1*4882a593Smuzhiyun/* SPDX-License-Identifier: GPL-2.0-or-later */ 2*4882a593Smuzhiyun/* 3*4882a593Smuzhiyun * Cast6 Cipher 8-way parallel algorithm (AVX/x86_64) 4*4882a593Smuzhiyun * 5*4882a593Smuzhiyun * Copyright (C) 2012 Johannes Goetzfried 6*4882a593Smuzhiyun * <Johannes.Goetzfried@informatik.stud.uni-erlangen.de> 7*4882a593Smuzhiyun * 8*4882a593Smuzhiyun * Copyright © 2012-2013 Jussi Kivilinna <jussi.kivilinna@iki.fi> 9*4882a593Smuzhiyun */ 10*4882a593Smuzhiyun 11*4882a593Smuzhiyun#include <linux/linkage.h> 12*4882a593Smuzhiyun#include <asm/frame.h> 13*4882a593Smuzhiyun#include "glue_helper-asm-avx.S" 14*4882a593Smuzhiyun 15*4882a593Smuzhiyun.file "cast6-avx-x86_64-asm_64.S" 16*4882a593Smuzhiyun 17*4882a593Smuzhiyun.extern cast_s1 18*4882a593Smuzhiyun.extern cast_s2 19*4882a593Smuzhiyun.extern cast_s3 20*4882a593Smuzhiyun.extern cast_s4 21*4882a593Smuzhiyun 22*4882a593Smuzhiyun/* structure of crypto context */ 23*4882a593Smuzhiyun#define km 0 24*4882a593Smuzhiyun#define kr (12*4*4) 25*4882a593Smuzhiyun 26*4882a593Smuzhiyun/* s-boxes */ 27*4882a593Smuzhiyun#define s1 cast_s1 28*4882a593Smuzhiyun#define s2 cast_s2 29*4882a593Smuzhiyun#define s3 cast_s3 30*4882a593Smuzhiyun#define s4 cast_s4 31*4882a593Smuzhiyun 32*4882a593Smuzhiyun/********************************************************************** 33*4882a593Smuzhiyun 8-way AVX cast6 34*4882a593Smuzhiyun **********************************************************************/ 35*4882a593Smuzhiyun#define CTX %r15 36*4882a593Smuzhiyun 37*4882a593Smuzhiyun#define RA1 %xmm0 38*4882a593Smuzhiyun#define RB1 %xmm1 39*4882a593Smuzhiyun#define RC1 %xmm2 40*4882a593Smuzhiyun#define RD1 %xmm3 41*4882a593Smuzhiyun 42*4882a593Smuzhiyun#define RA2 %xmm4 43*4882a593Smuzhiyun#define RB2 %xmm5 44*4882a593Smuzhiyun#define RC2 %xmm6 45*4882a593Smuzhiyun#define RD2 %xmm7 46*4882a593Smuzhiyun 47*4882a593Smuzhiyun#define RX %xmm8 48*4882a593Smuzhiyun 49*4882a593Smuzhiyun#define RKM %xmm9 50*4882a593Smuzhiyun#define RKR %xmm10 51*4882a593Smuzhiyun#define RKRF %xmm11 52*4882a593Smuzhiyun#define RKRR %xmm12 53*4882a593Smuzhiyun#define R32 %xmm13 54*4882a593Smuzhiyun#define R1ST %xmm14 55*4882a593Smuzhiyun 56*4882a593Smuzhiyun#define RTMP %xmm15 57*4882a593Smuzhiyun 58*4882a593Smuzhiyun#define RID1 %rdi 59*4882a593Smuzhiyun#define RID1d %edi 60*4882a593Smuzhiyun#define RID2 %rsi 61*4882a593Smuzhiyun#define RID2d %esi 62*4882a593Smuzhiyun 63*4882a593Smuzhiyun#define RGI1 %rdx 64*4882a593Smuzhiyun#define RGI1bl %dl 65*4882a593Smuzhiyun#define RGI1bh %dh 66*4882a593Smuzhiyun#define RGI2 %rcx 67*4882a593Smuzhiyun#define RGI2bl %cl 68*4882a593Smuzhiyun#define RGI2bh %ch 69*4882a593Smuzhiyun 70*4882a593Smuzhiyun#define RGI3 %rax 71*4882a593Smuzhiyun#define RGI3bl %al 72*4882a593Smuzhiyun#define RGI3bh %ah 73*4882a593Smuzhiyun#define RGI4 %rbx 74*4882a593Smuzhiyun#define RGI4bl %bl 75*4882a593Smuzhiyun#define RGI4bh %bh 76*4882a593Smuzhiyun 77*4882a593Smuzhiyun#define RFS1 %r8 78*4882a593Smuzhiyun#define RFS1d %r8d 79*4882a593Smuzhiyun#define RFS2 %r9 80*4882a593Smuzhiyun#define RFS2d %r9d 81*4882a593Smuzhiyun#define RFS3 %r10 82*4882a593Smuzhiyun#define RFS3d %r10d 83*4882a593Smuzhiyun 84*4882a593Smuzhiyun 85*4882a593Smuzhiyun#define lookup_32bit(src, dst, op1, op2, op3, interleave_op, il_reg) \ 86*4882a593Smuzhiyun movzbl src ## bh, RID1d; \ 87*4882a593Smuzhiyun movzbl src ## bl, RID2d; \ 88*4882a593Smuzhiyun shrq $16, src; \ 89*4882a593Smuzhiyun movl s1(, RID1, 4), dst ## d; \ 90*4882a593Smuzhiyun op1 s2(, RID2, 4), dst ## d; \ 91*4882a593Smuzhiyun movzbl src ## bh, RID1d; \ 92*4882a593Smuzhiyun movzbl src ## bl, RID2d; \ 93*4882a593Smuzhiyun interleave_op(il_reg); \ 94*4882a593Smuzhiyun op2 s3(, RID1, 4), dst ## d; \ 95*4882a593Smuzhiyun op3 s4(, RID2, 4), dst ## d; 96*4882a593Smuzhiyun 97*4882a593Smuzhiyun#define dummy(d) /* do nothing */ 98*4882a593Smuzhiyun 99*4882a593Smuzhiyun#define shr_next(reg) \ 100*4882a593Smuzhiyun shrq $16, reg; 101*4882a593Smuzhiyun 102*4882a593Smuzhiyun#define F_head(a, x, gi1, gi2, op0) \ 103*4882a593Smuzhiyun op0 a, RKM, x; \ 104*4882a593Smuzhiyun vpslld RKRF, x, RTMP; \ 105*4882a593Smuzhiyun vpsrld RKRR, x, x; \ 106*4882a593Smuzhiyun vpor RTMP, x, x; \ 107*4882a593Smuzhiyun \ 108*4882a593Smuzhiyun vmovq x, gi1; \ 109*4882a593Smuzhiyun vpextrq $1, x, gi2; 110*4882a593Smuzhiyun 111*4882a593Smuzhiyun#define F_tail(a, x, gi1, gi2, op1, op2, op3) \ 112*4882a593Smuzhiyun lookup_32bit(##gi1, RFS1, op1, op2, op3, shr_next, ##gi1); \ 113*4882a593Smuzhiyun lookup_32bit(##gi2, RFS3, op1, op2, op3, shr_next, ##gi2); \ 114*4882a593Smuzhiyun \ 115*4882a593Smuzhiyun lookup_32bit(##gi1, RFS2, op1, op2, op3, dummy, none); \ 116*4882a593Smuzhiyun shlq $32, RFS2; \ 117*4882a593Smuzhiyun orq RFS1, RFS2; \ 118*4882a593Smuzhiyun lookup_32bit(##gi2, RFS1, op1, op2, op3, dummy, none); \ 119*4882a593Smuzhiyun shlq $32, RFS1; \ 120*4882a593Smuzhiyun orq RFS1, RFS3; \ 121*4882a593Smuzhiyun \ 122*4882a593Smuzhiyun vmovq RFS2, x; \ 123*4882a593Smuzhiyun vpinsrq $1, RFS3, x, x; 124*4882a593Smuzhiyun 125*4882a593Smuzhiyun#define F_2(a1, b1, a2, b2, op0, op1, op2, op3) \ 126*4882a593Smuzhiyun F_head(b1, RX, RGI1, RGI2, op0); \ 127*4882a593Smuzhiyun F_head(b2, RX, RGI3, RGI4, op0); \ 128*4882a593Smuzhiyun \ 129*4882a593Smuzhiyun F_tail(b1, RX, RGI1, RGI2, op1, op2, op3); \ 130*4882a593Smuzhiyun F_tail(b2, RTMP, RGI3, RGI4, op1, op2, op3); \ 131*4882a593Smuzhiyun \ 132*4882a593Smuzhiyun vpxor a1, RX, a1; \ 133*4882a593Smuzhiyun vpxor a2, RTMP, a2; 134*4882a593Smuzhiyun 135*4882a593Smuzhiyun#define F1_2(a1, b1, a2, b2) \ 136*4882a593Smuzhiyun F_2(a1, b1, a2, b2, vpaddd, xorl, subl, addl) 137*4882a593Smuzhiyun#define F2_2(a1, b1, a2, b2) \ 138*4882a593Smuzhiyun F_2(a1, b1, a2, b2, vpxor, subl, addl, xorl) 139*4882a593Smuzhiyun#define F3_2(a1, b1, a2, b2) \ 140*4882a593Smuzhiyun F_2(a1, b1, a2, b2, vpsubd, addl, xorl, subl) 141*4882a593Smuzhiyun 142*4882a593Smuzhiyun#define qop(in, out, f) \ 143*4882a593Smuzhiyun F ## f ## _2(out ## 1, in ## 1, out ## 2, in ## 2); 144*4882a593Smuzhiyun 145*4882a593Smuzhiyun#define get_round_keys(nn) \ 146*4882a593Smuzhiyun vbroadcastss (km+(4*(nn)))(CTX), RKM; \ 147*4882a593Smuzhiyun vpand R1ST, RKR, RKRF; \ 148*4882a593Smuzhiyun vpsubq RKRF, R32, RKRR; \ 149*4882a593Smuzhiyun vpsrldq $1, RKR, RKR; 150*4882a593Smuzhiyun 151*4882a593Smuzhiyun#define Q(n) \ 152*4882a593Smuzhiyun get_round_keys(4*n+0); \ 153*4882a593Smuzhiyun qop(RD, RC, 1); \ 154*4882a593Smuzhiyun \ 155*4882a593Smuzhiyun get_round_keys(4*n+1); \ 156*4882a593Smuzhiyun qop(RC, RB, 2); \ 157*4882a593Smuzhiyun \ 158*4882a593Smuzhiyun get_round_keys(4*n+2); \ 159*4882a593Smuzhiyun qop(RB, RA, 3); \ 160*4882a593Smuzhiyun \ 161*4882a593Smuzhiyun get_round_keys(4*n+3); \ 162*4882a593Smuzhiyun qop(RA, RD, 1); 163*4882a593Smuzhiyun 164*4882a593Smuzhiyun#define QBAR(n) \ 165*4882a593Smuzhiyun get_round_keys(4*n+3); \ 166*4882a593Smuzhiyun qop(RA, RD, 1); \ 167*4882a593Smuzhiyun \ 168*4882a593Smuzhiyun get_round_keys(4*n+2); \ 169*4882a593Smuzhiyun qop(RB, RA, 3); \ 170*4882a593Smuzhiyun \ 171*4882a593Smuzhiyun get_round_keys(4*n+1); \ 172*4882a593Smuzhiyun qop(RC, RB, 2); \ 173*4882a593Smuzhiyun \ 174*4882a593Smuzhiyun get_round_keys(4*n+0); \ 175*4882a593Smuzhiyun qop(RD, RC, 1); 176*4882a593Smuzhiyun 177*4882a593Smuzhiyun#define shuffle(mask) \ 178*4882a593Smuzhiyun vpshufb mask, RKR, RKR; 179*4882a593Smuzhiyun 180*4882a593Smuzhiyun#define preload_rkr(n, do_mask, mask) \ 181*4882a593Smuzhiyun vbroadcastss .L16_mask, RKR; \ 182*4882a593Smuzhiyun /* add 16-bit rotation to key rotations (mod 32) */ \ 183*4882a593Smuzhiyun vpxor (kr+n*16)(CTX), RKR, RKR; \ 184*4882a593Smuzhiyun do_mask(mask); 185*4882a593Smuzhiyun 186*4882a593Smuzhiyun#define transpose_4x4(x0, x1, x2, x3, t0, t1, t2) \ 187*4882a593Smuzhiyun vpunpckldq x1, x0, t0; \ 188*4882a593Smuzhiyun vpunpckhdq x1, x0, t2; \ 189*4882a593Smuzhiyun vpunpckldq x3, x2, t1; \ 190*4882a593Smuzhiyun vpunpckhdq x3, x2, x3; \ 191*4882a593Smuzhiyun \ 192*4882a593Smuzhiyun vpunpcklqdq t1, t0, x0; \ 193*4882a593Smuzhiyun vpunpckhqdq t1, t0, x1; \ 194*4882a593Smuzhiyun vpunpcklqdq x3, t2, x2; \ 195*4882a593Smuzhiyun vpunpckhqdq x3, t2, x3; 196*4882a593Smuzhiyun 197*4882a593Smuzhiyun#define inpack_blocks(x0, x1, x2, x3, t0, t1, t2, rmask) \ 198*4882a593Smuzhiyun vpshufb rmask, x0, x0; \ 199*4882a593Smuzhiyun vpshufb rmask, x1, x1; \ 200*4882a593Smuzhiyun vpshufb rmask, x2, x2; \ 201*4882a593Smuzhiyun vpshufb rmask, x3, x3; \ 202*4882a593Smuzhiyun \ 203*4882a593Smuzhiyun transpose_4x4(x0, x1, x2, x3, t0, t1, t2) 204*4882a593Smuzhiyun 205*4882a593Smuzhiyun#define outunpack_blocks(x0, x1, x2, x3, t0, t1, t2, rmask) \ 206*4882a593Smuzhiyun transpose_4x4(x0, x1, x2, x3, t0, t1, t2) \ 207*4882a593Smuzhiyun \ 208*4882a593Smuzhiyun vpshufb rmask, x0, x0; \ 209*4882a593Smuzhiyun vpshufb rmask, x1, x1; \ 210*4882a593Smuzhiyun vpshufb rmask, x2, x2; \ 211*4882a593Smuzhiyun vpshufb rmask, x3, x3; 212*4882a593Smuzhiyun 213*4882a593Smuzhiyun.section .rodata.cst16, "aM", @progbits, 16 214*4882a593Smuzhiyun.align 16 215*4882a593Smuzhiyun.Lxts_gf128mul_and_shl1_mask: 216*4882a593Smuzhiyun .byte 0x87, 0, 0, 0, 0, 0, 0, 0, 1, 0, 0, 0, 0, 0, 0, 0 217*4882a593Smuzhiyun.Lbswap_mask: 218*4882a593Smuzhiyun .byte 3, 2, 1, 0, 7, 6, 5, 4, 11, 10, 9, 8, 15, 14, 13, 12 219*4882a593Smuzhiyun.Lbswap128_mask: 220*4882a593Smuzhiyun .byte 15, 14, 13, 12, 11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1, 0 221*4882a593Smuzhiyun.Lrkr_enc_Q_Q_QBAR_QBAR: 222*4882a593Smuzhiyun .byte 0, 1, 2, 3, 4, 5, 6, 7, 11, 10, 9, 8, 15, 14, 13, 12 223*4882a593Smuzhiyun.Lrkr_enc_QBAR_QBAR_QBAR_QBAR: 224*4882a593Smuzhiyun .byte 3, 2, 1, 0, 7, 6, 5, 4, 11, 10, 9, 8, 15, 14, 13, 12 225*4882a593Smuzhiyun.Lrkr_dec_Q_Q_Q_Q: 226*4882a593Smuzhiyun .byte 12, 13, 14, 15, 8, 9, 10, 11, 4, 5, 6, 7, 0, 1, 2, 3 227*4882a593Smuzhiyun.Lrkr_dec_Q_Q_QBAR_QBAR: 228*4882a593Smuzhiyun .byte 12, 13, 14, 15, 8, 9, 10, 11, 7, 6, 5, 4, 3, 2, 1, 0 229*4882a593Smuzhiyun.Lrkr_dec_QBAR_QBAR_QBAR_QBAR: 230*4882a593Smuzhiyun .byte 15, 14, 13, 12, 11, 10, 9, 8, 7, 6, 5, 4, 3, 2, 1, 0 231*4882a593Smuzhiyun 232*4882a593Smuzhiyun.section .rodata.cst4.L16_mask, "aM", @progbits, 4 233*4882a593Smuzhiyun.align 4 234*4882a593Smuzhiyun.L16_mask: 235*4882a593Smuzhiyun .byte 16, 16, 16, 16 236*4882a593Smuzhiyun 237*4882a593Smuzhiyun.section .rodata.cst4.L32_mask, "aM", @progbits, 4 238*4882a593Smuzhiyun.align 4 239*4882a593Smuzhiyun.L32_mask: 240*4882a593Smuzhiyun .byte 32, 0, 0, 0 241*4882a593Smuzhiyun 242*4882a593Smuzhiyun.section .rodata.cst4.first_mask, "aM", @progbits, 4 243*4882a593Smuzhiyun.align 4 244*4882a593Smuzhiyun.Lfirst_mask: 245*4882a593Smuzhiyun .byte 0x1f, 0, 0, 0 246*4882a593Smuzhiyun 247*4882a593Smuzhiyun.text 248*4882a593Smuzhiyun 249*4882a593Smuzhiyun.align 8 250*4882a593SmuzhiyunSYM_FUNC_START_LOCAL(__cast6_enc_blk8) 251*4882a593Smuzhiyun /* input: 252*4882a593Smuzhiyun * %rdi: ctx 253*4882a593Smuzhiyun * RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2: blocks 254*4882a593Smuzhiyun * output: 255*4882a593Smuzhiyun * RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2: encrypted blocks 256*4882a593Smuzhiyun */ 257*4882a593Smuzhiyun 258*4882a593Smuzhiyun pushq %r15; 259*4882a593Smuzhiyun pushq %rbx; 260*4882a593Smuzhiyun 261*4882a593Smuzhiyun movq %rdi, CTX; 262*4882a593Smuzhiyun 263*4882a593Smuzhiyun vmovdqa .Lbswap_mask, RKM; 264*4882a593Smuzhiyun vmovd .Lfirst_mask, R1ST; 265*4882a593Smuzhiyun vmovd .L32_mask, R32; 266*4882a593Smuzhiyun 267*4882a593Smuzhiyun inpack_blocks(RA1, RB1, RC1, RD1, RTMP, RX, RKRF, RKM); 268*4882a593Smuzhiyun inpack_blocks(RA2, RB2, RC2, RD2, RTMP, RX, RKRF, RKM); 269*4882a593Smuzhiyun 270*4882a593Smuzhiyun preload_rkr(0, dummy, none); 271*4882a593Smuzhiyun Q(0); 272*4882a593Smuzhiyun Q(1); 273*4882a593Smuzhiyun Q(2); 274*4882a593Smuzhiyun Q(3); 275*4882a593Smuzhiyun preload_rkr(1, shuffle, .Lrkr_enc_Q_Q_QBAR_QBAR); 276*4882a593Smuzhiyun Q(4); 277*4882a593Smuzhiyun Q(5); 278*4882a593Smuzhiyun QBAR(6); 279*4882a593Smuzhiyun QBAR(7); 280*4882a593Smuzhiyun preload_rkr(2, shuffle, .Lrkr_enc_QBAR_QBAR_QBAR_QBAR); 281*4882a593Smuzhiyun QBAR(8); 282*4882a593Smuzhiyun QBAR(9); 283*4882a593Smuzhiyun QBAR(10); 284*4882a593Smuzhiyun QBAR(11); 285*4882a593Smuzhiyun 286*4882a593Smuzhiyun popq %rbx; 287*4882a593Smuzhiyun popq %r15; 288*4882a593Smuzhiyun 289*4882a593Smuzhiyun vmovdqa .Lbswap_mask, RKM; 290*4882a593Smuzhiyun 291*4882a593Smuzhiyun outunpack_blocks(RA1, RB1, RC1, RD1, RTMP, RX, RKRF, RKM); 292*4882a593Smuzhiyun outunpack_blocks(RA2, RB2, RC2, RD2, RTMP, RX, RKRF, RKM); 293*4882a593Smuzhiyun 294*4882a593Smuzhiyun RET; 295*4882a593SmuzhiyunSYM_FUNC_END(__cast6_enc_blk8) 296*4882a593Smuzhiyun 297*4882a593Smuzhiyun.align 8 298*4882a593SmuzhiyunSYM_FUNC_START_LOCAL(__cast6_dec_blk8) 299*4882a593Smuzhiyun /* input: 300*4882a593Smuzhiyun * %rdi: ctx 301*4882a593Smuzhiyun * RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2: encrypted blocks 302*4882a593Smuzhiyun * output: 303*4882a593Smuzhiyun * RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2: decrypted blocks 304*4882a593Smuzhiyun */ 305*4882a593Smuzhiyun 306*4882a593Smuzhiyun pushq %r15; 307*4882a593Smuzhiyun pushq %rbx; 308*4882a593Smuzhiyun 309*4882a593Smuzhiyun movq %rdi, CTX; 310*4882a593Smuzhiyun 311*4882a593Smuzhiyun vmovdqa .Lbswap_mask, RKM; 312*4882a593Smuzhiyun vmovd .Lfirst_mask, R1ST; 313*4882a593Smuzhiyun vmovd .L32_mask, R32; 314*4882a593Smuzhiyun 315*4882a593Smuzhiyun inpack_blocks(RA1, RB1, RC1, RD1, RTMP, RX, RKRF, RKM); 316*4882a593Smuzhiyun inpack_blocks(RA2, RB2, RC2, RD2, RTMP, RX, RKRF, RKM); 317*4882a593Smuzhiyun 318*4882a593Smuzhiyun preload_rkr(2, shuffle, .Lrkr_dec_Q_Q_Q_Q); 319*4882a593Smuzhiyun Q(11); 320*4882a593Smuzhiyun Q(10); 321*4882a593Smuzhiyun Q(9); 322*4882a593Smuzhiyun Q(8); 323*4882a593Smuzhiyun preload_rkr(1, shuffle, .Lrkr_dec_Q_Q_QBAR_QBAR); 324*4882a593Smuzhiyun Q(7); 325*4882a593Smuzhiyun Q(6); 326*4882a593Smuzhiyun QBAR(5); 327*4882a593Smuzhiyun QBAR(4); 328*4882a593Smuzhiyun preload_rkr(0, shuffle, .Lrkr_dec_QBAR_QBAR_QBAR_QBAR); 329*4882a593Smuzhiyun QBAR(3); 330*4882a593Smuzhiyun QBAR(2); 331*4882a593Smuzhiyun QBAR(1); 332*4882a593Smuzhiyun QBAR(0); 333*4882a593Smuzhiyun 334*4882a593Smuzhiyun popq %rbx; 335*4882a593Smuzhiyun popq %r15; 336*4882a593Smuzhiyun 337*4882a593Smuzhiyun vmovdqa .Lbswap_mask, RKM; 338*4882a593Smuzhiyun outunpack_blocks(RA1, RB1, RC1, RD1, RTMP, RX, RKRF, RKM); 339*4882a593Smuzhiyun outunpack_blocks(RA2, RB2, RC2, RD2, RTMP, RX, RKRF, RKM); 340*4882a593Smuzhiyun 341*4882a593Smuzhiyun RET; 342*4882a593SmuzhiyunSYM_FUNC_END(__cast6_dec_blk8) 343*4882a593Smuzhiyun 344*4882a593SmuzhiyunSYM_FUNC_START(cast6_ecb_enc_8way) 345*4882a593Smuzhiyun /* input: 346*4882a593Smuzhiyun * %rdi: ctx 347*4882a593Smuzhiyun * %rsi: dst 348*4882a593Smuzhiyun * %rdx: src 349*4882a593Smuzhiyun */ 350*4882a593Smuzhiyun FRAME_BEGIN 351*4882a593Smuzhiyun pushq %r15; 352*4882a593Smuzhiyun 353*4882a593Smuzhiyun movq %rdi, CTX; 354*4882a593Smuzhiyun movq %rsi, %r11; 355*4882a593Smuzhiyun 356*4882a593Smuzhiyun load_8way(%rdx, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 357*4882a593Smuzhiyun 358*4882a593Smuzhiyun call __cast6_enc_blk8; 359*4882a593Smuzhiyun 360*4882a593Smuzhiyun store_8way(%r11, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 361*4882a593Smuzhiyun 362*4882a593Smuzhiyun popq %r15; 363*4882a593Smuzhiyun FRAME_END 364*4882a593Smuzhiyun RET; 365*4882a593SmuzhiyunSYM_FUNC_END(cast6_ecb_enc_8way) 366*4882a593Smuzhiyun 367*4882a593SmuzhiyunSYM_FUNC_START(cast6_ecb_dec_8way) 368*4882a593Smuzhiyun /* input: 369*4882a593Smuzhiyun * %rdi: ctx 370*4882a593Smuzhiyun * %rsi: dst 371*4882a593Smuzhiyun * %rdx: src 372*4882a593Smuzhiyun */ 373*4882a593Smuzhiyun FRAME_BEGIN 374*4882a593Smuzhiyun pushq %r15; 375*4882a593Smuzhiyun 376*4882a593Smuzhiyun movq %rdi, CTX; 377*4882a593Smuzhiyun movq %rsi, %r11; 378*4882a593Smuzhiyun 379*4882a593Smuzhiyun load_8way(%rdx, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 380*4882a593Smuzhiyun 381*4882a593Smuzhiyun call __cast6_dec_blk8; 382*4882a593Smuzhiyun 383*4882a593Smuzhiyun store_8way(%r11, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 384*4882a593Smuzhiyun 385*4882a593Smuzhiyun popq %r15; 386*4882a593Smuzhiyun FRAME_END 387*4882a593Smuzhiyun RET; 388*4882a593SmuzhiyunSYM_FUNC_END(cast6_ecb_dec_8way) 389*4882a593Smuzhiyun 390*4882a593SmuzhiyunSYM_FUNC_START(cast6_cbc_dec_8way) 391*4882a593Smuzhiyun /* input: 392*4882a593Smuzhiyun * %rdi: ctx 393*4882a593Smuzhiyun * %rsi: dst 394*4882a593Smuzhiyun * %rdx: src 395*4882a593Smuzhiyun */ 396*4882a593Smuzhiyun FRAME_BEGIN 397*4882a593Smuzhiyun pushq %r12; 398*4882a593Smuzhiyun pushq %r15; 399*4882a593Smuzhiyun 400*4882a593Smuzhiyun movq %rdi, CTX; 401*4882a593Smuzhiyun movq %rsi, %r11; 402*4882a593Smuzhiyun movq %rdx, %r12; 403*4882a593Smuzhiyun 404*4882a593Smuzhiyun load_8way(%rdx, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 405*4882a593Smuzhiyun 406*4882a593Smuzhiyun call __cast6_dec_blk8; 407*4882a593Smuzhiyun 408*4882a593Smuzhiyun store_cbc_8way(%r12, %r11, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 409*4882a593Smuzhiyun 410*4882a593Smuzhiyun popq %r15; 411*4882a593Smuzhiyun popq %r12; 412*4882a593Smuzhiyun FRAME_END 413*4882a593Smuzhiyun RET; 414*4882a593SmuzhiyunSYM_FUNC_END(cast6_cbc_dec_8way) 415*4882a593Smuzhiyun 416*4882a593SmuzhiyunSYM_FUNC_START(cast6_ctr_8way) 417*4882a593Smuzhiyun /* input: 418*4882a593Smuzhiyun * %rdi: ctx, CTX 419*4882a593Smuzhiyun * %rsi: dst 420*4882a593Smuzhiyun * %rdx: src 421*4882a593Smuzhiyun * %rcx: iv (little endian, 128bit) 422*4882a593Smuzhiyun */ 423*4882a593Smuzhiyun FRAME_BEGIN 424*4882a593Smuzhiyun pushq %r12; 425*4882a593Smuzhiyun pushq %r15 426*4882a593Smuzhiyun 427*4882a593Smuzhiyun movq %rdi, CTX; 428*4882a593Smuzhiyun movq %rsi, %r11; 429*4882a593Smuzhiyun movq %rdx, %r12; 430*4882a593Smuzhiyun 431*4882a593Smuzhiyun load_ctr_8way(%rcx, .Lbswap128_mask, RA1, RB1, RC1, RD1, RA2, RB2, RC2, 432*4882a593Smuzhiyun RD2, RX, RKR, RKM); 433*4882a593Smuzhiyun 434*4882a593Smuzhiyun call __cast6_enc_blk8; 435*4882a593Smuzhiyun 436*4882a593Smuzhiyun store_ctr_8way(%r12, %r11, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 437*4882a593Smuzhiyun 438*4882a593Smuzhiyun popq %r15; 439*4882a593Smuzhiyun popq %r12; 440*4882a593Smuzhiyun FRAME_END 441*4882a593Smuzhiyun RET; 442*4882a593SmuzhiyunSYM_FUNC_END(cast6_ctr_8way) 443*4882a593Smuzhiyun 444*4882a593SmuzhiyunSYM_FUNC_START(cast6_xts_enc_8way) 445*4882a593Smuzhiyun /* input: 446*4882a593Smuzhiyun * %rdi: ctx, CTX 447*4882a593Smuzhiyun * %rsi: dst 448*4882a593Smuzhiyun * %rdx: src 449*4882a593Smuzhiyun * %rcx: iv (t ⊕ αⁿ ∈ GF(2¹²⁸)) 450*4882a593Smuzhiyun */ 451*4882a593Smuzhiyun FRAME_BEGIN 452*4882a593Smuzhiyun pushq %r15; 453*4882a593Smuzhiyun 454*4882a593Smuzhiyun movq %rdi, CTX 455*4882a593Smuzhiyun movq %rsi, %r11; 456*4882a593Smuzhiyun 457*4882a593Smuzhiyun /* regs <= src, dst <= IVs, regs <= regs xor IVs */ 458*4882a593Smuzhiyun load_xts_8way(%rcx, %rdx, %rsi, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2, 459*4882a593Smuzhiyun RX, RKR, RKM, .Lxts_gf128mul_and_shl1_mask); 460*4882a593Smuzhiyun 461*4882a593Smuzhiyun call __cast6_enc_blk8; 462*4882a593Smuzhiyun 463*4882a593Smuzhiyun /* dst <= regs xor IVs(in dst) */ 464*4882a593Smuzhiyun store_xts_8way(%r11, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 465*4882a593Smuzhiyun 466*4882a593Smuzhiyun popq %r15; 467*4882a593Smuzhiyun FRAME_END 468*4882a593Smuzhiyun RET; 469*4882a593SmuzhiyunSYM_FUNC_END(cast6_xts_enc_8way) 470*4882a593Smuzhiyun 471*4882a593SmuzhiyunSYM_FUNC_START(cast6_xts_dec_8way) 472*4882a593Smuzhiyun /* input: 473*4882a593Smuzhiyun * %rdi: ctx, CTX 474*4882a593Smuzhiyun * %rsi: dst 475*4882a593Smuzhiyun * %rdx: src 476*4882a593Smuzhiyun * %rcx: iv (t ⊕ αⁿ ∈ GF(2¹²⁸)) 477*4882a593Smuzhiyun */ 478*4882a593Smuzhiyun FRAME_BEGIN 479*4882a593Smuzhiyun pushq %r15; 480*4882a593Smuzhiyun 481*4882a593Smuzhiyun movq %rdi, CTX 482*4882a593Smuzhiyun movq %rsi, %r11; 483*4882a593Smuzhiyun 484*4882a593Smuzhiyun /* regs <= src, dst <= IVs, regs <= regs xor IVs */ 485*4882a593Smuzhiyun load_xts_8way(%rcx, %rdx, %rsi, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2, 486*4882a593Smuzhiyun RX, RKR, RKM, .Lxts_gf128mul_and_shl1_mask); 487*4882a593Smuzhiyun 488*4882a593Smuzhiyun call __cast6_dec_blk8; 489*4882a593Smuzhiyun 490*4882a593Smuzhiyun /* dst <= regs xor IVs(in dst) */ 491*4882a593Smuzhiyun store_xts_8way(%r11, RA1, RB1, RC1, RD1, RA2, RB2, RC2, RD2); 492*4882a593Smuzhiyun 493*4882a593Smuzhiyun popq %r15; 494*4882a593Smuzhiyun FRAME_END 495*4882a593Smuzhiyun RET; 496*4882a593SmuzhiyunSYM_FUNC_END(cast6_xts_dec_8way) 497