db29ecb2ba++ // 2^64 * 2 * G++ .quad 0xdc4267b1834e2457+ .quad 0xb67544b570ce1bc5+ .quad 0x1af07a0bf7d15ed7+ .quad 0x4aefcffb71a03650+ .quad 0xfec7bc0c9b056f85+ .quad 0x537d5268e7f5ffd7+ .quad 0x77afc6624312aefa+ .quad 0x4f675f5302399fd9+ .quad 0xc32d36360415171e+ .quad 0xcd2bef118998483b+ .quad 0x870a6eadd0945110+ .quad 0x0bccbb72a2a86561++ // 2^64 * 3 * G++ .quad 0x185e962feab1a9c8+ .quad 0x86e7e63565147dcd+ .quad 0xb092e031bb5b6df2+ .quad 0x4024f0ab59d6b73e+ .quad 0x186d5e4c50fe1296+ .quad 0xe0397b82fee89f7e+ .quad 0x3bc7f6c5507031b0+ .quad 0x6678fd69108f37c2+ .quad 0x1586fa31636863c2+ .quad 0x07f68c48572d33f2+ .quad 0x4f73cc9f789eaefc+ .quad 0x2d42e2108ead4701++ // 2^64 * 4 * G++ .quad 0x97f5131594dfd29b+ .quad 0x6155985d313f4c6a+ .quad 0xeba13f0708455010+ .quad 0x676b2608b8d2d322+ .quad 0x21717b0d0f537593+ .quad 0x914e690b131e064c+ .quad 0x1bb687ae752ae09f+ .quad 0x420bf3a79b423c6e+ .quad 0x8138ba651c5b2b47+ .quad 0x8671b6ec311b1b80+ .quad 0x7bff0cb1bc3135b0+ .quad 0x745d2ffa9c0cf1e0++ // 2^64 * 5 * G++ .quad 0xbf525a1e2bc9c8bd+ .quad 0xea5b260826479d81+ .quad 0xd511c70edf0155db+ .quad 0x1ae23ceb960cf5d0+ .quad 0x6036df5721d34e6a+ .quad 0xb1db8827997bb3d0+ .quad 0xd3c209c3c8756afa+ .quad 0x06e15be54c1dc839+ .quad 0x5b725d871932994a+ .quad 0x32351cb5ceb1dab0+ .quad 0x7dc41549dab7ca05+ .quad 0x58ded861278ec1f7++ // 2^64 * 6 * G++ .quad 0xd8173793f266c55c+ .quad 0xc8c976c5cc454e49+ .quad 0x5ce382f8bc26c3a8+ .quad 0x2ff39de85485f6f9+ .quad 0x2dfb5ba8b6c2c9a8+ .quad 0x48eeef8ef52c598c+ .quad 0x33809107f12d1573+ .quad 0x08ba696b531d5bd8+ .quad 0x77ed3eeec3efc57a+ .quad 0x04e05517d4ff4811+ .quad 0xea3d7a3ff1a671cb+ .quad 0x120633b4947cfe54++ // 2^64 * 7 * G++ .quad 0x0b94987891610042+ .quad 0x4ee7b13cecebfae8+ .quad 0x70be739594f0a4c0+ .quad 0x35d30a99b4d59185+ .quad 0x82bd31474912100a+ .quad 0xde237b6d7e6fbe06+ .quad 0xe11e761911ea79c6+ .quad 0x07433be3cb393bde+ .quad 0xff7944c05ce997f4+ .quad 0x575d3de4b05c51a3+ .quad 0x583381fd5a76847c+ .quad 0x2d873ede7af6da9f++ // 2^64 * 8 * G++ .quad 0x157a316443373409+ .quad 0xfab8b7eef4aa81d9+ .quad 0xb093fee6f5a64806+ .quad 0x2e773654707fa7b6+ .quad 0xaa6202e14e5df981+ .quad 0xa20d59175015e1f5+ .quad 0x18a275d3bae21d6c+ .quad 0x0543618a01600253+ .quad 0x0deabdf4974c23c1+ .quad 0xaa6f0a259dce4693+ .quad 0x04202cb8a29aba2c+ .quad 0x4b1443362d07960d++ // 2^68 * 1 * G++ .quad 0x47b837f753242cec+ .quad 0x256dc48cc04212f2+ .quad 0xe222fbfbe1d928c5+ .quad 0x48ea295bad8a2c07+ .quad 0x299b1c3f57c5715e+ .quad 0x96cb929e6b686d90+ .quad 0x3004806447235ab3+ .quad 0x2c435c24a44d9fe1+ .quad 0x0607c97c80f8833f+ .quad 0x0e851578ca25ec5b+ .quad 0x54f7450b161ebb6f+ .quad 0x7bcb4792a0def80e++ // 2^68 * 2 * G++ .quad 0x8487e3d02bc73659+ .quad 0x4baf8445059979df+ .quad 0xd17c975adcad6fbf+ .quad 0x57369f0bdefc96b6+ .quad 0x1cecd0a0045224c2+ .quad 0x757f1b1b69e53952+ .quad 0x775b7a925289f681+ .quad 0x1b6cc62016736148+ .quad 0xf1a9990175638698+ .quad 0x353dd1beeeaa60d3+ .quad 0x849471334c9ba488+ .quad 0x63fa6e6843ade311++ // 2^68 * 3 * G++ .quad 0xd15c20536597c168+ .quad 0x9f73740098d28789+ .quad 0x18aee7f13257ba1f+ .quad 0x3418bfda07346f14+ .quad 0x2195becdd24b5eb7+ .quad 0x5e41f18cc0cd44f9+ .quad 0xdf28074441ca9ede+ .quad 0x07073b98f35b7d67+ .quad 0xd03c676c4ce530d4+ .quad 0x0b64c0473b5df9f4+ .quad 0x065cef8b19b3a31e+ .quad 0x3084d661533102c9++ // 2^68 * 4 * G++ .quad 0xe1f6b79ebf8469ad+ .quad 0x15801004e2663135+ .quad 0x9a498330af74181b+ .quad 0x3ba2504f049b673c+ .quad 0x9a6ce876760321fd+ .quad 0x7fe2b5109eb63ad8+ .quad 0x00e7d4ae8ac80592+ .quad 0x73d86b7abb6f723a+ .quad 0x0b52b5606dba5ab6+ .quad 0xa9134f0fbbb1edab+ .quad 0x30a9520d9b04a635+ .quad 0x6813b8f37973e5db++ // 2^68 * 5 * G++ .quad 0x9854b054334127c1+ .quad 0x105d047882fbff25+ .quad 0xdb49f7f944186f4f+ .quad 0x1768e838bed0b900+ .quad 0xf194ca56f3157e29+ .quad 0x136d35705ef528a5+ .quad 0xdd4cef778b0599bc+ .quad 0x7d5472af24f833ed+ .quad 0xd0ef874daf33da47+ .quad 0x00d3be5db6e339f9+ .quad 0x3f2a8a2f9c9ceece+ .quad 0x5d1aeb792352435a++ // 2^68 * 6 * G++ .quad 0xf59e6bb319cd63ca+ .quad 0x670c159221d06839+ .quad 0xb06d565b2150cab6+ .quad 0x20fb199d104f12a3+ .quad 0x12c7bfaeb61ba775+ .quad 0xb84e621fe263bffd+ .quad 0x0b47a5c35c840dcf+ .quad 0x7e83be0bccaf8634+ .quad 0x61943dee6d99c120+ .quad 0x86101f2e460b9fe0+ .quad 0x6bb2f1518ee8598d+ .quad 0x76b76289fcc475cc++ // 2^68 * 7 * G++ .quad 0x791b4cc1756286fa+ .quad 0xdbced317d74a157c+ .quad 0x7e732421ea72bde6+ .quad 0x01fe18491131c8e9+ .quad 0x4245f1a1522ec0b3+ .quad 0x558785b22a75656d+ .quad 0x1d485a2548a1b3c0+ .quad 0x60959eccd58fe09f+ .quad 0x3ebfeb7ba8ed7a09+ .quad 0x49fdc2bbe502789c+ .quad 0x44ebce5d3c119428+ .quad 0x35e1eb55be947f4a++ // 2^68 * 8 * G++ .quad 0xdbdae701c5738dd3+ .quad 0xf9c6f635b26f1bee+ .quad 0x61e96a8042f15ef4+ .quad 0x3aa1d11faf60a4d8+ .quad 0x14fd6dfa726ccc74+ .quad 0x3b084cfe2f53b965+ .quad 0xf33ae4f552a2c8b4+ .quad 0x59aab07a0d40166a+ .quad 0x77bcec4c925eac25+ .quad 0x1848718460137738+ .quad 0x5b374337fea9f451+ .quad 0x1865e78ec8e6aa46++ // 2^72 * 1 * G++ .quad 0xccc4b7c7b66e1f7a+ .quad 0x44157e25f50c2f7e+ .quad 0x3ef06dfc713eaf1c+ .quad 0x582f446752da63f7+ .quad 0x967c54e91c529ccb+ .quad 0x30f6269264c635fb+ .quad 0x2747aff478121965+ .quad 0x17038418eaf66f5c+ .quad 0xc6317bd320324ce4+ .quad 0xa81042e8a4488bc4+ .quad 0xb21ef18b4e5a1364+ .quad 0x0c2a1c4bcda28dc9++ // 2^72 * 2 * G++ .quad 0xd24dc7d06f1f0447+ .quad 0xb2269e3edb87c059+ .quad 0xd15b0272fbb2d28f+ .quad 0x7c558bd1c6f64877+ .quad 0xedc4814869bd6945+ .quad 0x0d6d907dbe1c8d22+ .quad 0xc63bd212d55cc5ab+ .quad 0x5a6a9b30a314dc83+ .quad 0xd0ec1524d396463d+ .quad 0x12bb628ac35a24f0+ .quad 0xa50c3a791cbc5fa4+ .quad 0x0404a5ca0afbafc3++ // 2^72 * 3 * G++ .quad 0x8c1f40070aa743d6+ .quad 0xccbad0cb5b265ee8+ .quad 0x574b046b668fd2de+ .quad 0x46395bfdcadd9633+ .quad 0x62bc9e1b2a416fd1+ .quad 0xb5c6f728e350598b+ .quad 0x04343fd83d5d6967+ .quad 0x39527516e7f8ee98+ .quad 0x117fdb2d1a5d9a9c+ .quad 0x9c7745bcd1005c2a+ .quad 0xefd4bef154d56fea+ .quad 0x76579a29e822d016++ // 2^72 * 4 * G++ .quad 0x45b68e7e49c02a17+ .quad 0x23cd51a2bca9a37f+ .quad 0x3ed65f11ec224c1b+ .quad 0x43a384dc9e05bdb1+ .quad 0x333cb51352b434f2+ .quad 0xd832284993de80e1+ .quad 0xb5512887750d35ce+ .quad 0x02c514bb2a2777c1+ .quad 0x684bd5da8bf1b645+ .quad 0xfb8bd37ef6b54b53+ .quad 0x313916d7a9b0d253+ .quad 0x1160920961548059++ // 2^72 * 5 * G++ .quad 0xb44d166929dacfaa+ .quad 0xda529f4c8413598f+ .quad 0xe9ef63ca453d5559+ .quad 0x351e125bc5698e0b+ .quad 0x7a385616369b4dcd+ .quad 0x75c02ca7655c3563+ .quad 0x7dc21bf9d4f18021+ .quad 0x2f637d7491e6e042+ .quad 0xd4b49b461af67bbe+ .quad 0xd603037ac8ab8961+ .quad 0x71dee19ff9a699fb+ .quad 0x7f182d06e7ce2a9a++ // 2^72 * 6 * G++ .quad 0x7a7c8e64ab0168ec+ .quad 0xcb5a4a5515edc543+ .quad 0x095519d347cd0eda+ .quad 0x67d4ac8c343e93b0+ .quad 0x09454b728e217522+ .quad 0xaa58e8f4d484b8d8+ .quad 0xd358254d7f46903c+ .quad 0x44acc043241c5217+ .quad 0x1c7d6bbb4f7a5777+ .quad 0x8b35fed4918313e1+ .quad 0x4adca1c6c96b4684+ .quad 0x556d1c8312ad71bd++ // 2^72 * 7 * G++ .quad 0x17ef40e30c8d3982+ .quad 0x31f7073e15a3fa34+ .quad 0x4f21f3cb0773646e+ .quad 0x746c6c6d1d824eff+ .quad 0x81f06756b11be821+ .quad 0x0faff82310a3f3dd+ .quad 0xf8b2d0556a99465d+ .quad 0x097abe38cc8c7f05+ .quad 0x0c49c9877ea52da4+ .quad 0x4c4369559bdc1d43+ .quad 0x022c3809f7ccebd2+ .quad 0x577e14a34bee84bd++ // 2^72 * 8 * G++ .quad 0xf0e268ac61a73b0a+ .quad 0xf2fafa103791a5f5+ .quad 0xc1e13e826b6d00e9+ .quad 0x60fa7ee96fd78f42+ .quad 0x94fecebebd4dd72b+ .quad 0xf46a4fda060f2211+ .quad 0x124a5977c0c8d1ff+ .quad 0x705304b8fb009295+ .quad 0xb63d1d354d296ec6+ .quad 0xf3c3053e5fad31d8+ .quad 0x670b958cb4bd42ec+ .quad 0x21398e0ca16353fd++ // 2^76 * 1 * G++ .quad 0x216ab2ca8da7d2ef+ .quad 0x366ad9dd99f42827+ .quad 0xae64b9004fdd3c75+ .quad 0x403a395b53909e62+ .quad 0x86c5fc16861b7e9a+ .quad 0xf6a330476a27c451+ .quad 0x01667267a1e93597+ .quad 0x05ffb9cd6082dfeb+ .quad 0xa617fa9ff53f6139+ .quad 0x60f2b5e513e66cb6+ .quad 0xd7a8beefb3448aa4+ .quad 0x7a2932856f5ea192++ // 2^76 * 2 * G++ .quad 0x0b39d761b02de888+ .quad 0x5f550e7ed2414e1f+ .quad 0xa6bfa45822e1a940+ .quad 0x050a2f7dfd447b99+ .quad 0xb89c444879639302+ .quad 0x4ae4f19350c67f2c+ .quad 0xf0b35da8c81af9c6+ .quad 0x39d0003546871017+ .quad 0x437c3b33a650db77+ .quad 0x6bafe81dbac52bb2+ .quad 0xfe99402d2db7d318+ .quad 0x2b5b7eec372ba6ce++ // 2^76 * 3 * G++ .quad 0xb3bc4bbd83f50eef+ .quad 0x508f0c998c927866+ .quad 0x43e76587c8b7e66e+ .quad 0x0f7655a3a47f98d9+ .quad 0xa694404d613ac8f4+ .quad 0x500c3c2bfa97e72c+ .quad 0x874104d21fcec210+ .quad 0x1b205fb38604a8ee+ .quad 0x55ecad37d24b133c+ .quad 0x441e147d6038c90b+ .quad 0x656683a1d62c6fee+ .quad 0x0157d5dc87e0ecae++ // 2^76 * 4 * G++ .quad 0xf2a7af510354c13d+ .quad 0xd7a0b145aa372b60+ .quad 0x2869b96a05a3d470+ .quad 0x6528e42d82460173+ .quad 0x95265514d71eb524+ .quad 0xe603d8815df14593+ .quad 0x147cdf410d4de6b7+ .quad 0x5293b1730437c850+ .quad 0x23d0e0814bccf226+ .quad 0x92c745cd8196fb93+ .quad 0x8b61796c59541e5b+ .quad 0x40a44df0c021f978++ // 2^76 * 5 * G++ .quad 0xdaa869894f20ea6a+ .quad 0xea14a3d14c620618+ .quad 0x6001fccb090bf8be+ .quad 0x35f4e822947e9cf0+ .quad 0x86c96e514bc5d095+ .quad 0xf20d4098fca6804a+ .quad 0x27363d89c826ea5d+ .quad 0x39ca36565719cacf+ .quad 0x97506f2f6f87b75c+ .quad 0xc624aea0034ae070+ .quad 0x1ec856e3aad34dd6+ .quad 0x055b0be0e440e58f++ // 2^76 * 6 * G++ .quad 0x6469a17d89735d12+ .quad 0xdb6f27d5e662b9f1+ .quad 0x9fcba3286a395681+ .quad 0x363b8004d269af25+ .quad 0x4d12a04b6ea33da2+ .quad 0x57cf4c15e36126dd+ .quad 0x90ec9675ee44d967+ .quad 0x64ca348d2a985aac+ .quad 0x99588e19e4c4912d+ .quad 0xefcc3b4e1ca5ce6b+ .quad 0x4522ea60fa5b98d5+ .quad 0x7064bbab1de4a819++ // 2^76 * 7 * G++ .quad 0xb919e1515a770641+ .quad 0xa9a2e2c74e7f8039+ .quad 0x7527250b3df23109+ .quad 0x756a7330ac27b78b+ .quad 0xa290c06142542129+ .quad 0xf2e2c2aebe8d5b90+ .quad 0xcf2458db76abfe1b+ .quad 0x02157ade83d626bf+ .quad 0x3e46972a1b9a038b+ .quad 0x2e4ee66a7ee03fb4+ .quad 0x81a248776edbb4ca+ .quad 0x1a944ee88ecd0563++ // 2^76 * 8 * G++ .quad 0xd5a91d1151039372+ .quad 0x2ed377b799ca26de+ .quad 0xa17202acfd366b6b+ .quad 0x0730291bd6901995+ .quad 0xbb40a859182362d6+ .quad 0xb99f55778a4d1abb+ .quad 0x8d18b427758559f6+ .quad 0x26c20fe74d26235a+ .quad 0x648d1d9fe9cc22f5+ .quad 0x66bc561928dd577c+ .quad 0x47d3ed21652439d1+ .quad 0x49d271acedaf8b49++ // 2^80 * 1 * G++ .quad 0x89f5058a382b33f3+ .quad 0x5ae2ba0bad48c0b4+ .quad 0x8f93b503a53db36e+ .quad 0x5aa3ed9d95a232e6+ .quad 0x2798aaf9b4b75601+ .quad 0x5eac72135c8dad72+ .quad 0xd2ceaa6161b7a023+ .quad 0x1bbfb284e98f7d4e+ .quad 0x656777e9c7d96561+ .quad 0xcb2b125472c78036+ .quad 0x65053299d9506eee+ .quad 0x4a07e14e5e8957cc++ // 2^80 * 2 * G++ .quad 0x4ee412cb980df999+ .quad 0xa315d76f3c6ec771+ .quad 0xbba5edde925c77fd+ .quad 0x3f0bac391d313402+ .quad 0x240b58cdc477a49b+ .quad 0xfd38dade6447f017+ .quad 0x19928d32a7c86aad+ .quad 0x50af7aed84afa081+ .quad 0x6e4fde0115f65be5+ .quad 0x29982621216109b2+ .quad 0x780205810badd6d9+ .quad 0x1921a316baebd006++ // 2^80 * 3 * G++ .quad 0x89422f7edfb870fc+ .quad 0x2c296beb4f76b3bd+ .quad 0x0738f1d436c24df7+ .quad 0x6458df41e273aeb0+ .quad 0xd75aad9ad9f3c18b+ .quad 0x566a0eef60b1c19c+ .quad 0x3e9a0bac255c0ed9+ .quad 0x7b049deca062c7f5+ .quad 0xdccbe37a35444483+ .quad 0x758879330fedbe93+ .quad 0x786004c312c5dd87+ .quad 0x6093dccbc2950e64++ // 2^80 * 4 * G++ .quad 0x1ff39a8585e0706d+ .quad 0x36d0a5d8b3e73933+ .quad 0x43b9f2e1718f453b+ .quad 0x57d1ea084827a97c+ .quad 0x6bdeeebe6084034b+ .quad 0x3199c2b6780fb854+ .quad 0x973376abb62d0695+ .quad 0x6e3180c98b647d90+ .quad 0xee7ab6e7a128b071+ .quad 0xa4c1596d93a88baa+ .quad 0xf7b4de82b2216130+ .quad 0x363e999ddd97bd18++ // 2^80 * 5 * G++ .quad 0x96a843c135ee1fc4+ .quad 0x976eb35508e4c8cf+ .quad 0xb42f6801b58cd330+ .quad 0x48ee9b78693a052b+ .quad 0x2f1848dce24baec6+ .quad 0x769b7255babcaf60+ .quad 0x90cb3c6e3cefe931+ .quad 0x231f979bc6f9b355+ .quad 0x5c31de4bcc2af3c6+ .quad 0xb04bb030fe208d1f+ .quad 0xb78d7009c14fb466+ .quad 0x079bfa9b08792413++ // 2^80 * 6 * G++ .quad 0xe3903a51da300df4+ .quad 0x843964233da95ab0+ .quad 0xed3cf12d0b356480+ .quad 0x038c77f684817194+ .quad 0xf3c9ed80a2d54245+ .quad 0x0aa08b7877f63952+ .quad 0xd76dac63d1085475+ .quad 0x1ef4fb159470636b+ .quad 0x854e5ee65b167bec+ .quad 0x59590a4296d0cdc2+ .quad 0x72b2df3498102199+ .quad 0x575ee92a4a0bff56++ // 2^80 * 7 * G++ .quad 0xd4c080908a182fcf+ .quad 0x30e170c299489dbd+ .quad 0x05babd5752f733de+ .quad 0x43d4e7112cd3fd00+ .quad 0x5d46bc450aa4d801+ .quad 0xc3af1227a533b9d8+ .quad 0x389e3b262b8906c2+ .quad 0x200a1e7e382f581b+ .quad 0x518db967eaf93ac5+ .quad 0x71bc989b056652c0+ .quad 0xfe2b85d9567197f5+ .quad 0x050eca52651e4e38++ // 2^80 * 8 * G++ .quad 0xc3431ade453f0c9c+ .quad 0xe9f5045eff703b9b+ .quad 0xfcd97ac9ed847b3d+ .quad 0x4b0ee6c21c58f4c6+ .quad 0x97ac397660e668ea+ .quad 0x9b19bbfe153ab497+ .quad 0x4cb179b534eca79f+ .quad 0x6151c09fa131ae57+ .quad 0x3af55c0dfdf05d96+ .quad 0xdd262ee02ab4ee7a+ .quad 0x11b2bb8712171709+ .quad 0x1fef24fa800f030b++ // 2^84 * 1 * G++ .quad 0xb496123a6b6c6609+ .quad 0xa750fe8580ab5938+ .quad 0xf471bf39b7c27a5f+ .quad 0x507903ce77ac193c+ .quad 0xff91a66a90166220+ .quad 0xf22552ae5bf1e009+ .quad 0x7dff85d87f90df7c+ .quad 0x4f620ffe0c736fb9+ .quad 0x62f90d65dfde3e34+ .quad 0xcf28c592b9fa5fad+ .quad 0x99c86ef9c6164510+ .quad 0x25d448044a256c84++ // 2^84 * 2 * G++ .quad 0xbd68230ec7e9b16f+ .quad 0x0eb1b9c1c1c5795d+ .quad 0x7943c8c495b6b1ff+ .quad 0x2f9faf620bbacf5e+ .quad 0x2c7c4415c9022b55+ .quad 0x56a0d241812eb1fe+ .quad 0xf02ea1c9d7b65e0d+ .quad 0x4180512fd5323b26+ .quad 0xa4ff3e698a48a5db+ .quad 0xba6a3806bd95403b+ .quad 0x9f7ce1af47d5b65d+ .quad 0x15e087e55939d2fb++ // 2^84 * 3 * G++ .quad 0x12207543745c1496+ .quad 0xdaff3cfdda38610c+ .quad 0xe4e797272c71c34f+ .quad 0x39c07b1934bdede9+ .quad 0x8894186efb963f38+ .quad 0x48a00e80dc639bd5+ .quad 0xa4e8092be96c1c99+ .quad 0x5a097d54ca573661+ .quad 0x2d45892b17c9e755+ .quad 0xd033fd7289308df8+ .quad 0x6c2fe9d9525b8bd9+ .quad 0x2edbecf1c11cc079++ // 2^84 * 4 * G++ .quad 0x1616a4e3c715a0d2+ .quad 0x53623cb0f8341d4d+ .quad 0x96ef5329c7e899cb+ .quad 0x3d4e8dbba668baa6+ .quad 0xee0f0fddd087a25f+ .quad 0x9c7531555c3e34ee+ .quad 0x660c572e8fab3ab5+ .quad 0x0854fc44544cd3b2+ .quad 0x61eba0c555edad19+ .quad 0x24b533fef0a83de6+ .quad 0x3b77042883baa5f8+ .quad 0x678f82b898a47e8d++ // 2^84 * 5 * G++ .quad 0xb1491d0bd6900c54+ .quad 0x3539722c9d132636+ .quad 0x4db928920b362bc9+ .quad 0x4d7cd1fea68b69df+ .quad 0x1e09d94057775696+ .quad 0xeed1265c3cd951db+ .quad 0xfa9dac2b20bce16f+ .quad 0x0f7f76e0e8d089f4+ .quad 0x36d9ebc5d485b00c+ .quad 0xa2596492e4adb365+ .quad 0xc1659480c2119ccd+ .quad 0x45306349186e0d5f++ // 2^84 * 6 * G++ .quad 0x94ddd0c1a6cdff1d+ .quad 0x55f6f115e84213ae+ .quad 0x6c935f85992fcf6a+ .quad 0x067ee0f54a37f16f+ .quad 0x96a414ec2b072491+ .quad 0x1bb2218127a7b65b+ .quad 0x6d2849596e8a4af0+ .quad 0x65f3b08ccd27765f+ .quad 0xecb29fff199801f7+ .quad 0x9d361d1fa2a0f72f+ .quad 0x25f11d2375fd2f49+ .quad 0x124cefe80fe10fe2++ // 2^84 * 7 * G++ .quad 0x4c126cf9d18df255+ .quad 0xc1d471e9147a63b6+ .quad 0x2c6d3c73f3c93b5f+ .quad 0x6be3a6a2e3ff86a2+ .quad 0x1518e85b31b16489+ .quad 0x8faadcb7db710bfb+ .quad 0x39b0bdf4a14ae239+ .quad 0x05f4cbea503d20c1+ .quad 0xce040e9ec04145bc+ .quad 0xc71ff4e208f6834c+ .quad 0xbd546e8dab8847a3+ .quad 0x64666aa0a4d2aba5++ // 2^84 * 8 * G++ .quad 0x6841435a7c06d912+ .quad 0xca123c21bb3f830b+ .quad 0xd4b37b27b1cbe278+ .quad 0x1d753b84c76f5046+ .quad 0xb0c53bf73337e94c+ .quad 0x7cb5697e11e14f15+ .quad 0x4b84abac1930c750+ .quad 0x28dd4abfe0640468+ .quad 0x7dc0b64c44cb9f44+ .quad 0x18a3e1ace3925dbf+ .quad 0x7a3034862d0457c4+ .quad 0x4c498bf78a0c892e++ // 2^88 * 1 * G++ .quad 0x37d653fb1aa73196+ .quad 0x0f9495303fd76418+ .quad 0xad200b09fb3a17b2+ .quad 0x544d49292fc8613e+ .quad 0x22d2aff530976b86+ .quad 0x8d90b806c2d24604+ .quad 0xdca1896c4de5bae5+ .quad 0x28005fe6c8340c17+ .quad 0x6aefba9f34528688+ .quad 0x5c1bff9425107da1+ .quad 0xf75bbbcd66d94b36+ .quad 0x72e472930f316dfa++ // 2^88 * 2 * G++ .quad 0x2695208c9781084f+ .quad 0xb1502a0b23450ee1+ .quad 0xfd9daea603efde02+ .quad 0x5a9d2e8c2733a34c+ .quad 0x07f3f635d32a7627+ .quad 0x7aaa4d865f6566f0+ .quad 0x3c85e79728d04450+ .quad 0x1fee7f000fe06438+ .quad 0x765305da03dbf7e5+ .quad 0xa4daf2491434cdbd+ .quad 0x7b4ad5cdd24a88ec+ .quad 0x00f94051ee040543++ // 2^88 * 3 * G++ .quad 0x8d356b23c3d330b2+ .quad 0xf21c8b9bb0471b06+ .quad 0xb36c316c6e42b83c+ .quad 0x07d79c7e8beab10d+ .quad 0xd7ef93bb07af9753+ .quad 0x583ed0cf3db766a7+ .quad 0xce6998bf6e0b1ec5+ .quad 0x47b7ffd25dd40452+ .quad 0x87fbfb9cbc08dd12+ .quad 0x8a066b3ae1eec29b+ .quad 0x0d57242bdb1fc1bf+ .quad 0x1c3520a35ea64bb6++ // 2^88 * 4 * G++ .quad 0x80d253a6bccba34a+ .quad 0x3e61c3a13838219b+ .quad 0x90c3b6019882e396+ .quad 0x1c3d05775d0ee66f+ .quad 0xcda86f40216bc059+ .quad 0x1fbb231d12bcd87e+ .quad 0xb4956a9e17c70990+ .quad 0x38750c3b66d12e55+ .quad 0x692ef1409422e51a+ .quad 0xcbc0c73c2b5df671+ .quad 0x21014fe7744ce029+ .quad 0x0621e2c7d330487c++ // 2^88 * 5 * G++ .quad 0xaf9860cc8259838d+ .quad 0x90ea48c1c69f9adc+ .quad 0x6526483765581e30+ .quad 0x0007d6097bd3a5bc+ .quad 0xb7ae1796b0dbf0f3+ .quad 0x54dfafb9e17ce196+ .quad 0x25923071e9aaa3b4+ .quad 0x5d8e589ca1002e9d+ .quad 0xc0bf1d950842a94b+ .quad 0xb2d3c363588f2e3e+ .quad 0x0a961438bb51e2ef+ .quad 0x1583d7783c1cbf86++ // 2^88 * 6 * G++ .quad 0xeceea2ef5da27ae1+ .quad 0x597c3a1455670174+ .quad 0xc9a62a126609167a+ .quad 0x252a5f2e81ed8f70+ .quad 0x90034704cc9d28c7+ .quad 0x1d1b679ef72cc58f+ .quad 0x16e12b5fbe5b8726+ .quad 0x4958064e83c5580a+ .quad 0x0d2894265066e80d+ .quad 0xfcc3f785307c8c6b+ .quad 0x1b53da780c1112fd+ .quad 0x079c170bd843b388++ // 2^88 * 7 * G++ .quad 0x0506ece464fa6fff+ .quad 0xbee3431e6205e523+ .quad 0x3579422451b8ea42+ .quad 0x6dec05e34ac9fb00+ .quad 0xcdd6cd50c0d5d056+ .quad 0x9af7686dbb03573b+ .quad 0x3ca6723ff3c3ef48+ .quad 0x6768c0d7317b8acc+ .quad 0x94b625e5f155c1b3+ .quad 0x417bf3a7997b7b91+ .quad 0xc22cbddc6d6b2600+ .quad 0x51445e14ddcd52f4++ // 2^88 * 8 * G++ .quad 0x57502b4b3b144951+ .quad 0x8e67ff6b444bbcb3+ .quad 0xb8bd6927166385db+ .quad 0x13186f31e39295c8+ .quad 0x893147ab2bbea455+ .quad 0x8c53a24f92079129+ .quad 0x4b49f948be30f7a7+ .quad 0x12e990086e4fd43d+ .quad 0xf10c96b37fdfbb2e+ .quad 0x9f9a935e121ceaf9+ .quad 0xdf1136c43a5b983f+ .quad 0x77b2e3f05d3e99af++ // 2^92 * 1 * G++ .quad 0xfd0d75879cf12657+ .quad 0xe82fef94e53a0e29+ .quad 0xcc34a7f05bbb4be7+ .quad 0x0b251172a50c38a2+ .quad 0x9532f48fcc5cd29b+ .quad 0x2ba851bea3ce3671+ .quad 0x32dacaa051122941+ .quad 0x478d99d9350004f2+ .quad 0x1d5ad94890bb02c0+ .quad 0x50e208b10ec25115+ .quad 0xa26a22894ef21702+ .quad 0x4dc923343b524805++ // 2^92 * 2 * G++ .quad 0xe3828c400f8086b6+ .quad 0x3f77e6f7979f0dc8+ .quad 0x7ef6de304df42cb4+ .quad 0x5265797cb6abd784+ .quad 0x3ad3e3ebf36c4975+ .quad 0xd75d25a537862125+ .quad 0xe873943da025a516+ .quad 0x6bbc7cb4c411c847+ .quad 0x3c6f9cd1d4a50d56+ .quad 0xb6244077c6feab7e+ .quad 0x6ff9bf483580972e+ .quad 0x00375883b332acfb++ // 2^92 * 3 * G++ .quad 0x0001b2cd28cb0940+ .quad 0x63fb51a06f1c24c9+ .quad 0xb5ad8691dcd5ca31+ .quad 0x67238dbd8c450660+ .quad 0xc98bec856c75c99c+ .quad 0xe44184c000e33cf4+ .quad 0x0a676b9bba907634+ .quad 0x669e2cb571f379d7+ .quad 0xcb116b73a49bd308+ .quad 0x025aad6b2392729e+ .quad 0xb4793efa3f55d9b1+ .quad 0x72a1056140678bb9++ // 2^92 * 4 * G++ .quad 0xa2b6812b1cc9249d+ .quad 0x62866eee21211f58+ .quad 0x2cb5c5b85df10ece+ .quad 0x03a6b259e263ae00+ .quad 0x0d8d2909e2e505b6+ .quad 0x98ca78abc0291230+ .quad 0x77ef5569a9b12327+ .quad 0x7c77897b81439b47+ .quad 0xf1c1b5e2de331cb5+ .quad 0x5a9f5d8e15fca420+ .quad 0x9fa438f17bd932b1+ .quad 0x2a381bf01c6146e7++ // 2^92 * 5 * G++ .quad 0xac9b9879cfc811c1+ .quad 0x8b7d29813756e567+ .quad 0x50da4e607c70edfc+ .quad 0x5dbca62f884400b6+ .quad 0xf7c0be32b534166f+ .quad 0x27e6ca6419cf70d4+ .quad 0x934df7d7a957a759+ .quad 0x5701461dabdec2aa+ .quad 0x2c6747402c915c25+ .quad 0x1bdcd1a80b0d340a+ .quad 0x5e5601bd07b43f5f+ .quad 0x2555b4e05539a242++ // 2^92 * 6 * G++ .quad 0x6fc09f5266ddd216+ .quad 0xdce560a7c8e37048+ .quad 0xec65939da2df62fd+ .quad 0x7a869ae7e52ed192+ .quad 0x78409b1d87e463d4+ .quad 0xad4da95acdfb639d+ .quad 0xec28773755259b9c+ .quad 0x69c806e9c31230ab+ .quad 0x7b48f57414bb3f22+ .quad 0x68c7cee4aedccc88+ .quad 0xed2f936179ed80be+ .quad 0x25d70b885f77bc4b++ // 2^92 * 7 * G++ .quad 0x4151c3d9762bf4de+ .quad 0x083f435f2745d82b+ .quad 0x29775a2e0d23ddd5+ .quad 0x138e3a6269a5db24+ .quad 0x98459d29bb1ae4d4+ .quad 0x56b9c4c739f954ec+ .quad 0x832743f6c29b4b3e+ .quad 0x21ea8e2798b6878a+ .quad 0x87bef4b46a5a7b9c+ .quad 0xd2299d1b5fc1d062+ .quad 0x82409818dd321648+ .quad 0x5c5abeb1e5a2e03d++ // 2^92 * 8 * G++ .quad 0x14722af4b73c2ddb+ .quad 0xbc470c5f5a05060d+ .quad 0x00943eac2581b02e+ .quad 0x0e434b3b1f499c8f+ .quad 0x02cde6de1306a233+ .quad 0x7b5a52a2116f8ec7+ .quad 0xe1c681f4c1163b5b+ .quad 0x241d350660d32643+ .quad 0x6be4404d0ebc52c7+ .quad 0xae46233bb1a791f5+ .quad 0x2aec170ed25db42b+ .quad 0x1d8dfd966645d694++ // 2^96 * 1 * G++ .quad 0x296fa9c59c2ec4de+ .quad 0xbc8b61bf4f84f3cb+ .quad 0x1c7706d917a8f908+ .quad 0x63b795fc7ad3255d+ .quad 0xd598639c12ddb0a4+ .quad 0xa5d19f30c024866b+ .quad 0xd17c2f0358fce460+ .quad 0x07a195152e095e8a+ .quad 0xa8368f02389e5fc8+ .quad 0x90433b02cf8de43b+ .quad 0xafa1fd5dc5412643+ .quad 0x3e8fe83d032f0137++ // 2^96 * 2 * G++ .quad 0x2f8b15b90570a294+ .quad 0x94f2427067084549+ .quad 0xde1c5ae161bbfd84+ .quad 0x75ba3b797fac4007+ .quad 0x08704c8de8efd13c+ .quad 0xdfc51a8e33e03731+ .quad 0xa59d5da51260cde3+ .quad 0x22d60899a6258c86+ .quad 0x6239dbc070cdd196+ .quad 0x60fe8a8b6c7d8a9a+ .quad 0xb38847bceb401260+ .quad 0x0904d07b87779e5e++ // 2^96 * 3 * G++ .quad 0xb4ce1fd4ddba919c+ .quad 0xcf31db3ec74c8daa+ .quad 0x2c63cc63ad86cc51+ .quad 0x43e2143fbc1dde07+ .quad 0xf4322d6648f940b9+ .quad 0x06952f0cbd2d0c39+ .quad 0x167697ada081f931+ .quad 0x6240aacebaf72a6c+ .quad 0xf834749c5ba295a0+ .quad 0xd6947c5bca37d25a+ .quad 0x66f13ba7e7c9316a+ .quad 0x56bdaf238db40cac++ // 2^96 * 4 * G++ .quad 0x362ab9e3f53533eb+ .quad 0x338568d56eb93d40+ .quad 0x9e0e14521d5a5572+ .quad 0x1d24a86d83741318+ .quad 0x1310d36cc19d3bb2+ .quad 0x062a6bb7622386b9+ .quad 0x7c9b8591d7a14f5c+ .quad 0x03aa31507e1e5754+ .quad 0xf4ec7648ffd4ce1f+ .quad 0xe045eaf054ac8c1c+ .quad 0x88d225821d09357c+ .quad 0x43b261dc9aeb4859++ // 2^96 * 5 * G++ .quad 0xe55b1e1988bb79bb+ .quad 0xa09ed07dc17a359d+ .quad 0xb02c2ee2603dea33+ .quad 0x326055cf5b276bc2+ .quad 0x19513d8b6c951364+ .quad 0x94fe7126000bf47b+ .quad 0x028d10ddd54f9567+ .quad 0x02b4d5e242940964+ .quad 0xb4a155cb28d18df2+ .quad 0xeacc4646186ce508+ .quad 0xc49cf4936c824389+ .quad 0x27a6c809ae5d3410++ // 2^96 * 6 * G++ .quad 0x8ba6ebcd1f0db188+ .quad 0x37d3d73a675a5be8+ .quad 0xf22edfa315f5585a+ .quad 0x2cb67174ff60a17e+ .quad 0xcd2c270ac43d6954+ .quad 0xdd4a3e576a66cab2+ .quad 0x79fa592469d7036c+ .quad 0x221503603d8c2599+ .quad 0x59eecdf9390be1d0+ .quad 0xa9422044728ce3f1+ .quad 0x82891c667a94f0f4+ .quad 0x7b1df4b73890f436++ // 2^96 * 7 * G++ .quad 0xe492f2e0b3b2a224+ .quad 0x7c6c9e062b551160+ .quad 0x15eb8fe20d7f7b0e+ .quad 0x61fcef2658fc5992+ .quad 0x5f2e221807f8f58c+ .quad 0xe3555c9fd49409d4+ .quad 0xb2aaa88d1fb6a630+ .quad 0x68698245d352e03d+ .quad 0xdbb15d852a18187a+ .quad 0xf3e4aad386ddacd7+ .quad 0x44bae2810ff6c482+ .quad 0x46cf4c473daf01cf++ // 2^96 * 8 * G++ .quad 0x426525ed9ec4e5f9+ .quad 0x0e5eda0116903303+ .quad 0x72b1a7f2cbe5cadc+ .quad 0x29387bcd14eb5f40+ .quad 0x213c6ea7f1498140+ .quad 0x7c1e7ef8392b4854+ .quad 0x2488c38c5629ceba+ .quad 0x1065aae50d8cc5bb+ .quad 0x1c2c4525df200d57+ .quad 0x5c3b2dd6bfca674a+ .quad 0x0a07e7b1e1834030+ .quad 0x69a198e64f1ce716++ // 2^100 * 1 * G++ .quad 0x7afcd613efa9d697+ .quad 0x0cc45aa41c067959+ .quad 0xa56fe104c1fada96+ .quad 0x3a73b70472e40365+ .quad 0x7b26e56b9e2d4734+ .quad 0xc4c7132b81c61675+ .quad 0xef5c9525ec9cde7f+ .quad 0x39c80b16e71743ad+ .quad 0x0f196e0d1b826c68+ .quad 0xf71ff0e24960e3db+ .quad 0x6113167023b7436c+ .quad 0x0cf0ea5877da7282++ // 2^100 * 2 * G++ .quad 0x196c80a4ddd4ccbd+ .quad 0x22e6f55d95f2dd9d+ .quad 0xc75e33c740d6c71b+ .quad 0x7bb51279cb3c042f+ .quad 0xe332ced43ba6945a+ .quad 0xde0b1361e881c05d+ .quad 0x1ad40f095e67ed3b+ .quad 0x5da8acdab8c63d5d+ .quad 0xc4b6664a3a70159f+ .quad 0x76194f0f0a904e14+ .quad 0xa5614c39a4096c13+ .quad 0x6cd0ff50979feced++ // 2^100 * 3 * G++ .quad 0xc0e067e78f4428ac+ .quad 0x14835ab0a61135e3+ .quad 0xf21d14f338062935+ .quad 0x6390a4c8df04849c+ .quad 0x7fecfabdb04ba18e+ .quad 0xd0fc7bfc3bddbcf7+ .quad 0xa41d486e057a131c+ .quad 0x641a4391f2223a61+ .quad 0xc5c6b95aa606a8db+ .quad 0x914b7f9eb06825f1+ .quad 0x2a731f6b44fc9eff+ .quad 0x30ddf38562705cfc++ // 2^100 * 4 * G++ .quad 0x4e3dcbdad1bff7f9+ .quad 0xc9118e8220645717+ .quad 0xbacccebc0f189d56+ .quad 0x1b4822e9d4467668+ .quad 0x33bef2bd68bcd52c+ .quad 0xc649dbb069482ef2+ .quad 0xb5b6ee0c41cb1aee+ .quad 0x5c294d270212a7e5+ .quad 0xab360a7f25563781+ .quad 0x2512228a480f7958+ .quad 0xc75d05276114b4e3+ .quad 0x222d9625d976fe2a++ // 2^100 * 5 * G++ .quad 0x1c717f85b372ace1+ .quad 0x81930e694638bf18+ .quad 0x239cad056bc08b58+ .quad 0x0b34271c87f8fff4+ .quad 0x0f94be7e0a344f85+ .quad 0xeb2faa8c87f22c38+ .quad 0x9ce1e75e4ee16f0f+ .quad 0x43e64e5418a08dea+ .quad 0x8155e2521a35ce63+ .quad 0xbe100d4df912028e+ .quad 0xbff80bf8a57ddcec+ .quad 0x57342dc96d6bc6e4++ // 2^100 * 6 * G++ .quad 0xefeef065c8ce5998+ .quad 0xbf029510b5cbeaa2+ .quad 0x8c64a10620b7c458+ .quad 0x35134fb231c24855+ .quad 0xf3c3bcb71e707bf6+ .quad 0x351d9b8c7291a762+ .quad 0x00502e6edad69a33+ .quad 0x522f521f1ec8807f+ .quad 0x272c1f46f9a3902b+ .quad 0xc91ba3b799657bcc+ .quad 0xae614b304f8a1c0e+ .quad 0x7afcaad70b99017b++ // 2^100 * 7 * G++ .quad 0xc25ded54a4b8be41+ .quad 0x902d13e11bb0e2dd+ .quad 0x41f43233cde82ab2+ .quad 0x1085faa5c3aae7cb+ .quad 0xa88141ecef842b6b+ .quad 0x55e7b14797abe6c5+ .quad 0x8c748f9703784ffe+ .quad 0x5b50a1f7afcd00b7+ .quad 0x9b840f66f1361315+ .quad 0x18462242701003e9+ .quad 0x65ed45fae4a25080+ .quad 0x0a2862393fda7320++ // 2^100 * 8 * G++ .quad 0x46ab13c8347cbc9d+ .quad 0x3849e8d499c12383+ .quad 0x4cea314087d64ac9+ .quad 0x1f354134b1a29ee7+ .quad 0x960e737b6ecb9d17+ .quad 0xfaf24948d67ceae1+ .quad 0x37e7a9b4d55e1b89+ .quad 0x5cb7173cb46c59eb+ .quad 0x4a89e68b82b7abf0+ .quad 0xf41cd9279ba6b7b9+ .quad 0x16e6c210e18d876f+ .quad 0x7cacdb0f7f1b09c6++ // 2^104 * 1 * G++ .quad 0x9062b2e0d91a78bc+ .quad 0x47c9889cc8509667+ .quad 0x9df54a66405070b8+ .quad 0x7369e6a92493a1bf+ .quad 0xe1014434dcc5caed+ .quad 0x47ed5d963c84fb33+ .quad 0x70019576ed86a0e7+ .quad 0x25b2697bd267f9e4+ .quad 0x9d673ffb13986864+ .quad 0x3ca5fbd9415dc7b8+ .quad 0xe04ecc3bdf273b5e+ .quad 0x1420683db54e4cd2++ // 2^104 * 2 * G++ .quad 0xb478bd1e249dd197+ .quad 0x620c35005e58c102+ .quad 0xfb02d32fccbaac5c+ .quad 0x60b63bebf508a72d+ .quad 0x34eebb6fc1cc5ad0+ .quad 0x6a1b0ce99646ac8b+ .quad 0xd3b0da49a66bde53+ .quad 0x31e83b4161d081c1+ .quad 0x97e8c7129e062b4f+ .quad 0x49e48f4f29320ad8+ .quad 0x5bece14b6f18683f+ .quad 0x55cf1eb62d550317++ // 2^104 * 3 * G++ .quad 0x5879101065c23d58+ .quad 0x8b9d086d5094819c+ .quad 0xe2402fa912c55fa7+ .quad 0x669a6564570891d4+ .quad 0x3076b5e37df58c52+ .quad 0xd73ab9dde799cc36+ .quad 0xbd831ce34913ee20+ .quad 0x1a56fbaa62ba0133+ .quad 0x943e6b505c9dc9ec+ .quad 0x302557bba77c371a+ .quad 0x9873ae5641347651+ .quad 0x13c4836799c58a5c++ // 2^104 * 4 * G++ .quad 0x423a5d465ab3e1b9+ .quad 0xfc13c187c7f13f61+ .quad 0x19f83664ecb5b9b6+ .quad 0x66f80c93a637b607+ .quad 0xc4dcfb6a5d8bd080+ .quad 0xdeebc4ec571a4842+ .quad 0xd4b2e883b8e55365+ .quad 0x50bdc87dc8e5b827+ .quad 0x606d37836edfe111+ .quad 0x32353e15f011abd9+ .quad 0x64b03ac325b73b96+ .quad 0x1dd56444725fd5ae++ // 2^104 * 5 * G++ .quad 0x8fa47ff83362127d+ .quad 0xbc9f6ac471cd7c15+ .quad 0x6e71454349220c8b+ .quad 0x0e645912219f732e+ .quad 0xc297e60008bac89a+ .quad 0x7d4cea11eae1c3e0+ .quad 0xf3e38be19fe7977c+ .quad 0x3a3a450f63a305cd+ .quad 0x078f2f31d8394627+ .quad 0x389d3183de94a510+ .quad 0xd1e36c6d17996f80+ .quad 0x318c8d9393a9a87b++ // 2^104 * 6 * G++ .quad 0xf2745d032afffe19+ .quad 0x0c9f3c497f24db66+ .quad 0xbc98d3e3ba8598ef+ .quad 0x224c7c679a1d5314+ .quad 0x5d669e29ab1dd398+ .quad 0xfc921658342d9e3b+ .quad 0x55851dfdf35973cd+ .quad 0x509a41c325950af6+ .quad 0xbdc06edca6f925e9+ .quad 0x793ef3f4641b1f33+ .quad 0x82ec12809d833e89+ .quad 0x05bff02328a11389++ // 2^104 * 7 * G++ .quad 0x3632137023cae00b+ .quad 0x544acf0ad1accf59+ .quad 0x96741049d21a1c88+ .quad 0x780b8cc3fa2a44a7+ .quad 0x6881a0dd0dc512e4+ .quad 0x4fe70dc844a5fafe+ .quad 0x1f748e6b8f4a5240+ .quad 0x576277cdee01a3ea+ .quad 0x1ef38abc234f305f+ .quad 0x9a577fbd1405de08+ .quad 0x5e82a51434e62a0d+ .quad 0x5ff418726271b7a1++ // 2^104 * 8 * G++ .quad 0x398e080c1789db9d+ .quad 0xa7602025f3e778f5+ .quad 0xfa98894c06bd035d+ .quad 0x106a03dc25a966be+ .quad 0xe5db47e813b69540+ .quad 0xf35d2a3b432610e1+ .quad 0xac1f26e938781276+ .quad 0x29d4db8ca0a0cb69+ .quad 0xd9ad0aaf333353d0+ .quad 0x38669da5acd309e5+ .quad 0x3c57658ac888f7f0+ .quad 0x4ab38a51052cbefa++ // 2^108 * 1 * G++ .quad 0xdfdacbee4324c0e9+ .quad 0x054442883f955bb7+ .quad 0xdef7aaa8ea31609f+ .quad 0x68aee70642287cff+ .quad 0xf68fe2e8809de054+ .quad 0xe3bc096a9c82bad1+ .quad 0x076353d40aadbf45+ .quad 0x7b9b1fb5dea1959e+ .quad 0xf01cc8f17471cc0c+ .quad 0x95242e37579082bb+ .quad 0x27776093d3e46b5f+ .quad 0x2d13d55a28bd85fb++ // 2^108 * 2 * G++ .quad 0xfac5d2065b35b8da+ .quad 0xa8da8a9a85624bb7+ .quad 0xccd2ca913d21cd0f+ .quad 0x6b8341ee8bf90d58+ .quad 0xbf019cce7aee7a52+ .quad 0xa8ded2b6e454ead3+ .quad 0x3c619f0b87a8bb19+ .quad 0x3619b5d7560916d8+ .quad 0x3579f26b0282c4b2+ .quad 0x64d592f24fafefae+ .quad 0xb7cded7b28c8c7c0+ .quad 0x6a927b6b7173a8d7++ // 2^108 * 3 * G++ .quad 0x1f6db24f986e4656+ .quad 0x1021c02ed1e9105b+ .quad 0xf8ff3fff2cc0a375+ .quad 0x1d2a6bf8c6c82592+ .quad 0x8d7040863ece88eb+ .quad 0xf0e307a980eec08c+ .quad 0xac2250610d788fda+ .quad 0x056d92a43a0d478d+ .quad 0x1b05a196fc3da5a1+ .quad 0x77d7a8c243b59ed0+ .quad 0x06da3d6297d17918+ .quad 0x66fbb494f12353f7++ // 2^108 * 4 * G++ .quad 0x751a50b9d85c0fb8+ .quad 0xd1afdc258bcf097b+ .quad 0x2f16a6a38309a969+ .quad 0x14ddff9ee5b00659+ .quad 0xd6d70996f12309d6+ .quad 0xdbfb2385e9c3d539+ .quad 0x46d602b0f7552411+ .quad 0x270a0b0557843e0c+ .quad 0x61ff0640a7862bcc+ .quad 0x81cac09a5f11abfe+ .quad 0x9047830455d12abb+ .quad 0x19a4bde1945ae873++ // 2^108 * 5 * G++ .quad 0x9b9f26f520a6200a+ .quad 0x64804443cf13eaf8+ .quad 0x8a63673f8631edd3+ .quad 0x72bbbce11ed39dc1+ .quad 0x40c709dec076c49f+ .quad 0x657bfaf27f3e53f6+ .quad 0x40662331eca042c4+ .quad 0x14b375487eb4df04+ .quad 0xae853c94ab66dc47+ .quad 0xeb62343edf762d6e+ .quad 0xf08e0e186fb2f7d1+ .quad 0x4f0b1c02700ab37a++ // 2^108 * 6 * G++ .quad 0xe1706787d81951fa+ .quad 0xa10a2c8eb290c77b+ .quad 0xe7382fa03ed66773+ .quad 0x0a4d84710bcc4b54+ .quad 0x79fd21ccc1b2e23f+ .quad 0x4ae7c281453df52a+ .quad 0xc8172ec9d151486b+ .quad 0x68abe9443e0a7534+ .quad 0xda12c6c407831dcb+ .quad 0x0da230d74d5c510d+ .quad 0x4ab1531e6bd404e1+ .quad 0x4106b166bcf440ef++ // 2^108 * 7 * G++ .quad 0x02e57a421cd23668+ .quad 0x4ad9fb5d0eaef6fd+ .quad 0x954e6727b1244480+ .quad 0x7f792f9d2699f331+ .quad 0xa485ccd539e4ecf2+ .quad 0x5aa3f3ad0555bab5+ .quad 0x145e3439937df82d+ .quad 0x1238b51e1214283f+ .quad 0x0b886b925fd4d924+ .quad 0x60906f7a3626a80d+ .quad 0xecd367b4b98abd12+ .quad 0x2876beb1def344cf++ // 2^108 * 8 * G++ .quad 0xdc84e93563144691+ .quad 0x632fe8a0d61f23f4+ .quad 0x4caa800612a9a8d5+ .quad 0x48f9dbfa0e9918d3+ .quad 0xd594b3333a8a85f8+ .quad 0x4ea37689e78d7d58+ .quad 0x73bf9f455e8e351f+ .quad 0x5507d7d2bc41ebb4+ .quad 0x1ceb2903299572fc+ .quad 0x7c8ccaa29502d0ee+ .quad 0x91bfa43411cce67b+ .quad 0x5784481964a831e7++ // 2^112 * 1 * G++ .quad 0xda7c2b256768d593+ .quad 0x98c1c0574422ca13+ .quad 0xf1a80bd5ca0ace1d+ .quad 0x29cdd1adc088a690+ .quad 0xd6cfd1ef5fddc09c+ .quad 0xe82b3efdf7575dce+ .quad 0x25d56b5d201634c2+ .quad 0x3041c6bb04ed2b9b+ .quad 0x0ff2f2f9d956e148+ .quad 0xade797759f356b2e+ .quad 0x1a4698bb5f6c025c+ .quad 0x104bbd6814049a7b++ // 2^112 * 2 * G++ .quad 0x51f0fd3168f1ed67+ .quad 0x2c811dcdd86f3bc2+ .quad 0x44dc5c4304d2f2de+ .quad 0x5be8cc57092a7149+ .quad 0xa95d9a5fd67ff163+ .quad 0xe92be69d4cc75681+ .quad 0xb7f8024cde20f257+ .quad 0x204f2a20fb072df5+ .quad 0xc8143b3d30ebb079+ .quad 0x7589155abd652e30+ .quad 0x653c3c318f6d5c31+ .quad 0x2570fb17c279161f++ // 2^112 * 3 * G++ .quad 0x3efa367f2cb61575+ .quad 0xf5f96f761cd6026c+ .quad 0xe8c7142a65b52562+ .quad 0x3dcb65ea53030acd+ .quad 0x192ea9550bb8245a+ .quad 0xc8e6fba88f9050d1+ .quad 0x7986ea2d88a4c935+ .quad 0x241c5f91de018668+ .quad 0x28d8172940de6caa+ .quad 0x8fbf2cf022d9733a+ .quad 0x16d7fcdd235b01d1+ .quad 0x08420edd5fcdf0e5++ // 2^112 * 4 * G++ .quad 0xcdff20ab8362fa4a+ .quad 0x57e118d4e21a3e6e+ .quad 0xe3179617fc39e62b+ .quad 0x0d9a53efbc1769fd+ .quad 0x0358c34e04f410ce+ .quad 0xb6135b5a276e0685+ .quad 0x5d9670c7ebb91521+ .quad 0x04d654f321db889c+ .quad 0x5e7dc116ddbdb5d5+ .quad 0x2954deb68da5dd2d+ .quad 0x1cb608173334a292+ .quad 0x4a7a4f2618991ad7++ // 2^112 * 5 * G++ .quad 0xf4a718025fb15f95+ .quad 0x3df65f346b5c1b8f+ .quad 0xcdfcf08500e01112+ .quad 0x11b50c4cddd31848+ .quad 0x24c3b291af372a4b+ .quad 0x93da8270718147f2+ .quad 0xdd84856486899ef2+ .quad 0x4a96314223e0ee33+ .quad 0xa6e8274408a4ffd6+ .quad 0x738e177e9c1576d9+ .quad 0x773348b63d02b3f2+ .quad 0x4f4bce4dce6bcc51++ // 2^112 * 6 * G++ .quad 0xa71fce5ae2242584+ .quad 0x26ea725692f58a9e+ .quad 0xd21a09d71cea3cf4+ .quad 0x73fcdd14b71c01e6+ .quad 0x30e2616ec49d0b6f+ .quad 0xe456718fcaec2317+ .quad 0x48eb409bf26b4fa6+ .quad 0x3042cee561595f37+ .quad 0x427e7079449bac41+ .quad 0x855ae36dbce2310a+ .quad 0x4cae76215f841a7c+ .quad 0x389e740c9a9ce1d6++ // 2^112 * 7 * G++ .quad 0x64fcb3ae34dcb9ce+ .quad 0x97500323e348d0ad+ .quad 0x45b3f07d62c6381b+ .quad 0x61545379465a6788+ .quad 0xc9bd78f6570eac28+ .quad 0xe55b0b3227919ce1+ .quad 0x65fc3eaba19b91ed+ .quad 0x25c425e5d6263690+ .quad 0x3f3e06a6f1d7de6e+ .quad 0x3ef976278e062308+ .quad 0x8c14f6264e8a6c77+ .quad 0x6539a08915484759++ // 2^112 * 8 * G++ .quad 0xe9d21f74c3d2f773+ .quad 0xc150544125c46845+ .quad 0x624e5ce8f9b99e33+ .quad 0x11c5e4aac5cd186c+ .quad 0xddc4dbd414bb4a19+ .quad 0x19b2bc3c98424f8e+ .quad 0x48a89fd736ca7169+ .quad 0x0f65320ef019bd90+ .quad 0xd486d1b1cafde0c6+ .quad 0x4f3fe6e3163b5181+ .quad 0x59a8af0dfaf2939a+ .quad 0x4cabc7bdec33072a++ // 2^116 * 1 * G++ .quad 0x16faa8fb532f7428+ .quad 0xdbd42ea046a4e272+ .quad 0x5337653b8b9ea480+ .quad 0x4065947223973f03+ .quad 0xf7c0a19c1a54a044+ .quad 0x4a1c5e2477bd9fbb+ .quad 0xa6e3ca115af22972+ .quad 0x1819bb953f2e9e0d+ .quad 0x498fbb795e042e84+ .quad 0x7d0dd89a7698b714+ .quad 0x8bfb0ba427fe6295+ .quad 0x36ba82e721200524++ // 2^116 * 2 * G++ .quad 0xd60ecbb74245ec41+ .quad 0xfd9be89e34348716+ .quad 0xc9240afee42284de+ .quad 0x4472f648d0531db4+ .quad 0xc8d69d0a57274ed5+ .quad 0x45ba803260804b17+ .quad 0xdf3cda102255dfac+ .quad 0x77d221232709b339+ .quad 0x498a6d7064ad94d8+ .quad 0xa5b5c8fd9af62263+ .quad 0x8ca8ed0545c141f4+ .quad 0x2c63bec3662d358c++ // 2^116 * 3 * G++ .quad 0x7fe60d8bea787955+ .quad 0xb9dc117eb5f401b7+ .quad 0x91c7c09a19355cce+ .quad 0x22692ef59442bedf+ .quad 0x9a518b3a8586f8bf+ .quad 0x9ee71af6cbb196f0+ .quad 0xaa0625e6a2385cf2+ .quad 0x1deb2176ddd7c8d1+ .quad 0x8563d19a2066cf6c+ .quad 0x401bfd8c4dcc7cd7+ .quad 0xd976a6becd0d8f62+ .quad 0x67cfd773a278b05e++ // 2^116 * 4 * G++ .quad 0x8dec31faef3ee475+ .quad 0x99dbff8a9e22fd92+ .quad 0x512d11594e26cab1+ .quad 0x0cde561eec4310b9+ .quad 0x2d5fa9855a4e586a+ .quad 0x65f8f7a449beab7e+ .quad 0xaa074dddf21d33d3+ .quad 0x185cba721bcb9dee+ .quad 0x93869da3f4e3cb41+ .quad 0xbf0392f540f7977e+ .quad 0x026204fcd0463b83+ .quad 0x3ec91a769eec6eed++ // 2^116 * 5 * G++ .quad 0x1e9df75bf78166ad+ .quad 0x4dfda838eb0cd7af+ .quad 0xba002ed8c1eaf988+ .quad 0x13fedb3e11f33cfc+ .quad 0x0fad2fb7b0a3402f+ .quad 0x46615ecbfb69f4a8+ .quad 0xf745bcc8c5f8eaa6+ .quad 0x7a5fa8794a94e896+ .quad 0x52958faa13cd67a1+ .quad 0x965ee0818bdbb517+ .quad 0x16e58daa2e8845b3+ .quad 0x357d397d5499da8f++ // 2^116 * 6 * G++ .quad 0x1ebfa05fb0bace6c+ .quad 0xc934620c1caf9a1e+ .quad 0xcc771cc41d82b61a+ .quad 0x2d94a16aa5f74fec+ .quad 0x481dacb4194bfbf8+ .quad 0x4d77e3f1bae58299+ .quad 0x1ef4612e7d1372a0+ .quad 0x3a8d867e70ff69e1+ .quad 0x6f58cd5d55aff958+ .quad 0xba3eaa5c75567721+ .quad 0x75c123999165227d+ .quad 0x69be1343c2f2b35e++ // 2^116 * 7 * G++ .quad 0x0e091d5ee197c92a+ .quad 0x4f51019f2945119f+ .quad 0x143679b9f034e99c+ .quad 0x7d88112e4d24c696+ .quad 0x82bbbdac684b8de3+ .quad 0xa2f4c7d03fca0718+ .quad 0x337f92fbe096aaa8+ .quad 0x200d4d8c63587376+ .quad 0x208aed4b4893b32b+ .quad 0x3efbf23ebe59b964+ .quad 0xd762deb0dba5e507+ .quad 0x69607bd681bd9d94++ // 2^116 * 8 * G++ .quad 0xf6be021068de1ce1+ .quad 0xe8d518e70edcbc1f+ .quad 0xe3effdd01b5505a5+ .quad 0x35f63353d3ec3fd0+ .quad 0x3b7f3bd49323a902+ .quad 0x7c21b5566b2c6e53+ .quad 0xe5ba8ff53a7852a7+ .quad 0x28bc77a5838ece00+ .quad 0x63ba78a8e25d8036+ .quad 0x63651e0094333490+ .quad 0x48d82f20288ce532+ .quad 0x3a31abfa36b57524++ // 2^120 * 1 * G++ .quad 0x239e9624089c0a2e+ .quad 0xc748c4c03afe4738+ .quad 0x17dbed2a764fa12a+ .quad 0x639b93f0321c8582+ .quad 0xc08f788f3f78d289+ .quad 0xfe30a72ca1404d9f+ .quad 0xf2778bfccf65cc9d+ .quad 0x7ee498165acb2021+ .quad 0x7bd508e39111a1c3+ .quad 0x2b2b90d480907489+ .quad 0xe7d2aec2ae72fd19+ .quad 0x0edf493c85b602a6++ // 2^120 * 2 * G++ .quad 0xaecc8158599b5a68+ .quad 0xea574f0febade20e+ .quad 0x4fe41d7422b67f07+ .quad 0x403b92e3019d4fb4+ .quad 0x6767c4d284764113+ .quad 0xa090403ff7f5f835+ .quad 0x1c8fcffacae6bede+ .quad 0x04c00c54d1dfa369+ .quad 0x4dc22f818b465cf8+ .quad 0x71a0f35a1480eff8+ .quad 0xaee8bfad04c7d657+ .quad 0x355bb12ab26176f4++ // 2^120 * 3 * G++ .quad 0xa71e64cc7493bbf4+ .quad 0xe5bd84d9eca3b0c3+ .quad 0x0a6bc50cfa05e785+ .quad 0x0f9b8132182ec312+ .quad 0xa301dac75a8c7318+ .quad 0xed90039db3ceaa11+ .quad 0x6f077cbf3bae3f2d+ .quad 0x7518eaf8e052ad8e+ .quad 0xa48859c41b7f6c32+ .quad 0x0f2d60bcf4383298+ .quad 0x1815a929c9b1d1d9+ .quad 0x47c3871bbb1755c4++ // 2^120 * 4 * G++ .quad 0x5144539771ec4f48+ .quad 0xf805b17dc98c5d6e+ .quad 0xf762c11a47c3c66b+ .quad 0x00b89b85764699dc+ .quad 0xfbe65d50c85066b0+ .quad 0x62ecc4b0b3a299b0+ .quad 0xe53754ea441ae8e0+ .quad 0x08fea02ce8d48d5f+ .quad 0x824ddd7668deead0+ .quad 0xc86445204b685d23+ .quad 0xb514cfcd5d89d665+ .quad 0x473829a74f75d537++ // 2^120 * 5 * G++ .quad 0x82d2da754679c418+ .quad 0xe63bd7d8b2618df0+ .quad 0x355eef24ac47eb0a+ .quad 0x2078684c4833c6b4+ .quad 0x23d9533aad3902c9+ .quad 0x64c2ddceef03588f+ .quad 0x15257390cfe12fb4+ .quad 0x6c668b4d44e4d390+ .quad 0x3b48cf217a78820c+ .quad 0xf76a0ab281273e97+ .quad 0xa96c65a78c8eed7b+ .quad 0x7411a6054f8a433f++ // 2^120 * 6 * G++ .quad 0x4d659d32b99dc86d+ .quad 0x044cdc75603af115+ .quad 0xb34c712cdcc2e488+ .quad 0x7c136574fb8134ff+ .quad 0x579ae53d18b175b4+ .quad 0x68713159f392a102+ .quad 0x8455ecba1eef35f5+ .quad 0x1ec9a872458c398f+ .quad 0xb8e6a4d400a2509b+ .quad 0x9b81d7020bc882b4+ .quad 0x57e7cc9bf1957561+ .quad 0x3add88a5c7cd6460++ // 2^120 * 7 * G++ .quad 0xab895770b635dcf2+ .quad 0x02dfef6cf66c1fbc+ .quad 0x85530268beb6d187+ .quad 0x249929fccc879e74+ .quad 0x85c298d459393046+ .quad 0x8f7e35985ff659ec+ .quad 0x1d2ca22af2f66e3a+ .quad 0x61ba1131a406a720+ .quad 0xa3d0a0f116959029+ .quad 0x023b6b6cba7ebd89+ .quad 0x7bf15a3e26783307+ .quad 0x5620310cbbd8ece7++ // 2^120 * 8 * G++ .quad 0x528993434934d643+ .quad 0xb9dbf806a51222f5+ .quad 0x8f6d878fc3f41c22+ .quad 0x37676a2a4d9d9730+ .quad 0x6646b5f477e285d6+ .quad 0x40e8ff676c8f6193+ .quad 0xa6ec7311abb594dd+ .quad 0x7ec846f3658cec4d+ .quad 0x9b5e8f3f1da22ec7+ .quad 0x130f1d776c01cd13+ .quad 0x214c8fcfa2989fb8+ .quad 0x6daaf723399b9dd5++ // 2^124 * 1 * G++ .quad 0x591e4a5610628564+ .quad 0x2a4bb87ca8b4df34+ .quad 0xde2a2572e7a38e43+ .quad 0x3cbdabd9fee5046e+ .quad 0x81aebbdd2cd13070+ .quad 0x962e4325f85a0e9e+ .quad 0xde9391aacadffecb+ .quad 0x53177fda52c230e6+ .quad 0xa7bc970650b9de79+ .quad 0x3d12a7fbc301b59b+ .quad 0x02652e68d36ae38c+ .quad 0x79d739835a6199dc++ // 2^124 * 2 * G++ .quad 0xd9354df64131c1bd+ .quad 0x758094a186ec5822+ .quad 0x4464ee12e459f3c2+ .quad 0x6c11fce4cb133282+ .quad 0x21c9d9920d591737+ .quad 0x9bea41d2e9b46cd6+ .quad 0xe20e84200d89bfca+ .quad 0x79d99f946eae5ff8+ .quad 0xf17b483568673205+ .quad 0x387deae83caad96c+ .quad 0x61b471fd56ffe386+ .quad 0x31741195b745a599++ // 2^124 * 3 * G++ .quad 0xe8d10190b77a360b+ .quad 0x99b983209995e702+ .quad 0xbd4fdff8fa0247aa+ .quad 0x2772e344e0d36a87+ .quad 0x17f8ba683b02a047+ .quad 0x50212096feefb6c8+ .quad 0x70139be21556cbe2+ .quad 0x203e44a11d98915b+ .quad 0xd6863eba37b9e39f+ .quad 0x105bc169723b5a23+ .quad 0x104f6459a65c0762+ .quad 0x567951295b4d38d4++ // 2^124 * 4 * G++ .quad 0x535fd60613037524+ .quad 0xe210adf6b0fbc26a+ .quad 0xac8d0a9b23e990ae+ .quad 0x47204d08d72fdbf9+ .quad 0x07242eb30d4b497f+ .quad 0x1ef96306b9bccc87+ .quad 0x37950934d8116f45+ .quad 0x05468d6201405b04+ .quad 0x00f565a9f93267de+ .quad 0xcecfd78dc0d58e8a+ .quad 0xa215e2dcf318e28e+ .quad 0x4599ee919b633352++ // 2^124 * 5 * G++ .quad 0xd3c220ca70e0e76b+ .quad 0xb12bea58ea9f3094+ .quad 0x294ddec8c3271282+ .quad 0x0c3539e1a1d1d028+ .quad 0xac746d6b861ae579+ .quad 0x31ab0650f6aea9dc+ .quad 0x241d661140256d4c+ .quad 0x2f485e853d21a5de+ .quad 0x329744839c0833f3+ .quad 0x6fe6257fd2abc484+ .quad 0x5327d1814b358817+ .quad 0x65712585893fe9bc++ // 2^124 * 6 * G++ .quad 0x9c102fb732a61161+ .quad 0xe48e10dd34d520a8+ .quad 0x365c63546f9a9176+ .quad 0x32f6fe4c046f6006+ .quad 0x81c29f1bd708ee3f+ .quad 0xddcb5a05ae6407d0+ .quad 0x97aec1d7d2a3eba7+ .quad 0x1590521a91d50831+ .quad 0x40a3a11ec7910acc+ .quad 0x9013dff8f16d27ae+ .quad 0x1a9720d8abb195d4+ .quad 0x1bb9fe452ea98463++ // 2^124 * 7 * G++ .quad 0xe9d1d950b3d54f9e+ .quad 0x2d5f9cbee00d33c1+ .quad 0x51c2c656a04fc6ac+ .quad 0x65c091ee3c1cbcc9+ .quad 0xcf5e6c95cc36747c+ .quad 0x294201536b0bc30d+ .quad 0x453ac67cee797af0+ .quad 0x5eae6ab32a8bb3c9+ .quad 0x7083661114f118ea+ .quad 0x2b37b87b94349cad+ .quad 0x7273f51cb4e99f40+ .quad 0x78a2a95823d75698++ // 2^124 * 8 * G++ .quad 0xa2b072e95c8c2ace+ .quad 0x69cffc96651e9c4b+ .quad 0x44328ef842e7b42b+ .quad 0x5dd996c122aadeb3+ .quad 0xb4f23c425ef83207+ .quad 0xabf894d3c9a934b5+ .quad 0xd0708c1339fd87f7+ .quad 0x1876789117166130+ .quad 0x925b5ef0670c507c+ .quad 0x819bc842b93c33bf+ .quad 0x10792e9a70dd003f+ .quad 0x59ad4b7a6e28dc74++ // 2^128 * 1 * G++ .quad 0x5f3a7562eb3dbe47+ .quad 0xf7ea38548ebda0b8+ .quad 0x00c3e53145747299+ .quad 0x1304e9e71627d551+ .quad 0x583b04bfacad8ea2+ .quad 0x29b743e8148be884+ .quad 0x2b1e583b0810c5db+ .quad 0x2b5449e58eb3bbaa+ .quad 0x789814d26adc9cfe+ .quad 0x3c1bab3f8b48dd0b+ .quad 0xda0fe1fff979c60a+ .quad 0x4468de2d7c2dd693++ // 2^128 * 2 * G++ .quad 0x51bb355e9419469e+ .quad 0x33e6dc4c23ddc754+ .quad 0x93a5b6d6447f9962+ .quad 0x6cce7c6ffb44bd63+ .quad 0x4b9ad8c6f86307ce+ .quad 0x21113531435d0c28+ .quad 0xd4a866c5657a772c+ .quad 0x5da6427e63247352+ .quad 0x1a94c688deac22ca+ .quad 0xb9066ef7bbae1ff8+ .quad 0x88ad8c388d59580f+ .quad 0x58f29abfe79f2ca8++ // 2^128 * 3 * G++ .quad 0xe90ecfab8de73e68+ .quad 0x54036f9f377e76a5+ .quad 0xf0495b0bbe015982+ .quad 0x577629c4a7f41e36+ .quad 0x4b5a64bf710ecdf6+ .quad 0xb14ce538462c293c+ .quad 0x3643d056d50b3ab9+ .quad 0x6af93724185b4870+ .quad 0x3220024509c6a888+ .quad 0xd2e036134b558973+ .quad 0x83e236233c33289f+ .quad 0x701f25bb0caec18f++ // 2^128 * 4 * G++ .quad 0xc3a8b0f8e4616ced+ .quad 0xf700660e9e25a87d+ .quad 0x61e3061ff4bca59c+ .quad 0x2e0c92bfbdc40be9+ .quad 0x9d18f6d97cbec113+ .quad 0x844a06e674bfdbe4+ .quad 0x20f5b522ac4e60d6+ .quad 0x720a5bc050955e51+ .quad 0x0c3f09439b805a35+ .quad 0xe84e8b376242abfc+ .quad 0x691417f35c229346+ .quad 0x0e9b9cbb144ef0ec++ // 2^128 * 5 * G++ .quad 0xfbbad48ffb5720ad+ .quad 0xee81916bdbf90d0e+ .quad 0xd4813152635543bf+ .quad 0x221104eb3f337bd8+ .quad 0x8dee9bd55db1beee+ .quad 0xc9c3ab370a723fb9+ .quad 0x44a8f1bf1c68d791+ .quad 0x366d44191cfd3cde+ .quad 0x9e3c1743f2bc8c14+ .quad 0x2eda26fcb5856c3b+ .quad 0xccb82f0e68a7fb97+ .quad 0x4167a4e6bc593244++ // 2^128 * 6 * G++ .quad 0x643b9d2876f62700+ .quad 0x5d1d9d400e7668eb+ .quad 0x1b4b430321fc0684+ .quad 0x7938bb7e2255246a+ .quad 0xc2be2665f8ce8fee+ .quad 0xe967ff14e880d62c+ .quad 0xf12e6e7e2f364eee+ .quad 0x34b33370cb7ed2f6+ .quad 0xcdc591ee8681d6cc+ .quad 0xce02109ced85a753+ .quad 0xed7485c158808883+ .quad 0x1176fc6e2dfe65e4++ // 2^128 * 7 * G++ .quad 0xb4af6cd05b9c619b+ .quad 0x2ddfc9f4b2a58480+ .quad 0x3d4fa502ebe94dc4+ .quad 0x08fc3a4c677d5f34+ .quad 0xdb90e28949770eb8+ .quad 0x98fbcc2aacf440a3+ .quad 0x21354ffeded7879b+ .quad 0x1f6a3e54f26906b6+ .quad 0x60a4c199d30734ea+ .quad 0x40c085b631165cd6+ .quad 0xe2333e23f7598295+ .quad 0x4f2fad0116b900d1++ // 2^128 * 8 * G++ .quad 0x44beb24194ae4e54+ .quad 0x5f541c511857ef6c+ .quad 0xa61e6b2d368d0498+ .quad 0x445484a4972ef7ab+ .quad 0x962cd91db73bb638+ .quad 0xe60577aafc129c08+ .quad 0x6f619b39f3b61689+ .quad 0x3451995f2944ee81+ .quad 0x9152fcd09fea7d7c+ .quad 0x4a816c94b0935cf6+ .quad 0x258e9aaa47285c40+ .quad 0x10b89ca6042893b7++ // 2^132 * 1 * G++ .quad 0x9b2a426e3b646025+ .quad 0x32127190385ce4cf+ .quad 0xa25cffc2dd6dea45+ .quad 0x06409010bea8de75+ .quad 0xd67cded679d34aa0+ .quad 0xcc0b9ec0cc4db39f+ .quad 0xa535a456e35d190f+ .quad 0x2e05d9eaf61f6fef+ .quad 0xc447901ad61beb59+ .quad 0x661f19bce5dc880a+ .quad 0x24685482b7ca6827+ .quad 0x293c778cefe07f26++ // 2^132 * 2 * G++ .quad 0x86809e7007069096+ .quad 0xaad75b15e4e50189+ .quad 0x07f35715a21a0147+ .quad 0x0487f3f112815d5e+ .quad 0x16c795d6a11ff200+ .quad 0xcb70d0e2b15815c9+ .quad 0x89f293209b5395b5+ .quad 0x50b8c2d031e47b4f+ .quad 0x48350c08068a4962+ .quad 0x6ffdd05351092c9a+ .quad 0x17af4f4aaf6fc8dd+ .quad 0x4b0553b53cdba58b++ // 2^132 * 3 * G++ .quad 0x9c65fcbe1b32ff79+ .quad 0xeb75ea9f03b50f9b+ .quad 0xfced2a6c6c07e606+ .quad 0x35106cd551717908+ .quad 0xbf05211b27c152d4+ .quad 0x5ec26849bd1af639+ .quad 0x5e0b2caa8e6fab98+ .quad 0x054c8bdd50bd0840+ .quad 0x38a0b12f1dcf073d+ .quad 0x4b60a8a3b7f6a276+ .quad 0xfed5ac25d3404f9a+ .quad 0x72e82d5e5505c229++ // 2^132 * 4 * G++ .quad 0x6b0b697ff0d844c8+ .quad 0xbb12f85cd979cb49+ .quad 0xd2a541c6c1da0f1f+ .quad 0x7b7c242958ce7211+ .quad 0x00d9cdfd69771d02+ .quad 0x410276cd6cfbf17e+ .quad 0x4c45306c1cb12ec7+ .quad 0x2857bf1627500861+ .quad 0x9f21903f0101689e+ .quad 0xd779dfd3bf861005+ .quad 0xa122ee5f3deb0f1b+ .quad 0x510df84b485a00d4++ // 2^132 * 5 * G++ .quad 0xa54133bb9277a1fa+ .quad 0x74ec3b6263991237+ .quad 0x1a3c54dc35d2f15a+ .quad 0x2d347144e482ba3a+ .quad 0x24b3c887c70ac15e+ .quad 0xb0f3a557fb81b732+ .quad 0x9b2cde2fe578cc1b+ .quad 0x4cf7ed0703b54f8e+ .quad 0x6bd47c6598fbee0f+ .quad 0x9e4733e2ab55be2d+ .quad 0x1093f624127610c5+ .quad 0x4e05e26ad0a1eaa4++ // 2^132 * 6 * G++ .quad 0xda9b6b624b531f20+ .quad 0x429a760e77509abb+ .quad 0xdbe9f522e823cb80+ .quad 0x618f1856880c8f82+ .quad 0x1833c773e18fe6c0+ .quad 0xe3c4711ad3c87265+ .quad 0x3bfd3c4f0116b283+ .quad 0x1955875eb4cd4db8+ .quad 0x6da6de8f0e399799+ .quad 0x7ad61aa440fda178+ .quad 0xb32cd8105e3563dd+ .quad 0x15f6beae2ae340ae++ // 2^132 * 7 * G++ .quad 0x862bcb0c31ec3a62+ .quad 0x810e2b451138f3c2+ .quad 0x788ec4b839dac2a4+ .quad 0x28f76867ae2a9281+ .quad 0xba9a0f7b9245e215+ .quad 0xf368612dd98c0dbb+ .quad 0x2e84e4cbf220b020+ .quad 0x6ba92fe962d90eda+ .quad 0x3e4df9655884e2aa+ .quad 0xbd62fbdbdbd465a5+ .quad 0xd7596caa0de9e524+ .quad 0x6e8042ccb2b1b3d7++ // 2^132 * 8 * G++ .quad 0xf10d3c29ce28ca6e+ .quad 0xbad34540fcb6093d+ .quad 0xe7426ed7a2ea2d3f+ .quad 0x08af9d4e4ff298b9+ .quad 0x1530653616521f7e+ .quad 0x660d06b896203dba+ .quad 0x2d3989bc545f0879+ .quad 0x4b5303af78ebd7b0+ .quad 0x72f8a6c3bebcbde8+ .quad 0x4f0fca4adc3a8e89+ .quad 0x6fa9d4e8c7bfdf7a+ .quad 0x0dcf2d679b624eb7++ // 2^136 * 1 * G++ .quad 0x3d5947499718289c+ .quad 0x12ebf8c524533f26+ .quad 0x0262bfcb14c3ef15+ .quad 0x20b878d577b7518e+ .quad 0x753941be5a45f06e+ .quad 0xd07caeed6d9c5f65+ .quad 0x11776b9c72ff51b6+ .quad 0x17d2d1d9ef0d4da9+ .quad 0x27f2af18073f3e6a+ .quad 0xfd3fe519d7521069+ .quad 0x22e3b72c3ca60022+ .quad 0x72214f63cc65c6a7++ // 2^136 * 2 * G++ .quad 0xb4e37f405307a693+ .quad 0xaba714d72f336795+ .quad 0xd6fbd0a773761099+ .quad 0x5fdf48c58171cbc9+ .quad 0x1d9db7b9f43b29c9+ .quad 0xd605824a4f518f75+ .quad 0xf2c072bd312f9dc4+ .quad 0x1f24ac855a1545b0+ .quad 0x24d608328e9505aa+ .quad 0x4748c1d10c1420ee+ .quad 0xc7ffe45c06fb25a2+ .quad 0x00ba739e2ae395e6++ // 2^136 * 3 * G++ .quad 0x592e98de5c8790d6+ .quad 0xe5bfb7d345c2a2df+ .quad 0x115a3b60f9b49922+ .quad 0x03283a3e67ad78f3+ .quad 0xae4426f5ea88bb26+ .quad 0x360679d984973bfb+ .quad 0x5c9f030c26694e50+ .quad 0x72297de7d518d226+ .quad 0x48241dc7be0cb939+ .quad 0x32f19b4d8b633080+ .quad 0xd3dfc90d02289308+ .quad 0x05e1296846271945++ // 2^136 * 4 * G++ .quad 0xba82eeb32d9c495a+ .quad 0xceefc8fcf12bb97c+ .quad 0xb02dabae93b5d1e0+ .quad 0x39c00c9c13698d9b+ .quad 0xadbfbbc8242c4550+ .quad 0xbcc80cecd03081d9+ .quad 0x843566a6f5c8df92+ .quad 0x78cf25d38258ce4c+ .quad 0x15ae6b8e31489d68+ .quad 0xaa851cab9c2bf087+ .quad 0xc9a75a97f04efa05+ .quad 0x006b52076b3ff832++ // 2^136 * 5 * G++ .quad 0x29e0cfe19d95781c+ .quad 0xb681df18966310e2+ .quad 0x57df39d370516b39+ .quad 0x4d57e3443bc76122+ .quad 0xf5cb7e16b9ce082d+ .quad 0x3407f14c417abc29+ .quad 0xd4b36bce2bf4a7ab+ .quad 0x7de2e9561a9f75ce+ .quad 0xde70d4f4b6a55ecb+ .quad 0x4801527f5d85db99+ .quad 0xdbc9c440d3ee9a81+ .quad 0x6b2a90af1a6029ed++ // 2^136 * 6 * G++ .quad 0x6923f4fc9ae61e97+ .quad 0x5735281de03f5fd1+ .quad 0xa764ae43e6edd12d+ .quad 0x5fd8f4e9d12d3e4a+ .quad 0x77ebf3245bb2d80a+ .quad 0xd8301b472fb9079b+ .quad 0xc647e6f24cee7333+ .quad 0x465812c8276c2109+ .quad 0x4d43beb22a1062d9+ .quad 0x7065fb753831dc16+ .quad 0x180d4a7bde2968d7+ .quad 0x05b32c2b1cb16790++ // 2^136 * 7 * G++ .quad 0xc8c05eccd24da8fd+ .quad 0xa1cf1aac05dfef83+ .quad 0xdbbeeff27df9cd61+ .quad 0x3b5556a37b471e99+ .quad 0xf7fca42c7ad58195+ .quad 0x3214286e4333f3cc+ .quad 0xb6c29d0d340b979d+ .quad 0x31771a48567307e1+ .quad 0x32b0c524e14dd482+ .quad 0xedb351541a2ba4b6+ .quad 0xa3d16048282b5af3+ .quad 0x4fc079d27a7336eb++ // 2^136 * 8 * G++ .quad 0x51c938b089bf2f7f+ .quad 0x2497bd6502dfe9a7+ .quad 0xffffc09c7880e453+ .quad 0x124567cecaf98e92+ .quad 0xdc348b440c86c50d+ .quad 0x1337cbc9cc94e651+ .quad 0x6422f74d643e3cb9+ .quad 0x241170c2bae3cd08+ .quad 0x3ff9ab860ac473b4+ .quad 0xf0911dee0113e435+ .quad 0x4ae75060ebc6c4af+ .quad 0x3f8612966c87000d++ // 2^140 * 1 * G++ .quad 0x0c9c5303f7957be4+ .quad 0xa3c31a20e085c145+ .quad 0xb0721d71d0850050+ .quad 0x0aba390eab0bf2da+ .quad 0x529fdffe638c7bf3+ .quad 0xdf2b9e60388b4995+ .quad 0xe027b34f1bad0249+ .quad 0x7bc92fc9b9fa74ed+ .quad 0x9f97ef2e801ad9f9+ .quad 0x83697d5479afda3a+ .quad 0xe906b3ffbd596b50+ .quad 0x02672b37dd3fb8e0++ // 2^140 * 2 * G++ .quad 0x48b2ca8b260885e4+ .quad 0xa4286bec82b34c1c+ .quad 0x937e1a2617f58f74+ .quad 0x741d1fcbab2ca2a5+ .quad 0xee9ba729398ca7f5+ .quad 0xeb9ca6257a4849db+ .quad 0x29eb29ce7ec544e1+ .quad 0x232ca21ef736e2c8+ .quad 0xbf61423d253fcb17+ .quad 0x08803ceafa39eb14+ .quad 0xf18602df9851c7af+ .quad 0x0400f3a049e3414b++ // 2^140 * 3 * G++ .quad 0xabce0476ba61c55b+ .quad 0x36a3d6d7c4d39716+ .quad 0x6eb259d5e8d82d09+ .quad 0x0c9176e984d756fb+ .quad 0x2efba412a06e7b06+ .quad 0x146785452c8d2560+ .quad 0xdf9713ebd67a91c7+ .quad 0x32830ac7157eadf3+ .quad 0x0e782a7ab73769e8+ .quad 0x04a05d7875b18e2c+ .quad 0x29525226ebcceae1+ .quad 0x0d794f8383eba820++ // 2^140 * 4 * G++ .quad 0xff35f5cb9e1516f4+ .quad 0xee805bcf648aae45+ .quad 0xf0d73c2bb93a9ef3+ .quad 0x097b0bf22092a6c2+ .quad 0x7be44ce7a7a2e1ac+ .quad 0x411fd93efad1b8b7+ .quad 0x1734a1d70d5f7c9b+ .quad 0x0d6592233127db16+ .quad 0xc48bab1521a9d733+ .quad 0xa6c2eaead61abb25+ .quad 0x625c6c1cc6cb4305+ .quad 0x7fc90fea93eb3a67++ // 2^140 * 5 * G++ .quad 0x0408f1fe1f5c5926+ .quad 0x1a8f2f5e3b258bf4+ .quad 0x40a951a2fdc71669+ .quad 0x6598ee93c98b577e+ .quad 0xc527deb59c7cb23d+ .quad 0x955391695328404e+ .quad 0xd64392817ccf2c7a+ .quad 0x6ce97dabf7d8fa11+ .quad 0x25b5a8e50ef7c48f+ .quad 0xeb6034116f2ce532+ .quad 0xc5e75173e53de537+ .quad 0x73119fa08c12bb03++ // 2^140 * 6 * G++ .quad 0xed30129453f1a4cb+ .quad 0xbce621c9c8f53787+ .quad 0xfacb2b1338bee7b9+ .quad 0x3025798a9ea8428c+ .quad 0x7845b94d21f4774d+ .quad 0xbf62f16c7897b727+ .quad 0x671857c03c56522b+ .quad 0x3cd6a85295621212+ .quad 0x3fecde923aeca999+ .quad 0xbdaa5b0062e8c12f+ .quad 0x67b99dfc96988ade+ .quad 0x3f52c02852661036++ // 2^140 * 7 * G++ .quad 0xffeaa48e2a1351c6+ .quad 0x28624754fa7f53d7+ .quad 0x0b5ba9e57582ddf1+ .quad 0x60c0104ba696ac59+ .quad 0x9258bf99eec416c6+ .quad 0xac8a5017a9d2f671+ .quad 0x629549ab16dea4ab+ .quad 0x05d0e85c99091569+ .quad 0x051de020de9cbe97+ .quad 0xfa07fc56b50bcf74+ .quad 0x378cec9f0f11df65+ .quad 0x36853c69ab96de4d++ // 2^140 * 8 * G++ .quad 0x36d9b8de78f39b2d+ .quad 0x7f42ed71a847b9ec+ .quad 0x241cd1d679bd3fde+ .quad 0x6a704fec92fbce6b+ .quad 0x4433c0b0fac5e7be+ .quad 0x724bae854c08dcbe+ .quad 0xf1f24cc446978f9b+ .quad 0x4a0aff6d62825fc8+ .quad 0xe917fb9e61095301+ .quad 0xc102df9402a092f8+ .quad 0xbf09e2f5fa66190b+ .quad 0x681109bee0dcfe37++ // 2^144 * 1 * G++ .quad 0x559a0cc9782a0dde+ .quad 0x551dcdb2ea718385+ .quad 0x7f62865b31ef238c+ .quad 0x504aa7767973613d+ .quad 0x9c18fcfa36048d13+ .quad 0x29159db373899ddd+ .quad 0xdc9f350b9f92d0aa+ .quad 0x26f57eee878a19d4+ .quad 0x0cab2cd55687efb1+ .quad 0x5180d162247af17b+ .quad 0x85c15a344f5a2467+ .quad 0x4041943d9dba3069++ // 2^144 * 2 * G++ .quad 0xc3c0eeba43ebcc96+ .quad 0x8d749c9c26ea9caf+ .quad 0xd9fa95ee1c77ccc6+ .quad 0x1420a1d97684340f+ .quad 0x4b217743a26caadd+ .quad 0x47a6b424648ab7ce+ .quad 0xcb1d4f7a03fbc9e3+ .quad 0x12d931429800d019+ .quad 0x00c67799d337594f+ .quad 0x5e3c5140b23aa47b+ .quad 0x44182854e35ff395+ .quad 0x1b4f92314359a012++ // 2^144 * 3 * G++ .quad 0x3e5c109d89150951+ .quad 0x39cefa912de9696a+ .quad 0x20eae43f975f3020+ .quad 0x239b572a7f132dae+ .quad 0x33cf3030a49866b1+ .quad 0x251f73d2215f4859+ .quad 0xab82aa4051def4f6+ .quad 0x5ff191d56f9a23f6+ .quad 0x819ed433ac2d9068+ .quad 0x2883ab795fc98523+ .quad 0xef4572805593eb3d+ .quad 0x020c526a758f36cb++ // 2^144 * 4 * G++ .quad 0x779834f89ed8dbbc+ .quad 0xc8f2aaf9dc7ca46c+ .quad 0xa9524cdca3e1b074+ .quad 0x02aacc4615313877+ .quad 0xe931ef59f042cc89+ .quad 0x2c589c9d8e124bb6+ .quad 0xadc8e18aaec75997+ .quad 0x452cfe0a5602c50c+ .quad 0x86a0f7a0647877df+ .quad 0xbbc464270e607c9f+ .quad 0xab17ea25f1fb11c9+ .quad 0x4cfb7d7b304b877b++ // 2^144 * 5 * G++ .quad 0x72b43d6cb89b75fe+ .quad 0x54c694d99c6adc80+ .quad 0xb8c3aa373ee34c9f+ .quad 0x14b4622b39075364+ .quad 0xe28699c29789ef12+ .quad 0x2b6ecd71df57190d+ .quad 0xc343c857ecc970d0+ .quad 0x5b1d4cbc434d3ac5+ .quad 0xb6fb2615cc0a9f26+ .quad 0x3a4f0e2bb88dcce5+ .quad 0x1301498b3369a705+ .quad 0x2f98f71258592dd1++ // 2^144 * 6 * G++ .quad 0x0c94a74cb50f9e56+ .quad 0x5b1ff4a98e8e1320+ .quad 0x9a2acc2182300f67+ .quad 0x3a6ae249d806aaf9+ .quad 0x2e12ae444f54a701+ .quad 0xfcfe3ef0a9cbd7de+ .quad 0xcebf890d75835de0+ .quad 0x1d8062e9e7614554+ .quad 0x657ada85a9907c5a+ .quad 0x1a0ea8b591b90f62+ .quad 0x8d0e1dfbdf34b4e9+ .quad 0x298b8ce8aef25ff3++ // 2^144 * 7 * G++ .quad 0x2a927953eff70cb2+ .quad 0x4b89c92a79157076+ .quad 0x9418457a30a7cf6a+ .quad 0x34b8a8404d5ce485+ .quad 0x837a72ea0a2165de+ .quad 0x3fab07b40bcf79f6+ .quad 0x521636c77738ae70+ .quad 0x6ba6271803a7d7dc+ .quad 0xc26eecb583693335+ .quad 0xd5a813df63b5fefd+ .quad 0xa293aa9aa4b22573+ .quad 0x71d62bdd465e1c6a++ // 2^144 * 8 * G++ .quad 0x6533cc28d378df80+ .quad 0xf6db43790a0fa4b4+ .quad 0xe3645ff9f701da5a+ .quad 0x74d5f317f3172ba4+ .quad 0xcd2db5dab1f75ef5+ .quad 0xd77f95cf16b065f5+ .quad 0x14571fea3f49f085+ .quad 0x1c333621262b2b3d+ .quad 0xa86fe55467d9ca81+ .quad 0x398b7c752b298c37+ .quad 0xda6d0892e3ac623b+ .quad 0x4aebcc4547e9d98c++ // 2^148 * 1 * G++ .quad 0x53175a7205d21a77+ .quad 0xb0c04422d3b934d4+ .quad 0xadd9f24bdd5deadc+ .quad 0x074f46e69f10ff8c+ .quad 0x0de9b204a059a445+ .quad 0xe15cb4aa4b17ad0f+ .quad 0xe1bbec521f79c557+ .quad 0x2633f1b9d071081b+ .quad 0xc1fb4177018b9910+ .quad 0xa6ea20dc6c0fe140+ .quad 0xd661f3e74354c6ff+ .quad 0x5ecb72e6f1a3407a++ // 2^148 * 2 * G++ .quad 0xa515a31b2259fb4e+ .quad 0x0960f3972bcac52f+ .quad 0xedb52fec8d3454cb+ .quad 0x382e2720c476c019+ .quad 0xfeeae106e8e86997+ .quad 0x9863337f98d09383+ .quad 0x9470480eaa06ebef+ .quad 0x038b6898d4c5c2d0+ .quad 0xf391c51d8ace50a6+ .quad 0x3142d0b9ae2d2948+ .quad 0xdb4d5a1a7f24ca80+ .quad 0x21aeba8b59250ea8++ // 2^148 * 3 * G++ .quad 0x24f13b34cf405530+ .quad 0x3c44ea4a43088af7+ .quad 0x5dd5c5170006a482+ .quad 0x118eb8f8890b086d+ .quad 0x53853600f0087f23+ .quad 0x4c461879da7d5784+ .quad 0x6af303deb41f6860+ .quad 0x0a3c16c5c27c18ed+ .quad 0x17e49c17cc947f3d+ .quad 0xccc6eda6aac1d27b+ .quad 0xdf6092ceb0f08e56+ .quad 0x4909b3e22c67c36b++ // 2^148 * 4 * G++ .quad 0x9c9c85ea63fe2e89+ .quad 0xbe1baf910e9412ec+ .quad 0x8f7baa8a86fbfe7b+ .quad 0x0fb17f9fef968b6c+ .quad 0x59a16676706ff64e+ .quad 0x10b953dd0d86a53d+ .quad 0x5848e1e6ce5c0b96+ .quad 0x2d8b78e712780c68+ .quad 0x79d5c62eafc3902b+ .quad 0x773a215289e80728+ .quad 0xc38ae640e10120b9+ .quad 0x09ae23717b2b1a6d++ // 2^148 * 5 * G++ .quad 0xbb6a192a4e4d083c+ .quad 0x34ace0630029e192+ .quad 0x98245a59aafabaeb+ .quad 0x6d9c8a9ada97faac+ .quad 0x10ab8fa1ad32b1d0+ .quad 0xe9aced1be2778b24+ .quad 0xa8856bc0373de90f+ .quad 0x66f35ddddda53996+ .quad 0xd27d9afb24997323+ .quad 0x1bb7e07ef6f01d2e+ .quad 0x2ba7472df52ecc7f+ .quad 0x03019b4f646f9dc8++ // 2^148 * 6 * G++ .quad 0x04a186b5565345cd+ .quad 0xeee76610bcc4116a+ .quad 0x689c73b478fb2a45+ .quad 0x387dcbff65697512+ .quad 0xaf09b214e6b3dc6b+ .quad 0x3f7573b5ad7d2f65+ .quad 0xd019d988100a23b0+ .quad 0x392b63a58b5c35f7+ .quad 0x4093addc9c07c205+ .quad 0xc565be15f532c37e+ .quad 0x63dbecfd1583402a+ .quad 0x61722b4aef2e032e++ // 2^148 * 7 * G++ .quad 0x0012aafeecbd47af+ .quad 0x55a266fb1cd46309+ .quad 0xf203eb680967c72c+ .quad 0x39633944ca3c1429+ .quad 0xd6b07a5581cb0e3c+ .quad 0x290ff006d9444969+ .quad 0x08680b6a16dcda1f+ .quad 0x5568d2b75a06de59+ .quad 0x8d0cb88c1b37cfe1+ .quad 0x05b6a5a3053818f3+ .quad 0xf2e9bc04b787d959+ .quad 0x6beba1249add7f64++ // 2^148 * 8 * G++ .quad 0x1d06005ca5b1b143+ .quad 0x6d4c6bb87fd1cda2+ .quad 0x6ef5967653fcffe7+ .quad 0x097c29e8c1ce1ea5+ .quad 0x5c3cecb943f5a53b+ .quad 0x9cc9a61d06c08df2+ .quad 0xcfba639a85895447+ .quad 0x5a845ae80df09fd5+ .quad 0x4ce97dbe5deb94ca+ .quad 0x38d0a4388c709c48+ .quad 0xc43eced4a169d097+ .quad 0x0a1249fff7e587c3++ // 2^152 * 1 * G++ .quad 0x12f0071b276d01c9+ .quad 0xe7b8bac586c48c70+ .quad 0x5308129b71d6fba9+ .quad 0x5d88fbf95a3db792+ .quad 0x0b408d9e7354b610+ .quad 0x806b32535ba85b6e+ .quad 0xdbe63a034a58a207+ .quad 0x173bd9ddc9a1df2c+ .quad 0x2b500f1efe5872df+ .quad 0x58d6582ed43918c1+ .quad 0xe6ed278ec9673ae0+ .quad 0x06e1cd13b19ea319++ // 2^152 * 2 * G++ .quad 0x40d0ad516f166f23+ .quad 0x118e32931fab6abe+ .quad 0x3fe35e14a04d088e+ .quad 0x3080603526e16266+ .quad 0x472baf629e5b0353+ .quad 0x3baa0b90278d0447+ .quad 0x0c785f469643bf27+ .quad 0x7f3a6a1a8d837b13+ .quad 0xf7e644395d3d800b+ .quad 0x95a8d555c901edf6+ .quad 0x68cd7830592c6339+ .quad 0x30d0fded2e51307e++ // 2^152 * 3 * G++ .quad 0xe0594d1af21233b3+ .quad 0x1bdbe78ef0cc4d9c+ .quad 0x6965187f8f499a77+ .quad 0x0a9214202c099868+ .quad 0x9cb4971e68b84750+ .quad 0xa09572296664bbcf+ .quad 0x5c8de72672fa412b+ .quad 0x4615084351c589d9+ .quad 0xbc9019c0aeb9a02e+ .quad 0x55c7110d16034cae+ .quad 0x0e6df501659932ec+ .quad 0x3bca0d2895ca5dfe++ // 2^152 * 4 * G++ .quad 0x40f031bc3c5d62a4+ .quad 0x19fc8b3ecff07a60+ .quad 0x98183da2130fb545+ .quad 0x5631deddae8f13cd+ .quad 0x9c688eb69ecc01bf+ .quad 0xf0bc83ada644896f+ .quad 0xca2d955f5f7a9fe2+ .quad 0x4ea8b4038df28241+ .quad 0x2aed460af1cad202+ .quad 0x46305305a48cee83+ .quad 0x9121774549f11a5f+ .quad 0x24ce0930542ca463++ // 2^152 * 5 * G++ .quad 0x1fe890f5fd06c106+ .quad 0xb5c468355d8810f2+ .quad 0x827808fe6e8caf3e+ .quad 0x41d4e3c28a06d74b+ .quad 0x3fcfa155fdf30b85+ .quad 0xd2f7168e36372ea4+ .quad 0xb2e064de6492f844+ .quad 0x549928a7324f4280+ .quad 0xf26e32a763ee1a2e+ .quad 0xae91e4b7d25ffdea+ .quad 0xbc3bd33bd17f4d69+ .quad 0x491b66dec0dcff6a++ // 2^152 * 6 * G++ .quad 0x98f5b13dc7ea32a7+ .quad 0xe3d5f8cc7e16db98+ .quad 0xac0abf52cbf8d947+ .quad 0x08f338d0c85ee4ac+ .quad 0x75f04a8ed0da64a1+ .quad 0xed222caf67e2284b+ .quad 0x8234a3791f7b7ba4+ .quad 0x4cf6b8b0b7018b67+ .quad 0xc383a821991a73bd+ .quad 0xab27bc01df320c7a+ .quad 0xc13d331b84777063+ .quad 0x530d4a82eb078a99++ // 2^152 * 7 * G++ .quad 0x004c3630e1f94825+ .quad 0x7e2d78268cab535a+ .quad 0xc7482323cc84ff8b+ .quad 0x65ea753f101770b9+ .quad 0x6d6973456c9abf9e+ .quad 0x257fb2fc4900a880+ .quad 0x2bacf412c8cfb850+ .quad 0x0db3e7e00cbfbd5b+ .quad 0x3d66fc3ee2096363+ .quad 0x81d62c7f61b5cb6b+ .quad 0x0fbe044213443b1a+ .quad 0x02a4ec1921e1a1db++ // 2^152 * 8 * G++ .quad 0x5ce6259a3b24b8a2+ .quad 0xb8577acc45afa0b8+ .quad 0xcccbe6e88ba07037+ .quad 0x3d143c51127809bf+ .quad 0xf5c86162f1cf795f+ .quad 0x118c861926ee57f2+ .quad 0x172124851c063578+ .quad 0x36d12b5dec067fcf+ .quad 0x126d279179154557+ .quad 0xd5e48f5cfc783a0a+ .quad 0x36bdb6e8df179bac+ .quad 0x2ef517885ba82859++ // 2^156 * 1 * G++ .quad 0x88bd438cd11e0d4a+ .quad 0x30cb610d43ccf308+ .quad 0xe09a0e3791937bcc+ .quad 0x4559135b25b1720c+ .quad 0x1ea436837c6da1e9+ .quad 0xf9c189af1fb9bdbe+ .quad 0x303001fcce5dd155+ .quad 0x28a7c99ebc57be52+ .quad 0xb8fd9399e8d19e9d+ .quad 0x908191cb962423ff+ .quad 0xb2b948d747c742a3+ .quad 0x37f33226d7fb44c4++ // 2^156 * 2 * G++ .quad 0x0dae8767b55f6e08+ .quad 0x4a43b3b35b203a02+ .quad 0xe3725a6e80af8c79+ .quad 0x0f7a7fd1705fa7a3+ .quad 0x33912553c821b11d+ .quad 0x66ed42c241e301df+ .quad 0x066fcc11104222fd+ .quad 0x307a3b41c192168f+ .quad 0x8eeb5d076eb55ce0+ .quad 0x2fc536bfaa0d925a+ .quad 0xbe81830fdcb6c6e8+ .quad 0x556c7045827baf52++ // 2^156 * 3 * G++ .quad 0x8e2b517302e9d8b7+ .quad 0xe3e52269248714e8+ .quad 0xbd4fbd774ca960b5+ .quad 0x6f4b4199c5ecada9+ .quad 0xb94b90022bf44406+ .quad 0xabd4237eff90b534+ .quad 0x7600a960faf86d3a+ .quad 0x2f45abdac2322ee3+ .quad 0x61af4912c8ef8a6a+ .quad 0xe58fa4fe43fb6e5e+ .quad 0xb5afcc5d6fd427cf+ .quad 0x6a5393281e1e11eb++ // 2^156 * 4 * G++ .quad 0xf3da5139a5d1ee89+ .quad 0x8145457cff936988+ .quad 0x3f622fed00e188c4+ .quad 0x0f513815db8b5a3d+ .quad 0x0fff04fe149443cf+ .quad 0x53cac6d9865cddd7+ .quad 0x31385b03531ed1b7+ .quad 0x5846a27cacd1039d+ .quad 0x4ff5cdac1eb08717+ .quad 0x67e8b29590f2e9bc+ .quad 0x44093b5e237afa99+ .quad 0x0d414bed8708b8b2++ // 2^156 * 5 * G++ .quad 0xcfb68265fd0e75f6+ .quad 0xe45b3e28bb90e707+ .quad 0x7242a8de9ff92c7a+ .quad 0x685b3201933202dd+ .quad 0x81886a92294ac9e8+ .quad 0x23162b45d55547be+ .quad 0x94cfbc4403715983+ .quad 0x50eb8fdb134bc401+ .quad 0xc0b73ec6d6b330cd+ .quad 0x84e44807132faff1+ .quad 0x732b7352c4a5dee1+ .quad 0x5d7c7cf1aa7cd2d2++ // 2^156 * 6 * G++ .quad 0xaf3b46bf7a4aafa2+ .quad 0xb78705ec4d40d411+ .quad 0x114f0c6aca7c15e3+ .quad 0x3f364faaa9489d4d+ .quad 0x33d1013e9b73a562+ .quad 0x925cef5748ec26e1+ .quad 0xa7fce614dd468058+ .quad 0x78b0fad41e9aa438+ .quad 0xbf56a431ed05b488+ .quad 0xa533e66c9c495c7e+ .quad 0xe8652baf87f3651a+ .quad 0x0241800059d66c33++ // 2^156 * 7 * G++ .quad 0xceb077fea37a5be4+ .quad 0xdb642f02e5a5eeb7+ .quad 0xc2e6d0c5471270b8+ .quad 0x4771b65538e4529c+ .quad 0x28350c7dcf38ea01+ .quad 0x7c6cdbc0b2917ab6+ .quad 0xace7cfbe857082f7+ .quad 0x4d2845aba2d9a1e0+ .quad 0xbb537fe0447070de+ .quad 0xcba744436dd557df+ .quad 0xd3b5a3473600dbcb+ .quad 0x4aeabbe6f9ffd7f8++ // 2^156 * 8 * G++ .quad 0x4630119e40d8f78c+ .quad 0xa01a9bc53c710e11+ .quad 0x486d2b258910dd79+ .quad 0x1e6c47b3db0324e5+ .quad 0x6a2134bcc4a9c8f2+ .quad 0xfbf8fd1c8ace2e37+ .quad 0x000ae3049911a0ba+ .quad 0x046e3a616bc89b9e+ .quad 0x14e65442f03906be+ .quad 0x4a019d54e362be2a+ .quad 0x68ccdfec8dc230c7+ .quad 0x7cfb7e3faf6b861c++ // 2^160 * 1 * G++ .quad 0x4637974e8c58aedc+ .quad 0xb9ef22fbabf041a4+ .quad 0xe185d956e980718a+ .quad 0x2f1b78fab143a8a6+ .quad 0x96eebffb305b2f51+ .quad 0xd3f938ad889596b8+ .quad 0xf0f52dc746d5dd25+ .quad 0x57968290bb3a0095+ .quad 0xf71ab8430a20e101+ .quad 0xf393658d24f0ec47+ .quad 0xcf7509a86ee2eed1+ .quad 0x7dc43e35dc2aa3e1++ // 2^160 * 2 * G++ .quad 0x85966665887dd9c3+ .quad 0xc90f9b314bb05355+ .quad 0xc6e08df8ef2079b1+ .quad 0x7ef72016758cc12f+ .quad 0x5a782a5c273e9718+ .quad 0x3576c6995e4efd94+ .quad 0x0f2ed8051f237d3e+ .quad 0x044fb81d82d50a99+ .quad 0xc1df18c5a907e3d9+ .quad 0x57b3371dce4c6359+ .quad 0xca704534b201bb49+ .quad 0x7f79823f9c30dd2e++ // 2^160 * 3 * G++ .quad 0x8334d239a3b513e8+ .quad 0xc13670d4b91fa8d8+ .quad 0x12b54136f590bd33+ .quad 0x0a4e0373d784d9b4+ .quad 0x6a9c1ff068f587ba+ .quad 0x0827894e0050c8de+ .quad 0x3cbf99557ded5be7+ .quad 0x64a9b0431c06d6f0+ .quad 0x2eb3d6a15b7d2919+ .quad 0xb0b4f6a0d53a8235+ .quad 0x7156ce4389a45d47+ .quad 0x071a7d0ace18346c++ // 2^160 * 4 * G++ .quad 0xd3072daac887ba0b+ .quad 0x01262905bfa562ee+ .quad 0xcf543002c0ef768b+ .quad 0x2c3bcc7146ea7e9c+ .quad 0xcc0c355220e14431+ .quad 0x0d65950709b15141+ .quad 0x9af5621b209d5f36+ .quad 0x7c69bcf7617755d3+ .quad 0x07f0d7eb04e8295f+ .quad 0x10db18252f50f37d+ .quad 0xe951a9a3171798d7+ .quad 0x6f5a9a7322aca51d++ // 2^160 * 5 * G++ .quad 0x8ba1000c2f41c6c5+ .quad 0xc49f79c10cfefb9b+ .quad 0x4efa47703cc51c9f+ .quad 0x494e21a2e147afca+ .quad 0xe729d4eba3d944be+ .quad 0x8d9e09408078af9e+ .quad 0x4525567a47869c03+ .quad 0x02ab9680ee8d3b24+ .quad 0xefa48a85dde50d9a+ .quad 0x219a224e0fb9a249+ .quad 0xfa091f1dd91ef6d9+ .quad 0x6b5d76cbea46bb34++ // 2^160 * 6 * G++ .quad 0x8857556cec0cd994+ .quad 0x6472dc6f5cd01dba+ .quad 0xaf0169148f42b477+ .quad 0x0ae333f685277354+ .quad 0xe0f941171e782522+ .quad 0xf1e6ae74036936d3+ .quad 0x408b3ea2d0fcc746+ .quad 0x16fb869c03dd313e+ .quad 0x288e199733b60962+ .quad 0x24fc72b4d8abe133+ .quad 0x4811f7ed0991d03e+ .quad 0x3f81e38b8f70d075++ // 2^160 * 7 * G++ .quad 0x7f910fcc7ed9affe+ .quad 0x545cb8a12465874b+ .quad 0xa8397ed24b0c4704+ .quad 0x50510fc104f50993+ .quad 0x0adb7f355f17c824+ .quad 0x74b923c3d74299a4+ .quad 0xd57c3e8bcbf8eaf7+ .quad 0x0ad3e2d34cdedc3d+ .quad 0x6f0c0fc5336e249d+ .quad 0x745ede19c331cfd9+ .quad 0xf2d6fd0009eefe1c+ .quad 0x127c158bf0fa1ebe++ // 2^160 * 8 * G++ .quad 0xf6197c422e9879a2+ .quad 0xa44addd452ca3647+ .quad 0x9b413fc14b4eaccb+ .quad 0x354ef87d07ef4f68+ .quad 0xdea28fc4ae51b974+ .quad 0x1d9973d3744dfe96+ .quad 0x6240680b873848a8+ .quad 0x4ed82479d167df95+ .quad 0xfee3b52260c5d975+ .quad 0x50352efceb41b0b8+ .quad 0x8808ac30a9f6653c+ .quad 0x302d92d20539236d++ // 2^164 * 1 * G++ .quad 0x4c59023fcb3efb7c+ .quad 0x6c2fcb99c63c2a94+ .quad 0xba4190e2c3c7e084+ .quad 0x0e545daea51874d9+ .quad 0x957b8b8b0df53c30+ .quad 0x2a1c770a8e60f098+ .quad 0xbbc7a670345796de+ .quad 0x22a48f9a90c99bc9+ .quad 0x6b7dc0dc8d3fac58+ .quad 0x5497cd6ce6e42bfd+ .quad 0x542f7d1bf400d305+ .quad 0x4159f47f048d9136++ // 2^164 * 2 * G++ .quad 0x20ad660839e31e32+ .quad 0xf81e1bd58405be50+ .quad 0xf8064056f4dabc69+ .quad 0x14d23dd4ce71b975+ .quad 0x748515a8bbd24839+ .quad 0x77128347afb02b55+ .quad 0x50ba2ac649a2a17f+ .quad 0x060525513ad730f1+ .quad 0xf2398e098aa27f82+ .quad 0x6d7982bb89a1b024+ .quad 0xfa694084214dd24c+ .quad 0x71ab966fa32301c3++ // 2^164 * 3 * G++ .quad 0x2dcbd8e34ded02fc+ .quad 0x1151f3ec596f22aa+ .quad 0xbca255434e0328da+ .quad 0x35768fbe92411b22+ .quad 0xb1088a0702809955+ .quad 0x43b273ea0b43c391+ .quad 0xca9b67aefe0686ed+ .quad 0x605eecbf8335f4ed+ .quad 0x83200a656c340431+ .quad 0x9fcd71678ee59c2f+ .quad 0x75d4613f71300f8a+ .quad 0x7a912faf60f542f9++ // 2^164 * 4 * G++ .quad 0xb204585e5edc1a43+ .quad 0x9f0e16ee5897c73c+ .quad 0x5b82c0ae4e70483c+ .quad 0x624a170e2bddf9be+ .quad 0x253f4f8dfa2d5597+ .quad 0x25e49c405477130c+ .quad 0x00c052e5996b1102+ .quad 0x33cb966e33bb6c4a+ .quad 0x597028047f116909+ .quad 0x828ac41c1e564467+ .quad 0x70417dbde6217387+ .quad 0x721627aefbac4384++ // 2^164 * 5 * G++ .quad 0x97d03bc38736add5+ .quad 0x2f1422afc532b130+ .quad 0x3aa68a057101bbc4+ .quad 0x4c946cf7e74f9fa7+ .quad 0xfd3097bc410b2f22+ .quad 0xf1a05da7b5cfa844+ .quad 0x61289a1def57ca74+ .quad 0x245ea199bb821902+ .quad 0xaedca66978d477f8+ .quad 0x1898ba3c29117fe1+ .quad 0xcf73f983720cbd58+ .quad 0x67da12e6b8b56351++ // 2^164 * 6 * G++ .quad 0x7067e187b4bd6e07+ .quad 0x6e8f0203c7d1fe74+ .quad 0x93c6aa2f38c85a30+ .quad 0x76297d1f3d75a78a+ .quad 0x2b7ef3d38ec8308c+ .quad 0x828fd7ec71eb94ab+ .quad 0x807c3b36c5062abd+ .quad 0x0cb64cb831a94141+ .quad 0x3030fc33534c6378+ .quad 0xb9635c5ce541e861+ .quad 0x15d9a9bed9b2c728+ .quad 0x49233ea3f3775dcb++ // 2^164 * 7 * G++ .quad 0x629398fa8dbffc3a+ .quad 0xe12fe52dd54db455+ .quad 0xf3be11dfdaf25295+ .quad 0x628b140dce5e7b51+ .quad 0x7b3985fe1c9f249b+ .quad 0x4fd6b2d5a1233293+ .quad 0xceb345941adf4d62+ .quad 0x6987ff6f542de50c+ .quad 0x47e241428f83753c+ .quad 0x6317bebc866af997+ .quad 0xdabb5b433d1a9829+ .quad 0x074d8d245287fb2d++ // 2^164 * 8 * G++ .quad 0x8337d9cd440bfc31+ .quad 0x729d2ca1af318fd7+ .quad 0xa040a4a4772c2070+ .quad 0x46002ef03a7349be+ .quad 0x481875c6c0e31488+ .quad 0x219429b2e22034b4+ .quad 0x7223c98a31283b65+ .quad 0x3420d60b342277f9+ .quad 0xfaa23adeaffe65f7+ .quad 0x78261ed45be0764c+ .quad 0x441c0a1e2f164403+ .quad 0x5aea8e567a87d395++ // 2^168 * 1 * G++ .quad 0x7813c1a2bca4283d+ .quad 0xed62f091a1863dd9+ .quad 0xaec7bcb8c268fa86+ .quad 0x10e5d3b76f1cae4c+ .quad 0x2dbc6fb6e4e0f177+ .quad 0x04e1bf29a4bd6a93+ .quad 0x5e1966d4787af6e8+ .quad 0x0edc5f5eb426d060+ .quad 0x5453bfd653da8e67+ .quad 0xe9dc1eec24a9f641+ .quad 0xbf87263b03578a23+ .quad 0x45b46c51361cba72++ // 2^168 * 2 * G++ .quad 0xa9402abf314f7fa1+ .quad 0xe257f1dc8e8cf450+ .quad 0x1dbbd54b23a8be84+ .quad 0x2177bfa36dcb713b+ .quad 0xce9d4ddd8a7fe3e4+ .quad 0xab13645676620e30+ .quad 0x4b594f7bb30e9958+ .quad 0x5c1c0aef321229df+ .quad 0x37081bbcfa79db8f+ .quad 0x6048811ec25f59b3+ .quad 0x087a76659c832487+ .quad 0x4ae619387d8ab5bb++ // 2^168 * 3 * G++ .quad 0x8ddbf6aa5344a32e+ .quad 0x7d88eab4b41b4078+ .quad 0x5eb0eb974a130d60+ .quad 0x1a00d91b17bf3e03+ .quad 0x61117e44985bfb83+ .quad 0xfce0462a71963136+ .quad 0x83ac3448d425904b+ .quad 0x75685abe5ba43d64+ .quad 0x6e960933eb61f2b2+ .quad 0x543d0fa8c9ff4952+ .quad 0xdf7275107af66569+ .quad 0x135529b623b0e6aa++ // 2^168 * 4 * G++ .quad 0x18f0dbd7add1d518+ .quad 0x979f7888cfc11f11+ .quad 0x8732e1f07114759b+ .quad 0x79b5b81a65ca3a01+ .quad 0xf5c716bce22e83fe+ .quad 0xb42beb19e80985c1+ .quad 0xec9da63714254aae+ .quad 0x5972ea051590a613+ .quad 0x0fd4ac20dc8f7811+ .quad 0x9a9ad294ac4d4fa8+ .quad 0xc01b2d64b3360434+ .quad 0x4f7e9c95905f3bdb++ // 2^168 * 5 * G++ .quad 0x62674bbc5781302e+ .quad 0xd8520f3989addc0f+ .quad 0x8c2999ae53fbd9c6+ .quad 0x31993ad92e638e4c+ .quad 0x71c8443d355299fe+ .quad 0x8bcd3b1cdbebead7+ .quad 0x8092499ef1a49466+ .quad 0x1942eec4a144adc8+ .quad 0x7dac5319ae234992+ .quad 0x2c1b3d910cea3e92+ .quad 0x553ce494253c1122+ .quad 0x2a0a65314ef9ca75++ // 2^168 * 6 * G++ .quad 0x2db7937ff7f927c2+ .quad 0xdb741f0617d0a635+ .quad 0x5982f3a21155af76+ .quad 0x4cf6e218647c2ded+ .quad 0xcf361acd3c1c793a+ .quad 0x2f9ebcac5a35bc3b+ .quad 0x60e860e9a8cda6ab+ .quad 0x055dc39b6dea1a13+ .quad 0xb119227cc28d5bb6+ .quad 0x07e24ebc774dffab+ .quad 0xa83c78cee4a32c89+ .quad 0x121a307710aa24b6++ // 2^168 * 7 * G++ .quad 0xe4db5d5e9f034a97+ .quad 0xe153fc093034bc2d+ .quad 0x460546919551d3b1+ .quad 0x333fc76c7a40e52d+ .quad 0xd659713ec77483c9+ .quad 0x88bfe077b82b96af+ .quad 0x289e28231097bcd3+ .quad 0x527bb94a6ced3a9b+ .quad 0x563d992a995b482e+ .quad 0x3405d07c6e383801+ .quad 0x485035de2f64d8e5+ .quad 0x6b89069b20a7a9f7++ // 2^168 * 8 * G++ .quad 0x812aa0416270220d+ .quad 0x995a89faf9245b4e+ .quad 0xffadc4ce5072ef05+ .quad 0x23bc2103aa73eb73+ .quad 0x4082fa8cb5c7db77+ .quad 0x068686f8c734c155+ .quad 0x29e6c8d9f6e7a57e+ .quad 0x0473d308a7639bcf+ .quad 0xcaee792603589e05+ .quad 0x2b4b421246dcc492+ .quad 0x02a1ef74e601a94f+ .quad 0x102f73bfde04341a++ // 2^172 * 1 * G++ .quad 0xb5a2d50c7ec20d3e+ .quad 0xc64bdd6ea0c97263+ .quad 0x56e89052c1ff734d+ .quad 0x4929c6f72b2ffaba+ .quad 0x358ecba293a36247+ .quad 0xaf8f9862b268fd65+ .quad 0x412f7e9968a01c89+ .quad 0x5786f312cd754524+ .quad 0x337788ffca14032c+ .quad 0xf3921028447f1ee3+ .quad 0x8b14071f231bccad+ .quad 0x4c817b4bf2344783++ // 2^172 * 2 * G++ .quad 0x0ff853852871b96e+ .quad 0xe13e9fab60c3f1bb+ .quad 0xeefd595325344402+ .quad 0x0a37c37075b7744b+ .quad 0x413ba057a40b4484+ .quad 0xba4c2e1a4f5f6a43+ .quad 0x614ba0a5aee1d61c+ .quad 0x78a1531a8b05dc53+ .quad 0x6cbdf1703ad0562b+ .quad 0x8ecf4830c92521a3+ .quad 0xdaebd303fd8424e7+ .quad 0x72ad82a42e5ec56f++ // 2^172 * 3 * G++ .quad 0x3f9e8e35bafb65f6+ .quad 0x39d69ec8f27293a1+ .quad 0x6cb8cd958cf6a3d0+ .quad 0x1734778173adae6d+ .quad 0xc368939167024bc3+ .quad 0x8e69d16d49502fda+ .quad 0xfcf2ec3ce45f4b29+ .quad 0x065f669ea3b4cbc4+ .quad 0x8a00aec75532db4d+ .quad 0xb869a4e443e31bb1+ .quad 0x4a0f8552d3a7f515+ .quad 0x19adeb7c303d7c08++ // 2^172 * 4 * G++ .quad 0xc720cb6153ead9a3+ .quad 0x55b2c97f512b636e+ .quad 0xb1e35b5fd40290b1+ .quad 0x2fd9ccf13b530ee2+ .quad 0x9d05ba7d43c31794+ .quad 0x2470c8ff93322526+ .quad 0x8323dec816197438+ .quad 0x2852709881569b53+ .quad 0x07bd475b47f796b8+ .quad 0xd2c7b013542c8f54+ .quad 0x2dbd23f43b24f87e+ .quad 0x6551afd77b0901d6++ // 2^172 * 5 * G++ .quad 0x4546baaf54aac27f+ .quad 0xf6f66fecb2a45a28+ .quad 0x582d1b5b562bcfe8+ .quad 0x44b123f3920f785f+ .quad 0x68a24ce3a1d5c9ac+ .quad 0xbb77a33d10ff6461+ .quad 0x0f86ce4425d3166e+ .quad 0x56507c0950b9623b+ .quad 0x1206f0b7d1713e63+ .quad 0x353fe3d915bafc74+ .quad 0x194ceb970ad9d94d+ .quad 0x62fadd7cf9d03ad3++ // 2^172 * 6 * G++ .quad 0xc6b5967b5598a074+ .quad 0x5efe91ce8e493e25+ .quad 0xd4b72c4549280888+ .quad 0x20ef1149a26740c2+ .quad 0x3cd7bc61e7ce4594+ .quad 0xcd6b35a9b7dd267e+ .quad 0xa080abc84366ef27+ .quad 0x6ec7c46f59c79711+ .quad 0x2f07ad636f09a8a2+ .quad 0x8697e6ce24205e7d+ .quad 0xc0aefc05ee35a139+ .quad 0x15e80958b5f9d897++ // 2^172 * 7 * G++ .quad 0x25a5ef7d0c3e235b+ .quad 0x6c39c17fbe134ee7+ .quad 0xc774e1342dc5c327+ .quad 0x021354b892021f39+ .quad 0x4dd1ed355bb061c4+ .quad 0x42dc0cef941c0700+ .quad 0x61305dc1fd86340e+ .quad 0x56b2cc930e55a443+ .quad 0x1df79da6a6bfc5a2+ .quad 0x02f3a2749fde4369+ .quad 0xb323d9f2cda390a7+ .quad 0x7be0847b8774d363++ // 2^172 * 8 * G++ .quad 0x8c99cc5a8b3f55c3+ .quad 0x0611d7253fded2a0+ .quad 0xed2995ff36b70a36+ .quad 0x1f699a54d78a2619+ .quad 0x1466f5af5307fa11+ .quad 0x817fcc7ded6c0af2+ .quad 0x0a6de44ec3a4a3fb+ .quad 0x74071475bc927d0b+ .quad 0xe77292f373e7ea8a+ .quad 0x296537d2cb045a31+ .quad 0x1bd0653ed3274fde+ .quad 0x2f9a2c4476bd2966++ // 2^176 * 1 * G++ .quad 0xeb18b9ab7f5745c6+ .quad 0x023a8aee5787c690+ .quad 0xb72712da2df7afa9+ .quad 0x36597d25ea5c013d+ .quad 0xa2b4dae0b5511c9a+ .quad 0x7ac860292bffff06+ .quad 0x981f375df5504234+ .quad 0x3f6bd725da4ea12d+ .quad 0x734d8d7b106058ac+ .quad 0xd940579e6fc6905f+ .quad 0x6466f8f99202932d+ .quad 0x7b7ecc19da60d6d0++ // 2^176 * 2 * G++ .quad 0x78c2373c695c690d+ .quad 0xdd252e660642906e+ .quad 0x951d44444ae12bd2+ .quad 0x4235ad7601743956+ .quad 0x6dae4a51a77cfa9b+ .quad 0x82263654e7a38650+ .quad 0x09bbffcd8f2d82db+ .quad 0x03bedc661bf5caba+ .quad 0x6258cb0d078975f5+ .quad 0x492942549189f298+ .quad 0xa0cab423e2e36ee4+ .quad 0x0e7ce2b0cdf066a1++ // 2^176 * 3 * G++ .quad 0xc494643ac48c85a3+ .quad 0xfd361df43c6139ad+ .quad 0x09db17dd3ae94d48+ .quad 0x666e0a5d8fb4674a+ .quad 0xfea6fedfd94b70f9+ .quad 0xf130c051c1fcba2d+ .quad 0x4882d47e7f2fab89+ .quad 0x615256138aeceeb5+ .quad 0x2abbf64e4870cb0d+ .quad 0xcd65bcf0aa458b6b+ .quad 0x9abe4eba75e8985d+ .quad 0x7f0bc810d514dee4++ // 2^176 * 4 * G++ .quad 0xb9006ba426f4136f+ .quad 0x8d67369e57e03035+ .quad 0xcbc8dfd94f463c28+ .quad 0x0d1f8dbcf8eedbf5+ .quad 0x83ac9dad737213a0+ .quad 0x9ff6f8ba2ef72e98+ .quad 0x311e2edd43ec6957+ .quad 0x1d3a907ddec5ab75+ .quad 0xba1693313ed081dc+ .quad 0x29329fad851b3480+ .quad 0x0128013c030321cb+ .quad 0x00011b44a31bfde3++ // 2^176 * 5 * G++ .quad 0x3fdfa06c3fc66c0c+ .quad 0x5d40e38e4dd60dd2+ .quad 0x7ae38b38268e4d71+ .quad 0x3ac48d916e8357e1+ .quad 0x16561f696a0aa75c+ .quad 0xc1bf725c5852bd6a+ .quad 0x11a8dd7f9a7966ad+ .quad 0x63d988a2d2851026+ .quad 0x00120753afbd232e+ .quad 0xe92bceb8fdd8f683+ .quad 0xf81669b384e72b91+ .quad 0x33fad52b2368a066++ // 2^176 * 6 * G++ .quad 0x540649c6c5e41e16+ .quad 0x0af86430333f7735+ .quad 0xb2acfcd2f305e746+ .quad 0x16c0f429a256dca7+ .quad 0x8d2cc8d0c422cfe8+ .quad 0x072b4f7b05a13acb+ .quad 0xa3feb6e6ecf6a56f+ .quad 0x3cc355ccb90a71e2+ .quad 0xe9b69443903e9131+ .quad 0xb8a494cb7a5637ce+ .quad 0xc87cd1a4baba9244+ .quad 0x631eaf426bae7568++ // 2^176 * 7 * G++ .quad 0xb3e90410da66fe9f+ .quad 0x85dd4b526c16e5a6+ .quad 0xbc3d97611ef9bf83+ .quad 0x5599648b1ea919b5+ .quad 0x47d975b9a3700de8+ .quad 0x7280c5fbe2f80552+ .quad 0x53658f2732e45de1+ .quad 0x431f2c7f665f80b5+ .quad 0xd6026344858f7b19+ .quad 0x14ab352fa1ea514a+ .quad 0x8900441a2090a9d7+ .quad 0x7b04715f91253b26++ // 2^176 * 8 * G++ .quad 0x83edbd28acf6ae43+ .quad 0x86357c8b7d5c7ab4+ .quad 0xc0404769b7eb2c44+ .quad 0x59b37bf5c2f6583f+ .quad 0xb376c280c4e6bac6+ .quad 0x970ed3dd6d1d9b0b+ .quad 0xb09a9558450bf944+ .quad 0x48d0acfa57cde223+ .quad 0xb60f26e47dabe671+ .quad 0xf1d1a197622f3a37+ .quad 0x4208ce7ee9960394+ .quad 0x16234191336d3bdb++ // 2^180 * 1 * G++ .quad 0xf19aeac733a63aef+ .quad 0x2c7fba5d4442454e+ .quad 0x5da87aa04795e441+ .quad 0x413051e1a4e0b0f5+ .quad 0x852dd1fd3d578bbe+ .quad 0x2b65ce72c3286108+ .quad 0x658c07f4eace2273+ .quad 0x0933f804ec38ab40+ .quad 0xa7ab69798d496476+ .quad 0x8121aadefcb5abc8+ .quad 0xa5dc12ef7b539472+ .quad 0x07fd47065e45351a++ // 2^180 * 2 * G++ .quad 0xc8583c3d258d2bcd+ .quad 0x17029a4daf60b73f+ .quad 0xfa0fc9d6416a3781+ .quad 0x1c1e5fba38b3fb23+ .quad 0x304211559ae8e7c3+ .quad 0xf281b229944882a5+ .quad 0x8a13ac2e378250e4+ .quad 0x014afa0954ba48f4+ .quad 0xcb3197001bb3666c+ .quad 0x330060524bffecb9+ .quad 0x293711991a88233c+ .quad 0x291884363d4ed364++ // 2^180 * 3 * G++ .quad 0x033c6805dc4babfa+ .quad 0x2c15bf5e5596ecc1+ .quad 0x1bc70624b59b1d3b+ .quad 0x3ede9850a19f0ec5+ .quad 0xfb9d37c3bc1ab6eb+ .quad 0x02be14534d57a240+ .quad 0xf4d73415f8a5e1f6+ .quad 0x5964f4300ccc8188+ .quad 0xe44a23152d096800+ .quad 0x5c08c55970866996+ .quad 0xdf2db60a46affb6e+ .quad 0x579155c1f856fd89++ // 2^180 * 4 * G++ .quad 0x96324edd12e0c9ef+ .quad 0x468b878df2420297+ .quad 0x199a3776a4f573be+ .quad 0x1e7fbcf18e91e92a+ .quad 0xb5f16b630817e7a6+ .quad 0x808c69233c351026+ .quad 0x324a983b54cef201+ .quad 0x53c092084a485345+ .quad 0xd2d41481f1cbafbf+ .quad 0x231d2db6716174e5+ .quad 0x0b7d7656e2a55c98+ .quad 0x3e955cd82aa495f6++ // 2^180 * 5 * G++ .quad 0xe48f535e3ed15433+ .quad 0xd075692a0d7270a3+ .quad 0x40fbd21daade6387+ .quad 0x14264887cf4495f5+ .quad 0xab39f3ef61bb3a3f+ .quad 0x8eb400652eb9193e+ .quad 0xb5de6ecc38c11f74+ .quad 0x654d7e9626f3c49f+ .quad 0xe564cfdd5c7d2ceb+ .quad 0x82eeafded737ccb9+ .quad 0x6107db62d1f9b0ab+ .quad 0x0b6baac3b4358dbb++ // 2^180 * 6 * G++ .quad 0x7ae62bcb8622fe98+ .quad 0x47762256ceb891af+ .quad 0x1a5a92bcf2e406b4+ .quad 0x7d29401784e41501+ .quad 0x204abad63700a93b+ .quad 0xbe0023d3da779373+ .quad 0xd85f0346633ab709+ .quad 0x00496dc490820412+ .quad 0x1c74b88dc27e6360+ .quad 0x074854268d14850c+ .quad 0xa145fb7b3e0dcb30+ .quad 0x10843f1b43803b23++ // 2^180 * 7 * G++ .quad 0xc5f90455376276dd+ .quad 0xce59158dd7645cd9+ .quad 0x92f65d511d366b39+ .quad 0x11574b6e526996c4+ .quad 0xd56f672de324689b+ .quad 0xd1da8aedb394a981+ .quad 0xdd7b58fe9168cfed+ .quad 0x7ce246cd4d56c1e8+ .quad 0xb8f4308e7f80be53+ .quad 0x5f3cb8cb34a9d397+ .quad 0x18a961bd33cc2b2c+ .quad 0x710045fb3a9af671++ // 2^180 * 8 * G++ .quad 0x73f93d36101b95eb+ .quad 0xfaef33794f6f4486+ .quad 0x5651735f8f15e562+ .quad 0x7fa3f19058b40da1+ .quad 0xa03fc862059d699e+ .quad 0x2370cfa19a619e69+ .quad 0xc4fe3b122f823deb+ .quad 0x1d1b056fa7f0844e+ .quad 0x1bc64631e56bf61f+ .quad 0xd379ab106e5382a3+ .quad 0x4d58c57e0540168d+ .quad 0x566256628442d8e4++ // 2^184 * 1 * G++ .quad 0xb9e499def6267ff6+ .quad 0x7772ca7b742c0843+ .quad 0x23a0153fe9a4f2b1+ .quad 0x2cdfdfecd5d05006+ .quad 0xdd499cd61ff38640+ .quad 0x29cd9bc3063625a0+ .quad 0x51e2d8023dd73dc3+ .quad 0x4a25707a203b9231+ .quad 0x2ab7668a53f6ed6a+ .quad 0x304242581dd170a1+ .quad 0x4000144c3ae20161+ .quad 0x5721896d248e49fc++ // 2^184 * 2 * G++ .quad 0x0b6e5517fd181bae+ .quad 0x9022629f2bb963b4+ .quad 0x5509bce932064625+ .quad 0x578edd74f63c13da+ .quad 0x285d5091a1d0da4e+ .quad 0x4baa6fa7b5fe3e08+ .quad 0x63e5177ce19393b3+ .quad 0x03c935afc4b030fd+ .quad 0x997276c6492b0c3d+ .quad 0x47ccc2c4dfe205fc+ .quad 0xdcd29b84dd623a3c+ .quad 0x3ec2ab590288c7a2++ // 2^184 * 3 * G++ .quad 0xa1a0d27be4d87bb9+ .quad 0xa98b4deb61391aed+ .quad 0x99a0ddd073cb9b83+ .quad 0x2dd5c25a200fcace+ .quad 0xa7213a09ae32d1cb+ .quad 0x0f2b87df40f5c2d5+ .quad 0x0baea4c6e81eab29+ .quad 0x0e1bf66c6adbac5e+ .quad 0xe2abd5e9792c887e+ .quad 0x1a020018cb926d5d+ .quad 0xbfba69cdbaae5f1e+ .quad 0x730548b35ae88f5f++ // 2^184 * 4 * G++ .quad 0xc43551a3cba8b8ee+ .quad 0x65a26f1db2115f16+ .quad 0x760f4f52ab8c3850+ .quad 0x3043443b411db8ca+ .quad 0x805b094ba1d6e334+ .quad 0xbf3ef17709353f19+ .quad 0x423f06cb0622702b+ .quad 0x585a2277d87845dd+ .quad 0xa18a5f8233d48962+ .quad 0x6698c4b5ec78257f+ .quad 0xa78e6fa5373e41ff+ .quad 0x7656278950ef981f++ // 2^184 * 5 * G++ .quad 0x38c3cf59d51fc8c0+ .quad 0x9bedd2fd0506b6f2+ .quad 0x26bf109fab570e8f+ .quad 0x3f4160a8c1b846a6+ .quad 0xe17073a3ea86cf9d+ .quad 0x3a8cfbb707155fdc+ .quad 0x4853e7fc31838a8e+ .quad 0x28bbf484b613f616+ .quad 0xf2612f5c6f136c7c+ .quad 0xafead107f6dd11be+ .quad 0x527e9ad213de6f33+ .quad 0x1e79cb358188f75d++ // 2^184 * 6 * G++ .quad 0x013436c3eef7e3f1+ .quad 0x828b6a7ffe9e10f8+ .quad 0x7ff908e5bcf9defc+ .quad 0x65d7951b3a3b3831+ .quad 0x77e953d8f5e08181+ .quad 0x84a50c44299dded9+ .quad 0xdc6c2d0c864525e5+ .quad 0x478ab52d39d1f2f4+ .quad 0x66a6a4d39252d159+ .quad 0xe5dde1bc871ac807+ .quad 0xb82c6b40a6c1c96f+ .quad 0x16d87a411a212214++ // 2^184 * 7 * G++ .quad 0xb3bd7e5a42066215+ .quad 0x879be3cd0c5a24c1+ .quad 0x57c05db1d6f994b7+ .quad 0x28f87c8165f38ca6+ .quad 0xfba4d5e2d54e0583+ .quad 0xe21fafd72ebd99fa+ .quad 0x497ac2736ee9778f+ .quad 0x1f990b577a5a6dde+ .quad 0xa3344ead1be8f7d6+ .quad 0x7d1e50ebacea798f+ .quad 0x77c6569e520de052+ .quad 0x45882fe1534d6d3e++ // 2^184 * 8 * G++ .quad 0x6669345d757983d6+ .quad 0x62b6ed1117aa11a6+ .quad 0x7ddd1857985e128f+ .quad 0x688fe5b8f626f6dd+ .quad 0xd8ac9929943c6fe4+ .quad 0xb5f9f161a38392a2+ .quad 0x2699db13bec89af3+ .quad 0x7dcf843ce405f074+ .quad 0x6c90d6484a4732c0+ .quad 0xd52143fdca563299+ .quad 0xb3be28c3915dc6e1+ .quad 0x6739687e7327191b++ // 2^188 * 1 * G++ .quad 0x9f65c5ea200814cf+ .quad 0x840536e169a31740+ .quad 0x8b0ed13925c8b4ad+ .quad 0x0080dbafe936361d+ .quad 0x8ce5aad0c9cb971f+ .quad 0x1156aaa99fd54a29+ .quad 0x41f7247015af9b78+ .quad 0x1fe8cca8420f49aa+ .quad 0x72a1848f3c0cc82a+ .quad 0x38c560c2877c9e54+ .quad 0x5004e228ce554140+ .quad 0x042418a103429d71++ // 2^188 * 2 * G++ .quad 0x899dea51abf3ff5f+ .quad 0x9b93a8672fc2d8ba+ .quad 0x2c38cb97be6ebd5c+ .quad 0x114d578497263b5d+ .quad 0x58e84c6f20816247+ .quad 0x8db2b2b6e36fd793+ .quad 0x977182561d484d85+ .quad 0x0822024f8632abd7+ .quad 0xb301bb7c6b1beca3+ .quad 0x55393f6dc6eb1375+ .quad 0x910d281097b6e4eb+ .quad 0x1ad4548d9d479ea3++ // 2^188 * 3 * G++ .quad 0xcd5a7da0389a48fd+ .quad 0xb38fa4aa9a78371e+ .quad 0xc6d9761b2cdb8e6c+ .quad 0x35cf51dbc97e1443+ .quad 0xa06fe66d0fe9fed3+ .quad 0xa8733a401c587909+ .quad 0x30d14d800df98953+ .quad 0x41ce5876c7b30258+ .quad 0x59ac3bc5d670c022+ .quad 0xeae67c109b119406+ .quad 0x9798bdf0b3782fda+ .quad 0x651e3201fd074092++ // 2^188 * 4 * G++ .quad 0xd63d8483ef30c5cf+ .quad 0x4cd4b4962361cc0c+ .quad 0xee90e500a48426ac+ .quad 0x0af51d7d18c14eeb+ .quad 0xa57ba4a01efcae9e+ .quad 0x769f4beedc308a94+ .quad 0xd1f10eeb3603cb2e+ .quad 0x4099ce5e7e441278+ .quad 0x1ac98e4f8a5121e9+ .quad 0x7dae9544dbfa2fe0+ .quad 0x8320aa0dd6430df9+ .quad 0x667282652c4a2fb5++ // 2^188 * 5 * G++ .quad 0x874621f4d86bc9ab+ .quad 0xb54c7bbe56fe6fea+ .quad 0x077a24257fadc22c+ .quad 0x1ab53be419b90d39+ .quad 0xada8b6e02946db23+ .quad 0x1c0ce51a7b253ab7+ .quad 0x8448c85a66dd485b+ .quad 0x7f1fc025d0675adf+ .quad 0xd8ee1b18319ea6aa+ .quad 0x004d88083a21f0da+ .quad 0x3bd6aa1d883a4f4b+ .quad 0x4db9a3a6dfd9fd14++ // 2^188 * 6 * G++ .quad 0x8ce7b23bb99c0755+ .quad 0x35c5d6edc4f50f7a+ .quad 0x7e1e2ed2ed9b50c3+ .quad 0x36305f16e8934da1+ .quad 0xd95b00bbcbb77c68+ .quad 0xddbc846a91f17849+ .quad 0x7cf700aebe28d9b3+ .quad 0x5ce1285c85d31f3e+ .quad 0x31b6972d98b0bde8+ .quad 0x7d920706aca6de5b+ .quad 0xe67310f8908a659f+ .quad 0x50fac2a6efdf0235++ // 2^188 * 7 * G++ .quad 0xf3d3a9f35b880f5a+ .quad 0xedec050cdb03e7c2+ .quad 0xa896981ff9f0b1a2+ .quad 0x49a4ae2bac5e34a4+ .quad 0x295b1c86f6f449bc+ .quad 0x51b2e84a1f0ab4dd+ .quad 0xc001cb30aa8e551d+ .quad 0x6a28d35944f43662+ .quad 0x28bb12ee04a740e0+ .quad 0x14313bbd9bce8174+ .quad 0x72f5b5e4e8c10c40+ .quad 0x7cbfb19936adcd5b++ // 2^188 * 8 * G++ .quad 0xa311ddc26b89792d+ .quad 0x1b30b4c6da512664+ .quad 0x0ca77b4ccf150859+ .quad 0x1de443df1b009408+ .quad 0x8e793a7acc36e6e0+ .quad 0xf9fab7a37d586eed+ .quad 0x3a4f9692bae1f4e4+ .quad 0x1c14b03eff5f447e+ .quad 0x19647bd114a85291+ .quad 0x57b76cb21034d3af+ .quad 0x6329db440f9d6dfa+ .quad 0x5ef43e586a571493++ // 2^192 * 1 * G++ .quad 0xef782014385675a6+ .quad 0xa2649f30aafda9e8+ .quad 0x4cd1eb505cdfa8cb+ .quad 0x46115aba1d4dc0b3+ .quad 0xa66dcc9dc80c1ac0+ .quad 0x97a05cf41b38a436+ .quad 0xa7ebf3be95dbd7c6+ .quad 0x7da0b8f68d7e7dab+ .quad 0xd40f1953c3b5da76+ .quad 0x1dac6f7321119e9b+ .quad 0x03cc6021feb25960+ .quad 0x5a5f887e83674b4b++ // 2^192 * 2 * G++ .quad 0x8f6301cf70a13d11+ .quad 0xcfceb815350dd0c4+ .quad 0xf70297d4a4bca47e+ .quad 0x3669b656e44d1434+ .quad 0x9e9628d3a0a643b9+ .quad 0xb5c3cb00e6c32064+ .quad 0x9b5302897c2dec32+ .quad 0x43e37ae2d5d1c70c+ .quad 0x387e3f06eda6e133+ .quad 0x67301d5199a13ac0+ .quad 0xbd5ad8f836263811+ .quad 0x6a21e6cd4fd5e9be++ // 2^192 * 3 * G++ .quad 0xf1c6170a3046e65f+ .quad 0x58712a2a00d23524+ .quad 0x69dbbd3c8c82b755+ .quad 0x586bf9f1a195ff57+ .quad 0xef4129126699b2e3+ .quad 0x71d30847708d1301+ .quad 0x325432d01182b0bd+ .quad 0x45371b07001e8b36+ .quad 0xa6db088d5ef8790b+ .quad 0x5278f0dc610937e5+ .quad 0xac0349d261a16eb8+ .quad 0x0eafb03790e52179++ // 2^192 * 4 * G++ .quad 0x960555c13748042f+ .quad 0x219a41e6820baa11+ .quad 0x1c81f73873486d0c+ .quad 0x309acc675a02c661+ .quad 0x5140805e0f75ae1d+ .quad 0xec02fbe32662cc30+ .quad 0x2cebdf1eea92396d+ .quad 0x44ae3344c5435bb3+ .quad 0x9cf289b9bba543ee+ .quad 0xf3760e9d5ac97142+ .quad 0x1d82e5c64f9360aa+ .quad 0x62d5221b7f94678f++ // 2^192 * 5 * G++ .quad 0x524c299c18d0936d+ .quad 0xc86bb56c8a0c1a0c+ .quad 0xa375052edb4a8631+ .quad 0x5c0efde4bc754562+ .quad 0x7585d4263af77a3c+ .quad 0xdfae7b11fee9144d+ .quad 0xa506708059f7193d+ .quad 0x14f29a5383922037+ .quad 0xdf717edc25b2d7f5+ .quad 0x21f970db99b53040+ .quad 0xda9234b7c3ed4c62+ .quad 0x5e72365c7bee093e++ // 2^192 * 6 * G++ .quad 0x575bfc074571217f+ .quad 0x3779675d0694d95b+ .quad 0x9a0a37bbf4191e33+ .quad 0x77f1104c47b4eabc+ .quad 0x7d9339062f08b33e+ .quad 0x5b9659e5df9f32be+ .quad 0xacff3dad1f9ebdfd+ .quad 0x70b20555cb7349b7+ .quad 0xbe5113c555112c4c+ .quad 0x6688423a9a881fcd+ .quad 0x446677855e503b47+ .quad 0x0e34398f4a06404a++ // 2^192 * 7 * G++ .quad 0xb67d22d93ecebde8+ .quad 0x09b3e84127822f07+ .quad 0x743fa61fb05b6d8d+ .quad 0x5e5405368a362372+ .quad 0x18930b093e4b1928+ .quad 0x7de3e10e73f3f640+ .quad 0xf43217da73395d6f+ .quad 0x6f8aded6ca379c3e+ .quad 0xe340123dfdb7b29a+ .quad 0x487b97e1a21ab291+ .quad 0xf9967d02fde6949e+ .quad 0x780de72ec8d3de97++ // 2^192 * 8 * G++ .quad 0x0ae28545089ae7bc+ .quad 0x388ddecf1c7f4d06+ .quad 0x38ac15510a4811b8+ .quad 0x0eb28bf671928ce4+ .quad 0x671feaf300f42772+ .quad 0x8f72eb2a2a8c41aa+ .quad 0x29a17fd797373292+ .quad 0x1defc6ad32b587a6+ .quad 0xaf5bbe1aef5195a7+ .quad 0x148c1277917b15ed+ .quad 0x2991f7fb7ae5da2e+ .quad 0x467d201bf8dd2867++ // 2^196 * 1 * G++ .quad 0x7906ee72f7bd2e6b+ .quad 0x05d270d6109abf4e+ .quad 0x8d5cfe45b941a8a4+ .quad 0x44c218671c974287+ .quad 0x745f9d56296bc318+ .quad 0x993580d4d8152e65+ .quad 0xb0e5b13f5839e9ce+ .quad 0x51fc2b28d43921c0+ .quad 0x1b8fd11795e2a98c+ .quad 0x1c4e5ee12b6b6291+ .quad 0x5b30e7107424b572+ .quad 0x6e6b9de84c4f4ac6++ // 2^196 * 2 * G++ .quad 0xdff25fce4b1de151+ .quad 0xd841c0c7e11c4025+ .quad 0x2554b3c854749c87+ .quad 0x2d292459908e0df9+ .quad 0x6b7c5f10f80cb088+ .quad 0x736b54dc56e42151+ .quad 0xc2b620a5c6ef99c4+ .quad 0x5f4c802cc3a06f42+ .quad 0x9b65c8f17d0752da+ .quad 0x881ce338c77ee800+ .quad 0xc3b514f05b62f9e3+ .quad 0x66ed5dd5bec10d48++ // 2^196 * 3 * G++ .quad 0x7d38a1c20bb2089d+ .quad 0x808334e196ccd412+ .quad 0xc4a70b8c6c97d313+ .quad 0x2eacf8bc03007f20+ .quad 0xf0adf3c9cbca047d+ .quad 0x81c3b2cbf4552f6b+ .quad 0xcfda112d44735f93+ .quad 0x1f23a0c77e20048c+ .quad 0xf235467be5bc1570+ .quad 0x03d2d9020dbab38c+ .quad 0x27529aa2fcf9e09e+ .quad 0x0840bef29d34bc50++ // 2^196 * 4 * G++ .quad 0x796dfb35dc10b287+ .quad 0x27176bcd5c7ff29d+ .quad 0x7f3d43e8c7b24905+ .quad 0x0304f5a191c54276+ .quad 0xcd54e06b7f37e4eb+ .quad 0x8cc15f87f5e96cca+ .quad 0xb8248bb0d3597dce+ .quad 0x246affa06074400c+ .quad 0x37d88e68fbe45321+ .quad 0x86097548c0d75032+ .quad 0x4e9b13ef894a0d35+ .quad 0x25a83cac5753d325++ // 2^196 * 5 * G++ .quad 0x10222f48eed8165e+ .quad 0x623fc1234b8bcf3a+ .quad 0x1e145c09c221e8f0+ .quad 0x7ccfa59fca782630+ .quad 0x9f0f66293952b6e2+ .quad 0x33db5e0e0934267b+ .quad 0xff45252bd609fedc+ .quad 0x06be10f5c506e0c9+ .quad 0x1a9615a9b62a345f+ .quad 0x22050c564a52fecc+ .quad 0xa7a2788528bc0dfe+ .quad 0x5e82770a1a1ee71d++ // 2^196 * 6 * G++ .quad 0x35425183ad896a5c+ .quad 0xe8673afbe78d52f6+ .quad 0x2c66f25f92a35f64+ .quad 0x09d04f3b3b86b102+ .quad 0xe802e80a42339c74+ .quad 0x34175166a7fffae5+ .quad 0x34865d1f1c408cae+ .quad 0x2cca982c605bc5ee+ .quad 0xfd2d5d35197dbe6e+ .quad 0x207c2eea8be4ffa3+ .quad 0x2613d8db325ae918+ .quad 0x7a325d1727741d3e++ // 2^196 * 7 * G++ .quad 0xd036b9bbd16dfde2+ .quad 0xa2055757c497a829+ .quad 0x8e6cc966a7f12667+ .quad 0x4d3b1a791239c180+ .quad 0xecd27d017e2a076a+ .quad 0xd788689f1636495e+ .quad 0x52a61af0919233e5+ .quad 0x2a479df17bb1ae64+ .quad 0x9e5eee8e33db2710+ .quad 0x189854ded6c43ca5+ .quad 0xa41c22c592718138+ .quad 0x27ad5538a43a5e9b++ // 2^196 * 8 * G++ .quad 0x2746dd4b15350d61+ .quad 0xd03fcbc8ee9521b7+ .quad 0xe86e365a138672ca+ .quad 0x510e987f7e7d89e2+ .quad 0xcb5a7d638e47077c+ .quad 0x8db7536120a1c059+ .quad 0x549e1e4d8bedfdcc+ .quad 0x080153b7503b179d+ .quad 0xdda69d930a3ed3e3+ .quad 0x3d386ef1cd60a722+ .quad 0xc817ad58bdaa4ee6+ .quad 0x23be8d554fe7372a++ // 2^200 * 1 * G++ .quad 0x95fe919a74ef4fad+ .quad 0x3a827becf6a308a2+ .quad 0x964e01d309a47b01+ .quad 0x71c43c4f5ba3c797+ .quad 0xbc1ef4bd567ae7a9+ .quad 0x3f624cb2d64498bd+ .quad 0xe41064d22c1f4ec8+ .quad 0x2ef9c5a5ba384001+ .quad 0xb6fd6df6fa9e74cd+ .quad 0xf18278bce4af267a+ .quad 0x8255b3d0f1ef990e+ .quad 0x5a758ca390c5f293++ // 2^200 * 2 * G++ .quad 0xa2b72710d9462495+ .quad 0x3aa8c6d2d57d5003+ .quad 0xe3d400bfa0b487ca+ .quad 0x2dbae244b3eb72ec+ .quad 0x8ce0918b1d61dc94+ .quad 0x8ded36469a813066+ .quad 0xd4e6a829afe8aad3+ .quad 0x0a738027f639d43f+ .quad 0x980f4a2f57ffe1cc+ .quad 0x00670d0de1839843+ .quad 0x105c3f4a49fb15fd+ .quad 0x2698ca635126a69c++ // 2^200 * 3 * G++ .quad 0xe765318832b0ba78+ .quad 0x381831f7925cff8b+ .quad 0x08a81b91a0291fcc+ .quad 0x1fb43dcc49caeb07+ .quad 0x2e3d702f5e3dd90e+ .quad 0x9e3f0918e4d25386+ .quad 0x5e773ef6024da96a+ .quad 0x3c004b0c4afa3332+ .quad 0x9aa946ac06f4b82b+ .quad 0x1ca284a5a806c4f3+ .quad 0x3ed3265fc6cd4787+ .quad 0x6b43fd01cd1fd217++ // 2^200 * 4 * G++ .quad 0xc7a75d4b4697c544+ .quad 0x15fdf848df0fffbf+ .quad 0x2868b9ebaa46785a+ .quad 0x5a68d7105b52f714+ .quad 0xb5c742583e760ef3+ .quad 0x75dc52b9ee0ab990+ .quad 0xbf1427c2072b923f+ .quad 0x73420b2d6ff0d9f0+ .quad 0xaf2cf6cb9e851e06+ .quad 0x8f593913c62238c4+ .quad 0xda8ab89699fbf373+ .quad 0x3db5632fea34bc9e++ // 2^200 * 5 * G++ .quad 0xf46eee2bf75dd9d8+ .quad 0x0d17b1f6396759a5+ .quad 0x1bf2d131499e7273+ .quad 0x04321adf49d75f13+ .quad 0x2e4990b1829825d5+ .quad 0xedeaeb873e9a8991+ .quad 0xeef03d394c704af8+ .quad 0x59197ea495df2b0e+ .quad 0x04e16019e4e55aae+ .quad 0xe77b437a7e2f92e9+ .quad 0xc7ce2dc16f159aa4+ .quad 0x45eafdc1f4d70cc0++ // 2^200 * 6 * G++ .quad 0x698401858045d72b+ .quad 0x4c22faa2cf2f0651+ .quad 0x941a36656b222dc6+ .quad 0x5a5eebc80362dade+ .quad 0xb60e4624cfccb1ed+ .quad 0x59dbc292bd5c0395+ .quad 0x31a09d1ddc0481c9+ .quad 0x3f73ceea5d56d940+ .quad 0xb7a7bfd10a4e8dc6+ .quad 0xbe57007e44c9b339+ .quad 0x60c1207f1557aefa+ .quad 0x26058891266218db++ // 2^200 * 7 * G++ .quad 0x59f704a68360ff04+ .quad 0xc3d93fde7661e6f4+ .quad 0x831b2a7312873551+ .quad 0x54ad0c2e4e615d57+ .quad 0x4c818e3cc676e542+ .quad 0x5e422c9303ceccad+ .quad 0xec07cccab4129f08+ .quad 0x0dedfa10b24443b8+ .quad 0xee3b67d5b82b522a+ .quad 0x36f163469fa5c1eb+ .quad 0xa5b4d2f26ec19fd3+ .quad 0x62ecb2baa77a9408++ // 2^200 * 8 * G++ .quad 0xe5ed795261152b3d+ .quad 0x4962357d0eddd7d1+ .quad 0x7482c8d0b96b4c71+ .quad 0x2e59f919a966d8be+ .quad 0x92072836afb62874+ .quad 0x5fcd5e8579e104a5+ .quad 0x5aad01adc630a14a+ .quad 0x61913d5075663f98+ .quad 0x0dc62d361a3231da+ .quad 0xfa47583294200270+ .quad 0x02d801513f9594ce+ .quad 0x3ddbc2a131c05d5c++ // 2^204 * 1 * G++ .quad 0x3f50a50a4ffb81ef+ .quad 0xb1e035093bf420bf+ .quad 0x9baa8e1cc6aa2cd0+ .quad 0x32239861fa237a40+ .quad 0xfb735ac2004a35d1+ .quad 0x31de0f433a6607c3+ .quad 0x7b8591bfc528d599+ .quad 0x55be9a25f5bb050c+ .quad 0x0d005acd33db3dbf+ .quad 0x0111b37c80ac35e2+ .quad 0x4892d66c6f88ebeb+ .quad 0x770eadb16508fbcd++ // 2^204 * 2 * G++ .quad 0x8451f9e05e4e89dd+ .quad 0xc06302ffbc793937+ .quad 0x5d22749556a6495c+ .quad 0x09a6755ca05603fb+ .quad 0xf1d3b681a05071b9+ .quad 0x2207659a3592ff3a+ .quad 0x5f0169297881e40e+ .quad 0x16bedd0e86ba374e+ .quad 0x5ecccc4f2c2737b5+ .quad 0x43b79e0c2dccb703+ .quad 0x33e008bc4ec43df3+ .quad 0x06c1b840f07566c0++ // 2^204 * 3 * G++ .quad 0x7688a5c6a388f877+ .quad 0x02a96c14deb2b6ac+ .quad 0x64c9f3431b8c2af8+ .quad 0x3628435554a1eed6+ .quad 0x69ee9e7f9b02805c+ .quad 0xcbff828a547d1640+ .quad 0x3d93a869b2430968+ .quad 0x46b7b8cd3fe26972+ .quad 0xe9812086fe7eebe0+ .quad 0x4cba6be72f515437+ .quad 0x1d04168b516efae9+ .quad 0x5ea1391043982cb9++ // 2^204 * 4 * G++ .quad 0x49125c9cf4702ee1+ .quad 0x4520b71f8b25b32d+ .quad 0x33193026501fef7e+ .quad 0x656d8997c8d2eb2b+ .quad 0x6f2b3be4d5d3b002+ .quad 0xafec33d96a09c880+ .quad 0x035f73a4a8bcc4cc+ .quad 0x22c5b9284662198b+ .quad 0xcb58c8fe433d8939+ .quad 0x89a0cb2e6a8d7e50+ .quad 0x79ca955309fbbe5a+ .quad 0x0c626616cd7fc106++ // 2^204 * 5 * G++ .quad 0x1ffeb80a4879b61f+ .quad 0x6396726e4ada21ed+ .quad 0x33c7b093368025ba+ .quad 0x471aa0c6f3c31788+ .quad 0x8fdfc379fbf454b1+ .quad 0x45a5a970f1a4b771+ .quad 0xac921ef7bad35915+ .quad 0x42d088dca81c2192+ .quad 0x8fda0f37a0165199+ .quad 0x0adadb77c8a0e343+ .quad 0x20fbfdfcc875e820+ .quad 0x1cf2bea80c2206e7++ // 2^204 * 6 * G++ .quad 0xc2ddf1deb36202ac+ .quad 0x92a5fe09d2e27aa5+ .quad 0x7d1648f6fc09f1d3+ .quad 0x74c2cc0513bc4959+ .quad 0x982d6e1a02c0412f+ .quad 0x90fa4c83db58e8fe+ .quad 0x01c2f5bcdcb18bc0+ .quad 0x686e0c90216abc66+ .quad 0x1fadbadba54395a7+ .quad 0xb41a02a0ae0da66a+ .quad 0xbf19f598bba37c07+ .quad 0x6a12b8acde48430d++ // 2^204 * 7 * G++ .quad 0xf8daea1f39d495d9+ .quad 0x592c190e525f1dfc+ .quad 0xdb8cbd04c9991d1b+ .quad 0x11f7fda3d88f0cb7+ .quad 0x793bdd801aaeeb5f+ .quad 0x00a2a0aac1518871+ .quad 0xe8a373a31f2136b4+ .quad 0x48aab888fc91ef19+ .quad 0x041f7e925830f40e+ .quad 0x002d6ca979661c06+ .quad 0x86dc9ff92b046a2e+ .quad 0x760360928b0493d1++ // 2^204 * 8 * G++ .quad 0x21bb41c6120cf9c6+ .quad 0xeab2aa12decda59b+ .quad 0xc1a72d020aa48b34+ .quad 0x215d4d27e87d3b68+ .quad 0xb43108e5695a0b05+ .quad 0x6cb00ee8ad37a38b+ .quad 0x5edad6eea3537381+ .quad 0x3f2602d4b6dc3224+ .quad 0xc8b247b65bcaf19c+ .quad 0x49779dc3b1b2c652+ .quad 0x89a180bbd5ece2e2+ .quad 0x13f098a3cec8e039++ // 2^208 * 1 * G++ .quad 0x9adc0ff9ce5ec54b+ .quad 0x039c2a6b8c2f130d+ .quad 0x028007c7f0f89515+ .quad 0x78968314ac04b36b+ .quad 0xf3aa57a22796bb14+ .quad 0x883abab79b07da21+ .quad 0xe54be21831a0391c+ .quad 0x5ee7fb38d83205f9+ .quad 0x538dfdcb41446a8e+ .quad 0xa5acfda9434937f9+ .quad 0x46af908d263c8c78+ .quad 0x61d0633c9bca0d09++ // 2^208 * 2 * G++ .quad 0x63744935ffdb2566+ .quad 0xc5bd6b89780b68bb+ .quad 0x6f1b3280553eec03+ .quad 0x6e965fd847aed7f5+ .quad 0xada328bcf8fc73df+ .quad 0xee84695da6f037fc+ .quad 0x637fb4db38c2a909+ .quad 0x5b23ac2df8067bdc+ .quad 0x9ad2b953ee80527b+ .quad 0xe88f19aafade6d8d+ .quad 0x0e711704150e82cf+ .quad 0x79b9bbb9dd95dedc++ // 2^208 * 3 * G++ .quad 0xebb355406a3126c2+ .quad 0xd26383a868c8c393+ .quad 0x6c0c6429e5b97a82+ .quad 0x5065f158c9fd2147+ .quad 0xd1997dae8e9f7374+ .quad 0xa032a2f8cfbb0816+ .quad 0xcd6cba126d445f0a+ .quad 0x1ba811460accb834+ .quad 0x708169fb0c429954+ .quad 0xe14600acd76ecf67+ .quad 0x2eaab98a70e645ba+ .quad 0x3981f39e58a4faf2++ // 2^208 * 4 * G++ .quad 0x18fb8a7559230a93+ .quad 0x1d168f6960e6f45d+ .quad 0x3a85a94514a93cb5+ .quad 0x38dc083705acd0fd+ .quad 0xc845dfa56de66fde+ .quad 0xe152a5002c40483a+ .quad 0xe9d2e163c7b4f632+ .quad 0x30f4452edcbc1b65+ .quad 0x856d2782c5759740+ .quad 0xfa134569f99cbecc+ .quad 0x8844fc73c0ea4e71+ .quad 0x632d9a1a593f2469++ // 2^208 * 5 * G++ .quad 0xf6bb6b15b807cba6+ .quad 0x1823c7dfbc54f0d7+ .quad 0xbb1d97036e29670b+ .quad 0x0b24f48847ed4a57+ .quad 0xbf09fd11ed0c84a7+ .quad 0x63f071810d9f693a+ .quad 0x21908c2d57cf8779+ .quad 0x3a5a7df28af64ba2+ .quad 0xdcdad4be511beac7+ .quad 0xa4538075ed26ccf2+ .quad 0xe19cff9f005f9a65+ .quad 0x34fcf74475481f63++ // 2^208 * 6 * G++ .quad 0xc197e04c789767ca+ .quad 0xb8714dcb38d9467d+ .quad 0x55de888283f95fa8+ .quad 0x3d3bdc164dfa63f7+ .quad 0xa5bb1dab78cfaa98+ .quad 0x5ceda267190b72f2+ .quad 0x9309c9110a92608e+ .quad 0x0119a3042fb374b0+ .quad 0x67a2d89ce8c2177d+ .quad 0x669da5f66895d0c1+ .quad 0xf56598e5b282a2b0+ .quad 0x56c088f1ede20a73++ // 2^208 * 7 * G++ .quad 0x336d3d1110a86e17+ .quad 0xd7f388320b75b2fa+ .quad 0xf915337625072988+ .quad 0x09674c6b99108b87+ .quad 0x581b5fac24f38f02+ .quad 0xa90be9febae30cbd+ .quad 0x9a2169028acf92f0+ .quad 0x038b7ea48359038f+ .quad 0x9f4ef82199316ff8+ .quad 0x2f49d282eaa78d4f+ .quad 0x0971a5ab5aef3174+ .quad 0x6e5e31025969eb65++ // 2^208 * 8 * G++ .quad 0xb16c62f587e593fb+ .quad 0x4999eddeca5d3e71+ .quad 0xb491c1e014cc3e6d+ .quad 0x08f5114789a8dba8+ .quad 0x3304fb0e63066222+ .quad 0xfb35068987acba3f+ .quad 0xbd1924778c1061a3+ .quad 0x3058ad43d1838620+ .quad 0x323c0ffde57663d0+ .quad 0x05c3df38a22ea610+ .quad 0xbdc78abdac994f9a+ .quad 0x26549fa4efe3dc99++ // 2^212 * 1 * G++ .quad 0x738b38d787ce8f89+ .quad 0xb62658e24179a88d+ .quad 0x30738c9cf151316d+ .quad 0x49128c7f727275c9+ .quad 0x04dbbc17f75396b9+ .quad 0x69e6a2d7d2f86746+ .quad 0xc6409d99f53eabc6+ .quad 0x606175f6332e25d2+ .quad 0x4021370ef540e7dd+ .quad 0x0910d6f5a1f1d0a5+ .quad 0x4634aacd5b06b807+ .quad 0x6a39e6356944f235++ // 2^212 * 2 * G++ .quad 0x96cd5640df90f3e7+ .quad 0x6c3a760edbfa25ea+ .quad 0x24f3ef0959e33cc4+ .quad 0x42889e7e530d2e58+ .quad 0x1da1965774049e9d+ .quad 0xfbcd6ea198fe352b+ .quad 0xb1cbcd50cc5236a6+ .quad 0x1f5ec83d3f9846e2+ .quad 0x8efb23c3328ccb75+ .quad 0xaf42a207dd876ee9+ .quad 0x20fbdadc5dfae796+ .quad 0x241e246b06bf9f51++ // 2^212 * 3 * G++ .quad 0x29e68e57ad6e98f6+ .quad 0x4c9260c80b462065+ .quad 0x3f00862ea51ebb4b+ .quad 0x5bc2c77fb38d9097+ .quad 0x7eaafc9a6280bbb8+ .quad 0x22a70f12f403d809+ .quad 0x31ce40bb1bfc8d20+ .quad 0x2bc65635e8bd53ee+ .quad 0xe8d5dc9fa96bad93+ .quad 0xe58fb17dde1947dc+ .quad 0x681532ea65185fa3+ .quad 0x1fdd6c3b034a7830++ // 2^212 * 4 * G++ .quad 0x0a64e28c55dc18fe+ .quad 0xe3df9e993399ebdd+ .quad 0x79ac432370e2e652+ .quad 0x35ff7fc33ae4cc0e+ .quad 0x9c13a6a52dd8f7a9+ .quad 0x2dbb1f8c3efdcabf+ .quad 0x961e32405e08f7b5+ .quad 0x48c8a121bbe6c9e5+ .quad 0xfc415a7c59646445+ .quad 0xd224b2d7c128b615+ .quad 0x6035c9c905fbb912+ .quad 0x42d7a91274429fab++ // 2^212 * 5 * G++ .quad 0x4e6213e3eaf72ed3+ .quad 0x6794981a43acd4e7+ .quad 0xff547cde6eb508cb+ .quad 0x6fed19dd10fcb532+ .quad 0xa9a48947933da5bc+ .quad 0x4a58920ec2e979ec+ .quad 0x96d8800013e5ac4c+ .quad 0x453692d74b48b147+ .quad 0xdd775d99a8559c6f+ .quad 0xf42a2140df003e24+ .quad 0x5223e229da928a66+ .quad 0x063f46ba6d38f22c++ // 2^212 * 6 * G++ .quad 0xd2d242895f536694+ .quad 0xca33a2c542939b2c+ .quad 0x986fada6c7ddb95c+ .quad 0x5a152c042f712d5d+ .quad 0x39843cb737346921+ .quad 0xa747fb0738c89447+ .quad 0xcb8d8031a245307e+ .quad 0x67810f8e6d82f068+ .quad 0x3eeb8fbcd2287db4+ .quad 0x72c7d3a301a03e93+ .quad 0x5473e88cbd98265a+ .quad 0x7324aa515921b403++ // 2^212 * 7 * G++ .quad 0x857942f46c3cbe8e+ .quad 0xa1d364b14730c046+ .quad 0x1c8ed914d23c41bf+ .quad 0x0838e161eef6d5d2+ .quad 0xad23f6dae82354cb+ .quad 0x6962502ab6571a6d+ .quad 0x9b651636e38e37d1+ .quad 0x5cac5005d1a3312f+ .quad 0x8cc154cce9e39904+ .quad 0x5b3a040b84de6846+ .quad 0xc4d8a61cb1be5d6e+ .quad 0x40fb897bd8861f02++ // 2^212 * 8 * G++ .quad 0x84c5aa9062de37a1+ .quad 0x421da5000d1d96e1+ .quad 0x788286306a9242d9+ .quad 0x3c5e464a690d10da+ .quad 0xe57ed8475ab10761+ .quad 0x71435e206fd13746+ .quad 0x342f824ecd025632+ .quad 0x4b16281ea8791e7b+ .quad 0xd1c101d50b813381+ .quad 0xdee60f1176ee6828+ .quad 0x0cb68893383f6409+ .quad 0x6183c565f6ff484a++ // 2^216 * 1 * G++ .quad 0x741d5a461e6bf9d6+ .quad 0x2305b3fc7777a581+ .quad 0xd45574a26474d3d9+ .quad 0x1926e1dc6401e0ff+ .quad 0xdb468549af3f666e+ .quad 0xd77fcf04f14a0ea5+ .quad 0x3df23ff7a4ba0c47+ .quad 0x3a10dfe132ce3c85+ .quad 0xe07f4e8aea17cea0+ .quad 0x2fd515463a1fc1fd+ .quad 0x175322fd31f2c0f1+ .quad 0x1fa1d01d861e5d15++ // 2^216 * 2 * G++ .quad 0xcc8055947d599832+ .quad 0x1e4656da37f15520+ .quad 0x99f6f7744e059320+ .quad 0x773563bc6a75cf33+ .quad 0x38dcac00d1df94ab+ .quad 0x2e712bddd1080de9+ .quad 0x7f13e93efdd5e262+ .quad 0x73fced18ee9a01e5+ .quad 0x06b1e90863139cb3+ .quad 0xa493da67c5a03ecd+ .quad 0x8d77cec8ad638932+ .quad 0x1f426b701b864f44++ // 2^216 * 3 * G++ .quad 0xefc9264c41911c01+ .quad 0xf1a3b7b817a22c25+ .quad 0x5875da6bf30f1447+ .quad 0x4e1af5271d31b090+ .quad 0xf17e35c891a12552+ .quad 0xb76b8153575e9c76+ .quad 0xfa83406f0d9b723e+ .quad 0x0b76bb1b3fa7e438+ .quad 0x08b8c1f97f92939b+ .quad 0xbe6771cbd444ab6e+ .quad 0x22e5646399bb8017+ .quad 0x7b6dd61eb772a955++ // 2^216 * 4 * G++ .quad 0xb7adc1e850f33d92+ .quad 0x7998fa4f608cd5cf+ .quad 0xad962dbd8dfc5bdb+ .quad 0x703e9bceaf1d2f4f+ .quad 0x5730abf9ab01d2c7+ .quad 0x16fb76dc40143b18+ .quad 0x866cbe65a0cbb281+ .quad 0x53fa9b659bff6afe+ .quad 0x6c14c8e994885455+ .quad 0x843a5d6665aed4e5+ .quad 0x181bb73ebcd65af1+ .quad 0x398d93e5c4c61f50++ // 2^216 * 5 * G++ .quad 0x1c4bd16733e248f3+ .quad 0xbd9e128715bf0a5f+ .quad 0xd43f8cf0a10b0376+ .quad 0x53b09b5ddf191b13+ .quad 0xc3877c60d2e7e3f2+ .quad 0x3b34aaa030828bb1+ .quad 0x283e26e7739ef138+ .quad 0x699c9c9002c30577+ .quad 0xf306a7235946f1cc+ .quad 0x921718b5cce5d97d+ .quad 0x28cdd24781b4e975+ .quad 0x51caf30c6fcdd907++ // 2^216 * 6 * G++ .quad 0xa60ba7427674e00a+ .quad 0x630e8570a17a7bf3+ .quad 0x3758563dcf3324cc+ .quad 0x5504aa292383fdaa+ .quad 0x737af99a18ac54c7+ .quad 0x903378dcc51cb30f+ .quad 0x2b89bc334ce10cc7+ .quad 0x12ae29c189f8e99a+ .quad 0xa99ec0cb1f0d01cf+ .quad 0x0dd1efcc3a34f7ae+ .quad 0x55ca7521d09c4e22+ .quad 0x5fd14fe958eba5ea++ // 2^216 * 7 * G++ .quad 0xb5dc2ddf2845ab2c+ .quad 0x069491b10a7fe993+ .quad 0x4daaf3d64002e346+ .quad 0x093ff26e586474d1+ .quad 0x3c42fe5ebf93cb8e+ .quad 0xbedfa85136d4565f+ .quad 0xe0f0859e884220e8+ .quad 0x7dd73f960725d128+ .quad 0xb10d24fe68059829+ .quad 0x75730672dbaf23e5+ .quad 0x1367253ab457ac29+ .quad 0x2f59bcbc86b470a4++ // 2^216 * 8 * G++ .quad 0x83847d429917135f+ .quad 0xad1b911f567d03d7+ .quad 0x7e7748d9be77aad1+ .quad 0x5458b42e2e51af4a+ .quad 0x7041d560b691c301+ .quad 0x85201b3fadd7e71e+ .quad 0x16c2e16311335585+ .quad 0x2aa55e3d010828b1+ .quad 0xed5192e60c07444f+ .quad 0x42c54e2d74421d10+ .quad 0x352b4c82fdb5c864+ .quad 0x13e9004a8a768664++ // 2^220 * 1 * G++ .quad 0xcbb5b5556c032bff+ .quad 0xdf7191b729297a3a+ .quad 0xc1ff7326aded81bb+ .quad 0x71ade8bb68be03f5+ .quad 0x1e6284c5806b467c+ .quad 0xc5f6997be75d607b+ .quad 0x8b67d958b378d262+ .quad 0x3d88d66a81cd8b70+ .quad 0x8b767a93204ed789+ .quad 0x762fcacb9fa0ae2a+ .quad 0x771febcc6dce4887+ .quad 0x343062158ff05fb3++ // 2^220 * 2 * G++ .quad 0xe05da1a7e1f5bf49+ .quad 0x26457d6dd4736092+ .quad 0x77dcb07773cc32f6+ .quad 0x0a5d94969cdd5fcd+ .quad 0xfce219072a7b31b4+ .quad 0x4d7adc75aa578016+ .quad 0x0ec276a687479324+ .quad 0x6d6d9d5d1fda4beb+ .quad 0x22b1a58ae9b08183+ .quad 0xfd95d071c15c388b+ .quad 0xa9812376850a0517+ .quad 0x33384cbabb7f335e++ // 2^220 * 3 * G++ .quad 0x3c6fa2680ca2c7b5+ .quad 0x1b5082046fb64fda+ .quad 0xeb53349c5431d6de+ .quad 0x5278b38f6b879c89+ .quad 0x33bc627a26218b8d+ .quad 0xea80b21fc7a80c61+ .quad 0x9458b12b173e9ee6+ .quad 0x076247be0e2f3059+ .quad 0x52e105f61416375a+ .quad 0xec97af3685abeba4+ .quad 0x26e6b50623a67c36+ .quad 0x5cf0e856f3d4fb01++ // 2^220 * 4 * G++ .quad 0xf6c968731ae8cab4+ .quad 0x5e20741ecb4f92c5+ .quad 0x2da53be58ccdbc3e+ .quad 0x2dddfea269970df7+ .quad 0xbeaece313db342a8+ .quad 0xcba3635b842db7ee+ .quad 0xe88c6620817f13ef+ .quad 0x1b9438aa4e76d5c6+ .quad 0x8a50777e166f031a+ .quad 0x067b39f10fb7a328+ .quad 0x1925c9a6010fbd76+ .quad 0x6df9b575cc740905++ // 2^220 * 5 * G++ .quad 0x42c1192927f6bdcf+ .quad 0x8f91917a403d61ca+ .quad 0xdc1c5a668b9e1f61+ .quad 0x1596047804ec0f8d+ .quad 0xecdfc35b48cade41+ .quad 0x6a88471fb2328270+ .quad 0x740a4a2440a01b6a+ .quad 0x471e5796003b5f29+ .quad 0xda96bbb3aced37ac+ .quad 0x7a2423b5e9208cea+ .quad 0x24cc5c3038aebae2+ .quad 0x50c356afdc5dae2f++ // 2^220 * 6 * G++ .quad 0x09dcbf4341c30318+ .quad 0xeeba061183181dce+ .quad 0xc179c0cedc1e29a1+ .quad 0x1dbf7b89073f35b0+ .quad 0xcfed9cdf1b31b964+ .quad 0xf486a9858ca51af3+ .quad 0x14897265ea8c1f84+ .quad 0x784a53dd932acc00+ .quad 0x2d99f9df14fc4920+ .quad 0x76ccb60cc4499fe5+ .quad 0xa4132cbbe5cf0003+ .quad 0x3f93d82354f000ea++ // 2^220 * 7 * G++ .quad 0x8183e7689e04ce85+ .quad 0x678fb71e04465341+ .quad 0xad92058f6688edac+ .quad 0x5da350d3532b099a+ .quad 0xeaac12d179e14978+ .quad 0xff923ff3bbebff5e+ .quad 0x4af663e40663ce27+ .quad 0x0fd381a811a5f5ff+ .quad 0xf256aceca436df54+ .quad 0x108b6168ae69d6e8+ .quad 0x20d986cb6b5d036c+ .quad 0x655957b9fee2af50++ // 2^220 * 8 * G++ .quad 0xaea8b07fa902030f+ .quad 0xf88c766af463d143+ .quad 0x15b083663c787a60+ .quad 0x08eab1148267a4a8+ .quad 0xbdc1409bd002d0ac+ .quad 0x66660245b5ccd9a6+ .quad 0x82317dc4fade85ec+ .quad 0x02fe934b6ad7df0d+ .quad 0xef5cf100cfb7ea74+ .quad 0x22897633a1cb42ac+ .quad 0xd4ce0c54cef285e2+ .quad 0x30408c048a146a55++ // 2^224 * 1 * G++ .quad 0x739d8845832fcedb+ .quad 0xfa38d6c9ae6bf863+ .quad 0x32bc0dcab74ffef7+ .quad 0x73937e8814bce45e+ .quad 0xbb2e00c9193b877f+ .quad 0xece3a890e0dc506b+ .quad 0xecf3b7c036de649f+ .quad 0x5f46040898de9e1a+ .quad 0xb9037116297bf48d+ .quad 0xa9d13b22d4f06834+ .quad 0xe19715574696bdc6+ .quad 0x2cf8a4e891d5e835++ // 2^224 * 2 * G++ .quad 0x6d93fd8707110f67+ .quad 0xdd4c09d37c38b549+ .quad 0x7cb16a4cc2736a86+ .quad 0x2049bd6e58252a09+ .quad 0x2cb5487e17d06ba2+ .quad 0x24d2381c3950196b+ .quad 0xd7659c8185978a30+ .quad 0x7a6f7f2891d6a4f6+ .quad 0x7d09fd8d6a9aef49+ .quad 0xf0ee60be5b3db90b+ .quad 0x4c21b52c519ebfd4+ .quad 0x6011aadfc545941d++ // 2^224 * 3 * G++ .quad 0x5f67926dcf95f83c+ .quad 0x7c7e856171289071+ .quad 0xd6a1e7f3998f7a5b+ .quad 0x6fc5cc1b0b62f9e0+ .quad 0x63ded0c802cbf890+ .quad 0xfbd098ca0dff6aaa+ .quad 0x624d0afdb9b6ed99+ .quad 0x69ce18b779340b1e+ .quad 0xd1ef5528b29879cb+ .quad 0xdd1aae3cd47e9092+ .quad 0x127e0442189f2352+ .quad 0x15596b3ae57101f1++ // 2^224 * 4 * G++ .quad 0x462739d23f9179a2+ .quad 0xff83123197d6ddcf+ .quad 0x1307deb553f2148a+ .quad 0x0d2237687b5f4dda+ .quad 0x09ff31167e5124ca+ .quad 0x0be4158bd9c745df+ .quad 0x292b7d227ef556e5+ .quad 0x3aa4e241afb6d138+ .quad 0x2cc138bf2a3305f5+ .quad 0x48583f8fa2e926c3+ .quad 0x083ab1a25549d2eb+ .quad 0x32fcaa6e4687a36c++ // 2^224 * 5 * G++ .quad 0x7bc56e8dc57d9af5+ .quad 0x3e0bd2ed9df0bdf2+ .quad 0xaac014de22efe4a3+ .quad 0x4627e9cefebd6a5c+ .quad 0x3207a4732787ccdf+ .quad 0x17e31908f213e3f8+ .quad 0xd5b2ecd7f60d964e+ .quad 0x746f6336c2600be9+ .quad 0x3f4af345ab6c971c+ .quad 0xe288eb729943731f+ .quad 0x33596a8a0344186d+ .quad 0x7b4917007ed66293++ // 2^224 * 6 * G++ .quad 0x2d85fb5cab84b064+ .quad 0x497810d289f3bc14+ .quad 0x476adc447b15ce0c+ .quad 0x122ba376f844fd7b+ .quad 0x54341b28dd53a2dd+ .quad 0xaa17905bdf42fc3f+ .quad 0x0ff592d94dd2f8f4+ .quad 0x1d03620fe08cd37d+ .quad 0xc20232cda2b4e554+ .quad 0x9ed0fd42115d187f+ .quad 0x2eabb4be7dd479d9+ .quad 0x02c70bf52b68ec4c++ // 2^224 * 7 * G++ .quad 0xa287ec4b5d0b2fbb+ .quad 0x415c5790074882ca+ .quad 0xe044a61ec1d0815c+ .quad 0x26334f0a409ef5e0+ .quad 0xace532bf458d72e1+ .quad 0x5be768e07cb73cb5+ .quad 0x56cf7d94ee8bbde7+ .quad 0x6b0697e3feb43a03+ .quad 0xb6c8f04adf62a3c0+ .quad 0x3ef000ef076da45d+ .quad 0x9c9cb95849f0d2a9+ .quad 0x1cc37f43441b2fae++ // 2^224 * 8 * G++ .quad 0x508f565a5cc7324f+ .quad 0xd061c4c0e506a922+ .quad 0xfb18abdb5c45ac19+ .quad 0x6c6809c10380314a+ .quad 0xd76656f1c9ceaeb9+ .quad 0x1c5b15f818e5656a+ .quad 0x26e72832844c2334+ .quad 0x3a346f772f196838+ .quad 0xd2d55112e2da6ac8+ .quad 0xe9bd0331b1e851ed+ .quad 0x960746dd8ec67262+ .quad 0x05911b9f6ef7c5d0++ // 2^228 * 1 * G++ .quad 0xe9dcd756b637ff2d+ .quad 0xec4c348fc987f0c4+ .quad 0xced59285f3fbc7b7+ .quad 0x3305354793e1ea87+ .quad 0x01c18980c5fe9f94+ .quad 0xcd656769716fd5c8+ .quad 0x816045c3d195a086+ .quad 0x6e2b7f3266cc7982+ .quad 0xcc802468f7c3568f+ .quad 0x9de9ba8219974cb3+ .quad 0xabb7229cb5b81360+ .quad 0x44e2017a6fbeba62++ // 2^228 * 2 * G++ .quad 0xc4c2a74354dab774+ .quad 0x8e5d4c3c4eaf031a+ .quad 0xb76c23d242838f17+ .quad 0x749a098f68dce4ea+ .quad 0x87f82cf3b6ca6ecd+ .quad 0x580f893e18f4a0c2+ .quad 0x058930072604e557+ .quad 0x6cab6ac256d19c1d+ .quad 0xdcdfe0a02cc1de60+ .quad 0x032665ff51c5575b+ .quad 0x2c0c32f1073abeeb+ .quad 0x6a882014cd7b8606++ // 2^228 * 3 * G++ .quad 0xa52a92fea4747fb5+ .quad 0xdc12a4491fa5ab89+ .quad 0xd82da94bb847a4ce+ .quad 0x4d77edce9512cc4e+ .quad 0xd111d17caf4feb6e+ .quad 0x050bba42b33aa4a3+ .quad 0x17514c3ceeb46c30+ .quad 0x54bedb8b1bc27d75+ .quad 0x77c8e14577e2189c+ .quad 0xa3e46f6aff99c445+ .quad 0x3144dfc86d335343+ .quad 0x3a96559e7c4216a9++ // 2^228 * 4 * G++ .quad 0x12550d37f42ad2ee+ .quad 0x8b78e00498a1fbf5+ .quad 0x5d53078233894cb2+ .quad 0x02c84e4e3e498d0c+ .quad 0x4493896880baaa52+ .quad 0x4c98afc4f285940e+ .quad 0xef4aa79ba45448b6+ .quad 0x5278c510a57aae7f+ .quad 0xa54dd074294c0b94+ .quad 0xf55d46b8df18ffb6+ .quad 0xf06fecc58dae8366+ .quad 0x588657668190d165++ // 2^228 * 5 * G++ .quad 0xd47712311aef7117+ .quad 0x50343101229e92c7+ .quad 0x7a95e1849d159b97+ .quad 0x2449959b8b5d29c9+ .quad 0xbf5834f03de25cc3+ .quad 0xb887c8aed6815496+ .quad 0x5105221a9481e892+ .quad 0x6760ed19f7723f93+ .quad 0x669ba3b7ac35e160+ .quad 0x2eccf73fba842056+ .quad 0x1aec1f17c0804f07+ .quad 0x0d96bc031856f4e7++ // 2^228 * 6 * G++ .quad 0x3318be7775c52d82+ .quad 0x4cb764b554d0aab9+ .quad 0xabcf3d27cc773d91+ .quad 0x3bf4d1848123288a+ .quad 0xb1d534b0cc7505e1+ .quad 0x32cd003416c35288+ .quad 0xcb36a5800762c29d+ .quad 0x5bfe69b9237a0bf8+ .quad 0x183eab7e78a151ab+ .quad 0xbbe990c999093763+ .quad 0xff717d6e4ac7e335+ .quad 0x4c5cddb325f39f88++ // 2^228 * 7 * G++ .quad 0xc0f6b74d6190a6eb+ .quad 0x20ea81a42db8f4e4+ .quad 0xa8bd6f7d97315760+ .quad 0x33b1d60262ac7c21+ .quad 0x57750967e7a9f902+ .quad 0x2c37fdfc4f5b467e+ .quad 0xb261663a3177ba46+ .quad 0x3a375e78dc2d532b+ .quad 0x8141e72f2d4dddea+ .quad 0xe6eafe9862c607c8+ .quad 0x23c28458573cafd0+ .quad 0x46b9476f4ff97346++ // 2^228 * 8 * G++ .quad 0x0c1ffea44f901e5c+ .quad 0x2b0b6fb72184b782+ .quad 0xe587ff910114db88+ .quad 0x37130f364785a142+ .quad 0x1215505c0d58359f+ .quad 0x2a2013c7fc28c46b+ .quad 0x24a0a1af89ea664e+ .quad 0x4400b638a1130e1f+ .quad 0x3a01b76496ed19c3+ .quad 0x31e00ab0ed327230+ .quad 0x520a885783ca15b1+ .quad 0x06aab9875accbec7++ // 2^232 * 1 * G++ .quad 0xc1339983f5df0ebb+ .quad 0xc0f3758f512c4cac+ .quad 0x2cf1130a0bb398e1+ .quad 0x6b3cecf9aa270c62+ .quad 0x5349acf3512eeaef+ .quad 0x20c141d31cc1cb49+ .quad 0x24180c07a99a688d+ .quad 0x555ef9d1c64b2d17+ .quad 0x36a770ba3b73bd08+ .quad 0x624aef08a3afbf0c+ .quad 0x5737ff98b40946f2+ .quad 0x675f4de13381749d++ // 2^232 * 2 * G++ .quad 0x0e2c52036b1782fc+ .quad 0x64816c816cad83b4+ .quad 0xd0dcbdd96964073e+ .quad 0x13d99df70164c520+ .quad 0xa12ff6d93bdab31d+ .quad 0x0725d80f9d652dfe+ .quad 0x019c4ff39abe9487+ .quad 0x60f450b882cd3c43+ .quad 0x014b5ec321e5c0ca+ .quad 0x4fcb69c9d719bfa2+ .quad 0x4e5f1c18750023a0+ .quad 0x1c06de9e55edac80++ // 2^232 * 3 * G++ .quad 0x990f7ad6a33ec4e2+ .quad 0x6608f938be2ee08e+ .quad 0x9ca143c563284515+ .quad 0x4cf38a1fec2db60d+ .quad 0xffd52b40ff6d69aa+ .quad 0x34530b18dc4049bb+ .quad 0x5e4a5c2fa34d9897+ .quad 0x78096f8e7d32ba2d+ .quad 0xa0aaaa650dfa5ce7+ .quad 0xf9c49e2a48b5478c+ .quad 0x4f09cc7d7003725b+ .quad 0x373cad3a26091abe++ // 2^232 * 4 * G++ .quad 0xb294634d82c9f57c+ .quad 0x1fcbfde124934536+ .quad 0x9e9c4db3418cdb5a+ .quad 0x0040f3d9454419fc+ .quad 0xf1bea8fb89ddbbad+ .quad 0x3bcb2cbc61aeaecb+ .quad 0x8f58a7bb1f9b8d9d+ .quad 0x21547eda5112a686+ .quad 0xdefde939fd5986d3+ .quad 0xf4272c89510a380c+ .quad 0xb72ba407bb3119b9+ .quad 0x63550a334a254df4++ // 2^232 * 5 * G++ .quad 0x6507d6edb569cf37+ .quad 0x178429b00ca52ee1+ .quad 0xea7c0090eb6bd65d+ .quad 0x3eea62c7daf78f51+ .quad 0x9bba584572547b49+ .quad 0xf305c6fae2c408e0+ .quad 0x60e8fa69c734f18d+ .quad 0x39a92bafaa7d767a+ .quad 0x9d24c713e693274e+ .quad 0x5f63857768dbd375+ .quad 0x70525560eb8ab39a+ .quad 0x68436a0665c9c4cd++ // 2^232 * 6 * G++ .quad 0xbc0235e8202f3f27+ .quad 0xc75c00e264f975b0+ .quad 0x91a4e9d5a38c2416+ .quad 0x17b6e7f68ab789f9+ .quad 0x1e56d317e820107c+ .quad 0xc5266844840ae965+ .quad 0xc1e0a1c6320ffc7a+ .quad 0x5373669c91611472+ .quad 0x5d2814ab9a0e5257+ .quad 0x908f2084c9cab3fc+ .quad 0xafcaf5885b2d1eca+ .quad 0x1cb4b5a678f87d11++ // 2^232 * 7 * G++ .quad 0xb664c06b394afc6c+ .quad 0x0c88de2498da5fb1+ .quad 0x4f8d03164bcad834+ .quad 0x330bca78de7434a2+ .quad 0x6b74aa62a2a007e7+ .quad 0xf311e0b0f071c7b1+ .quad 0x5707e438000be223+ .quad 0x2dc0fd2d82ef6eac+ .quad 0x982eff841119744e+ .quad 0xf9695e962b074724+ .quad 0xc58ac14fbfc953fb+ .quad 0x3c31be1b369f1cf5++ // 2^232 * 8 * G++ .quad 0xb0f4864d08948aee+ .quad 0x07dc19ee91ba1c6f+ .quad 0x7975cdaea6aca158+ .quad 0x330b61134262d4bb+ .quad 0xc168bc93f9cb4272+ .quad 0xaeb8711fc7cedb98+ .quad 0x7f0e52aa34ac8d7a+ .quad 0x41cec1097e7d55bb+ .quad 0xf79619d7a26d808a+ .quad 0xbb1fd49e1d9e156d+ .quad 0x73d7c36cdba1df27+ .quad 0x26b44cd91f28777d++ // 2^236 * 1 * G++ .quad 0x300a9035393aa6d8+ .quad 0x2b501131a12bb1cd+ .quad 0x7b1ff677f093c222+ .quad 0x4309c1f8cab82bad+ .quad 0xaf44842db0285f37+ .quad 0x8753189047efc8df+ .quad 0x9574e091f820979a+ .quad 0x0e378d6069615579+ .quad 0xd9fa917183075a55+ .quad 0x4bdb5ad26b009fdc+ .quad 0x7829ad2cd63def0e+ .quad 0x078fc54975fd3877++ // 2^236 * 2 * G++ .quad 0x87dfbd1428878f2d+ .quad 0x134636dd1e9421a1+ .quad 0x4f17c951257341a3+ .quad 0x5df98d4bad296cb8+ .quad 0xe2004b5bb833a98a+ .quad 0x44775dec2d4c3330+ .quad 0x3aa244067eace913+ .quad 0x272630e3d58e00a9+ .quad 0xf3678fd0ecc90b54+ .quad 0xf001459b12043599+ .quad 0x26725fbc3758b89b+ .quad 0x4325e4aa73a719ae++ // 2^236 * 3 * G++ .quad 0x657dc6ef433c3493+ .quad 0x65375e9f80dbf8c3+ .quad 0x47fd2d465b372dae+ .quad 0x4966ab79796e7947+ .quad 0xed24629acf69f59d+ .quad 0x2a4a1ccedd5abbf4+ .quad 0x3535ca1f56b2d67b+ .quad 0x5d8c68d043b1b42d+ .quad 0xee332d4de3b42b0a+ .quad 0xd84e5a2b16a4601c+ .quad 0x78243877078ba3e4+ .quad 0x77ed1eb4184ee437++ // 2^236 * 4 * G++ .quad 0xbfd4e13f201839a0+ .quad 0xaeefffe23e3df161+ .quad 0xb65b04f06b5d1fe3+ .quad 0x52e085fb2b62fbc0+ .quad 0x185d43f89e92ed1a+ .quad 0xb04a1eeafe4719c6+ .quad 0x499fbe88a6f03f4f+ .quad 0x5d8b0d2f3c859bdd+ .quad 0x124079eaa54cf2ba+ .quad 0xd72465eb001b26e7+ .quad 0x6843bcfdc97af7fd+ .quad 0x0524b42b55eacd02++ // 2^236 * 5 * G++ .quad 0xfd0d5dbee45447b0+ .quad 0x6cec351a092005ee+ .quad 0x99a47844567579cb+ .quad 0x59d242a216e7fa45+ .quad 0xbc18dcad9b829eac+ .quad 0x23ae7d28b5f579d0+ .quad 0xc346122a69384233+ .quad 0x1a6110b2e7d4ac89+ .quad 0x4f833f6ae66997ac+ .quad 0x6849762a361839a4+ .quad 0x6985dec1970ab525+ .quad 0x53045e89dcb1f546++ // 2^236 * 6 * G++ .quad 0xcb8bb346d75353db+ .quad 0xfcfcb24bae511e22+ .quad 0xcba48d40d50ae6ef+ .quad 0x26e3bae5f4f7cb5d+ .quad 0x84da3cde8d45fe12+ .quad 0xbd42c218e444e2d2+ .quad 0xa85196781f7e3598+ .quad 0x7642c93f5616e2b2+ .quad 0x2323daa74595f8e4+ .quad 0xde688c8b857abeb4+ .quad 0x3fc48e961c59326e+ .quad 0x0b2e73ca15c9b8ba++ // 2^236 * 7 * G++ .quad 0xd6bb4428c17f5026+ .quad 0x9eb27223fb5a9ca7+ .quad 0xe37ba5031919c644+ .quad 0x21ce380db59a6602+ .quad 0x0e3fbfaf79c03a55+ .quad 0x3077af054cbb5acf+ .quad 0xd5c55245db3de39f+ .quad 0x015e68c1476a4af7+ .quad 0xc1d5285220066a38+ .quad 0x95603e523570aef3+ .quad 0x832659a7226b8a4d+ .quad 0x5dd689091f8eedc9++ // 2^236 * 8 * G++ .quad 0xcbac84debfd3c856+ .quad 0x1624c348b35ff244+ .quad 0xb7f88dca5d9cad07+ .quad 0x3b0e574da2c2ebe8+ .quad 0x1d022591a5313084+ .quad 0xca2d4aaed6270872+ .quad 0x86a12b852f0bfd20+ .quad 0x56e6c439ad7da748+ .quad 0xc704ff4942bdbae6+ .quad 0x5e21ade2b2de1f79+ .quad 0xe95db3f35652fad8+ .quad 0x0822b5378f08ebc1++ // 2^240 * 1 * G++ .quad 0x51f048478f387475+ .quad 0xb25dbcf49cbecb3c+ .quad 0x9aab1244d99f2055+ .quad 0x2c709e6c1c10a5d6+ .quad 0xe1b7f29362730383+ .quad 0x4b5279ffebca8a2c+ .quad 0xdafc778abfd41314+ .quad 0x7deb10149c72610f+ .quad 0xcb62af6a8766ee7a+ .quad 0x66cbec045553cd0e+ .quad 0x588001380f0be4b5+ .quad 0x08e68e9ff62ce2ea++ // 2^240 * 2 * G++ .quad 0x34ad500a4bc130ad+ .quad 0x8d38db493d0bd49c+ .quad 0xa25c3d98500a89be+ .quad 0x2f1f3f87eeba3b09+ .quad 0x2f2d09d50ab8f2f9+ .quad 0xacb9218dc55923df+ .quad 0x4a8f342673766cb9+ .quad 0x4cb13bd738f719f5+ .quad 0xf7848c75e515b64a+ .quad 0xa59501badb4a9038+ .quad 0xc20d313f3f751b50+ .quad 0x19a1e353c0ae2ee8++ // 2^240 * 3 * G++ .quad 0x7d1c7560bafa05c3+ .quad 0xb3e1a0a0c6e55e61+ .quad 0xe3529718c0d66473+ .quad 0x41546b11c20c3486+ .quad 0xb42172cdd596bdbd+ .quad 0x93e0454398eefc40+ .quad 0x9fb15347b44109b5+ .quad 0x736bd3990266ae34+ .quad 0x85532d509334b3b4+ .quad 0x46fd114b60816573+ .quad 0xcc5f5f30425c8375+ .quad 0x412295a2b87fab5c++ // 2^240 * 4 * G++ .quad 0x19c99b88f57ed6e9+ .quad 0x5393cb266df8c825+ .quad 0x5cee3213b30ad273+ .quad 0x14e153ebb52d2e34+ .quad 0x2e655261e293eac6+ .quad 0x845a92032133acdb+ .quad 0x460975cb7900996b+ .quad 0x0760bb8d195add80+ .quad 0x413e1a17cde6818a+ .quad 0x57156da9ed69a084+ .quad 0x2cbf268f46caccb1+ .quad 0x6b34be9bc33ac5f2++ // 2^240 * 5 * G++ .quad 0xf3df2f643a78c0b2+ .quad 0x4c3e971ef22e027c+ .quad 0xec7d1c5e49c1b5a3+ .quad 0x2012c18f0922dd2d+ .quad 0x11fc69656571f2d3+ .quad 0xc6c9e845530e737a+ .quad 0xe33ae7a2d4fe5035+ .quad 0x01b9c7b62e6dd30b+ .quad 0x880b55e55ac89d29+ .quad 0x1483241f45a0a763+ .quad 0x3d36efdfc2e76c1f+ .quad 0x08af5b784e4bade8++ // 2^240 * 6 * G++ .quad 0x283499dc881f2533+ .quad 0x9d0525da779323b6+ .quad 0x897addfb673441f4+ .quad 0x32b79d71163a168d+ .quad 0xe27314d289cc2c4b+ .quad 0x4be4bd11a287178d+ .quad 0x18d528d6fa3364ce+ .quad 0x6423c1d5afd9826e+ .quad 0xcc85f8d9edfcb36a+ .quad 0x22bcc28f3746e5f9+ .quad 0xe49de338f9e5d3cd+ .quad 0x480a5efbc13e2dcc++ // 2^240 * 7 * G++ .quad 0x0b51e70b01622071+ .quad 0x06b505cf8b1dafc5+ .quad 0x2c6bb061ef5aabcd+ .quad 0x47aa27600cb7bf31+ .quad 0xb6614ce442ce221f+ .quad 0x6e199dcc4c053928+ .quad 0x663fb4a4dc1cbe03+ .quad 0x24b31d47691c8e06+ .quad 0x2a541eedc015f8c3+ .quad 0x11a4fe7e7c693f7c+ .quad 0xf0af66134ea278d6+ .quad 0x545b585d14dda094++ // 2^240 * 8 * G++ .quad 0x67bf275ea0d43a0f+ .quad 0xade68e34089beebe+ .quad 0x4289134cd479e72e+ .quad 0x0f62f9c332ba5454+ .quad 0x6204e4d0e3b321e1+ .quad 0x3baa637a28ff1e95+ .quad 0x0b0ccffd5b99bd9e+ .quad 0x4d22dc3e64c8d071+ .quad 0xfcb46589d63b5f39+ .quad 0x5cae6a3f57cbcf61+ .quad 0xfebac2d2953afa05+ .quad 0x1c0fa01a36371436++ // 2^244 * 1 * G++ .quad 0xe7547449bc7cd692+ .quad 0x0f9abeaae6f73ddf+ .quad 0x4af01ca700837e29+ .quad 0x63ab1b5d3f1bc183+ .quad 0xc11ee5e854c53fae+ .quad 0x6a0b06c12b4f3ff4+ .quad 0x33540f80e0b67a72+ .quad 0x15f18fc3cd07e3ef+ .quad 0x32750763b028f48c+ .quad 0x06020740556a065f+ .quad 0xd53bd812c3495b58+ .quad 0x08706c9b865f508d++ // 2^244 * 2 * G++ .quad 0xf37ca2ab3d343dff+ .quad 0x1a8c6a2d80abc617+ .quad 0x8e49e035d4ccffca+ .quad 0x48b46beebaa1d1b9+ .quad 0xcc991b4138b41246+ .quad 0x243b9c526f9ac26b+ .quad 0xb9ef494db7cbabbd+ .quad 0x5fba433dd082ed00+ .quad 0x9c49e355c9941ad0+ .quad 0xb9734ade74498f84+ .quad 0x41c3fed066663e5c+ .quad 0x0ecfedf8e8e710b3++ // 2^244 * 3 * G++ .quad 0x76430f9f9cd470d9+ .quad 0xb62acc9ba42f6008+ .quad 0x1898297c59adad5e+ .quad 0x7789dd2db78c5080+ .quad 0x744f7463e9403762+ .quad 0xf79a8dee8dfcc9c9+ .quad 0x163a649655e4cde3+ .quad 0x3b61788db284f435+ .quad 0xb22228190d6ef6b2+ .quad 0xa94a66b246ce4bfa+ .quad 0x46c1a77a4f0b6cc7+ .quad 0x4236ccffeb7338cf++ // 2^244 * 4 * G++ .quad 0x8497404d0d55e274+ .quad 0x6c6663d9c4ad2b53+ .quad 0xec2fb0d9ada95734+ .quad 0x2617e120cdb8f73c+ .quad 0x3bd82dbfda777df6+ .quad 0x71b177cc0b98369e+ .quad 0x1d0e8463850c3699+ .quad 0x5a71945b48e2d1f1+ .quad 0x6f203dd5405b4b42+ .quad 0x327ec60410b24509+ .quad 0x9c347230ac2a8846+ .quad 0x77de29fc11ffeb6a++ // 2^244 * 5 * G++ .quad 0xb0ac57c983b778a8+ .quad 0x53cdcca9d7fe912c+ .quad 0x61c2b854ff1f59dc+ .quad 0x3a1a2cf0f0de7dac+ .quad 0x835e138fecced2ca+ .quad 0x8c9eaf13ea963b9a+ .quad 0xc95fbfc0b2160ea6+ .quad 0x575e66f3ad877892+ .quad 0x99803a27c88fcb3a+ .quad 0x345a6789275ec0b0+ .quad 0x459789d0ff6c2be5+ .quad 0x62f882651e70a8b2++ // 2^244 * 6 * G++ .quad 0x085ae2c759ff1be4+ .quad 0x149145c93b0e40b7+ .quad 0xc467e7fa7ff27379+ .quad 0x4eeecf0ad5c73a95+ .quad 0x6d822986698a19e0+ .quad 0xdc9821e174d78a71+ .quad 0x41a85f31f6cb1f47+ .quad 0x352721c2bcda9c51+ .quad 0x48329952213fc985+ .quad 0x1087cf0d368a1746+ .quad 0x8e5261b166c15aa5+ .quad 0x2d5b2d842ed24c21++ // 2^244 * 7 * G++ .quad 0x02cfebd9ebd3ded1+ .quad 0xd45b217739021974+ .quad 0x7576f813fe30a1b7+ .quad 0x5691b6f9a34ef6c2+ .quad 0x5eb7d13d196ac533+ .quad 0x377234ecdb80be2b+ .quad 0xe144cffc7cf5ae24+ .quad 0x5226bcf9c441acec+ .quad 0x79ee6c7223e5b547+ .quad 0x6f5f50768330d679+ .quad 0xed73e1e96d8adce9+ .quad 0x27c3da1e1d8ccc03++ // 2^244 * 8 * G++ .quad 0x7eb9efb23fe24c74+ .quad 0x3e50f49f1651be01+ .quad 0x3ea732dc21858dea+ .quad 0x17377bd75bb810f9+ .quad 0x28302e71630ef9f6+ .quad 0xc2d4a2032b64cee0+ .quad 0x090820304b6292be+ .quad 0x5fca747aa82adf18+ .quad 0x232a03c35c258ea5+ .quad 0x86f23a2c6bcb0cf1+ .quad 0x3dad8d0d2e442166+ .quad 0x04a8933cab76862b++ // 2^248 * 1 * G++ .quad 0xd2c604b622943dff+ .quad 0xbc8cbece44cfb3a0+ .quad 0x5d254ff397808678+ .quad 0x0fa3614f3b1ca6bf+ .quad 0x69082b0e8c936a50+ .quad 0xf9c9a035c1dac5b6+ .quad 0x6fb73e54c4dfb634+ .quad 0x4005419b1d2bc140+ .quad 0xa003febdb9be82f0+ .quad 0x2089c1af3a44ac90+ .quad 0xf8499f911954fa8e+ .quad 0x1fba218aef40ab42++ // 2^248 * 2 * G++ .quad 0xab549448fac8f53e+ .quad 0x81f6e89a7ba63741+ .quad 0x74fd6c7d6c2b5e01+ .quad 0x392e3acaa8c86e42+ .quad 0x4f3e57043e7b0194+ .quad 0xa81d3eee08daaf7f+ .quad 0xc839c6ab99dcdef1+ .quad 0x6c535d13ff7761d5+ .quad 0x4cbd34e93e8a35af+ .quad 0x2e0781445887e816+ .quad 0x19319c76f29ab0ab+ .quad 0x25e17fe4d50ac13b++ // 2^248 * 3 * G++ .quad 0x0a289bd71e04f676+ .quad 0x208e1c52d6420f95+ .quad 0x5186d8b034691fab+ .quad 0x255751442a9fb351+ .quad 0x915f7ff576f121a7+ .quad 0xc34a32272fcd87e3+ .quad 0xccba2fde4d1be526+ .quad 0x6bba828f8969899b+ .quad 0xe2d1bc6690fe3901+ .quad 0x4cb54a18a0997ad5+ .quad 0x971d6914af8460d4+ .quad 0x559d504f7f6b7be4++ // 2^248 * 4 * G++ .quad 0xa7738378b3eb54d5+ .quad 0x1d69d366a5553c7c+ .quad 0x0a26cf62f92800ba+ .quad 0x01ab12d5807e3217+ .quad 0x9c4891e7f6d266fd+ .quad 0x0744a19b0307781b+ .quad 0x88388f1d6061e23b+ .quad 0x123ea6a3354bd50e+ .quad 0x118d189041e32d96+ .quad 0xb9ede3c2d8315848+ .quad 0x1eab4271d83245d9+ .quad 0x4a3961e2c918a154++ // 2^248 * 5 * G++ .quad 0x71dc3be0f8e6bba0+ .quad 0xd6cef8347effe30a+ .quad 0xa992425fe13a476a+ .quad 0x2cd6bce3fb1db763+ .quad 0x0327d644f3233f1e+ .quad 0x499a260e34fcf016+ .quad 0x83b5a716f2dab979+ .quad 0x68aceead9bd4111f+ .quad 0x38b4c90ef3d7c210+ .quad 0x308e6e24b7ad040c+ .quad 0x3860d9f1b7e73e23+ .quad 0x595760d5b508f597++ // 2^248 * 6 * G++ .quad 0x6129bfe104aa6397+ .quad 0x8f960008a4a7fccb+ .quad 0x3f8bc0897d909458+ .quad 0x709fa43edcb291a9+ .quad 0x882acbebfd022790+ .quad 0x89af3305c4115760+ .quad 0x65f492e37d3473f4+ .quad 0x2cb2c5df54515a2b+ .quad 0xeb0a5d8c63fd2aca+ .quad 0xd22bc1662e694eff+ .quad 0x2723f36ef8cbb03a+ .quad 0x70f029ecf0c8131f++ // 2^248 * 7 * G++ .quad 0x461307b32eed3e33+ .quad 0xae042f33a45581e7+ .quad 0xc94449d3195f0366+ .quad 0x0b7d5d8a6c314858+ .quad 0x2a6aafaa5e10b0b9+ .quad 0x78f0a370ef041aa9+ .quad 0x773efb77aa3ad61f+ .quad 0x44eca5a2a74bd9e1+ .quad 0x25d448327b95d543+ .quad 0x70d38300a3340f1d+ .quad 0xde1c531c60e1c52b+ .quad 0x272224512c7de9e4++ // 2^248 * 8 * G++ .quad 0x1abc92af49c5342e+ .quad 0xffeed811b2e6fad0+ .quad 0xefa28c8dfcc84e29+ .quad 0x11b5df18a44cc543+ .quad 0xbf7bbb8a42a975fc+ .quad 0x8c5c397796ada358+ .quad 0xe27fc76fcdedaa48+ .quad 0x19735fd7f6bc20a6+ .quad 0xe3ab90d042c84266+ .quad 0xeb848e0f7f19547e+ .quad 0x2503a1d065a497b9+ .quad 0x0fef911191df895f
+ cbits/s2n/x86_att/p256_montjadd.S view
@@ -0,0 +1,593 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjadd(uint64_t p3[static 12], const uint64_t p1[static 12],+// const uint64_t p2[static 12]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard x86-64 ABI: RDI = p3, RSI = p1, RDX = p2+// Microsoft x64 ABI: RCX = p3, RDX = p1, R8 = p2+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjadd)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjadd)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjadd)+ .text++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for inputs and outputs+// These assume %rdi = p3, %rsi = p1 and %rbp = p2,+// which needs to be set up explicitly before use.+// The first two hold initially, and the second is+// set up by copying the initial %rdx input to %rbp.+// Thereafter, no code macro modifies any of them.++#define x_1 0(%rsi)+#define y_1 NUMSIZE(%rsi)+#define z_1 (2*NUMSIZE)(%rsi)++#define x_2 0(%rbp)+#define y_2 NUMSIZE(%rbp)+#define z_2 (2*NUMSIZE)(%rbp)++#define x_3 0(%rdi)+#define y_3 NUMSIZE(%rdi)+#define z_3 (2*NUMSIZE)(%rdi)++// Pointer-offset pairs for temporaries, with some aliasing+// NSPACE is the total stack needed for these temporaries++#define z1sq (NUMSIZE*0)(%rsp)+#define ww (NUMSIZE*0)(%rsp)+#define resx (NUMSIZE*0)(%rsp)++#define yd (NUMSIZE*1)(%rsp)+#define y2a (NUMSIZE*1)(%rsp)++#define x2a (NUMSIZE*2)(%rsp)+#define zzx2 (NUMSIZE*2)(%rsp)++#define zz (NUMSIZE*3)(%rsp)+#define t1 (NUMSIZE*3)(%rsp)++#define t2 (NUMSIZE*4)(%rsp)+#define x1a (NUMSIZE*4)(%rsp)+#define zzx1 (NUMSIZE*4)(%rsp)+#define resy (NUMSIZE*4)(%rsp)++#define xd (NUMSIZE*5)(%rsp)+#define z2sq (NUMSIZE*5)(%rsp)+#define resz (NUMSIZE*5)(%rsp)++#define y1a (NUMSIZE*6)(%rsp)++#define NSPACE NUMSIZE*7++// Corresponds exactly to bignum_montmul_p256++#define montmul_p256(P0,P1,P2) \+ xorl %r13d, %r13d ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rbx, %r10 ; \+ adcq %rbx, %r9 ; \+ mulxq 0x10+P1, %rbx, %r11 ; \+ adcq %rbx, %r10 ; \+ mulxq 0x18+P1, %rbx, %r12 ; \+ adcq %rbx, %r11 ; \+ adcq %r13, %r12 ; \+ movq 0x8+P2, %rdx ; \+ xorl %r14d, %r14d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcq %r14, %r13 ; \+ xorl %r15d, %r15d ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ notq %rdx; \+ leaq 0x2(%rdx), %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %r15, %r13 ; \+ adoxq %r15, %r14 ; \+ adcq %r15, %r14 ; \+ movq 0x10+P2, %rdx ; \+ xorl %r8d, %r8d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adoxq %r8, %r14 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcq %rax, %r13 ; \+ adcq %rbx, %r14 ; \+ adcq %r8, %r15 ; \+ movq 0x18+P2, %rdx ; \+ xorl %r9d, %r9d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ adoxq %r9, %r15 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcq %rax, %r14 ; \+ adcq %rbx, %r15 ; \+ adcq %r9, %r8 ; \+ xorl %r9d, %r9d ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ notq %rdx; \+ leaq 0x2(%rdx), %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %r9, %r15 ; \+ adoxq %r9, %r8 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ decq %rdx; \+ adcq %r13, %rdx ; \+ decq %r9; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rdx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_montsqr_p256 except for+// register tweaks to avoid modifying %rbp.++#define montsqr_p256(P0,P1) \+ movq P1, %rdx ; \+ mulxq %rdx, %r8, %r15 ; \+ mulxq 0x8+P1, %r9, %r10 ; \+ mulxq 0x18+P1, %r11, %r12 ; \+ movq 0x10+P1, %rdx ; \+ mulxq 0x18+P1, %r13, %r14 ; \+ xorl %ecx, %ecx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ movq 0x18+P1, %rdx ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ adoxq %rcx, %r14 ; \+ adcq %rcx, %r14 ; \+ xorl %ecx, %ecx ; \+ adcxq %r9, %r9 ; \+ adoxq %r15, %r9 ; \+ movq 0x8+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r10, %r10 ; \+ adoxq %rax, %r10 ; \+ adcxq %r11, %r11 ; \+ adoxq %rdx, %r11 ; \+ movq 0x10+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r12, %r12 ; \+ adoxq %rax, %r12 ; \+ adcxq %r13, %r13 ; \+ adoxq %rdx, %r13 ; \+ movq 0x18+P1, %rdx ; \+ mulxq %rdx, %rax, %r15 ; \+ adcxq %r14, %r14 ; \+ adoxq %rax, %r14 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r15 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ movl %ecx, %r9d ; \+ adoxq %rcx, %r9 ; \+ adcxq %rcx, %r9 ; \+ addq %r9, %r14 ; \+ adcq %rcx, %r15 ; \+ movl %ecx, %r8d ; \+ adcq %rcx, %r8 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r8 ; \+ adcq %rcx, %r8 ; \+ movl $0x1, %ebx ; \+ addq %r12, %rbx ; \+ leaq -0x1(%rdx), %rdx ; \+ adcq %r13, %rdx ; \+ leaq -0x1(%rcx), %rcx ; \+ movq %rcx, %rax ; \+ adcq %r14, %rcx ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rbx, %r12 ; \+ cmovbq %rdx, %r13 ; \+ cmovbq %rcx, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Almost-Montgomery variant which we use when an input to other muls+// with the other argument fully reduced (which is always safe).+// Again, the basic squaring code is tweaked to avoid modifying %rbp.++#define amontsqr_p256(P0,P1) \+ movq P1, %rdx ; \+ mulxq %rdx, %r8, %r15 ; \+ mulxq 0x8+P1, %r9, %r10 ; \+ mulxq 0x18+P1, %r11, %r12 ; \+ movq 0x10+P1, %rdx ; \+ mulxq 0x18+P1, %r13, %r14 ; \+ xorl %ecx, %ecx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ movq 0x18+P1, %rdx ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ adoxq %rcx, %r14 ; \+ adcq %rcx, %r14 ; \+ xorl %ecx, %ecx ; \+ adcxq %r9, %r9 ; \+ adoxq %r15, %r9 ; \+ movq 0x8+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r10, %r10 ; \+ adoxq %rax, %r10 ; \+ adcxq %r11, %r11 ; \+ adoxq %rdx, %r11 ; \+ movq 0x10+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r12, %r12 ; \+ adoxq %rax, %r12 ; \+ adcxq %r13, %r13 ; \+ adoxq %rdx, %r13 ; \+ movq 0x18+P1, %rdx ; \+ mulxq %rdx, %rax, %r15 ; \+ adcxq %r14, %r14 ; \+ adoxq %rax, %r14 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r15 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ movl %ecx, %r9d ; \+ adoxq %rcx, %r9 ; \+ adcxq %rcx, %r9 ; \+ addq %r9, %r14 ; \+ adcq %rcx, %r15 ; \+ movl %ecx, %r8d ; \+ adcq %rcx, %r8 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r8 ; \+ adcq %rcx, %r8 ; \+ movl $0x1, %r8d ; \+ leaq -0x1(%rdx), %rdx ; \+ leaq -0x1(%rcx), %rax ; \+ movl $0xfffffffe, %r11d ; \+ cmovzq %rcx, %r8 ; \+ cmovzq %rcx, %rdx ; \+ cmovzq %rcx, %rax ; \+ cmovzq %rcx, %r11 ; \+ addq %r8, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %rax, %r14 ; \+ adcq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ movq P1, %rax ; \+ subq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ sbbq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ sbbq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ sbbq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// Additional macros to help with final multiplexing++#define load4(r0,r1,r2,r3,P) \+ movq P, r0 ; \+ movq 8+P, r1 ; \+ movq 16+P, r2 ; \+ movq 24+P, r3++#define store4(P,r0,r1,r2,r3) \+ movq r0, P ; \+ movq r1, 8+P ; \+ movq r2, 16+P ; \+ movq r3, 24+P++#define czload4(r0,r1,r2,r3,P) \+ cmovzq P, r0 ; \+ cmovzq 8+P, r1 ; \+ cmovzq 16+P, r2 ; \+ cmovzq 24+P, r3++#define muxload4(r0,r1,r2,r3,P0,P1,P2) \+ movq P0, r0 ; \+ cmovbq P1, r0 ; \+ cmovnbe P2, r0 ; \+ movq 8+P0, r1 ; \+ cmovbq 8+P1, r1 ; \+ cmovnbe 8+P2, r1 ; \+ movq 16+P0, r2 ; \+ cmovbq 16+P1, r2 ; \+ cmovnbe 16+P2, r2 ; \+ movq 24+P0, r3 ; \+ cmovbq 24+P1, r3 ; \+ cmovnbe 24+P2, r3++S2N_BN_SYMBOL(p256_montjadd):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save registers and make room on stack for temporary variables+// Put the input y in %rbp where it lasts as long as it's needed.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++ movq %rdx, %rbp++// Main code, just a sequence of basic field operations+// 12 * multiply + 4 * square + 7 * subtract++ amontsqr_p256(z1sq,z_1)+ amontsqr_p256(z2sq,z_2)++ montmul_p256(y1a,z_2,y_1)+ montmul_p256(y2a,z_1,y_2)++ montmul_p256(x2a,z1sq,x_2)+ montmul_p256(x1a,z2sq,x_1)+ montmul_p256(y2a,z1sq,y2a)+ montmul_p256(y1a,z2sq,y1a)++ sub_p256(xd,x2a,x1a)+ sub_p256(yd,y2a,y1a)++ amontsqr_p256(zz,xd)+ montsqr_p256(ww,yd)++ montmul_p256(zzx1,zz,x1a)+ montmul_p256(zzx2,zz,x2a)++ sub_p256(resx,ww,zzx1)+ sub_p256(t1,zzx2,zzx1)++ montmul_p256(xd,xd,z_1)++ sub_p256(resx,resx,zzx2)++ sub_p256(t2,zzx1,resx)++ montmul_p256(t1,t1,y1a)++ montmul_p256(resz,xd,z_2)+ montmul_p256(t2,yd,t2)++ sub_p256(resy,t2,t1)++// Load in the z coordinates of the inputs to check for P1 = 0 and P2 = 0+// The condition codes get set by a comparison (P2 != 0) - (P1 != 0)+// So "NBE" <=> ~(CF \/ ZF) <=> P1 = 0 /\ ~(P2 = 0)+// and "B" <=> CF <=> ~(P1 = 0) /\ P2 = 0+// and "Z" <=> ZF <=> (P1 = 0 <=> P2 = 0)++ load4(%r8,%r9,%r10,%r11,z_1)++ movq %r8, %rax+ movq %r9, %rdx+ orq %r10, %rax+ orq %r11, %rdx+ orq %rdx, %rax+ negq %rax+ sbbq %rax, %rax++ load4(%r12,%r13,%r14,%r15,z_2)++ movq %r12, %rbx+ movq %r13, %rdx+ orq %r14, %rbx+ orq %r15, %rdx+ orq %rdx, %rbx+ negq %rbx+ sbbq %rbx, %rbx++ cmpq %rax, %rbx++// Multiplex the outputs accordingly, re-using the z's in registers++ cmovbq %r8, %r12+ cmovbq %r9, %r13+ cmovbq %r10, %r14+ cmovbq %r11, %r15++ czload4(%r12,%r13,%r14,%r15,resz)++ muxload4(%rax,%rbx,%rcx,%rdx,resx,x_1,x_2)+ muxload4(%r8,%r9,%r10,%r11,resy,y_1,y_2)++// Finally store back the multiplexed values++ store4(x_3,%rax,%rbx,%rcx,%rdx)+ store4(y_3,%r8,%r9,%r10,%r11)+ store4(z_3,%r12,%r13,%r14,%r15)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_montjadd_alt.S view
@@ -0,0 +1,579 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjadd_alt(uint64_t p3[static 12],+// const uint64_t p1[static 12],+// const uint64_t p2[static 12]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard x86-64 ABI: RDI = p3, RSI = p1, RDX = p2+// Microsoft x64 ABI: RCX = p3, RDX = p1, R8 = p2+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjadd_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjadd_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjadd_alt)+ .text++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for inputs and outputs+// These assume %rdi = p3, %rsi = p1 and %rbp = p2,+// which needs to be set up explicitly before use.+// The first two hold initially, and the second is+// set up by copying the initial %rdx input to %rbp.+// Thereafter, no code macro modifies any of them.++#define x_1 0(%rsi)+#define y_1 NUMSIZE(%rsi)+#define z_1 (2*NUMSIZE)(%rsi)++#define x_2 0(%rbp)+#define y_2 NUMSIZE(%rbp)+#define z_2 (2*NUMSIZE)(%rbp)++#define x_3 0(%rdi)+#define y_3 NUMSIZE(%rdi)+#define z_3 (2*NUMSIZE)(%rdi)++// Pointer-offset pairs for temporaries, with some aliasing+// NSPACE is the total stack needed for these temporaries++#define z1sq (NUMSIZE*0)(%rsp)+#define ww (NUMSIZE*0)(%rsp)+#define resx (NUMSIZE*0)(%rsp)++#define yd (NUMSIZE*1)(%rsp)+#define y2a (NUMSIZE*1)(%rsp)++#define x2a (NUMSIZE*2)(%rsp)+#define zzx2 (NUMSIZE*2)(%rsp)++#define zz (NUMSIZE*3)(%rsp)+#define t1 (NUMSIZE*3)(%rsp)++#define t2 (NUMSIZE*4)(%rsp)+#define x1a (NUMSIZE*4)(%rsp)+#define zzx1 (NUMSIZE*4)(%rsp)+#define resy (NUMSIZE*4)(%rsp)++#define xd (NUMSIZE*5)(%rsp)+#define z2sq (NUMSIZE*5)(%rsp)+#define resz (NUMSIZE*5)(%rsp)++#define y1a (NUMSIZE*6)(%rsp)++#define NSPACE NUMSIZE*7++// Corresponds exactly to bignum_montmul_p256_alt++#define montmul_p256(P0,P1,P2) \+ movq P2, %rbx ; \+ movq P1, %rax ; \+ mulq %rbx; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ xorl %r10d, %r10d ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ xorl %r11d, %r11d ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ xorl %r12d, %r12d ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ movq 0x8+P2, %rbx ; \+ xorl %r13d, %r13d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r14, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ xorl %r14d, %r14d ; \+ movq $0x100000000, %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %r15, %r15 ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r15, %r15 ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r15, %r15 ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P2, %rbx ; \+ xorl %r15d, %r15d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r8, %r8 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r8, %r8 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r8, %r8 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P2, %rbx ; \+ xorl %r8d, %r8d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r9, %r9 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r9, %r9 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %r9, %r9 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r8, %r8 ; \+ xorl %r9d, %r9d ; \+ movq $0x100000000, %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ decq %rbx; \+ adcq %r13, %rbx ; \+ decq %r9; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rbx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_montsqr_p256_alt++#define montsqr_p256(P0,P1) \+ movq P1, %rax ; \+ movq %rax, %rbx ; \+ mulq %rax; \+ movq %rax, %r8 ; \+ movq %rdx, %r15 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ movq %rax, %r9 ; \+ movq %rdx, %r10 ; \+ movq 0x18+P1, %rax ; \+ movq %rax, %r13 ; \+ mulq %rbx; \+ movq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ movq 0x10+P1, %rax ; \+ movq %rax, %rbx ; \+ mulq %r13; \+ movq %rax, %r13 ; \+ movq %rdx, %r14 ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq 0x18+P1, %rbx ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorl %ecx, %ecx ; \+ addq %r9, %r9 ; \+ adcq %r10, %r10 ; \+ adcq %r11, %r11 ; \+ adcq %r12, %r12 ; \+ adcq %r13, %r13 ; \+ adcq %r14, %r14 ; \+ adcq %rcx, %rcx ; \+ movq 0x8+P1, %rax ; \+ mulq %rax; \+ addq %r15, %r9 ; \+ adcq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq %rax; \+ negq %r15; \+ adcq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq %rax; \+ negq %r15; \+ adcq %rax, %r14 ; \+ adcq %rcx, %rdx ; \+ movq %rdx, %r15 ; \+ movq $0x100000000, %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ xorl %r8d, %r8d ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r8, %r14 ; \+ adcq %r8, %r15 ; \+ adcq %r8, %r8 ; \+ movq $0x100000000, %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %rcx, %rcx ; \+ xorl %r9d, %r9d ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ leaq -0x1(%rbx), %rbx ; \+ adcq %r13, %rbx ; \+ leaq -0x1(%r9), %r9 ; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rbx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ movq P1, %rax ; \+ subq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ sbbq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ sbbq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ sbbq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// Additional macros to help with final multiplexing++#define load4(r0,r1,r2,r3,P) \+ movq P, r0 ; \+ movq 8+P, r1 ; \+ movq 16+P, r2 ; \+ movq 24+P, r3++#define store4(P,r0,r1,r2,r3) \+ movq r0, P ; \+ movq r1, 8+P ; \+ movq r2, 16+P ; \+ movq r3, 24+P++#define czload4(r0,r1,r2,r3,P) \+ cmovzq P, r0 ; \+ cmovzq 8+P, r1 ; \+ cmovzq 16+P, r2 ; \+ cmovzq 24+P, r3++#define muxload4(r0,r1,r2,r3,P0,P1,P2) \+ movq P0, r0 ; \+ cmovbq P1, r0 ; \+ cmovnbe P2, r0 ; \+ movq 8+P0, r1 ; \+ cmovbq 8+P1, r1 ; \+ cmovnbe 8+P2, r1 ; \+ movq 16+P0, r2 ; \+ cmovbq 16+P1, r2 ; \+ cmovnbe 16+P2, r2 ; \+ movq 24+P0, r3 ; \+ cmovbq 24+P1, r3 ; \+ cmovnbe 24+P2, r3++S2N_BN_SYMBOL(p256_montjadd_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save registers and make room on stack for temporary variables+// Put the input y in %rbp where it lasts as long as it's needed.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++ movq %rdx, %rbp++// Main code, just a sequence of basic field operations+// 12 * multiply + 4 * square + 7 * subtract++ montsqr_p256(z1sq,z_1)+ montsqr_p256(z2sq,z_2)++ montmul_p256(y1a,z_2,y_1)+ montmul_p256(y2a,z_1,y_2)++ montmul_p256(x2a,z1sq,x_2)+ montmul_p256(x1a,z2sq,x_1)+ montmul_p256(y2a,z1sq,y2a)+ montmul_p256(y1a,z2sq,y1a)++ sub_p256(xd,x2a,x1a)+ sub_p256(yd,y2a,y1a)++ montsqr_p256(zz,xd)+ montsqr_p256(ww,yd)++ montmul_p256(zzx1,zz,x1a)+ montmul_p256(zzx2,zz,x2a)++ sub_p256(resx,ww,zzx1)+ sub_p256(t1,zzx2,zzx1)++ montmul_p256(xd,xd,z_1)++ sub_p256(resx,resx,zzx2)++ sub_p256(t2,zzx1,resx)++ montmul_p256(t1,t1,y1a)++ montmul_p256(resz,xd,z_2)+ montmul_p256(t2,yd,t2)++ sub_p256(resy,t2,t1)++// Load in the z coordinates of the inputs to check for P1 = 0 and P2 = 0+// The condition codes get set by a comparison (P2 != 0) - (P1 != 0)+// So "NBE" <=> ~(CF \/ ZF) <=> P1 = 0 /\ ~(P2 = 0)+// and "B" <=> CF <=> ~(P1 = 0) /\ P2 = 0+// and "Z" <=> ZF <=> (P1 = 0 <=> P2 = 0)++ load4(%r8,%r9,%r10,%r11,z_1)++ movq %r8, %rax+ movq %r9, %rdx+ orq %r10, %rax+ orq %r11, %rdx+ orq %rdx, %rax+ negq %rax+ sbbq %rax, %rax++ load4(%r12,%r13,%r14,%r15,z_2)++ movq %r12, %rbx+ movq %r13, %rdx+ orq %r14, %rbx+ orq %r15, %rdx+ orq %rdx, %rbx+ negq %rbx+ sbbq %rbx, %rbx++ cmpq %rax, %rbx++// Multiplex the outputs accordingly, re-using the z's in registers++ cmovbq %r8, %r12+ cmovbq %r9, %r13+ cmovbq %r10, %r14+ cmovbq %r11, %r15++ czload4(%r12,%r13,%r14,%r15,resz)++ muxload4(%rax,%rbx,%rcx,%rdx,resx,x_1,x_2)+ muxload4(%r8,%r9,%r10,%r11,resy,y_1,y_2)++// Finally store back the multiplexed values++ store4(x_3,%rax,%rbx,%rcx,%rdx)+ store4(y_3,%r8,%r9,%r10,%r11)+ store4(z_3,%r12,%r13,%r14,%r15)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjadd_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_montjdouble.S view
@@ -0,0 +1,634 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point doubling on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjdouble(uint64_t p3[static 12],+// const uint64_t p1[static 12]);+//+// Does p3 := 2 * p1 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard x86-64 ABI: RDI = p3, RSI = p1+// Microsoft x64 ABI: RCX = p3, RDX = p1+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjdouble)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjdouble)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjdouble)+ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for inputs and outputs+// These assume %rdi = p3, %rsi = p1, which is true when the+// arguments come in initially and is not disturbed throughout.++#define x_1 0(%rsi)+#define y_1 NUMSIZE(%rsi)+#define z_1 (2*NUMSIZE)(%rsi)++#define x_3 0(%rdi)+#define y_3 NUMSIZE(%rdi)+#define z_3 (2*NUMSIZE)(%rdi)++// Pointer-offset pairs for temporaries, with some aliasing+// NSPACE is the total stack needed for these temporaries++#define z2 (NUMSIZE*0)(%rsp)+#define y4 (NUMSIZE*0)(%rsp)++#define y2 (NUMSIZE*1)(%rsp)++#define t1 (NUMSIZE*2)(%rsp)++#define t2 (NUMSIZE*3)(%rsp)+#define x2p (NUMSIZE*3)(%rsp)+#define dx2 (NUMSIZE*3)(%rsp)++#define xy2 (NUMSIZE*4)(%rsp)++#define x4p (NUMSIZE*5)(%rsp)+#define d (NUMSIZE*5)(%rsp)++#define NSPACE NUMSIZE*6++// Corresponds exactly to bignum_montmul_p256++#define montmul_p256(P0,P1,P2) \+ xorl %r13d, %r13d ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rbx, %r10 ; \+ adcq %rbx, %r9 ; \+ mulxq 0x10+P1, %rbx, %r11 ; \+ adcq %rbx, %r10 ; \+ mulxq 0x18+P1, %rbx, %r12 ; \+ adcq %rbx, %r11 ; \+ adcq %r13, %r12 ; \+ movq 0x8+P2, %rdx ; \+ xorl %r14d, %r14d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcq %r14, %r13 ; \+ xorl %r15d, %r15d ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ notq %rdx; \+ leaq 0x2(%rdx), %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %r15, %r13 ; \+ adoxq %r15, %r14 ; \+ adcq %r15, %r14 ; \+ movq 0x10+P2, %rdx ; \+ xorl %r8d, %r8d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adoxq %r8, %r14 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcq %rax, %r13 ; \+ adcq %rbx, %r14 ; \+ adcq %r8, %r15 ; \+ movq 0x18+P2, %rdx ; \+ xorl %r9d, %r9d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ adoxq %r9, %r15 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcq %rax, %r14 ; \+ adcq %rbx, %r15 ; \+ adcq %r9, %r8 ; \+ xorl %r9d, %r9d ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ notq %rdx; \+ leaq 0x2(%rdx), %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %r9, %r15 ; \+ adoxq %r9, %r8 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ decq %rdx; \+ adcq %r13, %rdx ; \+ decq %r9; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rdx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_montsqr_p256++#define montsqr_p256(P0,P1) \+ movq P1, %rdx ; \+ mulxq %rdx, %r8, %r15 ; \+ mulxq 0x8+P1, %r9, %r10 ; \+ mulxq 0x18+P1, %r11, %r12 ; \+ movq 0x10+P1, %rdx ; \+ mulxq 0x18+P1, %r13, %r14 ; \+ xorl %ebp, %ebp ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ movq 0x18+P1, %rdx ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rbp, %r13 ; \+ adoxq %rbp, %r14 ; \+ adcq %rbp, %r14 ; \+ xorl %ebp, %ebp ; \+ adcxq %r9, %r9 ; \+ adoxq %r15, %r9 ; \+ movq 0x8+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r10, %r10 ; \+ adoxq %rax, %r10 ; \+ adcxq %r11, %r11 ; \+ adoxq %rdx, %r11 ; \+ movq 0x10+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r12, %r12 ; \+ adoxq %rax, %r12 ; \+ adcxq %r13, %r13 ; \+ adoxq %rdx, %r13 ; \+ movq 0x18+P1, %rdx ; \+ mulxq %rdx, %rax, %r15 ; \+ adcxq %r14, %r14 ; \+ adoxq %rax, %r14 ; \+ adcxq %rbp, %r15 ; \+ adoxq %rbp, %r15 ; \+ xorl %ebp, %ebp ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rbp, %r13 ; \+ movl %ebp, %r9d ; \+ adoxq %rbp, %r9 ; \+ adcxq %rbp, %r9 ; \+ addq %r9, %r14 ; \+ adcq %rbp, %r15 ; \+ movl %ebp, %r8d ; \+ adcq %rbp, %r8 ; \+ xorl %ebp, %ebp ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %rbp, %r15 ; \+ adoxq %rbp, %r8 ; \+ adcq %rbp, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ leaq -0x1(%rdx), %rdx ; \+ adcq %r13, %rdx ; \+ leaq -0x1(%rbp), %rbp ; \+ movq %rbp, %rax ; \+ adcq %r14, %rbp ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rdx, %r13 ; \+ cmovbq %rbp, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ movq P1, %rax ; \+ subq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ sbbq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ sbbq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ sbbq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// Corresponds exactly to bignum_add_p256++#define add_p256(P0,P1,P2) \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ addq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ adcq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ adcq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ adcq 0x18+P2, %r9 ; \+ adcq %r11, %r11 ; \+ subq $0xffffffffffffffff, %rax ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r10, %rcx ; \+ sbbq $0x0, %r8 ; \+ movq $0xffffffff00000001, %rdx ; \+ sbbq %rdx, %r9 ; \+ sbbq $0x0, %r11 ; \+ andq %r11, %r10 ; \+ andq %r11, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// A weak version of add that only guarantees sum in 4 digits++#define weakadd_p256(P0,P1,P2) \+ movq P1, %rax ; \+ addq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ adcq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ adcq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ adcq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ subq %r11, %rax ; \+ movq %rax, P0 ; \+ sbbq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ sbbq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ sbbq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// P0 = C * P1 - D * P2 computed as d * (p_256 - P2) + c * P1+// Quotient estimation is done just as q = h + 1 as in bignum_triple_p256+// This also applies to the other functions following.++#define cmsub_p256(P0,C,P1,D,P2) \+ /* First (%r11;%r10;%r9;%r8) = p_256 - P2 */ \+ movq $0xffffffffffffffff, %r8 ; \+ xorl %r10d, %r10d ; \+ subq P2, %r8 ; \+ movq $0x00000000ffffffff, %r9 ; \+ sbbq 0x8+P2, %r9 ; \+ sbbq 0x10+P2, %r10 ; \+ movq $0xffffffff00000001, %r11 ; \+ sbbq 0x18+P2, %r11 ; \+ /* (%r12;%r11;%r10;%r9;%r8) = D * (p_256 - P2) */ \+ xorl %r12d, %r12d ; \+ movq $D, %rdx ; \+ mulxq %r8, %r8, %rax ; \+ mulxq %r9, %r9, %rcx ; \+ addq %rax, %r9 ; \+ mulxq %r10, %r10, %rax ; \+ adcq %rcx, %r10 ; \+ mulxq %r11, %r11, %rcx ; \+ adcq %rax, %r11 ; \+ adcq %rcx, %r12 ; \+ /* (%rdx;%r11;%r10;%r9;%r8) = 2^256 + C * P1 + D * (p_256 - P2) */ \+ movq $C, %rdx ; \+ xorl %eax, %eax ; \+ mulxq P1, %rax, %rcx ; \+ adcxq %rax, %r8 ; \+ adoxq %rcx, %r9 ; \+ mulxq 0x8+P1, %rax, %rcx ; \+ adcxq %rax, %r9 ; \+ adoxq %rcx, %r10 ; \+ mulxq 0x10+P1, %rax, %rcx ; \+ adcxq %rax, %r10 ; \+ adoxq %rcx, %r11 ; \+ mulxq 0x18+P1, %rax, %rdx ; \+ adcxq %rax, %r11 ; \+ adoxq %r12, %rdx ; \+ adcq $1, %rdx ; \+ /* Now the tail for modular reduction from tripling */ \+ addq %rdx, %r8 ; \+ movq $0x100000000, %rax ; \+ mulxq %rax, %rax, %rcx ; \+ sbbq $0x0, %rax ; \+ sbbq $0x0, %rcx ; \+ subq %rax, %r9 ; \+ sbbq %rcx, %r10 ; \+ movq $0xffffffff00000001, %rax ; \+ mulxq %rax, %rax, %rcx ; \+ sbbq %rax, %r11 ; \+ sbbq %rcx, %rdx ; \+ decq %rdx; \+ movl $0xffffffff, %eax ; \+ andq %rdx, %rax ; \+ xorl %ecx, %ecx ; \+ subq %rax, %rcx ; \+ addq %rdx, %r8 ; \+ movq %r8, P0 ; \+ adcq %rax, %r9 ; \+ movq %r9, 0x8+P0 ; \+ adcq $0x0, %r10 ; \+ movq %r10, 0x10+P0 ; \+ adcq %rcx, %r11 ; \+ movq %r11, 0x18+P0++// P0 = 3 * P1 - 8 * P2, computed as (p_256 - P2) << 3 + 3 * P1++#define cmsub38_p256(P0,P1,P2) \+ /* First (%r11;%r10;%r9;%r8) = p_256 - P2 */ \+ movq $0xffffffffffffffff, %r8 ; \+ xorl %r10d, %r10d ; \+ subq P2, %r8 ; \+ movq $0x00000000ffffffff, %r9 ; \+ sbbq 0x8+P2, %r9 ; \+ sbbq 0x10+P2, %r10 ; \+ movq $0xffffffff00000001, %r11 ; \+ sbbq 0x18+P2, %r11 ; \+ /* (%r12;%r11;%r10;%r9;%r8) = (p_256 - P2) << 3 */ \+ movq %r11, %r12 ; \+ shldq $3, %r10, %r11 ; \+ shldq $3, %r9, %r10 ; \+ shldq $3, %r8, %r9 ; \+ shlq $3, %r8 ; \+ shrq $61, %r12 ; \+ /* (%rdx;%r11;%r10;%r9;%r8) = 2^256 + 3 * P1 + 8 * (p_256 - P2) */ \+ movq $3, %rdx ; \+ xorl %eax, %eax ; \+ mulxq P1, %rax, %rcx ; \+ adcxq %rax, %r8 ; \+ adoxq %rcx, %r9 ; \+ mulxq 0x8+P1, %rax, %rcx ; \+ adcxq %rax, %r9 ; \+ adoxq %rcx, %r10 ; \+ mulxq 0x10+P1, %rax, %rcx ; \+ adcxq %rax, %r10 ; \+ adoxq %rcx, %r11 ; \+ mulxq 0x18+P1, %rax, %rdx ; \+ adcxq %rax, %r11 ; \+ adoxq %r12, %rdx ; \+ adcq $1, %rdx ; \+ /* Now the tail for modular reduction from tripling */ \+ addq %rdx, %r8 ; \+ movq $0x100000000, %rax ; \+ mulxq %rax, %rax, %rcx ; \+ sbbq $0x0, %rax ; \+ sbbq $0x0, %rcx ; \+ subq %rax, %r9 ; \+ sbbq %rcx, %r10 ; \+ movq $0xffffffff00000001, %rax ; \+ mulxq %rax, %rax, %rcx ; \+ sbbq %rax, %r11 ; \+ sbbq %rcx, %rdx ; \+ decq %rdx; \+ movl $0xffffffff, %eax ; \+ andq %rdx, %rax ; \+ xorl %ecx, %ecx ; \+ subq %rax, %rcx ; \+ addq %rdx, %r8 ; \+ movq %r8, P0 ; \+ adcq %rax, %r9 ; \+ movq %r9, 0x8+P0 ; \+ adcq $0x0, %r10 ; \+ movq %r10, 0x10+P0 ; \+ adcq %rcx, %r11 ; \+ movq %r11, 0x18+P0++// P0 = 4 * P1 - P2, by direct subtraction of P2,+// since the quotient estimate still works safely+// for initial value > -p_256++#define cmsub41_p256(P0,P1,P2) \+ movq 0x18+P1, %r11 ; \+ movq %r11, %rdx ; \+ movq 0x10+P1, %r10 ; \+ shldq $2, %r10, %r11 ; \+ movq 0x8+P1, %r9 ; \+ shldq $2, %r9, %r10 ; \+ movq P1, %r8 ; \+ shldq $2, %r8, %r9 ; \+ shlq $2, %r8 ; \+ shrq $62, %rdx ; \+ addq $1, %rdx ; \+ subq P2, %r8 ; \+ sbbq 0x8+P2, %r9 ; \+ sbbq 0x10+P2, %r10 ; \+ sbbq 0x18+P2, %r11 ; \+ sbbq $0, %rdx ; \+ /* Now the tail for modular reduction from tripling */ \+ addq %rdx, %r8 ; \+ movq $0x100000000, %rax ; \+ mulxq %rax, %rax, %rcx ; \+ sbbq $0x0, %rax ; \+ sbbq $0x0, %rcx ; \+ subq %rax, %r9 ; \+ sbbq %rcx, %r10 ; \+ movq $0xffffffff00000001, %rax ; \+ mulxq %rax, %rax, %rcx ; \+ sbbq %rax, %r11 ; \+ sbbq %rcx, %rdx ; \+ decq %rdx; \+ movl $0xffffffff, %eax ; \+ andq %rdx, %rax ; \+ xorl %ecx, %ecx ; \+ subq %rax, %rcx ; \+ addq %rdx, %r8 ; \+ movq %r8, P0 ; \+ adcq %rax, %r9 ; \+ movq %r9, 0x8+P0 ; \+ adcq $0x0, %r10 ; \+ movq %r10, 0x10+P0 ; \+ adcq %rcx, %r11 ; \+ movq %r11, 0x18+P0++S2N_BN_SYMBOL(p256_montjdouble):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save registers and make room on stack for temporary variables++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++// Main code, just a sequence of basic field operations++// z2 = z^2+// y2 = y^2++ montsqr_p256(z2,z_1)+ montsqr_p256(y2,y_1)++// x2p = x^2 - z^4 = (x + z^2) * (x - z^2)++ sub_p256(t2,x_1,z2)+ weakadd_p256(t1,x_1,z2)+ montmul_p256(x2p,t1,t2)++// t1 = y + z+// xy2 = x * y^2+// x4p = x2p^2++ add_p256(t1,y_1,z_1)+ montmul_p256(xy2,x_1,y2)+ montsqr_p256(x4p,x2p)++// t1 = (y + z)^2++ montsqr_p256(t1,t1)++// d = 12 * xy2 - 9 * x4p+// t1 = y^2 + 2 * y * z++ cmsub_p256(d,12,xy2,9,x4p)+ sub_p256(t1,t1,z2)++// y4 = y^4++ montsqr_p256(y4,y2)++// dx2 = d * x2p++ montmul_p256(dx2,d,x2p)++// z_3' = 2 * y * z++ sub_p256(z_3,t1,y2)++// x' = 4 * xy2 - d++ cmsub41_p256(x_3,xy2,d)++// y' = 3 * dx2 - 8 * y4++ cmsub38_p256(y_3,dx2,y4)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjdouble)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_montjdouble_alt.S view
@@ -0,0 +1,747 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point doubling on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjdouble_alt(uint64_t p3[static 12],+// const uint64_t p1[static 12]);+//+// Does p3 := 2 * p1 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+//+// Standard x86-64 ABI: RDI = p3, RSI = p1+// Microsoft x64 ABI: RCX = p3, RDX = p1+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjdouble_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjdouble_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjdouble_alt)+ .text+ .balign 4++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for inputs and outputs+// These assume %rdi = p3, %rsi = p1, which is true when the+// arguments come in initially and is not disturbed throughout.++#define x_1 0(%rsi)+#define y_1 NUMSIZE(%rsi)+#define z_1 (2*NUMSIZE)(%rsi)++#define x_3 0(%rdi)+#define y_3 NUMSIZE(%rdi)+#define z_3 (2*NUMSIZE)(%rdi)++// Pointer-offset pairs for temporaries, with some aliasing+// NSPACE is the total stack needed for these temporaries++#define z2 (NUMSIZE*0)(%rsp)+#define y4 (NUMSIZE*0)(%rsp)++#define y2 (NUMSIZE*1)(%rsp)++#define t1 (NUMSIZE*2)(%rsp)++#define t2 (NUMSIZE*3)(%rsp)+#define x2p (NUMSIZE*3)(%rsp)+#define dx2 (NUMSIZE*3)(%rsp)++#define xy2 (NUMSIZE*4)(%rsp)++#define x4p (NUMSIZE*5)(%rsp)+#define d (NUMSIZE*5)(%rsp)++#define NSPACE NUMSIZE*6++// Corresponds exactly to bignum_montmul_p256_alt++#define montmul_p256(P0,P1,P2) \+ movq P2, %rbx ; \+ movq P1, %rax ; \+ mulq %rbx; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ xorl %r10d, %r10d ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ xorl %r11d, %r11d ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ xorl %r12d, %r12d ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ movq 0x8+P2, %rbx ; \+ xorl %r13d, %r13d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r14, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ xorl %r14d, %r14d ; \+ movq $0x100000000, %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %r15, %r15 ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r15, %r15 ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r15, %r15 ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P2, %rbx ; \+ xorl %r15d, %r15d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r8, %r8 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r8, %r8 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r8, %r8 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P2, %rbx ; \+ xorl %r8d, %r8d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r9, %r9 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r9, %r9 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %r9, %r9 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r8, %r8 ; \+ xorl %r9d, %r9d ; \+ movq $0x100000000, %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ decq %rbx; \+ adcq %r13, %rbx ; \+ decq %r9; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rbx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_montsqr_p256_alt++#define montsqr_p256(P0,P1) \+ movq P1, %rax ; \+ movq %rax, %rbx ; \+ mulq %rax; \+ movq %rax, %r8 ; \+ movq %rdx, %r15 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ movq %rax, %r9 ; \+ movq %rdx, %r10 ; \+ movq 0x18+P1, %rax ; \+ movq %rax, %r13 ; \+ mulq %rbx; \+ movq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ movq 0x10+P1, %rax ; \+ movq %rax, %rbx ; \+ mulq %r13; \+ movq %rax, %r13 ; \+ movq %rdx, %r14 ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq 0x18+P1, %rbx ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorl %ecx, %ecx ; \+ addq %r9, %r9 ; \+ adcq %r10, %r10 ; \+ adcq %r11, %r11 ; \+ adcq %r12, %r12 ; \+ adcq %r13, %r13 ; \+ adcq %r14, %r14 ; \+ adcq %rcx, %rcx ; \+ movq 0x8+P1, %rax ; \+ mulq %rax; \+ addq %r15, %r9 ; \+ adcq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq %rax; \+ negq %r15; \+ adcq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq %rax; \+ negq %r15; \+ adcq %rax, %r14 ; \+ adcq %rcx, %rdx ; \+ movq %rdx, %r15 ; \+ movq $0x100000000, %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ xorl %r8d, %r8d ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r8, %r14 ; \+ adcq %r8, %r15 ; \+ adcq %r8, %r8 ; \+ movq $0x100000000, %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %rcx, %rcx ; \+ xorl %r9d, %r9d ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ leaq -0x1(%rbx), %rbx ; \+ adcq %r13, %rbx ; \+ leaq -0x1(%r9), %r9 ; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rbx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ movq P1, %rax ; \+ subq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ sbbq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ sbbq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ sbbq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// Corresponds exactly to bignum_add_p256++#define add_p256(P0,P1,P2) \+ xorq %r11, %r11 ; \+ movq P1, %rax ; \+ addq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ adcq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ adcq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ adcq 0x18+P2, %r9 ; \+ adcq %r11, %r11 ; \+ subq $0xffffffffffffffff, %rax ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r10, %rcx ; \+ sbbq $0x0, %r8 ; \+ movq $0xffffffff00000001, %rdx ; \+ sbbq %rdx, %r9 ; \+ sbbq $0x0, %r11 ; \+ andq %r11, %r10 ; \+ andq %r11, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// A weak version of add that only guarantees sum in 4 digits++#define weakadd_p256(P0,P1,P2) \+ movq P1, %rax ; \+ addq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ adcq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ adcq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ adcq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ subq %r11, %rax ; \+ movq %rax, P0 ; \+ sbbq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ sbbq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ sbbq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// P0 = C * P1 - D * P2 computed as d * (p_256 - P2) + c * P1+// Quotient estimation is done just as q = h + 1 as in bignum_triple_p256_alt.+// This also applies to the other functions following.++#define cmsub_p256(P0,C,P1,D,P2) \+ /* First (%r12;%r11;%r10;%r9) = p_256 - P2 */ \+ movq $0xffffffffffffffff, %r9 ; \+ xorl %r11d, %r11d ; \+ subq P2, %r9 ; \+ movq $0x00000000ffffffff, %r10 ; \+ sbbq 0x8+P2, %r10 ; \+ sbbq 0x10+P2, %r11 ; \+ movq $0xffffffff00000001, %r12 ; \+ sbbq 0x18+P2, %r12 ; \+ /* (%r12;%r11;%r10;%r9;%r8) = D * (p_256 - P2) */ \+ movq $D, %rcx ; \+ movq %r9, %rax ; \+ mulq %rcx; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ movq %r10, %rax ; \+ xorl %r10d, %r10d ; \+ mulq %rcx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq %r11, %rax ; \+ xorl %r11d, %r11d ; \+ mulq %rcx; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ movq %r12, %rax ; \+ xorl %r12d, %r12d ; \+ mulq %rcx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ /* (%rcx;%r11;%r10;%r9;%r8) = 2^256 + C * P1 + D * (p_256 - P2) */ \+ movl $C, %ecx ; \+ movq P1, %rax ; \+ mulq %rcx; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rbx, %rbx ; \+ movq 0x8+P1, %rax ; \+ mulq %rcx; \+ subq %rbx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rbx, %rbx ; \+ movq 0x10+P1, %rax ; \+ mulq %rcx; \+ subq %rbx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rbx, %rbx ; \+ movq 0x18+P1, %rax ; \+ mulq %rcx; \+ subq %rbx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ leaq 1(%r12), %rcx ; \+ /* Now the tail for modular reduction from tripling */ \+ movq $0xffffffff00000001, %rax ; \+ mulq %rcx; \+ movq %rcx, %rbx ; \+ shlq $0x20, %rbx ; \+ addq %rcx, %r8 ; \+ sbbq $0x0, %rbx ; \+ subq %rbx, %r9 ; \+ sbbq $0x0, %r10 ; \+ sbbq %rax, %r11 ; \+ sbbq %rdx, %rcx ; \+ decq %rcx; \+ movl $0xffffffff, %eax ; \+ andq %rcx, %rax ; \+ xorl %edx, %edx ; \+ subq %rax, %rdx ; \+ addq %rcx, %r8 ; \+ movq %r8, P0 ; \+ adcq %rax, %r9 ; \+ movq %r9, 0x8+P0 ; \+ adcq $0x0, %r10 ; \+ movq %r10, 0x10+P0 ; \+ adcq %rdx, %r11 ; \+ movq %r11, 0x18+P0++// P0 = 3 * P1 - 8 * P2, computed as (p_256 - P2) << 3 + 3 * P1++#define cmsub38_p256(P0,P1,P2) \+ /* First (%r11;%r10;%r9;%r8) = p_256 - P2 */ \+ movq $0xffffffffffffffff, %r8 ; \+ xorl %r10d, %r10d ; \+ subq P2, %r8 ; \+ movq $0x00000000ffffffff, %r9 ; \+ sbbq 0x8+P2, %r9 ; \+ sbbq 0x10+P2, %r10 ; \+ movq $0xffffffff00000001, %r11 ; \+ sbbq 0x18+P2, %r11 ; \+ /* (%r12;%r11;%r10;%r9;%r8) = (p_256 - P2) << 3 */ \+ movq %r11, %r12 ; \+ shldq $3, %r10, %r11 ; \+ shldq $3, %r9, %r10 ; \+ shldq $3, %r8, %r9 ; \+ shlq $3, %r8 ; \+ shrq $61, %r12 ; \+ /* (%rcx;%r11;%r10;%r9;%r8) = 2^256 + 3 * P1 + 8 * (p_256 - P2) */ \+ movl $3, %ecx ; \+ movq P1, %rax ; \+ mulq %rcx; \+ addq %rax, %r8 ; \+ adcq %rdx, %r9 ; \+ sbbq %rbx, %rbx ; \+ movq 0x8+P1, %rax ; \+ mulq %rcx; \+ subq %rbx, %rdx ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rbx, %rbx ; \+ movq 0x10+P1, %rax ; \+ mulq %rcx; \+ subq %rbx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rbx, %rbx ; \+ movq 0x18+P1, %rax ; \+ mulq %rcx; \+ subq %rbx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ leaq 1(%r12), %rcx ; \+ /* Now the tail for modular reduction from tripling */ \+ movq $0xffffffff00000001, %rax ; \+ mulq %rcx; \+ movq %rcx, %rbx ; \+ shlq $0x20, %rbx ; \+ addq %rcx, %r8 ; \+ sbbq $0x0, %rbx ; \+ subq %rbx, %r9 ; \+ sbbq $0x0, %r10 ; \+ sbbq %rax, %r11 ; \+ sbbq %rdx, %rcx ; \+ decq %rcx; \+ movl $0xffffffff, %eax ; \+ andq %rcx, %rax ; \+ xorl %edx, %edx ; \+ subq %rax, %rdx ; \+ addq %rcx, %r8 ; \+ movq %r8, P0 ; \+ adcq %rax, %r9 ; \+ movq %r9, 0x8+P0 ; \+ adcq $0x0, %r10 ; \+ movq %r10, 0x10+P0 ; \+ adcq %rdx, %r11 ; \+ movq %r11, 0x18+P0++// P0 = 4 * P1 - P2, by direct subtraction of P2,+// since the quotient estimate still works safely+// for initial value > -p_256++#define cmsub41_p256(P0,P1,P2) \+ movq 0x18+P1, %r11 ; \+ movq %r11, %rcx ; \+ movq 0x10+P1, %r10 ; \+ shldq $2, %r10, %r11 ; \+ movq 0x8+P1, %r9 ; \+ shldq $2, %r9, %r10 ; \+ movq P1, %r8 ; \+ shldq $2, %r8, %r9 ; \+ shlq $2, %r8 ; \+ shrq $62, %rcx ; \+ addq $1, %rcx ; \+ subq P2, %r8 ; \+ sbbq 0x8+P2, %r9 ; \+ sbbq 0x10+P2, %r10 ; \+ sbbq 0x18+P2, %r11 ; \+ sbbq $0, %rcx ; \+ /* Now the tail for modular reduction from tripling */ \+ movq $0xffffffff00000001, %rax ; \+ mulq %rcx; \+ movq %rcx, %rbx ; \+ shlq $0x20, %rbx ; \+ addq %rcx, %r8 ; \+ sbbq $0x0, %rbx ; \+ subq %rbx, %r9 ; \+ sbbq $0x0, %r10 ; \+ sbbq %rax, %r11 ; \+ sbbq %rdx, %rcx ; \+ decq %rcx; \+ movl $0xffffffff, %eax ; \+ andq %rcx, %rax ; \+ xorl %edx, %edx ; \+ subq %rax, %rdx ; \+ addq %rcx, %r8 ; \+ movq %r8, P0 ; \+ adcq %rax, %r9 ; \+ movq %r9, 0x8+P0 ; \+ adcq $0x0, %r10 ; \+ movq %r10, 0x10+P0 ; \+ adcq %rdx, %r11 ; \+ movq %r11, 0x18+P0++S2N_BN_SYMBOL(p256_montjdouble_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+#endif++// Save registers and make room on stack for temporary variables++ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++// Main code, just a sequence of basic field operations++// z2 = z^2+// y2 = y^2++ montsqr_p256(z2,z_1)+ montsqr_p256(y2,y_1)++// x2p = x^2 - z^4 = (x + z^2) * (x - z^2)++ sub_p256(t2,x_1,z2)+ weakadd_p256(t1,x_1,z2)+ montmul_p256(x2p,t1,t2)++// t1 = y + z+// xy2 = x * y^2+// x4p = x2p^2++ add_p256(t1,y_1,z_1)+ montmul_p256(xy2,x_1,y2)+ montsqr_p256(x4p,x2p)++// t1 = (y + z)^2++ montsqr_p256(t1,t1)++// d = 12 * xy2 - 9 * x4p+// t1 = y^2 + 2 * y * z++ cmsub_p256(d,12,xy2,9,x4p)+ sub_p256(t1,t1,z2)++// y4 = y^4++ montsqr_p256(y4,y2)++// dx2 = d * x2p++ montmul_p256(dx2,d,x2p)++// z_3' = 2 * y * z++ sub_p256(z_3,t1,y2)++// x' = 4 * xy2 - d++ cmsub41_p256(x_3,xy2,d)++// y' = 3 * dx2 - 8 * y4++ cmsub38_p256(y_3,dx2,y4)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjdouble_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_montjmixadd.S view
@@ -0,0 +1,567 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point mixed addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjmixadd(uint64_t p3[static 12],+// const uint64_t p1[static 12],+// const uint64_t p2[static 8]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+// The "mixed" part means that p2 only has x and y coordinates, with the+// implicit z coordinate assumed to be the identity.+//+// Standard x86-64 ABI: RDI = p3, RSI = p1, RDX = p2+// Microsoft x64 ABI: RCX = p3, RDX = p1, R8 = p2+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjmixadd)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjmixadd)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjmixadd)+ .text++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for inputs and outputs.+// These assume %rdi = p3, %rsi = p1 and %rbp = p2,+// which needs to be set up explicitly before use.+// The first two hold initially, and the second is+// set up by copying the initial %rdx input to %rbp.+// Thereafter, no code macro modifies any of them.++#define x_1 0(%rsi)+#define y_1 NUMSIZE(%rsi)+#define z_1 (2*NUMSIZE)(%rsi)++#define x_2 0(%rbp)+#define y_2 NUMSIZE(%rbp)++#define x_3 0(%rdi)+#define y_3 NUMSIZE(%rdi)+#define z_3 (2*NUMSIZE)(%rdi)++// Pointer-offset pairs for temporaries, with some aliasing.+// NSPACE is the total stack needed for all temporaries.++#define zp2 (NUMSIZE*0)(%rsp)+#define ww (NUMSIZE*0)(%rsp)+#define resx (NUMSIZE*0)(%rsp)++#define yd (NUMSIZE*1)(%rsp)+#define y2a (NUMSIZE*1)(%rsp)++#define x2a (NUMSIZE*2)(%rsp)+#define zzx2 (NUMSIZE*2)(%rsp)++#define zz (NUMSIZE*3)(%rsp)+#define t1 (NUMSIZE*3)(%rsp)++#define t2 (NUMSIZE*4)(%rsp)+#define zzx1 (NUMSIZE*4)(%rsp)+#define resy (NUMSIZE*4)(%rsp)++#define xd (NUMSIZE*5)(%rsp)+#define resz (NUMSIZE*5)(%rsp)++#define NSPACE NUMSIZE*6++// Corresponds exactly to bignum_montmul_p256++#define montmul_p256(P0,P1,P2) \+ xorl %r13d, %r13d ; \+ movq P2, %rdx ; \+ mulxq P1, %r8, %r9 ; \+ mulxq 0x8+P1, %rbx, %r10 ; \+ adcq %rbx, %r9 ; \+ mulxq 0x10+P1, %rbx, %r11 ; \+ adcq %rbx, %r10 ; \+ mulxq 0x18+P1, %rbx, %r12 ; \+ adcq %rbx, %r11 ; \+ adcq %r13, %r12 ; \+ movq 0x8+P2, %rdx ; \+ xorl %r14d, %r14d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcq %r14, %r13 ; \+ xorl %r15d, %r15d ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ notq %rdx; \+ leaq 0x2(%rdx), %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %r15, %r13 ; \+ adoxq %r15, %r14 ; \+ adcq %r15, %r14 ; \+ movq 0x10+P2, %rdx ; \+ xorl %r8d, %r8d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adoxq %r8, %r14 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcq %rax, %r13 ; \+ adcq %rbx, %r14 ; \+ adcq %r8, %r15 ; \+ movq 0x18+P2, %rdx ; \+ xorl %r9d, %r9d ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ mulxq 0x10+P1, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ adoxq %r9, %r15 ; \+ mulxq 0x18+P1, %rax, %rbx ; \+ adcq %rax, %r14 ; \+ adcq %rbx, %r15 ; \+ adcq %r9, %r8 ; \+ xorl %r9d, %r9d ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ notq %rdx; \+ leaq 0x2(%rdx), %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %r9, %r15 ; \+ adoxq %r9, %r8 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ decq %rdx; \+ adcq %r13, %rdx ; \+ decq %r9; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rdx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_montsqr_p256 except for+// register tweaks to avoid modifying %rbp.++#define montsqr_p256(P0,P1) \+ movq P1, %rdx ; \+ mulxq %rdx, %r8, %r15 ; \+ mulxq 0x8+P1, %r9, %r10 ; \+ mulxq 0x18+P1, %r11, %r12 ; \+ movq 0x10+P1, %rdx ; \+ mulxq 0x18+P1, %r13, %r14 ; \+ xorl %ecx, %ecx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ movq 0x18+P1, %rdx ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ adoxq %rcx, %r14 ; \+ adcq %rcx, %r14 ; \+ xorl %ecx, %ecx ; \+ adcxq %r9, %r9 ; \+ adoxq %r15, %r9 ; \+ movq 0x8+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r10, %r10 ; \+ adoxq %rax, %r10 ; \+ adcxq %r11, %r11 ; \+ adoxq %rdx, %r11 ; \+ movq 0x10+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r12, %r12 ; \+ adoxq %rax, %r12 ; \+ adcxq %r13, %r13 ; \+ adoxq %rdx, %r13 ; \+ movq 0x18+P1, %rdx ; \+ mulxq %rdx, %rax, %r15 ; \+ adcxq %r14, %r14 ; \+ adoxq %rax, %r14 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r15 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ movl %ecx, %r9d ; \+ adoxq %rcx, %r9 ; \+ adcxq %rcx, %r9 ; \+ addq %r9, %r14 ; \+ adcq %rcx, %r15 ; \+ movl %ecx, %r8d ; \+ adcq %rcx, %r8 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r8 ; \+ adcq %rcx, %r8 ; \+ movl $0x1, %ebx ; \+ addq %r12, %rbx ; \+ leaq -0x1(%rdx), %rdx ; \+ adcq %r13, %rdx ; \+ leaq -0x1(%rcx), %rcx ; \+ movq %rcx, %rax ; \+ adcq %r14, %rcx ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rbx, %r12 ; \+ cmovbq %rdx, %r13 ; \+ cmovbq %rcx, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Almost-Montgomery variant which we use when an input to other muls+// with the other argument fully reduced (which is always safe).+// Again, the basic squaring code is tweaked to avoid modifying %rbp.++#define amontsqr_p256(P0,P1) \+ movq P1, %rdx ; \+ mulxq %rdx, %r8, %r15 ; \+ mulxq 0x8+P1, %r9, %r10 ; \+ mulxq 0x18+P1, %r11, %r12 ; \+ movq 0x10+P1, %rdx ; \+ mulxq 0x18+P1, %r13, %r14 ; \+ xorl %ecx, %ecx ; \+ mulxq P1, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ movq 0x18+P1, %rdx ; \+ mulxq 0x8+P1, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ adoxq %rcx, %r14 ; \+ adcq %rcx, %r14 ; \+ xorl %ecx, %ecx ; \+ adcxq %r9, %r9 ; \+ adoxq %r15, %r9 ; \+ movq 0x8+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r10, %r10 ; \+ adoxq %rax, %r10 ; \+ adcxq %r11, %r11 ; \+ adoxq %rdx, %r11 ; \+ movq 0x10+P1, %rdx ; \+ mulxq %rdx, %rax, %rdx ; \+ adcxq %r12, %r12 ; \+ adoxq %rax, %r12 ; \+ adcxq %r13, %r13 ; \+ adoxq %rdx, %r13 ; \+ movq 0x18+P1, %rdx ; \+ mulxq %rdx, %rax, %r15 ; \+ adcxq %r14, %r14 ; \+ adoxq %rax, %r14 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r15 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r9 ; \+ adoxq %rbx, %r10 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r10 ; \+ adoxq %rbx, %r11 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r8, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r9, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ adcxq %rcx, %r13 ; \+ movl %ecx, %r9d ; \+ adoxq %rcx, %r9 ; \+ adcxq %rcx, %r9 ; \+ addq %r9, %r14 ; \+ adcq %rcx, %r15 ; \+ movl %ecx, %r8d ; \+ adcq %rcx, %r8 ; \+ xorl %ecx, %ecx ; \+ movabsq $0x100000000, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r11 ; \+ adoxq %rbx, %r12 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r12 ; \+ adoxq %rbx, %r13 ; \+ movabsq $0xffffffff00000001, %rdx ; \+ mulxq %r10, %rax, %rbx ; \+ adcxq %rax, %r13 ; \+ adoxq %rbx, %r14 ; \+ mulxq %r11, %rax, %rbx ; \+ adcxq %rax, %r14 ; \+ adoxq %rbx, %r15 ; \+ adcxq %rcx, %r15 ; \+ adoxq %rcx, %r8 ; \+ adcq %rcx, %r8 ; \+ movl $0x1, %r8d ; \+ leaq -0x1(%rdx), %rdx ; \+ leaq -0x1(%rcx), %rax ; \+ movl $0xfffffffe, %r11d ; \+ cmovzq %rcx, %r8 ; \+ cmovzq %rcx, %rdx ; \+ cmovzq %rcx, %rax ; \+ cmovzq %rcx, %r11 ; \+ addq %r8, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %rax, %r14 ; \+ adcq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ movq P1, %rax ; \+ subq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ sbbq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ sbbq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ sbbq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// Additional macros to help with final multiplexing++#define testzero4(P) \+ movq P, %rax ; \+ movq 8+P, %rdx ; \+ orq 16+P, %rax ; \+ orq 24+P, %rdx ; \+ orq %rdx, %rax++#define mux4(r0,r1,r2,r3,PNE,PEQ) \+ movq PNE, r0 ; \+ movq PEQ, %rax ; \+ cmovzq %rax, r0 ; \+ movq 8+PNE, r1 ; \+ movq 8+PEQ, %rax ; \+ cmovzq %rax, r1 ; \+ movq 16+PNE, r2 ; \+ movq 16+PEQ, %rax ; \+ cmovzq %rax, r2 ; \+ movq 24+PNE, r3 ; \+ movq 24+PEQ, %rax ; \+ cmovzq %rax, r3++#define load4(r0,r1,r2,r3,P) \+ movq P, r0 ; \+ movq 8+P, r1 ; \+ movq 16+P, r2 ; \+ movq 24+P, r3++#define store4(P,r0,r1,r2,r3) \+ movq r0, P ; \+ movq r1, 8+P ; \+ movq r2, 16+P ; \+ movq r3, 24+P++S2N_BN_SYMBOL(p256_montjmixadd):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save registers and make room on stack for temporary variables+// Put the input y in %rbp where it lasts as long as it's needed.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++ movq %rdx, %rbp++// Main code, just a sequence of basic field operations+// 8 * multiply + 3 * square + 7 * subtract++ amontsqr_p256(zp2,z_1)++ montmul_p256(y2a,z_1,y_2)+ montmul_p256(x2a,zp2,x_2)+ montmul_p256(y2a,zp2,y2a)++ sub_p256(xd,x2a,x_1)++ sub_p256(yd,y2a,y_1)++ amontsqr_p256(zz,xd)+ montsqr_p256(ww,yd)++ montmul_p256(zzx1,zz,x_1)+ montmul_p256(zzx2,zz,x2a)++ sub_p256(resx,ww,zzx1)+ sub_p256(t1,zzx2,zzx1)++ montmul_p256(resz,xd,z_1)++ sub_p256(resx,resx,zzx2)++ sub_p256(t2,zzx1,resx)++ montmul_p256(t1,t1,y_1)+ montmul_p256(t2,yd,t2)++ sub_p256(resy,t2,t1)++// Test if z_1 = 0 to decide if p1 = 0 (up to projective equivalence)++ testzero4(z_1)++// Multiplex: if p1 <> 0 just copy the computed result from the staging area.+// If p1 = 0 then return the point p2 augmented with a z = 1 coordinate (in+// Montgomery form so not the simple constant 1 but rather 2^256 - p_256),+// hence giving 0 + p2 = p2 for the final result.++ mux4(%r8,%r9,%r10,%r11,resx,x_2)+ mux4(%r12,%r13,%r14,%r15,resy,y_2)++ store4(x_3,%r8,%r9,%r10,%r11)+ store4(y_3,%r12,%r13,%r14,%r15)++ load4(%r8,%r9,%r10,%r11,resz)+ movl $1, %eax+ cmovzq %rax, %r8+ movq $0xffffffff00000000, %rax+ cmovzq %rax, %r9+ movq $0xffffffffffffffff, %rax+ cmovzq %rax, %r10+ movl $0x00000000fffffffe, %eax+ cmovzq %rax, %r11++ store4(z_3,%r8,%r9,%r10,%r11)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_montjmixadd_alt.S view
@@ -0,0 +1,552 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Point mixed addition on NIST curve P-256 in Montgomery-Jacobian coordinates+//+// extern void p256_montjmixadd_alt(uint64_t p3[static 12],+// const uint64_t p1[static 12],+// const uint64_t p2[static 8]);+//+// Does p3 := p1 + p2 where all points are regarded as Jacobian triples with+// each coordinate in the Montgomery domain, i.e. x' = (2^256 * x) mod p_256.+// A Jacobian triple (x',y',z') represents affine point (x/z^2,y/z^3).+// The "mixed" part means that p2 only has x and y coordinates, with the+// implicit z coordinate assumed to be the identity.+//+// Standard x86-64 ABI: RDI = p3, RSI = p1, RDX = p2+// Microsoft x64 ABI: RCX = p3, RDX = p1, R8 = p2+// ----------------------------------------------------------------------------+#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_montjmixadd_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_montjmixadd_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_montjmixadd_alt)+ .text++// Size of individual field elements++#define NUMSIZE 32++// Pointer-offset pairs for inputs and outputs.+// These assume %rdi = p3, %rsi = p1 and %rbp = p2,+// which needs to be set up explicitly before use.+// The first two hold initially, and the second is+// set up by copying the initial %rdx input to %rbp.+// Thereafter, no code macro modifies any of them.++#define x_1 0(%rsi)+#define y_1 NUMSIZE(%rsi)+#define z_1 (2*NUMSIZE)(%rsi)++#define x_2 0(%rbp)+#define y_2 NUMSIZE(%rbp)++#define x_3 0(%rdi)+#define y_3 NUMSIZE(%rdi)+#define z_3 (2*NUMSIZE)(%rdi)++// Pointer-offset pairs for temporaries, with some aliasing.+// NSPACE is the total stack needed for all temporaries.++#define zp2 (NUMSIZE*0)(%rsp)+#define ww (NUMSIZE*0)(%rsp)+#define resx (NUMSIZE*0)(%rsp)++#define yd (NUMSIZE*1)(%rsp)+#define y2a (NUMSIZE*1)(%rsp)++#define x2a (NUMSIZE*2)(%rsp)+#define zzx2 (NUMSIZE*2)(%rsp)++#define zz (NUMSIZE*3)(%rsp)+#define t1 (NUMSIZE*3)(%rsp)++#define t2 (NUMSIZE*4)(%rsp)+#define zzx1 (NUMSIZE*4)(%rsp)+#define resy (NUMSIZE*4)(%rsp)++#define xd (NUMSIZE*5)(%rsp)+#define resz (NUMSIZE*5)(%rsp)++#define NSPACE NUMSIZE*6++// Corresponds exactly to bignum_montmul_p256_alt++#define montmul_p256(P0,P1,P2) \+ movq P2, %rbx ; \+ movq P1, %rax ; \+ mulq %rbx; \+ movq %rax, %r8 ; \+ movq %rdx, %r9 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ xorl %r10d, %r10d ; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ xorl %r11d, %r11d ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ xorl %r12d, %r12d ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ movq 0x8+P2, %rbx ; \+ xorl %r13d, %r13d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %r14, %r14 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r14, %r14 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r14, %r14 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r14, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ xorl %r14d, %r14d ; \+ movq $0x100000000, %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %r15, %r15 ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r15, %r15 ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r15, %r15 ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %r15, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r14, %r14 ; \+ movq 0x10+P2, %rbx ; \+ xorl %r15d, %r15d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r8, %r8 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r8, %r8 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r8, %r8 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r8, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ adcq %r15, %r15 ; \+ movq 0x18+P2, %rbx ; \+ xorl %r8d, %r8d ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %r9, %r9 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r9, %r9 ; \+ movq 0x10+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %r9, %r9 ; \+ movq 0x18+P1, %rax ; \+ mulq %rbx; \+ subq %r9, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r8, %r8 ; \+ xorl %r9d, %r9d ; \+ movq $0x100000000, %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ decq %rbx; \+ adcq %r13, %rbx ; \+ decq %r9; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rbx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_montsqr_p256_alt++#define montsqr_p256(P0,P1) \+ movq P1, %rax ; \+ movq %rax, %rbx ; \+ mulq %rax; \+ movq %rax, %r8 ; \+ movq %rdx, %r15 ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ movq %rax, %r9 ; \+ movq %rdx, %r10 ; \+ movq 0x18+P1, %rax ; \+ movq %rax, %r13 ; \+ mulq %rbx; \+ movq %rax, %r11 ; \+ movq %rdx, %r12 ; \+ movq 0x10+P1, %rax ; \+ movq %rax, %rbx ; \+ mulq %r13; \+ movq %rax, %r13 ; \+ movq %rdx, %r14 ; \+ movq P1, %rax ; \+ mulq %rbx; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq 0x18+P1, %rbx ; \+ movq 0x8+P1, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq $0x0, %r14 ; \+ xorl %ecx, %ecx ; \+ addq %r9, %r9 ; \+ adcq %r10, %r10 ; \+ adcq %r11, %r11 ; \+ adcq %r12, %r12 ; \+ adcq %r13, %r13 ; \+ adcq %r14, %r14 ; \+ adcq %rcx, %rcx ; \+ movq 0x8+P1, %rax ; \+ mulq %rax; \+ addq %r15, %r9 ; \+ adcq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %r15, %r15 ; \+ movq 0x10+P1, %rax ; \+ mulq %rax; \+ negq %r15; \+ adcq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %r15, %r15 ; \+ movq 0x18+P1, %rax ; \+ mulq %rax; \+ negq %r15; \+ adcq %rax, %r14 ; \+ adcq %rcx, %rdx ; \+ movq %rdx, %r15 ; \+ movq $0x100000000, %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ addq %rax, %r9 ; \+ adcq %rdx, %r10 ; \+ sbbq %rcx, %rcx ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r10 ; \+ adcq %rdx, %r11 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r8, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ xorl %r8d, %r8d ; \+ movq %r9, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ adcq %r8, %r14 ; \+ adcq %r8, %r15 ; \+ adcq %r8, %r8 ; \+ movq $0x100000000, %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ addq %rax, %r11 ; \+ adcq %rdx, %r12 ; \+ sbbq %rcx, %rcx ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r12 ; \+ adcq %rdx, %r13 ; \+ sbbq %rcx, %rcx ; \+ notq %rbx; \+ leaq 0x2(%rbx), %rbx ; \+ movq %r10, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r13 ; \+ adcq %rdx, %r14 ; \+ sbbq %rcx, %rcx ; \+ xorl %r9d, %r9d ; \+ movq %r11, %rax ; \+ mulq %rbx; \+ subq %rcx, %rdx ; \+ addq %rax, %r14 ; \+ adcq %rdx, %r15 ; \+ adcq %r9, %r8 ; \+ movl $0x1, %ecx ; \+ addq %r12, %rcx ; \+ leaq -0x1(%rbx), %rbx ; \+ adcq %r13, %rbx ; \+ leaq -0x1(%r9), %r9 ; \+ movq %r9, %rax ; \+ adcq %r14, %r9 ; \+ movl $0xfffffffe, %r11d ; \+ adcq %r15, %r11 ; \+ adcq %r8, %rax ; \+ cmovbq %rcx, %r12 ; \+ cmovbq %rbx, %r13 ; \+ cmovbq %r9, %r14 ; \+ cmovbq %r11, %r15 ; \+ movq %r12, P0 ; \+ movq %r13, 0x8+P0 ; \+ movq %r14, 0x10+P0 ; \+ movq %r15, 0x18+P0++// Corresponds exactly to bignum_sub_p256++#define sub_p256(P0,P1,P2) \+ movq P1, %rax ; \+ subq P2, %rax ; \+ movq 0x8+P1, %rcx ; \+ sbbq 0x8+P2, %rcx ; \+ movq 0x10+P1, %r8 ; \+ sbbq 0x10+P2, %r8 ; \+ movq 0x18+P1, %r9 ; \+ sbbq 0x18+P2, %r9 ; \+ movl $0xffffffff, %r10d ; \+ sbbq %r11, %r11 ; \+ xorq %rdx, %rdx ; \+ andq %r11, %r10 ; \+ subq %r10, %rdx ; \+ addq %r11, %rax ; \+ movq %rax, P0 ; \+ adcq %r10, %rcx ; \+ movq %rcx, 0x8+P0 ; \+ adcq $0x0, %r8 ; \+ movq %r8, 0x10+P0 ; \+ adcq %rdx, %r9 ; \+ movq %r9, 0x18+P0++// Additional macros to help with final multiplexing++#define testzero4(P) \+ movq P, %rax ; \+ movq 8+P, %rdx ; \+ orq 16+P, %rax ; \+ orq 24+P, %rdx ; \+ orq %rdx, %rax++#define mux4(r0,r1,r2,r3,PNE,PEQ) \+ movq PNE, r0 ; \+ movq PEQ, %rax ; \+ cmovzq %rax, r0 ; \+ movq 8+PNE, r1 ; \+ movq 8+PEQ, %rax ; \+ cmovzq %rax, r1 ; \+ movq 16+PNE, r2 ; \+ movq 16+PEQ, %rax ; \+ cmovzq %rax, r2 ; \+ movq 24+PNE, r3 ; \+ movq 24+PEQ, %rax ; \+ cmovzq %rax, r3++#define load4(r0,r1,r2,r3,P) \+ movq P, r0 ; \+ movq 8+P, r1 ; \+ movq 16+P, r2 ; \+ movq 24+P, r3++#define store4(P,r0,r1,r2,r3) \+ movq r0, P ; \+ movq r1, 8+P ; \+ movq r2, 16+P ; \+ movq r3, 24+P++S2N_BN_SYMBOL(p256_montjmixadd_alt):+ CFI_START+ _CET_ENDBR++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+#endif++// Save registers and make room on stack for temporary variables+// Put the input y in %rbp where it lasts as long as it's needed.++ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)++ CFI_DEC_RSP(NSPACE)++ movq %rdx, %rbp++// Main code, just a sequence of basic field operations+// 8 * multiply + 3 * square + 7 * subtract++ montsqr_p256(zp2,z_1)++ montmul_p256(y2a,z_1,y_2)+ montmul_p256(x2a,zp2,x_2)+ montmul_p256(y2a,zp2,y2a)++ sub_p256(xd,x2a,x_1)++ sub_p256(yd,y2a,y_1)++ montsqr_p256(zz,xd)+ montsqr_p256(ww,yd)++ montmul_p256(zzx1,zz,x_1)+ montmul_p256(zzx2,zz,x2a)++ sub_p256(resx,ww,zzx1)+ sub_p256(t1,zzx2,zzx1)++ montmul_p256(resz,xd,z_1)++ sub_p256(resx,resx,zzx2)++ sub_p256(t2,zzx1,resx)++ montmul_p256(t1,t1,y_1)+ montmul_p256(t2,yd,t2)++ sub_p256(resy,t2,t1)++// Test if z_1 = 0 to decide if p1 = 0 (up to projective equivalence)++ testzero4(z_1)++// Multiplex: if p1 <> 0 just copy the computed result from the staging area.+// If p1 = 0 then return the point p2 augmented with a z = 1 coordinate (in+// Montgomery form so not the simple constant 1 but rather 2^256 - p_256),+// hence giving 0 + p2 = p2 for the final result.++ mux4(%r8,%r9,%r10,%r11,resx,x_2)+ mux4(%r12,%r13,%r14,%r15,resy,y_2)++ store4(x_3,%r8,%r9,%r10,%r11)+ store4(y_3,%r12,%r13,%r14,%r15)++ load4(%r8,%r9,%r10,%r11,resz)+ movl $1, %eax+ cmovzq %rax, %r8+ movq $0xffffffff00000000, %rax+ cmovzq %rax, %r9+ movq $0xffffffffffffffff, %rax+ cmovzq %rax, %r10+ movl $0x00000000fffffffe, %eax+ cmovzq %rax, %r11++ store4(z_3,%r8,%r9,%r10,%r11)++// Restore stack and registers++ CFI_INC_RSP(NSPACE)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)++#if WINDOWS_ABI+ CFI_POP(%rsi)+ CFI_POP(%rdi)+#endif+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_montjmixadd_alt)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_scalarmul.S view
@@ -0,0 +1,6823 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for P-256+// Input scalar[4], point[8]; output res[8]+//+// extern void p256_scalarmul+// (uint64_t res[static 8],const uint64_t scalar[static 4],+// const uint64_t point[static 8]);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, returns the point (X,Y) = n * P. The input and output+// are affine points, and in the case of the point at infinity as+// the result, (0,0) is returned.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmul)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmul)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmul)++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on the table, which is no longer needed at the end.+// Uppercase syntactic variants make x86_att version simpler to generate++#define SCALARB (0*NUMSIZE)+#define scalarb (0*NUMSIZE)(%rsp)+#define ACC (1*NUMSIZE)+#define acc (1*NUMSIZE)(%rsp)+#define TABENT (4*NUMSIZE)+#define tabent (4*NUMSIZE)(%rsp)++#define TAB (7*NUMSIZE)+#define tab (7*NUMSIZE)(%rsp)++#define Z2 (7*NUMSIZE)+#define z2 (7*NUMSIZE)(%rsp)+#define Z3 (8*NUMSIZE)+#define z3 (8*NUMSIZE)(%rsp)++#define res (31*NUMSIZE)(%rsp)++#define NSPACE 32*NUMSIZE++S2N_BN_SYMBOL(p256_scalarmul):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ CFI_CALL(Lp256_scalarmul_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmul)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_standard)++Lp256_scalarmul_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the "res" and "point" input arguments. We load and process the+// scalar immediately so we don't bother preserving that input argument.+// Also, "point" is only needed early on and so its register gets re-used.++ movq %rdx, %rbx+ movq %rdi, res++// Load the digits of group order n_256 = [%r15;%r14;%r13;%r12]++ movq $0xf3b9cac2fc632551, %r12+ movq $0xbce6faada7179e84, %r13+ movq $0xffffffffffffffff, %r14+ movq $0xffffffff00000000, %r15++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256++ movq (%rsi), %r8+ subq %r12, %r8+ movq 8(%rsi), %r9+ sbbq %r13, %r9+ movq 16(%rsi), %r10+ sbbq %r14, %r10+ movq 24(%rsi), %r11+ sbbq %r15, %r11++ cmovcq (%rsi), %r8+ cmovcq 8(%rsi), %r9+ cmovcq 16(%rsi), %r10+ cmovcq 24(%rsi), %r11++// Now if the top bit of the reduced scalar is set, negate it mod n_256,+// i.e. do n |-> n_256 - n. Remember the sign in %rbp so we can+// correspondingly negate the point below.++ subq %r8, %r12+ sbbq %r9, %r13+ sbbq %r10, %r14+ sbbq %r11, %r15++ movq %r11, %rbp+ shrq $63, %rbp+ cmovnzq %r12, %r8+ cmovnzq %r13, %r9+ cmovnzq %r14, %r10+ cmovnzq %r15, %r11++// In either case then add the recoding constant 0x08888...888 to allow+// signed digits.++ movq $0x8888888888888888, %rax+ addq %rax, %r8+ adcq %rax, %r9+ adcq %rax, %r10+ adcq %rax, %r11+ btc $63, %r11++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)++// Set the tab[0] table entry to Montgomery-Jacobian point = 1 * P+// The z coordinate is just the Montgomery form of the constant 1.++ leaq TAB(%rsp), %rdi+ movq %rbx, %rsi+ CFI_CALL(Lp256_scalarmul_local_tomont_p256)++ leaq 32(%rbx), %rsi+ leaq TAB+32(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_local_tomont_p256)++ movl $1, %eax+ movq %rax, TAB+64(%rsp)+ movq $0xffffffff00000000, %rdx+ movq %rdx, TAB+72(%rsp)+ subq $2, %rax+ movq %rax, TAB+80(%rsp)+ movq $0x00000000fffffffe, %rax+ movq %rax, TAB+88(%rsp)++// If the top bit of the scalar was set, negate (y coordinate of) the point++ movq TAB+32(%rsp), %r12+ movq TAB+40(%rsp), %r13+ movq TAB+48(%rsp), %r14+ movq TAB+56(%rsp), %r15++ xorl %r10d, %r10d+ leaq -1(%r10), %r8+ movq $0x00000000ffffffff, %r11+ movq %r11, %r9+ negq %r11++ subq %r12, %r8+ sbbq %r13, %r9+ sbbq %r14, %r10+ sbbq %r15, %r11++ testq %rbp, %rbp+ cmovzq %r12, %r8+ cmovzq %r13, %r9+ cmovzq %r14, %r10+ cmovzq %r15, %r11++ movq %r8, TAB+32(%rsp)+ movq %r9, TAB+40(%rsp)+ movq %r10, TAB+48(%rsp)+ movq %r11, TAB+56(%rsp)++// Compute and record tab[1] = 2 * p, ..., tab[7] = 8 * P++ leaq TAB+96*1(%rsp), %rdi+ leaq TAB(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++ leaq TAB+96*2(%rsp), %rdi+ leaq TAB+96*1(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_local_p256_montjmixadd)++ leaq TAB+96*3(%rsp), %rdi+ leaq TAB+96*1(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++ leaq TAB+96*4(%rsp), %rdi+ leaq TAB+96*3(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_local_p256_montjmixadd)++ leaq TAB+96*5(%rsp), %rdi+ leaq TAB+96*2(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++ leaq TAB+96*6(%rsp), %rdi+ leaq TAB+96*5(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_local_p256_montjmixadd)++ leaq TAB+96*7(%rsp), %rdi+ leaq TAB+96*3(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++// Set up accumulator as table entry for top 4 bits (constant-time indexing)++ movq SCALARB+24(%rsp), %rdi+ shrq $60, %rdi++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ .set I, 1+.rep 8+ cmpq $I, %rdi++ cmovzq TAB+96*(I-1)(%rsp), %rax+ cmovzq TAB+96*(I-1)+8(%rsp), %rbx+ cmovzq TAB+96*(I-1)+16(%rsp), %rcx+ cmovzq TAB+96*(I-1)+24(%rsp), %rdx+ cmovzq TAB+96*(I-1)+32(%rsp), %r8+ cmovzq TAB+96*(I-1)+40(%rsp), %r9+ cmovzq TAB+96*(I-1)+48(%rsp), %r10+ cmovzq TAB+96*(I-1)+56(%rsp), %r11+ cmovzq TAB+96*(I-1)+64(%rsp), %r12+ cmovzq TAB+96*(I-1)+72(%rsp), %r13+ cmovzq TAB+96*(I-1)+80(%rsp), %r14+ cmovzq TAB+96*(I-1)+88(%rsp), %r15+ .set I, (I+1)+.endr+ movq %rax, ACC(%rsp)+ movq %rbx, ACC+8(%rsp)+ movq %rcx, ACC+16(%rsp)+ movq %rdx, ACC+24(%rsp)+ movq %r8, ACC+32(%rsp)+ movq %r9, ACC+40(%rsp)+ movq %r10, ACC+48(%rsp)+ movq %r11, ACC+56(%rsp)+ movq %r12, ACC+64(%rsp)+ movq %r13, ACC+72(%rsp)+ movq %r14, ACC+80(%rsp)+ movq %r15, ACC+88(%rsp)++// Main loop over size-4 bitfield++ movl $252, %ebp++Lp256_scalarmul_loop:+ subq $4, %rbp++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_local_p256_montjdouble)++ movq %rbp, %rax+ shrq $6, %rax+ movq (%rsp,%rax,8), %rdi+ movq %rbp, %rcx+ shrq %cl, %rdi+ andq $15, %rdi++ subq $8, %rdi+ sbbq %rsi, %rsi // %rsi = sign of digit (-1 = negative)+ xorq %rsi, %rdi+ subq %rsi, %rdi // %rdi = absolute value of digit++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ .set I, 1+.rep 8+ cmpq $I, %rdi++ cmovzq TAB+96*(I-1)(%rsp), %rax+ cmovzq TAB+96*(I-1)+8(%rsp), %rbx+ cmovzq TAB+96*(I-1)+16(%rsp), %rcx+ cmovzq TAB+96*(I-1)+24(%rsp), %rdx+ cmovzq TAB+96*(I-1)+32(%rsp), %r8+ cmovzq TAB+96*(I-1)+40(%rsp), %r9+ cmovzq TAB+96*(I-1)+48(%rsp), %r10+ cmovzq TAB+96*(I-1)+56(%rsp), %r11+ cmovzq TAB+96*(I-1)+64(%rsp), %r12+ cmovzq TAB+96*(I-1)+72(%rsp), %r13+ cmovzq TAB+96*(I-1)+80(%rsp), %r14+ cmovzq TAB+96*(I-1)+88(%rsp), %r15+ .set I, (I+1)+.endr++ movq %r12, TABENT+64(%rsp)+ movq %r13, TABENT+72(%rsp)+ movq %r14, TABENT+80(%rsp)+ movq %r15, TABENT+88(%rsp)++ xorl %r14d, %r14d+ leaq -1(%r14), %r12+ movq $0x00000000ffffffff, %r15+ movq %r15, %r13+ negq %r15++ subq %r8, %r12+ sbbq %r9, %r13+ sbbq %r10, %r14+ sbbq %r11, %r15++ testq %rsi, %rsi+ cmovnzq %r12, %r8+ cmovnzq %r13, %r9+ cmovnzq %r14, %r10+ cmovnzq %r15, %r11++ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)++ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+48(%rsp)+ movq %r11, TABENT+56(%rsp)++ leaq TABENT(%rsp), %rdx+ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_local_p256_montjadd)++ testq %rbp, %rbp+ jne Lp256_scalarmul_loop++// Let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_local_montsqr_p256)++ leaq Z3(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_local_montmul_p256)++ leaq Z2(%rsp), %rdi+ leaq Z3(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_local_demont_p256)++ leaq Z3(%rsp), %rdi+ leaq Z2(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_local_inv_p256)++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_local_montmul_p256)++// Convert back from Jacobian (X, Y, Z) |-> (X/Z^2, Y/Z^3)++ movq res, %rdi+ leaq ACC(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ movq %rdi, %rbx+ CFI_CALL(Lp256_scalarmul_local_montmul_p256)++ leaq 32(%rbx), %rdi+ leaq ACC+32(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p256_scalarmul)+#endif++// Local copies of subroutines, complete clones at the moment++Lp256_scalarmul_local_demont_p256:+ CFI_START+ CFI_PUSH(%rbx)+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ xorq %rbx, %rbx+ xorq %rsi, %rsi+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq %r9, %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %rbx+ mulxq %r9, %rax, %rcx+ adcxq %rax, %rbx+ adoxq %rcx, %rsi+ movl $0x0, %r8d+ adcxq %r8, %rsi+ xorq %r9, %r9+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %rbx+ mulxq %r11, %rax, %rcx+ adcxq %rax, %rbx+ adoxq %rcx, %rsi+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rcx+ adcxq %rax, %rsi+ adoxq %rcx, %r8+ mulxq %r11, %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ movl $0x0, %r10d+ adcxq %r10, %r9+ movq %rbx, (%rdi)+ movq %rsi, 0x8(%rdi)+ movq %r8, 0x10(%rdi)+ movq %r9, 0x18(%rdi)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_local_inv_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(240)+ movq %rdi, 0xe0(%rsp)+ xorl %ecx, %ecx+ movl $0xffffffff, %edx+ movq %rdx, %rbx+ leaq -0x1(%rcx), %rax+ negq %rdx+ movq %rax, (%rsp)+ movq %rbx, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rdx, 0x18(%rsp)+ movq %rcx, 0x20(%rsp)+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ leaq 0x1(%rcx), %rax+ addq %r8, %rax+ leaq -0x1(%rdx), %rbx+ adcq %r9, %rbx+ notq %rcx+ adcq %r10, %rcx+ notq %rdx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq %rax, 0x28(%rsp)+ movq %rbx, 0x30(%rsp)+ movq %rcx, 0x38(%rsp)+ movq %rdx, 0x40(%rsp)+ xorl %eax, %eax+ movq %rax, 0x48(%rsp)+ xorl %eax, %eax+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movq %rax, 0x60(%rsp)+ movq %rax, 0x68(%rsp)+ movq $0x4000000000000, %rcx+ movq %rcx, 0x78(%rsp)+ movq %rax, 0x80(%rsp)+ movq %rax, 0x88(%rsp)+ movq %rax, 0x90(%rsp)+ movq $0xa, 0xb0(%rsp)+ movq $0x1, 0xb8(%rsp)+ jmp Lp256_scalarmul_inv_midloop+Lp256_scalarmul_inv_loop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0xa0(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0xa8(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x28(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x30(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq 0x20(%rsp), %rbp+ xorq %r9, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x40(%rsp), %rax+ xorq %r11, %rax+ movq 0x48(%rsp), %rdx+ xorq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ sarq $0x3b, %rbp+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ movq 0x20(%rsp), %rsi+ movq %rbp, 0x20(%rsp)+ xorq %r13, %rax+ xorq %r13, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x40(%rsp), %rax+ xorq %r15, %rax+ movq 0x48(%rsp), %rdx+ xorq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x38(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x40(%rsp)+ sarq $0x3b, %rsi+ movq %rsi, 0x48(%rsp)+ movq 0xa0(%rsp), %rbx+ movq 0xa8(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x78(%rsp)+ xorl %ebx, %ebx+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x58(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x58(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x80(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x80(%rsp)+ xorl %ecx, %ecx+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x60(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x60(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x88(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x88(%rsp)+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq 0x68(%rsp), %rax+ movq %rcx, 0x68(%rsp)+ movq %rdx, 0x70(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x90(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rsi, 0x90(%rsp)+ movq %rdx, 0x98(%rsp)+ movq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movq $0xe000000000000000, %r8+ addq 0x78(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x80(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x88(%rsp), %r10+ movq $0x2000000000000000, %r11+ adcq 0x90(%rsp), %r11+ movq $0x1fffffffe0000000, %r12+ adcq 0x98(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x78(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x80(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x88(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x90(%rsp)+Lp256_scalarmul_inv_midloop:+ movq 0xb8(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x28(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xc0(%rsp)+ movq %rbx, 0xc8(%rsp)+ movq %rdi, 0xd0(%rsp)+ movq %rcx, 0xd8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x28(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xc0(%rsp), %rax+ imulq %r8, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xc8(%rsp), %r8+ imulq 0xd8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xc0(%rsp), %rax+ imulq %r10, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xc8(%rsp), %r10+ imulq 0xd8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0xb8(%rsp)+ decq 0xb0(%rsp)+ jne Lp256_scalarmul_inv_loop+ movq (%rsp), %rax+ movq 0x28(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r12, 0x50(%rsp)+ movq %r13, 0x58(%rsp)+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r9, 0x70(%rsp)+ movq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movq 0x50(%rsp), %r8+ movq 0x58(%rsp), %r9+ movq 0x60(%rsp), %r10+ movq 0x68(%rsp), %r11+ movl $0x1, %eax+ movl $0xffffffff, %ebx+ leaq -0x2(%rax), %rcx+ leaq -0x1(%rbx), %rdx+ notq %rbx+ addq %r8, %rax+ adcq %r9, %rbx+ adcq %r10, %rcx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq 0xe0(%rsp), %rdi+ movq %rax, (%rdi)+ movq %rbx, 0x8(%rdi)+ movq %rcx, 0x10(%rdi)+ movq %rdx, 0x18(%rdi)+ CFI_INC_RSP(240)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_local_montmul_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq %rdx, %rcx+ xorl %r13d, %r13d+ movq (%rcx), %rdx+ mulxq (%rsi), %r8, %r9+ mulxq 0x8(%rsi), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsi), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rcx), %rdx+ xorl %r14d, %r14d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rcx), %rdx+ xorl %r8d, %r8d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rcx), %rdx+ xorl %r9d, %r9d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_local_montsqr_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq (%rsi), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x8(%rsi), %r9, %r10+ mulxq 0x18(%rsi), %r11, %r12+ movq 0x10(%rsi), %rdx+ mulxq 0x18(%rsi), %r13, %r14+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x18(%rsi), %rdx+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ xorl %ebp, %ebp+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x8(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x10(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x18(%rsi), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ movl %ebp, %r9d+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ addq %r9, %r14+ adcq %rbp, %r15+ movl %ebp, %r8d+ adcq %rbp, %r8+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rbp), %rbp+ movq %rbp, %rax+ adcq %r14, %rbp+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %rbp, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_local_tomont_p256:+ CFI_START+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ xorq %r13, %r13+ movl $0x3, %edx+ mulxq (%rsi), %r8, %r9+ mulxq 0x8(%rsi), %rcx, %r10+ adcxq %rcx, %r9+ mulxq 0x10(%rsi), %rcx, %r11+ adcxq %rcx, %r10+ mulxq 0x18(%rsi), %rcx, %r12+ adcxq %rcx, %r11+ adcxq %r13, %r12+ movq $0xfffffffbffffffff, %rdx+ xorq %r14, %r14+ mulxq (%rsi), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq 0x8(%rsi), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ mulxq 0x10(%rsi), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq 0x18(%rsi), %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ adcq %r14, %r13+ xorq %r15, %r15+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq %r9, %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq %r9, %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcxq %r15, %r14+ movq $0xfffffffffffffffe, %rdx+ xorq %r8, %r8+ mulxq (%rsi), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ mulxq 0x8(%rsi), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq 0x10(%rsi), %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ mulxq 0x18(%rsi), %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ adcxq %r8, %r14+ adoxq %r8, %r15+ adcxq %r8, %r15+ movq $0x4fffffffd, %rdx+ xorq %r9, %r9+ mulxq (%rsi), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq 0x8(%rsi), %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ mulxq 0x10(%rsi), %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ mulxq 0x18(%rsi), %rax, %rcx+ adcxq %rax, %r14+ adoxq %rcx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcxq %r9, %r8+ xorq %r9, %r9+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq %r11, %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ mulxq %r11, %rax, %rcx+ adcxq %rax, %r14+ adoxq %rcx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcxq %r9, %r8+ movl $0xffffffff, %edx+ movq $0xffffffff00000001, %rcx+ movq $0xfffffffffffffffe, %rax+ subq %r12, %rax+ movq %rdx, %rax+ sbbq %r13, %rax+ movl $0x0, %eax+ sbbq %r14, %rax+ movq %rcx, %rax+ sbbq %r15, %rax+ movl $0x0, %eax+ sbbq %r8, %rax+ andq %rax, %rdx+ andq %rax, %rcx+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq $0x0, %r14+ sbbq %rcx, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_RET++Lp256_scalarmul_local_p256_montjadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(224)+ movq %rdx, %rbp+ movq 0x40(%rsi), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x48(%rsi), %r9, %r10+ mulxq 0x58(%rsi), %r11, %r12+ movq 0x50(%rsi), %rdx+ mulxq 0x58(%rsi), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x58(%rsi), %rdx+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x48(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x50(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x58(%rsi), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %r8d+ leaq -0x1(%rdx), %rdx+ leaq -0x1(%rcx), %rax+ movl $0xfffffffe, %r11d+ cmoveq %rcx, %r8+ cmoveq %rcx, %rdx+ cmoveq %rcx, %rax+ cmoveq %rcx, %r11+ addq %r8, %r12+ adcq %rdx, %r13+ adcq %rax, %r14+ adcq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x40(%rbp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x48(%rbp), %r9, %r10+ mulxq 0x58(%rbp), %r11, %r12+ movq 0x50(%rbp), %rdx+ mulxq 0x58(%rbp), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0x40(%rbp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rbp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x58(%rbp), %rdx+ mulxq 0x48(%rbp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x48(%rbp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x50(%rbp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x58(%rbp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %r8d+ leaq -0x1(%rdx), %rdx+ leaq -0x1(%rcx), %rax+ movl $0xfffffffe, %r11d+ cmoveq %rcx, %r8+ cmoveq %rcx, %rdx+ cmoveq %rcx, %rax+ cmoveq %rcx, %r11+ addq %r8, %r12+ adcq %rdx, %r13+ adcq %rax, %r14+ adcq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rsi), %rdx+ mulxq 0x40(%rbp), %r8, %r9+ mulxq 0x48(%rbp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x50(%rbp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x58(%rbp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0x40(%rbp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x48(%rbp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x50(%rbp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x58(%rbp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0x40(%rbp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rbp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x50(%rbp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x58(%rbp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0x40(%rbp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x48(%rbp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rbp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x58(%rbp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xc0(%rsp)+ movq %r13, 0xc8(%rsp)+ movq %r14, 0xd0(%rsp)+ movq %r15, 0xd8(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rbp), %rdx+ mulxq 0x40(%rsi), %r8, %r9+ mulxq 0x48(%rsi), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x50(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x58(%rsi), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rbp), %rdx+ xorl %r14d, %r14d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x58(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rbp), %rdx+ xorl %r8d, %r8d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x58(%rsi), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rbp), %rdx+ xorl %r9d, %r9d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x58(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ xorl %r13d, %r13d+ movq 0x0(%rbp), %rdx+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rbp), %rdx+ xorl %r14d, %r14d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rbp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rbp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ xorl %r13d, %r13d+ movq (%rsi), %rdx+ mulxq 0xa0(%rsp), %r8, %r9+ mulxq 0xa8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0xb0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xb8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rsp), %rdx+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ xorl %r13d, %r13d+ movq 0xc0(%rsp), %rdx+ mulxq 0xa0(%rsp), %r8, %r9+ mulxq 0xa8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0xb0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xb8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0xc8(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0xd0(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0xd8(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xc0(%rsp)+ movq %r13, 0xc8(%rsp)+ movq %r14, 0xd0(%rsp)+ movq %r15, 0xd8(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0xa0(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0xa8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0xb0(%rsp)+ adcq %rdx, %r9+ movq %r9, 0xb8(%rsp)+ movq 0x20(%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x28(%rsp), %rcx+ sbbq 0xc8(%rsp), %rcx+ movq 0x30(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x38(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x20(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x28(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x30(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x38(%rsp)+ movq 0xa0(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0xa8(%rsp), %r9, %r10+ mulxq 0xb8(%rsp), %r11, %r12+ movq 0xb0(%rsp), %rdx+ mulxq 0xb8(%rsp), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0xb8(%rsp), %rdx+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0xa8(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0xb0(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0xb8(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %r8d+ leaq -0x1(%rdx), %rdx+ leaq -0x1(%rcx), %rax+ movl $0xfffffffe, %r11d+ cmoveq %rcx, %r8+ cmoveq %rcx, %rdx+ cmoveq %rcx, %rax+ cmoveq %rcx, %r11+ addq %r8, %r12+ adcq %rdx, %r13+ adcq %rax, %r14+ adcq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x20(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x28(%rsp), %r9, %r10+ mulxq 0x38(%rsp), %r11, %r12+ movq 0x30(%rsp), %rdx+ mulxq 0x38(%rsp), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsp), %rdx+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x28(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x30(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x38(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %ebx+ addq %r12, %rbx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rcx), %rcx+ movq %rcx, %rax+ adcq %r14, %rcx+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rbx, %r12+ cmovbq %rdx, %r13+ cmovbq %rcx, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ xorl %r13d, %r13d+ movq 0x80(%rsp), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x88(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x90(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x98(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x48(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x50(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x58(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq (%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ xorl %r13d, %r13d+ movq 0x40(%rsi), %rdx+ mulxq 0xa0(%rsp), %r8, %r9+ mulxq 0xa8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0xb0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xb8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x48(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x50(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x58(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq (%rsp), %rax+ subq 0x40(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x48(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x50(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x58(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x80(%rsp), %rax+ subq (%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ xorl %r13d, %r13d+ movq 0xc0(%rsp), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0xc8(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0xd0(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0xd8(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ xorl %r13d, %r13d+ movq 0x40(%rbp), %rdx+ mulxq 0xa0(%rsp), %r8, %r9+ mulxq 0xa8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0xb0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xb8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x48(%rbp), %rdx+ xorl %r14d, %r14d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x50(%rbp), %rdx+ xorl %r8d, %r8d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x58(%rbp), %rdx+ xorl %r9d, %r9d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ xorl %r13d, %r13d+ movq 0x80(%rsp), %rdx+ mulxq 0x20(%rsp), %r8, %r9+ mulxq 0x28(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x30(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x38(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x88(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x90(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x38(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x98(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x38(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x80(%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x68(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x40(%rsi), %r8+ movq 0x48(%rsi), %r9+ movq 0x50(%rsi), %r10+ movq 0x58(%rsi), %r11+ movq %r8, %rax+ movq %r9, %rdx+ orq %r10, %rax+ orq %r11, %rdx+ orq %rdx, %rax+ negq %rax+ sbbq %rax, %rax+ movq 0x40(%rbp), %r12+ movq 0x48(%rbp), %r13+ movq 0x50(%rbp), %r14+ movq 0x58(%rbp), %r15+ movq %r12, %rbx+ movq %r13, %rdx+ orq %r14, %rbx+ orq %r15, %rdx+ orq %rdx, %rbx+ negq %rbx+ sbbq %rbx, %rbx+ cmpq %rax, %rbx+ cmovbq %r8, %r12+ cmovbq %r9, %r13+ cmovbq %r10, %r14+ cmovbq %r11, %r15+ cmoveq 0xa0(%rsp), %r12+ cmoveq 0xa8(%rsp), %r13+ cmoveq 0xb0(%rsp), %r14+ cmoveq 0xb8(%rsp), %r15+ movq (%rsp), %rax+ cmovbq (%rsi), %rax+ cmova 0x0(%rbp), %rax+ movq 0x8(%rsp), %rbx+ cmovbq 0x8(%rsi), %rbx+ cmova 0x8(%rbp), %rbx+ movq 0x10(%rsp), %rcx+ cmovbq 0x10(%rsi), %rcx+ cmova 0x10(%rbp), %rcx+ movq 0x18(%rsp), %rdx+ cmovbq 0x18(%rsi), %rdx+ cmova 0x18(%rbp), %rdx+ movq 0x80(%rsp), %r8+ cmovbq 0x20(%rsi), %r8+ cmova 0x20(%rbp), %r8+ movq 0x88(%rsp), %r9+ cmovbq 0x28(%rsi), %r9+ cmova 0x28(%rbp), %r9+ movq 0x90(%rsp), %r10+ cmovbq 0x30(%rsi), %r10+ cmova 0x30(%rbp), %r10+ movq 0x98(%rsp), %r11+ cmovbq 0x38(%rsi), %r11+ cmova 0x38(%rbp), %r11+ movq %rax, (%rdi)+ movq %rbx, 0x8(%rdi)+ movq %rcx, 0x10(%rdi)+ movq %rdx, 0x18(%rdi)+ movq %r8, 0x20(%rdi)+ movq %r9, 0x28(%rdi)+ movq %r10, 0x30(%rdi)+ movq %r11, 0x38(%rdi)+ movq %r12, 0x40(%rdi)+ movq %r13, 0x48(%rdi)+ movq %r14, 0x50(%rdi)+ movq %r15, 0x58(%rdi)+ CFI_INC_RSP(224)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_local_p256_montjdouble:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(192)+ movq 0x40(%rsi), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x48(%rsi), %r9, %r10+ mulxq 0x58(%rsi), %r11, %r12+ movq 0x50(%rsi), %rdx+ mulxq 0x58(%rsi), %r13, %r14+ xorl %ebp, %ebp+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x58(%rsi), %rdx+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ xorl %ebp, %ebp+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x48(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x50(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x58(%rsi), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ movl %ebp, %r9d+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ addq %r9, %r14+ adcq %rbp, %r15+ movl %ebp, %r8d+ adcq %rbp, %r8+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rbp), %rbp+ movq %rbp, %rax+ adcq %r14, %rbp+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %rbp, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x20(%rsi), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x28(%rsi), %r9, %r10+ mulxq 0x38(%rsi), %r11, %r12+ movq 0x30(%rsi), %rdx+ mulxq 0x38(%rsi), %r13, %r14+ xorl %ebp, %ebp+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsi), %rdx+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ xorl %ebp, %ebp+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x28(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x30(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x38(%rsi), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ movl %ebp, %r9d+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ addq %r9, %r14+ adcq %rbp, %r15+ movl %ebp, %r8d+ adcq %rbp, %r8+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rbp), %rbp+ movq %rbp, %rax+ adcq %r14, %rbp+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %rbp, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq (%rsi), %rax+ subq (%rsp), %rax+ movq 0x8(%rsi), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x10(%rsi), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ movq (%rsi), %rax+ addq (%rsp), %rax+ movq 0x8(%rsi), %rcx+ adcq 0x8(%rsp), %rcx+ movq 0x10(%rsi), %r8+ adcq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ adcq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ subq %r11, %rax+ movq %rax, 0x40(%rsp)+ sbbq %r10, %rcx+ movq %rcx, 0x48(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x50(%rsp)+ sbbq %rdx, %r9+ movq %r9, 0x58(%rsp)+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rdx+ mulxq 0x40(%rsp), %r8, %r9+ mulxq 0x48(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x50(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x58(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x68(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x58(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x70(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x58(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x78(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x58(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ xorq %r11, %r11+ movq 0x20(%rsi), %rax+ addq 0x40(%rsi), %rax+ movq 0x28(%rsi), %rcx+ adcq 0x48(%rsi), %rcx+ movq 0x30(%rsi), %r8+ adcq 0x50(%rsi), %r8+ movq 0x38(%rsi), %r9+ adcq 0x58(%rsi), %r9+ adcq %r11, %r11+ subq $0xffffffffffffffff, %rax+ movl $0xffffffff, %r10d+ sbbq %r10, %rcx+ sbbq $0x0, %r8+ movq $0xffffffff00000001, %rdx+ sbbq %rdx, %r9+ sbbq $0x0, %r11+ andq %r11, %r10+ andq %r11, %rdx+ addq %r11, %rax+ movq %rax, 0x40(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x48(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x50(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x58(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rsp), %rdx+ mulxq (%rsi), %r8, %r9+ mulxq 0x8(%rsi), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsi), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x60(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x68(%rsp), %r9, %r10+ mulxq 0x78(%rsp), %r11, %r12+ movq 0x70(%rsp), %rdx+ mulxq 0x78(%rsp), %r13, %r14+ xorl %ebp, %ebp+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x78(%rsp), %rdx+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ xorl %ebp, %ebp+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x68(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x70(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x78(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ movl %ebp, %r9d+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ addq %r9, %r14+ adcq %rbp, %r15+ movl %ebp, %r8d+ adcq %rbp, %r8+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rbp), %rbp+ movq %rbp, %rax+ adcq %r14, %rbp+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %rbp, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq 0x40(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x48(%rsp), %r9, %r10+ mulxq 0x58(%rsp), %r11, %r12+ movq 0x50(%rsp), %rdx+ mulxq 0x58(%rsp), %r13, %r14+ xorl %ebp, %ebp+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x58(%rsp), %rdx+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ xorl %ebp, %ebp+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x48(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x50(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x58(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ movl %ebp, %r9d+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ addq %r9, %r14+ adcq %rbp, %r15+ movl %ebp, %r8d+ adcq %rbp, %r8+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rbp), %rbp+ movq %rbp, %rax+ adcq %r14, %rbp+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %rbp, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq $0xffffffffffffffff, %r8+ xorl %r10d, %r10d+ subq 0xa0(%rsp), %r8+ movq $0xffffffff, %r9+ sbbq 0xa8(%rsp), %r9+ sbbq 0xb0(%rsp), %r10+ movq $0xffffffff00000001, %r11+ sbbq 0xb8(%rsp), %r11+ xorl %r12d, %r12d+ movq $0x9, %rdx+ mulxq %r8, %r8, %rax+ mulxq %r9, %r9, %rcx+ addq %rax, %r9+ mulxq %r10, %r10, %rax+ adcq %rcx, %r10+ mulxq %r11, %r11, %rcx+ adcq %rax, %r11+ adcq %rcx, %r12+ movq $0xc, %rdx+ xorl %eax, %eax+ mulxq 0x80(%rsp), %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ mulxq 0x88(%rsp), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq 0x90(%rsp), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ mulxq 0x98(%rsp), %rax, %rdx+ adcxq %rax, %r11+ adoxq %r12, %rdx+ adcq $0x1, %rdx+ addq %rdx, %r8+ movq $0x100000000, %rax+ mulxq %rax, %rax, %rcx+ sbbq $0x0, %rax+ sbbq $0x0, %rcx+ subq %rax, %r9+ sbbq %rcx, %r10+ movq $0xffffffff00000001, %rax+ mulxq %rax, %rax, %rcx+ sbbq %rax, %r11+ sbbq %rcx, %rdx+ decq %rdx+ movl $0xffffffff, %eax+ andq %rdx, %rax+ xorl %ecx, %ecx+ subq %rax, %rcx+ addq %rdx, %r8+ movq %r8, 0xa0(%rsp)+ adcq %rax, %r9+ movq %r9, 0xa8(%rsp)+ adcq $0x0, %r10+ movq %r10, 0xb0(%rsp)+ adcq %rcx, %r11+ movq %r11, 0xb8(%rsp)+ movq 0x40(%rsp), %rax+ subq (%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x40(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x48(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x50(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x58(%rsp)+ movq 0x20(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x28(%rsp), %r9, %r10+ mulxq 0x38(%rsp), %r11, %r12+ movq 0x30(%rsp), %rdx+ mulxq 0x38(%rsp), %r13, %r14+ xorl %ebp, %ebp+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsp), %rdx+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ xorl %ebp, %ebp+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x28(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x30(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x38(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ movl %ebp, %r9d+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ addq %r9, %r14+ adcq %rbp, %r15+ movl %ebp, %r8d+ adcq %rbp, %r8+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rbp), %rbp+ movq %rbp, %rax+ adcq %r14, %rbp+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %rbp, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rdx+ mulxq 0xa0(%rsp), %r8, %r9+ mulxq 0xa8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0xb0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xb8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x68(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x70(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x78(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x20(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x28(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x30(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x38(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x40(%rdi)+ adcq %r10, %rcx+ movq %rcx, 0x48(%rdi)+ adcq $0x0, %r8+ movq %r8, 0x50(%rdi)+ adcq %rdx, %r9+ movq %r9, 0x58(%rdi)+ movq 0x98(%rsp), %r11+ movq %r11, %rdx+ movq 0x90(%rsp), %r10+ shldq $0x2, %r10, %r11+ movq 0x88(%rsp), %r9+ shldq $0x2, %r9, %r10+ movq 0x80(%rsp), %r8+ shldq $0x2, %r8, %r9+ shlq $0x2, %r8+ shrq $0x3e, %rdx+ addq $0x1, %rdx+ subq 0xa0(%rsp), %r8+ sbbq 0xa8(%rsp), %r9+ sbbq 0xb0(%rsp), %r10+ sbbq 0xb8(%rsp), %r11+ sbbq $0x0, %rdx+ addq %rdx, %r8+ movq $0x100000000, %rax+ mulxq %rax, %rax, %rcx+ sbbq $0x0, %rax+ sbbq $0x0, %rcx+ subq %rax, %r9+ sbbq %rcx, %r10+ movq $0xffffffff00000001, %rax+ mulxq %rax, %rax, %rcx+ sbbq %rax, %r11+ sbbq %rcx, %rdx+ decq %rdx+ movl $0xffffffff, %eax+ andq %rdx, %rax+ xorl %ecx, %ecx+ subq %rax, %rcx+ addq %rdx, %r8+ movq %r8, (%rdi)+ adcq %rax, %r9+ movq %r9, 0x8(%rdi)+ adcq $0x0, %r10+ movq %r10, 0x10(%rdi)+ adcq %rcx, %r11+ movq %r11, 0x18(%rdi)+ movq $0xffffffffffffffff, %r8+ xorl %r10d, %r10d+ subq (%rsp), %r8+ movq $0xffffffff, %r9+ sbbq 0x8(%rsp), %r9+ sbbq 0x10(%rsp), %r10+ movq $0xffffffff00000001, %r11+ sbbq 0x18(%rsp), %r11+ movq %r11, %r12+ shldq $0x3, %r10, %r11+ shldq $0x3, %r9, %r10+ shldq $0x3, %r8, %r9+ shlq $0x3, %r8+ shrq $0x3d, %r12+ movq $0x3, %rdx+ xorl %eax, %eax+ mulxq 0x60(%rsp), %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ mulxq 0x68(%rsp), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq 0x70(%rsp), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ mulxq 0x78(%rsp), %rax, %rdx+ adcxq %rax, %r11+ adoxq %r12, %rdx+ adcq $0x1, %rdx+ addq %rdx, %r8+ movq $0x100000000, %rax+ mulxq %rax, %rax, %rcx+ sbbq $0x0, %rax+ sbbq $0x0, %rcx+ subq %rax, %r9+ sbbq %rcx, %r10+ movq $0xffffffff00000001, %rax+ mulxq %rax, %rax, %rcx+ sbbq %rax, %r11+ sbbq %rcx, %rdx+ decq %rdx+ movl $0xffffffff, %eax+ andq %rdx, %rax+ xorl %ecx, %ecx+ subq %rax, %rcx+ addq %rdx, %r8+ movq %r8, 0x20(%rdi)+ adcq %rax, %r9+ movq %r9, 0x28(%rdi)+ adcq $0x0, %r10+ movq %r10, 0x30(%rdi)+ adcq %rcx, %r11+ movq %r11, 0x38(%rdi)+ CFI_INC_RSP(192)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_local_p256_montjmixadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(192)+ movq %rdx, %rbp+ movq 0x40(%rsi), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x48(%rsi), %r9, %r10+ mulxq 0x58(%rsi), %r11, %r12+ movq 0x50(%rsi), %rdx+ mulxq 0x58(%rsi), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x58(%rsi), %rdx+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x48(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x50(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x58(%rsi), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %r8d+ leaq -0x1(%rdx), %rdx+ leaq -0x1(%rcx), %rax+ movl $0xfffffffe, %r11d+ cmoveq %rcx, %r8+ cmoveq %rcx, %rdx+ cmoveq %rcx, %rax+ cmoveq %rcx, %r11+ addq %r8, %r12+ adcq %rdx, %r13+ adcq %rax, %r14+ adcq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rbp), %rdx+ mulxq 0x40(%rsi), %r8, %r9+ mulxq 0x48(%rsi), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x50(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x58(%rsi), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rbp), %rdx+ xorl %r14d, %r14d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x58(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rbp), %rdx+ xorl %r8d, %r8d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x58(%rsi), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rbp), %rdx+ xorl %r9d, %r9d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x58(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ xorl %r13d, %r13d+ movq 0x0(%rbp), %rdx+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rbp), %rdx+ xorl %r14d, %r14d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rbp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rbp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rsp), %rdx+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0x40(%rsp), %rax+ subq (%rsi), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x8(%rsi), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x10(%rsi), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x18(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0xa0(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0xa8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0xb0(%rsp)+ adcq %rdx, %r9+ movq %r9, 0xb8(%rsp)+ movq 0x20(%rsp), %rax+ subq 0x20(%rsi), %rax+ movq 0x28(%rsp), %rcx+ sbbq 0x28(%rsi), %rcx+ movq 0x30(%rsp), %r8+ sbbq 0x30(%rsi), %r8+ movq 0x38(%rsp), %r9+ sbbq 0x38(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x20(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x28(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x30(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x38(%rsp)+ movq 0xa0(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0xa8(%rsp), %r9, %r10+ mulxq 0xb8(%rsp), %r11, %r12+ movq 0xb0(%rsp), %rdx+ mulxq 0xb8(%rsp), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0xb8(%rsp), %rdx+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0xa8(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0xb0(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0xb8(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %r8d+ leaq -0x1(%rdx), %rdx+ leaq -0x1(%rcx), %rax+ movl $0xfffffffe, %r11d+ cmoveq %rcx, %r8+ cmoveq %rcx, %rdx+ cmoveq %rcx, %rax+ cmoveq %rcx, %r11+ addq %r8, %r12+ adcq %rdx, %r13+ adcq %rax, %r14+ adcq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x20(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x28(%rsp), %r9, %r10+ mulxq 0x38(%rsp), %r11, %r12+ movq 0x30(%rsp), %rdx+ mulxq 0x38(%rsp), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsp), %rdx+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x28(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x30(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x38(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %ebx+ addq %r12, %rbx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rcx), %rcx+ movq %rcx, %rax+ adcq %r14, %rcx+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rbx, %r12+ cmovbq %rdx, %r13+ cmovbq %rcx, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ xorl %r13d, %r13d+ movq (%rsi), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x48(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x50(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x58(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq (%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ xorl %r13d, %r13d+ movq 0x40(%rsi), %rdx+ mulxq 0xa0(%rsp), %r8, %r9+ mulxq 0xa8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0xb0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xb8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x48(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x50(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x58(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq (%rsp), %rax+ subq 0x40(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x48(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x50(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x58(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x80(%rsp), %rax+ subq (%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rsi), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ xorl %r13d, %r13d+ movq 0x80(%rsp), %rdx+ mulxq 0x20(%rsp), %r8, %r9+ mulxq 0x28(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x30(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x38(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x88(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x90(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x38(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x98(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x38(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x80(%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x68(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x40(%rsi), %rax+ movq 0x48(%rsi), %rdx+ orq 0x50(%rsi), %rax+ orq 0x58(%rsi), %rdx+ orq %rdx, %rax+ movq (%rsp), %r8+ movq 0x0(%rbp), %rax+ cmoveq %rax, %r8+ movq 0x8(%rsp), %r9+ movq 0x8(%rbp), %rax+ cmoveq %rax, %r9+ movq 0x10(%rsp), %r10+ movq 0x10(%rbp), %rax+ cmoveq %rax, %r10+ movq 0x18(%rsp), %r11+ movq 0x18(%rbp), %rax+ cmoveq %rax, %r11+ movq 0x80(%rsp), %r12+ movq 0x20(%rbp), %rax+ cmoveq %rax, %r12+ movq 0x88(%rsp), %r13+ movq 0x28(%rbp), %rax+ cmoveq %rax, %r13+ movq 0x90(%rsp), %r14+ movq 0x30(%rbp), %rax+ cmoveq %rax, %r14+ movq 0x98(%rsp), %r15+ movq 0x38(%rbp), %rax+ cmoveq %rax, %r15+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %r12, 0x20(%rdi)+ movq %r13, 0x28(%rdi)+ movq %r14, 0x30(%rdi)+ movq %r15, 0x38(%rdi)+ movq 0xa0(%rsp), %r8+ movq 0xa8(%rsp), %r9+ movq 0xb0(%rsp), %r10+ movq 0xb8(%rsp), %r11+ movl $0x1, %eax+ cmoveq %rax, %r8+ movq $0xffffffff00000000, %rax+ cmoveq %rax, %r9+ movq $0xffffffffffffffff, %rax+ cmoveq %rax, %r10+ movl $0xfffffffe, %eax+ cmoveq %rax, %r11+ movq %r8, 0x40(%rdi)+ movq %r9, 0x48(%rdi)+ movq %r10, 0x50(%rdi)+ movq %r11, 0x58(%rdi)+ CFI_INC_RSP(192)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_scalarmul_alt.S view
@@ -0,0 +1,8672 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for P-256+// Input scalar[4], point[8]; output res[8]+//+// extern void p256_scalarmul_alt+// (uint64_t res[static 8],const uint64_t scalar[static 4],+// const uint64_t point[static 8]);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, returns the point (X,Y) = n * P. The input and output+// are affine points, and in the case of the point at infinity as+// the result, (0,0) is returned.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmul_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmul_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmul_alt)++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on the table, which is no longer needed at the end.+// Uppercase syntactic variants make x86_att version simpler to generate++#define SCALARB (0*NUMSIZE)+#define scalarb (0*NUMSIZE)(%rsp)+#define ACC (1*NUMSIZE)+#define acc (1*NUMSIZE)(%rsp)+#define TABENT (4*NUMSIZE)+#define tabent (4*NUMSIZE)(%rsp)++#define TAB (7*NUMSIZE)+#define tab (7*NUMSIZE)(%rsp)++#define Z2 (7*NUMSIZE)+#define z2 (7*NUMSIZE)(%rsp)+#define Z3 (8*NUMSIZE)+#define z3 (8*NUMSIZE)(%rsp)++#define res (31*NUMSIZE)(%rsp)++#define NSPACE 32*NUMSIZE++S2N_BN_SYMBOL(p256_scalarmul_alt):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ CFI_CALL(Lp256_scalarmul_alt_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmul_alt)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmul_alt_standard)++Lp256_scalarmul_alt_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the "res" and "point" input arguments. We load and process the+// scalar immediately so we don't bother preserving that input argument.+// Also, "point" is only needed early on and so its register gets re-used.++ movq %rdx, %rbx+ movq %rdi, res++// Load the digits of group order n_256 = [%r15;%r14;%r13;%r12]++ movq $0xf3b9cac2fc632551, %r12+ movq $0xbce6faada7179e84, %r13+ movq $0xffffffffffffffff, %r14+ movq $0xffffffff00000000, %r15++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256++ movq (%rsi), %r8+ subq %r12, %r8+ movq 8(%rsi), %r9+ sbbq %r13, %r9+ movq 16(%rsi), %r10+ sbbq %r14, %r10+ movq 24(%rsi), %r11+ sbbq %r15, %r11++ cmovcq (%rsi), %r8+ cmovcq 8(%rsi), %r9+ cmovcq 16(%rsi), %r10+ cmovcq 24(%rsi), %r11++// Now if the top bit of the reduced scalar is set, negate it mod n_256,+// i.e. do n |-> n_256 - n. Remember the sign in %rbp so we can+// correspondingly negate the point below.++ subq %r8, %r12+ sbbq %r9, %r13+ sbbq %r10, %r14+ sbbq %r11, %r15++ movq %r11, %rbp+ shrq $63, %rbp+ cmovnzq %r12, %r8+ cmovnzq %r13, %r9+ cmovnzq %r14, %r10+ cmovnzq %r15, %r11++// In either case then add the recoding constant 0x08888...888 to allow+// signed digits.++ movq $0x8888888888888888, %rax+ addq %rax, %r8+ adcq %rax, %r9+ adcq %rax, %r10+ adcq %rax, %r11+ btc $63, %r11++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)++// Set the tab[0] table entry to Montgomery-Jacobian point = 1 * P+// The z coordinate is just the Montgomery form of the constant 1.++ leaq TAB(%rsp), %rdi+ movq %rbx, %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_tomont_p256)++ leaq 32(%rbx), %rsi+ leaq TAB+32(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_alt_local_tomont_p256)++ movl $1, %eax+ movq %rax, TAB+64(%rsp)+ movq $0xffffffff00000000, %rdx+ movq %rdx, TAB+72(%rsp)+ subq $2, %rax+ movq %rax, TAB+80(%rsp)+ movq $0x00000000fffffffe, %rax+ movq %rax, TAB+88(%rsp)++// If the top bit of the scalar was set, negate (y coordinate of) the point++ movq TAB+32(%rsp), %r12+ movq TAB+40(%rsp), %r13+ movq TAB+48(%rsp), %r14+ movq TAB+56(%rsp), %r15++ xorl %r10d, %r10d+ leaq -1(%r10), %r8+ movq $0x00000000ffffffff, %r11+ movq %r11, %r9+ negq %r11++ subq %r12, %r8+ sbbq %r13, %r9+ sbbq %r14, %r10+ sbbq %r15, %r11++ testq %rbp, %rbp+ cmovzq %r12, %r8+ cmovzq %r13, %r9+ cmovzq %r14, %r10+ cmovzq %r15, %r11++ movq %r8, TAB+32(%rsp)+ movq %r9, TAB+40(%rsp)+ movq %r10, TAB+48(%rsp)+ movq %r11, TAB+56(%rsp)++// Compute and record tab[1] = 2 * p, ..., tab[7] = 8 * P++ leaq TAB+96*1(%rsp), %rdi+ leaq TAB(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++ leaq TAB+96*2(%rsp), %rdi+ leaq TAB+96*1(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjmixadd)++ leaq TAB+96*3(%rsp), %rdi+ leaq TAB+96*1(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++ leaq TAB+96*4(%rsp), %rdi+ leaq TAB+96*3(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjmixadd)++ leaq TAB+96*5(%rsp), %rdi+ leaq TAB+96*2(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++ leaq TAB+96*6(%rsp), %rdi+ leaq TAB+96*5(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjmixadd)++ leaq TAB+96*7(%rsp), %rdi+ leaq TAB+96*3(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++// Set up accumulator as table entry for top 4 bits (constant-time indexing)++ movq SCALARB+24(%rsp), %rdi+ shrq $60, %rdi++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ .set I, 1+.rep 8+ cmpq $I, %rdi++ cmovzq TAB+96*(I-1)(%rsp), %rax+ cmovzq TAB+96*(I-1)+8(%rsp), %rbx+ cmovzq TAB+96*(I-1)+16(%rsp), %rcx+ cmovzq TAB+96*(I-1)+24(%rsp), %rdx+ cmovzq TAB+96*(I-1)+32(%rsp), %r8+ cmovzq TAB+96*(I-1)+40(%rsp), %r9+ cmovzq TAB+96*(I-1)+48(%rsp), %r10+ cmovzq TAB+96*(I-1)+56(%rsp), %r11+ cmovzq TAB+96*(I-1)+64(%rsp), %r12+ cmovzq TAB+96*(I-1)+72(%rsp), %r13+ cmovzq TAB+96*(I-1)+80(%rsp), %r14+ cmovzq TAB+96*(I-1)+88(%rsp), %r15+ .set I, (I+1)+.endr+ movq %rax, ACC(%rsp)+ movq %rbx, ACC+8(%rsp)+ movq %rcx, ACC+16(%rsp)+ movq %rdx, ACC+24(%rsp)+ movq %r8, ACC+32(%rsp)+ movq %r9, ACC+40(%rsp)+ movq %r10, ACC+48(%rsp)+ movq %r11, ACC+56(%rsp)+ movq %r12, ACC+64(%rsp)+ movq %r13, ACC+72(%rsp)+ movq %r14, ACC+80(%rsp)+ movq %r15, ACC+88(%rsp)++// Main loop over size-4 bitfield++ movl $252, %ebp++Lp256_scalarmul_alt_loop:+ subq $4, %rbp++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjdouble)++ movq %rbp, %rax+ shrq $6, %rax+ movq (%rsp,%rax,8), %rdi+ movq %rbp, %rcx+ shrq %cl, %rdi+ andq $15, %rdi++ subq $8, %rdi+ sbbq %rsi, %rsi // %rsi = sign of digit (-1 = negative)+ xorq %rsi, %rdi+ subq %rsi, %rdi // %rdi = absolute value of digit++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ .set I, 1+.rep 8+ cmpq $I, %rdi++ cmovzq TAB+96*(I-1)(%rsp), %rax+ cmovzq TAB+96*(I-1)+8(%rsp), %rbx+ cmovzq TAB+96*(I-1)+16(%rsp), %rcx+ cmovzq TAB+96*(I-1)+24(%rsp), %rdx+ cmovzq TAB+96*(I-1)+32(%rsp), %r8+ cmovzq TAB+96*(I-1)+40(%rsp), %r9+ cmovzq TAB+96*(I-1)+48(%rsp), %r10+ cmovzq TAB+96*(I-1)+56(%rsp), %r11+ cmovzq TAB+96*(I-1)+64(%rsp), %r12+ cmovzq TAB+96*(I-1)+72(%rsp), %r13+ cmovzq TAB+96*(I-1)+80(%rsp), %r14+ cmovzq TAB+96*(I-1)+88(%rsp), %r15+ .set I, (I+1)+.endr++ movq %r12, TABENT+64(%rsp)+ movq %r13, TABENT+72(%rsp)+ movq %r14, TABENT+80(%rsp)+ movq %r15, TABENT+88(%rsp)++ xorl %r14d, %r14d+ leaq -1(%r14), %r12+ movq $0x00000000ffffffff, %r15+ movq %r15, %r13+ negq %r15++ subq %r8, %r12+ sbbq %r9, %r13+ sbbq %r10, %r14+ sbbq %r11, %r15++ testq %rsi, %rsi+ cmovnzq %r12, %r8+ cmovnzq %r13, %r9+ cmovnzq %r14, %r10+ cmovnzq %r15, %r11++ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)++ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+48(%rsp)+ movq %r11, TABENT+56(%rsp)++ leaq TABENT(%rsp), %rdx+ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp256_scalarmul_alt_local_p256_montjadd)++ testq %rbp, %rbp+ jne Lp256_scalarmul_alt_loop++// Let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_montsqr_p256)++ leaq Z3(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_alt_local_montmul_p256)++ leaq Z2(%rsp), %rdi+ leaq Z3(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_demont_p256)++ leaq Z3(%rsp), %rdi+ leaq Z2(%rsp), %rsi+ CFI_CALL(Lp256_scalarmul_alt_local_inv_p256)++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_alt_local_montmul_p256)++// Convert back from Jacobian (X, Y, Z) |-> (X/Z^2, Y/Z^3)++ movq res, %rdi+ leaq ACC(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ movq %rdi, %rbx+ CFI_CALL(Lp256_scalarmul_alt_local_montmul_p256)++ leaq 32(%rbx), %rdi+ leaq ACC+32(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmul_alt_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmul_alt_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p256_scalarmul_alt)+#endif++// Local copies of subroutines, complete clones at the moment++Lp256_scalarmul_alt_local_demont_p256:+ CFI_START+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ movabsq $0x100000000, %rcx+ movq %r8, %rax+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rsi, %rsi+ movq %r9, %rax+ mulq %rcx+ subq %rsi, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rsi, %rsi+ negq %rcx+ negq %rsi+ incq %rcx+ movq %r8, %rax+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %rsi+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rax+ mulq %rcx+ addq %rax, %rsi+ adcq %rdx, %r8+ negq %rcx+ incq %rcx+ movq %r10, %rax+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %rsi+ sbbq %r9, %r9+ movq %r11, %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %rsi+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %rcx+ negq %r9+ incq %rcx+ movq %r10, %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rax+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ movq %rsi, (%rdi)+ movq %r8, 0x8(%rdi)+ movq %r9, 0x10(%rdi)+ movq %r10, 0x18(%rdi)+ CFI_RET++Lp256_scalarmul_alt_local_inv_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(240)+ movq %rdi, 0xe0(%rsp)+ xorl %ecx, %ecx+ movl $0xffffffff, %edx+ movq %rdx, %rbx+ leaq -0x1(%rcx), %rax+ negq %rdx+ movq %rax, (%rsp)+ movq %rbx, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rdx, 0x18(%rsp)+ movq %rcx, 0x20(%rsp)+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ leaq 0x1(%rcx), %rax+ addq %r8, %rax+ leaq -0x1(%rdx), %rbx+ adcq %r9, %rbx+ notq %rcx+ adcq %r10, %rcx+ notq %rdx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq %rax, 0x28(%rsp)+ movq %rbx, 0x30(%rsp)+ movq %rcx, 0x38(%rsp)+ movq %rdx, 0x40(%rsp)+ xorl %eax, %eax+ movq %rax, 0x48(%rsp)+ xorl %eax, %eax+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movq %rax, 0x60(%rsp)+ movq %rax, 0x68(%rsp)+ movabsq $0x4000000000000, %rcx+ movq %rcx, 0x78(%rsp)+ movq %rax, 0x80(%rsp)+ movq %rax, 0x88(%rsp)+ movq %rax, 0x90(%rsp)+ movq $0xa, 0xb0(%rsp)+ movq $0x1, 0xb8(%rsp)+ jmp Lp256_scalarmul_alt_inv_midloop+Lp256_scalarmul_alt_inv_loop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0xa0(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0xa8(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x28(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x30(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq 0x20(%rsp), %rbp+ xorq %r9, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x40(%rsp), %rax+ xorq %r11, %rax+ movq 0x48(%rsp), %rdx+ xorq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ sarq $0x3b, %rbp+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ movq 0x20(%rsp), %rsi+ movq %rbp, 0x20(%rsp)+ xorq %r13, %rax+ xorq %r13, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x40(%rsp), %rax+ xorq %r15, %rax+ movq 0x48(%rsp), %rdx+ xorq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x38(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x40(%rsp)+ sarq $0x3b, %rsi+ movq %rsi, 0x48(%rsp)+ movq 0xa0(%rsp), %rbx+ movq 0xa8(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x78(%rsp)+ xorl %ebx, %ebx+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x58(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x58(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x80(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x80(%rsp)+ xorl %ecx, %ecx+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x60(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x60(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x88(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x88(%rsp)+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq 0x68(%rsp), %rax+ movq %rcx, 0x68(%rsp)+ movq %rdx, 0x70(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x90(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rsi, 0x90(%rsp)+ movq %rdx, 0x98(%rsp)+ movabsq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movabsq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movabsq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movabsq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movabsq $0xe000000000000000, %r8+ addq 0x78(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x80(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x88(%rsp), %r10+ movabsq $0x2000000000000000, %r11+ adcq 0x90(%rsp), %r11+ movabsq $0x1fffffffe0000000, %r12+ adcq 0x98(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movabsq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x78(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x80(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x88(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x90(%rsp)+Lp256_scalarmul_alt_inv_midloop:+ movq 0xb8(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x28(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xc0(%rsp)+ movq %rbx, 0xc8(%rsp)+ movq %rdi, 0xd0(%rsp)+ movq %rcx, 0xd8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x28(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xc0(%rsp), %rax+ imulq %r8, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xc8(%rsp), %r8+ imulq 0xd8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xc0(%rsp), %rax+ imulq %r10, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xc8(%rsp), %r10+ imulq 0xd8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0xb8(%rsp)+ decq 0xb0(%rsp)+ jne Lp256_scalarmul_alt_inv_loop+ movq (%rsp), %rax+ movq 0x28(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r12, 0x50(%rsp)+ movq %r13, 0x58(%rsp)+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r9, 0x70(%rsp)+ movabsq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movabsq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movabsq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movabsq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movq 0x50(%rsp), %r8+ movq 0x58(%rsp), %r9+ movq 0x60(%rsp), %r10+ movq 0x68(%rsp), %r11+ movl $0x1, %eax+ movl $0xffffffff, %ebx+ leaq -0x2(%rax), %rcx+ leaq -0x1(%rbx), %rdx+ notq %rbx+ addq %r8, %rax+ adcq %r9, %rbx+ adcq %r10, %rcx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq 0xe0(%rsp), %rdi+ movq %rax, (%rdi)+ movq %rbx, 0x8(%rdi)+ movq %rcx, 0x10(%rdi)+ movq %rdx, 0x18(%rdi)+ CFI_INC_RSP(240)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_alt_local_montmul_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq %rdx, %rcx+ movq (%rcx), %rbx+ movq (%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rcx), %rbx+ xorl %r13d, %r13d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rcx), %rbx+ xorl %r15d, %r15d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rcx), %rbx+ xorl %r8d, %r8d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_alt_local_montsqr_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq (%rsi), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x8(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x18(%rsi), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x10(%rsi), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x18(%rsi), %rbx+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x8(%rsi), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x10(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x18(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_RET+++Lp256_scalarmul_alt_local_tomont_p256:+ CFI_START+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movl $0x3, %ecx+ movq (%rsi), %rax+ mulq %rcx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsi), %rax+ mulq %rcx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsi), %rax+ mulq %rcx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsi), %rax+ mulq %rcx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movabsq $0xfffffffbffffffff, %rcx+ xorl %r13d, %r13d+ movq (%rsi), %rax+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsi), %rax+ mulq %rcx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsi), %rax+ mulq %rcx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsi), %rax+ mulq %rcx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rcx+ movq %r8, %rax+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rcx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rcx+ leaq 0x2(%rcx), %rcx+ movq %r8, %rax+ mulq %rcx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rcx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq $0xfffffffffffffffe, %rcx+ xorl %r15d, %r15d+ movq (%rsi), %rax+ mulq %rcx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsi), %rax+ mulq %rcx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsi), %rax+ mulq %rcx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsi), %rax+ mulq %rcx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movabsq $0x4fffffffd, %rcx+ xorl %r8d, %r8d+ movq (%rsi), %rax+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsi), %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsi), %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsi), %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rcx+ movq %r10, %rax+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq %r11, %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ notq %rcx+ leaq 0x2(%rcx), %rcx+ movq %r10, %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq %r11, %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ subq %r9, %r8+ xorl %edx, %edx+ leaq -0x1(%rdx), %r9+ incq %rdx+ addq %r12, %rdx+ decq %rcx+ adcq %r13, %rcx+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rdx, %r12+ cmovbq %rcx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_RET++Lp256_scalarmul_alt_local_p256_montjadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(224)+ movq %rdx, %rbp+ movq 0x40(%rsi), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x48(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x58(%rsi), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x50(%rsi), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x58(%rsi), %rbx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x50(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x58(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x40(%rbp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x48(%rbp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x58(%rbp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x50(%rbp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x40(%rbp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x48(%rbp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x58(%rbp), %rbx+ movq 0x48(%rbp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x48(%rbp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x50(%rbp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x58(%rbp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq 0x20(%rsi), %rbx+ movq 0x40(%rbp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x48(%rbp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x50(%rbp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x58(%rbp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0x40(%rbp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x48(%rbp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x50(%rbp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x58(%rbp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0x40(%rbp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x48(%rbp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x50(%rbp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x58(%rbp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0x40(%rbp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x48(%rbp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x50(%rbp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x58(%rbp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xc0(%rsp)+ movq %r13, 0xc8(%rsp)+ movq %r14, 0xd0(%rsp)+ movq %r15, 0xd8(%rsp)+ movq 0x20(%rbp), %rbx+ movq 0x40(%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x48(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x50(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x58(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rbp), %rbx+ xorl %r13d, %r13d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rbp), %rbx+ xorl %r15d, %r15d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rbp), %rbx+ xorl %r8d, %r8d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0x0(%rbp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rbp), %rbx+ xorl %r13d, %r13d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rbp), %rbx+ xorl %r15d, %r15d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rbp), %rbx+ xorl %r8d, %r8d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq (%rsi), %rbx+ movq 0xa0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x20(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rsp), %rbx+ xorl %r13d, %r13d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rsp), %rbx+ xorl %r15d, %r15d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rsp), %rbx+ xorl %r8d, %r8d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0xc0(%rsp), %rbx+ movq 0xa0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0xc8(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0xd0(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0xd8(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xc0(%rsp)+ movq %r13, 0xc8(%rsp)+ movq %r14, 0xd0(%rsp)+ movq %r15, 0xd8(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0xa0(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0xa8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0xb0(%rsp)+ adcq %rdx, %r9+ movq %r9, 0xb8(%rsp)+ movq 0x20(%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x28(%rsp), %rcx+ sbbq 0xc8(%rsp), %rcx+ movq 0x30(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x38(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x20(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x28(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x30(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x38(%rsp)+ movq 0xa0(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0xa8(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0xb8(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0xb0(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0xb8(%rsp), %rbx+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0xa8(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0xb0(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0xb8(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x20(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x28(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x38(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x30(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x38(%rsp), %rbx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x30(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x38(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x88(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x90(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x98(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x40(%rsp), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x48(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x50(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x58(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq (%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ movq 0x40(%rsi), %rbx+ movq 0xa0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x48(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x50(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x58(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq (%rsp), %rax+ subq 0x40(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x48(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x50(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x58(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x80(%rsp), %rax+ subq (%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0xc0(%rsp), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0xc8(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0xd0(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0xd8(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x40(%rbp), %rbx+ movq 0xa0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x48(%rbp), %rbx+ xorl %r13d, %r13d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x50(%rbp), %rbx+ xorl %r15d, %r15d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x58(%rbp), %rbx+ xorl %r8d, %r8d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x20(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x30(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x38(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x88(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x90(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x98(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x80(%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x68(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x40(%rsi), %r8+ movq 0x48(%rsi), %r9+ movq 0x50(%rsi), %r10+ movq 0x58(%rsi), %r11+ movq %r8, %rax+ movq %r9, %rdx+ orq %r10, %rax+ orq %r11, %rdx+ orq %rdx, %rax+ negq %rax+ sbbq %rax, %rax+ movq 0x40(%rbp), %r12+ movq 0x48(%rbp), %r13+ movq 0x50(%rbp), %r14+ movq 0x58(%rbp), %r15+ movq %r12, %rbx+ movq %r13, %rdx+ orq %r14, %rbx+ orq %r15, %rdx+ orq %rdx, %rbx+ negq %rbx+ sbbq %rbx, %rbx+ cmpq %rax, %rbx+ cmovbq %r8, %r12+ cmovbq %r9, %r13+ cmovbq %r10, %r14+ cmovbq %r11, %r15+ cmoveq 0xa0(%rsp), %r12+ cmoveq 0xa8(%rsp), %r13+ cmoveq 0xb0(%rsp), %r14+ cmoveq 0xb8(%rsp), %r15+ movq (%rsp), %rax+ cmovbq (%rsi), %rax+ cmova 0x0(%rbp), %rax+ movq 0x8(%rsp), %rbx+ cmovbq 0x8(%rsi), %rbx+ cmova 0x8(%rbp), %rbx+ movq 0x10(%rsp), %rcx+ cmovbq 0x10(%rsi), %rcx+ cmova 0x10(%rbp), %rcx+ movq 0x18(%rsp), %rdx+ cmovbq 0x18(%rsi), %rdx+ cmova 0x18(%rbp), %rdx+ movq 0x80(%rsp), %r8+ cmovbq 0x20(%rsi), %r8+ cmova 0x20(%rbp), %r8+ movq 0x88(%rsp), %r9+ cmovbq 0x28(%rsi), %r9+ cmova 0x28(%rbp), %r9+ movq 0x90(%rsp), %r10+ cmovbq 0x30(%rsi), %r10+ cmova 0x30(%rbp), %r10+ movq 0x98(%rsp), %r11+ cmovbq 0x38(%rsi), %r11+ cmova 0x38(%rbp), %r11+ movq %rax, (%rdi)+ movq %rbx, 0x8(%rdi)+ movq %rcx, 0x10(%rdi)+ movq %rdx, 0x18(%rdi)+ movq %r8, 0x20(%rdi)+ movq %r9, 0x28(%rdi)+ movq %r10, 0x30(%rdi)+ movq %r11, 0x38(%rdi)+ movq %r12, 0x40(%rdi)+ movq %r13, 0x48(%rdi)+ movq %r14, 0x50(%rdi)+ movq %r15, 0x58(%rdi)+ CFI_INC_RSP(224)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_alt_local_p256_montjdouble:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(192)+ movq 0x40(%rsi), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x48(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x58(%rsi), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x50(%rsi), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x58(%rsi), %rbx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x50(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x58(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x20(%rsi), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x28(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x38(%rsi), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x30(%rsi), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x20(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x28(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x38(%rsi), %rbx+ movq 0x28(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x28(%rsi), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x30(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x38(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq (%rsi), %rax+ subq (%rsp), %rax+ movq 0x8(%rsi), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x10(%rsi), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ movq (%rsi), %rax+ addq (%rsp), %rax+ movq 0x8(%rsi), %rcx+ adcq 0x8(%rsp), %rcx+ movq 0x10(%rsi), %r8+ adcq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ adcq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ subq %r11, %rax+ movq %rax, 0x40(%rsp)+ sbbq %r10, %rcx+ movq %rcx, 0x48(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x50(%rsp)+ sbbq %rdx, %r9+ movq %r9, 0x58(%rsp)+ movq 0x60(%rsp), %rbx+ movq 0x40(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x48(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x50(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x58(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x68(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x70(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x40(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x78(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x40(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ xorq %r11, %r11+ movq 0x20(%rsi), %rax+ addq 0x40(%rsi), %rax+ movq 0x28(%rsi), %rcx+ adcq 0x48(%rsi), %rcx+ movq 0x30(%rsi), %r8+ adcq 0x50(%rsi), %r8+ movq 0x38(%rsi), %r9+ adcq 0x58(%rsi), %r9+ adcq %r11, %r11+ subq $0xffffffffffffffff, %rax+ movl $0xffffffff, %r10d+ sbbq %r10, %rcx+ sbbq $0x0, %r8+ movabsq $0xffffffff00000001, %rdx+ sbbq %rdx, %r9+ sbbq $0x0, %r11+ andq %r11, %r10+ andq %r11, %rdx+ addq %r11, %rax+ movq %rax, 0x40(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x48(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x50(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x58(%rsp)+ movq 0x20(%rsp), %rbx+ movq (%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rsp), %rbx+ xorl %r13d, %r13d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rsp), %rbx+ xorl %r15d, %r15d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rsp), %rbx+ xorl %r8d, %r8d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x60(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x68(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x78(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x70(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x78(%rsp), %rbx+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x68(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x70(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x78(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq 0x40(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x48(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x58(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x50(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x40(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x58(%rsp), %rbx+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x48(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x50(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x58(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq $0xffffffffffffffff, %r9+ xorl %r11d, %r11d+ subq 0xa0(%rsp), %r9+ movabsq $0xffffffff, %r10+ sbbq 0xa8(%rsp), %r10+ sbbq 0xb0(%rsp), %r11+ movabsq $0xffffffff00000001, %r12+ sbbq 0xb8(%rsp), %r12+ movq $0x9, %rcx+ movq %r9, %rax+ mulq %rcx+ movq %rax, %r8+ movq %rdx, %r9+ movq %r10, %rax+ xorl %r10d, %r10d+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ movq %r11, %rax+ xorl %r11d, %r11d+ mulq %rcx+ addq %rax, %r10+ adcq %rdx, %r11+ movq %r12, %rax+ xorl %r12d, %r12d+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %r12+ movl $0xc, %ecx+ movq 0x80(%rsp), %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %rbx, %rbx+ movq 0x88(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rbx, %rbx+ movq 0x90(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbx, %rbx+ movq 0x98(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ leaq 0x1(%r12), %rcx+ movabsq $0xffffffff00000001, %rax+ mulq %rcx+ movq %rcx, %rbx+ shlq $0x20, %rbx+ addq %rcx, %r8+ sbbq $0x0, %rbx+ subq %rbx, %r9+ sbbq $0x0, %r10+ sbbq %rax, %r11+ sbbq %rdx, %rcx+ decq %rcx+ movl $0xffffffff, %eax+ andq %rcx, %rax+ xorl %edx, %edx+ subq %rax, %rdx+ addq %rcx, %r8+ movq %r8, 0xa0(%rsp)+ adcq %rax, %r9+ movq %r9, 0xa8(%rsp)+ adcq $0x0, %r10+ movq %r10, 0xb0(%rsp)+ adcq %rdx, %r11+ movq %r11, 0xb8(%rsp)+ movq 0x40(%rsp), %rax+ subq (%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x40(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x48(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x50(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x58(%rsp)+ movq 0x20(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x28(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x38(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x30(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x38(%rsp), %rbx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x30(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x38(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x60(%rsp), %rbx+ movq 0xa0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x68(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x70(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x78(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x20(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x28(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x30(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x38(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x40(%rdi)+ adcq %r10, %rcx+ movq %rcx, 0x48(%rdi)+ adcq $0x0, %r8+ movq %r8, 0x50(%rdi)+ adcq %rdx, %r9+ movq %r9, 0x58(%rdi)+ movq 0x98(%rsp), %r11+ movq %r11, %rcx+ movq 0x90(%rsp), %r10+ shldq $0x2, %r10, %r11+ movq 0x88(%rsp), %r9+ shldq $0x2, %r9, %r10+ movq 0x80(%rsp), %r8+ shldq $0x2, %r8, %r9+ shlq $0x2, %r8+ shrq $0x3e, %rcx+ addq $0x1, %rcx+ subq 0xa0(%rsp), %r8+ sbbq 0xa8(%rsp), %r9+ sbbq 0xb0(%rsp), %r10+ sbbq 0xb8(%rsp), %r11+ sbbq $0x0, %rcx+ movabsq $0xffffffff00000001, %rax+ mulq %rcx+ movq %rcx, %rbx+ shlq $0x20, %rbx+ addq %rcx, %r8+ sbbq $0x0, %rbx+ subq %rbx, %r9+ sbbq $0x0, %r10+ sbbq %rax, %r11+ sbbq %rdx, %rcx+ decq %rcx+ movl $0xffffffff, %eax+ andq %rcx, %rax+ xorl %edx, %edx+ subq %rax, %rdx+ addq %rcx, %r8+ movq %r8, (%rdi)+ adcq %rax, %r9+ movq %r9, 0x8(%rdi)+ adcq $0x0, %r10+ movq %r10, 0x10(%rdi)+ adcq %rdx, %r11+ movq %r11, 0x18(%rdi)+ movq $0xffffffffffffffff, %r8+ xorl %r10d, %r10d+ subq (%rsp), %r8+ movabsq $0xffffffff, %r9+ sbbq 0x8(%rsp), %r9+ sbbq 0x10(%rsp), %r10+ movabsq $0xffffffff00000001, %r11+ sbbq 0x18(%rsp), %r11+ movq %r11, %r12+ shldq $0x3, %r10, %r11+ shldq $0x3, %r9, %r10+ shldq $0x3, %r8, %r9+ shlq $0x3, %r8+ shrq $0x3d, %r12+ movl $0x3, %ecx+ movq 0x60(%rsp), %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %rbx, %rbx+ movq 0x68(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rbx, %rbx+ movq 0x70(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbx, %rbx+ movq 0x78(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ leaq 0x1(%r12), %rcx+ movabsq $0xffffffff00000001, %rax+ mulq %rcx+ movq %rcx, %rbx+ shlq $0x20, %rbx+ addq %rcx, %r8+ sbbq $0x0, %rbx+ subq %rbx, %r9+ sbbq $0x0, %r10+ sbbq %rax, %r11+ sbbq %rdx, %rcx+ decq %rcx+ movl $0xffffffff, %eax+ andq %rcx, %rax+ xorl %edx, %edx+ subq %rax, %rdx+ addq %rcx, %r8+ movq %r8, 0x20(%rdi)+ adcq %rax, %r9+ movq %r9, 0x28(%rdi)+ adcq $0x0, %r10+ movq %r10, 0x30(%rdi)+ adcq %rdx, %r11+ movq %r11, 0x38(%rdi)+ CFI_INC_RSP(192)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_RET++Lp256_scalarmul_alt_local_p256_montjmixadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(192)+ movq %rdx, %rbp+ movq 0x40(%rsi), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x48(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x58(%rsi), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x50(%rsi), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x58(%rsi), %rbx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x50(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x58(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x20(%rbp), %rbx+ movq 0x40(%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x48(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x50(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x58(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rbp), %rbx+ xorl %r13d, %r13d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rbp), %rbx+ xorl %r15d, %r15d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rbp), %rbx+ xorl %r8d, %r8d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0x0(%rbp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rbp), %rbx+ xorl %r13d, %r13d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rbp), %rbx+ xorl %r15d, %r15d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rbp), %rbx+ xorl %r8d, %r8d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq 0x20(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rsp), %rbx+ xorl %r13d, %r13d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rsp), %rbx+ xorl %r15d, %r15d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rsp), %rbx+ xorl %r8d, %r8d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0x40(%rsp), %rax+ subq (%rsi), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x8(%rsi), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x10(%rsi), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x18(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0xa0(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0xa8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0xb0(%rsp)+ adcq %rdx, %r9+ movq %r9, 0xb8(%rsp)+ movq 0x20(%rsp), %rax+ subq 0x20(%rsi), %rax+ movq 0x28(%rsp), %rcx+ sbbq 0x28(%rsi), %rcx+ movq 0x30(%rsp), %r8+ sbbq 0x30(%rsi), %r8+ movq 0x38(%rsp), %r9+ sbbq 0x38(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x20(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x28(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x30(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x38(%rsp)+ movq 0xa0(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0xa8(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0xb8(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0xb0(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0xb8(%rsp), %rbx+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0xa8(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0xb0(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0xb8(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x20(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x28(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x38(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x30(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x38(%rsp), %rbx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x30(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x38(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq (%rsi), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x40(%rsp), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x48(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x50(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x58(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq (%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ movq 0x40(%rsi), %rbx+ movq 0xa0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x48(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x50(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x58(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq (%rsp), %rax+ subq 0x40(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x48(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x50(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x58(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x80(%rsp), %rax+ subq (%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x20(%rsi), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x20(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x30(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x38(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x88(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x90(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x98(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x80(%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x68(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x40(%rsi), %rax+ movq 0x48(%rsi), %rdx+ orq 0x50(%rsi), %rax+ orq 0x58(%rsi), %rdx+ orq %rdx, %rax+ movq (%rsp), %r8+ movq 0x0(%rbp), %rax+ cmoveq %rax, %r8+ movq 0x8(%rsp), %r9+ movq 0x8(%rbp), %rax+ cmoveq %rax, %r9+ movq 0x10(%rsp), %r10+ movq 0x10(%rbp), %rax+ cmoveq %rax, %r10+ movq 0x18(%rsp), %r11+ movq 0x18(%rbp), %rax+ cmoveq %rax, %r11+ movq 0x80(%rsp), %r12+ movq 0x20(%rbp), %rax+ cmoveq %rax, %r12+ movq 0x88(%rsp), %r13+ movq 0x28(%rbp), %rax+ cmoveq %rax, %r13+ movq 0x90(%rsp), %r14+ movq 0x30(%rbp), %rax+ cmoveq %rax, %r14+ movq 0x98(%rsp), %r15+ movq 0x38(%rbp), %rax+ cmoveq %rax, %r15+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %r12, 0x20(%rdi)+ movq %r13, 0x28(%rdi)+ movq %r14, 0x30(%rdi)+ movq %r15, 0x38(%rdi)+ movq 0xa0(%rsp), %r8+ movq 0xa8(%rsp), %r9+ movq 0xb0(%rsp), %r10+ movq 0xb8(%rsp), %r11+ movl $0x1, %eax+ cmoveq %rax, %r8+ movabsq $0xffffffff00000000, %rax+ cmoveq %rax, %r9+ movq $0xffffffffffffffff, %rax+ cmoveq %rax, %r10+ movl $0xfffffffe, %eax+ cmoveq %rax, %r11+ movq %r8, 0x40(%rdi)+ movq %r9, 0x48(%rdi)+ movq %r10, 0x50(%rdi)+ movq %r11, 0x58(%rdi)+ CFI_INC_RSP(192)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_scalarmulbase.S view
@@ -0,0 +1,3571 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for precomputed point on NIST curve P-256+// Input scalar[4], blocksize, table[]; output res[8]+//+// extern void p256_scalarmulbase+// (uint64_t res[static 8],+// const uint64_t scalar[static 4],+// uint64_t blocksize,+// const uint64_t *table);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, the input argument "table" is expected to be a table of+// multiples of the point P in Montgomery-affine form, with each block+// corresponding to "blocksize" bits of the scalar as follows, where+// B = 2^{blocksize-1} (e.g. B = 8 for blocksize = 4):+//+// For each i,j with blocksize * i <= 256 and 1 <= j <= B+// the multiple 2^{blocksize * i} * j * P is stored at+// tab[8 * (B * i + (j - 1))], considered as uint64_t pointers+// or tab + 64 * (B * i + (j - 1)) as byte pointers.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = blocksize, RCX = table+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = blocksize, R9 = table+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmulbase)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmulbase)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmulbase)+++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on "nacc", which is no longer needed at the end.+// Uppercase syntactic variants make x86_att version simpler to generate++#define RSCALAR (0*NUMSIZE)+#define ACC (1*NUMSIZE)+#define NACC (4*NUMSIZE)+#define TABENT (7*NUMSIZE)+#define Z2 (4*NUMSIZE)+#define Z3 (5*NUMSIZE)++#define rscalar RSCALAR(%rsp)+#define acc ACC(%rsp)+#define nacc NACC(%rsp)+#define tabent TABENT(%rsp)++#define z2 Z2(%rsp)+#define z3 Z3(%rsp)++#define res (9*NUMSIZE)(%rsp)+#define blocksize (9*NUMSIZE+8)(%rsp)+#define table (9*NUMSIZE+16)(%rsp)+#define i (9*NUMSIZE+24)(%rsp)+#define bf (9*NUMSIZE+32)(%rsp)+#define cf (9*NUMSIZE+40)(%rsp)+#define j (9*NUMSIZE+48)(%rsp)++#define NSPACE 11*NUMSIZE++S2N_BN_SYMBOL(p256_scalarmulbase):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ movq %r9, %rcx+ CFI_CALL(Lp256_scalarmulbase_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmulbase)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_standard)++Lp256_scalarmulbase_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the input arguments except the scalar, since that gets absorbed+// immediately. The "table" value subsequently gets shifted up each iteration+// of the loop, while "res" and "blocksize" are static throughout.++ movq %rdi, res+ movq %rdx, blocksize+ movq %rcx, table++// Load the digits of group order n_256 = [%r15;%r14;%r13;%r12]++ movq $0xf3b9cac2fc632551, %r12+ movq $0xbce6faada7179e84, %r13+ movq $0xffffffffffffffff, %r14+ movq $0xffffffff00000000, %r15++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256+// Store it to "rscalar" (reduced scalar)++ movq (%rsi), %r8+ subq %r12, %r8+ movq 8(%rsi), %r9+ sbbq %r13, %r9+ movq 16(%rsi), %r10+ sbbq %r14, %r10+ movq 24(%rsi), %r11+ sbbq %r15, %r11++ cmovcq (%rsi), %r8+ cmovcq 8(%rsi), %r9+ cmovcq 16(%rsi), %r10+ cmovcq 24(%rsi), %r11++ movq %r8, RSCALAR(%rsp)+ movq %r9, RSCALAR+8(%rsp)+ movq %r10, RSCALAR+16(%rsp)+ movq %r11, RSCALAR+24(%rsp)++// Initialize the accumulator to all zeros and the "carry flag" cf to 0++ xorl %eax, %eax++ movq %rax, ACC(%rsp)+ movq %rax, ACC+8(%rsp)+ movq %rax, ACC+16(%rsp)+ movq %rax, ACC+24(%rsp)+ movq %rax, ACC+32(%rsp)+ movq %rax, ACC+40(%rsp)+ movq %rax, ACC+48(%rsp)+ movq %rax, ACC+56(%rsp)+ movq %rax, ACC+64(%rsp)+ movq %rax, ACC+72(%rsp)+ movq %rax, ACC+80(%rsp)+ movq %rax, ACC+88(%rsp)++ movq %rax, cf++// Main loop over {i >= 0 | blocksize * i <= 256}. Note the non-strict+// inequality, to allow top carry for any choices of blocksize.++ movq %rax, i++Lp256_scalarmulbase_loop:++// The next raw bitfield is bf = bitfield(blocksize * i,blocksize) + cf,+// adding in the deferred carry cf. We then shift the whole scalar right+// by blocksize so we can keep picking bitfield(0,blocksize).++ movq RSCALAR(%rsp), %r8+ movq RSCALAR+8(%rsp), %r9+ movq RSCALAR+16(%rsp), %r10+ movq RSCALAR+24(%rsp), %r11++ movq blocksize, %rcx+ movl $1, %eax+ shlq %cl, %rax+ decq %rax+ andq %r8, %rax++ shrdq %cl, %r9, %r8+ shrdq %cl, %r10, %r9+ shrdq %cl, %r11, %r10+ shrq %cl, %r11++ addq cf, %rax+ movq %rax, bf++ movq %r8, RSCALAR(%rsp)+ movq %r9, RSCALAR+8(%rsp)+ movq %r10, RSCALAR+16(%rsp)+ movq %r11, RSCALAR+24(%rsp)++// Now if bf <= B we just select entry j, unnegated and set cf = 0.+// If bf > B we set j = 2 * B - bf and negate the j'th entry, setting cf = 1.+// In either case we ultimately add bf, in the latter case with deferred+// carry as 2 * B - (2 * B - bf) = bf.++ movl $1, %eax+ movq blocksize, %rcx+ shlq %cl, %rax+ movq %rax, %rbx+ shrq $1, %rax++ subq bf, %rbx+ cmpq bf, %rax++ cmovncq bf, %rbx+ sbbq %rax, %rax+ movq %rbx, j+ negq %rax+ movq %rax, cf++// Load table entry j - 1 for nonzero j in constant-time style.++ movq blocksize, %rcx+ decq %rcx+ movl $1, %esi+ shlq %cl, %rsi+ movq j, %r12+ movq table, %rbp++Lp256_scalarmulbase_tabloop:+ subq $1, %r12+ cmovzq (%rbp), %rax+ cmovzq 8(%rbp), %rbx+ cmovzq 16(%rbp), %rcx+ cmovzq 24(%rbp), %rdx+ cmovzq 32(%rbp), %r8+ cmovzq 40(%rbp), %r9+ cmovzq 48(%rbp), %r10+ cmovzq 56(%rbp), %r11++ addq $64, %rbp+ decq %rsi+ jnz Lp256_scalarmulbase_tabloop++ movq %rbp, table++// Before storing back, optionally negate the y coordinate of the table entry++ xorl %r14d, %r14d+ leaq -1(%r14), %r12+ movq $0x00000000ffffffff, %r15+ movq %r15, %r13+ negq %r15++ subq %r8, %r12+ sbbq %r9, %r13+ sbbq %r10, %r14+ sbbq %r11, %r15++ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)++ movq cf, %rax+ testq %rax, %rax+ cmovnzq %r12, %r8+ cmovnzq %r13, %r9+ cmovnzq %r14, %r10+ cmovnzq %r15, %r11++ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+48(%rsp)+ movq %r11, TABENT+56(%rsp)++// Add the adjusted table point to the accumulator++ leaq NACC(%rsp), %rdi+ leaq ACC(%rsp), %rsi+ leaq TABENT(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_local_p256_montjmixadd)++// However, only commit that update to the accumulator if j is nonzero,+// because the mixed addition function does not handle this case directly,+// and in any case we didn't choose the table entry appropriately.++ movq j, %rax+ testq %rax, %rax++ movq ACC(%rsp), %rax+ cmovnzq NACC(%rsp), %rax+ movq %rax, ACC(%rsp)++ movq ACC+8(%rsp), %rax+ cmovnzq NACC+8(%rsp), %rax+ movq %rax, ACC+8(%rsp)++ movq ACC+16(%rsp), %rax+ cmovnzq NACC+16(%rsp), %rax+ movq %rax, ACC+16(%rsp)++ movq ACC+24(%rsp), %rax+ cmovnzq NACC+24(%rsp), %rax+ movq %rax, ACC+24(%rsp)++ movq ACC+32(%rsp), %rax+ cmovnzq NACC+32(%rsp), %rax+ movq %rax, ACC+32(%rsp)++ movq ACC+40(%rsp), %rax+ cmovnzq NACC+40(%rsp), %rax+ movq %rax, ACC+40(%rsp)++ movq ACC+48(%rsp), %rax+ cmovnzq NACC+48(%rsp), %rax+ movq %rax, ACC+48(%rsp)++ movq ACC+56(%rsp), %rax+ cmovnzq NACC+56(%rsp), %rax+ movq %rax, ACC+56(%rsp)++ movq ACC+64(%rsp), %rax+ cmovnzq NACC+64(%rsp), %rax+ movq %rax, ACC+64(%rsp)++ movq ACC+72(%rsp), %rax+ cmovnzq NACC+72(%rsp), %rax+ movq %rax, ACC+72(%rsp)++ movq ACC+80(%rsp), %rax+ cmovnzq NACC+80(%rsp), %rax+ movq %rax, ACC+80(%rsp)++ movq ACC+88(%rsp), %rax+ cmovnzq NACC+88(%rsp), %rax+ movq %rax, ACC+88(%rsp)++// Loop while blocksize * i <= 256++ movq i, %rax+ incq %rax+ movq %rax, i++ imulq blocksize, %rax+ cmpq $257, %rax+ jc Lp256_scalarmulbase_loop++// That's the end of the main loop, and we just need to translate+// back from the Jacobian representation to affine. First of all,+// let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ CFI_CALL(Lp256_scalarmulbase_local_montsqr_p256)++ leaq Z3(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_local_montmul_p256)++ leaq Z2(%rsp), %rdi+ leaq Z3(%rsp), %rsi+ CFI_CALL(Lp256_scalarmulbase_local_demont_p256)++ leaq Z3(%rsp), %rdi+ leaq Z2(%rsp), %rsi+ CFI_CALL(Lp256_scalarmulbase_local_inv_p256)++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_local_montmul_p256)++// Convert back from Jacobian (X, Y, Z) |-> (X/Z^2, Y/Z^3)++ movq res, %rdi+ leaq ACC(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ movq %rdi, %rbx+ CFI_CALL(Lp256_scalarmulbase_local_montmul_p256)++ leaq 32(%rbx), %rdi+ leaq ACC+32(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p256_scalarmulbase)+#endif++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_demont_p256)++Lp256_scalarmulbase_local_demont_p256:+ CFI_START+ CFI_PUSH(%rbx)+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ xorq %rbx, %rbx+ xorq %rsi, %rsi+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq %r9, %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %rbx+ mulxq %r9, %rax, %rcx+ adcxq %rax, %rbx+ adoxq %rcx, %rsi+ movl $0x0, %r8d+ adcxq %r8, %rsi+ xorq %r9, %r9+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %rbx+ mulxq %r11, %rax, %rcx+ adcxq %rax, %rbx+ adoxq %rcx, %rsi+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rcx+ adcxq %rax, %rsi+ adoxq %rcx, %r8+ mulxq %r11, %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ movl $0x0, %r10d+ adcxq %r10, %r9+ movq %rbx, (%rdi)+ movq %rsi, 0x8(%rdi)+ movq %r8, 0x10(%rdi)+ movq %r9, 0x18(%rdi)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_demont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_inv_p256)++Lp256_scalarmulbase_local_inv_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(240)+ movq %rdi, 0xe0(%rsp)+ xorl %ecx, %ecx+ movl $0xffffffff, %edx+ movq %rdx, %rbx+ leaq -0x1(%rcx), %rax+ negq %rdx+ movq %rax, (%rsp)+ movq %rbx, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rdx, 0x18(%rsp)+ movq %rcx, 0x20(%rsp)+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ leaq 0x1(%rcx), %rax+ addq %r8, %rax+ leaq -0x1(%rdx), %rbx+ adcq %r9, %rbx+ notq %rcx+ adcq %r10, %rcx+ notq %rdx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq %rax, 0x28(%rsp)+ movq %rbx, 0x30(%rsp)+ movq %rcx, 0x38(%rsp)+ movq %rdx, 0x40(%rsp)+ xorl %eax, %eax+ movq %rax, 0x48(%rsp)+ xorl %eax, %eax+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movq %rax, 0x60(%rsp)+ movq %rax, 0x68(%rsp)+ movq $0x4000000000000, %rcx+ movq %rcx, 0x78(%rsp)+ movq %rax, 0x80(%rsp)+ movq %rax, 0x88(%rsp)+ movq %rax, 0x90(%rsp)+ movq $0xa, 0xb0(%rsp)+ movq $0x1, 0xb8(%rsp)+ jmp Lp256_scalarmulbase_inv_midloop+Lp256_scalarmulbase_inv_loop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0xa0(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0xa8(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x28(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x30(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq 0x20(%rsp), %rbp+ xorq %r9, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x40(%rsp), %rax+ xorq %r11, %rax+ movq 0x48(%rsp), %rdx+ xorq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ sarq $0x3b, %rbp+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ movq 0x20(%rsp), %rsi+ movq %rbp, 0x20(%rsp)+ xorq %r13, %rax+ xorq %r13, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x40(%rsp), %rax+ xorq %r15, %rax+ movq 0x48(%rsp), %rdx+ xorq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x38(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x40(%rsp)+ sarq $0x3b, %rsi+ movq %rsi, 0x48(%rsp)+ movq 0xa0(%rsp), %rbx+ movq 0xa8(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x78(%rsp)+ xorl %ebx, %ebx+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x58(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x58(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x80(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x80(%rsp)+ xorl %ecx, %ecx+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x60(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x60(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x88(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x88(%rsp)+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq 0x68(%rsp), %rax+ movq %rcx, 0x68(%rsp)+ movq %rdx, 0x70(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x90(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rsi, 0x90(%rsp)+ movq %rdx, 0x98(%rsp)+ movq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movq $0xe000000000000000, %r8+ addq 0x78(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x80(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x88(%rsp), %r10+ movq $0x2000000000000000, %r11+ adcq 0x90(%rsp), %r11+ movq $0x1fffffffe0000000, %r12+ adcq 0x98(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x78(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x80(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x88(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x90(%rsp)+Lp256_scalarmulbase_inv_midloop:+ movq 0xb8(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x28(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xc0(%rsp)+ movq %rbx, 0xc8(%rsp)+ movq %rdi, 0xd0(%rsp)+ movq %rcx, 0xd8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x28(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xc0(%rsp), %rax+ imulq %r8, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xc8(%rsp), %r8+ imulq 0xd8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xc0(%rsp), %rax+ imulq %r10, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xc8(%rsp), %r10+ imulq 0xd8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0xb8(%rsp)+ decq 0xb0(%rsp)+ jne Lp256_scalarmulbase_inv_loop+ movq (%rsp), %rax+ movq 0x28(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r12, 0x50(%rsp)+ movq %r13, 0x58(%rsp)+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r9, 0x70(%rsp)+ movq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movq 0x50(%rsp), %r8+ movq 0x58(%rsp), %r9+ movq 0x60(%rsp), %r10+ movq 0x68(%rsp), %r11+ movl $0x1, %eax+ movl $0xffffffff, %ebx+ leaq -0x2(%rax), %rcx+ leaq -0x1(%rbx), %rdx+ notq %rbx+ addq %r8, %rax+ adcq %r9, %rbx+ adcq %r10, %rcx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq 0xe0(%rsp), %rdi+ movq %rax, (%rdi)+ movq %rbx, 0x8(%rdi)+ movq %rcx, 0x10(%rdi)+ movq %rdx, 0x18(%rdi)+ CFI_INC_RSP(240)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_inv_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_montmul_p256)++Lp256_scalarmulbase_local_montmul_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq %rdx, %rcx+ xorl %r13d, %r13d+ movq (%rcx), %rdx+ mulxq (%rsi), %r8, %r9+ mulxq 0x8(%rsi), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsi), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rcx), %rdx+ xorl %r14d, %r14d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rcx), %rdx+ xorl %r8d, %r8d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rcx), %rdx+ xorl %r9d, %r9d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_montmul_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_montsqr_p256)++Lp256_scalarmulbase_local_montsqr_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq (%rsi), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x8(%rsi), %r9, %r10+ mulxq 0x18(%rsi), %r11, %r12+ movq 0x10(%rsi), %rdx+ mulxq 0x18(%rsi), %r13, %r14+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x18(%rsi), %rdx+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ xorl %ebp, %ebp+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x8(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x10(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x18(%rsi), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rbp, %r13+ movl %ebp, %r9d+ adoxq %rbp, %r9+ adcxq %rbp, %r9+ addq %r9, %r14+ adcq %rbp, %r15+ movl %ebp, %r8d+ adcq %rbp, %r8+ xorl %ebp, %ebp+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %r8+ adcq %rbp, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rbp), %rbp+ movq %rbp, %rax+ adcq %r14, %rbp+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %rbp, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_montsqr_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_local_p256_montjmixadd)++Lp256_scalarmulbase_local_p256_montjmixadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(192)+ movq %rdx, %rbp+ movq 0x40(%rsi), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x48(%rsi), %r9, %r10+ mulxq 0x58(%rsi), %r11, %r12+ movq 0x50(%rsi), %rdx+ mulxq 0x58(%rsi), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x58(%rsi), %rdx+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x48(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x50(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x58(%rsi), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %r8d+ leaq -0x1(%rdx), %rdx+ leaq -0x1(%rcx), %rax+ movl $0xfffffffe, %r11d+ cmoveq %rcx, %r8+ cmoveq %rcx, %rdx+ cmoveq %rcx, %rax+ cmoveq %rcx, %r11+ addq %r8, %r12+ adcq %rdx, %r13+ adcq %rax, %r14+ adcq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rbp), %rdx+ mulxq 0x40(%rsi), %r8, %r9+ mulxq 0x48(%rsi), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x50(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x58(%rsi), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rbp), %rdx+ xorl %r14d, %r14d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x58(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rbp), %rdx+ xorl %r8d, %r8d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x58(%rsi), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rbp), %rdx+ xorl %r9d, %r9d+ mulxq 0x40(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x58(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ xorl %r13d, %r13d+ movq 0x0(%rbp), %rdx+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rbp), %rdx+ xorl %r14d, %r14d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rbp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rbp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rsp), %rdx+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0x40(%rsp), %rax+ subq (%rsi), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x8(%rsi), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x10(%rsi), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x18(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0xa0(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0xa8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0xb0(%rsp)+ adcq %rdx, %r9+ movq %r9, 0xb8(%rsp)+ movq 0x20(%rsp), %rax+ subq 0x20(%rsi), %rax+ movq 0x28(%rsp), %rcx+ sbbq 0x28(%rsi), %rcx+ movq 0x30(%rsp), %r8+ sbbq 0x30(%rsi), %r8+ movq 0x38(%rsp), %r9+ sbbq 0x38(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x20(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x28(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x30(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x38(%rsp)+ movq 0xa0(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0xa8(%rsp), %r9, %r10+ mulxq 0xb8(%rsp), %r11, %r12+ movq 0xb0(%rsp), %rdx+ mulxq 0xb8(%rsp), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0xb8(%rsp), %rdx+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0xa8(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0xb0(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0xb8(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %r8d+ leaq -0x1(%rdx), %rdx+ leaq -0x1(%rcx), %rax+ movl $0xfffffffe, %r11d+ cmoveq %rcx, %r8+ cmoveq %rcx, %rdx+ cmoveq %rcx, %rax+ cmoveq %rcx, %r11+ addq %r8, %r12+ adcq %rdx, %r13+ adcq %rax, %r14+ adcq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x20(%rsp), %rdx+ mulxq %rdx, %r8, %r15+ mulxq 0x28(%rsp), %r9, %r10+ mulxq 0x38(%rsp), %r11, %r12+ movq 0x30(%rsp), %rdx+ mulxq 0x38(%rsp), %r13, %r14+ xorl %ecx, %ecx+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsp), %rdx+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ adoxq %rcx, %r14+ adcq %rcx, %r14+ xorl %ecx, %ecx+ adcxq %r9, %r9+ adoxq %r15, %r9+ movq 0x28(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x30(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x38(%rsp), %rdx+ mulxq %rdx, %rax, %r15+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %rcx, %r15+ adoxq %rcx, %r15+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq $0xffffffff00000001, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %rcx, %r13+ movl %ecx, %r9d+ adoxq %rcx, %r9+ adcxq %rcx, %r9+ addq %r9, %r14+ adcq %rcx, %r15+ movl %ecx, %r8d+ adcq %rcx, %r8+ xorl %ecx, %ecx+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq $0xffffffff00000001, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rcx, %r15+ adoxq %rcx, %r8+ adcq %rcx, %r8+ movl $0x1, %ebx+ addq %r12, %rbx+ leaq -0x1(%rdx), %rdx+ adcq %r13, %rdx+ leaq -0x1(%rcx), %rcx+ movq %rcx, %rax+ adcq %r14, %rcx+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rbx, %r12+ cmovbq %rdx, %r13+ cmovbq %rcx, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ xorl %r13d, %r13d+ movq (%rsi), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x8(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x10(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x18(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ xorl %r13d, %r13d+ movq 0x40(%rsp), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x48(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x50(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x58(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq (%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ xorl %r13d, %r13d+ movq 0x40(%rsi), %rdx+ mulxq 0xa0(%rsp), %r8, %r9+ mulxq 0xa8(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0xb0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xb8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x48(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x50(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x58(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq (%rsp), %rax+ subq 0x40(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x48(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x50(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x58(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x80(%rsp), %rax+ subq (%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ xorl %r13d, %r13d+ movq 0x20(%rsi), %rdx+ mulxq 0x60(%rsp), %r8, %r9+ mulxq 0x68(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x70(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x28(%rsi), %rdx+ xorl %r14d, %r14d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x30(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x38(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x78(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ xorl %r13d, %r13d+ movq 0x80(%rsp), %rdx+ mulxq 0x20(%rsp), %r8, %r9+ mulxq 0x28(%rsp), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x30(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x38(%rsp), %rbx, %r12+ adcq %rbx, %r11+ adcq %r13, %r12+ movq 0x88(%rsp), %rdx+ xorl %r14d, %r14d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcq %r14, %r13+ xorl %r15d, %r15d+ movq $0x100000000, %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r8, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r9, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adcxq %r15, %r13+ adoxq %r15, %r14+ adcq %r15, %r14+ movq 0x90(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ adoxq %r8, %r14+ mulxq 0x38(%rsp), %rax, %rbx+ adcq %rax, %r13+ adcq %rbx, %r14+ adcq %r8, %r15+ movq 0x98(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r9, %r15+ mulxq 0x38(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r9, %r8+ xorl %r9d, %r9d+ movq $0x100000000, %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ notq %rdx+ leaq 0x2(%rdx), %rdx+ mulxq %r10, %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq %r11, %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %r9, %r15+ adoxq %r9, %r8+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rdx+ adcq %r13, %rdx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rdx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x80(%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x68(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x40(%rsi), %rax+ movq 0x48(%rsi), %rdx+ orq 0x50(%rsi), %rax+ orq 0x58(%rsi), %rdx+ orq %rdx, %rax+ movq (%rsp), %r8+ movq 0x0(%rbp), %rax+ cmoveq %rax, %r8+ movq 0x8(%rsp), %r9+ movq 0x8(%rbp), %rax+ cmoveq %rax, %r9+ movq 0x10(%rsp), %r10+ movq 0x10(%rbp), %rax+ cmoveq %rax, %r10+ movq 0x18(%rsp), %r11+ movq 0x18(%rbp), %rax+ cmoveq %rax, %r11+ movq 0x80(%rsp), %r12+ movq 0x20(%rbp), %rax+ cmoveq %rax, %r12+ movq 0x88(%rsp), %r13+ movq 0x28(%rbp), %rax+ cmoveq %rax, %r13+ movq 0x90(%rsp), %r14+ movq 0x30(%rbp), %rax+ cmoveq %rax, %r14+ movq 0x98(%rsp), %r15+ movq 0x38(%rbp), %rax+ cmoveq %rax, %r15+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %r12, 0x20(%rdi)+ movq %r13, 0x28(%rdi)+ movq %r14, 0x30(%rdi)+ movq %r15, 0x38(%rdi)+ movq 0xa0(%rsp), %r8+ movq 0xa8(%rsp), %r9+ movq 0xb0(%rsp), %r10+ movq 0xb8(%rsp), %r11+ movl $0x1, %eax+ cmoveq %rax, %r8+ movq $0xffffffff00000000, %rax+ cmoveq %rax, %r9+ movq $0xffffffffffffffff, %rax+ cmoveq %rax, %r10+ movl $0xfffffffe, %eax+ cmoveq %rax, %r11+ movq %r8, 0x40(%rdi)+ movq %r9, 0x48(%rdi)+ movq %r10, 0x50(%rdi)+ movq %r11, 0x58(%rdi)+ CFI_INC_RSP(192)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_local_p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p256_scalarmulbase_alt.S view
@@ -0,0 +1,4212 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Scalar multiplication for precomputed point on NIST curve P-256+// Input scalar[4], blocksize, table[]; output res[8]+//+// extern void p256_scalarmulbase_alt+// (uint64_t res[static 8],+// const uint64_t scalar[static 4],+// uint64_t blocksize,+// const uint64_t *table);+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-256, the input argument "table" is expected to be a table of+// multiples of the point P in Montgomery-affine form, with each block+// corresponding to "blocksize" bits of the scalar as follows, where+// B = 2^{blocksize-1} (e.g. B = 8 for blocksize = 4):+//+// For each i,j with blocksize * i <= 256 and 1 <= j <= B+// the multiple 2^{blocksize * i} * j * P is stored at+// tab[8 * (B * i + (j - 1))], considered as uint64_t pointers+// or tab + 64 * (B * i + (j - 1)) as byte pointers.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = blocksize, RCX = table+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = blocksize, R9 = table+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p256_scalarmulbase_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p256_scalarmulbase_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p256_scalarmulbase_alt)+++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 32++// Intermediate variables on the stack. The last z2, z3 values can+// safely be overlaid on "nacc", which is no longer needed at the end.+// Uppercase syntactic variants make x86_att version simpler to generate++#define RSCALAR (0*NUMSIZE)+#define ACC (1*NUMSIZE)+#define NACC (4*NUMSIZE)+#define TABENT (7*NUMSIZE)+#define Z2 (4*NUMSIZE)+#define Z3 (5*NUMSIZE)++#define rscalar RSCALAR(%rsp)+#define acc ACC(%rsp)+#define nacc NACC(%rsp)+#define tabent TABENT(%rsp)++#define z2 Z2(%rsp)+#define z3 Z3(%rsp)++#define res (9*NUMSIZE)(%rsp)+#define blocksize (9*NUMSIZE+8)(%rsp)+#define table (9*NUMSIZE+16)(%rsp)+#define i (9*NUMSIZE+24)(%rsp)+#define bf (9*NUMSIZE+32)(%rsp)+#define cf (9*NUMSIZE+40)(%rsp)+#define j (9*NUMSIZE+48)(%rsp)++#define NSPACE 11*NUMSIZE++S2N_BN_SYMBOL(p256_scalarmulbase_alt):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ movq %r9, %rcx+ CFI_CALL(Lp256_scalarmulbase_alt_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p256_scalarmulbase_alt)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_standard)++Lp256_scalarmulbase_alt_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the input arguments except the scalar, since that gets absorbed+// immediately. The "table" value subsequently gets shifted up each iteration+// of the loop, while "res" and "blocksize" are static throughout.++ movq %rdi, res+ movq %rdx, blocksize+ movq %rcx, table++// Load the digits of group order n_256 = [%r15;%r14;%r13;%r12]++ movq $0xf3b9cac2fc632551, %r12+ movq $0xbce6faada7179e84, %r13+ movq $0xffffffffffffffff, %r14+ movq $0xffffffff00000000, %r15++// First, reduce the input scalar mod n_256, i.e. conditionally subtract n_256+// Store it to "rscalar" (reduced scalar)++ movq (%rsi), %r8+ subq %r12, %r8+ movq 8(%rsi), %r9+ sbbq %r13, %r9+ movq 16(%rsi), %r10+ sbbq %r14, %r10+ movq 24(%rsi), %r11+ sbbq %r15, %r11++ cmovcq (%rsi), %r8+ cmovcq 8(%rsi), %r9+ cmovcq 16(%rsi), %r10+ cmovcq 24(%rsi), %r11++ movq %r8, RSCALAR(%rsp)+ movq %r9, RSCALAR+8(%rsp)+ movq %r10, RSCALAR+16(%rsp)+ movq %r11, RSCALAR+24(%rsp)++// Initialize the accumulator to all zeros and the "carry flag" cf to 0++ xorl %eax, %eax++ movq %rax, ACC(%rsp)+ movq %rax, ACC+8(%rsp)+ movq %rax, ACC+16(%rsp)+ movq %rax, ACC+24(%rsp)+ movq %rax, ACC+32(%rsp)+ movq %rax, ACC+40(%rsp)+ movq %rax, ACC+48(%rsp)+ movq %rax, ACC+56(%rsp)+ movq %rax, ACC+64(%rsp)+ movq %rax, ACC+72(%rsp)+ movq %rax, ACC+80(%rsp)+ movq %rax, ACC+88(%rsp)++ movq %rax, cf++// Main loop over {i >= 0 | blocksize * i <= 256}. Note the non-strict+// inequality, to allow top carry for any choices of blocksize.++ movq %rax, i++Lp256_scalarmulbase_alt_loop:++// The next raw bitfield is bf = bitfield(blocksize * i,blocksize) + cf,+// adding in the deferred carry cf. We then shift the whole scalar right+// by blocksize so we can keep picking bitfield(0,blocksize).++ movq RSCALAR(%rsp), %r8+ movq RSCALAR+8(%rsp), %r9+ movq RSCALAR+16(%rsp), %r10+ movq RSCALAR+24(%rsp), %r11++ movq blocksize, %rcx+ movl $1, %eax+ shlq %cl, %rax+ decq %rax+ andq %r8, %rax++ shrdq %cl, %r9, %r8+ shrdq %cl, %r10, %r9+ shrdq %cl, %r11, %r10+ shrq %cl, %r11++ addq cf, %rax+ movq %rax, bf++ movq %r8, RSCALAR(%rsp)+ movq %r9, RSCALAR+8(%rsp)+ movq %r10, RSCALAR+16(%rsp)+ movq %r11, RSCALAR+24(%rsp)++// Now if bf <= B we just select entry j, unnegated and set cf = 0.+// If bf > B we set j = 2 * B - bf and negate the j'th entry, setting cf = 1.+// In either case we ultimately add bf, in the latter case with deferred+// carry as 2 * B - (2 * B - bf) = bf.++ movl $1, %eax+ movq blocksize, %rcx+ shlq %cl, %rax+ movq %rax, %rbx+ shrq $1, %rax++ subq bf, %rbx+ cmpq bf, %rax++ cmovncq bf, %rbx+ sbbq %rax, %rax+ movq %rbx, j+ negq %rax+ movq %rax, cf++// Load table entry j - 1 for nonzero j in constant-time style.++ movq blocksize, %rcx+ decq %rcx+ movl $1, %esi+ shlq %cl, %rsi+ movq j, %r12+ movq table, %rbp++Lp256_scalarmulbase_alt_tabloop:+ subq $1, %r12+ cmovzq (%rbp), %rax+ cmovzq 8(%rbp), %rbx+ cmovzq 16(%rbp), %rcx+ cmovzq 24(%rbp), %rdx+ cmovzq 32(%rbp), %r8+ cmovzq 40(%rbp), %r9+ cmovzq 48(%rbp), %r10+ cmovzq 56(%rbp), %r11++ addq $64, %rbp+ decq %rsi+ jnz Lp256_scalarmulbase_alt_tabloop++ movq %rbp, table++// Before storing back, optionally negate the y coordinate of the table entry++ xorl %r14d, %r14d+ leaq -1(%r14), %r12+ movq $0x00000000ffffffff, %r15+ movq %r15, %r13+ negq %r15++ subq %r8, %r12+ sbbq %r9, %r13+ sbbq %r10, %r14+ sbbq %r11, %r15++ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)++ movq cf, %rax+ testq %rax, %rax+ cmovnzq %r12, %r8+ cmovnzq %r13, %r9+ cmovnzq %r14, %r10+ cmovnzq %r15, %r11++ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+48(%rsp)+ movq %r11, TABENT+56(%rsp)++// Add the adjusted table point to the accumulator++ leaq NACC(%rsp), %rdi+ leaq ACC(%rsp), %rsi+ leaq TABENT(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_alt_local_p256_montjmixadd)++// However, only commit that update to the accumulator if j is nonzero,+// because the mixed addition function does not handle this case directly,+// and in any case we didn't choose the table entry appropriately.++ movq j, %rax+ testq %rax, %rax++ movq ACC(%rsp), %rax+ cmovnzq NACC(%rsp), %rax+ movq %rax, ACC(%rsp)++ movq ACC+8(%rsp), %rax+ cmovnzq NACC+8(%rsp), %rax+ movq %rax, ACC+8(%rsp)++ movq ACC+16(%rsp), %rax+ cmovnzq NACC+16(%rsp), %rax+ movq %rax, ACC+16(%rsp)++ movq ACC+24(%rsp), %rax+ cmovnzq NACC+24(%rsp), %rax+ movq %rax, ACC+24(%rsp)++ movq ACC+32(%rsp), %rax+ cmovnzq NACC+32(%rsp), %rax+ movq %rax, ACC+32(%rsp)++ movq ACC+40(%rsp), %rax+ cmovnzq NACC+40(%rsp), %rax+ movq %rax, ACC+40(%rsp)++ movq ACC+48(%rsp), %rax+ cmovnzq NACC+48(%rsp), %rax+ movq %rax, ACC+48(%rsp)++ movq ACC+56(%rsp), %rax+ cmovnzq NACC+56(%rsp), %rax+ movq %rax, ACC+56(%rsp)++ movq ACC+64(%rsp), %rax+ cmovnzq NACC+64(%rsp), %rax+ movq %rax, ACC+64(%rsp)++ movq ACC+72(%rsp), %rax+ cmovnzq NACC+72(%rsp), %rax+ movq %rax, ACC+72(%rsp)++ movq ACC+80(%rsp), %rax+ cmovnzq NACC+80(%rsp), %rax+ movq %rax, ACC+80(%rsp)++ movq ACC+88(%rsp), %rax+ cmovnzq NACC+88(%rsp), %rax+ movq %rax, ACC+88(%rsp)++// Loop while blocksize * i <= 256++ movq i, %rax+ incq %rax+ movq %rax, i++ imulq blocksize, %rax+ cmpq $257, %rax+ jc Lp256_scalarmulbase_alt_loop++// That's the end of the main loop, and we just need to translate+// back from the Jacobian representation to affine. First of all,+// let z2 = 1/z^2 and z3 = 1/z^3, both without Montgomery form++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ CFI_CALL(Lp256_scalarmulbase_alt_local_montsqr_p256)++ leaq Z3(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_alt_local_montmul_p256)++ leaq Z2(%rsp), %rdi+ leaq Z3(%rsp), %rsi+ CFI_CALL(Lp256_scalarmulbase_alt_local_demont_p256)++ leaq Z3(%rsp), %rdi+ leaq Z2(%rsp), %rsi+ CFI_CALL(Lp256_scalarmulbase_alt_local_inv_p256)++ leaq Z2(%rsp), %rdi+ leaq ACC+64(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_alt_local_montmul_p256)++// Convert back from Jacobian (X, Y, Z) |-> (X/Z^2, Y/Z^3)++ movq res, %rdi+ leaq ACC(%rsp), %rsi+ leaq Z2(%rsp), %rdx+ movq %rdi, %rbx+ CFI_CALL(Lp256_scalarmulbase_alt_local_montmul_p256)++ leaq 32(%rbx), %rdi+ leaq ACC+32(%rsp), %rsi+ leaq Z3(%rsp), %rdx+ CFI_CALL(Lp256_scalarmulbase_alt_local_montmul_p256)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p256_scalarmulbase_alt)+#endif++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_demont_p256)++Lp256_scalarmulbase_alt_local_demont_p256:+ CFI_START+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ movabsq $0x100000000, %rcx+ movq %r8, %rax+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rsi, %rsi+ movq %r9, %rax+ mulq %rcx+ subq %rsi, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rsi, %rsi+ negq %rcx+ negq %rsi+ incq %rcx+ movq %r8, %rax+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %rsi+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rax+ mulq %rcx+ addq %rax, %rsi+ adcq %rdx, %r8+ negq %rcx+ incq %rcx+ movq %r10, %rax+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %rsi+ sbbq %r9, %r9+ movq %r11, %rax+ mulq %rcx+ subq %r9, %rdx+ addq %rax, %rsi+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %rcx+ negq %r9+ incq %rcx+ movq %r10, %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rax+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ movq %rsi, (%rdi)+ movq %r8, 0x8(%rdi)+ movq %r9, 0x10(%rdi)+ movq %r10, 0x18(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_demont_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_inv_p256)++Lp256_scalarmulbase_alt_local_inv_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(240)+ movq %rdi, 0xe0(%rsp)+ xorl %ecx, %ecx+ movl $0xffffffff, %edx+ movq %rdx, %rbx+ leaq -0x1(%rcx), %rax+ negq %rdx+ movq %rax, (%rsp)+ movq %rbx, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rdx, 0x18(%rsp)+ movq %rcx, 0x20(%rsp)+ movq (%rsi), %r8+ movq 0x8(%rsi), %r9+ movq 0x10(%rsi), %r10+ movq 0x18(%rsi), %r11+ leaq 0x1(%rcx), %rax+ addq %r8, %rax+ leaq -0x1(%rdx), %rbx+ adcq %r9, %rbx+ notq %rcx+ adcq %r10, %rcx+ notq %rdx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq %rax, 0x28(%rsp)+ movq %rbx, 0x30(%rsp)+ movq %rcx, 0x38(%rsp)+ movq %rdx, 0x40(%rsp)+ xorl %eax, %eax+ movq %rax, 0x48(%rsp)+ xorl %eax, %eax+ movq %rax, 0x50(%rsp)+ movq %rax, 0x58(%rsp)+ movq %rax, 0x60(%rsp)+ movq %rax, 0x68(%rsp)+ movabsq $0x4000000000000, %rcx+ movq %rcx, 0x78(%rsp)+ movq %rax, 0x80(%rsp)+ movq %rax, 0x88(%rsp)+ movq %rax, 0x90(%rsp)+ movq $0xa, 0xb0(%rsp)+ movq $0x1, 0xb8(%rsp)+ jmp Lp256_scalarmulbase_alt_inv_midloop+Lp256_scalarmulbase_alt_inv_loop:+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %rdi+ andq %r11, %rdi+ addq %rax, %rdi+ movq %rdi, 0xa0(%rsp)+ movq %r12, %rax+ andq %r13, %rax+ movq %r14, %rsi+ andq %r15, %rsi+ addq %rax, %rsi+ movq %rsi, 0xa8(%rsp)+ xorl %ebx, %ebx+ movq (%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x28(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rdi+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq (%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x28(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ xorl %ecx, %ecx+ movq 0x8(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x30(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, (%rsp)+ xorl %edi, %edi+ movq 0x8(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rbp+ adcq %rdx, %rdi+ movq 0x30(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rdi+ shrdq $0x3b, %rbp, %rsi+ movq %rsi, 0x28(%rsp)+ xorl %esi, %esi+ movq 0x10(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rsi+ movq 0x38(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rsi+ shrdq $0x3b, %rcx, %rbx+ movq %rbx, 0x8(%rsp)+ xorl %ebx, %ebx+ movq 0x10(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ addq %rax, %rdi+ adcq %rdx, %rbx+ movq 0x38(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rdi+ adcq %rdx, %rbx+ shrdq $0x3b, %rdi, %rbp+ movq %rbp, 0x30(%rsp)+ movq 0x18(%rsp), %rax+ xorq %r9, %rax+ movq 0x20(%rsp), %rbp+ xorq %r9, %rbp+ andq %r8, %rbp+ negq %rbp+ mulq %r8+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x40(%rsp), %rax+ xorq %r11, %rax+ movq 0x48(%rsp), %rdx+ xorq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbp+ mulq %r10+ addq %rax, %rsi+ adcq %rdx, %rbp+ shrdq $0x3b, %rsi, %rcx+ movq %rcx, 0x10(%rsp)+ shrdq $0x3b, %rbp, %rsi+ sarq $0x3b, %rbp+ movq 0x18(%rsp), %rax+ movq %rsi, 0x18(%rsp)+ movq 0x20(%rsp), %rsi+ movq %rbp, 0x20(%rsp)+ xorq %r13, %rax+ xorq %r13, %rsi+ andq %r12, %rsi+ negq %rsi+ mulq %r12+ addq %rax, %rbx+ adcq %rdx, %rsi+ movq 0x40(%rsp), %rax+ xorq %r15, %rax+ movq 0x48(%rsp), %rdx+ xorq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rsi+ mulq %r14+ addq %rax, %rbx+ adcq %rdx, %rsi+ shrdq $0x3b, %rbx, %rdi+ movq %rdi, 0x38(%rsp)+ shrdq $0x3b, %rsi, %rbx+ movq %rbx, 0x40(%rsp)+ sarq $0x3b, %rsi+ movq %rsi, 0x48(%rsp)+ movq 0xa0(%rsp), %rbx+ movq 0xa8(%rsp), %rbp+ xorl %ecx, %ecx+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x50(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x50(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x78(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x78(%rsp)+ xorl %ebx, %ebx+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rcx+ adcq %rdx, %rbx+ xorl %ebp, %ebp+ movq 0x58(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rcx, 0x58(%rsp)+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq 0x80(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rsi+ adcq %rdx, %rbp+ movq %rsi, 0x80(%rsp)+ xorl %ecx, %ecx+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %rbx+ adcq %rdx, %rcx+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %rbx+ adcq %rdx, %rcx+ xorl %esi, %esi+ movq 0x60(%rsp), %rax+ xorq %r13, %rax+ mulq %r12+ movq %rbx, 0x60(%rsp)+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq 0x88(%rsp), %rax+ xorq %r15, %rax+ mulq %r14+ addq %rax, %rbp+ adcq %rdx, %rsi+ movq %rbp, 0x88(%rsp)+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ movq %r9, %rbx+ andq %r8, %rbx+ negq %rbx+ mulq %r8+ addq %rax, %rcx+ adcq %rdx, %rbx+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %rbx+ mulq %r10+ addq %rax, %rcx+ adcq %rbx, %rdx+ movq 0x68(%rsp), %rax+ movq %rcx, 0x68(%rsp)+ movq %rdx, 0x70(%rsp)+ xorq %r13, %rax+ movq %r13, %rcx+ andq %r12, %rcx+ negq %rcx+ mulq %r12+ addq %rax, %rsi+ adcq %rdx, %rcx+ movq 0x90(%rsp), %rax+ xorq %r15, %rax+ movq %r15, %rdx+ andq %r14, %rdx+ subq %rdx, %rcx+ mulq %r14+ addq %rax, %rsi+ adcq %rcx, %rdx+ movq %rsi, 0x90(%rsp)+ movq %rdx, 0x98(%rsp)+ movabsq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movabsq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movabsq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movabsq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movabsq $0xe000000000000000, %r8+ addq 0x78(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x80(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x88(%rsp), %r10+ movabsq $0x2000000000000000, %r11+ adcq 0x90(%rsp), %r11+ movabsq $0x1fffffffe0000000, %r12+ adcq 0x98(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movabsq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x78(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x80(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x88(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x90(%rsp)+Lp256_scalarmulbase_alt_inv_midloop:+ movq 0xb8(%rsp), %rsi+ movq (%rsp), %rdx+ movq 0x28(%rsp), %rcx+ movq %rdx, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ xorl %ebp, %ebp+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %rdx+ leaq (%rcx,%rax), %rdi+ shlq $0x16, %rdx+ shlq $0x16, %rdi+ sarq $0x2b, %rdx+ sarq $0x2b, %rdi+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %rbx+ leaq (%rcx,%rax), %rcx+ sarq $0x2a, %rbx+ sarq $0x2a, %rcx+ movq %rdx, 0xc0(%rsp)+ movq %rbx, 0xc8(%rsp)+ movq %rdi, 0xd0(%rsp)+ movq %rcx, 0xd8(%rsp)+ movq (%rsp), %r12+ imulq %r12, %rdi+ imulq %rdx, %r12+ movq 0x28(%rsp), %r13+ imulq %r13, %rbx+ imulq %rcx, %r13+ addq %rbx, %r12+ addq %rdi, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r10+ shlq $0x16, %r8+ shlq $0x16, %r10+ sarq $0x2b, %r8+ sarq $0x2b, %r10+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r15+ leaq (%rcx,%rax), %r11+ sarq $0x2a, %r15+ sarq $0x2a, %r11+ movq %r13, %rbx+ movq %r12, %rcx+ imulq %r8, %r12+ imulq %r15, %rbx+ addq %rbx, %r12+ imulq %r11, %r13+ imulq %r10, %rcx+ addq %rcx, %r13+ sarq $0x14, %r12+ sarq $0x14, %r13+ movq %r12, %rbx+ andq $0xfffff, %rbx+ movabsq $0xfffffe0000000000, %rax+ orq %rax, %rbx+ movq %r13, %rcx+ andq $0xfffff, %rcx+ movabsq $0xc000000000000000, %rax+ orq %rax, %rcx+ movq 0xc0(%rsp), %rax+ imulq %r8, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r15, %rdx+ imulq 0xc8(%rsp), %r8+ imulq 0xd8(%rsp), %r15+ addq %r8, %r15+ leaq (%rax,%rdx), %r9+ movq 0xc0(%rsp), %rax+ imulq %r10, %rax+ movq 0xd0(%rsp), %rdx+ imulq %r11, %rdx+ imulq 0xc8(%rsp), %r10+ imulq 0xd8(%rsp), %r11+ addq %r10, %r11+ leaq (%rax,%rdx), %r13+ movq $0xfffffffffffffffe, %rax+ movl $0x2, %edx+ movq %rbx, %rdi+ movq %rax, %r8+ testq %rsi, %rsi+ cmovs %rbp, %r8+ testq $0x1, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ cmovs %rbp, %r8+ movq %rbx, %rdi+ testq %rdx, %rcx+ cmoveq %rbp, %r8+ cmoveq %rbp, %rdi+ sarq $1, %rcx+ xorq %r8, %rdi+ xorq %r8, %rsi+ btq $0x3f, %r8+ cmovbq %rcx, %rbx+ movq %rax, %r8+ subq %rax, %rsi+ leaq (%rcx,%rdi), %rcx+ sarq $1, %rcx+ movl $0x100000, %eax+ leaq (%rbx,%rax), %r8+ leaq (%rcx,%rax), %r12+ shlq $0x15, %r8+ shlq $0x15, %r12+ sarq $0x2b, %r8+ sarq $0x2b, %r12+ movabsq $0x20000100000, %rax+ leaq (%rbx,%rax), %r10+ leaq (%rcx,%rax), %r14+ sarq $0x2b, %r10+ sarq $0x2b, %r14+ movq %r9, %rax+ imulq %r8, %rax+ movq %r13, %rdx+ imulq %r10, %rdx+ imulq %r15, %r8+ imulq %r11, %r10+ addq %r8, %r10+ leaq (%rax,%rdx), %r8+ movq %r9, %rax+ imulq %r12, %rax+ movq %r13, %rdx+ imulq %r14, %rdx+ imulq %r15, %r12+ imulq %r11, %r14+ addq %r12, %r14+ leaq (%rax,%rdx), %r12+ movq %rsi, 0xb8(%rsp)+ decq 0xb0(%rsp)+ jne Lp256_scalarmulbase_alt_inv_loop+ movq (%rsp), %rax+ movq 0x28(%rsp), %rcx+ imulq %r8, %rax+ imulq %r10, %rcx+ addq %rcx, %rax+ sarq $0x3f, %rax+ movq %r8, %r9+ sarq $0x3f, %r9+ xorq %r9, %r8+ subq %r9, %r8+ xorq %rax, %r9+ movq %r10, %r11+ sarq $0x3f, %r11+ xorq %r11, %r10+ subq %r11, %r10+ xorq %rax, %r11+ movq %r12, %r13+ sarq $0x3f, %r13+ xorq %r13, %r12+ subq %r13, %r12+ xorq %rax, %r13+ movq %r14, %r15+ sarq $0x3f, %r15+ xorq %r15, %r14+ subq %r15, %r14+ xorq %rax, %r15+ movq %r8, %rax+ andq %r9, %rax+ movq %r10, %r12+ andq %r11, %r12+ addq %rax, %r12+ xorl %r13d, %r13d+ movq 0x50(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x78(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movq 0x58(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x80(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ xorq %r9, %rax+ mulq %r8+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x88(%rsp), %rax+ xorq %r11, %rax+ mulq %r10+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x68(%rsp), %rax+ xorq %r9, %rax+ andq %r8, %r9+ negq %r9+ mulq %r8+ addq %rax, %r15+ adcq %rdx, %r9+ movq 0x90(%rsp), %rax+ xorq %r11, %rax+ movq %r11, %rdx+ andq %r10, %rdx+ subq %rdx, %r9+ mulq %r10+ addq %rax, %r15+ adcq %rdx, %r9+ movq %r12, 0x50(%rsp)+ movq %r13, 0x58(%rsp)+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r9, 0x70(%rsp)+ movabsq $0xe000000000000000, %r8+ addq 0x50(%rsp), %r8+ movq $0xffffffffffffffff, %r9+ adcq 0x58(%rsp), %r9+ movq $0x1fffffff, %r10+ adcq 0x60(%rsp), %r10+ movabsq $0x2000000000000000, %r11+ adcq 0x68(%rsp), %r11+ movabsq $0x1fffffffe0000000, %r12+ adcq 0x70(%rsp), %r12+ movq %r8, %rbx+ shlq $0x20, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %r8+ shrq $0x20, %r8+ addq %rbx, %r9+ adcq %r8, %r10+ adcq %rax, %r11+ adcq %rdx, %r12+ sbbq %rax, %rax+ movl $0xffffffff, %ebx+ andq %rax, %rbx+ movabsq $0xffffffff00000001, %rdx+ andq %rax, %rdx+ subq %rax, %r9+ movq %r9, 0x50(%rsp)+ sbbq %rbx, %r10+ movq %r10, 0x58(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x60(%rsp)+ sbbq %rdx, %r12+ movq %r12, 0x68(%rsp)+ movq 0x50(%rsp), %r8+ movq 0x58(%rsp), %r9+ movq 0x60(%rsp), %r10+ movq 0x68(%rsp), %r11+ movl $0x1, %eax+ movl $0xffffffff, %ebx+ leaq -0x2(%rax), %rcx+ leaq -0x1(%rbx), %rdx+ notq %rbx+ addq %r8, %rax+ adcq %r9, %rbx+ adcq %r10, %rcx+ adcq %r11, %rdx+ cmovaeq %r8, %rax+ cmovaeq %r9, %rbx+ cmovaeq %r10, %rcx+ cmovaeq %r11, %rdx+ movq 0xe0(%rsp), %rdi+ movq %rax, (%rdi)+ movq %rbx, 0x8(%rdi)+ movq %rcx, 0x10(%rdi)+ movq %rdx, 0x18(%rdi)+ CFI_INC_RSP(240)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_inv_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montmul_p256)++Lp256_scalarmulbase_alt_local_montmul_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq %rdx, %rcx+ movq (%rcx), %rbx+ movq (%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rcx), %rbx+ xorl %r13d, %r13d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rcx), %rbx+ xorl %r15d, %r15d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rcx), %rbx+ xorl %r8d, %r8d+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montmul_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montsqr_p256)++Lp256_scalarmulbase_alt_local_montsqr_p256:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ movq (%rsi), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x8(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x18(%rsi), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x10(%rsi), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x18(%rsi), %rbx+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x8(%rsi), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x10(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x18(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rdi)+ movq %r13, 0x8(%rdi)+ movq %r14, 0x10(%rdi)+ movq %r15, 0x18(%rdi)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_montsqr_p256)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp256_scalarmulbase_alt_local_p256_montjmixadd)++Lp256_scalarmulbase_alt_local_p256_montjmixadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(192)+ movq %rdx, %rbp+ movq 0x40(%rsi), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x48(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x58(%rsi), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x50(%rsi), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x58(%rsi), %rbx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x48(%rsi), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x50(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x58(%rsi), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq 0x20(%rbp), %rbx+ movq 0x40(%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x48(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x50(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x58(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rbp), %rbx+ xorl %r13d, %r13d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rbp), %rbx+ xorl %r15d, %r15d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rbp), %rbx+ xorl %r8d, %r8d+ movq 0x40(%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0x0(%rbp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rbp), %rbx+ xorl %r13d, %r13d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rbp), %rbx+ xorl %r15d, %r15d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rbp), %rbx+ xorl %r8d, %r8d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq 0x20(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rsp), %rbx+ xorl %r13d, %r13d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rsp), %rbx+ xorl %r15d, %r15d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rsp), %rbx+ xorl %r8d, %r8d+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x20(%rsp)+ movq %r13, 0x28(%rsp)+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq 0x40(%rsp), %rax+ subq (%rsi), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x8(%rsi), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x10(%rsi), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x18(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0xa0(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0xa8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0xb0(%rsp)+ adcq %rdx, %r9+ movq %r9, 0xb8(%rsp)+ movq 0x20(%rsp), %rax+ subq 0x20(%rsi), %rax+ movq 0x28(%rsp), %rcx+ sbbq 0x28(%rsi), %rcx+ movq 0x30(%rsp), %r8+ sbbq 0x30(%rsi), %r8+ movq 0x38(%rsp), %r9+ sbbq 0x38(%rsi), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x20(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x28(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x30(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x38(%rsp)+ movq 0xa0(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0xa8(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0xb8(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0xb0(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0xb8(%rsp), %rbx+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0xa8(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0xb0(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0xb8(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x20(%rsp), %rax+ movq %rax, %rbx+ mulq %rax+ movq %rax, %r8+ movq %rdx, %r15+ movq 0x28(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x38(%rsp), %rax+ movq %rax, %r13+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x30(%rsp), %rax+ movq %rax, %rbx+ mulq %r13+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq 0x38(%rsp), %rbx+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorl %ecx, %ecx+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %rcx, %rcx+ movq 0x28(%rsp), %rax+ mulq %rax+ addq %r15, %r9+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ movq 0x30(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %r15, %r15+ movq 0x38(%rsp), %rax+ mulq %rax+ negq %r15+ adcq %rax, %r14+ adcq %rcx, %rdx+ movq %rdx, %r15+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rcx, %rcx+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ xorl %r8d, %r8d+ movq %r9, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r8, %r14+ adcq %r8, %r15+ adcq %r8, %r8+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ xorl %r9d, %r9d+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ leaq -0x1(%rbx), %rbx+ adcq %r13, %rbx+ leaq -0x1(%r9), %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, (%rsp)+ movq %r13, 0x8(%rsp)+ movq %r14, 0x10(%rsp)+ movq %r15, 0x18(%rsp)+ movq (%rsi), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x8(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x10(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x18(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x40(%rsp), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x48(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x50(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x58(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x40(%rsp)+ movq %r13, 0x48(%rsp)+ movq %r14, 0x50(%rsp)+ movq %r15, 0x58(%rsp)+ movq (%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x40(%rsp), %rax+ subq 0x80(%rsp), %rax+ movq 0x48(%rsp), %rcx+ sbbq 0x88(%rsp), %rcx+ movq 0x50(%rsp), %r8+ sbbq 0x90(%rsp), %r8+ movq 0x58(%rsp), %r9+ sbbq 0x98(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x60(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x68(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x70(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x78(%rsp)+ movq 0x40(%rsi), %rbx+ movq 0xa0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x48(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x50(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x58(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0xa0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0xa0(%rsp)+ movq %r13, 0xa8(%rsp)+ movq %r14, 0xb0(%rsp)+ movq %r15, 0xb8(%rsp)+ movq (%rsp), %rax+ subq 0x40(%rsp), %rax+ movq 0x8(%rsp), %rcx+ sbbq 0x48(%rsp), %rcx+ movq 0x10(%rsp), %r8+ sbbq 0x50(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x58(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, (%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x8(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x10(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x18(%rsp)+ movq 0x80(%rsp), %rax+ subq (%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x8(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x20(%rsi), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x28(%rsi), %rbx+ xorl %r13d, %r13d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x30(%rsi), %rbx+ xorl %r15d, %r15d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x38(%rsi), %rbx+ xorl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x70(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x60(%rsp)+ movq %r13, 0x68(%rsp)+ movq %r14, 0x70(%rsp)+ movq %r15, 0x78(%rsp)+ movq 0x80(%rsp), %rbx+ movq 0x20(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x30(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x38(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x88(%rsp), %rbx+ xorl %r13d, %r13d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r14, %r14+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r14, %r14+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r14, %r14+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r14, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ xorl %r14d, %r14d+ movabsq $0x100000000, %rbx+ movq %r8, %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r15, %r15+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r8, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r15, %r15+ movq %r9, %rax+ mulq %rbx+ subq %r15, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x90(%rsp), %rbx+ xorl %r15d, %r15d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x98(%rsp), %rbx+ xorl %r8d, %r8d+ movq 0x20(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x30(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ xorl %r9d, %r9d+ movabsq $0x100000000, %rbx+ movq %r10, %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rcx, %rcx+ notq %rbx+ leaq 0x2(%rbx), %rbx+ movq %r10, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rcx, %rcx+ movq %r11, %rax+ mulq %rbx+ subq %rcx, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r9, %r8+ movl $0x1, %ecx+ addq %r12, %rcx+ decq %rbx+ adcq %r13, %rbx+ decq %r9+ movq %r9, %rax+ adcq %r14, %r9+ movl $0xfffffffe, %r11d+ adcq %r15, %r11+ adcq %r8, %rax+ cmovbq %rcx, %r12+ cmovbq %rbx, %r13+ cmovbq %r9, %r14+ cmovbq %r11, %r15+ movq %r12, 0x80(%rsp)+ movq %r13, 0x88(%rsp)+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq 0x80(%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x88(%rsp), %rcx+ sbbq 0x68(%rsp), %rcx+ movq 0x90(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x98(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movl $0xffffffff, %r10d+ sbbq %r11, %r11+ xorq %rdx, %rdx+ andq %r11, %r10+ subq %r10, %rdx+ addq %r11, %rax+ movq %rax, 0x80(%rsp)+ adcq %r10, %rcx+ movq %rcx, 0x88(%rsp)+ adcq $0x0, %r8+ movq %r8, 0x90(%rsp)+ adcq %rdx, %r9+ movq %r9, 0x98(%rsp)+ movq 0x40(%rsi), %rax+ movq 0x48(%rsi), %rdx+ orq 0x50(%rsi), %rax+ orq 0x58(%rsi), %rdx+ orq %rdx, %rax+ movq (%rsp), %r8+ movq 0x0(%rbp), %rax+ cmoveq %rax, %r8+ movq 0x8(%rsp), %r9+ movq 0x8(%rbp), %rax+ cmoveq %rax, %r9+ movq 0x10(%rsp), %r10+ movq 0x10(%rbp), %rax+ cmoveq %rax, %r10+ movq 0x18(%rsp), %r11+ movq 0x18(%rbp), %rax+ cmoveq %rax, %r11+ movq 0x80(%rsp), %r12+ movq 0x20(%rbp), %rax+ cmoveq %rax, %r12+ movq 0x88(%rsp), %r13+ movq 0x28(%rbp), %rax+ cmoveq %rax, %r13+ movq 0x90(%rsp), %r14+ movq 0x30(%rbp), %rax+ cmoveq %rax, %r14+ movq 0x98(%rsp), %r15+ movq 0x38(%rbp), %rax+ cmoveq %rax, %r15+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %r12, 0x20(%rdi)+ movq %r13, 0x28(%rdi)+ movq %r14, 0x30(%rdi)+ movq %r15, 0x38(%rdi)+ movq 0xa0(%rsp), %r8+ movq 0xa8(%rsp), %r9+ movq 0xb0(%rsp), %r10+ movq 0xb8(%rsp), %r11+ movl $0x1, %eax+ cmoveq %rax, %r8+ movabsq $0xffffffff00000000, %rax+ cmoveq %rax, %r9+ movq $0xffffffffffffffff, %rax+ cmoveq %rax, %r10+ movl $0xfffffffe, %eax+ cmoveq %rax, %r11+ movq %r8, 0x40(%rdi)+ movq %r9, 0x48(%rdi)+ movq %r10, 0x50(%rdi)+ movq %r11, 0x58(%rdi)+ CFI_INC_RSP(192)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp256_scalarmulbase_alt_local_p256_montjmixadd)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p384_montjscalarmul.S view
@@ -0,0 +1,7418 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery-Jacobian form scalar multiplication for P-384+// Input scalar[6], point[18]; output res[18]+//+// extern void p384_montjscalarmul+// (uint64_t res[static 18],+// const uint64_t scalar[static 6],+// const uint64_t point[static 18]);+//+// This function is a variant of its affine point version p384_scalarmul.+// Here, input and output points are assumed to be in Jacobian form with+// their coordinates in the Montgomery domain. Thus, if priming indicates+// Montgomery form, x' = (2^384 * x) mod p_384 etc., each point argument+// is a triple (x',y',z') representing the affine point (x/z^2,y/z^3) when+// z' is nonzero or the point at infinity (group identity) if z' = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-384, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_384) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p384_montjscalarmul)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p384_montjscalarmul)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p384_montjscalarmul)+++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 48+#define JACSIZE (3*NUMSIZE)++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE+// Uppercase syntactic variants make x86_att version simpler to generate.++#define SCALARB (0*NUMSIZE)+#define scalarb (0*NUMSIZE)(%rsp)+#define ACC (1*NUMSIZE)+#define acc (1*NUMSIZE)(%rsp)+#define TABENT (4*NUMSIZE)+#define tabent (4*NUMSIZE)(%rsp)++#define TAB (7*NUMSIZE)+#define tab (7*NUMSIZE)(%rsp)++#define res (55*NUMSIZE)(%rsp)++#define NSPACE 56*NUMSIZE++// Avoid using .rep for the sake of the BoringSSL/AWS-LC delocator,+// which doesn't accept repetitions, assembler macros etc.++#define selectblock_xz(I) \+ cmpq $I, %rdi ; \+ cmovzq TAB+JACSIZE*(I-1)(%rsp), %rax ; \+ cmovzq TAB+JACSIZE*(I-1)+8(%rsp), %rbx ; \+ cmovzq TAB+JACSIZE*(I-1)+16(%rsp), %rcx ; \+ cmovzq TAB+JACSIZE*(I-1)+24(%rsp), %rdx ; \+ cmovzq TAB+JACSIZE*(I-1)+32(%rsp), %r8 ; \+ cmovzq TAB+JACSIZE*(I-1)+40(%rsp), %r9 ; \+ cmovzq TAB+JACSIZE*(I-1)+96(%rsp), %r10 ; \+ cmovzq TAB+JACSIZE*(I-1)+104(%rsp), %r11 ; \+ cmovzq TAB+JACSIZE*(I-1)+112(%rsp), %r12 ; \+ cmovzq TAB+JACSIZE*(I-1)+120(%rsp), %r13 ; \+ cmovzq TAB+JACSIZE*(I-1)+128(%rsp), %r14 ; \+ cmovzq TAB+JACSIZE*(I-1)+136(%rsp), %r15++#define selectblock_y(I) \+ cmpq $I, %rdi ; \+ cmovzq TAB+JACSIZE*(I-1)+48(%rsp), %rax ; \+ cmovzq TAB+JACSIZE*(I-1)+56(%rsp), %rbx ; \+ cmovzq TAB+JACSIZE*(I-1)+64(%rsp), %rcx ; \+ cmovzq TAB+JACSIZE*(I-1)+72(%rsp), %rdx ; \+ cmovzq TAB+JACSIZE*(I-1)+80(%rsp), %r8 ; \+ cmovzq TAB+JACSIZE*(I-1)+88(%rsp), %r9++S2N_BN_SYMBOL(p384_montjscalarmul):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ CFI_CALL(Lp384_montjscalarmul_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p384_montjscalarmul)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_standard)++Lp384_montjscalarmul_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ movq %rdi, res++// Reduce the input scalar mod n_384, i.e. conditionally subtract n_384.+// Store it to "scalarb".++ movq (%rsi), %r8+ movq $0xecec196accc52973, %rax+ subq %rax, %r8+ movq 8(%rsi), %r9+ movq $0x581a0db248b0a77a, %rax+ sbbq %rax, %r9+ movq 16(%rsi), %r10+ movq $0xc7634d81f4372ddf, %rax+ sbbq %rax, %r10+ movq 24(%rsi), %r11+ movq $0xffffffffffffffff, %rax+ sbbq %rax, %r11+ movq 32(%rsi), %r12+ sbbq %rax, %r12+ movq 40(%rsi), %r13+ sbbq %rax, %r13++ cmovcq (%rsi), %r8+ cmovcq 8(%rsi), %r9+ cmovcq 16(%rsi), %r10+ cmovcq 24(%rsi), %r11+ cmovcq 32(%rsi), %r12+ cmovcq 40(%rsi), %r13++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)++// Set the tab[0] table entry to the input point = 1 * P++ movq (%rdx), %rax+ movq %rax, TAB(%rsp)+ movq 8(%rdx), %rax+ movq %rax, TAB+8(%rsp)+ movq 16(%rdx), %rax+ movq %rax, TAB+16(%rsp)+ movq 24(%rdx), %rax+ movq %rax, TAB+24(%rsp)+ movq 32(%rdx), %rax+ movq %rax, TAB+32(%rsp)+ movq 40(%rdx), %rax+ movq %rax, TAB+40(%rsp)++ movq 48(%rdx), %rax+ movq %rax, TAB+48(%rsp)+ movq 56(%rdx), %rax+ movq %rax, TAB+56(%rsp)+ movq 64(%rdx), %rax+ movq %rax, TAB+64(%rsp)+ movq 72(%rdx), %rax+ movq %rax, TAB+72(%rsp)+ movq 80(%rdx), %rax+ movq %rax, TAB+80(%rsp)+ movq 88(%rdx), %rax+ movq %rax, TAB+88(%rsp)++ movq 96(%rdx), %rax+ movq %rax, TAB+96(%rsp)+ movq 104(%rdx), %rax+ movq %rax, TAB+104(%rsp)+ movq 112(%rdx), %rax+ movq %rax, TAB+112(%rsp)+ movq 120(%rdx), %rax+ movq %rax, TAB+120(%rsp)+ movq 128(%rdx), %rax+ movq %rax, TAB+128(%rsp)+ movq 136(%rdx), %rax+ movq %rax, TAB+136(%rsp)++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ leaq TAB+JACSIZE*1(%rsp), %rdi+ leaq TAB(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq TAB+JACSIZE*2(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ leaq TAB+JACSIZE*3(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq TAB+JACSIZE*4(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ leaq TAB+JACSIZE*5(%rsp), %rdi+ leaq TAB+JACSIZE*2(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq TAB+JACSIZE*6(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ leaq TAB+JACSIZE*7(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq TAB+JACSIZE*8(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ leaq TAB+JACSIZE*9(%rsp), %rdi+ leaq TAB+JACSIZE*4(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq TAB+JACSIZE*10(%rsp), %rdi+ leaq TAB+JACSIZE*9(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ leaq TAB+JACSIZE*11(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq TAB+JACSIZE*12(%rsp), %rdi+ leaq TAB+JACSIZE*11(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ leaq TAB+JACSIZE*13(%rsp), %rdi+ leaq TAB+JACSIZE*6(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq TAB+JACSIZE*14(%rsp), %rdi+ leaq TAB+JACSIZE*13(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ leaq TAB+JACSIZE*15(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically to use fewer large constant loads.+//+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x4210842108421084+// 0x8421084210842108+// 0x0842108421084210++ movq $0x1084210842108421, %rax+ movq %rax, %rcx+ shrq $1, %rax+ movq SCALARB(%rsp), %r8+ addq %rax, %r8+ movq SCALARB+8(%rsp), %r9+ adcq %rcx, %r9+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+16(%rsp), %r10+ adcq %rcx, %r10+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+24(%rsp), %r11+ adcq %rcx, %r11+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+32(%rsp), %r12+ adcq %rcx, %r12+ movq SCALARB+40(%rsp), %r13+ adcq %rax, %r13+ sbbq %rdi, %rdi+ negq %rdi++// Record the top bitfield in %rdi then shift the whole scalar left 4 bits+// to align the top of the next bitfield with the MSB (bits 379..383).++ shldq $4, %r13, %rdi+ shldq $4, %r12, %r13+ shldq $4, %r11, %r12+ shldq $4, %r10, %r11+ shldq $4, %r9, %r10+ shldq $4, %r8, %r9+ shlq $4, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)++// Initialize the accumulator to the corresponding entry using constant-time+// lookup in the table. This top digit, uniquely, is not recoded so there is+// no sign adjustment to make. On the x86 integer side we don't have enough+// registers to hold all the fields; this could be better done with SIMD+// registers anyway. So we do x and z coordinates in one sweep, y in another+// (this is a rehearsal for below where we might need to negate the y).++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ selectblock_xz(1)+ selectblock_xz(2)+ selectblock_xz(3)+ selectblock_xz(4)+ selectblock_xz(5)+ selectblock_xz(6)+ selectblock_xz(7)+ selectblock_xz(8)+ selectblock_xz(9)+ selectblock_xz(10)+ selectblock_xz(11)+ selectblock_xz(12)+ selectblock_xz(13)+ selectblock_xz(14)+ selectblock_xz(15)+ selectblock_xz(16)++ movq %rax, ACC(%rsp)+ movq %rbx, ACC+8(%rsp)+ movq %rcx, ACC+16(%rsp)+ movq %rdx, ACC+24(%rsp)+ movq %r8, ACC+32(%rsp)+ movq %r9, ACC+40(%rsp)+ movq %r10, ACC+96(%rsp)+ movq %r11, ACC+104(%rsp)+ movq %r12, ACC+112(%rsp)+ movq %r13, ACC+120(%rsp)+ movq %r14, ACC+128(%rsp)+ movq %r15, ACC+136(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d++ selectblock_y(1)+ selectblock_y(2)+ selectblock_y(3)+ selectblock_y(4)+ selectblock_y(5)+ selectblock_y(6)+ selectblock_y(7)+ selectblock_y(8)+ selectblock_y(9)+ selectblock_y(10)+ selectblock_y(11)+ selectblock_y(12)+ selectblock_y(13)+ selectblock_y(14)+ selectblock_y(15)+ selectblock_y(16)++ movq %rax, ACC+48(%rsp)+ movq %rbx, ACC+56(%rsp)+ movq %rcx, ACC+64(%rsp)+ movq %rdx, ACC+72(%rsp)+ movq %r8, ACC+80(%rsp)+ movq %r9, ACC+88(%rsp)++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++ movl $380, %ebp++Lp384_montjscalarmul_mainloop:+ subq $5, %rbp++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_p384_montjdouble)++// Choose the bitfield and adjust it to sign and magnitude++ movq SCALARB(%rsp), %r8+ movq SCALARB+8(%rsp), %r9+ movq SCALARB+16(%rsp), %r10+ movq SCALARB+24(%rsp), %r11+ movq SCALARB+32(%rsp), %r12+ movq SCALARB+40(%rsp), %r13++ movq %r13, %rdi+ shrq $59, %rdi+ shldq $5, %r12, %r13+ shldq $5, %r11, %r12+ shldq $5, %r10, %r11+ shldq $5, %r9, %r10+ shldq $5, %r8, %r9+ shlq $5, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)++ subq $16, %rdi+ sbbq %rsi, %rsi // %rsi = sign of digit (-1 = negative)+ xorq %rsi, %rdi+ subq %rsi, %rdi // %rdi = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time+// Again, this is done in two sweeps, first doing x and z then y.++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ selectblock_xz(1)+ selectblock_xz(2)+ selectblock_xz(3)+ selectblock_xz(4)+ selectblock_xz(5)+ selectblock_xz(6)+ selectblock_xz(7)+ selectblock_xz(8)+ selectblock_xz(9)+ selectblock_xz(10)+ selectblock_xz(11)+ selectblock_xz(12)+ selectblock_xz(13)+ selectblock_xz(14)+ selectblock_xz(15)+ selectblock_xz(16)++ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)+ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+96(%rsp)+ movq %r11, TABENT+104(%rsp)+ movq %r12, TABENT+112(%rsp)+ movq %r13, TABENT+120(%rsp)+ movq %r14, TABENT+128(%rsp)+ movq %r15, TABENT+136(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d++ selectblock_y(1)+ selectblock_y(2)+ selectblock_y(3)+ selectblock_y(4)+ selectblock_y(5)+ selectblock_y(6)+ selectblock_y(7)+ selectblock_y(8)+ selectblock_y(9)+ selectblock_y(10)+ selectblock_y(11)+ selectblock_y(12)+ selectblock_y(13)+ selectblock_y(14)+ selectblock_y(15)+ selectblock_y(16)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_384 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).+// The digits of the prime p_384 are generated dynamically from+// the zeroth via not/lea to reduce the number of constant loads.++ movq %rax, %r10+ orq %rbx, %r10+ movq %rcx, %r11+ orq %rdx, %r11+ movq %r8, %r12+ orq %r9, %r12+ orq %r11, %r10+ orq %r12, %r10+ cmovzq %r10, %rsi++ movl $0xffffffff, %r10d+ movq %r10, %r11+ notq %r11+ leaq (%r10,%r11), %r13+ subq %rax, %r10+ leaq -1(%r13), %r12+ sbbq %rbx, %r11+ movq %r13, %r14+ sbbq %rcx, %r12+ sbbq %rdx, %r13+ movq %r14, %r15+ sbbq %r8, %r14+ sbbq %r9, %r15++ testq %rsi, %rsi+ cmovnzq %r10, %rax+ cmovnzq %r11, %rbx+ cmovnzq %r12, %rcx+ cmovnzq %r13, %rdx+ cmovnzq %r14, %r8+ cmovnzq %r15, %r9++ movq %rax, TABENT+48(%rsp)+ movq %rbx, TABENT+56(%rsp)+ movq %rcx, TABENT+64(%rsp)+ movq %rdx, TABENT+72(%rsp)+ movq %r8, TABENT+80(%rsp)+ movq %r9, TABENT+88(%rsp)++// Add to the accumulator++ leaq TABENT(%rsp), %rdx+ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_p384_montjadd)++ testq %rbp, %rbp+ jne Lp384_montjscalarmul_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ movq res, %rdi+ movq ACC(%rsp), %rax+ movq %rax, (%rdi)+ movq ACC+8(%rsp), %rax+ movq %rax, 8(%rdi)+ movq ACC+16(%rsp), %rax+ movq %rax, 16(%rdi)+ movq ACC+24(%rsp), %rax+ movq %rax, 24(%rdi)+ movq ACC+32(%rsp), %rax+ movq %rax, 32(%rdi)+ movq ACC+40(%rsp), %rax+ movq %rax, 40(%rdi)+ movq ACC+48(%rsp), %rax+ movq %rax, 48(%rdi)+ movq ACC+56(%rsp), %rax+ movq %rax, 56(%rdi)+ movq ACC+64(%rsp), %rax+ movq %rax, 64(%rdi)+ movq ACC+72(%rsp), %rax+ movq %rax, 72(%rdi)+ movq ACC+80(%rsp), %rax+ movq %rax, 80(%rdi)+ movq ACC+88(%rsp), %rax+ movq %rax, 88(%rdi)+ movq ACC+96(%rsp), %rax+ movq %rax, 96(%rdi)+ movq ACC+104(%rsp), %rax+ movq %rax, 104(%rdi)+ movq ACC+112(%rsp), %rax+ movq %rax, 112(%rdi)+ movq ACC+120(%rsp), %rax+ movq %rax, 120(%rdi)+ movq ACC+128(%rsp), %rax+ movq %rax, 128(%rdi)+ movq ACC+136(%rsp), %rax+ movq %rax, 136(%rdi)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p384_montjscalarmul)+#endif++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_p384_montjadd)++Lp384_montjscalarmul_p384_montjadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(352)+ movq %rsi, 0x150(%rsp)+ movq %rdx, 0x158(%rsp)+ movq 0x60(%rsi), %rdx+ mulxq 0x68(%rsi), %r9, %r10+ mulxq 0x78(%rsi), %r11, %r12+ mulxq 0x88(%rsi), %r13, %r14+ movq 0x78(%rsi), %rdx+ mulxq 0x80(%rsi), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x70(%rsi), %rdx+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x68(%rsi), %rdx+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x88(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x80(%rsi), %rdx+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x70(%rsi), %rdx+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x88(%rsi), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x88(%rsi), %rdx+ mulxq 0x80(%rsi), %rbx, %rbp+ mulxq 0x78(%rsi), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0x60(%rsi), %rdx+ mulxq 0x60(%rsi), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0x68(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x70(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x78(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x80(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x88(%rsi), %rdx+ mulxq %rdx, %rax, %rsi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rsi+ adoxq %rax, %rsi+ movq %rbx, (%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq (%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ movabsq $0xffffffff00000001, %rax+ movl $0xffffffff, %r9d+ movl $0x1, %r10d+ cmovaeq %r8, %rax+ cmovaeq %r8, %r9+ cmovaeq %r8, %r10+ addq %rax, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r8, %rbx+ adcq %r8, %rbp+ adcq %r8, %rsi+ movq %r14, (%rsp)+ movq %r15, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rbx, 0x18(%rsp)+ movq %rbp, 0x20(%rsp)+ movq %rsi, 0x28(%rsp)+ movq 0x158(%rsp), %rsi+ movq 0x60(%rsi), %rdx+ mulxq 0x68(%rsi), %r9, %r10+ mulxq 0x78(%rsi), %r11, %r12+ mulxq 0x88(%rsi), %r13, %r14+ movq 0x78(%rsi), %rdx+ mulxq 0x80(%rsi), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x70(%rsi), %rdx+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x68(%rsi), %rdx+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x88(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x80(%rsi), %rdx+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x70(%rsi), %rdx+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x88(%rsi), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x88(%rsi), %rdx+ mulxq 0x80(%rsi), %rbx, %rbp+ mulxq 0x78(%rsi), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0x60(%rsi), %rdx+ mulxq 0x60(%rsi), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0x68(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x70(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x78(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x80(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x88(%rsi), %rdx+ mulxq %rdx, %rax, %rsi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rsi+ adoxq %rax, %rsi+ movq %rbx, 0xf0(%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq 0xf0(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ movabsq $0xffffffff00000001, %rax+ movl $0xffffffff, %r9d+ movl $0x1, %r10d+ cmovaeq %r8, %rax+ cmovaeq %r8, %r9+ cmovaeq %r8, %r10+ addq %rax, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r8, %rbx+ adcq %r8, %rbp+ adcq %r8, %rsi+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %rcx, 0x100(%rsp)+ movq %rbx, 0x108(%rsp)+ movq %rbp, 0x110(%rsp)+ movq %rsi, 0x118(%rsp)+ movq 0x150(%rsp), %rsi+ movq 0x158(%rsp), %rcx+ movq 0x30(%rsi), %rdx+ xorl %r15d, %r15d+ mulxq 0x60(%rcx), %r8, %r9+ mulxq 0x68(%rcx), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x70(%rcx), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rcx), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x80(%rcx), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x88(%rcx), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x38(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rcx), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rcx), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rcx), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rcx), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x80(%rcx), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x88(%rcx), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x40(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rcx), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rcx), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rcx), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x78(%rcx), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x80(%rcx), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x88(%rcx), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x48(%rsi), %rdx+ xorl %r10d, %r10d+ mulxq 0x60(%rcx), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rcx), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rcx), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x78(%rcx), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x80(%rcx), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x88(%rcx), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x50(%rsi), %rdx+ xorl %r11d, %r11d+ mulxq 0x60(%rcx), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x68(%rcx), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x70(%rcx), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x78(%rcx), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x80(%rcx), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x88(%rcx), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x58(%rsi), %rdx+ xorl %r12d, %r12d+ mulxq 0x60(%rcx), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x68(%rcx), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x70(%rcx), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x78(%rcx), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x80(%rcx), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x88(%rcx), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x120(%rsp)+ movq %r15, 0x128(%rsp)+ movq %r8, 0x130(%rsp)+ movq %r9, 0x138(%rsp)+ movq %r10, 0x140(%rsp)+ movq %r11, 0x148(%rsp)+ movq 0x150(%rsp), %rsi+ movq 0x158(%rsp), %rcx+ movq 0x30(%rcx), %rdx+ xorl %r15d, %r15d+ mulxq 0x60(%rsi), %r8, %r9+ mulxq 0x68(%rsi), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x70(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x78(%rsi), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x80(%rsi), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x88(%rsi), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x38(%rcx), %rdx+ xorl %r8d, %r8d+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x70(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x88(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x40(%rcx), %rdx+ xorl %r9d, %r9d+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x70(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x88(%rsi), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x48(%rcx), %rdx+ xorl %r10d, %r10d+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x70(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x88(%rsi), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x50(%rcx), %rdx+ xorl %r11d, %r11d+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x70(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x88(%rsi), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x58(%rcx), %rdx+ xorl %r12d, %r12d+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x70(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x88(%rsi), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq %r8, 0x40(%rsp)+ movq %r9, 0x48(%rsp)+ movq %r10, 0x50(%rsp)+ movq %r11, 0x58(%rsp)+ movq 0x158(%rsp), %rcx+ movq (%rcx), %rdx+ xorl %r15d, %r15d+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x20(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x28(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x8(%rcx), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x10(%rcx), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x18(%rcx), %rdx+ xorl %r10d, %r10d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x20(%rcx), %rdx+ xorl %r11d, %r11d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x28(%rcx), %rdx+ xorl %r12d, %r12d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r8, 0x70(%rsp)+ movq %r9, 0x78(%rsp)+ movq %r10, 0x80(%rsp)+ movq %r11, 0x88(%rsp)+ movq 0x150(%rsp), %rsi+ movq (%rsi), %rdx+ xorl %r15d, %r15d+ mulxq 0xf0(%rsp), %r8, %r9+ mulxq 0xf8(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x100(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x108(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x110(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x118(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x8(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x10(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x18(%rsi), %rdx+ xorl %r10d, %r10d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x20(%rsi), %rdx+ xorl %r11d, %r11d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x28(%rsi), %rdx+ xorl %r12d, %r12d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %r8, 0xd0(%rsp)+ movq %r9, 0xd8(%rsp)+ movq %r10, 0xe0(%rsp)+ movq %r11, 0xe8(%rsp)+ movq 0x30(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq (%rsp), %r8, %r9+ mulxq 0x8(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x10(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x20(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x28(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x38(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x40(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x48(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x50(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x58(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq (%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x28(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq %r8, 0x40(%rsp)+ movq %r9, 0x48(%rsp)+ movq %r10, 0x50(%rsp)+ movq %r11, 0x58(%rsp)+ movq 0x120(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq 0xf0(%rsp), %r8, %r9+ mulxq 0xf8(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x100(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x108(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x110(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x118(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x128(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x130(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x138(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x140(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x148(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x120(%rsp)+ movq %r15, 0x128(%rsp)+ movq %r8, 0x130(%rsp)+ movq %r9, 0x138(%rsp)+ movq %r10, 0x140(%rsp)+ movq %r11, 0x148(%rsp)+ movq 0x60(%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x68(%rsp), %rdx+ sbbq 0xc8(%rsp), %rdx+ movq 0x70(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x78(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movq 0x80(%rsp), %r10+ sbbq 0xe0(%rsp), %r10+ movq 0x88(%rsp), %r11+ sbbq 0xe8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0xf0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xf8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x100(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x108(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x110(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq 0x30(%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x38(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0x40(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0x48(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0x50(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0x58(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0x30(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x38(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x40(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x48(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x50(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x58(%rsp)+ movq 0xf0(%rsp), %rdx+ mulxq 0xf8(%rsp), %r9, %r10+ mulxq 0x108(%rsp), %r11, %r12+ mulxq 0x118(%rsp), %r13, %r14+ movq 0x108(%rsp), %rdx+ mulxq 0x110(%rsp), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x100(%rsp), %rdx+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0xf8(%rsp), %rdx+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x118(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x110(%rsp), %rdx+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x100(%rsp), %rdx+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x118(%rsp), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x118(%rsp), %rdx+ mulxq 0x110(%rsp), %rbx, %rbp+ mulxq 0x108(%rsp), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0xf0(%rsp), %rdx+ mulxq 0xf0(%rsp), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0xf8(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x100(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x108(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x110(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x118(%rsp), %rdx+ mulxq %rdx, %rax, %rsi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rsi+ adoxq %rax, %rsi+ movq %rbx, 0x90(%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq 0x90(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ movabsq $0xffffffff00000001, %rax+ movl $0xffffffff, %r9d+ movl $0x1, %r10d+ cmovaeq %r8, %rax+ cmovaeq %r8, %r9+ cmovaeq %r8, %r10+ addq %rax, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r8, %rbx+ adcq %r8, %rbp+ adcq %r8, %rsi+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq %rcx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rbp, 0xb0(%rsp)+ movq %rsi, 0xb8(%rsp)+ movq 0x30(%rsp), %rdx+ mulxq 0x38(%rsp), %r9, %r10+ mulxq 0x48(%rsp), %r11, %r12+ mulxq 0x58(%rsp), %r13, %r14+ movq 0x48(%rsp), %rdx+ mulxq 0x50(%rsp), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x40(%rsp), %rdx+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsp), %rdx+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x58(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x50(%rsp), %rdx+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x40(%rsp), %rdx+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x58(%rsp), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x58(%rsp), %rdx+ mulxq 0x50(%rsp), %rbx, %rbp+ mulxq 0x48(%rsp), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0x30(%rsp), %rdx+ mulxq 0x30(%rsp), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0x38(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x40(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x48(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x50(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x58(%rsp), %rdx+ mulxq %rdx, %rax, %rsi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rsi+ adoxq %rax, %rsi+ movq %rbx, (%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq (%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rsi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rsi+ movq %r14, (%rsp)+ movq %r15, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rbx, 0x18(%rsp)+ movq %rbp, 0x20(%rsp)+ movq %rsi, 0x28(%rsp)+ movq 0xc0(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq 0x90(%rsp), %r8, %r9+ mulxq 0x98(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0xa0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xa8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0xb0(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0xb8(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0xc8(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0xd0(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0xd8(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0xe0(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0xe8(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %r8, 0xd0(%rsp)+ movq %r9, 0xd8(%rsp)+ movq %r10, 0xe0(%rsp)+ movq %r11, 0xe8(%rsp)+ movq 0x60(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq 0x90(%rsp), %r8, %r9+ mulxq 0x98(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0xa0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xa8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0xb0(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0xb8(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x68(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x70(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x78(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x80(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x88(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r8, 0x70(%rsp)+ movq %r9, 0x78(%rsp)+ movq %r10, 0x80(%rsp)+ movq %r11, 0x88(%rsp)+ movq (%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0xc8(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0xe0(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0xe8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, (%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ movq 0x60(%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x68(%rsp), %rdx+ sbbq 0xc8(%rsp), %rdx+ movq 0x70(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x78(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movq 0x80(%rsp), %r10+ sbbq 0xe0(%rsp), %r10+ movq 0x88(%rsp), %r11+ sbbq 0xe8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0x90(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x98(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xa0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xa8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xb0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xb8(%rsp)+ movq 0x150(%rsp), %rsi+ movq 0x60(%rsi), %rdx+ xorl %r15d, %r15d+ mulxq 0xf0(%rsp), %r8, %r9+ mulxq 0xf8(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x100(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x108(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x110(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x118(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x68(%rsi), %rdx+ xorl %r8d, %r8d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x70(%rsi), %rdx+ xorl %r9d, %r9d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x78(%rsi), %rdx+ xorl %r10d, %r10d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x80(%rsi), %rdx+ xorl %r11d, %r11d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x88(%rsi), %rdx+ xorl %r12d, %r12d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %r8, 0x100(%rsp)+ movq %r9, 0x108(%rsp)+ movq %r10, 0x110(%rsp)+ movq %r11, 0x118(%rsp)+ movq (%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0x68(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0x80(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0x88(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, (%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ movq 0xc0(%rsp), %rax+ subq (%rsp), %rax+ movq 0xc8(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0xd0(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0xd8(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0xe0(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0xe8(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0xc0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xc8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xd0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xd8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xe0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xe8(%rsp)+ movq 0x120(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq 0x90(%rsp), %r8, %r9+ mulxq 0x98(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0xa0(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0xa8(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0xb0(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0xb8(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x128(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x130(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x138(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x140(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x148(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0xb8(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq %r8, 0xa0(%rsp)+ movq %r9, 0xa8(%rsp)+ movq %r10, 0xb0(%rsp)+ movq %r11, 0xb8(%rsp)+ movq 0x158(%rsp), %rcx+ movq 0x60(%rcx), %rdx+ xorl %r15d, %r15d+ mulxq 0xf0(%rsp), %r8, %r9+ mulxq 0xf8(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x100(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x108(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x110(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x118(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x68(%rcx), %rdx+ xorl %r8d, %r8d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x70(%rcx), %rdx+ xorl %r9d, %r9d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x78(%rcx), %rdx+ xorl %r10d, %r10d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x80(%rcx), %rdx+ xorl %r11d, %r11d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x88(%rcx), %rdx+ xorl %r12d, %r12d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %r8, 0x100(%rsp)+ movq %r9, 0x108(%rsp)+ movq %r10, 0x110(%rsp)+ movq %r11, 0x118(%rsp)+ movq 0xc0(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq 0x30(%rsp), %r8, %r9+ mulxq 0x38(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x40(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x48(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x50(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x58(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0xc8(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x58(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0xd0(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x58(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0xd8(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x58(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0xe0(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x58(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0xe8(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x40(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x58(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %r8, 0xd0(%rsp)+ movq %r9, 0xd8(%rsp)+ movq %r10, 0xe0(%rsp)+ movq %r11, 0xe8(%rsp)+ movq 0xc0(%rsp), %rax+ subq 0x90(%rsp), %rax+ movq 0xc8(%rsp), %rdx+ sbbq 0x98(%rsp), %rdx+ movq 0xd0(%rsp), %r8+ sbbq 0xa0(%rsp), %r8+ movq 0xd8(%rsp), %r9+ sbbq 0xa8(%rsp), %r9+ movq 0xe0(%rsp), %r10+ sbbq 0xb0(%rsp), %r10+ movq 0xe8(%rsp), %r11+ sbbq 0xb8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0xc0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xc8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xd0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xd8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xe0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xe8(%rsp)+ movq 0x158(%rsp), %rcx+ movq 0x60(%rcx), %r8+ movq 0x68(%rcx), %r9+ movq 0x70(%rcx), %r10+ movq 0x78(%rcx), %r11+ movq 0x80(%rcx), %rbx+ movq 0x88(%rcx), %rbp+ movq %r8, %rax+ movq %r9, %rdx+ orq %r10, %rax+ orq %r11, %rdx+ orq %rbx, %rax+ orq %rbp, %rdx+ orq %rdx, %rax+ negq %rax+ sbbq %rax, %rax+ movq 0x150(%rsp), %rsi+ movq 0x60(%rsi), %r12+ movq 0x68(%rsi), %r13+ movq 0x70(%rsi), %r14+ movq 0x78(%rsi), %r15+ movq 0x80(%rsi), %rdx+ movq 0x88(%rsi), %rcx+ cmoveq %r12, %r8+ cmoveq %r13, %r9+ cmoveq %r14, %r10+ cmoveq %r15, %r11+ cmoveq %rdx, %rbx+ cmoveq %rcx, %rbp+ orq %r13, %r12+ orq %r15, %r14+ orq %rcx, %rdx+ orq %r14, %r12+ orq %r12, %rdx+ negq %rdx+ sbbq %rdx, %rdx+ cmpq %rdx, %rax+ cmoveq 0xf0(%rsp), %r8+ cmoveq 0xf8(%rsp), %r9+ cmoveq 0x100(%rsp), %r10+ cmoveq 0x108(%rsp), %r11+ cmoveq 0x110(%rsp), %rbx+ cmoveq 0x118(%rsp), %rbp+ movq %r8, 0xf0(%rsp)+ movq %r9, 0xf8(%rsp)+ movq %r10, 0x100(%rsp)+ movq %r11, 0x108(%rsp)+ movq %rbx, 0x110(%rsp)+ movq %rbp, 0x118(%rsp)+ movq 0x158(%rsp), %rcx+ movq 0x150(%rsp), %rsi+ movq (%rsp), %r8+ cmovbq (%rsi), %r8+ cmova (%rcx), %r8+ movq 0x8(%rsp), %r9+ cmovbq 0x8(%rsi), %r9+ cmova 0x8(%rcx), %r9+ movq 0x10(%rsp), %r10+ cmovbq 0x10(%rsi), %r10+ cmova 0x10(%rcx), %r10+ movq 0x18(%rsp), %r11+ cmovbq 0x18(%rsi), %r11+ cmova 0x18(%rcx), %r11+ movq 0x20(%rsp), %rbx+ cmovbq 0x20(%rsi), %rbx+ cmova 0x20(%rcx), %rbx+ movq 0x28(%rsp), %rbp+ cmovbq 0x28(%rsi), %rbp+ cmova 0x28(%rcx), %rbp+ movq 0xc0(%rsp), %r12+ cmovbq 0x30(%rsi), %r12+ cmova 0x30(%rcx), %r12+ movq 0xc8(%rsp), %r13+ cmovbq 0x38(%rsi), %r13+ cmova 0x38(%rcx), %r13+ movq 0xd0(%rsp), %r14+ cmovbq 0x40(%rsi), %r14+ cmova 0x40(%rcx), %r14+ movq 0xd8(%rsp), %r15+ cmovbq 0x48(%rsi), %r15+ cmova 0x48(%rcx), %r15+ movq 0xe0(%rsp), %rdx+ cmovbq 0x50(%rsi), %rdx+ cmova 0x50(%rcx), %rdx+ movq 0xe8(%rsp), %rax+ cmovbq 0x58(%rsi), %rax+ cmova 0x58(%rcx), %rax+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %rbx, 0x20(%rdi)+ movq %rbp, 0x28(%rdi)+ movq 0xf0(%rsp), %r8+ movq 0xf8(%rsp), %r9+ movq 0x100(%rsp), %r10+ movq 0x108(%rsp), %r11+ movq 0x110(%rsp), %rbx+ movq 0x118(%rsp), %rbp+ movq %r12, 0x30(%rdi)+ movq %r13, 0x38(%rdi)+ movq %r14, 0x40(%rdi)+ movq %r15, 0x48(%rdi)+ movq %rdx, 0x50(%rdi)+ movq %rax, 0x58(%rdi)+ movq %r8, 0x60(%rdi)+ movq %r9, 0x68(%rdi)+ movq %r10, 0x70(%rdi)+ movq %r11, 0x78(%rdi)+ movq %rbx, 0x80(%rdi)+ movq %rbp, 0x88(%rdi)+ CFI_INC_RSP(352)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_p384_montjadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_p384_montjdouble)++Lp384_montjscalarmul_p384_montjdouble:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(344)+ movq %rdi, 0x150(%rsp)+ movq 0x60(%rsi), %rdx+ mulxq 0x68(%rsi), %r9, %r10+ mulxq 0x78(%rsi), %r11, %r12+ mulxq 0x88(%rsi), %r13, %r14+ movq 0x78(%rsi), %rdx+ mulxq 0x80(%rsi), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x70(%rsi), %rdx+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x68(%rsi), %rdx+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x88(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x80(%rsi), %rdx+ mulxq 0x60(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x70(%rsi), %rdx+ mulxq 0x78(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x80(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x88(%rsi), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x88(%rsi), %rdx+ mulxq 0x80(%rsi), %rbx, %rbp+ mulxq 0x78(%rsi), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0x60(%rsi), %rdx+ mulxq 0x60(%rsi), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0x68(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x70(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x78(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x80(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x88(%rsi), %rdx+ mulxq %rdx, %rax, %rdi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rdi+ adoxq %rax, %rdi+ movq %rbx, (%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq (%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, (%rsp)+ movq %r15, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rbx, 0x18(%rsp)+ movq %rbp, 0x20(%rsp)+ movq %rdi, 0x28(%rsp)+ movq 0x30(%rsi), %rdx+ mulxq 0x38(%rsi), %r9, %r10+ mulxq 0x48(%rsi), %r11, %r12+ mulxq 0x58(%rsi), %r13, %r14+ movq 0x48(%rsi), %rdx+ mulxq 0x50(%rsi), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x40(%rsi), %rdx+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsi), %rdx+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x58(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x50(%rsi), %rdx+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x40(%rsi), %rdx+ mulxq 0x48(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x50(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x58(%rsi), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x58(%rsi), %rdx+ mulxq 0x50(%rsi), %rbx, %rbp+ mulxq 0x48(%rsi), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0x30(%rsi), %rdx+ mulxq 0x30(%rsi), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0x38(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x40(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x48(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x50(%rsi), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x58(%rsi), %rdx+ mulxq %rdx, %rax, %rdi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rdi+ adoxq %rax, %rdi+ movq %rbx, 0x30(%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq 0x30(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq %rcx, 0x40(%rsp)+ movq %rbx, 0x48(%rsp)+ movq %rbp, 0x50(%rsp)+ movq %rdi, 0x58(%rsp)+ movq (%rsi), %rax+ addq (%rsp), %rax+ movq 0x8(%rsi), %rcx+ adcq 0x8(%rsp), %rcx+ movq 0x10(%rsi), %r8+ adcq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ adcq 0x18(%rsp), %r9+ movq 0x20(%rsi), %r10+ adcq 0x20(%rsp), %r10+ movq 0x28(%rsi), %r11+ adcq 0x28(%rsp), %r11+ sbbq %rdx, %rdx+ movl $0x1, %ebx+ andq %rdx, %rbx+ movl $0xffffffff, %ebp+ andq %rbp, %rdx+ xorq %rbp, %rbp+ subq %rdx, %rbp+ addq %rbp, %rax+ movq %rax, 0xf0(%rsp)+ adcq %rdx, %rcx+ movq %rcx, 0xf8(%rsp)+ adcq %rbx, %r8+ movq %r8, 0x100(%rsp)+ adcq $0x0, %r9+ movq %r9, 0x108(%rsp)+ adcq $0x0, %r10+ movq %r10, 0x110(%rsp)+ adcq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq (%rsi), %rax+ subq (%rsp), %rax+ movq 0x8(%rsi), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x10(%rsi), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x20(%rsi), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x28(%rsi), %r11+ sbbq 0x28(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %ebx+ andq %rbx, %rcx+ xorq %rbx, %rbx+ subq %rcx, %rbx+ subq %rbx, %rax+ movq %rax, 0xc0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xc8(%rsp)+ sbbq %rax, %rax+ andq %rbx, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xd0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xd8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xe0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xe8(%rsp)+ movq 0xc0(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq 0xf0(%rsp), %r8, %r9+ mulxq 0xf8(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x100(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x108(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x110(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x118(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0xc8(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0xd0(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0xd8(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0xe0(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0xe8(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x118(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r8, 0x70(%rsp)+ movq %r9, 0x78(%rsp)+ movq %r10, 0x80(%rsp)+ movq %r11, 0x88(%rsp)+ movq 0x30(%rsi), %rax+ addq 0x60(%rsi), %rax+ movq 0x38(%rsi), %rcx+ adcq 0x68(%rsi), %rcx+ movq 0x40(%rsi), %r8+ adcq 0x70(%rsi), %r8+ movq 0x48(%rsi), %r9+ adcq 0x78(%rsi), %r9+ movq 0x50(%rsi), %r10+ adcq 0x80(%rsi), %r10+ movq 0x58(%rsi), %r11+ adcq 0x88(%rsi), %r11+ movl $0x0, %edx+ adcq %rdx, %rdx+ movabsq $0xffffffff00000001, %rbp+ addq %rbp, %rax+ movl $0xffffffff, %ebp+ adcq %rbp, %rcx+ adcq $0x1, %r8+ adcq $0x0, %r9+ adcq $0x0, %r10+ adcq $0x0, %r11+ adcq $0xffffffffffffffff, %rdx+ movl $0x1, %ebx+ andq %rdx, %rbx+ andq %rbp, %rdx+ xorq %rbp, %rbp+ subq %rdx, %rbp+ subq %rbp, %rax+ movq %rax, 0xf0(%rsp)+ sbbq %rdx, %rcx+ movq %rcx, 0xf8(%rsp)+ sbbq %rbx, %r8+ movq %r8, 0x100(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x108(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x110(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq 0x60(%rsp), %rdx+ mulxq 0x68(%rsp), %r9, %r10+ mulxq 0x78(%rsp), %r11, %r12+ mulxq 0x88(%rsp), %r13, %r14+ movq 0x78(%rsp), %rdx+ mulxq 0x80(%rsp), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x70(%rsp), %rdx+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x68(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x68(%rsp), %rdx+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x80(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x88(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x80(%rsp), %rdx+ mulxq 0x60(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x70(%rsp), %rdx+ mulxq 0x78(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x80(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x88(%rsp), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x88(%rsp), %rdx+ mulxq 0x80(%rsp), %rbx, %rbp+ mulxq 0x78(%rsp), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0x60(%rsp), %rdx+ mulxq 0x60(%rsp), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0x68(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x70(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x78(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x80(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x88(%rsp), %rdx+ mulxq %rdx, %rax, %rdi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rdi+ adoxq %rax, %rdi+ movq %rbx, 0x120(%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq 0x120(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0x120(%rsp)+ movq %r15, 0x128(%rsp)+ movq %rcx, 0x130(%rsp)+ movq %rbx, 0x138(%rsp)+ movq %rbp, 0x140(%rsp)+ movq %rdi, 0x148(%rsp)+ movq 0x30(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq (%rsi), %r8, %r9+ mulxq 0x8(%rsi), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x10(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsi), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x20(%rsi), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x28(%rsi), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x38(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x28(%rsi), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x40(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x28(%rsi), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x48(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x28(%rsi), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x50(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x28(%rsi), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x58(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x28(%rsi), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq %r8, 0xa0(%rsp)+ movq %r9, 0xa8(%rsp)+ movq %r10, 0xb0(%rsp)+ movq %r11, 0xb8(%rsp)+ movq 0xf0(%rsp), %rdx+ mulxq 0xf8(%rsp), %r9, %r10+ mulxq 0x108(%rsp), %r11, %r12+ mulxq 0x118(%rsp), %r13, %r14+ movq 0x108(%rsp), %rdx+ mulxq 0x110(%rsp), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x100(%rsp), %rdx+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0xf8(%rsp), %rdx+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x118(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x110(%rsp), %rdx+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x100(%rsp), %rdx+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x118(%rsp), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x118(%rsp), %rdx+ mulxq 0x110(%rsp), %rbx, %rbp+ mulxq 0x108(%rsp), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0xf0(%rsp), %rdx+ mulxq 0xf0(%rsp), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0xf8(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x100(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x108(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x110(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x118(%rsp), %rdx+ mulxq %rdx, %rax, %rdi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rdi+ adoxq %rax, %rdi+ movq %rbx, 0xc0(%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq 0xc0(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %rcx, 0xd0(%rsp)+ movq %rbx, 0xd8(%rsp)+ movq %rbp, 0xe0(%rsp)+ movq %rdi, 0xe8(%rsp)+ movabsq $0xffffffff, %r8+ subq 0x120(%rsp), %r8+ movabsq $0xffffffff00000000, %r9+ sbbq 0x128(%rsp), %r9+ movq $0xfffffffffffffffe, %r10+ sbbq 0x130(%rsp), %r10+ movq $0xffffffffffffffff, %r11+ sbbq 0x138(%rsp), %r11+ movq $0xffffffffffffffff, %r12+ sbbq 0x140(%rsp), %r12+ movq $0xffffffffffffffff, %r13+ sbbq 0x148(%rsp), %r13+ movq $0x9, %rdx+ mulxq %r8, %r8, %rax+ mulxq %r9, %r9, %rcx+ addq %rax, %r9+ mulxq %r10, %r10, %rax+ adcq %rcx, %r10+ mulxq %r11, %r11, %rcx+ adcq %rax, %r11+ mulxq %r12, %r12, %rax+ adcq %rcx, %r12+ mulxq %r13, %r13, %r14+ adcq %rax, %r13+ adcq $0x1, %r14+ xorl %ecx, %ecx+ movq $0xc, %rdx+ mulxq 0x90(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x98(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0xa0(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0xa8(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0xb0(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0xb8(%rsp), %rax, %rdx+ adcxq %rax, %r13+ adoxq %r14, %rdx+ adcxq %rcx, %rdx+ xorq %rcx, %rcx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ movl $0xffffffff, %eax+ mulxq %rax, %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ adcxq %rdx, %r10+ movl $0x0, %eax+ movl $0x0, %ecx+ adoxq %rax, %rax+ adcq %rax, %r11+ adcq %rcx, %r12+ adcq %rcx, %r13+ adcq %rcx, %rcx+ subq $0x1, %rcx+ movl $0xffffffff, %edx+ xorq %rax, %rax+ andq %rcx, %rdx+ subq %rdx, %rax+ andq $0x1, %rcx+ subq %rax, %r8+ movq %r8, 0x120(%rsp)+ sbbq %rdx, %r9+ movq %r9, 0x128(%rsp)+ sbbq %rcx, %r10+ movq %r10, 0x130(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x138(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x140(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x148(%rsp)+ movq 0xc0(%rsp), %rax+ subq (%rsp), %rax+ movq 0xc8(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0xd0(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0xd8(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0xe0(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0xe8(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %ebx+ andq %rbx, %rcx+ xorq %rbx, %rbx+ subq %rcx, %rbx+ subq %rbx, %rax+ movq %rax, 0xf0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xf8(%rsp)+ sbbq %rax, %rax+ andq %rbx, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x100(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x108(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x110(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq 0x30(%rsp), %rdx+ mulxq 0x38(%rsp), %r9, %r10+ mulxq 0x48(%rsp), %r11, %r12+ mulxq 0x58(%rsp), %r13, %r14+ movq 0x48(%rsp), %rdx+ mulxq 0x50(%rsp), %r15, %rcx+ xorl %ebp, %ebp+ movq 0x40(%rsp), %rdx+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq 0x38(%rsp), %rdx+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x58(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adcxq %rbp, %r15+ adoxq %rbp, %rcx+ adcq %rbp, %rcx+ xorl %ebp, %ebp+ movq 0x50(%rsp), %rdx+ mulxq 0x30(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq 0x40(%rsp), %rdx+ mulxq 0x48(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x50(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x58(%rsp), %rax, %rdx+ adcxq %rax, %r15+ adoxq %rdx, %rcx+ movq 0x58(%rsp), %rdx+ mulxq 0x50(%rsp), %rbx, %rbp+ mulxq 0x48(%rsp), %rax, %rdx+ adcxq %rax, %rcx+ adoxq %rdx, %rbx+ movl $0x0, %eax+ adcxq %rax, %rbx+ adoxq %rax, %rbp+ adcq %rax, %rbp+ xorq %rax, %rax+ movq 0x30(%rsp), %rdx+ mulxq 0x30(%rsp), %r8, %rax+ adcxq %r9, %r9+ adoxq %rax, %r9+ movq 0x38(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r10, %r10+ adoxq %rax, %r10+ adcxq %r11, %r11+ adoxq %rdx, %r11+ movq 0x40(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r12, %r12+ adoxq %rax, %r12+ adcxq %r13, %r13+ adoxq %rdx, %r13+ movq 0x48(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %r14, %r14+ adoxq %rax, %r14+ adcxq %r15, %r15+ adoxq %rdx, %r15+ movq 0x50(%rsp), %rdx+ mulxq %rdx, %rax, %rdx+ adcxq %rcx, %rcx+ adoxq %rax, %rcx+ adcxq %rbx, %rbx+ adoxq %rdx, %rbx+ movq 0x58(%rsp), %rdx+ mulxq %rdx, %rax, %rdi+ adcxq %rbp, %rbp+ adoxq %rax, %rbp+ movl $0x0, %eax+ adcxq %rax, %rdi+ adoxq %rax, %rdi+ movq %rbx, 0xc0(%rsp)+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r8, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r8+ addq %rbx, %rax+ adcq %rdx, %r8+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r9+ sbbq %r8, %r10+ sbbq %rbx, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rdx, %r8+ sbbq $0x0, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r9, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r9+ addq %rbx, %rax+ adcq %rdx, %r9+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r10+ sbbq %r9, %r11+ sbbq %rbx, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rdx, %r9+ sbbq $0x0, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r10, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r10+ addq %rbx, %rax+ adcq %rdx, %r10+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r11+ sbbq %r10, %r12+ sbbq %rbx, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rdx, %r10+ sbbq $0x0, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r11, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r11+ addq %rbx, %rax+ adcq %rdx, %r11+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r12+ sbbq %r11, %r13+ sbbq %rbx, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rdx, %r11+ sbbq $0x0, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r12, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r12+ addq %rbx, %rax+ adcq %rdx, %r12+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r13+ sbbq %r12, %r8+ sbbq %rbx, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rdx, %r12+ sbbq $0x0, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %r13, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %rbx, %r13+ addq %rbx, %rax+ adcq %rdx, %r13+ movl $0x0, %ebx+ adcq %rbx, %rbx+ subq %rax, %r8+ sbbq %r13, %r9+ sbbq %rbx, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rdx, %r13+ sbbq $0x0, %r13+ movq 0xc0(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %rcx, 0xd0(%rsp)+ movq %rbx, 0xd8(%rsp)+ movq %rbp, 0xe0(%rsp)+ movq %rdi, 0xe8(%rsp)+ movq 0x150(%rsp), %rdi+ movq 0xf0(%rsp), %rax+ subq 0x30(%rsp), %rax+ movq 0xf8(%rsp), %rdx+ sbbq 0x38(%rsp), %rdx+ movq 0x100(%rsp), %r8+ sbbq 0x40(%rsp), %r8+ movq 0x108(%rsp), %r9+ sbbq 0x48(%rsp), %r9+ movq 0x110(%rsp), %r10+ sbbq 0x50(%rsp), %r10+ movq 0x118(%rsp), %r11+ sbbq 0x58(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %ebx+ andq %rbx, %rcx+ xorq %rbx, %rbx+ subq %rcx, %rbx+ subq %rbx, %rax+ movq %rax, 0x60(%rdi)+ sbbq %rcx, %rdx+ movq %rdx, 0x68(%rdi)+ sbbq %rax, %rax+ andq %rbx, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x70(%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x78(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x80(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x88(%rdi)+ movq 0x60(%rsp), %rdx+ xorl %r15d, %r15d+ mulxq 0x120(%rsp), %r8, %r9+ mulxq 0x128(%rsp), %rbx, %r10+ addq %rbx, %r9+ mulxq 0x130(%rsp), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x138(%rsp), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x140(%rsp), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x148(%rsp), %rbx, %r14+ adcq %rbx, %r13+ adcq %r15, %r14+ movq %r8, %rdx+ shlq $0x20, %rdx+ addq %r8, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r8, %rbx+ adcq %r8, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rbx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rdx+ addq %rdx, %r14+ adcq $0x0, %r15+ movq 0x68(%rsp), %rdx+ xorl %r8d, %r8d+ mulxq 0x120(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x128(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x130(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x138(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x140(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ adoxq %r8, %r15+ mulxq 0x148(%rsp), %rax, %rbx+ adcq %rax, %r14+ adcq %rbx, %r15+ adcq %r8, %r8+ movq %r9, %rdx+ shlq $0x20, %rdx+ addq %r9, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r9, %rbx+ adcq %r9, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rbx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rdx+ addq %rdx, %r15+ adcq $0x0, %r8+ movq 0x70(%rsp), %rdx+ xorl %r9d, %r9d+ mulxq 0x120(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x128(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x130(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x138(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x140(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ adoxq %r9, %r8+ mulxq 0x148(%rsp), %rax, %rbx+ adcq %rax, %r15+ adcq %rbx, %r8+ adcq %r9, %r9+ movq %r10, %rdx+ shlq $0x20, %rdx+ addq %r10, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r10, %rbx+ adcq %r10, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rbx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rdx+ addq %rdx, %r8+ adcq $0x0, %r9+ movq 0x78(%rsp), %rdx+ xorl %r10d, %r10d+ mulxq 0x120(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x128(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x130(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x138(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x140(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ adoxq %r10, %r9+ mulxq 0x148(%rsp), %rax, %rbx+ adcq %rax, %r8+ adcq %rbx, %r9+ adcq %r10, %r10+ movq %r11, %rdx+ shlq $0x20, %rdx+ addq %r11, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r11, %rbx+ adcq %r11, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rbx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rdx+ addq %rdx, %r9+ adcq $0x0, %r10+ movq 0x80(%rsp), %rdx+ xorl %r11d, %r11d+ mulxq 0x120(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x128(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x130(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x138(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x140(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ adoxq %r11, %r10+ mulxq 0x148(%rsp), %rax, %rbx+ adcq %rax, %r9+ adcq %rbx, %r10+ adcq %r11, %r11+ movq %r12, %rdx+ shlq $0x20, %rdx+ addq %r12, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r12, %rbx+ adcq %r12, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rbx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rdx+ addq %rdx, %r10+ adcq $0x0, %r11+ movq 0x88(%rsp), %rdx+ xorl %r12d, %r12d+ mulxq 0x120(%rsp), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x128(%rsp), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x130(%rsp), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x138(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x140(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ adoxq %r12, %r11+ mulxq 0x148(%rsp), %rax, %rbx+ adcq %rax, %r10+ adcq %rbx, %r11+ adcq %r12, %r12+ movq %r13, %rdx+ shlq $0x20, %rdx+ addq %r13, %rdx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rbx, %rax+ movl $0xffffffff, %ebx+ mulxq %rbx, %r13, %rbx+ adcq %r13, %rax+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rbx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rdx+ addq %rdx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %r8, 0x100(%rsp)+ movq %r9, 0x108(%rsp)+ movq %r10, 0x110(%rsp)+ movq %r11, 0x118(%rsp)+ movq 0xb8(%rsp), %rdx+ movq %rdx, %r13+ shrq $0x3e, %rdx+ movq 0xb0(%rsp), %r12+ shldq $0x2, %r12, %r13+ movq 0xa8(%rsp), %r11+ shldq $0x2, %r11, %r12+ movq 0xa0(%rsp), %r10+ shldq $0x2, %r10, %r11+ movq 0x98(%rsp), %r9+ shldq $0x2, %r9, %r10+ movq 0x90(%rsp), %r8+ shldq $0x2, %r8, %r9+ shlq $0x2, %r8+ addq $0x1, %rdx+ subq 0x120(%rsp), %r8+ sbbq 0x128(%rsp), %r9+ sbbq 0x130(%rsp), %r10+ sbbq 0x138(%rsp), %r11+ sbbq 0x140(%rsp), %r12+ sbbq 0x148(%rsp), %r13+ sbbq $0x0, %rdx+ xorq %rcx, %rcx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ movl $0xffffffff, %eax+ mulxq %rax, %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ adcxq %rdx, %r10+ movl $0x0, %eax+ movl $0x0, %ecx+ adoxq %rax, %rax+ adcq %rax, %r11+ adcq %rcx, %r12+ adcq %rcx, %r13+ adcq %rcx, %rcx+ subq $0x1, %rcx+ movl $0xffffffff, %edx+ xorq %rax, %rax+ andq %rcx, %rdx+ subq %rdx, %rax+ andq $0x1, %rcx+ subq %rax, %r8+ movq %r8, (%rdi)+ sbbq %rdx, %r9+ movq %r9, 0x8(%rdi)+ sbbq %rcx, %r10+ movq %r10, 0x10(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x18(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x20(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x28(%rdi)+ movabsq $0xffffffff, %r8+ subq 0xc0(%rsp), %r8+ movabsq $0xffffffff00000000, %r9+ sbbq 0xc8(%rsp), %r9+ movq $0xfffffffffffffffe, %r10+ sbbq 0xd0(%rsp), %r10+ movq $0xffffffffffffffff, %r11+ sbbq 0xd8(%rsp), %r11+ movq $0xffffffffffffffff, %r12+ sbbq 0xe0(%rsp), %r12+ movq $0xffffffffffffffff, %r13+ sbbq 0xe8(%rsp), %r13+ movq %r13, %r14+ shrq $0x3d, %r14+ shldq $0x3, %r12, %r13+ shldq $0x3, %r11, %r12+ shldq $0x3, %r10, %r11+ shldq $0x3, %r9, %r10+ shldq $0x3, %r8, %r9+ shlq $0x3, %r8+ addq $0x1, %r14+ xorl %ecx, %ecx+ movq $0x3, %rdx+ mulxq 0xf0(%rsp), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0xf8(%rsp), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x100(%rsp), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x108(%rsp), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x110(%rsp), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x118(%rsp), %rax, %rdx+ adcxq %rax, %r13+ adoxq %r14, %rdx+ adcxq %rcx, %rdx+ xorq %rcx, %rcx+ movabsq $0xffffffff00000001, %rax+ mulxq %rax, %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ movl $0xffffffff, %eax+ mulxq %rax, %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ adcxq %rdx, %r10+ movl $0x0, %eax+ movl $0x0, %ecx+ adoxq %rax, %rax+ adcq %rax, %r11+ adcq %rcx, %r12+ adcq %rcx, %r13+ adcq %rcx, %rcx+ subq $0x1, %rcx+ movl $0xffffffff, %edx+ xorq %rax, %rax+ andq %rcx, %rdx+ subq %rdx, %rax+ andq $0x1, %rcx+ subq %rax, %r8+ movq %r8, 0x30(%rdi)+ sbbq %rdx, %r9+ movq %r9, 0x38(%rdi)+ sbbq %rcx, %r10+ movq %r10, 0x40(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x48(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x50(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x58(%rdi)+ CFI_INC_RSP(344)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_p384_montjdouble)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p384_montjscalarmul_alt.S view
@@ -0,0 +1,9440 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Montgomery-Jacobian form scalar multiplication for P-384+// Input scalar[6], point[18]; output res[18]+//+// extern void p384_montjscalarmul_alt+// (uint64_t res[static 18],+// const uint64_t scalar[static 6],+// const uint64_t point[static 18]);+//+// This function is a variant of its affine point version p384_scalarmul.+// Here, input and output points are assumed to be in Jacobian form with+// their coordinates in the Montgomery domain. Thus, if priming indicates+// Montgomery form, x' = (2^384 * x) mod p_384 etc., each point argument+// is a triple (x',y',z') representing the affine point (x/z^2,y/z^3) when+// z' is nonzero or the point at infinity (group identity) if z' = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-384, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_384) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p384_montjscalarmul_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p384_montjscalarmul_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p384_montjscalarmul_alt)+++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 48+#define JACSIZE (3*NUMSIZE)++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE+// Uppercase syntactic variants make x86_att version simpler to generate.++#define SCALARB (0*NUMSIZE)+#define scalarb (0*NUMSIZE)(%rsp)+#define ACC (1*NUMSIZE)+#define acc (1*NUMSIZE)(%rsp)+#define TABENT (4*NUMSIZE)+#define tabent (4*NUMSIZE)(%rsp)++#define TAB (7*NUMSIZE)+#define tab (7*NUMSIZE)(%rsp)++#define res (55*NUMSIZE)(%rsp)++#define NSPACE 56*NUMSIZE++// Avoid using .rep for the sake of the BoringSSL/AWS-LC delocator,+// which doesn't accept repetitions, assembler macros etc.++#define selectblock_xz(I) \+ cmpq $I, %rdi ; \+ cmovzq TAB+JACSIZE*(I-1)(%rsp), %rax ; \+ cmovzq TAB+JACSIZE*(I-1)+8(%rsp), %rbx ; \+ cmovzq TAB+JACSIZE*(I-1)+16(%rsp), %rcx ; \+ cmovzq TAB+JACSIZE*(I-1)+24(%rsp), %rdx ; \+ cmovzq TAB+JACSIZE*(I-1)+32(%rsp), %r8 ; \+ cmovzq TAB+JACSIZE*(I-1)+40(%rsp), %r9 ; \+ cmovzq TAB+JACSIZE*(I-1)+96(%rsp), %r10 ; \+ cmovzq TAB+JACSIZE*(I-1)+104(%rsp), %r11 ; \+ cmovzq TAB+JACSIZE*(I-1)+112(%rsp), %r12 ; \+ cmovzq TAB+JACSIZE*(I-1)+120(%rsp), %r13 ; \+ cmovzq TAB+JACSIZE*(I-1)+128(%rsp), %r14 ; \+ cmovzq TAB+JACSIZE*(I-1)+136(%rsp), %r15++#define selectblock_y(I) \+ cmpq $I, %rdi ; \+ cmovzq TAB+JACSIZE*(I-1)+48(%rsp), %rax ; \+ cmovzq TAB+JACSIZE*(I-1)+56(%rsp), %rbx ; \+ cmovzq TAB+JACSIZE*(I-1)+64(%rsp), %rcx ; \+ cmovzq TAB+JACSIZE*(I-1)+72(%rsp), %rdx ; \+ cmovzq TAB+JACSIZE*(I-1)+80(%rsp), %r8 ; \+ cmovzq TAB+JACSIZE*(I-1)+88(%rsp), %r9++S2N_BN_SYMBOL(p384_montjscalarmul_alt):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p384_montjscalarmul_alt)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_alt_standard)++Lp384_montjscalarmul_alt_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ movq %rdi, res++// Reduce the input scalar mod n_384, i.e. conditionally subtract n_384.+// Store it to "scalarb".++ movq (%rsi), %r8+ movq $0xecec196accc52973, %rax+ subq %rax, %r8+ movq 8(%rsi), %r9+ movq $0x581a0db248b0a77a, %rax+ sbbq %rax, %r9+ movq 16(%rsi), %r10+ movq $0xc7634d81f4372ddf, %rax+ sbbq %rax, %r10+ movq 24(%rsi), %r11+ movq $0xffffffffffffffff, %rax+ sbbq %rax, %r11+ movq 32(%rsi), %r12+ sbbq %rax, %r12+ movq 40(%rsi), %r13+ sbbq %rax, %r13++ cmovcq (%rsi), %r8+ cmovcq 8(%rsi), %r9+ cmovcq 16(%rsi), %r10+ cmovcq 24(%rsi), %r11+ cmovcq 32(%rsi), %r12+ cmovcq 40(%rsi), %r13++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)++// Set the tab[0] table entry to the input point = 1 * P++ movq (%rdx), %rax+ movq %rax, TAB(%rsp)+ movq 8(%rdx), %rax+ movq %rax, TAB+8(%rsp)+ movq 16(%rdx), %rax+ movq %rax, TAB+16(%rsp)+ movq 24(%rdx), %rax+ movq %rax, TAB+24(%rsp)+ movq 32(%rdx), %rax+ movq %rax, TAB+32(%rsp)+ movq 40(%rdx), %rax+ movq %rax, TAB+40(%rsp)++ movq 48(%rdx), %rax+ movq %rax, TAB+48(%rsp)+ movq 56(%rdx), %rax+ movq %rax, TAB+56(%rsp)+ movq 64(%rdx), %rax+ movq %rax, TAB+64(%rsp)+ movq 72(%rdx), %rax+ movq %rax, TAB+72(%rsp)+ movq 80(%rdx), %rax+ movq %rax, TAB+80(%rsp)+ movq 88(%rdx), %rax+ movq %rax, TAB+88(%rsp)++ movq 96(%rdx), %rax+ movq %rax, TAB+96(%rsp)+ movq 104(%rdx), %rax+ movq %rax, TAB+104(%rsp)+ movq 112(%rdx), %rax+ movq %rax, TAB+112(%rsp)+ movq 120(%rdx), %rax+ movq %rax, TAB+120(%rsp)+ movq 128(%rdx), %rax+ movq %rax, TAB+128(%rsp)+ movq 136(%rdx), %rax+ movq %rax, TAB+136(%rsp)++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ leaq TAB+JACSIZE*1(%rsp), %rdi+ leaq TAB(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq TAB+JACSIZE*2(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ leaq TAB+JACSIZE*3(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq TAB+JACSIZE*4(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ leaq TAB+JACSIZE*5(%rsp), %rdi+ leaq TAB+JACSIZE*2(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq TAB+JACSIZE*6(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ leaq TAB+JACSIZE*7(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq TAB+JACSIZE*8(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ leaq TAB+JACSIZE*9(%rsp), %rdi+ leaq TAB+JACSIZE*4(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq TAB+JACSIZE*10(%rsp), %rdi+ leaq TAB+JACSIZE*9(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ leaq TAB+JACSIZE*11(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq TAB+JACSIZE*12(%rsp), %rdi+ leaq TAB+JACSIZE*11(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ leaq TAB+JACSIZE*13(%rsp), %rdi+ leaq TAB+JACSIZE*6(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq TAB+JACSIZE*14(%rsp), %rdi+ leaq TAB+JACSIZE*13(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ leaq TAB+JACSIZE*15(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically to use fewer large constant loads.+//+// 0x0842108421084210+// 0x1084210842108421+// 0x2108421084210842+// 0x4210842108421084+// 0x8421084210842108+// 0x0842108421084210++ movq $0x1084210842108421, %rax+ movq %rax, %rcx+ shrq $1, %rax+ movq SCALARB(%rsp), %r8+ addq %rax, %r8+ movq SCALARB+8(%rsp), %r9+ adcq %rcx, %r9+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+16(%rsp), %r10+ adcq %rcx, %r10+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+24(%rsp), %r11+ adcq %rcx, %r11+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+32(%rsp), %r12+ adcq %rcx, %r12+ movq SCALARB+40(%rsp), %r13+ adcq %rax, %r13+ sbbq %rdi, %rdi+ negq %rdi++// Record the top bitfield in %rdi then shift the whole scalar left 4 bits+// to align the top of the next bitfield with the MSB (bits 379..383).++ shldq $4, %r13, %rdi+ shldq $4, %r12, %r13+ shldq $4, %r11, %r12+ shldq $4, %r10, %r11+ shldq $4, %r9, %r10+ shldq $4, %r8, %r9+ shlq $4, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)++// Initialize the accumulator to the corresponding entry using constant-time+// lookup in the table. This top digit, uniquely, is not recoded so there is+// no sign adjustment to make. On the x86 integer side we don't have enough+// registers to hold all the fields; this could be better done with SIMD+// registers anyway. So we do x and z coordinates in one sweep, y in another+// (this is a rehearsal for below where we might need to negate the y).++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++ selectblock_xz(1)+ selectblock_xz(2)+ selectblock_xz(3)+ selectblock_xz(4)+ selectblock_xz(5)+ selectblock_xz(6)+ selectblock_xz(7)+ selectblock_xz(8)+ selectblock_xz(9)+ selectblock_xz(10)+ selectblock_xz(11)+ selectblock_xz(12)+ selectblock_xz(13)+ selectblock_xz(14)+ selectblock_xz(15)+ selectblock_xz(16)++ movq %rax, ACC(%rsp)+ movq %rbx, ACC+8(%rsp)+ movq %rcx, ACC+16(%rsp)+ movq %rdx, ACC+24(%rsp)+ movq %r8, ACC+32(%rsp)+ movq %r9, ACC+40(%rsp)+ movq %r10, ACC+96(%rsp)+ movq %r11, ACC+104(%rsp)+ movq %r12, ACC+112(%rsp)+ movq %r13, ACC+120(%rsp)+ movq %r14, ACC+128(%rsp)+ movq %r15, ACC+136(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d++ selectblock_y(1)+ selectblock_y(2)+ selectblock_y(3)+ selectblock_y(4)+ selectblock_y(5)+ selectblock_y(6)+ selectblock_y(7)+ selectblock_y(8)+ selectblock_y(9)+ selectblock_y(10)+ selectblock_y(11)+ selectblock_y(12)+ selectblock_y(13)+ selectblock_y(14)+ selectblock_y(15)+ selectblock_y(16)++ movq %rax, ACC+48(%rsp)+ movq %rbx, ACC+56(%rsp)+ movq %rcx, ACC+64(%rsp)+ movq %rdx, ACC+72(%rsp)+ movq %r8, ACC+80(%rsp)+ movq %r9, ACC+88(%rsp)++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++ movl $380, %ebp++Lp384_montjscalarmul_alt_mainloop:+ subq $5, %rbp++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjdouble)++// Choose the bitfield and adjust it to sign and magnitude++ movq SCALARB(%rsp), %r8+ movq SCALARB+8(%rsp), %r9+ movq SCALARB+16(%rsp), %r10+ movq SCALARB+24(%rsp), %r11+ movq SCALARB+32(%rsp), %r12+ movq SCALARB+40(%rsp), %r13++ movq %r13, %rdi+ shrq $59, %rdi+ shldq $5, %r12, %r13+ shldq $5, %r11, %r12+ shldq $5, %r10, %r11+ shldq $5, %r9, %r10+ shldq $5, %r8, %r9+ shlq $5, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)++ subq $16, %rdi+ sbbq %rsi, %rsi // %rsi = sign of digit (-1 = negative)+ xorq %rsi, %rdi+ subq %rsi, %rdi // %rdi = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time+// Again, this is done in two sweeps, first doing x and z then y.++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ xorl %r13d, %r13d+ xorl %r14d, %r14d+ xorl %r15d, %r15d++selectblock_xz(1)+ selectblock_xz(2)+ selectblock_xz(3)+ selectblock_xz(4)+ selectblock_xz(5)+ selectblock_xz(6)+ selectblock_xz(7)+ selectblock_xz(8)+ selectblock_xz(9)+ selectblock_xz(10)+ selectblock_xz(11)+ selectblock_xz(12)+ selectblock_xz(13)+ selectblock_xz(14)+ selectblock_xz(15)+ selectblock_xz(16)++ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)+ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+96(%rsp)+ movq %r11, TABENT+104(%rsp)+ movq %r12, TABENT+112(%rsp)+ movq %r13, TABENT+120(%rsp)+ movq %r14, TABENT+128(%rsp)+ movq %r15, TABENT+136(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d++ selectblock_y(1)+ selectblock_y(2)+ selectblock_y(3)+ selectblock_y(4)+ selectblock_y(5)+ selectblock_y(6)+ selectblock_y(7)+ selectblock_y(8)+ selectblock_y(9)+ selectblock_y(10)+ selectblock_y(11)+ selectblock_y(12)+ selectblock_y(13)+ selectblock_y(14)+ selectblock_y(15)+ selectblock_y(16)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_384 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).+// The digits of the prime p_384 are generated dynamically from+// the zeroth via not/lea to reduce the number of constant loads.++ movq %rax, %r10+ orq %rbx, %r10+ movq %rcx, %r11+ orq %rdx, %r11+ movq %r8, %r12+ orq %r9, %r12+ orq %r11, %r10+ orq %r12, %r10+ cmovzq %r10, %rsi++ movl $0xffffffff, %r10d+ movq %r10, %r11+ notq %r11+ leaq (%r10,%r11), %r13+ subq %rax, %r10+ leaq -1(%r13), %r12+ sbbq %rbx, %r11+ movq %r13, %r14+ sbbq %rcx, %r12+ sbbq %rdx, %r13+ movq %r14, %r15+ sbbq %r8, %r14+ sbbq %r9, %r15++ testq %rsi, %rsi+ cmovnzq %r10, %rax+ cmovnzq %r11, %rbx+ cmovnzq %r12, %rcx+ cmovnzq %r13, %rdx+ cmovnzq %r14, %r8+ cmovnzq %r15, %r9++ movq %rax, TABENT+48(%rsp)+ movq %rbx, TABENT+56(%rsp)+ movq %rcx, TABENT+64(%rsp)+ movq %rdx, TABENT+72(%rsp)+ movq %r8, TABENT+80(%rsp)+ movq %r9, TABENT+88(%rsp)++// Add to the accumulator++ leaq TABENT(%rsp), %rdx+ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp384_montjscalarmul_alt_p384_montjadd)++ testq %rbp, %rbp+ jne Lp384_montjscalarmul_alt_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ movq res, %rdi+ movq ACC(%rsp), %rax+ movq %rax, (%rdi)+ movq ACC+8(%rsp), %rax+ movq %rax, 8(%rdi)+ movq ACC+16(%rsp), %rax+ movq %rax, 16(%rdi)+ movq ACC+24(%rsp), %rax+ movq %rax, 24(%rdi)+ movq ACC+32(%rsp), %rax+ movq %rax, 32(%rdi)+ movq ACC+40(%rsp), %rax+ movq %rax, 40(%rdi)+ movq ACC+48(%rsp), %rax+ movq %rax, 48(%rdi)+ movq ACC+56(%rsp), %rax+ movq %rax, 56(%rdi)+ movq ACC+64(%rsp), %rax+ movq %rax, 64(%rdi)+ movq ACC+72(%rsp), %rax+ movq %rax, 72(%rdi)+ movq ACC+80(%rsp), %rax+ movq %rax, 80(%rdi)+ movq ACC+88(%rsp), %rax+ movq %rax, 88(%rdi)+ movq ACC+96(%rsp), %rax+ movq %rax, 96(%rdi)+ movq ACC+104(%rsp), %rax+ movq %rax, 104(%rdi)+ movq ACC+112(%rsp), %rax+ movq %rax, 112(%rdi)+ movq ACC+120(%rsp), %rax+ movq %rax, 120(%rdi)+ movq ACC+128(%rsp), %rax+ movq %rax, 128(%rdi)+ movq ACC+136(%rsp), %rax+ movq %rax, 136(%rdi)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_alt_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p384_montjscalarmul_alt)+#endif++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjadd)++Lp384_montjscalarmul_alt_p384_montjadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(352)+ movq %rsi, 0x150(%rsp)+ movq %rdx, 0x158(%rsp)+ movq 0x60(%rsi), %rbx+ movq 0x68(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x78(%rsi), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x88(%rsi), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x78(%rsi), %rax+ mulq 0x80(%rsi)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x70(%rsi), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x68(%rsi), %rbx+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x80(%rsi), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x70(%rsi), %rbx+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x78(%rsi), %rax+ mulq 0x88(%rsi)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x80(%rsi), %rax+ mulq 0x88(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0x60(%rsi), %rax+ mulq %rax+ movq %r8, (%rsp)+ movq %rax, %r8+ movq 0x68(%rsi), %rax+ movq %rbp, 0x8(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x70(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x78(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq 0x8(%rsp), %rax+ adcq (%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rsi+ movq %rbx, (%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq (%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rsi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rsi+ movq %r14, (%rsp)+ movq %r15, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rbx, 0x18(%rsp)+ movq %rbp, 0x20(%rsp)+ movq %rsi, 0x28(%rsp)+ movq 0x158(%rsp), %rsi+ movq 0x60(%rsi), %rbx+ movq 0x68(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x78(%rsi), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x88(%rsi), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x78(%rsi), %rax+ mulq 0x80(%rsi)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x70(%rsi), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x68(%rsi), %rbx+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x80(%rsi), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x70(%rsi), %rbx+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x78(%rsi), %rax+ mulq 0x88(%rsi)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x80(%rsi), %rax+ mulq 0x88(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0x60(%rsi), %rax+ mulq %rax+ movq %r8, 0xf0(%rsp)+ movq %rax, %r8+ movq 0x68(%rsi), %rax+ movq %rbp, 0xf8(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x70(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x78(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq 0xf8(%rsp), %rax+ adcq 0xf0(%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rsi+ movq %rbx, 0xf0(%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq 0xf0(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rsi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rsi+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %rcx, 0x100(%rsp)+ movq %rbx, 0x108(%rsp)+ movq %rbp, 0x110(%rsp)+ movq %rsi, 0x118(%rsp)+ movq 0x150(%rsp), %rsi+ movq 0x158(%rsp), %rcx+ movq 0x30(%rsi), %rbx+ movq 0x60(%rcx), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rcx), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rcx), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rcx), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x80(%rcx), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x88(%rcx), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x38(%rsi), %rbx+ movq 0x60(%rcx), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x68(%rcx), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x70(%rcx), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x78(%rcx), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x80(%rcx), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x88(%rcx), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x40(%rsi), %rbx+ movq 0x60(%rcx), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x68(%rcx), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x70(%rcx), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x78(%rcx), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x80(%rcx), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x88(%rcx), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x48(%rsi), %rbx+ movq 0x60(%rcx), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x68(%rcx), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x70(%rcx), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x78(%rcx), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x80(%rcx), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x88(%rcx), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x50(%rsi), %rbx+ movq 0x60(%rcx), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x68(%rcx), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x70(%rcx), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x78(%rcx), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x80(%rcx), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x88(%rcx), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x58(%rsi), %rbx+ movq 0x60(%rcx), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x68(%rcx), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x70(%rcx), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x78(%rcx), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x80(%rcx), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x88(%rcx), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x120(%rsp)+ movq %r15, 0x128(%rsp)+ movq %r8, 0x130(%rsp)+ movq %r9, 0x138(%rsp)+ movq %r10, 0x140(%rsp)+ movq %r11, 0x148(%rsp)+ movq 0x150(%rsp), %rsi+ movq 0x158(%rsp), %rcx+ movq 0x30(%rcx), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x68(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x70(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x78(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x80(%rsi), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x88(%rsi), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x38(%rcx), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x70(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x40(%rcx), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x70(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x48(%rcx), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x70(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x50(%rcx), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x70(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x58(%rcx), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x70(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq %r8, 0x40(%rsp)+ movq %r9, 0x48(%rsp)+ movq %r10, 0x50(%rsp)+ movq %r11, 0x58(%rsp)+ movq 0x158(%rsp), %rcx+ movq (%rcx), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x20(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x28(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x8(%rcx), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x10(%rcx), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x18(%rcx), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x20(%rcx), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x28(%rcx), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r8, 0x70(%rsp)+ movq %r9, 0x78(%rsp)+ movq %r10, 0x80(%rsp)+ movq %r11, 0x88(%rsp)+ movq 0x150(%rsp), %rsi+ movq (%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x118(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x8(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x10(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x18(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x20(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x28(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %r8, 0xd0(%rsp)+ movq %r9, 0xd8(%rsp)+ movq %r10, 0xe0(%rsp)+ movq %r11, 0xe8(%rsp)+ movq 0x30(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x20(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x28(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x38(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x40(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x48(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x50(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x58(%rsp), %rbx+ movq (%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x10(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x18(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x20(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x28(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq %r8, 0x40(%rsp)+ movq %r9, 0x48(%rsp)+ movq %r10, 0x50(%rsp)+ movq %r11, 0x58(%rsp)+ movq 0x120(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x118(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x128(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x130(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x138(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x140(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x148(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x120(%rsp)+ movq %r15, 0x128(%rsp)+ movq %r8, 0x130(%rsp)+ movq %r9, 0x138(%rsp)+ movq %r10, 0x140(%rsp)+ movq %r11, 0x148(%rsp)+ movq 0x60(%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x68(%rsp), %rdx+ sbbq 0xc8(%rsp), %rdx+ movq 0x70(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x78(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movq 0x80(%rsp), %r10+ sbbq 0xe0(%rsp), %r10+ movq 0x88(%rsp), %r11+ sbbq 0xe8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0xf0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xf8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x100(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x108(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x110(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq 0x30(%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x38(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0x40(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0x48(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0x50(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0x58(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0x30(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x38(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x40(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x48(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x50(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x58(%rsp)+ movq 0xf0(%rsp), %rbx+ movq 0xf8(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x108(%rsp), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x118(%rsp), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x108(%rsp), %rax+ mulq 0x110(%rsp)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x100(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0xf8(%rsp), %rbx+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x110(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x100(%rsp), %rbx+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x108(%rsp), %rax+ mulq 0x118(%rsp)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x110(%rsp), %rax+ mulq 0x118(%rsp)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0xf0(%rsp), %rax+ mulq %rax+ movq %r8, 0x90(%rsp)+ movq %rax, %r8+ movq 0xf8(%rsp), %rax+ movq %rbp, 0x98(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x100(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x108(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x110(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x118(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq 0x98(%rsp), %rax+ adcq 0x90(%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rsi+ movq %rbx, 0x90(%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq 0x90(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rsi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rsi+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq %rcx, 0xa0(%rsp)+ movq %rbx, 0xa8(%rsp)+ movq %rbp, 0xb0(%rsp)+ movq %rsi, 0xb8(%rsp)+ movq 0x30(%rsp), %rbx+ movq 0x38(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x48(%rsp), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x58(%rsp), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x48(%rsp), %rax+ mulq 0x50(%rsp)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x40(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x38(%rsp), %rbx+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x50(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x40(%rsp), %rbx+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ mulq 0x58(%rsp)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x50(%rsp), %rax+ mulq 0x58(%rsp)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0x30(%rsp), %rax+ mulq %rax+ movq %r8, (%rsp)+ movq %rax, %r8+ movq 0x38(%rsp), %rax+ movq %rbp, 0x8(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x40(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x48(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x50(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x58(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq 0x8(%rsp), %rax+ adcq (%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rsi+ movq %rbx, (%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq (%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rsi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rsi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rsi+ movq %r14, (%rsp)+ movq %r15, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rbx, 0x18(%rsp)+ movq %rbp, 0x20(%rsp)+ movq %rsi, 0x28(%rsp)+ movq 0xc0(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x98(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xa0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0xc8(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0xd0(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0xd8(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0xe0(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0xe8(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %r8, 0xd0(%rsp)+ movq %r9, 0xd8(%rsp)+ movq %r10, 0xe0(%rsp)+ movq %r11, 0xe8(%rsp)+ movq 0x60(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x98(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xa0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x68(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x70(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x78(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x80(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x88(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r8, 0x70(%rsp)+ movq %r9, 0x78(%rsp)+ movq %r10, 0x80(%rsp)+ movq %r11, 0x88(%rsp)+ movq (%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0xc8(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0xe0(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0xe8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, (%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ movq 0x60(%rsp), %rax+ subq 0xc0(%rsp), %rax+ movq 0x68(%rsp), %rdx+ sbbq 0xc8(%rsp), %rdx+ movq 0x70(%rsp), %r8+ sbbq 0xd0(%rsp), %r8+ movq 0x78(%rsp), %r9+ sbbq 0xd8(%rsp), %r9+ movq 0x80(%rsp), %r10+ sbbq 0xe0(%rsp), %r10+ movq 0x88(%rsp), %r11+ sbbq 0xe8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0x90(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x98(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xa0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xa8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xb0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xb8(%rsp)+ movq 0x150(%rsp), %rsi+ movq 0x60(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x118(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x68(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x70(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x78(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x80(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x88(%rsi), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %r8, 0x100(%rsp)+ movq %r9, 0x108(%rsp)+ movq %r10, 0x110(%rsp)+ movq %r11, 0x118(%rsp)+ movq (%rsp), %rax+ subq 0x60(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0x68(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0x70(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x78(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0x80(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0x88(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, (%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ movq 0xc0(%rsp), %rax+ subq (%rsp), %rax+ movq 0xc8(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0xd0(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0xd8(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0xe0(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0xe8(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0xc0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xc8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xd0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xd8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xe0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xe8(%rsp)+ movq 0x120(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x98(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0xa0(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0xa8(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0xb0(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0xb8(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x128(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x130(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x138(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x140(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x148(%rsp), %rbx+ movq 0x90(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x98(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0xa0(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0xa8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0xb0(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0xb8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq %r8, 0xa0(%rsp)+ movq %r9, 0xa8(%rsp)+ movq %r10, 0xb0(%rsp)+ movq %r11, 0xb8(%rsp)+ movq 0x158(%rsp), %rcx+ movq 0x60(%rcx), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x118(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x68(%rcx), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x70(%rcx), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x78(%rcx), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x80(%rcx), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x88(%rcx), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %r8, 0x100(%rsp)+ movq %r9, 0x108(%rsp)+ movq %r10, 0x110(%rsp)+ movq %r11, 0x118(%rsp)+ movq 0xc0(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x38(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x40(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x48(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x50(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x58(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0xc8(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x40(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0xd0(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x40(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0xd8(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x40(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0xe0(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x40(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0xe8(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x40(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %r8, 0xd0(%rsp)+ movq %r9, 0xd8(%rsp)+ movq %r10, 0xe0(%rsp)+ movq %r11, 0xe8(%rsp)+ movq 0xc0(%rsp), %rax+ subq 0x90(%rsp), %rax+ movq 0xc8(%rsp), %rdx+ sbbq 0x98(%rsp), %rdx+ movq 0xd0(%rsp), %r8+ sbbq 0xa0(%rsp), %r8+ movq 0xd8(%rsp), %r9+ sbbq 0xa8(%rsp), %r9+ movq 0xe0(%rsp), %r10+ sbbq 0xb0(%rsp), %r10+ movq 0xe8(%rsp), %r11+ sbbq 0xb8(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %esi+ andq %rsi, %rcx+ xorq %rsi, %rsi+ subq %rcx, %rsi+ subq %rsi, %rax+ movq %rax, 0xc0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xc8(%rsp)+ sbbq %rax, %rax+ andq %rsi, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xd0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xd8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xe0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xe8(%rsp)+ movq 0x158(%rsp), %rcx+ movq 0x60(%rcx), %r8+ movq 0x68(%rcx), %r9+ movq 0x70(%rcx), %r10+ movq 0x78(%rcx), %r11+ movq 0x80(%rcx), %rbx+ movq 0x88(%rcx), %rbp+ movq %r8, %rax+ movq %r9, %rdx+ orq %r10, %rax+ orq %r11, %rdx+ orq %rbx, %rax+ orq %rbp, %rdx+ orq %rdx, %rax+ negq %rax+ sbbq %rax, %rax+ movq 0x150(%rsp), %rsi+ movq 0x60(%rsi), %r12+ movq 0x68(%rsi), %r13+ movq 0x70(%rsi), %r14+ movq 0x78(%rsi), %r15+ movq 0x80(%rsi), %rdx+ movq 0x88(%rsi), %rcx+ cmoveq %r12, %r8+ cmoveq %r13, %r9+ cmoveq %r14, %r10+ cmoveq %r15, %r11+ cmoveq %rdx, %rbx+ cmoveq %rcx, %rbp+ orq %r13, %r12+ orq %r15, %r14+ orq %rcx, %rdx+ orq %r14, %r12+ orq %r12, %rdx+ negq %rdx+ sbbq %rdx, %rdx+ cmpq %rdx, %rax+ cmoveq 0xf0(%rsp), %r8+ cmoveq 0xf8(%rsp), %r9+ cmoveq 0x100(%rsp), %r10+ cmoveq 0x108(%rsp), %r11+ cmoveq 0x110(%rsp), %rbx+ cmoveq 0x118(%rsp), %rbp+ movq %r8, 0xf0(%rsp)+ movq %r9, 0xf8(%rsp)+ movq %r10, 0x100(%rsp)+ movq %r11, 0x108(%rsp)+ movq %rbx, 0x110(%rsp)+ movq %rbp, 0x118(%rsp)+ movq 0x158(%rsp), %rcx+ movq 0x150(%rsp), %rsi+ movq (%rsp), %r8+ cmovbq (%rsi), %r8+ cmova (%rcx), %r8+ movq 0x8(%rsp), %r9+ cmovbq 0x8(%rsi), %r9+ cmova 0x8(%rcx), %r9+ movq 0x10(%rsp), %r10+ cmovbq 0x10(%rsi), %r10+ cmova 0x10(%rcx), %r10+ movq 0x18(%rsp), %r11+ cmovbq 0x18(%rsi), %r11+ cmova 0x18(%rcx), %r11+ movq 0x20(%rsp), %rbx+ cmovbq 0x20(%rsi), %rbx+ cmova 0x20(%rcx), %rbx+ movq 0x28(%rsp), %rbp+ cmovbq 0x28(%rsi), %rbp+ cmova 0x28(%rcx), %rbp+ movq 0xc0(%rsp), %r12+ cmovbq 0x30(%rsi), %r12+ cmova 0x30(%rcx), %r12+ movq 0xc8(%rsp), %r13+ cmovbq 0x38(%rsi), %r13+ cmova 0x38(%rcx), %r13+ movq 0xd0(%rsp), %r14+ cmovbq 0x40(%rsi), %r14+ cmova 0x40(%rcx), %r14+ movq 0xd8(%rsp), %r15+ cmovbq 0x48(%rsi), %r15+ cmova 0x48(%rcx), %r15+ movq 0xe0(%rsp), %rdx+ cmovbq 0x50(%rsi), %rdx+ cmova 0x50(%rcx), %rdx+ movq 0xe8(%rsp), %rax+ cmovbq 0x58(%rsi), %rax+ cmova 0x58(%rcx), %rax+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %rbx, 0x20(%rdi)+ movq %rbp, 0x28(%rdi)+ movq 0xf0(%rsp), %r8+ movq 0xf8(%rsp), %r9+ movq 0x100(%rsp), %r10+ movq 0x108(%rsp), %r11+ movq 0x110(%rsp), %rbx+ movq 0x118(%rsp), %rbp+ movq %r12, 0x30(%rdi)+ movq %r13, 0x38(%rdi)+ movq %r14, 0x40(%rdi)+ movq %r15, 0x48(%rdi)+ movq %rdx, 0x50(%rdi)+ movq %rax, 0x58(%rdi)+ movq %r8, 0x60(%rdi)+ movq %r9, 0x68(%rdi)+ movq %r10, 0x70(%rdi)+ movq %r11, 0x78(%rdi)+ movq %rbx, 0x80(%rdi)+ movq %rbp, 0x88(%rdi)+ CFI_INC_RSP(352)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjdouble)++Lp384_montjscalarmul_alt_p384_montjdouble:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(344)+ movq %rdi, 0x150(%rsp)+ movq 0x60(%rsi), %rbx+ movq 0x68(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x78(%rsi), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x88(%rsi), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x78(%rsi), %rax+ mulq 0x80(%rsi)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x70(%rsi), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x68(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x68(%rsi), %rbx+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x80(%rsi), %rbx+ movq 0x60(%rsi), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x70(%rsi), %rbx+ movq 0x78(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x78(%rsi), %rax+ mulq 0x88(%rsi)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x80(%rsi), %rax+ mulq 0x88(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0x60(%rsi), %rax+ mulq %rax+ movq %r8, (%rsp)+ movq %rax, %r8+ movq 0x68(%rsi), %rax+ movq %rbp, 0x8(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x70(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x78(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x80(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x88(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq 0x8(%rsp), %rax+ adcq (%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rdi+ movq %rbx, (%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq (%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, (%rsp)+ movq %r15, 0x8(%rsp)+ movq %rcx, 0x10(%rsp)+ movq %rbx, 0x18(%rsp)+ movq %rbp, 0x20(%rsp)+ movq %rdi, 0x28(%rsp)+ movq 0x30(%rsi), %rbx+ movq 0x38(%rsi), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x48(%rsi), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x58(%rsi), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x48(%rsi), %rax+ mulq 0x50(%rsi)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x40(%rsi), %rbx+ movq 0x30(%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x38(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x38(%rsi), %rbx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x50(%rsi), %rbx+ movq 0x30(%rsi), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x40(%rsi), %rbx+ movq 0x48(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x50(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x58(%rsi), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x48(%rsi), %rax+ mulq 0x58(%rsi)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x50(%rsi), %rax+ mulq 0x58(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0x30(%rsi), %rax+ mulq %rax+ movq %r8, 0x30(%rsp)+ movq %rax, %r8+ movq 0x38(%rsi), %rax+ movq %rbp, 0x38(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x40(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x48(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x50(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x58(%rsi), %rax+ mulq %rax+ negq %rbp+ adcq 0x38(%rsp), %rax+ adcq 0x30(%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rdi+ movq %rbx, 0x30(%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq 0x30(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0x30(%rsp)+ movq %r15, 0x38(%rsp)+ movq %rcx, 0x40(%rsp)+ movq %rbx, 0x48(%rsp)+ movq %rbp, 0x50(%rsp)+ movq %rdi, 0x58(%rsp)+ movq (%rsi), %rax+ addq (%rsp), %rax+ movq 0x8(%rsi), %rcx+ adcq 0x8(%rsp), %rcx+ movq 0x10(%rsi), %r8+ adcq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ adcq 0x18(%rsp), %r9+ movq 0x20(%rsi), %r10+ adcq 0x20(%rsp), %r10+ movq 0x28(%rsi), %r11+ adcq 0x28(%rsp), %r11+ sbbq %rdx, %rdx+ movl $0x1, %ebx+ andq %rdx, %rbx+ movl $0xffffffff, %ebp+ andq %rbp, %rdx+ xorq %rbp, %rbp+ subq %rdx, %rbp+ addq %rbp, %rax+ movq %rax, 0xf0(%rsp)+ adcq %rdx, %rcx+ movq %rcx, 0xf8(%rsp)+ adcq %rbx, %r8+ movq %r8, 0x100(%rsp)+ adcq $0x0, %r9+ movq %r9, 0x108(%rsp)+ adcq $0x0, %r10+ movq %r10, 0x110(%rsp)+ adcq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq (%rsi), %rax+ subq (%rsp), %rax+ movq 0x8(%rsi), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x10(%rsi), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x18(%rsi), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x20(%rsi), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x28(%rsi), %r11+ sbbq 0x28(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %ebx+ andq %rbx, %rcx+ xorq %rbx, %rbx+ subq %rcx, %rbx+ subq %rbx, %rax+ movq %rax, 0xc0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xc8(%rsp)+ sbbq %rax, %rax+ andq %rbx, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0xd0(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xd8(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xe0(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0xe8(%rsp)+ movq 0xc0(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x118(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0xc8(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0xd0(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0xd8(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0xe0(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0xe8(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x100(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x60(%rsp)+ movq %r15, 0x68(%rsp)+ movq %r8, 0x70(%rsp)+ movq %r9, 0x78(%rsp)+ movq %r10, 0x80(%rsp)+ movq %r11, 0x88(%rsp)+ movq 0x30(%rsi), %rax+ addq 0x60(%rsi), %rax+ movq 0x38(%rsi), %rcx+ adcq 0x68(%rsi), %rcx+ movq 0x40(%rsi), %r8+ adcq 0x70(%rsi), %r8+ movq 0x48(%rsi), %r9+ adcq 0x78(%rsi), %r9+ movq 0x50(%rsi), %r10+ adcq 0x80(%rsi), %r10+ movq 0x58(%rsi), %r11+ adcq 0x88(%rsi), %r11+ movl $0x0, %edx+ adcq %rdx, %rdx+ movabsq $0xffffffff00000001, %rbp+ addq %rbp, %rax+ movl $0xffffffff, %ebp+ adcq %rbp, %rcx+ adcq $0x1, %r8+ adcq $0x0, %r9+ adcq $0x0, %r10+ adcq $0x0, %r11+ adcq $0xffffffffffffffff, %rdx+ movl $0x1, %ebx+ andq %rdx, %rbx+ andq %rbp, %rdx+ xorq %rbp, %rbp+ subq %rdx, %rbp+ subq %rbp, %rax+ movq %rax, 0xf0(%rsp)+ sbbq %rdx, %rcx+ movq %rcx, 0xf8(%rsp)+ sbbq %rbx, %r8+ movq %r8, 0x100(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x108(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x110(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq 0x60(%rsp), %rbx+ movq 0x68(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x78(%rsp), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x88(%rsp), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x78(%rsp), %rax+ mulq 0x80(%rsp)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x70(%rsp), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x68(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x68(%rsp), %rbx+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x80(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x88(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x80(%rsp), %rbx+ movq 0x60(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x70(%rsp), %rbx+ movq 0x78(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x80(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x88(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x78(%rsp), %rax+ mulq 0x88(%rsp)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x80(%rsp), %rax+ mulq 0x88(%rsp)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0x60(%rsp), %rax+ mulq %rax+ movq %r8, 0x120(%rsp)+ movq %rax, %r8+ movq 0x68(%rsp), %rax+ movq %rbp, 0x128(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x70(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x78(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x80(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x88(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq 0x128(%rsp), %rax+ adcq 0x120(%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rdi+ movq %rbx, 0x120(%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq 0x120(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0x120(%rsp)+ movq %r15, 0x128(%rsp)+ movq %rcx, 0x130(%rsp)+ movq %rbx, 0x138(%rsp)+ movq %rbp, 0x140(%rsp)+ movq %rdi, 0x148(%rsp)+ movq 0x30(%rsp), %rbx+ movq (%rsi), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x10(%rsi), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x18(%rsi), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x20(%rsi), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x28(%rsi), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x38(%rsp), %rbx+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x20(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x28(%rsi), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x40(%rsp), %rbx+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x20(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x28(%rsi), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x48(%rsp), %rbx+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x20(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x28(%rsi), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x50(%rsp), %rbx+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x20(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x28(%rsi), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x58(%rsp), %rbx+ movq (%rsi), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x8(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x10(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x18(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x20(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x28(%rsi), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0x90(%rsp)+ movq %r15, 0x98(%rsp)+ movq %r8, 0xa0(%rsp)+ movq %r9, 0xa8(%rsp)+ movq %r10, 0xb0(%rsp)+ movq %r11, 0xb8(%rsp)+ movq 0xf0(%rsp), %rbx+ movq 0xf8(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x108(%rsp), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x118(%rsp), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x108(%rsp), %rax+ mulq 0x110(%rsp)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x100(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0xf8(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0xf8(%rsp), %rbx+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x110(%rsp), %rbx+ movq 0xf0(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x100(%rsp), %rbx+ movq 0x108(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x110(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x118(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x108(%rsp), %rax+ mulq 0x118(%rsp)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x110(%rsp), %rax+ mulq 0x118(%rsp)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0xf0(%rsp), %rax+ mulq %rax+ movq %r8, 0xc0(%rsp)+ movq %rax, %r8+ movq 0xf8(%rsp), %rax+ movq %rbp, 0xc8(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x100(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x108(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x110(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x118(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq 0xc8(%rsp), %rax+ adcq 0xc0(%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rdi+ movq %rbx, 0xc0(%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq 0xc0(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %rcx, 0xd0(%rsp)+ movq %rbx, 0xd8(%rsp)+ movq %rbp, 0xe0(%rsp)+ movq %rdi, 0xe8(%rsp)+ movabsq $0xffffffff, %r9+ subq 0x120(%rsp), %r9+ movabsq $0xffffffff00000000, %r10+ sbbq 0x128(%rsp), %r10+ movq $0xfffffffffffffffe, %r11+ sbbq 0x130(%rsp), %r11+ movq $0xffffffffffffffff, %r12+ sbbq 0x138(%rsp), %r12+ movq $0xffffffffffffffff, %r13+ sbbq 0x140(%rsp), %r13+ movq $0xffffffffffffffff, %r14+ sbbq 0x148(%rsp), %r14+ movq $0x9, %rcx+ movq %r9, %rax+ mulq %rcx+ movq %rax, %r8+ movq %rdx, %r9+ movq %r10, %rax+ xorl %r10d, %r10d+ mulq %rcx+ addq %rax, %r9+ adcq %rdx, %r10+ movq %r11, %rax+ xorl %r11d, %r11d+ mulq %rcx+ addq %rax, %r10+ adcq %rdx, %r11+ movq %r12, %rax+ xorl %r12d, %r12d+ mulq %rcx+ addq %rax, %r11+ adcq %rdx, %r12+ movq %r13, %rax+ xorl %r13d, %r13d+ mulq %rcx+ addq %rax, %r12+ adcq %rdx, %r13+ movq %r14, %rax+ movl $0x1, %r14d+ mulq %rcx+ addq %rax, %r13+ adcq %rdx, %r14+ movl $0xc, %ecx+ movq 0x90(%rsp), %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %rbx, %rbx+ movq 0x98(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rbx, %rbx+ movq 0xa0(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbx, %rbx+ movq 0xa8(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbx, %rbx+ movq 0xb0(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbx, %rbx+ movq 0xb8(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ movabsq $0xffffffff00000001, %rax+ mulq %r14+ addq %rax, %r8+ adcq %rdx, %r9+ adcq %r14, %r10+ movq %r14, %rax+ sbbq %rcx, %rcx+ movl $0xffffffff, %edx+ negq %rcx+ mulq %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ adcq %rcx, %r11+ adcq $0x0, %r12+ adcq $0x0, %r13+ sbbq %rcx, %rcx+ notq %rcx+ movl $0xffffffff, %edx+ xorq %rax, %rax+ andq %rcx, %rdx+ subq %rdx, %rax+ andq $0x1, %rcx+ subq %rax, %r8+ movq %r8, 0x120(%rsp)+ sbbq %rdx, %r9+ movq %r9, 0x128(%rsp)+ sbbq %rcx, %r10+ movq %r10, 0x130(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x138(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x140(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x148(%rsp)+ movq 0xc0(%rsp), %rax+ subq (%rsp), %rax+ movq 0xc8(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0xd0(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0xd8(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0xe0(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0xe8(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %ebx+ andq %rbx, %rcx+ xorq %rbx, %rbx+ subq %rcx, %rbx+ subq %rbx, %rax+ movq %rax, 0xf0(%rsp)+ sbbq %rcx, %rdx+ movq %rdx, 0xf8(%rsp)+ sbbq %rax, %rax+ andq %rbx, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x100(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x108(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x110(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x118(%rsp)+ movq 0x30(%rsp), %rbx+ movq 0x38(%rsp), %rax+ mulq %rbx+ movq %rax, %r9+ movq %rdx, %r10+ movq 0x48(%rsp), %rax+ mulq %rbx+ movq %rax, %r11+ movq %rdx, %r12+ movq 0x58(%rsp), %rax+ mulq %rbx+ movq %rax, %r13+ movq %rdx, %r14+ movq 0x48(%rsp), %rax+ mulq 0x50(%rsp)+ movq %rax, %r15+ movq %rdx, %rcx+ movq 0x40(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x38(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x38(%rsp), %rbx+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %rcx+ movq 0x50(%rsp), %rbx+ movq 0x30(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x40(%rsp), %rbx+ movq 0x48(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x50(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x58(%rsp), %rax+ mulq %rbx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rcx+ sbbq %rbp, %rbp+ xorl %ebx, %ebx+ movq 0x48(%rsp), %rax+ mulq 0x58(%rsp)+ subq %rbp, %rdx+ xorl %ebp, %ebp+ addq %rax, %rcx+ adcq %rdx, %rbx+ adcl %ebp, %ebp+ movq 0x50(%rsp), %rax+ mulq 0x58(%rsp)+ addq %rax, %rbx+ adcq %rdx, %rbp+ xorl %r8d, %r8d+ addq %r9, %r9+ adcq %r10, %r10+ adcq %r11, %r11+ adcq %r12, %r12+ adcq %r13, %r13+ adcq %r14, %r14+ adcq %r15, %r15+ adcq %rcx, %rcx+ adcq %rbx, %rbx+ adcq %rbp, %rbp+ adcl %r8d, %r8d+ movq 0x30(%rsp), %rax+ mulq %rax+ movq %r8, 0xc0(%rsp)+ movq %rax, %r8+ movq 0x38(%rsp), %rax+ movq %rbp, 0xc8(%rsp)+ addq %rdx, %r9+ sbbq %rbp, %rbp+ mulq %rax+ negq %rbp+ adcq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x40(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x48(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x50(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq %rax, %rcx+ adcq %rdx, %rbx+ sbbq %rbp, %rbp+ movq 0x58(%rsp), %rax+ mulq %rax+ negq %rbp+ adcq 0xc8(%rsp), %rax+ adcq 0xc0(%rsp), %rdx+ movq %rax, %rbp+ movq %rdx, %rdi+ movq %rbx, 0xc0(%rsp)+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r8+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r8, %r9+ sbbq %rdx, %r10+ sbbq %rax, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ movq %rbx, %r8+ sbbq $0x0, %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r9+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r9, %r10+ sbbq %rdx, %r11+ sbbq %rax, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r8+ movq %rbx, %r9+ sbbq $0x0, %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r10+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r10, %r11+ sbbq %rdx, %r12+ sbbq %rax, %r13+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ movq %rbx, %r10+ sbbq $0x0, %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r11+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r11, %r12+ sbbq %rdx, %r13+ sbbq %rax, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ movq %rbx, %r11+ sbbq $0x0, %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r12+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r12, %r13+ sbbq %rdx, %r8+ sbbq %rax, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %r11+ movq %rbx, %r12+ sbbq $0x0, %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %rax, %r13+ movl $0x0, %eax+ adcq %rbx, %rdx+ adcl %eax, %eax+ subq %r13, %r8+ sbbq %rdx, %r9+ sbbq %rax, %r10+ sbbq $0x0, %r11+ sbbq $0x0, %r12+ movq %rbx, %r13+ sbbq $0x0, %r13+ movq 0xc0(%rsp), %rbx+ addq %r8, %r14+ adcq %r9, %r15+ adcq %r10, %rcx+ adcq %r11, %rbx+ adcq %r12, %rbp+ adcq %r13, %rdi+ movl $0x0, %r8d+ adcq %r8, %r8+ xorq %r11, %r11+ xorq %r12, %r12+ xorq %r13, %r13+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %r9d+ adcq %r15, %r9+ movl $0x1, %r10d+ adcq %rcx, %r10+ adcq %rbx, %r11+ adcq %rbp, %r12+ adcq %rdi, %r13+ adcq $0x0, %r8+ cmovneq %rax, %r14+ cmovneq %r9, %r15+ cmovneq %r10, %rcx+ cmovneq %r11, %rbx+ cmovneq %r12, %rbp+ cmovneq %r13, %rdi+ movq %r14, 0xc0(%rsp)+ movq %r15, 0xc8(%rsp)+ movq %rcx, 0xd0(%rsp)+ movq %rbx, 0xd8(%rsp)+ movq %rbp, 0xe0(%rsp)+ movq %rdi, 0xe8(%rsp)+ movq 0x150(%rsp), %rdi+ movq 0xf0(%rsp), %rax+ subq 0x30(%rsp), %rax+ movq 0xf8(%rsp), %rdx+ sbbq 0x38(%rsp), %rdx+ movq 0x100(%rsp), %r8+ sbbq 0x40(%rsp), %r8+ movq 0x108(%rsp), %r9+ sbbq 0x48(%rsp), %r9+ movq 0x110(%rsp), %r10+ sbbq 0x50(%rsp), %r10+ movq 0x118(%rsp), %r11+ sbbq 0x58(%rsp), %r11+ sbbq %rcx, %rcx+ movl $0xffffffff, %ebx+ andq %rbx, %rcx+ xorq %rbx, %rbx+ subq %rcx, %rbx+ subq %rbx, %rax+ movq %rax, 0x60(%rdi)+ sbbq %rcx, %rdx+ movq %rdx, 0x68(%rdi)+ sbbq %rax, %rax+ andq %rbx, %rcx+ negq %rax+ sbbq %rcx, %r8+ movq %r8, 0x70(%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x78(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x80(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x88(%rdi)+ movq 0x60(%rsp), %rbx+ movq 0x120(%rsp), %rax+ mulq %rbx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x128(%rsp), %rax+ mulq %rbx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x130(%rsp), %rax+ mulq %rbx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x138(%rsp), %rax+ mulq %rbx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x140(%rsp), %rax+ mulq %rbx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x148(%rsp), %rax+ mulq %rbx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ xorl %r15d, %r15d+ movq %r8, %rbx+ shlq $0x20, %rbx+ addq %r8, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r8+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r8, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r9+ sbbq %rdx, %r10+ sbbq %rbp, %r11+ sbbq $0x0, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %rbx+ addq %rbx, %r14+ adcq $0x0, %r15+ movq 0x68(%rsp), %rbx+ movq 0x120(%rsp), %rax+ mulq %rbx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r8, %r8+ movq 0x128(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r8, %r8+ movq 0x130(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r8, %r8+ movq 0x138(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r8, %r8+ movq 0x140(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r8, %r8+ movq 0x148(%rsp), %rax+ mulq %rbx+ subq %r8, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r8, %r8+ negq %r8+ movq %r9, %rbx+ shlq $0x20, %rbx+ addq %r9, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r9+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r9, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r10+ sbbq %rdx, %r11+ sbbq %rbp, %r12+ sbbq $0x0, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %rbx+ addq %rbx, %r15+ adcq $0x0, %r8+ movq 0x70(%rsp), %rbx+ movq 0x120(%rsp), %rax+ mulq %rbx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r9, %r9+ movq 0x128(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r9, %r9+ movq 0x130(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r9, %r9+ movq 0x138(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r9, %r9+ movq 0x140(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r9, %r9+ movq 0x148(%rsp), %rax+ mulq %rbx+ subq %r9, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r9, %r9+ negq %r9+ movq %r10, %rbx+ shlq $0x20, %rbx+ addq %r10, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r10+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r10, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r11+ sbbq %rdx, %r12+ sbbq %rbp, %r13+ sbbq $0x0, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %rbx+ addq %rbx, %r8+ adcq $0x0, %r9+ movq 0x78(%rsp), %rbx+ movq 0x120(%rsp), %rax+ mulq %rbx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %r10, %r10+ movq 0x128(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r10, %r10+ movq 0x130(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r10, %r10+ movq 0x138(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r10, %r10+ movq 0x140(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r10, %r10+ movq 0x148(%rsp), %rax+ mulq %rbx+ subq %r10, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r10, %r10+ negq %r10+ movq %r11, %rbx+ shlq $0x20, %rbx+ addq %r11, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r11+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r11, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r12+ sbbq %rdx, %r13+ sbbq %rbp, %r14+ sbbq $0x0, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %rbx+ addq %rbx, %r9+ adcq $0x0, %r10+ movq 0x80(%rsp), %rbx+ movq 0x120(%rsp), %rax+ mulq %rbx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %r11, %r11+ movq 0x128(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r11, %r11+ movq 0x130(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r11, %r11+ movq 0x138(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r11, %r11+ movq 0x140(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r11, %r11+ movq 0x148(%rsp), %rax+ mulq %rbx+ subq %r11, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r11, %r11+ negq %r11+ movq %r12, %rbx+ shlq $0x20, %rbx+ addq %r12, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r12+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r12, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r13+ sbbq %rdx, %r14+ sbbq %rbp, %r15+ sbbq $0x0, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %rbx+ addq %rbx, %r10+ adcq $0x0, %r11+ movq 0x88(%rsp), %rbx+ movq 0x120(%rsp), %rax+ mulq %rbx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %r12, %r12+ movq 0x128(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %r12, %r12+ movq 0x130(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ sbbq %r12, %r12+ movq 0x138(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %r12, %r12+ movq 0x140(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %r12, %r12+ movq 0x148(%rsp), %rax+ mulq %rbx+ subq %r12, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %r12, %r12+ negq %r12+ movq %r13, %rbx+ shlq $0x20, %rbx+ addq %r13, %rbx+ xorl %ebp, %ebp+ movabsq $0xffffffff00000001, %rax+ mulq %rbx+ movq %rdx, %r13+ movabsq $0xffffffff, %rax+ mulq %rbx+ addq %r13, %rax+ adcq %rbx, %rdx+ adcl %ebp, %ebp+ subq %rax, %r14+ sbbq %rdx, %r15+ sbbq %rbp, %r8+ sbbq $0x0, %r9+ sbbq $0x0, %r10+ sbbq $0x0, %rbx+ addq %rbx, %r11+ adcq $0x0, %r12+ xorl %edx, %edx+ xorl %ebp, %ebp+ xorl %r13d, %r13d+ movabsq $0xffffffff00000001, %rax+ addq %r14, %rax+ movl $0xffffffff, %ebx+ adcq %r15, %rbx+ movl $0x1, %ecx+ adcq %r8, %rcx+ adcq %r9, %rdx+ adcq %r10, %rbp+ adcq %r11, %r13+ adcq $0x0, %r12+ cmovneq %rax, %r14+ cmovneq %rbx, %r15+ cmovneq %rcx, %r8+ cmovneq %rdx, %r9+ cmovneq %rbp, %r10+ cmovneq %r13, %r11+ movq %r14, 0xf0(%rsp)+ movq %r15, 0xf8(%rsp)+ movq %r8, 0x100(%rsp)+ movq %r9, 0x108(%rsp)+ movq %r10, 0x110(%rsp)+ movq %r11, 0x118(%rsp)+ movq 0xb8(%rsp), %rcx+ movq %rcx, %r13+ shrq $0x3e, %rcx+ movq 0xb0(%rsp), %r12+ shldq $0x2, %r12, %r13+ movq 0xa8(%rsp), %r11+ shldq $0x2, %r11, %r12+ movq 0xa0(%rsp), %r10+ shldq $0x2, %r10, %r11+ movq 0x98(%rsp), %r9+ shldq $0x2, %r9, %r10+ movq 0x90(%rsp), %r8+ shldq $0x2, %r8, %r9+ shlq $0x2, %r8+ addq $0x1, %rcx+ subq 0x120(%rsp), %r8+ sbbq 0x128(%rsp), %r9+ sbbq 0x130(%rsp), %r10+ sbbq 0x138(%rsp), %r11+ sbbq 0x140(%rsp), %r12+ sbbq 0x148(%rsp), %r13+ sbbq $0x0, %rcx+ movabsq $0xffffffff00000001, %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ adcq %rcx, %r10+ movq %rcx, %rax+ sbbq %rcx, %rcx+ movl $0xffffffff, %edx+ negq %rcx+ mulq %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ adcq %rcx, %r11+ adcq $0x0, %r12+ adcq $0x0, %r13+ sbbq %rcx, %rcx+ notq %rcx+ movl $0xffffffff, %edx+ xorq %rax, %rax+ andq %rcx, %rdx+ subq %rdx, %rax+ andq $0x1, %rcx+ subq %rax, %r8+ movq %r8, (%rdi)+ sbbq %rdx, %r9+ movq %r9, 0x8(%rdi)+ sbbq %rcx, %r10+ movq %r10, 0x10(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x18(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x20(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x28(%rdi)+ movabsq $0xffffffff, %r8+ subq 0xc0(%rsp), %r8+ movabsq $0xffffffff00000000, %r9+ sbbq 0xc8(%rsp), %r9+ movq $0xfffffffffffffffe, %r10+ sbbq 0xd0(%rsp), %r10+ movq $0xffffffffffffffff, %r11+ sbbq 0xd8(%rsp), %r11+ movq $0xffffffffffffffff, %r12+ sbbq 0xe0(%rsp), %r12+ movq $0xffffffffffffffff, %r13+ sbbq 0xe8(%rsp), %r13+ movq %r13, %r14+ shrq $0x3d, %r14+ shldq $0x3, %r12, %r13+ shldq $0x3, %r11, %r12+ shldq $0x3, %r10, %r11+ shldq $0x3, %r9, %r10+ shldq $0x3, %r8, %r9+ shlq $0x3, %r8+ addq $0x1, %r14+ movl $0x3, %ecx+ movq 0xf0(%rsp), %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %rbx, %rbx+ movq 0xf8(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rbx, %rbx+ movq 0x100(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbx, %rbx+ movq 0x108(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbx, %rbx+ movq 0x110(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbx, %rbx+ movq 0x118(%rsp), %rax+ mulq %rcx+ subq %rbx, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ movabsq $0xffffffff00000001, %rax+ mulq %r14+ addq %rax, %r8+ adcq %rdx, %r9+ adcq %r14, %r10+ movq %r14, %rax+ sbbq %rcx, %rcx+ movl $0xffffffff, %edx+ negq %rcx+ mulq %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ adcq %rcx, %r11+ adcq $0x0, %r12+ adcq $0x0, %r13+ sbbq %rcx, %rcx+ notq %rcx+ movl $0xffffffff, %edx+ xorq %rax, %rax+ andq %rcx, %rdx+ subq %rdx, %rax+ andq $0x1, %rcx+ subq %rax, %r8+ movq %r8, 0x30(%rdi)+ sbbq %rdx, %r9+ movq %r9, 0x38(%rdi)+ sbbq %rcx, %r10+ movq %r10, 0x40(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x48(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x50(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x58(%rdi)+ CFI_INC_RSP(344)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp384_montjscalarmul_alt_p384_montjdouble)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p521_jscalarmul.S view
@@ -0,0 +1,2505 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Jacobian form scalar multiplication for P-521+// Input scalar[9], point[27]; output res[27]+//+// extern void p521_jscalarmul+// (uint64_t res[static 27],+// const uint64_t scalar[static 9],+// const uint64_t point[static 27]);+//+// This function is a variant of its affine point version p521_scalarmul.+// Here, input and output points are assumed to be in Jacobian form with+// a triple (x,y,z) representing the affine point (x/z^2,y/z^3) when+// z is nonzero or the point at infinity (group identity) if z = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-521, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_521) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p521_jscalarmul)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p521_jscalarmul)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p521_jscalarmul)+++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 72+#define JACSIZE (3*NUMSIZE)++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE+// Uppercase syntactic variants make x86_att version simpler to generate.++#define SCALARB (0*NUMSIZE)+#define scalarb (0*NUMSIZE)(%rsp)+#define ACC (1*NUMSIZE)+#define acc (1*NUMSIZE)(%rsp)+#define TABENT (4*NUMSIZE)+#define tabent (4*NUMSIZE)(%rsp)++#define TAB (7*NUMSIZE)+#define tab (7*NUMSIZE)(%rsp)++#define res (55*NUMSIZE)(%rsp)++#define NSPACE 56*NUMSIZE++// Avoid using .rep for the sake of the BoringSSL/AWS-LC delocator,+// which doesn't accept repetitions, assembler macros etc.++#define selectblock(I,C) \+ cmpq $I, %rdi ; \+ cmovzq TAB+JACSIZE*(I-1)+C*NUMSIZE(%rsp), %rax ; \+ cmovzq TAB+JACSIZE*(I-1)+8+C*NUMSIZE(%rsp), %rbx ; \+ cmovzq TAB+JACSIZE*(I-1)+16+C*NUMSIZE(%rsp), %rcx ; \+ cmovzq TAB+JACSIZE*(I-1)+24+C*NUMSIZE(%rsp), %rdx ; \+ cmovzq TAB+JACSIZE*(I-1)+32+C*NUMSIZE(%rsp), %r8 ; \+ cmovzq TAB+JACSIZE*(I-1)+40+C*NUMSIZE(%rsp), %r9 ; \+ cmovzq TAB+JACSIZE*(I-1)+48+C*NUMSIZE(%rsp), %r10 ; \+ cmovzq TAB+JACSIZE*(I-1)+56+C*NUMSIZE(%rsp), %r11 ; \+ cmovzq TAB+JACSIZE*(I-1)+64+C*NUMSIZE(%rsp), %r12++S2N_BN_SYMBOL(p521_jscalarmul):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ CFI_CALL(Lp521_jscalarmul_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p521_jscalarmul)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_standard)++Lp521_jscalarmul_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ movq %rdi, res++// Reduce the input scalar mod n_521 and store it to "scalarb".++ movq %rdx, %rbx+ leaq SCALARB(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_bignum_mod_n521_9)++// Set the tab[0] table entry to the input point = 1 * P, but also+// reduce all coordinates modulo p. In principle we assume reduction+// as a precondition, but this reduces the scope for surprise, e.g.+// making sure that any input with z = 0 is treated as zero, even+// if the other coordinates are not in fact reduced.++ leaq TAB(%rsp), %rdi+ movq %rbx, %rsi+ CFI_CALL(Lp521_jscalarmul_bignum_mod_p521_9)++ leaq TAB+NUMSIZE(%rsp), %rdi+ leaq NUMSIZE(%rbx), %rsi+ CFI_CALL(Lp521_jscalarmul_bignum_mod_p521_9)++ leaq TAB+2*NUMSIZE(%rsp), %rdi+ leaq 2*NUMSIZE(%rbx), %rsi+ CFI_CALL(Lp521_jscalarmul_bignum_mod_p521_9)++// If bit 520 of the scalar is set, then negate the scalar mod n_521,+// i.e. do scalar |-> n_521 - scalar, and also the point to compensate+// by negating its y coordinate. This further step is not needed by+// the indexing scheme (the top window is only a couple of bits either+// way), but is convenient to exclude a problem with the specific value+// scalar = n_521 - 18, where the last Jacobian addition is of the form+// (n_521 - 9) * P + -(9 * P) and hence is a degenerate doubling case.++ xorl %eax, %eax+ notq %rax+ movq $0xbb6fb71e91386409, %r8+ subq SCALARB(%rsp), %r8+ movq $0x3bb5c9b8899c47ae, %r9+ sbbq SCALARB+8(%rsp), %r9+ movq $0x7fcc0148f709a5d0, %r10+ sbbq SCALARB+16(%rsp), %r10+ movq $0x51868783bf2f966b, %r11+ sbbq SCALARB+24(%rsp), %r11+ leaq -5(%rax), %r12+ sbbq SCALARB+32(%rsp), %r12+ movq %rax, %r13+ sbbq SCALARB+40(%rsp), %r13+ movq %rax, %r14+ sbbq SCALARB+48(%rsp), %r14+ movq %rax, %r15+ sbbq SCALARB+56(%rsp), %r15+ movq $0x1ff, %rax+ movq SCALARB+64(%rsp), %rcx+ sbbq %rcx, %rax++ btq $8, %rcx+ sbbq %rcx, %rcx++ cmovncq SCALARB(%rsp), %r8+ cmovncq SCALARB+8(%rsp), %r9+ cmovncq SCALARB+16(%rsp), %r10+ cmovncq SCALARB+24(%rsp), %r11+ cmovncq SCALARB+32(%rsp), %r12+ cmovncq SCALARB+40(%rsp), %r13+ cmovncq SCALARB+48(%rsp), %r14+ cmovncq SCALARB+56(%rsp), %r15+ cmovncq SCALARB+64(%rsp), %rax++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)+ movq %r14, SCALARB+48(%rsp)+ movq %r15, SCALARB+56(%rsp)+ movq %rax, SCALARB+64(%rsp)++ movq TAB+NUMSIZE(%rsp), %r8+ movq TAB+NUMSIZE+8(%rsp), %r9+ movq TAB+NUMSIZE+16(%rsp), %r10+ movq TAB+NUMSIZE+24(%rsp), %r11+ movq TAB+NUMSIZE+32(%rsp), %r12+ movq TAB+NUMSIZE+40(%rsp), %r13+ movq TAB+NUMSIZE+48(%rsp), %r14+ movq TAB+NUMSIZE+56(%rsp), %r15+ movq TAB+NUMSIZE+64(%rsp), %rax++ movq %r8, %rbx+ movq %r12, %rbp+ orq %r9, %rbx+ orq %r13, %rbp+ orq %r10, %rbx+ orq %r14, %rbp+ orq %r11, %rbx+ orq %r15, %rbp+ orq %rbp, %rbx+ orq %rax, %rbx+ cmovzq %rbx, %rcx++ xorq %rcx, %r8+ xorq %rcx, %r9+ xorq %rcx, %r10+ xorq %rcx, %r11+ xorq %rcx, %r12+ xorq %rcx, %r13+ xorq %rcx, %r14+ xorq %rcx, %r15+ andq $0x1FF, %rcx+ xorq %rcx, %rax++ movq %r8, TAB+NUMSIZE(%rsp)+ movq %r9, TAB+NUMSIZE+8(%rsp)+ movq %r10, TAB+NUMSIZE+16(%rsp)+ movq %r11, TAB+NUMSIZE+24(%rsp)+ movq %r12, TAB+NUMSIZE+32(%rsp)+ movq %r13, TAB+NUMSIZE+40(%rsp)+ movq %r14, TAB+NUMSIZE+48(%rsp)+ movq %r15, TAB+NUMSIZE+56(%rsp)+ movq %rax, TAB+NUMSIZE+64(%rsp)++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ leaq TAB+JACSIZE*1(%rsp), %rdi+ leaq TAB(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq TAB+JACSIZE*2(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_jadd)++ leaq TAB+JACSIZE*3(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq TAB+JACSIZE*4(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_jadd)++ leaq TAB+JACSIZE*5(%rsp), %rdi+ leaq TAB+JACSIZE*2(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq TAB+JACSIZE*6(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_jadd)++ leaq TAB+JACSIZE*7(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq TAB+JACSIZE*8(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_jadd)++ leaq TAB+JACSIZE*9(%rsp), %rdi+ leaq TAB+JACSIZE*4(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq TAB+JACSIZE*10(%rsp), %rdi+ leaq TAB+JACSIZE*9(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_jadd)++ leaq TAB+JACSIZE*11(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq TAB+JACSIZE*12(%rsp), %rdi+ leaq TAB+JACSIZE*11(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_jadd)++ leaq TAB+JACSIZE*13(%rsp), %rdi+ leaq TAB+JACSIZE*6(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq TAB+JACSIZE*14(%rsp), %rdi+ leaq TAB+JACSIZE*13(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_jadd)++ leaq TAB+JACSIZE*15(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_jdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically to use fewer large constant loads.+//+// 0x0842108421084210 %rax+// 0x1084210842108421 %rbx+// 0x2108421084210842 %rbx<<1+// 0x4210842108421084 %rbx<<2+// 0x8421084210842108 %rbx<<3+// 0x0842108421084210 %rax+// 0x1084210842108421 %rbx+// 0x2108421084210842 %rbx<<1+// 0x0000000000000084++ movq $0x1084210842108421, %rax+ movq %rax, %rbx+ shrq $1, %rax+ movq SCALARB(%rsp), %r8+ addq %rax, %r8+ movq SCALARB+8(%rsp), %r9+ adcq %rbx, %r9+ leaq (%rbx,%rbx), %rcx+ movq SCALARB+16(%rsp), %r10+ adcq %rcx, %r10+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+24(%rsp), %r11+ adcq %rcx, %r11+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+32(%rsp), %r12+ adcq %rcx, %r12+ movq SCALARB+40(%rsp), %r13+ adcq %rax, %r13+ movq SCALARB+48(%rsp), %r14+ adcq %rbx, %r14+ movq SCALARB+56(%rsp), %r15+ leaq (%rbx,%rbx), %rcx+ adcq %rcx, %r15+ movq SCALARB+64(%rsp), %rax+ adcq $0x84, %rax++// Because of the initial reduction the top bitfield (>= bits 520) is <= 1,+// i.e. just a single bit. Record that in %rdi, then shift the whole+// scalar left 56 bits to align the top of the next bitfield with the MSB+// (bits 571..575).++ movq %rax, %rdi+ shrq $8, %rdi+ shldq $56, %r15, %rax+ shldq $56, %r14, %r15+ shldq $56, %r13, %r14+ shldq $56, %r12, %r13+ shldq $56, %r11, %r12+ shldq $56, %r10, %r11+ shldq $56, %r9, %r10+ shldq $56, %r8, %r9+ shlq $56, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)+ movq %r14, SCALARB+48(%rsp)+ movq %r15, SCALARB+56(%rsp)+ movq %rax, SCALARB+64(%rsp)++// According to the top bit, initialize the accumulator to P or 0. This top+// digit, uniquely, is not recoded so there is no sign adjustment to make.+// We only really need to adjust the z coordinate to zero, but do all three.++ xorl %ecx, %ecx+ testq %rdi, %rdi++ movq TAB(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC(%rsp)+ movq TAB+8(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+8(%rsp)+ movq TAB+16(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+16(%rsp)+ movq TAB+24(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+24(%rsp)+ movq TAB+32(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+32(%rsp)+ movq TAB+40(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+40(%rsp)+ movq TAB+48(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+48(%rsp)+ movq TAB+56(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+56(%rsp)+ movq TAB+64(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+64(%rsp)+ movq TAB+72(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+72(%rsp)+ movq TAB+80(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+80(%rsp)+ movq TAB+88(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+88(%rsp)+ movq TAB+96(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+96(%rsp)+ movq TAB+104(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+104(%rsp)+ movq TAB+112(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+112(%rsp)+ movq TAB+120(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+120(%rsp)+ movq TAB+128(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+128(%rsp)+ movq TAB+136(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+136(%rsp)+ movq TAB+144(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+144(%rsp)+ movq TAB+152(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+152(%rsp)+ movq TAB+160(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+160(%rsp)+ movq TAB+168(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+168(%rsp)+ movq TAB+176(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+176(%rsp)+ movq TAB+184(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+184(%rsp)+ movq TAB+192(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+192(%rsp)+ movq TAB+200(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+200(%rsp)+ movq TAB+208(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+208(%rsp)++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++ movl $520, %ebp++Lp521_jscalarmul_mainloop:+ subq $5, %rbp++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_jdouble)++// Choose the bitfield and adjust it to sign and magnitude++ movq SCALARB(%rsp), %r8+ movq SCALARB+8(%rsp), %r9+ movq SCALARB+16(%rsp), %r10+ movq SCALARB+24(%rsp), %r11+ movq SCALARB+32(%rsp), %r12+ movq SCALARB+40(%rsp), %r13+ movq SCALARB+48(%rsp), %r14+ movq SCALARB+56(%rsp), %r15+ movq SCALARB+64(%rsp), %rax+++ movq %rax, %rdi+ shrq $59, %rdi++ shldq $5, %r15, %rax+ shldq $5, %r14, %r15+ shldq $5, %r13, %r14+ shldq $5, %r12, %r13+ shldq $5, %r11, %r12+ shldq $5, %r10, %r11+ shldq $5, %r9, %r10+ shldq $5, %r8, %r9+ shlq $5, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)+ movq %r14, SCALARB+48(%rsp)+ movq %r15, SCALARB+56(%rsp)+ movq %rax, SCALARB+64(%rsp)++ subq $16, %rdi+ sbbq %rsi, %rsi // %rsi = sign of digit (-1 = negative)+ xorq %rsi, %rdi+ subq %rsi, %rdi // %rdi = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time+// Again, this is done in separate sweeps per coordinate, doing y last.++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ selectblock(1,0)+ selectblock(2,0)+ selectblock(3,0)+ selectblock(4,0)+ selectblock(5,0)+ selectblock(6,0)+ selectblock(7,0)+ selectblock(8,0)+ selectblock(9,0)+ selectblock(10,0)+ selectblock(11,0)+ selectblock(12,0)+ selectblock(13,0)+ selectblock(14,0)+ selectblock(15,0)+ selectblock(16,0)+ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)+ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+48(%rsp)+ movq %r11, TABENT+56(%rsp)+ movq %r12, TABENT+64(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ selectblock(1,2)+ selectblock(2,2)+ selectblock(3,2)+ selectblock(4,2)+ selectblock(5,2)+ selectblock(6,2)+ selectblock(7,2)+ selectblock(8,2)+ selectblock(9,2)+ selectblock(10,2)+ selectblock(11,2)+ selectblock(12,2)+ selectblock(13,2)+ selectblock(14,2)+ selectblock(15,2)+ selectblock(16,2)+ movq %rax, TABENT+2*NUMSIZE(%rsp)+ movq %rbx, TABENT+2*NUMSIZE+8(%rsp)+ movq %rcx, TABENT+2*NUMSIZE+16(%rsp)+ movq %rdx, TABENT+2*NUMSIZE+24(%rsp)+ movq %r8, TABENT+2*NUMSIZE+32(%rsp)+ movq %r9, TABENT+2*NUMSIZE+40(%rsp)+ movq %r10, TABENT+2*NUMSIZE+48(%rsp)+ movq %r11, TABENT+2*NUMSIZE+56(%rsp)+ movq %r12, TABENT+2*NUMSIZE+64(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ selectblock(1,1)+ selectblock(2,1)+ selectblock(3,1)+ selectblock(4,1)+ selectblock(5,1)+ selectblock(6,1)+ selectblock(7,1)+ selectblock(8,1)+ selectblock(9,1)+ selectblock(10,1)+ selectblock(11,1)+ selectblock(12,1)+ selectblock(13,1)+ selectblock(14,1)+ selectblock(15,1)+ selectblock(16,1)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_521 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).++ movq %rax, %r13+ orq %rbx, %r13+ movq %rcx, %r14+ orq %rdx, %r14+ movq %r8, %r15+ orq %r9, %r15+ movq %r10, %rdi+ orq %r11, %rdi+ orq %r14, %r13+ orq %rdi, %r15+ orq %r12, %r15+ orq %r15, %r13+ cmovzq %r13, %rsi++ xorq %rsi, %rax+ xorq %rsi, %rbx+ xorq %rsi, %rcx+ xorq %rsi, %rdx+ xorq %rsi, %r8+ xorq %rsi, %r9+ xorq %rsi, %r10+ xorq %rsi, %r11+ andq $0x1FF, %rsi+ xorq %rsi, %r12++ movq %rax, TABENT+NUMSIZE(%rsp)+ movq %rbx, TABENT+NUMSIZE+8(%rsp)+ movq %rcx, TABENT+NUMSIZE+16(%rsp)+ movq %rdx, TABENT+NUMSIZE+24(%rsp)+ movq %r8, TABENT+NUMSIZE+32(%rsp)+ movq %r9, TABENT+NUMSIZE+40(%rsp)+ movq %r10, TABENT+NUMSIZE+48(%rsp)+ movq %r11, TABENT+NUMSIZE+56(%rsp)+ movq %r12, TABENT+NUMSIZE+64(%rsp)++// Add to the accumulator++ leaq TABENT(%rsp), %rdx+ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_jadd)++ testq %rbp, %rbp+ jne Lp521_jscalarmul_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ movq res, %rdi+ movq ACC(%rsp), %rax+ movq %rax, (%rdi)+ movq ACC+8(%rsp), %rax+ movq %rax, 8(%rdi)+ movq ACC+16(%rsp), %rax+ movq %rax, 16(%rdi)+ movq ACC+24(%rsp), %rax+ movq %rax, 24(%rdi)+ movq ACC+32(%rsp), %rax+ movq %rax, 32(%rdi)+ movq ACC+40(%rsp), %rax+ movq %rax, 40(%rdi)+ movq ACC+48(%rsp), %rax+ movq %rax, 48(%rdi)+ movq ACC+56(%rsp), %rax+ movq %rax, 56(%rdi)+ movq ACC+64(%rsp), %rax+ movq %rax, 64(%rdi)+ movq ACC+72(%rsp), %rax+ movq %rax, 72(%rdi)+ movq ACC+80(%rsp), %rax+ movq %rax, 80(%rdi)+ movq ACC+88(%rsp), %rax+ movq %rax, 88(%rdi)+ movq ACC+96(%rsp), %rax+ movq %rax, 96(%rdi)+ movq ACC+104(%rsp), %rax+ movq %rax, 104(%rdi)+ movq ACC+112(%rsp), %rax+ movq %rax, 112(%rdi)+ movq ACC+120(%rsp), %rax+ movq %rax, 120(%rdi)+ movq ACC+128(%rsp), %rax+ movq %rax, 128(%rdi)+ movq ACC+136(%rsp), %rax+ movq %rax, 136(%rdi)+ movq ACC+144(%rsp), %rax+ movq %rax, 144(%rdi)+ movq ACC+152(%rsp), %rax+ movq %rax, 152(%rdi)+ movq ACC+160(%rsp), %rax+ movq %rax, 160(%rdi)+ movq ACC+168(%rsp), %rax+ movq %rax, 168(%rdi)+ movq ACC+176(%rsp), %rax+ movq %rax, 176(%rdi)+ movq ACC+184(%rsp), %rax+ movq %rax, 184(%rdi)+ movq ACC+192(%rsp), %rax+ movq %rax, 192(%rdi)+ movq ACC+200(%rsp), %rax+ movq %rax, 200(%rdi)+ movq ACC+208(%rsp), %rax+ movq %rax, 208(%rdi)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p521_jscalarmul)+#endif++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_p521_9)++Lp521_jscalarmul_bignum_mod_p521_9:+ CFI_START+ CFI_PUSH(%rbx)+ movq 0x40(%rsi), %rax+ movl $0x1ff, %edx+ andq %rax, %rdx+ shrq $0x9, %rax+ stc+ adcq (%rsi), %rax+ movq 0x8(%rsi), %rcx+ adcq $0x0, %rcx+ movq 0x10(%rsi), %r8+ adcq $0x0, %r8+ movq 0x18(%rsi), %r9+ adcq $0x0, %r9+ movq 0x20(%rsi), %r10+ adcq $0x0, %r10+ movq 0x28(%rsi), %r11+ adcq $0x0, %r11+ movq 0x30(%rsi), %rbx+ adcq $0x0, %rbx+ movq 0x38(%rsi), %rsi+ adcq $0x0, %rsi+ adcq $0x0, %rdx+ cmpq $0x200, %rdx+ sbbq $0x0, %rax+ movq %rax, (%rdi)+ sbbq $0x0, %rcx+ movq %rcx, 0x8(%rdi)+ sbbq $0x0, %r8+ movq %r8, 0x10(%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rdi)+ sbbq $0x0, %rbx+ movq %rbx, 0x30(%rdi)+ sbbq $0x0, %rsi+ movq %rsi, 0x38(%rdi)+ sbbq $0x0, %rdx+ andq $0x1ff, %rdx+ movq %rdx, 0x40(%rdi)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_p521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_n521_9)++Lp521_jscalarmul_bignum_mod_n521_9:+ CFI_START+ movq 0x40(%rsi), %rdx+ movq $0xfffffffffffffe00, %rax+ orq %rdx, %rax+ movq %rax, 0x40(%rdi)+ shrq $0x9, %rdx+ addq $0x1, %rdx+ movq $0x449048e16ec79bf7, %r9+ mulxq %r9, %rax, %rcx+ adcxq (%rsi), %rax+ movq %rax, (%rdi)+ movq $0xc44a36477663b851, %r10+ mulxq %r10, %rax, %r8+ adcxq 0x8(%rsi), %rax+ adoxq %rcx, %rax+ movq %rax, 0x8(%rdi)+ movq $0x8033feb708f65a2f, %r11+ mulxq %r11, %rax, %rcx+ adcxq 0x10(%rsi), %rax+ adoxq %r8, %rax+ movq %rax, 0x10(%rdi)+ movq $0xae79787c40d06994, %rax+ mulxq %rax, %rax, %r8+ adcxq 0x18(%rsi), %rax+ adoxq %rcx, %rax+ movq %rax, 0x18(%rdi)+ movl $0x5, %eax+ mulxq %rax, %rax, %rcx+ adcxq 0x20(%rsi), %rax+ adoxq %r8, %rax+ movq %rax, 0x20(%rdi)+ movq %rcx, %rax+ adoxq %rcx, %rcx+ adcq 0x28(%rsi), %rcx+ movq %rcx, 0x28(%rdi)+ movq 0x30(%rsi), %rcx+ adcq %rax, %rcx+ movq %rcx, 0x30(%rdi)+ movq 0x38(%rsi), %rcx+ adcq %rax, %rcx+ movq %rcx, 0x38(%rdi)+ movq 0x40(%rdi), %rcx+ adcq %rax, %rcx+ cmc+ sbbq %rdx, %rdx+ andq %rdx, %r9+ andq %rdx, %r10+ andq %rdx, %r11+ movq $0xae79787c40d06994, %r8+ andq %rdx, %r8+ andl $0x5, %edx+ subq %r9, (%rdi)+ sbbq %r10, 0x8(%rdi)+ sbbq %r11, 0x10(%rdi)+ sbbq %r8, 0x18(%rdi)+ sbbq %rdx, 0x20(%rdi)+ sbbq %rax, 0x28(%rdi)+ sbbq %rax, 0x30(%rdi)+ sbbq %rax, 0x38(%rdi)+ sbbl %eax, %ecx+ andl $0x1ff, %ecx+ movq %rcx, 0x40(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_bignum_mod_n521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_jadd)++Lp521_jscalarmul_jadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(528)+ movq %rdi, 0x1f8(%rsp)+ movq %rsi, 0x200(%rsp)+ movq %rdx, 0x208(%rsp)+ movq 0x200(%rsp), %rsi+ leaq 0x90(%rsi), %rsi+ leaq (%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ movq 0x208(%rsp), %rdi+ leaq 0x90(%rdi), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ movq 0x200(%rsp), %rsi+ movq 0x208(%rsp), %rdi+ leaq 0x48(%rsi), %rdx+ leaq 0x90(%rdi), %rsi+ leaq 0x1b0(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x200(%rsp), %rsi+ movq 0x208(%rsp), %rdi+ leaq 0x48(%rdi), %rdx+ leaq 0x90(%rsi), %rsi+ leaq 0x48(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x208(%rsp), %rdi+ leaq (%rdi), %rdx+ leaq (%rsp), %rsi+ leaq 0x90(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x200(%rsp), %rsi+ leaq (%rsi), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ leaq 0x48(%rsp), %rdx+ leaq (%rsp), %rsi+ leaq 0x48(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ leaq 0x1b0(%rsp), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x1b0(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x90(%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x98(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0xa0(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0xa8(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0xb0(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0xb8(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ movq 0xc0(%rsp), %r12+ sbbq 0x150(%rsp), %r12+ movq 0xc8(%rsp), %r13+ sbbq 0x158(%rsp), %r13+ movq 0xd0(%rsp), %r14+ sbbq 0x160(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x1a8(%rsp)+ movq 0x48(%rsp), %rax+ subq 0x1b0(%rsp), %rax+ movq 0x50(%rsp), %rdx+ sbbq 0x1b8(%rsp), %rdx+ movq 0x58(%rsp), %r8+ sbbq 0x1c0(%rsp), %r8+ movq 0x60(%rsp), %r9+ sbbq 0x1c8(%rsp), %r9+ movq 0x68(%rsp), %r10+ sbbq 0x1d0(%rsp), %r10+ movq 0x70(%rsp), %r11+ sbbq 0x1d8(%rsp), %r11+ movq 0x78(%rsp), %r12+ sbbq 0x1e0(%rsp), %r12+ movq 0x80(%rsp), %r13+ sbbq 0x1e8(%rsp), %r13+ movq 0x88(%rsp), %r14+ sbbq 0x1f0(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x48(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x50(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x58(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x60(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x68(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x70(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x78(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x80(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x88(%rsp)+ leaq 0x168(%rsp), %rsi+ leaq 0xd8(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ leaq 0x48(%rsp), %rsi+ leaq (%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ leaq 0x120(%rsp), %rdx+ leaq 0xd8(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ leaq 0x90(%rsp), %rdx+ leaq 0xd8(%rsp), %rsi+ leaq 0x90(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq (%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ movq 0x30(%rsp), %r12+ sbbq 0x150(%rsp), %r12+ movq 0x38(%rsp), %r13+ sbbq 0x158(%rsp), %r13+ movq 0x40(%rsp), %r14+ sbbq 0x160(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, (%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x30(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x38(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x40(%rsp)+ movq 0x90(%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x98(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0xa0(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0xa8(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0xb0(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0xb8(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ movq 0xc0(%rsp), %r12+ sbbq 0x150(%rsp), %r12+ movq 0xc8(%rsp), %r13+ sbbq 0x158(%rsp), %r13+ movq 0xd0(%rsp), %r14+ sbbq 0x160(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0xd8(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0xe0(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0xe8(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xf0(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xf8(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x100(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x108(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x110(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x118(%rsp)+ movq 0x200(%rsp), %rsi+ leaq 0x90(%rsi), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq (%rsp), %rax+ subq 0x90(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0x98(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0xa0(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0xa8(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0xb0(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0xb8(%rsp), %r11+ movq 0x30(%rsp), %r12+ sbbq 0xc0(%rsp), %r12+ movq 0x38(%rsp), %r13+ sbbq 0xc8(%rsp), %r13+ movq 0x40(%rsp), %r14+ sbbq 0xd0(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, (%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x30(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x38(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x40(%rsp)+ movq 0x120(%rsp), %rax+ subq (%rsp), %rax+ movq 0x128(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x130(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x138(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x140(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x148(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ movq 0x150(%rsp), %r12+ sbbq 0x30(%rsp), %r12+ movq 0x158(%rsp), %r13+ sbbq 0x38(%rsp), %r13+ movq 0x160(%rsp), %r14+ sbbq 0x40(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x120(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x128(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x130(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x138(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x140(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x148(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x150(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x158(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x160(%rsp)+ leaq 0x1b0(%rsp), %rdx+ leaq 0xd8(%rsp), %rsi+ leaq 0xd8(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x208(%rsp), %rdi+ leaq 0x90(%rdi), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ leaq 0x120(%rsp), %rdx+ leaq 0x48(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x120(%rsp), %rax+ subq 0xd8(%rsp), %rax+ movq 0x128(%rsp), %rdx+ sbbq 0xe0(%rsp), %rdx+ movq 0x130(%rsp), %r8+ sbbq 0xe8(%rsp), %r8+ movq 0x138(%rsp), %r9+ sbbq 0xf0(%rsp), %r9+ movq 0x140(%rsp), %r10+ sbbq 0xf8(%rsp), %r10+ movq 0x148(%rsp), %r11+ sbbq 0x100(%rsp), %r11+ movq 0x150(%rsp), %r12+ sbbq 0x108(%rsp), %r12+ movq 0x158(%rsp), %r13+ sbbq 0x110(%rsp), %r13+ movq 0x160(%rsp), %r14+ sbbq 0x118(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x120(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x128(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x130(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x138(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x140(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x148(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x150(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x158(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x160(%rsp)+ movq 0x200(%rsp), %rsi+ movq 0x90(%rsi), %r8+ movq 0x98(%rsi), %r9+ movq 0xa0(%rsi), %r10+ movq 0xa8(%rsi), %r11+ movq 0xb0(%rsi), %r12+ movq 0xb8(%rsi), %r13+ movq 0xc0(%rsi), %r14+ movq 0xc8(%rsi), %r15+ movq 0xd0(%rsi), %rbp+ orq %r9, %r8+ orq %r11, %r10+ orq %r13, %r12+ orq %r15, %r14+ orq %r10, %r8+ orq %r14, %r12+ orq %rbp, %r8+ orq %r12, %r8+ negq %r8+ sbbq %rax, %rax+ movq 0x208(%rsp), %rdi+ movq 0x90(%rdi), %r8+ movq 0x98(%rdi), %r9+ movq 0xa0(%rdi), %r10+ movq 0xa8(%rdi), %r11+ movq 0xb0(%rdi), %r12+ movq 0xb8(%rdi), %r13+ movq 0xc0(%rdi), %r14+ movq 0xc8(%rdi), %r15+ movq 0xd0(%rdi), %rbp+ orq %r9, %r8+ orq %r11, %r10+ orq %r13, %r12+ orq %r15, %r14+ orq %r10, %r8+ orq %r14, %r12+ orq %rbp, %r8+ orq %r12, %r8+ negq %r8+ sbbq %rdx, %rdx+ cmpq %rax, %rdx+ movq 0x120(%rsp), %r8+ cmovbq 0x48(%rsi), %r8+ cmova 0x48(%rdi), %r8+ movq 0x128(%rsp), %r9+ cmovbq 0x50(%rsi), %r9+ cmova 0x50(%rdi), %r9+ movq 0x130(%rsp), %r10+ cmovbq 0x58(%rsi), %r10+ cmova 0x58(%rdi), %r10+ movq 0x138(%rsp), %r11+ cmovbq 0x60(%rsi), %r11+ cmova 0x60(%rdi), %r11+ movq 0x140(%rsp), %r12+ cmovbq 0x68(%rsi), %r12+ cmova 0x68(%rdi), %r12+ movq 0x148(%rsp), %r13+ cmovbq 0x70(%rsi), %r13+ cmova 0x70(%rdi), %r13+ movq 0x150(%rsp), %r14+ cmovbq 0x78(%rsi), %r14+ cmova 0x78(%rdi), %r14+ movq 0x158(%rsp), %r15+ cmovbq 0x80(%rsi), %r15+ cmova 0x80(%rdi), %r15+ movq 0x160(%rsp), %rbp+ cmovbq 0x88(%rsi), %rbp+ cmova 0x88(%rdi), %rbp+ movq %r8, 0x120(%rsp)+ movq %r9, 0x128(%rsp)+ movq %r10, 0x130(%rsp)+ movq %r11, 0x138(%rsp)+ movq %r12, 0x140(%rsp)+ movq %r13, 0x148(%rsp)+ movq %r14, 0x150(%rsp)+ movq %r15, 0x158(%rsp)+ movq %rbp, 0x160(%rsp)+ movq 0x168(%rsp), %r8+ cmovbq 0x90(%rsi), %r8+ cmova 0x90(%rdi), %r8+ movq 0x170(%rsp), %r9+ cmovbq 0x98(%rsi), %r9+ cmova 0x98(%rdi), %r9+ movq 0x178(%rsp), %r10+ cmovbq 0xa0(%rsi), %r10+ cmova 0xa0(%rdi), %r10+ movq 0x180(%rsp), %r11+ cmovbq 0xa8(%rsi), %r11+ cmova 0xa8(%rdi), %r11+ movq 0x188(%rsp), %r12+ cmovbq 0xb0(%rsi), %r12+ cmova 0xb0(%rdi), %r12+ movq 0x190(%rsp), %r13+ cmovbq 0xb8(%rsi), %r13+ cmova 0xb8(%rdi), %r13+ movq 0x198(%rsp), %r14+ cmovbq 0xc0(%rsi), %r14+ cmova 0xc0(%rdi), %r14+ movq 0x1a0(%rsp), %r15+ cmovbq 0xc8(%rsi), %r15+ cmova 0xc8(%rdi), %r15+ movq 0x1a8(%rsp), %rbp+ cmovbq 0xd0(%rsi), %rbp+ cmova 0xd0(%rdi), %rbp+ movq %r8, 0x168(%rsp)+ movq %r9, 0x170(%rsp)+ movq %r10, 0x178(%rsp)+ movq %r11, 0x180(%rsp)+ movq %r12, 0x188(%rsp)+ movq %r13, 0x190(%rsp)+ movq %r14, 0x198(%rsp)+ movq %r15, 0x1a0(%rsp)+ movq %rbp, 0x1a8(%rsp)+ movq (%rsp), %r8+ cmovbq (%rsi), %r8+ cmova (%rdi), %r8+ movq 0x8(%rsp), %r9+ cmovbq 0x8(%rsi), %r9+ cmova 0x8(%rdi), %r9+ movq 0x10(%rsp), %r10+ cmovbq 0x10(%rsi), %r10+ cmova 0x10(%rdi), %r10+ movq 0x18(%rsp), %r11+ cmovbq 0x18(%rsi), %r11+ cmova 0x18(%rdi), %r11+ movq 0x20(%rsp), %r12+ cmovbq 0x20(%rsi), %r12+ cmova 0x20(%rdi), %r12+ movq 0x28(%rsp), %r13+ cmovbq 0x28(%rsi), %r13+ cmova 0x28(%rdi), %r13+ movq 0x30(%rsp), %r14+ cmovbq 0x30(%rsi), %r14+ cmova 0x30(%rdi), %r14+ movq 0x38(%rsp), %r15+ cmovbq 0x38(%rsi), %r15+ cmova 0x38(%rdi), %r15+ movq 0x40(%rsp), %rbp+ cmovbq 0x40(%rsi), %rbp+ cmova 0x40(%rdi), %rbp+ movq 0x1f8(%rsp), %rdi+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %r12, 0x20(%rdi)+ movq %r13, 0x28(%rdi)+ movq %r14, 0x30(%rdi)+ movq %r15, 0x38(%rdi)+ movq %rbp, 0x40(%rdi)+ movq 0x120(%rsp), %rax+ movq %rax, 0x48(%rdi)+ movq 0x128(%rsp), %rax+ movq %rax, 0x50(%rdi)+ movq 0x130(%rsp), %rax+ movq %rax, 0x58(%rdi)+ movq 0x138(%rsp), %rax+ movq %rax, 0x60(%rdi)+ movq 0x140(%rsp), %rax+ movq %rax, 0x68(%rdi)+ movq 0x148(%rsp), %rax+ movq %rax, 0x70(%rdi)+ movq 0x150(%rsp), %rax+ movq %rax, 0x78(%rdi)+ movq 0x158(%rsp), %rax+ movq %rax, 0x80(%rdi)+ movq 0x160(%rsp), %rax+ movq %rax, 0x88(%rdi)+ movq 0x168(%rsp), %rax+ movq %rax, 0x90(%rdi)+ movq 0x170(%rsp), %rax+ movq %rax, 0x98(%rdi)+ movq 0x178(%rsp), %rax+ movq %rax, 0xa0(%rdi)+ movq 0x180(%rsp), %rax+ movq %rax, 0xa8(%rdi)+ movq 0x188(%rsp), %rax+ movq %rax, 0xb0(%rdi)+ movq 0x190(%rsp), %rax+ movq %rax, 0xb8(%rdi)+ movq 0x198(%rsp), %rax+ movq %rax, 0xc0(%rdi)+ movq 0x1a0(%rsp), %rax+ movq %rax, 0xc8(%rdi)+ movq 0x1a8(%rsp), %rax+ movq %rax, 0xd0(%rdi)+ CFI_INC_RSP(528)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_jadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_jdouble)++Lp521_jscalarmul_jdouble:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(520)+ movq %rdi, 0x1f8(%rsp)+ movq %rsi, 0x200(%rsp)+ movq 0x200(%rsp), %rdi+ leaq 0x90(%rdi), %rsi+ leaq (%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ movq 0x200(%rsp), %rdi+ leaq 0x48(%rdi), %rsi+ leaq 0x48(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ movq 0x200(%rsp), %rdi+ stc+ movq (%rdi), %rax+ adcq (%rsp), %rax+ movq 0x8(%rdi), %rbx+ adcq 0x8(%rsp), %rbx+ movq 0x10(%rdi), %r8+ adcq 0x10(%rsp), %r8+ movq 0x18(%rdi), %r9+ adcq 0x18(%rsp), %r9+ movq 0x20(%rdi), %r10+ adcq 0x20(%rsp), %r10+ movq 0x28(%rdi), %r11+ adcq 0x28(%rsp), %r11+ movq 0x30(%rdi), %r12+ adcq 0x30(%rsp), %r12+ movq 0x38(%rdi), %r13+ adcq 0x38(%rsp), %r13+ movq 0x40(%rdi), %r14+ adcq 0x40(%rsp), %r14+ movq $0x200, %rdx+ andq %r14, %rdx+ cmpq $0x200, %rdx+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rbx+ movq %rbx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq %rdx, %r14+ movq %r14, 0x1a8(%rsp)+ movq 0x200(%rsp), %rdi+ movq (%rdi), %rax+ subq (%rsp), %rax+ movq 0x8(%rdi), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x10(%rdi), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x18(%rdi), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x20(%rdi), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x28(%rdi), %r11+ sbbq 0x28(%rsp), %r11+ movq 0x30(%rdi), %r12+ sbbq 0x30(%rsp), %r12+ movq 0x38(%rdi), %r13+ sbbq 0x38(%rsp), %r13+ movq 0x40(%rdi), %r14+ sbbq 0x40(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x120(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x128(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x130(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x138(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x140(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x148(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x150(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x158(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x160(%rsp)+ leaq 0x120(%rsp), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x90(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x200(%rsp), %rdi+ stc+ movq 0x48(%rdi), %rax+ adcq 0x90(%rdi), %rax+ movq 0x50(%rdi), %rbx+ adcq 0x98(%rdi), %rbx+ movq 0x58(%rdi), %r8+ adcq 0xa0(%rdi), %r8+ movq 0x60(%rdi), %r9+ adcq 0xa8(%rdi), %r9+ movq 0x68(%rdi), %r10+ adcq 0xb0(%rdi), %r10+ movq 0x70(%rdi), %r11+ adcq 0xb8(%rdi), %r11+ movq 0x78(%rdi), %r12+ adcq 0xc0(%rdi), %r12+ movq 0x80(%rdi), %r13+ adcq 0xc8(%rdi), %r13+ movq 0x88(%rdi), %r14+ adcq 0xd0(%rdi), %r14+ movq $0x200, %rdx+ andq %r14, %rdx+ cmpq $0x200, %rdx+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rbx+ movq %rbx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq %rdx, %r14+ movq %r14, 0x1a8(%rsp)+ leaq 0x90(%rsp), %rsi+ leaq 0x1b0(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ movq 0x200(%rsp), %rdi+ leaq 0x48(%rsp), %rdx+ leaq (%rdi), %rsi+ leaq 0xd8(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ leaq 0x168(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ movq $0x9, %rdx+ movq 0x1f0(%rsp), %rbx+ xorq $0x1ff, %rbx+ movq 0x1b0(%rsp), %rax+ notq %rax+ mulxq %rax, %r8, %r9+ movq 0x1b8(%rsp), %rax+ notq %rax+ mulxq %rax, %rax, %r10+ addq %rax, %r9+ movq 0x1c0(%rsp), %rax+ notq %rax+ mulxq %rax, %rax, %r11+ adcq %rax, %r10+ movq 0x1c8(%rsp), %rax+ notq %rax+ mulxq %rax, %rax, %r12+ adcq %rax, %r11+ movq 0x1d0(%rsp), %rax+ notq %rax+ mulxq %rax, %rax, %r13+ adcq %rax, %r12+ movq 0x1d8(%rsp), %rax+ notq %rax+ mulxq %rax, %rax, %r14+ adcq %rax, %r13+ movq 0x1e0(%rsp), %rax+ notq %rax+ mulxq %rax, %rax, %r15+ adcq %rax, %r14+ movq 0x1e8(%rsp), %rax+ notq %rax+ mulxq %rax, %rax, %rcx+ adcq %rax, %r15+ mulxq %rbx, %rbx, %rax+ adcq %rcx, %rbx+ xorl %eax, %eax+ movq $0xc, %rdx+ mulxq 0xd8(%rsp), %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ mulxq 0xe0(%rsp), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq 0xe8(%rsp), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ mulxq 0xf0(%rsp), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq 0xf8(%rsp), %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ mulxq 0x100(%rsp), %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ mulxq 0x108(%rsp), %rax, %rcx+ adcxq %rax, %r14+ adoxq %rcx, %r15+ mulxq 0x110(%rsp), %rax, %rcx+ adcxq %rax, %r15+ adoxq %rcx, %rbx+ mulxq 0x118(%rsp), %rax, %rcx+ adcxq %rax, %rbx+ movq %r9, %rax+ andq %r10, %rax+ andq %r11, %rax+ andq %r12, %rax+ andq %r13, %rax+ andq %r14, %rax+ andq %r15, %rax+ movq %rbx, %rdx+ shrq $0x9, %rdx+ orq $0xfffffffffffffe00, %rbx+ leaq 0x1(%rdx), %rcx+ addq %r8, %rcx+ movl $0x0, %ecx+ adcq %rcx, %rax+ movq %rbx, %rax+ adcq %rcx, %rax+ adcq %rdx, %r8+ movq %r8, 0x1b0(%rsp)+ adcq %rcx, %r9+ movq %r9, 0x1b8(%rsp)+ adcq %rcx, %r10+ movq %r10, 0x1c0(%rsp)+ adcq %rcx, %r11+ movq %r11, 0x1c8(%rsp)+ adcq %rcx, %r12+ movq %r12, 0x1d0(%rsp)+ adcq %rcx, %r13+ movq %r13, 0x1d8(%rsp)+ adcq %rcx, %r14+ movq %r14, 0x1e0(%rsp)+ adcq %rcx, %r15+ movq %r15, 0x1e8(%rsp)+ adcq %rcx, %rbx+ andq $0x1ff, %rbx+ movq %rbx, 0x1f0(%rsp)+ movq 0x120(%rsp), %rax+ subq (%rsp), %rax+ movq 0x128(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x130(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x138(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x140(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x148(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ movq 0x150(%rsp), %r12+ sbbq 0x30(%rsp), %r12+ movq 0x158(%rsp), %r13+ sbbq 0x38(%rsp), %r13+ movq 0x160(%rsp), %r14+ sbbq 0x40(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x1a8(%rsp)+ leaq 0x48(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_sqr_p521)+ movq 0x1f8(%rsp), %rdi+ movq 0x168(%rsp), %rax+ subq 0x48(%rsp), %rax+ movq 0x170(%rsp), %rdx+ sbbq 0x50(%rsp), %rdx+ movq 0x178(%rsp), %r8+ sbbq 0x58(%rsp), %r8+ movq 0x180(%rsp), %r9+ sbbq 0x60(%rsp), %r9+ movq 0x188(%rsp), %r10+ sbbq 0x68(%rsp), %r10+ movq 0x190(%rsp), %r11+ sbbq 0x70(%rsp), %r11+ movq 0x198(%rsp), %r12+ sbbq 0x78(%rsp), %r12+ movq 0x1a0(%rsp), %r13+ sbbq 0x80(%rsp), %r13+ movq 0x1a8(%rsp), %r14+ sbbq 0x88(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x90(%rdi)+ sbbq $0x0, %rdx+ movq %rdx, 0x98(%rdi)+ sbbq $0x0, %r8+ movq %r8, 0xa0(%rdi)+ sbbq $0x0, %r9+ movq %r9, 0xa8(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0xb0(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0xb8(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0xc0(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0xc8(%rdi)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0xd0(%rdi)+ leaq 0x90(%rsp), %rdx+ leaq 0x1b0(%rsp), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_mul_p521)+ movq 0x1f8(%rsp), %rdi+ movq 0x118(%rsp), %rbx+ movq 0x110(%rsp), %r15+ shldq $0x2, %r15, %rbx+ movq 0x108(%rsp), %r14+ shldq $0x2, %r14, %r15+ movq 0x100(%rsp), %r13+ shldq $0x2, %r13, %r14+ movq 0xf8(%rsp), %r12+ shldq $0x2, %r12, %r13+ movq 0xf0(%rsp), %r11+ shldq $0x2, %r11, %r12+ movq 0xe8(%rsp), %r10+ shldq $0x2, %r10, %r11+ movq 0xe0(%rsp), %r9+ shldq $0x2, %r9, %r10+ movq 0xd8(%rsp), %r8+ shldq $0x2, %r8, %r9+ shlq $0x2, %r8+ movq 0x1f0(%rsp), %rcx+ xorq $0x1ff, %rcx+ movq 0x1b0(%rsp), %rax+ notq %rax+ addq %rax, %r8+ movq 0x1b8(%rsp), %rax+ notq %rax+ adcq %rax, %r9+ movq 0x1c0(%rsp), %rax+ notq %rax+ adcq %rax, %r10+ movq 0x1c8(%rsp), %rax+ notq %rax+ adcq %rax, %r11+ movq 0x1d0(%rsp), %rax+ notq %rax+ adcq %rax, %r12+ movq 0x1d8(%rsp), %rax+ notq %rax+ adcq %rax, %r13+ movq 0x1e0(%rsp), %rax+ notq %rax+ adcq %rax, %r14+ movq 0x1e8(%rsp), %rax+ notq %rax+ adcq %rax, %r15+ adcq %rcx, %rbx+ movq %r9, %rax+ andq %r10, %rax+ andq %r11, %rax+ andq %r12, %rax+ andq %r13, %rax+ andq %r14, %rax+ andq %r15, %rax+ movq %rbx, %rdx+ shrq $0x9, %rdx+ orq $0xfffffffffffffe00, %rbx+ leaq 0x1(%rdx), %rcx+ addq %r8, %rcx+ movl $0x0, %ecx+ adcq %rcx, %rax+ movq %rbx, %rax+ adcq %rcx, %rax+ adcq %rdx, %r8+ movq %r8, (%rdi)+ adcq %rcx, %r9+ movq %r9, 0x8(%rdi)+ adcq %rcx, %r10+ movq %r10, 0x10(%rdi)+ adcq %rcx, %r11+ movq %r11, 0x18(%rdi)+ adcq %rcx, %r12+ movq %r12, 0x20(%rdi)+ adcq %rcx, %r13+ movq %r13, 0x28(%rdi)+ adcq %rcx, %r14+ movq %r14, 0x30(%rdi)+ adcq %rcx, %r15+ movq %r15, 0x38(%rdi)+ adcq %rcx, %rbx+ andq $0x1ff, %rbx+ movq %rbx, 0x40(%rdi)+ movq 0x1f8(%rsp), %rdi+ movq 0x160(%rsp), %rbx+ xorq $0x1ff, %rbx+ movq 0x158(%rsp), %r15+ notq %r15+ shldq $0x3, %r15, %rbx+ movq 0x150(%rsp), %r14+ notq %r14+ shldq $0x3, %r14, %r15+ movq 0x148(%rsp), %r13+ notq %r13+ shldq $0x3, %r13, %r14+ movq 0x140(%rsp), %r12+ notq %r12+ shldq $0x3, %r12, %r13+ movq 0x138(%rsp), %r11+ notq %r11+ shldq $0x3, %r11, %r12+ movq 0x130(%rsp), %r10+ notq %r10+ shldq $0x3, %r10, %r11+ movq 0x128(%rsp), %r9+ notq %r9+ shldq $0x3, %r9, %r10+ movq 0x120(%rsp), %r8+ notq %r8+ shldq $0x3, %r8, %r9+ shlq $0x3, %r8+ movq $0x3, %rdx+ xorl %eax, %eax+ mulxq 0x168(%rsp), %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ mulxq 0x170(%rsp), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq 0x178(%rsp), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ mulxq 0x180(%rsp), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq 0x188(%rsp), %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ mulxq 0x190(%rsp), %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ mulxq 0x198(%rsp), %rax, %rcx+ adcxq %rax, %r14+ adoxq %rcx, %r15+ mulxq 0x1a0(%rsp), %rax, %rcx+ adcxq %rax, %r15+ adoxq %rcx, %rbx+ mulxq 0x1a8(%rsp), %rax, %rcx+ adcxq %rax, %rbx+ movq %r9, %rax+ andq %r10, %rax+ andq %r11, %rax+ andq %r12, %rax+ andq %r13, %rax+ andq %r14, %rax+ andq %r15, %rax+ movq %rbx, %rdx+ shrq $0x9, %rdx+ orq $0xfffffffffffffe00, %rbx+ leaq 0x1(%rdx), %rcx+ addq %r8, %rcx+ movl $0x0, %ecx+ adcq %rcx, %rax+ movq %rbx, %rax+ adcq %rcx, %rax+ adcq %rdx, %r8+ movq %r8, 0x48(%rdi)+ adcq %rcx, %r9+ movq %r9, 0x50(%rdi)+ adcq %rcx, %r10+ movq %r10, 0x58(%rdi)+ adcq %rcx, %r11+ movq %r11, 0x60(%rdi)+ adcq %rcx, %r12+ movq %r12, 0x68(%rdi)+ adcq %rcx, %r13+ movq %r13, 0x70(%rdi)+ adcq %rcx, %r14+ movq %r14, 0x78(%rdi)+ adcq %rcx, %r15+ movq %r15, 0x80(%rdi)+ adcq %rcx, %rbx+ andq $0x1ff, %rbx+ movq %rbx, 0x88(%rdi)+ CFI_INC_RSP(520)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_jdouble)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_mul_p521)++Lp521_jscalarmul_mul_p521:+ CFI_START+ CFI_DEC_RSP(64)+ movq %rdx, %rcx+ xorl %ebp, %ebp+ movq (%rcx), %rdx+ mulxq (%rsi), %r8, %r9+ movq %r8, (%rsp)+ mulxq 0x8(%rsi), %rbx, %r10+ adcq %rbx, %r9+ mulxq 0x10(%rsi), %rbx, %r11+ adcq %rbx, %r10+ mulxq 0x18(%rsi), %rbx, %r12+ adcq %rbx, %r11+ mulxq 0x20(%rsi), %rbx, %r13+ adcq %rbx, %r12+ mulxq 0x28(%rsi), %rbx, %r14+ adcq %rbx, %r13+ mulxq 0x30(%rsi), %rbx, %r15+ adcq %rbx, %r14+ mulxq 0x38(%rsi), %rbx, %r8+ adcq %rbx, %r15+ adcq %rbp, %r8+ movq 0x8(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ movq %r9, 0x8(%rsp)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x38(%rsi), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ adcq %rbp, %r9+ movq 0x10(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ movq %r10, 0x10(%rsp)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x38(%rsi), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcq %rbp, %r10+ movq 0x18(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ movq %r11, 0x18(%rsp)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x38(%rsi), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ adcq %rbp, %r11+ movq 0x20(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ movq %r12, 0x20(%rsp)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x38(%rsi), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcq %rbp, %r12+ movq 0x28(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ movq %r13, 0x28(%rsp)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x38(%rsi), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ adcq %rbp, %r13+ movq 0x30(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ movq %r14, 0x30(%rsp)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x38(%rsi), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcq %rbp, %r14+ movq 0x38(%rcx), %rdx+ xorl %ebp, %ebp+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %r8+ movq %r15, 0x38(%rsp)+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x38(%rsi), %rax, %r15+ adcxq %rax, %r14+ adoxq %rbp, %r15+ adcq %rbp, %r15+ movq 0x40(%rsi), %rdx+ xorl %ebp, %ebp+ mulxq (%rcx), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x8(%rcx), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x10(%rcx), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x18(%rcx), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x20(%rcx), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x28(%rcx), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x30(%rcx), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x38(%rcx), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbp, %rbx+ adcq %rbx, %rbp+ movq 0x40(%rcx), %rdx+ xorl %eax, %eax+ mulxq (%rsi), %rax, %rbx+ adcxq %rax, %r8+ adoxq %rbx, %r9+ mulxq 0x8(%rsi), %rax, %rbx+ adcxq %rax, %r9+ adoxq %rbx, %r10+ mulxq 0x10(%rsi), %rax, %rbx+ adcxq %rax, %r10+ adoxq %rbx, %r11+ mulxq 0x18(%rsi), %rax, %rbx+ adcxq %rax, %r11+ adoxq %rbx, %r12+ mulxq 0x20(%rsi), %rax, %rbx+ adcxq %rax, %r12+ adoxq %rbx, %r13+ mulxq 0x28(%rsi), %rax, %rbx+ adcxq %rax, %r13+ adoxq %rbx, %r14+ mulxq 0x30(%rsi), %rax, %rbx+ adcxq %rax, %r14+ adoxq %rbx, %r15+ mulxq 0x38(%rsi), %rax, %rbx+ adcxq %rax, %r15+ adoxq %rbx, %rbp+ mulxq 0x40(%rsi), %rax, %rbx+ adcq %rax, %rbp+ movq %r8, %rax+ andq $0x1ff, %rax+ shrdq $0x9, %r9, %r8+ shrdq $0x9, %r10, %r9+ shrdq $0x9, %r11, %r10+ shrdq $0x9, %r12, %r11+ shrdq $0x9, %r13, %r12+ shrdq $0x9, %r14, %r13+ shrdq $0x9, %r15, %r14+ shrdq $0x9, %rbp, %r15+ shrq $0x9, %rbp+ addq %rax, %rbp+ stc+ adcq (%rsp), %r8+ adcq 0x8(%rsp), %r9+ adcq 0x10(%rsp), %r10+ adcq 0x18(%rsp), %r11+ adcq 0x20(%rsp), %r12+ adcq 0x28(%rsp), %r13+ adcq 0x30(%rsp), %r14+ adcq 0x38(%rsp), %r15+ adcq $0xfffffffffffffe00, %rbp+ cmc+ sbbq $0x0, %r8+ movq %r8, (%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x8(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x10(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x18(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x20(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x28(%rdi)+ sbbq $0x0, %r14+ movq %r14, 0x30(%rdi)+ sbbq $0x0, %r15+ movq %r15, 0x38(%rdi)+ sbbq $0x0, %rbp+ andq $0x1ff, %rbp+ movq %rbp, 0x40(%rdi)+ CFI_INC_RSP(64)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_mul_p521)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_sqr_p521)++Lp521_jscalarmul_sqr_p521:+ CFI_START+ CFI_DEC_RSP(64)+ xorl %ebp, %ebp+ movq (%rsi), %rdx+ mulxq 0x8(%rsi), %r9, %rax+ movq %r9, 0x8(%rsp)+ mulxq 0x10(%rsi), %r10, %rcx+ adcxq %rax, %r10+ movq %r10, 0x10(%rsp)+ mulxq 0x18(%rsi), %r11, %rax+ adcxq %rcx, %r11+ mulxq 0x20(%rsi), %r12, %rcx+ adcxq %rax, %r12+ mulxq 0x28(%rsi), %r13, %rax+ adcxq %rcx, %r13+ mulxq 0x30(%rsi), %r14, %rcx+ adcxq %rax, %r14+ mulxq 0x38(%rsi), %r15, %r8+ adcxq %rcx, %r15+ adcxq %rbp, %r8+ xorl %ebp, %ebp+ movq 0x8(%rsi), %rdx+ mulxq 0x10(%rsi), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ movq %r11, 0x18(%rsp)+ mulxq 0x18(%rsi), %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ movq %r12, 0x20(%rsp)+ mulxq 0x20(%rsi), %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ mulxq 0x28(%rsi), %rax, %rcx+ adcxq %rax, %r14+ adoxq %rcx, %r15+ mulxq 0x30(%rsi), %rax, %rcx+ adcxq %rax, %r15+ adoxq %rcx, %r8+ mulxq 0x38(%rsi), %rax, %r9+ adcxq %rax, %r8+ adoxq %rbp, %r9+ movq 0x20(%rsi), %rdx+ mulxq 0x28(%rsi), %rax, %r10+ adcxq %rax, %r9+ adoxq %rbp, %r10+ adcxq %rbp, %r10+ xorl %ebp, %ebp+ movq 0x10(%rsi), %rdx+ mulxq 0x18(%rsi), %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ movq %r13, 0x28(%rsp)+ mulxq 0x20(%rsi), %rax, %rcx+ adcxq %rax, %r14+ adoxq %rcx, %r15+ movq %r14, 0x30(%rsp)+ mulxq 0x28(%rsi), %rax, %rcx+ adcxq %rax, %r15+ adoxq %rcx, %r8+ mulxq 0x30(%rsi), %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ mulxq 0x38(%rsi), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ movq 0x30(%rsi), %rdx+ mulxq 0x20(%rsi), %rax, %r11+ adcxq %rax, %r10+ adoxq %rbp, %r11+ mulxq 0x28(%rsi), %rax, %r12+ adcxq %rax, %r11+ adoxq %rbp, %r12+ adcxq %rbp, %r12+ xorl %ebp, %ebp+ movq 0x18(%rsi), %rdx+ mulxq 0x20(%rsi), %rax, %rcx+ adcxq %rax, %r15+ adoxq %rcx, %r8+ movq %r15, 0x38(%rsp)+ mulxq 0x28(%rsi), %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ mulxq 0x30(%rsi), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq 0x38(%rsi), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ movq 0x38(%rsi), %rdx+ mulxq 0x20(%rsi), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq 0x28(%rsi), %rax, %r13+ adcxq %rax, %r12+ adoxq %rbp, %r13+ mulxq 0x30(%rsi), %rax, %r14+ adcxq %rax, %r13+ adoxq %rbp, %r14+ adcxq %rbp, %r14+ xorl %ebp, %ebp+ movq (%rsi), %rdx+ mulxq %rdx, %rax, %rcx+ movq %rax, (%rsp)+ movq 0x8(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 0x8(%rsp)+ movq 0x10(%rsp), %rax+ movq 0x8(%rsi), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %rax, %rax+ adoxq %rdx, %rax+ movq %rax, 0x10(%rsp)+ movq 0x18(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 0x18(%rsp)+ movq 0x20(%rsp), %rax+ movq 0x10(%rsi), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %rax, %rax+ adoxq %rdx, %rax+ movq %rax, 0x20(%rsp)+ movq 0x28(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 0x28(%rsp)+ movq 0x30(%rsp), %rax+ movq 0x18(%rsi), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %rax, %rax+ adoxq %rdx, %rax+ movq %rax, 0x30(%rsp)+ movq 0x38(%rsp), %rax+ adcxq %rax, %rax+ adoxq %rcx, %rax+ movq %rax, 0x38(%rsp)+ movq 0x20(%rsi), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %r8, %r8+ adoxq %rdx, %r8+ adcxq %r9, %r9+ adoxq %rcx, %r9+ movq 0x28(%rsi), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %r10, %r10+ adoxq %rdx, %r10+ adcxq %r11, %r11+ adoxq %rcx, %r11+ movq 0x30(%rsi), %rdx+ mulxq %rdx, %rdx, %rcx+ adcxq %r12, %r12+ adoxq %rdx, %r12+ adcxq %r13, %r13+ adoxq %rcx, %r13+ movq 0x38(%rsi), %rdx+ mulxq %rdx, %rdx, %r15+ adcxq %r14, %r14+ adoxq %rdx, %r14+ adcxq %rbp, %r15+ adoxq %rbp, %r15+ movq 0x40(%rsi), %rdx+ movq %rdx, %rbp+ imulq %rbp, %rbp+ addq %rdx, %rdx+ mulxq (%rsi), %rax, %rcx+ adcxq %rax, %r8+ adoxq %rcx, %r9+ mulxq 0x8(%rsi), %rax, %rcx+ adcxq %rax, %r9+ adoxq %rcx, %r10+ mulxq 0x10(%rsi), %rax, %rcx+ adcxq %rax, %r10+ adoxq %rcx, %r11+ mulxq 0x18(%rsi), %rax, %rcx+ adcxq %rax, %r11+ adoxq %rcx, %r12+ mulxq 0x20(%rsi), %rax, %rcx+ adcxq %rax, %r12+ adoxq %rcx, %r13+ mulxq 0x28(%rsi), %rax, %rcx+ adcxq %rax, %r13+ adoxq %rcx, %r14+ mulxq 0x30(%rsi), %rax, %rcx+ adcxq %rax, %r14+ adoxq %rcx, %r15+ mulxq 0x38(%rsi), %rax, %rcx+ adcxq %rax, %r15+ adoxq %rcx, %rbp+ adcq $0x0, %rbp+ movq %r8, %rax+ andq $0x1ff, %rax+ shrdq $0x9, %r9, %r8+ shrdq $0x9, %r10, %r9+ shrdq $0x9, %r11, %r10+ shrdq $0x9, %r12, %r11+ shrdq $0x9, %r13, %r12+ shrdq $0x9, %r14, %r13+ shrdq $0x9, %r15, %r14+ shrdq $0x9, %rbp, %r15+ shrq $0x9, %rbp+ addq %rax, %rbp+ stc+ adcq (%rsp), %r8+ adcq 0x8(%rsp), %r9+ adcq 0x10(%rsp), %r10+ adcq 0x18(%rsp), %r11+ adcq 0x20(%rsp), %r12+ adcq 0x28(%rsp), %r13+ adcq 0x30(%rsp), %r14+ adcq 0x38(%rsp), %r15+ adcq $0xfffffffffffffe00, %rbp+ cmc+ sbbq $0x0, %r8+ movq %r8, (%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x8(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x10(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x18(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x20(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x28(%rdi)+ sbbq $0x0, %r14+ movq %r14, 0x30(%rdi)+ sbbq $0x0, %r15+ movq %r15, 0x38(%rdi)+ sbbq $0x0, %rbp+ andq $0x1ff, %rbp+ movq %rbp, 0x40(%rdi)+ CFI_INC_RSP(64)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_sqr_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
+ cbits/s2n/x86_att/p521_jscalarmul_alt.S view
@@ -0,0 +1,2850 @@+// Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.+// SPDX-License-Identifier: Apache-2.0 OR ISC OR MIT-0++// ----------------------------------------------------------------------------+// Jacobian form scalar multiplication for P-521+// Input scalar[9], point[27]; output res[27]+//+// extern void p521_jscalarmul_alt+// (uint64_t res[static 27],+// const uint64_t scalar[static 9],+// const uint64_t point[static 27]);+//+// This function is a variant of its affine point version p521_scalarmul.+// Here, input and output points are assumed to be in Jacobian form with+// a triple (x,y,z) representing the affine point (x/z^2,y/z^3) when+// z is nonzero or the point at infinity (group identity) if z = 0.+//+// Given scalar = n and point = P, assumed to be on the NIST elliptic+// curve P-521, returns a representation of n * P. If the result is the+// point at infinity (either because the input point was or because the+// scalar was a multiple of p_521) then the output is guaranteed to+// represent the point at infinity, i.e. to have its z coordinate zero.+//+// Standard x86-64 ABI: RDI = res, RSI = scalar, RDX = point+// Microsoft x64 ABI: RCX = res, RDX = scalar, R8 = point+// ----------------------------------------------------------------------------++#include "_internal_s2n_bignum_x86_att.h"+++ S2N_BN_SYM_VISIBILITY_DIRECTIVE(p521_jscalarmul_alt)+ S2N_BN_FUNCTION_TYPE_DIRECTIVE(p521_jscalarmul_alt)+ S2N_BN_SYM_PRIVACY_DIRECTIVE(p521_jscalarmul_alt)+++ .text+ .balign 32++// Size of individual field elements++#define NUMSIZE 72+#define JACSIZE (3*NUMSIZE)++// Intermediate variables on the stack.+// The table is 16 entries, each of size JACSIZE = 3 * NUMSIZE+// Uppercase syntactic variants make x86_att version simpler to generate.++#define SCALARB (0*NUMSIZE)+#define scalarb (0*NUMSIZE)(%rsp)+#define ACC (1*NUMSIZE)+#define acc (1*NUMSIZE)(%rsp)+#define TABENT (4*NUMSIZE)+#define tabent (4*NUMSIZE)(%rsp)++#define TAB (7*NUMSIZE)+#define tab (7*NUMSIZE)(%rsp)++#define res (55*NUMSIZE)(%rsp)++#define NSPACE 56*NUMSIZE++// Avoid using .rep for the sake of the BoringSSL/AWS-LC delocator,+// which doesn't accept repetitions, assembler macros etc.++#define selectblock(I,C) \+ cmpq $I, %rdi ; \+ cmovzq TAB+JACSIZE*(I-1)+C*NUMSIZE(%rsp), %rax ; \+ cmovzq TAB+JACSIZE*(I-1)+8+C*NUMSIZE(%rsp), %rbx ; \+ cmovzq TAB+JACSIZE*(I-1)+16+C*NUMSIZE(%rsp), %rcx ; \+ cmovzq TAB+JACSIZE*(I-1)+24+C*NUMSIZE(%rsp), %rdx ; \+ cmovzq TAB+JACSIZE*(I-1)+32+C*NUMSIZE(%rsp), %r8 ; \+ cmovzq TAB+JACSIZE*(I-1)+40+C*NUMSIZE(%rsp), %r9 ; \+ cmovzq TAB+JACSIZE*(I-1)+48+C*NUMSIZE(%rsp), %r10 ; \+ cmovzq TAB+JACSIZE*(I-1)+56+C*NUMSIZE(%rsp), %r11 ; \+ cmovzq TAB+JACSIZE*(I-1)+64+C*NUMSIZE(%rsp), %r12++S2N_BN_SYMBOL(p521_jscalarmul_alt):+ CFI_START+ _CET_ENDBR++// The Windows version literally calls the standard ABI version.+// This simplifies the proofs since subroutine offsets are fixed.++#if WINDOWS_ABI+ CFI_PUSH(%rdi)+ CFI_PUSH(%rsi)+ movq %rcx, %rdi+ movq %rdx, %rsi+ movq %r8, %rdx+ CFI_CALL(Lp521_jscalarmul_alt_standard)+ CFI_POP(%rsi)+ CFI_POP(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(p521_jscalarmul_alt)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_standard)++Lp521_jscalarmul_alt_standard:+ CFI_START+#endif++// Real start of the standard ABI code.++ CFI_PUSH(%r15)+ CFI_PUSH(%r14)+ CFI_PUSH(%r13)+ CFI_PUSH(%r12)+ CFI_PUSH(%rbp)+ CFI_PUSH(%rbx)++ CFI_DEC_RSP(NSPACE)++// Preserve the "res" input argument; others get processed early.++ movq %rdi, res++// Reduce the input scalar mod n_521 and store it to "scalarb".++ movq %rdx, %rbx+ leaq SCALARB(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_bignum_mod_n521_9)++// Set the tab[0] table entry to the input point = 1 * P, but also+// reduce all coordinates modulo p. In principle we assume reduction+// as a precondition, but this reduces the scope for surprise, e.g.+// making sure that any input with z = 0 is treated as zero, even+// if the other coordinates are not in fact reduced.++ leaq TAB(%rsp), %rdi+ movq %rbx, %rsi+ CFI_CALL(Lp521_jscalarmul_alt_bignum_mod_p521_9)++ leaq TAB+NUMSIZE(%rsp), %rdi+ leaq NUMSIZE(%rbx), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_bignum_mod_p521_9)++ leaq TAB+2*NUMSIZE(%rsp), %rdi+ leaq 2*NUMSIZE(%rbx), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_bignum_mod_p521_9)++// If bit 520 of the scalar is set, then negate the scalar mod n_521,+// i.e. do scalar |-> n_521 - scalar, and also the point to compensate+// by negating its y coordinate. This further step is not needed by+// the indexing scheme (the top window is only a couple of bits either+// way), but is convenient to exclude a problem with the specific value+// scalar = n_521 - 18, where the last Jacobian addition is of the form+// (n_521 - 9) * P + -(9 * P) and hence is a degenerate doubling case.++ xorl %eax, %eax+ notq %rax+ movq $0xbb6fb71e91386409, %r8+ subq SCALARB(%rsp), %r8+ movq $0x3bb5c9b8899c47ae, %r9+ sbbq SCALARB+8(%rsp), %r9+ movq $0x7fcc0148f709a5d0, %r10+ sbbq SCALARB+16(%rsp), %r10+ movq $0x51868783bf2f966b, %r11+ sbbq SCALARB+24(%rsp), %r11+ leaq -5(%rax), %r12+ sbbq SCALARB+32(%rsp), %r12+ movq %rax, %r13+ sbbq SCALARB+40(%rsp), %r13+ movq %rax, %r14+ sbbq SCALARB+48(%rsp), %r14+ movq %rax, %r15+ sbbq SCALARB+56(%rsp), %r15+ movq $0x1ff, %rax+ movq SCALARB+64(%rsp), %rcx+ sbbq %rcx, %rax++ btq $8, %rcx+ sbbq %rcx, %rcx++ cmovncq SCALARB(%rsp), %r8+ cmovncq SCALARB+8(%rsp), %r9+ cmovncq SCALARB+16(%rsp), %r10+ cmovncq SCALARB+24(%rsp), %r11+ cmovncq SCALARB+32(%rsp), %r12+ cmovncq SCALARB+40(%rsp), %r13+ cmovncq SCALARB+48(%rsp), %r14+ cmovncq SCALARB+56(%rsp), %r15+ cmovncq SCALARB+64(%rsp), %rax++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)+ movq %r14, SCALARB+48(%rsp)+ movq %r15, SCALARB+56(%rsp)+ movq %rax, SCALARB+64(%rsp)++ movq TAB+NUMSIZE(%rsp), %r8+ movq TAB+NUMSIZE+8(%rsp), %r9+ movq TAB+NUMSIZE+16(%rsp), %r10+ movq TAB+NUMSIZE+24(%rsp), %r11+ movq TAB+NUMSIZE+32(%rsp), %r12+ movq TAB+NUMSIZE+40(%rsp), %r13+ movq TAB+NUMSIZE+48(%rsp), %r14+ movq TAB+NUMSIZE+56(%rsp), %r15+ movq TAB+NUMSIZE+64(%rsp), %rax++ movq %r8, %rbx+ movq %r12, %rbp+ orq %r9, %rbx+ orq %r13, %rbp+ orq %r10, %rbx+ orq %r14, %rbp+ orq %r11, %rbx+ orq %r15, %rbp+ orq %rbp, %rbx+ orq %rax, %rbx+ cmovzq %rbx, %rcx++ xorq %rcx, %r8+ xorq %rcx, %r9+ xorq %rcx, %r10+ xorq %rcx, %r11+ xorq %rcx, %r12+ xorq %rcx, %r13+ xorq %rcx, %r14+ xorq %rcx, %r15+ andq $0x1FF, %rcx+ xorq %rcx, %rax++ movq %r8, TAB+NUMSIZE(%rsp)+ movq %r9, TAB+NUMSIZE+8(%rsp)+ movq %r10, TAB+NUMSIZE+16(%rsp)+ movq %r11, TAB+NUMSIZE+24(%rsp)+ movq %r12, TAB+NUMSIZE+32(%rsp)+ movq %r13, TAB+NUMSIZE+40(%rsp)+ movq %r14, TAB+NUMSIZE+48(%rsp)+ movq %r15, TAB+NUMSIZE+56(%rsp)+ movq %rax, TAB+NUMSIZE+64(%rsp)++// Compute and record tab[1] = 2 * p, ..., tab[15] = 16 * P++ leaq TAB+JACSIZE*1(%rsp), %rdi+ leaq TAB(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq TAB+JACSIZE*2(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ leaq TAB+JACSIZE*3(%rsp), %rdi+ leaq TAB+JACSIZE*1(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq TAB+JACSIZE*4(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ leaq TAB+JACSIZE*5(%rsp), %rdi+ leaq TAB+JACSIZE*2(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq TAB+JACSIZE*6(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ leaq TAB+JACSIZE*7(%rsp), %rdi+ leaq TAB+JACSIZE*3(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq TAB+JACSIZE*8(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ leaq TAB+JACSIZE*9(%rsp), %rdi+ leaq TAB+JACSIZE*4(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq TAB+JACSIZE*10(%rsp), %rdi+ leaq TAB+JACSIZE*9(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ leaq TAB+JACSIZE*11(%rsp), %rdi+ leaq TAB+JACSIZE*5(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq TAB+JACSIZE*12(%rsp), %rdi+ leaq TAB+JACSIZE*11(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ leaq TAB+JACSIZE*13(%rsp), %rdi+ leaq TAB+JACSIZE*6(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq TAB+JACSIZE*14(%rsp), %rdi+ leaq TAB+JACSIZE*13(%rsp), %rsi+ leaq TAB(%rsp), %rdx+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ leaq TAB+JACSIZE*15(%rsp), %rdi+ leaq TAB+JACSIZE*7(%rsp), %rsi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++// Add the recoding constant sum_i(16 * 32^i) to the scalar to allow signed+// digits. The digits of the constant, in lowest-to-highest order, are as+// follows; they are generated dynamically to use fewer large constant loads.+//+// 0x0842108421084210 %rax+// 0x1084210842108421 %rbx+// 0x2108421084210842 %rbx<<1+// 0x4210842108421084 %rbx<<2+// 0x8421084210842108 %rbx<<3+// 0x0842108421084210 %rax+// 0x1084210842108421 %rbx+// 0x2108421084210842 %rbx<<1+// 0x0000000000000084++ movq $0x1084210842108421, %rax+ movq %rax, %rbx+ shrq $1, %rax+ movq SCALARB(%rsp), %r8+ addq %rax, %r8+ movq SCALARB+8(%rsp), %r9+ adcq %rbx, %r9+ leaq (%rbx,%rbx), %rcx+ movq SCALARB+16(%rsp), %r10+ adcq %rcx, %r10+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+24(%rsp), %r11+ adcq %rcx, %r11+ leaq (%rcx,%rcx), %rcx+ movq SCALARB+32(%rsp), %r12+ adcq %rcx, %r12+ movq SCALARB+40(%rsp), %r13+ adcq %rax, %r13+ movq SCALARB+48(%rsp), %r14+ adcq %rbx, %r14+ movq SCALARB+56(%rsp), %r15+ leaq (%rbx,%rbx), %rcx+ adcq %rcx, %r15+ movq SCALARB+64(%rsp), %rax+ adcq $0x84, %rax++// Because of the initial reduction the top bitfield (>= bits 520) is <= 1,+// i.e. just a single bit. Record that in %rdi, then shift the whole+// scalar left 56 bits to align the top of the next bitfield with the MSB+// (bits 571..575).++ movq %rax, %rdi+ shrq $8, %rdi+ shldq $56, %r15, %rax+ shldq $56, %r14, %r15+ shldq $56, %r13, %r14+ shldq $56, %r12, %r13+ shldq $56, %r11, %r12+ shldq $56, %r10, %r11+ shldq $56, %r9, %r10+ shldq $56, %r8, %r9+ shlq $56, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)+ movq %r14, SCALARB+48(%rsp)+ movq %r15, SCALARB+56(%rsp)+ movq %rax, SCALARB+64(%rsp)++// According to the top bit, initialize the accumulator to P or 0. This top+// digit, uniquely, is not recoded so there is no sign adjustment to make.+// We only really need to adjust the z coordinate to zero, but do all three.++ xorl %ecx, %ecx+ testq %rdi, %rdi++ movq TAB(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC(%rsp)+ movq TAB+8(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+8(%rsp)+ movq TAB+16(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+16(%rsp)+ movq TAB+24(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+24(%rsp)+ movq TAB+32(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+32(%rsp)+ movq TAB+40(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+40(%rsp)+ movq TAB+48(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+48(%rsp)+ movq TAB+56(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+56(%rsp)+ movq TAB+64(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+64(%rsp)+ movq TAB+72(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+72(%rsp)+ movq TAB+80(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+80(%rsp)+ movq TAB+88(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+88(%rsp)+ movq TAB+96(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+96(%rsp)+ movq TAB+104(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+104(%rsp)+ movq TAB+112(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+112(%rsp)+ movq TAB+120(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+120(%rsp)+ movq TAB+128(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+128(%rsp)+ movq TAB+136(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+136(%rsp)+ movq TAB+144(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+144(%rsp)+ movq TAB+152(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+152(%rsp)+ movq TAB+160(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+160(%rsp)+ movq TAB+168(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+168(%rsp)+ movq TAB+176(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+176(%rsp)+ movq TAB+184(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+184(%rsp)+ movq TAB+192(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+192(%rsp)+ movq TAB+200(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+200(%rsp)+ movq TAB+208(%rsp), %rax+ cmovzq %rcx, %rax+ movq %rax, ACC+208(%rsp)++// Main loop over size-5 bitfields: double 5 times then add signed digit+// At each stage we shift the scalar left by 5 bits so we can simply pick+// the top 5 bits as the bitfield, saving some fiddle over indexing.++ movl $520, %ebp++Lp521_jscalarmul_alt_mainloop:+ subq $5, %rbp++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_jdouble)++// Choose the bitfield and adjust it to sign and magnitude++ movq SCALARB(%rsp), %r8+ movq SCALARB+8(%rsp), %r9+ movq SCALARB+16(%rsp), %r10+ movq SCALARB+24(%rsp), %r11+ movq SCALARB+32(%rsp), %r12+ movq SCALARB+40(%rsp), %r13+ movq SCALARB+48(%rsp), %r14+ movq SCALARB+56(%rsp), %r15+ movq SCALARB+64(%rsp), %rax+++ movq %rax, %rdi+ shrq $59, %rdi++ shldq $5, %r15, %rax+ shldq $5, %r14, %r15+ shldq $5, %r13, %r14+ shldq $5, %r12, %r13+ shldq $5, %r11, %r12+ shldq $5, %r10, %r11+ shldq $5, %r9, %r10+ shldq $5, %r8, %r9+ shlq $5, %r8++ movq %r8, SCALARB(%rsp)+ movq %r9, SCALARB+8(%rsp)+ movq %r10, SCALARB+16(%rsp)+ movq %r11, SCALARB+24(%rsp)+ movq %r12, SCALARB+32(%rsp)+ movq %r13, SCALARB+40(%rsp)+ movq %r14, SCALARB+48(%rsp)+ movq %r15, SCALARB+56(%rsp)+ movq %rax, SCALARB+64(%rsp)++ subq $16, %rdi+ sbbq %rsi, %rsi // %rsi = sign of digit (-1 = negative)+ xorq %rsi, %rdi+ subq %rsi, %rdi // %rdi = absolute value of digit++// Conditionally select the table entry tab[i-1] = i * P in constant time+// Again, this is done in separate sweeps per coordinate, doing y last.++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ selectblock(1,0)+ selectblock(2,0)+ selectblock(3,0)+ selectblock(4,0)+ selectblock(5,0)+ selectblock(6,0)+ selectblock(7,0)+ selectblock(8,0)+ selectblock(9,0)+ selectblock(10,0)+ selectblock(11,0)+ selectblock(12,0)+ selectblock(13,0)+ selectblock(14,0)+ selectblock(15,0)+ selectblock(16,0)+ movq %rax, TABENT(%rsp)+ movq %rbx, TABENT+8(%rsp)+ movq %rcx, TABENT+16(%rsp)+ movq %rdx, TABENT+24(%rsp)+ movq %r8, TABENT+32(%rsp)+ movq %r9, TABENT+40(%rsp)+ movq %r10, TABENT+48(%rsp)+ movq %r11, TABENT+56(%rsp)+ movq %r12, TABENT+64(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ selectblock(1,2)+ selectblock(2,2)+ selectblock(3,2)+ selectblock(4,2)+ selectblock(5,2)+ selectblock(6,2)+ selectblock(7,2)+ selectblock(8,2)+ selectblock(9,2)+ selectblock(10,2)+ selectblock(11,2)+ selectblock(12,2)+ selectblock(13,2)+ selectblock(14,2)+ selectblock(15,2)+ selectblock(16,2)+ movq %rax, TABENT+2*NUMSIZE(%rsp)+ movq %rbx, TABENT+2*NUMSIZE+8(%rsp)+ movq %rcx, TABENT+2*NUMSIZE+16(%rsp)+ movq %rdx, TABENT+2*NUMSIZE+24(%rsp)+ movq %r8, TABENT+2*NUMSIZE+32(%rsp)+ movq %r9, TABENT+2*NUMSIZE+40(%rsp)+ movq %r10, TABENT+2*NUMSIZE+48(%rsp)+ movq %r11, TABENT+2*NUMSIZE+56(%rsp)+ movq %r12, TABENT+2*NUMSIZE+64(%rsp)++ xorl %eax, %eax+ xorl %ebx, %ebx+ xorl %ecx, %ecx+ xorl %edx, %edx+ xorl %r8d, %r8d+ xorl %r9d, %r9d+ xorl %r10d, %r10d+ xorl %r11d, %r11d+ xorl %r12d, %r12d+ selectblock(1,1)+ selectblock(2,1)+ selectblock(3,1)+ selectblock(4,1)+ selectblock(5,1)+ selectblock(6,1)+ selectblock(7,1)+ selectblock(8,1)+ selectblock(9,1)+ selectblock(10,1)+ selectblock(11,1)+ selectblock(12,1)+ selectblock(13,1)+ selectblock(14,1)+ selectblock(15,1)+ selectblock(16,1)++// Store it to "tabent" with the y coordinate optionally negated.+// This is done carefully to give coordinates < p_521 even in+// the degenerate case y = 0 (when z = 0 for points on the curve).++ movq %rax, %r13+ orq %rbx, %r13+ movq %rcx, %r14+ orq %rdx, %r14+ movq %r8, %r15+ orq %r9, %r15+ movq %r10, %rdi+ orq %r11, %rdi+ orq %r14, %r13+ orq %rdi, %r15+ orq %r12, %r15+ orq %r15, %r13+ cmovzq %r13, %rsi++ xorq %rsi, %rax+ xorq %rsi, %rbx+ xorq %rsi, %rcx+ xorq %rsi, %rdx+ xorq %rsi, %r8+ xorq %rsi, %r9+ xorq %rsi, %r10+ xorq %rsi, %r11+ andq $0x1FF, %rsi+ xorq %rsi, %r12++ movq %rax, TABENT+NUMSIZE(%rsp)+ movq %rbx, TABENT+NUMSIZE+8(%rsp)+ movq %rcx, TABENT+NUMSIZE+16(%rsp)+ movq %rdx, TABENT+NUMSIZE+24(%rsp)+ movq %r8, TABENT+NUMSIZE+32(%rsp)+ movq %r9, TABENT+NUMSIZE+40(%rsp)+ movq %r10, TABENT+NUMSIZE+48(%rsp)+ movq %r11, TABENT+NUMSIZE+56(%rsp)+ movq %r12, TABENT+NUMSIZE+64(%rsp)++// Add to the accumulator++ leaq TABENT(%rsp), %rdx+ leaq ACC(%rsp), %rsi+ leaq ACC(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_jadd)++ testq %rbp, %rbp+ jne Lp521_jscalarmul_alt_mainloop++// That's the end of the main loop, and we just need to copy the+// result in "acc" to the output.++ movq res, %rdi+ movq ACC(%rsp), %rax+ movq %rax, (%rdi)+ movq ACC+8(%rsp), %rax+ movq %rax, 8(%rdi)+ movq ACC+16(%rsp), %rax+ movq %rax, 16(%rdi)+ movq ACC+24(%rsp), %rax+ movq %rax, 24(%rdi)+ movq ACC+32(%rsp), %rax+ movq %rax, 32(%rdi)+ movq ACC+40(%rsp), %rax+ movq %rax, 40(%rdi)+ movq ACC+48(%rsp), %rax+ movq %rax, 48(%rdi)+ movq ACC+56(%rsp), %rax+ movq %rax, 56(%rdi)+ movq ACC+64(%rsp), %rax+ movq %rax, 64(%rdi)+ movq ACC+72(%rsp), %rax+ movq %rax, 72(%rdi)+ movq ACC+80(%rsp), %rax+ movq %rax, 80(%rdi)+ movq ACC+88(%rsp), %rax+ movq %rax, 88(%rdi)+ movq ACC+96(%rsp), %rax+ movq %rax, 96(%rdi)+ movq ACC+104(%rsp), %rax+ movq %rax, 104(%rdi)+ movq ACC+112(%rsp), %rax+ movq %rax, 112(%rdi)+ movq ACC+120(%rsp), %rax+ movq %rax, 120(%rdi)+ movq ACC+128(%rsp), %rax+ movq %rax, 128(%rdi)+ movq ACC+136(%rsp), %rax+ movq %rax, 136(%rdi)+ movq ACC+144(%rsp), %rax+ movq %rax, 144(%rdi)+ movq ACC+152(%rsp), %rax+ movq %rax, 152(%rdi)+ movq ACC+160(%rsp), %rax+ movq %rax, 160(%rdi)+ movq ACC+168(%rsp), %rax+ movq %rax, 168(%rdi)+ movq ACC+176(%rsp), %rax+ movq %rax, 176(%rdi)+ movq ACC+184(%rsp), %rax+ movq %rax, 184(%rdi)+ movq ACC+192(%rsp), %rax+ movq %rax, 192(%rdi)+ movq ACC+200(%rsp), %rax+ movq %rax, 200(%rdi)+ movq ACC+208(%rsp), %rax+ movq %rax, 208(%rdi)++// Restore stack and registers and return++ CFI_INC_RSP(NSPACE)+ CFI_POP(%rbx)+ CFI_POP(%rbp)+ CFI_POP(%r12)+ CFI_POP(%r13)+ CFI_POP(%r14)+ CFI_POP(%r15)+ CFI_RET++#if WINDOWS_ABI+S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_standard)+#else+S2N_BN_SIZE_DIRECTIVE(p521_jscalarmul_alt)+#endif++// Local copies of subroutines, complete clones at the moment++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_p521_9)++Lp521_jscalarmul_alt_bignum_mod_p521_9:+ CFI_START+ CFI_PUSH(%rbx)+ movq 0x40(%rsi), %rax+ movl $0x1ff, %edx+ andq %rax, %rdx+ shrq $0x9, %rax+ stc+ adcq (%rsi), %rax+ movq 0x8(%rsi), %rcx+ adcq $0x0, %rcx+ movq 0x10(%rsi), %r8+ adcq $0x0, %r8+ movq 0x18(%rsi), %r9+ adcq $0x0, %r9+ movq 0x20(%rsi), %r10+ adcq $0x0, %r10+ movq 0x28(%rsi), %r11+ adcq $0x0, %r11+ movq 0x30(%rsi), %rbx+ adcq $0x0, %rbx+ movq 0x38(%rsi), %rsi+ adcq $0x0, %rsi+ adcq $0x0, %rdx+ cmpq $0x200, %rdx+ sbbq $0x0, %rax+ movq %rax, (%rdi)+ sbbq $0x0, %rcx+ movq %rcx, 0x8(%rdi)+ sbbq $0x0, %r8+ movq %r8, 0x10(%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rdi)+ sbbq $0x0, %rbx+ movq %rbx, 0x30(%rdi)+ sbbq $0x0, %rsi+ movq %rsi, 0x38(%rdi)+ sbbq $0x0, %rdx+ andq $0x1ff, %rdx+ movq %rdx, 0x40(%rdi)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_p521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_n521_9)++Lp521_jscalarmul_alt_bignum_mod_n521_9:+ CFI_START+ movq 0x40(%rsi), %rcx+ movq $0xfffffffffffffe00, %rax+ orq %rcx, %rax+ movq %rax, 0x40(%rdi)+ shrq $0x9, %rcx+ addq $0x1, %rcx+ movq $0x449048e16ec79bf7, %rax+ mulq %rcx+ movq %rax, %r8+ movq %rdx, %r9+ movq $0xc44a36477663b851, %rax+ mulq %rcx+ xorq %r10, %r10+ addq %rax, %r9+ adcq %rdx, %r10+ movq $0x8033feb708f65a2f, %rax+ mulq %rcx+ xorq %r11, %r11+ addq %rax, %r10+ adcq %rdx, %r11+ movq $0xae79787c40d06994, %rax+ mulq %rcx+ imulq $0x5, %rcx, %rcx+ addq %rax, %r11+ adcq %rdx, %rcx+ sbbq %rdx, %rdx+ negq %rdx+ xorl %eax, %eax+ addq (%rsi), %r8+ movq %r8, (%rdi)+ adcq 0x8(%rsi), %r9+ movq %r9, 0x8(%rdi)+ adcq 0x10(%rsi), %r10+ movq %r10, 0x10(%rdi)+ adcq 0x18(%rsi), %r11+ movq %r11, 0x18(%rdi)+ adcq 0x20(%rsi), %rcx+ movq %rcx, 0x20(%rdi)+ adcq 0x28(%rsi), %rdx+ movq %rdx, 0x28(%rdi)+ movq 0x30(%rsi), %rdx+ adcq %rax, %rdx+ movq %rdx, 0x30(%rdi)+ movq 0x38(%rsi), %rdx+ adcq %rax, %rdx+ movq %rdx, 0x38(%rdi)+ movq 0x40(%rdi), %rcx+ adcq %rax, %rcx+ cmc+ sbbq %rdx, %rdx+ movq $0x449048e16ec79bf7, %r8+ andq %rdx, %r8+ movq $0xc44a36477663b851, %r9+ andq %rdx, %r9+ movq $0x8033feb708f65a2f, %r10+ andq %rdx, %r10+ movq $0xae79787c40d06994, %r11+ andq %rdx, %r11+ andq $0x5, %rdx+ subq %r8, (%rdi)+ sbbq %r9, 0x8(%rdi)+ sbbq %r10, 0x10(%rdi)+ sbbq %r11, 0x18(%rdi)+ sbbq %rdx, 0x20(%rdi)+ sbbq %rax, 0x28(%rdi)+ sbbq %rax, 0x30(%rdi)+ sbbq %rax, 0x38(%rdi)+ sbbl %eax, %ecx+ andl $0x1ff, %ecx+ movq %rcx, 0x40(%rdi)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_bignum_mod_n521_9)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_jadd)++Lp521_jscalarmul_alt_jadd:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(528)+ movq %rdi, 0x1f8(%rsp)+ movq %rsi, 0x200(%rsp)+ movq %rdx, 0x208(%rsp)+ movq 0x200(%rsp), %rsi+ leaq 0x90(%rsi), %rsi+ leaq (%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ movq 0x208(%rsp), %rdi+ leaq 0x90(%rdi), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ movq 0x200(%rsp), %rsi+ movq 0x208(%rsp), %rdi+ leaq 0x48(%rsi), %rdx+ leaq 0x90(%rdi), %rsi+ leaq 0x1b0(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x200(%rsp), %rsi+ movq 0x208(%rsp), %rdi+ leaq 0x48(%rdi), %rdx+ leaq 0x90(%rsi), %rsi+ leaq 0x48(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x208(%rsp), %rdi+ leaq (%rdi), %rdx+ leaq (%rsp), %rsi+ leaq 0x90(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x200(%rsp), %rsi+ leaq (%rsi), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ leaq 0x48(%rsp), %rdx+ leaq (%rsp), %rsi+ leaq 0x48(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ leaq 0x1b0(%rsp), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x1b0(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x90(%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x98(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0xa0(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0xa8(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0xb0(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0xb8(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ movq 0xc0(%rsp), %r12+ sbbq 0x150(%rsp), %r12+ movq 0xc8(%rsp), %r13+ sbbq 0x158(%rsp), %r13+ movq 0xd0(%rsp), %r14+ sbbq 0x160(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x1a8(%rsp)+ movq 0x48(%rsp), %rax+ subq 0x1b0(%rsp), %rax+ movq 0x50(%rsp), %rdx+ sbbq 0x1b8(%rsp), %rdx+ movq 0x58(%rsp), %r8+ sbbq 0x1c0(%rsp), %r8+ movq 0x60(%rsp), %r9+ sbbq 0x1c8(%rsp), %r9+ movq 0x68(%rsp), %r10+ sbbq 0x1d0(%rsp), %r10+ movq 0x70(%rsp), %r11+ sbbq 0x1d8(%rsp), %r11+ movq 0x78(%rsp), %r12+ sbbq 0x1e0(%rsp), %r12+ movq 0x80(%rsp), %r13+ sbbq 0x1e8(%rsp), %r13+ movq 0x88(%rsp), %r14+ sbbq 0x1f0(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x48(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x50(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x58(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x60(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x68(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x70(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x78(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x80(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x88(%rsp)+ leaq 0x168(%rsp), %rsi+ leaq 0xd8(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ leaq 0x48(%rsp), %rsi+ leaq (%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ leaq 0x120(%rsp), %rdx+ leaq 0xd8(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ leaq 0x90(%rsp), %rdx+ leaq 0xd8(%rsp), %rsi+ leaq 0x90(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq (%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ movq 0x30(%rsp), %r12+ sbbq 0x150(%rsp), %r12+ movq 0x38(%rsp), %r13+ sbbq 0x158(%rsp), %r13+ movq 0x40(%rsp), %r14+ sbbq 0x160(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, (%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x30(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x38(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x40(%rsp)+ movq 0x90(%rsp), %rax+ subq 0x120(%rsp), %rax+ movq 0x98(%rsp), %rdx+ sbbq 0x128(%rsp), %rdx+ movq 0xa0(%rsp), %r8+ sbbq 0x130(%rsp), %r8+ movq 0xa8(%rsp), %r9+ sbbq 0x138(%rsp), %r9+ movq 0xb0(%rsp), %r10+ sbbq 0x140(%rsp), %r10+ movq 0xb8(%rsp), %r11+ sbbq 0x148(%rsp), %r11+ movq 0xc0(%rsp), %r12+ sbbq 0x150(%rsp), %r12+ movq 0xc8(%rsp), %r13+ sbbq 0x158(%rsp), %r13+ movq 0xd0(%rsp), %r14+ sbbq 0x160(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0xd8(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0xe0(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0xe8(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0xf0(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0xf8(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x100(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x108(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x110(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x118(%rsp)+ movq 0x200(%rsp), %rsi+ leaq 0x90(%rsi), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq (%rsp), %rax+ subq 0x90(%rsp), %rax+ movq 0x8(%rsp), %rdx+ sbbq 0x98(%rsp), %rdx+ movq 0x10(%rsp), %r8+ sbbq 0xa0(%rsp), %r8+ movq 0x18(%rsp), %r9+ sbbq 0xa8(%rsp), %r9+ movq 0x20(%rsp), %r10+ sbbq 0xb0(%rsp), %r10+ movq 0x28(%rsp), %r11+ sbbq 0xb8(%rsp), %r11+ movq 0x30(%rsp), %r12+ sbbq 0xc0(%rsp), %r12+ movq 0x38(%rsp), %r13+ sbbq 0xc8(%rsp), %r13+ movq 0x40(%rsp), %r14+ sbbq 0xd0(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, (%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x8(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x10(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x18(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x20(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x28(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x30(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x38(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x40(%rsp)+ movq 0x120(%rsp), %rax+ subq (%rsp), %rax+ movq 0x128(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x130(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x138(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x140(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x148(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ movq 0x150(%rsp), %r12+ sbbq 0x30(%rsp), %r12+ movq 0x158(%rsp), %r13+ sbbq 0x38(%rsp), %r13+ movq 0x160(%rsp), %r14+ sbbq 0x40(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x120(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x128(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x130(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x138(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x140(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x148(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x150(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x158(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x160(%rsp)+ leaq 0x1b0(%rsp), %rdx+ leaq 0xd8(%rsp), %rsi+ leaq 0xd8(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x208(%rsp), %rdi+ leaq 0x90(%rdi), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ leaq 0x120(%rsp), %rdx+ leaq 0x48(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x120(%rsp), %rax+ subq 0xd8(%rsp), %rax+ movq 0x128(%rsp), %rdx+ sbbq 0xe0(%rsp), %rdx+ movq 0x130(%rsp), %r8+ sbbq 0xe8(%rsp), %r8+ movq 0x138(%rsp), %r9+ sbbq 0xf0(%rsp), %r9+ movq 0x140(%rsp), %r10+ sbbq 0xf8(%rsp), %r10+ movq 0x148(%rsp), %r11+ sbbq 0x100(%rsp), %r11+ movq 0x150(%rsp), %r12+ sbbq 0x108(%rsp), %r12+ movq 0x158(%rsp), %r13+ sbbq 0x110(%rsp), %r13+ movq 0x160(%rsp), %r14+ sbbq 0x118(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x120(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x128(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x130(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x138(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x140(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x148(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x150(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x158(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x160(%rsp)+ movq 0x200(%rsp), %rsi+ movq 0x90(%rsi), %r8+ movq 0x98(%rsi), %r9+ movq 0xa0(%rsi), %r10+ movq 0xa8(%rsi), %r11+ movq 0xb0(%rsi), %r12+ movq 0xb8(%rsi), %r13+ movq 0xc0(%rsi), %r14+ movq 0xc8(%rsi), %r15+ movq 0xd0(%rsi), %rbp+ orq %r9, %r8+ orq %r11, %r10+ orq %r13, %r12+ orq %r15, %r14+ orq %r10, %r8+ orq %r14, %r12+ orq %rbp, %r8+ orq %r12, %r8+ negq %r8+ sbbq %rax, %rax+ movq 0x208(%rsp), %rdi+ movq 0x90(%rdi), %r8+ movq 0x98(%rdi), %r9+ movq 0xa0(%rdi), %r10+ movq 0xa8(%rdi), %r11+ movq 0xb0(%rdi), %r12+ movq 0xb8(%rdi), %r13+ movq 0xc0(%rdi), %r14+ movq 0xc8(%rdi), %r15+ movq 0xd0(%rdi), %rbp+ orq %r9, %r8+ orq %r11, %r10+ orq %r13, %r12+ orq %r15, %r14+ orq %r10, %r8+ orq %r14, %r12+ orq %rbp, %r8+ orq %r12, %r8+ negq %r8+ sbbq %rdx, %rdx+ cmpq %rax, %rdx+ movq 0x120(%rsp), %r8+ cmovbq 0x48(%rsi), %r8+ cmova 0x48(%rdi), %r8+ movq 0x128(%rsp), %r9+ cmovbq 0x50(%rsi), %r9+ cmova 0x50(%rdi), %r9+ movq 0x130(%rsp), %r10+ cmovbq 0x58(%rsi), %r10+ cmova 0x58(%rdi), %r10+ movq 0x138(%rsp), %r11+ cmovbq 0x60(%rsi), %r11+ cmova 0x60(%rdi), %r11+ movq 0x140(%rsp), %r12+ cmovbq 0x68(%rsi), %r12+ cmova 0x68(%rdi), %r12+ movq 0x148(%rsp), %r13+ cmovbq 0x70(%rsi), %r13+ cmova 0x70(%rdi), %r13+ movq 0x150(%rsp), %r14+ cmovbq 0x78(%rsi), %r14+ cmova 0x78(%rdi), %r14+ movq 0x158(%rsp), %r15+ cmovbq 0x80(%rsi), %r15+ cmova 0x80(%rdi), %r15+ movq 0x160(%rsp), %rbp+ cmovbq 0x88(%rsi), %rbp+ cmova 0x88(%rdi), %rbp+ movq %r8, 0x120(%rsp)+ movq %r9, 0x128(%rsp)+ movq %r10, 0x130(%rsp)+ movq %r11, 0x138(%rsp)+ movq %r12, 0x140(%rsp)+ movq %r13, 0x148(%rsp)+ movq %r14, 0x150(%rsp)+ movq %r15, 0x158(%rsp)+ movq %rbp, 0x160(%rsp)+ movq 0x168(%rsp), %r8+ cmovbq 0x90(%rsi), %r8+ cmova 0x90(%rdi), %r8+ movq 0x170(%rsp), %r9+ cmovbq 0x98(%rsi), %r9+ cmova 0x98(%rdi), %r9+ movq 0x178(%rsp), %r10+ cmovbq 0xa0(%rsi), %r10+ cmova 0xa0(%rdi), %r10+ movq 0x180(%rsp), %r11+ cmovbq 0xa8(%rsi), %r11+ cmova 0xa8(%rdi), %r11+ movq 0x188(%rsp), %r12+ cmovbq 0xb0(%rsi), %r12+ cmova 0xb0(%rdi), %r12+ movq 0x190(%rsp), %r13+ cmovbq 0xb8(%rsi), %r13+ cmova 0xb8(%rdi), %r13+ movq 0x198(%rsp), %r14+ cmovbq 0xc0(%rsi), %r14+ cmova 0xc0(%rdi), %r14+ movq 0x1a0(%rsp), %r15+ cmovbq 0xc8(%rsi), %r15+ cmova 0xc8(%rdi), %r15+ movq 0x1a8(%rsp), %rbp+ cmovbq 0xd0(%rsi), %rbp+ cmova 0xd0(%rdi), %rbp+ movq %r8, 0x168(%rsp)+ movq %r9, 0x170(%rsp)+ movq %r10, 0x178(%rsp)+ movq %r11, 0x180(%rsp)+ movq %r12, 0x188(%rsp)+ movq %r13, 0x190(%rsp)+ movq %r14, 0x198(%rsp)+ movq %r15, 0x1a0(%rsp)+ movq %rbp, 0x1a8(%rsp)+ movq (%rsp), %r8+ cmovbq (%rsi), %r8+ cmova (%rdi), %r8+ movq 0x8(%rsp), %r9+ cmovbq 0x8(%rsi), %r9+ cmova 0x8(%rdi), %r9+ movq 0x10(%rsp), %r10+ cmovbq 0x10(%rsi), %r10+ cmova 0x10(%rdi), %r10+ movq 0x18(%rsp), %r11+ cmovbq 0x18(%rsi), %r11+ cmova 0x18(%rdi), %r11+ movq 0x20(%rsp), %r12+ cmovbq 0x20(%rsi), %r12+ cmova 0x20(%rdi), %r12+ movq 0x28(%rsp), %r13+ cmovbq 0x28(%rsi), %r13+ cmova 0x28(%rdi), %r13+ movq 0x30(%rsp), %r14+ cmovbq 0x30(%rsi), %r14+ cmova 0x30(%rdi), %r14+ movq 0x38(%rsp), %r15+ cmovbq 0x38(%rsi), %r15+ cmova 0x38(%rdi), %r15+ movq 0x40(%rsp), %rbp+ cmovbq 0x40(%rsi), %rbp+ cmova 0x40(%rdi), %rbp+ movq 0x1f8(%rsp), %rdi+ movq %r8, (%rdi)+ movq %r9, 0x8(%rdi)+ movq %r10, 0x10(%rdi)+ movq %r11, 0x18(%rdi)+ movq %r12, 0x20(%rdi)+ movq %r13, 0x28(%rdi)+ movq %r14, 0x30(%rdi)+ movq %r15, 0x38(%rdi)+ movq %rbp, 0x40(%rdi)+ movq 0x120(%rsp), %rax+ movq %rax, 0x48(%rdi)+ movq 0x128(%rsp), %rax+ movq %rax, 0x50(%rdi)+ movq 0x130(%rsp), %rax+ movq %rax, 0x58(%rdi)+ movq 0x138(%rsp), %rax+ movq %rax, 0x60(%rdi)+ movq 0x140(%rsp), %rax+ movq %rax, 0x68(%rdi)+ movq 0x148(%rsp), %rax+ movq %rax, 0x70(%rdi)+ movq 0x150(%rsp), %rax+ movq %rax, 0x78(%rdi)+ movq 0x158(%rsp), %rax+ movq %rax, 0x80(%rdi)+ movq 0x160(%rsp), %rax+ movq %rax, 0x88(%rdi)+ movq 0x168(%rsp), %rax+ movq %rax, 0x90(%rdi)+ movq 0x170(%rsp), %rax+ movq %rax, 0x98(%rdi)+ movq 0x178(%rsp), %rax+ movq %rax, 0xa0(%rdi)+ movq 0x180(%rsp), %rax+ movq %rax, 0xa8(%rdi)+ movq 0x188(%rsp), %rax+ movq %rax, 0xb0(%rdi)+ movq 0x190(%rsp), %rax+ movq %rax, 0xb8(%rdi)+ movq 0x198(%rsp), %rax+ movq %rax, 0xc0(%rdi)+ movq 0x1a0(%rsp), %rax+ movq %rax, 0xc8(%rdi)+ movq 0x1a8(%rsp), %rax+ movq %rax, 0xd0(%rdi)+ CFI_INC_RSP(528)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_jadd)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_jdouble)++Lp521_jscalarmul_alt_jdouble:+ CFI_START+ CFI_PUSH(%rbx)+ CFI_PUSH(%rbp)+ CFI_PUSH(%r12)+ CFI_PUSH(%r13)+ CFI_PUSH(%r14)+ CFI_PUSH(%r15)+ CFI_DEC_RSP(520)+ movq %rdi, 0x1f8(%rsp)+ movq %rsi, 0x200(%rsp)+ movq 0x200(%rsp), %rdi+ leaq 0x90(%rdi), %rsi+ leaq (%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ movq 0x200(%rsp), %rdi+ leaq 0x48(%rdi), %rsi+ leaq 0x48(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ movq 0x200(%rsp), %rdi+ stc+ movq (%rdi), %rax+ adcq (%rsp), %rax+ movq 0x8(%rdi), %rbx+ adcq 0x8(%rsp), %rbx+ movq 0x10(%rdi), %r8+ adcq 0x10(%rsp), %r8+ movq 0x18(%rdi), %r9+ adcq 0x18(%rsp), %r9+ movq 0x20(%rdi), %r10+ adcq 0x20(%rsp), %r10+ movq 0x28(%rdi), %r11+ adcq 0x28(%rsp), %r11+ movq 0x30(%rdi), %r12+ adcq 0x30(%rsp), %r12+ movq 0x38(%rdi), %r13+ adcq 0x38(%rsp), %r13+ movq 0x40(%rdi), %r14+ adcq 0x40(%rsp), %r14+ movq $0x200, %rdx+ andq %r14, %rdx+ cmpq $0x200, %rdx+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rbx+ movq %rbx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq %rdx, %r14+ movq %r14, 0x1a8(%rsp)+ movq 0x200(%rsp), %rdi+ movq (%rdi), %rax+ subq (%rsp), %rax+ movq 0x8(%rdi), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x10(%rdi), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x18(%rdi), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x20(%rdi), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x28(%rdi), %r11+ sbbq 0x28(%rsp), %r11+ movq 0x30(%rdi), %r12+ sbbq 0x30(%rsp), %r12+ movq 0x38(%rdi), %r13+ sbbq 0x38(%rsp), %r13+ movq 0x40(%rdi), %r14+ sbbq 0x40(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x120(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x128(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x130(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x138(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x140(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x148(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x150(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x158(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x160(%rsp)+ leaq 0x120(%rsp), %rdx+ leaq 0x168(%rsp), %rsi+ leaq 0x90(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x200(%rsp), %rdi+ stc+ movq 0x48(%rdi), %rax+ adcq 0x90(%rdi), %rax+ movq 0x50(%rdi), %rbx+ adcq 0x98(%rdi), %rbx+ movq 0x58(%rdi), %r8+ adcq 0xa0(%rdi), %r8+ movq 0x60(%rdi), %r9+ adcq 0xa8(%rdi), %r9+ movq 0x68(%rdi), %r10+ adcq 0xb0(%rdi), %r10+ movq 0x70(%rdi), %r11+ adcq 0xb8(%rdi), %r11+ movq 0x78(%rdi), %r12+ adcq 0xc0(%rdi), %r12+ movq 0x80(%rdi), %r13+ adcq 0xc8(%rdi), %r13+ movq 0x88(%rdi), %r14+ adcq 0xd0(%rdi), %r14+ movq $0x200, %rdx+ andq %r14, %rdx+ cmpq $0x200, %rdx+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rbx+ movq %rbx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq %rdx, %r14+ movq %r14, 0x1a8(%rsp)+ leaq 0x90(%rsp), %rsi+ leaq 0x1b0(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ movq 0x200(%rsp), %rdi+ leaq 0x48(%rsp), %rdx+ leaq (%rdi), %rsi+ leaq 0xd8(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ leaq 0x168(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ movq $0x9, %rcx+ movq 0x1b0(%rsp), %rax+ notq %rax+ mulq %rcx+ movq %rax, %r8+ movq %rdx, %r9+ movq 0x1b8(%rsp), %rax+ notq %rax+ mulq %rcx+ xorl %r10d, %r10d+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x1c0(%rsp), %rax+ notq %rax+ mulq %rcx+ xorl %r11d, %r11d+ addq %rax, %r10+ adcq %rdx, %r11+ movq 0x1c8(%rsp), %rax+ notq %rax+ mulq %rcx+ xorl %r12d, %r12d+ addq %rax, %r11+ adcq %rdx, %r12+ movq 0x1d0(%rsp), %rax+ notq %rax+ mulq %rcx+ xorl %r13d, %r13d+ addq %rax, %r12+ adcq %rdx, %r13+ movq 0x1d8(%rsp), %rax+ notq %rax+ mulq %rcx+ xorl %r14d, %r14d+ addq %rax, %r13+ adcq %rdx, %r14+ movq 0x1e0(%rsp), %rax+ notq %rax+ mulq %rcx+ xorl %r15d, %r15d+ addq %rax, %r14+ adcq %rdx, %r15+ movq 0x1e8(%rsp), %rax+ notq %rax+ mulq %rcx+ xorl %ebx, %ebx+ addq %rax, %r15+ adcq %rdx, %rbx+ movq 0x1f0(%rsp), %rax+ xorq $0x1ff, %rax+ imulq %rcx, %rax+ addq %rax, %rbx+ xorl %eax, %eax+ movl $0xc, %ecx+ movq 0xd8(%rsp), %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %rbp, %rbp+ movq 0xe0(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rbp, %rbp+ movq 0xe8(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0xf0(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0xf8(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x100(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x108(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x110(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rbx+ movq 0x118(%rsp), %rax+ imulq %rcx, %rax+ addq %rax, %rbx+ movq %r9, %rax+ andq %r10, %rax+ andq %r11, %rax+ andq %r12, %rax+ andq %r13, %rax+ andq %r14, %rax+ andq %r15, %rax+ movq %rbx, %rdx+ shrq $0x9, %rdx+ orq $0xfffffffffffffe00, %rbx+ leaq 0x1(%rdx), %rcx+ addq %r8, %rcx+ movl $0x0, %ecx+ adcq %rcx, %rax+ movq %rbx, %rax+ adcq %rcx, %rax+ adcq %rdx, %r8+ movq %r8, 0x1b0(%rsp)+ adcq %rcx, %r9+ movq %r9, 0x1b8(%rsp)+ adcq %rcx, %r10+ movq %r10, 0x1c0(%rsp)+ adcq %rcx, %r11+ movq %r11, 0x1c8(%rsp)+ adcq %rcx, %r12+ movq %r12, 0x1d0(%rsp)+ adcq %rcx, %r13+ movq %r13, 0x1d8(%rsp)+ adcq %rcx, %r14+ movq %r14, 0x1e0(%rsp)+ adcq %rcx, %r15+ movq %r15, 0x1e8(%rsp)+ adcq %rcx, %rbx+ andq $0x1ff, %rbx+ movq %rbx, 0x1f0(%rsp)+ movq 0x120(%rsp), %rax+ subq (%rsp), %rax+ movq 0x128(%rsp), %rdx+ sbbq 0x8(%rsp), %rdx+ movq 0x130(%rsp), %r8+ sbbq 0x10(%rsp), %r8+ movq 0x138(%rsp), %r9+ sbbq 0x18(%rsp), %r9+ movq 0x140(%rsp), %r10+ sbbq 0x20(%rsp), %r10+ movq 0x148(%rsp), %r11+ sbbq 0x28(%rsp), %r11+ movq 0x150(%rsp), %r12+ sbbq 0x30(%rsp), %r12+ movq 0x158(%rsp), %r13+ sbbq 0x38(%rsp), %r13+ movq 0x160(%rsp), %r14+ sbbq 0x40(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x168(%rsp)+ sbbq $0x0, %rdx+ movq %rdx, 0x170(%rsp)+ sbbq $0x0, %r8+ movq %r8, 0x178(%rsp)+ sbbq $0x0, %r9+ movq %r9, 0x180(%rsp)+ sbbq $0x0, %r10+ movq %r10, 0x188(%rsp)+ sbbq $0x0, %r11+ movq %r11, 0x190(%rsp)+ sbbq $0x0, %r12+ movq %r12, 0x198(%rsp)+ sbbq $0x0, %r13+ movq %r13, 0x1a0(%rsp)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0x1a8(%rsp)+ leaq 0x48(%rsp), %rsi+ leaq 0x120(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_sqr_p521)+ movq 0x1f8(%rsp), %rdi+ movq 0x168(%rsp), %rax+ subq 0x48(%rsp), %rax+ movq 0x170(%rsp), %rdx+ sbbq 0x50(%rsp), %rdx+ movq 0x178(%rsp), %r8+ sbbq 0x58(%rsp), %r8+ movq 0x180(%rsp), %r9+ sbbq 0x60(%rsp), %r9+ movq 0x188(%rsp), %r10+ sbbq 0x68(%rsp), %r10+ movq 0x190(%rsp), %r11+ sbbq 0x70(%rsp), %r11+ movq 0x198(%rsp), %r12+ sbbq 0x78(%rsp), %r12+ movq 0x1a0(%rsp), %r13+ sbbq 0x80(%rsp), %r13+ movq 0x1a8(%rsp), %r14+ sbbq 0x88(%rsp), %r14+ sbbq $0x0, %rax+ movq %rax, 0x90(%rdi)+ sbbq $0x0, %rdx+ movq %rdx, 0x98(%rdi)+ sbbq $0x0, %r8+ movq %r8, 0xa0(%rdi)+ sbbq $0x0, %r9+ movq %r9, 0xa8(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0xb0(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0xb8(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0xc0(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0xc8(%rdi)+ sbbq $0x0, %r14+ andq $0x1ff, %r14+ movq %r14, 0xd0(%rdi)+ leaq 0x90(%rsp), %rdx+ leaq 0x1b0(%rsp), %rsi+ leaq 0x168(%rsp), %rdi+ CFI_CALL(Lp521_jscalarmul_alt_mul_p521)+ movq 0x1f8(%rsp), %rdi+ movq 0x118(%rsp), %rbx+ movq 0x110(%rsp), %r15+ shldq $0x2, %r15, %rbx+ movq 0x108(%rsp), %r14+ shldq $0x2, %r14, %r15+ movq 0x100(%rsp), %r13+ shldq $0x2, %r13, %r14+ movq 0xf8(%rsp), %r12+ shldq $0x2, %r12, %r13+ movq 0xf0(%rsp), %r11+ shldq $0x2, %r11, %r12+ movq 0xe8(%rsp), %r10+ shldq $0x2, %r10, %r11+ movq 0xe0(%rsp), %r9+ shldq $0x2, %r9, %r10+ movq 0xd8(%rsp), %r8+ shldq $0x2, %r8, %r9+ shlq $0x2, %r8+ movq 0x1f0(%rsp), %rcx+ xorq $0x1ff, %rcx+ movq 0x1b0(%rsp), %rax+ notq %rax+ addq %rax, %r8+ movq 0x1b8(%rsp), %rax+ notq %rax+ adcq %rax, %r9+ movq 0x1c0(%rsp), %rax+ notq %rax+ adcq %rax, %r10+ movq 0x1c8(%rsp), %rax+ notq %rax+ adcq %rax, %r11+ movq 0x1d0(%rsp), %rax+ notq %rax+ adcq %rax, %r12+ movq 0x1d8(%rsp), %rax+ notq %rax+ adcq %rax, %r13+ movq 0x1e0(%rsp), %rax+ notq %rax+ adcq %rax, %r14+ movq 0x1e8(%rsp), %rax+ notq %rax+ adcq %rax, %r15+ adcq %rcx, %rbx+ movq %r9, %rax+ andq %r10, %rax+ andq %r11, %rax+ andq %r12, %rax+ andq %r13, %rax+ andq %r14, %rax+ andq %r15, %rax+ movq %rbx, %rdx+ shrq $0x9, %rdx+ orq $0xfffffffffffffe00, %rbx+ leaq 0x1(%rdx), %rcx+ addq %r8, %rcx+ movl $0x0, %ecx+ adcq %rcx, %rax+ movq %rbx, %rax+ adcq %rcx, %rax+ adcq %rdx, %r8+ movq %r8, (%rdi)+ adcq %rcx, %r9+ movq %r9, 0x8(%rdi)+ adcq %rcx, %r10+ movq %r10, 0x10(%rdi)+ adcq %rcx, %r11+ movq %r11, 0x18(%rdi)+ adcq %rcx, %r12+ movq %r12, 0x20(%rdi)+ adcq %rcx, %r13+ movq %r13, 0x28(%rdi)+ adcq %rcx, %r14+ movq %r14, 0x30(%rdi)+ adcq %rcx, %r15+ movq %r15, 0x38(%rdi)+ adcq %rcx, %rbx+ andq $0x1ff, %rbx+ movq %rbx, 0x40(%rdi)+ movq 0x1f8(%rsp), %rdi+ movq 0x160(%rsp), %rbx+ xorq $0x1ff, %rbx+ movq 0x158(%rsp), %r15+ notq %r15+ shldq $0x3, %r15, %rbx+ movq 0x150(%rsp), %r14+ notq %r14+ shldq $0x3, %r14, %r15+ movq 0x148(%rsp), %r13+ notq %r13+ shldq $0x3, %r13, %r14+ movq 0x140(%rsp), %r12+ notq %r12+ shldq $0x3, %r12, %r13+ movq 0x138(%rsp), %r11+ notq %r11+ shldq $0x3, %r11, %r12+ movq 0x130(%rsp), %r10+ notq %r10+ shldq $0x3, %r10, %r11+ movq 0x128(%rsp), %r9+ notq %r9+ shldq $0x3, %r9, %r10+ movq 0x120(%rsp), %r8+ notq %r8+ shldq $0x3, %r8, %r9+ shlq $0x3, %r8+ movl $0x3, %ecx+ movq 0x168(%rsp), %rax+ mulq %rcx+ addq %rax, %r8+ adcq %rdx, %r9+ sbbq %rbp, %rbp+ movq 0x170(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r9+ adcq %rdx, %r10+ sbbq %rbp, %rbp+ movq 0x178(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r10+ adcq %rdx, %r11+ sbbq %rbp, %rbp+ movq 0x180(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r11+ adcq %rdx, %r12+ sbbq %rbp, %rbp+ movq 0x188(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r12+ adcq %rdx, %r13+ sbbq %rbp, %rbp+ movq 0x190(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r13+ adcq %rdx, %r14+ sbbq %rbp, %rbp+ movq 0x198(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r14+ adcq %rdx, %r15+ sbbq %rbp, %rbp+ movq 0x1a0(%rsp), %rax+ mulq %rcx+ subq %rbp, %rdx+ addq %rax, %r15+ adcq %rdx, %rbx+ movq 0x1a8(%rsp), %rax+ imulq %rcx, %rax+ addq %rax, %rbx+ movq %r9, %rax+ andq %r10, %rax+ andq %r11, %rax+ andq %r12, %rax+ andq %r13, %rax+ andq %r14, %rax+ andq %r15, %rax+ movq %rbx, %rdx+ shrq $0x9, %rdx+ orq $0xfffffffffffffe00, %rbx+ leaq 0x1(%rdx), %rcx+ addq %r8, %rcx+ movl $0x0, %ecx+ adcq %rcx, %rax+ movq %rbx, %rax+ adcq %rcx, %rax+ adcq %rdx, %r8+ movq %r8, 0x48(%rdi)+ adcq %rcx, %r9+ movq %r9, 0x50(%rdi)+ adcq %rcx, %r10+ movq %r10, 0x58(%rdi)+ adcq %rcx, %r11+ movq %r11, 0x60(%rdi)+ adcq %rcx, %r12+ movq %r12, 0x68(%rdi)+ adcq %rcx, %r13+ movq %r13, 0x70(%rdi)+ adcq %rcx, %r14+ movq %r14, 0x78(%rdi)+ adcq %rcx, %r15+ movq %r15, 0x80(%rdi)+ adcq %rcx, %rbx+ andq $0x1ff, %rbx+ movq %rbx, 0x88(%rdi)+ CFI_INC_RSP(520)+ CFI_POP(%r15)+ CFI_POP(%r14)+ CFI_POP(%r13)+ CFI_POP(%r12)+ CFI_POP(%rbp)+ CFI_POP(%rbx)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_jdouble)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_mul_p521)++Lp521_jscalarmul_alt_mul_p521:+ CFI_START+ CFI_DEC_RSP(72)+ movq %rdx, %rcx+ movq (%rsi), %rax+ mulq (%rcx)+ movq %rax, (%rsp)+ movq %rdx, %r9+ xorq %r10, %r10+ xorq %r11, %r11+ movq (%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ movq 0x8(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq %r11, %r11+ movq %r9, 0x8(%rsp)+ xorq %r12, %r12+ movq (%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq %r12, %r12+ movq 0x8(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq 0x10(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq %r10, 0x10(%rsp)+ xorq %r13, %r13+ movq (%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq %r13, %r13+ movq 0x8(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ movq 0x10(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ movq 0x18(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ movq %r11, 0x18(%rsp)+ xorq %r14, %r14+ movq (%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x8(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq 0x10(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq 0x18(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq 0x20(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq %r12, 0x20(%rsp)+ xorq %r15, %r15+ movq (%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x8(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ movq 0x10(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ movq 0x18(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ movq 0x20(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ movq 0x28(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ movq %r13, 0x28(%rsp)+ xorq %r8, %r8+ movq (%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ movq 0x8(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x10(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x18(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x20(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x28(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x30(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq %r14, 0x30(%rsp)+ xorq %r9, %r9+ movq (%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq %r9, %r9+ movq 0x8(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq $0x0, %r9+ movq 0x10(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq $0x0, %r9+ movq 0x18(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq $0x0, %r9+ movq 0x20(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq $0x0, %r9+ movq 0x28(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq $0x0, %r9+ movq 0x30(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq $0x0, %r9+ movq 0x38(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ adcq $0x0, %r9+ movq %r15, 0x38(%rsp)+ xorq %r10, %r10+ movq (%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq %r10, %r10+ movq 0x8(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq 0x10(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq 0x18(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq 0x20(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq 0x28(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq 0x30(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq 0x38(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq 0x40(%rsi), %rax+ mulq (%rcx)+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq %r8, 0x40(%rsp)+ xorq %r11, %r11+ movq 0x8(%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq %r11, %r11+ movq 0x10(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ movq 0x18(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ movq 0x20(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ movq 0x28(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ movq 0x30(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ movq 0x38(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ movq 0x40(%rsi), %rax+ mulq 0x8(%rcx)+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ xorq %r12, %r12+ movq 0x10(%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq %r12, %r12+ movq 0x18(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq 0x20(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq 0x28(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq 0x30(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq 0x38(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq 0x40(%rsi), %rax+ mulq 0x10(%rcx)+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ xorq %r13, %r13+ movq 0x18(%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq %r13, %r13+ movq 0x20(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ movq 0x28(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ movq 0x30(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ movq 0x38(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ movq 0x40(%rsi), %rax+ mulq 0x18(%rcx)+ addq %rax, %r11+ adcq %rdx, %r12+ adcq $0x0, %r13+ xorq %r14, %r14+ movq 0x20(%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq %r14, %r14+ movq 0x28(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq 0x30(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq 0x38(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq 0x40(%rsi), %rax+ mulq 0x20(%rcx)+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ xorq %r15, %r15+ movq 0x28(%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq %r15, %r15+ movq 0x30(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ movq 0x38(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ movq 0x40(%rsi), %rax+ mulq 0x28(%rcx)+ addq %rax, %r13+ adcq %rdx, %r14+ adcq $0x0, %r15+ xorq %r8, %r8+ movq 0x30(%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq %r8, %r8+ movq 0x38(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x40(%rsi), %rax+ mulq 0x30(%rcx)+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x38(%rsi), %rax+ mulq 0x40(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ movq 0x40(%rsi), %rax+ mulq 0x38(%rcx)+ addq %rax, %r15+ adcq %rdx, %r8+ movq 0x40(%rsi), %rax+ imulq 0x40(%rcx), %rax+ addq %r8, %rax+ movq 0x40(%rsp), %r8+ movq %r8, %rdx+ andq $0x1ff, %rdx+ shrdq $0x9, %r9, %r8+ shrdq $0x9, %r10, %r9+ shrdq $0x9, %r11, %r10+ shrdq $0x9, %r12, %r11+ shrdq $0x9, %r13, %r12+ shrdq $0x9, %r14, %r13+ shrdq $0x9, %r15, %r14+ shrdq $0x9, %rax, %r15+ shrq $0x9, %rax+ addq %rax, %rdx+ stc+ adcq (%rsp), %r8+ adcq 0x8(%rsp), %r9+ adcq 0x10(%rsp), %r10+ adcq 0x18(%rsp), %r11+ adcq 0x20(%rsp), %r12+ adcq 0x28(%rsp), %r13+ adcq 0x30(%rsp), %r14+ adcq 0x38(%rsp), %r15+ adcq $0xfffffffffffffe00, %rdx+ cmc+ sbbq $0x0, %r8+ movq %r8, (%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x8(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x10(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x18(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x20(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x28(%rdi)+ sbbq $0x0, %r14+ movq %r14, 0x30(%rdi)+ sbbq $0x0, %r15+ movq %r15, 0x38(%rdi)+ sbbq $0x0, %rdx+ andq $0x1ff, %rdx+ movq %rdx, 0x40(%rdi)+ CFI_INC_RSP(72)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_mul_p521)++S2N_BN_FUNCTION_TYPE_DIRECTIVE(Lp521_jscalarmul_alt_sqr_p521)++Lp521_jscalarmul_alt_sqr_p521:+ CFI_START+ CFI_DEC_RSP(72)+ movq (%rsi), %rax+ mulq %rax+ movq %rax, (%rsp)+ movq %rdx, %r9+ xorq %r10, %r10+ xorq %r11, %r11+ movq (%rsi), %rax+ mulq 0x8(%rsi)+ addq %rax, %rax+ adcq %rdx, %rdx+ adcq $0x0, %r11+ addq %rax, %r9+ adcq %rdx, %r10+ adcq $0x0, %r11+ movq %r9, 0x8(%rsp)+ xorq %r12, %r12+ movq 0x8(%rsi), %rax+ mulq %rax+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq (%rsi), %rax+ mulq 0x10(%rsi)+ addq %rax, %rax+ adcq %rdx, %rdx+ adcq $0x0, %r12+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq %r10, 0x10(%rsp)+ movq (%rsi), %rax+ mulq 0x18(%rsi)+ xorq %r13, %r13+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x8(%rsi), %rax+ mulq 0x10(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r13+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r13, %r13+ addq %rbx, %r11+ adcq %rcx, %r12+ adcq $0x0, %r13+ movq %r11, 0x18(%rsp)+ movq (%rsi), %rax+ mulq 0x20(%rsi)+ xorq %r14, %r14+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x8(%rsi), %rax+ mulq 0x18(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r14+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r14, %r14+ addq %rbx, %r12+ adcq %rcx, %r13+ adcq $0x0, %r14+ movq 0x10(%rsi), %rax+ mulq %rax+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq %r12, 0x20(%rsp)+ movq (%rsi), %rax+ mulq 0x28(%rsi)+ xorq %r15, %r15+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x8(%rsi), %rax+ mulq 0x20(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r15+ movq 0x10(%rsi), %rax+ mulq 0x18(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r15+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r15, %r15+ addq %rbx, %r13+ adcq %rcx, %r14+ adcq $0x0, %r15+ movq %r13, 0x28(%rsp)+ movq (%rsi), %rax+ mulq 0x30(%rsi)+ xorq %r8, %r8+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x8(%rsi), %rax+ mulq 0x28(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r8+ movq 0x10(%rsi), %rax+ mulq 0x20(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r8+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r8, %r8+ addq %rbx, %r14+ adcq %rcx, %r15+ adcq $0x0, %r8+ movq 0x18(%rsi), %rax+ mulq %rax+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq %r14, 0x30(%rsp)+ movq (%rsi), %rax+ mulq 0x38(%rsi)+ xorq %r9, %r9+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x8(%rsi), %rax+ mulq 0x30(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r9+ movq 0x10(%rsi), %rax+ mulq 0x28(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r9+ movq 0x18(%rsi), %rax+ mulq 0x20(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r9+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r9, %r9+ addq %rbx, %r15+ adcq %rcx, %r8+ adcq $0x0, %r9+ movq %r15, 0x38(%rsp)+ movq (%rsi), %rax+ mulq 0x40(%rsi)+ xorq %r10, %r10+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x8(%rsi), %rax+ mulq 0x38(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r10+ movq 0x10(%rsi), %rax+ mulq 0x30(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r10+ movq 0x18(%rsi), %rax+ mulq 0x28(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r10+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r10, %r10+ addq %rbx, %r8+ adcq %rcx, %r9+ adcq $0x0, %r10+ movq 0x20(%rsi), %rax+ mulq %rax+ addq %rax, %r8+ adcq %rdx, %r9+ adcq $0x0, %r10+ movq %r8, 0x40(%rsp)+ movq 0x8(%rsi), %rax+ mulq 0x40(%rsi)+ xorq %r11, %r11+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x10(%rsi), %rax+ mulq 0x38(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r11+ movq 0x18(%rsi), %rax+ mulq 0x30(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r11+ movq 0x20(%rsi), %rax+ mulq 0x28(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r11+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r11, %r11+ addq %rbx, %r9+ adcq %rcx, %r10+ adcq $0x0, %r11+ movq 0x10(%rsi), %rax+ mulq 0x40(%rsi)+ xorq %r12, %r12+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x18(%rsi), %rax+ mulq 0x38(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r12+ movq 0x20(%rsi), %rax+ mulq 0x30(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r12+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r12, %r12+ addq %rbx, %r10+ adcq %rcx, %r11+ adcq $0x0, %r12+ movq 0x28(%rsi), %rax+ mulq %rax+ addq %rax, %r10+ adcq %rdx, %r11+ adcq $0x0, %r12+ movq 0x18(%rsi), %rax+ mulq 0x40(%rsi)+ xorq %r13, %r13+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x20(%rsi), %rax+ mulq 0x38(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r13+ movq 0x28(%rsi), %rax+ mulq 0x30(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r13+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r13, %r13+ addq %rbx, %r11+ adcq %rcx, %r12+ adcq $0x0, %r13+ movq 0x20(%rsi), %rax+ mulq 0x40(%rsi)+ xorq %r14, %r14+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x28(%rsi), %rax+ mulq 0x38(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r14+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r14, %r14+ addq %rbx, %r12+ adcq %rcx, %r13+ adcq $0x0, %r14+ movq 0x30(%rsi), %rax+ mulq %rax+ addq %rax, %r12+ adcq %rdx, %r13+ adcq $0x0, %r14+ movq 0x28(%rsi), %rax+ mulq 0x40(%rsi)+ xorq %r15, %r15+ movq %rax, %rbx+ movq %rdx, %rcx+ movq 0x30(%rsi), %rax+ mulq 0x38(%rsi)+ addq %rax, %rbx+ adcq %rdx, %rcx+ adcq $0x0, %r15+ addq %rbx, %rbx+ adcq %rcx, %rcx+ adcq %r15, %r15+ addq %rbx, %r13+ adcq %rcx, %r14+ adcq $0x0, %r15+ xorq %r8, %r8+ movq 0x38(%rsi), %rax+ mulq %rax+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x30(%rsi), %rax+ mulq 0x40(%rsi)+ addq %rax, %rax+ adcq %rdx, %rdx+ adcq $0x0, %r8+ addq %rax, %r14+ adcq %rdx, %r15+ adcq $0x0, %r8+ movq 0x38(%rsi), %rax+ mulq 0x40(%rsi)+ addq %rax, %rax+ adcq %rdx, %rdx+ addq %rax, %r15+ adcq %rdx, %r8+ movq 0x40(%rsi), %rax+ imulq %rax, %rax+ addq %r8, %rax+ movq 0x40(%rsp), %r8+ movq %r8, %rdx+ andq $0x1ff, %rdx+ shrdq $0x9, %r9, %r8+ shrdq $0x9, %r10, %r9+ shrdq $0x9, %r11, %r10+ shrdq $0x9, %r12, %r11+ shrdq $0x9, %r13, %r12+ shrdq $0x9, %r14, %r13+ shrdq $0x9, %r15, %r14+ shrdq $0x9, %rax, %r15+ shrq $0x9, %rax+ addq %rax, %rdx+ stc+ adcq (%rsp), %r8+ adcq 0x8(%rsp), %r9+ adcq 0x10(%rsp), %r10+ adcq 0x18(%rsp), %r11+ adcq 0x20(%rsp), %r12+ adcq 0x28(%rsp), %r13+ adcq 0x30(%rsp), %r14+ adcq 0x38(%rsp), %r15+ adcq $0xfffffffffffffe00, %rdx+ cmc+ sbbq $0x0, %r8+ movq %r8, (%rdi)+ sbbq $0x0, %r9+ movq %r9, 0x8(%rdi)+ sbbq $0x0, %r10+ movq %r10, 0x10(%rdi)+ sbbq $0x0, %r11+ movq %r11, 0x18(%rdi)+ sbbq $0x0, %r12+ movq %r12, 0x20(%rdi)+ sbbq $0x0, %r13+ movq %r13, 0x28(%rdi)+ sbbq $0x0, %r14+ movq %r14, 0x30(%rdi)+ sbbq $0x0, %r15+ movq %r15, 0x38(%rdi)+ sbbq $0x0, %rdx+ andq $0x1ff, %rdx+ movq %rdx, 0x40(%rdi)+ CFI_INC_RSP(72)+ CFI_RET++S2N_BN_SIZE_DIRECTIVE(Lp521_jscalarmul_alt_sqr_p521)++#if defined(__linux__) && defined(__ELF__)+.section .note.GNU-stack, "", %progbits+#endif
cbits/sha1_armv8.c view
@@ -23,11 +23,7 @@ * baseline ARMv8-A may not use them; see sha256_armv8.c for the whole of that * argument. */-#ifdef WITH_TARGET_ATTRIBUTES-#define TARGET_ARMV8_CRYPTO __attribute__((target("+crypto")))-#else-#define TARGET_ARMV8_CRYPTO-#endif+#include "crypton_armv8_target.h" /* * A group of four rounds, and the schedule that goes with it.@@ -55,7 +51,7 @@ * One 64-byte block. `state` is the five words of chaining value in host * order, `buf` the block as it arrived, which SHA-1 reads big-endian. */-TARGET_ARMV8_CRYPTO+CRYPTON_TARGET_ARMV8_CRYPTO void crypton_sha1_armv8_do_chunks(uint32_t state[5], const uint8_t *data, uint32_t blocks) {@@ -72,15 +68,15 @@ e0 = state[4]; for (; blocks > 0; blocks--, data += 64) {- const uint32_t *buf = (const uint32_t *) data;+ const uint8_t *buf = data; abcd_prev = abcd; e_prev = e0; - m0 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf))));- m1 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf + 4))));- m2 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf + 8))));- m3 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf + 12))));+ m0 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf)));+ m1 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf + 16)));+ m2 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf + 32)));+ m3 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf + 48))); wk0 = vaddq_u32(m0, k0); wk1 = vaddq_u32(m1, k0);@@ -151,7 +147,7 @@ } /* the one-block form, for the partial block a message ends with */-void crypton_sha1_armv8_do_chunk(uint32_t state[5], const uint32_t buf[16])+void crypton_sha1_armv8_do_chunk(uint32_t state[5], const uint8_t buf[64]) { crypton_sha1_armv8_do_chunks(state, (const uint8_t *) buf, 1); }
cbits/sha1_x86.c view
@@ -168,7 +168,7 @@ } /* the one-block form, for the partial block a message ends with */-void crypton_sha1_x86_do_chunk(uint32_t state[5], const uint32_t buf[16])+void crypton_sha1_x86_do_chunk(uint32_t state[5], const uint8_t buf[64]) { crypton_sha1_x86_do_chunks(state, (const uint8_t *) buf, 1); }
cbits/sha256_armv8.c view
@@ -29,11 +29,7 @@ * * "+crypto" rather than "crypto": GCC rejects the latter. */-#ifdef WITH_TARGET_ATTRIBUTES-#define TARGET_ARMV8_CRYPTO __attribute__((target("+crypto")))-#else-#define TARGET_ARMV8_CRYPTO-#endif+#include "crypton_armv8_target.h" static const uint32_t K[64] = { 0x428a2f98, 0x71374491, 0xb5c0fbcf, 0xe9b5dba5,@@ -58,8 +54,8 @@ * One 64-byte block. `state` is the eight words of chaining value in host * order, `buf` the block as it arrived, which SHA-256 reads big-endian. */-TARGET_ARMV8_CRYPTO-void crypton_sha256_armv8_do_chunk(uint32_t state[8], const uint32_t buf[16])+CRYPTON_TARGET_ARMV8_CRYPTO+void crypton_sha256_armv8_do_chunk(uint32_t state[8], const uint8_t buf[64]) { uint32x4_t abcd, efgh, abcd_prev, efgh_prev, abcd_save, tmp; uint32x4_t m0, m1, m2, m3;@@ -68,10 +64,10 @@ abcd_prev = abcd = vld1q_u32(state); efgh_prev = efgh = vld1q_u32(state + 4); - m0 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf))));- m1 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf + 4))));- m2 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf + 8))));- m3 = vreinterpretq_u32_u8(vrev32q_u8(vreinterpretq_u8_u32(vld1q_u32(buf + 12))));+ m0 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf)));+ m1 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf + 16)));+ m2 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf + 32)));+ m3 = vreinterpretq_u32_u8(vrev32q_u8(vld1q_u8(buf + 48))); /* twelve groups of four rounds that also extend the schedule ... */ for (i = 0; i < 48; i += 16) {
cbits/sha3_armv8.c view
@@ -38,11 +38,7 @@ * of that argument. The flag for a build without attributes already asks for * "+sha3", which the SHA-512 path needed. */-#ifdef WITH_TARGET_ATTRIBUTES-#define TARGET_ARMV8_SHA3 __attribute__((target("+sha3")))-#else-#define TARGET_ARMV8_SHA3-#endif+#include "crypton_armv8_target.h" static const uint64_t rc[24] = { 0x0000000000000001ULL, 0x0000000000008082ULL, 0x800000000000808aULL,@@ -130,7 +126,7 @@ } while (0) /* the twenty-four rounds over the state, in place */-TARGET_ARMV8_SHA3+CRYPTON_TARGET_ARMV8_SHA3 void crypton_sha3_armv8_permute(uint64_t state[25]) { uint64x2_t a[25], b[25], c[5], d[5];
cbits/sha512_armv8.c view
@@ -28,11 +28,7 @@ * baseline ARMv8-A may not use them; mark the function that does. The * SHA-512 instructions live behind "+sha3" in both GCC and clang. */-#ifdef WITH_TARGET_ATTRIBUTES-#define TARGET_ARMV8_SHA3 __attribute__((target("+sha3")))-#else-#define TARGET_ARMV8_SHA3-#endif+#include "crypton_armv8_target.h" static const uint64_t K[80] = { 0x428a2f98d728ae22ULL, 0x7137449123ef65cdULL, 0xb5c0fbcfec4d3b2fULL,@@ -72,8 +68,8 @@ * two rounds and rotates which pair plays which part, so four steps return * to the start; a group of eight steps is one pass over the schedule. */-TARGET_ARMV8_SHA3-void crypton_sha512_armv8_do_chunk(uint64_t state[8], const uint64_t buf[16])+CRYPTON_TARGET_ARMV8_SHA3+void crypton_sha512_armv8_do_chunk(uint64_t state[8], const uint8_t buf[128]) { uint64x2_t ab, cd, ef, gh, ab0, cd0, ef0, gh0; uint64x2_t s[8];@@ -86,7 +82,7 @@ for (i = 0; i < 8; i++) s[i] = vreinterpretq_u64_u8(vrev64q_u8(- vld1q_u8((const uint8_t *) (buf + 2 * i))));+ vld1q_u8(buf + 16 * i))); /* two rounds; A, B, C, D is a rotation of gh, ef, cd, ab */ #define RND(A, B, C, D, sv, ki) \
+ cbits/tests/ct/README view
@@ -0,0 +1,84 @@+Does the code that handles a secret run in time independent of it?++memcheck already follows undefined bytes through arithmetic and reports the+moment one of them decides a branch or an address. That is the same question,+so each driver here declares its secret undefined and runs under valgrind:+every report names a place where a secret reached a branch or an index. The+technique is Adam Langley's ctgrind.++ct_canary.c is the calibration. It branches on a secret and indexes a table+with one, so it must report; if it does not, the marking is not reaching the+code and the silence of every other driver in that run means nothing. Round+five learned this the hard way with ThreadSanitizer, which saw nothing through+GHC's runtime including a deliberate race.++What is marked secret in each driver is the thing the caller would call a+private key, and nothing else. A modulus, a peer's public key, a nonce and a+message are public and stay defined; so does each answer, which is declared+public again before anything looks at it.++ canary a branch and a table index on a secret -- must report+ powm crypton_powm_sec, the exponent being an RSA private key+ p256 both scalar multiplications and the scalar inversion+ x25519 the scalar+ ed25519 the private key, through signing+ decaf Ed448 signing and X448, both private scalars+ chapoly the ChaCha20 key, the plaintext, and the Poly1305 key+ aes the AES key and the plaintext, through ECB and GCM+ aes_armv8 the same driver again, on AArch64, against the instructions++The aes driver is built against cbits/aes/generic.c and cbits/aes/gf.c on+purpose, rather than whatever the machine offers. AES-NI and the ARMv8+instructions do not look anything up and would report nothing, which would say+nothing about the table-driven code every other machine runs. That code is+variable-time by construction -- a table index is a byte of the state -- and+so is the table-driven GHASH beside it. A report from the aes driver is+therefore expected and is a property of those implementations, not a defect+found in them; it is here so that the size of it is written down rather than+assumed. Everything else is expected to be silent.++On AArch64 the same driver is then built a second time, as aes_armv8, against+cbits/aes/armv8.c with the crypto extension turned on. AESE, AESMC and PMULL+look nothing up and branch on nothing, so that run must report nothing at all+-- not "nothing outside known.txt", nothing; a table site appearing there+would mean the dispatch had not picked the instructions. The two runs keep+each other honest: the table-driven one has to report and the instruction one+has to be silent, and either going the wrong way says the run is not+measuring what it claims to.++Until that was added the harness ran only on x86-64, so crypton's AArch64 AES+and GHASH had never been put to it -- which was noticed when the GHASH was+rewritten.++What round eight found+----------------------++Of the eight drivers, five were silent: the RSA exponentiation, X25519,+Ed25519, ChaCha20 and Poly1305 never let a private key decide a branch or an+address. The AES driver reported from the tables, as it was built to.++The other two reported, five places between them, and every one of them an+assert():++ crypton_p256_modmul assert(top <= 1), assert(top == 0)+ crypton_gf_448_strong_reduce two asserts on a carry and a borrow+ crypton_gf_invert assert(ret), that what was inverted had an+ inverse++The first four check an invariant of a reduction rather than anything about+the data, so they hold whatever the input is. The fifth holds because the two+callers that ask for it are inverting a projective z, which is never zero for+a point on the curve. Either way the branch goes the same way every time and+no timing follows from it. They are reported at all because+crypton's C is compiled without NDEBUG, so assert() is live in a released+library. Twenty-eight assertions ship that way, none of them with a side+effect, and defining NDEBUG measured no faster on P-256, so whether to keep+them is a question about what a library should do when an internal invariant+fails -- abort the process, or carry on -- rather than one about speed. They+are listed in known.txt and the job passes with them.++The decision was to keep them: an internal invariant that fails in a+cryptographic library is better met with an abort than with a wrong answer+carried onwards. So this is settled rather than open, and the five entries in+known.txt are permanent. What is not permanent is anything else appearing+beside them.
+ cbits/tests/ct/ct.h view
@@ -0,0 +1,53 @@+/* Marking secrets for valgrind.+ *+ * memcheck already follows undefined bytes through arithmetic and complains+ * the moment one decides a branch or an address. That is the same question+ * as "does this run in time independent of the secret", so a secret declared+ * undefined turns memcheck into a checker for it. The technique is Adam+ * Langley's ctgrind.+ *+ * Without CRYPTON_CT_VALGRIND the macros vanish and the drivers still build+ * and run, which is how they are kept honest on a machine with no valgrind.+ */+#ifndef CRYPTON_TESTS_CT_H+#define CRYPTON_TESTS_CT_H++#ifdef CRYPTON_CT_VALGRIND+#include <valgrind/memcheck.h>+/* this memory is a secret: report any branch or index that depends on it */+#define CT_SECRET(p, n) VALGRIND_MAKE_MEM_UNDEFINED((p), (n))+/* and this is the answer, which the caller is allowed to look at */+#define CT_PUBLIC(p, n) VALGRIND_MAKE_MEM_DEFINED((p), (n))+#else+#define CT_SECRET(p, n) ((void)(p), (void)(n))+#define CT_PUBLIC(p, n) ((void)(p), (void)(n))+#endif++#include <stdint.h>+#include <stdio.h>++/* A deterministic filler, so that a report names the same operation on every+ * run. It is not random and does not need to be. */+static uint64_t ct_s0 = 0x243f6a8885a308d3ULL, ct_s1 = 0x13198a2e03707344ULL;+static uint64_t ct_rnd(void) {+ uint64_t x = ct_s0, y = ct_s1;+ ct_s0 = y;+ x ^= x << 23;+ ct_s1 = x ^ y ^ (x >> 17) ^ (y >> 26);+ return ct_s1 + y;+}+static void ct_fill(void *p, size_t n) {+ uint8_t *q = (uint8_t *)p;+ size_t i;+ for (i = 0; i < n; i++) q[i] = (uint8_t)(ct_rnd() >> 24);+}+/* Look at the answer, so that nothing above is optimized away. Whatever is+ * handed here has been declared public first. */+static void ct_sink(const void *p, size_t n) {+ const uint8_t *q = (const uint8_t *)p;+ size_t i;+ uint8_t acc = 0;+ for (i = 0; i < n; i++) acc ^= q[i];+ if (acc == 0xa5 && n == (size_t)-1) printf("unreachable\n");+}+#endif
+ cbits/tests/ct/ct_aes.c view
@@ -0,0 +1,35 @@+/* AES, and AES-GCM. The key is the secret, and so is the plaintext.+ *+ * Whether this reports depends on which implementation the machine selected.+ * AES-NI and the ARMv8 instructions do not look anything up; the generic C+ * is table-driven and is variable-time by construction, which is a property+ * of that code rather than a defect in it. See cbits/tests/ct/README. */+#include "tests/ct/ct.h"+#include <string.h>+#include "crypton_aes.h"++int main(void) {+ aes_key k;+ aes_gcm_key gk;+ uint8_t key[32], pt[256], ct[256 + 16], iv[12];++ ct_fill(key, sizeof key);+ ct_fill(pt, sizeof pt);+ ct_fill(iv, sizeof iv);+ CT_SECRET(key, sizeof key);+ CT_SECRET(pt, sizeof pt);++ crypton_aes_initkey(&k, key, sizeof key);+ crypton_aes_encrypt_ecb((aes_block *)ct, &k, (aes_block *)pt,+ sizeof pt / 16);+ CT_PUBLIC(ct, sizeof pt);+ ct_sink(ct, sizeof pt);++ crypton_aes_gcm_key_init(&gk, &k);+ /* the output takes the ciphertext and then the tag */+ crypton_aes_gcm_full_encrypt(ct, &gk, &k, iv, sizeof iv, NULL, 0,+ pt, sizeof pt, 16);+ CT_PUBLIC(ct, sizeof ct);+ ct_sink(ct, sizeof ct);+ return 0;+}
+ cbits/tests/ct/ct_aes_armv8.c view
@@ -0,0 +1,12 @@+/* The same driver as ct_aes.c, built against the AArch64 implementation+ * instead of the table-driven C.+ *+ * AESE, AESMC and PMULL look nothing up and branch on nothing, so this one+ * must report nothing at all -- not "nothing unknown", nothing. The+ * table-driven run of the same driver is what keeps that honest: if the+ * marking stopped reaching the code, that run would fall silent and fail,+ * and a silence here would mean no more than a silence there.+ *+ * Until this existed the constant-time harness ran only on x86-64, so+ * crypton's AArch64 AES and GHASH had never been put to it. */+#include "ct_aes.c"
+ cbits/tests/ct/ct_canary.c view
@@ -0,0 +1,21 @@+/* The calibration. This one is deliberately not constant time: it branches+ * on a secret byte and indexes a table with another. If it reports nothing,+ * the marking is not reaching the code and every other driver's silence in+ * this run means nothing either -- which is the whole reason it is here. */+#include "tests/ct/ct.h"++static const uint8_t table[256] = {1};++int main(void) {+ uint8_t secret[32], out[2];++ ct_fill(secret, sizeof secret);+ CT_SECRET(secret, sizeof secret);++ out[0] = secret[0] & 1 ? 0x5a : 0xa5; /* a branch on the secret */+ out[1] = table[secret[1]]; /* an address from the secret */++ CT_PUBLIC(out, sizeof out);+ ct_sink(out, sizeof out);+ return 0;+}
+ cbits/tests/ct/ct_chapoly.c view
@@ -0,0 +1,33 @@+/* ChaCha20 and Poly1305. The key is the secret, and so is the plaintext. */+#include "tests/ct/ct.h"+#include <string.h>+#include "crypton_chacha.h"+#include "crypton_poly1305.h"++int main(void) {+ crypton_chacha_context ctx;+ poly1305_ctx pctx;+ poly1305_key pkey;+ poly1305_mac mac;+ uint8_t key[32], iv[12], pt[256], ct[256];++ ct_fill(key, sizeof key);+ ct_fill(iv, sizeof iv);+ ct_fill(pt, sizeof pt);+ ct_fill(pkey, sizeof pkey);+ CT_SECRET(key, sizeof key);+ CT_SECRET(pt, sizeof pt);+ CT_SECRET(pkey, sizeof pkey);++ crypton_chacha_init(&ctx, 20, sizeof key, key, sizeof iv, iv);+ crypton_chacha_combine(ct, &ctx, pt, sizeof pt);+ CT_PUBLIC(ct, sizeof ct); /* the ciphertext goes on the wire */+ ct_sink(ct, sizeof ct);++ crypton_poly1305_init(&pctx, &pkey);+ crypton_poly1305_update(&pctx, ct, sizeof ct);+ crypton_poly1305_finalize(mac, &pctx);+ CT_PUBLIC(mac, sizeof mac);+ ct_sink(mac, sizeof mac);+ return 0;+}
+ cbits/tests/ct/ct_decaf.c view
@@ -0,0 +1,36 @@+/* X448 and Ed448. The scalar and the private key are the secrets. */+#include "tests/ct/ct.h"+#include <string.h>+#include "decaf/ed448.h"+#include "decaf/point_448.h"++int main(void) {+ uint8_t priv[CRYPTON_DECAF_EDDSA_448_PRIVATE_BYTES];+ uint8_t pub[CRYPTON_DECAF_EDDSA_448_PUBLIC_BYTES];+ uint8_t sig[CRYPTON_DECAF_EDDSA_448_SIGNATURE_BYTES];+ uint8_t xs[CRYPTON_DECAF_X448_PRIVATE_BYTES];+ uint8_t xb[CRYPTON_DECAF_X448_PUBLIC_BYTES];+ uint8_t xo[CRYPTON_DECAF_X448_PUBLIC_BYTES];+ uint8_t msg[64];++ ct_fill(priv, sizeof priv);+ ct_fill(msg, sizeof msg);+ ct_fill(xs, sizeof xs);+ ct_fill(xb, sizeof xb);+ CT_SECRET(priv, sizeof priv);+ CT_SECRET(xs, sizeof xs);++ crypton_decaf_ed448_derive_public_key(pub, priv);+ CT_PUBLIC(pub, sizeof pub);+ crypton_decaf_ed448_sign(sig, priv, pub, msg, sizeof msg, 0, NULL, 0);+ CT_PUBLIC(sig, sizeof sig);+ ct_sink(sig, sizeof sig);++ crypton_decaf_x448_derive_public_key(xo, xs);+ CT_PUBLIC(xo, sizeof xo);+ ct_sink(xo, sizeof xo);+ (void)crypton_decaf_x448(xo, xb, xs);+ CT_PUBLIC(xo, sizeof xo);+ ct_sink(xo, sizeof xo);+ return 0;+}
+ cbits/tests/ct/ct_ed25519.c view
@@ -0,0 +1,23 @@+/* Ed25519 signing. The private key is the secret; the message is not. */+#include "tests/ct/ct.h"+#include <string.h>+#include "ed25519/ed25519.h"++int main(void) {+ ed25519_secret_key sk;+ ed25519_public_key pk;+ ed25519_signature sig;+ uint8_t msg[64];++ ct_fill(sk, sizeof sk);+ ct_fill(msg, sizeof msg);+ CT_SECRET(sk, sizeof sk);++ crypton_ed25519_publickey(sk, pk);+ CT_PUBLIC(pk, sizeof pk);++ crypton_ed25519_sign(msg, sizeof msg, sk, pk, sig);+ CT_PUBLIC(sig, sizeof sig);+ ct_sink(sig, sizeof sig);+ return 0;+}
+ cbits/tests/ct/ct_p256.c view
@@ -0,0 +1,42 @@+/* The two P-256 scalar multiplications and the scalar inversion, all of+ * which take the private key as the scalar. */+#include "tests/ct/ct.h"+#include <string.h>+#include "p256/p256.h"++void crypton_p256e_point_mul(const crypton_p256_int *n,+ const crypton_p256_int *ix, const crypton_p256_int *iy,+ crypton_p256_int *ox, crypton_p256_int *oy);+void crypton_p256e_scalar_invert(const crypton_p256_int *a,+ crypton_p256_int *b);++int main(void) {+ crypton_p256_int n, px, py, ox, oy, inv, one;+ int i;++ /* a public point to be multiplied: the generator's 0x9e3779b9 multiple */+ crypton_p256_init(&one);+ P256_DIGIT(&one, 0) = 0x9e3779b9u;+ crypton_p256_base_point_mul(&one, &px, &py);++ for (i = 0; i < P256_NDIGITS; i++)+ P256_DIGIT(&n, i) = (crypton_p256_digit)ct_rnd();+ crypton_p256_mod(&crypton_SECP256r1_n, &n, &n);++ CT_SECRET(&n, sizeof n);++ crypton_p256_base_point_mul(&n, &ox, &oy);+ CT_PUBLIC(&ox, sizeof ox);+ CT_PUBLIC(&oy, sizeof oy);+ ct_sink(&ox, sizeof ox);++ crypton_p256e_point_mul(&n, &px, &py, &ox, &oy);+ CT_PUBLIC(&ox, sizeof ox);+ CT_PUBLIC(&oy, sizeof oy);+ ct_sink(&oy, sizeof oy);++ crypton_p256e_scalar_invert(&n, &inv);+ CT_PUBLIC(&inv, sizeof inv);+ ct_sink(&inv, sizeof inv);+ return 0;+}
+ cbits/tests/ct/ct_powm.c view
@@ -0,0 +1,29 @@+/* The windowed modular exponentiation, which is what an RSA private key+ * operation runs. The exponent is the secret it is built to hide. */+#include "tests/ct/ct.h"+#include <string.h>+#include "crypton_powm.h"++int main(void) {+ enum { LEN = 256 }; /* a 2048-bit modulus */+ uint8_t out[LEN], base[LEN], mod[LEN], exp[LEN];++ ct_fill(base, sizeof base);+ ct_fill(mod, sizeof mod);+ ct_fill(exp, sizeof exp);+ mod[0] |= 0x80; /* full width */+ mod[LEN - 1] |= 1; /* and odd, which is what it wants */+ base[0] &= 0x7f; /* below the modulus */++ /* The exponent is the private key. The base is the ciphertext, which an+ * attacker chooses and already knows, so it stays public. */+ CT_SECRET(exp, sizeof exp);++ if (crypton_powm_sec(out, base, LEN, exp, LEN, mod, LEN) != 0) {+ printf("powm_sec refused\n");+ return 1;+ }+ CT_PUBLIC(out, sizeof out);+ ct_sink(out, sizeof out);+ return 0;+}
+ cbits/tests/ct/ct_x25519.c view
@@ -0,0 +1,25 @@+/* X25519. The scalar is the private key; the base point is the peer's+ * public key and is not secret. */+#include "tests/ct/ct.h"+#include <string.h>++void crypton_curve25519_donna(uint8_t *mypublic, const uint8_t *secret,+ const uint8_t *basepoint);++int main(void) {+ uint8_t sec[32], base[32], out[32];+ static const uint8_t g[32] = {9};++ ct_fill(sec, sizeof sec);+ ct_fill(base, sizeof base);+ CT_SECRET(sec, sizeof sec);++ crypton_curve25519_donna(out, sec, g); /* the public key */+ CT_PUBLIC(out, sizeof out);+ ct_sink(out, sizeof out);++ crypton_curve25519_donna(out, sec, base); /* the shared secret */+ CT_PUBLIC(out, sizeof out);+ ct_sink(out, sizeof out);+ return 0;+}
+ cbits/tests/ct/known.txt view
@@ -0,0 +1,54 @@+# Places where a secret reaches a branch that are known, understood and not+# defects. A driver reporting only these passes; anything else fails.+#+# Every entry is "file:line what it is". Keep it short: a long one means+# something has been accepted that should have been fixed.++# assert() on a value derived from the secret. The asserted condition holds+# on every input -- these check an internal invariant of the reduction, not+# anything about the data -- so the branch goes the same way every time and+# no timing follows from it. They are reported because crypton's C is built+# without NDEBUG, so assert() is live in a released library. See the round+# eight notes in cbits/tests/ct/README.+p256.c:200 assert(top <= 1) in crypton_p256_modmul+p256.c:204 assert(top == 0) in crypton_p256_modmul+f_generic.c:94 assert on the borrow in crypton_gf_448_strong_reduce+f_generic.c:106 assert on the carry in crypton_gf_448_strong_reduce++# The same thing for a different reason. crypton_gf_invert asserts that what+# it inverted had an inverse, and the two callers that ask for the assertion+# are inverting a projective z, which is never zero for a point on the curve.+# So this one holds because of what the callers pass rather than because of+# arithmetic, and it too goes the same way on every valid input.+decaf.c:136 assert(ret) in crypton_gf_invert++# The table-driven AES and the table-driven GHASH index with a byte of the+# state, which is what makes them fast and what makes them variable-time.+# That is a property of those implementations rather than a defect in them;+# a machine with AES-NI or the ARMv8 instructions runs neither.+generic.c the AES tables, in key expansion and in the rounds+gf.c the GHASH table+crypton_aes.c the same tables, attributed to the code that inlines them+block128.h likewise++# AArch64 only. gcc keeps a carry in the flags and takes it out with `cset`+# or `cinc`, where on x86-64 it uses `adc` and the carry never leaves the+# data path. memcheck calls `cset` a conditional move and reports it, and+# it attributes the report to the branch that ends the block rather than to+# the `cset` itself -- so the site it names is a loop back-edge, not the+# instruction that touched the secret.+#+# Checked by disassembling the address memcheck named, in a -no-pie build so+# that its addresses and objdump's agree. At every one of these the branch+# reads flags from a `cmp` against a loop counter or a pointer bound, both+# public; the only instructions consuming the secret's flags are `cset` and+# `cinc`, which do not branch and take the same time either way. In decaf's+# lookup the secret only reaches a `dup` and a NEON `and`/`orr`.+#+# 400f60 cmp x3, #0x20 <- public: four digits of 8 bytes+# 400f64 b.ne 400f3c <- what memcheck names+# 404c6c cmp x3, x6 <- public: j against n_table+# 404c70 b.ne 404c30 <- what memcheck names+p256.c:147 addM's loop; the carry is taken with cset and cinc+p256.c:149 the same+constant_time.h:150 decaf's constant-time lookup, over j < n_table
+ cbits/tests/ct/run.sh view
@@ -0,0 +1,167 @@+#!/bin/sh+# Does the code that handles a secret run in time independent of it?+#+# memcheck already follows undefined bytes through arithmetic and reports the+# moment one decides a branch or an address. That is the same question, so+# each driver declares its secret undefined and runs under valgrind: every+# report names a place where the secret reached a branch or an index.+# The technique is Adam Langley's ctgrind.+#+# Without valgrind the drivers are still built and run, which says only that+# the plumbing is right -- it checks nothing about timing, and says so.+#+# Usage: cbits/tests/ct/run.sh [build-dir]+set -eu++root=$(CDPATH= cd -- "$(dirname -- "$0")/../../.." && pwd)+out=${1:-$(mktemp -d)}+cc=${CC:-cc}+mkdir -p "$out"+cd "$root"++D=cbits/decaf+decaf_src="$D/ed448goldilocks/decaf_all.c $D/ed448goldilocks/eddsa.c+ $D/ed448goldilocks/scalar.c $D/p448/f_arithmetic.c+ $D/p448/f_generic.c $D/utils.c $D/p448/arch_ref64/f_impl.c+ cbits/crypton_sha3.c"+decaf_inc="-DCRYPTON_DECAF_WORD_BITS=64 -I$D/include -I$D/p448+ -I$D/include/arch_ref64 -I$D/p448/arch_ref64"++# The generic C, not whatever the machine happens to offer. A build that+# takes AES-NI reports nothing from the AES driver and says nothing about the+# table-driven code every other machine runs.+aes_src="cbits/crypton_aes.c cbits/aes/generic.c cbits/aes/gf.c"++# And, on AArch64, the same driver again against the instructions. That one+# has to be silent; this one has to report. Either going the wrong way says+# the run is not measuring what it claims to.+armv8_src="$aes_src cbits/aes/armv8.c cbits/crypton_cpu.c"+armv8_inc="-DWITH_ARMV8_CRYPTO -march=armv8-a+crypto -Icbits/aes"++status=0+have_valgrind=no+ct_define=+if command -v valgrind > /dev/null 2>&1; then+ have_valgrind=yes+ ct_define=-DCRYPTON_CT_VALGRIND+fi++run_one() {+ name=$1; srcs=$2; inc=$3+ # shellcheck disable=SC2086+ $cc -O2 -g $ct_define -Icbits -Icbits/include64 $inc \+ -o "$out/$name" "cbits/tests/ct/ct_$name.c" $srcs 2> "$out/$name.cc" || {+ echo "FAIL $name did not build"; sed -n '1,12p' "$out/$name.cc"; status=1; return+ }+ if [ "$have_valgrind" = no ]; then+ "$out/$name" > /dev/null 2>&1 && echo "built $name (no valgrind here; nothing checked)" \+ || { echo "FAIL $name did not run"; status=1; }+ return+ fi+ valgrind --error-exitcode=0 --track-origins=yes --num-callers=20 \+ --log-file="$out/$name.log" "$out/$name" > /dev/null 2>&1 || true+ n=$(grep -c "^==[0-9]*== \(Conditional jump\|Use of uninitialised\)" "$out/$name.log" || true)+ # Which places did it name? Only the frame the report is against -- the+ # first "at" line under the complaint -- is the place; the "by" lines+ # below it are how the code got there and are not themselves branching+ # on anything. Nor is the "at" line under "Uninitialised value was+ # created by", which --track-origins prints to say where the value came+ # from: that frame is a stack allocation, not a branch, and taking it+ # for one put a function's opening brace on the list. A site is+ # "file:line", and the ones listed in known.txt are understood.+ sites=$(awk '+ /^==[0-9]*== (Conditional jump|Use of uninitialised)/ { want = 1; next }+ want && /^==[0-9]*== at 0x/ { print; want = 0 }+ ' "$out/$name.log" |+ sed -n 's/^==[0-9]*== at 0x[0-9A-Fa-f]*: [A-Za-z_0-9]* (\([^)]*\))$/\1/p' |+ grep -v '^ct_' | sort -u)+ unknown=+ for site in $sites; do+ file=${site%%:*}+ if grep -q "^$site[[:space:]]" cbits/tests/ct/known.txt ||+ grep -q "^$file[[:space:]]" cbits/tests/ct/known.txt; then+ continue+ fi+ unknown="$unknown $site"+ done++ case $name in+ canary)+ # the calibration: silence here would mean the marking never reached+ # the code, and every other zero in this run would be worthless+ if [ "$n" -eq 0 ]; then+ echo "FAIL canary: the deliberately leaky driver reported nothing,"+ echo " so the marking is not reaching the code and nothing below counts"+ status=1+ else+ echo "ok canary: reported $n, so the marking works"+ fi+ ;;+ aes)+ # Silence would mean the build took an accelerated path and so+ # measured nothing; the tables reporting is the point.+ if [ "$n" -eq 0 ]; then+ echo "FAIL aes: reported nothing, so this build did not take the"+ echo " table-driven code the driver exists to measure"+ status=1+ else+ echo "note aes: $n report(s), from $(echo "$sites" | tr '\n' ' ')"+ fi+ ;;+ aes_armv8)+ # The opposite demand, and known.txt does not apply: the entries in+ # it are for the tables, and this build is not supposed to reach+ # them. Anything at all here is a finding, including a table site,+ # which would mean the dispatch did not pick the instructions.+ if [ "$n" -eq 0 ]; then+ echo "ok aes_armv8: the instructions decided nothing"+ else+ echo "FAIL aes_armv8: $n report(s) from the AArch64 AES or GHASH,"+ echo " which look nothing up and should branch on nothing:"+ for site in $sites; do echo " $site"; done+ sed -n '/Conditional jump\|Use of uninitialised/,/^==[0-9]*== $/p' \+ "$out/$name.log" | head -30 | sed 's/^/ /'+ status=1+ fi+ ;;+ *)+ if [ "$n" -eq 0 ]; then+ echo "ok $name: the secret decided nothing"+ elif [ -z "$unknown" ]; then+ echo "ok $name: $n report(s), all known -- $(echo "$sites" | tr '\n' ' ')"+ else+ echo "REPORT $name: the secret decided a branch or an address"+ echo " somewhere not listed in cbits/tests/ct/known.txt:"+ for site in $unknown; do echo " $site"; done+ sed -n '/Conditional jump\|Use of uninitialised/,/^==[0-9]*== $/p' \+ "$out/$name.log" | head -30 | sed 's/^/ /'+ status=1+ fi+ ;;+ esac+}++# The calibration first: it must report, or nothing below means anything.+run_one canary "" ""++run_one powm "cbits/crypton_powm.c" ""+run_one p256 "cbits/p256/p256.c cbits/p256/p256_ec.c" ""+run_one x25519 "cbits/curve25519/curve25519-donna-c64.c" ""+run_one ed25519 "cbits/ed25519/ed25519.c cbits/crypton_sha512.c" "-Icbits/ed25519"+run_one decaf "$decaf_src" "$decaf_inc"+run_one chapoly "cbits/crypton_chacha.c cbits/crypton_poly1305.c" ""+run_one aes "$aes_src" ""++# Only where the instructions exist. Elsewhere there is nothing to measure+# and the build would not even compile.+case $(uname -m) in+aarch64 | arm64)+ run_one aes_armv8 "$armv8_src" "$armv8_inc"+ ;;+esac++if [ "$have_valgrind" = no ]; then+ echo "skip no valgrind here, so none of the above was checked"+ exit 0+fi+exit $status
+ cbits/tests/endian/README view
@@ -0,0 +1,27 @@+Does this C give the same answers on a big-endian machine?++The cabal file lists s390x and ppc64 among the architectures it builds for.+Neither is in the CI matrix, and neither had ever compiled this code, let+alone run it. Eighteen files read their input through the loaders in+crypton_align.h -- which were rewritten from word-typed casts to memcpy in+#256 -- and eight more decide something from the byte order themselves. That+is the largest body of untested endianness-sensitive code in the tree, and the+riskiest part of it is the most recently written.++The two sides cannot be compared in one run the way the 32-bit harness+compares two builds, because only one endianness exists on the machine doing+the comparing. So the answers are frozen instead: vectors.txt is what this+code gives on a little-endian host, and check mode reads it back and compares.+Any machine can run check mode, and a big-endian one that disagrees says so+line by line.++ cbits/tests/endian/run.sh generate write vectors.txt from this machine+ cbits/tests/endian/run.sh check this machine against vectors.txt++Generate mode is for a maintainer on a little-endian machine after adding a+primitive, and the file it writes is committed. It is not run in CI, where+only check mode makes sense.++The first few lines of vectors.txt are published test vectors rather than+whatever this code happened to produce -- SHA-256 of "abc" and the like --+so that a mistake on the generating host is caught rather than frozen in.
+ cbits/tests/endian/endian.c view
@@ -0,0 +1,192 @@+/* What this C answers, so that a big-endian machine can be asked the same.+ *+ * Every primitive here reads its input a word at a time, or writes its output+ * that way, or both -- which is the step that goes wrong when the byte order+ * changes. Each one is fed the same deterministic bytes at several lengths,+ * including lengths either side of its block, since the tail is where the+ * length is packed in and where the byte order shows.+ */+#include <stdio.h>+#include <stdint.h>+#include <string.h>+#include <stdlib.h>++#include "crypton_md4.h"+#include "crypton_md5.h"+#include "crypton_sha1.h"+#include "crypton_sha256.h"+#include "crypton_sha512.h"+#include "crypton_sha3.h"+#include "crypton_ripemd.h"+#include "crypton_skein256.h"+#include "crypton_skein512.h"+#include "crypton_tiger.h"+#include "crypton_whirlpool.h"+#include "crypton_chacha.h"+#include "crypton_salsa.h"+#include "crypton_poly1305.h"++/* The skein headers spell the prefix "cryponite", which nothing defines. */+void crypton_skein256_init(struct skein256_ctx *ctx, uint32_t hashlen);+void crypton_skein256_update(struct skein256_ctx *ctx, const uint8_t *data, uint32_t len);+void crypton_skein256_finalize(struct skein256_ctx *ctx, uint32_t hashlen, uint8_t *out);+void crypton_skein512_init(struct skein512_ctx *ctx, uint32_t hashlen);+void crypton_skein512_update(struct skein512_ctx *ctx, const uint8_t *data, uint32_t len);+void crypton_skein512_finalize(struct skein512_ctx *ctx, uint32_t hashlen, uint8_t *out);++static int generating;+static FILE *vf;+static int failures, checked;++/* one answer: named, and either written out or compared with what was */+static void answer(const char *name, const uint8_t *out, size_t n) {+ char got[512], want[512], label[128];+ size_t i;+ for (i = 0; i < n && i * 2 + 2 < sizeof got; i++)+ snprintf(got + i * 2, 3, "%02x", out[i]);+ got[n * 2] = 0;+ /* an answer of no bytes still has to be a token, or the reader below+ takes the next line's name for this line's answer and everything+ after it is compared against the wrong thing */+ if (n == 0) strcpy(got, "-");+ if (generating) {+ fprintf(vf, "%s %s\n", name, got);+ return;+ }+ if (fscanf(vf, "%127s %511s", label, want) != 2) {+ printf("FAIL %s: vectors.txt ended early\n", name);+ failures++;+ return;+ }+ checked++;+ if (strcmp(label, name) != 0) {+ printf("FAIL out of step: expected %s, vectors.txt has %s\n", name, label);+ failures++;+ } else if (strcmp(got, want) != 0) {+ printf("FAIL %s\n little-endian %s\n this machine %s\n", name, want, got);+ failures++;+ }+}++/* the input: deterministic, and at lengths either side of every block size */+static const size_t lengths[] = {0, 1, 3, 55, 56, 63, 64, 65, 111, 112,+ 127, 128, 129, 135, 136, 255, 256, 1000};+static uint8_t buf[1024];+static void fill(void) {+ size_t i;+ for (i = 0; i < sizeof buf; i++) buf[i] = (uint8_t)(i * 7 + (i >> 5) * 31);+}++#define HASH(nm, ctxt, initcall, updcall, fincall, outlen) \+ do { \+ size_t li; \+ for (li = 0; li < sizeof lengths / sizeof *lengths; li++) { \+ ctxt ctx; \+ uint8_t out[outlen]; \+ char nmbuf[128]; \+ initcall; \+ updcall; \+ fincall; \+ snprintf(nmbuf, sizeof nmbuf, "%s/%zu", nm, lengths[li]); \+ answer(nmbuf, out, outlen); \+ } \+ } while (0)++int main(int argc, char **argv) {+ generating = (argc > 1 && strcmp(argv[1], "generate") == 0);+ vf = fopen(argc > 2 ? argv[2] : "cbits/tests/endian/vectors.txt",+ generating ? "w" : "r");+ if (!vf) { printf("cannot open vectors.txt\n"); return 2; }+ fill();++ HASH("md4", struct md4_ctx, crypton_md4_init(&ctx),+ crypton_md4_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_md4_finalize(&ctx, out), 16);+ HASH("md5", struct md5_ctx, crypton_md5_init(&ctx),+ crypton_md5_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_md5_finalize(&ctx, out), 16);+ HASH("sha1", struct sha1_ctx, crypton_sha1_init(&ctx),+ crypton_sha1_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_sha1_finalize(&ctx, out), 20);+ HASH("sha256", struct sha256_ctx, crypton_sha256_init(&ctx),+ crypton_sha256_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_sha256_finalize(&ctx, out), 32);+ HASH("sha512", struct sha512_ctx, crypton_sha512_init(&ctx),+ crypton_sha512_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_sha512_finalize(&ctx, out), 64);+ /* sha3's context ends in a flexible buffer whose width comes from the+ * hash length, so it is not a plain automatic variable like the rest. */+ {+ size_t li;+ for (li = 0; li < sizeof lengths / sizeof *lengths; li++) {+ uint8_t space[SHA3_CTX_BUF_MAX_SIZE];+ struct sha3_ctx *ctx = (struct sha3_ctx *)space;+ uint8_t out[32];+ char nmbuf[128];+ crypton_sha3_init(ctx, 256);+ crypton_sha3_update(ctx, buf, (uint32_t)lengths[li]);+ crypton_sha3_finalize(ctx, 256, out);+ snprintf(nmbuf, sizeof nmbuf, "sha3-256/%zu", lengths[li]);+ answer(nmbuf, out, sizeof out);+ }+ }+ HASH("ripemd160", struct ripemd160_ctx, crypton_ripemd160_init(&ctx),+ crypton_ripemd160_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_ripemd160_finalize(&ctx, out), 20);+ HASH("skein256", struct skein256_ctx, crypton_skein256_init(&ctx, 256),+ crypton_skein256_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_skein256_finalize(&ctx, 256, out), 32);+ HASH("skein512", struct skein512_ctx, crypton_skein512_init(&ctx, 512),+ crypton_skein512_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_skein512_finalize(&ctx, 512, out), 64);+ HASH("tiger", struct tiger_ctx, crypton_tiger_init(&ctx),+ crypton_tiger_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_tiger_finalize(&ctx, out), 24);+ HASH("whirlpool", struct whirlpool_ctx, crypton_whirlpool_init(&ctx),+ crypton_whirlpool_update(&ctx, buf, (uint32_t)lengths[li]),+ crypton_whirlpool_finalize(&ctx, out), 64);++ /* The stream ciphers and the one-time authenticator. Each reads its key+ * and its input a word at a time and writes its output the same way, so+ * the byte order shows in the answer rather than in a length field. */+ {+ size_t li;+ for (li = 0; li < sizeof lengths / sizeof *lengths; li++) {+ crypton_chacha_context cctx;+ crypton_salsa_context sctx;+ poly1305_ctx pctx;+ poly1305_key pkey;+ poly1305_mac mac;+ uint8_t key[32], iv[8], outbuf[1024];+ char nmbuf[128];+ size_t i;++ for (i = 0; i < sizeof key; i++) key[i] = (uint8_t)(i * 11 + 3);+ for (i = 0; i < sizeof iv; i++) iv[i] = (uint8_t)(i * 5 + 1);++ crypton_chacha_init(&cctx, 20, sizeof key, key, sizeof iv, iv);+ crypton_chacha_combine(outbuf, &cctx, buf, (uint32_t)lengths[li]);+ snprintf(nmbuf, sizeof nmbuf, "chacha20/%zu", lengths[li]);+ answer(nmbuf, outbuf, lengths[li] < 64 ? lengths[li] : 64);++ crypton_salsa_init(&sctx, 20, sizeof key, key, sizeof iv, iv);+ crypton_salsa_combine(outbuf, &sctx, buf, (uint32_t)lengths[li]);+ snprintf(nmbuf, sizeof nmbuf, "salsa20/%zu", lengths[li]);+ answer(nmbuf, outbuf, lengths[li] < 64 ? lengths[li] : 64);++ for (i = 0; i < sizeof pkey; i++) pkey[i] = (uint8_t)(i * 13 + 7);+ crypton_poly1305_init(&pctx, &pkey);+ crypton_poly1305_update(&pctx, buf, (uint32_t)lengths[li]);+ crypton_poly1305_finalize(mac, &pctx);+ snprintf(nmbuf, sizeof nmbuf, "poly1305/%zu", lengths[li]);+ answer(nmbuf, mac, sizeof mac);+ }+ }++ if (!generating && failures == 0)+ printf("ok %d answers match the little-endian ones\n", checked);+ else if (!generating)+ printf("FAIL %d of %d answers differ\n", failures, checked);+ fclose(vf);+ return failures != 0;+}
+ cbits/tests/endian/run.sh view
@@ -0,0 +1,50 @@+#!/bin/sh+# Does this C give the same answers on a big-endian machine?+#+# s390x and ppc64 are among the architectures the cabal file builds for, and+# neither is in the matrix. Eighteen files read their input through the+# loaders in crypton_align.h -- rewritten from word-typed casts to memcpy in+# #256 -- and eight more decide something from the byte order themselves.+#+# The two sides cannot be compared in one run the way the 32-bit harness+# compares two builds, because the machine doing the comparing has only one+# byte order. So the answers are frozen: vectors.txt is what this code gives+# on a little-endian host, and check mode reads it back.+#+# Usage: cbits/tests/endian/run.sh [generate] [build-dir]+set -eu++root=$(CDPATH= cd -- "$(dirname -- "$0")/../../.." && pwd)+mode=check+if [ "${1:-}" = generate ]; then mode=generate; shift; fi+out=${1:-$(mktemp -d)}+cc=${CC:-cc}+mkdir -p "$out"+cd "$root"++srcs="cbits/crypton_md4.c cbits/crypton_md5.c cbits/crypton_sha1.c+ cbits/crypton_sha256.c cbits/crypton_sha512.c cbits/crypton_sha3.c+ cbits/crypton_ripemd.c cbits/crypton_skein256.c cbits/crypton_skein512.c+ cbits/crypton_tiger.c cbits/crypton_whirlpool.c+ cbits/crypton_chacha.c cbits/crypton_salsa.c cbits/crypton_poly1305.c"++# Generating is done under the sanitizers, since a driver that writes out of+# bounds would otherwise freeze whatever it happened to leave behind. That+# is not hypothetical: sha3's context ends in a flexible buffer and the first+# draft of the driver put it on the stack as a plain struct.+san=+if [ "$mode" = generate ]; then+ san="-fsanitize=address,undefined -fno-sanitize-recover=all"+fi++# shellcheck disable=SC2086+$cc -O2 -g $san -Icbits -Icbits/include64 -o "$out/endian" \+ cbits/tests/endian/endian.c $srcs++if [ "$mode" = generate ]; then+ "$out/endian" generate cbits/tests/endian/vectors.txt+ echo "wrote $(wc -l < cbits/tests/endian/vectors.txt | tr -d ' ') answers"+ echo "commit cbits/tests/endian/vectors.txt"+else+ "$out/endian" check cbits/tests/endian/vectors.txt+fi
+ cbits/tests/endian/vectors.txt view
@@ -0,0 +1,252 @@+md4/0 31d6cfe0d16ae931b73c59d7e0c089c0+md4/1 47c61a0fa8738ba77308a8a600f88e4b+md4/3 5dc60555aff84f4f4d75c487477bd40e+md4/55 7fb3b8a921fbb273575603f44876e276+md4/56 150c4579f2a8f07aa321b3825b46cbf3+md4/63 a6fc40dc3217aaf3bdd437886ee24644+md4/64 e29ccc2f2131c0d40572b6dbf243369b+md4/65 9e8345b86c1dc8ed95f1a591bd01a02a+md4/111 815d46faeafcc449d668b476b28d16b4+md4/112 bb70170948d31fae99063ea7ce0be725+md4/127 c6f47dc12fd474f894fa9f51e043a109+md4/128 1379e209df9100a5b5c0d3c3068baf23+md4/129 bf3a7c34766fa54bfa6335e8fd2d89b5+md4/135 0985ede04e702bd38e6c10955120c3dc+md4/136 46e572e144b3130b4993660116ed1d29+md4/255 adc67d84a7b2ccfe7e5d541a4c55aaae+md4/256 1ef108f24aac5e2df49d8e692a68cfae+md4/1000 0ae32726214fc6eb8133de6ec0e3ab03+md5/0 d41d8cd98f00b204e9800998ecf8427e+md5/1 93b885adfe0da089cdf634904fd59f71+md5/3 ed41c1aca5ad5feb033df37822dae4b7+md5/55 c051c9637f919672c309560032dee7ab+md5/56 0f4e8d49afd96d05c011692366b0e92f+md5/63 39b5ef10a4f0648885ac75ec5fbfbd9e+md5/64 56bce76bade2e3259fd44ec9592893f3+md5/65 a41bf4e0f25f0705ead601e8f5481dd1+md5/111 39ffc0fb12a340f0f0cef28c7c5d73f2+md5/112 9330636dc725a2bea4026e2ffcbf5e01+md5/127 bb7911f7538cf8139325caf596135fa0+md5/128 89248d055d67dc618b5fa8e6a7936747+md5/129 e0295e53676fb80f77c499a6f747705d+md5/135 80c0d9601f6b0371c533d601deac9d15+md5/136 5d49aa8ae1bb7f6d426897800b281547+md5/255 38c3929ff959900de1f79decd32110ee+md5/256 def8272a2a5a237a4590c8abc83261c5+md5/1000 6d1e3c683bc932d465a43307a4dfb791+sha1/0 da39a3ee5e6b4b0d3255bfef95601890afd80709+sha1/1 5ba93c9db0cff93f52b521d7420e43f6eda2784f+sha1/3 75550941124b46eb4161d17ac200c05c4fc03ce7+sha1/55 4574696c8a057e3b8169f6946e96fe694ac1f63d+sha1/56 cc1ecce36813cd3f62aa8b6b00b9ca127619fc41+sha1/63 fa09a13f3c17facdcf2fe69a63023e5b5bdb7ab4+sha1/64 cb8d5827b951666a2fd890cea3fc5afbe527b6da+sha1/65 7264c8d694493c5f81fb537c6085387878aa1571+sha1/111 50d721885aca3ebeeaaec214d7bed12303fdbbb9+sha1/112 ecace0ac5661c929fbad2810d081988461f9375d+sha1/127 9039e73e76720f39656f5b10aa188d9135a0dd4e+sha1/128 cfb672f8266b134afdbc79b79988d9a2aa2c511f+sha1/129 f9ccb7eb40a100fa075f0f1992e61bc775d8c882+sha1/135 9cec88751569f9d70ef6bb764fac3a2f2ec93a51+sha1/136 2125c7780f72d171f651cdb70efa0f5011a45c1d+sha1/255 c9069eb027c7b6de5d2385779003c0c3b81152f4+sha1/256 d397a655930755132ebc094b6353b23dfee0f155+sha1/1000 7f0b25e59adefabd5323e7fba76def0018847494+sha256/0 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855+sha256/1 6e340b9cffb37a989ca544e6bb780a2c78901d3fb33738768511a30617afa01d+sha256/3 b361d0f9a938a2bb4fbdc9c21dc5a859788041b0040919d8a811c1888184f4df+sha256/55 8c9d785249c00ba19b5c8c6d0df51b3da614b8af732fe566909d47897f580f79+sha256/56 e458987ff5bc3a0e1d2d84fb1cab06a8d8e7bcec2d5b6fe43498280b93d65003+sha256/63 e3c8148d3ba2928b012cc55b325faa2d2bec48d319fed4ea2a3791150ebbfb60+sha256/64 e9c6e41c26bd6bedc6a8e61bc7a02b85818c632875643db2c5c5db65eac2d0b8+sha256/65 f0960adca320b44bc378b2839ad6b0dbfd2d7d98fb12802f7fb823ab9c424f93+sha256/111 ecf5dd1da8d2b562cbdb69e6714ad568483f1b0a5b79c65e07d4b1807190fc90+sha256/112 51221cdabbf22da7d38a3ec00200cd011bab7487bdf6947bb3356bc0c94bdea8+sha256/127 75df9f55cf2ec2201b5bdb9671df418dfd6b7fdcff8dd85b768872949ef0863c+sha256/128 fa52030abda28172c20bc098a70e13e4a764979b7f536a332f6ea29867c0dcb3+sha256/129 e08048e99eb6c53cb09d709071f1f1eda4d52cbfbff9dd4e756ce4c939a50498+sha256/135 4cf50d0a4148ed5147501e6ef09835c775da2ac903e0760288bdfa03454fa923+sha256/136 a571b968a9479df4ddb5bedcaa1cde191864b5fee12d969407056eeb2a39aeb0+sha256/255 eb6337ccc19a34a3ac4fb140185955cfaaab38440deb2ff87ed6f22ff1fa0239+sha256/256 0617cb171a31c804506afbbec540a7a1d17953017a883fc7ff2bc913d77bf2e7+sha256/1000 7fd5abf2b68d694aa89ca16c6a325450c83ad0b07cdbe3c86dbd55db684623b6+sha512/0 cf83e1357eefb8bdf1542850d66d8007d620e4050b5715dc83f4a921d36ce9ce47d0d13c5d85f2b0ff8318d2877eec2f63b931bd47417a81a538327af927da3e+sha512/1 b8244d028981d693af7b456af8efa4cad63d282e19ff14942c246e50d9351d22704a802a71c3580b6370de4ceb293c324a8423342557d4e5c38438f0e36910ee+sha512/3 9d1d055e0ac16db8b8b3b6c44692743b855129eb6b9fb9706ac623cf5c086ce4983ae494e5abeafc77a05e5e95f87c96bf8bd9434bccace808732165a43a6412+sha512/55 541042668dfe41adb3801f723e7c02886e5f1b4fda826bfe4d2ae2a2749ad9f2a764509f74018e8b050c6e822283546066fa6aa09389a50d4b66c0890ad146cd+sha512/56 a09c32a7c3a410c136ef656933a616366394455b85ec7ad284f1048d7472d68cea43de3df7f24b384ebcd724ee552325dfef830619022a189ef2c36fa702693c+sha512/63 4d6719f704edfd162acd129079a6692dfcbd99497394aa8703667288e3fca6bc1bc45f95616458ae43b7529ffd08d7b06aa5b5a8193051aeaec23cedc444dc96+sha512/64 dce432552c3db0b0628a924dd1fb617d7ccff63dd7643aaba7f0d97629c6c22cb8e9f24eea742b4aaa5b72f4772ca387a1175ef2bc3f6d2653b3a9479ef35fa5+sha512/65 0c627ddbf62632ac97c3b955db49181fec702992f0a0bd07b553f226075133db40532c90854b1447675ced18f950fa2a2207d6b6db1757b34374e0f5f3900a3b+sha512/111 993f2d3b273771809640eb7cd2f2830681faaec2d2ea91375b6467b5b04b0581e02262d9715201c7b5c1abcb3f5a9f64d4f2e8f18961a25153d3b6c99a81f501+sha512/112 186430ceef81d4724e1196c32a956fff9c11676064711432f9b828001c488cd3beaf8f35c3283887bbdbed1915c5dce0b298d9c88ccf8113ad5e1f0f6121993c+sha512/127 1dae2ca13d511448d2fda00b57f03481a3c01a51273c756f6dd4934a2c271f0096960b3188a2cf1c485327958785abdfcc876e17ad4f16a66d311a81270a8b40+sha512/128 dfe931ea5f331a50c1f2e2b8ef5e9d417bac976f13c1439a1655a134669a64d4f9c33ad540233a43796ea6266eae953a6b99d49fd88f27d4f342c0fe43ae42ca+sha512/129 eca5ea3ff8033c59d5a891c5d0e2cfb099d4cab8bcea7f4878342fa60a10f26cb3e570870932c69b6b3419e865f9dd4e0281a132861c54ea21947d3bbd599aa1+sha512/135 000bb1bda38edd5e935b1f4a865ff74cacc325af1c8485ddd04a0f4e3f859ac5c1733f32af5c6646cb94dbb4678d8704d022fbfcea8f2dbcbc41e5cdc5921fed+sha512/136 0b0ce141f1a6a6d27522b26a2683aac47b04e99d64e29472969391fe5521dd0d7e6898c84b007103ee908dc73f7acb7cb1c4a4d4b418aaa3edba51cdd9e3de60+sha512/255 45bf80a489f2579063e0890396d5bcbea66469e93ccf0e04cf933e7b10e7e9826ec0376d706b0f601599f69dc8629a1bdb4de1c9b03890ea0ac7889db258ffef+sha512/256 8e287890cf2beb5414ff4035dc579fc41b8d9ef21febb0a40e3d7c310f291ed3c2588a637bd314ea3b73ac398d0183a0dca8e4cc830cc59f39b9567427766bba+sha512/1000 8f61fbcd0e1f611d5f996c4c21002f9311ca0e4f4a101fd9843596a5693230e40e6f3fbe59bbdfd5ece955563234939d2a1ec809f6572ac06119f82a5c1a90e1+sha3-256/0 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a+sha3-256/1 5d53469f20fef4f8eab52b88044ede69c77a6a68a60728609fc4a65ff531e7d0+sha3-256/3 aa6c85d1a41110dd488f4a35719cf4bbcf2634d7c50401958ad41097096c7760+sha3-256/55 81fe59ad864db751440e1251d7792a74d1af93ff48e24b25b65639f97bf48bf2+sha3-256/56 129a430d7d7f2ad866b0da79f1c50a8a0f80f248c21a280eb3528cdff3b6f26c+sha3-256/63 d305b528e64c7e3c88cc1a937c152c169ad07871cb359e71f478ca6c1ad20c7e+sha3-256/64 c47f2570ff2e79c00bcbd0674a2ee9e0eed07c0c5db8c3a1aa68357aa39abe97+sha3-256/65 5b73115520ad1b600cae25ebdbd2510037ea11e158c7ec8d2b63b9945b32981a+sha3-256/111 2aa0850d3ed0fa9d5e8f00053f0f4f8248dc24577925d27c82e7584a49da39a9+sha3-256/112 c031eec2ab94c67081f5729f8718dc048d3a17daed923fc6d247f495ca66acf7+sha3-256/127 92927f72784017dfc937c60ced80e2bba7c59abe9367e8bbf95b76afd9123d04+sha3-256/128 10cab47e12f96037ac9d1d962a2031fd9e3bdf345cb5ae4827ae19ab1c50d077+sha3-256/129 fb32880265355aa1082038604b8b633933f16c650dd402546e5f92db425a6663+sha3-256/135 009f270e8f6dcaa6a7af6134429c49068a372ae93ed022bfd39eb665b3b226ee+sha3-256/136 efde869e19bad5db360fe59a0ea91abe35ea8e0fc87aadcef11d480cb63d1d7e+sha3-256/255 1998ee5adc07d9b0f3c87bb2520dac580b48cb1e65ee14959634f4e25e78618e+sha3-256/256 71d78d32c485425571f393927366001e60ea0d404be34137b9bfad1c065293d0+sha3-256/1000 671cf26630a648c48c2eee1125dbcdc3f0b0ee7ea5fa5e4311efe7b536db03ea+ripemd160/0 9c1185a5c5e9fc54612808977ee8f548b2258d31+ripemd160/1 c81b94933420221a7ac004a90242d8b1d3e5070d+ripemd160/3 1a51cd060324236aef3ca82f633638c3d34693f7+ripemd160/55 79dd03427a79bff167b170be1fd01edaa69c48da+ripemd160/56 8fd66d9a2808b45155c2532c5be09a49db1138b7+ripemd160/63 9fed7522e7537e1ec07d1d3fb04fe528b94db59d+ripemd160/64 bb8e58b9b697f8a6001318e6dd7b97fdb96cbbb2+ripemd160/65 9f4b683e9ffcef970435986daab885750258af82+ripemd160/111 c46b3c4192a0b9db5b6f327dca3d2979536a51b8+ripemd160/112 4146822be4f0fb524965b46e18b405400e4a077e+ripemd160/127 f000414f29cfd8c047cc4e00594ba4448baae0a1+ripemd160/128 2864a0a1a3f701a27dd29eb3b08e6eb98705e6da+ripemd160/129 5d12f9405bf021ac7edd672d9b05f0be6c40b5c3+ripemd160/135 87667a9b70214ed9552e049c9e173f774e7045a6+ripemd160/136 34e83a91054cac23d5bee365e346bd9592e3ad80+ripemd160/255 fd4fa53a24ed05cac5746fe7ad4a51aa7b0f906f+ripemd160/256 4d29394d45cb3a350fb04abfd7abefd98d5dbc71+ripemd160/1000 09d36b8fc9c87979223ad021c0e5bed386f1c502+skein256/0 c8877087da56e072870daa843f176e9453115929094c3a40c463a196c29bf7ba+skein256/1 34e2b65bf0be667ca5deba82c37cb253eb9f8474f3426ba622a25219fd182433+skein256/3 175623dce1b0cb69bed8a38af2ec2d8f81e2ca1edac0423bc765b90a89eb693f+skein256/55 acb6ea7280880ee8814bf2228fba49c9860bea7bcdd18f5fa9c93471d3af4585+skein256/56 87edff7a077c3a72ff2ad09dad290dcb156aaacf472d11451231cfb48577960d+skein256/63 3a74537a726a4987042e8cf3c285396b94cdca3297f3c618af0035efd2d77cd0+skein256/64 31e6401745b92aa5cabbb55a032b9285e9a978fd7ee0a7756903190bf31dffc2+skein256/65 ec66f99651b0d7d4cfead397b4d3d2284fe0d3cde3df2fc00f7faea0d5e83eb0+skein256/111 a67fc7fbb5babe99f92ccd808bf61af941a69ea064b01c145ab8b8a51c65dc83+skein256/112 c738917c7e782f30c1bb7af09e9593f5e12ba339353f10a12c83d9054bd81c53+skein256/127 c3ba1dfa5b9dd1e80a203026213e34b5408663a895f91a09e719f9dcb187f7b4+skein256/128 81188e87abc45684a64ca1591259830f758a5c8b11a7144a0c58fbab6923bd7e+skein256/129 f6c477673becfbbbdc6b6510649f94423b91d5b159181d8cdb4d60d5aadb9c9e+skein256/135 b5c7ba0a7265390af1982e3c61d15d30cf6f25b6c0452d6bbb932de85cf8d1fc+skein256/136 e982d50fc214234541c6b1779bacf6c6d592d6c88275635f3fe9f4517c04a3e9+skein256/255 e9a0544f7252e46be8e3dedf5a9db4f502f01183a6c593cf25e7fad93ac5e888+skein256/256 625327ea0bc0edcb43b70f0b979742cf223f55ae15bf021f3636d50141b23853+skein256/1000 23b8bbd0a122b07e9ccf552a0763e7aaead3ef25b74cea8282ea0c0fd24de7b9+skein512/0 bc5b4c50925519c290cc634277ae3d6257212395cba733bbad37a4af0fa06af41fca7903d06564fea7a2d3730dbdb80c1f85562dfcc070334ea4d1d9e72cba7a+skein512/1 40285f433699a1d8c799b276ccf18010c9dc9d418b0e8a4ed987b44c61c01c5ccbcc0977b1d34a4d3665d20e12716df934d208fea6607f74968ed86be3c99832+skein512/3 cf8bc9d2f25e5a8633d564fd73ffc76308819232a13a1dece60ce8e81651e5bd7569c95cb4b5772c1cfa885acadfdbab5bb94b28b01421770f278b1d8968c053+skein512/55 523aecc435dcb541f5be26dd5935132b1f40bc78abd8aaa2b87f29202837e3b55ad576ffeb1692a47b6e0c5a2bb0fb669262751900dcf5c63dd654043ed934a7+skein512/56 81641af4c81d0f52f0345c1e742a8c52a28fc09b22ad132c5599fb50c77f5c4f310d3a213fe7a1768711df13361a60c67e0ab6587592b30aa01433a79b134260+skein512/63 5aa0c9c865d56c0dc8e6430290d3e3d6c785912c1ec2961dc4a928efefe4faa4711ae95b976db1b3d1af33cb4992dd84e35ce204371d357fc03754f9eb3dc25b+skein512/64 2ebf29904f1d770a56fa50408927dc948bb28bed094aa735940653b204b2e23adb18932893cb4f927be7d0b86eed144f7cbccb02afacb47c834b4fdcafce5dac+skein512/65 debfe997c41e391d00143289d49c807b1b763569b29b013ff58b015172859eaa202b223f17c357506765c2ec43f561c339d7b184b1982c1d44a3c4b3933f8d62+skein512/111 f338e3b93dea8713b80f3d4f61f7cea1bb6b3c71ba90b0798e5178ba0c6431c68e34c6a6759c0c1181ab5ca765c17d3a200b4a440c262b92e2158b87a5576908+skein512/112 4d6372e5f65a3462730a9db06eda6b6e2b35672abbc624cba58ec17440bd0d922a25d5923685d4625ca955c88da134353df92638d5cd3c3f9f1500138c639191+skein512/127 c9094df9b9e0bfdb94a36b291fa26150a7d0ab2d5c90e9364c58ee1144eee6c8939333ed796af9ee0f84286f46748002cca1a9c9a6f84f3d3a71fa6562afece1+skein512/128 9a69ca7d3222bb63d0ffa9b153ec118356e8c18b59adfb23376836b2d9f1a4684117000594261c91fbfef549f188cf831bbd27142b5af4df8be1f80ca0490d9b+skein512/129 cbef633515a50c561518d1a7a200de7cb269ea17a2861a852d65002562174a5b471adbd0e45ab4317827b2756f2be2b897da906456a062927d9e14839eae7ede+skein512/135 116b23ac95a0b499a62e571703f43af7e79c8de5450bc793964cdd1c64158eaa7ec463ce67ab1b3fd23c5b653ffa09015efbc225f753c0a5964687a16c25fe30+skein512/136 12bc711a66f7f09f7ad2994e666c7064c3c9a1695a8fe6bc0092cf035e11192aab53c006e409449f0971fd68f4248253477d099ba2d85a4ada064bbe91c53558+skein512/255 dd7f2f871bcdd425b07c691325b808aca79551e661dc9a72b95d5f059ae0c1e7039f64d10bea14b4c2fc251e5a7ce11b4e9400503fd7e3684d4eefcf2ceca425+skein512/256 234270864103c6fed1dc8249bf6c91f5660f5438a6cec17c8f97dfbcde0e4a9ffc3a971f4e23d58db01fab96621a13f41ca4914883f7a149401a3d347161532c+skein512/1000 3631c9fcf9af7bd2c9e6b474bf56de55261f002c5a2d0ecb478a6024a56366efba38e4b6936d3a5cdc8f7800dc39250520dded0b3583719c2b3159a9ea326b25+tiger/0 3293ac630c13f0245f92bbb1766e16167a4e58492dde73f3+tiger/1 5d9ed00a030e638bdb753a6a24fb900e5a63b8e73e6c25b6+tiger/3 53b5b6bd6bab3c1c63a8d8c62572e9a3502eae8e80d2143d+tiger/55 3aa4132b6dce81714c8b76a2b69eb25a870ca99101196d4b+tiger/56 28a5e8fd6f9b87ec0b9d2e46a94c9663dbe7d81eefb3fe48+tiger/63 f919691beddf54789d147663465b2ec8f93d7c3999504aa1+tiger/64 ff2896adeb7883a369da8e71ffa30c6ae0892bd7e4f3b943+tiger/65 7d72e2840ba3895c4bfc9120daf8858f48741fb5dc64e4ce+tiger/111 e30fec5c5b5e862b7b085fa7f71c3e6d687fac374149beb7+tiger/112 0e8f76b3168b6ce849055b405685334c75c6e10fa0ee3727+tiger/127 01287abaaa42f9150c6fa88dc921fb061a564b6371f67dba+tiger/128 4a4c0ee2b099109011e95568165ab9216fd2987c0f852a38+tiger/129 628843804c1769616bc717659fdcf6d21a73f0e6a0ea1eca+tiger/135 ad945cec97c5ec4565d2f5ebe5d28c297cadc3f90b072526+tiger/136 322c7537dac6383fe8b55d4fcdd4888574601cd5123b511f+tiger/255 2bdd7d685a587f31bf202cfd2e1d90e5d53d043b66e773f2+tiger/256 d8adfc2e0f57a67f8088edb54e2b1f8a93783ffc5aa17833+tiger/1000 79b772b89f0536af5cf5f34b26ce13ced821d05b468dcdce+whirlpool/0 19fa61d75522a4669b44e39c1d2e1726c530232130d407f89afee0964997f7a73e83be698b288febcf88e3e03c4f0757ea8964e59b63d93708b138cc42a66eb3+whirlpool/1 4d9444c212955963d425a410176fccfb74161e6839692b4c11fde2ed6eb559efe0560c39a7b61d5a8bcabd6817a3135af80f342a4942ccaae745abddfb6afed0+whirlpool/3 a83205596a19327369464c5a98896a274ebea82da9ff93e69ddde9eb7ee90757a2173fd3bf10f6d2b7c241acd0ac23f5f1b414b51d33b26f75e63831f303324f+whirlpool/55 ad06ca5facbc8457391c279446818876cc2302eaddd9d39576aa39dff825fa9d0fe455bb245c260b7b7672193607cefbefb41a18706fd2fac2a7e1a2fb8f0cfa+whirlpool/56 6b9e3c1a6714ba482d06f5da0f11c85bb7436f7aebc334e3aeb36745b4cb5d561b27fab0bd59979ede3cca617610c9dccbd0a41b1779e2875ca75761c68e43c0+whirlpool/63 67da72d6fa8713cba84cca7be5ac53f8ab9d3551a934c7f3376ecebd468d944359772aa83005d815ff74bc26dfe6f22ebbb299b13fbe8f899961d471c76ce871+whirlpool/64 d893e82c6bf61b2423e8c09e0308d7776b1b1d9556b629cac8c4b82508d6b11891cd2a31312b5d01b640a70acbf94c44c546cdb17389b006943bce62a1e9bd83+whirlpool/65 6d4593ad291898521736fc63d758a5d5789d9fa3b521cd188f191cd5899b14669006d1d8e6611baa5f782e65aa3d46c47b734b6feca0041a3ada84741e4a57e8+whirlpool/111 87c6b4fc91580b9ad15689f0e7a9c5378b13646ede124af2cb3cb8124a74e64946214720669f0e2fbd1f23b62980f8d3f19ecda1d26723f7a12f4bef2c6082c4+whirlpool/112 94826949d4fda3d38d1627bc667261460c8b46e7a11fd24de6116643059e6e02d8271af809e4a4535fd4de8af11c13efad4cea8afe1c348deb10b7c362fd5f23+whirlpool/127 008f8b8b3dffba832750f542b2a6a3f8ff81547d48715851116c20e475f93893fc7e4ed7a2feaf7595e26b30fde6805335a326b70591ca6d913b66961ea8c5a5+whirlpool/128 c6dc5ef8e9f449b75b35875c043def87c37ff7f8078044f6cd020fcd311fa5655ba433ef9fd4b6007a0f310f88f63aaba0649175ceb851b0537856c1adf43fa6+whirlpool/129 2f53c6ddab30118a451bd8dee8e12ee7443e8f3a4132453cc5d74948c008048b5b99ce51f2795e158d0758ccaa6db80f6f1d876533336f7d41f7a098512eb2ca+whirlpool/135 5835a5cfd59d0f75b0af7ee2b667adcf66168dd6d3f710d895211802e8798fa80a6bcaf05f63473245227332d3983fd6580bc90afd56caebe7470ed95c37b081+whirlpool/136 0356408b498a01e39ea4966dffc809df366747b79fce4c978bd4cc59c7d6765910b88cfea9ac63b1fc1720bee5c45efb51b22cf7047203f0840076d3c2eb2b24+whirlpool/255 23a0a3cea1f2d971c467993b40582618a8b75acbb6c3bd7fd76e93ae8d0cd8a6797838daffb13cb21ebb07f8ed3729c77abf83ad4c17c2a5866b46bfd327e1f6+whirlpool/256 e13d036a12baf02ddcb79354e0e4b6e808eed3102864591d57250fbdfc7822208771af0d0a99b65d355c1c05cd09f57874c14bf1731ecaa24350596d1db0b7ad+whirlpool/1000 10d2452c3f4d5c4e124cc6e4542c258d7c122da116650fdd894a599df8bd9673b801301794560c2d2b186d131e46a0e4ddf765590b33a1638351727fa9104f27+chacha20/0 -+salsa20/0 -+poly1305/0 d7e4f1fe0b1825323f4c596673808d9a+chacha20/1 06+salsa20/1 9e+poly1305/1 e1eb05201a506d8741b8d5ef79203e58+chacha20/3 064429+salsa20/3 9ee7f7+poly1305/3 453fee0552873db241b6aa62a2c52813+chacha20/55 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dd+salsa20/55 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b+poly1305/55 269c983cc75a974291409f4ae5d403cc+chacha20/56 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc+salsa20/56 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b02+poly1305/56 02b5d7816f3c5bb108e08629f814cce3+chacha20/63 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bc+salsa20/63 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae+poly1305/63 9f0dcc8932e4f6637ee198bf2c8000d6+chacha20/64 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/64 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/64 6da04a74098654ca6392a1c62040b4cf+chacha20/65 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/65 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/65 db28069b3ca255821238da8b086fe27a+chacha20/111 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/111 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/111 f10eb1e2364e6ed3ccc9326d9e56ed64+chacha20/112 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/112 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/112 183852995a777f1af0f29760c17fa63a+chacha20/127 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/127 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/127 234fcf18eb82f1b2821f113a22fab7f9+chacha20/128 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/128 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/128 3f8f2a778d4f490bb17809b1dcdf50e5+chacha20/129 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/129 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/129 e3fe11911fea16b2b3bf2be93d22c7d7+chacha20/135 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/135 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/135 4520d5997340683ccd21a2804631d700+chacha20/136 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/136 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/136 848568032e1e248045e53031e8219393+chacha20/255 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/255 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/255 8ae46792e840f083d98f7e78f34a8f9d+chacha20/256 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/256 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/256 427f7cd821633cc0993956cf3a7cf26c+chacha20/1000 064429ccbd6ef85054af07f8dee3a283e75e844df9a59b1b76addd7d41fb554946f5dd12b49b97f4a72f05b0b41c557e8c69da034ae9dddc8a54dbf245d2bcff+salsa20/1000 9ee7f7b5774db507d8e78fe7398594de9b40444a5301c14dfbc675e6310f9aa659e9cca9892563df9386a60607a2e18781d35d4897ea2b029db7b8819cafae17+poly1305/1000 c403a63071ea2f2e732472db8e7b79c0
+ cbits/tests/fuzz/README view
@@ -0,0 +1,35 @@+Generated bytes fed to the code that parses what comes off the wire.++Rounds one to ten asked prepared questions. This one asks whether anything+breaks on input nobody chose. What is looked for is memory safety rather+than wrong answers: these inputs are meant to be rejected, and the question is+how they are rejected.++The harnesses are the places where bytes from elsewhere are taken apart:++ ed25519 a public key and a signature, both the sender's to choose+ decaf point decoding, EdDSA public key decoding, Ed448 verification+ p256 a point checked for being on the curve, then multiplied+ aead AES-GCM decryption, with the iv, aad and tag lengths from the wire+ canary the calibration++fuzz_canary reads one byte past a buffer when the input opens with four+particular bytes. Four is the point: one chance in 2^32 puts it out of reach+of throwing random input at the harness, and well within reach of a fuzzer+that watches which comparisons it got past. So a campaign that does not+report the canary is not exploring, and the silence of the others would mean+nothing. Round five believed a ThreadSanitizer zero that meant nothing and+round ten twice believed a scrubbing zero that meant nothing; this is cheaper+than learning it a third time.++The corpus is seeded with inputs each harness accepts -- a signature that+verifies, the same with one bit of the message moved, a point that is on the+curve, a ciphertext that authenticates -- so that a campaign starts from the+far side of the checks rather than in front of them. They were generated by+running the primitives, and checked: the valid signature verifies, the+tampered one does not, the point is on the curve.++Where clang has no libFuzzer runtime -- Apple's does not -- run.sh replays the+corpus and a deterministic stream through standalone.c instead. That says the+harnesses build and run clean under the sanitizers. It explores nothing, and+it says so rather than reporting a pass.
+ cbits/tests/fuzz/corpus/aead-authentic.bin view
binary file changed (absent → 55 bytes)
+ cbits/tests/fuzz/corpus/ed25519-tampered.bin view
binary file changed (absent → 104 bytes)
+ cbits/tests/fuzz/corpus/ed25519-valid.bin view
binary file changed (absent → 104 bytes)
+ cbits/tests/fuzz/corpus/p256-on-curve.bin view
binary file changed (absent → 96 bytes)
+ cbits/tests/fuzz/fuzz.h view
@@ -0,0 +1,34 @@+/* Feeding generated bytes to the code that parses what comes off the wire.+ *+ * Each harness is an LLVMFuzzerTestOneInput, so a real fuzzer drives it.+ * Where there is no fuzzer -- Apple's clang ships no libFuzzer runtime --+ * standalone.c supplies a main that replays the committed corpus and then a+ * deterministic stream of its own, which says the harness is wired up+ * correctly and nothing about coverage.+ *+ * What is being looked for is memory safety, not wrong answers: these inputs+ * are meant to be rejected, and the question is how they are rejected.+ */+#ifndef CRYPTON_TESTS_FUZZ_H+#define CRYPTON_TESTS_FUZZ_H++#include <stdint.h>+#include <stddef.h>+#include <string.h>++int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size);++/* Carve a fixed-width field out of the input. Short input means the harness+ * returns rather than reading past the end, which is the harness's own bug to+ * avoid and not the library's to report. */+static int fz_take(const uint8_t **p, size_t *left, void *out, size_t n)+{+ if (*left < n)+ return 0;+ memcpy(out, *p, n);+ *p += n;+ *left -= n;+ return 1;+}++#endif
+ cbits/tests/fuzz/fuzz_aead.c view
@@ -0,0 +1,60 @@+/* AES-GCM decryption, where the lengths and the tag are the sender's to+ * choose. The key is not attacker-controlled and is fixed here; what varies+ * is everything that arrives with the message. */+#include "tests/fuzz/fuzz.h"+#include <stdlib.h>+#include "crypton_aes.h"++int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)+{+ static const uint8_t key[16] = {+ 0x9e, 0x37, 0x79, 0xb9, 0x7f, 0x4a, 0x7c, 0x15,+ 0xf3, 0x9c, 0xc0, 0x60, 0x5c, 0xed, 0xc8, 0x34,+ };+ aes_key k;+ aes_gcm_key gk;+ uint8_t ivlen, aadlen, taglen;+ const uint8_t *p = data;+ size_t left = size;+ uint8_t *out;++ if (!fz_take(&p, &left, &ivlen, 1))+ return 0;+ if (!fz_take(&p, &left, &aadlen, 1))+ return 0;+ if (!fz_take(&p, &left, &taglen, 1))+ return 0;++ /* the three lengths are the sender's, so they are taken as they come,+ * short of asking for more bytes than arrived */+ if (left < (size_t)ivlen + aadlen)+ return 0;+ taglen = (uint8_t)(taglen % 17); /* 0..16, as the API allows */++ {+ const uint8_t *iv = p;+ const uint8_t *aad = p + ivlen;+ const uint8_t *ct = p + ivlen + aadlen;+ size_t rest = left - ivlen - aadlen;+ const uint8_t *tag;+ size_t ctlen;++ /* the tag arrives with the message, so it comes off the end */+ if (rest < taglen)+ return 0;+ ctlen = rest - taglen;+ tag = ct + ctlen;++ out = (uint8_t *)malloc(ctlen + 1);+ if (!out)+ return 0;+ crypton_aes_initkey(&k, (uint8_t *)key, sizeof key);+ crypton_aes_gcm_key_init(&gk, &k);+ (void)crypton_aes_gcm_full_decrypt(out, &gk, &k, (uint8_t *)iv, ivlen,+ (uint8_t *)aad, aadlen,+ (uint8_t *)ct, (uint32_t)ctlen,+ tag, taglen);+ free(out);+ }+ return 0;+}
+ cbits/tests/fuzz/fuzz_canary.c view
@@ -0,0 +1,41 @@+/* The calibration. This harness reads one byte past a buffer when the input+ * opens with a four-byte marker. Four bytes is the point: one chance in+ * 2^32 puts it out of reach of throwing random input at the harness, while a+ * fuzzer that watches which comparisons it got past finds it in seconds. So+ * a campaign that does not report this one is not fuzzing, and the silence of+ * the harnesses beside it means nothing.+ *+ * Round five believed a ThreadSanitizer zero that meant nothing, and round+ * ten twice believed a scrubbing zero that meant nothing. This is cheaper+ * than learning it a third time.+ *+ * Replaying the corpus is not expected to reach it, and run.sh says so.+ */+#include "tests/fuzz/fuzz.h"+#include <stdlib.h>++int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)+{+ uint8_t *buf;+ int r;++ if (size < 5)+ return 0;+ if (data[0] != 0xde || data[1] != 0xad)+ return 0;+ if (data[2] != 0xbe || data[3] != 0xef)+ return 0;++ /* On the heap, not the stack. A compiler that can see the size of a+ * local can also see that reading past it is undefined and remove the+ * read, which is what the first attempt at this did: the campaign found+ * nothing because by then there was nothing left to find. It cannot+ * reason that way about what malloc returned. */+ buf = (uint8_t *)malloc(16);+ if (!buf)+ return 0;+ memset(buf, 0, 16);+ r = buf[16] == data[4] ? 1 : 0; /* deliberately one past the end */+ free(buf);+ return r;+}
+ cbits/tests/fuzz/fuzz_decaf.c view
@@ -0,0 +1,40 @@+/* Decoding a point and verifying an Ed448 signature, both from bytes that+ * came from somewhere else. point_decode validates; the EdDSA decode is the+ * first thing a verifier does with a public key. */+#include "tests/fuzz/fuzz.h"+#include "decaf/point_448.h"+#include "decaf/ed448.h"++int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)+{+ uint8_t ser[CRYPTON_DECAF_448_SER_BYTES];+ uint8_t pub[CRYPTON_DECAF_EDDSA_448_PUBLIC_BYTES];+ uint8_t sig[CRYPTON_DECAF_EDDSA_448_SIGNATURE_BYTES];+ crypton_decaf_448_point_t pt;+ const uint8_t *p = data;+ size_t left = size;+ uint8_t selector;++ if (!fz_take(&p, &left, &selector, 1))+ return 0;++ if (selector & 1) {+ if (!fz_take(&p, &left, ser, sizeof ser))+ return 0;+ (void)crypton_decaf_448_point_decode(pt, ser, selector & 2 ? 1 : 0);+ return 0;+ }++ if (!fz_take(&p, &left, pub, sizeof pub))+ return 0;+ if (selector & 2) {+ (void)crypton_decaf_448_point_decode_like_eddsa_and_mul_by_ratio(pt, pub);+ return 0;+ }+ if (!fz_take(&p, &left, sig, sizeof sig))+ return 0;+ /* a context of at most 255 bytes, as the API takes a uint8_t length */+ (void)crypton_decaf_ed448_verify(sig, pub, p, left, selector & 4 ? 1 : 0,+ NULL, 0);+ return 0;+}
+ cbits/tests/fuzz/fuzz_ed25519.c view
@@ -0,0 +1,22 @@+/* Ed25519 signature verification: the public key and the signature are both+ * whatever the sender chose, and both are decoded before anything is+ * checked. */+#include "tests/fuzz/fuzz.h"+#include "ed25519/ed25519.h"++int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)+{+ ed25519_public_key pk;+ ed25519_signature sig;+ const uint8_t *p = data;+ size_t left = size;++ if (!fz_take(&p, &left, pk, sizeof pk))+ return 0;+ if (!fz_take(&p, &left, sig, sizeof sig))+ return 0;++ /* whatever is left is the message */+ (void)crypton_ed25519_sign_open(p, left, pk, sig);+ return 0;+}
+ cbits/tests/fuzz/fuzz_p256.c view
@@ -0,0 +1,33 @@+/* A P-256 point as it arrives: two field elements, checked for being on the+ * curve, and then multiplied if they are. */+#include "tests/fuzz/fuzz.h"+#include "p256/p256.h"++void crypton_p256e_point_mul(const crypton_p256_int *n,+ const crypton_p256_int *ix, const crypton_p256_int *iy,+ crypton_p256_int *ox, crypton_p256_int *oy);++int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size)+{+ uint8_t xb[P256_NBYTES], yb[P256_NBYTES], nb[P256_NBYTES];+ crypton_p256_int x, y, n, ox, oy;+ const uint8_t *p = data;+ size_t left = size;++ if (!fz_take(&p, &left, xb, sizeof xb))+ return 0;+ if (!fz_take(&p, &left, yb, sizeof yb))+ return 0;+ if (!fz_take(&p, &left, nb, sizeof nb))+ return 0;++ crypton_p256_from_bin(xb, &x);+ crypton_p256_from_bin(yb, &y);+ crypton_p256_from_bin(nb, &n);++ if (crypton_p256_is_valid_point(&x, &y)) {+ crypton_p256_mod(&crypton_SECP256r1_n, &n, &n);+ crypton_p256e_point_mul(&n, &x, &y, &ox, &oy);+ }+ return 0;+}
+ cbits/tests/fuzz/run.sh view
@@ -0,0 +1,132 @@+#!/bin/sh+# Generated bytes fed to the code that parses what comes off the wire.+#+# Each harness is an LLVMFuzzerTestOneInput. With a clang that has the+# libFuzzer runtime, each gets a bounded campaign under ASan and UBSan; with+# one that does not -- Apple's, for instance -- standalone.c replays the+# corpus and a deterministic stream instead, which says the harnesses are+# wired up and nothing about coverage, and says so.+#+# fuzz_canary reads one byte past a buffer when the input opens with four+# particular bytes. One chance in 2^32 puts that out of reach of random+# input and well within reach of a fuzzer that watches which comparisons it+# got past, so a campaign that does not report it is not fuzzing, and the+# silence of the others would mean nothing.+#+# Usage: cbits/tests/fuzz/run.sh [seconds-per-harness] [build-dir]+set -eu++root=$(CDPATH= cd -- "$(dirname -- "$0")/../../.." && pwd)+secs=${1:-30}+out=${2:-$(mktemp -d)}+cc=${CC:-cc}+mkdir -p "$out"+cd "$root"++D=cbits/decaf+san="-fsanitize=address,undefined -fno-sanitize-recover=all"++sources_for() {+ case $1 in+ canary) echo "" ;;+ ed25519) echo "cbits/ed25519/ed25519.c cbits/crypton_sha512.c" ;;+ p256) echo "cbits/p256/p256.c cbits/p256/p256_ec.c" ;;+ aead) echo "cbits/crypton_aes.c cbits/aes/generic.c cbits/aes/gf.c" ;;+ decaf) echo "$D/ed448goldilocks/decaf_all.c $D/ed448goldilocks/eddsa.c+ $D/ed448goldilocks/scalar.c $D/p448/f_arithmetic.c+ $D/p448/f_generic.c $D/utils.c+ $D/p448/arch_ref64/f_impl.c cbits/crypton_sha3.c" ;;+ esac+}+includes_for() {+ case $1 in+ ed25519) echo "-Icbits/ed25519" ;;+ decaf) echo "-DCRYPTON_DECAF_WORD_BITS=64 -I$D/include -I$D/p448+ -I$D/include/arch_ref64 -I$D/p448/arch_ref64" ;;+ *) echo "" ;;+ esac+}++# Is there a libFuzzer to drive these?+have_fuzzer=no+printf '#include <stdint.h>\n#include <stddef.h>\nint LLVMFuzzerTestOneInput(const uint8_t *d, size_t n){(void)d;(void)n;return 0;}\n' \+ > "$out/probe.c"+if $cc -fsanitize=fuzzer,address -o "$out/probe" "$out/probe.c" 2>/dev/null; then+ have_fuzzer=yes+fi++status=0+harnesses="canary ed25519 decaf p256 aead"++for h in $harnesses; do+ # shellcheck disable=SC2046,SC2086+ $cc -O1 -g $san $(test $have_fuzzer = yes && echo -fsanitize=fuzzer) \+ -Icbits -Icbits/include64 $(includes_for $h) \+ -o "$out/fuzz_$h" "cbits/tests/fuzz/fuzz_$h.c" \+ $(test $have_fuzzer = no && echo cbits/tests/fuzz/standalone.c) \+ $(sources_for $h) 2> "$out/$h.cc" || {+ echo "FAIL $h did not build"; sed -n '1,12p' "$out/$h.cc"; status=1; continue+ }++ if [ $have_fuzzer = no ]; then+ "$out/fuzz_$h" cbits/tests/fuzz/corpus 20000 > "$out/$h.log" 2>&1 || true+ if grep -qE "ERROR: |runtime error:" "$out/$h.log"; then+ echo "FOUND $h: the sanitizers reported on replayed input"+ grep -m1 -E "ERROR: |runtime error:" "$out/$h.log" | sed 's/^/ /'+ status=1+ else+ echo "ran $h ($(tail -1 "$out/$h.log"))"+ fi+ continue+ fi++ mkdir -p "$out/corpus-$h"+ cp cbits/tests/fuzz/corpus/* "$out/corpus-$h/" 2>/dev/null || true+ # -use_value_profile records the operands of comparisons, which is how a+ # fuzzer gets past a check for particular bytes rather than waiting for+ # them to come up at random. The canary is exactly that check, and the+ # parsers here are full of them.+ "$out/fuzz_$h" "$out/corpus-$h" -max_total_time="$secs" \+ -use_value_profile=1 -print_final_stats=1 \+ > "$out/$h.log" 2>&1 || true++ # What a find looks like. AddressSanitizer writes "ERROR:", but+ # UndefinedBehaviorSanitizer writes "runtime error:" and nothing else,+ # so a detector that waits for "ERROR:" reads a campaign that found the+ # canary as one that found nothing -- which is what the first three+ # attempts at this file did. libFuzzer's own line is the one that+ # covers every case: it writes the input out whatever reported.+ found=no+ grep -qE "Test unit written to|ERROR: |runtime error:|deadly signal" \+ "$out/$h.log" && found=yes++ if [ "$h" = canary ]; then+ if [ $found = no ]; then+ echo "FAIL canary: the harness that reads out of bounds on a"+ echo " four-byte marker was not found in ${secs}s, so this"+ echo " campaign is not exploring and nothing below counts."+ echo " What it did do:"+ tail -12 "$out/$h.log" | sed 's/^/ /'+ status=1+ else+ echo "ok canary: found, so the campaign explores"+ fi+ continue+ fi++ if [ $found = yes ]; then+ echo "FOUND $h: the sanitizers reported"+ grep -m1 -E "ERROR: |runtime error:|deadly signal" "$out/$h.log" |+ sed 's/^/ /'+ sed -n '/#0 /,/#8 /p' "$out/$h.log" | head -12 | sed 's/^/ /'+ status=1+ else+ echo "ok $h: $(grep -oE 'stat::number_of_executed_units: *[0-9]+' \+ "$out/$h.log" | grep -oE '[0-9]+' | tail -1) inputs, nothing reported"+ fi+done++if [ $have_fuzzer = no ]; then+ echo "skip $cc has no libFuzzer, so the corpus was replayed and nothing explored"+fi+exit $status
+ cbits/tests/fuzz/standalone.c view
@@ -0,0 +1,66 @@+/* A main for the harnesses, for where there is no fuzzer.+ *+ * Apple's clang ships no libFuzzer runtime, so this replays the committed+ * corpus and then a deterministic stream of generated inputs. That says the+ * harness is wired up and that the sanitizers are clean on what it feeds --+ * it is not a fuzzing campaign and does not explore anything. The campaign+ * runs in CI, where clang has the runtime.+ */+#include <stdio.h>+#include <stdlib.h>+#include <string.h>+#include <stdint.h>+#include <dirent.h>++int LLVMFuzzerTestOneInput(const uint8_t *data, size_t size);++static uint64_t s0 = 0x243f6a8885a308d3ULL, s1 = 0x13198a2e03707344ULL;+static uint64_t rnd(void)+{+ uint64_t x = s0, y = s1;+ s0 = y;+ x ^= x << 23;+ s1 = x ^ y ^ (x >> 17) ^ (y >> 26);+ return s1 + y;+}++int main(int argc, char **argv)+{+ static uint8_t buf[4096];+ long rounds = argc > 2 ? strtol(argv[2], NULL, 10) : 20000;+ long i;+ int replayed = 0;++ if (argc > 1) {+ DIR *d = opendir(argv[1]);+ struct dirent *e;+ if (d) {+ while ((e = readdir(d)) != NULL) {+ char path[1024];+ FILE *f;+ size_t n;+ if (e->d_name[0] == '.')+ continue;+ snprintf(path, sizeof path, "%s/%s", argv[1], e->d_name);+ f = fopen(path, "rb");+ if (!f)+ continue;+ n = fread(buf, 1, sizeof buf, f);+ fclose(f);+ LLVMFuzzerTestOneInput(buf, n);+ replayed++;+ }+ closedir(d);+ }+ }++ for (i = 0; i < rounds; i++) {+ size_t n = (size_t)(rnd() % sizeof buf);+ size_t j;+ for (j = 0; j < n; j++)+ buf[j] = (uint8_t)(rnd() >> 24);+ LLVMFuzzerTestOneInput(buf, n);+ }+ printf("replayed %d corpus input(s), then %ld generated\n", replayed, rounds);+ return 0;+}
+ cbits/tests/perf/floors.txt view
@@ -0,0 +1,22 @@+# A primitive that falls off its accelerated path does not get a little+# slower, it falls off a cliff: #274 took SHA-256 from 3396 MB/s to 644 on an+# Apple M4, a factor of five, and no test noticed because the answers stayed+# right.+#+# Absolute numbers cannot be checked here. ubuntu-latest is not one machine+# -- EPYC 7763, EPYC 9V74, Xeon 8370C and Xeon 6973P-C have all turned up, and+# the ones with AVX-512 differ from the ones without by more than twofold on+# AES-GCM. So each line is a ratio between two primitives measured in the+# same run on the same machine, with a floor generous enough that only a cliff+# reaches it.+#+# faster slower floor what it would catch+#+# Measured for the floors: an M4 gives 1.00, 0.56, 4.04 and 0.58 for the four+# below; an EPYC 7763 gives 0.94, 0.46, 2.75 and 0.55. Every floor is less+# than half of both, and #274 put the first at 0.19.++sha256 sha1 0.40 SHA-256 off the SHA-2 instructions+sha512 sha1 0.20 SHA-512 off its assembly+aes128gcm chachapoly 1.00 AES-GCM off AES-NI or the ARMv8 AES instructions+sha3-256 sha512 0.25 SHA-3 off the SHA-3 instructions
+ cbits/tests/perf/run.sh view
@@ -0,0 +1,102 @@+#!/bin/sh+# Watching for a primitive that has fallen off its accelerated path.+#+# #274 took SHA-256 from 3396 MB/s to 644 on an Apple M4 and shipped, because+# the answers were right and only the speed was wrong. No test can catch+# that; this is what does.+#+# What it checks is ratios between primitives measured in the same run, not+# absolute throughput, because the runner is not the same machine twice --+# see cbits/tests/perf/floors.txt. A ratio is only useful against a cliff;+# this will not notice a few per cent, and is not meant to.+#+# The last thing it does is build the library again with the AES acceleration+# turned off and check that the AES line then fails. Without that, a run+# where the measurement had quietly stopped working would look exactly like a+# run where everything was fast.+#+# Usage: cbits/tests/perf/run.sh [build-dir]+set -eu++root=$(CDPATH= cd -- "$(dirname -- "$0")/../../.." && pwd)+out=${1:-$(mktemp -d)}+cc=${CC:-cc}+mkdir -p "$out"+cd "$root"++# The harness links against the library as cabal built it, so that what is+# measured is the configuration the package actually ships.+build_harness() {+ builddir=$1; bin=$2; shift 2+ cabal build lib:crypton --builddir="$builddir" -v0 "$@" > /dev/null+ archive=$(find "$builddir" -name 'libHScrypton-*.a' | head -1)+ test -n "$archive" || { echo "no library archive under $builddir"; exit 1; }+ $cc -O3 -Icbits -Icbits/include64 -Icbits/include32 \+ -o "$bin" cbits/tests/perf/throughput.c "$archive" 2>/dev/null ||+ $cc -O3 -Icbits -Icbits/include64 \+ -o "$bin" cbits/tests/perf/throughput.c "$archive"+}++measure() {+ best=0+ for _ in 1 2 3; do+ v=$("$1" "$2" 2>/dev/null || echo 0)+ best=$(awk -v a="$best" -v b="$v" 'BEGIN{print (b>a)?b:a}')+ done+ echo "$best"+}++# Every ratio in floors.txt, against the binary named. Prints one line each+# and returns the number that were under the floor.+check() {+ bin=$1; label=$2; quiet=${3:-no}+ bad=0+ while read -r fast slow floor _rest; do+ case "$fast" in ''|\#*) continue ;; esac+ a=$(measure "$bin" "$fast")+ b=$(measure "$bin" "$slow")+ r=$(awk -v a="$a" -v b="$b" 'BEGIN{printf "%.2f", (b>0)?a/b:0}')+ under=$(awk -v r="$r" -v f="$floor" 'BEGIN{print (r<f)?1:0}')+ if [ "$under" = 1 ]; then+ bad=$((bad + 1))+ [ "$quiet" = yes ] ||+ printf 'BELOW %-10s %-11s %s / %s = %s, floor %s\n' \+ "$fast" "$slow" "$a" "$b" "$r" "$floor"+ else+ [ "$quiet" = yes ] ||+ printf 'ok %-10s %-11s %s / %s = %s, floor %s\n' \+ "$fast" "$slow" "$a" "$b" "$r" "$floor"+ fi+ done < cbits/tests/perf/floors.txt+ return $bad+}++build_harness "$out/dist-perf" "$out/throughput"+set +e+check "$out/throughput" "as shipped"+failed=$?+set -e++# The calibration: with the AES acceleration compiled out, the AES line has to+# fail. If it does not, the measurement is not reaching the library and+# nothing above meant anything.+echo "--- with -f-support_aesni, the AES line must fail ---"+build_harness "$out/dist-noaes" "$out/throughput-noaes" -f-support_aesni+set +e+check "$out/throughput-noaes" "no AES" yes+noaes=$?+set -e+if [ "$noaes" -eq 0 ]; then+ echo "FAIL the build without AES acceleration passed every floor, so this"+ echo " job is not measuring the library and its result means nothing"+ exit 1+fi+echo "ok the detector notices a primitive taken off its fast path"++if [ "$failed" -ne 0 ]; then+ echo ""+ echo "$failed ratio(s) under the floor: a primitive has lost its"+ echo "accelerated path, as in #274. The floors are in"+ echo "cbits/tests/perf/floors.txt with what each one is for."+ exit 1+fi
+ cbits/tests/perf/throughput.c view
@@ -0,0 +1,156 @@+/* Throughput of the primitives that have an accelerated implementation, one+ * per process so that a caller can ask for them one at a time.+ *+ * Prints MB/s over 16 KiB. The state is set up once and the same buffer run+ * through it, which is the shape `openssl speed` measures and the shape the+ * README's tables are in.+ *+ * This is here to be compared with itself -- see run.sh -- and not to be+ * quoted. A number from a CI runner is a number from whichever machine the+ * job landed on.+ */+#include <stdio.h>+#include <string.h>+#include <stdlib.h>+#include <stdint.h>+#include <time.h>++#include "crypton_aes.h"+#include "crypton_sha1.h"+#include "crypton_sha256.h"+#include "crypton_sha512.h"+#include "crypton_sha3.h"+#include "crypton_chacha.h"+#include "crypton_poly1305.h"++#define LEN 16384+#define REPS 12++static uint8_t inb[LEN], outb[LEN + 64];+static uint64_t sink;++static double now_us(void)+{+ struct timespec ts;+ clock_gettime(CLOCK_MONOTONIC, &ts);+ return ts.tv_sec * 1e6 + ts.tv_nsec / 1e3;+}++static void bench_gcm(int keybits, int iters)+{+ aes_key key;+ aes_gcm gcm;+ uint8_t kb[32], iv[12], tag[16];+ int i;+ for (i = 0; i < 32; i++) kb[i] = (uint8_t)(i * 7);+ for (i = 0; i < 12; i++) iv[i] = (uint8_t)(i + 3);+ crypton_aes_initkey(&key, kb, keybits / 8);+ crypton_aes_gcm_init(&gcm, &key, iv, 12);+ for (i = 0; i < iters; i++) {+ crypton_aes_gcm_encrypt(outb, &gcm, &key, inb, LEN);+ sink += outb[i & 1023];+ }+ crypton_aes_gcm_finish(tag, &gcm, &key);+ sink += tag[0];+}++static void bench_chachapoly(int iters)+{+ crypton_chacha_context ctx;+ poly1305_ctx pctx;+ poly1305_key pkey;+ poly1305_mac mac;+ uint8_t kb[32], iv[12];+ int i;+ for (i = 0; i < 32; i++) kb[i] = (uint8_t)(i * 5);+ for (i = 0; i < 12; i++) iv[i] = (uint8_t)(i + 1);+ memcpy(&pkey, kb, sizeof(pkey));+ for (i = 0; i < iters; i++) {+ crypton_chacha_init(&ctx, 20, 32, kb, 12, iv);+ crypton_chacha_combine(outb, &ctx, inb, LEN);+ crypton_poly1305_init(&pctx, &pkey);+ crypton_poly1305_update(&pctx, outb, LEN);+ crypton_poly1305_finalize(mac, &pctx);+ sink += mac[0] + outb[i & 1023];+ }+}++static void bench_sha1(int iters)+{+ struct sha1_ctx c;+ uint8_t out[20];+ int i;+ for (i = 0; i < iters; i++) {+ crypton_sha1_init(&c);+ crypton_sha1_update(&c, inb, LEN);+ crypton_sha1_finalize(&c, out);+ sink += out[0];+ }+}++static void bench_sha256(int iters)+{+ struct sha256_ctx c;+ uint8_t out[32];+ int i;+ for (i = 0; i < iters; i++) {+ crypton_sha256_init(&c);+ crypton_sha256_update(&c, inb, LEN);+ crypton_sha256_finalize(&c, out);+ sink += out[0];+ }+}++static void bench_sha512(int iters)+{+ struct sha512_ctx c;+ uint8_t out[64];+ int i;+ for (i = 0; i < iters; i++) {+ crypton_sha512_init(&c);+ crypton_sha512_update(&c, inb, LEN);+ crypton_sha512_finalize(&c, out);+ sink += out[0];+ }+}++static void bench_sha3(int iters)+{+ /* sha3_ctx ends in a flexible array the caller provides room for. */+ uint8_t raw[SHA3_CTX_BUF_MAX_SIZE];+ struct sha3_ctx *c = (struct sha3_ctx *)raw;+ uint8_t out[32];+ int i;+ for (i = 0; i < iters; i++) {+ crypton_sha3_init(c, 256);+ crypton_sha3_update(c, inb, LEN);+ crypton_sha3_finalize(c, 256, out);+ sink += out[0];+ }+}++int main(int argc, char **argv)+{+ const char *algo = argc > 1 ? argv[1] : "sha256";+ int iters = 2000, r, i;+ double best = 1e30;++ for (i = 0; i < LEN; i++) inb[i] = (uint8_t)(i * 17 + 3);++ for (r = 0; r < REPS; r++) {+ double t0 = now_us(), t1;+ if (!strcmp(algo, "aes128gcm")) bench_gcm(128, iters);+ else if (!strcmp(algo, "aes256gcm")) bench_gcm(256, iters);+ else if (!strcmp(algo, "chachapoly")) bench_chachapoly(iters);+ else if (!strcmp(algo, "sha1")) bench_sha1(iters);+ else if (!strcmp(algo, "sha256")) bench_sha256(iters);+ else if (!strcmp(algo, "sha512")) bench_sha512(iters);+ else if (!strcmp(algo, "sha3-256")) bench_sha3(iters);+ else { fprintf(stderr, "unknown algo %s\n", algo); return 2; }+ t1 = now_us();+ if (r > 1 && t1 - t0 < best) best = t1 - t0;+ }+ if (sink == 0) return 3;+ printf("%.1f\n", (double)LEN * iters / best); /* bytes/us == MB/s */+ return 0;+}
+ cbits/tests/scrub/README view
@@ -0,0 +1,53 @@+What is left in memory after a secret has been through it.++Round eight asked whether a secret can be read from the time a primitive+takes. This asks whether it can be read from the memory afterwards. The+stack below a returning function is not erased -- it is simply no longer+addressed -- and a context handed back to a caller is whatever the primitive+left in it, so a later core file, crash dump or swapped page can carry a key+away long after the caller believes it is done with it.++Each probe paints the stack with a filler, runs a primitive on an+unmistakable secret, copies the painted region away before anything can+disturb it, and looks for the pattern. Two things are asked separately:++ scratch what the primitive left below the caller's frame, in its own+ working memory+ context what it left in the context object the caller still holds, which+ is on the heap here as it is in crypton++The first probe keeps the secret on purpose and has to be found. That is not+ceremony: the first two versions of this file reported that nothing was ever+left behind, including by that probe, and both times the search was at fault.+Once because the probed function was inlined into its caller, so its locals+sat in a live frame rather than an abandoned one; once because the loop that+copies the region away was turned into a call to memcpy, whose own frame+landed exactly on the evidence.++What this can say and what it cannot+------------------------------------++It finds a secret that survives *as it was handed over*. It cannot find one+that survives transformed, and the difference matters: Poly1305 reports+nothing, but its finalize clears nothing either -- the key is clamped into r+and pad, so it is still there and simply not byte-for-byte what was passed in.+Read "no verbatim copy" as exactly that and no more.++What it found+-------------++Nothing survives in any primitive's own scratch. The RSA exponentiation is+clean, which is worth saying because crypton_powm_sec memsets its table and+then frees it, and a compiler is entitled to drop a store to memory that is+about to die. clang at -O2 keeps it -- the bzero is still there in the+assembly, two instructions before the free -- but that is the compiler's+choice rather than a guarantee, and explicit_bzero exists for this.++Three contexts keep the secret as it was given: SHA-256, SHA-512 and+ChaCha20. The hash ones hold the buffered message, the ChaCha one holds the+key. Nothing clears any of them, in the C or in the Haskell above it, where+Context is Bytes rather than ScrubbedBytes -- and hashFinalize copies the+context before finalizing, so there are two of them per digest. They are+listed in known.txt; whether to clear them is a question about what a context+means after it is finished with, and about the cost of scrubbing every hash,+rather than something to settle here.
+ cbits/tests/scrub/known.txt view
@@ -0,0 +1,16 @@+# Places that keep a secret as it was handed over, which are known and not+# treated as defects here. A probe reporting only these passes; anything+# else fails.++# A hash context buffers the message a block at a time, so hashing a secret+# leaves it in the context. Nothing clears it: crypton_sha256_finalize and+# its siblings compute the digest and return, and the Haskell side holds the+# context as Bytes rather than ScrubbedBytes, so it is not cleared there+# either. hashFinalize copies the context before finalizing it, so there are+# two such objects per digest rather than one.+sha256 context+sha512 context++# crypton_chacha_init copies the key into the state, where it stays for the+# life of the context.+chacha20 context
+ cbits/tests/scrub/run.sh view
@@ -0,0 +1,30 @@+#!/bin/sh+# What is left on the stack after a secret has been through it.+#+# The stack below a returning function is not erased -- it is simply no longer+# addressed -- so whatever a primitive kept there stays until something else+# writes over it, and a later core file or swapped page carries it away.+#+# The driver paints the stack, runs each primitive on an unmistakable secret,+# copies the painted region away before anything can disturb it, and looks for+# the pattern. The first probe keeps the secret on purpose and has to be+# found; if it is not, the search is looking somewhere the calls do not use+# and no other result counts.+#+# Not run under the sanitizers: reading the stack below the current frame is+# exactly what this does, and ASan calls that an error.+#+# Usage: cbits/tests/scrub/run.sh [build-dir]+set -eu++root=$(CDPATH= cd -- "$(dirname -- "$0")/../../.." && pwd)+out=${1:-$(mktemp -d)}+cc=${CC:-cc}+mkdir -p "$out"+cd "$root"++$cc -O2 -Icbits -Icbits/include64 -o "$out/scrub" cbits/tests/scrub/scrub.c \+ cbits/crypton_sha256.c cbits/crypton_sha512.c cbits/crypton_chacha.c \+ cbits/crypton_poly1305.c cbits/crypton_powm.c++"$out/scrub"
+ cbits/tests/scrub/scrub.c view
@@ -0,0 +1,271 @@+/* What is left on the stack after a secret has been through it.+ *+ * The stack below a returning function is not erased -- it is simply no+ * longer addressed -- so whatever the function kept there stays until+ * something else writes over it. For a hash context or a key schedule that+ * means a copy of the key can outlive every object the caller thinks holds+ * it, and a later crash dump, core file or swapped page carries it away.+ *+ * So: paint the stack with a filler, run the primitive on a secret made of+ * an unmistakable pattern, copy the painted region somewhere else before+ * anything can disturb it, and look for the pattern in the copy. A hit is a+ * place where the secret outlived the call.+ *+ * The region examined is below this file's own frame, so the driver's own+ * copy of the secret is not what is being found.+ */+#include <stdio.h>+#include <stdint.h>+#include <stdlib.h>+#include <string.h>++/* Each probed function needs a frame of its own: inlined into probe, its+ * locals would sit in a live frame rather than an abandoned one, and finding+ * them there would mean nothing. That cost the first attempt at this file. */+#if defined(__GNUC__) || defined(__clang__)+#define NOINLINE __attribute__((noinline))+#else+#define NOINLINE+#endif++/* 32 bytes that nothing else would produce */+static const uint8_t SECRET[32] = {+ 0x9e, 0x37, 0x79, 0xb9, 0x7f, 0x4a, 0x7c, 0x15,+ 0xf3, 0x9c, 0xc0, 0x60, 0x5c, 0xed, 0xc8, 0x34,+ 0x1a, 0x2e, 0x8f, 0x5b, 0xd7, 0x06, 0x41, 0x92,+ 0xc3, 0x58, 0xe6, 0x70, 0xb1, 0x24, 0xaf, 0x8d,+};++#define REGION (512 * 1024)+#define FILLER 0x5a++/* Write the filler over the stack the primitive is about to use. Recursion+ * rather than one large frame, so that the compiler cannot decide the whole+ * thing is dead and skip it. */+static void paint(int depth) {+ volatile uint8_t pad[8192];+ size_t i;+ for (i = 0; i < sizeof pad; i++) pad[i] = FILLER;+ if (depth > 0) paint(depth - 1);+}++/* How many times the pattern appears in the copy. A run of the filler is+ * what is expected; anything else is what was left behind. */+static int count_hits(const uint8_t *hay, size_t n, const uint8_t *needle,+ size_t m) {+ size_t i;+ int hits = 0;+ if (n < m) return 0;+ for (i = 0; i + m <= n; i++)+ if (hay[i] == needle[0] && memcmp(hay + i, needle, m) == 0) hits++;+ return hits;+}++static uint8_t *snapshot;+static int failures, checked;++/* The context a primitive is handed, on the heap where crypton's own callers+ * put it. After the call it is looked at directly: whatever is still in it+ * is what the caller is left holding. */+static void *ctx_mem;+static size_t ctx_len;++/* known.txt lists the places that keep the secret and are understood. A+ * probe that reports only those passes; anything else is new and fails. */+static int is_known(const char *name, const char *what) {+ char line[256], want[128];+ FILE *f = fopen("cbits/tests/scrub/known.txt", "r");+ int found = 0;+ if (!f) return 0;+ snprintf(want, sizeof want, "%s %s", name, what);+ while (fgets(line, sizeof line, f)) {+ char a[64], b[64];+ if (line[0] == '#' || sscanf(line, "%63s %63s", a, b) != 2) continue;+ if (strcmp(a, name) == 0 && strcmp(b, what) == 0) { found = 1; break; }+ }+ fclose(f);+ return found;+}++/* Run one primitive and report what it left. The callback is handed the+ * secret and is expected to use it and return. */+static void probe(const char *name, void (*run)(const uint8_t *, size_t),+ size_t look_for) {+ volatile uint8_t here;+ const uint8_t *low;+ int hits;++ paint(24); /* about 200 KB of filler */+ run(SECRET, sizeof SECRET);++ /* Everything below this frame is what the call used. Copied with a+ * loop rather than memcpy: a call pushes a frame exactly where the one+ * being examined was, and would erase the top of the evidence before it+ * could be read. That is how the first version of this reported that+ * nothing was ever left behind, including by the canary. */+ low = (const uint8_t *)&here - REGION;+ {+ /* volatile, or the compiler recognises the loop and emits memcpy --+ * which is the call this loop exists to avoid. That cost the first+ * two attempts at this file. */+ const volatile uint8_t *v = low;+ size_t k;+ for (k = 0; k < REGION; k++) snapshot[k] = v[k];+ }++ hits = count_hits(snapshot, REGION, SECRET, look_for);+ checked++;+ if (strcmp(name, "canary") == 0) {+ if (hits == 0) {+ printf("FAIL canary: the driver that keeps the secret on purpose\n"+ " was not found, so nothing below this line counts\n");+ failures++;+ } else {+ printf("ok canary: found %d, so the search works\n", hits);+ }+ return;+ }+ /* two separate questions: what the primitive left in its own scratch,+ and what it left in the context its caller still holds */+ if (hits == 0) {+ printf("ok %-9s scratch: no verbatim copy below the frame\n", name);+ } else if (is_known(name, "scratch")) {+ printf("note %-9s scratch: %d verbatim copy(ies), known\n", name, hits);+ } else {+ printf("LEFT %-9s scratch: %d verbatim copy(ies) below the frame,\n"+ " and cbits/tests/scrub/known.txt does not list it\n",+ name, hits);+ failures++;+ }+ if (ctx_len) {+ int chits = count_hits((const uint8_t *)ctx_mem, ctx_len, SECRET,+ look_for);+ /* No hit is not the same as no secret. A primitive that stores the+ key transformed -- Poly1305 clamps it into r and pad -- keeps key+ material the search cannot see. All this can say is whether the+ bytes survive as they were handed over. */+ if (chits == 0) {+ printf("ok %-9s context: no verbatim copy of the secret\n",+ name);+ } else if (is_known(name, "context")) {+ printf("note %-9s context: %d verbatim copy(ies), known\n",+ name, chits);+ } else {+ printf("LEFT %-9s context: %d verbatim copy(ies) of the secret,\n"+ " and cbits/tests/scrub/known.txt does not list it\n",+ name, chits);+ failures++;+ }+ ctx_len = 0;+ }+}++/* ---- the primitives ---------------------------------------------------- */++#include "crypton_sha256.h"+#include "crypton_sha512.h"+#include "crypton_chacha.h"+#include "crypton_poly1305.h"+#include "crypton_powm.h"++NOINLINE static void run_sha256(const uint8_t *s, size_t n) {+ struct sha256_ctx *ctx = ctx_mem;+ uint8_t out[32];+ ctx_len = sizeof *ctx;+ crypton_sha256_init(ctx);+ crypton_sha256_update(ctx, s, (uint32_t)n);+ crypton_sha256_finalize(ctx, out);+ if (out[0] == 0xff && out[31] == 0xff) printf("unreachable\n");+}++NOINLINE static void run_sha512(const uint8_t *s, size_t n) {+ struct sha512_ctx *ctx = ctx_mem;+ uint8_t out[64];+ ctx_len = sizeof *ctx;+ crypton_sha512_init(ctx);+ crypton_sha512_update(ctx, s, (uint32_t)n);+ crypton_sha512_finalize(ctx, out);+ if (out[0] == 0xff && out[63] == 0xff) printf("unreachable\n");+}++NOINLINE static void run_chacha(const uint8_t *s, size_t n) {+ crypton_chacha_context *ctx = ctx_mem;+ uint8_t iv[8] = {1, 2, 3, 4, 5, 6, 7, 8};+ uint8_t out[64];+ ctx_len = sizeof *ctx;+ crypton_chacha_init(ctx, 20, (uint32_t)n, s, sizeof iv, iv);+ crypton_chacha_combine(out, ctx, out, sizeof out);+ if (out[0] == 0xff && out[63] == 0xff) printf("unreachable\n");+}++NOINLINE static void run_poly1305(const uint8_t *s, size_t n) {+ poly1305_ctx *ctx = ctx_mem;+ poly1305_mac mac;+ uint8_t msg[64];+ /* the key is handed over where it already lies, so that nothing of it is+ put on this frame by the driver rather than by the library */+ (void)n;+ memset(msg, 0x11, sizeof msg);+ ctx_len = sizeof *ctx;+ crypton_poly1305_init(ctx, (poly1305_key *)(void *)(uintptr_t)s);+ crypton_poly1305_update(ctx, msg, sizeof msg);+ crypton_poly1305_finalize(mac, ctx);+ if (mac[0] == 0xff && mac[15] == 0xff) printf("unreachable\n");+}++/* The RSA private-key exponentiation. Its scratch is on the heap, but the+ * windows it selects and the accumulators pass through the stack. */+static uint8_t *powm_out, *powm_base, *powm_mod, *powm_exp;+NOINLINE static void run_powm(const uint8_t *s, size_t n) {+ /* Everything is on the heap: the exponent because it is the secret and+ must not be put on this frame by the driver, the rest to keep the+ frame small enough that what is found below it came from the library. */+ enum { LEN = 128 };+ uint8_t *out = powm_out, *base = powm_base, *mod = powm_mod;+ (void)s; (void)n;+ if (crypton_powm_sec(out, base, LEN, powm_exp, LEN, mod, LEN) != 0)+ printf("powm_sec refused\n");+ if (out[0] == 0xff && out[LEN - 1] == 0xff) printf("unreachable\n");+}++/* The calibration. This one keeps the secret on the stack on purpose, so it+ * has to be found; if it is not, the painting or the snapshot is looking+ * somewhere the calls do not use and every "ok" below means nothing. */+NOINLINE static void run_canary(const uint8_t *s, size_t n) {+ volatile uint8_t copy[128];+ size_t i;+ for (i = 0; i < n && i < sizeof copy; i++) copy[i] = s[i];+ if (copy[0] == 0xff && copy[31] == 0xff) printf("unreachable\n");+}++int main(void) {+ size_t i;+ snapshot = malloc(REGION);+ ctx_mem = malloc(4096);+ powm_out = malloc(128); powm_base = malloc(128);+ powm_mod = malloc(128); powm_exp = malloc(128);+ if (!snapshot || !ctx_mem || !powm_out || !powm_base || !powm_mod || !powm_exp) return 2;+ for (i = 0; i < 128; i++) {+ powm_base[i] = (uint8_t)(i * 3 + 1);+ powm_mod[i] = (uint8_t)(i * 5 + 7);+ powm_exp[i] = SECRET[i % sizeof SECRET];+ }+ powm_mod[0] |= 0x80;+ powm_mod[127] |= 1;+ powm_base[0] &= 0x7f;++ probe("canary", run_canary, 32);+ probe("sha256", run_sha256, 32);+ probe("sha512", run_sha512, 32);+ probe("chacha20", run_chacha, 32);+ probe("poly1305", run_poly1305, 16);+ probe("powm_sec", run_powm, 32);++ free(snapshot);+ if (failures)+ printf("\n%d place(s) keep the secret and are not in known.txt\n",+ failures);+ else+ printf("\nnothing keeps the secret that known.txt does not name\n");+ return failures != 0;+}
+ cbits/tests/width/ed448_width.c view
@@ -0,0 +1,87 @@+/* Ed448 and X448 asked of the 32-bit field arithmetic and of the 64-bit one.+ Only the f_impl.c under p448/arch_32 or p448/arch_ref64, and the two arch+ include directories, differ between the builds; everything above them is+ the same source. */+#include <stdio.h>+#include <stdint.h>+#include <string.h>+#include "decaf/ed448.h"+#include "decaf/point_448.h"++static uint64_t s0 = 0x243f6a8885a308d3ULL, s1 = 0x13198a2e03707344ULL;+static uint64_t rnd(void) {+ uint64_t x = s0, y = s1;+ s0 = y; x ^= x << 23;+ s1 = x ^ y ^ (x >> 17) ^ (y >> 26);+ return s1 + y;+}+static void fill(uint8_t *p, size_t n) {+ for (size_t i = 0; i < n; i++) p[i] = (uint8_t)(rnd() >> 24);+}+static void show(const char *t, const uint8_t *b, size_t n) {+ printf("%s ", t);+ for (size_t i = 0; i < n; i++) printf("%02x", b[i]);+ printf("\n");+}++int main(void) {+ uint8_t priv[CRYPTON_DECAF_EDDSA_448_PRIVATE_BYTES];+ uint8_t pub[CRYPTON_DECAF_EDDSA_448_PUBLIC_BYTES];+ uint8_t sig[CRYPTON_DECAF_EDDSA_448_SIGNATURE_BYTES];+ uint8_t msg[256], ctx[8];+ uint8_t xs[CRYPTON_DECAF_X448_PRIVATE_BYTES];+ uint8_t xb[CRYPTON_DECAF_X448_PUBLIC_BYTES];+ uint8_t xo[CRYPTON_DECAF_X448_PUBLIC_BYTES];++ /* the scalars and points worth naming */+ static const uint8_t edge[3] = {0x00, 0x01, 0xff};+ for (unsigned e = 0; e < 3; e++) {+ memset(priv, edge[e], sizeof priv);+ crypton_decaf_ed448_derive_public_key(pub, priv);+ show("epub", pub, sizeof pub);+ crypton_decaf_ed448_sign(sig, priv, pub, (const uint8_t *)"", 0, 0, NULL, 0);+ show("esig", sig, sizeof sig);+ printf("everify=%d\n",+ crypton_decaf_ed448_verify(sig, pub, (const uint8_t *)"", 0, 0, NULL, 0));++ memset(xs, edge[e], sizeof xs);+ crypton_decaf_x448_derive_public_key(xo, xs);+ show("xpub", xo, sizeof xo);+ memset(xb, edge[e], sizeof xb);+ printf("x448=%d\n", crypton_decaf_x448(xo, xb, xs));+ show("xsh", xo, sizeof xo);+ }++ for (int it = 0; it < 512; it++) {+ size_t mlen = (size_t)(rnd() % sizeof msg);+ uint8_t clen = (uint8_t)(rnd() % sizeof ctx);+ fill(priv, sizeof priv);+ fill(msg, sizeof msg);+ fill(ctx, sizeof ctx);++ crypton_decaf_ed448_derive_public_key(pub, priv);+ show("pub", pub, sizeof pub);+ crypton_decaf_ed448_sign(sig, priv, pub, msg, mlen, 0, ctx, clen);+ show("sig", sig, sizeof sig);+ printf("ok=%d bad=%d\n",+ crypton_decaf_ed448_verify(sig, pub, msg, mlen, 0, ctx, clen),+ crypton_decaf_ed448_verify(sig, pub, msg, mlen, 1, ctx, clen));+ /* a signature with one bit moved has to fail on both builds alike */+ sig[(size_t)(rnd() % sizeof sig)] ^= 1;+ printf("tampered=%d\n",+ crypton_decaf_ed448_verify(sig, pub, msg, mlen, 0, ctx, clen));++ fill(xs, sizeof xs);+ crypton_decaf_x448_derive_public_key(xb, xs);+ show("xp", xb, sizeof xb);+ uint8_t xs2[CRYPTON_DECAF_X448_PRIVATE_BYTES], xb2[CRYPTON_DECAF_X448_PUBLIC_BYTES];+ uint8_t sh1[CRYPTON_DECAF_X448_PUBLIC_BYTES], sh2[CRYPTON_DECAF_X448_PUBLIC_BYTES];+ fill(xs2, sizeof xs2);+ crypton_decaf_x448_derive_public_key(xb2, xs2);+ int r1 = crypton_decaf_x448(sh1, xb2, xs);+ int r2 = crypton_decaf_x448(sh2, xb, xs2);+ printf("r=%d,%d agree=%d\n", r1, r2, memcmp(sh1, sh2, sizeof sh1) == 0);+ show("sh", sh1, sizeof sh1);+ }+ return 0;+}
+ cbits/tests/width/p256_width.c view
@@ -0,0 +1,144 @@+/* Exercise the public P-256 API and print everything it answers, so that the+ 32-bit build and the 64-bit build can be compared byte for byte. Every+ value crosses the boundary as big-endian bytes, which is the one form the+ two representations agree on by construction. */+#include <stdio.h>+#include <stdint.h>+#include <string.h>+#include "p256/p256.h"++/* This family has no header at all -- the Haskell side declares it through+ the FFI -- so it is declared here. */+void crypton_p256e_point_mul(const crypton_p256_int *n,+ const crypton_p256_int *in_x, const crypton_p256_int *in_y,+ crypton_p256_int *out_x, crypton_p256_int *out_y);+void crypton_p256e_point_add(+ const crypton_p256_int *in_x1, const crypton_p256_int *in_y1,+ const crypton_p256_int *in_x2, const crypton_p256_int *in_y2,+ crypton_p256_int *out_x, crypton_p256_int *out_y);+void crypton_p256e_point_negate(+ const crypton_p256_int *in_x, const crypton_p256_int *in_y,+ crypton_p256_int *out_x, crypton_p256_int *out_y);+void crypton_p256e_modadd(const crypton_p256_int *MOD,+ const crypton_p256_int *a, const crypton_p256_int *b, crypton_p256_int *c);+void crypton_p256e_modsub(const crypton_p256_int *MOD,+ const crypton_p256_int *a, const crypton_p256_int *b, crypton_p256_int *c);+void crypton_p256e_scalar_invert(const crypton_p256_int *a, crypton_p256_int *b);++static uint64_t s0 = 0x243f6a8885a308d3ULL, s1 = 0x13198a2e03707344ULL;+static uint64_t rnd(void) { /* xoroshiro-ish, deterministic */+ uint64_t x = s0, y = s1;+ s0 = y;+ x ^= x << 23;+ s1 = x ^ y ^ (x >> 17) ^ (y >> 26);+ return s1 + y;+}+static void rnd_bytes(uint8_t *p, int n) {+ for (int i = 0; i < n; i++) p[i] = (uint8_t)(rnd() >> 24);+}+static void show(const char *tag, const crypton_p256_int *v) {+ uint8_t b[P256_NBYTES];+ crypton_p256_to_bin(v, b);+ printf("%s ", tag);+ for (int i = 0; i < P256_NBYTES; i++) printf("%02x", b[i]);+ printf("\n");+}+static void from_hex(const char *h, crypton_p256_int *out) {+ uint8_t b[P256_NBYTES];+ for (int i = 0; i < P256_NBYTES; i++) {+ unsigned v; sscanf(h + 2 * i, "%2x", &v); b[i] = (uint8_t)v;+ }+ crypton_p256_from_bin(b, out);+}++int main(void) {+ crypton_p256_int n, x, y, x2, y2, r, a, b, n2tmp;+ uint8_t buf[P256_NBYTES];++ show("order", &crypton_SECP256r1_n);+ show("prime", &crypton_SECP256r1_p);+ show("bparam", &crypton_SECP256r1_b);++ /* the scalars worth naming: zero, one, the order and its neighbours, and+ the all-bits-set shapes the comb recoding has to single out */+ static const char *corners[] = {+ "0000000000000000000000000000000000000000000000000000000000000000",+ "0000000000000000000000000000000000000000000000000000000000000001",+ "0000000000000000000000000000000000000000000000000000000000000002",+ "ffffffff00000000ffffffffffffffffbce6faada7179e84f3b9cac2fc632551", /* n */+ "ffffffff00000000ffffffffffffffffbce6faada7179e84f3b9cac2fc632550", /* n-1 */+ "ffffffff00000000ffffffffffffffffbce6faada7179e84f3b9cac2fc632552", /* n+1 */+ "7fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",+ "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff",+ "0000000000000000000000000000000000000000000000000000000000000000",+ };+ for (unsigned i = 0; i < sizeof corners / sizeof *corners; i++) {+ from_hex(corners[i], &n);+ crypton_p256_base_point_mul(&n, &x, &y);+ printf("corner%u valid=%d\n", i, crypton_p256_is_valid_point(&x, &y));+ show(" cx", &x); show(" cy", &y);+ }++ for (int it = 0; it < 1024; it++) {+ rnd_bytes(buf, P256_NBYTES);+ crypton_p256_from_bin(buf, &n);+ crypton_p256_mod(&crypton_SECP256r1_n, &n, &n);+ show("n", &n);++ crypton_p256_base_point_mul(&n, &x, &y);+ printf("valid=%d zero=%d odd=%d even=%d\n",+ crypton_p256_is_valid_point(&x, &y),+ crypton_p256_is_zero(&x), crypton_p256_is_odd(&y),+ crypton_p256_is_even(&y));+ show("x", &x); show("y", &y);++ /* n2 * (that point), then n1*G + n2*P through the vartime pair */+ rnd_bytes(buf, P256_NBYTES);+ crypton_p256_from_bin(buf, &a);+ crypton_p256_mod(&crypton_SECP256r1_n, &a, &a);+ crypton_p256e_point_mul(&a, &x, &y, &x2, &y2);+ show("px", &x2); show("py", &y2);+ printf("pvalid=%d\n", crypton_p256_is_valid_point(&x2, &y2));++ rnd_bytes(buf, P256_NBYTES);+ crypton_p256_from_bin(buf, &b);+ crypton_p256_mod(&crypton_SECP256r1_n, &b, &b);+ crypton_p256_points_mul_vartime(&a, &b, &x, &y, &x2, &y2);+ show("vx", &x2); show("vy", &y2);++ /* the integer side: every arithmetic entry point the header offers */+ crypton_p256_modmul(&crypton_SECP256r1_n, &a, 0, &b, &r); show("mul", &r);+ crypton_p256_modmul(&crypton_SECP256r1_p, &a, 1, &b, &r); show("mulc", &r);+ crypton_p256e_scalar_invert(&a, &r); show("inv", &r);+ crypton_p256e_modadd(&crypton_SECP256r1_n, &a, &b, &r); show("madd", &r);+ crypton_p256e_modsub(&crypton_SECP256r1_n, &a, &b, &r); show("msub", &r);+ crypton_p256e_point_add(&x, &y, &x2, &y2, &r, &n2tmp); show("ax", &r); show("ay", &n2tmp);+ crypton_p256e_point_negate(&x, &y, &r, &n2tmp); show("gx", &r); show("gy", &n2tmp);+ crypton_p256_modinv_vartime(&crypton_SECP256r1_n, &a, &r); show("invv", &r);+ printf("cmp=%d add=%d sub=%d addd=%d\n",+ crypton_p256_cmp(&a, &b),+ crypton_p256_add(&a, &b, &r),+ crypton_p256_sub(&a, &b, &r),+ crypton_p256_add_d(&a, 0x9e3779b9u, &r));+ show("sum", &r);+ /* the shifts are defined as n % P256_BITSPERDIGIT, which is 32 on one+ build and 64 on the other, so keep the ask inside both */+ /* a shift of nothing has to be the number itself. Held here rather+ than left to the random amounts below, because zero is the amount+ that used to shift a digit by its own width. */+ crypton_p256_shl(&a, 0, &r);+ printf("shl0=%d ", crypton_p256_cmp(&a, &r) == 0);+ crypton_p256_shr(&a, 0, &r);+ printf("shr0=%d\n", crypton_p256_cmp(&a, &r) == 0);+ for (int s = 0; s < 3; s++) {+ int k = (int)(rnd() % 32);+ printf("shl%d=%d\n", k, (int)(crypton_p256_shl(&a, k, &r) & 0xff));+ show("shl", &r);+ crypton_p256_shr(&a, k, &r); show("shr", &r);+ }+ for (int bit = 0; bit < 256; bit += 37)+ printf("bit%d=%d ", bit, crypton_p256_get_bit(&a, bit));+ printf("\n");+ }+ return 0;+}
+ cbits/tests/width/run.sh view
@@ -0,0 +1,103 @@+#!/bin/sh+# The three implementations that only a 32-bit architecture receives, asked+# the same questions as the 64-bit ones they stand in for.+#+# cbits/include32/p256 against cbits/include64/p256+# cbits/curve25519-donna.c against curve25519-donna-c64.c+# cbits/decaf/p448/arch_32 against cbits/decaf/p448/arch_ref64+#+# No job in the matrix is 32-bit, so until this ran, none of the left column+# had ever been compiled, let alone executed. The two sides of each pair+# define the same symbols, so they cannot share a binary: each driver is built+# twice and the two outputs compared.+#+# With a compiler that can target 32-bit x86 -- gcc-multilib on the Linux+# runner -- the 32-bit side is built a second time as a real 32-bit binary,+# which is the only way to see what the narrower int, size_t and pointer do.+#+# Usage: cbits/tests/width/run.sh [build-dir]+set -eu++root=$(CDPATH= cd -- "$(dirname -- "$0")/../../.." && pwd)+out=${1:-$(mktemp -d)}+cc=${CC:-cc}+mkdir -p "$out"+cd "$root"++D=cbits/decaf+decaf_common="$D/ed448goldilocks/decaf_all.c $D/ed448goldilocks/eddsa.c+ $D/ed448goldilocks/scalar.c $D/p448/f_arithmetic.c+ $D/p448/f_generic.c $D/utils.c cbits/crypton_sha3.c"++# name, the flags and sources for the 64-bit side, then for the 32-bit side+build() {+ # shellcheck disable=SC2086+ $cc -O2 -Wno-deprecated-declarations $EXTRA -o "$out/$1" $2 2>&1 |+ grep -vE "^$|deprecated" || true+ test -x "$out/$1" || { echo "did not build: $1"; exit 1; }+}++status=0+compare() {+ if cmp -s "$out/$1.txt" "$out/$2.txt"; then+ echo "ok $3 ($(wc -l < "$out/$1.txt" | tr -d ' ') lines)"+ else+ echo "FAIL $3"+ diff "$out/$1.txt" "$out/$2.txt" | head -20+ status=1+ fi+}++for width in 64 32; do+ case $width in+ 64) p256_inc=cbits/include64; donna=cbits/curve25519/curve25519-donna-c64.c; arch=arch_ref64 ;;+ 32) p256_inc=cbits/include32; donna=cbits/curve25519/curve25519-donna.c; arch=arch_32 ;;+ esac++ # decaf decides its word size twice and from two different things: the+ # field limbs from ARCH_WORD_BITS, which follows the arch directory+ # picked above, and the scalar limbs from CRYPTON_DECAF_WORD_BITS, which+ # common.h reads off the host compiler. On a 32-bit machine -- the only+ # place cabal asks for arch_32 -- both come out 32. Here the host is+ # 64-bit whichever side is being built, so say which is wanted rather+ # than compile a half-32-bit-half-64-bit library and compare that.++ EXTRA="-Icbits -I$p256_inc"+ build "p256_$width" "cbits/tests/width/p256_width.c cbits/p256/p256.c cbits/p256/p256_ec.c"++ EXTRA="-Icbits"+ build "x25519_$width" "cbits/tests/width/x25519_width.c $donna"++ EXTRA="-DCRYPTON_DECAF_WORD_BITS=$width -Icbits -I$D/include -I$D/p448 -I$D/include/$arch -I$D/p448/$arch"+ build "ed448_$width" "cbits/tests/width/ed448_width.c $decaf_common $D/p448/$arch/f_impl.c"++ for t in p256 x25519 ed448; do+ "$out/${t}_$width" > "$out/${t}_$width.txt"+ done+done++for t in p256 x25519 ed448; do+ compare "${t}_64" "${t}_32" "$t: the 32-bit implementation answers what the 64-bit one answers"+done++# The same sources again, this time actually narrow. Only the 32-bit side is+# tried: the 64-bit P-256 wants __uint128_t, which a 32-bit target has not got,+# which is the whole reason the 32-bit side exists.+printf 'int main(void){return 0;}\n' > "$out/probe.c"+if $cc -m32 -o "$out/probe" "$out/probe.c" 2>/dev/null && "$out/probe"; then+ EXTRA="-m32 -Icbits -Icbits/include32"+ build p256_m32 "cbits/tests/width/p256_width.c cbits/p256/p256.c cbits/p256/p256_ec.c"+ EXTRA="-m32 -Icbits"+ build x25519_m32 "cbits/tests/width/x25519_width.c cbits/curve25519/curve25519-donna.c"+ EXTRA="-m32 -DCRYPTON_DECAF_WORD_BITS=32 -Icbits -I$D/include -I$D/p448 -I$D/include/arch_32 -I$D/p448/arch_32"+ build ed448_m32 "cbits/tests/width/ed448_width.c $decaf_common $D/p448/arch_32/f_impl.c"++ for t in p256 x25519 ed448; do+ "$out/${t}_m32" > "$out/${t}_m32.txt"+ compare "${t}_32" "${t}_m32" "$t: a 32-bit host answers what a 64-bit host answers"+ done+else+ echo "skip $cc cannot build and run a 32-bit binary here; the comparison above still ran"+fi++exit $status
+ cbits/tests/width/x25519_width.c view
@@ -0,0 +1,74 @@+/* The same X25519 asked of the 32-bit donna and the 64-bit donna. Both files+ define crypton_curve25519_donna, so they cannot share a binary: build twice+ and compare. */+#include <stdio.h>+#include <stdint.h>+#include <string.h>++void crypton_curve25519_donna(uint8_t *mypublic, const uint8_t *secret,+ const uint8_t *basepoint);++static uint64_t s0 = 0x243f6a8885a308d3ULL, s1 = 0x13198a2e03707344ULL;+static uint64_t rnd(void) {+ uint64_t x = s0, y = s1;+ s0 = y; x ^= x << 23;+ s1 = x ^ y ^ (x >> 17) ^ (y >> 26);+ return s1 + y;+}+static void show(const char *t, const uint8_t *b) {+ printf("%s ", t);+ for (int i = 0; i < 32; i++) printf("%02x", b[i]);+ printf("\n");+}++int main(void) {+ uint8_t sec[32], base[32], out[32];+ /* the named points: the generator, zero, one, the low-order points and+ the all-ones field element that reduces to nothing */+ static const uint8_t corners[][32] = {+ {9},+ {0},+ {1},+ {0xe0,0xeb,0x7a,0x7c,0x3b,0x41,0xb8,0xae,0x16,0x56,0xe3,0xfa,0xf1,0x9f,+ 0xc4,0x6a,0xda,0x09,0x8d,0xeb,0x9c,0x32,0xb1,0xfd,0x86,0x62,0x05,0x16,+ 0x5f,0x49,0xb8,0x00},+ {0x5f,0x9c,0x95,0xbc,0xa3,0x50,0x8c,0x24,0xb1,0xd0,0xb1,0x55,0x9c,0x83,+ 0xef,0x5b,0x04,0x44,0x5c,0xc4,0x58,0x1c,0x8e,0x86,0xd8,0x22,0x4e,0xdd,+ 0xd0,0x9f,0x11,0x57},+ {0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff},+ {0xec,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,+ 0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0xff,0x7f},+ };+ for (unsigned c = 0; c < sizeof corners / sizeof *corners; c++) {+ memset(sec, 0, 32);+ sec[0] = (uint8_t)(0x40 + c); sec[31] = 0x40;+ crypton_curve25519_donna(out, sec, corners[c]);+ show("corner", out);+ /* and the scalars with every clamped bit at an edge */+ memset(sec, 0xff, 32); sec[0] = 0xf8; sec[31] = 0x7f;+ crypton_curve25519_donna(out, sec, corners[c]);+ show("cmax", out);+ memset(sec, 0x00, 32); sec[31] = 0x40;+ crypton_curve25519_donna(out, sec, corners[c]);+ show("cmin", out);+ }+ for (int it = 0; it < 2048; it++) {+ for (int i = 0; i < 32; i++) sec[i] = (uint8_t)(rnd() >> 24);+ for (int i = 0; i < 32; i++) base[i] = (uint8_t)(rnd() >> 24);+ crypton_curve25519_donna(out, sec, base);+ show("r", out);+ /* and a round trip: the shared secret both sides should agree on */+ uint8_t pa[32], pb[32], sa[32], sb[32], g[32] = {9};+ uint8_t s2[32];+ for (int i = 0; i < 32; i++) s2[i] = (uint8_t)(rnd() >> 24);+ crypton_curve25519_donna(pa, sec, g);+ crypton_curve25519_donna(pb, s2, g);+ crypton_curve25519_donna(sa, sec, pb);+ crypton_curve25519_donna(sb, s2, pa);+ printf("agree=%d\n", memcmp(sa, sb, 32) == 0);+ show("sa", sa);+ }+ return 0;+}
crypton.cabal view
@@ -1,9 +1,24 @@ cabal-version: 3.0 name: crypton-version: 2.0.1-license: BSD-3-Clause-license-file: LICENSE-copyright: Vincent Hanquez <vincent@snarc.org>+version: 2.1.7+-- crypton's own code is BSD-3-Clause. The parts of+-- cbits/aes/gcm_fused_x86.c that follow picotls's fusion are MIT, and the+-- vendored s2n-bignum assembly in cbits/s2n is taken under ISC; each has+-- its licence beside it, and they are listed below. The CRYPTOGAMS+-- assembly in cbits/asm is taken under its BSD-3-Clause option, and the+-- AArch64 multiply-accumulate loop in cbits/crypton_bignum.h follows Go's,+-- which is BSD-3-Clause too; the first term already covers both.+license: BSD-3-Clause AND MIT AND ISC+license-files:+ LICENSE+ cbits/LICENSE.go+ cbits/aes/LICENSE.fusion+ cbits/asm/LICENSE.cryptogams+ cbits/s2n/LICENSE+copyright:+ 2006-2022 Vincent Hanquez <vincent@snarc.org> and contributors,+ 2023-2026 Kazu Yamamoto <kazu@iij.ad.jp>+ maintainer: Kazu Yamamoto <kazu@iij.ad.jp> author: Vincent Hanquez <vincent@snarc.org> stability: experimental@@ -12,40 +27,20 @@ homepage: https://github.com/kazu-yamamoto/crypton bug-reports: https://github.com/kazu-yamamoto/crypton/issues-synopsis: Cryptography Primitives sink-description:- A repository of cryptographic primitives.- .- * Symmetric ciphers: AES, DES, 3DES, CAST5, Blowfish, Twofish, Camellia, RC4, Salsa, XSalsa, ChaCha.- .- * Hash: SHA1, SHA2, SHA3, SHAKE, MD2, MD4, MD5, Keccak, Skein, Ripemd, Tiger, Whirlpool, Blake2- .- * MAC: HMAC, KMAC, Poly1305- .- * Asymmetric crypto: DSA, RSA, DH, ECDH, ECDSA, ECC, Curve25519, Curve448, Ed25519, Ed448- .- * Key Derivation Function: PBKDF2, Scrypt, HKDF, Argon2, BCrypt, BCryptPBKDF- .- * Cryptographic Random generation: System Entropy, Deterministic Random Generator- .- * Data related: Anti-Forensic Information Splitter (AFIS)- .- If anything cryptographic related is missing from here, submit- a pull request to have it added. This package strives to be a- cryptographic kitchen sink that provides cryptography for everyone.- .- Evaluate the security related to your requirements before using.- .- Read "Crypto.Tutorial" for a quick start guide.+synopsis: Cryptography Primitives+description: `crypton` is a low-level cryptography library.+ To achieve high performance, it utilizes C and assembly+ language to define FFI bindings, structuring them+ in a way that makes them easy to use. category: Cryptography build-type: Simple extra-source-files: cbits/*.h cbits/aes/*.h+ cbits/curve25519/*.h cbits/aes/armv8_impl.c cbits/aes/x86ni_impl.c- cbits/asm/LICENSE.cryptogams cbits/asm/README.md cbits/asm/aesni-gcm-x86_64.pl cbits/asm/arm-xlate.pl@@ -79,6 +74,37 @@ cbits/ed25519/*.h cbits/include32/p256/*.h cbits/include64/p256/*.h+ cbits/s2n/COMMIT+ cbits/s2n/README.md+ cbits/s2n/arm/*.S+ cbits/p256/*.h+ cbits/p256/gen_base_table.py+ cbits/s2n/import.sh+ cbits/s2n/include/*.h+ cbits/s2n/x86_att/*.S+ cbits/tests/ct/*.c+ cbits/tests/ct/*.h+ cbits/tests/ct/known.txt+ cbits/tests/ct/README+ cbits/tests/ct/run.sh+ cbits/tests/endian/*.c+ cbits/tests/endian/README+ cbits/tests/endian/run.sh+ cbits/tests/endian/vectors.txt+ cbits/tests/fuzz/*.c+ cbits/tests/fuzz/*.h+ cbits/tests/fuzz/README+ cbits/tests/fuzz/corpus/*.bin+ cbits/tests/fuzz/run.sh+ cbits/tests/perf/*.c+ cbits/tests/perf/floors.txt+ cbits/tests/perf/run.sh+ cbits/tests/scrub/*.c+ cbits/tests/scrub/README+ cbits/tests/scrub/known.txt+ cbits/tests/scrub/run.sh+ cbits/tests/width/*.c+ cbits/tests/width/run.sh tests/*.hs extra-doc-files:@@ -108,10 +134,22 @@ manual: True flag support_sse- description: Use SSE optimized version of (BLAKE2, ARGON2)+ description:+ Use SSE optimized version of (BLAKE2, ARGON2) on i386. x86-64 takes+ them anyway; every other architecture has no SSE to offer and ignores+ this flag, rather than failing to compile the sources.+ default: False manual: True +flag support_s2n_bignum+ description:+ Use the vendored s2n-bignum assembly for the NIST prime curves on+ x86-64 and AArch64. See cbits/s2n/README.md.++ default: True+ manual: True+ flag integer-gmp description: Whether or not to use GMP for some functions manual: True@@ -143,11 +181,13 @@ library exposed-modules: Crypto.Cipher.AES+ Crypto.Cipher.AES.GCM Crypto.Cipher.AESGCMSIV Crypto.Cipher.Blowfish Crypto.Cipher.Camellia Crypto.Cipher.CAST5 Crypto.Cipher.ChaCha+ Crypto.Cipher.ChaCha.Poly1305 Crypto.Cipher.ChaChaPoly1305 Crypto.Cipher.DES Crypto.Cipher.RC4@@ -236,6 +276,8 @@ -- limb counts, which are public. cc-options: -std=gnu99 -O3 c-sources:+ cbits/curve25519/x25519.c+ cbits/crypton_modinv.c cbits/argon2/argon2.c cbits/crypton_blake2b.c cbits/crypton_blake2bp.c@@ -244,6 +286,7 @@ cbits/crypton_blowfish.c cbits/crypton_camellia.c cbits/crypton_chacha.c+ cbits/crypton_chachapoly.c cbits/crypton_cpu.c cbits/crypton_des.c cbits/crypton_ecc.c@@ -269,6 +312,7 @@ cbits/crypton_whirlpool.c cbits/crypton_xsalsa.c cbits/ed25519/ed25519.c+ cbits/ed25519/ed25519_s2n.c cbits/p256/p256.c cbits/p256/p256_ec.c @@ -319,6 +363,7 @@ Crypto.Internal.ECC Crypto.Internal.Endian Crypto.Internal.Imports+ Crypto.Internal.Poly1305 Crypto.Internal.Nat Crypto.Internal.WordArray Crypto.Internal.Words@@ -339,12 +384,11 @@ ghc-options: -Wall -fwarn-tabs -optc-O3 build-depends: base >=4.13 && <5,- bytestring,- primitive >=0.9,- deepseq,- base16 >=1.0,- bytestring,- text,+ bytestring <0.13,+ primitive >=0.9 && <0.10,+ deepseq <1.6,+ base16 >=1.0 && <1.1,+ text <2.2, ram >=0.20.1 && <0.23 if flag(old_toolchain_inliner)@@ -368,6 +412,17 @@ include-dirs: cbits/decaf/include/arch_ref64 cbits/decaf/p448/arch_ref64 + -- decaf sizes its field limbs from the arch directory just chosen and+ -- its scalar limbs from a separate macro that cbits/decaf/include/+ -- decaf/common.h works out from the compiler, by asking after+ -- __x86_64__ and the width of uint_fast32_t. The two answers need+ -- not agree: on Apple Silicon uint_fast32_t is four bytes, so the+ -- same aarch64 CPU takes 64-bit field limbs and 32-bit scalar limbs,+ -- where on Linux it takes 64-bit for both. Ed448 signing pays 5.5%+ -- for that (20.69 us against 19.56 on an M4). The architecture is+ -- already decided here, so decide this with it.+ cc-options: -DCRYPTON_DECAF_WORD_BITS=64+ else c-sources: cbits/decaf/ed448goldilocks/decaf_all.c@@ -379,6 +434,7 @@ cbits/decaf/utils.c include-dirs: cbits/decaf/include/arch_32 cbits/decaf/p448/arch_32+ cc-options: -DCRYPTON_DECAF_WORD_BITS=32 if ((((((((arch(x86_64) || arch(aarch64)) || arch(loongarch64)) || arch(ppc64le)) || arch(riscv64)) || arch(s390x)) || arch(alpha)) || arch(ppc64)) || arch(sparc64)) c-sources: cbits/curve25519/curve25519-donna-c64.c@@ -447,6 +503,121 @@ cbits/asm/sha256-x86_64-elf.S cbits/asm/sha512-x86_64-elf.S + -- AWS's s2n-bignum: hand-written, formally verified, constant-time+ -- assembly for the NIST prime curves, two and a half to three times+ -- faster than the C it replaces here. Apache-2.0 OR ISC OR MIT-0, so+ -- unlike OpenSSL's and BoringSSL's ecp_nistz256 it can be used. Both+ -- variants of each routine are built and chosen between in+ -- cbits/p256/p256_s2n.c -- see cbits/s2n/README.md for why the question+ -- is a different one on the two architectures. Windows is left out for+ -- now: the vendored files carry ELF and Mach-O directives and nothing+ -- for COFF, the same reason the CRYPTOGAMS AArch64 assembly above skips+ -- it. x86-64 there wants -DWINDOWS_ABI=1 as well.+ if (flag(support_s2n_bignum) && (arch(x86_64) || arch(aarch64)) && !os(windows))+ cc-options: -DCRYPTON_S2N_BIGNUM+ include-dirs: cbits/s2n/include+ c-sources:+ cbits/crypton_ecc_s2n.c+ cbits/p256/p256_base_table.c+ cbits/p256/p256_s2n.c+ cbits/p256/p256_verify.c+ cbits/p256/p256_wnaf_table.c++ if arch(aarch64)+ asm-sources:+ cbits/s2n/arm/bignum_deamont_p384.S+ cbits/s2n/arm/bignum_modinv.S+ cbits/s2n/arm/curve25519_x25519.S+ cbits/s2n/arm/curve25519_x25519_alt.S+ cbits/s2n/arm/curve25519_x25519base.S+ cbits/s2n/arm/curve25519_x25519base_alt.S+ cbits/s2n/arm/edwards25519_encode.S+ cbits/s2n/arm/edwards25519_scalarmulbase.S+ cbits/s2n/arm/edwards25519_scalarmulbase_alt.S+ cbits/s2n/arm/bignum_inv_p521.S+ cbits/s2n/arm/bignum_montinv_p384.S+ cbits/s2n/arm/bignum_montmul_p384.S+ cbits/s2n/arm/bignum_montmul_p384_alt.S+ cbits/s2n/arm/bignum_montsqr_p384.S+ cbits/s2n/arm/bignum_montsqr_p384_alt.S+ cbits/s2n/arm/bignum_mul_p521.S+ cbits/s2n/arm/bignum_mul_p521_alt.S+ cbits/s2n/arm/bignum_sqr_p521.S+ cbits/s2n/arm/bignum_sqr_p521_alt.S+ cbits/s2n/arm/bignum_tomont_p384.S+ cbits/s2n/arm/bignum_demont_p256.S+ cbits/s2n/arm/bignum_neg_p256.S+ cbits/s2n/arm/bignum_tomont_p256.S+ cbits/s2n/arm/p256_montjadd.S+ cbits/s2n/arm/p256_montjadd_alt.S+ cbits/s2n/arm/p256_montjdouble.S+ cbits/s2n/arm/p256_montjdouble_alt.S+ cbits/s2n/arm/p256_montjmixadd.S+ cbits/s2n/arm/p256_montjmixadd_alt.S+ cbits/s2n/arm/p256_scalarmul.S+ cbits/s2n/arm/p256_scalarmul_alt.S+ cbits/s2n/arm/p256_scalarmulbase.S+ cbits/s2n/arm/p256_scalarmulbase_alt.S+ cbits/s2n/arm/p384_montjscalarmul.S+ cbits/s2n/arm/p384_montjscalarmul_alt.S+ cbits/s2n/arm/p521_jscalarmul.S+ cbits/s2n/arm/p521_jscalarmul_alt.S++ else+ asm-sources:+ cbits/s2n/x86_att/bignum_deamont_p384.S+ cbits/s2n/x86_att/bignum_modinv.S+ cbits/s2n/x86_att/curve25519_x25519.S+ cbits/s2n/x86_att/curve25519_x25519_alt.S+ cbits/s2n/x86_att/curve25519_x25519base.S+ cbits/s2n/x86_att/curve25519_x25519base_alt.S+ cbits/s2n/x86_att/edwards25519_encode.S+ cbits/s2n/x86_att/edwards25519_scalarmulbase.S+ cbits/s2n/x86_att/edwards25519_scalarmulbase_alt.S+ cbits/s2n/x86_att/bignum_deamont_p384_alt.S+ cbits/s2n/x86_att/bignum_inv_p521.S+ cbits/s2n/x86_att/bignum_montinv_p384.S+ cbits/s2n/x86_att/bignum_montmul_p384.S+ cbits/s2n/x86_att/bignum_montmul_p384_alt.S+ cbits/s2n/x86_att/bignum_montsqr_p384.S+ cbits/s2n/x86_att/bignum_montsqr_p384_alt.S+ cbits/s2n/x86_att/bignum_mul_p521.S+ cbits/s2n/x86_att/bignum_mul_p521_alt.S+ cbits/s2n/x86_att/bignum_sqr_p521.S+ cbits/s2n/x86_att/bignum_sqr_p521_alt.S+ cbits/s2n/x86_att/bignum_tomont_p384.S+ cbits/s2n/x86_att/bignum_tomont_p384_alt.S+ cbits/s2n/x86_att/bignum_demont_p256.S+ cbits/s2n/x86_att/bignum_demont_p256_alt.S+ cbits/s2n/x86_att/bignum_neg_p256.S+ cbits/s2n/x86_att/bignum_tomont_p256.S+ cbits/s2n/x86_att/bignum_tomont_p256_alt.S+ cbits/s2n/x86_att/p256_montjadd.S+ cbits/s2n/x86_att/p256_montjadd_alt.S+ cbits/s2n/x86_att/p256_montjdouble.S+ cbits/s2n/x86_att/p256_montjdouble_alt.S+ cbits/s2n/x86_att/p256_montjmixadd.S+ cbits/s2n/x86_att/p256_montjmixadd_alt.S+ cbits/s2n/x86_att/p256_scalarmul.S+ cbits/s2n/x86_att/p256_scalarmul_alt.S+ cbits/s2n/x86_att/p256_scalarmulbase.S+ cbits/s2n/x86_att/p256_scalarmulbase_alt.S++ -- Modular exponentiation at RSA sizes, x86-64 only: on AArch64+ -- crypton's C measures faster than these, so nothing is taken+ -- for it. All of them want ADX, which the run-time check in+ -- cbits/crypton_powm.c asks about before using any.+ asm-sources:+ cbits/s2n/x86_att/bignum_emontredc_8n.S+ cbits/s2n/x86_att/bignum_kmul_16_32.S+ cbits/s2n/x86_att/bignum_kmul_32_64.S+ cbits/s2n/x86_att/bignum_ksqr_16_32.S+ cbits/s2n/x86_att/bignum_ksqr_32_64.S+ cbits/s2n/x86_att/p384_montjscalarmul.S+ cbits/s2n/x86_att/p384_montjscalarmul_alt.S+ cbits/s2n/x86_att/p521_jscalarmul.S+ cbits/s2n/x86_att/p521_jscalarmul_alt.S+ if ((flag(support_rdrand) && (arch(i386) || arch(x86_64))) && !os(windows)) cpp-options: -DSUPPORT_RDRAND c-sources: cbits/crypton_rdrand.c@@ -543,8 +714,25 @@ -- checked in per object format since it comes from a -- generator. if arch(x86_64)- cc-options: -DWITH_X86_GCM_ASM- c-sources: cbits/aes/gcm_x86_asm.c+ cc-options: -DWITH_X86_GCM_ASM -DWITH_GCM_FUSED+ c-sources:+ cbits/aes/gcm_fused_x86.c+ -- AES-GCM in the 256-bit form of the same two+ -- instructions, two blocks to each, which is worth+ -- twice the throughput where the processor has them --+ -- Zen 3 and Ice Lake onwards. Nothing to borrow: the+ -- wide AES-GCM in OpenSSL and BoringSSL is Apache-2.0,+ -- s2n-bignum has no GCM, and the assembly above is+ -- 128-bit throughout. crypton_cpu.c asks the+ -- processor before any of it runs.+ cbits/aes/gcm_vaes_x86.c+ -- and the 512-bit form, four blocks to each, which Ice+ -- Lake and Zen 4 onwards have. Same story about+ -- borrowing, and the same run-time question -- with+ -- three more bits of XCR0 in it, since these need the+ -- operating system to save the AVX-512 state.+ cbits/aes/gcm_vaes512_x86.c+ cbits/aes/gcm_x86_asm.c if os(osx) asm-sources: cbits/asm/aesni-gcm-x86_64-macosx.S@@ -555,13 +743,18 @@ else asm-sources: cbits/asm/aesni-gcm-x86_64-elf.S - else+ -- Neither of the two branches above. This was an `else`, which pairs with+ -- the x86 `if` alone and so fired on AArch64 as well, where the ARMv8+ -- branch had already named every file it names. Cabal drops the repeats,+ -- so nothing was built twice, but the line read as the fallback for a+ -- platform with no AES instructions and was not one.+ if !((flag(support_aesni) && arch(aarch64)) || ((flag(support_aesni) && (((os(linux) || os(freebsd)) || os(osx)) || os(windows))) && (arch(i386) || arch(x86_64)))) c-sources: cbits/aes/generic.c cbits/aes/gf.c cbits/crypton_aes.c - if (arch(x86_64) || flag(support_sse))+ if (arch(x86_64) || (flag(support_sse) && arch(i386))) c-sources: cbits/blake2/sse/blake2b.c cbits/blake2/sse/blake2bp.c@@ -579,7 +772,7 @@ include-dirs: cbits/blake2/ref - if (arch(x86_64) || flag(support_sse))+ if (arch(x86_64) || (flag(support_sse) && arch(i386))) cpp-options: -DSUPPORT_SSE if arch(i386)@@ -589,13 +782,13 @@ cpp-options: -DWINDOWS other-modules: Crypto.Random.Entropy.Windows extra-libraries: advapi32- build-depends: Win32+ build-depends: Win32 <2.15 else other-modules: Crypto.Random.Entropy.Unix if (impl(ghc >=0) && flag(integer-gmp))- build-depends: integer-gmp+ build-depends: integer-gmp <1.2 if flag(support_deepseq) cpp-options: -DWITH_DEEPSEQ_SUPPORT
tests/BlockCipher/AESSpec.hs view
@@ -3,6 +3,7 @@ module BlockCipher.AESSpec (spec) where import BlockCipher+import Control.Exception (evaluate) import qualified Crypto.Cipher.AES as AES import Crypto.Cipher.Types import Crypto.Error@@ -20,6 +21,10 @@ import qualified BlockCipher.AES.GCMLong as KATGCMLong import qualified BlockCipher.AES.OCB3 as KATOCB3 import qualified BlockCipher.AES.XTS as KATXTS+import qualified Crypto.Cipher.AES.GCM as GCM+import Data.Bits (xor)+import Foreign.Marshal.Alloc (allocaBytes)+import Foreign.Ptr (castPtr) {- instance Show AES.AES where@@ -200,8 +205,8 @@ ++ "-byte AAD, " ++ show ptlen ++ "-byte message"- ) $- case klen of+ )+ $ case klen of 16 -> run (undefined :: AES.AES128) v 24 -> run (undefined :: AES.AES192) v _ -> run (undefined :: AES.AES256) v@@ -215,13 +220,172 @@ digest ciphertext `shouldBe` ctHash aeadSimpleDecrypt aead aad ciphertext authTag `shouldBe` Just plaintext where- cipher = throwCryptoError (cipherInit (KATGCMLong.gcmKey klen)) `asTypeOf` cipherWitness+ cipher =+ throwCryptoError (cipherInit (KATGCMLong.gcmKey klen)) `asTypeOf` cipherWitness aead = throwCryptoError (aeadInit AEAD_GCM cipher KATGCMLong.gcmIV) aad = KATGCMLong.gcmAAD aadlen plaintext = KATGCMLong.gcmPlaintext ptlen (authTag, ciphertext) = aeadSimpleEncrypt aead aad plaintext 16 digest bs = BA.convert (hash bs :: Digest SHA256) :: ByteString +-- | Crypto.Cipher.AES.GCM builds the key part of the state once and does a+-- whole message in one call. It has to answer exactly what the general+-- interface answers, so it is run over the same vectors, and a tampered+-- message has to come back as Nothing rather than as plaintext.+oneShotTests :: Spec+oneShotTests = describe "Crypto.Cipher.AES.GCM" $ do+ describe "agrees with the general interface" $ do+ run "AES-128" KATGCM.vectors_aes128_enc+ run "AES-192" KATGCM.vectors_aes192_enc+ run "AES-256" KATGCM.vectors_aes256_enc+ describe "decryptWithTag hands back the tag encrypt made" $ do+ runTag "AES-128" KATGCM.vectors_aes128_enc+ runTag "AES-192" KATGCM.vectors_aes192_enc+ runTag "AES-256" KATGCM.vectors_aes256_enc+ it "decryptWithTag gives a different tag for a tampered ciphertext" $+ let ctx = ctx16+ sealed = GCM.encrypt ctx iv16 B.empty message 16 :: B.ByteString+ body = B.take (B.length sealed - 16) sealed+ tag = AuthTag (BA.convert (B.drop (B.length sealed - 16) sealed))+ (_, tag') =+ GCM.decryptWithTag ctx iv16 B.empty (flipFirst body) 16+ :: (B.ByteString, AuthTag)+ in tag' `shouldSatisfy` (/= tag)+ describe "refuses a message that was interfered with" $ do+ it "a flipped bit in the tag" $ tamper (\(c, t) -> (c, flipFirst t))+ it "a flipped bit in the ciphertext" $ tamper (\(c, t) -> (flipFirst c, t))+ it "refuses input shorter than the tag" $+ (GCM.decrypt ctx16 iv16 B.empty (B.replicate 8 0) 16 :: Maybe B.ByteString)+ `shouldBe` Nothing+ it "refuses a ciphertext with no authentication tag" $+ let sealed = GCM.encrypt ctx16 iv16 header message 16 :: B.ByteString+ body = B.take (B.length sealed - 16) sealed+ in (GCM.decrypt ctx16 iv16 header body 0 :: Maybe B.ByteString)+ `shouldBe` Nothing+ it "does not authenticate an altered ciphertext with a zero-length tag" $+ let sealed = GCM.encrypt ctx16 iv16 header message 16 :: B.ByteString+ body = B.take (B.length sealed - 16) sealed+ in (GCM.decrypt ctx16 iv16 header (flipFirst body) 0 :: Maybe B.ByteString)+ `shouldBe` Nothing+ -- Shorter than four bytes the tag authenticates next to nothing, and+ -- longer than sixteen there is no more tag for GCM to give.+ describe "refuses a tag length outside 4 to 16 bytes" $+ forM_ [0, 3, 17 :: Int] $ \taglen -> describe (show taglen) $ do+ it "encrypt" $+ evaluate (GCM.encrypt ctx16 iv16 header message taglen :: B.ByteString)+ `shouldThrow` (== CryptoError_AuthenticationTagSizeInvalid)+ it "decrypt" $+ (GCM.decrypt ctx16 iv16 header plainSealed taglen :: Maybe B.ByteString)+ `shouldBe` Nothing+ it "decryptWithTag" $+ evaluate+ ( GCM.decryptWithTag ctx16 iv16 header message taglen+ :: (B.ByteString, AuthTag)+ )+ `shouldThrow` (== CryptoError_AuthenticationTagSizeInvalid)+ it "encryptWithMask" $+ withMaskTag taglen 0 `shouldReturn` Nothing+ -- SP 800-38D 5.2.1.1 wants at least one byte of IV. With none, GCM's+ -- pre-counter block is zero and the tag of a message is+ -- GHASH_H(A, C) XOR E(K, 0^128) -- and E(K, 0^128) is the GHASH key H+ -- itself. One full tag therefore gives H away, H belongs to the key+ -- rather than to the nonce, and with it a tag can be forged for any+ -- message under any nonce the key has been used with, twelve-byte ones+ -- included. The general interface has refused the empty IV since+ -- f98cff3 and these four did not.+ describe "refuses a nonce of no bytes" $ do+ it "encrypt" $+ evaluate (GCM.encrypt ctx16 B.empty header message 16 :: B.ByteString)+ `shouldThrow` (== CryptoError_IvSizeInvalid)+ -- a message that really is sealed under the empty nonce, so that this+ -- says something whether or not `encrypt` refuses one: before the+ -- check, `decrypt` returned the sixteen bytes of plaintext for it+ it "decrypt, on a message that is genuine under it" $+ (GCM.decrypt ctx16 B.empty header emptyNonceSealed 16 :: Maybe B.ByteString)+ `shouldBe` Nothing+ it "decryptWithTag" $+ evaluate+ ( GCM.decryptWithTag ctx16 B.empty header message 16+ :: (B.ByteString, AuthTag)+ )+ `shouldThrow` (== CryptoError_IvSizeInvalid)+ it "encryptWithMask, writing nothing" $+ withMaskIv B.empty 16 4 `shouldReturn` Nothing+ -- and only the empty one: SP 800-38D allows every length from one byte up,+ -- so this must not become a check for twelve+ it "takes a nonce of one byte" $+ let iv1 = B.singleton 0x77+ sealed = GCM.encrypt ctx16 iv1 header message 16 :: B.ByteString+ in (GCM.decrypt ctx16 iv1 header sealed 16 :: Maybe B.ByteString)+ `shouldBe` Just message+ describe "header protection" $ do+ it "writes the ciphertext encrypt gives" $+ withMask 4 `shouldReturn` Just (plainSealed, expectedMask 4)+ it "and at another offset" $+ withMask 0 `shouldReturn` Just (plainSealed, expectedMask 0)+ it "refuses a sample that does not fit, writing nothing" $ do+ withMask (B.length plainSealed - 15) `shouldReturn` Nothing+ withMask (-1) `shouldReturn` Nothing+ where+ run name vs =+ it name $+ [ (key, iv)+ | (key, iv, aad, input, out, taglen, tag) <- vs+ , let ctx = throwCryptoError (GCM.newContext key)+ , let sealed = GCM.encrypt ctx iv aad input taglen :: B.ByteString+ , sealed /= out `B.append` tag+ || GCM.decrypt ctx iv aad sealed taglen /= Just input+ ]+ `shouldBe` []+ -- The tag decryptWithTag computes has to be the one encrypt appended, and+ -- the body it returns the one decrypt returns, over the same vectors.+ runTag name vs =+ it name $+ [ (key, iv)+ | (key, iv, aad, input, out, taglen, tag) <- vs+ , let ctx = throwCryptoError (GCM.newContext key)+ , let (body, tag') =+ GCM.decryptWithTag ctx iv aad out taglen+ :: (B.ByteString, AuthTag)+ , body /= input || tag' /= AuthTag (BA.convert tag)+ ]+ `shouldBe` []+ ctx16 = throwCryptoError (GCM.newContext (B.replicate 16 0x2b))+ iv16 = B.replicate 12 0x77+ -- header protection keeps a key of its own, as QUIC does+ hpKeyBytes = B.replicate 16 0x9c+ hpKey = throwCryptoError (GCM.newHeaderKey hpKeyBytes)+ hpAes = throwCryptoError (cipherInit hpKeyBytes) :: AES.AES128+ message = "a packet payload" :: B.ByteString+ header = "\x40\x01\x02\x03" :: B.ByteString+ plainSealed = GCM.encrypt ctx16 iv16 header message 16 :: B.ByteString+ -- ctx16, no nonce at all, `header` as the additional data and `message`+ -- as the plaintext, taken from the tree before the check went in+ emptyNonceSealed =+ "\x09\x25\xea\x53\x9b\x98\xf1\x0e\x02\x5f\x8a\x70\x8d\xf4\x6d\xb2\xf2\xce\x43\x31\x67\x12\x32\xef\x29\xcc\x69\x52\x12\x98\xd1\xf3"+ :: B.ByteString+ -- the buffers the caller owns, as a packet writer would have them+ withMask = withMaskTag 16+ withMaskTag = withMaskIv iv16+ withMaskIv iv taglen off =+ allocaBytes (B.length message + taglen) $ \outp ->+ allocaBytes 16 $ \maskp -> do+ ok <- GCM.encryptWithMask ctx16 hpKey iv header message taglen off outp maskp+ if ok+ then do+ sealed <- B.packCStringLen (castPtr outp, B.length message + taglen)+ mask <- B.packCStringLen (castPtr maskp, 16)+ return (Just (sealed, mask))+ else return Nothing+ expectedMask off = ecbEncrypt hpAes (B.take 16 (B.drop off plainSealed))+ flipFirst b = B.cons (B.head b `xor` 1) (B.tail b)+ tamper f =+ let sealed = GCM.encrypt ctx16 iv16 B.empty ("hello there" :: B.ByteString) 16+ (c, t) = B.splitAt (B.length sealed - 16) sealed+ (c', t') = f (c, t)+ in (GCM.decrypt ctx16 iv16 B.empty (c' `B.append` t') 16 :: Maybe B.ByteString)+ `shouldBe` Nothing+ spec :: Spec spec = do testBlockCipher128 kats128 (undefined :: AES.AES128)@@ -230,3 +394,4 @@ aeadIVLengthTests aeadTagLengthTests gcmLongTests+ oneShotTests
tests/ECDSASpec.hs view
@@ -79,8 +79,42 @@ ECC.signExtendedDigestWith k key digest >>= \s -> pure $ ECC.sign_s (ECC.signature s) <= n `div` 2 pure $ propertyHold [eqTest "normalized" (Just True) check] +-- | The deterministic nonce of RFC 6979, against the implementation in+-- Crypto.PubKey.ECC.ECDSA, which is itself held to the vectors in the RFC by+-- tests/PubKey/ECDSASpec.hs. Agreeing with it is agreeing with those.+propertyDeterministic+ :: HashAlgorithm hash => hash -> Curve -> ArbitraryBS0_2901 -> Gen Bool+propertyDeterministic hashAlg (Curve c curve _) (ArbitraryBS0_2901 msg) = do+ d <- arbitraryScalar curve+ let prx = Just c -- using Maybe as Proxy+ privECC = ECC.PrivateKey curve d+ privECDSA = throwCryptoError $ ECDSA.scalarFromInteger prx d+ pubECDSA = ECDSA.toPublic prx privECDSA+ digest = hashWith hashAlg msg+ kECC = ECC.deterministicNonce hashAlg privECC digest Just+ kECDSA =+ ECDSA.deterministicNonce prx hashAlg privECDSA digest Just+ sigECDSA = ECDSA.signDeterministic prx hashAlg privECDSA hashAlg msg+ sigWithK = fromJust $ ECDSA.signWith prx kECDSA privECDSA hashAlg msg+ pure $+ propertyHold+ [ eqTest "nonce" kECC (ECDSA.scalarToInteger prx kECDSA)+ , eqTest "signature matches signWith" sigWithK sigECDSA+ , eqTest+ "signature verifies"+ True+ (ECDSA.verify prx hashAlg pubECDSA sigECDSA msg)+ ]+ spec :: Spec spec = do+ modifyMaxSuccess (const 5) $+ describe "RFC 6979 deterministic nonce" $ do+ prop "SHA1" $ propertyDeterministic SHA1+ prop "SHA224" $ propertyDeterministic SHA224+ prop "SHA256" $ propertyDeterministic SHA256+ prop "SHA384" $ propertyDeterministic SHA384+ prop "SHA512" $ propertyDeterministic SHA512 modifyMaxSuccess (const 5) $ describe "verification" $ do prop "SHA1" $ propertyECDSA SHA1
tests/HashSpec.hs view
@@ -135,13 +135,16 @@ , "a8f04b0f7201a0d728101c9d26525b31764a3493fcd8458f" ] )- , {-- , ("Skein256-160", HashAlg Skein256_160, [- "ff800bed6d2044ee9d604a674e3fda50d9b24a72",- "3265703c166aa3e0d7da070b9cf1b1a5953f0a77",- "17b29aa1424b3ec022505bd215ff73fd2e6d1e5a" ])- -}-+ ,+ ( "Skein256-160"+ , HashAlg (Skein256 :: Skein256 160)+ ,+ [ "ff800bed6d2044ee9d604a674e3fda50d9b24a72"+ , "3265703c166aa3e0d7da070b9cf1b1a5953f0a77"+ , "17b29aa1424b3ec022505bd215ff73fd2e6d1e5a"+ ]+ )+ , ( "Skein256-256" , HashAlg Skein256_256 ,@@ -150,13 +153,16 @@ , "fb2f2f2deed0e1dd7ee2b91cee34e2d1c22072e1f5eaee288c35a0723eb653cd" ] )- , {-- , ("Skein512-160", HashAlg Skein512_160, [- "49daf1ccebb3544bc93cb5019ba91b0eea8876ee",- "826325ee55a6dd18c3b2dbbc9c10420f5475975e",- "7544ec7a35712ec953f02b0d0c86641cae4eb6e5" ])- -}-+ ,+ ( "Skein512-160"+ , HashAlg (Skein512 :: Skein512 160)+ ,+ [ "49daf1ccebb3544bc93cb5019ba91b0eea8876ee"+ , "826325ee55a6dd18c3b2dbbc9c10420f5475975e"+ , "7544ec7a35712ec953f02b0d0c86641cae4eb6e5"+ ]+ )+ , ( "Skein512-384" , HashAlg Skein512_384 ,@@ -563,9 +569,41 @@ Nothing -> error ("invalid Nat: " ++ show n) Just (SomeNat p) -> convert (hashEmpty p) +-- | The Skein types with the size in their name and the ones that take it as+-- a type parameter are the same function, and the parameter also takes the+-- sizes that have no name of their own.+skeinNatTests :: Spec+skeinNatTests = describe "Skein with the digest size as a type parameter" $ do+ describe "agrees with the type of that name" $ do+ it "Skein256 224" $ same (Skein256 :: Skein256 224) Skein256_224+ it "Skein256 256" $ same (Skein256 :: Skein256 256) Skein256_256+ it "Skein512 224" $ same (Skein512 :: Skein512 224) Skein512_224+ it "Skein512 256" $ same (Skein512 :: Skein512 256) Skein512_256+ it "Skein512 384" $ same (Skein512 :: Skein512 384) Skein512_384+ it "Skein512 512" $ same (Skein512 :: Skein512 512) Skein512_512+ describe "takes a size no named type offers" $ do+ it "8 bits" $ len (Skein512 :: Skein512 8) `shouldBe` 1+ it "1024 bits" $ len (Skein512 :: Skein512 1024) `shouldBe` 128+ it "8192 bits" $ len (Skein512 :: Skein512 8192) `shouldBe` 1024+ it "rounds a size that is not a whole number of bytes up" $ do+ len (Skein512 :: Skein512 100) `shouldBe` 13+ len (Skein256 :: Skein256 1) `shouldBe` 1+ -- the length goes into the configuration block, so it changes the chaining+ -- value the message is hashed from: a longer digest is not an extension of+ -- a shorter one, which is the opposite of how SHAKE behaves+ it "answers a different size with an unrelated digest, not a longer one" $ do+ let short = convert (hashWith (Skein512 :: Skein512 256) v1) :: ByteString+ long = convert (hashWith (Skein512 :: Skein512 512) v1) :: ByteString+ B.take (B.length short) long `shouldNotBe` short+ where+ same a b = map (h a) vectors `shouldBe` map (h b) vectors+ h alg m = convert (hashWith alg m) :: ByteString+ len alg = B.length (convert (hashWith alg v1) :: ByteString)+ spec :: Spec spec = do describe "KATs" $ mapM_ makeTestAlg expected+ skeinNatTests describe "KATs over several blocks" $ mapM_ (makeTestAlgWith longVectors) expectedLong describe "Chunking" $ mapM_ makeTestChunk expected
tests/KDF/PBKDF2Spec.hs view
@@ -110,7 +110,18 @@ `shouldBe` refused PBKDF2.tryFastPBKDF2_SHA512 (PBKDF2.Parameters 1 (-1)) badPass badSalt `shouldBe` refused+ -- Zero is not rejected: asking for no key is asking for no work, and+ -- that is what the slow path has always answered. The fast ones go+ -- straight to C, where `assert(out && nout)` took the process down+ -- on a length the caller chose -- a library built without NDEBUG+ -- keeps its assertions. All four agree now.+ it "derives nothing when asked for nothing" $ do+ slow none `shouldBe` ""+ fast1 none `shouldBe` ""+ fast256 none `shouldBe` ""+ fast512 none `shouldBe` "" where+ none = PBKDF2.Parameters 1 0 badPrf = PBKDF2.prfHMAC SHA256 badPass = "password" :: ByteString badSalt = "salt" :: ByteString
tests/NumberSpec.hs view
@@ -95,6 +95,24 @@ bigPrime = 2 ^ (512 :: Int) - 569 bigComposite = (2 ^ (256 :: Int) - 189) * (2 ^ (256 :: Int) - 357) +-- | The two sizes at which the exponentiation hands its multiplication to+-- s2n-bignum's assembly: a modulus of exactly sixteen or thirty-two 64-bit+-- limbs, which is 1024 or 2048 bits -- the halves a CRT exponentiation works+-- in for RSA-2048 and RSA-4096, and nothing else. A property over moduli of+-- no particular size reaches that path only by accident, and the one below+-- with "a modulus a key would have" is 1025 bits, one limb too wide.+modulus1024, modulus2048 :: Integer+modulus1024 = bit 1023 .|. (bigPrime * bigComposite `mod` bit 1023) .|. 1+modulus2048 =+ bit 2047 .|. ((bigPrime * bigComposite) ^ (2 :: Int) `mod` bit 2047) .|. 1++-- | A number of up to this many bytes. 'QAInteger' stops at thirty-two,+-- which is too narrow for either of these: the base has to be able to fill a+-- modulus and to overflow it, and the exponent's length is what the window+-- walks.+wideOf :: Int -> Gen Integer+wideOf bytes = BE.os2ip <$> arbitraryBSof 0 bytes+ -- the index is threaded through so that repeated calls cannot be shared askAgain :: Int -> Integer -> Bool askAgain i n = i `seq` primalityTestMillerRabin 1 n@@ -174,6 +192,16 @@ \(QAInteger b) (QAInteger e) -> let m = 2 * bigPrime * bigComposite + 1 -- odd, and 1025 bits in expSafe b (abs e) m === expFast b (abs e) m+ prop "agrees with the fast one at the two sizes with assembly behind them" $+ forAll (elements [modulus1024, modulus2048]) $ \m ->+ forAll (wideOf 300) $ \b ->+ forAll (wideOf 256) $ \e ->+ expSafe b e m === expFast b e m+ prop "agrees with the fast one whatever the exponent's length" $+ forAll (choose (0, 129)) $ \bytes ->+ forAll (wideOf bytes) $ \e ->+ forAll (wideOf 128) $ \b ->+ expSafe b e modulus1024 === expFast b e modulus1024 where safely (b, e, m) = expSafe b e m fastly (b, e, m) = expFast b e m@@ -239,6 +267,10 @@ numBytes i == byteCount i prop "num-bytes-small" $ \() -> map numBytes [0, 1, 255, 256, 257, 65535, 65536] == [0, 1, 1, 2, 2, 2, 3]+ -- the magnitude, which is what GMP counts, and what the fallback used to+ -- divide by 256 forever looking for a quotient of zero+ prop "num-bits-negative" $ \(Positive i) ->+ numBits (negate i) == numBits i prop "generate-param" $ \testDRG (Int1_2901 bits) -> let r = withTestDRG testDRG $ generateParams bits (Just SetHighest) False in r >= 0 && numBits r == bits && testBit r (bits - 1)
tests/PubKey/P256Spec.hs view
@@ -157,6 +157,21 @@ [ eqTest "scalarZero" P256.scalarZero inv0 , eqTest "scalarN" P256.scalarZero invN ]+ -- The same two for the variable-time inverse, which is exported and+ -- which scalarFromBinary will happily hand a zero. It used not to+ -- return at all on that: in the binary extended Euclid below it, zero+ -- stays even and is halved forever, and the loop's only exit is in+ -- the branch both operands must be odd to reach. Not even+ -- System.Timeout gets a program out of that, the hang being inside a+ -- foreign call. The properties above step around it with a+ -- precondition; this one walks into it.+ prop "inv-zero" $+ let inv0 = P256.scalarInv P256.scalarZero+ invN = P256.scalarInv P256.scalarN+ in propertyHold+ [ eqTest "scalarZero" P256.scalarZero inv0+ , eqTest "scalarN" P256.scalarZero invN+ ] describe "point" $ do prop "marshalling" $ \rx ry -> let p = P256.pointFromIntegers (unP256 rx, unP256 ry)@@ -191,6 +206,19 @@ prop "point-add-inverse" propertyPointAddInverse prop "point-negate" propertyPointNegate prop "point-mul" propertyPointMul+ -- A signed window can reach the last addition with the accumulator+ -- equal to the very point it is adding, which the formulas cannot+ -- do: they answer the infinity where the truth is twice that point.+ -- Which scalars do it depends on the window and on the order mod 64;+ -- for the five-bit window here it is 30 alone, and the sweep that+ -- found it covered every scalar below a million and every one within+ -- a million of the order. The neighbours are here because they are+ -- the family it came from.+ describe "point-mul-small-scalars" $+ sequence_+ [ it (show k) (casePointMulSmall k)+ | k <- [1 .. 70] ++ [2 ^ (32 :: Int), 2 ^ (64 :: Int)]+ ] prop "infinity" $ let gN = P256.toPoint P256.scalarN g1 = P256.pointBase@@ -198,7 +226,18 @@ [ eqTest "zero" True (P256.pointIsAtInfinity gN) , eqTest "base" False (P256.pointIsAtInfinity g1) ]+ -- The variable-point multiplication is what the vendored assembly+ -- replaces where there is any, so say out loud what the two ends of+ -- the scalar range do on a point that is not the base one.+ it "point-mul-order" $+ P256.pointIsAtInfinity (P256.pointMul P256.scalarN point7)+ `shouldBe` True+ it "point-mul-order-minus-one" $+ P256.pointMul (unP256Scalar (P256Scalar (curveN - 1))) point7+ `shouldBe` P256.pointNegate point7 where+ point7 = P256.toPoint (unP256Scalar (P256Scalar 7))+ casePointIsValid pointTuple = let s = P256.pointFromIntegers pointTuple in P256.pointIsValid s `shouldBe` True @@ -239,6 +278,13 @@ [ eqTest "p256" pR (P256.pointMul (unP256Scalar s) p) , eqTest "ecc" peR (pointP256ToECC pR) ]++ -- k * (7 * G), against the reference implementation.+ casePointMulSmall k =+ let base = P256.toPoint (unP256Scalar (P256Scalar 7))+ baseE = ECC.pointMul curve 7 curveGen+ got = P256.pointMul (unP256Scalar (P256Scalar k)) base+ in ECC.pointMul curve k baseE `propertyEq` pointP256ToECC got pointInfinity :: P256.Point pointInfinity = P256.pointFromIntegers (0, 0)
tests/PubKey/PSSSpec.hs view
@@ -2,9 +2,14 @@ module PubKey.PSSSpec (spec) where +import Crypto.Number.Basic (numBits) import Crypto.Number.Serialize (i2ospOf_, os2ip) import Crypto.PubKey.RSA+import Crypto.PubKey.RSA.Prim (dp, ep) import qualified Crypto.PubKey.RSA.PSS as PSS+import qualified Data.ByteString as B+import qualified Data.Bits as Bits+import Data.Word (Word8) import Imports @@ -494,10 +499,61 @@ , os2ip sg + modulus < 2 ^ (8 * k) ] +-- | RFC 8017 9.1.2 step 6: the leftmost @8*emLen - emBits@ bits of the+-- leftmost octet of maskedDB have to be zero. Step 9 clears them in DB,+-- and clearing is not checking -- an encoding with one of them set used to+-- verify as though it were sound, because the bit that made it wrong was+-- thrown away before anything looked at it.+--+-- Only the signer can produce such a thing, since it takes the private key+-- to sign a chosen encoding, so this is conformance rather than forgery.+-- The vectors are walked for one whose altered encoding stays below the+-- modulus, as the signature range tests above do, because an encoding at or+-- past it says nothing.+step6Tests :: Spec+step6Tests = describe "an encoding with a bit outside emBits set" $ do+ it "the honest signature verifies, key 1024" $+ verifies rsaKey1 (fst (altered rsaKey1 vectorsKey1)) `shouldBe` True+ it "and the altered one does not, key 1024" $+ verifies rsaKey1 (snd (altered rsaKey1 vectorsKey1)) `shouldBe` False+ it "the honest signature verifies, key 1026" $+ verifies rsaKey3 (fst (altered rsaKey3 vectorsKey3)) `shouldBe` True+ it "and the altered one does not, key 1026" $+ verifies rsaKey3 (snd (altered rsaKey3 vectorsKey3)) `shouldBe` False+ it "key 1025 has no bits outside emBits to set" $+ forbidden (numBits (public_n (private_pub rsaKey2))) `shouldBe` 0+ where+ verifies key (v, sg) =+ PSS.verify PSS.defaultPSSParamsSHA1 (private_pub key) (message v) sg++ -- the bits of the leftmost octet the standard requires to be zero+ forbidden bits = Bits.complement mask+ where+ mask = if sh > 0 then 0xff `Bits.shiftR` (8 - sh) else 0xff :: Word8+ sh = (bits - 1) Bits..&. 0x7++ -- the first vector whose encoding, with a forbidden bit set, is still+ -- below the modulus, paired as (honest, altered)+ altered key vs = firstVector+ [ ((v, signature v), (v, dp Nothing key em'))+ | v <- vs+ , let pub = private_pub key+ em = ep pub (signature v)+ bit = lowestSet (forbidden (numBits (public_n pub)))+ em' = B.cons (B.head em Bits..|. bit) (B.tail em)+ , B.head em Bits..&. forbidden (numBits (public_n pub)) == 0+ , os2ip em' < public_n pub+ ]++ -- the forbidden bit worth setting is the lowest of them: it is the one+ -- that adds least, and an encoding at or past the modulus proves nothing+ lowestSet w = minimum ([2 ^ i | i <- [0 .. 7 :: Int], Bits.testBit w i])+ spec :: Spec spec = describe "RSA-PSS" $ do signatureRangeTests+ step6Tests describe "signature internal" $ do doSignTest rsaKeyInt katZero vectorInt describe "verify internal" $ do
tests/StreamCipher/ChaChaPoly1305Spec.hs view
@@ -2,12 +2,14 @@ module StreamCipher.ChaChaPoly1305Spec where +import qualified Crypto.Cipher.ChaCha.Poly1305 as One import qualified Crypto.Cipher.ChaChaPoly1305 as CP import Crypto.Cipher.Types import Crypto.Error import Imports import MAC.Poly1305Spec () +import Data.Bits (xor) import qualified Data.ByteArray as B (convert) import qualified Data.ByteString as B @@ -89,8 +91,39 @@ CryptoPassed st -> aeadSimpleDecrypt st a5aad a5cipher (AuthTag $ B.convert a5tag) _ -> Nothing +-- | The key is checked once, where it is made, and initializing cannot fail+-- after that.+keyTests :: Spec+keyTests = describe "key" $ do+ it "takes thirty-two bytes" $+ passed (CP.key (B.replicate 32 0x41)) `shouldBe` True+ it "refuses any other length" $+ [n | n <- [0, 1, 16, 31, 33, 64], passed (CP.key (B.replicate n 0x41))]+ `shouldBe` []+ it "says which error" $+ -- Key has no Show, on purpose: it is key material+ errorOf (CP.key (B.replicate 31 0x41))+ `shouldBe` Just CryptoError_KeySizeInvalid+ it "and the AEAD entry point reports the same thing" $+ errorOf+ (CP.aeadChacha20poly1305Init (B.replicate 31 0x41) (B.replicate 12 0x42))+ `shouldBe` Just CryptoError_KeySizeInvalid+ it "a key that was taken initializes without an error case" $ do+ let k = throwCryptoError (CP.key (B.replicate 32 0x41))+ n = throwCryptoError (CP.nonce12 (B.replicate 12 0x42))+ st = CP.initialize k n+ (out, st') = CP.encrypt ("hello" :: B.ByteString) (CP.finalizeAAD st)+ B.length out `shouldBe` 5+ B.length (B.convert (CP.finalize st') :: B.ByteString) `shouldBe` 16+ where+ passed (CryptoPassed _) = True+ passed (CryptoFailed _) = False+ errorOf (CryptoFailed e) = Just e+ errorOf (CryptoPassed _) = Nothing+ spec :: Spec spec = do+ keyTests it "V1" runEncrypt it "V1-decrypt" runDecrypt it "V1-extended" runEncryptX@@ -98,11 +131,13 @@ it "nonce increment" runNonceInc it "RFC8439 A5 enc" rfc8439encrypt it "RFC8439 A5 dec" rfc8439decrypt+ oneShotTests where runEncrypt = let ini =- throwCryptoError $- CP.initialize key (throwCryptoError $ CP.nonce8 constant iv)+ CP.initialize+ (throwCryptoError $ CP.key key)+ (throwCryptoError $ CP.nonce8 constant iv) afterAAD = CP.finalizeAAD (CP.appendAAD aad ini) (out, afterEncrypt) = CP.encrypt plaintext afterAAD outtag = CP.finalize afterEncrypt@@ -112,7 +147,9 @@ ] runEncryptX = let ini =- throwCryptoError $ CP.initializeX key (throwCryptoError $ CP.nonce24 ivX)+ CP.initializeX+ (throwCryptoError $ CP.key key)+ (throwCryptoError $ CP.nonce24 ivX) afterAAD = CP.finalizeAAD (CP.appendAAD aad ini) (out, afterEncrypt) = CP.encrypt plaintext afterAAD outtag = CP.finalize afterEncrypt@@ -123,8 +160,9 @@ runDecrypt = let ini =- throwCryptoError $- CP.initialize key (throwCryptoError $ CP.nonce8 constant iv)+ CP.initialize+ (throwCryptoError $ CP.key key)+ (throwCryptoError $ CP.nonce8 constant iv) afterAAD = CP.finalizeAAD (CP.appendAAD aad ini) (out, afterDecrypt) = CP.decrypt ciphertext afterAAD outtag = CP.finalize afterDecrypt@@ -135,7 +173,9 @@ runDecryptX = let ini =- throwCryptoError $ CP.initializeX key (throwCryptoError $ CP.nonce24 ivX)+ CP.initializeX+ (throwCryptoError $ CP.key key)+ (throwCryptoError $ CP.nonce24 ivX) afterAAD = CP.finalizeAAD (CP.appendAAD aad ini) (out, afterDecrypt) = CP.decrypt ciphertextX afterAAD outtag = CP.finalize afterDecrypt@@ -165,3 +205,66 @@ B.convert . CP.incrementNonce $ n10 ]++-- | Crypto.Cipher.ChaCha.Poly1305 does a whole message in one call where+-- Crypto.Cipher.ChaChaPoly1305 does it in steps. It has to answer exactly+-- what the steps answer, and what RFC 8439 prints.+oneShotTests :: Spec+oneShotTests = describe "Crypto.Cipher.ChaCha.Poly1305" $ do+ it "RFC 8439 2.8.2, twelve-byte nonce" $+ propertyHoldCase+ [ eqTest "ciphertext" ciphertext (B.take (B.length ciphertext) sealed)+ , eqTest "tag" tag (B.drop (B.length ciphertext) sealed)+ ]+ it "decrypt undoes encrypt" $+ One.decrypt ctx nonce12 aad sealed 16 `shouldBe` Just plaintext+ it "refuses a flipped bit in the ciphertext" $+ One.decrypt ctx nonce12 aad (flipHead sealed) 16+ `shouldBe` (Nothing :: Maybe B.ByteString)+ it "refuses a flipped bit in the tag" $+ One.decrypt ctx nonce12 aad (flipLast sealed) 16+ `shouldBe` (Nothing :: Maybe B.ByteString)+ it "refuses input shorter than the tag" $+ One.decrypt ctx nonce12 aad (B.replicate 8 0) 16+ `shouldBe` (Nothing :: Maybe B.ByteString)+ it "refuses a ciphertext with no authentication tag" $+ One.decrypt ctx nonce12 aad ciphertext 0+ `shouldBe` (Nothing :: Maybe B.ByteString)+ it "does not authenticate an altered ciphertext with a zero-length tag" $+ One.decrypt ctx nonce12 aad (flipHead ciphertext) 0+ `shouldBe` (Nothing :: Maybe B.ByteString)+ it "refuses a nonce that is not twelve bytes" $ do+ One.decrypt ctx (B.replicate 10 0) aad sealed 16+ `shouldBe` (Nothing :: Maybe B.ByteString)+ -- eight is the other ChaCha construction, not this AEAD+ One.decrypt ctx (B.replicate 8 0) aad sealed 16+ `shouldBe` (Nothing :: Maybe B.ByteString)+ it "decryptWithTag hands back the tag encrypt made" $+ case One.decryptWithTag ctx nonce12 aad (B.take (B.length ciphertext) sealed) 16 of+ CryptoFailed e -> expectationFailure (show e)+ CryptoPassed (body, t) ->+ propertyHoldCase+ [ eqTest "plaintext" plaintext body+ , eqTest "tag" (AuthTag (B.convert tag)) t+ ]+ it "agrees with the step-at-a-time interface over a different message" $+ let msg = "another message, of a length that is not a multiple of 16" :: B.ByteString+ ad = "\x01\x02\x03" :: B.ByteString+ ini = CP.initialize (throwCryptoError $ CP.key key)+ (throwCryptoError $ CP.nonce12 nonce12)+ afterAAD = CP.finalizeAAD (CP.appendAAD ad ini)+ (out, afterEnc) = CP.encrypt msg afterAAD+ t = CP.finalize afterEnc+ one = throwCryptoError (One.encrypt ctx nonce12 ad msg 16) :: B.ByteString+ in propertyHoldCase+ [ eqTest "ciphertext" out (B.take (B.length out) one)+ , eqTest "tag" (B.convert t :: B.ByteString) (B.drop (B.length out) one)+ ]+ where+ ctx = throwCryptoError (One.newContext key)+ -- the same nonce the step interface builds from constant and iv+ nonce12 = constant `B.append` iv+ sealed = throwCryptoError (One.encrypt ctx nonce12 aad plaintext 16) :: B.ByteString+ flipHead bs = B.cons (B.head bs `xor` 1) (B.tail bs)+ flipLast bs =+ B.snoc (B.init bs) (B.last bs `xor` 1)