line |
stmt |
bran |
cond |
sub |
pod |
time |
code |
1
|
|
|
|
|
|
|
#include "fixedint.h" |
2
|
|
|
|
|
|
|
#include "sc.h" |
3
|
|
|
|
|
|
|
|
4
|
79764
|
|
|
|
|
|
static uint64_t load_3(const unsigned char *in) { |
5
|
|
|
|
|
|
|
uint64_t result; |
6
|
|
|
|
|
|
|
|
7
|
79764
|
|
|
|
|
|
result = (uint64_t) in[0]; |
8
|
79764
|
|
|
|
|
|
result |= ((uint64_t) in[1]) << 8; |
9
|
79764
|
|
|
|
|
|
result |= ((uint64_t) in[2]) << 16; |
10
|
|
|
|
|
|
|
|
11
|
79764
|
|
|
|
|
|
return result; |
12
|
|
|
|
|
|
|
} |
13
|
|
|
|
|
|
|
|
14
|
89148
|
|
|
|
|
|
static uint64_t load_4(const unsigned char *in) { |
15
|
|
|
|
|
|
|
uint64_t result; |
16
|
|
|
|
|
|
|
|
17
|
89148
|
|
|
|
|
|
result = (uint64_t) in[0]; |
18
|
89148
|
|
|
|
|
|
result |= ((uint64_t) in[1]) << 8; |
19
|
89148
|
|
|
|
|
|
result |= ((uint64_t) in[2]) << 16; |
20
|
89148
|
|
|
|
|
|
result |= ((uint64_t) in[3]) << 24; |
21
|
|
|
|
|
|
|
|
22
|
89148
|
|
|
|
|
|
return result; |
23
|
|
|
|
|
|
|
} |
24
|
|
|
|
|
|
|
|
25
|
|
|
|
|
|
|
/* |
26
|
|
|
|
|
|
|
Input: |
27
|
|
|
|
|
|
|
s[0]+256*s[1]+...+256^63*s[63] = s |
28
|
|
|
|
|
|
|
|
29
|
|
|
|
|
|
|
Output: |
30
|
|
|
|
|
|
|
s[0]+256*s[1]+...+256^31*s[31] = s mod l |
31
|
|
|
|
|
|
|
where l = 2^252 + 27742317777372353535851937790883648493. |
32
|
|
|
|
|
|
|
Overwrites s in place. |
33
|
|
|
|
|
|
|
*/ |
34
|
|
|
|
|
|
|
|
35
|
4692
|
|
|
|
|
|
void sc_reduce(unsigned char *s) { |
36
|
4692
|
|
|
|
|
|
int64_t s0 = 2097151 & load_3(s); |
37
|
4692
|
|
|
|
|
|
int64_t s1 = 2097151 & (load_4(s + 2) >> 5); |
38
|
4692
|
|
|
|
|
|
int64_t s2 = 2097151 & (load_3(s + 5) >> 2); |
39
|
4692
|
|
|
|
|
|
int64_t s3 = 2097151 & (load_4(s + 7) >> 7); |
40
|
4692
|
|
|
|
|
|
int64_t s4 = 2097151 & (load_4(s + 10) >> 4); |
41
|
4692
|
|
|
|
|
|
int64_t s5 = 2097151 & (load_3(s + 13) >> 1); |
42
|
4692
|
|
|
|
|
|
int64_t s6 = 2097151 & (load_4(s + 15) >> 6); |
43
|
4692
|
|
|
|
|
|
int64_t s7 = 2097151 & (load_3(s + 18) >> 3); |
44
|
4692
|
|
|
|
|
|
int64_t s8 = 2097151 & load_3(s + 21); |
45
|
4692
|
|
|
|
|
|
int64_t s9 = 2097151 & (load_4(s + 23) >> 5); |
46
|
4692
|
|
|
|
|
|
int64_t s10 = 2097151 & (load_3(s + 26) >> 2); |
47
|
4692
|
|
|
|
|
|
int64_t s11 = 2097151 & (load_4(s + 28) >> 7); |
48
|
4692
|
|
|
|
|
|
int64_t s12 = 2097151 & (load_4(s + 31) >> 4); |
49
|
4692
|
|
|
|
|
|
int64_t s13 = 2097151 & (load_3(s + 34) >> 1); |
50
|
4692
|
|
|
|
|
|
int64_t s14 = 2097151 & (load_4(s + 36) >> 6); |
51
|
4692
|
|
|
|
|
|
int64_t s15 = 2097151 & (load_3(s + 39) >> 3); |
52
|
4692
|
|
|
|
|
|
int64_t s16 = 2097151 & load_3(s + 42); |
53
|
4692
|
|
|
|
|
|
int64_t s17 = 2097151 & (load_4(s + 44) >> 5); |
54
|
4692
|
|
|
|
|
|
int64_t s18 = 2097151 & (load_3(s + 47) >> 2); |
55
|
4692
|
|
|
|
|
|
int64_t s19 = 2097151 & (load_4(s + 49) >> 7); |
56
|
4692
|
|
|
|
|
|
int64_t s20 = 2097151 & (load_4(s + 52) >> 4); |
57
|
4692
|
|
|
|
|
|
int64_t s21 = 2097151 & (load_3(s + 55) >> 1); |
58
|
4692
|
|
|
|
|
|
int64_t s22 = 2097151 & (load_4(s + 57) >> 6); |
59
|
4692
|
|
|
|
|
|
int64_t s23 = (load_4(s + 60) >> 3); |
60
|
|
|
|
|
|
|
int64_t carry0; |
61
|
|
|
|
|
|
|
int64_t carry1; |
62
|
|
|
|
|
|
|
int64_t carry2; |
63
|
|
|
|
|
|
|
int64_t carry3; |
64
|
|
|
|
|
|
|
int64_t carry4; |
65
|
|
|
|
|
|
|
int64_t carry5; |
66
|
|
|
|
|
|
|
int64_t carry6; |
67
|
|
|
|
|
|
|
int64_t carry7; |
68
|
|
|
|
|
|
|
int64_t carry8; |
69
|
|
|
|
|
|
|
int64_t carry9; |
70
|
|
|
|
|
|
|
int64_t carry10; |
71
|
|
|
|
|
|
|
int64_t carry11; |
72
|
|
|
|
|
|
|
int64_t carry12; |
73
|
|
|
|
|
|
|
int64_t carry13; |
74
|
|
|
|
|
|
|
int64_t carry14; |
75
|
|
|
|
|
|
|
int64_t carry15; |
76
|
|
|
|
|
|
|
int64_t carry16; |
77
|
|
|
|
|
|
|
|
78
|
4692
|
|
|
|
|
|
s11 += s23 * 666643; |
79
|
4692
|
|
|
|
|
|
s12 += s23 * 470296; |
80
|
4692
|
|
|
|
|
|
s13 += s23 * 654183; |
81
|
4692
|
|
|
|
|
|
s14 -= s23 * 997805; |
82
|
4692
|
|
|
|
|
|
s15 += s23 * 136657; |
83
|
4692
|
|
|
|
|
|
s16 -= s23 * 683901; |
84
|
4692
|
|
|
|
|
|
s23 = 0; |
85
|
4692
|
|
|
|
|
|
s10 += s22 * 666643; |
86
|
4692
|
|
|
|
|
|
s11 += s22 * 470296; |
87
|
4692
|
|
|
|
|
|
s12 += s22 * 654183; |
88
|
4692
|
|
|
|
|
|
s13 -= s22 * 997805; |
89
|
4692
|
|
|
|
|
|
s14 += s22 * 136657; |
90
|
4692
|
|
|
|
|
|
s15 -= s22 * 683901; |
91
|
4692
|
|
|
|
|
|
s22 = 0; |
92
|
4692
|
|
|
|
|
|
s9 += s21 * 666643; |
93
|
4692
|
|
|
|
|
|
s10 += s21 * 470296; |
94
|
4692
|
|
|
|
|
|
s11 += s21 * 654183; |
95
|
4692
|
|
|
|
|
|
s12 -= s21 * 997805; |
96
|
4692
|
|
|
|
|
|
s13 += s21 * 136657; |
97
|
4692
|
|
|
|
|
|
s14 -= s21 * 683901; |
98
|
4692
|
|
|
|
|
|
s21 = 0; |
99
|
4692
|
|
|
|
|
|
s8 += s20 * 666643; |
100
|
4692
|
|
|
|
|
|
s9 += s20 * 470296; |
101
|
4692
|
|
|
|
|
|
s10 += s20 * 654183; |
102
|
4692
|
|
|
|
|
|
s11 -= s20 * 997805; |
103
|
4692
|
|
|
|
|
|
s12 += s20 * 136657; |
104
|
4692
|
|
|
|
|
|
s13 -= s20 * 683901; |
105
|
4692
|
|
|
|
|
|
s20 = 0; |
106
|
4692
|
|
|
|
|
|
s7 += s19 * 666643; |
107
|
4692
|
|
|
|
|
|
s8 += s19 * 470296; |
108
|
4692
|
|
|
|
|
|
s9 += s19 * 654183; |
109
|
4692
|
|
|
|
|
|
s10 -= s19 * 997805; |
110
|
4692
|
|
|
|
|
|
s11 += s19 * 136657; |
111
|
4692
|
|
|
|
|
|
s12 -= s19 * 683901; |
112
|
4692
|
|
|
|
|
|
s19 = 0; |
113
|
4692
|
|
|
|
|
|
s6 += s18 * 666643; |
114
|
4692
|
|
|
|
|
|
s7 += s18 * 470296; |
115
|
4692
|
|
|
|
|
|
s8 += s18 * 654183; |
116
|
4692
|
|
|
|
|
|
s9 -= s18 * 997805; |
117
|
4692
|
|
|
|
|
|
s10 += s18 * 136657; |
118
|
4692
|
|
|
|
|
|
s11 -= s18 * 683901; |
119
|
4692
|
|
|
|
|
|
s18 = 0; |
120
|
4692
|
|
|
|
|
|
carry6 = (s6 + (1 << 20)) >> 21; |
121
|
4692
|
|
|
|
|
|
s7 += carry6; |
122
|
4692
|
|
|
|
|
|
s6 -= carry6 << 21; |
123
|
4692
|
|
|
|
|
|
carry8 = (s8 + (1 << 20)) >> 21; |
124
|
4692
|
|
|
|
|
|
s9 += carry8; |
125
|
4692
|
|
|
|
|
|
s8 -= carry8 << 21; |
126
|
4692
|
|
|
|
|
|
carry10 = (s10 + (1 << 20)) >> 21; |
127
|
4692
|
|
|
|
|
|
s11 += carry10; |
128
|
4692
|
|
|
|
|
|
s10 -= carry10 << 21; |
129
|
4692
|
|
|
|
|
|
carry12 = (s12 + (1 << 20)) >> 21; |
130
|
4692
|
|
|
|
|
|
s13 += carry12; |
131
|
4692
|
|
|
|
|
|
s12 -= carry12 << 21; |
132
|
4692
|
|
|
|
|
|
carry14 = (s14 + (1 << 20)) >> 21; |
133
|
4692
|
|
|
|
|
|
s15 += carry14; |
134
|
4692
|
|
|
|
|
|
s14 -= carry14 << 21; |
135
|
4692
|
|
|
|
|
|
carry16 = (s16 + (1 << 20)) >> 21; |
136
|
4692
|
|
|
|
|
|
s17 += carry16; |
137
|
4692
|
|
|
|
|
|
s16 -= carry16 << 21; |
138
|
4692
|
|
|
|
|
|
carry7 = (s7 + (1 << 20)) >> 21; |
139
|
4692
|
|
|
|
|
|
s8 += carry7; |
140
|
4692
|
|
|
|
|
|
s7 -= carry7 << 21; |
141
|
4692
|
|
|
|
|
|
carry9 = (s9 + (1 << 20)) >> 21; |
142
|
4692
|
|
|
|
|
|
s10 += carry9; |
143
|
4692
|
|
|
|
|
|
s9 -= carry9 << 21; |
144
|
4692
|
|
|
|
|
|
carry11 = (s11 + (1 << 20)) >> 21; |
145
|
4692
|
|
|
|
|
|
s12 += carry11; |
146
|
4692
|
|
|
|
|
|
s11 -= carry11 << 21; |
147
|
4692
|
|
|
|
|
|
carry13 = (s13 + (1 << 20)) >> 21; |
148
|
4692
|
|
|
|
|
|
s14 += carry13; |
149
|
4692
|
|
|
|
|
|
s13 -= carry13 << 21; |
150
|
4692
|
|
|
|
|
|
carry15 = (s15 + (1 << 20)) >> 21; |
151
|
4692
|
|
|
|
|
|
s16 += carry15; |
152
|
4692
|
|
|
|
|
|
s15 -= carry15 << 21; |
153
|
4692
|
|
|
|
|
|
s5 += s17 * 666643; |
154
|
4692
|
|
|
|
|
|
s6 += s17 * 470296; |
155
|
4692
|
|
|
|
|
|
s7 += s17 * 654183; |
156
|
4692
|
|
|
|
|
|
s8 -= s17 * 997805; |
157
|
4692
|
|
|
|
|
|
s9 += s17 * 136657; |
158
|
4692
|
|
|
|
|
|
s10 -= s17 * 683901; |
159
|
4692
|
|
|
|
|
|
s17 = 0; |
160
|
4692
|
|
|
|
|
|
s4 += s16 * 666643; |
161
|
4692
|
|
|
|
|
|
s5 += s16 * 470296; |
162
|
4692
|
|
|
|
|
|
s6 += s16 * 654183; |
163
|
4692
|
|
|
|
|
|
s7 -= s16 * 997805; |
164
|
4692
|
|
|
|
|
|
s8 += s16 * 136657; |
165
|
4692
|
|
|
|
|
|
s9 -= s16 * 683901; |
166
|
4692
|
|
|
|
|
|
s16 = 0; |
167
|
4692
|
|
|
|
|
|
s3 += s15 * 666643; |
168
|
4692
|
|
|
|
|
|
s4 += s15 * 470296; |
169
|
4692
|
|
|
|
|
|
s5 += s15 * 654183; |
170
|
4692
|
|
|
|
|
|
s6 -= s15 * 997805; |
171
|
4692
|
|
|
|
|
|
s7 += s15 * 136657; |
172
|
4692
|
|
|
|
|
|
s8 -= s15 * 683901; |
173
|
4692
|
|
|
|
|
|
s15 = 0; |
174
|
4692
|
|
|
|
|
|
s2 += s14 * 666643; |
175
|
4692
|
|
|
|
|
|
s3 += s14 * 470296; |
176
|
4692
|
|
|
|
|
|
s4 += s14 * 654183; |
177
|
4692
|
|
|
|
|
|
s5 -= s14 * 997805; |
178
|
4692
|
|
|
|
|
|
s6 += s14 * 136657; |
179
|
4692
|
|
|
|
|
|
s7 -= s14 * 683901; |
180
|
4692
|
|
|
|
|
|
s14 = 0; |
181
|
4692
|
|
|
|
|
|
s1 += s13 * 666643; |
182
|
4692
|
|
|
|
|
|
s2 += s13 * 470296; |
183
|
4692
|
|
|
|
|
|
s3 += s13 * 654183; |
184
|
4692
|
|
|
|
|
|
s4 -= s13 * 997805; |
185
|
4692
|
|
|
|
|
|
s5 += s13 * 136657; |
186
|
4692
|
|
|
|
|
|
s6 -= s13 * 683901; |
187
|
4692
|
|
|
|
|
|
s13 = 0; |
188
|
4692
|
|
|
|
|
|
s0 += s12 * 666643; |
189
|
4692
|
|
|
|
|
|
s1 += s12 * 470296; |
190
|
4692
|
|
|
|
|
|
s2 += s12 * 654183; |
191
|
4692
|
|
|
|
|
|
s3 -= s12 * 997805; |
192
|
4692
|
|
|
|
|
|
s4 += s12 * 136657; |
193
|
4692
|
|
|
|
|
|
s5 -= s12 * 683901; |
194
|
4692
|
|
|
|
|
|
s12 = 0; |
195
|
4692
|
|
|
|
|
|
carry0 = (s0 + (1 << 20)) >> 21; |
196
|
4692
|
|
|
|
|
|
s1 += carry0; |
197
|
4692
|
|
|
|
|
|
s0 -= carry0 << 21; |
198
|
4692
|
|
|
|
|
|
carry2 = (s2 + (1 << 20)) >> 21; |
199
|
4692
|
|
|
|
|
|
s3 += carry2; |
200
|
4692
|
|
|
|
|
|
s2 -= carry2 << 21; |
201
|
4692
|
|
|
|
|
|
carry4 = (s4 + (1 << 20)) >> 21; |
202
|
4692
|
|
|
|
|
|
s5 += carry4; |
203
|
4692
|
|
|
|
|
|
s4 -= carry4 << 21; |
204
|
4692
|
|
|
|
|
|
carry6 = (s6 + (1 << 20)) >> 21; |
205
|
4692
|
|
|
|
|
|
s7 += carry6; |
206
|
4692
|
|
|
|
|
|
s6 -= carry6 << 21; |
207
|
4692
|
|
|
|
|
|
carry8 = (s8 + (1 << 20)) >> 21; |
208
|
4692
|
|
|
|
|
|
s9 += carry8; |
209
|
4692
|
|
|
|
|
|
s8 -= carry8 << 21; |
210
|
4692
|
|
|
|
|
|
carry10 = (s10 + (1 << 20)) >> 21; |
211
|
4692
|
|
|
|
|
|
s11 += carry10; |
212
|
4692
|
|
|
|
|
|
s10 -= carry10 << 21; |
213
|
4692
|
|
|
|
|
|
carry1 = (s1 + (1 << 20)) >> 21; |
214
|
4692
|
|
|
|
|
|
s2 += carry1; |
215
|
4692
|
|
|
|
|
|
s1 -= carry1 << 21; |
216
|
4692
|
|
|
|
|
|
carry3 = (s3 + (1 << 20)) >> 21; |
217
|
4692
|
|
|
|
|
|
s4 += carry3; |
218
|
4692
|
|
|
|
|
|
s3 -= carry3 << 21; |
219
|
4692
|
|
|
|
|
|
carry5 = (s5 + (1 << 20)) >> 21; |
220
|
4692
|
|
|
|
|
|
s6 += carry5; |
221
|
4692
|
|
|
|
|
|
s5 -= carry5 << 21; |
222
|
4692
|
|
|
|
|
|
carry7 = (s7 + (1 << 20)) >> 21; |
223
|
4692
|
|
|
|
|
|
s8 += carry7; |
224
|
4692
|
|
|
|
|
|
s7 -= carry7 << 21; |
225
|
4692
|
|
|
|
|
|
carry9 = (s9 + (1 << 20)) >> 21; |
226
|
4692
|
|
|
|
|
|
s10 += carry9; |
227
|
4692
|
|
|
|
|
|
s9 -= carry9 << 21; |
228
|
4692
|
|
|
|
|
|
carry11 = (s11 + (1 << 20)) >> 21; |
229
|
4692
|
|
|
|
|
|
s12 += carry11; |
230
|
4692
|
|
|
|
|
|
s11 -= carry11 << 21; |
231
|
4692
|
|
|
|
|
|
s0 += s12 * 666643; |
232
|
4692
|
|
|
|
|
|
s1 += s12 * 470296; |
233
|
4692
|
|
|
|
|
|
s2 += s12 * 654183; |
234
|
4692
|
|
|
|
|
|
s3 -= s12 * 997805; |
235
|
4692
|
|
|
|
|
|
s4 += s12 * 136657; |
236
|
4692
|
|
|
|
|
|
s5 -= s12 * 683901; |
237
|
4692
|
|
|
|
|
|
s12 = 0; |
238
|
4692
|
|
|
|
|
|
carry0 = s0 >> 21; |
239
|
4692
|
|
|
|
|
|
s1 += carry0; |
240
|
4692
|
|
|
|
|
|
s0 -= carry0 << 21; |
241
|
4692
|
|
|
|
|
|
carry1 = s1 >> 21; |
242
|
4692
|
|
|
|
|
|
s2 += carry1; |
243
|
4692
|
|
|
|
|
|
s1 -= carry1 << 21; |
244
|
4692
|
|
|
|
|
|
carry2 = s2 >> 21; |
245
|
4692
|
|
|
|
|
|
s3 += carry2; |
246
|
4692
|
|
|
|
|
|
s2 -= carry2 << 21; |
247
|
4692
|
|
|
|
|
|
carry3 = s3 >> 21; |
248
|
4692
|
|
|
|
|
|
s4 += carry3; |
249
|
4692
|
|
|
|
|
|
s3 -= carry3 << 21; |
250
|
4692
|
|
|
|
|
|
carry4 = s4 >> 21; |
251
|
4692
|
|
|
|
|
|
s5 += carry4; |
252
|
4692
|
|
|
|
|
|
s4 -= carry4 << 21; |
253
|
4692
|
|
|
|
|
|
carry5 = s5 >> 21; |
254
|
4692
|
|
|
|
|
|
s6 += carry5; |
255
|
4692
|
|
|
|
|
|
s5 -= carry5 << 21; |
256
|
4692
|
|
|
|
|
|
carry6 = s6 >> 21; |
257
|
4692
|
|
|
|
|
|
s7 += carry6; |
258
|
4692
|
|
|
|
|
|
s6 -= carry6 << 21; |
259
|
4692
|
|
|
|
|
|
carry7 = s7 >> 21; |
260
|
4692
|
|
|
|
|
|
s8 += carry7; |
261
|
4692
|
|
|
|
|
|
s7 -= carry7 << 21; |
262
|
4692
|
|
|
|
|
|
carry8 = s8 >> 21; |
263
|
4692
|
|
|
|
|
|
s9 += carry8; |
264
|
4692
|
|
|
|
|
|
s8 -= carry8 << 21; |
265
|
4692
|
|
|
|
|
|
carry9 = s9 >> 21; |
266
|
4692
|
|
|
|
|
|
s10 += carry9; |
267
|
4692
|
|
|
|
|
|
s9 -= carry9 << 21; |
268
|
4692
|
|
|
|
|
|
carry10 = s10 >> 21; |
269
|
4692
|
|
|
|
|
|
s11 += carry10; |
270
|
4692
|
|
|
|
|
|
s10 -= carry10 << 21; |
271
|
4692
|
|
|
|
|
|
carry11 = s11 >> 21; |
272
|
4692
|
|
|
|
|
|
s12 += carry11; |
273
|
4692
|
|
|
|
|
|
s11 -= carry11 << 21; |
274
|
4692
|
|
|
|
|
|
s0 += s12 * 666643; |
275
|
4692
|
|
|
|
|
|
s1 += s12 * 470296; |
276
|
4692
|
|
|
|
|
|
s2 += s12 * 654183; |
277
|
4692
|
|
|
|
|
|
s3 -= s12 * 997805; |
278
|
4692
|
|
|
|
|
|
s4 += s12 * 136657; |
279
|
4692
|
|
|
|
|
|
s5 -= s12 * 683901; |
280
|
4692
|
|
|
|
|
|
s12 = 0; |
281
|
4692
|
|
|
|
|
|
carry0 = s0 >> 21; |
282
|
4692
|
|
|
|
|
|
s1 += carry0; |
283
|
4692
|
|
|
|
|
|
s0 -= carry0 << 21; |
284
|
4692
|
|
|
|
|
|
carry1 = s1 >> 21; |
285
|
4692
|
|
|
|
|
|
s2 += carry1; |
286
|
4692
|
|
|
|
|
|
s1 -= carry1 << 21; |
287
|
4692
|
|
|
|
|
|
carry2 = s2 >> 21; |
288
|
4692
|
|
|
|
|
|
s3 += carry2; |
289
|
4692
|
|
|
|
|
|
s2 -= carry2 << 21; |
290
|
4692
|
|
|
|
|
|
carry3 = s3 >> 21; |
291
|
4692
|
|
|
|
|
|
s4 += carry3; |
292
|
4692
|
|
|
|
|
|
s3 -= carry3 << 21; |
293
|
4692
|
|
|
|
|
|
carry4 = s4 >> 21; |
294
|
4692
|
|
|
|
|
|
s5 += carry4; |
295
|
4692
|
|
|
|
|
|
s4 -= carry4 << 21; |
296
|
4692
|
|
|
|
|
|
carry5 = s5 >> 21; |
297
|
4692
|
|
|
|
|
|
s6 += carry5; |
298
|
4692
|
|
|
|
|
|
s5 -= carry5 << 21; |
299
|
4692
|
|
|
|
|
|
carry6 = s6 >> 21; |
300
|
4692
|
|
|
|
|
|
s7 += carry6; |
301
|
4692
|
|
|
|
|
|
s6 -= carry6 << 21; |
302
|
4692
|
|
|
|
|
|
carry7 = s7 >> 21; |
303
|
4692
|
|
|
|
|
|
s8 += carry7; |
304
|
4692
|
|
|
|
|
|
s7 -= carry7 << 21; |
305
|
4692
|
|
|
|
|
|
carry8 = s8 >> 21; |
306
|
4692
|
|
|
|
|
|
s9 += carry8; |
307
|
4692
|
|
|
|
|
|
s8 -= carry8 << 21; |
308
|
4692
|
|
|
|
|
|
carry9 = s9 >> 21; |
309
|
4692
|
|
|
|
|
|
s10 += carry9; |
310
|
4692
|
|
|
|
|
|
s9 -= carry9 << 21; |
311
|
4692
|
|
|
|
|
|
carry10 = s10 >> 21; |
312
|
4692
|
|
|
|
|
|
s11 += carry10; |
313
|
4692
|
|
|
|
|
|
s10 -= carry10 << 21; |
314
|
|
|
|
|
|
|
|
315
|
4692
|
|
|
|
|
|
s[0] = (unsigned char) (s0 >> 0); |
316
|
4692
|
|
|
|
|
|
s[1] = (unsigned char) (s0 >> 8); |
317
|
4692
|
|
|
|
|
|
s[2] = (unsigned char) ((s0 >> 16) | (s1 << 5)); |
318
|
4692
|
|
|
|
|
|
s[3] = (unsigned char) (s1 >> 3); |
319
|
4692
|
|
|
|
|
|
s[4] = (unsigned char) (s1 >> 11); |
320
|
4692
|
|
|
|
|
|
s[5] = (unsigned char) ((s1 >> 19) | (s2 << 2)); |
321
|
4692
|
|
|
|
|
|
s[6] = (unsigned char) (s2 >> 6); |
322
|
4692
|
|
|
|
|
|
s[7] = (unsigned char) ((s2 >> 14) | (s3 << 7)); |
323
|
4692
|
|
|
|
|
|
s[8] = (unsigned char) (s3 >> 1); |
324
|
4692
|
|
|
|
|
|
s[9] = (unsigned char) (s3 >> 9); |
325
|
4692
|
|
|
|
|
|
s[10] = (unsigned char) ((s3 >> 17) | (s4 << 4)); |
326
|
4692
|
|
|
|
|
|
s[11] = (unsigned char) (s4 >> 4); |
327
|
4692
|
|
|
|
|
|
s[12] = (unsigned char) (s4 >> 12); |
328
|
4692
|
|
|
|
|
|
s[13] = (unsigned char) ((s4 >> 20) | (s5 << 1)); |
329
|
4692
|
|
|
|
|
|
s[14] = (unsigned char) (s5 >> 7); |
330
|
4692
|
|
|
|
|
|
s[15] = (unsigned char) ((s5 >> 15) | (s6 << 6)); |
331
|
4692
|
|
|
|
|
|
s[16] = (unsigned char) (s6 >> 2); |
332
|
4692
|
|
|
|
|
|
s[17] = (unsigned char) (s6 >> 10); |
333
|
4692
|
|
|
|
|
|
s[18] = (unsigned char) ((s6 >> 18) | (s7 << 3)); |
334
|
4692
|
|
|
|
|
|
s[19] = (unsigned char) (s7 >> 5); |
335
|
4692
|
|
|
|
|
|
s[20] = (unsigned char) (s7 >> 13); |
336
|
4692
|
|
|
|
|
|
s[21] = (unsigned char) (s8 >> 0); |
337
|
4692
|
|
|
|
|
|
s[22] = (unsigned char) (s8 >> 8); |
338
|
4692
|
|
|
|
|
|
s[23] = (unsigned char) ((s8 >> 16) | (s9 << 5)); |
339
|
4692
|
|
|
|
|
|
s[24] = (unsigned char) (s9 >> 3); |
340
|
4692
|
|
|
|
|
|
s[25] = (unsigned char) (s9 >> 11); |
341
|
4692
|
|
|
|
|
|
s[26] = (unsigned char) ((s9 >> 19) | (s10 << 2)); |
342
|
4692
|
|
|
|
|
|
s[27] = (unsigned char) (s10 >> 6); |
343
|
4692
|
|
|
|
|
|
s[28] = (unsigned char) ((s10 >> 14) | (s11 << 7)); |
344
|
4692
|
|
|
|
|
|
s[29] = (unsigned char) (s11 >> 1); |
345
|
4692
|
|
|
|
|
|
s[30] = (unsigned char) (s11 >> 9); |
346
|
4692
|
|
|
|
|
|
s[31] = (unsigned char) (s11 >> 17); |
347
|
4692
|
|
|
|
|
|
} |
348
|
|
|
|
|
|
|
|
349
|
|
|
|
|
|
|
|
350
|
|
|
|
|
|
|
|
351
|
|
|
|
|
|
|
/* |
352
|
|
|
|
|
|
|
Input: |
353
|
|
|
|
|
|
|
a[0]+256*a[1]+...+256^31*a[31] = a |
354
|
|
|
|
|
|
|
b[0]+256*b[1]+...+256^31*b[31] = b |
355
|
|
|
|
|
|
|
c[0]+256*c[1]+...+256^31*c[31] = c |
356
|
|
|
|
|
|
|
|
357
|
|
|
|
|
|
|
Output: |
358
|
|
|
|
|
|
|
s[0]+256*s[1]+...+256^31*s[31] = (ab+c) mod l |
359
|
|
|
|
|
|
|
where l = 2^252 + 27742317777372353535851937790883648493. |
360
|
|
|
|
|
|
|
*/ |
361
|
|
|
|
|
|
|
|
362
|
1564
|
|
|
|
|
|
void sc_muladd(unsigned char *s, const unsigned char *a, const unsigned char *b, const unsigned char *c) { |
363
|
1564
|
|
|
|
|
|
int64_t a0 = 2097151 & load_3(a); |
364
|
1564
|
|
|
|
|
|
int64_t a1 = 2097151 & (load_4(a + 2) >> 5); |
365
|
1564
|
|
|
|
|
|
int64_t a2 = 2097151 & (load_3(a + 5) >> 2); |
366
|
1564
|
|
|
|
|
|
int64_t a3 = 2097151 & (load_4(a + 7) >> 7); |
367
|
1564
|
|
|
|
|
|
int64_t a4 = 2097151 & (load_4(a + 10) >> 4); |
368
|
1564
|
|
|
|
|
|
int64_t a5 = 2097151 & (load_3(a + 13) >> 1); |
369
|
1564
|
|
|
|
|
|
int64_t a6 = 2097151 & (load_4(a + 15) >> 6); |
370
|
1564
|
|
|
|
|
|
int64_t a7 = 2097151 & (load_3(a + 18) >> 3); |
371
|
1564
|
|
|
|
|
|
int64_t a8 = 2097151 & load_3(a + 21); |
372
|
1564
|
|
|
|
|
|
int64_t a9 = 2097151 & (load_4(a + 23) >> 5); |
373
|
1564
|
|
|
|
|
|
int64_t a10 = 2097151 & (load_3(a + 26) >> 2); |
374
|
1564
|
|
|
|
|
|
int64_t a11 = (load_4(a + 28) >> 7); |
375
|
1564
|
|
|
|
|
|
int64_t b0 = 2097151 & load_3(b); |
376
|
1564
|
|
|
|
|
|
int64_t b1 = 2097151 & (load_4(b + 2) >> 5); |
377
|
1564
|
|
|
|
|
|
int64_t b2 = 2097151 & (load_3(b + 5) >> 2); |
378
|
1564
|
|
|
|
|
|
int64_t b3 = 2097151 & (load_4(b + 7) >> 7); |
379
|
1564
|
|
|
|
|
|
int64_t b4 = 2097151 & (load_4(b + 10) >> 4); |
380
|
1564
|
|
|
|
|
|
int64_t b5 = 2097151 & (load_3(b + 13) >> 1); |
381
|
1564
|
|
|
|
|
|
int64_t b6 = 2097151 & (load_4(b + 15) >> 6); |
382
|
1564
|
|
|
|
|
|
int64_t b7 = 2097151 & (load_3(b + 18) >> 3); |
383
|
1564
|
|
|
|
|
|
int64_t b8 = 2097151 & load_3(b + 21); |
384
|
1564
|
|
|
|
|
|
int64_t b9 = 2097151 & (load_4(b + 23) >> 5); |
385
|
1564
|
|
|
|
|
|
int64_t b10 = 2097151 & (load_3(b + 26) >> 2); |
386
|
1564
|
|
|
|
|
|
int64_t b11 = (load_4(b + 28) >> 7); |
387
|
1564
|
|
|
|
|
|
int64_t c0 = 2097151 & load_3(c); |
388
|
1564
|
|
|
|
|
|
int64_t c1 = 2097151 & (load_4(c + 2) >> 5); |
389
|
1564
|
|
|
|
|
|
int64_t c2 = 2097151 & (load_3(c + 5) >> 2); |
390
|
1564
|
|
|
|
|
|
int64_t c3 = 2097151 & (load_4(c + 7) >> 7); |
391
|
1564
|
|
|
|
|
|
int64_t c4 = 2097151 & (load_4(c + 10) >> 4); |
392
|
1564
|
|
|
|
|
|
int64_t c5 = 2097151 & (load_3(c + 13) >> 1); |
393
|
1564
|
|
|
|
|
|
int64_t c6 = 2097151 & (load_4(c + 15) >> 6); |
394
|
1564
|
|
|
|
|
|
int64_t c7 = 2097151 & (load_3(c + 18) >> 3); |
395
|
1564
|
|
|
|
|
|
int64_t c8 = 2097151 & load_3(c + 21); |
396
|
1564
|
|
|
|
|
|
int64_t c9 = 2097151 & (load_4(c + 23) >> 5); |
397
|
1564
|
|
|
|
|
|
int64_t c10 = 2097151 & (load_3(c + 26) >> 2); |
398
|
1564
|
|
|
|
|
|
int64_t c11 = (load_4(c + 28) >> 7); |
399
|
|
|
|
|
|
|
int64_t s0; |
400
|
|
|
|
|
|
|
int64_t s1; |
401
|
|
|
|
|
|
|
int64_t s2; |
402
|
|
|
|
|
|
|
int64_t s3; |
403
|
|
|
|
|
|
|
int64_t s4; |
404
|
|
|
|
|
|
|
int64_t s5; |
405
|
|
|
|
|
|
|
int64_t s6; |
406
|
|
|
|
|
|
|
int64_t s7; |
407
|
|
|
|
|
|
|
int64_t s8; |
408
|
|
|
|
|
|
|
int64_t s9; |
409
|
|
|
|
|
|
|
int64_t s10; |
410
|
|
|
|
|
|
|
int64_t s11; |
411
|
|
|
|
|
|
|
int64_t s12; |
412
|
|
|
|
|
|
|
int64_t s13; |
413
|
|
|
|
|
|
|
int64_t s14; |
414
|
|
|
|
|
|
|
int64_t s15; |
415
|
|
|
|
|
|
|
int64_t s16; |
416
|
|
|
|
|
|
|
int64_t s17; |
417
|
|
|
|
|
|
|
int64_t s18; |
418
|
|
|
|
|
|
|
int64_t s19; |
419
|
|
|
|
|
|
|
int64_t s20; |
420
|
|
|
|
|
|
|
int64_t s21; |
421
|
|
|
|
|
|
|
int64_t s22; |
422
|
|
|
|
|
|
|
int64_t s23; |
423
|
|
|
|
|
|
|
int64_t carry0; |
424
|
|
|
|
|
|
|
int64_t carry1; |
425
|
|
|
|
|
|
|
int64_t carry2; |
426
|
|
|
|
|
|
|
int64_t carry3; |
427
|
|
|
|
|
|
|
int64_t carry4; |
428
|
|
|
|
|
|
|
int64_t carry5; |
429
|
|
|
|
|
|
|
int64_t carry6; |
430
|
|
|
|
|
|
|
int64_t carry7; |
431
|
|
|
|
|
|
|
int64_t carry8; |
432
|
|
|
|
|
|
|
int64_t carry9; |
433
|
|
|
|
|
|
|
int64_t carry10; |
434
|
|
|
|
|
|
|
int64_t carry11; |
435
|
|
|
|
|
|
|
int64_t carry12; |
436
|
|
|
|
|
|
|
int64_t carry13; |
437
|
|
|
|
|
|
|
int64_t carry14; |
438
|
|
|
|
|
|
|
int64_t carry15; |
439
|
|
|
|
|
|
|
int64_t carry16; |
440
|
|
|
|
|
|
|
int64_t carry17; |
441
|
|
|
|
|
|
|
int64_t carry18; |
442
|
|
|
|
|
|
|
int64_t carry19; |
443
|
|
|
|
|
|
|
int64_t carry20; |
444
|
|
|
|
|
|
|
int64_t carry21; |
445
|
|
|
|
|
|
|
int64_t carry22; |
446
|
|
|
|
|
|
|
|
447
|
1564
|
|
|
|
|
|
s0 = c0 + a0 * b0; |
448
|
1564
|
|
|
|
|
|
s1 = c1 + a0 * b1 + a1 * b0; |
449
|
1564
|
|
|
|
|
|
s2 = c2 + a0 * b2 + a1 * b1 + a2 * b0; |
450
|
1564
|
|
|
|
|
|
s3 = c3 + a0 * b3 + a1 * b2 + a2 * b1 + a3 * b0; |
451
|
1564
|
|
|
|
|
|
s4 = c4 + a0 * b4 + a1 * b3 + a2 * b2 + a3 * b1 + a4 * b0; |
452
|
1564
|
|
|
|
|
|
s5 = c5 + a0 * b5 + a1 * b4 + a2 * b3 + a3 * b2 + a4 * b1 + a5 * b0; |
453
|
1564
|
|
|
|
|
|
s6 = c6 + a0 * b6 + a1 * b5 + a2 * b4 + a3 * b3 + a4 * b2 + a5 * b1 + a6 * b0; |
454
|
1564
|
|
|
|
|
|
s7 = c7 + a0 * b7 + a1 * b6 + a2 * b5 + a3 * b4 + a4 * b3 + a5 * b2 + a6 * b1 + a7 * b0; |
455
|
1564
|
|
|
|
|
|
s8 = c8 + a0 * b8 + a1 * b7 + a2 * b6 + a3 * b5 + a4 * b4 + a5 * b3 + a6 * b2 + a7 * b1 + a8 * b0; |
456
|
1564
|
|
|
|
|
|
s9 = c9 + a0 * b9 + a1 * b8 + a2 * b7 + a3 * b6 + a4 * b5 + a5 * b4 + a6 * b3 + a7 * b2 + a8 * b1 + a9 * b0; |
457
|
1564
|
|
|
|
|
|
s10 = c10 + a0 * b10 + a1 * b9 + a2 * b8 + a3 * b7 + a4 * b6 + a5 * b5 + a6 * b4 + a7 * b3 + a8 * b2 + a9 * b1 + a10 * b0; |
458
|
1564
|
|
|
|
|
|
s11 = c11 + a0 * b11 + a1 * b10 + a2 * b9 + a3 * b8 + a4 * b7 + a5 * b6 + a6 * b5 + a7 * b4 + a8 * b3 + a9 * b2 + a10 * b1 + a11 * b0; |
459
|
1564
|
|
|
|
|
|
s12 = a1 * b11 + a2 * b10 + a3 * b9 + a4 * b8 + a5 * b7 + a6 * b6 + a7 * b5 + a8 * b4 + a9 * b3 + a10 * b2 + a11 * b1; |
460
|
1564
|
|
|
|
|
|
s13 = a2 * b11 + a3 * b10 + a4 * b9 + a5 * b8 + a6 * b7 + a7 * b6 + a8 * b5 + a9 * b4 + a10 * b3 + a11 * b2; |
461
|
1564
|
|
|
|
|
|
s14 = a3 * b11 + a4 * b10 + a5 * b9 + a6 * b8 + a7 * b7 + a8 * b6 + a9 * b5 + a10 * b4 + a11 * b3; |
462
|
1564
|
|
|
|
|
|
s15 = a4 * b11 + a5 * b10 + a6 * b9 + a7 * b8 + a8 * b7 + a9 * b6 + a10 * b5 + a11 * b4; |
463
|
1564
|
|
|
|
|
|
s16 = a5 * b11 + a6 * b10 + a7 * b9 + a8 * b8 + a9 * b7 + a10 * b6 + a11 * b5; |
464
|
1564
|
|
|
|
|
|
s17 = a6 * b11 + a7 * b10 + a8 * b9 + a9 * b8 + a10 * b7 + a11 * b6; |
465
|
1564
|
|
|
|
|
|
s18 = a7 * b11 + a8 * b10 + a9 * b9 + a10 * b8 + a11 * b7; |
466
|
1564
|
|
|
|
|
|
s19 = a8 * b11 + a9 * b10 + a10 * b9 + a11 * b8; |
467
|
1564
|
|
|
|
|
|
s20 = a9 * b11 + a10 * b10 + a11 * b9; |
468
|
1564
|
|
|
|
|
|
s21 = a10 * b11 + a11 * b10; |
469
|
1564
|
|
|
|
|
|
s22 = a11 * b11; |
470
|
1564
|
|
|
|
|
|
s23 = 0; |
471
|
1564
|
|
|
|
|
|
carry0 = (s0 + (1 << 20)) >> 21; |
472
|
1564
|
|
|
|
|
|
s1 += carry0; |
473
|
1564
|
|
|
|
|
|
s0 -= carry0 << 21; |
474
|
1564
|
|
|
|
|
|
carry2 = (s2 + (1 << 20)) >> 21; |
475
|
1564
|
|
|
|
|
|
s3 += carry2; |
476
|
1564
|
|
|
|
|
|
s2 -= carry2 << 21; |
477
|
1564
|
|
|
|
|
|
carry4 = (s4 + (1 << 20)) >> 21; |
478
|
1564
|
|
|
|
|
|
s5 += carry4; |
479
|
1564
|
|
|
|
|
|
s4 -= carry4 << 21; |
480
|
1564
|
|
|
|
|
|
carry6 = (s6 + (1 << 20)) >> 21; |
481
|
1564
|
|
|
|
|
|
s7 += carry6; |
482
|
1564
|
|
|
|
|
|
s6 -= carry6 << 21; |
483
|
1564
|
|
|
|
|
|
carry8 = (s8 + (1 << 20)) >> 21; |
484
|
1564
|
|
|
|
|
|
s9 += carry8; |
485
|
1564
|
|
|
|
|
|
s8 -= carry8 << 21; |
486
|
1564
|
|
|
|
|
|
carry10 = (s10 + (1 << 20)) >> 21; |
487
|
1564
|
|
|
|
|
|
s11 += carry10; |
488
|
1564
|
|
|
|
|
|
s10 -= carry10 << 21; |
489
|
1564
|
|
|
|
|
|
carry12 = (s12 + (1 << 20)) >> 21; |
490
|
1564
|
|
|
|
|
|
s13 += carry12; |
491
|
1564
|
|
|
|
|
|
s12 -= carry12 << 21; |
492
|
1564
|
|
|
|
|
|
carry14 = (s14 + (1 << 20)) >> 21; |
493
|
1564
|
|
|
|
|
|
s15 += carry14; |
494
|
1564
|
|
|
|
|
|
s14 -= carry14 << 21; |
495
|
1564
|
|
|
|
|
|
carry16 = (s16 + (1 << 20)) >> 21; |
496
|
1564
|
|
|
|
|
|
s17 += carry16; |
497
|
1564
|
|
|
|
|
|
s16 -= carry16 << 21; |
498
|
1564
|
|
|
|
|
|
carry18 = (s18 + (1 << 20)) >> 21; |
499
|
1564
|
|
|
|
|
|
s19 += carry18; |
500
|
1564
|
|
|
|
|
|
s18 -= carry18 << 21; |
501
|
1564
|
|
|
|
|
|
carry20 = (s20 + (1 << 20)) >> 21; |
502
|
1564
|
|
|
|
|
|
s21 += carry20; |
503
|
1564
|
|
|
|
|
|
s20 -= carry20 << 21; |
504
|
1564
|
|
|
|
|
|
carry22 = (s22 + (1 << 20)) >> 21; |
505
|
1564
|
|
|
|
|
|
s23 += carry22; |
506
|
1564
|
|
|
|
|
|
s22 -= carry22 << 21; |
507
|
1564
|
|
|
|
|
|
carry1 = (s1 + (1 << 20)) >> 21; |
508
|
1564
|
|
|
|
|
|
s2 += carry1; |
509
|
1564
|
|
|
|
|
|
s1 -= carry1 << 21; |
510
|
1564
|
|
|
|
|
|
carry3 = (s3 + (1 << 20)) >> 21; |
511
|
1564
|
|
|
|
|
|
s4 += carry3; |
512
|
1564
|
|
|
|
|
|
s3 -= carry3 << 21; |
513
|
1564
|
|
|
|
|
|
carry5 = (s5 + (1 << 20)) >> 21; |
514
|
1564
|
|
|
|
|
|
s6 += carry5; |
515
|
1564
|
|
|
|
|
|
s5 -= carry5 << 21; |
516
|
1564
|
|
|
|
|
|
carry7 = (s7 + (1 << 20)) >> 21; |
517
|
1564
|
|
|
|
|
|
s8 += carry7; |
518
|
1564
|
|
|
|
|
|
s7 -= carry7 << 21; |
519
|
1564
|
|
|
|
|
|
carry9 = (s9 + (1 << 20)) >> 21; |
520
|
1564
|
|
|
|
|
|
s10 += carry9; |
521
|
1564
|
|
|
|
|
|
s9 -= carry9 << 21; |
522
|
1564
|
|
|
|
|
|
carry11 = (s11 + (1 << 20)) >> 21; |
523
|
1564
|
|
|
|
|
|
s12 += carry11; |
524
|
1564
|
|
|
|
|
|
s11 -= carry11 << 21; |
525
|
1564
|
|
|
|
|
|
carry13 = (s13 + (1 << 20)) >> 21; |
526
|
1564
|
|
|
|
|
|
s14 += carry13; |
527
|
1564
|
|
|
|
|
|
s13 -= carry13 << 21; |
528
|
1564
|
|
|
|
|
|
carry15 = (s15 + (1 << 20)) >> 21; |
529
|
1564
|
|
|
|
|
|
s16 += carry15; |
530
|
1564
|
|
|
|
|
|
s15 -= carry15 << 21; |
531
|
1564
|
|
|
|
|
|
carry17 = (s17 + (1 << 20)) >> 21; |
532
|
1564
|
|
|
|
|
|
s18 += carry17; |
533
|
1564
|
|
|
|
|
|
s17 -= carry17 << 21; |
534
|
1564
|
|
|
|
|
|
carry19 = (s19 + (1 << 20)) >> 21; |
535
|
1564
|
|
|
|
|
|
s20 += carry19; |
536
|
1564
|
|
|
|
|
|
s19 -= carry19 << 21; |
537
|
1564
|
|
|
|
|
|
carry21 = (s21 + (1 << 20)) >> 21; |
538
|
1564
|
|
|
|
|
|
s22 += carry21; |
539
|
1564
|
|
|
|
|
|
s21 -= carry21 << 21; |
540
|
1564
|
|
|
|
|
|
s11 += s23 * 666643; |
541
|
1564
|
|
|
|
|
|
s12 += s23 * 470296; |
542
|
1564
|
|
|
|
|
|
s13 += s23 * 654183; |
543
|
1564
|
|
|
|
|
|
s14 -= s23 * 997805; |
544
|
1564
|
|
|
|
|
|
s15 += s23 * 136657; |
545
|
1564
|
|
|
|
|
|
s16 -= s23 * 683901; |
546
|
1564
|
|
|
|
|
|
s23 = 0; |
547
|
1564
|
|
|
|
|
|
s10 += s22 * 666643; |
548
|
1564
|
|
|
|
|
|
s11 += s22 * 470296; |
549
|
1564
|
|
|
|
|
|
s12 += s22 * 654183; |
550
|
1564
|
|
|
|
|
|
s13 -= s22 * 997805; |
551
|
1564
|
|
|
|
|
|
s14 += s22 * 136657; |
552
|
1564
|
|
|
|
|
|
s15 -= s22 * 683901; |
553
|
1564
|
|
|
|
|
|
s22 = 0; |
554
|
1564
|
|
|
|
|
|
s9 += s21 * 666643; |
555
|
1564
|
|
|
|
|
|
s10 += s21 * 470296; |
556
|
1564
|
|
|
|
|
|
s11 += s21 * 654183; |
557
|
1564
|
|
|
|
|
|
s12 -= s21 * 997805; |
558
|
1564
|
|
|
|
|
|
s13 += s21 * 136657; |
559
|
1564
|
|
|
|
|
|
s14 -= s21 * 683901; |
560
|
1564
|
|
|
|
|
|
s21 = 0; |
561
|
1564
|
|
|
|
|
|
s8 += s20 * 666643; |
562
|
1564
|
|
|
|
|
|
s9 += s20 * 470296; |
563
|
1564
|
|
|
|
|
|
s10 += s20 * 654183; |
564
|
1564
|
|
|
|
|
|
s11 -= s20 * 997805; |
565
|
1564
|
|
|
|
|
|
s12 += s20 * 136657; |
566
|
1564
|
|
|
|
|
|
s13 -= s20 * 683901; |
567
|
1564
|
|
|
|
|
|
s20 = 0; |
568
|
1564
|
|
|
|
|
|
s7 += s19 * 666643; |
569
|
1564
|
|
|
|
|
|
s8 += s19 * 470296; |
570
|
1564
|
|
|
|
|
|
s9 += s19 * 654183; |
571
|
1564
|
|
|
|
|
|
s10 -= s19 * 997805; |
572
|
1564
|
|
|
|
|
|
s11 += s19 * 136657; |
573
|
1564
|
|
|
|
|
|
s12 -= s19 * 683901; |
574
|
1564
|
|
|
|
|
|
s19 = 0; |
575
|
1564
|
|
|
|
|
|
s6 += s18 * 666643; |
576
|
1564
|
|
|
|
|
|
s7 += s18 * 470296; |
577
|
1564
|
|
|
|
|
|
s8 += s18 * 654183; |
578
|
1564
|
|
|
|
|
|
s9 -= s18 * 997805; |
579
|
1564
|
|
|
|
|
|
s10 += s18 * 136657; |
580
|
1564
|
|
|
|
|
|
s11 -= s18 * 683901; |
581
|
1564
|
|
|
|
|
|
s18 = 0; |
582
|
1564
|
|
|
|
|
|
carry6 = (s6 + (1 << 20)) >> 21; |
583
|
1564
|
|
|
|
|
|
s7 += carry6; |
584
|
1564
|
|
|
|
|
|
s6 -= carry6 << 21; |
585
|
1564
|
|
|
|
|
|
carry8 = (s8 + (1 << 20)) >> 21; |
586
|
1564
|
|
|
|
|
|
s9 += carry8; |
587
|
1564
|
|
|
|
|
|
s8 -= carry8 << 21; |
588
|
1564
|
|
|
|
|
|
carry10 = (s10 + (1 << 20)) >> 21; |
589
|
1564
|
|
|
|
|
|
s11 += carry10; |
590
|
1564
|
|
|
|
|
|
s10 -= carry10 << 21; |
591
|
1564
|
|
|
|
|
|
carry12 = (s12 + (1 << 20)) >> 21; |
592
|
1564
|
|
|
|
|
|
s13 += carry12; |
593
|
1564
|
|
|
|
|
|
s12 -= carry12 << 21; |
594
|
1564
|
|
|
|
|
|
carry14 = (s14 + (1 << 20)) >> 21; |
595
|
1564
|
|
|
|
|
|
s15 += carry14; |
596
|
1564
|
|
|
|
|
|
s14 -= carry14 << 21; |
597
|
1564
|
|
|
|
|
|
carry16 = (s16 + (1 << 20)) >> 21; |
598
|
1564
|
|
|
|
|
|
s17 += carry16; |
599
|
1564
|
|
|
|
|
|
s16 -= carry16 << 21; |
600
|
1564
|
|
|
|
|
|
carry7 = (s7 + (1 << 20)) >> 21; |
601
|
1564
|
|
|
|
|
|
s8 += carry7; |
602
|
1564
|
|
|
|
|
|
s7 -= carry7 << 21; |
603
|
1564
|
|
|
|
|
|
carry9 = (s9 + (1 << 20)) >> 21; |
604
|
1564
|
|
|
|
|
|
s10 += carry9; |
605
|
1564
|
|
|
|
|
|
s9 -= carry9 << 21; |
606
|
1564
|
|
|
|
|
|
carry11 = (s11 + (1 << 20)) >> 21; |
607
|
1564
|
|
|
|
|
|
s12 += carry11; |
608
|
1564
|
|
|
|
|
|
s11 -= carry11 << 21; |
609
|
1564
|
|
|
|
|
|
carry13 = (s13 + (1 << 20)) >> 21; |
610
|
1564
|
|
|
|
|
|
s14 += carry13; |
611
|
1564
|
|
|
|
|
|
s13 -= carry13 << 21; |
612
|
1564
|
|
|
|
|
|
carry15 = (s15 + (1 << 20)) >> 21; |
613
|
1564
|
|
|
|
|
|
s16 += carry15; |
614
|
1564
|
|
|
|
|
|
s15 -= carry15 << 21; |
615
|
1564
|
|
|
|
|
|
s5 += s17 * 666643; |
616
|
1564
|
|
|
|
|
|
s6 += s17 * 470296; |
617
|
1564
|
|
|
|
|
|
s7 += s17 * 654183; |
618
|
1564
|
|
|
|
|
|
s8 -= s17 * 997805; |
619
|
1564
|
|
|
|
|
|
s9 += s17 * 136657; |
620
|
1564
|
|
|
|
|
|
s10 -= s17 * 683901; |
621
|
1564
|
|
|
|
|
|
s17 = 0; |
622
|
1564
|
|
|
|
|
|
s4 += s16 * 666643; |
623
|
1564
|
|
|
|
|
|
s5 += s16 * 470296; |
624
|
1564
|
|
|
|
|
|
s6 += s16 * 654183; |
625
|
1564
|
|
|
|
|
|
s7 -= s16 * 997805; |
626
|
1564
|
|
|
|
|
|
s8 += s16 * 136657; |
627
|
1564
|
|
|
|
|
|
s9 -= s16 * 683901; |
628
|
1564
|
|
|
|
|
|
s16 = 0; |
629
|
1564
|
|
|
|
|
|
s3 += s15 * 666643; |
630
|
1564
|
|
|
|
|
|
s4 += s15 * 470296; |
631
|
1564
|
|
|
|
|
|
s5 += s15 * 654183; |
632
|
1564
|
|
|
|
|
|
s6 -= s15 * 997805; |
633
|
1564
|
|
|
|
|
|
s7 += s15 * 136657; |
634
|
1564
|
|
|
|
|
|
s8 -= s15 * 683901; |
635
|
1564
|
|
|
|
|
|
s15 = 0; |
636
|
1564
|
|
|
|
|
|
s2 += s14 * 666643; |
637
|
1564
|
|
|
|
|
|
s3 += s14 * 470296; |
638
|
1564
|
|
|
|
|
|
s4 += s14 * 654183; |
639
|
1564
|
|
|
|
|
|
s5 -= s14 * 997805; |
640
|
1564
|
|
|
|
|
|
s6 += s14 * 136657; |
641
|
1564
|
|
|
|
|
|
s7 -= s14 * 683901; |
642
|
1564
|
|
|
|
|
|
s14 = 0; |
643
|
1564
|
|
|
|
|
|
s1 += s13 * 666643; |
644
|
1564
|
|
|
|
|
|
s2 += s13 * 470296; |
645
|
1564
|
|
|
|
|
|
s3 += s13 * 654183; |
646
|
1564
|
|
|
|
|
|
s4 -= s13 * 997805; |
647
|
1564
|
|
|
|
|
|
s5 += s13 * 136657; |
648
|
1564
|
|
|
|
|
|
s6 -= s13 * 683901; |
649
|
1564
|
|
|
|
|
|
s13 = 0; |
650
|
1564
|
|
|
|
|
|
s0 += s12 * 666643; |
651
|
1564
|
|
|
|
|
|
s1 += s12 * 470296; |
652
|
1564
|
|
|
|
|
|
s2 += s12 * 654183; |
653
|
1564
|
|
|
|
|
|
s3 -= s12 * 997805; |
654
|
1564
|
|
|
|
|
|
s4 += s12 * 136657; |
655
|
1564
|
|
|
|
|
|
s5 -= s12 * 683901; |
656
|
1564
|
|
|
|
|
|
s12 = 0; |
657
|
1564
|
|
|
|
|
|
carry0 = (s0 + (1 << 20)) >> 21; |
658
|
1564
|
|
|
|
|
|
s1 += carry0; |
659
|
1564
|
|
|
|
|
|
s0 -= carry0 << 21; |
660
|
1564
|
|
|
|
|
|
carry2 = (s2 + (1 << 20)) >> 21; |
661
|
1564
|
|
|
|
|
|
s3 += carry2; |
662
|
1564
|
|
|
|
|
|
s2 -= carry2 << 21; |
663
|
1564
|
|
|
|
|
|
carry4 = (s4 + (1 << 20)) >> 21; |
664
|
1564
|
|
|
|
|
|
s5 += carry4; |
665
|
1564
|
|
|
|
|
|
s4 -= carry4 << 21; |
666
|
1564
|
|
|
|
|
|
carry6 = (s6 + (1 << 20)) >> 21; |
667
|
1564
|
|
|
|
|
|
s7 += carry6; |
668
|
1564
|
|
|
|
|
|
s6 -= carry6 << 21; |
669
|
1564
|
|
|
|
|
|
carry8 = (s8 + (1 << 20)) >> 21; |
670
|
1564
|
|
|
|
|
|
s9 += carry8; |
671
|
1564
|
|
|
|
|
|
s8 -= carry8 << 21; |
672
|
1564
|
|
|
|
|
|
carry10 = (s10 + (1 << 20)) >> 21; |
673
|
1564
|
|
|
|
|
|
s11 += carry10; |
674
|
1564
|
|
|
|
|
|
s10 -= carry10 << 21; |
675
|
1564
|
|
|
|
|
|
carry1 = (s1 + (1 << 20)) >> 21; |
676
|
1564
|
|
|
|
|
|
s2 += carry1; |
677
|
1564
|
|
|
|
|
|
s1 -= carry1 << 21; |
678
|
1564
|
|
|
|
|
|
carry3 = (s3 + (1 << 20)) >> 21; |
679
|
1564
|
|
|
|
|
|
s4 += carry3; |
680
|
1564
|
|
|
|
|
|
s3 -= carry3 << 21; |
681
|
1564
|
|
|
|
|
|
carry5 = (s5 + (1 << 20)) >> 21; |
682
|
1564
|
|
|
|
|
|
s6 += carry5; |
683
|
1564
|
|
|
|
|
|
s5 -= carry5 << 21; |
684
|
1564
|
|
|
|
|
|
carry7 = (s7 + (1 << 20)) >> 21; |
685
|
1564
|
|
|
|
|
|
s8 += carry7; |
686
|
1564
|
|
|
|
|
|
s7 -= carry7 << 21; |
687
|
1564
|
|
|
|
|
|
carry9 = (s9 + (1 << 20)) >> 21; |
688
|
1564
|
|
|
|
|
|
s10 += carry9; |
689
|
1564
|
|
|
|
|
|
s9 -= carry9 << 21; |
690
|
1564
|
|
|
|
|
|
carry11 = (s11 + (1 << 20)) >> 21; |
691
|
1564
|
|
|
|
|
|
s12 += carry11; |
692
|
1564
|
|
|
|
|
|
s11 -= carry11 << 21; |
693
|
1564
|
|
|
|
|
|
s0 += s12 * 666643; |
694
|
1564
|
|
|
|
|
|
s1 += s12 * 470296; |
695
|
1564
|
|
|
|
|
|
s2 += s12 * 654183; |
696
|
1564
|
|
|
|
|
|
s3 -= s12 * 997805; |
697
|
1564
|
|
|
|
|
|
s4 += s12 * 136657; |
698
|
1564
|
|
|
|
|
|
s5 -= s12 * 683901; |
699
|
1564
|
|
|
|
|
|
s12 = 0; |
700
|
1564
|
|
|
|
|
|
carry0 = s0 >> 21; |
701
|
1564
|
|
|
|
|
|
s1 += carry0; |
702
|
1564
|
|
|
|
|
|
s0 -= carry0 << 21; |
703
|
1564
|
|
|
|
|
|
carry1 = s1 >> 21; |
704
|
1564
|
|
|
|
|
|
s2 += carry1; |
705
|
1564
|
|
|
|
|
|
s1 -= carry1 << 21; |
706
|
1564
|
|
|
|
|
|
carry2 = s2 >> 21; |
707
|
1564
|
|
|
|
|
|
s3 += carry2; |
708
|
1564
|
|
|
|
|
|
s2 -= carry2 << 21; |
709
|
1564
|
|
|
|
|
|
carry3 = s3 >> 21; |
710
|
1564
|
|
|
|
|
|
s4 += carry3; |
711
|
1564
|
|
|
|
|
|
s3 -= carry3 << 21; |
712
|
1564
|
|
|
|
|
|
carry4 = s4 >> 21; |
713
|
1564
|
|
|
|
|
|
s5 += carry4; |
714
|
1564
|
|
|
|
|
|
s4 -= carry4 << 21; |
715
|
1564
|
|
|
|
|
|
carry5 = s5 >> 21; |
716
|
1564
|
|
|
|
|
|
s6 += carry5; |
717
|
1564
|
|
|
|
|
|
s5 -= carry5 << 21; |
718
|
1564
|
|
|
|
|
|
carry6 = s6 >> 21; |
719
|
1564
|
|
|
|
|
|
s7 += carry6; |
720
|
1564
|
|
|
|
|
|
s6 -= carry6 << 21; |
721
|
1564
|
|
|
|
|
|
carry7 = s7 >> 21; |
722
|
1564
|
|
|
|
|
|
s8 += carry7; |
723
|
1564
|
|
|
|
|
|
s7 -= carry7 << 21; |
724
|
1564
|
|
|
|
|
|
carry8 = s8 >> 21; |
725
|
1564
|
|
|
|
|
|
s9 += carry8; |
726
|
1564
|
|
|
|
|
|
s8 -= carry8 << 21; |
727
|
1564
|
|
|
|
|
|
carry9 = s9 >> 21; |
728
|
1564
|
|
|
|
|
|
s10 += carry9; |
729
|
1564
|
|
|
|
|
|
s9 -= carry9 << 21; |
730
|
1564
|
|
|
|
|
|
carry10 = s10 >> 21; |
731
|
1564
|
|
|
|
|
|
s11 += carry10; |
732
|
1564
|
|
|
|
|
|
s10 -= carry10 << 21; |
733
|
1564
|
|
|
|
|
|
carry11 = s11 >> 21; |
734
|
1564
|
|
|
|
|
|
s12 += carry11; |
735
|
1564
|
|
|
|
|
|
s11 -= carry11 << 21; |
736
|
1564
|
|
|
|
|
|
s0 += s12 * 666643; |
737
|
1564
|
|
|
|
|
|
s1 += s12 * 470296; |
738
|
1564
|
|
|
|
|
|
s2 += s12 * 654183; |
739
|
1564
|
|
|
|
|
|
s3 -= s12 * 997805; |
740
|
1564
|
|
|
|
|
|
s4 += s12 * 136657; |
741
|
1564
|
|
|
|
|
|
s5 -= s12 * 683901; |
742
|
1564
|
|
|
|
|
|
s12 = 0; |
743
|
1564
|
|
|
|
|
|
carry0 = s0 >> 21; |
744
|
1564
|
|
|
|
|
|
s1 += carry0; |
745
|
1564
|
|
|
|
|
|
s0 -= carry0 << 21; |
746
|
1564
|
|
|
|
|
|
carry1 = s1 >> 21; |
747
|
1564
|
|
|
|
|
|
s2 += carry1; |
748
|
1564
|
|
|
|
|
|
s1 -= carry1 << 21; |
749
|
1564
|
|
|
|
|
|
carry2 = s2 >> 21; |
750
|
1564
|
|
|
|
|
|
s3 += carry2; |
751
|
1564
|
|
|
|
|
|
s2 -= carry2 << 21; |
752
|
1564
|
|
|
|
|
|
carry3 = s3 >> 21; |
753
|
1564
|
|
|
|
|
|
s4 += carry3; |
754
|
1564
|
|
|
|
|
|
s3 -= carry3 << 21; |
755
|
1564
|
|
|
|
|
|
carry4 = s4 >> 21; |
756
|
1564
|
|
|
|
|
|
s5 += carry4; |
757
|
1564
|
|
|
|
|
|
s4 -= carry4 << 21; |
758
|
1564
|
|
|
|
|
|
carry5 = s5 >> 21; |
759
|
1564
|
|
|
|
|
|
s6 += carry5; |
760
|
1564
|
|
|
|
|
|
s5 -= carry5 << 21; |
761
|
1564
|
|
|
|
|
|
carry6 = s6 >> 21; |
762
|
1564
|
|
|
|
|
|
s7 += carry6; |
763
|
1564
|
|
|
|
|
|
s6 -= carry6 << 21; |
764
|
1564
|
|
|
|
|
|
carry7 = s7 >> 21; |
765
|
1564
|
|
|
|
|
|
s8 += carry7; |
766
|
1564
|
|
|
|
|
|
s7 -= carry7 << 21; |
767
|
1564
|
|
|
|
|
|
carry8 = s8 >> 21; |
768
|
1564
|
|
|
|
|
|
s9 += carry8; |
769
|
1564
|
|
|
|
|
|
s8 -= carry8 << 21; |
770
|
1564
|
|
|
|
|
|
carry9 = s9 >> 21; |
771
|
1564
|
|
|
|
|
|
s10 += carry9; |
772
|
1564
|
|
|
|
|
|
s9 -= carry9 << 21; |
773
|
1564
|
|
|
|
|
|
carry10 = s10 >> 21; |
774
|
1564
|
|
|
|
|
|
s11 += carry10; |
775
|
1564
|
|
|
|
|
|
s10 -= carry10 << 21; |
776
|
|
|
|
|
|
|
|
777
|
1564
|
|
|
|
|
|
s[0] = (unsigned char) (s0 >> 0); |
778
|
1564
|
|
|
|
|
|
s[1] = (unsigned char) (s0 >> 8); |
779
|
1564
|
|
|
|
|
|
s[2] = (unsigned char) ((s0 >> 16) | (s1 << 5)); |
780
|
1564
|
|
|
|
|
|
s[3] = (unsigned char) (s1 >> 3); |
781
|
1564
|
|
|
|
|
|
s[4] = (unsigned char) (s1 >> 11); |
782
|
1564
|
|
|
|
|
|
s[5] = (unsigned char) ((s1 >> 19) | (s2 << 2)); |
783
|
1564
|
|
|
|
|
|
s[6] = (unsigned char) (s2 >> 6); |
784
|
1564
|
|
|
|
|
|
s[7] = (unsigned char) ((s2 >> 14) | (s3 << 7)); |
785
|
1564
|
|
|
|
|
|
s[8] = (unsigned char) (s3 >> 1); |
786
|
1564
|
|
|
|
|
|
s[9] = (unsigned char) (s3 >> 9); |
787
|
1564
|
|
|
|
|
|
s[10] = (unsigned char) ((s3 >> 17) | (s4 << 4)); |
788
|
1564
|
|
|
|
|
|
s[11] = (unsigned char) (s4 >> 4); |
789
|
1564
|
|
|
|
|
|
s[12] = (unsigned char) (s4 >> 12); |
790
|
1564
|
|
|
|
|
|
s[13] = (unsigned char) ((s4 >> 20) | (s5 << 1)); |
791
|
1564
|
|
|
|
|
|
s[14] = (unsigned char) (s5 >> 7); |
792
|
1564
|
|
|
|
|
|
s[15] = (unsigned char) ((s5 >> 15) | (s6 << 6)); |
793
|
1564
|
|
|
|
|
|
s[16] = (unsigned char) (s6 >> 2); |
794
|
1564
|
|
|
|
|
|
s[17] = (unsigned char) (s6 >> 10); |
795
|
1564
|
|
|
|
|
|
s[18] = (unsigned char) ((s6 >> 18) | (s7 << 3)); |
796
|
1564
|
|
|
|
|
|
s[19] = (unsigned char) (s7 >> 5); |
797
|
1564
|
|
|
|
|
|
s[20] = (unsigned char) (s7 >> 13); |
798
|
1564
|
|
|
|
|
|
s[21] = (unsigned char) (s8 >> 0); |
799
|
1564
|
|
|
|
|
|
s[22] = (unsigned char) (s8 >> 8); |
800
|
1564
|
|
|
|
|
|
s[23] = (unsigned char) ((s8 >> 16) | (s9 << 5)); |
801
|
1564
|
|
|
|
|
|
s[24] = (unsigned char) (s9 >> 3); |
802
|
1564
|
|
|
|
|
|
s[25] = (unsigned char) (s9 >> 11); |
803
|
1564
|
|
|
|
|
|
s[26] = (unsigned char) ((s9 >> 19) | (s10 << 2)); |
804
|
1564
|
|
|
|
|
|
s[27] = (unsigned char) (s10 >> 6); |
805
|
1564
|
|
|
|
|
|
s[28] = (unsigned char) ((s10 >> 14) | (s11 << 7)); |
806
|
1564
|
|
|
|
|
|
s[29] = (unsigned char) (s11 >> 1); |
807
|
1564
|
|
|
|
|
|
s[30] = (unsigned char) (s11 >> 9); |
808
|
1564
|
|
|
|
|
|
s[31] = (unsigned char) (s11 >> 17); |
809
|
1564
|
|
|
|
|
|
} |