aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorprosecco <prosecco@github.com>2018-02-01 22:31:40 +0100
committerprosecco <prosecco@github.com>2018-02-01 22:31:40 +0100
commit8b7f68d393da2e7808f4760f070fe85c20b0e67b (patch)
tree237952378ed291580c76585fa4e4d7c93196e5a5
parenthacl64: optimizations (diff)
downloadkbench9000-8b7f68d393da2e7808f4760f070fe85c20b0e67b.tar.xz
kbench9000-8b7f68d393da2e7808f4760f070fe85c20b0e67b.zip
poly
-rw-r--r--Makefile2
-rw-r--r--curve25519-amd64-asm.S1888
-rw-r--r--curve25519-amd64.c234
-rw-r--r--curve25519-donna32.c861
-rw-r--r--curve25519-donna64.c414
-rw-r--r--curve25519-fiat32.c838
-rw-r--r--curve25519-fiat64.c577
-rw-r--r--curve25519-hacl64.c763
-rw-r--r--curve25519-precomp.c1551
-rw-r--r--curve25519-sandy2x-asm.S3261
-rw-r--r--curve25519-sandy2x.c139
-rw-r--r--kremlib.h569
-rw-r--r--main.c55
-rw-r--r--poly1305-hacl64.c569
-rw-r--r--res26005
-rw-r--r--test_vectors.h1487
16 files changed, 28614 insertions, 10599 deletions
diff --git a/Makefile b/Makefile
index b32bd88..0a8f19a 100644
--- a/Makefile
+++ b/Makefile
@@ -1,5 +1,5 @@
ifneq ($(KERNELRELEASE),)
-kbench9000-y := main.o curve25519-donna64.o curve25519-hacl64.o curve25519-fiat64.o curve25519-sandy2x.o curve25519-sandy2x-asm.o curve25519-amd64.o curve25519-precomp.o curve25519-amd64-asm.o curve25519-donna32.o curve25519-fiat32.o
+kbench9000-y := main.o poly1305-hacl64.o
obj-m := kbench9000.o
ccflags-y += -O3
ccflags-y += -D'pr_fmt(fmt)=KBUILD_MODNAME ": " fmt'
diff --git a/curve25519-amd64-asm.S b/curve25519-amd64-asm.S
deleted file mode 100644
index 27a5b6a..0000000
--- a/curve25519-amd64-asm.S
+++ /dev/null
@@ -1,1888 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2015 Google Inc. All Rights Reserved.
- * Copyright (C) 2015-2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * Original author: Peter Schwabe <peter@cryptojedi.org>
- */
-
-/************************************************
- * W A R N I N G
- * W A R N I N G
- * W A R N I N G
- * W A R N I N G
- * W A R N I N G
- *
- * Do not import this file into the kernel as-is,
- * because it makes use of the x86_64 redzone,
- * which will entirely melt the kernel. We're sort
- * of getting away with it here, since interrupts
- * are disabled, but DANGER this will kill kittens.
- *
- * W A R N I N G
- * W A R N I N G
- * W A R N I N G
- * W A R N I N G
- * W A R N I N G
- ************************************************/
-
-.data
-.p2align 4
-
-x25519_x86_64_REDMASK51: .quad 0x0007FFFFFFFFFFFF
-x25519_x86_64_121666_213: .quad 996687872
-x25519_x86_64_2P0: .quad 0xFFFFFFFFFFFDA
-x25519_x86_64_2P1234: .quad 0xFFFFFFFFFFFFE
-x25519_x86_64_4P0: .quad 0x1FFFFFFFFFFFB4
-x25519_x86_64_4P1234: .quad 0x1FFFFFFFFFFFFC
-x25519_x86_64_MU0: .quad 0xED9CE5A30A2C131B
-x25519_x86_64_MU1: .quad 0x2106215D086329A7
-x25519_x86_64_MU2: .quad 0xFFFFFFFFFFFFFFEB
-x25519_x86_64_MU3: .quad 0xFFFFFFFFFFFFFFFF
-x25519_x86_64_MU4: .quad 0x000000000000000F
-x25519_x86_64_ORDER0: .quad 0x5812631A5CF5D3ED
-x25519_x86_64_ORDER1: .quad 0x14DEF9DEA2F79CD6
-x25519_x86_64_ORDER2: .quad 0x0000000000000000
-x25519_x86_64_ORDER3: .quad 0x1000000000000000
-x25519_x86_64_EC2D0: .quad 1859910466990425
-x25519_x86_64_EC2D1: .quad 932731440258426
-x25519_x86_64_EC2D2: .quad 1072319116312658
-x25519_x86_64_EC2D3: .quad 1815898335770999
-x25519_x86_64_EC2D4: .quad 633789495995903
-x25519_x86_64__38: .quad 38
-
-.text
-.p2align 5
-
-.globl x25519_x86_64_freeze
-.hidden x25519_x86_64_freeze
-x25519_x86_64_freeze:
-.cfi_startproc
-/* This is a leaf function and uses the redzone for saving registers. */
-movq %r12,-8(%rsp)
-.cfi_rel_offset r12, -8
-movq 0(%rdi),%rsi
-movq 8(%rdi),%rdx
-movq 16(%rdi),%rcx
-movq 24(%rdi),%r8
-movq 32(%rdi),%r9
-movq x25519_x86_64_REDMASK51(%rip),%rax
-mov %rax,%r10
-sub $18,%r10
-mov $3,%r11
-._reduceloop:
-mov %rsi,%r12
-shr $51,%r12
-and %rax,%rsi
-add %r12,%rdx
-mov %rdx,%r12
-shr $51,%r12
-and %rax,%rdx
-add %r12,%rcx
-mov %rcx,%r12
-shr $51,%r12
-and %rax,%rcx
-add %r12,%r8
-mov %r8,%r12
-shr $51,%r12
-and %rax,%r8
-add %r12,%r9
-mov %r9,%r12
-shr $51,%r12
-and %rax,%r9
-imulq $19,%r12,%r12
-add %r12,%rsi
-sub $1,%r11
-ja ._reduceloop
-mov $1,%r12
-cmp %r10,%rsi
-cmovl %r11,%r12
-cmp %rax,%rdx
-cmovne %r11,%r12
-cmp %rax,%rcx
-cmovne %r11,%r12
-cmp %rax,%r8
-cmovne %r11,%r12
-cmp %rax,%r9
-cmovne %r11,%r12
-neg %r12
-and %r12,%rax
-and %r12,%r10
-sub %r10,%rsi
-sub %rax,%rdx
-sub %rax,%rcx
-sub %rax,%r8
-sub %rax,%r9
-movq %rsi,0(%rdi)
-movq %rdx,8(%rdi)
-movq %rcx,16(%rdi)
-movq %r8,24(%rdi)
-movq %r9,32(%rdi)
-movq -8(%rsp),%r12
-ret
-.cfi_endproc
-
-.p2align 5
-.globl x25519_x86_64_mul
-.hidden x25519_x86_64_mul
-x25519_x86_64_mul:
-.cfi_startproc
-/* This is a leaf function and uses the redzone for saving registers. */
-movq %r12,-8(%rsp)
-.cfi_rel_offset r12, -8
-movq %r13,-16(%rsp)
-.cfi_rel_offset r13, -16
-movq %r14,-24(%rsp)
-.cfi_rel_offset r14, -24
-movq %r15,-32(%rsp)
-.cfi_rel_offset r15, -32
-movq %rbx,-40(%rsp)
-.cfi_rel_offset rbx, -40
-movq %rbp,-48(%rsp)
-.cfi_rel_offset rbp, -48
-mov %rdx,%rcx
-movq 24(%rsi),%rdx
-imulq $19,%rdx,%rax
-movq %rax,-64(%rsp)
-mulq 16(%rcx)
-mov %rax,%r8
-mov %rdx,%r9
-movq 32(%rsi),%rdx
-imulq $19,%rdx,%rax
-movq %rax,-72(%rsp)
-mulq 8(%rcx)
-add %rax,%r8
-adc %rdx,%r9
-movq 0(%rsi),%rax
-mulq 0(%rcx)
-add %rax,%r8
-adc %rdx,%r9
-movq 0(%rsi),%rax
-mulq 8(%rcx)
-mov %rax,%r10
-mov %rdx,%r11
-movq 0(%rsi),%rax
-mulq 16(%rcx)
-mov %rax,%r12
-mov %rdx,%r13
-movq 0(%rsi),%rax
-mulq 24(%rcx)
-mov %rax,%r14
-mov %rdx,%r15
-movq 0(%rsi),%rax
-mulq 32(%rcx)
-mov %rax,%rbx
-mov %rdx,%rbp
-movq 8(%rsi),%rax
-mulq 0(%rcx)
-add %rax,%r10
-adc %rdx,%r11
-movq 8(%rsi),%rax
-mulq 8(%rcx)
-add %rax,%r12
-adc %rdx,%r13
-movq 8(%rsi),%rax
-mulq 16(%rcx)
-add %rax,%r14
-adc %rdx,%r15
-movq 8(%rsi),%rax
-mulq 24(%rcx)
-add %rax,%rbx
-adc %rdx,%rbp
-movq 8(%rsi),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rcx)
-add %rax,%r8
-adc %rdx,%r9
-movq 16(%rsi),%rax
-mulq 0(%rcx)
-add %rax,%r12
-adc %rdx,%r13
-movq 16(%rsi),%rax
-mulq 8(%rcx)
-add %rax,%r14
-adc %rdx,%r15
-movq 16(%rsi),%rax
-mulq 16(%rcx)
-add %rax,%rbx
-adc %rdx,%rbp
-movq 16(%rsi),%rdx
-imulq $19,%rdx,%rax
-mulq 24(%rcx)
-add %rax,%r8
-adc %rdx,%r9
-movq 16(%rsi),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rcx)
-add %rax,%r10
-adc %rdx,%r11
-movq 24(%rsi),%rax
-mulq 0(%rcx)
-add %rax,%r14
-adc %rdx,%r15
-movq 24(%rsi),%rax
-mulq 8(%rcx)
-add %rax,%rbx
-adc %rdx,%rbp
-movq -64(%rsp),%rax
-mulq 24(%rcx)
-add %rax,%r10
-adc %rdx,%r11
-movq -64(%rsp),%rax
-mulq 32(%rcx)
-add %rax,%r12
-adc %rdx,%r13
-movq 32(%rsi),%rax
-mulq 0(%rcx)
-add %rax,%rbx
-adc %rdx,%rbp
-movq -72(%rsp),%rax
-mulq 16(%rcx)
-add %rax,%r10
-adc %rdx,%r11
-movq -72(%rsp),%rax
-mulq 24(%rcx)
-add %rax,%r12
-adc %rdx,%r13
-movq -72(%rsp),%rax
-mulq 32(%rcx)
-add %rax,%r14
-adc %rdx,%r15
-movq x25519_x86_64_REDMASK51(%rip),%rsi
-shld $13,%r8,%r9
-and %rsi,%r8
-shld $13,%r10,%r11
-and %rsi,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rsi,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rsi,%r14
-add %r13,%r14
-shld $13,%rbx,%rbp
-and %rsi,%rbx
-add %r15,%rbx
-imulq $19,%rbp,%rdx
-add %rdx,%r8
-mov %r8,%rdx
-shr $51,%rdx
-add %r10,%rdx
-mov %rdx,%rcx
-shr $51,%rdx
-and %rsi,%r8
-add %r12,%rdx
-mov %rdx,%r9
-shr $51,%rdx
-and %rsi,%rcx
-add %r14,%rdx
-mov %rdx,%rax
-shr $51,%rdx
-and %rsi,%r9
-add %rbx,%rdx
-mov %rdx,%r10
-shr $51,%rdx
-and %rsi,%rax
-imulq $19,%rdx,%rdx
-add %rdx,%r8
-and %rsi,%r10
-movq %r8,0(%rdi)
-movq %rcx,8(%rdi)
-movq %r9,16(%rdi)
-movq %rax,24(%rdi)
-movq %r10,32(%rdi)
-movq -8(%rsp),%r12
-movq -16(%rsp),%r13
-movq -24(%rsp),%r14
-movq -32(%rsp),%r15
-movq -40(%rsp),%rbx
-movq -48(%rsp),%rbp
-ret
-.cfi_endproc
-
-.p2align 5
-.globl x25519_x86_64_square
-.hidden x25519_x86_64_square
-x25519_x86_64_square:
-.cfi_startproc
-/* This is a leaf function and uses the redzone for saving registers. */
-movq %r12,-8(%rsp)
-.cfi_rel_offset r12, -8
-movq %r13,-16(%rsp)
-.cfi_rel_offset r13, -16
-movq %r14,-24(%rsp)
-.cfi_rel_offset r14, -24
-movq %r15,-32(%rsp)
-.cfi_rel_offset r15, -32
-movq %rbx,-40(%rsp)
-.cfi_rel_offset rbx, -40
-movq 0(%rsi),%rax
-mulq 0(%rsi)
-mov %rax,%rcx
-mov %rdx,%r8
-movq 0(%rsi),%rax
-shl $1,%rax
-mulq 8(%rsi)
-mov %rax,%r9
-mov %rdx,%r10
-movq 0(%rsi),%rax
-shl $1,%rax
-mulq 16(%rsi)
-mov %rax,%r11
-mov %rdx,%r12
-movq 0(%rsi),%rax
-shl $1,%rax
-mulq 24(%rsi)
-mov %rax,%r13
-mov %rdx,%r14
-movq 0(%rsi),%rax
-shl $1,%rax
-mulq 32(%rsi)
-mov %rax,%r15
-mov %rdx,%rbx
-movq 8(%rsi),%rax
-mulq 8(%rsi)
-add %rax,%r11
-adc %rdx,%r12
-movq 8(%rsi),%rax
-shl $1,%rax
-mulq 16(%rsi)
-add %rax,%r13
-adc %rdx,%r14
-movq 8(%rsi),%rax
-shl $1,%rax
-mulq 24(%rsi)
-add %rax,%r15
-adc %rdx,%rbx
-movq 8(%rsi),%rdx
-imulq $38,%rdx,%rax
-mulq 32(%rsi)
-add %rax,%rcx
-adc %rdx,%r8
-movq 16(%rsi),%rax
-mulq 16(%rsi)
-add %rax,%r15
-adc %rdx,%rbx
-movq 16(%rsi),%rdx
-imulq $38,%rdx,%rax
-mulq 24(%rsi)
-add %rax,%rcx
-adc %rdx,%r8
-movq 16(%rsi),%rdx
-imulq $38,%rdx,%rax
-mulq 32(%rsi)
-add %rax,%r9
-adc %rdx,%r10
-movq 24(%rsi),%rdx
-imulq $19,%rdx,%rax
-mulq 24(%rsi)
-add %rax,%r9
-adc %rdx,%r10
-movq 24(%rsi),%rdx
-imulq $38,%rdx,%rax
-mulq 32(%rsi)
-add %rax,%r11
-adc %rdx,%r12
-movq 32(%rsi),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rsi)
-add %rax,%r13
-adc %rdx,%r14
-movq x25519_x86_64_REDMASK51(%rip),%rsi
-shld $13,%rcx,%r8
-and %rsi,%rcx
-shld $13,%r9,%r10
-and %rsi,%r9
-add %r8,%r9
-shld $13,%r11,%r12
-and %rsi,%r11
-add %r10,%r11
-shld $13,%r13,%r14
-and %rsi,%r13
-add %r12,%r13
-shld $13,%r15,%rbx
-and %rsi,%r15
-add %r14,%r15
-imulq $19,%rbx,%rdx
-add %rdx,%rcx
-mov %rcx,%rdx
-shr $51,%rdx
-add %r9,%rdx
-and %rsi,%rcx
-mov %rdx,%r8
-shr $51,%rdx
-add %r11,%rdx
-and %rsi,%r8
-mov %rdx,%r9
-shr $51,%rdx
-add %r13,%rdx
-and %rsi,%r9
-mov %rdx,%rax
-shr $51,%rdx
-add %r15,%rdx
-and %rsi,%rax
-mov %rdx,%r10
-shr $51,%rdx
-imulq $19,%rdx,%rdx
-add %rdx,%rcx
-and %rsi,%r10
-movq %rcx,0(%rdi)
-movq %r8,8(%rdi)
-movq %r9,16(%rdi)
-movq %rax,24(%rdi)
-movq %r10,32(%rdi)
-movq -8(%rsp),%r12
-movq -16(%rsp),%r13
-movq -24(%rsp),%r14
-movq -32(%rsp),%r15
-movq -40(%rsp),%rbx
-ret
-.cfi_endproc
-
-.p2align 5
-.globl x25519_x86_64_ladderstep
-.hidden x25519_x86_64_ladderstep
-x25519_x86_64_ladderstep:
-.cfi_startproc
-sub $344,%rsp
-.cfi_adjust_cfa_offset 344
-movq %r12,296(%rsp)
-.cfi_rel_offset r12, 296
-movq %r13,304(%rsp)
-.cfi_rel_offset r13, 304
-movq %r14,312(%rsp)
-.cfi_rel_offset r14, 312
-movq %r15,320(%rsp)
-.cfi_rel_offset r15, 320
-movq %rbx,328(%rsp)
-.cfi_rel_offset rbx, 328
-movq %rbp,336(%rsp)
-.cfi_rel_offset rbp, 336
-movq 40(%rdi),%rsi
-movq 48(%rdi),%rdx
-movq 56(%rdi),%rcx
-movq 64(%rdi),%r8
-movq 72(%rdi),%r9
-mov %rsi,%rax
-mov %rdx,%r10
-mov %rcx,%r11
-mov %r8,%r12
-mov %r9,%r13
-add x25519_x86_64_2P0(%rip),%rax
-add x25519_x86_64_2P1234(%rip),%r10
-add x25519_x86_64_2P1234(%rip),%r11
-add x25519_x86_64_2P1234(%rip),%r12
-add x25519_x86_64_2P1234(%rip),%r13
-addq 80(%rdi),%rsi
-addq 88(%rdi),%rdx
-addq 96(%rdi),%rcx
-addq 104(%rdi),%r8
-addq 112(%rdi),%r9
-subq 80(%rdi),%rax
-subq 88(%rdi),%r10
-subq 96(%rdi),%r11
-subq 104(%rdi),%r12
-subq 112(%rdi),%r13
-movq %rsi,0(%rsp)
-movq %rdx,8(%rsp)
-movq %rcx,16(%rsp)
-movq %r8,24(%rsp)
-movq %r9,32(%rsp)
-movq %rax,40(%rsp)
-movq %r10,48(%rsp)
-movq %r11,56(%rsp)
-movq %r12,64(%rsp)
-movq %r13,72(%rsp)
-movq 40(%rsp),%rax
-mulq 40(%rsp)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 40(%rsp),%rax
-shl $1,%rax
-mulq 48(%rsp)
-mov %rax,%r8
-mov %rdx,%r9
-movq 40(%rsp),%rax
-shl $1,%rax
-mulq 56(%rsp)
-mov %rax,%r10
-mov %rdx,%r11
-movq 40(%rsp),%rax
-shl $1,%rax
-mulq 64(%rsp)
-mov %rax,%r12
-mov %rdx,%r13
-movq 40(%rsp),%rax
-shl $1,%rax
-mulq 72(%rsp)
-mov %rax,%r14
-mov %rdx,%r15
-movq 48(%rsp),%rax
-mulq 48(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 48(%rsp),%rax
-shl $1,%rax
-mulq 56(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 48(%rsp),%rax
-shl $1,%rax
-mulq 64(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 48(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 72(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 56(%rsp),%rax
-mulq 56(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 56(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 64(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 56(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 72(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 64(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 64(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 64(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 72(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 72(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 72(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-and %rdx,%rsi
-mov %rcx,%r8
-shr $51,%rcx
-add %r10,%rcx
-and %rdx,%r8
-mov %rcx,%r9
-shr $51,%rcx
-add %r12,%rcx
-and %rdx,%r9
-mov %rcx,%rax
-shr $51,%rcx
-add %r14,%rcx
-and %rdx,%rax
-mov %rcx,%r10
-shr $51,%rcx
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,80(%rsp)
-movq %r8,88(%rsp)
-movq %r9,96(%rsp)
-movq %rax,104(%rsp)
-movq %r10,112(%rsp)
-movq 0(%rsp),%rax
-mulq 0(%rsp)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 0(%rsp),%rax
-shl $1,%rax
-mulq 8(%rsp)
-mov %rax,%r8
-mov %rdx,%r9
-movq 0(%rsp),%rax
-shl $1,%rax
-mulq 16(%rsp)
-mov %rax,%r10
-mov %rdx,%r11
-movq 0(%rsp),%rax
-shl $1,%rax
-mulq 24(%rsp)
-mov %rax,%r12
-mov %rdx,%r13
-movq 0(%rsp),%rax
-shl $1,%rax
-mulq 32(%rsp)
-mov %rax,%r14
-mov %rdx,%r15
-movq 8(%rsp),%rax
-mulq 8(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 8(%rsp),%rax
-shl $1,%rax
-mulq 16(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 8(%rsp),%rax
-shl $1,%rax
-mulq 24(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 8(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 32(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 16(%rsp),%rax
-mulq 16(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 16(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 24(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 16(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 32(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 24(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 24(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 24(%rsp),%rdx
-imulq $38,%rdx,%rax
-mulq 32(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 32(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-and %rdx,%rsi
-mov %rcx,%r8
-shr $51,%rcx
-add %r10,%rcx
-and %rdx,%r8
-mov %rcx,%r9
-shr $51,%rcx
-add %r12,%rcx
-and %rdx,%r9
-mov %rcx,%rax
-shr $51,%rcx
-add %r14,%rcx
-and %rdx,%rax
-mov %rcx,%r10
-shr $51,%rcx
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,120(%rsp)
-movq %r8,128(%rsp)
-movq %r9,136(%rsp)
-movq %rax,144(%rsp)
-movq %r10,152(%rsp)
-mov %rsi,%rsi
-mov %r8,%rdx
-mov %r9,%rcx
-mov %rax,%r8
-mov %r10,%r9
-add x25519_x86_64_2P0(%rip),%rsi
-add x25519_x86_64_2P1234(%rip),%rdx
-add x25519_x86_64_2P1234(%rip),%rcx
-add x25519_x86_64_2P1234(%rip),%r8
-add x25519_x86_64_2P1234(%rip),%r9
-subq 80(%rsp),%rsi
-subq 88(%rsp),%rdx
-subq 96(%rsp),%rcx
-subq 104(%rsp),%r8
-subq 112(%rsp),%r9
-movq %rsi,160(%rsp)
-movq %rdx,168(%rsp)
-movq %rcx,176(%rsp)
-movq %r8,184(%rsp)
-movq %r9,192(%rsp)
-movq 120(%rdi),%rsi
-movq 128(%rdi),%rdx
-movq 136(%rdi),%rcx
-movq 144(%rdi),%r8
-movq 152(%rdi),%r9
-mov %rsi,%rax
-mov %rdx,%r10
-mov %rcx,%r11
-mov %r8,%r12
-mov %r9,%r13
-add x25519_x86_64_2P0(%rip),%rax
-add x25519_x86_64_2P1234(%rip),%r10
-add x25519_x86_64_2P1234(%rip),%r11
-add x25519_x86_64_2P1234(%rip),%r12
-add x25519_x86_64_2P1234(%rip),%r13
-addq 160(%rdi),%rsi
-addq 168(%rdi),%rdx
-addq 176(%rdi),%rcx
-addq 184(%rdi),%r8
-addq 192(%rdi),%r9
-subq 160(%rdi),%rax
-subq 168(%rdi),%r10
-subq 176(%rdi),%r11
-subq 184(%rdi),%r12
-subq 192(%rdi),%r13
-movq %rsi,200(%rsp)
-movq %rdx,208(%rsp)
-movq %rcx,216(%rsp)
-movq %r8,224(%rsp)
-movq %r9,232(%rsp)
-movq %rax,240(%rsp)
-movq %r10,248(%rsp)
-movq %r11,256(%rsp)
-movq %r12,264(%rsp)
-movq %r13,272(%rsp)
-movq 224(%rsp),%rsi
-imulq $19,%rsi,%rax
-movq %rax,280(%rsp)
-mulq 56(%rsp)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 232(%rsp),%rdx
-imulq $19,%rdx,%rax
-movq %rax,288(%rsp)
-mulq 48(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 200(%rsp),%rax
-mulq 40(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 200(%rsp),%rax
-mulq 48(%rsp)
-mov %rax,%r8
-mov %rdx,%r9
-movq 200(%rsp),%rax
-mulq 56(%rsp)
-mov %rax,%r10
-mov %rdx,%r11
-movq 200(%rsp),%rax
-mulq 64(%rsp)
-mov %rax,%r12
-mov %rdx,%r13
-movq 200(%rsp),%rax
-mulq 72(%rsp)
-mov %rax,%r14
-mov %rdx,%r15
-movq 208(%rsp),%rax
-mulq 40(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 208(%rsp),%rax
-mulq 48(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 208(%rsp),%rax
-mulq 56(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 208(%rsp),%rax
-mulq 64(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 208(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 72(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 216(%rsp),%rax
-mulq 40(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 216(%rsp),%rax
-mulq 48(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 216(%rsp),%rax
-mulq 56(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 216(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 64(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 216(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 72(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 224(%rsp),%rax
-mulq 40(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 224(%rsp),%rax
-mulq 48(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 280(%rsp),%rax
-mulq 64(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 280(%rsp),%rax
-mulq 72(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 232(%rsp),%rax
-mulq 40(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 288(%rsp),%rax
-mulq 56(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 288(%rsp),%rax
-mulq 64(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 288(%rsp),%rax
-mulq 72(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-mov %rcx,%r8
-shr $51,%rcx
-and %rdx,%rsi
-add %r10,%rcx
-mov %rcx,%r9
-shr $51,%rcx
-and %rdx,%r8
-add %r12,%rcx
-mov %rcx,%rax
-shr $51,%rcx
-and %rdx,%r9
-add %r14,%rcx
-mov %rcx,%r10
-shr $51,%rcx
-and %rdx,%rax
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,40(%rsp)
-movq %r8,48(%rsp)
-movq %r9,56(%rsp)
-movq %rax,64(%rsp)
-movq %r10,72(%rsp)
-movq 264(%rsp),%rsi
-imulq $19,%rsi,%rax
-movq %rax,200(%rsp)
-mulq 16(%rsp)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 272(%rsp),%rdx
-imulq $19,%rdx,%rax
-movq %rax,208(%rsp)
-mulq 8(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 240(%rsp),%rax
-mulq 0(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 240(%rsp),%rax
-mulq 8(%rsp)
-mov %rax,%r8
-mov %rdx,%r9
-movq 240(%rsp),%rax
-mulq 16(%rsp)
-mov %rax,%r10
-mov %rdx,%r11
-movq 240(%rsp),%rax
-mulq 24(%rsp)
-mov %rax,%r12
-mov %rdx,%r13
-movq 240(%rsp),%rax
-mulq 32(%rsp)
-mov %rax,%r14
-mov %rdx,%r15
-movq 248(%rsp),%rax
-mulq 0(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 248(%rsp),%rax
-mulq 8(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 248(%rsp),%rax
-mulq 16(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 248(%rsp),%rax
-mulq 24(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 248(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 256(%rsp),%rax
-mulq 0(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 256(%rsp),%rax
-mulq 8(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 256(%rsp),%rax
-mulq 16(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 256(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 24(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 256(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 264(%rsp),%rax
-mulq 0(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 264(%rsp),%rax
-mulq 8(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 200(%rsp),%rax
-mulq 24(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 200(%rsp),%rax
-mulq 32(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 272(%rsp),%rax
-mulq 0(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 208(%rsp),%rax
-mulq 16(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 208(%rsp),%rax
-mulq 24(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 208(%rsp),%rax
-mulq 32(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-mov %rcx,%r8
-shr $51,%rcx
-and %rdx,%rsi
-add %r10,%rcx
-mov %rcx,%r9
-shr $51,%rcx
-and %rdx,%r8
-add %r12,%rcx
-mov %rcx,%rax
-shr $51,%rcx
-and %rdx,%r9
-add %r14,%rcx
-mov %rcx,%r10
-shr $51,%rcx
-and %rdx,%rax
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-mov %rsi,%rdx
-mov %r8,%rcx
-mov %r9,%r11
-mov %rax,%r12
-mov %r10,%r13
-add x25519_x86_64_2P0(%rip),%rdx
-add x25519_x86_64_2P1234(%rip),%rcx
-add x25519_x86_64_2P1234(%rip),%r11
-add x25519_x86_64_2P1234(%rip),%r12
-add x25519_x86_64_2P1234(%rip),%r13
-addq 40(%rsp),%rsi
-addq 48(%rsp),%r8
-addq 56(%rsp),%r9
-addq 64(%rsp),%rax
-addq 72(%rsp),%r10
-subq 40(%rsp),%rdx
-subq 48(%rsp),%rcx
-subq 56(%rsp),%r11
-subq 64(%rsp),%r12
-subq 72(%rsp),%r13
-movq %rsi,120(%rdi)
-movq %r8,128(%rdi)
-movq %r9,136(%rdi)
-movq %rax,144(%rdi)
-movq %r10,152(%rdi)
-movq %rdx,160(%rdi)
-movq %rcx,168(%rdi)
-movq %r11,176(%rdi)
-movq %r12,184(%rdi)
-movq %r13,192(%rdi)
-movq 120(%rdi),%rax
-mulq 120(%rdi)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 120(%rdi),%rax
-shl $1,%rax
-mulq 128(%rdi)
-mov %rax,%r8
-mov %rdx,%r9
-movq 120(%rdi),%rax
-shl $1,%rax
-mulq 136(%rdi)
-mov %rax,%r10
-mov %rdx,%r11
-movq 120(%rdi),%rax
-shl $1,%rax
-mulq 144(%rdi)
-mov %rax,%r12
-mov %rdx,%r13
-movq 120(%rdi),%rax
-shl $1,%rax
-mulq 152(%rdi)
-mov %rax,%r14
-mov %rdx,%r15
-movq 128(%rdi),%rax
-mulq 128(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 128(%rdi),%rax
-shl $1,%rax
-mulq 136(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq 128(%rdi),%rax
-shl $1,%rax
-mulq 144(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 128(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 152(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 136(%rdi),%rax
-mulq 136(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 136(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 144(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 136(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 152(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 144(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 144(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 144(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 152(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 152(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 152(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-and %rdx,%rsi
-mov %rcx,%r8
-shr $51,%rcx
-add %r10,%rcx
-and %rdx,%r8
-mov %rcx,%r9
-shr $51,%rcx
-add %r12,%rcx
-and %rdx,%r9
-mov %rcx,%rax
-shr $51,%rcx
-add %r14,%rcx
-and %rdx,%rax
-mov %rcx,%r10
-shr $51,%rcx
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,120(%rdi)
-movq %r8,128(%rdi)
-movq %r9,136(%rdi)
-movq %rax,144(%rdi)
-movq %r10,152(%rdi)
-movq 160(%rdi),%rax
-mulq 160(%rdi)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 160(%rdi),%rax
-shl $1,%rax
-mulq 168(%rdi)
-mov %rax,%r8
-mov %rdx,%r9
-movq 160(%rdi),%rax
-shl $1,%rax
-mulq 176(%rdi)
-mov %rax,%r10
-mov %rdx,%r11
-movq 160(%rdi),%rax
-shl $1,%rax
-mulq 184(%rdi)
-mov %rax,%r12
-mov %rdx,%r13
-movq 160(%rdi),%rax
-shl $1,%rax
-mulq 192(%rdi)
-mov %rax,%r14
-mov %rdx,%r15
-movq 168(%rdi),%rax
-mulq 168(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 168(%rdi),%rax
-shl $1,%rax
-mulq 176(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq 168(%rdi),%rax
-shl $1,%rax
-mulq 184(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 168(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 192(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 176(%rdi),%rax
-mulq 176(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 176(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 184(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 176(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 192(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 184(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 184(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 184(%rdi),%rdx
-imulq $38,%rdx,%rax
-mulq 192(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 192(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 192(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-and %rdx,%rsi
-mov %rcx,%r8
-shr $51,%rcx
-add %r10,%rcx
-and %rdx,%r8
-mov %rcx,%r9
-shr $51,%rcx
-add %r12,%rcx
-and %rdx,%r9
-mov %rcx,%rax
-shr $51,%rcx
-add %r14,%rcx
-and %rdx,%rax
-mov %rcx,%r10
-shr $51,%rcx
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,160(%rdi)
-movq %r8,168(%rdi)
-movq %r9,176(%rdi)
-movq %rax,184(%rdi)
-movq %r10,192(%rdi)
-movq 184(%rdi),%rsi
-imulq $19,%rsi,%rax
-movq %rax,0(%rsp)
-mulq 16(%rdi)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 192(%rdi),%rdx
-imulq $19,%rdx,%rax
-movq %rax,8(%rsp)
-mulq 8(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 160(%rdi),%rax
-mulq 0(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 160(%rdi),%rax
-mulq 8(%rdi)
-mov %rax,%r8
-mov %rdx,%r9
-movq 160(%rdi),%rax
-mulq 16(%rdi)
-mov %rax,%r10
-mov %rdx,%r11
-movq 160(%rdi),%rax
-mulq 24(%rdi)
-mov %rax,%r12
-mov %rdx,%r13
-movq 160(%rdi),%rax
-mulq 32(%rdi)
-mov %rax,%r14
-mov %rdx,%r15
-movq 168(%rdi),%rax
-mulq 0(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 168(%rdi),%rax
-mulq 8(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 168(%rdi),%rax
-mulq 16(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq 168(%rdi),%rax
-mulq 24(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 168(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 176(%rdi),%rax
-mulq 0(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 176(%rdi),%rax
-mulq 8(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq 176(%rdi),%rax
-mulq 16(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 176(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 24(%rdi)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 176(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 32(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 184(%rdi),%rax
-mulq 0(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq 184(%rdi),%rax
-mulq 8(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 0(%rsp),%rax
-mulq 24(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 0(%rsp),%rax
-mulq 32(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 192(%rdi),%rax
-mulq 0(%rdi)
-add %rax,%r14
-adc %rdx,%r15
-movq 8(%rsp),%rax
-mulq 16(%rdi)
-add %rax,%r8
-adc %rdx,%r9
-movq 8(%rsp),%rax
-mulq 24(%rdi)
-add %rax,%r10
-adc %rdx,%r11
-movq 8(%rsp),%rax
-mulq 32(%rdi)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-mov %rcx,%r8
-shr $51,%rcx
-and %rdx,%rsi
-add %r10,%rcx
-mov %rcx,%r9
-shr $51,%rcx
-and %rdx,%r8
-add %r12,%rcx
-mov %rcx,%rax
-shr $51,%rcx
-and %rdx,%r9
-add %r14,%rcx
-mov %rcx,%r10
-shr $51,%rcx
-and %rdx,%rax
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,160(%rdi)
-movq %r8,168(%rdi)
-movq %r9,176(%rdi)
-movq %rax,184(%rdi)
-movq %r10,192(%rdi)
-movq 144(%rsp),%rsi
-imulq $19,%rsi,%rax
-movq %rax,0(%rsp)
-mulq 96(%rsp)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 152(%rsp),%rdx
-imulq $19,%rdx,%rax
-movq %rax,8(%rsp)
-mulq 88(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 120(%rsp),%rax
-mulq 80(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 120(%rsp),%rax
-mulq 88(%rsp)
-mov %rax,%r8
-mov %rdx,%r9
-movq 120(%rsp),%rax
-mulq 96(%rsp)
-mov %rax,%r10
-mov %rdx,%r11
-movq 120(%rsp),%rax
-mulq 104(%rsp)
-mov %rax,%r12
-mov %rdx,%r13
-movq 120(%rsp),%rax
-mulq 112(%rsp)
-mov %rax,%r14
-mov %rdx,%r15
-movq 128(%rsp),%rax
-mulq 80(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 128(%rsp),%rax
-mulq 88(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 128(%rsp),%rax
-mulq 96(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 128(%rsp),%rax
-mulq 104(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 128(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 112(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 136(%rsp),%rax
-mulq 80(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 136(%rsp),%rax
-mulq 88(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 136(%rsp),%rax
-mulq 96(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 136(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 104(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 136(%rsp),%rdx
-imulq $19,%rdx,%rax
-mulq 112(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 144(%rsp),%rax
-mulq 80(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 144(%rsp),%rax
-mulq 88(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 0(%rsp),%rax
-mulq 104(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 0(%rsp),%rax
-mulq 112(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 152(%rsp),%rax
-mulq 80(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 8(%rsp),%rax
-mulq 96(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 8(%rsp),%rax
-mulq 104(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 8(%rsp),%rax
-mulq 112(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-mov %rcx,%r8
-shr $51,%rcx
-and %rdx,%rsi
-add %r10,%rcx
-mov %rcx,%r9
-shr $51,%rcx
-and %rdx,%r8
-add %r12,%rcx
-mov %rcx,%rax
-shr $51,%rcx
-and %rdx,%r9
-add %r14,%rcx
-mov %rcx,%r10
-shr $51,%rcx
-and %rdx,%rax
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,40(%rdi)
-movq %r8,48(%rdi)
-movq %r9,56(%rdi)
-movq %rax,64(%rdi)
-movq %r10,72(%rdi)
-movq 160(%rsp),%rax
-mulq x25519_x86_64_121666_213(%rip)
-shr $13,%rax
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 168(%rsp),%rax
-mulq x25519_x86_64_121666_213(%rip)
-shr $13,%rax
-add %rax,%rcx
-mov %rdx,%r8
-movq 176(%rsp),%rax
-mulq x25519_x86_64_121666_213(%rip)
-shr $13,%rax
-add %rax,%r8
-mov %rdx,%r9
-movq 184(%rsp),%rax
-mulq x25519_x86_64_121666_213(%rip)
-shr $13,%rax
-add %rax,%r9
-mov %rdx,%r10
-movq 192(%rsp),%rax
-mulq x25519_x86_64_121666_213(%rip)
-shr $13,%rax
-add %rax,%r10
-imulq $19,%rdx,%rdx
-add %rdx,%rsi
-addq 80(%rsp),%rsi
-addq 88(%rsp),%rcx
-addq 96(%rsp),%r8
-addq 104(%rsp),%r9
-addq 112(%rsp),%r10
-movq %rsi,80(%rdi)
-movq %rcx,88(%rdi)
-movq %r8,96(%rdi)
-movq %r9,104(%rdi)
-movq %r10,112(%rdi)
-movq 104(%rdi),%rsi
-imulq $19,%rsi,%rax
-movq %rax,0(%rsp)
-mulq 176(%rsp)
-mov %rax,%rsi
-mov %rdx,%rcx
-movq 112(%rdi),%rdx
-imulq $19,%rdx,%rax
-movq %rax,8(%rsp)
-mulq 168(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 80(%rdi),%rax
-mulq 160(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 80(%rdi),%rax
-mulq 168(%rsp)
-mov %rax,%r8
-mov %rdx,%r9
-movq 80(%rdi),%rax
-mulq 176(%rsp)
-mov %rax,%r10
-mov %rdx,%r11
-movq 80(%rdi),%rax
-mulq 184(%rsp)
-mov %rax,%r12
-mov %rdx,%r13
-movq 80(%rdi),%rax
-mulq 192(%rsp)
-mov %rax,%r14
-mov %rdx,%r15
-movq 88(%rdi),%rax
-mulq 160(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 88(%rdi),%rax
-mulq 168(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 88(%rdi),%rax
-mulq 176(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 88(%rdi),%rax
-mulq 184(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 88(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 192(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 96(%rdi),%rax
-mulq 160(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 96(%rdi),%rax
-mulq 168(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 96(%rdi),%rax
-mulq 176(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 96(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 184(%rsp)
-add %rax,%rsi
-adc %rdx,%rcx
-movq 96(%rdi),%rdx
-imulq $19,%rdx,%rax
-mulq 192(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 104(%rdi),%rax
-mulq 160(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq 104(%rdi),%rax
-mulq 168(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 0(%rsp),%rax
-mulq 184(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 0(%rsp),%rax
-mulq 192(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 112(%rdi),%rax
-mulq 160(%rsp)
-add %rax,%r14
-adc %rdx,%r15
-movq 8(%rsp),%rax
-mulq 176(%rsp)
-add %rax,%r8
-adc %rdx,%r9
-movq 8(%rsp),%rax
-mulq 184(%rsp)
-add %rax,%r10
-adc %rdx,%r11
-movq 8(%rsp),%rax
-mulq 192(%rsp)
-add %rax,%r12
-adc %rdx,%r13
-movq x25519_x86_64_REDMASK51(%rip),%rdx
-shld $13,%rsi,%rcx
-and %rdx,%rsi
-shld $13,%r8,%r9
-and %rdx,%r8
-add %rcx,%r8
-shld $13,%r10,%r11
-and %rdx,%r10
-add %r9,%r10
-shld $13,%r12,%r13
-and %rdx,%r12
-add %r11,%r12
-shld $13,%r14,%r15
-and %rdx,%r14
-add %r13,%r14
-imulq $19,%r15,%rcx
-add %rcx,%rsi
-mov %rsi,%rcx
-shr $51,%rcx
-add %r8,%rcx
-mov %rcx,%r8
-shr $51,%rcx
-and %rdx,%rsi
-add %r10,%rcx
-mov %rcx,%r9
-shr $51,%rcx
-and %rdx,%r8
-add %r12,%rcx
-mov %rcx,%rax
-shr $51,%rcx
-and %rdx,%r9
-add %r14,%rcx
-mov %rcx,%r10
-shr $51,%rcx
-and %rdx,%rax
-imulq $19,%rcx,%rcx
-add %rcx,%rsi
-and %rdx,%r10
-movq %rsi,80(%rdi)
-movq %r8,88(%rdi)
-movq %r9,96(%rdi)
-movq %rax,104(%rdi)
-movq %r10,112(%rdi)
-movq 296(%rsp),%r12
-movq 304(%rsp),%r13
-movq 312(%rsp),%r14
-movq 320(%rsp),%r15
-movq 328(%rsp),%rbx
-movq 336(%rsp),%rbp
-add $344,%rsp
-.cfi_adjust_cfa_offset -344
-ret
-.cfi_endproc
-
-.p2align 5
-.globl x25519_x86_64_work_cswap
-.hidden x25519_x86_64_work_cswap
-x25519_x86_64_work_cswap:
-.cfi_startproc
-subq $1,%rsi
-notq %rsi
-movq %rsi,%xmm15
-pshufd $0x44,%xmm15,%xmm15
-movdqu 0(%rdi),%xmm0
-movdqu 16(%rdi),%xmm2
-movdqu 32(%rdi),%xmm4
-movdqu 48(%rdi),%xmm6
-movdqu 64(%rdi),%xmm8
-movdqu 80(%rdi),%xmm1
-movdqu 96(%rdi),%xmm3
-movdqu 112(%rdi),%xmm5
-movdqu 128(%rdi),%xmm7
-movdqu 144(%rdi),%xmm9
-movdqa %xmm1,%xmm10
-movdqa %xmm3,%xmm11
-movdqa %xmm5,%xmm12
-movdqa %xmm7,%xmm13
-movdqa %xmm9,%xmm14
-pxor %xmm0,%xmm10
-pxor %xmm2,%xmm11
-pxor %xmm4,%xmm12
-pxor %xmm6,%xmm13
-pxor %xmm8,%xmm14
-pand %xmm15,%xmm10
-pand %xmm15,%xmm11
-pand %xmm15,%xmm12
-pand %xmm15,%xmm13
-pand %xmm15,%xmm14
-pxor %xmm10,%xmm0
-pxor %xmm10,%xmm1
-pxor %xmm11,%xmm2
-pxor %xmm11,%xmm3
-pxor %xmm12,%xmm4
-pxor %xmm12,%xmm5
-pxor %xmm13,%xmm6
-pxor %xmm13,%xmm7
-pxor %xmm14,%xmm8
-pxor %xmm14,%xmm9
-movdqu %xmm0,0(%rdi)
-movdqu %xmm2,16(%rdi)
-movdqu %xmm4,32(%rdi)
-movdqu %xmm6,48(%rdi)
-movdqu %xmm8,64(%rdi)
-movdqu %xmm1,80(%rdi)
-movdqu %xmm3,96(%rdi)
-movdqu %xmm5,112(%rdi)
-movdqu %xmm7,128(%rdi)
-movdqu %xmm9,144(%rdi)
-ret
-.cfi_endproc
diff --git a/curve25519-amd64.c b/curve25519-amd64.c
deleted file mode 100644
index 095b0d2..0000000
--- a/curve25519-amd64.c
+++ /dev/null
@@ -1,234 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2015 Google Inc. All Rights Reserved.
- * Copyright (C) 2015-2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * Original author: Peter Schwabe <peter@cryptojedi.org>
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-typedef struct { uint64_t v[5]; } fe25519;
-
-asmlinkage void x25519_x86_64_work_cswap(fe25519 *, uint64_t);
-asmlinkage void x25519_x86_64_mul(fe25519 *out, const fe25519 *a, const fe25519 *b);
-asmlinkage void x25519_x86_64_square(fe25519 *out, const fe25519 *a);
-asmlinkage void x25519_x86_64_freeze(fe25519 *);
-asmlinkage void x25519_x86_64_ladderstep(fe25519 *work);
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-static void fe25519_setint(fe25519 *r, unsigned v)
-{
- r->v[0] = v;
- r->v[1] = 0;
- r->v[2] = 0;
- r->v[3] = 0;
- r->v[4] = 0;
-}
-
-// Assumes input x being reduced below 2^255
-static void fe25519_pack(unsigned char r[32], const fe25519 *x)
-{
- fe25519 t;
- t = *x;
- x25519_x86_64_freeze(&t);
-
- r[0] = (uint8_t)(t.v[0] & 0xff);
- r[1] = (uint8_t)((t.v[0] >> 8) & 0xff);
- r[2] = (uint8_t)((t.v[0] >> 16) & 0xff);
- r[3] = (uint8_t)((t.v[0] >> 24) & 0xff);
- r[4] = (uint8_t)((t.v[0] >> 32) & 0xff);
- r[5] = (uint8_t)((t.v[0] >> 40) & 0xff);
- r[6] = (uint8_t)((t.v[0] >> 48));
-
- r[6] ^= (uint8_t)((t.v[1] << 3) & 0xf8);
- r[7] = (uint8_t)((t.v[1] >> 5) & 0xff);
- r[8] = (uint8_t)((t.v[1] >> 13) & 0xff);
- r[9] = (uint8_t)((t.v[1] >> 21) & 0xff);
- r[10] = (uint8_t)((t.v[1] >> 29) & 0xff);
- r[11] = (uint8_t)((t.v[1] >> 37) & 0xff);
- r[12] = (uint8_t)((t.v[1] >> 45));
-
- r[12] ^= (uint8_t)((t.v[2] << 6) & 0xc0);
- r[13] = (uint8_t)((t.v[2] >> 2) & 0xff);
- r[14] = (uint8_t)((t.v[2] >> 10) & 0xff);
- r[15] = (uint8_t)((t.v[2] >> 18) & 0xff);
- r[16] = (uint8_t)((t.v[2] >> 26) & 0xff);
- r[17] = (uint8_t)((t.v[2] >> 34) & 0xff);
- r[18] = (uint8_t)((t.v[2] >> 42) & 0xff);
- r[19] = (uint8_t)((t.v[2] >> 50));
-
- r[19] ^= (uint8_t)((t.v[3] << 1) & 0xfe);
- r[20] = (uint8_t)((t.v[3] >> 7) & 0xff);
- r[21] = (uint8_t)((t.v[3] >> 15) & 0xff);
- r[22] = (uint8_t)((t.v[3] >> 23) & 0xff);
- r[23] = (uint8_t)((t.v[3] >> 31) & 0xff);
- r[24] = (uint8_t)((t.v[3] >> 39) & 0xff);
- r[25] = (uint8_t)((t.v[3] >> 47));
-
- r[25] ^= (uint8_t)((t.v[4] << 4) & 0xf0);
- r[26] = (uint8_t)((t.v[4] >> 4) & 0xff);
- r[27] = (uint8_t)((t.v[4] >> 12) & 0xff);
- r[28] = (uint8_t)((t.v[4] >> 20) & 0xff);
- r[29] = (uint8_t)((t.v[4] >> 28) & 0xff);
- r[30] = (uint8_t)((t.v[4] >> 36) & 0xff);
- r[31] = (uint8_t)((t.v[4] >> 44));
-}
-
-static void fe25519_unpack(fe25519 *r, const uint8_t x[32])
-{
- r->v[0] = x[0];
- r->v[0] += (uint64_t)x[1] << 8;
- r->v[0] += (uint64_t)x[2] << 16;
- r->v[0] += (uint64_t)x[3] << 24;
- r->v[0] += (uint64_t)x[4] << 32;
- r->v[0] += (uint64_t)x[5] << 40;
- r->v[0] += ((uint64_t)x[6] & 7) << 48;
-
- r->v[1] = x[6] >> 3;
- r->v[1] += (uint64_t)x[7] << 5;
- r->v[1] += (uint64_t)x[8] << 13;
- r->v[1] += (uint64_t)x[9] << 21;
- r->v[1] += (uint64_t)x[10] << 29;
- r->v[1] += (uint64_t)x[11] << 37;
- r->v[1] += ((uint64_t)x[12] & 63) << 45;
-
- r->v[2] = x[12] >> 6;
- r->v[2] += (uint64_t)x[13] << 2;
- r->v[2] += (uint64_t)x[14] << 10;
- r->v[2] += (uint64_t)x[15] << 18;
- r->v[2] += (uint64_t)x[16] << 26;
- r->v[2] += (uint64_t)x[17] << 34;
- r->v[2] += (uint64_t)x[18] << 42;
- r->v[2] += ((uint64_t)x[19] & 1) << 50;
-
- r->v[3] = x[19] >> 1;
- r->v[3] += (uint64_t)x[20] << 7;
- r->v[3] += (uint64_t)x[21] << 15;
- r->v[3] += (uint64_t)x[22] << 23;
- r->v[3] += (uint64_t)x[23] << 31;
- r->v[3] += (uint64_t)x[24] << 39;
- r->v[3] += ((uint64_t)x[25] & 15) << 47;
-
- r->v[4] = x[25] >> 4;
- r->v[4] += (uint64_t)x[26] << 4;
- r->v[4] += (uint64_t)x[27] << 12;
- r->v[4] += (uint64_t)x[28] << 20;
- r->v[4] += (uint64_t)x[29] << 28;
- r->v[4] += (uint64_t)x[30] << 36;
- r->v[4] += ((uint64_t)x[31] & 127) << 44;
-}
-
-static void fe25519_invert(fe25519 *r, const fe25519 *x)
-{
- fe25519 z2;
- fe25519 z9;
- fe25519 z11;
- fe25519 z2_5_0;
- fe25519 z2_10_0;
- fe25519 z2_20_0;
- fe25519 z2_50_0;
- fe25519 z2_100_0;
- fe25519 t;
- int i;
-
- /* 2 */ x25519_x86_64_square(&z2, x);
- /* 4 */ x25519_x86_64_square(&t, &z2);
- /* 8 */ x25519_x86_64_square(&t, &t);
- /* 9 */ x25519_x86_64_mul(&z9, &t, x);
- /* 11 */ x25519_x86_64_mul(&z11, &z9, &z2);
- /* 22 */ x25519_x86_64_square(&t, &z11);
- /* 2^5 - 2^0 = 31 */ x25519_x86_64_mul(&z2_5_0, &t, &z9);
-
- /* 2^6 - 2^1 */ x25519_x86_64_square(&t, &z2_5_0);
- /* 2^20 - 2^10 */ for (i = 1; i < 5; i++) { x25519_x86_64_square(&t, &t); }
- /* 2^10 - 2^0 */ x25519_x86_64_mul(&z2_10_0, &t, &z2_5_0);
-
- /* 2^11 - 2^1 */ x25519_x86_64_square(&t, &z2_10_0);
- /* 2^20 - 2^10 */ for (i = 1; i < 10; i++) { x25519_x86_64_square(&t, &t); }
- /* 2^20 - 2^0 */ x25519_x86_64_mul(&z2_20_0, &t, &z2_10_0);
-
- /* 2^21 - 2^1 */ x25519_x86_64_square(&t, &z2_20_0);
- /* 2^40 - 2^20 */ for (i = 1; i < 20; i++) { x25519_x86_64_square(&t, &t); }
- /* 2^40 - 2^0 */ x25519_x86_64_mul(&t, &t, &z2_20_0);
-
- /* 2^41 - 2^1 */ x25519_x86_64_square(&t, &t);
- /* 2^50 - 2^10 */ for (i = 1; i < 10; i++) { x25519_x86_64_square(&t, &t); }
- /* 2^50 - 2^0 */ x25519_x86_64_mul(&z2_50_0, &t, &z2_10_0);
-
- /* 2^51 - 2^1 */ x25519_x86_64_square(&t, &z2_50_0);
- /* 2^100 - 2^50 */ for (i = 1; i < 50; i++) { x25519_x86_64_square(&t, &t); }
- /* 2^100 - 2^0 */ x25519_x86_64_mul(&z2_100_0, &t, &z2_50_0);
-
- /* 2^101 - 2^1 */ x25519_x86_64_square(&t, &z2_100_0);
- /* 2^200 - 2^100 */ for (i = 1; i < 100; i++) {
- x25519_x86_64_square(&t, &t);
- }
- /* 2^200 - 2^0 */ x25519_x86_64_mul(&t, &t, &z2_100_0);
-
- /* 2^201 - 2^1 */ x25519_x86_64_square(&t, &t);
- /* 2^250 - 2^50 */ for (i = 1; i < 50; i++) { x25519_x86_64_square(&t, &t); }
- /* 2^250 - 2^0 */ x25519_x86_64_mul(&t, &t, &z2_50_0);
-
- /* 2^251 - 2^1 */ x25519_x86_64_square(&t, &t);
- /* 2^252 - 2^2 */ x25519_x86_64_square(&t, &t);
- /* 2^253 - 2^3 */ x25519_x86_64_square(&t, &t);
-
- /* 2^254 - 2^4 */ x25519_x86_64_square(&t, &t);
-
- /* 2^255 - 2^5 */ x25519_x86_64_square(&t, &t);
- /* 2^255 - 21 */ x25519_x86_64_mul(r, &t, &z11);
-}
-
-static void mladder(fe25519 *xr, fe25519 *zr, const uint8_t s[32])
-{
- int i, j;
- uint8_t prevbit = 0;
- fe25519 work[5];
-
- work[0] = *xr;
- fe25519_setint(work + 1, 1);
- fe25519_setint(work + 2, 0);
- work[3] = *xr;
- fe25519_setint(work + 4, 1);
-
- j = 6;
- for (i = 31; i >= 0; i--) {
- while (j >= 0) {
- const uint8_t bit = 1 & (s[i] >> j);
- const uint64_t swap = bit ^ prevbit;
- prevbit = bit;
- x25519_x86_64_work_cswap(work + 1, swap);
- x25519_x86_64_ladderstep(work);
- j -= 1;
- }
- j = 7;
- }
-
- *xr = work[1];
- *zr = work[2];
-}
-bool curve25519_amd64(u8 out[CURVE25519_POINT_SIZE], const u8 scalar[CURVE25519_POINT_SIZE], const u8 point[CURVE25519_POINT_SIZE])
-{
- fe25519 t;
- fe25519 z;
- uint8_t e[32];
- memcpy(e, scalar, sizeof(e));
- normalize_secret(e);
-
- fe25519_unpack(&t, point);
- mladder(&t, &z, e);
- fe25519_invert(&z, &z);
- x25519_x86_64_mul(&t, &t, &z);
- fe25519_pack(out, &t);
- return true;
-}
diff --git a/curve25519-donna32.c b/curve25519-donna32.c
deleted file mode 100644
index 4721864..0000000
--- a/curve25519-donna32.c
+++ /dev/null
@@ -1,861 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2008 Google Inc. All Rights Reserved.
- * Copyright (C) 2015-2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * Original author: Adam Langley <agl@imperialviolet.org>
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-typedef s64 limb;
-
-/* Field element representation:
- *
- * Field elements are written as an array of signed, 64-bit limbs, least
- * significant first. The value of the field element is:
- * x[0] + 2^26·x[1] + x^51·x[2] + 2^102·x[3] + ...
- *
- * i.e. the limbs are 26, 25, 26, 25, ... bits wide.
- */
-
-/* Sum two numbers: output += in */
-static void fsum(limb *output, const limb *in)
-{
- unsigned int i;
-
- for (i = 0; i < 10; i += 2) {
- output[0 + i] = output[0 + i] + in[0 + i];
- output[1 + i] = output[1 + i] + in[1 + i];
- }
-}
-
-/* Find the difference of two numbers: output = in - output
- * (note the order of the arguments!).
- */
-static void fdifference(limb *output, const limb *in)
-{
- unsigned int i;
-
- for (i = 0; i < 10; ++i)
- output[i] = in[i] - output[i];
-}
-
-/* Multiply a number by a scalar: output = in * scalar */
-static void fscalar_product(limb *output, const limb *in, const limb scalar)
-{
- unsigned int i;
-
- for (i = 0; i < 10; ++i)
- output[i] = in[i] * scalar;
-}
-
-/* Multiply two numbers: output = in2 * in
- *
- * output must be distinct to both inputs. The inputs are reduced coefficient
- * form, the output is not.
- *
- * output[x] <= 14 * the largest product of the input limbs.
- */
-static void fproduct(limb *output, const limb *in2, const limb *in)
-{
- output[0] = ((limb) ((s32) in2[0])) * ((s32) in[0]);
- output[1] = ((limb) ((s32) in2[0])) * ((s32) in[1]) +
- ((limb) ((s32) in2[1])) * ((s32) in[0]);
- output[2] = 2 * ((limb) ((s32) in2[1])) * ((s32) in[1]) +
- ((limb) ((s32) in2[0])) * ((s32) in[2]) +
- ((limb) ((s32) in2[2])) * ((s32) in[0]);
- output[3] = ((limb) ((s32) in2[1])) * ((s32) in[2]) +
- ((limb) ((s32) in2[2])) * ((s32) in[1]) +
- ((limb) ((s32) in2[0])) * ((s32) in[3]) +
- ((limb) ((s32) in2[3])) * ((s32) in[0]);
- output[4] = ((limb) ((s32) in2[2])) * ((s32) in[2]) +
- 2 * (((limb) ((s32) in2[1])) * ((s32) in[3]) +
- ((limb) ((s32) in2[3])) * ((s32) in[1])) +
- ((limb) ((s32) in2[0])) * ((s32) in[4]) +
- ((limb) ((s32) in2[4])) * ((s32) in[0]);
- output[5] = ((limb) ((s32) in2[2])) * ((s32) in[3]) +
- ((limb) ((s32) in2[3])) * ((s32) in[2]) +
- ((limb) ((s32) in2[1])) * ((s32) in[4]) +
- ((limb) ((s32) in2[4])) * ((s32) in[1]) +
- ((limb) ((s32) in2[0])) * ((s32) in[5]) +
- ((limb) ((s32) in2[5])) * ((s32) in[0]);
- output[6] = 2 * (((limb) ((s32) in2[3])) * ((s32) in[3]) +
- ((limb) ((s32) in2[1])) * ((s32) in[5]) +
- ((limb) ((s32) in2[5])) * ((s32) in[1])) +
- ((limb) ((s32) in2[2])) * ((s32) in[4]) +
- ((limb) ((s32) in2[4])) * ((s32) in[2]) +
- ((limb) ((s32) in2[0])) * ((s32) in[6]) +
- ((limb) ((s32) in2[6])) * ((s32) in[0]);
- output[7] = ((limb) ((s32) in2[3])) * ((s32) in[4]) +
- ((limb) ((s32) in2[4])) * ((s32) in[3]) +
- ((limb) ((s32) in2[2])) * ((s32) in[5]) +
- ((limb) ((s32) in2[5])) * ((s32) in[2]) +
- ((limb) ((s32) in2[1])) * ((s32) in[6]) +
- ((limb) ((s32) in2[6])) * ((s32) in[1]) +
- ((limb) ((s32) in2[0])) * ((s32) in[7]) +
- ((limb) ((s32) in2[7])) * ((s32) in[0]);
- output[8] = ((limb) ((s32) in2[4])) * ((s32) in[4]) +
- 2 * (((limb) ((s32) in2[3])) * ((s32) in[5]) +
- ((limb) ((s32) in2[5])) * ((s32) in[3]) +
- ((limb) ((s32) in2[1])) * ((s32) in[7]) +
- ((limb) ((s32) in2[7])) * ((s32) in[1])) +
- ((limb) ((s32) in2[2])) * ((s32) in[6]) +
- ((limb) ((s32) in2[6])) * ((s32) in[2]) +
- ((limb) ((s32) in2[0])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[0]);
- output[9] = ((limb) ((s32) in2[4])) * ((s32) in[5]) +
- ((limb) ((s32) in2[5])) * ((s32) in[4]) +
- ((limb) ((s32) in2[3])) * ((s32) in[6]) +
- ((limb) ((s32) in2[6])) * ((s32) in[3]) +
- ((limb) ((s32) in2[2])) * ((s32) in[7]) +
- ((limb) ((s32) in2[7])) * ((s32) in[2]) +
- ((limb) ((s32) in2[1])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[1]) +
- ((limb) ((s32) in2[0])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[0]);
- output[10] = 2 * (((limb) ((s32) in2[5])) * ((s32) in[5]) +
- ((limb) ((s32) in2[3])) * ((s32) in[7]) +
- ((limb) ((s32) in2[7])) * ((s32) in[3]) +
- ((limb) ((s32) in2[1])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[1])) +
- ((limb) ((s32) in2[4])) * ((s32) in[6]) +
- ((limb) ((s32) in2[6])) * ((s32) in[4]) +
- ((limb) ((s32) in2[2])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[2]);
- output[11] = ((limb) ((s32) in2[5])) * ((s32) in[6]) +
- ((limb) ((s32) in2[6])) * ((s32) in[5]) +
- ((limb) ((s32) in2[4])) * ((s32) in[7]) +
- ((limb) ((s32) in2[7])) * ((s32) in[4]) +
- ((limb) ((s32) in2[3])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[3]) +
- ((limb) ((s32) in2[2])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[2]);
- output[12] = ((limb) ((s32) in2[6])) * ((s32) in[6]) +
- 2 * (((limb) ((s32) in2[5])) * ((s32) in[7]) +
- ((limb) ((s32) in2[7])) * ((s32) in[5]) +
- ((limb) ((s32) in2[3])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[3])) +
- ((limb) ((s32) in2[4])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[4]);
- output[13] = ((limb) ((s32) in2[6])) * ((s32) in[7]) +
- ((limb) ((s32) in2[7])) * ((s32) in[6]) +
- ((limb) ((s32) in2[5])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[5]) +
- ((limb) ((s32) in2[4])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[4]);
- output[14] = 2 * (((limb) ((s32) in2[7])) * ((s32) in[7]) +
- ((limb) ((s32) in2[5])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[5])) +
- ((limb) ((s32) in2[6])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[6]);
- output[15] = ((limb) ((s32) in2[7])) * ((s32) in[8]) +
- ((limb) ((s32) in2[8])) * ((s32) in[7]) +
- ((limb) ((s32) in2[6])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[6]);
- output[16] = ((limb) ((s32) in2[8])) * ((s32) in[8]) +
- 2 * (((limb) ((s32) in2[7])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[7]));
- output[17] = ((limb) ((s32) in2[8])) * ((s32) in[9]) +
- ((limb) ((s32) in2[9])) * ((s32) in[8]);
- output[18] = 2 * ((limb) ((s32) in2[9])) * ((s32) in[9]);
-}
-
-/* Reduce a long form to a short form by taking the input mod 2^255 - 19.
- *
- * On entry: |output[i]| < 14*2^54
- * On exit: |output[0..8]| < 280*2^54
- */
-static void freduce_degree(limb *output)
-{
- /* Each of these shifts and adds ends up multiplying the value by 19.
- *
- * For output[0..8], the absolute entry value is < 14*2^54 and we add, at
- * most, 19*14*2^54 thus, on exit, |output[0..8]| < 280*2^54.
- */
- output[8] += output[18] << 4;
- output[8] += output[18] << 1;
- output[8] += output[18];
- output[7] += output[17] << 4;
- output[7] += output[17] << 1;
- output[7] += output[17];
- output[6] += output[16] << 4;
- output[6] += output[16] << 1;
- output[6] += output[16];
- output[5] += output[15] << 4;
- output[5] += output[15] << 1;
- output[5] += output[15];
- output[4] += output[14] << 4;
- output[4] += output[14] << 1;
- output[4] += output[14];
- output[3] += output[13] << 4;
- output[3] += output[13] << 1;
- output[3] += output[13];
- output[2] += output[12] << 4;
- output[2] += output[12] << 1;
- output[2] += output[12];
- output[1] += output[11] << 4;
- output[1] += output[11] << 1;
- output[1] += output[11];
- output[0] += output[10] << 4;
- output[0] += output[10] << 1;
- output[0] += output[10];
-}
-
-/* return v / 2^26, using only shifts and adds.
- *
- * On entry: v can take any value.
- */
-static inline limb div_by_2_26(const limb v)
-{
- /* High word of v; no shift needed. */
- const u32 highword = (u32) (((u64) v) >> 32);
- /* Set to all 1s if v was negative; else set to 0s. */
- const s32 sign = ((s32) highword) >> 31;
- /* Set to 0x3ffffff if v was negative; else set to 0. */
- const s32 roundoff = ((u32) sign) >> 6;
- /* Should return v / (1<<26) */
- return (v + roundoff) >> 26;
-}
-
-/* return v / (2^25), using only shifts and adds.
- *
- * On entry: v can take any value.
- */
-static inline limb div_by_2_25(const limb v)
-{
- /* High word of v; no shift needed*/
- const u32 highword = (u32) (((u64) v) >> 32);
- /* Set to all 1s if v was negative; else set to 0s. */
- const s32 sign = ((s32) highword) >> 31;
- /* Set to 0x1ffffff if v was negative; else set to 0. */
- const s32 roundoff = ((u32) sign) >> 7;
- /* Should return v / (1<<25) */
- return (v + roundoff) >> 25;
-}
-
-/* Reduce all coefficients of the short form input so that |x| < 2^26.
- *
- * On entry: |output[i]| < 280*2^54
- */
-static void freduce_coefficients(limb *output)
-{
- unsigned int i;
-
- output[10] = 0;
-
- for (i = 0; i < 10; i += 2) {
- limb over = div_by_2_26(output[i]);
- /* The entry condition (that |output[i]| < 280*2^54) means that over is, at
- * most, 280*2^28 in the first iteration of this loop. This is added to the
- * next limb and we can approximate the resulting bound of that limb by
- * 281*2^54.
- */
- output[i] -= over << 26;
- output[i+1] += over;
-
- /* For the first iteration, |output[i+1]| < 281*2^54, thus |over| <
- * 281*2^29. When this is added to the next limb, the resulting bound can
- * be approximated as 281*2^54.
- *
- * For subsequent iterations of the loop, 281*2^54 remains a conservative
- * bound and no overflow occurs.
- */
- over = div_by_2_25(output[i+1]);
- output[i+1] -= over << 25;
- output[i+2] += over;
- }
- /* Now |output[10]| < 281*2^29 and all other coefficients are reduced. */
- output[0] += output[10] << 4;
- output[0] += output[10] << 1;
- output[0] += output[10];
-
- output[10] = 0;
-
- /* Now output[1..9] are reduced, and |output[0]| < 2^26 + 19*281*2^29
- * So |over| will be no more than 2^16.
- */
- {
- limb over = div_by_2_26(output[0]);
-
- output[0] -= over << 26;
- output[1] += over;
- }
-
- /* Now output[0,2..9] are reduced, and |output[1]| < 2^25 + 2^16 < 2^26. The
- * bound on |output[1]| is sufficient to meet our needs.
- */
-}
-
-/* A helpful wrapper around fproduct: output = in * in2.
- *
- * On entry: |in[i]| < 2^27 and |in2[i]| < 2^27.
- *
- * output must be distinct to both inputs. The output is reduced degree
- * (indeed, one need only provide storage for 10 limbs) and |output[i]| < 2^26.
- */
-static void fmul(limb *output, const limb *in, const limb *in2)
-{
- limb t[19];
-
- fproduct(t, in, in2);
- /* |t[i]| < 14*2^54 */
- freduce_degree(t);
- freduce_coefficients(t);
- /* |t[i]| < 2^26 */
- memcpy(output, t, sizeof(limb) * 10);
-}
-
-/* Square a number: output = in**2
- *
- * output must be distinct from the input. The inputs are reduced coefficient
- * form, the output is not.
- *
- * output[x] <= 14 * the largest product of the input limbs.
- */
-static void fsquare_inner(limb *output, const limb *in)
-{
- output[0] = ((limb) ((s32) in[0])) * ((s32) in[0]);
- output[1] = 2 * ((limb) ((s32) in[0])) * ((s32) in[1]);
- output[2] = 2 * (((limb) ((s32) in[1])) * ((s32) in[1]) +
- ((limb) ((s32) in[0])) * ((s32) in[2]));
- output[3] = 2 * (((limb) ((s32) in[1])) * ((s32) in[2]) +
- ((limb) ((s32) in[0])) * ((s32) in[3]));
- output[4] = ((limb) ((s32) in[2])) * ((s32) in[2]) +
- 4 * ((limb) ((s32) in[1])) * ((s32) in[3]) +
- 2 * ((limb) ((s32) in[0])) * ((s32) in[4]);
- output[5] = 2 * (((limb) ((s32) in[2])) * ((s32) in[3]) +
- ((limb) ((s32) in[1])) * ((s32) in[4]) +
- ((limb) ((s32) in[0])) * ((s32) in[5]));
- output[6] = 2 * (((limb) ((s32) in[3])) * ((s32) in[3]) +
- ((limb) ((s32) in[2])) * ((s32) in[4]) +
- ((limb) ((s32) in[0])) * ((s32) in[6]) +
- 2 * ((limb) ((s32) in[1])) * ((s32) in[5]));
- output[7] = 2 * (((limb) ((s32) in[3])) * ((s32) in[4]) +
- ((limb) ((s32) in[2])) * ((s32) in[5]) +
- ((limb) ((s32) in[1])) * ((s32) in[6]) +
- ((limb) ((s32) in[0])) * ((s32) in[7]));
- output[8] = ((limb) ((s32) in[4])) * ((s32) in[4]) +
- 2 * (((limb) ((s32) in[2])) * ((s32) in[6]) +
- ((limb) ((s32) in[0])) * ((s32) in[8]) +
- 2 * (((limb) ((s32) in[1])) * ((s32) in[7]) +
- ((limb) ((s32) in[3])) * ((s32) in[5])));
- output[9] = 2 * (((limb) ((s32) in[4])) * ((s32) in[5]) +
- ((limb) ((s32) in[3])) * ((s32) in[6]) +
- ((limb) ((s32) in[2])) * ((s32) in[7]) +
- ((limb) ((s32) in[1])) * ((s32) in[8]) +
- ((limb) ((s32) in[0])) * ((s32) in[9]));
- output[10] = 2 * (((limb) ((s32) in[5])) * ((s32) in[5]) +
- ((limb) ((s32) in[4])) * ((s32) in[6]) +
- ((limb) ((s32) in[2])) * ((s32) in[8]) +
- 2 * (((limb) ((s32) in[3])) * ((s32) in[7]) +
- ((limb) ((s32) in[1])) * ((s32) in[9])));
- output[11] = 2 * (((limb) ((s32) in[5])) * ((s32) in[6]) +
- ((limb) ((s32) in[4])) * ((s32) in[7]) +
- ((limb) ((s32) in[3])) * ((s32) in[8]) +
- ((limb) ((s32) in[2])) * ((s32) in[9]));
- output[12] = ((limb) ((s32) in[6])) * ((s32) in[6]) +
- 2 * (((limb) ((s32) in[4])) * ((s32) in[8]) +
- 2 * (((limb) ((s32) in[5])) * ((s32) in[7]) +
- ((limb) ((s32) in[3])) * ((s32) in[9])));
- output[13] = 2 * (((limb) ((s32) in[6])) * ((s32) in[7]) +
- ((limb) ((s32) in[5])) * ((s32) in[8]) +
- ((limb) ((s32) in[4])) * ((s32) in[9]));
- output[14] = 2 * (((limb) ((s32) in[7])) * ((s32) in[7]) +
- ((limb) ((s32) in[6])) * ((s32) in[8]) +
- 2 * ((limb) ((s32) in[5])) * ((s32) in[9]));
- output[15] = 2 * (((limb) ((s32) in[7])) * ((s32) in[8]) +
- ((limb) ((s32) in[6])) * ((s32) in[9]));
- output[16] = ((limb) ((s32) in[8])) * ((s32) in[8]) +
- 4 * ((limb) ((s32) in[7])) * ((s32) in[9]);
- output[17] = 2 * ((limb) ((s32) in[8])) * ((s32) in[9]);
- output[18] = 2 * ((limb) ((s32) in[9])) * ((s32) in[9]);
-}
-
-/* fsquare sets output = in^2.
- *
- * On entry: The |in| argument is in reduced coefficients form and |in[i]| <
- * 2^27.
- *
- * On exit: The |output| argument is in reduced coefficients form (indeed, one
- * need only provide storage for 10 limbs) and |out[i]| < 2^26.
- */
-static void fsquare(limb *output, const limb *in)
-{
- limb t[19];
-
- fsquare_inner(t, in);
- /* |t[i]| < 14*2^54 because the largest product of two limbs will be <
- * 2^(27+27) and fsquare_inner adds together, at most, 14 of those
- * products.
- */
- freduce_degree(t);
- freduce_coefficients(t);
- /* |t[i]| < 2^26 */
- memcpy(output, t, sizeof(limb) * 10);
-}
-
-/* Take a little-endian, 32-byte number and expand it into polynomial form */
-static inline void fexpand(limb *output, const u8 *input)
-{
-#define F(n, start, shift, mask) \
- output[n] = ((((limb) input[start + 0]) | \
- ((limb) input[start + 1]) << 8 | \
- ((limb) input[start + 2]) << 16 | \
- ((limb) input[start + 3]) << 24) >> shift) & mask;
- F(0, 0, 0, 0x3ffffff);
- F(1, 3, 2, 0x1ffffff);
- F(2, 6, 3, 0x3ffffff);
- F(3, 9, 5, 0x1ffffff);
- F(4, 12, 6, 0x3ffffff);
- F(5, 16, 0, 0x1ffffff);
- F(6, 19, 1, 0x3ffffff);
- F(7, 22, 3, 0x1ffffff);
- F(8, 25, 4, 0x3ffffff);
- F(9, 28, 6, 0x1ffffff);
-#undef F
-}
-
-/* s32_eq returns 0xffffffff iff a == b and zero otherwise. */
-static s32 s32_eq(s32 a, s32 b)
-{
- a = ~(a ^ b);
- a &= a << 16;
- a &= a << 8;
- a &= a << 4;
- a &= a << 2;
- a &= a << 1;
- return a >> 31;
-}
-
-/* s32_gte returns 0xffffffff if a >= b and zero otherwise, where a and b are
- * both non-negative.
- */
-static s32 s32_gte(s32 a, s32 b)
-{
- a -= b;
- /* a >= 0 iff a >= b. */
- return ~(a >> 31);
-}
-
-/* Take a fully reduced polynomial form number and contract it into a
- * little-endian, 32-byte array.
- *
- * On entry: |input_limbs[i]| < 2^26
- */
-static void fcontract(u8 *output, limb *input_limbs)
-{
- int i;
- int j;
- s32 input[10];
- s32 mask;
-
- /* |input_limbs[i]| < 2^26, so it's valid to convert to an s32. */
- for (i = 0; i < 10; i++) {
- input[i] = input_limbs[i];
- }
-
- for (j = 0; j < 2; ++j) {
- for (i = 0; i < 9; ++i) {
- if ((i & 1) == 1) {
- /* This calculation is a time-invariant way to make input[i]
- * non-negative by borrowing from the next-larger limb.
- */
- const s32 mask = input[i] >> 31;
- const s32 carry = -((input[i] & mask) >> 25);
-
- input[i] = input[i] + (carry << 25);
- input[i+1] = input[i+1] - carry;
- } else {
- const s32 mask = input[i] >> 31;
- const s32 carry = -((input[i] & mask) >> 26);
-
- input[i] = input[i] + (carry << 26);
- input[i+1] = input[i+1] - carry;
- }
- }
-
- /* There's no greater limb for input[9] to borrow from, but we can multiply
- * by 19 and borrow from input[0], which is valid mod 2^255-19.
- */
- {
- const s32 mask = input[9] >> 31;
- const s32 carry = -((input[9] & mask) >> 25);
-
- input[9] = input[9] + (carry << 25);
- input[0] = input[0] - (carry * 19);
- }
-
- /* After the first iteration, input[1..9] are non-negative and fit within
- * 25 or 26 bits, depending on position. However, input[0] may be
- * negative.
- */
- }
-
- /* The first borrow-propagation pass above ended with every limb
- except (possibly) input[0] non-negative.
- If input[0] was negative after the first pass, then it was because of a
- carry from input[9]. On entry, input[9] < 2^26 so the carry was, at most,
- one, since (2**26-1) >> 25 = 1. Thus input[0] >= -19.
- In the second pass, each limb is decreased by at most one. Thus the second
- borrow-propagation pass could only have wrapped around to decrease
- input[0] again if the first pass left input[0] negative *and* input[1]
- through input[9] were all zero. In that case, input[1] is now 2^25 - 1,
- and this last borrow-propagation step will leave input[1] non-negative. */
- {
- const s32 mask = input[0] >> 31;
- const s32 carry = -((input[0] & mask) >> 26);
-
- input[0] = input[0] + (carry << 26);
- input[1] = input[1] - carry;
- }
-
- /* All input[i] are now non-negative. However, there might be values between
- * 2^25 and 2^26 in a limb which is, nominally, 25 bits wide.
- */
- for (j = 0; j < 2; j++) {
- for (i = 0; i < 9; i++) {
- if ((i & 1) == 1) {
- const s32 carry = input[i] >> 25;
-
- input[i] &= 0x1ffffff;
- input[i+1] += carry;
- } else {
- const s32 carry = input[i] >> 26;
-
- input[i] &= 0x3ffffff;
- input[i+1] += carry;
- }
- }
-
- {
- const s32 carry = input[9] >> 25;
-
- input[9] &= 0x1ffffff;
- input[0] += 19*carry;
- }
- }
-
- /* If the first carry-chain pass, just above, ended up with a carry from
- * input[9], and that caused input[0] to be out-of-bounds, then input[0] was
- * < 2^26 + 2*19, because the carry was, at most, two.
- *
- * If the second pass carried from input[9] again then input[0] is < 2*19 and
- * the input[9] -> input[0] carry didn't push input[0] out of bounds.
- */
-
- /* It still remains the case that input might be between 2^255-19 and 2^255.
- * In this case, input[1..9] must take their maximum value and input[0] must
- * be >= (2^255-19) & 0x3ffffff, which is 0x3ffffed.
- */
- mask = s32_gte(input[0], 0x3ffffed);
- for (i = 1; i < 10; i++) {
- if ((i & 1) == 1) {
- mask &= s32_eq(input[i], 0x1ffffff);
- } else {
- mask &= s32_eq(input[i], 0x3ffffff);
- }
- }
-
- /* mask is either 0xffffffff (if input >= 2^255-19) and zero otherwise. Thus
- * this conditionally subtracts 2^255-19.
- */
- input[0] -= mask & 0x3ffffed;
-
- for (i = 1; i < 10; i++) {
- if ((i & 1) == 1) {
- input[i] -= mask & 0x1ffffff;
- } else {
- input[i] -= mask & 0x3ffffff;
- }
- }
-
- input[1] <<= 2;
- input[2] <<= 3;
- input[3] <<= 5;
- input[4] <<= 6;
- input[6] <<= 1;
- input[7] <<= 3;
- input[8] <<= 4;
- input[9] <<= 6;
-#define F(i, s) \
- output[s+0] |= input[i] & 0xff; \
- output[s+1] = (input[i] >> 8) & 0xff; \
- output[s+2] = (input[i] >> 16) & 0xff; \
- output[s+3] = (input[i] >> 24) & 0xff;
- output[0] = 0;
- output[16] = 0;
- F(0, 0);
- F(1, 3);
- F(2, 6);
- F(3, 9);
- F(4, 12);
- F(5, 16);
- F(6, 19);
- F(7, 22);
- F(8, 25);
- F(9, 28);
-#undef F
-}
-
-/* Conditionally swap two reduced-form limb arrays if 'iswap' is 1, but leave
- * them unchanged if 'iswap' is 0. Runs in data-invariant time to avoid
- * side-channel attacks.
- *
- * NOTE that this function requires that 'iswap' be 1 or 0; other values give
- * wrong results. Also, the two limb arrays must be in reduced-coefficient,
- * reduced-degree form: the values in a[10..19] or b[10..19] aren't swapped,
- * and all all values in a[0..9],b[0..9] must have magnitude less than
- * INT32_MAX.
- */
-static void swap_conditional(limb a[19], limb b[19], limb iswap)
-{
- unsigned int i;
- const s32 swap = (s32) -iswap;
-
- for (i = 0; i < 10; ++i) {
- const s32 x = swap & (((s32)a[i]) ^ ((s32)b[i]));
-
- a[i] = ((s32)a[i]) ^ x;
- b[i] = ((s32)b[i]) ^ x;
- }
-}
-
-static void crecip(limb *out, const limb *z)
-{
- limb z2[10];
- limb z9[10];
- limb z11[10];
- limb z2_5_0[10];
- limb z2_10_0[10];
- limb z2_20_0[10];
- limb z2_50_0[10];
- limb z2_100_0[10];
- limb t0[10];
- limb t1[10];
- int i;
-
- /* 2 */ fsquare(z2, z);
- /* 4 */ fsquare(t1, z2);
- /* 8 */ fsquare(t0, t1);
- /* 9 */ fmul(z9, t0, z);
- /* 11 */ fmul(z11, z9, z2);
- /* 22 */ fsquare(t0, z11);
- /* 2^5 - 2^0 = 31 */ fmul(z2_5_0, t0, z9);
-
- /* 2^6 - 2^1 */ fsquare(t0, z2_5_0);
- /* 2^7 - 2^2 */ fsquare(t1, t0);
- /* 2^8 - 2^3 */ fsquare(t0, t1);
- /* 2^9 - 2^4 */ fsquare(t1, t0);
- /* 2^10 - 2^5 */ fsquare(t0, t1);
- /* 2^10 - 2^0 */ fmul(z2_10_0, t0, z2_5_0);
-
- /* 2^11 - 2^1 */ fsquare(t0, z2_10_0);
- /* 2^12 - 2^2 */ fsquare(t1, t0);
- /* 2^20 - 2^10 */ for (i = 2; i < 10; i += 2) { fsquare(t0, t1); fsquare(t1, t0); }
- /* 2^20 - 2^0 */ fmul(z2_20_0, t1, z2_10_0);
-
- /* 2^21 - 2^1 */ fsquare(t0, z2_20_0);
- /* 2^22 - 2^2 */ fsquare(t1, t0);
- /* 2^40 - 2^20 */ for (i = 2; i < 20; i += 2) { fsquare(t0, t1); fsquare(t1, t0); }
- /* 2^40 - 2^0 */ fmul(t0, t1, z2_20_0);
-
- /* 2^41 - 2^1 */ fsquare(t1, t0);
- /* 2^42 - 2^2 */ fsquare(t0, t1);
- /* 2^50 - 2^10 */ for (i = 2; i < 10; i += 2) { fsquare(t1, t0); fsquare(t0, t1); }
- /* 2^50 - 2^0 */ fmul(z2_50_0, t0, z2_10_0);
-
- /* 2^51 - 2^1 */ fsquare(t0, z2_50_0);
- /* 2^52 - 2^2 */ fsquare(t1, t0);
- /* 2^100 - 2^50 */ for (i = 2; i < 50; i += 2) { fsquare(t0, t1); fsquare(t1, t0); }
- /* 2^100 - 2^0 */ fmul(z2_100_0, t1, z2_50_0);
-
- /* 2^101 - 2^1 */ fsquare(t1, z2_100_0);
- /* 2^102 - 2^2 */ fsquare(t0, t1);
- /* 2^200 - 2^100 */ for (i = 2; i < 100; i += 2) { fsquare(t1, t0); fsquare(t0, t1); }
- /* 2^200 - 2^0 */ fmul(t1, t0, z2_100_0);
-
- /* 2^201 - 2^1 */ fsquare(t0, t1);
- /* 2^202 - 2^2 */ fsquare(t1, t0);
- /* 2^250 - 2^50 */ for (i = 2; i < 50; i += 2) { fsquare(t0, t1); fsquare(t1, t0); }
- /* 2^250 - 2^0 */ fmul(t0, t1, z2_50_0);
-
- /* 2^251 - 2^1 */ fsquare(t1, t0);
- /* 2^252 - 2^2 */ fsquare(t0, t1);
- /* 2^253 - 2^3 */ fsquare(t1, t0);
- /* 2^254 - 2^4 */ fsquare(t0, t1);
- /* 2^255 - 2^5 */ fsquare(t1, t0);
- /* 2^255 - 21 */ fmul(out, t1, z11);
-}
-
-
-/* Input: Q, Q', Q-Q'
- * Output: 2Q, Q+Q'
- *
- * x2 z3: long form
- * x3 z3: long form
- * x z: short form, destroyed
- * xprime zprime: short form, destroyed
- * qmqp: short form, preserved
- *
- * On entry and exit, the absolute value of the limbs of all inputs and outputs
- * are < 2^26.
- */
-static void fmonty(limb *x2, limb *z2, /* output 2Q */
- limb *x3, limb *z3, /* output Q + Q' */
- limb *x, limb *z, /* input Q */
- limb *xprime, limb *zprime, /* input Q' */
-
- const limb *qmqp /* input Q - Q' */)
-{
- limb origx[10], origxprime[10], zzz[19], xx[19], zz[19], xxprime[19],
- zzprime[19], zzzprime[19], xxxprime[19];
-
- memcpy(origx, x, 10 * sizeof(limb));
- fsum(x, z);
- /* |x[i]| < 2^27 */
- fdifference(z, origx); /* does x - z */
- /* |z[i]| < 2^27 */
-
- memcpy(origxprime, xprime, sizeof(limb) * 10);
- fsum(xprime, zprime);
- /* |xprime[i]| < 2^27 */
- fdifference(zprime, origxprime);
- /* |zprime[i]| < 2^27 */
- fproduct(xxprime, xprime, z);
- /* |xxprime[i]| < 14*2^54: the largest product of two limbs will be <
- * 2^(27+27) and fproduct adds together, at most, 14 of those products.
- * (Approximating that to 2^58 doesn't work out.)
- */
- fproduct(zzprime, x, zprime);
- /* |zzprime[i]| < 14*2^54 */
- freduce_degree(xxprime);
- freduce_coefficients(xxprime);
- /* |xxprime[i]| < 2^26 */
- freduce_degree(zzprime);
- freduce_coefficients(zzprime);
- /* |zzprime[i]| < 2^26 */
- memcpy(origxprime, xxprime, sizeof(limb) * 10);
- fsum(xxprime, zzprime);
- /* |xxprime[i]| < 2^27 */
- fdifference(zzprime, origxprime);
- /* |zzprime[i]| < 2^27 */
- fsquare(xxxprime, xxprime);
- /* |xxxprime[i]| < 2^26 */
- fsquare(zzzprime, zzprime);
- /* |zzzprime[i]| < 2^26 */
- fproduct(zzprime, zzzprime, qmqp);
- /* |zzprime[i]| < 14*2^52 */
- freduce_degree(zzprime);
- freduce_coefficients(zzprime);
- /* |zzprime[i]| < 2^26 */
- memcpy(x3, xxxprime, sizeof(limb) * 10);
- memcpy(z3, zzprime, sizeof(limb) * 10);
-
- fsquare(xx, x);
- /* |xx[i]| < 2^26 */
- fsquare(zz, z);
- /* |zz[i]| < 2^26 */
- fproduct(x2, xx, zz);
- /* |x2[i]| < 14*2^52 */
- freduce_degree(x2);
- freduce_coefficients(x2);
- /* |x2[i]| < 2^26 */
- fdifference(zz, xx); // does zz = xx - zz
- /* |zz[i]| < 2^27 */
- memset(zzz + 10, 0, sizeof(limb) * 9);
- fscalar_product(zzz, zz, 121665);
- /* |zzz[i]| < 2^(27+17) */
- /* No need to call freduce_degree here:
- fscalar_product doesn't increase the degree of its input. */
- freduce_coefficients(zzz);
- /* |zzz[i]| < 2^26 */
- fsum(zzz, xx);
- /* |zzz[i]| < 2^27 */
- fproduct(z2, zz, zzz);
- /* |z2[i]| < 14*2^(26+27) */
- freduce_degree(z2);
- freduce_coefficients(z2);
- /* |z2|i| < 2^26 */
-}
-
-/* Calculates nQ where Q is the x-coordinate of a point on the curve
- *
- * resultx/resultz: the x coordinate of the resulting curve point (short form)
- * n: a little endian, 32-byte number
- * q: a point of the curve (short form)
- */
-static void cmult(limb *resultx, limb *resultz, const u8 *n, const limb *q)
-{
- limb a[19] = {0}, b[19] = {1}, c[19] = {1}, d[19] = {0};
- limb *nqpqx = a, *nqpqz = b, *nqx = c, *nqz = d, *t;
- limb e[19] = {0}, f[19] = {1}, g[19] = {0}, h[19] = {1};
- limb *nqpqx2 = e, *nqpqz2 = f, *nqx2 = g, *nqz2 = h;
-
- unsigned int i, j;
-
- memcpy(nqpqx, q, sizeof(limb) * 10);
-
- for (i = 0; i < 32; ++i) {
- u8 byte = n[31 - i];
-
- for (j = 0; j < 8; ++j) {
- const limb bit = byte >> 7;
-
- swap_conditional(nqx, nqpqx, bit);
- swap_conditional(nqz, nqpqz, bit);
- fmonty(nqx2, nqz2,
- nqpqx2, nqpqz2,
- nqx, nqz,
- nqpqx, nqpqz,
- q);
- swap_conditional(nqx2, nqpqx2, bit);
- swap_conditional(nqz2, nqpqz2, bit);
-
- t = nqx;
- nqx = nqx2;
- nqx2 = t;
- t = nqz;
- nqz = nqz2;
- nqz2 = t;
- t = nqpqx;
- nqpqx = nqpqx2;
- nqpqx2 = t;
- t = nqpqz;
- nqpqz = nqpqz2;
- nqpqz2 = t;
-
- byte <<= 1;
- }
- }
-
- memcpy(resultx, nqx, sizeof(limb) * 10);
- memcpy(resultz, nqz, sizeof(limb) * 10);
-}
-
-bool curve25519_donna32(u8 mypublic[CURVE25519_POINT_SIZE], const u8 secret[CURVE25519_POINT_SIZE], const u8 basepoint[CURVE25519_POINT_SIZE])
-{
- limb bp[10], x[10], z[11], zmone[10];
- u8 e[32];
-
- memcpy(e, secret, 32);
- normalize_secret(e);
-
- fexpand(bp, basepoint);
- cmult(x, z, e, bp);
- crecip(zmone, z);
- fmul(z, x, zmone);
- fcontract(mypublic, z);
-
- return true;
-}
diff --git a/curve25519-donna64.c b/curve25519-donna64.c
deleted file mode 100644
index f294369..0000000
--- a/curve25519-donna64.c
+++ /dev/null
@@ -1,414 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2008 Google Inc. All Rights Reserved.
- * Copyright (C) 2015-2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * Original author: Adam Langley <agl@imperialviolet.org>
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-typedef u64 limb;
-typedef limb felem[5];
-typedef __uint128_t u128;
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-/* Sum two numbers: output += in */
-static __always_inline void fsum(limb *output, const limb *in)
-{
- output[0] += in[0];
- output[1] += in[1];
- output[2] += in[2];
- output[3] += in[3];
- output[4] += in[4];
-}
-
-/* Find the difference of two numbers: output = in - output
- * (note the order of the arguments!)
- *
- * Assumes that out[i] < 2**52
- * On return, out[i] < 2**55
- */
-static __always_inline void fdifference_backwards(felem out, const felem in)
-{
- /* 152 is 19 << 3 */
- static const limb two54m152 = (((limb)1) << 54) - 152;
- static const limb two54m8 = (((limb)1) << 54) - 8;
-
- out[0] = in[0] + two54m152 - out[0];
- out[1] = in[1] + two54m8 - out[1];
- out[2] = in[2] + two54m8 - out[2];
- out[3] = in[3] + two54m8 - out[3];
- out[4] = in[4] + two54m8 - out[4];
-}
-
-/* Multiply a number by a scalar: output = in * scalar */
-static __always_inline void fscalar_product(felem output, const felem in, const limb scalar)
-{
- u128 a;
-
- a = ((u128) in[0]) * scalar;
- output[0] = ((limb)a) & 0x7ffffffffffffUL;
-
- a = ((u128) in[1]) * scalar + ((limb) (a >> 51));
- output[1] = ((limb)a) & 0x7ffffffffffffUL;
-
- a = ((u128) in[2]) * scalar + ((limb) (a >> 51));
- output[2] = ((limb)a) & 0x7ffffffffffffUL;
-
- a = ((u128) in[3]) * scalar + ((limb) (a >> 51));
- output[3] = ((limb)a) & 0x7ffffffffffffUL;
-
- a = ((u128) in[4]) * scalar + ((limb) (a >> 51));
- output[4] = ((limb)a) & 0x7ffffffffffffUL;
-
- output[0] += (a >> 51) * 19;
-}
-
-/* Multiply two numbers: output = in2 * in
- *
- * output must be distinct to both inputs. The inputs are reduced coefficient
- * form, the output is not.
- *
- * Assumes that in[i] < 2**55 and likewise for in2.
- * On return, output[i] < 2**52
- */
-static __always_inline void fmul(felem output, const felem in2, const felem in)
-{
- u128 t[5];
- limb r0, r1, r2, r3, r4, s0, s1, s2, s3, s4, c;
-
- r0 = in[0];
- r1 = in[1];
- r2 = in[2];
- r3 = in[3];
- r4 = in[4];
-
- s0 = in2[0];
- s1 = in2[1];
- s2 = in2[2];
- s3 = in2[3];
- s4 = in2[4];
-
- t[0] = ((u128) r0) * s0;
- t[1] = ((u128) r0) * s1 + ((u128) r1) * s0;
- t[2] = ((u128) r0) * s2 + ((u128) r2) * s0 + ((u128) r1) * s1;
- t[3] = ((u128) r0) * s3 + ((u128) r3) * s0 + ((u128) r1) * s2 + ((u128) r2) * s1;
- t[4] = ((u128) r0) * s4 + ((u128) r4) * s0 + ((u128) r3) * s1 + ((u128) r1) * s3 + ((u128) r2) * s2;
-
- r4 *= 19;
- r1 *= 19;
- r2 *= 19;
- r3 *= 19;
-
- t[0] += ((u128) r4) * s1 + ((u128) r1) * s4 + ((u128) r2) * s3 + ((u128) r3) * s2;
- t[1] += ((u128) r4) * s2 + ((u128) r2) * s4 + ((u128) r3) * s3;
- t[2] += ((u128) r4) * s3 + ((u128) r3) * s4;
- t[3] += ((u128) r4) * s4;
-
- r0 = (limb)t[0] & 0x7ffffffffffffUL; c = (limb)(t[0] >> 51);
- t[1] += c; r1 = (limb)t[1] & 0x7ffffffffffffUL; c = (limb)(t[1] >> 51);
- t[2] += c; r2 = (limb)t[2] & 0x7ffffffffffffUL; c = (limb)(t[2] >> 51);
- t[3] += c; r3 = (limb)t[3] & 0x7ffffffffffffUL; c = (limb)(t[3] >> 51);
- t[4] += c; r4 = (limb)t[4] & 0x7ffffffffffffUL; c = (limb)(t[4] >> 51);
- r0 += c * 19; c = r0 >> 51; r0 = r0 & 0x7ffffffffffffUL;
- r1 += c; c = r1 >> 51; r1 = r1 & 0x7ffffffffffffUL;
- r2 += c;
-
- output[0] = r0;
- output[1] = r1;
- output[2] = r2;
- output[3] = r3;
- output[4] = r4;
-}
-
-static __always_inline void fsquare_times(felem output, const felem in, limb count)
-{
- u128 t[5];
- limb r0, r1, r2, r3, r4, c;
- limb d0, d1, d2, d4, d419;
-
- r0 = in[0];
- r1 = in[1];
- r2 = in[2];
- r3 = in[3];
- r4 = in[4];
-
- do {
- d0 = r0 * 2;
- d1 = r1 * 2;
- d2 = r2 * 2 * 19;
- d419 = r4 * 19;
- d4 = d419 * 2;
-
- t[0] = ((u128) r0) * r0 + ((u128) d4) * r1 + (((u128) d2) * (r3 ));
- t[1] = ((u128) d0) * r1 + ((u128) d4) * r2 + (((u128) r3) * (r3 * 19));
- t[2] = ((u128) d0) * r2 + ((u128) r1) * r1 + (((u128) d4) * (r3 ));
- t[3] = ((u128) d0) * r3 + ((u128) d1) * r2 + (((u128) r4) * (d419 ));
- t[4] = ((u128) d0) * r4 + ((u128) d1) * r3 + (((u128) r2) * (r2 ));
-
- r0 = (limb)t[0] & 0x7ffffffffffffUL; c = (limb)(t[0] >> 51);
- t[1] += c; r1 = (limb)t[1] & 0x7ffffffffffffUL; c = (limb)(t[1] >> 51);
- t[2] += c; r2 = (limb)t[2] & 0x7ffffffffffffUL; c = (limb)(t[2] >> 51);
- t[3] += c; r3 = (limb)t[3] & 0x7ffffffffffffUL; c = (limb)(t[3] >> 51);
- t[4] += c; r4 = (limb)t[4] & 0x7ffffffffffffUL; c = (limb)(t[4] >> 51);
- r0 += c * 19; c = r0 >> 51; r0 = r0 & 0x7ffffffffffffUL;
- r1 += c; c = r1 >> 51; r1 = r1 & 0x7ffffffffffffUL;
- r2 += c;
- } while (--count);
-
- output[0] = r0;
- output[1] = r1;
- output[2] = r2;
- output[3] = r3;
- output[4] = r4;
-}
-
-/* Load a little-endian 64-bit number */
-static inline limb load_limb(const u8 *in)
-{
- return le64_to_cpu(*(__le64 *)in);
-}
-
-static inline void store_limb(u8 *out, limb in)
-{
- *(__le64 *)out = cpu_to_le64(in);
-}
-
-/* Take a little-endian, 32-byte number and expand it into polynomial form */
-static inline void fexpand(limb *output, const u8 *in)
-{
- output[0] = load_limb(in) & 0x7ffffffffffffUL;
- output[1] = (load_limb(in + 6) >> 3) & 0x7ffffffffffffUL;
- output[2] = (load_limb(in + 12) >> 6) & 0x7ffffffffffffUL;
- output[3] = (load_limb(in + 19) >> 1) & 0x7ffffffffffffUL;
- output[4] = (load_limb(in + 24) >> 12) & 0x7ffffffffffffUL;
-}
-
-/* Take a fully reduced polynomial form number and contract it into a
- * little-endian, 32-byte array
- */
-static void fcontract(u8 *output, const felem input)
-{
- u128 t[5];
-
- t[0] = input[0];
- t[1] = input[1];
- t[2] = input[2];
- t[3] = input[3];
- t[4] = input[4];
-
- t[1] += t[0] >> 51; t[0] &= 0x7ffffffffffffUL;
- t[2] += t[1] >> 51; t[1] &= 0x7ffffffffffffUL;
- t[3] += t[2] >> 51; t[2] &= 0x7ffffffffffffUL;
- t[4] += t[3] >> 51; t[3] &= 0x7ffffffffffffUL;
- t[0] += 19 * (t[4] >> 51); t[4] &= 0x7ffffffffffffUL;
-
- t[1] += t[0] >> 51; t[0] &= 0x7ffffffffffffUL;
- t[2] += t[1] >> 51; t[1] &= 0x7ffffffffffffUL;
- t[3] += t[2] >> 51; t[2] &= 0x7ffffffffffffUL;
- t[4] += t[3] >> 51; t[3] &= 0x7ffffffffffffUL;
- t[0] += 19 * (t[4] >> 51); t[4] &= 0x7ffffffffffffUL;
-
- /* now t is between 0 and 2^255-1, properly carried. */
- /* case 1: between 0 and 2^255-20. case 2: between 2^255-19 and 2^255-1. */
-
- t[0] += 19;
-
- t[1] += t[0] >> 51; t[0] &= 0x7ffffffffffffUL;
- t[2] += t[1] >> 51; t[1] &= 0x7ffffffffffffUL;
- t[3] += t[2] >> 51; t[2] &= 0x7ffffffffffffUL;
- t[4] += t[3] >> 51; t[3] &= 0x7ffffffffffffUL;
- t[0] += 19 * (t[4] >> 51); t[4] &= 0x7ffffffffffffUL;
-
- /* now between 19 and 2^255-1 in both cases, and offset by 19. */
-
- t[0] += 0x8000000000000UL - 19;
- t[1] += 0x8000000000000UL - 1;
- t[2] += 0x8000000000000UL - 1;
- t[3] += 0x8000000000000UL - 1;
- t[4] += 0x8000000000000UL - 1;
-
- /* now between 2^255 and 2^256-20, and offset by 2^255. */
-
- t[1] += t[0] >> 51; t[0] &= 0x7ffffffffffffUL;
- t[2] += t[1] >> 51; t[1] &= 0x7ffffffffffffUL;
- t[3] += t[2] >> 51; t[2] &= 0x7ffffffffffffUL;
- t[4] += t[3] >> 51; t[3] &= 0x7ffffffffffffUL;
- t[4] &= 0x7ffffffffffffUL;
-
- store_limb(output, t[0] | (t[1] << 51));
- store_limb(output+8, (t[1] >> 13) | (t[2] << 38));
- store_limb(output+16, (t[2] >> 26) | (t[3] << 25));
- store_limb(output+24, (t[3] >> 39) | (t[4] << 12));
-}
-
-/* Input: Q, Q', Q-Q'
- * Output: 2Q, Q+Q'
- *
- * x2 z3: long form
- * x3 z3: long form
- * x z: short form, destroyed
- * xprime zprime: short form, destroyed
- * qmqp: short form, preserved
- */
-static void fmonty(limb *x2, limb *z2, /* output 2Q */
- limb *x3, limb *z3, /* output Q + Q' */
- limb *x, limb *z, /* input Q */
- limb *xprime, limb *zprime, /* input Q' */
-
- const limb *qmqp /* input Q - Q' */)
-{
- limb origx[5], origxprime[5], zzz[5], xx[5], zz[5], xxprime[5], zzprime[5], zzzprime[5];
-
- memcpy(origx, x, 5 * sizeof(limb));
- fsum(x, z);
- fdifference_backwards(z, origx); // does x - z
-
- memcpy(origxprime, xprime, sizeof(limb) * 5);
- fsum(xprime, zprime);
- fdifference_backwards(zprime, origxprime);
- fmul(xxprime, xprime, z);
- fmul(zzprime, x, zprime);
- memcpy(origxprime, xxprime, sizeof(limb) * 5);
- fsum(xxprime, zzprime);
- fdifference_backwards(zzprime, origxprime);
- fsquare_times(x3, xxprime, 1);
- fsquare_times(zzzprime, zzprime, 1);
- fmul(z3, zzzprime, qmqp);
-
- fsquare_times(xx, x, 1);
- fsquare_times(zz, z, 1);
- fmul(x2, xx, zz);
- fdifference_backwards(zz, xx); // does zz = xx - zz
- fscalar_product(zzz, zz, 121665);
- fsum(zzz, xx);
- fmul(z2, zz, zzz);
-}
-
-/* Maybe swap the contents of two limb arrays (@a and @b), each @len elements
- * long. Perform the swap iff @swap is non-zero.
- *
- * This function performs the swap without leaking any side-channel
- * information.
- */
-static void swap_conditional(limb a[5], limb b[5], limb iswap)
-{
- unsigned int i;
- const limb swap = -iswap;
-
- for (i = 0; i < 5; ++i) {
- const limb x = swap & (a[i] ^ b[i]);
-
- a[i] ^= x;
- b[i] ^= x;
- }
-}
-
-/* Calculates nQ where Q is the x-coordinate of a point on the curve
- *
- * resultx/resultz: the x coordinate of the resulting curve point (short form)
- * n: a little endian, 32-byte number
- * q: a point of the curve (short form)
- */
-static void cmult(limb *resultx, limb *resultz, const u8 *n, const limb *q)
-{
- limb a[5] = {0}, b[5] = {1}, c[5] = {1}, d[5] = {0};
- limb *nqpqx = a, *nqpqz = b, *nqx = c, *nqz = d, *t;
- limb e[5] = {0}, f[5] = {1}, g[5] = {0}, h[5] = {1};
- limb *nqpqx2 = e, *nqpqz2 = f, *nqx2 = g, *nqz2 = h;
-
- unsigned int i, j;
-
- memcpy(nqpqx, q, sizeof(limb) * 5);
-
- for (i = 0; i < 32; ++i) {
- u8 byte = n[31 - i];
-
- for (j = 0; j < 8; ++j) {
- const limb bit = byte >> 7;
-
- swap_conditional(nqx, nqpqx, bit);
- swap_conditional(nqz, nqpqz, bit);
- fmonty(nqx2, nqz2,
- nqpqx2, nqpqz2,
- nqx, nqz,
- nqpqx, nqpqz,
- q);
- swap_conditional(nqx2, nqpqx2, bit);
- swap_conditional(nqz2, nqpqz2, bit);
-
- t = nqx;
- nqx = nqx2;
- nqx2 = t;
- t = nqz;
- nqz = nqz2;
- nqz2 = t;
- t = nqpqx;
- nqpqx = nqpqx2;
- nqpqx2 = t;
- t = nqpqz;
- nqpqz = nqpqz2;
- nqpqz2 = t;
-
- byte <<= 1;
- }
- }
-
- memcpy(resultx, nqx, sizeof(limb) * 5);
- memcpy(resultz, nqz, sizeof(limb) * 5);
-}
-
-static void crecip(felem out, const felem z)
-{
- felem a, t0, b, c;
-
- /* 2 */ fsquare_times(a, z, 1); // a = 2
- /* 8 */ fsquare_times(t0, a, 2);
- /* 9 */ fmul(b, t0, z); // b = 9
- /* 11 */ fmul(a, b, a); // a = 11
- /* 22 */ fsquare_times(t0, a, 1);
- /* 2^5 - 2^0 = 31 */ fmul(b, t0, b);
- /* 2^10 - 2^5 */ fsquare_times(t0, b, 5);
- /* 2^10 - 2^0 */ fmul(b, t0, b);
- /* 2^20 - 2^10 */ fsquare_times(t0, b, 10);
- /* 2^20 - 2^0 */ fmul(c, t0, b);
- /* 2^40 - 2^20 */ fsquare_times(t0, c, 20);
- /* 2^40 - 2^0 */ fmul(t0, t0, c);
- /* 2^50 - 2^10 */ fsquare_times(t0, t0, 10);
- /* 2^50 - 2^0 */ fmul(b, t0, b);
- /* 2^100 - 2^50 */ fsquare_times(t0, b, 50);
- /* 2^100 - 2^0 */ fmul(c, t0, b);
- /* 2^200 - 2^100 */ fsquare_times(t0, c, 100);
- /* 2^200 - 2^0 */ fmul(t0, t0, c);
- /* 2^250 - 2^50 */ fsquare_times(t0, t0, 50);
- /* 2^250 - 2^0 */ fmul(t0, t0, b);
- /* 2^255 - 2^5 */ fsquare_times(t0, t0, 5);
- /* 2^255 - 21 */ fmul(out, t0, a);
-}
-
-bool curve25519_donna64(u8 mypublic[CURVE25519_POINT_SIZE], const u8 secret[CURVE25519_POINT_SIZE], const u8 basepoint[CURVE25519_POINT_SIZE])
-{
- limb bp[5], x[5], z[5], zmone[5];
- u8 e[32];
-
- memcpy(e, secret, 32);
- normalize_secret(e);
-
- fexpand(bp, basepoint);
- cmult(x, z, e, bp);
- crecip(zmone, z);
- fmul(z, x, zmone);
- fcontract(mypublic, z);
-
- return true;
-}
diff --git a/curve25519-fiat32.c b/curve25519-fiat32.c
deleted file mode 100644
index 6d9ee7d..0000000
--- a/curve25519-fiat32.c
+++ /dev/null
@@ -1,838 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2015-2016 The fiat-crypto Authors.
- * Copyright (C) 2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * This is a machine-generated formally verified implementation of curve25519 DH from:
- * https://github.com/mit-plv/fiat-crypto
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-/* fe means field element. Here the field is \Z/(2^255-19). An element t,
- * entries t[0]...t[9], represents the integer t[0]+2^26 t[1]+2^51 t[2]+2^77
- * t[3]+2^102 t[4]+...+2^230 t[9].
- * fe limbs are bounded by 1.125*2^26,1.125*2^25,1.125*2^26,1.125*2^25,etc.
- * Multiplication and carrying produce fe from fe_loose.
- */
-typedef struct fe { u32 v[10]; } fe;
-
-/* fe_loose limbs are bounded by 3.375*2^26,3.375*2^25,3.375*2^26,3.375*2^25,etc.
- * Addition and subtraction produce fe_loose from (fe, fe).
- */
-typedef struct fe_loose { u32 v[10]; } fe_loose;
-
-static __always_inline void fe_frombytes_impl(u32 h[10], const u8 *s)
-{
- /* Ignores top bit of s. */
- u32 a0 = le32_to_cpup((__force __le32 *)(s));
- u32 a1 = le32_to_cpup((__force __le32 *)(s+4));
- u32 a2 = le32_to_cpup((__force __le32 *)(s+8));
- u32 a3 = le32_to_cpup((__force __le32 *)(s+12));
- u32 a4 = le32_to_cpup((__force __le32 *)(s+16));
- u32 a5 = le32_to_cpup((__force __le32 *)(s+20));
- u32 a6 = le32_to_cpup((__force __le32 *)(s+24));
- u32 a7 = le32_to_cpup((__force __le32 *)(s+28));
- h[0] = a0&((1<<26)-1); /* 26 used, 32-26 left. 26 */
- h[1] = (a0>>26) | ((a1&((1<<19)-1))<< 6); /* (32-26) + 19 = 6+19 = 25 */
- h[2] = (a1>>19) | ((a2&((1<<13)-1))<<13); /* (32-19) + 13 = 13+13 = 26 */
- h[3] = (a2>>13) | ((a3&((1<< 6)-1))<<19); /* (32-13) + 6 = 19+ 6 = 25 */
- h[4] = (a3>> 6); /* (32- 6) = 26 */
- h[5] = a4&((1<<25)-1); /* 25 */
- h[6] = (a4>>25) | ((a5&((1<<19)-1))<< 7); /* (32-25) + 19 = 7+19 = 26 */
- h[7] = (a5>>19) | ((a6&((1<<12)-1))<<13); /* (32-19) + 12 = 13+12 = 25 */
- h[8] = (a6>>12) | ((a7&((1<< 6)-1))<<20); /* (32-12) + 6 = 20+ 6 = 26 */
- h[9] = (a7>> 6)&((1<<25)-1); /* 25 */
-}
-
-static __always_inline void fe_frombytes(fe *h, const u8 *s)
-{
- fe_frombytes_impl(h->v, s);
-}
-
-static __always_inline u8 /*bool*/ addcarryx_u25(u8 /*bool*/ c, u32 a, u32 b, u32 *low)
-{
- /* This function extracts 25 bits of result and 1 bit of carry (26 total), so
- * a 32-bit intermediate is sufficient.
- */
- u32 x = a + b + c;
- *low = x & ((1 << 25) - 1);
- return (x >> 25) & 1;
-}
-
-static __always_inline u8 /*bool*/ addcarryx_u26(u8 /*bool*/ c, u32 a, u32 b, u32 *low)
-{
- /* This function extracts 26 bits of result and 1 bit of carry (27 total), so
- * a 32-bit intermediate is sufficient.
- */
- u32 x = a + b + c;
- *low = x & ((1 << 26) - 1);
- return (x >> 26) & 1;
-}
-
-static __always_inline u8 /*bool*/ subborrow_u25(u8 /*bool*/ c, u32 a, u32 b, u32 *low)
-{
- /* This function extracts 25 bits of result and 1 bit of borrow (26 total), so
- * a 32-bit intermediate is sufficient.
- */
- u32 x = a - b - c;
- *low = x & ((1 << 25) - 1);
- return x >> 31;
-}
-
-static __always_inline u8 /*bool*/ subborrow_u26(u8 /*bool*/ c, u32 a, u32 b, u32 *low)
-{
- /* This function extracts 26 bits of result and 1 bit of borrow (27 total), so
- * a 32-bit intermediate is sufficient.
- */
- u32 x = a - b - c;
- *low = x & ((1 << 26) - 1);
- return x >> 31;
-}
-
-static __always_inline u32 cmovznz32(u32 t, u32 z, u32 nz)
-{
- t = -!!t; /* all set if nonzero, 0 if 0 */
- return (t&nz) | ((~t)&z);
-}
-
-static __always_inline void fe_freeze(u32 out[10], const u32 in1[10])
-{
- { const u32 x17 = in1[9];
- { const u32 x18 = in1[8];
- { const u32 x16 = in1[7];
- { const u32 x14 = in1[6];
- { const u32 x12 = in1[5];
- { const u32 x10 = in1[4];
- { const u32 x8 = in1[3];
- { const u32 x6 = in1[2];
- { const u32 x4 = in1[1];
- { const u32 x2 = in1[0];
- { u32 x20; u8/*bool*/ x21 = subborrow_u26(0x0, x2, 0x3ffffed, &x20);
- { u32 x23; u8/*bool*/ x24 = subborrow_u25(x21, x4, 0x1ffffff, &x23);
- { u32 x26; u8/*bool*/ x27 = subborrow_u26(x24, x6, 0x3ffffff, &x26);
- { u32 x29; u8/*bool*/ x30 = subborrow_u25(x27, x8, 0x1ffffff, &x29);
- { u32 x32; u8/*bool*/ x33 = subborrow_u26(x30, x10, 0x3ffffff, &x32);
- { u32 x35; u8/*bool*/ x36 = subborrow_u25(x33, x12, 0x1ffffff, &x35);
- { u32 x38; u8/*bool*/ x39 = subborrow_u26(x36, x14, 0x3ffffff, &x38);
- { u32 x41; u8/*bool*/ x42 = subborrow_u25(x39, x16, 0x1ffffff, &x41);
- { u32 x44; u8/*bool*/ x45 = subborrow_u26(x42, x18, 0x3ffffff, &x44);
- { u32 x47; u8/*bool*/ x48 = subborrow_u25(x45, x17, 0x1ffffff, &x47);
- { u32 x49 = cmovznz32(x48, 0x0, 0xffffffff);
- { u32 x50 = (x49 & 0x3ffffed);
- { u32 x52; u8/*bool*/ x53 = addcarryx_u26(0x0, x20, x50, &x52);
- { u32 x54 = (x49 & 0x1ffffff);
- { u32 x56; u8/*bool*/ x57 = addcarryx_u25(x53, x23, x54, &x56);
- { u32 x58 = (x49 & 0x3ffffff);
- { u32 x60; u8/*bool*/ x61 = addcarryx_u26(x57, x26, x58, &x60);
- { u32 x62 = (x49 & 0x1ffffff);
- { u32 x64; u8/*bool*/ x65 = addcarryx_u25(x61, x29, x62, &x64);
- { u32 x66 = (x49 & 0x3ffffff);
- { u32 x68; u8/*bool*/ x69 = addcarryx_u26(x65, x32, x66, &x68);
- { u32 x70 = (x49 & 0x1ffffff);
- { u32 x72; u8/*bool*/ x73 = addcarryx_u25(x69, x35, x70, &x72);
- { u32 x74 = (x49 & 0x3ffffff);
- { u32 x76; u8/*bool*/ x77 = addcarryx_u26(x73, x38, x74, &x76);
- { u32 x78 = (x49 & 0x1ffffff);
- { u32 x80; u8/*bool*/ x81 = addcarryx_u25(x77, x41, x78, &x80);
- { u32 x82 = (x49 & 0x3ffffff);
- { u32 x84; u8/*bool*/ x85 = addcarryx_u26(x81, x44, x82, &x84);
- { u32 x86 = (x49 & 0x1ffffff);
- { u32 x88; addcarryx_u25(x85, x47, x86, &x88);
- out[0] = x52;
- out[1] = x56;
- out[2] = x60;
- out[3] = x64;
- out[4] = x68;
- out[5] = x72;
- out[6] = x76;
- out[7] = x80;
- out[8] = x84;
- out[9] = x88;
- }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_tobytes(u8 s[32], const fe *f)
-{
- u32 h[10];
- fe_freeze(h, f->v);
- s[0] = h[0] >> 0;
- s[1] = h[0] >> 8;
- s[2] = h[0] >> 16;
- s[3] = (h[0] >> 24) | (h[1] << 2);
- s[4] = h[1] >> 6;
- s[5] = h[1] >> 14;
- s[6] = (h[1] >> 22) | (h[2] << 3);
- s[7] = h[2] >> 5;
- s[8] = h[2] >> 13;
- s[9] = (h[2] >> 21) | (h[3] << 5);
- s[10] = h[3] >> 3;
- s[11] = h[3] >> 11;
- s[12] = (h[3] >> 19) | (h[4] << 6);
- s[13] = h[4] >> 2;
- s[14] = h[4] >> 10;
- s[15] = h[4] >> 18;
- s[16] = h[5] >> 0;
- s[17] = h[5] >> 8;
- s[18] = h[5] >> 16;
- s[19] = (h[5] >> 24) | (h[6] << 1);
- s[20] = h[6] >> 7;
- s[21] = h[6] >> 15;
- s[22] = (h[6] >> 23) | (h[7] << 3);
- s[23] = h[7] >> 5;
- s[24] = h[7] >> 13;
- s[25] = (h[7] >> 21) | (h[8] << 4);
- s[26] = h[8] >> 4;
- s[27] = h[8] >> 12;
- s[28] = (h[8] >> 20) | (h[9] << 6);
- s[29] = h[9] >> 2;
- s[30] = h[9] >> 10;
- s[31] = h[9] >> 18;
-}
-
-/* h = f */
-static __always_inline void fe_copy(fe *h, const fe *f)
-{
- memmove(h, f, sizeof(fe));
-}
-
-static __always_inline void fe_copy_lt(fe_loose *h, const fe *f)
-{
- memmove(h, f, sizeof(fe));
-}
-
-/* h = 0 */
-static __always_inline void fe_0(fe *h)
-{
- memset(h, 0, sizeof(fe));
-}
-
-/* h = 1 */
-static __always_inline void fe_1(fe *h)
-{
- memset(h, 0, sizeof(fe));
- h->v[0] = 1;
-}
-
-static __always_inline void fe_add_impl(u32 out[10], const u32 in1[10], const u32 in2[10])
-{
- { const u32 x20 = in1[9];
- { const u32 x21 = in1[8];
- { const u32 x19 = in1[7];
- { const u32 x17 = in1[6];
- { const u32 x15 = in1[5];
- { const u32 x13 = in1[4];
- { const u32 x11 = in1[3];
- { const u32 x9 = in1[2];
- { const u32 x7 = in1[1];
- { const u32 x5 = in1[0];
- { const u32 x38 = in2[9];
- { const u32 x39 = in2[8];
- { const u32 x37 = in2[7];
- { const u32 x35 = in2[6];
- { const u32 x33 = in2[5];
- { const u32 x31 = in2[4];
- { const u32 x29 = in2[3];
- { const u32 x27 = in2[2];
- { const u32 x25 = in2[1];
- { const u32 x23 = in2[0];
- out[0] = (x5 + x23);
- out[1] = (x7 + x25);
- out[2] = (x9 + x27);
- out[3] = (x11 + x29);
- out[4] = (x13 + x31);
- out[5] = (x15 + x33);
- out[6] = (x17 + x35);
- out[7] = (x19 + x37);
- out[8] = (x21 + x39);
- out[9] = (x20 + x38);
- }}}}}}}}}}}}}}}}}}}}
-}
-
-/* h = f + g
- * Can overlap h with f or g.
- */
-static __always_inline void fe_add(fe_loose *h, const fe *f, const fe *g)
-{
- fe_add_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_sub_impl(u32 out[10], const u32 in1[10], const u32 in2[10])
-{
- { const u32 x20 = in1[9];
- { const u32 x21 = in1[8];
- { const u32 x19 = in1[7];
- { const u32 x17 = in1[6];
- { const u32 x15 = in1[5];
- { const u32 x13 = in1[4];
- { const u32 x11 = in1[3];
- { const u32 x9 = in1[2];
- { const u32 x7 = in1[1];
- { const u32 x5 = in1[0];
- { const u32 x38 = in2[9];
- { const u32 x39 = in2[8];
- { const u32 x37 = in2[7];
- { const u32 x35 = in2[6];
- { const u32 x33 = in2[5];
- { const u32 x31 = in2[4];
- { const u32 x29 = in2[3];
- { const u32 x27 = in2[2];
- { const u32 x25 = in2[1];
- { const u32 x23 = in2[0];
- out[0] = ((0x7ffffda + x5) - x23);
- out[1] = ((0x3fffffe + x7) - x25);
- out[2] = ((0x7fffffe + x9) - x27);
- out[3] = ((0x3fffffe + x11) - x29);
- out[4] = ((0x7fffffe + x13) - x31);
- out[5] = ((0x3fffffe + x15) - x33);
- out[6] = ((0x7fffffe + x17) - x35);
- out[7] = ((0x3fffffe + x19) - x37);
- out[8] = ((0x7fffffe + x21) - x39);
- out[9] = ((0x3fffffe + x20) - x38);
- }}}}}}}}}}}}}}}}}}}}
-}
-
-/* h = f - g
- * Can overlap h with f or g.
- */
-static __always_inline void fe_sub(fe_loose *h, const fe *f, const fe *g)
-{
- fe_sub_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_mul_impl(u32 out[10], const u32 in1[10], const u32 in2[10])
-{
- { const u32 x20 = in1[9];
- { const u32 x21 = in1[8];
- { const u32 x19 = in1[7];
- { const u32 x17 = in1[6];
- { const u32 x15 = in1[5];
- { const u32 x13 = in1[4];
- { const u32 x11 = in1[3];
- { const u32 x9 = in1[2];
- { const u32 x7 = in1[1];
- { const u32 x5 = in1[0];
- { const u32 x38 = in2[9];
- { const u32 x39 = in2[8];
- { const u32 x37 = in2[7];
- { const u32 x35 = in2[6];
- { const u32 x33 = in2[5];
- { const u32 x31 = in2[4];
- { const u32 x29 = in2[3];
- { const u32 x27 = in2[2];
- { const u32 x25 = in2[1];
- { const u32 x23 = in2[0];
- { u64 x40 = ((u64)x23 * x5);
- { u64 x41 = (((u64)x23 * x7) + ((u64)x25 * x5));
- { u64 x42 = ((((u64)(0x2 * x25) * x7) + ((u64)x23 * x9)) + ((u64)x27 * x5));
- { u64 x43 = (((((u64)x25 * x9) + ((u64)x27 * x7)) + ((u64)x23 * x11)) + ((u64)x29 * x5));
- { u64 x44 = (((((u64)x27 * x9) + (0x2 * (((u64)x25 * x11) + ((u64)x29 * x7)))) + ((u64)x23 * x13)) + ((u64)x31 * x5));
- { u64 x45 = (((((((u64)x27 * x11) + ((u64)x29 * x9)) + ((u64)x25 * x13)) + ((u64)x31 * x7)) + ((u64)x23 * x15)) + ((u64)x33 * x5));
- { u64 x46 = (((((0x2 * ((((u64)x29 * x11) + ((u64)x25 * x15)) + ((u64)x33 * x7))) + ((u64)x27 * x13)) + ((u64)x31 * x9)) + ((u64)x23 * x17)) + ((u64)x35 * x5));
- { u64 x47 = (((((((((u64)x29 * x13) + ((u64)x31 * x11)) + ((u64)x27 * x15)) + ((u64)x33 * x9)) + ((u64)x25 * x17)) + ((u64)x35 * x7)) + ((u64)x23 * x19)) + ((u64)x37 * x5));
- { u64 x48 = (((((((u64)x31 * x13) + (0x2 * (((((u64)x29 * x15) + ((u64)x33 * x11)) + ((u64)x25 * x19)) + ((u64)x37 * x7)))) + ((u64)x27 * x17)) + ((u64)x35 * x9)) + ((u64)x23 * x21)) + ((u64)x39 * x5));
- { u64 x49 = (((((((((((u64)x31 * x15) + ((u64)x33 * x13)) + ((u64)x29 * x17)) + ((u64)x35 * x11)) + ((u64)x27 * x19)) + ((u64)x37 * x9)) + ((u64)x25 * x21)) + ((u64)x39 * x7)) + ((u64)x23 * x20)) + ((u64)x38 * x5));
- { u64 x50 = (((((0x2 * ((((((u64)x33 * x15) + ((u64)x29 * x19)) + ((u64)x37 * x11)) + ((u64)x25 * x20)) + ((u64)x38 * x7))) + ((u64)x31 * x17)) + ((u64)x35 * x13)) + ((u64)x27 * x21)) + ((u64)x39 * x9));
- { u64 x51 = (((((((((u64)x33 * x17) + ((u64)x35 * x15)) + ((u64)x31 * x19)) + ((u64)x37 * x13)) + ((u64)x29 * x21)) + ((u64)x39 * x11)) + ((u64)x27 * x20)) + ((u64)x38 * x9));
- { u64 x52 = (((((u64)x35 * x17) + (0x2 * (((((u64)x33 * x19) + ((u64)x37 * x15)) + ((u64)x29 * x20)) + ((u64)x38 * x11)))) + ((u64)x31 * x21)) + ((u64)x39 * x13));
- { u64 x53 = (((((((u64)x35 * x19) + ((u64)x37 * x17)) + ((u64)x33 * x21)) + ((u64)x39 * x15)) + ((u64)x31 * x20)) + ((u64)x38 * x13));
- { u64 x54 = (((0x2 * ((((u64)x37 * x19) + ((u64)x33 * x20)) + ((u64)x38 * x15))) + ((u64)x35 * x21)) + ((u64)x39 * x17));
- { u64 x55 = (((((u64)x37 * x21) + ((u64)x39 * x19)) + ((u64)x35 * x20)) + ((u64)x38 * x17));
- { u64 x56 = (((u64)x39 * x21) + (0x2 * (((u64)x37 * x20) + ((u64)x38 * x19))));
- { u64 x57 = (((u64)x39 * x20) + ((u64)x38 * x21));
- { u64 x58 = ((u64)(0x2 * x38) * x20);
- { u64 x59 = (x48 + (x58 << 0x4));
- { u64 x60 = (x59 + (x58 << 0x1));
- { u64 x61 = (x60 + x58);
- { u64 x62 = (x47 + (x57 << 0x4));
- { u64 x63 = (x62 + (x57 << 0x1));
- { u64 x64 = (x63 + x57);
- { u64 x65 = (x46 + (x56 << 0x4));
- { u64 x66 = (x65 + (x56 << 0x1));
- { u64 x67 = (x66 + x56);
- { u64 x68 = (x45 + (x55 << 0x4));
- { u64 x69 = (x68 + (x55 << 0x1));
- { u64 x70 = (x69 + x55);
- { u64 x71 = (x44 + (x54 << 0x4));
- { u64 x72 = (x71 + (x54 << 0x1));
- { u64 x73 = (x72 + x54);
- { u64 x74 = (x43 + (x53 << 0x4));
- { u64 x75 = (x74 + (x53 << 0x1));
- { u64 x76 = (x75 + x53);
- { u64 x77 = (x42 + (x52 << 0x4));
- { u64 x78 = (x77 + (x52 << 0x1));
- { u64 x79 = (x78 + x52);
- { u64 x80 = (x41 + (x51 << 0x4));
- { u64 x81 = (x80 + (x51 << 0x1));
- { u64 x82 = (x81 + x51);
- { u64 x83 = (x40 + (x50 << 0x4));
- { u64 x84 = (x83 + (x50 << 0x1));
- { u64 x85 = (x84 + x50);
- { u64 x86 = (x85 >> 0x1a);
- { u32 x87 = ((u32)x85 & 0x3ffffff);
- { u64 x88 = (x86 + x82);
- { u64 x89 = (x88 >> 0x19);
- { u32 x90 = ((u32)x88 & 0x1ffffff);
- { u64 x91 = (x89 + x79);
- { u64 x92 = (x91 >> 0x1a);
- { u32 x93 = ((u32)x91 & 0x3ffffff);
- { u64 x94 = (x92 + x76);
- { u64 x95 = (x94 >> 0x19);
- { u32 x96 = ((u32)x94 & 0x1ffffff);
- { u64 x97 = (x95 + x73);
- { u64 x98 = (x97 >> 0x1a);
- { u32 x99 = ((u32)x97 & 0x3ffffff);
- { u64 x100 = (x98 + x70);
- { u64 x101 = (x100 >> 0x19);
- { u32 x102 = ((u32)x100 & 0x1ffffff);
- { u64 x103 = (x101 + x67);
- { u64 x104 = (x103 >> 0x1a);
- { u32 x105 = ((u32)x103 & 0x3ffffff);
- { u64 x106 = (x104 + x64);
- { u64 x107 = (x106 >> 0x19);
- { u32 x108 = ((u32)x106 & 0x1ffffff);
- { u64 x109 = (x107 + x61);
- { u64 x110 = (x109 >> 0x1a);
- { u32 x111 = ((u32)x109 & 0x3ffffff);
- { u64 x112 = (x110 + x49);
- { u64 x113 = (x112 >> 0x19);
- { u32 x114 = ((u32)x112 & 0x1ffffff);
- { u64 x115 = (x87 + (0x13 * x113));
- { u32 x116 = (u32) (x115 >> 0x1a);
- { u32 x117 = ((u32)x115 & 0x3ffffff);
- { u32 x118 = (x116 + x90);
- { u32 x119 = (x118 >> 0x19);
- { u32 x120 = (x118 & 0x1ffffff);
- out[0] = x117;
- out[1] = x120;
- out[2] = (x119 + x93);
- out[3] = x96;
- out[4] = x99;
- out[5] = x102;
- out[6] = x105;
- out[7] = x108;
- out[8] = x111;
- out[9] = x114;
- }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_mul_ttt(fe *h, const fe *f, const fe *g)
-{
- fe_mul_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g)
-{
- fe_mul_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_mul_tll(fe *h, const fe_loose *f, const fe_loose *g)
-{
- fe_mul_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_sqr_impl(u32 out[10], const u32 in1[10])
-{
- { const u32 x17 = in1[9];
- { const u32 x18 = in1[8];
- { const u32 x16 = in1[7];
- { const u32 x14 = in1[6];
- { const u32 x12 = in1[5];
- { const u32 x10 = in1[4];
- { const u32 x8 = in1[3];
- { const u32 x6 = in1[2];
- { const u32 x4 = in1[1];
- { const u32 x2 = in1[0];
- { u64 x19 = ((u64)x2 * x2);
- { u64 x20 = ((u64)(0x2 * x2) * x4);
- { u64 x21 = (0x2 * (((u64)x4 * x4) + ((u64)x2 * x6)));
- { u64 x22 = (0x2 * (((u64)x4 * x6) + ((u64)x2 * x8)));
- { u64 x23 = ((((u64)x6 * x6) + ((u64)(0x4 * x4) * x8)) + ((u64)(0x2 * x2) * x10));
- { u64 x24 = (0x2 * ((((u64)x6 * x8) + ((u64)x4 * x10)) + ((u64)x2 * x12)));
- { u64 x25 = (0x2 * (((((u64)x8 * x8) + ((u64)x6 * x10)) + ((u64)x2 * x14)) + ((u64)(0x2 * x4) * x12)));
- { u64 x26 = (0x2 * (((((u64)x8 * x10) + ((u64)x6 * x12)) + ((u64)x4 * x14)) + ((u64)x2 * x16)));
- { u64 x27 = (((u64)x10 * x10) + (0x2 * ((((u64)x6 * x14) + ((u64)x2 * x18)) + (0x2 * (((u64)x4 * x16) + ((u64)x8 * x12))))));
- { u64 x28 = (0x2 * ((((((u64)x10 * x12) + ((u64)x8 * x14)) + ((u64)x6 * x16)) + ((u64)x4 * x18)) + ((u64)x2 * x17)));
- { u64 x29 = (0x2 * (((((u64)x12 * x12) + ((u64)x10 * x14)) + ((u64)x6 * x18)) + (0x2 * (((u64)x8 * x16) + ((u64)x4 * x17)))));
- { u64 x30 = (0x2 * (((((u64)x12 * x14) + ((u64)x10 * x16)) + ((u64)x8 * x18)) + ((u64)x6 * x17)));
- { u64 x31 = (((u64)x14 * x14) + (0x2 * (((u64)x10 * x18) + (0x2 * (((u64)x12 * x16) + ((u64)x8 * x17))))));
- { u64 x32 = (0x2 * ((((u64)x14 * x16) + ((u64)x12 * x18)) + ((u64)x10 * x17)));
- { u64 x33 = (0x2 * ((((u64)x16 * x16) + ((u64)x14 * x18)) + ((u64)(0x2 * x12) * x17)));
- { u64 x34 = (0x2 * (((u64)x16 * x18) + ((u64)x14 * x17)));
- { u64 x35 = (((u64)x18 * x18) + ((u64)(0x4 * x16) * x17));
- { u64 x36 = ((u64)(0x2 * x18) * x17);
- { u64 x37 = ((u64)(0x2 * x17) * x17);
- { u64 x38 = (x27 + (x37 << 0x4));
- { u64 x39 = (x38 + (x37 << 0x1));
- { u64 x40 = (x39 + x37);
- { u64 x41 = (x26 + (x36 << 0x4));
- { u64 x42 = (x41 + (x36 << 0x1));
- { u64 x43 = (x42 + x36);
- { u64 x44 = (x25 + (x35 << 0x4));
- { u64 x45 = (x44 + (x35 << 0x1));
- { u64 x46 = (x45 + x35);
- { u64 x47 = (x24 + (x34 << 0x4));
- { u64 x48 = (x47 + (x34 << 0x1));
- { u64 x49 = (x48 + x34);
- { u64 x50 = (x23 + (x33 << 0x4));
- { u64 x51 = (x50 + (x33 << 0x1));
- { u64 x52 = (x51 + x33);
- { u64 x53 = (x22 + (x32 << 0x4));
- { u64 x54 = (x53 + (x32 << 0x1));
- { u64 x55 = (x54 + x32);
- { u64 x56 = (x21 + (x31 << 0x4));
- { u64 x57 = (x56 + (x31 << 0x1));
- { u64 x58 = (x57 + x31);
- { u64 x59 = (x20 + (x30 << 0x4));
- { u64 x60 = (x59 + (x30 << 0x1));
- { u64 x61 = (x60 + x30);
- { u64 x62 = (x19 + (x29 << 0x4));
- { u64 x63 = (x62 + (x29 << 0x1));
- { u64 x64 = (x63 + x29);
- { u64 x65 = (x64 >> 0x1a);
- { u32 x66 = ((u32)x64 & 0x3ffffff);
- { u64 x67 = (x65 + x61);
- { u64 x68 = (x67 >> 0x19);
- { u32 x69 = ((u32)x67 & 0x1ffffff);
- { u64 x70 = (x68 + x58);
- { u64 x71 = (x70 >> 0x1a);
- { u32 x72 = ((u32)x70 & 0x3ffffff);
- { u64 x73 = (x71 + x55);
- { u64 x74 = (x73 >> 0x19);
- { u32 x75 = ((u32)x73 & 0x1ffffff);
- { u64 x76 = (x74 + x52);
- { u64 x77 = (x76 >> 0x1a);
- { u32 x78 = ((u32)x76 & 0x3ffffff);
- { u64 x79 = (x77 + x49);
- { u64 x80 = (x79 >> 0x19);
- { u32 x81 = ((u32)x79 & 0x1ffffff);
- { u64 x82 = (x80 + x46);
- { u64 x83 = (x82 >> 0x1a);
- { u32 x84 = ((u32)x82 & 0x3ffffff);
- { u64 x85 = (x83 + x43);
- { u64 x86 = (x85 >> 0x19);
- { u32 x87 = ((u32)x85 & 0x1ffffff);
- { u64 x88 = (x86 + x40);
- { u64 x89 = (x88 >> 0x1a);
- { u32 x90 = ((u32)x88 & 0x3ffffff);
- { u64 x91 = (x89 + x28);
- { u64 x92 = (x91 >> 0x19);
- { u32 x93 = ((u32)x91 & 0x1ffffff);
- { u64 x94 = (x66 + (0x13 * x92));
- { u32 x95 = (u32) (x94 >> 0x1a);
- { u32 x96 = ((u32)x94 & 0x3ffffff);
- { u32 x97 = (x95 + x69);
- { u32 x98 = (x97 >> 0x19);
- { u32 x99 = (x97 & 0x1ffffff);
- out[0] = x96;
- out[1] = x99;
- out[2] = (x98 + x72);
- out[3] = x75;
- out[4] = x78;
- out[5] = x81;
- out[6] = x84;
- out[7] = x87;
- out[8] = x90;
- out[9] = x93;
- }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_sq_tl(fe *h, const fe_loose *f)
-{
- fe_sqr_impl(h->v, f->v);
-}
-
-static __always_inline void fe_sq_tt(fe *h, const fe *f)
-{
- fe_sqr_impl(h->v, f->v);
-}
-
-static __always_inline void fe_loose_invert(fe *out, const fe_loose *z)
-{
- fe t0;
- fe t1;
- fe t2;
- fe t3;
- int i;
-
- fe_sq_tl(&t0, z);
- fe_sq_tt(&t1, &t0);
- for (i = 1; i < 2; ++i)
- fe_sq_tt(&t1, &t1);
- fe_mul_tlt(&t1, z, &t1);
- fe_mul_ttt(&t0, &t0, &t1);
- fe_sq_tt(&t2, &t0);
- fe_mul_ttt(&t1, &t1, &t2);
- fe_sq_tt(&t2, &t1);
- for (i = 1; i < 5; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t1, &t2, &t1);
- fe_sq_tt(&t2, &t1);
- for (i = 1; i < 10; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t2, &t2, &t1);
- fe_sq_tt(&t3, &t2);
- for (i = 1; i < 20; ++i)
- fe_sq_tt(&t3, &t3);
- fe_mul_ttt(&t2, &t3, &t2);
- fe_sq_tt(&t2, &t2);
- for (i = 1; i < 10; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t1, &t2, &t1);
- fe_sq_tt(&t2, &t1);
- for (i = 1; i < 50; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t2, &t2, &t1);
- fe_sq_tt(&t3, &t2);
- for (i = 1; i < 100; ++i)
- fe_sq_tt(&t3, &t3);
- fe_mul_ttt(&t2, &t3, &t2);
- fe_sq_tt(&t2, &t2);
- for (i = 1; i < 50; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t1, &t2, &t1);
- fe_sq_tt(&t1, &t1);
- for (i = 1; i < 5; ++i)
- fe_sq_tt(&t1, &t1);
- fe_mul_ttt(out, &t1, &t0);
-}
-
-static __always_inline void fe_invert(fe *out, const fe *z)
-{
- fe_loose l;
- fe_copy_lt(&l, z);
- fe_loose_invert(out, &l);
-}
-
-/* Replace (f,g) with (g,f) if b == 1;
- * replace (f,g) with (f,g) if b == 0.
- *
- * Preconditions: b in {0,1}
- */
-static __always_inline void fe_cswap(fe *f, fe *g, unsigned int b)
-{
- unsigned i;
- b = 0-b;
- for (i = 0; i < 10; i++) {
- u32 x = f->v[i] ^ g->v[i];
- x &= b;
- f->v[i] ^= x;
- g->v[i] ^= x;
- }
-}
-
-/* NOTE: based on fiat-crypto fe_mul, edited for in2=121666, 0, 0.*/
-static __always_inline void fe_mul_121666_impl(u32 out[10], const u32 in1[10])
-{
- { const u32 x20 = in1[9];
- { const u32 x21 = in1[8];
- { const u32 x19 = in1[7];
- { const u32 x17 = in1[6];
- { const u32 x15 = in1[5];
- { const u32 x13 = in1[4];
- { const u32 x11 = in1[3];
- { const u32 x9 = in1[2];
- { const u32 x7 = in1[1];
- { const u32 x5 = in1[0];
- { const u32 x38 = 0;
- { const u32 x39 = 0;
- { const u32 x37 = 0;
- { const u32 x35 = 0;
- { const u32 x33 = 0;
- { const u32 x31 = 0;
- { const u32 x29 = 0;
- { const u32 x27 = 0;
- { const u32 x25 = 0;
- { const u32 x23 = 121666;
- { u64 x40 = ((u64)x23 * x5);
- { u64 x41 = (((u64)x23 * x7) + ((u64)x25 * x5));
- { u64 x42 = ((((u64)(0x2 * x25) * x7) + ((u64)x23 * x9)) + ((u64)x27 * x5));
- { u64 x43 = (((((u64)x25 * x9) + ((u64)x27 * x7)) + ((u64)x23 * x11)) + ((u64)x29 * x5));
- { u64 x44 = (((((u64)x27 * x9) + (0x2 * (((u64)x25 * x11) + ((u64)x29 * x7)))) + ((u64)x23 * x13)) + ((u64)x31 * x5));
- { u64 x45 = (((((((u64)x27 * x11) + ((u64)x29 * x9)) + ((u64)x25 * x13)) + ((u64)x31 * x7)) + ((u64)x23 * x15)) + ((u64)x33 * x5));
- { u64 x46 = (((((0x2 * ((((u64)x29 * x11) + ((u64)x25 * x15)) + ((u64)x33 * x7))) + ((u64)x27 * x13)) + ((u64)x31 * x9)) + ((u64)x23 * x17)) + ((u64)x35 * x5));
- { u64 x47 = (((((((((u64)x29 * x13) + ((u64)x31 * x11)) + ((u64)x27 * x15)) + ((u64)x33 * x9)) + ((u64)x25 * x17)) + ((u64)x35 * x7)) + ((u64)x23 * x19)) + ((u64)x37 * x5));
- { u64 x48 = (((((((u64)x31 * x13) + (0x2 * (((((u64)x29 * x15) + ((u64)x33 * x11)) + ((u64)x25 * x19)) + ((u64)x37 * x7)))) + ((u64)x27 * x17)) + ((u64)x35 * x9)) + ((u64)x23 * x21)) + ((u64)x39 * x5));
- { u64 x49 = (((((((((((u64)x31 * x15) + ((u64)x33 * x13)) + ((u64)x29 * x17)) + ((u64)x35 * x11)) + ((u64)x27 * x19)) + ((u64)x37 * x9)) + ((u64)x25 * x21)) + ((u64)x39 * x7)) + ((u64)x23 * x20)) + ((u64)x38 * x5));
- { u64 x50 = (((((0x2 * ((((((u64)x33 * x15) + ((u64)x29 * x19)) + ((u64)x37 * x11)) + ((u64)x25 * x20)) + ((u64)x38 * x7))) + ((u64)x31 * x17)) + ((u64)x35 * x13)) + ((u64)x27 * x21)) + ((u64)x39 * x9));
- { u64 x51 = (((((((((u64)x33 * x17) + ((u64)x35 * x15)) + ((u64)x31 * x19)) + ((u64)x37 * x13)) + ((u64)x29 * x21)) + ((u64)x39 * x11)) + ((u64)x27 * x20)) + ((u64)x38 * x9));
- { u64 x52 = (((((u64)x35 * x17) + (0x2 * (((((u64)x33 * x19) + ((u64)x37 * x15)) + ((u64)x29 * x20)) + ((u64)x38 * x11)))) + ((u64)x31 * x21)) + ((u64)x39 * x13));
- { u64 x53 = (((((((u64)x35 * x19) + ((u64)x37 * x17)) + ((u64)x33 * x21)) + ((u64)x39 * x15)) + ((u64)x31 * x20)) + ((u64)x38 * x13));
- { u64 x54 = (((0x2 * ((((u64)x37 * x19) + ((u64)x33 * x20)) + ((u64)x38 * x15))) + ((u64)x35 * x21)) + ((u64)x39 * x17));
- { u64 x55 = (((((u64)x37 * x21) + ((u64)x39 * x19)) + ((u64)x35 * x20)) + ((u64)x38 * x17));
- { u64 x56 = (((u64)x39 * x21) + (0x2 * (((u64)x37 * x20) + ((u64)x38 * x19))));
- { u64 x57 = (((u64)x39 * x20) + ((u64)x38 * x21));
- { u64 x58 = ((u64)(0x2 * x38) * x20);
- { u64 x59 = (x48 + (x58 << 0x4));
- { u64 x60 = (x59 + (x58 << 0x1));
- { u64 x61 = (x60 + x58);
- { u64 x62 = (x47 + (x57 << 0x4));
- { u64 x63 = (x62 + (x57 << 0x1));
- { u64 x64 = (x63 + x57);
- { u64 x65 = (x46 + (x56 << 0x4));
- { u64 x66 = (x65 + (x56 << 0x1));
- { u64 x67 = (x66 + x56);
- { u64 x68 = (x45 + (x55 << 0x4));
- { u64 x69 = (x68 + (x55 << 0x1));
- { u64 x70 = (x69 + x55);
- { u64 x71 = (x44 + (x54 << 0x4));
- { u64 x72 = (x71 + (x54 << 0x1));
- { u64 x73 = (x72 + x54);
- { u64 x74 = (x43 + (x53 << 0x4));
- { u64 x75 = (x74 + (x53 << 0x1));
- { u64 x76 = (x75 + x53);
- { u64 x77 = (x42 + (x52 << 0x4));
- { u64 x78 = (x77 + (x52 << 0x1));
- { u64 x79 = (x78 + x52);
- { u64 x80 = (x41 + (x51 << 0x4));
- { u64 x81 = (x80 + (x51 << 0x1));
- { u64 x82 = (x81 + x51);
- { u64 x83 = (x40 + (x50 << 0x4));
- { u64 x84 = (x83 + (x50 << 0x1));
- { u64 x85 = (x84 + x50);
- { u64 x86 = (x85 >> 0x1a);
- { u32 x87 = ((u32)x85 & 0x3ffffff);
- { u64 x88 = (x86 + x82);
- { u64 x89 = (x88 >> 0x19);
- { u32 x90 = ((u32)x88 & 0x1ffffff);
- { u64 x91 = (x89 + x79);
- { u64 x92 = (x91 >> 0x1a);
- { u32 x93 = ((u32)x91 & 0x3ffffff);
- { u64 x94 = (x92 + x76);
- { u64 x95 = (x94 >> 0x19);
- { u32 x96 = ((u32)x94 & 0x1ffffff);
- { u64 x97 = (x95 + x73);
- { u64 x98 = (x97 >> 0x1a);
- { u32 x99 = ((u32)x97 & 0x3ffffff);
- { u64 x100 = (x98 + x70);
- { u64 x101 = (x100 >> 0x19);
- { u32 x102 = ((u32)x100 & 0x1ffffff);
- { u64 x103 = (x101 + x67);
- { u64 x104 = (x103 >> 0x1a);
- { u32 x105 = ((u32)x103 & 0x3ffffff);
- { u64 x106 = (x104 + x64);
- { u64 x107 = (x106 >> 0x19);
- { u32 x108 = ((u32)x106 & 0x1ffffff);
- { u64 x109 = (x107 + x61);
- { u64 x110 = (x109 >> 0x1a);
- { u32 x111 = ((u32)x109 & 0x3ffffff);
- { u64 x112 = (x110 + x49);
- { u64 x113 = (x112 >> 0x19);
- { u32 x114 = ((u32)x112 & 0x1ffffff);
- { u64 x115 = (x87 + (0x13 * x113));
- { u32 x116 = (u32) (x115 >> 0x1a);
- { u32 x117 = ((u32)x115 & 0x3ffffff);
- { u32 x118 = (x116 + x90);
- { u32 x119 = (x118 >> 0x19);
- { u32 x120 = (x118 & 0x1ffffff);
- out[0] = x117;
- out[1] = x120;
- out[2] = (x119 + x93);
- out[3] = x96;
- out[4] = x99;
- out[5] = x102;
- out[6] = x105;
- out[7] = x108;
- out[8] = x111;
- out[9] = x114;
- }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_mul121666(fe *h, const fe_loose *f)
-{
- fe_mul_121666_impl(h->v, f->v);
-}
-
-bool curve25519_fiat32(u8 out[CURVE25519_POINT_SIZE], const u8 scalar[CURVE25519_POINT_SIZE], const u8 point[CURVE25519_POINT_SIZE])
-{
- fe x1, x2, z2, x3, z3, tmp0, tmp1;
- fe_loose x2l, z2l, x3l, tmp0l, tmp1l;
- unsigned swap = 0;
- int pos;
- u8 e[32];
-
- memcpy(e, scalar, 32);
- normalize_secret(e);
-
- /* The following implementation was transcribed to Coq and proven to
- * correspond to unary scalar multiplication in affine coordinates given that
- * x1 != 0 is the x coordinate of some point on the curve. It was also checked
- * in Coq that doing a ladderstep with x1 = x3 = 0 gives z2' = z3' = 0, and z2
- * = z3 = 0 gives z2' = z3' = 0. The statement was quantified over the
- * underlying field, so it applies to Curve25519 itself and the quadratic
- * twist of Curve25519. It was not proven in Coq that prime-field arithmetic
- * correctly simulates extension-field arithmetic on prime-field values.
- * The decoding of the byte array representation of e was not considered.
- * Specification of Montgomery curves in affine coordinates:
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Spec/MontgomeryCurve.v#L27>
- * Proof that these form a group that is isomorphic to a Weierstrass curve:
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/AffineProofs.v#L35>
- * Coq transcription and correctness proof of the loop (where scalarbits=255):
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZ.v#L118>
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L278>
- * preconditions: 0 <= e < 2^255 (not necessarily e < order), fe_invert(0) = 0
- */
- fe_frombytes(&x1, point);
- fe_1(&x2);
- fe_0(&z2);
- fe_copy(&x3, &x1);
- fe_1(&z3);
-
- for (pos = 254; pos >= 0; --pos) {
- /* loop invariant as of right before the test, for the case where x1 != 0:
- * pos >= -1; if z2 = 0 then x2 is nonzero; if z3 = 0 then x3 is nonzero
- * let r := e >> (pos+1) in the following equalities of projective points:
- * to_xz (r*P) === if swap then (x3, z3) else (x2, z2)
- * to_xz ((r+1)*P) === if swap then (x2, z2) else (x3, z3)
- * x1 is the nonzero x coordinate of the nonzero point (r*P-(r+1)*P)
- */
- unsigned b = 1 & (e[pos / 8] >> (pos & 7));
- swap ^= b;
- fe_cswap(&x2, &x3, swap);
- fe_cswap(&z2, &z3, swap);
- swap = b;
- /* Coq transcription of ladderstep formula (called from transcribed loop):
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZ.v#L89>
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L131>
- * x1 != 0 <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L217>
- * x1 = 0 <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L147>
- */
- fe_sub(&tmp0l, &x3, &z3);
- fe_sub(&tmp1l, &x2, &z2);
- fe_add(&x2l, &x2, &z2);
- fe_add(&z2l, &x3, &z3);
- fe_mul_tll(&z3, &tmp0l, &x2l);
- fe_mul_tll(&z2, &z2l, &tmp1l);
- fe_sq_tl(&tmp0, &tmp1l);
- fe_sq_tl(&tmp1, &x2l);
- fe_add(&x3l, &z3, &z2);
- fe_sub(&z2l, &z3, &z2);
- fe_mul_ttt(&x2, &tmp1, &tmp0);
- fe_sub(&tmp1l, &tmp1, &tmp0);
- fe_sq_tl(&z2, &z2l);
- fe_mul121666(&z3, &tmp1l);
- fe_sq_tl(&x3, &x3l);
- fe_add(&tmp0l, &tmp0, &z3);
- fe_mul_ttt(&z3, &x1, &z2);
- fe_mul_tll(&z2, &tmp1l, &tmp0l);
- }
- /* here pos=-1, so r=e, so to_xz (e*P) === if swap then (x3, z3) else (x2, z2) */
- fe_cswap(&x2, &x3, swap);
- fe_cswap(&z2, &z3, swap);
-
- fe_invert(&z2, &z2);
- fe_mul_ttt(&x2, &x2, &z2);
- fe_tobytes(out, &x2);
-
- return true;
-}
diff --git a/curve25519-fiat64.c b/curve25519-fiat64.c
deleted file mode 100644
index ed8119f..0000000
--- a/curve25519-fiat64.c
+++ /dev/null
@@ -1,577 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2015-2016 The fiat-crypto Authors.
- * Copyright (C) 2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * This is a machine-generated formally verified implementation of curve25519 DH from:
- * https://github.com/mit-plv/fiat-crypto
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-typedef __uint128_t u128;
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-/* fe means field element. Here the field is \Z/(2^255-19). An element t,
- * entries t[0]...t[4], represents the integer t[0]+2^51 t[1]+2^102 t[2]+2^153
- * t[3]+2^204 t[4].
- * fe limbs are bounded by 1.125*2^51.
- * Multiplication and carrying produce fe from fe_loose.
- */
-typedef struct fe { u64 v[5]; } fe;
-
-/* fe_loose limbs are bounded by 3.375*2^51.
- * Addition and subtraction produce fe_loose from (fe, fe).
- */
-typedef struct fe_loose { u64 v[5]; } fe_loose;
-
-static __always_inline void fe_frombytes_impl(u64 h[5], const u8 *s)
-{
- // Ignores top bit of s.
- u64 a0 = le64_to_cpup((__force __le64 *)(s));
- u64 a1 = le64_to_cpup((__force __le64 *)(s+8));
- u64 a2 = le64_to_cpup((__force __le64 *)(s+16));
- u64 a3 = le64_to_cpup((__force __le64 *)(s+24));
- // Use 51 bits, 64-51 = 13 left.
- h[0] = a0 & ((1ULL << 51) - 1);
- // (64-51) + 38 = 13 + 38 = 51
- h[1] = (a0 >> 51) | ((a1 & ((1ULL << 38) - 1)) << 13);
- // (64-38) + 25 = 26 + 25 = 51
- h[2] = (a1 >> 38) | ((a2 & ((1ULL << 25) - 1)) << 26);
- // (64-25) + 12 = 39 + 12 = 51
- h[3] = (a2 >> 25) | ((a3 & ((1ULL << 12) - 1)) << 39);
- // (64-12) = 52, ignore top bit
- h[4] = (a3 >> 12) & ((1ULL << 51) - 1);
-}
-
-static __always_inline void fe_frombytes(fe *h, const u8 *s)
-{
- fe_frombytes_impl(h->v, s);
-}
-
-static __always_inline u8 /*bool*/ addcarryx_u51(u8 /*bool*/ c, u64 a, u64 b, u64 *low)
-{
- /* This function extracts 51 bits of result and 1 bit of carry (52 total), so
- *a 64-bit intermediate is sufficient.
- */
- u64 x = a + b + c;
- *low = x & ((1ULL << 51) - 1);
- return (x >> 51) & 1;
-}
-
-static __always_inline u8 /*bool*/ subborrow_u51(u8 /*bool*/ c, u64 a, u64 b, u64 *low)
-{
- /* This function extracts 51 bits of result and 1 bit of borrow (52 total), so
- * a 64-bit intermediate is sufficient.
- */
- u64 x = a - b - c;
- *low = x & ((1ULL << 51) - 1);
- return x >> 63;
-}
-
-static __always_inline u64 cmovznz64(u64 t, u64 z, u64 nz)
-{
- /* all set if nonzero, 0 if 0 */
- t = -!!t;
- return (t&nz) | ((~t)&z);
-}
-
-static __always_inline void fe_freeze(u64 out[5], const u64 in1[5])
-{
- { const u64 x7 = in1[4];
- { const u64 x8 = in1[3];
- { const u64 x6 = in1[2];
- { const u64 x4 = in1[1];
- { const u64 x2 = in1[0];
- { u64 x10; u8/*bool*/ x11 = subborrow_u51(0x0, x2, 0x7ffffffffffed, &x10);
- { u64 x13; u8/*bool*/ x14 = subborrow_u51(x11, x4, 0x7ffffffffffff, &x13);
- { u64 x16; u8/*bool*/ x17 = subborrow_u51(x14, x6, 0x7ffffffffffff, &x16);
- { u64 x19; u8/*bool*/ x20 = subborrow_u51(x17, x8, 0x7ffffffffffff, &x19);
- { u64 x22; u8/*bool*/ x23 = subborrow_u51(x20, x7, 0x7ffffffffffff, &x22);
- { u64 x24 = cmovznz64(x23, 0x0, 0xffffffffffffffffL);
- { u64 x25 = (x24 & 0x7ffffffffffed);
- { u64 x27; u8/*bool*/ x28 = addcarryx_u51(0x0, x10, x25, &x27);
- { u64 x29 = (x24 & 0x7ffffffffffff);
- { u64 x31; u8/*bool*/ x32 = addcarryx_u51(x28, x13, x29, &x31);
- { u64 x33 = (x24 & 0x7ffffffffffff);
- { u64 x35; u8/*bool*/ x36 = addcarryx_u51(x32, x16, x33, &x35);
- { u64 x37 = (x24 & 0x7ffffffffffff);
- { u64 x39; u8/*bool*/ x40 = addcarryx_u51(x36, x19, x37, &x39);
- { u64 x41 = (x24 & 0x7ffffffffffff);
- { u64 x43; addcarryx_u51(x40, x22, x41, &x43);
- out[0] = x27;
- out[1] = x31;
- out[2] = x35;
- out[3] = x39;
- out[4] = x43;
- }}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_tobytes(u8 s[32], const fe *f)
-{
- u64 h[5];
- fe_freeze(h, f->v);
-
- s[0] = h[0] >> 0;
- s[1] = h[0] >> 8;
- s[2] = h[0] >> 16;
- s[3] = h[0] >> 24;
- s[4] = h[0] >> 32;
- s[5] = h[0] >> 40;
- s[6] = (h[0] >> 48) | (h[1] << 3);
- s[7] = h[1] >> 5;
- s[8] = h[1] >> 13;
- s[9] = h[1] >> 21;
- s[10] = h[1] >> 29;
- s[11] = h[1] >> 37;
- s[12] = (h[1] >> 45) | (h[2] << 6);
- s[13] = h[2] >> 2;
- s[14] = h[2] >> 10;
- s[15] = h[2] >> 18;
- s[16] = h[2] >> 26;
- s[17] = h[2] >> 34;
- s[18] = h[2] >> 42;
- s[19] = (h[2] >> 50) | (h[3] << 1);
- s[20] = h[3] >> 7;
- s[21] = h[3] >> 15;
- s[22] = h[3] >> 23;
- s[23] = h[3] >> 31;
- s[24] = h[3] >> 39;
- s[25] = (h[3] >> 47) | (h[4] << 4);
- s[26] = h[4] >> 4;
- s[27] = h[4] >> 12;
- s[28] = h[4] >> 20;
- s[29] = h[4] >> 28;
- s[30] = h[4] >> 36;
- s[31] = h[4] >> 44;
-}
-
-/* h = f */
-static __always_inline void fe_copy(fe *h, const fe *f)
-{
- memmove(h, f, sizeof(fe));
-}
-
-static __always_inline void fe_copy_lt(fe_loose *h, const fe *f)
-{
- memmove(h, f, sizeof(fe));
-}
-
-/* h = 0 */
-static __always_inline void fe_0(fe *h)
-{
- memset(h, 0, sizeof(fe));
-}
-
-/* h = 1 */
-static __always_inline void fe_1(fe *h)
-{
- memset(h, 0, sizeof(fe));
- h->v[0] = 1;
-}
-
-static __always_inline void fe_add_impl(u64 out[5], const u64 in1[5], const u64 in2[5])
-{
- { const u64 x10 = in1[4];
- { const u64 x11 = in1[3];
- { const u64 x9 = in1[2];
- { const u64 x7 = in1[1];
- { const u64 x5 = in1[0];
- { const u64 x18 = in2[4];
- { const u64 x19 = in2[3];
- { const u64 x17 = in2[2];
- { const u64 x15 = in2[1];
- { const u64 x13 = in2[0];
- out[0] = (x5 + x13);
- out[1] = (x7 + x15);
- out[2] = (x9 + x17);
- out[3] = (x11 + x19);
- out[4] = (x10 + x18);
- }}}}}}}}}}
-}
-
-/* h = f + g
- * Can overlap h with f or g.
- */
-static __always_inline void fe_add(fe_loose *h, const fe *f, const fe *g)
-{
- fe_add_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_sub_impl(u64 out[5], const u64 in1[5], const u64 in2[5])
-{
- { const u64 x10 = in1[4];
- { const u64 x11 = in1[3];
- { const u64 x9 = in1[2];
- { const u64 x7 = in1[1];
- { const u64 x5 = in1[0];
- { const u64 x18 = in2[4];
- { const u64 x19 = in2[3];
- { const u64 x17 = in2[2];
- { const u64 x15 = in2[1];
- { const u64 x13 = in2[0];
- out[0] = ((0xfffffffffffda + x5) - x13);
- out[1] = ((0xffffffffffffe + x7) - x15);
- out[2] = ((0xffffffffffffe + x9) - x17);
- out[3] = ((0xffffffffffffe + x11) - x19);
- out[4] = ((0xffffffffffffe + x10) - x18);
- }}}}}}}}}}
-}
-
-/* h = f - g
- * Can overlap h with f or g.
- */
-static __always_inline void fe_sub(fe_loose *h, const fe *f, const fe *g)
-{
- fe_sub_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_mul_impl(u64 out[5], const u64 in1[5], const u64 in2[5])
-{
- { const u64 x10 = in1[4];
- { const u64 x11 = in1[3];
- { const u64 x9 = in1[2];
- { const u64 x7 = in1[1];
- { const u64 x5 = in1[0];
- { const u64 x18 = in2[4];
- { const u64 x19 = in2[3];
- { const u64 x17 = in2[2];
- { const u64 x15 = in2[1];
- { const u64 x13 = in2[0];
- { u128 x20 = ((u128)x5 * x13);
- { u128 x21 = (((u128)x5 * x15) + ((u128)x7 * x13));
- { u128 x22 = ((((u128)x5 * x17) + ((u128)x9 * x13)) + ((u128)x7 * x15));
- { u128 x23 = (((((u128)x5 * x19) + ((u128)x11 * x13)) + ((u128)x7 * x17)) + ((u128)x9 * x15));
- { u128 x24 = ((((((u128)x5 * x18) + ((u128)x10 * x13)) + ((u128)x11 * x15)) + ((u128)x7 * x19)) + ((u128)x9 * x17));
- { u64 x25 = (x10 * 0x13);
- { u64 x26 = (x7 * 0x13);
- { u64 x27 = (x9 * 0x13);
- { u64 x28 = (x11 * 0x13);
- { u128 x29 = ((((x20 + ((u128)x25 * x15)) + ((u128)x26 * x18)) + ((u128)x27 * x19)) + ((u128)x28 * x17));
- { u128 x30 = (((x21 + ((u128)x25 * x17)) + ((u128)x27 * x18)) + ((u128)x28 * x19));
- { u128 x31 = ((x22 + ((u128)x25 * x19)) + ((u128)x28 * x18));
- { u128 x32 = (x23 + ((u128)x25 * x18));
- { u64 x33 = (u64) (x29 >> 0x33);
- { u64 x34 = ((u64)x29 & 0x7ffffffffffff);
- { u128 x35 = (x33 + x30);
- { u64 x36 = (u64) (x35 >> 0x33);
- { u64 x37 = ((u64)x35 & 0x7ffffffffffff);
- { u128 x38 = (x36 + x31);
- { u64 x39 = (u64) (x38 >> 0x33);
- { u64 x40 = ((u64)x38 & 0x7ffffffffffff);
- { u128 x41 = (x39 + x32);
- { u64 x42 = (u64) (x41 >> 0x33);
- { u64 x43 = ((u64)x41 & 0x7ffffffffffff);
- { u128 x44 = (x42 + x24);
- { u64 x45 = (u64) (x44 >> 0x33);
- { u64 x46 = ((u64)x44 & 0x7ffffffffffff);
- { u64 x47 = (x34 + (0x13 * x45));
- { u64 x48 = (x47 >> 0x33);
- { u64 x49 = (x47 & 0x7ffffffffffff);
- { u64 x50 = (x48 + x37);
- { u64 x51 = (x50 >> 0x33);
- { u64 x52 = (x50 & 0x7ffffffffffff);
- out[0] = x49;
- out[1] = x52;
- out[2] = (x51 + x40);
- out[3] = x43;
- out[4] = x46;
- }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_mul_ttt(fe *h, const fe *f, const fe *g)
-{
- fe_mul_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_mul_tlt(fe *h, const fe_loose *f, const fe *g)
-{
- fe_mul_impl(h->v, f->v, g->v);
-}
-
-static __always_inline void fe_mul_tll(fe *h, const fe_loose *f, const fe_loose *g)
-{
- fe_mul_impl(h->v, f->v, g->v);
-}
-
-
-static __always_inline void fe_sqr_impl(u64 out[5], const u64 in1[5])
-{
- { const u64 x7 = in1[4];
- { const u64 x8 = in1[3];
- { const u64 x6 = in1[2];
- { const u64 x4 = in1[1];
- { const u64 x2 = in1[0];
- { u64 x9 = (x2 * 0x2);
- { u64 x10 = (x4 * 0x2);
- { u64 x11 = ((x6 * 0x2) * 0x13);
- { u64 x12 = (x7 * 0x13);
- { u64 x13 = (x12 * 0x2);
- { u128 x14 = ((((u128)x2 * x2) + ((u128)x13 * x4)) + ((u128)x11 * x8));
- { u128 x15 = ((((u128)x9 * x4) + ((u128)x13 * x6)) + ((u128)x8 * (x8 * 0x13)));
- { u128 x16 = ((((u128)x9 * x6) + ((u128)x4 * x4)) + ((u128)x13 * x8));
- { u128 x17 = ((((u128)x9 * x8) + ((u128)x10 * x6)) + ((u128)x7 * x12));
- { u128 x18 = ((((u128)x9 * x7) + ((u128)x10 * x8)) + ((u128)x6 * x6));
- { u64 x19 = (u64) (x14 >> 0x33);
- { u64 x20 = ((u64)x14 & 0x7ffffffffffff);
- { u128 x21 = (x19 + x15);
- { u64 x22 = (u64) (x21 >> 0x33);
- { u64 x23 = ((u64)x21 & 0x7ffffffffffff);
- { u128 x24 = (x22 + x16);
- { u64 x25 = (u64) (x24 >> 0x33);
- { u64 x26 = ((u64)x24 & 0x7ffffffffffff);
- { u128 x27 = (x25 + x17);
- { u64 x28 = (u64) (x27 >> 0x33);
- { u64 x29 = ((u64)x27 & 0x7ffffffffffff);
- { u128 x30 = (x28 + x18);
- { u64 x31 = (u64) (x30 >> 0x33);
- { u64 x32 = ((u64)x30 & 0x7ffffffffffff);
- { u64 x33 = (x20 + (0x13 * x31));
- { u64 x34 = (x33 >> 0x33);
- { u64 x35 = (x33 & 0x7ffffffffffff);
- { u64 x36 = (x34 + x23);
- { u64 x37 = (x36 >> 0x33);
- { u64 x38 = (x36 & 0x7ffffffffffff);
- out[0] = x35;
- out[1] = x38;
- out[2] = (x37 + x26);
- out[3] = x29;
- out[4] = x32;
- }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_sq_tl(fe *h, const fe_loose *f)
-{
- fe_sqr_impl(h->v, f->v);
-}
-
-static __always_inline void fe_sq_tt(fe *h, const fe *f)
-{
- fe_sqr_impl(h->v, f->v);
-}
-
-static __always_inline void fe_loose_invert(fe *out, const fe_loose *z)
-{
- fe t0;
- fe t1;
- fe t2;
- fe t3;
- int i;
-
- fe_sq_tl(&t0, z);
- fe_sq_tt(&t1, &t0);
- for (i = 1; i < 2; ++i)
- fe_sq_tt(&t1, &t1);
- fe_mul_tlt(&t1, z, &t1);
- fe_mul_ttt(&t0, &t0, &t1);
- fe_sq_tt(&t2, &t0);
- fe_mul_ttt(&t1, &t1, &t2);
- fe_sq_tt(&t2, &t1);
- for (i = 1; i < 5; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t1, &t2, &t1);
- fe_sq_tt(&t2, &t1);
- for (i = 1; i < 10; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t2, &t2, &t1);
- fe_sq_tt(&t3, &t2);
- for (i = 1; i < 20; ++i)
- fe_sq_tt(&t3, &t3);
- fe_mul_ttt(&t2, &t3, &t2);
- fe_sq_tt(&t2, &t2);
- for (i = 1; i < 10; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t1, &t2, &t1);
- fe_sq_tt(&t2, &t1);
- for (i = 1; i < 50; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t2, &t2, &t1);
- fe_sq_tt(&t3, &t2);
- for (i = 1; i < 100; ++i)
- fe_sq_tt(&t3, &t3);
- fe_mul_ttt(&t2, &t3, &t2);
- fe_sq_tt(&t2, &t2);
- for (i = 1; i < 50; ++i)
- fe_sq_tt(&t2, &t2);
- fe_mul_ttt(&t1, &t2, &t1);
- fe_sq_tt(&t1, &t1);
- for (i = 1; i < 5; ++i)
- fe_sq_tt(&t1, &t1);
- fe_mul_ttt(out, &t1, &t0);
-}
-
-static __always_inline void fe_invert(fe *out, const fe *z)
-{
- fe_loose l;
- fe_copy_lt(&l, z);
- fe_loose_invert(out, &l);
-}
-
-/* Replace (f,g) with (g,f) if b == 1;
- * replace (f,g) with (f,g) if b == 0.
- *
- * Preconditions: b in {0,1}
- */
-static __always_inline void fe_cswap(fe *f, fe *g, u64 b)
-{
- unsigned i;
- b = 0-b;
- for (i = 0; i < 5; i++) {
- u64 x = f->v[i] ^ g->v[i];
- x &= b;
- f->v[i] ^= x;
- g->v[i] ^= x;
- }
-}
-
-/* NOTE: based on fiat-crypto fe_mul, edited for in2=121666, 0, 0.*/
-static __always_inline void fe_mul_121666_impl(u64 out[5], const u64 in1[5])
-{
- { const u64 x10 = in1[4];
- { const u64 x11 = in1[3];
- { const u64 x9 = in1[2];
- { const u64 x7 = in1[1];
- { const u64 x5 = in1[0];
- { const u64 x18 = 0;
- { const u64 x19 = 0;
- { const u64 x17 = 0;
- { const u64 x15 = 0;
- { const u64 x13 = 121666;
- { u128 x20 = ((u128)x5 * x13);
- { u128 x21 = (((u128)x5 * x15) + ((u128)x7 * x13));
- { u128 x22 = ((((u128)x5 * x17) + ((u128)x9 * x13)) + ((u128)x7 * x15));
- { u128 x23 = (((((u128)x5 * x19) + ((u128)x11 * x13)) + ((u128)x7 * x17)) + ((u128)x9 * x15));
- { u128 x24 = ((((((u128)x5 * x18) + ((u128)x10 * x13)) + ((u128)x11 * x15)) + ((u128)x7 * x19)) + ((u128)x9 * x17));
- { u64 x25 = (x10 * 0x13);
- { u64 x26 = (x7 * 0x13);
- { u64 x27 = (x9 * 0x13);
- { u64 x28 = (x11 * 0x13);
- { u128 x29 = ((((x20 + ((u128)x25 * x15)) + ((u128)x26 * x18)) + ((u128)x27 * x19)) + ((u128)x28 * x17));
- { u128 x30 = (((x21 + ((u128)x25 * x17)) + ((u128)x27 * x18)) + ((u128)x28 * x19));
- { u128 x31 = ((x22 + ((u128)x25 * x19)) + ((u128)x28 * x18));
- { u128 x32 = (x23 + ((u128)x25 * x18));
- { u64 x33 = (u64) (x29 >> 0x33);
- { u64 x34 = ((u64)x29 & 0x7ffffffffffff);
- { u128 x35 = (x33 + x30);
- { u64 x36 = (u64) (x35 >> 0x33);
- { u64 x37 = ((u64)x35 & 0x7ffffffffffff);
- { u128 x38 = (x36 + x31);
- { u64 x39 = (u64) (x38 >> 0x33);
- { u64 x40 = ((u64)x38 & 0x7ffffffffffff);
- { u128 x41 = (x39 + x32);
- { u64 x42 = (u64) (x41 >> 0x33);
- { u64 x43 = ((u64)x41 & 0x7ffffffffffff);
- { u128 x44 = (x42 + x24);
- { u64 x45 = (u64) (x44 >> 0x33);
- { u64 x46 = ((u64)x44 & 0x7ffffffffffff);
- { u64 x47 = (x34 + (0x13 * x45));
- { u64 x48 = (x47 >> 0x33);
- { u64 x49 = (x47 & 0x7ffffffffffff);
- { u64 x50 = (x48 + x37);
- { u64 x51 = (x50 >> 0x33);
- { u64 x52 = (x50 & 0x7ffffffffffff);
- out[0] = x49;
- out[1] = x52;
- out[2] = (x51 + x40);
- out[3] = x43;
- out[4] = x46;
- }}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}}
-}
-
-static __always_inline void fe_mul121666(fe *h, const fe_loose *f)
-{
- fe_mul_121666_impl(h->v, f->v);
-}
-
-bool curve25519_fiat64(u8 out[CURVE25519_POINT_SIZE], const u8 scalar[CURVE25519_POINT_SIZE], const u8 point[CURVE25519_POINT_SIZE])
-{
- fe x1, x2, z2, x3, z3, tmp0, tmp1;
- fe_loose x2l, z2l, x3l, tmp0l, tmp1l;
- unsigned swap = 0;
- int pos;
- u8 e[32];
-
- memcpy(e, scalar, 32);
- normalize_secret(e);
-
- /* The following implementation was transcribed to Coq and proven to
- * correspond to unary scalar multiplication in affine coordinates given that
- * x1 != 0 is the x coordinate of some point on the curve. It was also checked
- * in Coq that doing a ladderstep with x1 = x3 = 0 gives z2' = z3' = 0, and z2
- * = z3 = 0 gives z2' = z3' = 0. The statement was quantified over the
- * underlying field, so it applies to Curve25519 itself and the quadratic
- * twist of Curve25519. It was not proven in Coq that prime-field arithmetic
- * correctly simulates extension-field arithmetic on prime-field values.
- * The decoding of the byte array representation of e was not considered.
- * Specification of Montgomery curves in affine coordinates:
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Spec/MontgomeryCurve.v#L27>
- * Proof that these form a group that is isomorphic to a Weierstrass curve:
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/AffineProofs.v#L35>
- * Coq transcription and correctness proof of the loop (where scalarbits=255):
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZ.v#L118>
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L278>
- * preconditions: 0 <= e < 2^255 (not necessarily e < order), fe_invert(0) = 0
- */
- fe_frombytes(&x1, point);
- fe_1(&x2);
- fe_0(&z2);
- fe_copy(&x3, &x1);
- fe_1(&z3);
-
- for (pos = 254; pos >= 0; --pos) {
- /* loop invariant as of right before the test, for the case where x1 != 0:
- * pos >= -1; if z2 = 0 then x2 is nonzero; if z3 = 0 then x3 is nonzero
- * let r := e >> (pos+1) in the following equalities of projective points:
- * to_xz (r*P) === if swap then (x3, z3) else (x2, z2)
- * to_xz ((r+1)*P) === if swap then (x2, z2) else (x3, z3)
- * x1 is the nonzero x coordinate of the nonzero point (r*P-(r+1)*P)
- */
- unsigned b = 1 & (e[pos / 8] >> (pos & 7));
- swap ^= b;
- fe_cswap(&x2, &x3, swap);
- fe_cswap(&z2, &z3, swap);
- swap = b;
- /* Coq transcription of ladderstep formula (called from transcribed loop):
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZ.v#L89>
- * <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L131>
- * x1 != 0 <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L217>
- * x1 = 0 <https://github.com/mit-plv/fiat-crypto/blob/2456d821825521f7e03e65882cc3521795b0320f/src/Curves/Montgomery/XZProofs.v#L147>
- */
- fe_sub(&tmp0l, &x3, &z3);
- fe_sub(&tmp1l, &x2, &z2);
- fe_add(&x2l, &x2, &z2);
- fe_add(&z2l, &x3, &z3);
- fe_mul_tll(&z3, &tmp0l, &x2l);
- fe_mul_tll(&z2, &z2l, &tmp1l);
- fe_sq_tl(&tmp0, &tmp1l);
- fe_sq_tl(&tmp1, &x2l);
- fe_add(&x3l, &z3, &z2);
- fe_sub(&z2l, &z3, &z2);
- fe_mul_ttt(&x2, &tmp1, &tmp0);
- fe_sub(&tmp1l, &tmp1, &tmp0);
- fe_sq_tl(&z2, &z2l);
- fe_mul121666(&z3, &tmp1l);
- fe_sq_tl(&x3, &x3l);
- fe_add(&tmp0l, &tmp0, &z3);
- fe_mul_ttt(&z3, &x1, &z2);
- fe_mul_tll(&z2, &tmp1l, &tmp0l);
- }
- /* here pos=-1, so r=e, so to_xz (e*P) === if swap then (x3, z3) else (x2, z2) */
- fe_cswap(&x2, &x3, swap);
- fe_cswap(&z2, &z3, swap);
-
- fe_invert(&z2, &z2);
- fe_mul_ttt(&x2, &x2, &z2);
- fe_tobytes(out, &x2);
-
- return true;
-}
diff --git a/curve25519-hacl64.c b/curve25519-hacl64.c
deleted file mode 100644
index 2f1ba14..0000000
--- a/curve25519-hacl64.c
+++ /dev/null
@@ -1,763 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2016-2017 INRIA and Microsoft Corporation.
- * Copyright (C) 2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * This is a machine-generated formally verified implementation of curve25519 DH from:
- * https://github.com/mitls/hacl-star
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-typedef __uint128_t u128;
-
-static __always_inline u64 u64_eq_mask(u64 x, u64 y)
-{
- x = ~(x ^ y);
- x &= x << 32;
- x &= x << 16;
- x &= x << 8;
- x &= x << 4;
- x &= x << 2;
- x &= x << 1;
- return ((s64)x) >> 63;
-}
-
-static __always_inline u64 u64_gte_mask(u64 x, u64 y)
-{
- u64 low63 = ~((u64)((s64)((s64)(x & 0x7fffffffffffffffLLU) - (s64)(y & 0x7fffffffffffffffLLU)) >> 63));
- u64 high_bit = ~((u64)((s64)((s64)(x & 0x8000000000000000LLU) - (s64)(y & 0x8000000000000000LLU)) >> 63));
- return low63 & high_bit;
-}
-
-static __always_inline void modulo_carry_top(u64 *b)
-{
- u64 b4 = b[4];
- u64 b0 = b[0];
- u64 b4_ = b4 & 0x7ffffffffffffLLU;
- u64 b0_ = b0 + 19 * (b4 >> 51);
- b[4] = b4_;
- b[0] = b0_;
-}
-
-static __always_inline void fproduct_copy_from_wide_(u64 *output, u128 *input)
-{
- {
- u128 xi = input[0];
- output[0] = ((u64)(xi));
- }
- {
- u128 xi = input[1];
- output[1] = ((u64)(xi));
- }
- {
- u128 xi = input[2];
- output[2] = ((u64)(xi));
- }
- {
- u128 xi = input[3];
- output[3] = ((u64)(xi));
- }
- {
- u128 xi = input[4];
- output[4] = ((u64)(xi));
- }
-}
-
-static __always_inline void fproduct_sum_scalar_multiplication_(u128 *output, u64 *input, u64 s)
-{
- output[0] += (u128)input[0] * s;
- output[1] += (u128)input[1] * s;
- output[2] += (u128)input[2] * s;
- output[3] += (u128)input[3] * s;
- output[4] += (u128)input[4] * s;
-}
-
-static __always_inline void fproduct_carry_wide_(u128 *tmp)
-{
- {
- u32 ctr = 0;
- u128 tctr = tmp[ctr];
- u128 tctrp1 = tmp[ctr + 1];
- u64 r0 = ((u64)(tctr)) & 0x7ffffffffffffLLU;
- u128 c = ((tctr) >> (51));
- tmp[ctr] = ((u128)(r0));
- tmp[ctr + 1] = ((tctrp1) + (c));
- }
- {
- u32 ctr = 1;
- u128 tctr = tmp[ctr];
- u128 tctrp1 = tmp[ctr + 1];
- u64 r0 = ((u64)(tctr)) & 0x7ffffffffffffLLU;
- u128 c = ((tctr) >> (51));
- tmp[ctr] = ((u128)(r0));
- tmp[ctr + 1] = ((tctrp1) + (c));
- }
-
- {
- u32 ctr = 2;
- u128 tctr = tmp[ctr];
- u128 tctrp1 = tmp[ctr + 1];
- u64 r0 = ((u64)(tctr)) & 0x7ffffffffffffLLU;
- u128 c = ((tctr) >> (51));
- tmp[ctr] = ((u128)(r0));
- tmp[ctr + 1] = ((tctrp1) + (c));
- }
- {
- u32 ctr = 3;
- u128 tctr = tmp[ctr];
- u128 tctrp1 = tmp[ctr + 1];
- u64 r0 = ((u64)(tctr)) & 0x7ffffffffffffLLU;
- u128 c = ((tctr) >> (51));
- tmp[ctr] = ((u128)(r0));
- tmp[ctr + 1] = ((tctrp1) + (c));
- }
-}
-
-static __always_inline void fmul_shift_reduce(u64 *output)
-{
- u64 tmp = output[4];
- u64 b0;
- {
- u32 ctr = 5 - 0 - 1;
- u64 z = output[ctr - 1];
- output[ctr] = z;
- }
- {
- u32 ctr = 5 - 1 - 1;
- u64 z = output[ctr - 1];
- output[ctr] = z;
- }
- {
- u32 ctr = 5 - 2 - 1;
- u64 z = output[ctr - 1];
- output[ctr] = z;
- }
- {
- u32 ctr = 5 - 3 - 1;
- u64 z = output[ctr - 1];
- output[ctr] = z;
- }
- output[0] = tmp;
- b0 = output[0];
- output[0] = 19 * b0;
-}
-
-static __always_inline void fmul_mul_shift_reduce_(u128 *output, u64 *input, u64 *input21)
-{
- u32 i;
- u64 input2i;
- {
- u64 input2i = input21[0];
- fproduct_sum_scalar_multiplication_(output, input, input2i);
- fmul_shift_reduce(input);
- }
- {
- u64 input2i = input21[1];
- fproduct_sum_scalar_multiplication_(output, input, input2i);
- fmul_shift_reduce(input);
- }
- {
- u64 input2i = input21[2];
- fproduct_sum_scalar_multiplication_(output, input, input2i);
- fmul_shift_reduce(input);
- }
- {
- u64 input2i = input21[3];
- fproduct_sum_scalar_multiplication_(output, input, input2i);
- fmul_shift_reduce(input);
- }
- i = 4;
- input2i = input21[i];
- fproduct_sum_scalar_multiplication_(output, input, input2i);
-}
-
-static __always_inline void fmul_fmul(u64 *output, u64 *input, u64 *input21)
-{
- u64 tmp[5];
- memcpy(tmp, input, 5 * sizeof(*input));
- {
- u128 b4;
- u128 b0;
- u128 b4_;
- u128 b0_;
- u64 i0;
- u64 i1;
- u64 i0_;
- u64 i1_;
- u128 t[5] = { 0 };
- fmul_mul_shift_reduce_(t, tmp, input21);
- fproduct_carry_wide_(t);
- b4 = t[4];
- b0 = t[0];
- b4_ = ((b4) & (((u128)(0x7ffffffffffffLLU))));
- b0_ = ((b0) + (((u128)(19) * (((u64)(((b4) >> (51))))))));
- t[4] = b4_;
- t[0] = b0_;
- fproduct_copy_from_wide_(output, t);
- i0 = output[0];
- i1 = output[1];
- i0_ = i0 & 0x7ffffffffffffLLU;
- i1_ = i1 + (i0 >> 51);
- output[0] = i0_;
- output[1] = i1_;
- }
-}
-
-static __always_inline void fsquare_fsquare__(u128 *tmp, u64 *output)
-{
- u64 r0 = output[0];
- u64 r1 = output[1];
- u64 r2 = output[2];
- u64 r3 = output[3];
- u64 r4 = output[4];
- u64 d0 = r0 * 2;
- u64 d1 = r1 * 2;
- u64 d2 = r2 * 2 * 19;
- u64 d419 = r4 * 19;
- u64 d4 = d419 * 2;
- u128 s0 = ((((((u128)(r0) * (r0))) + (((u128)(d4) * (r1))))) + (((u128)(d2) * (r3))));
- u128 s1 = ((((((u128)(d0) * (r1))) + (((u128)(d4) * (r2))))) + (((u128)(r3 * 19) * (r3))));
- u128 s2 = ((((((u128)(d0) * (r2))) + (((u128)(r1) * (r1))))) + (((u128)(d4) * (r3))));
- u128 s3 = ((((((u128)(d0) * (r3))) + (((u128)(d1) * (r2))))) + (((u128)(r4) * (d419))));
- u128 s4 = ((((((u128)(d0) * (r4))) + (((u128)(d1) * (r3))))) + (((u128)(r2) * (r2))));
- tmp[0] = s0;
- tmp[1] = s1;
- tmp[2] = s2;
- tmp[3] = s3;
- tmp[4] = s4;
-}
-
-static __always_inline void fsquare_fsquare_(u128 *tmp, u64 *output)
-{
- u128 b4;
- u128 b0;
- u128 b4_;
- u128 b0_;
- u64 i0;
- u64 i1;
- u64 i0_;
- u64 i1_;
- fsquare_fsquare__(tmp, output);
- fproduct_carry_wide_(tmp);
- b4 = tmp[4];
- b0 = tmp[0];
- b4_ = ((b4) & (((u128)(0x7ffffffffffffLLU))));
- b0_ = ((b0) + (((u128)(19) * (((u64)(((b4) >> (51))))))));
- tmp[4] = b4_;
- tmp[0] = b0_;
- fproduct_copy_from_wide_(output, tmp);
- i0 = output[0];
- i1 = output[1];
- i0_ = i0 & 0x7ffffffffffffLLU;
- i1_ = i1 + (i0 >> 51);
- output[0] = i0_;
- output[1] = i1_;
-}
-
-static __always_inline void fsquare_fsquare_times_(u64 *output, u128 *tmp, u32 count1)
-{
- u32 i;
- fsquare_fsquare_(tmp, output);
- for (i = 1; i < count1; ++i)
- fsquare_fsquare_(tmp, output);
-}
-
-static __always_inline void fsquare_fsquare_times(u64 *output, u64 *input, u32 count1)
-{
- u128 t[5];
- memcpy(output, input, 5 * sizeof(*input));
- fsquare_fsquare_times_(output, t, count1);
-}
-
-static __always_inline void fsquare_fsquare_times_inplace(u64 *output, u32 count1)
-{
- u128 t[5];
- fsquare_fsquare_times_(output, t, count1);
-}
-
-static __always_inline void crecip_crecip(u64 *out, u64 *z)
-{
- u64 buf[20] = { 0 };
- u64 *a0 = buf;
- u64 *t00 = buf + 5;
- u64 *b0 = buf + 10;
- u64 *t01;
- u64 *b1;
- u64 *c0;
- u64 *a;
- u64 *t0;
- u64 *b;
- u64 *c;
- fsquare_fsquare_times(a0, z, 1);
- fsquare_fsquare_times(t00, a0, 2);
- fmul_fmul(b0, t00, z);
- fmul_fmul(a0, b0, a0);
- fsquare_fsquare_times(t00, a0, 1);
- fmul_fmul(b0, t00, b0);
- fsquare_fsquare_times(t00, b0, 5);
- t01 = buf + 5;
- b1 = buf + 10;
- c0 = buf + 15;
- fmul_fmul(b1, t01, b1);
- fsquare_fsquare_times(t01, b1, 10);
- fmul_fmul(c0, t01, b1);
- fsquare_fsquare_times(t01, c0, 20);
- fmul_fmul(t01, t01, c0);
- fsquare_fsquare_times_inplace(t01, 10);
- fmul_fmul(b1, t01, b1);
- fsquare_fsquare_times(t01, b1, 50);
- a = buf;
- t0 = buf + 5;
- b = buf + 10;
- c = buf + 15;
- fmul_fmul(c, t0, b);
- fsquare_fsquare_times(t0, c, 100);
- fmul_fmul(t0, t0, c);
- fsquare_fsquare_times_inplace(t0, 50);
- fmul_fmul(t0, t0, b);
- fsquare_fsquare_times_inplace(t0, 5);
- fmul_fmul(out, t0, a);
-}
-
-static __always_inline void fsum(u64 *a, u64 *b)
-{
- a[0] += b[0];
- a[1] += b[1];
- a[2] += b[2];
- a[3] += b[3];
- a[4] += b[4];
-}
-
-static __always_inline void fdifference(u64 *a, u64 *b)
-{
- u64 tmp[5] = { 0 };
- u64 b0;
- u64 b1;
- u64 b2;
- u64 b3;
- u64 b4;
- memcpy(tmp, b, 5 * sizeof(*b));
- b0 = tmp[0];
- b1 = tmp[1];
- b2 = tmp[2];
- b3 = tmp[3];
- b4 = tmp[4];
- tmp[0] = b0 + 0x3fffffffffff68LLU;
- tmp[1] = b1 + 0x3ffffffffffff8LLU;
- tmp[2] = b2 + 0x3ffffffffffff8LLU;
- tmp[3] = b3 + 0x3ffffffffffff8LLU;
- tmp[4] = b4 + 0x3ffffffffffff8LLU;
- {
- u64 xi = a[0];
- u64 yi = tmp[0];
- a[0] = yi - xi;
- }
- {
- u64 xi = a[1];
- u64 yi = tmp[1];
- a[1] = yi - xi;
- }
- {
- u64 xi = a[2];
- u64 yi = tmp[2];
- a[2] = yi - xi;
- }
- {
- u64 xi = a[3];
- u64 yi = tmp[3];
- a[3] = yi - xi;
- }
- {
- u64 xi = a[4];
- u64 yi = tmp[4];
- a[4] = yi - xi;
- }
-}
-
-static __always_inline void fscalar(u64 *output, u64 *b, u64 s)
-{
- u128 tmp[5];
- u128 b4;
- u128 b0;
- u128 b4_;
- u128 b0_;
- {
- u64 xi = b[0];
- tmp[0] = ((u128)(xi) * (s));
- }
- {
- u64 xi = b[1];
- tmp[1] = ((u128)(xi) * (s));
- }
- {
- u64 xi = b[2];
- tmp[2] = ((u128)(xi) * (s));
- }
- {
- u64 xi = b[3];
- tmp[3] = ((u128)(xi) * (s));
- }
- {
- u64 xi = b[4];
- tmp[4] = ((u128)(xi) * (s));
- }
- fproduct_carry_wide_(tmp);
- b4 = tmp[4];
- b0 = tmp[0];
- b4_ = ((b4) & (((u128)(0x7ffffffffffffLLU))));
- b0_ = ((b0) + (((u128)(19) * (((u64)(((b4) >> (51))))))));
- tmp[4] = b4_;
- tmp[0] = b0_;
- fproduct_copy_from_wide_(output, tmp);
-}
-
-static __always_inline void fmul(u64 *output, u64 *a, u64 *b)
-{
- fmul_fmul(output, a, b);
-}
-
-static __always_inline void crecip(u64 *output, u64 *input)
-{
- crecip_crecip(output, input);
-}
-
-static __always_inline void point_swap_conditional_step(u64 *a, u64 *b, u64 swap1, u32 ctr)
-{
- u32 i = ctr - 1;
- u64 ai = a[i];
- u64 bi = b[i];
- u64 x = swap1 & (ai ^ bi);
- u64 ai1 = ai ^ x;
- u64 bi1 = bi ^ x;
- a[i] = ai1;
- b[i] = bi1;
-}
-
-static __always_inline void point_swap_conditional5(u64 *a, u64 *b, u64 swap1)
-{
- point_swap_conditional_step(a, b, swap1, 5);
- point_swap_conditional_step(a, b, swap1, 4);
- point_swap_conditional_step(a, b, swap1, 3);
- point_swap_conditional_step(a, b, swap1, 2);
- point_swap_conditional_step(a, b, swap1, 1);
-}
-
-static __always_inline void point_swap_conditional(u64 *a, u64 *b, u64 iswap)
-{
- u64 swap1 = 0 - iswap;
- point_swap_conditional5(a, b, swap1);
- point_swap_conditional5(a + 5, b + 5, swap1);
-}
-
-static __always_inline void point_copy(u64 *output, u64 *input)
-{
- memcpy(output, input, 5 * sizeof(*input));
- memcpy(output + 5, input + 5, 5 * sizeof(*input));
-}
-
-static __always_inline void addanddouble_fmonty(u64 *pp, u64 *ppq, u64 *p, u64 *pq, u64 *qmqp)
-{
- u64 *qx = qmqp;
- u64 *x2 = pp;
- u64 *z2 = pp + 5;
- u64 *x3 = ppq;
- u64 *z3 = ppq + 5;
- u64 *x = p;
- u64 *z = p + 5;
- u64 *xprime = pq;
- u64 *zprime = pq + 5;
- u64 buf[40] = { 0 };
- u64 *origx = buf;
- u64 *origxprime0 = buf + 5;
- u64 *xxprime0;
- u64 *zzprime0;
- u64 *origxprime;
- xxprime0 = buf + 25;
- zzprime0 = buf + 30;
- memcpy(origx, x, 5 * sizeof(*x));
- fsum(x, z);
- fdifference(z, origx);
- memcpy(origxprime0, xprime, 5 * sizeof(*xprime));
- fsum(xprime, zprime);
- fdifference(zprime, origxprime0);
- fmul(xxprime0, xprime, z);
- fmul(zzprime0, x, zprime);
- origxprime = buf + 5;
- {
- u64 *xx0;
- u64 *zz0;
- u64 *xxprime;
- u64 *zzprime;
- u64 *zzzprime;
- xx0 = buf + 15;
- zz0 = buf + 20;
- xxprime = buf + 25;
- zzprime = buf + 30;
- zzzprime = buf + 35;
- memcpy(origxprime, xxprime, 5 * sizeof(*xxprime));
- fsum(xxprime, zzprime);
- fdifference(zzprime, origxprime);
- fsquare_fsquare_times(x3, xxprime, 1);
- fsquare_fsquare_times(zzzprime, zzprime, 1);
- fmul(z3, zzzprime, qx);
- fsquare_fsquare_times(xx0, x, 1);
- fsquare_fsquare_times(zz0, z, 1);
- {
- u64 *zzz;
- u64 *xx;
- u64 *zz;
- u64 scalar;
- zzz = buf + 10;
- xx = buf + 15;
- zz = buf + 20;
- fmul(x2, xx, zz);
- fdifference(zz, xx);
- scalar = 121665;
- fscalar(zzz, zz, scalar);
- fsum(zzz, xx);
- fmul(z2, zzz, zz);
- }
- }
-}
-
-static __always_inline void ladder_smallloop_cmult_small_loop_step(u64 *nq, u64 *nqpq, u64 *nq2, u64 *nqpq2, u64 *q, u8 byt)
-{
- u64 bit0 = (u64)(byt >> 7);
- u64 bit;
- point_swap_conditional(nq, nqpq, bit0);
- addanddouble_fmonty(nq2, nqpq2, nq, nqpq, q);
- bit = (u64)(byt >> 7);
- point_swap_conditional(nq2, nqpq2, bit);
-}
-
-static __always_inline void ladder_smallloop_cmult_small_loop_double_step(u64 *nq, u64 *nqpq, u64 *nq2, u64 *nqpq2, u64 *q, u8 byt)
-{
- u8 byt1;
- ladder_smallloop_cmult_small_loop_step(nq, nqpq, nq2, nqpq2, q, byt);
- byt1 = byt << 1;
- ladder_smallloop_cmult_small_loop_step(nq2, nqpq2, nq, nqpq, q, byt1);
-}
-
-static __always_inline void ladder_smallloop_cmult_small_loop(u64 *nq, u64 *nqpq, u64 *nq2, u64 *nqpq2, u64 *q, u8 byt, u32 i)
-{
- while (i--) {
- ladder_smallloop_cmult_small_loop_double_step(nq, nqpq, nq2, nqpq2, q, byt);
- byt <<= 2;
- }
-}
-
-static __always_inline void ladder_bigloop_cmult_big_loop(u8 *n1, u64 *nq, u64 *nqpq, u64 *nq2, u64 *nqpq2, u64 *q, u32 i)
-{
- while (i--) {
- u8 byte = n1[i];
- ladder_smallloop_cmult_small_loop(nq, nqpq, nq2, nqpq2, q, byte, 4);
- }
-}
-
-static __always_inline void ladder_cmult(u64 *result, u8 *n1, u64 *q)
-{
- u64 point_buf[40] = { 0 };
- u64 *nq = point_buf;
- u64 *nqpq = point_buf + 10;
- u64 *nq2 = point_buf + 20;
- u64 *nqpq2 = point_buf + 30;
- point_copy(nqpq, q);
- nq[0] = 1;
- ladder_bigloop_cmult_big_loop(n1, nq, nqpq, nq2, nqpq2, q, 32);
- point_copy(result, nq);
-}
-
-static __always_inline void format_fexpand(u64 *output, const u8 *input)
-{
- const u8 *x00 = input + 6;
- const u8 *x01 = input + 12;
- const u8 *x02 = input + 19;
- const u8 *x0 = input + 24;
- u64 i0, i1, i2, i3, i4, output0, output1, output2, output3, output4;
- i0 = le64_to_cpup((__force __le64 *)input);
- i1 = le64_to_cpup((__force __le64 *)x00);
- i2 = le64_to_cpup((__force __le64 *)x01);
- i3 = le64_to_cpup((__force __le64 *)x02);
- i4 = le64_to_cpup((__force __le64 *)x0);
- output0 = i0 & 0x7ffffffffffffLLU;
- output1 = i1 >> 3 & 0x7ffffffffffffLLU;
- output2 = i2 >> 6 & 0x7ffffffffffffLLU;
- output3 = i3 >> 1 & 0x7ffffffffffffLLU;
- output4 = i4 >> 12 & 0x7ffffffffffffLLU;
- output[0] = output0;
- output[1] = output1;
- output[2] = output2;
- output[3] = output3;
- output[4] = output4;
-}
-
-static __always_inline void format_fcontract_first_carry_pass(u64 *input)
-{
- u64 t0 = input[0];
- u64 t1 = input[1];
- u64 t2 = input[2];
- u64 t3 = input[3];
- u64 t4 = input[4];
- u64 t1_ = t1 + (t0 >> 51);
- u64 t0_ = t0 & 0x7ffffffffffffLLU;
- u64 t2_ = t2 + (t1_ >> 51);
- u64 t1__ = t1_ & 0x7ffffffffffffLLU;
- u64 t3_ = t3 + (t2_ >> 51);
- u64 t2__ = t2_ & 0x7ffffffffffffLLU;
- u64 t4_ = t4 + (t3_ >> 51);
- u64 t3__ = t3_ & 0x7ffffffffffffLLU;
- input[0] = t0_;
- input[1] = t1__;
- input[2] = t2__;
- input[3] = t3__;
- input[4] = t4_;
-}
-
-static __always_inline void format_fcontract_first_carry_full(u64 *input)
-{
- format_fcontract_first_carry_pass(input);
- modulo_carry_top(input);
-}
-
-static __always_inline void format_fcontract_second_carry_pass(u64 *input)
-{
- u64 t0 = input[0];
- u64 t1 = input[1];
- u64 t2 = input[2];
- u64 t3 = input[3];
- u64 t4 = input[4];
- u64 t1_ = t1 + (t0 >> 51);
- u64 t0_ = t0 & 0x7ffffffffffffLLU;
- u64 t2_ = t2 + (t1_ >> 51);
- u64 t1__ = t1_ & 0x7ffffffffffffLLU;
- u64 t3_ = t3 + (t2_ >> 51);
- u64 t2__ = t2_ & 0x7ffffffffffffLLU;
- u64 t4_ = t4 + (t3_ >> 51);
- u64 t3__ = t3_ & 0x7ffffffffffffLLU;
- input[0] = t0_;
- input[1] = t1__;
- input[2] = t2__;
- input[3] = t3__;
- input[4] = t4_;
-}
-
-static __always_inline void format_fcontract_second_carry_full(u64 *input)
-{
- u64 i0;
- u64 i1;
- u64 i0_;
- u64 i1_;
- format_fcontract_second_carry_pass(input);
- modulo_carry_top(input);
- i0 = input[0];
- i1 = input[1];
- i0_ = i0 & 0x7ffffffffffffLLU;
- i1_ = i1 + (i0 >> 51);
- input[0] = i0_;
- input[1] = i1_;
-}
-
-static __always_inline void format_fcontract_trim(u64 *input)
-{
- u64 a0 = input[0];
- u64 a1 = input[1];
- u64 a2 = input[2];
- u64 a3 = input[3];
- u64 a4 = input[4];
- u64 mask0 = u64_gte_mask(a0, 0x7ffffffffffedLLU);
- u64 mask1 = u64_eq_mask(a1, 0x7ffffffffffffLLU);
- u64 mask2 = u64_eq_mask(a2, 0x7ffffffffffffLLU);
- u64 mask3 = u64_eq_mask(a3, 0x7ffffffffffffLLU);
- u64 mask4 = u64_eq_mask(a4, 0x7ffffffffffffLLU);
- u64 mask = (((mask0 & mask1) & mask2) & mask3) & mask4;
- u64 a0_ = a0 - (0x7ffffffffffedLLU & mask);
- u64 a1_ = a1 - (0x7ffffffffffffLLU & mask);
- u64 a2_ = a2 - (0x7ffffffffffffLLU & mask);
- u64 a3_ = a3 - (0x7ffffffffffffLLU & mask);
- u64 a4_ = a4 - (0x7ffffffffffffLLU & mask);
- input[0] = a0_;
- input[1] = a1_;
- input[2] = a2_;
- input[3] = a3_;
- input[4] = a4_;
-}
-
-static __always_inline void format_fcontract_store(u8 *output, u64 *input)
-{
- u64 t0 = input[0];
- u64 t1 = input[1];
- u64 t2 = input[2];
- u64 t3 = input[3];
- u64 t4 = input[4];
- u64 o0 = t1 << 51 | t0;
- u64 o1 = t2 << 38 | t1 >> 13;
- u64 o2 = t3 << 25 | t2 >> 26;
- u64 o3 = t4 << 12 | t3 >> 39;
- u8 *b0 = output;
- u8 *b1 = output + 8;
- u8 *b2 = output + 16;
- u8 *b3 = output + 24;
- *(__force __le64 *)b0 = cpu_to_le64(o0);
- *(__force __le64 *)b1 = cpu_to_le64(o1);
- *(__force __le64 *)b2 = cpu_to_le64(o2);
- *(__force __le64 *)b3 = cpu_to_le64(o3);
-}
-
-static __always_inline void format_fcontract(u8 *output, u64 *input)
-{
- format_fcontract_first_carry_full(input);
- format_fcontract_second_carry_full(input);
- format_fcontract_trim(input);
- format_fcontract_store(output, input);
-}
-
-static __always_inline void format_scalar_of_point(u8 *scalar, u64 *point)
-{
- u64 *x = point;
- u64 *z = point + 5;
- u64 buf[10] __aligned(32) = { 0 };
- u64 *zmone = buf;
- u64 *sc = buf + 5;
- crecip(zmone, z);
- fmul(sc, x, zmone);
- format_fcontract(scalar, sc);
-}
-
-bool curve25519_hacl64(u8 mypublic[CURVE25519_POINT_SIZE], const u8 secret[CURVE25519_POINT_SIZE], const u8 basepoint[CURVE25519_POINT_SIZE])
-{
- u64 buf0[10] __aligned(32) = { 0 };
- u64 *x0 = buf0;
- u64 *z = buf0 + 5;
- u64 *q;
- format_fexpand(x0, basepoint);
- z[0] = 1;
- q = buf0;
- {
- u8 e[32] __aligned(32) = { 0 };
- u8 *scalar;
- memcpy(e, secret, 32);
- normalize_secret(e);
- scalar = e;
- {
- u64 buf[15] = { 0 };
- u64 *nq = buf;
- u64 *x = nq;
- x[0] = 1;
- ladder_cmult(nq, scalar, q);
- format_scalar_of_point(mypublic, nq);
- }
- }
-
- return true;
-}
diff --git a/curve25519-precomp.c b/curve25519-precomp.c
deleted file mode 100644
index 1ac8380..0000000
--- a/curve25519-precomp.c
+++ /dev/null
@@ -1,1551 +0,0 @@
-/* SPDX-License-Identifier: GPL-3+, but GPL-2 requested from authors; awaiting feedback.
- *
- * Copyright (C) 2017 Armando Faz <armfazh@ic.unicamp.br>.
- * Copyright (C) 2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- * Copyright (C) 2018 Samuel Neves <sneves@dei.uc.pt>. All Rights Reserved.
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-#define NUM_WORDS_ELTFP25519_X64 4
-typedef __aligned(32) u64 EltFp25519_1w_x64[NUM_WORDS_ELTFP25519_X64];
-typedef __aligned(32) u64 EltFp25519_1w_Buffer_x64[2 * NUM_WORDS_ELTFP25519_X64];
-
-#define mul_EltFp25519_1w_x64(c, a, b) \
- mul_256x256_integer_x64(buffer_1w, a, b); \
- red_EltFp25519_1w_x64(c, buffer_1w);
-
-#define sqr_EltFp25519_1w_x64(a) \
- sqr_256x256_integer_x64(buffer_1w, a); \
- red_EltFp25519_1w_x64(a, buffer_1w);
-
-#define mul_EltFp25519_2w_x64(c, a, b) \
- mul2_256x256_integer_x64(buffer_2w, a, b); \
- red_EltFp25519_2w_x64(c, buffer_2w);
-
-#define sqr_EltFp25519_2w_x64(a) \
- sqr2_256x256_integer_x64(buffer_2w, a); \
- red_EltFp25519_2w_x64(a, buffer_2w);
-
-#define copy_EltFp25519_1w_x64(C, A) \
- (C)[0] = (A)[0]; \
- (C)[1] = (A)[1]; \
- (C)[2] = (A)[2]; \
- (C)[3] = (A)[3];
-
-#define setzero_EltFp25519_1w_x64(C) \
- (C)[0] = 0; \
- (C)[1] = 0; \
- (C)[2] = 0; \
- (C)[3] = 0;
-
-__aligned(32) static const u64 Table_Ladder_8k[252 * NUM_WORDS_ELTFP25519_X64] = {
- /* 1 */ 0xfffffffffffffff3, 0xffffffffffffffff, 0xffffffffffffffff, 0x5fffffffffffffff,
- /* 2 */ 0x6b8220f416aafe96, 0x82ebeb2b4f566a34, 0xd5a9a5b075a5950f, 0x5142b2cf4b2488f4,
- /* 3 */ 0x6aaebc750069680c, 0x89cf7820a0f99c41, 0x2a58d9183b56d0f4, 0x4b5aca80e36011a4,
- /* 4 */ 0x329132348c29745d, 0xf4a2e616e1642fd7, 0x1e45bb03ff67bc34, 0x306912d0f42a9b4a,
- /* 5 */ 0xff886507e6af7154, 0x04f50e13dfeec82f, 0xaa512fe82abab5ce, 0x174e251a68d5f222,
- /* 6 */ 0xcf96700d82028898, 0x1743e3370a2c02c5, 0x379eec98b4e86eaa, 0x0c59888a51e0482e,
- /* 7 */ 0xfbcbf1d699b5d189, 0xacaef0d58e9fdc84, 0xc1c20d06231f7614, 0x2938218da274f972,
- /* 8 */ 0xf6af49beff1d7f18, 0xcc541c22387ac9c2, 0x96fcc9ef4015c56b, 0x69c1627c690913a9,
- /* 9 */ 0x7a86fd2f4733db0e, 0xfdb8c4f29e087de9, 0x095e4b1a8ea2a229, 0x1ad7a7c829b37a79,
- /* 10 */ 0x342d89cad17ea0c0, 0x67bedda6cced2051, 0x19ca31bf2bb42f74, 0x3df7b4c84980acbb,
- /* 11 */ 0xa8c6444dc80ad883, 0xb91e440366e3ab85, 0xc215cda00164f6d8, 0x3d867c6ef247e668,
- /* 12 */ 0xc7dd582bcc3e658c, 0xfd2c4748ee0e5528, 0xa0fd9b95cc9f4f71, 0x7529d871b0675ddf,
- /* 13 */ 0xb8f568b42d3cbd78, 0x1233011b91f3da82, 0x2dce6ccd4a7c3b62, 0x75e7fc8e9e498603,
- /* 14 */ 0x2f4f13f1fcd0b6ec, 0xf1a8ca1f29ff7a45, 0xc249c1a72981e29b, 0x6ebe0dbb8c83b56a,
- /* 15 */ 0x7114fa8d170bb222, 0x65a2dcd5bf93935f, 0xbdc41f68b59c979a, 0x2f0eef79a2ce9289,
- /* 16 */ 0x42ecbf0c083c37ce, 0x2930bc09ec496322, 0xf294b0c19cfeac0d, 0x3780aa4bedfabb80,
- /* 17 */ 0x56c17d3e7cead929, 0xe7cb4beb2e5722c5, 0x0ce931732dbfe15a, 0x41b883c7621052f8,
- /* 18 */ 0xdbf75ca0c3d25350, 0x2936be086eb1e351, 0xc936e03cb4a9b212, 0x1d45bf82322225aa,
- /* 19 */ 0xe81ab1036a024cc5, 0xe212201c304c9a72, 0xc5d73fba6832b1fc, 0x20ffdb5a4d839581,
- /* 20 */ 0xa283d367be5d0fad, 0x6c2b25ca8b164475, 0x9d4935467caaf22e, 0x5166408eee85ff49,
- /* 21 */ 0x3c67baa2fab4e361, 0xb3e433c67ef35cef, 0x5259729241159b1c, 0x6a621892d5b0ab33,
- /* 22 */ 0x20b74a387555cdcb, 0x532aa10e1208923f, 0xeaa17b7762281dd1, 0x61ab3443f05c44bf,
- /* 23 */ 0x257a6c422324def8, 0x131c6c1017e3cf7f, 0x23758739f630a257, 0x295a407a01a78580,
- /* 24 */ 0xf8c443246d5da8d9, 0x19d775450c52fa5d, 0x2afcfc92731bf83d, 0x7d10c8e81b2b4700,
- /* 25 */ 0xc8e0271f70baa20b, 0x993748867ca63957, 0x5412efb3cb7ed4bb, 0x3196d36173e62975,
- /* 26 */ 0xde5bcad141c7dffc, 0x47cc8cd2b395c848, 0xa34cd942e11af3cb, 0x0256dbf2d04ecec2,
- /* 27 */ 0x875ab7e94b0e667f, 0xcad4dd83c0850d10, 0x47f12e8f4e72c79f, 0x5f1a87bb8c85b19b,
- /* 28 */ 0x7ae9d0b6437f51b8, 0x12c7ce5518879065, 0x2ade09fe5cf77aee, 0x23a05a2f7d2c5627,
- /* 29 */ 0x5908e128f17c169a, 0xf77498dd8ad0852d, 0x74b4c4ceab102f64, 0x183abadd10139845,
- /* 30 */ 0xb165ba8daa92aaac, 0xd5c5ef9599386705, 0xbe2f8f0cf8fc40d1, 0x2701e635ee204514,
- /* 31 */ 0x629fa80020156514, 0xf223868764a8c1ce, 0x5b894fff0b3f060e, 0x60d9944cf708a3fa,
- /* 32 */ 0xaeea001a1c7a201f, 0xebf16a633ee2ce63, 0x6f7709594c7a07e1, 0x79b958150d0208cb,
- /* 33 */ 0x24b55e5301d410e7, 0xe3a34edff3fdc84d, 0xd88768e4904032d8, 0x131384427b3aaeec,
- /* 34 */ 0x8405e51286234f14, 0x14dc4739adb4c529, 0xb8a2b5b250634ffd, 0x2fe2a94ad8a7ff93,
- /* 35 */ 0xec5c57efe843fadd, 0x2843ce40f0bb9918, 0xa4b561d6cf3d6305, 0x743629bde8fb777e,
- /* 36 */ 0x343edd46bbaf738f, 0xed981828b101a651, 0xa401760b882c797a, 0x1fc223e28dc88730,
- /* 37 */ 0x48604e91fc0fba0e, 0xb637f78f052c6fa4, 0x91ccac3d09e9239c, 0x23f7eed4437a687c,
- /* 38 */ 0x5173b1118d9bd800, 0x29d641b63189d4a7, 0xfdbf177988bbc586, 0x2959894fcad81df5,
- /* 39 */ 0xaebc8ef3b4bbc899, 0x4148995ab26992b9, 0x24e20b0134f92cfb, 0x40d158894a05dee8,
- /* 40 */ 0x46b00b1185af76f6, 0x26bac77873187a79, 0x3dc0bf95ab8fff5f, 0x2a608bd8945524d7,
- /* 41 */ 0x26449588bd446302, 0x7c4bc21c0388439c, 0x8e98a4f383bd11b2, 0x26218d7bc9d876b9,
- /* 42 */ 0xe3081542997c178a, 0x3c2d29a86fb6606f, 0x5c217736fa279374, 0x7dde05734afeb1fa,
- /* 43 */ 0x3bf10e3906d42bab, 0xe4f7803e1980649c, 0xe6053bf89595bf7a, 0x394faf38da245530,
- /* 44 */ 0x7a8efb58896928f4, 0xfbc778e9cc6a113c, 0x72670ce330af596f, 0x48f222a81d3d6cf7,
- /* 45 */ 0xf01fce410d72caa7, 0x5a20ecc7213b5595, 0x7bc21165c1fa1483, 0x07f89ae31da8a741,
- /* 46 */ 0x05d2c2b4c6830ff9, 0xd43e330fc6316293, 0xa5a5590a96d3a904, 0x705edb91a65333b6,
- /* 47 */ 0x048ee15e0bb9a5f7, 0x3240cfca9e0aaf5d, 0x8f4b71ceedc4a40b, 0x621c0da3de544a6d,
- /* 48 */ 0x92872836a08c4091, 0xce8375b010c91445, 0x8a72eb524f276394, 0x2667fcfa7ec83635,
- /* 49 */ 0x7f4c173345e8752a, 0x061b47feee7079a5, 0x25dd9afa9f86ff34, 0x3780cef5425dc89c,
- /* 50 */ 0x1a46035a513bb4e9, 0x3e1ef379ac575ada, 0xc78c5f1c5fa24b50, 0x321a967634fd9f22,
- /* 51 */ 0x946707b8826e27fa, 0x3dca84d64c506fd0, 0xc189218075e91436, 0x6d9284169b3b8484,
- /* 52 */ 0x3a67e840383f2ddf, 0x33eec9a30c4f9b75, 0x3ec7c86fa783ef47, 0x26ec449fbac9fbc4,
- /* 53 */ 0x5c0f38cba09b9e7d, 0x81168cc762a3478c, 0x3e23b0d306fc121c, 0x5a238aa0a5efdcdd,
- /* 54 */ 0x1ba26121c4ea43ff, 0x36f8c77f7c8832b5, 0x88fbea0b0adcf99a, 0x5ca9938ec25bebf9,
- /* 55 */ 0xd5436a5e51fccda0, 0x1dbc4797c2cd893b, 0x19346a65d3224a08, 0x0f5034e49b9af466,
- /* 56 */ 0xf23c3967a1e0b96e, 0xe58b08fa867a4d88, 0xfb2fabc6a7341679, 0x2a75381eb6026946,
- /* 57 */ 0xc80a3be4c19420ac, 0x66b1f6c681f2b6dc, 0x7cf7036761e93388, 0x25abbbd8a660a4c4,
- /* 58 */ 0x91ea12ba14fd5198, 0x684950fc4a3cffa9, 0xf826842130f5ad28, 0x3ea988f75301a441,
- /* 59 */ 0xc978109a695f8c6f, 0x1746eb4a0530c3f3, 0x444d6d77b4459995, 0x75952b8c054e5cc7,
- /* 60 */ 0xa3703f7915f4d6aa, 0x66c346202f2647d8, 0xd01469df811d644b, 0x77fea47d81a5d71f,
- /* 61 */ 0xc5e9529ef57ca381, 0x6eeeb4b9ce2f881a, 0xb6e91a28e8009bd6, 0x4b80be3e9afc3fec,
- /* 62 */ 0x7e3773c526aed2c5, 0x1b4afcb453c9a49d, 0xa920bdd7baffb24d, 0x7c54699f122d400e,
- /* 63 */ 0xef46c8e14fa94bc8, 0xe0b074ce2952ed5e, 0xbea450e1dbd885d5, 0x61b68649320f712c,
- /* 64 */ 0x8a485f7309ccbdd1, 0xbd06320d7d4d1a2d, 0x25232973322dbef4, 0x445dc4758c17f770,
- /* 65 */ 0xdb0434177cc8933c, 0xed6fe82175ea059f, 0x1efebefdc053db34, 0x4adbe867c65daf99,
- /* 66 */ 0x3acd71a2a90609df, 0xe5e991856dd04050, 0x1ec69b688157c23c, 0x697427f6885cfe4d,
- /* 67 */ 0xd7be7b9b65e1a851, 0xa03d28d522c536dd, 0x28399d658fd2b645, 0x49e5b7e17c2641e1,
- /* 68 */ 0x6f8c3a98700457a4, 0x5078f0a25ebb6778, 0xd13c3ccbc382960f, 0x2e003258a7df84b1,
- /* 69 */ 0x8ad1f39be6296a1c, 0xc1eeaa652a5fbfb2, 0x33ee0673fd26f3cb, 0x59256173a69d2ccc,
- /* 70 */ 0x41ea07aa4e18fc41, 0xd9fc19527c87a51e, 0xbdaacb805831ca6f, 0x445b652dc916694f,
- /* 71 */ 0xce92a3a7f2172315, 0x1edc282de11b9964, 0xa1823aafe04c314a, 0x790a2d94437cf586,
- /* 72 */ 0x71c447fb93f6e009, 0x8922a56722845276, 0xbf70903b204f5169, 0x2f7a89891ba319fe,
- /* 73 */ 0x02a08eb577e2140c, 0xed9a4ed4427bdcf4, 0x5253ec44e4323cd1, 0x3e88363c14e9355b,
- /* 74 */ 0xaa66c14277110b8c, 0x1ae0391610a23390, 0x2030bd12c93fc2a2, 0x3ee141579555c7ab,
- /* 75 */ 0x9214de3a6d6e7d41, 0x3ccdd88607f17efe, 0x674f1288f8e11217, 0x5682250f329f93d0,
- /* 76 */ 0x6cf00b136d2e396e, 0x6e4cf86f1014debf, 0x5930b1b5bfcc4e83, 0x047069b48aba16b6,
- /* 77 */ 0x0d4ce4ab69b20793, 0xb24db91a97d0fb9e, 0xcdfa50f54e00d01d, 0x221b1085368bddb5,
- /* 78 */ 0xe7e59468b1e3d8d2, 0x53c56563bd122f93, 0xeee8a903e0663f09, 0x61efa662cbbe3d42,
- /* 79 */ 0x2cf8ddddde6eab2a, 0x9bf80ad51435f231, 0x5deadacec9f04973, 0x29275b5d41d29b27,
- /* 80 */ 0xcfde0f0895ebf14f, 0xb9aab96b054905a7, 0xcae80dd9a1c420fd, 0x0a63bf2f1673bbc7,
- /* 81 */ 0x092f6e11958fbc8c, 0x672a81e804822fad, 0xcac8351560d52517, 0x6f3f7722c8f192f8,
- /* 82 */ 0xf8ba90ccc2e894b7, 0x2c7557a438ff9f0d, 0x894d1d855ae52359, 0x68e122157b743d69,
- /* 83 */ 0xd87e5570cfb919f3, 0x3f2cdecd95798db9, 0x2121154710c0a2ce, 0x3c66a115246dc5b2,
- /* 84 */ 0xcbedc562294ecb72, 0xba7143c36a280b16, 0x9610c2efd4078b67, 0x6144735d946a4b1e,
- /* 85 */ 0x536f111ed75b3350, 0x0211db8c2041d81b, 0xf93cb1000e10413c, 0x149dfd3c039e8876,
- /* 86 */ 0xd479dde46b63155b, 0xb66e15e93c837976, 0xdafde43b1f13e038, 0x5fafda1a2e4b0b35,
- /* 87 */ 0x3600bbdf17197581, 0x3972050bbe3cd2c2, 0x5938906dbdd5be86, 0x34fce5e43f9b860f,
- /* 88 */ 0x75a8a4cd42d14d02, 0x828dabc53441df65, 0x33dcabedd2e131d3, 0x3ebad76fb814d25f,
- /* 89 */ 0xd4906f566f70e10f, 0x5d12f7aa51690f5a, 0x45adb16e76cefcf2, 0x01f768aead232999,
- /* 90 */ 0x2b6cc77b6248febd, 0x3cd30628ec3aaffd, 0xce1c0b80d4ef486a, 0x4c3bff2ea6f66c23,
- /* 91 */ 0x3f2ec4094aeaeb5f, 0x61b19b286e372ca7, 0x5eefa966de2a701d, 0x23b20565de55e3ef,
- /* 92 */ 0xe301ca5279d58557, 0x07b2d4ce27c2874f, 0xa532cd8a9dcf1d67, 0x2a52fee23f2bff56,
- /* 93 */ 0x8624efb37cd8663d, 0xbbc7ac20ffbd7594, 0x57b85e9c82d37445, 0x7b3052cb86a6ec66,
- /* 94 */ 0x3482f0ad2525e91e, 0x2cb68043d28edca0, 0xaf4f6d052e1b003a, 0x185f8c2529781b0a,
- /* 95 */ 0xaa41de5bd80ce0d6, 0x9407b2416853e9d6, 0x563ec36e357f4c3a, 0x4cc4b8dd0e297bce,
- /* 96 */ 0xa2fc1a52ffb8730e, 0x1811f16e67058e37, 0x10f9a366cddf4ee1, 0x72f4a0c4a0b9f099,
- /* 97 */ 0x8c16c06f663f4ea7, 0x693b3af74e970fba, 0x2102e7f1d69ec345, 0x0ba53cbc968a8089,
- /* 98 */ 0xca3d9dc7fea15537, 0x4c6824bb51536493, 0xb9886314844006b1, 0x40d2a72ab454cc60,
- /* 99 */ 0x5936a1b712570975, 0x91b9d648debda657, 0x3344094bb64330ea, 0x006ba10d12ee51d0,
- /* 100 */ 0x19228468f5de5d58, 0x0eb12f4c38cc05b0, 0xa1039f9dd5601990, 0x4502d4ce4fff0e0b,
- /* 101 */ 0xeb2054106837c189, 0xd0f6544c6dd3b93c, 0x40727064c416d74f, 0x6e15c6114b502ef0,
- /* 102 */ 0x4df2a398cfb1a76b, 0x11256c7419f2f6b1, 0x4a497962066e6043, 0x705b3aab41355b44,
- /* 103 */ 0x365ef536d797b1d8, 0x00076bd622ddf0db, 0x3bbf33b0e0575a88, 0x3777aa05c8e4ca4d,
- /* 104 */ 0x392745c85578db5f, 0x6fda4149dbae5ae2, 0xb1f0b00b8adc9867, 0x09963437d36f1da3,
- /* 105 */ 0x7e824e90a5dc3853, 0xccb5f6641f135cbd, 0x6736d86c87ce8fcc, 0x625f3ce26604249f,
- /* 106 */ 0xaf8ac8059502f63f, 0x0c05e70a2e351469, 0x35292e9c764b6305, 0x1a394360c7e23ac3,
- /* 107 */ 0xd5c6d53251183264, 0x62065abd43c2b74f, 0xb5fbf5d03b973f9b, 0x13a3da3661206e5e,
- /* 108 */ 0xc6bd5837725d94e5, 0x18e30912205016c5, 0x2088ce1570033c68, 0x7fba1f495c837987,
- /* 109 */ 0x5a8c7423f2f9079d, 0x1735157b34023fc5, 0xe4f9b49ad2fab351, 0x6691ff72c878e33c,
- /* 110 */ 0x122c2adedc5eff3e, 0xf8dd4bf1d8956cf4, 0xeb86205d9e9e5bda, 0x049b92b9d975c743,
- /* 111 */ 0xa5379730b0f6c05a, 0x72a0ffacc6f3a553, 0xb0032c34b20dcd6d, 0x470e9dbc88d5164a,
- /* 112 */ 0xb19cf10ca237c047, 0xb65466711f6c81a2, 0xb3321bd16dd80b43, 0x48c14f600c5fbe8e,
- /* 113 */ 0x66451c264aa6c803, 0xb66e3904a4fa7da6, 0xd45f19b0b3128395, 0x31602627c3c9bc10,
- /* 114 */ 0x3120dc4832e4e10d, 0xeb20c46756c717f7, 0x00f52e3f67280294, 0x566d4fc14730c509,
- /* 115 */ 0x7e3a5d40fd837206, 0xc1e926dc7159547a, 0x216730fba68d6095, 0x22e8c3843f69cea7,
- /* 116 */ 0x33d074e8930e4b2b, 0xb6e4350e84d15816, 0x5534c26ad6ba2365, 0x7773c12f89f1f3f3,
- /* 117 */ 0x8cba404da57962aa, 0x5b9897a81999ce56, 0x508e862f121692fc, 0x3a81907fa093c291,
- /* 118 */ 0x0dded0ff4725a510, 0x10d8cc10673fc503, 0x5b9d151c9f1f4e89, 0x32a5c1d5cb09a44c,
- /* 119 */ 0x1e0aa442b90541fb, 0x5f85eb7cc1b485db, 0xbee595ce8a9df2e5, 0x25e496c722422236,
- /* 120 */ 0x5edf3c46cd0fe5b9, 0x34e75a7ed2a43388, 0xe488de11d761e352, 0x0e878a01a085545c,
- /* 121 */ 0xba493c77e021bb04, 0x2b4d1843c7df899a, 0x9ea37a487ae80d67, 0x67a9958011e41794,
- /* 122 */ 0x4b58051a6697b065, 0x47e33f7d8d6ba6d4, 0xbb4da8d483ca46c1, 0x68becaa181c2db0d,
- /* 123 */ 0x8d8980e90b989aa5, 0xf95eb14a2c93c99b, 0x51c6c7c4796e73a2, 0x6e228363b5efb569,
- /* 124 */ 0xc6bbc0b02dd624c8, 0x777eb47dec8170ee, 0x3cde15a004cfafa9, 0x1dc6bc087160bf9b,
- /* 125 */ 0x2e07e043eec34002, 0x18e9fc677a68dc7f, 0xd8da03188bd15b9a, 0x48fbc3bb00568253,
- /* 126 */ 0x57547d4cfb654ce1, 0xd3565b82a058e2ad, 0xf63eaf0bbf154478, 0x47531ef114dfbb18,
- /* 127 */ 0xe1ec630a4278c587, 0x5507d546ca8e83f3, 0x85e135c63adc0c2b, 0x0aa7efa85682844e,
- /* 128 */ 0x72691ba8b3e1f615, 0x32b4e9701fbe3ffa, 0x97b6d92e39bb7868, 0x2cfe53dea02e39e8,
- /* 129 */ 0x687392cd85cd52b0, 0x27ff66c910e29831, 0x97134556a9832d06, 0x269bb0360a84f8a0,
- /* 130 */ 0x706e55457643f85c, 0x3734a48c9b597d1b, 0x7aee91e8c6efa472, 0x5cd6abc198a9d9e0,
- /* 131 */ 0x0e04de06cb3ce41a, 0xd8c6eb893402e138, 0x904659bb686e3772, 0x7215c371746ba8c8,
- /* 132 */ 0xfd12a97eeae4a2d9, 0x9514b7516394f2c5, 0x266fd5809208f294, 0x5c847085619a26b9,
- /* 133 */ 0x52985410fed694ea, 0x3c905b934a2ed254, 0x10bb47692d3be467, 0x063b3d2d69e5e9e1,
- /* 134 */ 0x472726eedda57deb, 0xefb6c4ae10f41891, 0x2b1641917b307614, 0x117c554fc4f45b7c,
- /* 135 */ 0xc07cf3118f9d8812, 0x01dbd82050017939, 0xd7e803f4171b2827, 0x1015e87487d225ea,
- /* 136 */ 0xc58de3fed23acc4d, 0x50db91c294a7be2d, 0x0b94d43d1c9cf457, 0x6b1640fa6e37524a,
- /* 137 */ 0x692f346c5fda0d09, 0x200b1c59fa4d3151, 0xb8c46f760777a296, 0x4b38395f3ffdfbcf,
- /* 138 */ 0x18d25e00be54d671, 0x60d50582bec8aba6, 0x87ad8f263b78b982, 0x50fdf64e9cda0432,
- /* 139 */ 0x90f567aac578dcf0, 0xef1e9b0ef2a3133b, 0x0eebba9242d9de71, 0x15473c9bf03101c7,
- /* 140 */ 0x7c77e8ae56b78095, 0xb678e7666e6f078e, 0x2da0b9615348ba1f, 0x7cf931c1ff733f0b,
- /* 141 */ 0x26b357f50a0a366c, 0xe9708cf42b87d732, 0xc13aeea5f91cb2c0, 0x35d90c991143bb4c,
- /* 142 */ 0x47c1c404a9a0d9dc, 0x659e58451972d251, 0x3875a8c473b38c31, 0x1fbd9ed379561f24,
- /* 143 */ 0x11fabc6fd41ec28d, 0x7ef8dfe3cd2a2dca, 0x72e73b5d8c404595, 0x6135fa4954b72f27,
- /* 144 */ 0xccfc32a2de24b69c, 0x3f55698c1f095d88, 0xbe3350ed5ac3f929, 0x5e9bf806ca477eeb,
- /* 145 */ 0xe9ce8fb63c309f68, 0x5376f63565e1f9f4, 0xd1afcfb35a6393f1, 0x6632a1ede5623506,
- /* 146 */ 0x0b7d6c390c2ded4c, 0x56cb3281df04cb1f, 0x66305a1249ecc3c7, 0x5d588b60a38ca72a,
- /* 147 */ 0xa6ecbf78e8e5f42d, 0x86eeb44b3c8a3eec, 0xec219c48fbd21604, 0x1aaf1af517c36731,
- /* 148 */ 0xc306a2836769bde7, 0x208280622b1e2adb, 0x8027f51ffbff94a6, 0x76cfa1ce1124f26b,
- /* 149 */ 0x18eb00562422abb6, 0xf377c4d58f8c29c3, 0x4dbbc207f531561a, 0x0253b7f082128a27,
- /* 150 */ 0x3d1f091cb62c17e0, 0x4860e1abd64628a9, 0x52d17436309d4253, 0x356f97e13efae576,
- /* 151 */ 0xd351e11aa150535b, 0x3e6b45bb1dd878cc, 0x0c776128bed92c98, 0x1d34ae93032885b8,
- /* 152 */ 0x4ba0488ca85ba4c3, 0x985348c33c9ce6ce, 0x66124c6f97bda770, 0x0f81a0290654124a,
- /* 153 */ 0x9ed09ca6569b86fd, 0x811009fd18af9a2d, 0xff08d03f93d8c20a, 0x52a148199faef26b,
- /* 154 */ 0x3e03f9dc2d8d1b73, 0x4205801873961a70, 0xc0d987f041a35970, 0x07aa1f15a1c0d549,
- /* 155 */ 0xdfd46ce08cd27224, 0x6d0a024f934e4239, 0x808a7a6399897b59, 0x0a4556e9e13d95a2,
- /* 156 */ 0xd21a991fe9c13045, 0x9b0e8548fe7751b8, 0x5da643cb4bf30035, 0x77db28d63940f721,
- /* 157 */ 0xfc5eeb614adc9011, 0x5229419ae8c411eb, 0x9ec3e7787d1dcf74, 0x340d053e216e4cb5,
- /* 158 */ 0xcac7af39b48df2b4, 0xc0faec2871a10a94, 0x140a69245ca575ed, 0x0cf1c37134273a4c,
- /* 159 */ 0xc8ee306ac224b8a5, 0x57eaee7ccb4930b0, 0xa1e806bdaacbe74f, 0x7d9a62742eeb657d,
- /* 160 */ 0x9eb6b6ef546c4830, 0x885cca1fddb36e2e, 0xe6b9f383ef0d7105, 0x58654fef9d2e0412,
- /* 161 */ 0xa905c4ffbe0e8e26, 0x942de5df9b31816e, 0x497d723f802e88e1, 0x30684dea602f408d,
- /* 162 */ 0x21e5a278a3e6cb34, 0xaefb6e6f5b151dc4, 0xb30b8e049d77ca15, 0x28c3c9cf53b98981,
- /* 163 */ 0x287fb721556cdd2a, 0x0d317ca897022274, 0x7468c7423a543258, 0x4a7f11464eb5642f,
- /* 164 */ 0xa237a4774d193aa6, 0xd865986ea92129a1, 0x24c515ecf87c1a88, 0x604003575f39f5eb,
- /* 165 */ 0x47b9f189570a9b27, 0x2b98cede465e4b78, 0x026df551dbb85c20, 0x74fcd91047e21901,
- /* 166 */ 0x13e2a90a23c1bfa3, 0x0cb0074e478519f6, 0x5ff1cbbe3af6cf44, 0x67fe5438be812dbe,
- /* 167 */ 0xd13cf64fa40f05b0, 0x054dfb2f32283787, 0x4173915b7f0d2aea, 0x482f144f1f610d4e,
- /* 168 */ 0xf6210201b47f8234, 0x5d0ae1929e70b990, 0xdcd7f455b049567c, 0x7e93d0f1f0916f01,
- /* 169 */ 0xdd79cbf18a7db4fa, 0xbe8391bf6f74c62f, 0x027145d14b8291bd, 0x585a73ea2cbf1705,
- /* 170 */ 0x485ca03e928a0db2, 0x10fc01a5742857e7, 0x2f482edbd6d551a7, 0x0f0433b5048fdb8a,
- /* 171 */ 0x60da2e8dd7dc6247, 0x88b4c9d38cd4819a, 0x13033ac001f66697, 0x273b24fe3b367d75,
- /* 172 */ 0xc6e8f66a31b3b9d4, 0x281514a494df49d5, 0xd1726fdfc8b23da7, 0x4b3ae7d103dee548,
- /* 173 */ 0xc6256e19ce4b9d7e, 0xff5c5cf186e3c61c, 0xacc63ca34b8ec145, 0x74621888fee66574,
- /* 174 */ 0x956f409645290a1e, 0xef0bf8e3263a962e, 0xed6a50eb5ec2647b, 0x0694283a9dca7502,
- /* 175 */ 0x769b963643a2dcd1, 0x42b7c8ea09fc5353, 0x4f002aee13397eab, 0x63005e2c19b7d63a,
- /* 176 */ 0xca6736da63023bea, 0x966c7f6db12a99b7, 0xace09390c537c5e1, 0x0b696063a1aa89ee,
- /* 177 */ 0xebb03e97288c56e5, 0x432a9f9f938c8be8, 0xa6a5a93d5b717f71, 0x1a5fb4c3e18f9d97,
- /* 178 */ 0x1c94e7ad1c60cdce, 0xee202a43fc02c4a0, 0x8dafe4d867c46a20, 0x0a10263c8ac27b58,
- /* 179 */ 0xd0dea9dfe4432a4a, 0x856af87bbe9277c5, 0xce8472acc212c71a, 0x6f151b6d9bbb1e91,
- /* 180 */ 0x26776c527ceed56a, 0x7d211cb7fbf8faec, 0x37ae66a6fd4609cc, 0x1f81b702d2770c42,
- /* 181 */ 0x2fb0b057eac58392, 0xe1dd89fe29744e9d, 0xc964f8eb17beb4f8, 0x29571073c9a2d41e,
- /* 182 */ 0xa948a18981c0e254, 0x2df6369b65b22830, 0xa33eb2d75fcfd3c6, 0x078cd6ec4199a01f,
- /* 183 */ 0x4a584a41ad900d2f, 0x32142b78e2c74c52, 0x68c4e8338431c978, 0x7f69ea9008689fc2,
- /* 184 */ 0x52f2c81e46a38265, 0xfd78072d04a832fd, 0x8cd7d5fa25359e94, 0x4de71b7454cc29d2,
- /* 185 */ 0x42eb60ad1eda6ac9, 0x0aad37dfdbc09c3a, 0x81004b71e33cc191, 0x44e6be345122803c,
- /* 186 */ 0x03fe8388ba1920db, 0xf5d57c32150db008, 0x49c8c4281af60c29, 0x21edb518de701aee,
- /* 187 */ 0x7fb63e418f06dc99, 0xa4460d99c166d7b8, 0x24dd5248ce520a83, 0x5ec3ad712b928358,
- /* 188 */ 0x15022a5fbd17930f, 0xa4f64a77d82570e3, 0x12bc8d6915783712, 0x498194c0fc620abb,
- /* 189 */ 0x38a2d9d255686c82, 0x785c6bd9193e21f0, 0xe4d5c81ab24a5484, 0x56307860b2e20989,
- /* 190 */ 0x429d55f78b4d74c4, 0x22f1834643350131, 0x1e60c24598c71fff, 0x59f2f014979983ef,
- /* 191 */ 0x46a47d56eb494a44, 0x3e22a854d636a18e, 0xb346e15274491c3b, 0x2ceafd4e5390cde7,
- /* 192 */ 0xba8a8538be0d6675, 0x4b9074bb50818e23, 0xcbdab89085d304c3, 0x61a24fe0e56192c4,
- /* 193 */ 0xcb7615e6db525bcb, 0xdd7d8c35a567e4ca, 0xe6b4153acafcdd69, 0x2d668e097f3c9766,
- /* 194 */ 0xa57e7e265ce55ef0, 0x5d9f4e527cd4b967, 0xfbc83606492fd1e5, 0x090d52beb7c3f7ae,
- /* 195 */ 0x09b9515a1e7b4d7c, 0x1f266a2599da44c0, 0xa1c49548e2c55504, 0x7ef04287126f15cc,
- /* 196 */ 0xfed1659dbd30ef15, 0x8b4ab9eec4e0277b, 0x884d6236a5df3291, 0x1fd96ea6bf5cf788,
- /* 197 */ 0x42a161981f190d9a, 0x61d849507e6052c1, 0x9fe113bf285a2cd5, 0x7c22d676dbad85d8,
- /* 198 */ 0x82e770ed2bfbd27d, 0x4c05b2ece996f5a5, 0xcd40a9c2b0900150, 0x5895319213d9bf64,
- /* 199 */ 0xe7cc5d703fea2e08, 0xb50c491258e2188c, 0xcce30baa48205bf0, 0x537c659ccfa32d62,
- /* 200 */ 0x37b6623a98cfc088, 0xfe9bed1fa4d6aca4, 0x04d29b8e56a8d1b0, 0x725f71c40b519575,
- /* 201 */ 0x28c7f89cd0339ce6, 0x8367b14469ddc18b, 0x883ada83a6a1652c, 0x585f1974034d6c17,
- /* 202 */ 0x89cfb266f1b19188, 0xe63b4863e7c35217, 0xd88c9da6b4c0526a, 0x3e035c9df0954635,
- /* 203 */ 0xdd9d5412fb45de9d, 0xdd684532e4cff40d, 0x4b5c999b151d671c, 0x2d8c2cc811e7f690,
- /* 204 */ 0x7f54be1d90055d40, 0xa464c5df464aaf40, 0x33979624f0e917be, 0x2c018dc527356b30,
- /* 205 */ 0xa5415024e330b3d4, 0x73ff3d96691652d3, 0x94ec42c4ef9b59f1, 0x0747201618d08e5a,
- /* 206 */ 0x4d6ca48aca411c53, 0x66415f2fcfa66119, 0x9c4dd40051e227ff, 0x59810bc09a02f7eb,
- /* 207 */ 0x2a7eb171b3dc101d, 0x441c5ab99ffef68e, 0x32025c9b93b359ea, 0x5e8ce0a71e9d112f,
- /* 208 */ 0xbfcccb92429503fd, 0xd271ba752f095d55, 0x345ead5e972d091e, 0x18c8df11a83103ba,
- /* 209 */ 0x90cd949a9aed0f4c, 0xc5d1f4cb6660e37e, 0xb8cac52d56c52e0b, 0x6e42e400c5808e0d,
- /* 210 */ 0xa3b46966eeaefd23, 0x0c4f1f0be39ecdca, 0x189dc8c9d683a51d, 0x51f27f054c09351b,
- /* 211 */ 0x4c487ccd2a320682, 0x587ea95bb3df1c96, 0xc8ccf79e555cb8e8, 0x547dc829a206d73d,
- /* 212 */ 0xb822a6cd80c39b06, 0xe96d54732000d4c6, 0x28535b6f91463b4d, 0x228f4660e2486e1d,
- /* 213 */ 0x98799538de8d3abf, 0x8cd8330045ebca6e, 0x79952a008221e738, 0x4322e1a7535cd2bb,
- /* 214 */ 0xb114c11819d1801c, 0x2016e4d84f3f5ec7, 0xdd0e2df409260f4c, 0x5ec362c0ae5f7266,
- /* 215 */ 0xc0462b18b8b2b4ee, 0x7cc8d950274d1afb, 0xf25f7105436b02d2, 0x43bbf8dcbff9ccd3,
- /* 216 */ 0xb6ad1767a039e9df, 0xb0714da8f69d3583, 0x5e55fa18b42931f5, 0x4ed5558f33c60961,
- /* 217 */ 0x1fe37901c647a5dd, 0x593ddf1f8081d357, 0x0249a4fd813fd7a6, 0x69acca274e9caf61,
- /* 218 */ 0x047ba3ea330721c9, 0x83423fc20e7e1ea0, 0x1df4c0af01314a60, 0x09a62dab89289527,
- /* 219 */ 0xa5b325a49cc6cb00, 0xe94b5dc654b56cb6, 0x3be28779adc994a0, 0x4296e8f8ba3a4aad,
- /* 220 */ 0x328689761e451eab, 0x2e4d598bff59594a, 0x49b96853d7a7084a, 0x4980a319601420a8,
- /* 221 */ 0x9565b9e12f552c42, 0x8a5318db7100fe96, 0x05c90b4d43add0d7, 0x538b4cd66a5d4eda,
- /* 222 */ 0xf4e94fc3e89f039f, 0x592c9af26f618045, 0x08a36eb5fd4b9550, 0x25fffaf6c2ed1419,
- /* 223 */ 0x34434459cc79d354, 0xeeecbfb4b1d5476b, 0xddeb34a061615d99, 0x5129cecceb64b773,
- /* 224 */ 0xee43215894993520, 0x772f9c7cf14c0b3b, 0xd2e2fce306bedad5, 0x715f42b546f06a97,
- /* 225 */ 0x434ecdceda5b5f1a, 0x0da17115a49741a9, 0x680bd77c73edad2e, 0x487c02354edd9041,
- /* 226 */ 0xb8efeff3a70ed9c4, 0x56a32aa3e857e302, 0xdf3a68bd48a2a5a0, 0x07f650b73176c444,
- /* 227 */ 0xe38b9b1626e0ccb1, 0x79e053c18b09fb36, 0x56d90319c9f94964, 0x1ca941e7ac9ff5c4,
- /* 228 */ 0x49c4df29162fa0bb, 0x8488cf3282b33305, 0x95dfda14cabb437d, 0x3391f78264d5ad86,
- /* 229 */ 0x729ae06ae2b5095d, 0xd58a58d73259a946, 0xe9834262d13921ed, 0x27fedafaa54bb592,
- /* 230 */ 0xa99dc5b829ad48bb, 0x5f025742499ee260, 0x802c8ecd5d7513fd, 0x78ceb3ef3f6dd938,
- /* 231 */ 0xc342f44f8a135d94, 0x7b9edb44828cdda3, 0x9436d11a0537cfe7, 0x5064b164ec1ab4c8,
- /* 232 */ 0x7020eccfd37eb2fc, 0x1f31ea3ed90d25fc, 0x1b930d7bdfa1bb34, 0x5344467a48113044,
- /* 233 */ 0x70073170f25e6dfb, 0xe385dc1a50114cc8, 0x2348698ac8fc4f00, 0x2a77a55284dd40d8,
- /* 234 */ 0xfe06afe0c98c6ce4, 0xc235df96dddfd6e4, 0x1428d01e33bf1ed3, 0x785768ec9300bdaf,
- /* 235 */ 0x9702e57a91deb63b, 0x61bdb8bfe5ce8b80, 0x645b426f3d1d58ac, 0x4804a82227a557bc,
- /* 236 */ 0x8e57048ab44d2601, 0x68d6501a4b3a6935, 0xc39c9ec3f9e1c293, 0x4172f257d4de63e2,
- /* 237 */ 0xd368b450330c6401, 0x040d3017418f2391, 0x2c34bb6090b7d90d, 0x16f649228fdfd51f,
- /* 238 */ 0xbea6818e2b928ef5, 0xe28ccf91cdc11e72, 0x594aaa68e77a36cd, 0x313034806c7ffd0f,
- /* 239 */ 0x8a9d27ac2249bd65, 0x19a3b464018e9512, 0xc26ccff352b37ec7, 0x056f68341d797b21,
- /* 240 */ 0x5e79d6757efd2327, 0xfabdbcb6553afe15, 0xd3e7222c6eaf5a60, 0x7046c76d4dae743b,
- /* 241 */ 0x660be872b18d4a55, 0x19992518574e1496, 0xc103053a302bdcbb, 0x3ed8e9800b218e8e,
- /* 242 */ 0x7b0b9239fa75e03e, 0xefe9fb684633c083, 0x98a35fbe391a7793, 0x6065510fe2d0fe34,
- /* 243 */ 0x55cb668548abad0c, 0xb4584548da87e527, 0x2c43ecea0107c1dd, 0x526028809372de35,
- /* 244 */ 0x3415c56af9213b1f, 0x5bee1a4d017e98db, 0x13f6b105b5cf709b, 0x5ff20e3482b29ab6,
- /* 245 */ 0x0aa29c75cc2e6c90, 0xfc7d73ca3a70e206, 0x899fc38fc4b5c515, 0x250386b124ffc207,
- /* 246 */ 0x54ea28d5ae3d2b56, 0x9913149dd6de60ce, 0x16694fc58f06d6c1, 0x46b23975eb018fc7,
- /* 247 */ 0x470a6a0fb4b7b4e2, 0x5d92475a8f7253de, 0xabeee5b52fbd3adb, 0x7fa20801a0806968,
- /* 248 */ 0x76f3faf19f7714d2, 0xb3e840c12f4660c3, 0x0fb4cd8df212744e, 0x4b065a251d3a2dd2,
- /* 249 */ 0x5cebde383d77cd4a, 0x6adf39df882c9cb1, 0xa2dd242eb09af759, 0x3147c0e50e5f6422,
- /* 250 */ 0x164ca5101d1350db, 0xf8d13479c33fc962, 0xe640ce4d13e5da08, 0x4bdee0c45061f8ba,
- /* 251 */ 0xd7c46dc1a4edb1c9, 0x5514d7b6437fd98a, 0x58942f6bb2a1c00b, 0x2dffb2ab1d70710e,
- /* 252 */ 0xccdfcf2fc18b6d68, 0xa8ebcba8b7806167, 0x980697f95e2937e3, 0x02fbba1cd0126e8c
-};
-
-static void mul2_256x256_integer_x64(u64 *const c, u64 *const a, u64 *const b)
-{
-#ifdef __ADX__
- __asm__ __volatile__(
- "movq (%1), %%rdx # A[0] \n\t"
- "mulx (%2), %%r8, %%r9 # A[0]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "movq %%r8, (%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[0]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "movq %%r10, 8(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[0]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[0]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
-
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx (%2), %%r8, %%r9 # A[1]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 8(%0), %%r8 \n\t"
- "movq %%r8, 8(%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[1]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 16(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[1]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[1]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx (%2), %%r8, %%r9 # A[2]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 16(%0), %%r8 \n\t"
- "movq %%r8, 16(%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[2]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 24(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[2]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[2]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
-
- "movq 24(%1), %%rdx # A[3] \n\t"
- "mulx (%2), %%r8, %%r9 # A[3]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 24(%0), %%r8 \n\t"
- "movq %%r8, 24(%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[3]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 32(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[3]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq %%r12, 40(%0) \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[3]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq %%r14, 48(%0) \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
- "movq %%rax, 56(%0) \n\t"
-
- "movq 32(%1), %%rdx # A[0] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[0]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "movq %%r8, 64(%0) \n\t"
- "mulx 40(%2), %%r10, %%r11 # A[0]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "movq %%r10, 72(%0) \n\t"
- "mulx 48(%2), %%r12, %%r13 # A[0]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "mulx 56(%2), %%r14, %%rdx # A[0]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
-
- "movq 40(%1), %%rdx # A[1] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[1]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 72(%0), %%r8 \n\t"
- "movq %%r8, 72(%0) \n\t"
- "mulx 40(%2), %%r10, %%r11 # A[1]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 80(%0) \n\t"
- "mulx 48(%2), %%r12, %%r13 # A[1]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 56(%2), %%r14, %%rdx # A[1]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
-
- "movq 48(%1), %%rdx # A[2] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[2]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 80(%0), %%r8 \n\t"
- "movq %%r8, 80(%0) \n\t"
- "mulx 40(%2), %%r10, %%r11 # A[2]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 88(%0) \n\t"
- "mulx 48(%2), %%r12, %%r13 # A[2]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 56(%2), %%r14, %%rdx # A[2]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
-
- "movq 56(%1), %%rdx # A[3] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[3]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 88(%0), %%r8 \n\t"
- "movq %%r8, 88(%0) \n\t"
- "mulx 40(%2), %%r10, %%r11 # A[3]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 96(%0) \n\t"
- "mulx 48(%2), %%r12, %%r13 # A[3]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq %%r12, 104(%0) \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 56(%2), %%r14, %%rdx # A[3]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq %%r14, 112(%0) \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
- "movq %%rax, 120(%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(b)
- : "memory", "cc", "%rax", "%rdx",
- "%r8", "%r9", "%r10", "%r11",
- "%r12", "%r13", "%r14");
-#else
- __asm__ __volatile__(
- "movq (%1), %%rdx # A[0] \n\t"
- "mulx (%2), %%r8, %%r9 # A[0]*B[0] \n\t"
- "movq %%r8, (%0) \n\t"
- "mulx 8(%2), %%r10, %%rax # A[0]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "movq %%r9, 8(%0) \n\t"
- "mulx 16(%2), %%r12, %%rbx # A[0]*B[2] \n\t"
- "adcq %%r12, %%rax \n\t"
- "mulx 24(%2), %%r14, %%rcx # A[0]*B[3] \n\t"
- "adcq %%r14, %%rbx \n\t"
- "adcq $0, %%rcx \n\t"
-
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx (%2), %%r8, %%r9 # A[1]*B[0] \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[1]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[1]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[1]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 8(%0) \n\t"
- "adcq %%rax, %%r9 \n\t"
- "movq %%r9, 16(%0) \n\t"
- "movq $0, %%rax \n\t"
- "adcq %%r11, %%rbx \n\t"
- "adcq %%r13, %%rcx \n\t"
- "adcq %%rdx, %%rax \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx (%2), %%r8, %%r9 # A[2]*B[0] \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[2]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[2]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[2]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 16(%0) \n\t"
- "adcq %%rbx, %%r9 \n\t"
- "movq %%r9, 24(%0) \n\t"
- "movq $0, %%rbx \n\t"
- "adcq %%r11, %%rcx \n\t"
- "adcq %%r13, %%rax \n\t"
- "adcq %%rdx, %%rbx \n\t"
-
- "movq 24(%1), %%rdx # A[3] \n\t"
- "mulx (%2), %%r8, %%r9 # A[3]*B[0] \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[3]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[3]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[3]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 24(%0) \n\t"
- "adcq %%rcx, %%r9 \n\t"
- "movq %%r9, 32(%0) \n\t"
- "movq $0, %%rcx \n\t"
- "adcq %%r11, %%rax \n\t"
- "movq %%rax, 40(%0) \n\t"
- "adcq %%r13, %%rbx \n\t"
- "movq %%rbx, 48(%0) \n\t"
- "adcq %%rdx, %%rcx \n\t"
- "movq %%rcx, 56(%0) \n\t"
-
- "movq 32(%1), %%rdx # A[0] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[0]*B[0] \n\t"
- "movq %%r8, 64(%0) \n\t"
- "mulx 40(%2), %%r10, %%rax # A[0]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "movq %%r9, 72(%0) \n\t"
- "mulx 48(%2), %%r12, %%rbx # A[0]*B[2] \n\t"
- "adcq %%r12, %%rax \n\t"
- "mulx 56(%2), %%r14, %%rcx # A[0]*B[3] \n\t"
- "adcq %%r14, %%rbx \n\t"
- "adcq $0, %%rcx \n\t"
-
- "movq 40(%1), %%rdx # A[1] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[1]*B[0] \n\t"
- "mulx 40(%2), %%r10, %%r11 # A[1]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 48(%2), %%r12, %%r13 # A[1]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 56(%2), %%r14, %%rdx # A[1]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 72(%0) \n\t"
- "adcq %%rax, %%r9 \n\t"
- "movq %%r9, 80(%0) \n\t"
- "movq $0, %%rax \n\t"
- "adcq %%r11, %%rbx \n\t"
- "adcq %%r13, %%rcx \n\t"
- "adcq %%rdx, %%rax \n\t"
-
- "movq 48(%1), %%rdx # A[2] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[2]*B[0] \n\t"
- "mulx 40(%2), %%r10, %%r11 # A[2]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 48(%2), %%r12, %%r13 # A[2]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 56(%2), %%r14, %%rdx # A[2]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 80(%0) \n\t"
- "adcq %%rbx, %%r9 \n\t"
- "movq %%r9, 88(%0) \n\t"
- "movq $0, %%rbx \n\t"
- "adcq %%r11, %%rcx \n\t"
- "adcq %%r13, %%rax \n\t"
- "adcq %%rdx, %%rbx \n\t"
-
- "movq 56(%1), %%rdx # A[3] \n\t"
- "mulx 32(%2), %%r8, %%r9 # A[3]*B[0] \n\t"
- "mulx 40(%2), %%r10, %%r11 # A[3]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 48(%2), %%r12, %%r13 # A[3]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 56(%2), %%r14, %%rdx # A[3]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 88(%0) \n\t"
- "adcq %%rcx, %%r9 \n\t"
- "movq %%r9, 96(%0) \n\t"
- "movq $0, %%rcx \n\t"
- "adcq %%r11, %%rax \n\t"
- "movq %%rax, 104(%0) \n\t"
- "adcq %%r13, %%rbx \n\t"
- "movq %%rbx, 112(%0) \n\t"
- "adcq %%rdx, %%rcx \n\t"
- "movq %%rcx, 120(%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(b)
- : "memory", "cc", "%rax", "%rbx", "%rcx", "%rdx", "%r8",
- "%r9", "%r10", "%r11", "%r12", "%r13", "%r14");
-#endif
-}
-
-static void sqr2_256x256_integer_x64(u64 *const c, u64 *const a)
-{
- __asm__ __volatile__(
- "movq (%1), %%rdx # A[0] \n\t"
- "mulx %%rdx, %%r8, %%r9 # A[0]^2 \n\t"
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx %%rdx, %%r10, %%r11 # A[1]^2 \n\t"
- "movq %%r8, (%0) \n\t"
- "movq %%r9, 8(%0) \n\t"
- "movq %%r10, 16(%0) \n\t"
- "movq %%r11, 24(%0) \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx %%rdx, %%r8, %%r9 # A[2]^2 \n\t"
- "movq 24(%1), %%rdx # A[3] \n\t"
- "mulx %%rdx, %%r10, %%r11 # A[3]^2 \n\t"
- "movq %%r8, 32(%0) \n\t"
- "movq %%r9, 40(%0) \n\t"
- "movq %%r10, 48(%0) \n\t"
- "movq %%r11, 56(%0) \n\t"
-
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx (%1), %%r8, %%r9 # A[0]*A[1] \n\t"
- "mulx 16(%1), %%r10, %%r11 # A[2]*A[1] \n\t"
- "mulx 24(%1), %%rcx, %%r14 # A[3]*A[1] \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx 24(%1), %%r12, %%r13 # A[3]*A[2] \n\t"
- "mulx (%1), %%rax, %%rdx # A[0]*A[2] \n\t"
-
- "addq %%rax, %%r9 \n\t"
- "adcq %%rdx, %%r10 \n\t"
- "adcq %%rcx, %%r11 \n\t"
- "adcq %%r14, %%r12 \n\t"
- "adcq $0, %%r13 \n\t"
- "movq $0, %%r14 \n\t"
- "adcq $0, %%r14 \n\t"
-
- "movq (%1), %%rdx # A[0] \n\t"
- "mulx 24(%1), %%rax, %%rdx # A[0]*A[3] \n\t"
-
- "addq %%rax, %%r10 \n\t"
- "adcq %%rdx, %%r11 \n\t"
- "adcq $0, %%r12 \n\t"
- "adcq $0, %%r13 \n\t"
- "adcq $0, %%r14 \n\t"
-
- "shldq $1, %%r13, %%r14 \n\t"
- "shldq $1, %%r12, %%r13 \n\t"
- "shldq $1, %%r11, %%r12 \n\t"
- "shldq $1, %%r10, %%r11 \n\t"
- "shldq $1, %%r9, %%r10 \n\t"
- "shldq $1, %%r8, %%r9 \n\t"
- "shlq $1, %%r8 \n\t"
-
- "addq 8(%0), %%r8 \n\t"
- "movq %%r8, 8(%0) \n\t"
- "adcq 16(%0), %%r9 \n\t"
- "movq %%r9, 16(%0) \n\t"
- "adcq 24(%0), %%r10 \n\t"
- "movq %%r10, 24(%0) \n\t"
- "adcq 32(%0), %%r11 \n\t"
- "movq %%r11, 32(%0) \n\t"
- "adcq 40(%0), %%r12 \n\t"
- "movq %%r12, 40(%0) \n\t"
- "adcq 48(%0), %%r13 \n\t"
- "movq %%r13, 48(%0) \n\t"
- "adcq 56(%0), %%r14 \n\t"
- "movq %%r14, 56(%0) \n\t"
-
-
- "movq 32(%1), %%rdx # A[0] \n\t"
- "mulx %%rdx, %%r8, %%r9 # A[0]^2 \n\t"
- "movq 40(%1), %%rdx # A[1] \n\t"
- "mulx %%rdx, %%r10, %%r11 # A[1]^2 \n\t"
- "movq %%r8, 64(%0) \n\t"
- "movq %%r9, 72(%0) \n\t"
- "movq %%r10, 80(%0) \n\t"
- "movq %%r11, 88(%0) \n\t"
-
- "movq 48(%1), %%rdx # A[2] \n\t"
- "mulx %%rdx, %%r8, %%r9 # A[2]^2 \n\t"
- "movq 56(%1), %%rdx # A[3] \n\t"
- "mulx %%rdx, %%r10, %%r11 # A[3]^2 \n\t"
- "movq %%r8, 96(%0) \n\t"
- "movq %%r9, 104(%0) \n\t"
- "movq %%r10, 112(%0) \n\t"
- "movq %%r11, 120(%0) \n\t"
-
- "movq 40(%1), %%rdx # A[1] \n\t"
- "mulx 32(%1), %%r8, %%r9 # A[0]*A[1] \n\t"
- "mulx 48(%1), %%r10, %%r11 # A[2]*A[1] \n\t"
- "mulx 56(%1), %%rcx, %%r14 # A[3]*A[1] \n\t"
-
- "movq 48(%1), %%rdx # A[2] \n\t"
- "mulx 56(%1), %%r12, %%r13 # A[3]*A[2] \n\t"
- "mulx 32(%1), %%rax, %%rdx # A[0]*A[2] \n\t"
-
- "addq %%rax, %%r9 \n\t"
- "adcq %%rdx, %%r10 \n\t"
- "adcq %%rcx, %%r11 \n\t"
- "adcq %%r14, %%r12 \n\t"
- "adcq $0, %%r13 \n\t"
- "movq $0, %%r14 \n\t"
- "adcq $0, %%r14 \n\t"
-
- "movq 32(%1), %%rdx # A[0] \n\t"
- "mulx 56(%1), %%rax, %%rdx # A[0]*A[3] \n\t"
-
- "addq %%rax, %%r10 \n\t"
- "adcq %%rdx, %%r11 \n\t"
- "adcq $0, %%r12 \n\t"
- "adcq $0, %%r13 \n\t"
- "adcq $0, %%r14 \n\t"
-
- "shldq $1, %%r13, %%r14 \n\t"
- "shldq $1, %%r12, %%r13 \n\t"
- "shldq $1, %%r11, %%r12 \n\t"
- "shldq $1, %%r10, %%r11 \n\t"
- "shldq $1, %%r9, %%r10 \n\t"
- "shldq $1, %%r8, %%r9 \n\t"
- "shlq $1, %%r8 \n\t"
-
- "addq 72(%0), %%r8 \n\t"
- "movq %%r8, 72(%0) \n\t"
- "adcq 80(%0), %%r9 \n\t"
- "movq %%r9, 80(%0) \n\t"
- "adcq 88(%0), %%r10 \n\t"
- "movq %%r10, 88(%0) \n\t"
- "adcq 96(%0), %%r11 \n\t"
- "movq %%r11, 96(%0) \n\t"
- "adcq 104(%0), %%r12 \n\t"
- "movq %%r12, 104(%0) \n\t"
- "adcq 112(%0), %%r13 \n\t"
- "movq %%r13, 112(%0) \n\t"
- "adcq 120(%0), %%r14 \n\t"
- "movq %%r14, 120(%0) \n\t"
- :
- : "r"(c), "r"(a)
- : "cc", "%rax", "%rcx", "%rdx",
- "%r8", "%r9", "%r10", "%r11",
- "%r12", "%r13", "%r14");
-}
-
-static void red_EltFp25519_2w_x64(u64 *const c, u64 *const a)
-{
-#ifdef __ADX__
- __asm__ __volatile__(
- "movl $38, %%edx # 2*c = 38 = 2^256 \n\t"
- "mulx 32(%1), %%r8, %%r10 # c*C[4] \n\t"
- "xorl %%ebx, %%ebx \n\t"
- "adox (%1), %%r8 \n\t"
- "mulx 40(%1), %%r9, %%r11 # c*C[5] \n\t"
- "adcx %%r10, %%r9 \n\t"
- "adox 8(%1), %%r9 \n\t"
- "mulx 48(%1), %%r10, %%rax # c*C[6] \n\t"
- "adcx %%r11, %%r10 \n\t"
- "adox 16(%1), %%r10 \n\t"
- "movq %%r10, 16(%0) \n\t"
- "mulx 56(%1), %%r11, %%rcx # c*C[7] \n\t"
- "adcx %%rax, %%r11 \n\t"
- "adox 24(%1), %%r11 \n\t"
- "movq %%r11, 24(%0) \n\t"
- "adcx %%rbx, %%rcx \n\t"
- "adox %%rbx, %%rcx \n\t"
- "xorl %%ebx, %%ebx \n\t"
- "mulx %%rcx, %%rax, %%rcx \n\t"
- "adcx %%rax, %%r8 \n\t"
- "movq %%r8, (%0) \n\t"
- "adcx %%rcx, %%r9 \n\t"
- "movq %%r9, 8(%0) \n\t"
-
- "mulx 96(%1), %%r8, %%r10 # c*C[4] \n\t"
- "xorl %%ebx, %%ebx \n\t"
- "adox 64(%1), %%r8 \n\t"
- "mulx 104(%1), %%r9, %%r11 # c*C[5] \n\t"
- "adcx %%r10, %%r9 \n\t"
- "adox 72(%1), %%r9 \n\t"
- "mulx 112(%1), %%r10, %%rax # c*C[6] \n\t"
- "adcx %%r11, %%r10 \n\t"
- "adox 80(%1), %%r10 \n\t"
- "movq %%r10, 48(%0) \n\t"
- "mulx 120(%1), %%r11, %%rcx # c*C[7] \n\t"
- "adcx %%rax, %%r11 \n\t"
- "adox 88(%1), %%r11 \n\t"
- "movq %%r11, 56(%0) \n\t"
- "adcx %%rbx, %%rcx \n\t"
- "adox %%rbx, %%rcx \n\t"
- "xorl %%ebx, %%ebx \n\t"
- "mulx %%rcx, %%rax, %%rcx \n\t"
- "adcx %%rax, %%r8 \n\t"
- "movq %%r8, 32(%0) \n\t"
- "adcx %%rcx, %%r9 \n\t"
- "movq %%r9, 40(%0) \n\t"
- :
- : "r"(c), "r"(a)
- : "cc", "%rax", "%rbx", "%rcx", "%rdx", "%r8", "%r9", "%r10", "%r11");
-#else
- __asm__ __volatile__(
- "movl $38, %%edx # 2*c = 38 = 2^256 \n\t"
- "mulx 32(%1), %%r8, %%r9 # c*C[4] \n\t"
- "mulx 40(%1), %%r10, %%r11 # c*C[5] \n\t"
- "addq %%r9, %%r10 \n\t"
- "mulx 48(%1), %%r12, %%r13 # c*C[6] \n\t"
- "adcq %%r11, %%r12 \n\t"
- "mulx 56(%1), %%rax, %%rcx # c*C[7] \n\t"
- "adcq %%r13, %%rax \n\t"
- "adcq $0, %%rcx \n\t"
-
- "addq (%1), %%r8 \n\t"
- "adcq 8(%1), %%r10 \n\t"
- "adcq 16(%1), %%r12 \n\t"
- "movq %%r12, 16(%0) \n\t"
- "adcq 24(%1), %%rax \n\t"
- "movq %%rax, 24(%0) \n\t"
- "adcq $0, %%rcx \n\t"
-
- "mulx %%rcx, %%rax, %%rcx \n\t"
- "addq %%rax, %%r8 \n\t"
- "movq %%r8, (%0) \n\t"
- "adcq %%rcx, %%r10 \n\t"
- "movq %%r10, 8(%0) \n\t"
-
- "mulx 96(%1), %%r8, %%r9 # c*C[4] \n\t"
- "mulx 104(%1), %%r10, %%r11 # c*C[5] \n\t"
- "addq %%r9, %%r10 \n\t"
- "mulx 112(%1), %%r12, %%r13 # c*C[6] \n\t"
- "adcq %%r11, %%r12 \n\t"
- "mulx 120(%1), %%rax, %%rcx # c*C[7] \n\t"
- "adcq %%r13, %%rax \n\t"
- "adcq $0, %%rcx \n\t"
-
- "addq 64(%1), %%r8 \n\t"
- "adcq 72(%1), %%r10 \n\t"
- "adcq 80(%1), %%r12 \n\t"
- "movq %%r12, 48(%0) \n\t"
- "adcq 88(%1), %%rax \n\t"
- "movq %%rax, 56(%0) \n\t"
- "adcq $0, %%rcx \n\t"
-
- "mulx %%rcx, %%rax, %%rcx \n\t"
- "addq %%rax, %%r8 \n\t"
- "movq %%r8, 32(%0) \n\t"
- "adcq %%rcx, %%r10 \n\t"
- "movq %%r10, 40(%0) \n\t"
-
- :
- : "r"(c), "r"(a)
- : "cc", "%rax", "%rbx", "%rcx", "%rdx", "%r8", "%r9", "%r10", "%r11", "%r12", "%r13");
-#endif
-}
-
-static void mul_256x256_integer_x64(u64 *const c, u64 *const a, u64 *const b)
-{
-#ifdef __ADX__
- __asm__ __volatile__(
- "movq (%1), %%rdx # A[0] \n\t"
- "mulx (%2), %%r8, %%r9 # A[0]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "movq %%r8, (%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[0]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "movq %%r10, 8(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[0]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[0]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
-
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx (%2), %%r8, %%r9 # A[1]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 8(%0), %%r8 \n\t"
- "movq %%r8, 8(%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[1]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 16(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[1]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[1]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx (%2), %%r8, %%r9 # A[2]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 16(%0), %%r8 \n\t"
- "movq %%r8, 16(%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[2]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 24(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[2]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[2]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
-
- "movq 24(%1), %%rdx # A[3] \n\t"
- "mulx (%2), %%r8, %%r9 # A[3]*B[0] \n\t"
- "xorl %%r10d, %%r10d \n\t"
- "adcx 24(%0), %%r8 \n\t"
- "movq %%r8, 24(%0) \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[3]*B[1] \n\t"
- "adox %%r9, %%r10 \n\t"
- "adcx %%r12, %%r10 \n\t"
- "movq %%r10, 32(%0) \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[3]*B[2] \n\t"
- "adox %%r11, %%r12 \n\t"
- "adcx %%r14, %%r12 \n\t"
- "movq %%r12, 40(%0) \n\t"
- "movq $0, %%r8 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[3]*B[3] \n\t"
- "adox %%r13, %%r14 \n\t"
- "adcx %%rax, %%r14 \n\t"
- "movq %%r14, 48(%0) \n\t"
- "movq $0, %%rax \n\t"
- "adox %%rdx, %%rax \n\t"
- "adcx %%r8, %%rax \n\t"
- "movq %%rax, 56(%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(b)
- : "memory", "cc", "%rax", "%rdx",
- "%r8", "%r9", "%r10", "%r11",
- "%r12", "%r13", "%r14");
-#else
- __asm__ __volatile__(
- "movq (%1), %%rdx # A[0] \n\t"
- "mulx (%2), %%r8, %%r9 # A[0]*B[0] \n\t"
- "movq %%r8, (%0) \n\t"
- "mulx 8(%2), %%r10, %%rax # A[0]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "movq %%r9, 8(%0) \n\t"
- "mulx 16(%2), %%r12, %%rbx # A[0]*B[2] \n\t"
- "adcq %%r12, %%rax \n\t"
- "mulx 24(%2), %%r14, %%rcx # A[0]*B[3] \n\t"
- "adcq %%r14, %%rbx \n\t"
- "adcq $0, %%rcx \n\t"
-
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx (%2), %%r8, %%r9 # A[1]*B[0] \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[1]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[1]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[1]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 8(%0) \n\t"
- "adcq %%rax, %%r9 \n\t"
- "movq %%r9, 16(%0) \n\t"
- "movq $0, %%rax \n\t"
- "adcq %%r11, %%rbx \n\t"
- "adcq %%r13, %%rcx \n\t"
- "adcq %%rdx, %%rax \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx (%2), %%r8, %%r9 # A[2]*B[0] \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[2]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[2]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[2]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 16(%0) \n\t"
- "adcq %%rbx, %%r9 \n\t"
- "movq %%r9, 24(%0) \n\t"
- "movq $0, %%rbx \n\t"
- "adcq %%r11, %%rcx \n\t"
- "adcq %%r13, %%rax \n\t"
- "adcq %%rdx, %%rbx \n\t"
-
- "movq 24(%1), %%rdx # A[3] \n\t"
- "mulx (%2), %%r8, %%r9 # A[3]*B[0] \n\t"
- "mulx 8(%2), %%r10, %%r11 # A[3]*B[1] \n\t"
- "addq %%r10, %%r9 \n\t"
- "mulx 16(%2), %%r12, %%r13 # A[3]*B[2] \n\t"
- "adcq %%r12, %%r11 \n\t"
- "mulx 24(%2), %%r14, %%rdx # A[3]*B[3] \n\t"
- "adcq %%r14, %%r13 \n\t"
- "adcq $0, %%rdx \n\t"
-
- "addq %%r8, 24(%0) \n\t"
- "adcq %%rcx, %%r9 \n\t"
- "movq %%r9, 32(%0) \n\t"
- "movq $0, %%rcx \n\t"
- "adcq %%r11, %%rax \n\t"
- "movq %%rax, 40(%0) \n\t"
- "adcq %%r13, %%rbx \n\t"
- "movq %%rbx, 48(%0) \n\t"
- "adcq %%rdx, %%rcx \n\t"
- "movq %%rcx, 56(%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(b)
- : "memory", "cc", "%rax", "%rbx", "%rcx", "%rdx", "%r8",
- "%r9", "%r10", "%r11", "%r12", "%r13", "%r14");
-#endif
-}
-
-static void sqr_256x256_integer_x64(u64 *const c, u64 *const a)
-{
- __asm__ __volatile__(
- "movq (%1), %%rdx # A[0] \n\t"
- "mulx %%rdx, %%r8, %%r9 # A[0]^2 \n\t"
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx %%rdx, %%r10, %%r11 # A[1]^2 \n\t"
- "movq %%r8, (%0) \n\t"
- "movq %%r9, 8(%0) \n\t"
- "movq %%r10, 16(%0) \n\t"
- "movq %%r11, 24(%0) \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx %%rdx, %%r8, %%r9 # A[2]^2 \n\t"
- "movq 24(%1), %%rdx # A[3] \n\t"
- "mulx %%rdx, %%r10, %%r11 # A[3]^2 \n\t"
- "movq %%r8, 32(%0) \n\t"
- "movq %%r9, 40(%0) \n\t"
- "movq %%r10, 48(%0) \n\t"
- "movq %%r11, 56(%0) \n\t"
-
- "movq 8(%1), %%rdx # A[1] \n\t"
- "mulx (%1), %%r8, %%r9 # A[0]*A[1] \n\t"
- "mulx 16(%1), %%r10, %%r11 # A[2]*A[1] \n\t"
- "mulx 24(%1), %%rcx, %%r14 # A[3]*A[1] \n\t"
-
- "movq 16(%1), %%rdx # A[2] \n\t"
- "mulx 24(%1), %%r12, %%r13 # A[3]*A[2] \n\t"
- "mulx (%1), %%rax, %%rdx # A[0]*A[2] \n\t"
-
- " addq %%rax, %%r9 \n\t"
- " adcq %%rdx, %%r10 \n\t"
- " adcq %%rcx, %%r11 \n\t"
- " adcq %%r14, %%r12 \n\t"
- " adcq $0, %%r13 \n\t"
- " movq $0, %%r14 \n\t"
- " adcq $0, %%r14 \n\t"
-
- " movq (%1), %%rdx # A[0] \n\t"
- " mulx 24(%1), %%rax, %%rdx # A[0]*A[3] \n\t"
-
- " addq %%rax, %%r10 \n\t"
- " adcq %%rdx, %%r11 \n\t"
- " adcq $0, %%r12 \n\t"
- " adcq $0, %%r13 \n\t"
- " adcq $0, %%r14 \n\t"
-
- " shldq $1, %%r13, %%r14 \n\t"
- " shldq $1, %%r12, %%r13 \n\t"
- " shldq $1, %%r11, %%r12 \n\t"
- " shldq $1, %%r10, %%r11 \n\t"
- " shldq $1, %%r9, %%r10 \n\t"
- " shldq $1, %%r8, %%r9 \n\t"
- " shlq $1, %%r8 \n\t"
-
- " addq 8(%0), %%r8 \n\t"
- " movq %%r8, 8(%0) \n\t"
- " adcq 16(%0), %%r9 \n\t"
- " movq %%r9, 16(%0) \n\t"
- " adcq 24(%0), %%r10 \n\t"
- " movq %%r10, 24(%0) \n\t"
- " adcq 32(%0), %%r11 \n\t"
- " movq %%r11, 32(%0) \n\t"
- " adcq 40(%0), %%r12 \n\t"
- " movq %%r12, 40(%0) \n\t"
- " adcq 48(%0), %%r13 \n\t"
- " movq %%r13, 48(%0) \n\t"
- " adcq 56(%0), %%r14 \n\t"
- " movq %%r14, 56(%0) \n\t"
- :
- : "r"(c), "r"(a)
- : "memory", "cc", "%rax", "%rcx", "%rdx",
- "%r8", "%r9", "%r10", "%r11",
- "%r12", "%r13", "%r14");
-}
-
-static void red_EltFp25519_1w_x64(u64 *const c, u64 *const a)
-{
-#ifdef __ADX__
- __asm__ __volatile__(
- "movl $38, %%edx # 2*c = 38 = 2^256 \n\t"
- "mulx 32(%1), %%r8, %%r10 # c*C[4] \n\t"
- "xorl %%ebx, %%ebx \n\t"
- "adox (%1), %%r8 \n\t"
- "mulx 40(%1), %%r9, %%r11 # c*C[5] \n\t"
- "adcx %%r10, %%r9 \n\t"
- "adox 8(%1), %%r9 \n\t"
- "mulx 48(%1), %%r10, %%rax # c*C[6] \n\t"
- "adcx %%r11, %%r10 \n\t"
- "adox 16(%1), %%r10 \n\t"
- "movq %%r10, 16(%0) \n\t"
- "mulx 56(%1), %%r11, %%rcx # c*C[7] \n\t"
- "adcx %%rax, %%r11 \n\t"
- "adox 24(%1), %%r11 \n\t"
- "movq %%r11, 24(%0) \n\t"
- "adcx %%rbx, %%rcx \n\t"
- "adox %%rbx, %%rcx \n\t"
- "xorl %%ebx, %%ebx \n\t"
- "mulx %%rcx, %%rax, %%rcx \n\t"
- "adcx %%rax, %%r8 \n\t"
- "movq %%r8, (%0) \n\t"
- "adcx %%rcx, %%r9 \n\t"
- "movq %%r9, 8(%0) \n\t"
- :
- : "r"(c), "r"(a)
- : "memory", "cc", "%rax", "%rbx", "%rcx", "%rdx", "%r8", "%r9", "%r10", "%r11");
-#else
- __asm__ __volatile__(
- "movl $38, %%edx # 2*c = 38 = 2^256 \n\t"
- "mulx 32(%1), %%r8, %%r9 # c*C[4] \n\t"
- "mulx 40(%1), %%r10, %%r11 # c*C[5] \n\t"
- "addq %%r9, %%r10 \n\t"
- "mulx 48(%1), %%r12, %%r13 # c*C[6] \n\t"
- "adcq %%r11, %%r12 \n\t"
- "mulx 56(%1), %%rax, %%rcx # c*C[7] \n\t"
- "adcq %%r13, %%rax \n\t"
- "adcq $0, %%rcx \n\t"
-
- "addq (%1), %%r8 \n\t"
- "adcq 8(%1), %%r10 \n\t"
- "adcq 16(%1), %%r12 \n\t"
- "movq %%r12, 16(%0) \n\t"
- "adcq 24(%1), %%rax \n\t"
- "movq %%rax, 24(%0) \n\t"
- "adcq $0, %%rcx \n\t"
-
- "mulx %%rcx, %%rax, %%rcx \n\t"
- "addq %%rax, %%r8 \n\t"
- "movq %%r8, (%0) \n\t"
- "adcq %%rcx, %%r10 \n\t"
- "movq %%r10, 8(%0) \n\t"
- :
- : "r"(c), "r"(a)
- : "memory", "cc", "%rax", "%rbx", "%rcx", "%rdx", "%r8", "%r9", "%r10", "%r11", "%r12", "%r13");
-#endif
-}
-
-static inline void add_EltFp25519_1w_x64(u64 *const c, u64 *const a, u64 *const b)
-{
-#ifdef __ADX__
- __asm__ __volatile__(
- "movq (%2), %%rax \n\t"
- "movq 8(%2), %%rcx \n\t"
- "movq 16(%2), %%r8 \n\t"
- "movq 24(%2), %%r9 \n\t"
- "clc \n\t"
- "adcx (%1), %%rax \n\t"
- "adcx 8(%1), %%rcx \n\t"
- "adcx 16(%1), %%r8 \n\t"
- "adcx 24(%1), %%r9 \n\t"
- "movq %%rcx, 8(%0) \n\t"
- "movq %%r8 , 16(%0) \n\t"
- "movq %%r9 , 24(%0) \n\t"
- "setc %%cl \n\t"
- "neg %%rcx \n\t"
- "andq $38, %%rcx \n\t"
- "addq %%rcx, %%rax \n\t"
- "movq %%rax, (%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(b)
- : "memory", "cc", "%rax", "%rcx", "%r8", "%r9");
-#else
- __asm__ __volatile__(
- "movq (%2), %%rax \n\t"
- "movq 8(%2), %%rcx \n\t"
- "movq 16(%2), %%r8 \n\t"
- "movq 24(%2), %%r9 \n\t"
- "add (%1), %%rax \n\t"
- "adc 8(%1), %%rcx \n\t"
- "adc 16(%1), %%r8 \n\t"
- "adc 24(%1), %%r9 \n\t"
- "movq %%rcx, 8(%0) \n\t"
- "movq %%r8 , 16(%0) \n\t"
- "movq %%r9 , 24(%0) \n\t"
- "setc %%cl \n\t"
- "neg %%rcx \n\t"
- "andq $38, %%rcx \n\t"
- "addq %%rcx, %%rax \n\t"
- "movq %%rax, (%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(b)
- : "memory", "cc", "%rax", "%rcx", "%r8", "%r9");
-#endif
-}
-
-static inline void sub_EltFp25519_1w_x64(u64 *const __restrict c, u64 *const __restrict a, u64 *const __restrict b)
-{
- __asm__ __volatile__(
- "movq (%1), %%rax \n\t"
- "movq 8(%1), %%rcx \n\t"
- "movq 16(%1), %%r8 \n\t"
- "movq 24(%1), %%r9 \n\t"
- "subq (%2), %%rax \n\t"
- "sbbq 8(%2), %%rcx \n\t"
- "sbbq 16(%2), %%r8 \n\t"
- "sbbq 24(%2), %%r9 \n\t"
- "movq %%rcx, 8(%0) \n\t"
- "movq %%r8 , 16(%0) \n\t"
- "movq %%r9 , 24(%0) \n\t"
- "setc %%cl \n\t"
- "neg %%rcx \n\t"
- "andq $38, %%rcx \n\t"
- "subq %%rcx, %%rax \n\t"
- "movq %%rax, (%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(b)
- : "memory", "cc", "%rax", "%rcx", "%r8", "%r9");
-}
-
-static inline void mul_a24_EltFp25519_1w_x64(u64 *const c, u64 *const a)
-{
- /* a24 = (A+2)/4 = (486662+2)/4 = 121666 */
- const u64 a24 = 121666;
- __asm__ __volatile__(
- "movq %2, %%rdx \n\t"
- "mulx (%1), %%rax, %%r8 \n\t"
- "mulx 8(%1), %%rcx, %%r9 \n\t"
- "movq %%rax, (%0) \n\t"
- "movq %%rcx, 8(%0) \n\t"
- "mulx 16(%1), %%rax, %%r10 \n\t"
- "mulx 24(%1), %%rcx, %%r11 \n\t"
- "movq %%rax, 16(%0) \n\t"
- "movq %%rcx, 24(%0) \n\t"
- "movq $38, %%rdx \n\t"
- "mulx %%r11, %%rax, %%rcx \n\t"
- "addq %%rax, (%0) \n\t"
- "adcq %%r8, 8(%0) \n\t"
- "adcq %%r9, 16(%0) \n\t"
- "adcq %%r10, 24(%0) \n\t"
- :
- : "r"(c), "r"(a), "r"(a24)
- : "cc", "%rax", "%rcx", "%rdx", "%r8", "%r9", "%r10", "%r11");
-}
-
-static void inv_EltFp25519_1w_x64(u64 *const pC, u64 *const pA)
-{
-#define sqrn_EltFp25519_1w_x64(a, times) \
- counter = times; \
- while (counter-- > 0) { \
- sqr_EltFp25519_1w_x64(a); \
- }
-
- EltFp25519_1w_Buffer_x64 buffer_1w;
- EltFp25519_1w_x64 x0, x1, x2;
- u64 *T[5];
- u64 counter;
-
- T[0] = x0;
- T[1] = pC; /* x^(-1) */
- T[2] = x1;
- T[3] = x2;
- T[4] = pA; /* x */
-
- copy_EltFp25519_1w_x64(T[1], pA);
- sqrn_EltFp25519_1w_x64(T[1], 1);
- copy_EltFp25519_1w_x64(T[2], T[1]);
- sqrn_EltFp25519_1w_x64(T[2], 2);
- mul_EltFp25519_1w_x64(T[0], pA, T[2]);
- mul_EltFp25519_1w_x64(T[1], T[1], T[0]);
- copy_EltFp25519_1w_x64(T[2], T[1]);
- sqrn_EltFp25519_1w_x64(T[2], 1);
- mul_EltFp25519_1w_x64(T[0], T[0], T[2]);
- copy_EltFp25519_1w_x64(T[2], T[0]);
- sqrn_EltFp25519_1w_x64(T[2], 5);
- mul_EltFp25519_1w_x64(T[0], T[0], T[2]);
- copy_EltFp25519_1w_x64(T[2], T[0]);
- sqrn_EltFp25519_1w_x64(T[2], 10);
- mul_EltFp25519_1w_x64(T[2], T[2], T[0]);
- copy_EltFp25519_1w_x64(T[3], T[2]);
- sqrn_EltFp25519_1w_x64(T[3], 20);
- mul_EltFp25519_1w_x64(T[3], T[3], T[2]);
- sqrn_EltFp25519_1w_x64(T[3], 10);
- mul_EltFp25519_1w_x64(T[3], T[3], T[0]);
- copy_EltFp25519_1w_x64(T[0], T[3]);
- sqrn_EltFp25519_1w_x64(T[0], 50);
- mul_EltFp25519_1w_x64(T[0], T[0], T[3]);
- copy_EltFp25519_1w_x64(T[2], T[0]);
- sqrn_EltFp25519_1w_x64(T[2], 100);
- mul_EltFp25519_1w_x64(T[2], T[2], T[0]);
- sqrn_EltFp25519_1w_x64(T[2], 50);
- mul_EltFp25519_1w_x64(T[2], T[2], T[3]);
- sqrn_EltFp25519_1w_x64(T[2], 5);
- mul_EltFp25519_1w_x64(T[1], T[1], T[2]);
-#undef sqrn_EltFp25519_1w_x64
-}
-
-static inline void fred_EltFp25519_1w_x64(u64 *const c)
-{
- s64 last = (((s64 *)c)[3]) >> 63;
- c[3] &= (1ULL << 63) - 1;
- c[0] += 19 & last;
-}
-
-static inline void cswap_x64(u64 bit, u64 *const px, u64 *const py)
-{
- int i = 0;
- u64 mask = 0ULL - bit;
- for (i = 0; i < NUM_WORDS_ELTFP25519_X64; ++i) {
- u64 t = mask & (px[i] ^ py[i]);
- px[i] = px[i] ^ t;
- py[i] = py[i] ^ t;
- }
-}
-
-static __always_inline void reduce_point_mod_2_255_19(u64 *p)
-{
- __asm__ __volatile__ (
- "cmpq $-19, %0\n"
- "setaeb %%al\n"
- "cmpq $-1, %1\n"
- "setzb %%bl\n"
- "cmpq $-1, %2\n"
- "setzb %%cl\n"
- "leaq 1(%3), %%rdx\n"
- "shrq $63, %%rdx\n"
- "andb %%bl, %%al\n"
- "andb %%dl, %%cl\n"
- "testb %%cl, %%al\n"
- "movl $0, %%eax\n"
- "movl $19, %%ecx\n"
- "cmovnzq %%rcx, %%rax\n"
- "addq %%rax, %0\n"
- "adcq $0, %1\n"
- "adcq $0, %2\n"
- "adcq $0, %3\n"
- "btrq $63, %3\n"
- : "+r"(p[0]), "+r"(p[1]), "+r"(p[2]), "+r"(p[3])
- :
- : "memory", "cc", "%rax", "%rbx", "%rcx", "%rdx"
- );
-}
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-bool curve25519_precomp(u8 shared[CURVE25519_POINT_SIZE], const u8 private[CURVE25519_POINT_SIZE], const u8 session[CURVE25519_POINT_SIZE])
-{
- __aligned(32) u64 buffer[4 * NUM_WORDS_ELTFP25519_X64];
- __aligned(32) u64 coordinates[4 * NUM_WORDS_ELTFP25519_X64];
- __aligned(32) u64 workspace[6 * NUM_WORDS_ELTFP25519_X64];
- __aligned(32) u8 private_key[CURVE25519_POINT_SIZE];
- __aligned(32) u8 session_key[CURVE25519_POINT_SIZE];
-
- int i = 0, j = 0;
- u64 prev = 0;
- u64 *const X1 = (u64 *)session_key;
- u64 *const key = (u64 *)private_key;
- u64 *const Px = coordinates + 0;
- u64 *const Pz = coordinates + 4;
- u64 *const Qx = coordinates + 8;
- u64 *const Qz = coordinates + 12;
- u64 *const X2 = Qx;
- u64 *const Z2 = Qz;
- u64 *const X3 = Px;
- u64 *const Z3 = Pz;
- u64 *const X2Z2 = Qx;
- u64 *const X3Z3 = Px;
-
- u64 *const A = workspace + 0;
- u64 *const B = workspace + 4;
- u64 *const D = workspace + 8;
- u64 *const C = workspace + 12;
- u64 *const DA = workspace + 16;
- u64 *const CB = workspace + 20;
- u64 *const AB = A;
- u64 *const DC = D;
- u64 *const DACB = DA;
- u64 *const buffer_1w = buffer;
- u64 *const buffer_2w = buffer;
-
- memcpy(session_key, session, sizeof(session_key));
- memcpy(private_key, private, sizeof(private_key));
- normalize_secret(private_key);
-
- /* As in the draft:
- * When receiving such an array, implementations of curve25519
- * MUST mask the most-significant bit in the final byte. This
- * is done to preserve compatibility with point formats which
- * reserve the sign bit for use in other protocols and to
- * increase resistance to implementation fingerprinting
- */
- session_key[CURVE25519_POINT_SIZE - 1] &= (1 << (255 % 8)) - 1;
- reduce_point_mod_2_255_19((u64 *)session_key);
- copy_EltFp25519_1w_x64(Px, (u64 *)session_key);
-
- setzero_EltFp25519_1w_x64(Pz);
- setzero_EltFp25519_1w_x64(Qx);
- setzero_EltFp25519_1w_x64(Qz);
-
- Pz[0] = 1;
- Qx[0] = 1;
-
- /* main-loop */
- prev = 0;
- j = 62;
- for (i = 3; i >= 0; --i) {
- while (j >= 0) {
- u64 bit = (key[i] >> j) & 0x1;
- u64 swap = bit ^ prev;
- prev = bit;
-
- add_EltFp25519_1w_x64(A, X2, Z2); /* A = (X2+Z2) */
- sub_EltFp25519_1w_x64(B, X2, Z2); /* B = (X2-Z2) */
- add_EltFp25519_1w_x64(C, X3, Z3); /* C = (X3+Z3) */
- sub_EltFp25519_1w_x64(D, X3, Z3); /* D = (X3-Z3) */
- mul_EltFp25519_2w_x64(DACB, AB, DC); /* [DA|CB] = [A|B]*[D|C] */
-
- cswap_x64(swap, A, C);
- cswap_x64(swap, B, D);
-
- sqr_EltFp25519_2w_x64(AB); /* [AA|BB] = [A^2|B^2] */
- add_EltFp25519_1w_x64(X3, DA, CB); /* X3 = (DA+CB) */
- sub_EltFp25519_1w_x64(Z3, DA, CB); /* Z3 = (DA-CB) */
- sqr_EltFp25519_2w_x64(X3Z3); /* [X3|Z3] = [(DA+CB)|(DA+CB)]^2 */
-
- copy_EltFp25519_1w_x64(X2, B); /* X2 = B^2 */
- sub_EltFp25519_1w_x64(Z2, A, B); /* Z2 = E = AA-BB */
- mul_a24_EltFp25519_1w_x64(B, Z2); /* B = a24*E */
- add_EltFp25519_1w_x64(B, B, X2); /* B = a24*E+B */
- mul_EltFp25519_2w_x64(X2Z2, X2Z2, AB); /* [X2|Z2] = [B|E]*[A|a24*E+B] */
- mul_EltFp25519_1w_x64(Z3, Z3, X1); /* Z3 = Z3*X1 */
-
- --j;
- }
- j = 63;
- }
-
- inv_EltFp25519_1w_x64(A, Qz);
- mul_EltFp25519_1w_x64((u64 *)shared, Qx, A);
- fred_EltFp25519_1w_x64((u64 *)shared);
-
- return true;
-}
-
-bool curve25519_precomp_generate_public(u8 session_key[CURVE25519_POINT_SIZE], const u8 private[CURVE25519_POINT_SIZE])
-{
- __aligned(32) u64 buffer[4 * NUM_WORDS_ELTFP25519_X64];
- __aligned(32) u64 coordinates[4 * NUM_WORDS_ELTFP25519_X64];
- __aligned(32) u64 workspace[4 * NUM_WORDS_ELTFP25519_X64];
- __aligned(32) u8 private_key[CURVE25519_POINT_SIZE];
-
- int i = 0, j = 0, k = 0;
- u64 *const key = (u64 *)private_key;
- u64 *const Ur1 = coordinates + 0;
- u64 *const Zr1 = coordinates + 4;
- u64 *const Ur2 = coordinates + 8;
- u64 *const Zr2 = coordinates + 12;
-
- u64 *const UZr1 = coordinates + 0;
- u64 *const ZUr2 = coordinates + 8;
-
- u64 *const A = workspace + 0;
- u64 *const B = workspace + 4;
- u64 *const C = workspace + 8;
- u64 *const D = workspace + 12;
-
- u64 *const AB = workspace + 0;
- u64 *const CD = workspace + 8;
-
- u64 *const buffer_1w = buffer;
- u64 *const buffer_2w = buffer;
- u64 *P = (u64 *)Table_Ladder_8k;
-
- const int ite[4] = { 64, 64, 64, 63 };
- const int q = 3;
- u64 swap = 1;
-
- memcpy(private_key, private, sizeof(private_key));
- normalize_secret(private_key);
-
- setzero_EltFp25519_1w_x64(Ur1);
- setzero_EltFp25519_1w_x64(Zr1);
- setzero_EltFp25519_1w_x64(Zr2);
- Ur1[0] = 1;
- Zr1[0] = 1;
- Zr2[0] = 1;
-
- /* G-S */
- Ur2[3] = 0x1eaecdeee27cab34ULL;
- Ur2[2] = 0xadc7a0b9235d48e2ULL;
- Ur2[1] = 0xbbf095ae14b2edf8ULL;
- Ur2[0] = 0x7e94e1fec82faabdULL;
-
- /* main-loop */
- j = q;
- for (i = 0; i < NUM_WORDS_ELTFP25519_X64; ++i) {
- while (j < ite[i]) {
- u64 bit;
- k = (64 * i + j - q);
- bit = (key[i] >> j) & 0x1;
- swap = swap ^ bit;
- cswap_x64(swap, Ur1, Ur2);
- cswap_x64(swap, Zr1, Zr2);
- swap = bit;
- /* Addition */
- sub_EltFp25519_1w_x64(B, Ur1, Zr1); /* B = Ur1-Zr1 */
- add_EltFp25519_1w_x64(A, Ur1, Zr1); /* A = Ur1+Zr1 */
- mul_EltFp25519_1w_x64(C, &P[4 * k], B); /* C = M0-B */
- sub_EltFp25519_1w_x64(B, A, C); /* B = (Ur1+Zr1) - M*(Ur1-Zr1) */
- add_EltFp25519_1w_x64(A, A, C); /* A = (Ur1+Zr1) + M*(Ur1-Zr1) */
- sqr_EltFp25519_2w_x64(AB); /* A = A^2 | B = B^2 */
- mul_EltFp25519_2w_x64(UZr1, ZUr2, AB); /* Ur1 = Zr2*A | Zr1 = Ur2*B */
- ++j;
- }
- j = 0;
- }
-
- /* Doubling */
- for (i = 0; i < q; ++i) {
- add_EltFp25519_1w_x64(A, Ur1, Zr1); /* A = Ur1+Zr1 */
- sub_EltFp25519_1w_x64(B, Ur1, Zr1); /* B = Ur1-Zr1 */
- sqr_EltFp25519_2w_x64(AB); /* A = A**2 B = B**2 */
- copy_EltFp25519_1w_x64(C, B); /* C = B */
- sub_EltFp25519_1w_x64(B, A, B); /* B = A-B */
- mul_a24_EltFp25519_1w_x64(D, B); /* D = my_a24*B */
- add_EltFp25519_1w_x64(D, D, C); /* D = D+C */
- mul_EltFp25519_2w_x64(UZr1, AB, CD); /* Ur1 = A*B Zr1 = Zr1*A */
- }
-
- /* Convert to affine coordinates */
- inv_EltFp25519_1w_x64(A, Zr1);
- mul_EltFp25519_1w_x64((u64 *)session_key, Ur1, A);
- fred_EltFp25519_1w_x64((u64 *)session_key);
-
- return true;
-}
diff --git a/curve25519-sandy2x-asm.S b/curve25519-sandy2x-asm.S
deleted file mode 100644
index f2e466b..0000000
--- a/curve25519-sandy2x-asm.S
+++ /dev/null
@@ -1,3261 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2015-2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * Original author: Tung Chou <blueprint@crypto.tw>
- */
-
-#include <linux/linkage.h>
-
-.data
-.align 16
-curve25519_sandy2x_v0_0: .quad 0, 0
-curve25519_sandy2x_v1_0: .quad 1, 0
-curve25519_sandy2x_v2_1: .quad 2, 1
-curve25519_sandy2x_v9_0: .quad 9, 0
-curve25519_sandy2x_v9_9: .quad 9, 9
-curve25519_sandy2x_v19_19: .quad 19, 19
-curve25519_sandy2x_v38_1: .quad 38, 1
-curve25519_sandy2x_v38_38: .quad 38, 38
-curve25519_sandy2x_v121666_121666: .quad 121666, 121666
-curve25519_sandy2x_m25: .quad 33554431, 33554431
-curve25519_sandy2x_m26: .quad 67108863, 67108863
-curve25519_sandy2x_subc0: .quad 0x07FFFFDA, 0x03FFFFFE
-curve25519_sandy2x_subc2: .quad 0x07FFFFFE, 0x03FFFFFE
-curve25519_sandy2x_REDMASK51: .quad 0x0007FFFFFFFFFFFF
-
-.text
-.align 32
-#ifdef CONFIG_AS_AVX
-ENTRY(curve25519_sandy2x_fe51_mul)
- push %rbp
- mov %rsp,%rbp
- sub $96,%rsp
- and $-32,%rsp
- movq %r11,0(%rsp)
- movq %r12,8(%rsp)
- movq %r13,16(%rsp)
- movq %r14,24(%rsp)
- movq %r15,32(%rsp)
- movq %rbx,40(%rsp)
- movq %rbp,48(%rsp)
- movq %rdi,56(%rsp)
- mov %rdx,%rcx
- movq 24(%rsi),%rdx
- imulq $19,%rdx,%rax
- movq %rax,64(%rsp)
- mulq 16(%rcx)
- mov %rax,%r8
- mov %rdx,%r9
- movq 32(%rsi),%rdx
- imulq $19,%rdx,%rax
- movq %rax,72(%rsp)
- mulq 8(%rcx)
- add %rax,%r8
- adc %rdx,%r9
- movq 0(%rsi),%rax
- mulq 0(%rcx)
- add %rax,%r8
- adc %rdx,%r9
- movq 0(%rsi),%rax
- mulq 8(%rcx)
- mov %rax,%r10
- mov %rdx,%r11
- movq 0(%rsi),%rax
- mulq 16(%rcx)
- mov %rax,%r12
- mov %rdx,%r13
- movq 0(%rsi),%rax
- mulq 24(%rcx)
- mov %rax,%r14
- mov %rdx,%r15
- movq 0(%rsi),%rax
- mulq 32(%rcx)
- mov %rax,%rbx
- mov %rdx,%rbp
- movq 8(%rsi),%rax
- mulq 0(%rcx)
- add %rax,%r10
- adc %rdx,%r11
- movq 8(%rsi),%rax
- mulq 8(%rcx)
- add %rax,%r12
- adc %rdx,%r13
- movq 8(%rsi),%rax
- mulq 16(%rcx)
- add %rax,%r14
- adc %rdx,%r15
- movq 8(%rsi),%rax
- mulq 24(%rcx)
- add %rax,%rbx
- adc %rdx,%rbp
- movq 8(%rsi),%rdx
- imulq $19,%rdx,%rax
- mulq 32(%rcx)
- add %rax,%r8
- adc %rdx,%r9
- movq 16(%rsi),%rax
- mulq 0(%rcx)
- add %rax,%r12
- adc %rdx,%r13
- movq 16(%rsi),%rax
- mulq 8(%rcx)
- add %rax,%r14
- adc %rdx,%r15
- movq 16(%rsi),%rax
- mulq 16(%rcx)
- add %rax,%rbx
- adc %rdx,%rbp
- movq 16(%rsi),%rdx
- imulq $19,%rdx,%rax
- mulq 24(%rcx)
- add %rax,%r8
- adc %rdx,%r9
- movq 16(%rsi),%rdx
- imulq $19,%rdx,%rax
- mulq 32(%rcx)
- add %rax,%r10
- adc %rdx,%r11
- movq 24(%rsi),%rax
- mulq 0(%rcx)
- add %rax,%r14
- adc %rdx,%r15
- movq 24(%rsi),%rax
- mulq 8(%rcx)
- add %rax,%rbx
- adc %rdx,%rbp
- movq 64(%rsp),%rax
- mulq 24(%rcx)
- add %rax,%r10
- adc %rdx,%r11
- movq 64(%rsp),%rax
- mulq 32(%rcx)
- add %rax,%r12
- adc %rdx,%r13
- movq 32(%rsi),%rax
- mulq 0(%rcx)
- add %rax,%rbx
- adc %rdx,%rbp
- movq 72(%rsp),%rax
- mulq 16(%rcx)
- add %rax,%r10
- adc %rdx,%r11
- movq 72(%rsp),%rax
- mulq 24(%rcx)
- add %rax,%r12
- adc %rdx,%r13
- movq 72(%rsp),%rax
- mulq 32(%rcx)
- add %rax,%r14
- adc %rdx,%r15
- movq curve25519_sandy2x_REDMASK51(%rip),%rsi
- shld $13,%r8,%r9
- and %rsi,%r8
- shld $13,%r10,%r11
- and %rsi,%r10
- add %r9,%r10
- shld $13,%r12,%r13
- and %rsi,%r12
- add %r11,%r12
- shld $13,%r14,%r15
- and %rsi,%r14
- add %r13,%r14
- shld $13,%rbx,%rbp
- and %rsi,%rbx
- add %r15,%rbx
- imulq $19,%rbp,%rdx
- add %rdx,%r8
- mov %r8,%rdx
- shr $51,%rdx
- add %r10,%rdx
- mov %rdx,%rcx
- shr $51,%rdx
- and %rsi,%r8
- add %r12,%rdx
- mov %rdx,%r9
- shr $51,%rdx
- and %rsi,%rcx
- add %r14,%rdx
- mov %rdx,%rax
- shr $51,%rdx
- and %rsi,%r9
- add %rbx,%rdx
- mov %rdx,%r10
- shr $51,%rdx
- and %rsi,%rax
- imulq $19,%rdx,%rdx
- add %rdx,%r8
- and %rsi,%r10
- movq %r8,0(%rdi)
- movq %rcx,8(%rdi)
- movq %r9,16(%rdi)
- movq %rax,24(%rdi)
- movq %r10,32(%rdi)
- movq 0(%rsp),%r11
- movq 8(%rsp),%r12
- movq 16(%rsp),%r13
- movq 24(%rsp),%r14
- movq 32(%rsp),%r15
- movq 40(%rsp),%rbx
- movq 48(%rsp),%rbp
- leave
- ret
-ENDPROC(curve25519_sandy2x_fe51_mul)
-
-.align 32
-ENTRY(curve25519_sandy2x_fe51_nsquare)
- push %rbp
- mov %rsp,%rbp
- sub $64,%rsp
- and $-32,%rsp
- movq %r11,0(%rsp)
- movq %r12,8(%rsp)
- movq %r13,16(%rsp)
- movq %r14,24(%rsp)
- movq %r15,32(%rsp)
- movq %rbx,40(%rsp)
- movq %rbp,48(%rsp)
- movq 0(%rsi),%rcx
- movq 8(%rsi),%r8
- movq 16(%rsi),%r9
- movq 24(%rsi),%rax
- movq 32(%rsi),%rsi
- movq %r9,16(%rdi)
- movq %rax,24(%rdi)
- movq %rsi,32(%rdi)
- mov %rdx,%rsi
-
- .align 16
- .Lloop:
- sub $1,%rsi
- mov %rcx,%rax
- mul %rcx
- add %rcx,%rcx
- mov %rax,%r9
- mov %rdx,%r10
- mov %rcx,%rax
- mul %r8
- mov %rax,%r11
- mov %rdx,%r12
- mov %rcx,%rax
- mulq 16(%rdi)
- mov %rax,%r13
- mov %rdx,%r14
- mov %rcx,%rax
- mulq 24(%rdi)
- mov %rax,%r15
- mov %rdx,%rbx
- mov %rcx,%rax
- mulq 32(%rdi)
- mov %rax,%rcx
- mov %rdx,%rbp
- mov %r8,%rax
- mul %r8
- add %r8,%r8
- add %rax,%r13
- adc %rdx,%r14
- mov %r8,%rax
- mulq 16(%rdi)
- add %rax,%r15
- adc %rdx,%rbx
- mov %r8,%rax
- imulq $19, %r8,%r8
- mulq 24(%rdi)
- add %rax,%rcx
- adc %rdx,%rbp
- mov %r8,%rax
- mulq 32(%rdi)
- add %rax,%r9
- adc %rdx,%r10
- movq 16(%rdi),%rax
- mulq 16(%rdi)
- add %rax,%rcx
- adc %rdx,%rbp
- shld $13,%rcx,%rbp
- movq 16(%rdi),%rax
- imulq $38, %rax,%rax
- mulq 24(%rdi)
- add %rax,%r9
- adc %rdx,%r10
- shld $13,%r9,%r10
- movq 16(%rdi),%rax
- imulq $38, %rax,%rax
- mulq 32(%rdi)
- add %rax,%r11
- adc %rdx,%r12
- movq 24(%rdi),%rax
- imulq $19, %rax,%rax
- mulq 24(%rdi)
- add %rax,%r11
- adc %rdx,%r12
- shld $13,%r11,%r12
- movq 24(%rdi),%rax
- imulq $38, %rax,%rax
- mulq 32(%rdi)
- add %rax,%r13
- adc %rdx,%r14
- shld $13,%r13,%r14
- movq 32(%rdi),%rax
- imulq $19, %rax,%rax
- mulq 32(%rdi)
- add %rax,%r15
- adc %rdx,%rbx
- shld $13,%r15,%rbx
- movq curve25519_sandy2x_REDMASK51(%rip),%rdx
- and %rdx,%rcx
- add %rbx,%rcx
- and %rdx,%r9
- and %rdx,%r11
- add %r10,%r11
- and %rdx,%r13
- add %r12,%r13
- and %rdx,%r15
- add %r14,%r15
- imulq $19, %rbp,%rbp
- lea (%r9,%rbp),%r9
- mov %r9,%rax
- shr $51,%r9
- add %r11,%r9
- and %rdx,%rax
- mov %r9,%r8
- shr $51,%r9
- add %r13,%r9
- and %rdx,%r8
- mov %r9,%r10
- shr $51,%r9
- add %r15,%r9
- and %rdx,%r10
- movq %r10,16(%rdi)
- mov %r9,%r10
- shr $51,%r9
- add %rcx,%r9
- and %rdx,%r10
- movq %r10,24(%rdi)
- mov %r9,%r10
- shr $51,%r9
- imulq $19, %r9,%r9
- lea (%rax,%r9),%rcx
- and %rdx,%r10
- movq %r10,32(%rdi)
- cmp $0,%rsi
- jne .Lloop
-
- movq %rcx,0(%rdi)
- movq %r8,8(%rdi)
- movq 0(%rsp),%r11
- movq 8(%rsp),%r12
- movq 16(%rsp),%r13
- movq 24(%rsp),%r14
- movq 32(%rsp),%r15
- movq 40(%rsp),%rbx
- movq 48(%rsp),%rbp
- leave
- ret
-ENDPROC(curve25519_sandy2x_fe51_nsquare)
-
-.align 32
-ENTRY(curve25519_sandy2x_fe51_pack)
- push %rbp
- mov %rsp,%rbp
- sub $32,%rsp
- and $-32,%rsp
- movq %r11,0(%rsp)
- movq %r12,8(%rsp)
- movq 0(%rsi),%rdx
- movq 8(%rsi),%rcx
- movq 16(%rsi),%r8
- movq 24(%rsi),%r9
- movq 32(%rsi),%rsi
- movq curve25519_sandy2x_REDMASK51(%rip),%rax
- lea -18(%rax),%r10
- mov $3,%r11
-
- .align 16
- .Lreduceloop:
- mov %rdx,%r12
- shr $51,%r12
- and %rax,%rdx
- add %r12,%rcx
- mov %rcx,%r12
- shr $51,%r12
- and %rax,%rcx
- add %r12,%r8
- mov %r8,%r12
- shr $51,%r12
- and %rax,%r8
- add %r12,%r9
- mov %r9,%r12
- shr $51,%r12
- and %rax,%r9
- add %r12,%rsi
- mov %rsi,%r12
- shr $51,%r12
- and %rax,%rsi
- imulq $19, %r12,%r12
- add %r12,%rdx
- sub $1,%r11
- ja .Lreduceloop
-
- mov $1,%r12
- cmp %r10,%rdx
- cmovl %r11,%r12
- cmp %rax,%rcx
- cmovne %r11,%r12
- cmp %rax,%r8
- cmovne %r11,%r12
- cmp %rax,%r9
- cmovne %r11,%r12
- cmp %rax,%rsi
- cmovne %r11,%r12
- neg %r12
- and %r12,%rax
- and %r12,%r10
- sub %r10,%rdx
- sub %rax,%rcx
- sub %rax,%r8
- sub %rax,%r9
- sub %rax,%rsi
- mov %rdx,%rax
- and $0xFF,%eax
- movb %al,0(%rdi)
- mov %rdx,%rax
- shr $8,%rax
- and $0xFF,%eax
- movb %al,1(%rdi)
- mov %rdx,%rax
- shr $16,%rax
- and $0xFF,%eax
- movb %al,2(%rdi)
- mov %rdx,%rax
- shr $24,%rax
- and $0xFF,%eax
- movb %al,3(%rdi)
- mov %rdx,%rax
- shr $32,%rax
- and $0xFF,%eax
- movb %al,4(%rdi)
- mov %rdx,%rax
- shr $40,%rax
- and $0xFF,%eax
- movb %al,5(%rdi)
- mov %rdx,%rdx
- shr $48,%rdx
- mov %rcx,%rax
- shl $3,%rax
- and $0xF8,%eax
- xor %rdx,%rax
- movb %al,6(%rdi)
- mov %rcx,%rdx
- shr $5,%rdx
- and $0xFF,%edx
- movb %dl,7(%rdi)
- mov %rcx,%rdx
- shr $13,%rdx
- and $0xFF,%edx
- movb %dl,8(%rdi)
- mov %rcx,%rdx
- shr $21,%rdx
- and $0xFF,%edx
- movb %dl,9(%rdi)
- mov %rcx,%rdx
- shr $29,%rdx
- and $0xFF,%edx
- movb %dl,10(%rdi)
- mov %rcx,%rdx
- shr $37,%rdx
- and $0xFF,%edx
- movb %dl,11(%rdi)
- mov %rcx,%rdx
- shr $45,%rdx
- mov %r8,%rcx
- shl $6,%rcx
- and $0xC0,%ecx
- xor %rdx,%rcx
- movb %cl,12(%rdi)
- mov %r8,%rdx
- shr $2,%rdx
- and $0xFF,%edx
- movb %dl,13(%rdi)
- mov %r8,%rdx
- shr $10,%rdx
- and $0xFF,%edx
- movb %dl,14(%rdi)
- mov %r8,%rdx
- shr $18,%rdx
- and $0xFF,%edx
- movb %dl,15(%rdi)
- mov %r8,%rdx
- shr $26,%rdx
- and $0xFF,%edx
- movb %dl,16(%rdi)
- mov %r8,%rdx
- shr $34,%rdx
- and $0xFF,%edx
- movb %dl,17(%rdi)
- mov %r8,%rdx
- shr $42,%rdx
- movb %dl,18(%rdi)
- mov %r8,%rdx
- shr $50,%rdx
- mov %r9,%rcx
- shl $1,%rcx
- and $0xFE,%ecx
- xor %rdx,%rcx
- movb %cl,19(%rdi)
- mov %r9,%rdx
- shr $7,%rdx
- and $0xFF,%edx
- movb %dl,20(%rdi)
- mov %r9,%rdx
- shr $15,%rdx
- and $0xFF,%edx
- movb %dl,21(%rdi)
- mov %r9,%rdx
- shr $23,%rdx
- and $0xFF,%edx
- movb %dl,22(%rdi)
- mov %r9,%rdx
- shr $31,%rdx
- and $0xFF,%edx
- movb %dl,23(%rdi)
- mov %r9,%rdx
- shr $39,%rdx
- and $0xFF,%edx
- movb %dl,24(%rdi)
- mov %r9,%rdx
- shr $47,%rdx
- mov %rsi,%rcx
- shl $4,%rcx
- and $0xF0,%ecx
- xor %rdx,%rcx
- movb %cl,25(%rdi)
- mov %rsi,%rdx
- shr $4,%rdx
- and $0xFF,%edx
- movb %dl,26(%rdi)
- mov %rsi,%rdx
- shr $12,%rdx
- and $0xFF,%edx
- movb %dl,27(%rdi)
- mov %rsi,%rdx
- shr $20,%rdx
- and $0xFF,%edx
- movb %dl,28(%rdi)
- mov %rsi,%rdx
- shr $28,%rdx
- and $0xFF,%edx
- movb %dl,29(%rdi)
- mov %rsi,%rdx
- shr $36,%rdx
- and $0xFF,%edx
- movb %dl,30(%rdi)
- mov %rsi,%rsi
- shr $44,%rsi
- movb %sil,31(%rdi)
- movq 0(%rsp),%r11
- movq 8(%rsp),%r12
- leave
- ret
-ENDPROC(curve25519_sandy2x_fe51_pack)
-
-.align 32
-ENTRY(curve25519_sandy2x_ladder)
- push %rbp
- mov %rsp,%rbp
- sub $1856,%rsp
- and $-32,%rsp
- movq %r11,1824(%rsp)
- movq %r12,1832(%rsp)
- movq %r13,1840(%rsp)
- movq %r14,1848(%rsp)
- vmovdqa curve25519_sandy2x_v0_0(%rip),%xmm0
- vmovdqa curve25519_sandy2x_v1_0(%rip),%xmm1
- vmovdqu 0(%rdi),%xmm2
- vmovdqa %xmm2,0(%rsp)
- vmovdqu 16(%rdi),%xmm2
- vmovdqa %xmm2,16(%rsp)
- vmovdqu 32(%rdi),%xmm2
- vmovdqa %xmm2,32(%rsp)
- vmovdqu 48(%rdi),%xmm2
- vmovdqa %xmm2,48(%rsp)
- vmovdqu 64(%rdi),%xmm2
- vmovdqa %xmm2,64(%rsp)
- vmovdqa %xmm1,80(%rsp)
- vmovdqa %xmm0,96(%rsp)
- vmovdqa %xmm0,112(%rsp)
- vmovdqa %xmm0,128(%rsp)
- vmovdqa %xmm0,144(%rsp)
- vmovdqa %xmm1,%xmm0
- vpxor %xmm1,%xmm1,%xmm1
- vpxor %xmm2,%xmm2,%xmm2
- vpxor %xmm3,%xmm3,%xmm3
- vpxor %xmm4,%xmm4,%xmm4
- vpxor %xmm5,%xmm5,%xmm5
- vpxor %xmm6,%xmm6,%xmm6
- vpxor %xmm7,%xmm7,%xmm7
- vpxor %xmm8,%xmm8,%xmm8
- vpxor %xmm9,%xmm9,%xmm9
- vmovdqu 0(%rdi),%xmm10
- vmovdqa %xmm10,160(%rsp)
- vmovdqu 16(%rdi),%xmm10
- vmovdqa %xmm10,176(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,192(%rsp)
- vmovdqu 32(%rdi),%xmm10
- vmovdqa %xmm10,208(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,224(%rsp)
- vmovdqu 48(%rdi),%xmm10
- vmovdqa %xmm10,240(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,256(%rsp)
- vmovdqu 64(%rdi),%xmm10
- vmovdqa %xmm10,272(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,288(%rsp)
- vmovdqu 8(%rdi),%xmm10
- vpmuludq curve25519_sandy2x_v2_1(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,304(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,320(%rsp)
- vmovdqu 24(%rdi),%xmm10
- vpmuludq curve25519_sandy2x_v2_1(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,336(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,352(%rsp)
- vmovdqu 40(%rdi),%xmm10
- vpmuludq curve25519_sandy2x_v2_1(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,368(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,384(%rsp)
- vmovdqu 56(%rdi),%xmm10
- vpmuludq curve25519_sandy2x_v2_1(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,400(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,416(%rsp)
- vmovdqu 0(%rdi),%xmm10
- vmovdqu 64(%rdi),%xmm11
- vblendps $12, %xmm11, %xmm10, %xmm10
- vpshufd $2,%xmm10,%xmm10
- vpmuludq curve25519_sandy2x_v38_1(%rip),%xmm10,%xmm10
- vmovdqa %xmm10,432(%rsp)
- movq 0(%rsi),%rdx
- movq 8(%rsi),%rcx
- movq 16(%rsi),%r8
- movq 24(%rsi),%r9
- shrd $1,%rcx,%rdx
- shrd $1,%r8,%rcx
- shrd $1,%r9,%r8
- shr $1,%r9
- xorq 0(%rsi),%rdx
- xorq 8(%rsi),%rcx
- xorq 16(%rsi),%r8
- xorq 24(%rsi),%r9
- leaq 800(%rsp),%rsi
- mov $64,%rax
-
- .align 16
- .Lladder_small_loop:
- mov %rdx,%r10
- mov %rcx,%r11
- mov %r8,%r12
- mov %r9,%r13
- shr $1,%rdx
- shr $1,%rcx
- shr $1,%r8
- shr $1,%r9
- and $1,%r10d
- and $1,%r11d
- and $1,%r12d
- and $1,%r13d
- neg %r10
- neg %r11
- neg %r12
- neg %r13
- movl %r10d,0(%rsi)
- movl %r11d,256(%rsi)
- movl %r12d,512(%rsi)
- movl %r13d,768(%rsi)
- add $4,%rsi
- sub $1,%rax
- jne .Lladder_small_loop
- mov $255,%rdx
- add $760,%rsi
-
- .align 16
- .Lladder_loop:
- sub $1,%rdx
- vbroadcastss 0(%rsi),%xmm10
- sub $4,%rsi
- vmovdqa 0(%rsp),%xmm11
- vmovdqa 80(%rsp),%xmm12
- vpxor %xmm11,%xmm0,%xmm13
- vpand %xmm10,%xmm13,%xmm13
- vpxor %xmm13,%xmm0,%xmm0
- vpxor %xmm13,%xmm11,%xmm11
- vpxor %xmm12,%xmm1,%xmm13
- vpand %xmm10,%xmm13,%xmm13
- vpxor %xmm13,%xmm1,%xmm1
- vpxor %xmm13,%xmm12,%xmm12
- vmovdqa 16(%rsp),%xmm13
- vmovdqa 96(%rsp),%xmm14
- vpxor %xmm13,%xmm2,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm2,%xmm2
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm3,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm3,%xmm3
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,0(%rsp)
- vmovdqa %xmm14,16(%rsp)
- vmovdqa 32(%rsp),%xmm13
- vmovdqa 112(%rsp),%xmm14
- vpxor %xmm13,%xmm4,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm4,%xmm4
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm5,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm5,%xmm5
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,32(%rsp)
- vmovdqa %xmm14,80(%rsp)
- vmovdqa 48(%rsp),%xmm13
- vmovdqa 128(%rsp),%xmm14
- vpxor %xmm13,%xmm6,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm6,%xmm6
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm7,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm7,%xmm7
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,48(%rsp)
- vmovdqa %xmm14,96(%rsp)
- vmovdqa 64(%rsp),%xmm13
- vmovdqa 144(%rsp),%xmm14
- vpxor %xmm13,%xmm8,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm8,%xmm8
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm9,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm9,%xmm9
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,64(%rsp)
- vmovdqa %xmm14,112(%rsp)
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm11,%xmm10
- vpsubq %xmm12,%xmm10,%xmm10
- vpaddq %xmm12,%xmm11,%xmm11
- vpunpckhqdq %xmm10,%xmm11,%xmm12
- vpunpcklqdq %xmm10,%xmm11,%xmm10
- vpaddq %xmm1,%xmm0,%xmm11
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm0,%xmm0
- vpsubq %xmm1,%xmm0,%xmm0
- vpunpckhqdq %xmm11,%xmm0,%xmm1
- vpunpcklqdq %xmm11,%xmm0,%xmm0
- vpmuludq %xmm0,%xmm10,%xmm11
- vpmuludq %xmm1,%xmm10,%xmm13
- vmovdqa %xmm1,128(%rsp)
- vpaddq %xmm1,%xmm1,%xmm1
- vpmuludq %xmm0,%xmm12,%xmm14
- vmovdqa %xmm0,144(%rsp)
- vpaddq %xmm14,%xmm13,%xmm13
- vpmuludq %xmm1,%xmm12,%xmm0
- vmovdqa %xmm1,448(%rsp)
- vpaddq %xmm3,%xmm2,%xmm1
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm2,%xmm2
- vpsubq %xmm3,%xmm2,%xmm2
- vpunpckhqdq %xmm1,%xmm2,%xmm3
- vpunpcklqdq %xmm1,%xmm2,%xmm1
- vpmuludq %xmm1,%xmm10,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpmuludq %xmm3,%xmm10,%xmm2
- vmovdqa %xmm3,464(%rsp)
- vpaddq %xmm3,%xmm3,%xmm3
- vpmuludq %xmm1,%xmm12,%xmm14
- vmovdqa %xmm1,480(%rsp)
- vpaddq %xmm14,%xmm2,%xmm2
- vpmuludq %xmm3,%xmm12,%xmm1
- vmovdqa %xmm3,496(%rsp)
- vpaddq %xmm5,%xmm4,%xmm3
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm4,%xmm4
- vpsubq %xmm5,%xmm4,%xmm4
- vpunpckhqdq %xmm3,%xmm4,%xmm5
- vpunpcklqdq %xmm3,%xmm4,%xmm3
- vpmuludq %xmm3,%xmm10,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpmuludq %xmm5,%xmm10,%xmm4
- vmovdqa %xmm5,512(%rsp)
- vpaddq %xmm5,%xmm5,%xmm5
- vpmuludq %xmm3,%xmm12,%xmm14
- vmovdqa %xmm3,528(%rsp)
- vpaddq %xmm14,%xmm4,%xmm4
- vpaddq %xmm7,%xmm6,%xmm3
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm6,%xmm6
- vpsubq %xmm7,%xmm6,%xmm6
- vpunpckhqdq %xmm3,%xmm6,%xmm7
- vpunpcklqdq %xmm3,%xmm6,%xmm3
- vpmuludq %xmm3,%xmm10,%xmm6
- vpmuludq %xmm5,%xmm12,%xmm14
- vmovdqa %xmm5,544(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm5,%xmm5
- vmovdqa %xmm5,560(%rsp)
- vpaddq %xmm14,%xmm6,%xmm6
- vpmuludq %xmm7,%xmm10,%xmm5
- vmovdqa %xmm7,576(%rsp)
- vpaddq %xmm7,%xmm7,%xmm7
- vpmuludq %xmm3,%xmm12,%xmm14
- vmovdqa %xmm3,592(%rsp)
- vpaddq %xmm14,%xmm5,%xmm5
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vmovdqa %xmm3,608(%rsp)
- vpaddq %xmm9,%xmm8,%xmm3
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm8,%xmm8
- vpsubq %xmm9,%xmm8,%xmm8
- vpunpckhqdq %xmm3,%xmm8,%xmm9
- vpunpcklqdq %xmm3,%xmm8,%xmm3
- vmovdqa %xmm3,624(%rsp)
- vpmuludq %xmm7,%xmm12,%xmm8
- vmovdqa %xmm7,640(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm7,%xmm7
- vmovdqa %xmm7,656(%rsp)
- vpmuludq %xmm3,%xmm10,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq %xmm9,%xmm10,%xmm7
- vmovdqa %xmm9,672(%rsp)
- vpaddq %xmm9,%xmm9,%xmm9
- vpmuludq %xmm3,%xmm12,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vmovdqa %xmm3,688(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm12,%xmm12
- vpmuludq %xmm9,%xmm12,%xmm3
- vmovdqa %xmm9,704(%rsp)
- vpaddq %xmm3,%xmm11,%xmm11
- vmovdqa 0(%rsp),%xmm3
- vmovdqa 16(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm2,%xmm2
- vpmuludq 480(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 464(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpmuludq 528(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 512(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpmuludq 592(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 576(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 624(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 672(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 448(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpmuludq 480(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 496(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 528(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 544(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 592(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 640(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 624(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 704(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm0,%xmm0
- vmovdqa 32(%rsp),%xmm3
- vmovdqa 80(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpmuludq 480(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 464(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpmuludq 528(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 512(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 592(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 576(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm13,%xmm13
- vpmuludq 624(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 672(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 448(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 480(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 496(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 528(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 544(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 592(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 640(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpmuludq 624(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 704(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm1,%xmm1
- vmovdqa 48(%rsp),%xmm3
- vmovdqa 96(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpmuludq 480(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 464(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 528(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 512(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm13,%xmm13
- vpmuludq 592(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 576(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm2,%xmm2
- vpmuludq 624(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 672(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 448(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 480(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 496(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 528(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 544(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpmuludq 592(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 640(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpmuludq 624(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 704(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm6,%xmm6
- vmovdqa 64(%rsp),%xmm3
- vmovdqa 112(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 480(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 464(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm13,%xmm13
- vpmuludq 528(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 512(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm2,%xmm2
- vpmuludq 592(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 576(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpmuludq 624(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 672(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 448(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 480(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 496(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpmuludq 528(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 544(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpmuludq 592(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 640(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 624(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 704(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm8,%xmm8
- vpsrlq $25,%xmm4,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm4,%xmm4
- vpsrlq $26,%xmm11,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm6,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpsrlq $25,%xmm13,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpand curve25519_sandy2x_m25(%rip),%xmm13,%xmm13
- vpsrlq $25,%xmm5,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm0,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpand curve25519_sandy2x_m26(%rip),%xmm0,%xmm0
- vpsrlq $26,%xmm8,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpand curve25519_sandy2x_m26(%rip),%xmm8,%xmm8
- vpsrlq $25,%xmm2,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpand curve25519_sandy2x_m25(%rip),%xmm2,%xmm2
- vpsrlq $25,%xmm7,%xmm3
- vpsllq $4,%xmm3,%xmm9
- vpaddq %xmm3,%xmm11,%xmm11
- vpsllq $1,%xmm3,%xmm3
- vpaddq %xmm3,%xmm9,%xmm9
- vpaddq %xmm9,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm7,%xmm7
- vpsrlq $26,%xmm1,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpsrlq $26,%xmm11,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $25,%xmm4,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm4,%xmm4
- vpunpcklqdq %xmm13,%xmm11,%xmm3
- vpunpckhqdq %xmm13,%xmm11,%xmm9
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm9,%xmm10
- vpsubq %xmm3,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm3,%xmm10,%xmm9
- vpunpcklqdq %xmm3,%xmm10,%xmm10
- vpmuludq %xmm10,%xmm10,%xmm3
- vpaddq %xmm10,%xmm10,%xmm10
- vpmuludq %xmm9,%xmm10,%xmm11
- vpunpcklqdq %xmm2,%xmm0,%xmm12
- vpunpckhqdq %xmm2,%xmm0,%xmm0
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm0,%xmm2
- vpsubq %xmm12,%xmm2,%xmm2
- vpaddq %xmm0,%xmm12,%xmm12
- vpunpckhqdq %xmm12,%xmm2,%xmm0
- vpunpcklqdq %xmm12,%xmm2,%xmm2
- vpmuludq %xmm2,%xmm10,%xmm12
- vpaddq %xmm9,%xmm9,%xmm13
- vpmuludq %xmm13,%xmm9,%xmm9
- vpaddq %xmm9,%xmm12,%xmm12
- vpmuludq %xmm0,%xmm10,%xmm9
- vpmuludq %xmm2,%xmm13,%xmm14
- vpaddq %xmm14,%xmm9,%xmm9
- vpunpcklqdq %xmm4,%xmm1,%xmm14
- vpunpckhqdq %xmm4,%xmm1,%xmm1
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm1,%xmm4
- vpsubq %xmm14,%xmm4,%xmm4
- vpaddq %xmm1,%xmm14,%xmm14
- vpunpckhqdq %xmm14,%xmm4,%xmm1
- vpunpcklqdq %xmm14,%xmm4,%xmm4
- vmovdqa %xmm1,0(%rsp)
- vpaddq %xmm1,%xmm1,%xmm1
- vmovdqa %xmm1,16(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vmovdqa %xmm1,32(%rsp)
- vpmuludq %xmm4,%xmm10,%xmm1
- vpmuludq %xmm2,%xmm2,%xmm14
- vpaddq %xmm14,%xmm1,%xmm1
- vpmuludq 0(%rsp),%xmm10,%xmm14
- vpmuludq %xmm4,%xmm13,%xmm15
- vpaddq %xmm15,%xmm14,%xmm14
- vpunpcklqdq %xmm5,%xmm6,%xmm15
- vpunpckhqdq %xmm5,%xmm6,%xmm5
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm5,%xmm6
- vpsubq %xmm15,%xmm6,%xmm6
- vpaddq %xmm5,%xmm15,%xmm15
- vpunpckhqdq %xmm15,%xmm6,%xmm5
- vpunpcklqdq %xmm15,%xmm6,%xmm6
- vmovdqa %xmm6,48(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm6,%xmm6
- vmovdqa %xmm6,64(%rsp)
- vmovdqa %xmm5,80(%rsp)
- vpmuludq curve25519_sandy2x_v38_38(%rip),%xmm5,%xmm5
- vmovdqa %xmm5,96(%rsp)
- vpmuludq 48(%rsp),%xmm10,%xmm5
- vpaddq %xmm0,%xmm0,%xmm6
- vpmuludq %xmm6,%xmm0,%xmm0
- vpaddq %xmm0,%xmm5,%xmm5
- vpmuludq 80(%rsp),%xmm10,%xmm0
- vpmuludq %xmm4,%xmm6,%xmm15
- vpaddq %xmm15,%xmm0,%xmm0
- vpmuludq %xmm6,%xmm13,%xmm15
- vpaddq %xmm15,%xmm1,%xmm1
- vpmuludq %xmm6,%xmm2,%xmm15
- vpaddq %xmm15,%xmm14,%xmm14
- vpunpcklqdq %xmm7,%xmm8,%xmm15
- vpunpckhqdq %xmm7,%xmm8,%xmm7
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm7,%xmm8
- vpsubq %xmm15,%xmm8,%xmm8
- vpaddq %xmm7,%xmm15,%xmm15
- vpunpckhqdq %xmm15,%xmm8,%xmm7
- vpunpcklqdq %xmm15,%xmm8,%xmm8
- vmovdqa %xmm8,112(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm8,%xmm8
- vmovdqa %xmm8,448(%rsp)
- vpmuludq 112(%rsp),%xmm10,%xmm8
- vpmuludq %xmm7,%xmm10,%xmm10
- vpmuludq curve25519_sandy2x_v38_38(%rip),%xmm7,%xmm15
- vpmuludq %xmm15,%xmm7,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq %xmm15,%xmm13,%xmm7
- vpaddq %xmm7,%xmm3,%xmm3
- vpmuludq %xmm15,%xmm2,%xmm7
- vpaddq %xmm7,%xmm11,%xmm11
- vpmuludq 80(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm7,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq 16(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm5,%xmm5
- vpmuludq 48(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm0,%xmm0
- vpmuludq 112(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm10,%xmm10
- vpmuludq %xmm15,%xmm6,%xmm7
- vpaddq %xmm7,%xmm12,%xmm12
- vpmuludq %xmm15,%xmm4,%xmm7
- vpaddq %xmm7,%xmm9,%xmm9
- vpaddq %xmm2,%xmm2,%xmm2
- vpmuludq %xmm4,%xmm2,%xmm7
- vpaddq %xmm7,%xmm5,%xmm5
- vpmuludq 448(%rsp),%xmm2,%xmm7
- vpaddq %xmm7,%xmm3,%xmm3
- vpmuludq 448(%rsp),%xmm6,%xmm7
- vpaddq %xmm7,%xmm11,%xmm11
- vpmuludq 0(%rsp),%xmm2,%xmm7
- vpaddq %xmm7,%xmm0,%xmm0
- vpmuludq 48(%rsp),%xmm2,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq 80(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 96(%rsp),%xmm4,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq %xmm4,%xmm4,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpaddq %xmm4,%xmm4,%xmm2
- vpmuludq 448(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vpmuludq 16(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpmuludq 48(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm14,%xmm14
- vpmuludq 96(%rsp),%xmm6,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vmovdqa 16(%rsp),%xmm4
- vpmuludq 448(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 16(%rsp),%xmm6,%xmm4
- vpaddq %xmm4,%xmm8,%xmm8
- vpmuludq 48(%rsp),%xmm6,%xmm4
- vpaddq %xmm4,%xmm10,%xmm10
- vpmuludq 80(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpaddq %xmm4,%xmm5,%xmm5
- vpmuludq 112(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm0,%xmm0
- vmovdqa 48(%rsp),%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpmuludq 448(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vmovdqa 80(%rsp),%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpmuludq 448(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm14,%xmm14
- vpmuludq 64(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vmovdqa 16(%rsp),%xmm4
- vpmuludq 64(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm11,%xmm11
- vmovdqa 16(%rsp),%xmm4
- vpmuludq 96(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vmovdqa 48(%rsp),%xmm4
- vpmuludq 96(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 0(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vmovdqa 32(%rsp),%xmm2
- vpmuludq 0(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vmovdqa 64(%rsp),%xmm2
- vpmuludq 48(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vmovdqa 96(%rsp),%xmm2
- vpmuludq 80(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vmovdqa 448(%rsp),%xmm2
- vpmuludq 112(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpsrlq $26,%xmm3,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m26(%rip),%xmm3,%xmm3
- vpsrlq $25,%xmm14,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpand curve25519_sandy2x_m25(%rip),%xmm14,%xmm14
- vpsrlq $25,%xmm11,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpand curve25519_sandy2x_m25(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm5,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpand curve25519_sandy2x_m26(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm12,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpand curve25519_sandy2x_m26(%rip),%xmm12,%xmm12
- vpsrlq $25,%xmm0,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm0,%xmm0
- vpsrlq $25,%xmm9,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vpand curve25519_sandy2x_m25(%rip),%xmm9,%xmm9
- vpsrlq $26,%xmm8,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpand curve25519_sandy2x_m26(%rip),%xmm8,%xmm8
- vpsrlq $26,%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpsrlq $25,%xmm10,%xmm2
- vpsllq $4,%xmm2,%xmm4
- vpaddq %xmm2,%xmm3,%xmm3
- vpsllq $1,%xmm2,%xmm2
- vpaddq %xmm2,%xmm4,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $25,%xmm14,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpand curve25519_sandy2x_m25(%rip),%xmm14,%xmm14
- vpsrlq $26,%xmm3,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m26(%rip),%xmm3,%xmm3
- vpunpckhqdq %xmm11,%xmm3,%xmm2
- vmovdqa %xmm2,0(%rsp)
- vpshufd $0,%xmm3,%xmm2
- vpshufd $0,%xmm11,%xmm3
- vpmuludq 160(%rsp),%xmm2,%xmm4
- vpmuludq 432(%rsp),%xmm3,%xmm6
- vpaddq %xmm6,%xmm4,%xmm4
- vpmuludq 176(%rsp),%xmm2,%xmm6
- vpmuludq 304(%rsp),%xmm3,%xmm7
- vpaddq %xmm7,%xmm6,%xmm6
- vpmuludq 208(%rsp),%xmm2,%xmm7
- vpmuludq 336(%rsp),%xmm3,%xmm11
- vpaddq %xmm11,%xmm7,%xmm7
- vpmuludq 240(%rsp),%xmm2,%xmm11
- vpmuludq 368(%rsp),%xmm3,%xmm13
- vpaddq %xmm13,%xmm11,%xmm11
- vpmuludq 272(%rsp),%xmm2,%xmm2
- vpmuludq 400(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpunpckhqdq %xmm9,%xmm12,%xmm3
- vmovdqa %xmm3,16(%rsp)
- vpshufd $0,%xmm12,%xmm3
- vpshufd $0,%xmm9,%xmm9
- vpmuludq 288(%rsp),%xmm3,%xmm12
- vpaddq %xmm12,%xmm4,%xmm4
- vpmuludq 416(%rsp),%xmm9,%xmm12
- vpaddq %xmm12,%xmm4,%xmm4
- vpmuludq 160(%rsp),%xmm3,%xmm12
- vpaddq %xmm12,%xmm6,%xmm6
- vpmuludq 432(%rsp),%xmm9,%xmm12
- vpaddq %xmm12,%xmm6,%xmm6
- vpmuludq 176(%rsp),%xmm3,%xmm12
- vpaddq %xmm12,%xmm7,%xmm7
- vpmuludq 304(%rsp),%xmm9,%xmm12
- vpaddq %xmm12,%xmm7,%xmm7
- vpmuludq 208(%rsp),%xmm3,%xmm12
- vpaddq %xmm12,%xmm11,%xmm11
- vpmuludq 336(%rsp),%xmm9,%xmm12
- vpaddq %xmm12,%xmm11,%xmm11
- vpmuludq 240(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 368(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpunpckhqdq %xmm14,%xmm1,%xmm3
- vmovdqa %xmm3,32(%rsp)
- vpshufd $0,%xmm1,%xmm1
- vpshufd $0,%xmm14,%xmm3
- vpmuludq 256(%rsp),%xmm1,%xmm9
- vpaddq %xmm9,%xmm4,%xmm4
- vpmuludq 384(%rsp),%xmm3,%xmm9
- vpaddq %xmm9,%xmm4,%xmm4
- vpmuludq 288(%rsp),%xmm1,%xmm9
- vpaddq %xmm9,%xmm6,%xmm6
- vpmuludq 416(%rsp),%xmm3,%xmm9
- vpaddq %xmm9,%xmm6,%xmm6
- vpmuludq 160(%rsp),%xmm1,%xmm9
- vpaddq %xmm9,%xmm7,%xmm7
- vpmuludq 432(%rsp),%xmm3,%xmm9
- vpaddq %xmm9,%xmm7,%xmm7
- vpmuludq 176(%rsp),%xmm1,%xmm9
- vpaddq %xmm9,%xmm11,%xmm11
- vpmuludq 304(%rsp),%xmm3,%xmm9
- vpaddq %xmm9,%xmm11,%xmm11
- vpmuludq 208(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm2,%xmm2
- vpmuludq 336(%rsp),%xmm3,%xmm1
- vpaddq %xmm1,%xmm2,%xmm2
- vpunpckhqdq %xmm0,%xmm5,%xmm1
- vmovdqa %xmm1,48(%rsp)
- vpshufd $0,%xmm5,%xmm1
- vpshufd $0,%xmm0,%xmm0
- vpmuludq 224(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 352(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 256(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 384(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 288(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 416(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 160(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 432(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 176(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm2,%xmm2
- vpmuludq 304(%rsp),%xmm0,%xmm0
- vpaddq %xmm0,%xmm2,%xmm2
- vpunpckhqdq %xmm10,%xmm8,%xmm0
- vmovdqa %xmm0,64(%rsp)
- vpshufd $0,%xmm8,%xmm0
- vpshufd $0,%xmm10,%xmm1
- vpmuludq 192(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 320(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 224(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 352(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 256(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 384(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 288(%rsp),%xmm0,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 416(%rsp),%xmm1,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 160(%rsp),%xmm0,%xmm0
- vpaddq %xmm0,%xmm2,%xmm2
- vpmuludq 432(%rsp),%xmm1,%xmm0
- vpaddq %xmm0,%xmm2,%xmm2
- vmovdqa %xmm4,80(%rsp)
- vmovdqa %xmm6,96(%rsp)
- vmovdqa %xmm7,112(%rsp)
- vmovdqa %xmm11,448(%rsp)
- vmovdqa %xmm2,496(%rsp)
- vmovdqa 144(%rsp),%xmm0
- vpmuludq %xmm0,%xmm0,%xmm1
- vpaddq %xmm0,%xmm0,%xmm0
- vmovdqa 128(%rsp),%xmm2
- vpmuludq %xmm2,%xmm0,%xmm3
- vmovdqa 480(%rsp),%xmm4
- vpmuludq %xmm4,%xmm0,%xmm5
- vmovdqa 464(%rsp),%xmm6
- vpmuludq %xmm6,%xmm0,%xmm7
- vmovdqa 528(%rsp),%xmm8
- vpmuludq %xmm8,%xmm0,%xmm9
- vpmuludq 512(%rsp),%xmm0,%xmm10
- vpmuludq 592(%rsp),%xmm0,%xmm11
- vpmuludq 576(%rsp),%xmm0,%xmm12
- vpmuludq 624(%rsp),%xmm0,%xmm13
- vmovdqa 672(%rsp),%xmm14
- vpmuludq %xmm14,%xmm0,%xmm0
- vpmuludq curve25519_sandy2x_v38_38(%rip),%xmm14,%xmm15
- vpmuludq %xmm15,%xmm14,%xmm14
- vpaddq %xmm14,%xmm13,%xmm13
- vpaddq %xmm6,%xmm6,%xmm14
- vpmuludq %xmm14,%xmm6,%xmm6
- vpaddq %xmm6,%xmm11,%xmm11
- vpaddq %xmm2,%xmm2,%xmm6
- vpmuludq %xmm6,%xmm2,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq %xmm15,%xmm6,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vpmuludq %xmm15,%xmm4,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpmuludq 544(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 592(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 640(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 624(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpmuludq %xmm4,%xmm6,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq %xmm14,%xmm6,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq %xmm8,%xmm6,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq %xmm15,%xmm14,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq %xmm15,%xmm8,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq %xmm4,%xmm4,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq %xmm14,%xmm4,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpaddq %xmm4,%xmm4,%xmm2
- vpmuludq %xmm8,%xmm2,%xmm4
- vpaddq %xmm4,%xmm11,%xmm11
- vpmuludq 688(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpmuludq 688(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vpmuludq 512(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vpmuludq 592(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm13,%xmm13
- vpmuludq 576(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpmuludq 656(%rsp),%xmm8,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpmuludq %xmm8,%xmm14,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq %xmm8,%xmm8,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpaddq %xmm8,%xmm8,%xmm2
- vpmuludq 688(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm5,%xmm5
- vpmuludq 544(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 592(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm10,%xmm10
- vpmuludq 656(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vmovdqa 544(%rsp),%xmm4
- vpmuludq 688(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm7,%xmm7
- vpmuludq 544(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm13,%xmm13
- vpmuludq 592(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm0,%xmm0
- vpmuludq 640(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm11,%xmm11
- vpmuludq 624(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vmovdqa 592(%rsp),%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpmuludq 688(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 608(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vmovdqa 544(%rsp),%xmm4
- vpmuludq 608(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vmovdqa 544(%rsp),%xmm4
- vpmuludq 656(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm5,%xmm5
- vmovdqa 592(%rsp),%xmm4
- vpmuludq 656(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm7,%xmm7
- vmovdqa 640(%rsp),%xmm4
- vpmuludq 688(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm10,%xmm10
- vpmuludq 512(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vmovdqa 560(%rsp),%xmm2
- vpmuludq 512(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vmovdqa 608(%rsp),%xmm2
- vpmuludq 592(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vmovdqa 656(%rsp),%xmm2
- vpmuludq 576(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vmovdqa 688(%rsp),%xmm2
- vpmuludq 624(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpsrlq $26,%xmm1,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpsrlq $25,%xmm10,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $25,%xmm3,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpand curve25519_sandy2x_m25(%rip),%xmm3,%xmm3
- vpsrlq $26,%xmm11,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm5,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpand curve25519_sandy2x_m26(%rip),%xmm5,%xmm5
- vpsrlq $25,%xmm12,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpand curve25519_sandy2x_m25(%rip),%xmm12,%xmm12
- vpsrlq $25,%xmm7,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpand curve25519_sandy2x_m25(%rip),%xmm7,%xmm7
- vpsrlq $26,%xmm13,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpand curve25519_sandy2x_m26(%rip),%xmm13,%xmm13
- vpsrlq $26,%xmm9,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpand curve25519_sandy2x_m26(%rip),%xmm9,%xmm9
- vpsrlq $25,%xmm0,%xmm2
- vpsllq $4,%xmm2,%xmm4
- vpaddq %xmm2,%xmm1,%xmm1
- vpsllq $1,%xmm2,%xmm2
- vpaddq %xmm2,%xmm4,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpand curve25519_sandy2x_m25(%rip),%xmm0,%xmm0
- vpsrlq $25,%xmm10,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $26,%xmm1,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpunpckhqdq %xmm3,%xmm1,%xmm2
- vpunpcklqdq %xmm3,%xmm1,%xmm1
- vmovdqa %xmm1,464(%rsp)
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm2,%xmm3
- vpsubq %xmm1,%xmm3,%xmm3
- vpunpckhqdq %xmm3,%xmm2,%xmm1
- vpunpcklqdq %xmm3,%xmm2,%xmm2
- vmovdqa %xmm2,480(%rsp)
- vmovdqa %xmm1,512(%rsp)
- vpsllq $1,%xmm1,%xmm1
- vmovdqa %xmm1,528(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm3,%xmm3
- vmovdqa 80(%rsp),%xmm1
- vpunpcklqdq %xmm1,%xmm3,%xmm2
- vpunpckhqdq %xmm1,%xmm3,%xmm1
- vpunpckhqdq %xmm7,%xmm5,%xmm3
- vpunpcklqdq %xmm7,%xmm5,%xmm4
- vmovdqa %xmm4,544(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm5
- vpsubq %xmm4,%xmm5,%xmm5
- vpunpckhqdq %xmm5,%xmm3,%xmm4
- vpunpcklqdq %xmm5,%xmm3,%xmm3
- vmovdqa %xmm3,560(%rsp)
- vmovdqa %xmm4,576(%rsp)
- vpsllq $1,%xmm4,%xmm4
- vmovdqa %xmm4,592(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm5,%xmm5
- vmovdqa 96(%rsp),%xmm3
- vpunpcklqdq %xmm3,%xmm5,%xmm4
- vpunpckhqdq %xmm3,%xmm5,%xmm3
- vpunpckhqdq %xmm10,%xmm9,%xmm5
- vpunpcklqdq %xmm10,%xmm9,%xmm6
- vmovdqa %xmm6,608(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm5,%xmm7
- vpsubq %xmm6,%xmm7,%xmm7
- vpunpckhqdq %xmm7,%xmm5,%xmm6
- vpunpcklqdq %xmm7,%xmm5,%xmm5
- vmovdqa %xmm5,624(%rsp)
- vmovdqa %xmm6,640(%rsp)
- vpsllq $1,%xmm6,%xmm6
- vmovdqa %xmm6,656(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm7,%xmm7
- vmovdqa 112(%rsp),%xmm5
- vpunpcklqdq %xmm5,%xmm7,%xmm6
- vpunpckhqdq %xmm5,%xmm7,%xmm5
- vpunpckhqdq %xmm12,%xmm11,%xmm7
- vpunpcklqdq %xmm12,%xmm11,%xmm8
- vmovdqa %xmm8,672(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm7,%xmm9
- vpsubq %xmm8,%xmm9,%xmm9
- vpunpckhqdq %xmm9,%xmm7,%xmm8
- vpunpcklqdq %xmm9,%xmm7,%xmm7
- vmovdqa %xmm7,688(%rsp)
- vmovdqa %xmm8,704(%rsp)
- vpsllq $1,%xmm8,%xmm8
- vmovdqa %xmm8,720(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm9,%xmm9
- vmovdqa 448(%rsp),%xmm7
- vpunpcklqdq %xmm7,%xmm9,%xmm8
- vpunpckhqdq %xmm7,%xmm9,%xmm7
- vpunpckhqdq %xmm0,%xmm13,%xmm9
- vpunpcklqdq %xmm0,%xmm13,%xmm0
- vmovdqa %xmm0,448(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm9,%xmm10
- vpsubq %xmm0,%xmm10,%xmm10
- vpunpckhqdq %xmm10,%xmm9,%xmm0
- vpunpcklqdq %xmm10,%xmm9,%xmm9
- vmovdqa %xmm9,736(%rsp)
- vmovdqa %xmm0,752(%rsp)
- vpsllq $1,%xmm0,%xmm0
- vmovdqa %xmm0,768(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm10,%xmm10
- vmovdqa 496(%rsp),%xmm0
- vpunpcklqdq %xmm0,%xmm10,%xmm9
- vpunpckhqdq %xmm0,%xmm10,%xmm0
- vpsrlq $26,%xmm2,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpand curve25519_sandy2x_m26(%rip),%xmm2,%xmm2
- vpsrlq $25,%xmm5,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $25,%xmm1,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpand curve25519_sandy2x_m25(%rip),%xmm1,%xmm1
- vpsrlq $26,%xmm8,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpand curve25519_sandy2x_m26(%rip),%xmm8,%xmm8
- vpsrlq $26,%xmm4,%xmm10
- vpaddq %xmm10,%xmm3,%xmm3
- vpand curve25519_sandy2x_m26(%rip),%xmm4,%xmm4
- vpsrlq $25,%xmm7,%xmm10
- vpaddq %xmm10,%xmm9,%xmm9
- vpand curve25519_sandy2x_m25(%rip),%xmm7,%xmm7
- vpsrlq $25,%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm3,%xmm3
- vpsrlq $26,%xmm9,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpand curve25519_sandy2x_m26(%rip),%xmm9,%xmm9
- vpsrlq $26,%xmm6,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpsrlq $25,%xmm0,%xmm10
- vpsllq $4,%xmm10,%xmm11
- vpaddq %xmm10,%xmm2,%xmm2
- vpsllq $1,%xmm10,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpaddq %xmm11,%xmm2,%xmm2
- vpand curve25519_sandy2x_m25(%rip),%xmm0,%xmm0
- vpsrlq $25,%xmm5,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm2,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpand curve25519_sandy2x_m26(%rip),%xmm2,%xmm2
- vpunpckhqdq %xmm1,%xmm2,%xmm10
- vmovdqa %xmm10,80(%rsp)
- vpunpcklqdq %xmm1,%xmm2,%xmm1
- vpunpckhqdq %xmm3,%xmm4,%xmm2
- vmovdqa %xmm2,96(%rsp)
- vpunpcklqdq %xmm3,%xmm4,%xmm2
- vpunpckhqdq %xmm5,%xmm6,%xmm3
- vmovdqa %xmm3,112(%rsp)
- vpunpcklqdq %xmm5,%xmm6,%xmm3
- vpunpckhqdq %xmm7,%xmm8,%xmm4
- vmovdqa %xmm4,128(%rsp)
- vpunpcklqdq %xmm7,%xmm8,%xmm4
- vpunpckhqdq %xmm0,%xmm9,%xmm5
- vmovdqa %xmm5,144(%rsp)
- vpunpcklqdq %xmm0,%xmm9,%xmm0
- vmovdqa 464(%rsp),%xmm5
- vpaddq %xmm5,%xmm1,%xmm1
- vpunpcklqdq %xmm1,%xmm5,%xmm6
- vpunpckhqdq %xmm1,%xmm5,%xmm1
- vpmuludq 512(%rsp),%xmm6,%xmm5
- vpmuludq 480(%rsp),%xmm1,%xmm7
- vpaddq %xmm7,%xmm5,%xmm5
- vpmuludq 560(%rsp),%xmm6,%xmm7
- vpmuludq 528(%rsp),%xmm1,%xmm8
- vpaddq %xmm8,%xmm7,%xmm7
- vpmuludq 576(%rsp),%xmm6,%xmm8
- vpmuludq 560(%rsp),%xmm1,%xmm9
- vpaddq %xmm9,%xmm8,%xmm8
- vpmuludq 624(%rsp),%xmm6,%xmm9
- vpmuludq 592(%rsp),%xmm1,%xmm10
- vpaddq %xmm10,%xmm9,%xmm9
- vpmuludq 640(%rsp),%xmm6,%xmm10
- vpmuludq 624(%rsp),%xmm1,%xmm11
- vpaddq %xmm11,%xmm10,%xmm10
- vpmuludq 688(%rsp),%xmm6,%xmm11
- vpmuludq 656(%rsp),%xmm1,%xmm12
- vpaddq %xmm12,%xmm11,%xmm11
- vpmuludq 704(%rsp),%xmm6,%xmm12
- vpmuludq 688(%rsp),%xmm1,%xmm13
- vpaddq %xmm13,%xmm12,%xmm12
- vpmuludq 736(%rsp),%xmm6,%xmm13
- vpmuludq 720(%rsp),%xmm1,%xmm14
- vpaddq %xmm14,%xmm13,%xmm13
- vpmuludq 752(%rsp),%xmm6,%xmm14
- vpmuludq 736(%rsp),%xmm1,%xmm15
- vpaddq %xmm15,%xmm14,%xmm14
- vpmuludq 480(%rsp),%xmm6,%xmm6
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 768(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vmovdqa 544(%rsp),%xmm1
- vpaddq %xmm1,%xmm2,%xmm2
- vpunpcklqdq %xmm2,%xmm1,%xmm15
- vpunpckhqdq %xmm2,%xmm1,%xmm1
- vpmuludq 480(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq 512(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 560(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq 576(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 624(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 640(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 688(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 704(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm15,%xmm15
- vpmuludq 736(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 752(%rsp),%xmm15,%xmm15
- vpaddq %xmm15,%xmm5,%xmm5
- vpmuludq 480(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 528(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq 560(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 592(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 624(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 656(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 688(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 720(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 736(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq 768(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm7,%xmm7
- vmovdqa 608(%rsp),%xmm1
- vpaddq %xmm1,%xmm3,%xmm3
- vpunpcklqdq %xmm3,%xmm1,%xmm2
- vpunpckhqdq %xmm3,%xmm1,%xmm1
- vpmuludq 480(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm9,%xmm9
- vpmuludq 512(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm10,%xmm10
- vpmuludq 560(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 576(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm12,%xmm12
- vpmuludq 624(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 640(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm2,%xmm2
- vpmuludq 688(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 704(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 736(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 752(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 480(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 528(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 560(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 592(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 624(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 656(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 688(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq 720(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq 736(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 768(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm9,%xmm9
- vmovdqa 672(%rsp),%xmm1
- vpaddq %xmm1,%xmm4,%xmm4
- vpunpcklqdq %xmm4,%xmm1,%xmm2
- vpunpckhqdq %xmm4,%xmm1,%xmm1
- vpmuludq 480(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 512(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm12,%xmm12
- vpmuludq 560(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 576(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm2,%xmm2
- vpmuludq 624(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 640(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 688(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 704(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 736(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm9,%xmm9
- vpmuludq 752(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 480(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 528(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 560(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 592(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 624(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq 656(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq 688(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 720(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq 736(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 768(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm11,%xmm11
- vmovdqa 448(%rsp),%xmm1
- vpaddq %xmm1,%xmm0,%xmm0
- vpunpcklqdq %xmm0,%xmm1,%xmm2
- vpunpckhqdq %xmm0,%xmm1,%xmm0
- vpmuludq 480(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm13,%xmm13
- vpmuludq 512(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm2,%xmm2
- vpmuludq 560(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vpmuludq 576(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm5,%xmm5
- vpmuludq 624(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm7,%xmm7
- vpmuludq 640(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm8,%xmm8
- vpmuludq 688(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm9,%xmm9
- vpmuludq 704(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm10,%xmm10
- vpmuludq 736(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm11,%xmm11
- vpmuludq 752(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 480(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm0,%xmm0
- vpmuludq 528(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vpmuludq 560(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm5,%xmm5
- vpmuludq 592(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm7,%xmm7
- vpmuludq 624(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm8,%xmm8
- vpmuludq 656(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm9,%xmm9
- vpmuludq 688(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm10,%xmm10
- vpmuludq 720(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm11,%xmm11
- vpmuludq 736(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm12,%xmm12
- vpmuludq 768(%rsp),%xmm0,%xmm0
- vpaddq %xmm0,%xmm13,%xmm13
- vpsrlq $26,%xmm6,%xmm0
- vpaddq %xmm0,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpsrlq $25,%xmm10,%xmm0
- vpaddq %xmm0,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $25,%xmm5,%xmm0
- vpaddq %xmm0,%xmm7,%xmm7
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm11,%xmm0
- vpaddq %xmm0,%xmm12,%xmm12
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm7,%xmm0
- vpaddq %xmm0,%xmm8,%xmm8
- vpand curve25519_sandy2x_m26(%rip),%xmm7,%xmm7
- vpsrlq $25,%xmm12,%xmm0
- vpaddq %xmm0,%xmm13,%xmm13
- vpand curve25519_sandy2x_m25(%rip),%xmm12,%xmm12
- vpsrlq $25,%xmm8,%xmm0
- vpaddq %xmm0,%xmm9,%xmm9
- vpand curve25519_sandy2x_m25(%rip),%xmm8,%xmm8
- vpsrlq $26,%xmm13,%xmm0
- vpaddq %xmm0,%xmm14,%xmm14
- vpand curve25519_sandy2x_m26(%rip),%xmm13,%xmm13
- vpsrlq $26,%xmm9,%xmm0
- vpaddq %xmm0,%xmm10,%xmm10
- vpand curve25519_sandy2x_m26(%rip),%xmm9,%xmm9
- vpsrlq $25,%xmm14,%xmm0
- vpsllq $4,%xmm0,%xmm1
- vpaddq %xmm0,%xmm6,%xmm6
- vpsllq $1,%xmm0,%xmm0
- vpaddq %xmm0,%xmm1,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm14,%xmm14
- vpsrlq $25,%xmm10,%xmm0
- vpaddq %xmm0,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $26,%xmm6,%xmm0
- vpaddq %xmm0,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpunpckhqdq %xmm5,%xmm6,%xmm1
- vpunpcklqdq %xmm5,%xmm6,%xmm0
- vpunpckhqdq %xmm8,%xmm7,%xmm3
- vpunpcklqdq %xmm8,%xmm7,%xmm2
- vpunpckhqdq %xmm10,%xmm9,%xmm5
- vpunpcklqdq %xmm10,%xmm9,%xmm4
- vpunpckhqdq %xmm12,%xmm11,%xmm7
- vpunpcklqdq %xmm12,%xmm11,%xmm6
- vpunpckhqdq %xmm14,%xmm13,%xmm9
- vpunpcklqdq %xmm14,%xmm13,%xmm8
- cmp $0,%rdx
- jne .Lladder_loop
- vmovdqu %xmm1,160(%rdi)
- vmovdqu %xmm0,80(%rdi)
- vmovdqu %xmm3,176(%rdi)
- vmovdqu %xmm2,96(%rdi)
- vmovdqu %xmm5,192(%rdi)
- vmovdqu %xmm4,112(%rdi)
- vmovdqu %xmm7,208(%rdi)
- vmovdqu %xmm6,128(%rdi)
- vmovdqu %xmm9,224(%rdi)
- vmovdqu %xmm8,144(%rdi)
- movq 1824(%rsp),%r11
- movq 1832(%rsp),%r12
- movq 1840(%rsp),%r13
- movq 1848(%rsp),%r14
- leave
- ret
-ENDPROC(curve25519_sandy2x_ladder)
-
-.align 32
-ENTRY(curve25519_sandy2x_ladder_base)
- push %rbp
- mov %rsp,%rbp
- sub $1568,%rsp
- and $-32,%rsp
- movq %r11,1536(%rsp)
- movq %r12,1544(%rsp)
- movq %r13,1552(%rsp)
- vmovdqa curve25519_sandy2x_v0_0(%rip),%xmm0
- vmovdqa curve25519_sandy2x_v1_0(%rip),%xmm1
- vmovdqa curve25519_sandy2x_v9_0(%rip),%xmm2
- vmovdqa %xmm2,0(%rsp)
- vmovdqa %xmm0,16(%rsp)
- vmovdqa %xmm0,32(%rsp)
- vmovdqa %xmm0,48(%rsp)
- vmovdqa %xmm0,64(%rsp)
- vmovdqa %xmm1,80(%rsp)
- vmovdqa %xmm0,96(%rsp)
- vmovdqa %xmm0,112(%rsp)
- vmovdqa %xmm0,128(%rsp)
- vmovdqa %xmm0,144(%rsp)
- vmovdqa %xmm1,%xmm0
- vpxor %xmm1,%xmm1,%xmm1
- vpxor %xmm2,%xmm2,%xmm2
- vpxor %xmm3,%xmm3,%xmm3
- vpxor %xmm4,%xmm4,%xmm4
- vpxor %xmm5,%xmm5,%xmm5
- vpxor %xmm6,%xmm6,%xmm6
- vpxor %xmm7,%xmm7,%xmm7
- vpxor %xmm8,%xmm8,%xmm8
- vpxor %xmm9,%xmm9,%xmm9
- movq 0(%rsi),%rdx
- movq 8(%rsi),%rcx
- movq 16(%rsi),%r8
- movq 24(%rsi),%r9
- shrd $1,%rcx,%rdx
- shrd $1,%r8,%rcx
- shrd $1,%r9,%r8
- shr $1,%r9
- xorq 0(%rsi),%rdx
- xorq 8(%rsi),%rcx
- xorq 16(%rsi),%r8
- xorq 24(%rsi),%r9
- leaq 512(%rsp),%rsi
- mov $64,%rax
-
- .align 16
- .Lladder_base_small_loop:
- mov %rdx,%r10
- mov %rcx,%r11
- mov %r8,%r12
- mov %r9,%r13
- shr $1,%rdx
- shr $1,%rcx
- shr $1,%r8
- shr $1,%r9
- and $1,%r10d
- and $1,%r11d
- and $1,%r12d
- and $1,%r13d
- neg %r10
- neg %r11
- neg %r12
- neg %r13
- movl %r10d,0(%rsi)
- movl %r11d,256(%rsi)
- movl %r12d,512(%rsi)
- movl %r13d,768(%rsi)
- add $4,%rsi
- sub $1,%rax
- jne .Lladder_base_small_loop
- mov $255,%rdx
- add $760,%rsi
-
- .align 16
- .Lladder_base_loop:
- sub $1,%rdx
- vbroadcastss 0(%rsi),%xmm10
- sub $4,%rsi
- vmovdqa 0(%rsp),%xmm11
- vmovdqa 80(%rsp),%xmm12
- vpxor %xmm11,%xmm0,%xmm13
- vpand %xmm10,%xmm13,%xmm13
- vpxor %xmm13,%xmm0,%xmm0
- vpxor %xmm13,%xmm11,%xmm11
- vpxor %xmm12,%xmm1,%xmm13
- vpand %xmm10,%xmm13,%xmm13
- vpxor %xmm13,%xmm1,%xmm1
- vpxor %xmm13,%xmm12,%xmm12
- vmovdqa 16(%rsp),%xmm13
- vmovdqa 96(%rsp),%xmm14
- vpxor %xmm13,%xmm2,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm2,%xmm2
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm3,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm3,%xmm3
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,0(%rsp)
- vmovdqa %xmm14,16(%rsp)
- vmovdqa 32(%rsp),%xmm13
- vmovdqa 112(%rsp),%xmm14
- vpxor %xmm13,%xmm4,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm4,%xmm4
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm5,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm5,%xmm5
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,32(%rsp)
- vmovdqa %xmm14,80(%rsp)
- vmovdqa 48(%rsp),%xmm13
- vmovdqa 128(%rsp),%xmm14
- vpxor %xmm13,%xmm6,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm6,%xmm6
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm7,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm7,%xmm7
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,48(%rsp)
- vmovdqa %xmm14,96(%rsp)
- vmovdqa 64(%rsp),%xmm13
- vmovdqa 144(%rsp),%xmm14
- vpxor %xmm13,%xmm8,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm8,%xmm8
- vpxor %xmm15,%xmm13,%xmm13
- vpxor %xmm14,%xmm9,%xmm15
- vpand %xmm10,%xmm15,%xmm15
- vpxor %xmm15,%xmm9,%xmm9
- vpxor %xmm15,%xmm14,%xmm14
- vmovdqa %xmm13,64(%rsp)
- vmovdqa %xmm14,112(%rsp)
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm11,%xmm10
- vpsubq %xmm12,%xmm10,%xmm10
- vpaddq %xmm12,%xmm11,%xmm11
- vpunpckhqdq %xmm10,%xmm11,%xmm12
- vpunpcklqdq %xmm10,%xmm11,%xmm10
- vpaddq %xmm1,%xmm0,%xmm11
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm0,%xmm0
- vpsubq %xmm1,%xmm0,%xmm0
- vpunpckhqdq %xmm11,%xmm0,%xmm1
- vpunpcklqdq %xmm11,%xmm0,%xmm0
- vpmuludq %xmm0,%xmm10,%xmm11
- vpmuludq %xmm1,%xmm10,%xmm13
- vmovdqa %xmm1,128(%rsp)
- vpaddq %xmm1,%xmm1,%xmm1
- vpmuludq %xmm0,%xmm12,%xmm14
- vmovdqa %xmm0,144(%rsp)
- vpaddq %xmm14,%xmm13,%xmm13
- vpmuludq %xmm1,%xmm12,%xmm0
- vmovdqa %xmm1,160(%rsp)
- vpaddq %xmm3,%xmm2,%xmm1
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm2,%xmm2
- vpsubq %xmm3,%xmm2,%xmm2
- vpunpckhqdq %xmm1,%xmm2,%xmm3
- vpunpcklqdq %xmm1,%xmm2,%xmm1
- vpmuludq %xmm1,%xmm10,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpmuludq %xmm3,%xmm10,%xmm2
- vmovdqa %xmm3,176(%rsp)
- vpaddq %xmm3,%xmm3,%xmm3
- vpmuludq %xmm1,%xmm12,%xmm14
- vmovdqa %xmm1,192(%rsp)
- vpaddq %xmm14,%xmm2,%xmm2
- vpmuludq %xmm3,%xmm12,%xmm1
- vmovdqa %xmm3,208(%rsp)
- vpaddq %xmm5,%xmm4,%xmm3
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm4,%xmm4
- vpsubq %xmm5,%xmm4,%xmm4
- vpunpckhqdq %xmm3,%xmm4,%xmm5
- vpunpcklqdq %xmm3,%xmm4,%xmm3
- vpmuludq %xmm3,%xmm10,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpmuludq %xmm5,%xmm10,%xmm4
- vmovdqa %xmm5,224(%rsp)
- vpaddq %xmm5,%xmm5,%xmm5
- vpmuludq %xmm3,%xmm12,%xmm14
- vmovdqa %xmm3,240(%rsp)
- vpaddq %xmm14,%xmm4,%xmm4
- vpaddq %xmm7,%xmm6,%xmm3
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm6,%xmm6
- vpsubq %xmm7,%xmm6,%xmm6
- vpunpckhqdq %xmm3,%xmm6,%xmm7
- vpunpcklqdq %xmm3,%xmm6,%xmm3
- vpmuludq %xmm3,%xmm10,%xmm6
- vpmuludq %xmm5,%xmm12,%xmm14
- vmovdqa %xmm5,256(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm5,%xmm5
- vmovdqa %xmm5,272(%rsp)
- vpaddq %xmm14,%xmm6,%xmm6
- vpmuludq %xmm7,%xmm10,%xmm5
- vmovdqa %xmm7,288(%rsp)
- vpaddq %xmm7,%xmm7,%xmm7
- vpmuludq %xmm3,%xmm12,%xmm14
- vmovdqa %xmm3,304(%rsp)
- vpaddq %xmm14,%xmm5,%xmm5
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vmovdqa %xmm3,320(%rsp)
- vpaddq %xmm9,%xmm8,%xmm3
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm8,%xmm8
- vpsubq %xmm9,%xmm8,%xmm8
- vpunpckhqdq %xmm3,%xmm8,%xmm9
- vpunpcklqdq %xmm3,%xmm8,%xmm3
- vmovdqa %xmm3,336(%rsp)
- vpmuludq %xmm7,%xmm12,%xmm8
- vmovdqa %xmm7,352(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm7,%xmm7
- vmovdqa %xmm7,368(%rsp)
- vpmuludq %xmm3,%xmm10,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq %xmm9,%xmm10,%xmm7
- vmovdqa %xmm9,384(%rsp)
- vpaddq %xmm9,%xmm9,%xmm9
- vpmuludq %xmm3,%xmm12,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vmovdqa %xmm3,400(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm12,%xmm12
- vpmuludq %xmm9,%xmm12,%xmm3
- vmovdqa %xmm9,416(%rsp)
- vpaddq %xmm3,%xmm11,%xmm11
- vmovdqa 0(%rsp),%xmm3
- vmovdqa 16(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm2,%xmm2
- vpmuludq 192(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 176(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpmuludq 240(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 224(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpmuludq 304(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 288(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 336(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 384(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 160(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpmuludq 192(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 208(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 240(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 256(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 304(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 352(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 336(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 416(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm0,%xmm0
- vmovdqa 32(%rsp),%xmm3
- vmovdqa 80(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpmuludq 192(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 176(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpmuludq 240(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 224(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 304(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 288(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm13,%xmm13
- vpmuludq 336(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 384(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 160(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 192(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 208(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 240(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 256(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 304(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 352(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpmuludq 336(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 416(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm1,%xmm1
- vmovdqa 48(%rsp),%xmm3
- vmovdqa 96(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpmuludq 192(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 176(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 240(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 224(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm13,%xmm13
- vpmuludq 304(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 288(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm2,%xmm2
- vpmuludq 336(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 384(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 160(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 192(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 208(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 240(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 256(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpmuludq 304(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 352(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpmuludq 336(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 416(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm6,%xmm6
- vmovdqa 64(%rsp),%xmm3
- vmovdqa 112(%rsp),%xmm9
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm10
- vpsubq %xmm9,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm10,%xmm3,%xmm9
- vpunpcklqdq %xmm10,%xmm3,%xmm3
- vpmuludq 144(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpmuludq 128(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm3,%xmm3
- vpmuludq 192(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpmuludq 176(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm13,%xmm13
- vpmuludq 240(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpmuludq 224(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm2,%xmm2
- vpmuludq 304(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpmuludq 288(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpmuludq 336(%rsp),%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpmuludq 384(%rsp),%xmm3,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 144(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm9,%xmm9
- vpmuludq 160(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 192(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 208(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpmuludq 240(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpmuludq 256(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpmuludq 304(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpmuludq 352(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 336(%rsp),%xmm9,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 416(%rsp),%xmm9,%xmm9
- vpaddq %xmm9,%xmm8,%xmm8
- vpsrlq $25,%xmm4,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm4,%xmm4
- vpsrlq $26,%xmm11,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm6,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpsrlq $25,%xmm13,%xmm3
- vpaddq %xmm3,%xmm0,%xmm0
- vpand curve25519_sandy2x_m25(%rip),%xmm13,%xmm13
- vpsrlq $25,%xmm5,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm0,%xmm3
- vpaddq %xmm3,%xmm2,%xmm2
- vpand curve25519_sandy2x_m26(%rip),%xmm0,%xmm0
- vpsrlq $26,%xmm8,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpand curve25519_sandy2x_m26(%rip),%xmm8,%xmm8
- vpsrlq $25,%xmm2,%xmm3
- vpaddq %xmm3,%xmm1,%xmm1
- vpand curve25519_sandy2x_m25(%rip),%xmm2,%xmm2
- vpsrlq $25,%xmm7,%xmm3
- vpsllq $4,%xmm3,%xmm9
- vpaddq %xmm3,%xmm11,%xmm11
- vpsllq $1,%xmm3,%xmm3
- vpaddq %xmm3,%xmm9,%xmm9
- vpaddq %xmm9,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm7,%xmm7
- vpsrlq $26,%xmm1,%xmm3
- vpaddq %xmm3,%xmm4,%xmm4
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpsrlq $26,%xmm11,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $25,%xmm4,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm4,%xmm4
- vpunpcklqdq %xmm13,%xmm11,%xmm3
- vpunpckhqdq %xmm13,%xmm11,%xmm9
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm9,%xmm10
- vpsubq %xmm3,%xmm10,%xmm10
- vpaddq %xmm9,%xmm3,%xmm3
- vpunpckhqdq %xmm3,%xmm10,%xmm9
- vpunpcklqdq %xmm3,%xmm10,%xmm10
- vpmuludq %xmm10,%xmm10,%xmm3
- vpaddq %xmm10,%xmm10,%xmm10
- vpmuludq %xmm9,%xmm10,%xmm11
- vpunpcklqdq %xmm2,%xmm0,%xmm12
- vpunpckhqdq %xmm2,%xmm0,%xmm0
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm0,%xmm2
- vpsubq %xmm12,%xmm2,%xmm2
- vpaddq %xmm0,%xmm12,%xmm12
- vpunpckhqdq %xmm12,%xmm2,%xmm0
- vpunpcklqdq %xmm12,%xmm2,%xmm2
- vpmuludq %xmm2,%xmm10,%xmm12
- vpaddq %xmm9,%xmm9,%xmm13
- vpmuludq %xmm13,%xmm9,%xmm9
- vpaddq %xmm9,%xmm12,%xmm12
- vpmuludq %xmm0,%xmm10,%xmm9
- vpmuludq %xmm2,%xmm13,%xmm14
- vpaddq %xmm14,%xmm9,%xmm9
- vpunpcklqdq %xmm4,%xmm1,%xmm14
- vpunpckhqdq %xmm4,%xmm1,%xmm1
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm1,%xmm4
- vpsubq %xmm14,%xmm4,%xmm4
- vpaddq %xmm1,%xmm14,%xmm14
- vpunpckhqdq %xmm14,%xmm4,%xmm1
- vpunpcklqdq %xmm14,%xmm4,%xmm4
- vmovdqa %xmm1,0(%rsp)
- vpaddq %xmm1,%xmm1,%xmm1
- vmovdqa %xmm1,16(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vmovdqa %xmm1,32(%rsp)
- vpmuludq %xmm4,%xmm10,%xmm1
- vpmuludq %xmm2,%xmm2,%xmm14
- vpaddq %xmm14,%xmm1,%xmm1
- vpmuludq 0(%rsp),%xmm10,%xmm14
- vpmuludq %xmm4,%xmm13,%xmm15
- vpaddq %xmm15,%xmm14,%xmm14
- vpunpcklqdq %xmm5,%xmm6,%xmm15
- vpunpckhqdq %xmm5,%xmm6,%xmm5
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm5,%xmm6
- vpsubq %xmm15,%xmm6,%xmm6
- vpaddq %xmm5,%xmm15,%xmm15
- vpunpckhqdq %xmm15,%xmm6,%xmm5
- vpunpcklqdq %xmm15,%xmm6,%xmm6
- vmovdqa %xmm6,48(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm6,%xmm6
- vmovdqa %xmm6,64(%rsp)
- vmovdqa %xmm5,80(%rsp)
- vpmuludq curve25519_sandy2x_v38_38(%rip),%xmm5,%xmm5
- vmovdqa %xmm5,96(%rsp)
- vpmuludq 48(%rsp),%xmm10,%xmm5
- vpaddq %xmm0,%xmm0,%xmm6
- vpmuludq %xmm6,%xmm0,%xmm0
- vpaddq %xmm0,%xmm5,%xmm5
- vpmuludq 80(%rsp),%xmm10,%xmm0
- vpmuludq %xmm4,%xmm6,%xmm15
- vpaddq %xmm15,%xmm0,%xmm0
- vpmuludq %xmm6,%xmm13,%xmm15
- vpaddq %xmm15,%xmm1,%xmm1
- vpmuludq %xmm6,%xmm2,%xmm15
- vpaddq %xmm15,%xmm14,%xmm14
- vpunpcklqdq %xmm7,%xmm8,%xmm15
- vpunpckhqdq %xmm7,%xmm8,%xmm7
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm7,%xmm8
- vpsubq %xmm15,%xmm8,%xmm8
- vpaddq %xmm7,%xmm15,%xmm15
- vpunpckhqdq %xmm15,%xmm8,%xmm7
- vpunpcklqdq %xmm15,%xmm8,%xmm8
- vmovdqa %xmm8,112(%rsp)
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm8,%xmm8
- vmovdqa %xmm8,160(%rsp)
- vpmuludq 112(%rsp),%xmm10,%xmm8
- vpmuludq %xmm7,%xmm10,%xmm10
- vpmuludq curve25519_sandy2x_v38_38(%rip),%xmm7,%xmm15
- vpmuludq %xmm15,%xmm7,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq %xmm15,%xmm13,%xmm7
- vpaddq %xmm7,%xmm3,%xmm3
- vpmuludq %xmm15,%xmm2,%xmm7
- vpaddq %xmm7,%xmm11,%xmm11
- vpmuludq 80(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm7,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq 16(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm5,%xmm5
- vpmuludq 48(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm0,%xmm0
- vpmuludq 112(%rsp),%xmm13,%xmm7
- vpaddq %xmm7,%xmm10,%xmm10
- vpmuludq %xmm15,%xmm6,%xmm7
- vpaddq %xmm7,%xmm12,%xmm12
- vpmuludq %xmm15,%xmm4,%xmm7
- vpaddq %xmm7,%xmm9,%xmm9
- vpaddq %xmm2,%xmm2,%xmm2
- vpmuludq %xmm4,%xmm2,%xmm7
- vpaddq %xmm7,%xmm5,%xmm5
- vpmuludq 160(%rsp),%xmm2,%xmm7
- vpaddq %xmm7,%xmm3,%xmm3
- vpmuludq 160(%rsp),%xmm6,%xmm7
- vpaddq %xmm7,%xmm11,%xmm11
- vpmuludq 0(%rsp),%xmm2,%xmm7
- vpaddq %xmm7,%xmm0,%xmm0
- vpmuludq 48(%rsp),%xmm2,%xmm7
- vpaddq %xmm7,%xmm8,%xmm8
- vpmuludq 80(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 96(%rsp),%xmm4,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq %xmm4,%xmm4,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpaddq %xmm4,%xmm4,%xmm2
- vpmuludq 160(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vpmuludq 16(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpmuludq 48(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm14,%xmm14
- vpmuludq 96(%rsp),%xmm6,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vmovdqa 16(%rsp),%xmm4
- vpmuludq 160(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 16(%rsp),%xmm6,%xmm4
- vpaddq %xmm4,%xmm8,%xmm8
- vpmuludq 48(%rsp),%xmm6,%xmm4
- vpaddq %xmm4,%xmm10,%xmm10
- vpmuludq 80(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpaddq %xmm4,%xmm5,%xmm5
- vpmuludq 112(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm0,%xmm0
- vmovdqa 48(%rsp),%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpmuludq 160(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vmovdqa 80(%rsp),%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpmuludq 160(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm14,%xmm14
- vpmuludq 64(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vmovdqa 16(%rsp),%xmm4
- vpmuludq 64(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm11,%xmm11
- vmovdqa 16(%rsp),%xmm4
- vpmuludq 96(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vmovdqa 48(%rsp),%xmm4
- vpmuludq 96(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 0(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vmovdqa 32(%rsp),%xmm2
- vpmuludq 0(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vmovdqa 64(%rsp),%xmm2
- vpmuludq 48(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vmovdqa 96(%rsp),%xmm2
- vpmuludq 80(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vmovdqa 160(%rsp),%xmm2
- vpmuludq 112(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpsrlq $26,%xmm3,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m26(%rip),%xmm3,%xmm3
- vpsrlq $25,%xmm14,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpand curve25519_sandy2x_m25(%rip),%xmm14,%xmm14
- vpsrlq $25,%xmm11,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpand curve25519_sandy2x_m25(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm5,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpand curve25519_sandy2x_m26(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm12,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpand curve25519_sandy2x_m26(%rip),%xmm12,%xmm12
- vpsrlq $25,%xmm0,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm0,%xmm0
- vpsrlq $25,%xmm9,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vpand curve25519_sandy2x_m25(%rip),%xmm9,%xmm9
- vpsrlq $26,%xmm8,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpand curve25519_sandy2x_m26(%rip),%xmm8,%xmm8
- vpsrlq $26,%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpsrlq $25,%xmm10,%xmm2
- vpsllq $4,%xmm2,%xmm4
- vpaddq %xmm2,%xmm3,%xmm3
- vpsllq $1,%xmm2,%xmm2
- vpaddq %xmm2,%xmm4,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $25,%xmm14,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpand curve25519_sandy2x_m25(%rip),%xmm14,%xmm14
- vpsrlq $26,%xmm3,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m26(%rip),%xmm3,%xmm3
- vpunpckhqdq %xmm11,%xmm3,%xmm2
- vmovdqa %xmm2,0(%rsp)
- vpunpcklqdq %xmm11,%xmm3,%xmm2
- vpmuludq curve25519_sandy2x_v9_9(%rip),%xmm2,%xmm2
- vmovdqa %xmm2,80(%rsp)
- vpunpckhqdq %xmm9,%xmm12,%xmm2
- vmovdqa %xmm2,16(%rsp)
- vpunpcklqdq %xmm9,%xmm12,%xmm2
- vpmuludq curve25519_sandy2x_v9_9(%rip),%xmm2,%xmm2
- vmovdqa %xmm2,96(%rsp)
- vpunpckhqdq %xmm14,%xmm1,%xmm2
- vmovdqa %xmm2,32(%rsp)
- vpunpcklqdq %xmm14,%xmm1,%xmm1
- vpmuludq curve25519_sandy2x_v9_9(%rip),%xmm1,%xmm1
- vmovdqa %xmm1,112(%rsp)
- vpunpckhqdq %xmm0,%xmm5,%xmm1
- vmovdqa %xmm1,48(%rsp)
- vpunpcklqdq %xmm0,%xmm5,%xmm0
- vpmuludq curve25519_sandy2x_v9_9(%rip),%xmm0,%xmm0
- vmovdqa %xmm0,160(%rsp)
- vpunpckhqdq %xmm10,%xmm8,%xmm0
- vmovdqa %xmm0,64(%rsp)
- vpunpcklqdq %xmm10,%xmm8,%xmm0
- vpmuludq curve25519_sandy2x_v9_9(%rip),%xmm0,%xmm0
- vmovdqa %xmm0,208(%rsp)
- vmovdqa 144(%rsp),%xmm0
- vpmuludq %xmm0,%xmm0,%xmm1
- vpaddq %xmm0,%xmm0,%xmm0
- vmovdqa 128(%rsp),%xmm2
- vpmuludq %xmm2,%xmm0,%xmm3
- vmovdqa 192(%rsp),%xmm4
- vpmuludq %xmm4,%xmm0,%xmm5
- vmovdqa 176(%rsp),%xmm6
- vpmuludq %xmm6,%xmm0,%xmm7
- vmovdqa 240(%rsp),%xmm8
- vpmuludq %xmm8,%xmm0,%xmm9
- vpmuludq 224(%rsp),%xmm0,%xmm10
- vpmuludq 304(%rsp),%xmm0,%xmm11
- vpmuludq 288(%rsp),%xmm0,%xmm12
- vpmuludq 336(%rsp),%xmm0,%xmm13
- vmovdqa 384(%rsp),%xmm14
- vpmuludq %xmm14,%xmm0,%xmm0
- vpmuludq curve25519_sandy2x_v38_38(%rip),%xmm14,%xmm15
- vpmuludq %xmm15,%xmm14,%xmm14
- vpaddq %xmm14,%xmm13,%xmm13
- vpaddq %xmm6,%xmm6,%xmm14
- vpmuludq %xmm14,%xmm6,%xmm6
- vpaddq %xmm6,%xmm11,%xmm11
- vpaddq %xmm2,%xmm2,%xmm6
- vpmuludq %xmm6,%xmm2,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq %xmm15,%xmm6,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vpmuludq %xmm15,%xmm4,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpmuludq 256(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 304(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 352(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 336(%rsp),%xmm6,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpmuludq %xmm4,%xmm6,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq %xmm14,%xmm6,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq %xmm8,%xmm6,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq %xmm15,%xmm14,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq %xmm15,%xmm8,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq %xmm4,%xmm4,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq %xmm14,%xmm4,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpaddq %xmm4,%xmm4,%xmm2
- vpmuludq %xmm8,%xmm2,%xmm4
- vpaddq %xmm4,%xmm11,%xmm11
- vpmuludq 400(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpmuludq 400(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vpmuludq 224(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vpmuludq 304(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm13,%xmm13
- vpmuludq 288(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpmuludq 368(%rsp),%xmm8,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpmuludq %xmm8,%xmm14,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq %xmm8,%xmm8,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpaddq %xmm8,%xmm8,%xmm2
- vpmuludq 400(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm5,%xmm5
- vpmuludq 256(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 304(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm10,%xmm10
- vpmuludq 368(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vmovdqa 256(%rsp),%xmm4
- vpmuludq 400(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm7,%xmm7
- vpmuludq 256(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm13,%xmm13
- vpmuludq 304(%rsp),%xmm14,%xmm4
- vpaddq %xmm4,%xmm0,%xmm0
- vpmuludq 352(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm11,%xmm11
- vpmuludq 336(%rsp),%xmm15,%xmm4
- vpaddq %xmm4,%xmm12,%xmm12
- vmovdqa 304(%rsp),%xmm4
- vpaddq %xmm4,%xmm4,%xmm4
- vpmuludq 400(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm9,%xmm9
- vpmuludq 320(%rsp),%xmm2,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vmovdqa 256(%rsp),%xmm4
- vpmuludq 320(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm3,%xmm3
- vmovdqa 256(%rsp),%xmm4
- vpmuludq 368(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm5,%xmm5
- vmovdqa 304(%rsp),%xmm4
- vpmuludq 368(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm7,%xmm7
- vmovdqa 352(%rsp),%xmm4
- vpmuludq 400(%rsp),%xmm4,%xmm4
- vpaddq %xmm4,%xmm10,%xmm10
- vpmuludq 224(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vmovdqa 272(%rsp),%xmm2
- vpmuludq 224(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm1,%xmm1
- vmovdqa 320(%rsp),%xmm2
- vpmuludq 304(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vmovdqa 368(%rsp),%xmm2
- vpmuludq 288(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vmovdqa 400(%rsp),%xmm2
- vpmuludq 336(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpsrlq $26,%xmm1,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpsrlq $25,%xmm10,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $25,%xmm3,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpand curve25519_sandy2x_m25(%rip),%xmm3,%xmm3
- vpsrlq $26,%xmm11,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm5,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpand curve25519_sandy2x_m26(%rip),%xmm5,%xmm5
- vpsrlq $25,%xmm12,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpand curve25519_sandy2x_m25(%rip),%xmm12,%xmm12
- vpsrlq $25,%xmm7,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpand curve25519_sandy2x_m25(%rip),%xmm7,%xmm7
- vpsrlq $26,%xmm13,%xmm2
- vpaddq %xmm2,%xmm0,%xmm0
- vpand curve25519_sandy2x_m26(%rip),%xmm13,%xmm13
- vpsrlq $26,%xmm9,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpand curve25519_sandy2x_m26(%rip),%xmm9,%xmm9
- vpsrlq $25,%xmm0,%xmm2
- vpsllq $4,%xmm2,%xmm4
- vpaddq %xmm2,%xmm1,%xmm1
- vpsllq $1,%xmm2,%xmm2
- vpaddq %xmm2,%xmm4,%xmm4
- vpaddq %xmm4,%xmm1,%xmm1
- vpand curve25519_sandy2x_m25(%rip),%xmm0,%xmm0
- vpsrlq $25,%xmm10,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $26,%xmm1,%xmm2
- vpaddq %xmm2,%xmm3,%xmm3
- vpand curve25519_sandy2x_m26(%rip),%xmm1,%xmm1
- vpunpckhqdq %xmm3,%xmm1,%xmm2
- vpunpcklqdq %xmm3,%xmm1,%xmm1
- vmovdqa %xmm1,176(%rsp)
- vpaddq curve25519_sandy2x_subc0(%rip),%xmm2,%xmm3
- vpsubq %xmm1,%xmm3,%xmm3
- vpunpckhqdq %xmm3,%xmm2,%xmm1
- vpunpcklqdq %xmm3,%xmm2,%xmm2
- vmovdqa %xmm2,192(%rsp)
- vmovdqa %xmm1,224(%rsp)
- vpsllq $1,%xmm1,%xmm1
- vmovdqa %xmm1,240(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm3,%xmm3
- vmovdqa 80(%rsp),%xmm1
- vpunpcklqdq %xmm1,%xmm3,%xmm2
- vpunpckhqdq %xmm1,%xmm3,%xmm1
- vpunpckhqdq %xmm7,%xmm5,%xmm3
- vpunpcklqdq %xmm7,%xmm5,%xmm4
- vmovdqa %xmm4,256(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm3,%xmm5
- vpsubq %xmm4,%xmm5,%xmm5
- vpunpckhqdq %xmm5,%xmm3,%xmm4
- vpunpcklqdq %xmm5,%xmm3,%xmm3
- vmovdqa %xmm3,272(%rsp)
- vmovdqa %xmm4,288(%rsp)
- vpsllq $1,%xmm4,%xmm4
- vmovdqa %xmm4,304(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm5,%xmm5
- vmovdqa 96(%rsp),%xmm3
- vpunpcklqdq %xmm3,%xmm5,%xmm4
- vpunpckhqdq %xmm3,%xmm5,%xmm3
- vpunpckhqdq %xmm10,%xmm9,%xmm5
- vpunpcklqdq %xmm10,%xmm9,%xmm6
- vmovdqa %xmm6,320(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm5,%xmm7
- vpsubq %xmm6,%xmm7,%xmm7
- vpunpckhqdq %xmm7,%xmm5,%xmm6
- vpunpcklqdq %xmm7,%xmm5,%xmm5
- vmovdqa %xmm5,336(%rsp)
- vmovdqa %xmm6,352(%rsp)
- vpsllq $1,%xmm6,%xmm6
- vmovdqa %xmm6,368(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm7,%xmm7
- vmovdqa 112(%rsp),%xmm5
- vpunpcklqdq %xmm5,%xmm7,%xmm6
- vpunpckhqdq %xmm5,%xmm7,%xmm5
- vpunpckhqdq %xmm12,%xmm11,%xmm7
- vpunpcklqdq %xmm12,%xmm11,%xmm8
- vmovdqa %xmm8,384(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm7,%xmm9
- vpsubq %xmm8,%xmm9,%xmm9
- vpunpckhqdq %xmm9,%xmm7,%xmm8
- vpunpcklqdq %xmm9,%xmm7,%xmm7
- vmovdqa %xmm7,400(%rsp)
- vmovdqa %xmm8,416(%rsp)
- vpsllq $1,%xmm8,%xmm8
- vmovdqa %xmm8,432(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm9,%xmm9
- vmovdqa 160(%rsp),%xmm7
- vpunpcklqdq %xmm7,%xmm9,%xmm8
- vpunpckhqdq %xmm7,%xmm9,%xmm7
- vpunpckhqdq %xmm0,%xmm13,%xmm9
- vpunpcklqdq %xmm0,%xmm13,%xmm0
- vmovdqa %xmm0,160(%rsp)
- vpaddq curve25519_sandy2x_subc2(%rip),%xmm9,%xmm10
- vpsubq %xmm0,%xmm10,%xmm10
- vpunpckhqdq %xmm10,%xmm9,%xmm0
- vpunpcklqdq %xmm10,%xmm9,%xmm9
- vmovdqa %xmm9,448(%rsp)
- vmovdqa %xmm0,464(%rsp)
- vpsllq $1,%xmm0,%xmm0
- vmovdqa %xmm0,480(%rsp)
- vpmuludq curve25519_sandy2x_v121666_121666(%rip),%xmm10,%xmm10
- vmovdqa 208(%rsp),%xmm0
- vpunpcklqdq %xmm0,%xmm10,%xmm9
- vpunpckhqdq %xmm0,%xmm10,%xmm0
- vpsrlq $26,%xmm2,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpand curve25519_sandy2x_m26(%rip),%xmm2,%xmm2
- vpsrlq $25,%xmm5,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $25,%xmm1,%xmm10
- vpaddq %xmm10,%xmm4,%xmm4
- vpand curve25519_sandy2x_m25(%rip),%xmm1,%xmm1
- vpsrlq $26,%xmm8,%xmm10
- vpaddq %xmm10,%xmm7,%xmm7
- vpand curve25519_sandy2x_m26(%rip),%xmm8,%xmm8
- vpsrlq $26,%xmm4,%xmm10
- vpaddq %xmm10,%xmm3,%xmm3
- vpand curve25519_sandy2x_m26(%rip),%xmm4,%xmm4
- vpsrlq $25,%xmm7,%xmm10
- vpaddq %xmm10,%xmm9,%xmm9
- vpand curve25519_sandy2x_m25(%rip),%xmm7,%xmm7
- vpsrlq $25,%xmm3,%xmm10
- vpaddq %xmm10,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm3,%xmm3
- vpsrlq $26,%xmm9,%xmm10
- vpaddq %xmm10,%xmm0,%xmm0
- vpand curve25519_sandy2x_m26(%rip),%xmm9,%xmm9
- vpsrlq $26,%xmm6,%xmm10
- vpaddq %xmm10,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpsrlq $25,%xmm0,%xmm10
- vpsllq $4,%xmm10,%xmm11
- vpaddq %xmm10,%xmm2,%xmm2
- vpsllq $1,%xmm10,%xmm10
- vpaddq %xmm10,%xmm11,%xmm11
- vpaddq %xmm11,%xmm2,%xmm2
- vpand curve25519_sandy2x_m25(%rip),%xmm0,%xmm0
- vpsrlq $25,%xmm5,%xmm10
- vpaddq %xmm10,%xmm8,%xmm8
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm2,%xmm10
- vpaddq %xmm10,%xmm1,%xmm1
- vpand curve25519_sandy2x_m26(%rip),%xmm2,%xmm2
- vpunpckhqdq %xmm1,%xmm2,%xmm10
- vmovdqa %xmm10,80(%rsp)
- vpunpcklqdq %xmm1,%xmm2,%xmm1
- vpunpckhqdq %xmm3,%xmm4,%xmm2
- vmovdqa %xmm2,96(%rsp)
- vpunpcklqdq %xmm3,%xmm4,%xmm2
- vpunpckhqdq %xmm5,%xmm6,%xmm3
- vmovdqa %xmm3,112(%rsp)
- vpunpcklqdq %xmm5,%xmm6,%xmm3
- vpunpckhqdq %xmm7,%xmm8,%xmm4
- vmovdqa %xmm4,128(%rsp)
- vpunpcklqdq %xmm7,%xmm8,%xmm4
- vpunpckhqdq %xmm0,%xmm9,%xmm5
- vmovdqa %xmm5,144(%rsp)
- vpunpcklqdq %xmm0,%xmm9,%xmm0
- vmovdqa 176(%rsp),%xmm5
- vpaddq %xmm5,%xmm1,%xmm1
- vpunpcklqdq %xmm1,%xmm5,%xmm6
- vpunpckhqdq %xmm1,%xmm5,%xmm1
- vpmuludq 224(%rsp),%xmm6,%xmm5
- vpmuludq 192(%rsp),%xmm1,%xmm7
- vpaddq %xmm7,%xmm5,%xmm5
- vpmuludq 272(%rsp),%xmm6,%xmm7
- vpmuludq 240(%rsp),%xmm1,%xmm8
- vpaddq %xmm8,%xmm7,%xmm7
- vpmuludq 288(%rsp),%xmm6,%xmm8
- vpmuludq 272(%rsp),%xmm1,%xmm9
- vpaddq %xmm9,%xmm8,%xmm8
- vpmuludq 336(%rsp),%xmm6,%xmm9
- vpmuludq 304(%rsp),%xmm1,%xmm10
- vpaddq %xmm10,%xmm9,%xmm9
- vpmuludq 352(%rsp),%xmm6,%xmm10
- vpmuludq 336(%rsp),%xmm1,%xmm11
- vpaddq %xmm11,%xmm10,%xmm10
- vpmuludq 400(%rsp),%xmm6,%xmm11
- vpmuludq 368(%rsp),%xmm1,%xmm12
- vpaddq %xmm12,%xmm11,%xmm11
- vpmuludq 416(%rsp),%xmm6,%xmm12
- vpmuludq 400(%rsp),%xmm1,%xmm13
- vpaddq %xmm13,%xmm12,%xmm12
- vpmuludq 448(%rsp),%xmm6,%xmm13
- vpmuludq 432(%rsp),%xmm1,%xmm14
- vpaddq %xmm14,%xmm13,%xmm13
- vpmuludq 464(%rsp),%xmm6,%xmm14
- vpmuludq 448(%rsp),%xmm1,%xmm15
- vpaddq %xmm15,%xmm14,%xmm14
- vpmuludq 192(%rsp),%xmm6,%xmm6
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 480(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vmovdqa 256(%rsp),%xmm1
- vpaddq %xmm1,%xmm2,%xmm2
- vpunpcklqdq %xmm2,%xmm1,%xmm15
- vpunpckhqdq %xmm2,%xmm1,%xmm1
- vpmuludq 192(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq 224(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 272(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq 288(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 336(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 352(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 400(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 416(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm15,%xmm15
- vpmuludq 448(%rsp),%xmm15,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 464(%rsp),%xmm15,%xmm15
- vpaddq %xmm15,%xmm5,%xmm5
- vpmuludq 192(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 240(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq 272(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 304(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 336(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 368(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 400(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 432(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 448(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq 480(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm7,%xmm7
- vmovdqa 320(%rsp),%xmm1
- vpaddq %xmm1,%xmm3,%xmm3
- vpunpcklqdq %xmm3,%xmm1,%xmm2
- vpunpckhqdq %xmm3,%xmm1,%xmm1
- vpmuludq 192(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm9,%xmm9
- vpmuludq 224(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm10,%xmm10
- vpmuludq 272(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 288(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm12,%xmm12
- vpmuludq 336(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 352(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm2,%xmm2
- vpmuludq 400(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 416(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 448(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 464(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 192(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 240(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm11,%xmm11
- vpmuludq 272(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 304(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 336(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 368(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 400(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq 432(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq 448(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 480(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm9,%xmm9
- vmovdqa 384(%rsp),%xmm1
- vpaddq %xmm1,%xmm4,%xmm4
- vpunpcklqdq %xmm4,%xmm1,%xmm2
- vpunpckhqdq %xmm4,%xmm1,%xmm1
- vpmuludq 192(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm11,%xmm11
- vpmuludq 224(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm12,%xmm12
- vpmuludq 272(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm13,%xmm13
- vpmuludq 288(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm2,%xmm2
- vpmuludq 336(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm6,%xmm6
- vpmuludq 352(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm5,%xmm5
- vpmuludq 400(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm7,%xmm7
- vpmuludq 416(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm8,%xmm8
- vpmuludq 448(%rsp),%xmm2,%xmm3
- vpaddq %xmm3,%xmm9,%xmm9
- vpmuludq 464(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 192(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 240(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm13,%xmm13
- vpmuludq 272(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm1,%xmm1
- vpmuludq 304(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm6,%xmm6
- vpmuludq 336(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm5,%xmm5
- vpmuludq 368(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm7,%xmm7
- vpmuludq 400(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm8,%xmm8
- vpmuludq 432(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm9,%xmm9
- vpmuludq 448(%rsp),%xmm1,%xmm2
- vpaddq %xmm2,%xmm10,%xmm10
- vpmuludq 480(%rsp),%xmm1,%xmm1
- vpaddq %xmm1,%xmm11,%xmm11
- vmovdqa 160(%rsp),%xmm1
- vpaddq %xmm1,%xmm0,%xmm0
- vpunpcklqdq %xmm0,%xmm1,%xmm2
- vpunpckhqdq %xmm0,%xmm1,%xmm0
- vpmuludq 192(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm13,%xmm13
- vpmuludq 224(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm2,%xmm2
- vpmuludq 272(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vpmuludq 288(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm5,%xmm5
- vpmuludq 336(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm7,%xmm7
- vpmuludq 352(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm8,%xmm8
- vpmuludq 400(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm9,%xmm9
- vpmuludq 416(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm10,%xmm10
- vpmuludq 448(%rsp),%xmm2,%xmm1
- vpaddq %xmm1,%xmm11,%xmm11
- vpmuludq 464(%rsp),%xmm2,%xmm2
- vpaddq %xmm2,%xmm12,%xmm12
- vpmuludq 192(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm14,%xmm14
- vpmuludq curve25519_sandy2x_v19_19(%rip),%xmm0,%xmm0
- vpmuludq 240(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vpmuludq 272(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm5,%xmm5
- vpmuludq 304(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm7,%xmm7
- vpmuludq 336(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm8,%xmm8
- vpmuludq 368(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm9,%xmm9
- vpmuludq 400(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm10,%xmm10
- vpmuludq 432(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm11,%xmm11
- vpmuludq 448(%rsp),%xmm0,%xmm1
- vpaddq %xmm1,%xmm12,%xmm12
- vpmuludq 480(%rsp),%xmm0,%xmm0
- vpaddq %xmm0,%xmm13,%xmm13
- vpsrlq $26,%xmm6,%xmm0
- vpaddq %xmm0,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpsrlq $25,%xmm10,%xmm0
- vpaddq %xmm0,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $25,%xmm5,%xmm0
- vpaddq %xmm0,%xmm7,%xmm7
- vpand curve25519_sandy2x_m25(%rip),%xmm5,%xmm5
- vpsrlq $26,%xmm11,%xmm0
- vpaddq %xmm0,%xmm12,%xmm12
- vpand curve25519_sandy2x_m26(%rip),%xmm11,%xmm11
- vpsrlq $26,%xmm7,%xmm0
- vpaddq %xmm0,%xmm8,%xmm8
- vpand curve25519_sandy2x_m26(%rip),%xmm7,%xmm7
- vpsrlq $25,%xmm12,%xmm0
- vpaddq %xmm0,%xmm13,%xmm13
- vpand curve25519_sandy2x_m25(%rip),%xmm12,%xmm12
- vpsrlq $25,%xmm8,%xmm0
- vpaddq %xmm0,%xmm9,%xmm9
- vpand curve25519_sandy2x_m25(%rip),%xmm8,%xmm8
- vpsrlq $26,%xmm13,%xmm0
- vpaddq %xmm0,%xmm14,%xmm14
- vpand curve25519_sandy2x_m26(%rip),%xmm13,%xmm13
- vpsrlq $26,%xmm9,%xmm0
- vpaddq %xmm0,%xmm10,%xmm10
- vpand curve25519_sandy2x_m26(%rip),%xmm9,%xmm9
- vpsrlq $25,%xmm14,%xmm0
- vpsllq $4,%xmm0,%xmm1
- vpaddq %xmm0,%xmm6,%xmm6
- vpsllq $1,%xmm0,%xmm0
- vpaddq %xmm0,%xmm1,%xmm1
- vpaddq %xmm1,%xmm6,%xmm6
- vpand curve25519_sandy2x_m25(%rip),%xmm14,%xmm14
- vpsrlq $25,%xmm10,%xmm0
- vpaddq %xmm0,%xmm11,%xmm11
- vpand curve25519_sandy2x_m25(%rip),%xmm10,%xmm10
- vpsrlq $26,%xmm6,%xmm0
- vpaddq %xmm0,%xmm5,%xmm5
- vpand curve25519_sandy2x_m26(%rip),%xmm6,%xmm6
- vpunpckhqdq %xmm5,%xmm6,%xmm1
- vpunpcklqdq %xmm5,%xmm6,%xmm0
- vpunpckhqdq %xmm8,%xmm7,%xmm3
- vpunpcklqdq %xmm8,%xmm7,%xmm2
- vpunpckhqdq %xmm10,%xmm9,%xmm5
- vpunpcklqdq %xmm10,%xmm9,%xmm4
- vpunpckhqdq %xmm12,%xmm11,%xmm7
- vpunpcklqdq %xmm12,%xmm11,%xmm6
- vpunpckhqdq %xmm14,%xmm13,%xmm9
- vpunpcklqdq %xmm14,%xmm13,%xmm8
- cmp $0,%rdx
- jne .Lladder_base_loop
- vmovdqu %xmm1,80(%rdi)
- vmovdqu %xmm0,0(%rdi)
- vmovdqu %xmm3,96(%rdi)
- vmovdqu %xmm2,16(%rdi)
- vmovdqu %xmm5,112(%rdi)
- vmovdqu %xmm4,32(%rdi)
- vmovdqu %xmm7,128(%rdi)
- vmovdqu %xmm6,48(%rdi)
- vmovdqu %xmm9,144(%rdi)
- vmovdqu %xmm8,64(%rdi)
- movq 1536(%rsp),%r11
- movq 1544(%rsp),%r12
- movq 1552(%rsp),%r13
- leave
- ret
-ENDPROC(curve25519_sandy2x_ladder_base)
-#endif /* CONFIG_AS_AVX */
diff --git a/curve25519-sandy2x.c b/curve25519-sandy2x.c
deleted file mode 100644
index e8d5d2b..0000000
--- a/curve25519-sandy2x.c
+++ /dev/null
@@ -1,139 +0,0 @@
-/* SPDX-License-Identifier: GPL-2.0
- *
- * Copyright (C) 2015-2018 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
- *
- * Original author: Tung Chou <blueprint@crypto.tw>
- */
-
-#include <linux/kernel.h>
-#include <linux/string.h>
-
-enum { CURVE25519_POINT_SIZE = 32 };
-
-static __always_inline void normalize_secret(u8 secret[CURVE25519_POINT_SIZE])
-{
- secret[0] &= 248;
- secret[31] &= 127;
- secret[31] |= 64;
-}
-
-typedef u64 fe[10];
-typedef u64 fe51[5];
-asmlinkage void curve25519_sandy2x_ladder(fe *, const u8 *);
-asmlinkage void curve25519_sandy2x_ladder_base(fe *, const u8 *);
-asmlinkage void curve25519_sandy2x_fe51_pack(u8 *, const fe51 *);
-asmlinkage void curve25519_sandy2x_fe51_mul(fe51 *, const fe51 *, const fe51 *);
-asmlinkage void curve25519_sandy2x_fe51_nsquare(fe51 *, const fe51 *, int);
-
-static inline u32 le24_to_cpupv(const u8 *in)
-{
- return le16_to_cpup((__le16 *)in) | ((u32)in[2]) << 16;
-}
-
-static inline void fe_frombytes(fe h, const u8 *s)
-{
- u64 h0 = le32_to_cpup((__le32 *)s);
- u64 h1 = le24_to_cpupv(s + 4) << 6;
- u64 h2 = le24_to_cpupv(s + 7) << 5;
- u64 h3 = le24_to_cpupv(s + 10) << 3;
- u64 h4 = le24_to_cpupv(s + 13) << 2;
- u64 h5 = le32_to_cpup((__le32 *)(s + 16));
- u64 h6 = le24_to_cpupv(s + 20) << 7;
- u64 h7 = le24_to_cpupv(s + 23) << 5;
- u64 h8 = le24_to_cpupv(s + 26) << 4;
- u64 h9 = (le24_to_cpupv(s + 29) & 8388607) << 2;
- u64 carry0, carry1, carry2, carry3, carry4, carry5, carry6, carry7, carry8, carry9;
-
- carry9 = h9 >> 25; h0 += carry9 * 19; h9 &= 0x1FFFFFF;
- carry1 = h1 >> 25; h2 += carry1; h1 &= 0x1FFFFFF;
- carry3 = h3 >> 25; h4 += carry3; h3 &= 0x1FFFFFF;
- carry5 = h5 >> 25; h6 += carry5; h5 &= 0x1FFFFFF;
- carry7 = h7 >> 25; h8 += carry7; h7 &= 0x1FFFFFF;
-
- carry0 = h0 >> 26; h1 += carry0; h0 &= 0x3FFFFFF;
- carry2 = h2 >> 26; h3 += carry2; h2 &= 0x3FFFFFF;
- carry4 = h4 >> 26; h5 += carry4; h4 &= 0x3FFFFFF;
- carry6 = h6 >> 26; h7 += carry6; h6 &= 0x3FFFFFF;
- carry8 = h8 >> 26; h9 += carry8; h8 &= 0x3FFFFFF;
-
- h[0] = h0;
- h[1] = h1;
- h[2] = h2;
- h[3] = h3;
- h[4] = h4;
- h[5] = h5;
- h[6] = h6;
- h[7] = h7;
- h[8] = h8;
- h[9] = h9;
-}
-
-static inline void fe51_invert(fe51 *r, const fe51 *x)
-{
- fe51 z2, z9, z11, z2_5_0, z2_10_0, z2_20_0, z2_50_0, z2_100_0, t;
-
- /* 2 */ curve25519_sandy2x_fe51_nsquare(&z2, x, 1);
- /* 4 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&z2, 1);
- /* 8 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&t, 1);
- /* 9 */ curve25519_sandy2x_fe51_mul(&z9, (const fe51 *)&t, x);
- /* 11 */ curve25519_sandy2x_fe51_mul(&z11, (const fe51 *)&z9, (const fe51 *)&z2);
- /* 22 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&z11, 1);
- /* 2^5 - 2^0 = 31 */ curve25519_sandy2x_fe51_mul(&z2_5_0, (const fe51 *)&t, (const fe51 *)&z9);
-
- /* 2^10 - 2^5 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&z2_5_0, 5);
- /* 2^10 - 2^0 */ curve25519_sandy2x_fe51_mul(&z2_10_0, (const fe51 *)&t, (const fe51 *)&z2_5_0);
-
- /* 2^20 - 2^10 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&z2_10_0, 10);
- /* 2^20 - 2^0 */ curve25519_sandy2x_fe51_mul(&z2_20_0, (const fe51 *)&t, (const fe51 *)&z2_10_0);
-
- /* 2^40 - 2^20 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&z2_20_0, 20);
- /* 2^40 - 2^0 */ curve25519_sandy2x_fe51_mul(&t, (const fe51 *)&t, (const fe51 *)&z2_20_0);
-
- /* 2^50 - 2^10 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&t, 10);
- /* 2^50 - 2^0 */ curve25519_sandy2x_fe51_mul(&z2_50_0, (const fe51 *)&t, (const fe51 *)&z2_10_0);
-
- /* 2^100 - 2^50 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&z2_50_0, 50);
- /* 2^100 - 2^0 */ curve25519_sandy2x_fe51_mul(&z2_100_0, (const fe51 *)&t, (const fe51 *)&z2_50_0);
-
- /* 2^200 - 2^100 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&z2_100_0, 100);
- /* 2^200 - 2^0 */ curve25519_sandy2x_fe51_mul(&t, (const fe51 *)&t, (const fe51 *)&z2_100_0);
-
- /* 2^250 - 2^50 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&t, 50);
- /* 2^250 - 2^0 */ curve25519_sandy2x_fe51_mul(&t, (const fe51 *)&t, (const fe51 *)&z2_50_0);
-
- /* 2^255 - 2^5 */ curve25519_sandy2x_fe51_nsquare(&t, (const fe51 *)&t, 5);
- /* 2^255 - 21 */ curve25519_sandy2x_fe51_mul(r, (const fe51 *)t, (const fe51 *)&z11);
-}
-
-bool curve25519_sandy2x(u8 mypublic[CURVE25519_POINT_SIZE], const u8 secret[CURVE25519_POINT_SIZE], const u8 basepoint[CURVE25519_POINT_SIZE])
-{
- u8 e[32];
- fe var[3];
- fe51 x_51, z_51;
-
- memcpy(e, secret, 32);
- normalize_secret(e);
-#define x1 var[0]
-#define x2 var[1]
-#define z2 var[2]
- fe_frombytes(x1, basepoint);
- curve25519_sandy2x_ladder(var, e);
- z_51[0] = (z2[1] << 26) + z2[0];
- z_51[1] = (z2[3] << 26) + z2[2];
- z_51[2] = (z2[5] << 26) + z2[4];
- z_51[3] = (z2[7] << 26) + z2[6];
- z_51[4] = (z2[9] << 26) + z2[8];
- x_51[0] = (x2[1] << 26) + x2[0];
- x_51[1] = (x2[3] << 26) + x2[2];
- x_51[2] = (x2[5] << 26) + x2[4];
- x_51[3] = (x2[7] << 26) + x2[6];
- x_51[4] = (x2[9] << 26) + x2[8];
-#undef x1
-#undef x2
-#undef z2
- fe51_invert(&z_51, (const fe51 *)&z_51);
- curve25519_sandy2x_fe51_mul(&x_51, (const fe51 *)&x_51, (const fe51 *)&z_51);
- curve25519_sandy2x_fe51_pack(mypublic, (const fe51 *)&x_51);
-
- return true;
-}
diff --git a/kremlib.h b/kremlib.h
new file mode 100644
index 0000000..138846a
--- /dev/null
+++ b/kremlib.h
@@ -0,0 +1,569 @@
+/* MIT License
+ *
+ * Copyright (c) 2016-2017 INRIA and Microsoft Corporation
+ *
+ * Permission is hereby granted, free of charge, to any person obtaining a copy
+ * of this software and associated documentation files (the "Software"), to deal
+ * in the Software without restriction, including without limitation the rights
+ * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+ * copies of the Software, and to permit persons to whom the Software is
+ * furnished to do so, subject to the following conditions:
+ *
+ * The above copyright notice and this permission notice shall be included in all
+ * copies or substantial portions of the Software.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+ * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+ * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+ * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+ * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+ * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+ * SOFTWARE.
+ */
+#ifndef __KREMLIB_H
+#define __KREMLIB_H
+
+#include "kremlib_base.h"
+
+
+/* For tests only: we might need this function to be forward-declared, because
+ * the dependency on WasmSupport appears very late, after SimplifyWasm, and
+ * sadly, after the topological order has been done. */
+void WasmSupport_check_buffer_size(uint32_t s);
+
+/******************************************************************************/
+/* Stubs to ease compilation of non-Low* code */
+/******************************************************************************/
+
+/* Some types that KreMLin has no special knowledge of; many of them appear in
+ * signatures of ghost functions, meaning that it suffices to give them (any)
+ * definition. */
+typedef void *FStar_Seq_Base_seq, *Prims_prop, *FStar_HyperStack_mem,
+ *FStar_Set_set, *Prims_st_pre_h, *FStar_Heap_heap, *Prims_all_pre_h,
+ *FStar_TSet_set, *Prims_list, *FStar_Map_t, *FStar_UInt63_t_,
+ *FStar_Int63_t_, *FStar_UInt63_t, *FStar_Int63_t, *FStar_UInt_uint_t,
+ *FStar_Int_int_t, *FStar_HyperStack_stackref, *FStar_Bytes_bytes,
+ *FStar_HyperHeap_rid, *FStar_Heap_aref, *FStar_Monotonic_Heap_heap,
+ *FStar_Monotonic_Heap_aref, *FStar_Monotonic_HyperHeap_rid,
+ *FStar_Monotonic_HyperStack_mem, *FStar_Char_char_;
+
+typedef const char *Prims_string;
+
+/* For "bare" targets that do not have a C stdlib, the user might want to use
+ * [-add-include '"mydefinitions.h"'] and override these. */
+#ifndef KRML_HOST_PRINTF
+# define KRML_HOST_PRINTF printf
+#endif
+
+#ifndef KRML_HOST_EXIT
+# define KRML_HOST_EXIT exit
+#endif
+
+#ifndef KRML_HOST_MALLOC
+# define KRML_HOST_MALLOC malloc
+#endif
+
+/* In statement position, exiting is easy. */
+#define KRML_EXIT \
+ do { \
+ KRML_HOST_PRINTF("Unimplemented function at %s:%d\n", __FILE__, __LINE__); \
+ KRML_HOST_EXIT(254); \
+ } while (0)
+
+/* In expression position, use the comma-operator and a malloc to return an
+ * expression of the right size. KreMLin passes t as the parameter to the macro.
+ */
+#define KRML_EABORT(t, msg) \
+ (KRML_HOST_PRINTF("KreMLin abort at %s:%d\n%s\n", __FILE__, __LINE__, msg), \
+ KRML_HOST_EXIT(255), *((t *)KRML_HOST_MALLOC(sizeof(t))))
+
+/* In FStar.Buffer.fst, the size of arrays is uint32_t, but it's a number of
+ * *elements*. Do an ugly, run-time check (some of which KreMLin can eliminate).
+ */
+#define KRML_CHECK_SIZE(elt, size) \
+ if (((size_t)size) > SIZE_MAX / sizeof(elt)) { \
+ KRML_HOST_PRINTF( \
+ "Maximum allocatable size exceeded, aborting before overflow at " \
+ "%s:%d\n", \
+ __FILE__, __LINE__); \
+ KRML_HOST_EXIT(253); \
+ }
+
+/* A series of GCC atrocities to trace function calls (kremlin's [-d c-calls]
+ * option). Useful when trying to debug, say, Wasm, to compare traces. */
+/* clang-format off */
+#ifdef __GNUC__
+#define KRML_FORMAT(X) _Generic((X), \
+ uint8_t : "0x%08" PRIx8, \
+ uint16_t: "0x%08" PRIx16, \
+ uint32_t: "0x%08" PRIx32, \
+ uint64_t: "0x%08" PRIx64, \
+ int8_t : "0x%08" PRIx8, \
+ int16_t : "0x%08" PRIx16, \
+ int32_t : "0x%08" PRIx32, \
+ int64_t : "0x%08" PRIx64, \
+ default : "%s")
+
+#define KRML_FORMAT_ARG(X) _Generic((X), \
+ uint8_t : X, \
+ uint16_t: X, \
+ uint32_t: X, \
+ uint64_t: X, \
+ int8_t : X, \
+ int16_t : X, \
+ int32_t : X, \
+ int64_t : X, \
+ default : "unknown")
+/* clang-format on */
+
+# define KRML_DEBUG_RETURN(X) \
+ ({ \
+ __auto_type _ret = (X); \
+ KRML_HOST_PRINTF("returning: "); \
+ KRML_HOST_PRINTF(KRML_FORMAT(_ret), KRML_FORMAT_ARG(_ret)); \
+ KRML_HOST_PRINTF(" \n"); \
+ _ret; \
+ })
+#endif
+
+#define FStar_Buffer_eqb(b1, b2, n) \
+ (memcmp((b1), (b2), (n) * sizeof((b1)[0])) == 0)
+
+/* Stubs to make ST happy. Important note: you must generate a use of the macro
+ * argument, otherwise, you may have FStar_ST_recall(f) as the only use of f;
+ * KreMLin will think that this is a valid use, but then the C compiler, after
+ * macro expansion, will error out. */
+#define FStar_HyperHeap_root 0
+#define FStar_Pervasives_Native_fst(x) (x).fst
+#define FStar_Pervasives_Native_snd(x) (x).snd
+#define FStar_Seq_Base_createEmpty(x) 0
+#define FStar_Seq_Base_create(len, init) 0
+#define FStar_Seq_Base_upd(s, i, e) 0
+#define FStar_Seq_Base_eq(l1, l2) 0
+#define FStar_Seq_Base_length(l1) 0
+#define FStar_Seq_Base_append(x, y) 0
+#define FStar_Seq_Base_slice(x, y, z) 0
+#define FStar_Seq_Properties_snoc(x, y) 0
+#define FStar_Seq_Properties_cons(x, y) 0
+#define FStar_Seq_Base_index(x, y) 0
+#define FStar_HyperStack_is_eternal_color(x) 0
+#define FStar_Monotonic_HyperHeap_root 0
+#define FStar_Buffer_to_seq_full(x) 0
+#define FStar_Buffer_recall(x)
+#define FStar_HyperStack_ST_op_Colon_Equals(x, v) KRML_EXIT
+#define FStar_HyperStack_ST_op_Bang(x) 0
+#define FStar_HyperStack_ST_salloc(x) 0
+#define FStar_HyperStack_ST_ralloc(x, y) 0
+#define FStar_HyperStack_ST_new_region(x) (0)
+#define FStar_Monotonic_RRef_m_alloc(x) \
+ { 0 }
+
+#define FStar_HyperStack_ST_recall(x) \
+ do { \
+ (void)(x); \
+ } while (0)
+
+#define FStar_HyperStack_ST_recall_region(x) \
+ do { \
+ (void)(x); \
+ } while (0)
+
+#define FStar_Monotonic_RRef_m_recall(x1, x2) \
+ do { \
+ (void)(x1); \
+ (void)(x2); \
+ } while (0)
+
+#define FStar_Monotonic_RRef_m_write(x1, x2, x3, x4, x5) \
+ do { \
+ (void)(x1); \
+ (void)(x2); \
+ (void)(x3); \
+ (void)(x4); \
+ (void)(x5); \
+ } while (0)
+
+/******************************************************************************/
+/* Endian-ness macros that can only be implemented in C */
+/******************************************************************************/
+
+/* ... for Linux */
+#if defined(__linux__) || defined(__CYGWIN__)
+# include <endian.h>
+
+/* ... for OSX */
+#elif defined(__APPLE__)
+# include <libkern/OSByteOrder.h>
+# define htole64(x) OSSwapHostToLittleInt64(x)
+# define le64toh(x) OSSwapLittleToHostInt64(x)
+# define htobe64(x) OSSwapHostToBigInt64(x)
+# define be64toh(x) OSSwapBigToHostInt64(x)
+
+# define htole16(x) OSSwapHostToLittleInt16(x)
+# define le16toh(x) OSSwapLittleToHostInt16(x)
+# define htobe16(x) OSSwapHostToBigInt16(x)
+# define be16toh(x) OSSwapBigToHostInt16(x)
+
+# define htole32(x) OSSwapHostToLittleInt32(x)
+# define le32toh(x) OSSwapLittleToHostInt32(x)
+# define htobe32(x) OSSwapHostToBigInt32(x)
+# define be32toh(x) OSSwapBigToHostInt32(x)
+
+/* ... for Solaris */
+#elif defined(__sun__)
+# include <sys/byteorder.h>
+# define htole64(x) LE_64(x)
+# define le64toh(x) LE_64(x)
+# define htobe64(x) BE_64(x)
+# define be64toh(x) BE_64(x)
+
+# define htole16(x) LE_16(x)
+# define le16toh(x) LE_16(x)
+# define htobe16(x) BE_16(x)
+# define be16toh(x) BE_16(x)
+
+# define htole32(x) LE_32(x)
+# define le32toh(x) LE_32(x)
+# define htobe32(x) BE_32(x)
+# define be32toh(x) BE_32(x)
+
+/* ... for the BSDs */
+#elif defined(__FreeBSD__) || defined(__NetBSD__) || defined(__DragonFly__)
+# include <sys/endian.h>
+#elif defined(__OpenBSD__)
+# include <endian.h>
+
+/* ... for Windows (MSVC)... not targeting XBOX 360! */
+#elif defined(_MSC_VER)
+
+# include <stdlib.h>
+# define htobe16(x) _byteswap_ushort(x)
+# define htole16(x) (x)
+# define be16toh(x) _byteswap_ushort(x)
+# define le16toh(x) (x)
+
+# define htobe32(x) _byteswap_ulong(x)
+# define htole32(x) (x)
+# define be32toh(x) _byteswap_ulong(x)
+# define le32toh(x) (x)
+
+# define htobe64(x) _byteswap_uint64(x)
+# define htole64(x) (x)
+# define be64toh(x) _byteswap_uint64(x)
+# define le64toh(x) (x)
+
+/* ... for Windows (GCC-like, e.g. mingw or clang) */
+#elif (defined(_WIN32) || defined(_WIN64)) && \
+ (defined(__GNUC__) || defined(__clang__))
+
+# define htobe16(x) __builtin_bswap16(x)
+# define htole16(x) (x)
+# define be16toh(x) __builtin_bswap16(x)
+# define le16toh(x) (x)
+
+# define htobe32(x) __builtin_bswap32(x)
+# define htole32(x) (x)
+# define be32toh(x) __builtin_bswap32(x)
+# define le32toh(x) (x)
+
+# define htobe64(x) __builtin_bswap64(x)
+# define htole64(x) (x)
+# define be64toh(x) __builtin_bswap64(x)
+# define le64toh(x) (x)
+
+/* ... generic big-endian fallback code */
+#elif defined(__BYTE_ORDER__) && __BYTE_ORDER__ == __ORDER_BIG_ENDIAN__
+
+/* byte swapping code inspired by:
+ * https://github.com/rweather/arduinolibs/blob/master/libraries/Crypto/utility/EndianUtil.h
+ * */
+
+# define htobe32(x) (x)
+# define be32toh(x) (x)
+# define htole32(x) \
+ (__extension__({ \
+ uint32_t _temp = (x); \
+ ((_temp >> 24) & 0x000000FF) | ((_temp >> 8) & 0x0000FF00) | \
+ ((_temp << 8) & 0x00FF0000) | ((_temp << 24) & 0xFF000000); \
+ }))
+# define le32toh(x) (htole32((x)))
+
+# define htobe64(x) (x)
+# define be64toh(x) (x)
+# define htole64(x) \
+ (__extension__({ \
+ uint64_t __temp = (x); \
+ uint32_t __low = htobe32((uint32_t)__temp); \
+ uint32_t __high = htobe32((uint32_t)(__temp >> 32)); \
+ (((uint64_t)__low) << 32) | __high; \
+ }))
+# define le64toh(x) (htole64((x)))
+
+/* ... generic little-endian fallback code */
+#elif defined(__BYTE_ORDER__) && __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__
+
+# define htole32(x) (x)
+# define le32toh(x) (x)
+# define htobe32(x) \
+ (__extension__({ \
+ uint32_t _temp = (x); \
+ ((_temp >> 24) & 0x000000FF) | ((_temp >> 8) & 0x0000FF00) | \
+ ((_temp << 8) & 0x00FF0000) | ((_temp << 24) & 0xFF000000); \
+ }))
+# define be32toh(x) (htobe32((x)))
+
+# define htole64(x) (x)
+# define le64toh(x) (x)
+# define htobe64(x) \
+ (__extension__({ \
+ uint64_t __temp = (x); \
+ uint32_t __low = htobe32((uint32_t)__temp); \
+ uint32_t __high = htobe32((uint32_t)(__temp >> 32)); \
+ (((uint64_t)__low) << 32) | __high; \
+ }))
+# define be64toh(x) (htobe64((x)))
+
+/* ... couldn't determine endian-ness of the target platform */
+#else
+# error "Please define __BYTE_ORDER__!"
+
+#endif /* defined(__linux__) || ... */
+
+/* Loads and stores. These avoid undefined behavior due to unaligned memory
+ * accesses, via memcpy. */
+
+inline static uint16_t load16(uint8_t *b) {
+ uint16_t x;
+ memcpy(&x, b, 2);
+ return x;
+}
+
+inline static uint32_t load32(uint8_t *b) {
+ uint32_t x;
+ memcpy(&x, b, 4);
+ return x;
+}
+
+inline static uint64_t load64(uint8_t *b) {
+ uint64_t x;
+ memcpy(&x, b, 8);
+ return x;
+}
+
+inline static void store16(uint8_t *b, uint16_t i) { memcpy(b, &i, 2); }
+
+inline static void store32(uint8_t *b, uint32_t i) { memcpy(b, &i, 4); }
+
+inline static void store64(uint8_t *b, uint64_t i) { memcpy(b, &i, 8); }
+
+#define load16_le(b) (le16toh(load16(b)))
+#define store16_le(b, i) (store16(b, htole16(i)))
+#define load16_be(b) (be16toh(load16(b)))
+#define store16_be(b, i) (store16(b, htobe16(i)))
+
+#define load32_le(b) (le32toh(load32(b)))
+#define store32_le(b, i) (store32(b, htole32(i)))
+#define load32_be(b) (be32toh(load32(b)))
+#define store32_be(b, i) (store32(b, htobe32(i)))
+
+#define load64_le(b) (le64toh(load64(b)))
+#define store64_le(b, i) (store64(b, htole64(i)))
+#define load64_be(b) (be64toh(load64(b)))
+#define store64_be(b, i) (store64(b, htobe64(i)))
+
+/******************************************************************************/
+/* Checked integers to ease the compilation of non-Low* code */
+/******************************************************************************/
+
+typedef int32_t Prims_pos, Prims_nat, Prims_nonzero, Prims_int,
+ krml_checked_int_t;
+
+inline static bool Prims_op_GreaterThanOrEqual(int32_t x, int32_t y) {
+ return x >= y;
+}
+
+inline static bool Prims_op_LessThanOrEqual(int32_t x, int32_t y) {
+ return x <= y;
+}
+
+inline static bool Prims_op_GreaterThan(int32_t x, int32_t y) { return x > y; }
+
+inline static bool Prims_op_LessThan(int32_t x, int32_t y) { return x < y; }
+
+#define RETURN_OR(x) \
+ do { \
+ int64_t __ret = x; \
+ if (__ret < INT32_MIN || INT32_MAX < __ret) { \
+ KRML_HOST_PRINTF("Prims.{int,nat,pos} integer overflow at %s:%d\n", \
+ __FILE__, __LINE__); \
+ KRML_HOST_EXIT(252); \
+ } \
+ return (int32_t)__ret; \
+ } while (0)
+
+inline static int32_t Prims_pow2(int32_t x) {
+ RETURN_OR((int64_t)1 << (int64_t)x);
+}
+
+inline static int32_t Prims_op_Multiply(int32_t x, int32_t y) {
+ RETURN_OR((int64_t)x * (int64_t)y);
+}
+
+inline static int32_t Prims_op_Addition(int32_t x, int32_t y) {
+ RETURN_OR((int64_t)x + (int64_t)y);
+}
+
+inline static int32_t Prims_op_Subtraction(int32_t x, int32_t y) {
+ RETURN_OR((int64_t)x - (int64_t)y);
+}
+
+inline static int32_t Prims_op_Division(int32_t x, int32_t y) {
+ RETURN_OR((int64_t)x / (int64_t)y);
+}
+
+inline static int32_t Prims_op_Modulus(int32_t x, int32_t y) {
+ RETURN_OR((int64_t)x % (int64_t)y);
+}
+
+inline static int8_t FStar_UInt8_uint_to_t(int8_t x) { return x; }
+inline static int16_t FStar_UInt16_uint_to_t(int16_t x) { return x; }
+inline static int32_t FStar_UInt32_uint_to_t(int32_t x) { return x; }
+inline static int64_t FStar_UInt64_uint_to_t(int64_t x) { return x; }
+
+inline static int8_t FStar_UInt8_v(int8_t x) { return x; }
+inline static int16_t FStar_UInt16_v(int16_t x) { return x; }
+inline static int32_t FStar_UInt32_v(int32_t x) { return x; }
+inline static int64_t FStar_UInt64_v(int64_t x) { return x; }
+
+
+/* Platform-specific 128-bit arithmetic. These are static functions in a header,
+ * so that each translation unit gets its own copy and the C compiler can
+ * optimize. */
+#ifndef KRML_NOUINT128
+typedef unsigned __int128 FStar_UInt128_t, FStar_UInt128_t_, uint128_t;
+
+static inline void print128(const char *where, uint128_t n) {
+ KRML_HOST_PRINTF("%s: [%" PRIu64 ",%" PRIu64 "]\n", where,
+ (uint64_t)(n >> 64), (uint64_t)n);
+}
+
+static inline uint128_t load128_le(uint8_t *b) {
+ uint128_t l = (uint128_t)load64_le(b);
+ uint128_t h = (uint128_t)load64_le(b + 8);
+ return (h << 64 | l);
+}
+
+static inline void store128_le(uint8_t *b, uint128_t n) {
+ store64_le(b, (uint64_t)n);
+ store64_le(b + 8, (uint64_t)(n >> 64));
+}
+
+static inline uint128_t load128_be(uint8_t *b) {
+ uint128_t h = (uint128_t)load64_be(b);
+ uint128_t l = (uint128_t)load64_be(b + 8);
+ return (h << 64 | l);
+}
+
+static inline void store128_be(uint8_t *b, uint128_t n) {
+ store64_be(b, (uint64_t)(n >> 64));
+ store64_be(b + 8, (uint64_t)n);
+}
+
+# define FStar_UInt128_add(x, y) ((x) + (y))
+# define FStar_UInt128_mul(x, y) ((x) * (y))
+# define FStar_UInt128_add_mod(x, y) ((x) + (y))
+# define FStar_UInt128_sub(x, y) ((x) - (y))
+# define FStar_UInt128_sub_mod(x, y) ((x) - (y))
+# define FStar_UInt128_logand(x, y) ((x) & (y))
+# define FStar_UInt128_logor(x, y) ((x) | (y))
+# define FStar_UInt128_logxor(x, y) ((x) ^ (y))
+# define FStar_UInt128_lognot(x) (~(x))
+# define FStar_UInt128_shift_left(x, y) ((x) << (y))
+# define FStar_UInt128_shift_right(x, y) ((x) >> (y))
+# define FStar_UInt128_uint64_to_uint128(x) ((uint128_t)(x))
+# define FStar_UInt128_uint128_to_uint64(x) ((uint64_t)(x))
+# define FStar_UInt128_mul_wide(x, y) ((uint128_t)(x) * (y))
+# define FStar_UInt128_op_Hat_Hat(x, y) ((x) ^ (y))
+
+static inline uint128_t FStar_UInt128_eq_mask(uint128_t x, uint128_t y) {
+ uint64_t mask =
+ FStar_UInt64_eq_mask((uint64_t)(x >> 64), (uint64_t)(y >> 64)) &
+ FStar_UInt64_eq_mask(x, y);
+ return ((uint128_t)mask) << 64 | mask;
+}
+
+static inline uint128_t FStar_UInt128_gte_mask(uint128_t x, uint128_t y) {
+ uint64_t mask =
+ (FStar_UInt64_gte_mask(x >> 64, y >> 64) &
+ ~(FStar_UInt64_eq_mask(x >> 64, y >> 64))) |
+ (FStar_UInt64_eq_mask(x >> 64, y >> 64) & FStar_UInt64_gte_mask(x, y));
+ return ((uint128_t)mask) << 64 | mask;
+}
+
+
+
+# else /* !defined(KRML_NOUINT128) */
+
+ /* This is a bad circular dependency... should fix it properly. */
+# include "FStar.h"
+
+typedef FStar_UInt128_uint128 FStar_UInt128_t_, uint128_t;
+
+/* A series of definitions written using pointers. */
+static inline void print128_(const char *where, uint128_t *n) {
+ KRML_HOST_PRINTF("%s: [0x%08" PRIx64 ",0x%08" PRIx64 "]\n", where, n->high, n->low);
+}
+
+static inline void load128_le_(uint8_t *b, uint128_t *r) {
+ r->low = load64_le(b);
+ r->high = load64_le(b + 8);
+}
+
+static inline void store128_le_(uint8_t *b, uint128_t *n) {
+ store64_le(b, n->low);
+ store64_le(b + 8, n->high);
+}
+
+static inline void load128_be_(uint8_t *b, uint128_t *r) {
+ r->high = load64_be(b);
+ r->low = load64_be(b + 8);
+}
+
+static inline void store128_be_(uint8_t *b, uint128_t *n) {
+ store64_be(b, n->high);
+ store64_be(b + 8, n->low);
+}
+
+# ifndef KRML_NOSTRUCT_PASSING
+
+static inline void print128(const char *where, uint128_t n) {
+ print128_(where, &n);
+}
+
+static inline uint128_t load128_le(uint8_t *b) {
+ uint128_t r;
+ load128_le_(b, &r);
+ return r;
+}
+
+static inline void store128_le(uint8_t *b, uint128_t n) { store128_le_(b, &n); }
+
+static inline uint128_t load128_be(uint8_t *b) {
+ uint128_t r;
+ load128_be_(b, &r);
+ return r;
+}
+
+static inline void store128_be(uint8_t *b, uint128_t n) { store128_be_(b, &n); }
+
+# else /* !defined(KRML_STRUCT_PASSING) */
+
+# define print128 print128_
+# define load128_le load128_le_
+# define store128_le store128_le_
+# define load128_be load128_be_
+# define store128_be store128_be_
+
+# endif /* KRML_STRUCT_PASSING */
+# endif /* KRML_UINT128 */
+#endif /* __KREMLIB_H */
diff --git a/main.c b/main.c
index 09c7376..e5eb5fd 100644
--- a/main.c
+++ b/main.c
@@ -16,15 +16,15 @@ module_param(stamp, ulong, 0);
int dummy;
-enum { CURVE25519_POINT_SIZE = 32 };
-u8 dummy_out[CURVE25519_POINT_SIZE];
+enum { POLY1305_MAC_SIZE = 16, POLY1305_KEY_SIZE = 32 };
+u8 dummy_out[POLY1305_MAC_SIZE];
#include "test_vectors.h"
#define declare_it(name) \
-bool curve25519_ ## name(u8 mypublic[CURVE25519_POINT_SIZE], const u8 secret[CURVE25519_POINT_SIZE], const u8 basepoint[CURVE25519_POINT_SIZE]); \
+ bool poly1305_ ## name(u8 tag[POLY1305_MAC_SIZE], const u8 * msg, const u32 len, const u8 key[POLY1305_KEY_SIZE]); \
static __always_inline int name(void) \
{ \
- return curve25519_ ## name(dummy_out, curve25519_test_vectors[0].private, curve25519_test_vectors[0].public); \
+ return poly1305_ ## name(dummy_out, poly1305_test_vectors[0].input.data, poly1305_test_vectors[0].input.size, poly1305_test_vectors[0].key.data); \
}
#define do_it(name) do { \
@@ -37,11 +37,11 @@ static __always_inline int name(void) \
} while (0)
#define test_it(name, before, after) do { \
- memset(out, __LINE__, CURVE25519_POINT_SIZE); \
+ memset(out, __LINE__, POLY1305_MAC_SIZE); \
before; \
- ret = curve25519_ ## name(out, curve25519_test_vectors[i].private, curve25519_test_vectors[i].public); \
+ ret = poly1305_ ## name(out, poly1305_test_vectors[i].input.data,poly1305_test_vectors[i].input.size,poly1305_test_vectors[i].key.data); \
after; \
- if (memcmp(out, curve25519_test_vectors[i].result, CURVE25519_POINT_SIZE)) { \
+ if (memcmp(out, poly1305_test_vectors[i].expected.data, POLY1305_MAC_SIZE)) { \
pr_err(#name " self-test %zu: FAIL\n", i + 1); \
return false; \
} \
@@ -52,30 +52,16 @@ static __always_inline int name(void) \
} while (0)
-declare_it(donna64)
declare_it(hacl64)
-declare_it(fiat64)
-declare_it(sandy2x)
-declare_it(amd64)
-declare_it(precomp)
-declare_it(fiat32)
-declare_it(donna32)
static bool verify(void)
{
int ret;
size_t i = 0;
- u8 out[CURVE25519_POINT_SIZE];
+ u8 out[POLY1305_MAC_SIZE];
- for (i = 0; i < ARRAY_SIZE(curve25519_test_vectors); ++i) {
- test_it(donna64, {}, {});
+ for (i = 0; i < ARRAY_SIZE(poly1305_test_vectors); ++i) {
test_it(hacl64, {}, {});
- test_it(fiat64, {}, {});
- test_it(sandy2x, kernel_fpu_begin(), kernel_fpu_end());
- test_it(amd64, {}, {});
- test_it(precomp, {}, {});
- test_it(fiat32, {}, {});
- test_it(donna32, {}, {});
}
return true;
}
@@ -84,14 +70,7 @@ static int __init mod_init(void)
{
enum { WARMUP = 5000, TRIALS = 10000, IDLE = 1 * 1000 };
int ret = 0, i;
- cycles_t start_donna64, end_donna64;
cycles_t start_hacl64, end_hacl64;
- cycles_t start_fiat64, end_fiat64;
- cycles_t start_sandy2x, end_sandy2x;
- cycles_t start_amd64, end_amd64;
- cycles_t start_precomp, end_precomp;
- cycles_t start_fiat32, end_fiat32;
- cycles_t start_donna32, end_donna32;
unsigned long flags;
DEFINE_SPINLOCK(lock);
@@ -102,27 +81,11 @@ static int __init mod_init(void)
spin_lock_irqsave(&lock, flags);
- do_it(donna64);
do_it(hacl64);
- do_it(fiat64);
- kernel_fpu_begin();
- do_it(sandy2x);
- kernel_fpu_end();
- do_it(amd64);
- do_it(precomp);
- do_it(fiat32);
- do_it(donna32);
spin_unlock_irqrestore(&lock, flags);
- report_it(donna64);
report_it(hacl64);
- report_it(fiat64);
- report_it(sandy2x);
- report_it(amd64);
- report_it(precomp);
- report_it(fiat32);
- report_it(donna32);
/* Don't let compiler be too clever. */
dummy = ret;
diff --git a/poly1305-hacl64.c b/poly1305-hacl64.c
new file mode 100644
index 0000000..a4dd761
--- /dev/null
+++ b/poly1305-hacl64.c
@@ -0,0 +1,569 @@
+/* MIT License
+ *
+ * Copyright (c) 2016-2017 INRIA and Microsoft Corporation
+ *
+ * Permission is hereby granted, free of charge, to any person obtaining a copy
+ * of this software and associated documentation files (the "Software"), to deal
+ * in the Software without restriction, including without limitation the rights
+ * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
+ * copies of the Software, and to permit persons to whom the Software is
+ * furnished to do so, subject to the following conditions:
+ *
+ * The above copyright notice and this permission notice shall be included in all
+ * copies or substantial portions of the Software.
+ *
+ * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
+ * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
+ * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
+ * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
+ * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
+ * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
+ * SOFTWARE.
+ */
+
+#include <linux/kernel.h>
+#include <linux/string.h>
+
+typedef struct
+{
+ u64 *r;
+ u64 *h;
+}
+Hacl_Impl_Poly1305_64_State_poly1305_state;
+
+typedef __uint128_t u128;
+
+#define u128_logand(a,b) ((a) & (b))
+#define u128_logor(a,b) ((a) | (b))
+#define u128_add(a,b) ((a) + (b))
+#define u128_add_mod(a,b) ((a) + (b))
+#define u128_shift_right(a,b) ((a) >> (b))
+#define u128_shift_left(a,b) ((a) << (b))
+#define u128_mul_wide(a,b) (((u128)(a)) * b)
+
+#define KRML_CHECK_SIZE(a,b) {}
+#define u64_to_u128(a) ((u128)a)
+#define u128_to_u64(a) ((u64)a)
+
+static inline u64 FStar_UInt64_eq_mask(u64 x, u64 y) {
+ x = ~(x ^ y);
+ x &= x << 32;
+ x &= x << 16;
+ x &= x << 8;
+ x &= x << 4;
+ x &= x << 2;
+ x &= x << 1;
+ return ((s64)x) >> 63;
+}
+
+static inline u64 FStar_UInt64_gte_mask(u64 x, u64 y) {
+ u64 low63 =
+ ~((u64)((s64)((s64)(x & (u64)(0x7fffffffffffffff)) -
+ (s64)(y & (u64)(0x7fffffffffffffff))) >>
+ 63));
+ u64 high_bit =
+ ~((u64)((s64)((s64)(x & (u64)(0x8000000000000000)) -
+ (s64)(y & (u64)(0x8000000000000000))) >>
+ 63));
+ return low63 & high_bit;
+}
+
+static inline u128 load128_le(u8 *b) {
+ u64 l = le64_to_cpup((__force __le64 *)b);
+ u64 h = le64_to_cpup((__force __le64 *)(b+8));
+ return ((((u128)h) << 64) | l);
+}
+
+static inline void store128_le(u8 *b, u128 n) {
+ *(__force __le64 *)b = cpu_to_le64((u64)n);
+ *(__force __le64 *)(b+8) = cpu_to_le64((u64)(n >> 64));
+}
+
+inline static void Hacl_Bignum_Modulo_reduce(u64 *b)
+{
+ u64 b0 = b[0U];
+ b[0U] = (b0 << (u32)4U) + (b0 << (u32)2U);
+}
+
+inline static void Hacl_Bignum_Modulo_carry_top(u64 *b)
+{
+ u64 b2 = b[2U];
+ u64 b0 = b[0U];
+ u64 b2_42 = b2 >> (u32)42U;
+ b[2U] = b2 & (u64)0x3ffffffffffU;
+ b[0U] = (b2_42 << (u32)2U) + b2_42 + b0;
+}
+
+inline static void Hacl_Bignum_Modulo_carry_top_wide(u128 *b)
+{
+ u128 b2 = b[2U];
+ u128 b0 = b[0U];
+ u128
+ b2_ = u128_logand(b2, u64_to_u128((u64)0x3ffffffffffU));
+ u64 b2_42 = u128_to_u64(u128_shift_right(b2, (u32)42U));
+ u128
+ b0_ = u128_add(b0, u64_to_u128((b2_42 << (u32)2U) + b2_42));
+ b[2U] = b2_;
+ b[0U] = b0_;
+}
+
+inline static void
+Hacl_Bignum_Fproduct_copy_from_wide_(u64 *output, u128 *input)
+{
+ u32 i;
+ for (i = (u32)0U; i < (u32)3U; i = i + (u32)1U)
+ {
+ u128 xi = input[i];
+ output[i] = u128_to_u64(xi);
+ }
+}
+
+inline static void
+Hacl_Bignum_Fproduct_sum_scalar_multiplication_(
+ u128 *output,
+ u64 *input,
+ u64 s
+)
+{
+ u32 i;
+ for (i = (u32)0U; i < (u32)3U; i = i + (u32)1U)
+ {
+ u128 xi = output[i];
+ u64 yi = input[i];
+ output[i] = u128_add_mod(xi, u128_mul_wide(yi, s));
+ }
+}
+
+inline static void Hacl_Bignum_Fproduct_carry_wide_(u128 *tmp)
+{
+ u32 i;
+ for (i = (u32)0U; i < (u32)2U; i = i + (u32)1U)
+ {
+ u32 ctr = i;
+ u128 tctr = tmp[ctr];
+ u128 tctrp1 = tmp[ctr + (u32)1U];
+ u64 r0 = u128_to_u64(tctr) & (u64)0xfffffffffffU;
+ u128 c = u128_shift_right(tctr, (u32)44U);
+ tmp[ctr] = u64_to_u128(r0);
+ tmp[ctr + (u32)1U] = u128_add(tctrp1, c);
+ }
+}
+
+inline static void Hacl_Bignum_Fproduct_carry_limb_(u64 *tmp)
+{
+ u32 i;
+ for (i = (u32)0U; i < (u32)2U; i = i + (u32)1U)
+ {
+ u32 ctr = i;
+ u64 tctr = tmp[ctr];
+ u64 tctrp1 = tmp[ctr + (u32)1U];
+ u64 r0 = tctr & (u64)0xfffffffffffU;
+ u64 c = tctr >> (u32)44U;
+ tmp[ctr] = r0;
+ tmp[ctr + (u32)1U] = tctrp1 + c;
+ }
+}
+
+inline static void Hacl_Bignum_Fmul_shift_reduce(u64 *output)
+{
+ u64 tmp = output[2U];
+ u32 i;
+ for (i = (u32)0U; i < (u32)2U; i = i + (u32)1U)
+ {
+ u32 ctr = (u32)3U - i - (u32)1U;
+ u64 z = output[ctr - (u32)1U];
+ output[ctr] = z;
+ }
+ output[0U] = tmp;
+ Hacl_Bignum_Modulo_reduce(output);
+}
+
+static void
+Hacl_Bignum_Fmul_mul_shift_reduce_(u128 *output, u64 *input, u64 *input2)
+{
+ u32 i;
+ for (i = (u32)0U; i < (u32)2U; i = i + (u32)1U)
+ {
+ u64 input2i = input2[i];
+ Hacl_Bignum_Fproduct_sum_scalar_multiplication_(output, input, input2i);
+ Hacl_Bignum_Fmul_shift_reduce(input);
+ }
+ u64 input2i = input2[i];
+ Hacl_Bignum_Fproduct_sum_scalar_multiplication_(output, input, input2i);
+}
+
+inline static void Hacl_Bignum_Fmul_fmul(u64 *output, u64 *input, u64 *input2)
+{
+ u64 tmp[3U] = { 0U };
+ memcpy(tmp, input, (u32)3U * sizeof input[0U]);
+ KRML_CHECK_SIZE(u64_to_u128((u64)0U), (u32)3U);
+ u128 t[3U] = {0};
+
+ Hacl_Bignum_Fmul_mul_shift_reduce_(t, tmp, input2);
+ Hacl_Bignum_Fproduct_carry_wide_(t);
+ Hacl_Bignum_Modulo_carry_top_wide(t);
+ Hacl_Bignum_Fproduct_copy_from_wide_(output, t);
+ u64 i0 = output[0U];
+ u64 i1 = output[1U];
+ u64 i0_ = i0 & (u64)0xfffffffffffU;
+ u64 i1_ = i1 + (i0 >> (u32)44U);
+ output[0U] = i0_;
+ output[1U] = i1_;
+}
+
+inline static void
+Hacl_Bignum_AddAndMultiply_add_and_multiply(u64 *acc, u64 *block, u64 *r)
+{
+ u32 i;
+ for (i = (u32)0U; i < (u32)3U; i = i + (u32)1U)
+ {
+ u64 xi = acc[i];
+ u64 yi = block[i];
+ acc[i] = xi + yi;
+ }
+ Hacl_Bignum_Fmul_fmul(acc, acc, r);
+}
+
+inline static void
+Hacl_Impl_Poly1305_64_poly1305_update(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *m
+)
+{
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut0 = st;
+ u64 *h = scrut0.h;
+ u64 *acc = h;
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *r = scrut.r;
+ u64 *r3 = r;
+ u64 tmp[3U] = { 0U };
+ u128 m0 = load128_le(m);
+ u64 r0 = u128_to_u64(m0) & (u64)0xfffffffffffU;
+ u64
+ r1 =
+ u128_to_u64(u128_shift_right(m0, (u32)44U))
+ & (u64)0xfffffffffffU;
+ u64 r2 = u128_to_u64(u128_shift_right(m0, (u32)88U));
+ tmp[0U] = r0;
+ tmp[1U] = r1;
+ tmp[2U] = r2;
+ u64 b2 = tmp[2U];
+ u64 b2_ = (u64)0x10000000000U | b2;
+ tmp[2U] = b2_;
+ Hacl_Bignum_AddAndMultiply_add_and_multiply(acc, tmp, r3);
+}
+
+inline static void
+Hacl_Impl_Poly1305_64_poly1305_process_last_block_(
+ u8 *block,
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *m,
+ u64 rem_
+)
+{
+ u64 tmp[3U] = { 0U };
+ u128 m0 = load128_le(block);
+ u64 r0 = u128_to_u64(m0) & (u64)0xfffffffffffU;
+ u64
+ r1 =
+ u128_to_u64(u128_shift_right(m0, (u32)44U))
+ & (u64)0xfffffffffffU;
+ u64 r2 = u128_to_u64(u128_shift_right(m0, (u32)88U));
+ tmp[0U] = r0;
+ tmp[1U] = r1;
+ tmp[2U] = r2;
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut0 = st;
+ u64 *h = scrut0.h;
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *r = scrut.r;
+ Hacl_Bignum_AddAndMultiply_add_and_multiply(h, tmp, r);
+}
+
+inline static void
+Hacl_Impl_Poly1305_64_poly1305_process_last_block(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *m,
+ u64 rem_
+)
+{
+ u8 zero1 = (u8)0U;
+ KRML_CHECK_SIZE(zero1, (u32)16U);
+ u8 block[16U] = {0};
+ u32 i0 = (u32)rem_;
+ u32 i = (u32)rem_;
+ memcpy(block, m, i * sizeof m[0U]);
+ block[i0] = (u8)1U;
+ Hacl_Impl_Poly1305_64_poly1305_process_last_block_(block, st, m, rem_);
+}
+
+static void Hacl_Impl_Poly1305_64_poly1305_last_pass(u64 *acc)
+{
+ Hacl_Bignum_Fproduct_carry_limb_(acc);
+ Hacl_Bignum_Modulo_carry_top(acc);
+ u64 a0 = acc[0U];
+ u64 a10 = acc[1U];
+ u64 a20 = acc[2U];
+ u64 a0_ = a0 & (u64)0xfffffffffffU;
+ u64 r0 = a0 >> (u32)44U;
+ u64 a1_ = (a10 + r0) & (u64)0xfffffffffffU;
+ u64 r1 = (a10 + r0) >> (u32)44U;
+ u64 a2_ = a20 + r1;
+ acc[0U] = a0_;
+ acc[1U] = a1_;
+ acc[2U] = a2_;
+ Hacl_Bignum_Modulo_carry_top(acc);
+ u64 i0 = acc[0U];
+ u64 i1 = acc[1U];
+ u64 i0_ = i0 & (u64)0xfffffffffffU;
+ u64 i1_ = i1 + (i0 >> (u32)44U);
+ acc[0U] = i0_;
+ acc[1U] = i1_;
+ u64 a00 = acc[0U];
+ u64 a1 = acc[1U];
+ u64 a2 = acc[2U];
+ u64 mask0 = FStar_UInt64_gte_mask(a00, (u64)0xffffffffffbU);
+ u64 mask1 = FStar_UInt64_eq_mask(a1, (u64)0xfffffffffffU);
+ u64 mask2 = FStar_UInt64_eq_mask(a2, (u64)0x3ffffffffffU);
+ u64 mask = (mask0 & mask1) & mask2;
+ u64 a0_0 = a00 - ((u64)0xffffffffffbU & mask);
+ u64 a1_0 = a1 - ((u64)0xfffffffffffU & mask);
+ u64 a2_0 = a2 - ((u64)0x3ffffffffffU & mask);
+ acc[0U] = a0_0;
+ acc[1U] = a1_0;
+ acc[2U] = a2_0;
+}
+
+static Hacl_Impl_Poly1305_64_State_poly1305_state
+Hacl_Impl_Poly1305_64_mk_state(u64 *r, u64 *h)
+{
+ return ((Hacl_Impl_Poly1305_64_State_poly1305_state){ .r = r, .h = h });
+}
+
+static void
+Hacl_Standalone_Poly1305_64_poly1305_blocks(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *m,
+ u64 len1
+)
+{
+ if (!(len1 == (u64)0U))
+ {
+ u8 *block = m;
+ u8 *tail1 = m + (u32)16U;
+ Hacl_Impl_Poly1305_64_poly1305_update(st, block);
+ u64 len2 = len1 - (u64)1U;
+ Hacl_Standalone_Poly1305_64_poly1305_blocks(st, tail1, len2);
+ }
+}
+
+static void
+Hacl_Standalone_Poly1305_64_poly1305_partial(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *input,
+ u64 len1,
+ u8 *kr
+)
+{
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *r = scrut.r;
+ u64 *x0 = r;
+ u128 k1 = load128_le(kr);
+ u128
+ k_clamped =
+ u128_logand(k1,
+ u128_logor(u128_shift_left(u64_to_u128((u64)0x0ffffffc0ffffffcU),
+ (u32)64U),
+ u64_to_u128((u64)0x0ffffffc0fffffffU)));
+ u64 r0 = u128_to_u64(k_clamped) & (u64)0xfffffffffffU;
+ u64
+ r1 =
+ u128_to_u64(u128_shift_right(k_clamped, (u32)44U))
+ & (u64)0xfffffffffffU;
+ u64
+ r2 = u128_to_u64(u128_shift_right(k_clamped, (u32)88U));
+ x0[0U] = r0;
+ x0[1U] = r1;
+ x0[2U] = r2;
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut0 = st;
+ u64 *h = scrut0.h;
+ u64 *x00 = h;
+ x00[0U] = (u64)0U;
+ x00[1U] = (u64)0U;
+ x00[2U] = (u64)0U;
+ Hacl_Standalone_Poly1305_64_poly1305_blocks(st, input, len1);
+}
+
+static void
+Hacl_Standalone_Poly1305_64_poly1305_complete(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *m,
+ u64 len1,
+ u8 *k1
+)
+{
+ u8 *kr = k1;
+ u64 len16 = len1 >> (u32)4U;
+ u64 rem16 = len1 & (u64)0xfU;
+ u8 *part_input = m;
+ u8 *last_block = m + (u32)((u64)16U * len16);
+ Hacl_Standalone_Poly1305_64_poly1305_partial(st, part_input, len16, kr);
+ if (!(rem16 == (u64)0U))
+ Hacl_Impl_Poly1305_64_poly1305_process_last_block(st, last_block, rem16);
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *h = scrut.h;
+ u64 *acc = h;
+ Hacl_Impl_Poly1305_64_poly1305_last_pass(acc);
+}
+
+static void
+Hacl_Standalone_Poly1305_64_crypto_onetimeauth_(
+ u8 *output,
+ u8 *input,
+ u64 len1,
+ u8 *k1
+)
+{
+ u64 buf[6U] = { 0U };
+ u64 *r = buf;
+ u64 *h = buf + (u32)3U;
+ Hacl_Impl_Poly1305_64_State_poly1305_state st = Hacl_Impl_Poly1305_64_mk_state(r, h);
+ u8 *key_s = k1 + (u32)16U;
+ Hacl_Standalone_Poly1305_64_poly1305_complete(st, input, len1, k1);
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *h3 = scrut.h;
+ u64 *acc = h3;
+ u128 k_ = load128_le(key_s);
+ u64 h0 = acc[0U];
+ u64 h1 = acc[1U];
+ u64 h2 = acc[2U];
+ u128
+ acc_ =
+ u128_logor(u128_shift_left(u64_to_u128(h2
+ << (u32)24U
+ | h1 >> (u32)20U),
+ (u32)64U),
+ u64_to_u128(h1 << (u32)44U | h0));
+ u128 mac_ = u128_add_mod(acc_, k_);
+ store128_le(output, mac_);
+}
+
+static void
+Hacl_Standalone_Poly1305_64_crypto_onetimeauth(
+ u8 *output,
+ u8 *input,
+ u64 len1,
+ u8 *k1
+)
+{
+ Hacl_Standalone_Poly1305_64_crypto_onetimeauth_(output, input, len1, k1);
+}
+
+Hacl_Impl_Poly1305_64_State_poly1305_state
+Hacl_Poly1305_64_mk_state(u64 *r, u64 *acc)
+{
+ return Hacl_Impl_Poly1305_64_mk_state(r, acc);
+}
+
+void Hacl_Poly1305_64_init(Hacl_Impl_Poly1305_64_State_poly1305_state st, u8 *k1)
+{
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *r = scrut.r;
+ u64 *x0 = r;
+ u128 k10 = load128_le(k1);
+ u128
+ k_clamped =
+ u128_logand(k10,
+ u128_logor(u128_shift_left(u64_to_u128((u64)0x0ffffffc0ffffffcU),
+ (u32)64U),
+ u64_to_u128((u64)0x0ffffffc0fffffffU)));
+ u64 r0 = u128_to_u64(k_clamped) & (u64)0xfffffffffffU;
+ u64
+ r1 =
+ u128_to_u64(u128_shift_right(k_clamped, (u32)44U))
+ & (u64)0xfffffffffffU;
+ u64
+ r2 = u128_to_u64(u128_shift_right(k_clamped, (u32)88U));
+ x0[0U] = r0;
+ x0[1U] = r1;
+ x0[2U] = r2;
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut0 = st;
+ u64 *h = scrut0.h;
+ u64 *x00 = h;
+ x00[0U] = (u64)0U;
+ x00[1U] = (u64)0U;
+ x00[2U] = (u64)0U;
+}
+
+void Hacl_Poly1305_64_update_block(Hacl_Impl_Poly1305_64_State_poly1305_state st, u8 *m)
+{
+ Hacl_Impl_Poly1305_64_poly1305_update(st, m);
+}
+
+void
+Hacl_Poly1305_64_update(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *m,
+ u32 num_blocks
+)
+{
+ if (!(num_blocks == (u32)0U))
+ {
+ u8 *block = m;
+ u8 *m_ = m + (u32)16U;
+ u32 n1 = num_blocks - (u32)1U;
+ Hacl_Poly1305_64_update_block(st, block);
+ Hacl_Poly1305_64_update(st, m_, n1);
+ }
+}
+
+void
+Hacl_Poly1305_64_update_last(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *m,
+ u32 len1
+)
+{
+ if (!((u64)len1 == (u64)0U))
+ Hacl_Impl_Poly1305_64_poly1305_process_last_block(st, m, (u64)len1);
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *h = scrut.h;
+ u64 *acc = h;
+ Hacl_Impl_Poly1305_64_poly1305_last_pass(acc);
+}
+
+void
+Hacl_Poly1305_64_finish(
+ Hacl_Impl_Poly1305_64_State_poly1305_state st,
+ u8 *mac,
+ u8 *k1
+)
+{
+ Hacl_Impl_Poly1305_64_State_poly1305_state scrut = st;
+ u64 *h = scrut.h;
+ u64 *acc = h;
+ u128 k_ = load128_le(k1);
+ u64 h0 = acc[0U];
+ u64 h1 = acc[1U];
+ u64 h2 = acc[2U];
+ u128
+ acc_ =
+ u128_logor(u128_shift_left(u64_to_u128(h2
+ << (u32)24U
+ | h1 >> (u32)20U),
+ (u32)64U),
+ u64_to_u128(h1 << (u32)44U | h0));
+ u128 mac_ = u128_add_mod(acc_, k_);
+ store128_le(mac, mac_);
+}
+
+void
+poly1305_hacl64(
+ u8 *output,
+ u8 *input,
+ u64 len1,
+ u8 *k1
+)
+{
+ Hacl_Standalone_Poly1305_64_crypto_onetimeauth(output, input, len1, k1);
+}
+
diff --git a/res b/res
new file mode 100644
index 0000000..2e21662
--- /dev/null
+++ b/res
@@ -0,0 +1,26005 @@
+make -C /lib/modules/4.10.0-42-generic/build M=/home/bhargava/Desktop/repositories/kbench9000
+make[1]: Entering directory '/usr/src/linux-headers-4.10.0-42-generic'
+ CC [M] /home/bhargava/Desktop/repositories/kbench9000/main.o
+In file included from /home/bhargava/Desktop/repositories/kbench9000/main.c:9:0:
+/home/bhargava/Desktop/repositories/kbench9000/function.h: In function ‘poly1305’:
+/home/bhargava/Desktop/repositories/kbench9000/function.h:12:1: warning: empty declaration
+ struct poly1305_testdata {
+ ^~~~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:17:1: warning: empty declaration
+ struct poly1305_testvec {
+ ^~~~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:21:38: error: storage class specified for parameter ‘poly1305_testvecs’
+ static const struct poly1305_testvec poly1305_testvecs[] = {
+ ^~~~~~~~~~~~~~~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:21:21: error: parameter ‘poly1305_testvecs’ is initialized
+ static const struct poly1305_testvec poly1305_testvecs[] = {
+ ^~~~~~~~~~~~~~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:25:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:25:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:26:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:26:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:27:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 34,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:27:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:28:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:28:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:11: warning: excess elements in scalar initializer
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:17: warning: excess elements in scalar initializer
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:23: warning: excess elements in scalar initializer
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:29: warning: excess elements in scalar initializer
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:35: warning: excess elements in scalar initializer
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:41: warning: excess elements in scalar initializer
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:47: warning: excess elements in scalar initializer
+ 0x43, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x67, 0x72,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:29:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:5: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:11: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:17: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:23: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:29: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:35: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:41: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:47: warning: excess elements in scalar initializer
+ 0x61, 0x70, 0x68, 0x69, 0x63, 0x20, 0x46, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:30:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:5: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:11: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:17: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:23: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:29: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:35: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:41: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:47: warning: excess elements in scalar initializer
+ 0x72, 0x75, 0x6d, 0x20, 0x52, 0x65, 0x73, 0x65,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:31:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:5: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:11: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:17: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:23: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:29: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:35: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:41: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:47: warning: excess elements in scalar initializer
+ 0x61, 0x72, 0x63, 0x68, 0x20, 0x47, 0x72, 0x6f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:32:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:34:5: warning: excess elements in scalar initializer
+ 0x75, 0x70
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:34:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:34:11: warning: excess elements in scalar initializer
+ 0x75, 0x70
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:34:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:28:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:28:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:37:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:37:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:38:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:38:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:39:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:39:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:11: warning: excess elements in scalar initializer
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:17: warning: excess elements in scalar initializer
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:23: warning: excess elements in scalar initializer
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:29: warning: excess elements in scalar initializer
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:35: warning: excess elements in scalar initializer
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:41: warning: excess elements in scalar initializer
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:47: warning: excess elements in scalar initializer
+ 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:40:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:5: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:11: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:17: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:23: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:29: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:35: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:41: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:47: warning: excess elements in scalar initializer
+ 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:41:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:5: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:11: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:17: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:23: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:29: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:35: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:41: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:47: warning: excess elements in scalar initializer
+ 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:42:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:5: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:11: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:17: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:23: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:29: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:35: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:41: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:47: warning: excess elements in scalar initializer
+ 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:43:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:39:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:39:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:37:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:37:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:46:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:46:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:47:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:47:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:48:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:48:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:11: warning: excess elements in scalar initializer
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:17: warning: excess elements in scalar initializer
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:23: warning: excess elements in scalar initializer
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:29: warning: excess elements in scalar initializer
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:35: warning: excess elements in scalar initializer
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:41: warning: excess elements in scalar initializer
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:47: warning: excess elements in scalar initializer
+ 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:49:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:5: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:11: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:17: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:23: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:29: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:35: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:41: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:47: warning: excess elements in scalar initializer
+ 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:50:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:48:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:48:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:46:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:46:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:57:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:57:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:58:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:58:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:59:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 2,
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:59:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:60:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:60:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:61:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xf3, 0xf6
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:61:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:61:11: warning: excess elements in scalar initializer
+ 0xf3, 0xf6
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:61:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:60:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:60:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:64:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:64:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:65:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:65:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:66:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:66:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:11: warning: excess elements in scalar initializer
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:17: warning: excess elements in scalar initializer
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:23: warning: excess elements in scalar initializer
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:29: warning: excess elements in scalar initializer
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:35: warning: excess elements in scalar initializer
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:41: warning: excess elements in scalar initializer
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:47: warning: excess elements in scalar initializer
+ 0x85, 0x1f, 0xc4, 0x0c, 0x34, 0x67, 0xac, 0x0b,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:67:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:5: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:11: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:17: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:23: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:29: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:35: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:41: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:47: warning: excess elements in scalar initializer
+ 0xe0, 0x5c, 0xc2, 0x04, 0x04, 0xf3, 0xf7, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:68:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:5: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:11: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:17: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:23: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:29: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:35: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:41: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:47: warning: excess elements in scalar initializer
+ 0x58, 0x0b, 0x3b, 0x0f, 0x94, 0x47, 0xbb, 0x1e,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:69:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:5: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:11: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:17: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:23: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:29: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:35: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:41: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:47: warning: excess elements in scalar initializer
+ 0x69, 0xd0, 0x95, 0xb5, 0x92, 0x8b, 0x6d, 0xbc
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:70:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:66:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:66:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:64:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:64:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:73:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:73:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:74:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:74:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:75:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:75:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:11: warning: excess elements in scalar initializer
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:17: warning: excess elements in scalar initializer
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:23: warning: excess elements in scalar initializer
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:29: warning: excess elements in scalar initializer
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:35: warning: excess elements in scalar initializer
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:41: warning: excess elements in scalar initializer
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:47: warning: excess elements in scalar initializer
+ 0xf4, 0xc6, 0x33, 0xc3, 0x04, 0x4f, 0xc1, 0x45,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:76:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:5: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:11: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:17: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:23: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:29: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:35: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:41: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:47: warning: excess elements in scalar initializer
+ 0xf8, 0x4f, 0x33, 0x5c, 0xb8, 0x19, 0x53, 0xde
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:77:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:75:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:75:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:73:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:73:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:57:2: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:57:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:81:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:81:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:82:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:82:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:84:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:84:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:84:4: warning: excess elements in scalar initializer
+/home/bhargava/Desktop/repositories/kbench9000/function.h:84:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:88:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:88:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:89:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:89:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:90:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:90:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:11: warning: excess elements in scalar initializer
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:17: warning: excess elements in scalar initializer
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:23: warning: excess elements in scalar initializer
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:29: warning: excess elements in scalar initializer
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:35: warning: excess elements in scalar initializer
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:41: warning: excess elements in scalar initializer
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:47: warning: excess elements in scalar initializer
+ 0xa0, 0xf3, 0x08, 0x00, 0x00, 0xf4, 0x64, 0x00,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:91:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:5: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:11: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:17: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:23: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:29: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:35: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:41: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:47: warning: excess elements in scalar initializer
+ 0xd0, 0xc7, 0xe9, 0x07, 0x6c, 0x83, 0x44, 0x03,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:92:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:5: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:11: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:17: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:23: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:29: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:35: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:41: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:47: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:93:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:5: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:11: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:17: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:23: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:29: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:35: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:41: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:47: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:94:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:90:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:90:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:88:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:88:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:97:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:97:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:98:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:98:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:99:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:99:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:11: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:17: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:23: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:29: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:35: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:41: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:47: warning: excess elements in scalar initializer
+ 0xdd, 0x3f, 0xab, 0x22, 0x51, 0xf1, 0x1a, 0xc7,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:100:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:5: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:11: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:17: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:23: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:29: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:35: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:41: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:47: warning: excess elements in scalar initializer
+ 0x59, 0xf0, 0x88, 0x71, 0x29, 0xcc, 0x2e, 0xe7
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:101:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:99:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:99:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:97:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:97:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:81:2: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:81:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:105:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:105:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:106:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:106:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:107:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:107:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:108:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:108:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:11: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:17: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:23: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:29: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:35: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:41: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:47: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:109:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:5: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:11: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:17: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:23: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:29: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:35: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:41: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:47: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:110:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:5: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:11: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:17: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:23: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:29: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:35: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:41: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:47: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:111:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:5: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:11: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:17: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:23: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:29: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:35: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:41: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:47: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:112:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:108:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:108:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:115:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:115:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:116:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:116:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:117:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:117:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:11: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:17: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:23: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:29: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:35: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:41: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:47: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:118:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:5: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:11: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:17: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:23: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:29: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:35: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:41: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:47: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:119:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:5: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:11: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:17: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:23: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:29: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:35: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:41: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:47: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:120:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:5: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:11: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:17: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:23: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:29: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:35: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:41: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:47: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:121:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:117:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:117:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:115:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:115:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:124:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:124:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:125:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:125:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:126:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:126:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:11: warning: excess elements in scalar initializer
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:17: warning: excess elements in scalar initializer
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:23: warning: excess elements in scalar initializer
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:29: warning: excess elements in scalar initializer
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:35: warning: excess elements in scalar initializer
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:41: warning: excess elements in scalar initializer
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:47: warning: excess elements in scalar initializer
+ 0x0e, 0xe1, 0xc1, 0x6b, 0xb7, 0x3f, 0x0f, 0x4f,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:127:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:5: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:11: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:17: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:23: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:29: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:35: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:41: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:47: warning: excess elements in scalar initializer
+ 0xd1, 0x98, 0x81, 0x75, 0x3c, 0x01, 0xcd, 0xbe
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:128:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:126:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:126:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:124:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:124:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:105:2: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:105:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:132:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:132:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:133:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:133:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:134:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 63,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:134:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:135:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:135:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:11: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:17: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:23: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:29: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:35: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:41: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:47: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:136:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:5: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:11: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:17: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:23: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:29: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:35: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:41: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:47: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:137:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:5: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:11: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:17: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:23: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:29: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:35: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:41: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:47: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:138:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:5: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:11: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:17: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:23: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:29: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:35: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:41: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:47: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:139:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:5: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:11: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:17: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:23: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:29: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:35: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:41: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:47: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:141:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:5: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:11: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:17: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:23: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:29: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:35: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:41: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:47: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:142:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:5: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:11: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:17: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:23: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:29: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:35: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:41: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:47: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:143:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:5: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:11: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:17: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:23: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:29: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:35: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:41: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:144:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:135:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:135:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:147:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:147:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:148:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:148:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:149:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:149:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:11: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:17: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:23: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:29: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:35: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:41: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:47: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:150:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:5: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:11: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:17: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:23: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:29: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:35: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:41: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:47: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:151:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:5: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:11: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:17: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:23: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:29: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:35: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:41: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:47: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:152:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:5: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:11: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:17: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:23: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:29: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:35: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:41: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:47: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:153:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:149:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:149:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:147:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:147:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:156:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:156:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:157:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:157:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:158:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:158:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:11: warning: excess elements in scalar initializer
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:17: warning: excess elements in scalar initializer
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:23: warning: excess elements in scalar initializer
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:29: warning: excess elements in scalar initializer
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:35: warning: excess elements in scalar initializer
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:41: warning: excess elements in scalar initializer
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:47: warning: excess elements in scalar initializer
+ 0x51, 0x54, 0xad, 0x0d, 0x2c, 0xb2, 0x6e, 0x01,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:159:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:5: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:11: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:17: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:23: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:29: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:35: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:41: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:47: warning: excess elements in scalar initializer
+ 0x27, 0x4f, 0xc5, 0x11, 0x48, 0x49, 0x1f, 0x1b
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:160:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:158:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:158:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:156:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:156:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:132:2: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:132:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:168:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:168:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:169:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:169:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:170:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 64,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:170:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:171:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:171:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:11: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:17: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:23: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:29: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:35: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:41: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:47: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:172:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:5: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:11: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:17: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:23: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:29: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:35: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:41: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:47: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:173:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:5: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:11: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:17: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:23: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:29: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:35: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:41: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:47: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:174:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:5: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:11: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:17: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:23: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:29: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:35: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:41: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:47: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:175:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:5: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:11: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:17: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:23: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:29: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:35: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:41: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:47: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:177:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:5: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:11: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:17: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:23: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:29: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:35: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:41: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:47: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:178:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:5: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:11: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:17: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:23: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:29: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:35: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:41: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:47: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:179:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:5: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:11: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:17: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:23: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:29: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:35: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:41: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:47: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:180:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:171:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:171:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:183:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:183:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:184:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:184:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:185:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:185:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:11: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:17: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:23: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:29: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:35: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:41: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:47: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:186:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:5: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:11: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:17: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:23: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:29: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:35: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:41: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:47: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:187:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:5: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:11: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:17: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:23: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:29: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:35: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:41: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:47: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:188:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:5: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:11: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:17: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:23: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:29: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:35: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:41: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:47: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:189:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:185:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:185:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:183:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:183:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:192:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:192:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:193:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:193:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:194:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:194:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:11: warning: excess elements in scalar initializer
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:17: warning: excess elements in scalar initializer
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:23: warning: excess elements in scalar initializer
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:29: warning: excess elements in scalar initializer
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:35: warning: excess elements in scalar initializer
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:41: warning: excess elements in scalar initializer
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:47: warning: excess elements in scalar initializer
+ 0x81, 0x20, 0x59, 0xa5, 0xda, 0x19, 0x86, 0x37,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:195:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:5: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:11: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:17: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:23: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:29: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:35: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:41: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:47: warning: excess elements in scalar initializer
+ 0xca, 0xc7, 0xc4, 0xa6, 0x31, 0xbe, 0xe4, 0x66
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:196:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:194:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:194:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:192:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:192:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:168:2: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:168:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:200:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:200:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:201:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:201:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:202:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 48,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:202:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:203:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:203:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:11: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:17: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:23: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:29: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:35: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:41: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:47: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:204:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:5: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:11: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:17: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:23: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:29: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:35: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:41: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:47: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:205:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:5: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:11: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:17: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:23: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:29: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:35: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:41: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:47: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:206:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:5: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:11: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:17: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:23: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:29: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:35: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:41: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:47: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:207:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:5: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:11: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:17: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:23: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:29: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:35: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:41: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:47: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:209:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:5: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:11: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:17: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:23: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:29: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:35: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:41: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:47: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:210:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:203:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:203:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:213:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:213:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:214:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:214:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:215:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:215:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:11: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:17: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:23: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:29: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:35: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:41: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:47: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:216:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:5: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:11: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:17: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:23: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:29: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:35: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:41: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:47: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:217:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:5: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:11: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:17: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:23: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:29: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:35: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:41: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:47: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:218:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:5: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:11: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:17: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:23: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:29: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:35: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:41: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:47: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:219:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:215:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:215:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:213:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:213:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:223:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:223:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:224:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:224:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:225:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:225:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:11: warning: excess elements in scalar initializer
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:17: warning: excess elements in scalar initializer
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:23: warning: excess elements in scalar initializer
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:29: warning: excess elements in scalar initializer
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:35: warning: excess elements in scalar initializer
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:41: warning: excess elements in scalar initializer
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:47: warning: excess elements in scalar initializer
+ 0x5b, 0x88, 0xd7, 0xf6, 0x22, 0x8b, 0x11, 0xe2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:226:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:5: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:11: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:17: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:23: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:29: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:35: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:41: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:47: warning: excess elements in scalar initializer
+ 0xe2, 0x85, 0x79, 0xa5, 0xc0, 0xc1, 0xf7, 0x61
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:227:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:225:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:225:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:223:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:223:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:200:2: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:200:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:231:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:231:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:232:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:232:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:233:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 96,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:233:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:234:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:234:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:11: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:17: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:23: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:29: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:35: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:41: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:47: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:235:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:5: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:11: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:17: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:23: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:29: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:35: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:41: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:47: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:236:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:5: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:11: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:17: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:23: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:29: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:35: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:41: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:47: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:237:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:5: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:11: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:17: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:23: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:29: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:35: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:41: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:47: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:238:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:5: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:11: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:17: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:23: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:29: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:35: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:41: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:47: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:240:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:5: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:11: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:17: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:23: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:29: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:35: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:41: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:47: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:241:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:5: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:11: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:17: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:23: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:29: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:35: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:41: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:47: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:242:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:5: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:11: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:17: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:23: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:29: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:35: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:41: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:47: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:243:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:5: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:11: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:17: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:23: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:29: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:35: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:41: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:47: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:245:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:5: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:11: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:17: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:23: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:29: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:35: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:41: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:47: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:246:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:5: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:11: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:17: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:23: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:29: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:35: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:41: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:47: warning: excess elements in scalar initializer
+ 0xd7, 0xe6, 0x79, 0x10, 0x7e, 0xa2, 0x6a, 0xdb,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:247:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:5: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:11: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:17: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:23: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:29: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:35: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:41: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:47: warning: excess elements in scalar initializer
+ 0x8c, 0xaf, 0x66, 0x52, 0xd0, 0x65, 0x61, 0x36
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:248:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:234:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:234:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:251:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:251:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:252:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:252:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:253:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:253:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:11: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:17: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:23: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:29: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:35: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:41: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:47: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:254:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:5: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:11: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:17: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:23: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:29: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:35: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:41: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:47: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:255:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:5: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:11: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:17: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:23: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:29: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:35: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:41: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:47: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:256:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:5: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:11: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:17: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:23: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:29: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:35: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:41: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:47: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:257:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:253:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:253:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:251:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:251:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:260:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:260:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:261:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:261:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:262:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:262:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:11: warning: excess elements in scalar initializer
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:17: warning: excess elements in scalar initializer
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:23: warning: excess elements in scalar initializer
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:29: warning: excess elements in scalar initializer
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:35: warning: excess elements in scalar initializer
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:41: warning: excess elements in scalar initializer
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:47: warning: excess elements in scalar initializer
+ 0xbb, 0xb6, 0x13, 0xb2, 0xb6, 0xd7, 0x53, 0xba,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:263:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:5: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:11: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:17: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:23: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:29: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:35: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:41: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:47: warning: excess elements in scalar initializer
+ 0x07, 0x39, 0x5b, 0x91, 0x6a, 0xae, 0xce, 0x15
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:264:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:262:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:262:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:260:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:260:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:231:2: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:231:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:268:2: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:268:2: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:269:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:269:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:270:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 112,
+ ^~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:270:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:271:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:271:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:11: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:17: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:23: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:29: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:35: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:41: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:47: warning: excess elements in scalar initializer
+ 0xab, 0x08, 0x12, 0x72, 0x4a, 0x7f, 0x1e, 0x34,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:272:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:5: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:11: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:17: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:23: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:29: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:35: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:41: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:47: warning: excess elements in scalar initializer
+ 0x27, 0x42, 0xcb, 0xed, 0x37, 0x4d, 0x94, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:273:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:5: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:11: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:17: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:23: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:29: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:35: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:41: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:47: warning: excess elements in scalar initializer
+ 0x36, 0xc6, 0xb8, 0x79, 0x5d, 0x45, 0xb3, 0x81,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:274:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:5: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:11: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:17: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:23: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:29: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:35: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:41: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:47: warning: excess elements in scalar initializer
+ 0x98, 0x30, 0xf2, 0xc0, 0x44, 0x91, 0xfa, 0xf0,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:275:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:5: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:11: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:17: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:23: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:29: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:35: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:41: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:47: warning: excess elements in scalar initializer
+ 0x99, 0x0c, 0x62, 0xe4, 0x8b, 0x80, 0x18, 0xb2,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:277:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:5: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:11: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:17: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:23: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:29: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:35: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:41: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:47: warning: excess elements in scalar initializer
+ 0xc3, 0xe4, 0xa0, 0xfa, 0x31, 0x34, 0xcb, 0x67,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:278:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:5: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:11: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:17: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:23: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:29: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:35: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:41: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:47: warning: excess elements in scalar initializer
+ 0xfa, 0x83, 0xe1, 0x58, 0xc9, 0x94, 0xd9, 0x61,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:279:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:5: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:11: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:17: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:23: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:29: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:35: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:41: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:47: warning: excess elements in scalar initializer
+ 0xc4, 0xcb, 0x21, 0x09, 0x5c, 0x1b, 0xf9, 0xaf,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:280:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:5: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:11: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:17: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:23: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:29: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:35: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:41: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:47: warning: excess elements in scalar initializer
+ 0x48, 0x44, 0x3d, 0x0b, 0xb0, 0xd2, 0x11, 0x09,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:282:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:5: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:11: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:17: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:23: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:29: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:35: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:41: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:47: warning: excess elements in scalar initializer
+ 0xc8, 0x9a, 0x10, 0x0b, 0x5c, 0xe2, 0xc2, 0x08,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:283:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:5: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:11: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:17: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:23: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:29: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:35: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:41: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:47: warning: excess elements in scalar initializer
+ 0x83, 0x14, 0x9c, 0x69, 0xb5, 0x61, 0xdd, 0x88,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:284:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:5: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:11: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:17: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:23: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:29: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:35: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:41: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:47: warning: excess elements in scalar initializer
+ 0x29, 0x8a, 0x17, 0x98, 0xb1, 0x07, 0x16, 0xef,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:285:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:5: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:11: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:17: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:23: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:29: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:35: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:41: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:47: warning: excess elements in scalar initializer
+ 0x66, 0x3c, 0xea, 0x19, 0x0f, 0xfb, 0x83, 0xd8,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:287:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:5: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:11: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:17: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:23: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:29: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:35: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:41: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:47: warning: excess elements in scalar initializer
+ 0x95, 0x93, 0xf3, 0xf4, 0x76, 0xb6, 0xbc, 0x24
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:288:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:271:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:271:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:291:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:291:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:292:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 32,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:292:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:293:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:293:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:11: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:17: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:23: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:29: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:35: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:41: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:47: warning: excess elements in scalar initializer
+ 0x12, 0x97, 0x6a, 0x08, 0xc4, 0x42, 0x6d, 0x0c,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:294:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:5: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:11: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:17: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:23: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:29: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:35: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:41: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:47: warning: excess elements in scalar initializer
+ 0xe8, 0xa8, 0x24, 0x07, 0xc4, 0xf4, 0x82, 0x07,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:295:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:5: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:11: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:17: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:23: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:29: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:35: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:41: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:47: warning: excess elements in scalar initializer
+ 0x80, 0xf8, 0xc2, 0x0a, 0xa7, 0x12, 0x02, 0xd1,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:296:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:5: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:11: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:17: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:23: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:29: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:29: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:35: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:35: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:41: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:41: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:47: warning: excess elements in scalar initializer
+ 0xe2, 0x91, 0x79, 0xcb, 0xcb, 0x55, 0x5a, 0x57
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:297:47: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:293:4: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:293:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:291:3: warning: excess elements in scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:291:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:300:3: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:300:3: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:301:4: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 16,
+ ^~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:301:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:302:4: warning: braces around scalar initializer
+ {
+ ^
+/home/bhargava/Desktop/repositories/kbench9000/function.h:302:4: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:5: warning: initialization makes pointer from integer without a cast [-Wint-conversion]
+ 0xc7, 0x94, 0xd7, 0x05, 0x7d, 0x17, 0x78, 0xc4,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:5: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:11: warning: excess elements in scalar initializer
+ 0xc7, 0x94, 0xd7, 0x05, 0x7d, 0x17, 0x78, 0xc4,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:11: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:17: warning: excess elements in scalar initializer
+ 0xc7, 0x94, 0xd7, 0x05, 0x7d, 0x17, 0x78, 0xc4,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:17: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:23: warning: excess elements in scalar initializer
+ 0xc7, 0x94, 0xd7, 0x05, 0x7d, 0x17, 0x78, 0xc4,
+ ^~~~
+/home/bhargava/Desktop/repositories/kbench9000/function.h:303:23: note: (near initialization for ‘poly1305_testvecs’)
+/home/bhargava/Desktop/repositories/kbench9