xref: /OK3568_Linux_fs/kernel/arch/x86/crypto/sha256_ni_asm.S (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun/*
2*4882a593Smuzhiyun * Intel SHA Extensions optimized implementation of a SHA-256 update function
3*4882a593Smuzhiyun *
4*4882a593Smuzhiyun * This file is provided under a dual BSD/GPLv2 license.  When using or
5*4882a593Smuzhiyun * redistributing this file, you may do so under either license.
6*4882a593Smuzhiyun *
7*4882a593Smuzhiyun * GPL LICENSE SUMMARY
8*4882a593Smuzhiyun *
9*4882a593Smuzhiyun * Copyright(c) 2015 Intel Corporation.
10*4882a593Smuzhiyun *
11*4882a593Smuzhiyun * This program is free software; you can redistribute it and/or modify
12*4882a593Smuzhiyun * it under the terms of version 2 of the GNU General Public License as
13*4882a593Smuzhiyun * published by the Free Software Foundation.
14*4882a593Smuzhiyun *
15*4882a593Smuzhiyun * This program is distributed in the hope that it will be useful, but
16*4882a593Smuzhiyun * WITHOUT ANY WARRANTY; without even the implied warranty of
17*4882a593Smuzhiyun * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
18*4882a593Smuzhiyun * General Public License for more details.
19*4882a593Smuzhiyun *
20*4882a593Smuzhiyun * Contact Information:
21*4882a593Smuzhiyun * 	Sean Gulley <sean.m.gulley@intel.com>
22*4882a593Smuzhiyun * 	Tim Chen <tim.c.chen@linux.intel.com>
23*4882a593Smuzhiyun *
24*4882a593Smuzhiyun * BSD LICENSE
25*4882a593Smuzhiyun *
26*4882a593Smuzhiyun * Copyright(c) 2015 Intel Corporation.
27*4882a593Smuzhiyun *
28*4882a593Smuzhiyun * Redistribution and use in source and binary forms, with or without
29*4882a593Smuzhiyun * modification, are permitted provided that the following conditions
30*4882a593Smuzhiyun * are met:
31*4882a593Smuzhiyun *
32*4882a593Smuzhiyun * 	* Redistributions of source code must retain the above copyright
33*4882a593Smuzhiyun * 	  notice, this list of conditions and the following disclaimer.
34*4882a593Smuzhiyun * 	* Redistributions in binary form must reproduce the above copyright
35*4882a593Smuzhiyun * 	  notice, this list of conditions and the following disclaimer in
36*4882a593Smuzhiyun * 	  the documentation and/or other materials provided with the
37*4882a593Smuzhiyun * 	  distribution.
38*4882a593Smuzhiyun * 	* Neither the name of Intel Corporation nor the names of its
39*4882a593Smuzhiyun * 	  contributors may be used to endorse or promote products derived
40*4882a593Smuzhiyun * 	  from this software without specific prior written permission.
41*4882a593Smuzhiyun *
42*4882a593Smuzhiyun * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
43*4882a593Smuzhiyun * "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
44*4882a593Smuzhiyun * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
45*4882a593Smuzhiyun * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
46*4882a593Smuzhiyun * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
47*4882a593Smuzhiyun * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
48*4882a593Smuzhiyun * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
49*4882a593Smuzhiyun * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
50*4882a593Smuzhiyun * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
51*4882a593Smuzhiyun * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
52*4882a593Smuzhiyun * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
53*4882a593Smuzhiyun *
54*4882a593Smuzhiyun */
55*4882a593Smuzhiyun
56*4882a593Smuzhiyun#include <linux/linkage.h>
57*4882a593Smuzhiyun
58*4882a593Smuzhiyun#define DIGEST_PTR	%rdi	/* 1st arg */
59*4882a593Smuzhiyun#define DATA_PTR	%rsi	/* 2nd arg */
60*4882a593Smuzhiyun#define NUM_BLKS	%rdx	/* 3rd arg */
61*4882a593Smuzhiyun
62*4882a593Smuzhiyun#define SHA256CONSTANTS	%rax
63*4882a593Smuzhiyun
64*4882a593Smuzhiyun#define MSG		%xmm0
65*4882a593Smuzhiyun#define STATE0		%xmm1
66*4882a593Smuzhiyun#define STATE1		%xmm2
67*4882a593Smuzhiyun#define MSGTMP0		%xmm3
68*4882a593Smuzhiyun#define MSGTMP1		%xmm4
69*4882a593Smuzhiyun#define MSGTMP2		%xmm5
70*4882a593Smuzhiyun#define MSGTMP3		%xmm6
71*4882a593Smuzhiyun#define MSGTMP4		%xmm7
72*4882a593Smuzhiyun
73*4882a593Smuzhiyun#define SHUF_MASK	%xmm8
74*4882a593Smuzhiyun
75*4882a593Smuzhiyun#define ABEF_SAVE	%xmm9
76*4882a593Smuzhiyun#define CDGH_SAVE	%xmm10
77*4882a593Smuzhiyun
78*4882a593Smuzhiyun/*
79*4882a593Smuzhiyun * Intel SHA Extensions optimized implementation of a SHA-256 update function
80*4882a593Smuzhiyun *
81*4882a593Smuzhiyun * The function takes a pointer to the current hash values, a pointer to the
82*4882a593Smuzhiyun * input data, and a number of 64 byte blocks to process.  Once all blocks have
83*4882a593Smuzhiyun * been processed, the digest pointer is  updated with the resulting hash value.
84*4882a593Smuzhiyun * The function only processes complete blocks, there is no functionality to
85*4882a593Smuzhiyun * store partial blocks.  All message padding and hash value initialization must
86*4882a593Smuzhiyun * be done outside the update function.
87*4882a593Smuzhiyun *
88*4882a593Smuzhiyun * The indented lines in the loop are instructions related to rounds processing.
89*4882a593Smuzhiyun * The non-indented lines are instructions related to the message schedule.
90*4882a593Smuzhiyun *
91*4882a593Smuzhiyun * void sha256_ni_transform(uint32_t *digest, const void *data,
92*4882a593Smuzhiyun		uint32_t numBlocks);
93*4882a593Smuzhiyun * digest : pointer to digest
94*4882a593Smuzhiyun * data: pointer to input data
95*4882a593Smuzhiyun * numBlocks: Number of blocks to process
96*4882a593Smuzhiyun */
97*4882a593Smuzhiyun
98*4882a593Smuzhiyun.text
99*4882a593Smuzhiyun.align 32
100*4882a593SmuzhiyunSYM_FUNC_START(sha256_ni_transform)
101*4882a593Smuzhiyun
102*4882a593Smuzhiyun	shl		$6, NUM_BLKS		/*  convert to bytes */
103*4882a593Smuzhiyun	jz		.Ldone_hash
104*4882a593Smuzhiyun	add		DATA_PTR, NUM_BLKS	/* pointer to end of data */
105*4882a593Smuzhiyun
106*4882a593Smuzhiyun	/*
107*4882a593Smuzhiyun	 * load initial hash values
108*4882a593Smuzhiyun	 * Need to reorder these appropriately
109*4882a593Smuzhiyun	 * DCBA, HGFE -> ABEF, CDGH
110*4882a593Smuzhiyun	 */
111*4882a593Smuzhiyun	movdqu		0*16(DIGEST_PTR), STATE0
112*4882a593Smuzhiyun	movdqu		1*16(DIGEST_PTR), STATE1
113*4882a593Smuzhiyun
114*4882a593Smuzhiyun	pshufd		$0xB1, STATE0,  STATE0		/* CDAB */
115*4882a593Smuzhiyun	pshufd		$0x1B, STATE1,  STATE1		/* EFGH */
116*4882a593Smuzhiyun	movdqa		STATE0, MSGTMP4
117*4882a593Smuzhiyun	palignr		$8, STATE1,  STATE0		/* ABEF */
118*4882a593Smuzhiyun	pblendw		$0xF0, MSGTMP4, STATE1		/* CDGH */
119*4882a593Smuzhiyun
120*4882a593Smuzhiyun	movdqa		PSHUFFLE_BYTE_FLIP_MASK(%rip), SHUF_MASK
121*4882a593Smuzhiyun	lea		K256(%rip), SHA256CONSTANTS
122*4882a593Smuzhiyun
123*4882a593Smuzhiyun.Lloop0:
124*4882a593Smuzhiyun	/* Save hash values for addition after rounds */
125*4882a593Smuzhiyun	movdqa		STATE0, ABEF_SAVE
126*4882a593Smuzhiyun	movdqa		STATE1, CDGH_SAVE
127*4882a593Smuzhiyun
128*4882a593Smuzhiyun	/* Rounds 0-3 */
129*4882a593Smuzhiyun	movdqu		0*16(DATA_PTR), MSG
130*4882a593Smuzhiyun	pshufb		SHUF_MASK, MSG
131*4882a593Smuzhiyun	movdqa		MSG, MSGTMP0
132*4882a593Smuzhiyun		paddd		0*16(SHA256CONSTANTS), MSG
133*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
134*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
135*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
136*4882a593Smuzhiyun
137*4882a593Smuzhiyun	/* Rounds 4-7 */
138*4882a593Smuzhiyun	movdqu		1*16(DATA_PTR), MSG
139*4882a593Smuzhiyun	pshufb		SHUF_MASK, MSG
140*4882a593Smuzhiyun	movdqa		MSG, MSGTMP1
141*4882a593Smuzhiyun		paddd		1*16(SHA256CONSTANTS), MSG
142*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
143*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
144*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
145*4882a593Smuzhiyun	sha256msg1	MSGTMP1, MSGTMP0
146*4882a593Smuzhiyun
147*4882a593Smuzhiyun	/* Rounds 8-11 */
148*4882a593Smuzhiyun	movdqu		2*16(DATA_PTR), MSG
149*4882a593Smuzhiyun	pshufb		SHUF_MASK, MSG
150*4882a593Smuzhiyun	movdqa		MSG, MSGTMP2
151*4882a593Smuzhiyun		paddd		2*16(SHA256CONSTANTS), MSG
152*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
153*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
154*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
155*4882a593Smuzhiyun	sha256msg1	MSGTMP2, MSGTMP1
156*4882a593Smuzhiyun
157*4882a593Smuzhiyun	/* Rounds 12-15 */
158*4882a593Smuzhiyun	movdqu		3*16(DATA_PTR), MSG
159*4882a593Smuzhiyun	pshufb		SHUF_MASK, MSG
160*4882a593Smuzhiyun	movdqa		MSG, MSGTMP3
161*4882a593Smuzhiyun		paddd		3*16(SHA256CONSTANTS), MSG
162*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
163*4882a593Smuzhiyun	movdqa		MSGTMP3, MSGTMP4
164*4882a593Smuzhiyun	palignr		$4, MSGTMP2, MSGTMP4
165*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP0
166*4882a593Smuzhiyun	sha256msg2	MSGTMP3, MSGTMP0
167*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
168*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
169*4882a593Smuzhiyun	sha256msg1	MSGTMP3, MSGTMP2
170*4882a593Smuzhiyun
171*4882a593Smuzhiyun	/* Rounds 16-19 */
172*4882a593Smuzhiyun	movdqa		MSGTMP0, MSG
173*4882a593Smuzhiyun		paddd		4*16(SHA256CONSTANTS), MSG
174*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
175*4882a593Smuzhiyun	movdqa		MSGTMP0, MSGTMP4
176*4882a593Smuzhiyun	palignr		$4, MSGTMP3, MSGTMP4
177*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP1
178*4882a593Smuzhiyun	sha256msg2	MSGTMP0, MSGTMP1
179*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
180*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
181*4882a593Smuzhiyun	sha256msg1	MSGTMP0, MSGTMP3
182*4882a593Smuzhiyun
183*4882a593Smuzhiyun	/* Rounds 20-23 */
184*4882a593Smuzhiyun	movdqa		MSGTMP1, MSG
185*4882a593Smuzhiyun		paddd		5*16(SHA256CONSTANTS), MSG
186*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
187*4882a593Smuzhiyun	movdqa		MSGTMP1, MSGTMP4
188*4882a593Smuzhiyun	palignr		$4, MSGTMP0, MSGTMP4
189*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP2
190*4882a593Smuzhiyun	sha256msg2	MSGTMP1, MSGTMP2
191*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
192*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
193*4882a593Smuzhiyun	sha256msg1	MSGTMP1, MSGTMP0
194*4882a593Smuzhiyun
195*4882a593Smuzhiyun	/* Rounds 24-27 */
196*4882a593Smuzhiyun	movdqa		MSGTMP2, MSG
197*4882a593Smuzhiyun		paddd		6*16(SHA256CONSTANTS), MSG
198*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
199*4882a593Smuzhiyun	movdqa		MSGTMP2, MSGTMP4
200*4882a593Smuzhiyun	palignr		$4, MSGTMP1, MSGTMP4
201*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP3
202*4882a593Smuzhiyun	sha256msg2	MSGTMP2, MSGTMP3
203*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
204*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
205*4882a593Smuzhiyun	sha256msg1	MSGTMP2, MSGTMP1
206*4882a593Smuzhiyun
207*4882a593Smuzhiyun	/* Rounds 28-31 */
208*4882a593Smuzhiyun	movdqa		MSGTMP3, MSG
209*4882a593Smuzhiyun		paddd		7*16(SHA256CONSTANTS), MSG
210*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
211*4882a593Smuzhiyun	movdqa		MSGTMP3, MSGTMP4
212*4882a593Smuzhiyun	palignr		$4, MSGTMP2, MSGTMP4
213*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP0
214*4882a593Smuzhiyun	sha256msg2	MSGTMP3, MSGTMP0
215*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
216*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
217*4882a593Smuzhiyun	sha256msg1	MSGTMP3, MSGTMP2
218*4882a593Smuzhiyun
219*4882a593Smuzhiyun	/* Rounds 32-35 */
220*4882a593Smuzhiyun	movdqa		MSGTMP0, MSG
221*4882a593Smuzhiyun		paddd		8*16(SHA256CONSTANTS), MSG
222*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
223*4882a593Smuzhiyun	movdqa		MSGTMP0, MSGTMP4
224*4882a593Smuzhiyun	palignr		$4, MSGTMP3, MSGTMP4
225*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP1
226*4882a593Smuzhiyun	sha256msg2	MSGTMP0, MSGTMP1
227*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
228*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
229*4882a593Smuzhiyun	sha256msg1	MSGTMP0, MSGTMP3
230*4882a593Smuzhiyun
231*4882a593Smuzhiyun	/* Rounds 36-39 */
232*4882a593Smuzhiyun	movdqa		MSGTMP1, MSG
233*4882a593Smuzhiyun		paddd		9*16(SHA256CONSTANTS), MSG
234*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
235*4882a593Smuzhiyun	movdqa		MSGTMP1, MSGTMP4
236*4882a593Smuzhiyun	palignr		$4, MSGTMP0, MSGTMP4
237*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP2
238*4882a593Smuzhiyun	sha256msg2	MSGTMP1, MSGTMP2
239*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
240*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
241*4882a593Smuzhiyun	sha256msg1	MSGTMP1, MSGTMP0
242*4882a593Smuzhiyun
243*4882a593Smuzhiyun	/* Rounds 40-43 */
244*4882a593Smuzhiyun	movdqa		MSGTMP2, MSG
245*4882a593Smuzhiyun		paddd		10*16(SHA256CONSTANTS), MSG
246*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
247*4882a593Smuzhiyun	movdqa		MSGTMP2, MSGTMP4
248*4882a593Smuzhiyun	palignr		$4, MSGTMP1, MSGTMP4
249*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP3
250*4882a593Smuzhiyun	sha256msg2	MSGTMP2, MSGTMP3
251*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
252*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
253*4882a593Smuzhiyun	sha256msg1	MSGTMP2, MSGTMP1
254*4882a593Smuzhiyun
255*4882a593Smuzhiyun	/* Rounds 44-47 */
256*4882a593Smuzhiyun	movdqa		MSGTMP3, MSG
257*4882a593Smuzhiyun		paddd		11*16(SHA256CONSTANTS), MSG
258*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
259*4882a593Smuzhiyun	movdqa		MSGTMP3, MSGTMP4
260*4882a593Smuzhiyun	palignr		$4, MSGTMP2, MSGTMP4
261*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP0
262*4882a593Smuzhiyun	sha256msg2	MSGTMP3, MSGTMP0
263*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
264*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
265*4882a593Smuzhiyun	sha256msg1	MSGTMP3, MSGTMP2
266*4882a593Smuzhiyun
267*4882a593Smuzhiyun	/* Rounds 48-51 */
268*4882a593Smuzhiyun	movdqa		MSGTMP0, MSG
269*4882a593Smuzhiyun		paddd		12*16(SHA256CONSTANTS), MSG
270*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
271*4882a593Smuzhiyun	movdqa		MSGTMP0, MSGTMP4
272*4882a593Smuzhiyun	palignr		$4, MSGTMP3, MSGTMP4
273*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP1
274*4882a593Smuzhiyun	sha256msg2	MSGTMP0, MSGTMP1
275*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
276*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
277*4882a593Smuzhiyun	sha256msg1	MSGTMP0, MSGTMP3
278*4882a593Smuzhiyun
279*4882a593Smuzhiyun	/* Rounds 52-55 */
280*4882a593Smuzhiyun	movdqa		MSGTMP1, MSG
281*4882a593Smuzhiyun		paddd		13*16(SHA256CONSTANTS), MSG
282*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
283*4882a593Smuzhiyun	movdqa		MSGTMP1, MSGTMP4
284*4882a593Smuzhiyun	palignr		$4, MSGTMP0, MSGTMP4
285*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP2
286*4882a593Smuzhiyun	sha256msg2	MSGTMP1, MSGTMP2
287*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
288*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
289*4882a593Smuzhiyun
290*4882a593Smuzhiyun	/* Rounds 56-59 */
291*4882a593Smuzhiyun	movdqa		MSGTMP2, MSG
292*4882a593Smuzhiyun		paddd		14*16(SHA256CONSTANTS), MSG
293*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
294*4882a593Smuzhiyun	movdqa		MSGTMP2, MSGTMP4
295*4882a593Smuzhiyun	palignr		$4, MSGTMP1, MSGTMP4
296*4882a593Smuzhiyun	paddd		MSGTMP4, MSGTMP3
297*4882a593Smuzhiyun	sha256msg2	MSGTMP2, MSGTMP3
298*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
299*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
300*4882a593Smuzhiyun
301*4882a593Smuzhiyun	/* Rounds 60-63 */
302*4882a593Smuzhiyun	movdqa		MSGTMP3, MSG
303*4882a593Smuzhiyun		paddd		15*16(SHA256CONSTANTS), MSG
304*4882a593Smuzhiyun		sha256rnds2	STATE0, STATE1
305*4882a593Smuzhiyun		pshufd 		$0x0E, MSG, MSG
306*4882a593Smuzhiyun		sha256rnds2	STATE1, STATE0
307*4882a593Smuzhiyun
308*4882a593Smuzhiyun	/* Add current hash values with previously saved */
309*4882a593Smuzhiyun	paddd		ABEF_SAVE, STATE0
310*4882a593Smuzhiyun	paddd		CDGH_SAVE, STATE1
311*4882a593Smuzhiyun
312*4882a593Smuzhiyun	/* Increment data pointer and loop if more to process */
313*4882a593Smuzhiyun	add		$64, DATA_PTR
314*4882a593Smuzhiyun	cmp		NUM_BLKS, DATA_PTR
315*4882a593Smuzhiyun	jne		.Lloop0
316*4882a593Smuzhiyun
317*4882a593Smuzhiyun	/* Write hash values back in the correct order */
318*4882a593Smuzhiyun	pshufd		$0x1B, STATE0,  STATE0		/* FEBA */
319*4882a593Smuzhiyun	pshufd		$0xB1, STATE1,  STATE1		/* DCHG */
320*4882a593Smuzhiyun	movdqa		STATE0, MSGTMP4
321*4882a593Smuzhiyun	pblendw		$0xF0, STATE1,  STATE0		/* DCBA */
322*4882a593Smuzhiyun	palignr		$8, MSGTMP4, STATE1		/* HGFE */
323*4882a593Smuzhiyun
324*4882a593Smuzhiyun	movdqu		STATE0, 0*16(DIGEST_PTR)
325*4882a593Smuzhiyun	movdqu		STATE1, 1*16(DIGEST_PTR)
326*4882a593Smuzhiyun
327*4882a593Smuzhiyun.Ldone_hash:
328*4882a593Smuzhiyun
329*4882a593Smuzhiyun	RET
330*4882a593SmuzhiyunSYM_FUNC_END(sha256_ni_transform)
331*4882a593Smuzhiyun
332*4882a593Smuzhiyun.section	.rodata.cst256.K256, "aM", @progbits, 256
333*4882a593Smuzhiyun.align 64
334*4882a593SmuzhiyunK256:
335*4882a593Smuzhiyun	.long	0x428a2f98,0x71374491,0xb5c0fbcf,0xe9b5dba5
336*4882a593Smuzhiyun	.long	0x3956c25b,0x59f111f1,0x923f82a4,0xab1c5ed5
337*4882a593Smuzhiyun	.long	0xd807aa98,0x12835b01,0x243185be,0x550c7dc3
338*4882a593Smuzhiyun	.long	0x72be5d74,0x80deb1fe,0x9bdc06a7,0xc19bf174
339*4882a593Smuzhiyun	.long	0xe49b69c1,0xefbe4786,0x0fc19dc6,0x240ca1cc
340*4882a593Smuzhiyun	.long	0x2de92c6f,0x4a7484aa,0x5cb0a9dc,0x76f988da
341*4882a593Smuzhiyun	.long	0x983e5152,0xa831c66d,0xb00327c8,0xbf597fc7
342*4882a593Smuzhiyun	.long	0xc6e00bf3,0xd5a79147,0x06ca6351,0x14292967
343*4882a593Smuzhiyun	.long	0x27b70a85,0x2e1b2138,0x4d2c6dfc,0x53380d13
344*4882a593Smuzhiyun	.long	0x650a7354,0x766a0abb,0x81c2c92e,0x92722c85
345*4882a593Smuzhiyun	.long	0xa2bfe8a1,0xa81a664b,0xc24b8b70,0xc76c51a3
346*4882a593Smuzhiyun	.long	0xd192e819,0xd6990624,0xf40e3585,0x106aa070
347*4882a593Smuzhiyun	.long	0x19a4c116,0x1e376c08,0x2748774c,0x34b0bcb5
348*4882a593Smuzhiyun	.long	0x391c0cb3,0x4ed8aa4a,0x5b9cca4f,0x682e6ff3
349*4882a593Smuzhiyun	.long	0x748f82ee,0x78a5636f,0x84c87814,0x8cc70208
350*4882a593Smuzhiyun	.long	0x90befffa,0xa4506ceb,0xbef9a3f7,0xc67178f2
351*4882a593Smuzhiyun
352*4882a593Smuzhiyun.section	.rodata.cst16.PSHUFFLE_BYTE_FLIP_MASK, "aM", @progbits, 16
353*4882a593Smuzhiyun.align 16
354*4882a593SmuzhiyunPSHUFFLE_BYTE_FLIP_MASK:
355*4882a593Smuzhiyun	.octa 0x0c0d0e0f08090a0b0405060700010203
356