u0.h 2.8 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586
  1. if (bytes > 0) {
  2. __m128i x_0, x_1, x_2, x_3;
  3. __m128i t_1;
  4. const __m128i rot16 =
  5. _mm_set_epi8(13, 12, 15, 14, 9, 8, 11, 10, 5, 4, 7, 6, 1, 0, 3, 2);
  6. const __m128i rot8 =
  7. _mm_set_epi8(14, 13, 12, 15, 10, 9, 8, 11, 6, 5, 4, 7, 2, 1, 0, 3);
  8. uint8_t partialblock[64];
  9. unsigned int i;
  10. x_0 = _mm_loadu_si128((const __m128i*) (x + 0));
  11. x_1 = _mm_loadu_si128((const __m128i*) (x + 4));
  12. x_2 = _mm_loadu_si128((const __m128i*) (x + 8));
  13. x_3 = _mm_loadu_si128((const __m128i*) (x + 12));
  14. for (i = 0; i < ROUNDS; i += 2) {
  15. x_0 = _mm_add_epi32(x_0, x_1);
  16. x_3 = _mm_xor_si128(x_3, x_0);
  17. x_3 = _mm_shuffle_epi8(x_3, rot16);
  18. x_2 = _mm_add_epi32(x_2, x_3);
  19. x_1 = _mm_xor_si128(x_1, x_2);
  20. t_1 = x_1;
  21. x_1 = _mm_slli_epi32(x_1, 12);
  22. t_1 = _mm_srli_epi32(t_1, 20);
  23. x_1 = _mm_xor_si128(x_1, t_1);
  24. x_0 = _mm_add_epi32(x_0, x_1);
  25. x_3 = _mm_xor_si128(x_3, x_0);
  26. x_0 = _mm_shuffle_epi32(x_0, 0x93);
  27. x_3 = _mm_shuffle_epi8(x_3, rot8);
  28. x_2 = _mm_add_epi32(x_2, x_3);
  29. x_3 = _mm_shuffle_epi32(x_3, 0x4e);
  30. x_1 = _mm_xor_si128(x_1, x_2);
  31. x_2 = _mm_shuffle_epi32(x_2, 0x39);
  32. t_1 = x_1;
  33. x_1 = _mm_slli_epi32(x_1, 7);
  34. t_1 = _mm_srli_epi32(t_1, 25);
  35. x_1 = _mm_xor_si128(x_1, t_1);
  36. x_0 = _mm_add_epi32(x_0, x_1);
  37. x_3 = _mm_xor_si128(x_3, x_0);
  38. x_3 = _mm_shuffle_epi8(x_3, rot16);
  39. x_2 = _mm_add_epi32(x_2, x_3);
  40. x_1 = _mm_xor_si128(x_1, x_2);
  41. t_1 = x_1;
  42. x_1 = _mm_slli_epi32(x_1, 12);
  43. t_1 = _mm_srli_epi32(t_1, 20);
  44. x_1 = _mm_xor_si128(x_1, t_1);
  45. x_0 = _mm_add_epi32(x_0, x_1);
  46. x_3 = _mm_xor_si128(x_3, x_0);
  47. x_0 = _mm_shuffle_epi32(x_0, 0x39);
  48. x_3 = _mm_shuffle_epi8(x_3, rot8);
  49. x_2 = _mm_add_epi32(x_2, x_3);
  50. x_3 = _mm_shuffle_epi32(x_3, 0x4e);
  51. x_1 = _mm_xor_si128(x_1, x_2);
  52. x_2 = _mm_shuffle_epi32(x_2, 0x93);
  53. t_1 = x_1;
  54. x_1 = _mm_slli_epi32(x_1, 7);
  55. t_1 = _mm_srli_epi32(t_1, 25);
  56. x_1 = _mm_xor_si128(x_1, t_1);
  57. }
  58. x_0 = _mm_add_epi32(x_0, _mm_loadu_si128((const __m128i*) (x + 0)));
  59. x_1 = _mm_add_epi32(x_1, _mm_loadu_si128((const __m128i*) (x + 4)));
  60. x_2 = _mm_add_epi32(x_2, _mm_loadu_si128((const __m128i*) (x + 8)));
  61. x_3 = _mm_add_epi32(x_3, _mm_loadu_si128((const __m128i*) (x + 12)));
  62. _mm_storeu_si128((__m128i*) (partialblock + 0), x_0);
  63. _mm_storeu_si128((__m128i*) (partialblock + 16), x_1);
  64. _mm_storeu_si128((__m128i*) (partialblock + 32), x_2);
  65. _mm_storeu_si128((__m128i*) (partialblock + 48), x_3);
  66. for (i = 0; i < bytes; i++) {
  67. c[i] = m[i] ^ partialblock[i];
  68. }
  69. sodium_memzero(partialblock, sizeof partialblock);
  70. }