u8.h 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357
  1. #define VEC8_ROT(A, IMM) \
  2. _mm256_or_si256(_mm256_slli_epi32(A, IMM), _mm256_srli_epi32(A, (32 - IMM)))
  3. /* implements a vector quarter round by-the-book (naive!) */
  4. #define VEC8_QUARTERROUND_NAIVE(A, B, C, D) \
  5. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  6. t_##A = _mm256_xor_si256(x_##D, x_##A); \
  7. x_##D = VEC8_ROT(t_##A, 16); \
  8. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  9. t_##C = _mm256_xor_si256(x_##B, x_##C); \
  10. x_##B = VEC8_ROT(t_##C, 12); \
  11. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  12. t_##A = _mm256_xor_si256(x_##D, x_##A); \
  13. x_##D = VEC8_ROT(t_##A, 8); \
  14. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  15. t_##C = _mm256_xor_si256(x_##B, x_##C); \
  16. x_##B = VEC8_ROT(t_##C, 7)
  17. /* same, but replace 2 of the shift/shift/or "rotation" by byte shuffles (8 &
  18. * 16) (better) */
  19. #define VEC8_QUARTERROUND_SHUFFLE(A, B, C, D) \
  20. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  21. t_##A = _mm256_xor_si256(x_##D, x_##A); \
  22. x_##D = _mm256_shuffle_epi8(t_##A, rot16); \
  23. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  24. t_##C = _mm256_xor_si256(x_##B, x_##C); \
  25. x_##B = VEC8_ROT(t_##C, 12); \
  26. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  27. t_##A = _mm256_xor_si256(x_##D, x_##A); \
  28. x_##D = _mm256_shuffle_epi8(t_##A, rot8); \
  29. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  30. t_##C = _mm256_xor_si256(x_##B, x_##C); \
  31. x_##B = VEC8_ROT(t_##C, 7)
  32. /* same, but replace 2 of the shift/shift/or "rotation" by byte & word shuffles
  33. * (8 & 16) (not as good as previous) */
  34. #define VEC8_QUARTERROUND_SHUFFLE2(A, B, C, D) \
  35. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  36. t_##A = _mm256_xor_si256(x_##D, x_##A); \
  37. x_##D = _mm256_shufflehi_epi16(_mm256_shufflelo_epi16(t_##A, 0xb1), 0xb1); \
  38. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  39. t_##C = _mm256_xor_si256(x_##B, x_##C); \
  40. x_##B = VEC8_ROT(t_##C, 12); \
  41. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  42. t_##A = _mm256_xor_si256(x_##D, x_##A); \
  43. x_##D = _mm256_shuffle_epi8(t_##A, rot8); \
  44. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  45. t_##C = _mm256_xor_si256(x_##B, x_##C); \
  46. x_##B = VEC8_ROT(t_##C, 7)
  47. #define VEC8_QUARTERROUND(A, B, C, D) VEC8_QUARTERROUND_SHUFFLE(A, B, C, D)
  48. #define VEC8_LINE1(A, B, C, D) \
  49. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  50. x_##D = _mm256_shuffle_epi8(_mm256_xor_si256(x_##D, x_##A), rot16)
  51. #define VEC8_LINE2(A, B, C, D) \
  52. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  53. x_##B = VEC8_ROT(_mm256_xor_si256(x_##B, x_##C), 12)
  54. #define VEC8_LINE3(A, B, C, D) \
  55. x_##A = _mm256_add_epi32(x_##A, x_##B); \
  56. x_##D = _mm256_shuffle_epi8(_mm256_xor_si256(x_##D, x_##A), rot8)
  57. #define VEC8_LINE4(A, B, C, D) \
  58. x_##C = _mm256_add_epi32(x_##C, x_##D); \
  59. x_##B = VEC8_ROT(_mm256_xor_si256(x_##B, x_##C), 7)
  60. #define VEC8_ROUND_SEQ(A1, B1, C1, D1, A2, B2, C2, D2, A3, B3, C3, D3, A4, B4, \
  61. C4, D4) \
  62. VEC8_LINE1(A1, B1, C1, D1); \
  63. VEC8_LINE1(A2, B2, C2, D2); \
  64. VEC8_LINE1(A3, B3, C3, D3); \
  65. VEC8_LINE1(A4, B4, C4, D4); \
  66. VEC8_LINE2(A1, B1, C1, D1); \
  67. VEC8_LINE2(A2, B2, C2, D2); \
  68. VEC8_LINE2(A3, B3, C3, D3); \
  69. VEC8_LINE2(A4, B4, C4, D4); \
  70. VEC8_LINE3(A1, B1, C1, D1); \
  71. VEC8_LINE3(A2, B2, C2, D2); \
  72. VEC8_LINE3(A3, B3, C3, D3); \
  73. VEC8_LINE3(A4, B4, C4, D4); \
  74. VEC8_LINE4(A1, B1, C1, D1); \
  75. VEC8_LINE4(A2, B2, C2, D2); \
  76. VEC8_LINE4(A3, B3, C3, D3); \
  77. VEC8_LINE4(A4, B4, C4, D4)
  78. #define VEC8_ROUND_HALF(A1, B1, C1, D1, A2, B2, C2, D2, A3, B3, C3, D3, A4, \
  79. B4, C4, D4) \
  80. VEC8_LINE1(A1, B1, C1, D1); \
  81. VEC8_LINE1(A2, B2, C2, D2); \
  82. VEC8_LINE2(A1, B1, C1, D1); \
  83. VEC8_LINE2(A2, B2, C2, D2); \
  84. VEC8_LINE3(A1, B1, C1, D1); \
  85. VEC8_LINE3(A2, B2, C2, D2); \
  86. VEC8_LINE4(A1, B1, C1, D1); \
  87. VEC8_LINE4(A2, B2, C2, D2); \
  88. VEC8_LINE1(A3, B3, C3, D3); \
  89. VEC8_LINE1(A4, B4, C4, D4); \
  90. VEC8_LINE2(A3, B3, C3, D3); \
  91. VEC8_LINE2(A4, B4, C4, D4); \
  92. VEC8_LINE3(A3, B3, C3, D3); \
  93. VEC8_LINE3(A4, B4, C4, D4); \
  94. VEC8_LINE4(A3, B3, C3, D3); \
  95. VEC8_LINE4(A4, B4, C4, D4)
  96. #define VEC8_ROUND_HALFANDHALF(A1, B1, C1, D1, A2, B2, C2, D2, A3, B3, C3, D3, \
  97. A4, B4, C4, D4) \
  98. VEC8_LINE1(A1, B1, C1, D1); \
  99. VEC8_LINE1(A2, B2, C2, D2); \
  100. VEC8_LINE2(A1, B1, C1, D1); \
  101. VEC8_LINE2(A2, B2, C2, D2); \
  102. VEC8_LINE1(A3, B3, C3, D3); \
  103. VEC8_LINE1(A4, B4, C4, D4); \
  104. VEC8_LINE2(A3, B3, C3, D3); \
  105. VEC8_LINE2(A4, B4, C4, D4); \
  106. VEC8_LINE3(A1, B1, C1, D1); \
  107. VEC8_LINE3(A2, B2, C2, D2); \
  108. VEC8_LINE4(A1, B1, C1, D1); \
  109. VEC8_LINE4(A2, B2, C2, D2); \
  110. VEC8_LINE3(A3, B3, C3, D3); \
  111. VEC8_LINE3(A4, B4, C4, D4); \
  112. VEC8_LINE4(A3, B3, C3, D3); \
  113. VEC8_LINE4(A4, B4, C4, D4)
  114. #define VEC8_ROUND(A1, B1, C1, D1, A2, B2, C2, D2, A3, B3, C3, D3, A4, B4, C4, \
  115. D4) \
  116. VEC8_ROUND_SEQ(A1, B1, C1, D1, A2, B2, C2, D2, A3, B3, C3, D3, A4, B4, C4, \
  117. D4)
  118. if (bytes >= 512) {
  119. /* constant for shuffling bytes (replacing multiple-of-8 rotates) */
  120. __m256i rot16 =
  121. _mm256_set_epi8(13, 12, 15, 14, 9, 8, 11, 10, 5, 4, 7, 6, 1, 0, 3, 2,
  122. 13, 12, 15, 14, 9, 8, 11, 10, 5, 4, 7, 6, 1, 0, 3, 2);
  123. __m256i rot8 =
  124. _mm256_set_epi8(14, 13, 12, 15, 10, 9, 8, 11, 6, 5, 4, 7, 2, 1, 0, 3,
  125. 14, 13, 12, 15, 10, 9, 8, 11, 6, 5, 4, 7, 2, 1, 0, 3);
  126. uint32_t in12, in13;
  127. /* the naive way seems as fast (if not a bit faster) than the vector way */
  128. __m256i x_0 = _mm256_set1_epi32(x[0]);
  129. __m256i x_1 = _mm256_set1_epi32(x[1]);
  130. __m256i x_2 = _mm256_set1_epi32(x[2]);
  131. __m256i x_3 = _mm256_set1_epi32(x[3]);
  132. __m256i x_4 = _mm256_set1_epi32(x[4]);
  133. __m256i x_5 = _mm256_set1_epi32(x[5]);
  134. __m256i x_6 = _mm256_set1_epi32(x[6]);
  135. __m256i x_7 = _mm256_set1_epi32(x[7]);
  136. __m256i x_8 = _mm256_set1_epi32(x[8]);
  137. __m256i x_9 = _mm256_set1_epi32(x[9]);
  138. __m256i x_10 = _mm256_set1_epi32(x[10]);
  139. __m256i x_11 = _mm256_set1_epi32(x[11]);
  140. __m256i x_12;
  141. __m256i x_13;
  142. __m256i x_14 = _mm256_set1_epi32(x[14]);
  143. __m256i x_15 = _mm256_set1_epi32(x[15]);
  144. __m256i orig0 = x_0;
  145. __m256i orig1 = x_1;
  146. __m256i orig2 = x_2;
  147. __m256i orig3 = x_3;
  148. __m256i orig4 = x_4;
  149. __m256i orig5 = x_5;
  150. __m256i orig6 = x_6;
  151. __m256i orig7 = x_7;
  152. __m256i orig8 = x_8;
  153. __m256i orig9 = x_9;
  154. __m256i orig10 = x_10;
  155. __m256i orig11 = x_11;
  156. __m256i orig12;
  157. __m256i orig13;
  158. __m256i orig14 = x_14;
  159. __m256i orig15 = x_15;
  160. __m256i t_0, t_1, t_2, t_3, t_4, t_5, t_6, t_7, t_8, t_9, t_10, t_11, t_12,
  161. t_13, t_14, t_15;
  162. while (bytes >= 512) {
  163. const __m256i addv12 = _mm256_set_epi64x(3, 2, 1, 0);
  164. const __m256i addv13 = _mm256_set_epi64x(7, 6, 5, 4);
  165. const __m256i permute = _mm256_set_epi32(7, 6, 3, 2, 5, 4, 1, 0);
  166. __m256i t12, t13;
  167. uint64_t in1213;
  168. int i;
  169. x_0 = orig0;
  170. x_1 = orig1;
  171. x_2 = orig2;
  172. x_3 = orig3;
  173. x_4 = orig4;
  174. x_5 = orig5;
  175. x_6 = orig6;
  176. x_7 = orig7;
  177. x_8 = orig8;
  178. x_9 = orig9;
  179. x_10 = orig10;
  180. x_11 = orig11;
  181. x_14 = orig14;
  182. x_15 = orig15;
  183. in12 = x[12];
  184. in13 = x[13];
  185. in1213 = ((uint64_t) in12) | (((uint64_t) in13) << 32);
  186. x_12 = x_13 = _mm256_broadcastq_epi64(_mm_cvtsi64_si128(in1213));
  187. t12 = _mm256_add_epi64(addv12, x_12);
  188. t13 = _mm256_add_epi64(addv13, x_13);
  189. x_12 = _mm256_unpacklo_epi32(t12, t13);
  190. x_13 = _mm256_unpackhi_epi32(t12, t13);
  191. t12 = _mm256_unpacklo_epi32(x_12, x_13);
  192. t13 = _mm256_unpackhi_epi32(x_12, x_13);
  193. /* required because unpack* are intra-lane */
  194. x_12 = _mm256_permutevar8x32_epi32(t12, permute);
  195. x_13 = _mm256_permutevar8x32_epi32(t13, permute);
  196. orig12 = x_12;
  197. orig13 = x_13;
  198. in1213 += 8;
  199. x[12] = in1213 & 0xFFFFFFFF;
  200. x[13] = (in1213 >> 32) & 0xFFFFFFFF;
  201. for (i = 0; i < ROUNDS; i += 2) {
  202. VEC8_ROUND(0, 4, 8, 12, 1, 5, 9, 13, 2, 6, 10, 14, 3, 7, 11, 15);
  203. VEC8_ROUND(0, 5, 10, 15, 1, 6, 11, 12, 2, 7, 8, 13, 3, 4, 9, 14);
  204. }
  205. #define ONEQUAD_TRANSPOSE(A, B, C, D) \
  206. { \
  207. __m128i t0, t1, t2, t3; \
  208. x_##A = _mm256_add_epi32(x_##A, orig##A); \
  209. x_##B = _mm256_add_epi32(x_##B, orig##B); \
  210. x_##C = _mm256_add_epi32(x_##C, orig##C); \
  211. x_##D = _mm256_add_epi32(x_##D, orig##D); \
  212. t_##A = _mm256_unpacklo_epi32(x_##A, x_##B); \
  213. t_##B = _mm256_unpacklo_epi32(x_##C, x_##D); \
  214. t_##C = _mm256_unpackhi_epi32(x_##A, x_##B); \
  215. t_##D = _mm256_unpackhi_epi32(x_##C, x_##D); \
  216. x_##A = _mm256_unpacklo_epi64(t_##A, t_##B); \
  217. x_##B = _mm256_unpackhi_epi64(t_##A, t_##B); \
  218. x_##C = _mm256_unpacklo_epi64(t_##C, t_##D); \
  219. x_##D = _mm256_unpackhi_epi64(t_##C, t_##D); \
  220. t0 = _mm_xor_si128(_mm256_extracti128_si256(x_##A, 0), \
  221. _mm_loadu_si128((const __m128i*) (m + 0))); \
  222. _mm_storeu_si128((__m128i*) (c + 0), t0); \
  223. t1 = _mm_xor_si128(_mm256_extracti128_si256(x_##B, 0), \
  224. _mm_loadu_si128((const __m128i*) (m + 64))); \
  225. _mm_storeu_si128((__m128i*) (c + 64), t1); \
  226. t2 = _mm_xor_si128(_mm256_extracti128_si256(x_##C, 0), \
  227. _mm_loadu_si128((const __m128i*) (m + 128))); \
  228. _mm_storeu_si128((__m128i*) (c + 128), t2); \
  229. t3 = _mm_xor_si128(_mm256_extracti128_si256(x_##D, 0), \
  230. _mm_loadu_si128((const __m128i*) (m + 192))); \
  231. _mm_storeu_si128((__m128i*) (c + 192), t3); \
  232. t0 = _mm_xor_si128(_mm256_extracti128_si256(x_##A, 1), \
  233. _mm_loadu_si128((const __m128i*) (m + 256))); \
  234. _mm_storeu_si128((__m128i*) (c + 256), t0); \
  235. t1 = _mm_xor_si128(_mm256_extracti128_si256(x_##B, 1), \
  236. _mm_loadu_si128((const __m128i*) (m + 320))); \
  237. _mm_storeu_si128((__m128i*) (c + 320), t1); \
  238. t2 = _mm_xor_si128(_mm256_extracti128_si256(x_##C, 1), \
  239. _mm_loadu_si128((const __m128i*) (m + 384))); \
  240. _mm_storeu_si128((__m128i*) (c + 384), t2); \
  241. t3 = _mm_xor_si128(_mm256_extracti128_si256(x_##D, 1), \
  242. _mm_loadu_si128((const __m128i*) (m + 448))); \
  243. _mm_storeu_si128((__m128i*) (c + 448), t3); \
  244. }
  245. #define ONEQUAD(A, B, C, D) ONEQUAD_TRANSPOSE(A, B, C, D)
  246. #define ONEQUAD_UNPCK(A, B, C, D) \
  247. { \
  248. x_##A = _mm256_add_epi32(x_##A, orig##A); \
  249. x_##B = _mm256_add_epi32(x_##B, orig##B); \
  250. x_##C = _mm256_add_epi32(x_##C, orig##C); \
  251. x_##D = _mm256_add_epi32(x_##D, orig##D); \
  252. t_##A = _mm256_unpacklo_epi32(x_##A, x_##B); \
  253. t_##B = _mm256_unpacklo_epi32(x_##C, x_##D); \
  254. t_##C = _mm256_unpackhi_epi32(x_##A, x_##B); \
  255. t_##D = _mm256_unpackhi_epi32(x_##C, x_##D); \
  256. x_##A = _mm256_unpacklo_epi64(t_##A, t_##B); \
  257. x_##B = _mm256_unpackhi_epi64(t_##A, t_##B); \
  258. x_##C = _mm256_unpacklo_epi64(t_##C, t_##D); \
  259. x_##D = _mm256_unpackhi_epi64(t_##C, t_##D); \
  260. }
  261. #define ONEOCTO(A, B, C, D, A2, B2, C2, D2) \
  262. { \
  263. ONEQUAD_UNPCK(A, B, C, D); \
  264. ONEQUAD_UNPCK(A2, B2, C2, D2); \
  265. t_##A = _mm256_permute2x128_si256(x_##A, x_##A2, 0x20); \
  266. t_##A2 = _mm256_permute2x128_si256(x_##A, x_##A2, 0x31); \
  267. t_##B = _mm256_permute2x128_si256(x_##B, x_##B2, 0x20); \
  268. t_##B2 = _mm256_permute2x128_si256(x_##B, x_##B2, 0x31); \
  269. t_##C = _mm256_permute2x128_si256(x_##C, x_##C2, 0x20); \
  270. t_##C2 = _mm256_permute2x128_si256(x_##C, x_##C2, 0x31); \
  271. t_##D = _mm256_permute2x128_si256(x_##D, x_##D2, 0x20); \
  272. t_##D2 = _mm256_permute2x128_si256(x_##D, x_##D2, 0x31); \
  273. t_##A = _mm256_xor_si256( \
  274. t_##A, _mm256_loadu_si256((const __m256i*) (m + 0))); \
  275. t_##B = _mm256_xor_si256( \
  276. t_##B, _mm256_loadu_si256((const __m256i*) (m + 64))); \
  277. t_##C = _mm256_xor_si256( \
  278. t_##C, _mm256_loadu_si256((const __m256i*) (m + 128))); \
  279. t_##D = _mm256_xor_si256( \
  280. t_##D, _mm256_loadu_si256((const __m256i*) (m + 192))); \
  281. t_##A2 = _mm256_xor_si256( \
  282. t_##A2, _mm256_loadu_si256((const __m256i*) (m + 256))); \
  283. t_##B2 = _mm256_xor_si256( \
  284. t_##B2, _mm256_loadu_si256((const __m256i*) (m + 320))); \
  285. t_##C2 = _mm256_xor_si256( \
  286. t_##C2, _mm256_loadu_si256((const __m256i*) (m + 384))); \
  287. t_##D2 = _mm256_xor_si256( \
  288. t_##D2, _mm256_loadu_si256((const __m256i*) (m + 448))); \
  289. _mm256_storeu_si256((__m256i*) (c + 0), t_##A); \
  290. _mm256_storeu_si256((__m256i*) (c + 64), t_##B); \
  291. _mm256_storeu_si256((__m256i*) (c + 128), t_##C); \
  292. _mm256_storeu_si256((__m256i*) (c + 192), t_##D); \
  293. _mm256_storeu_si256((__m256i*) (c + 256), t_##A2); \
  294. _mm256_storeu_si256((__m256i*) (c + 320), t_##B2); \
  295. _mm256_storeu_si256((__m256i*) (c + 384), t_##C2); \
  296. _mm256_storeu_si256((__m256i*) (c + 448), t_##D2); \
  297. }
  298. ONEOCTO(0, 1, 2, 3, 4, 5, 6, 7);
  299. m += 32;
  300. c += 32;
  301. ONEOCTO(8, 9, 10, 11, 12, 13, 14, 15);
  302. m -= 32;
  303. c -= 32;
  304. #undef ONEQUAD
  305. #undef ONEQUAD_TRANSPOSE
  306. #undef ONEQUAD_UNPCK
  307. #undef ONEOCTO
  308. bytes -= 512;
  309. c += 512;
  310. m += 512;
  311. }
  312. }
  313. #undef VEC8_ROT
  314. #undef VEC8_QUARTERROUND
  315. #undef VEC8_QUARTERROUND_NAIVE
  316. #undef VEC8_QUARTERROUND_SHUFFLE
  317. #undef VEC8_QUARTERROUND_SHUFFLE2
  318. #undef VEC8_LINE1
  319. #undef VEC8_LINE2
  320. #undef VEC8_LINE3
  321. #undef VEC8_LINE4
  322. #undef VEC8_ROUND
  323. #undef VEC8_ROUND_SEQ
  324. #undef VEC8_ROUND_HALF
  325. #undef VEC8_ROUND_HALFANDHALF