des3_ede-asm_64.S 26 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806
  1. /*
  2. * des3_ede-asm_64.S - x86-64 assembly implementation of 3DES cipher
  3. *
  4. * Copyright © 2014 Jussi Kivilinna <jussi.kivilinna@iki.fi>
  5. *
  6. * This program is free software; you can redistribute it and/or modify
  7. * it under the terms of the GNU General Public License as published by
  8. * the Free Software Foundation; either version 2 of the License, or
  9. * (at your option) any later version.
  10. *
  11. * This program is distributed in the hope that it will be useful,
  12. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  13. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  14. * GNU General Public License for more details.
  15. */
  16. #include <linux/linkage.h>
  17. .file "des3_ede-asm_64.S"
  18. .text
  19. #define s1 .L_s1
  20. #define s2 ((s1) + (64*8))
  21. #define s3 ((s2) + (64*8))
  22. #define s4 ((s3) + (64*8))
  23. #define s5 ((s4) + (64*8))
  24. #define s6 ((s5) + (64*8))
  25. #define s7 ((s6) + (64*8))
  26. #define s8 ((s7) + (64*8))
  27. /* register macros */
  28. #define CTX %rdi
  29. #define RL0 %r8
  30. #define RL1 %r9
  31. #define RL2 %r10
  32. #define RL0d %r8d
  33. #define RL1d %r9d
  34. #define RL2d %r10d
  35. #define RR0 %r11
  36. #define RR1 %r12
  37. #define RR2 %r13
  38. #define RR0d %r11d
  39. #define RR1d %r12d
  40. #define RR2d %r13d
  41. #define RW0 %rax
  42. #define RW1 %rbx
  43. #define RW2 %rcx
  44. #define RW0d %eax
  45. #define RW1d %ebx
  46. #define RW2d %ecx
  47. #define RW0bl %al
  48. #define RW1bl %bl
  49. #define RW2bl %cl
  50. #define RW0bh %ah
  51. #define RW1bh %bh
  52. #define RW2bh %ch
  53. #define RT0 %r15
  54. #define RT1 %rbp
  55. #define RT2 %r14
  56. #define RT3 %rdx
  57. #define RT0d %r15d
  58. #define RT1d %ebp
  59. #define RT2d %r14d
  60. #define RT3d %edx
  61. /***********************************************************************
  62. * 1-way 3DES
  63. ***********************************************************************/
  64. #define do_permutation(a, b, offset, mask) \
  65. movl a, RT0d; \
  66. shrl $(offset), RT0d; \
  67. xorl b, RT0d; \
  68. andl $(mask), RT0d; \
  69. xorl RT0d, b; \
  70. shll $(offset), RT0d; \
  71. xorl RT0d, a;
  72. #define expand_to_64bits(val, mask) \
  73. movl val##d, RT0d; \
  74. rorl $4, RT0d; \
  75. shlq $32, RT0; \
  76. orq RT0, val; \
  77. andq mask, val;
  78. #define compress_to_64bits(val) \
  79. movq val, RT0; \
  80. shrq $32, RT0; \
  81. roll $4, RT0d; \
  82. orl RT0d, val##d;
  83. #define initial_permutation(left, right) \
  84. do_permutation(left##d, right##d, 4, 0x0f0f0f0f); \
  85. do_permutation(left##d, right##d, 16, 0x0000ffff); \
  86. do_permutation(right##d, left##d, 2, 0x33333333); \
  87. do_permutation(right##d, left##d, 8, 0x00ff00ff); \
  88. movabs $0x3f3f3f3f3f3f3f3f, RT3; \
  89. movl left##d, RW0d; \
  90. roll $1, right##d; \
  91. xorl right##d, RW0d; \
  92. andl $0xaaaaaaaa, RW0d; \
  93. xorl RW0d, left##d; \
  94. xorl RW0d, right##d; \
  95. roll $1, left##d; \
  96. expand_to_64bits(right, RT3); \
  97. expand_to_64bits(left, RT3);
  98. #define final_permutation(left, right) \
  99. compress_to_64bits(right); \
  100. compress_to_64bits(left); \
  101. movl right##d, RW0d; \
  102. rorl $1, left##d; \
  103. xorl left##d, RW0d; \
  104. andl $0xaaaaaaaa, RW0d; \
  105. xorl RW0d, right##d; \
  106. xorl RW0d, left##d; \
  107. rorl $1, right##d; \
  108. do_permutation(right##d, left##d, 8, 0x00ff00ff); \
  109. do_permutation(right##d, left##d, 2, 0x33333333); \
  110. do_permutation(left##d, right##d, 16, 0x0000ffff); \
  111. do_permutation(left##d, right##d, 4, 0x0f0f0f0f);
  112. #define round1(n, from, to, load_next_key) \
  113. xorq from, RW0; \
  114. \
  115. movzbl RW0bl, RT0d; \
  116. movzbl RW0bh, RT1d; \
  117. shrq $16, RW0; \
  118. movzbl RW0bl, RT2d; \
  119. movzbl RW0bh, RT3d; \
  120. shrq $16, RW0; \
  121. movq s8(, RT0, 8), RT0; \
  122. xorq s6(, RT1, 8), to; \
  123. movzbl RW0bl, RL1d; \
  124. movzbl RW0bh, RT1d; \
  125. shrl $16, RW0d; \
  126. xorq s4(, RT2, 8), RT0; \
  127. xorq s2(, RT3, 8), to; \
  128. movzbl RW0bl, RT2d; \
  129. movzbl RW0bh, RT3d; \
  130. xorq s7(, RL1, 8), RT0; \
  131. xorq s5(, RT1, 8), to; \
  132. xorq s3(, RT2, 8), RT0; \
  133. load_next_key(n, RW0); \
  134. xorq RT0, to; \
  135. xorq s1(, RT3, 8), to; \
  136. #define load_next_key(n, RWx) \
  137. movq (((n) + 1) * 8)(CTX), RWx;
  138. #define dummy2(a, b) /*_*/
  139. #define read_block(io, left, right) \
  140. movl (io), left##d; \
  141. movl 4(io), right##d; \
  142. bswapl left##d; \
  143. bswapl right##d;
  144. #define write_block(io, left, right) \
  145. bswapl left##d; \
  146. bswapl right##d; \
  147. movl left##d, (io); \
  148. movl right##d, 4(io);
  149. ENTRY(des3_ede_x86_64_crypt_blk)
  150. /* input:
  151. * %rdi: round keys, CTX
  152. * %rsi: dst
  153. * %rdx: src
  154. */
  155. pushq %rbp;
  156. pushq %rbx;
  157. pushq %r12;
  158. pushq %r13;
  159. pushq %r14;
  160. pushq %r15;
  161. read_block(%rdx, RL0, RR0);
  162. initial_permutation(RL0, RR0);
  163. movq (CTX), RW0;
  164. round1(0, RR0, RL0, load_next_key);
  165. round1(1, RL0, RR0, load_next_key);
  166. round1(2, RR0, RL0, load_next_key);
  167. round1(3, RL0, RR0, load_next_key);
  168. round1(4, RR0, RL0, load_next_key);
  169. round1(5, RL0, RR0, load_next_key);
  170. round1(6, RR0, RL0, load_next_key);
  171. round1(7, RL0, RR0, load_next_key);
  172. round1(8, RR0, RL0, load_next_key);
  173. round1(9, RL0, RR0, load_next_key);
  174. round1(10, RR0, RL0, load_next_key);
  175. round1(11, RL0, RR0, load_next_key);
  176. round1(12, RR0, RL0, load_next_key);
  177. round1(13, RL0, RR0, load_next_key);
  178. round1(14, RR0, RL0, load_next_key);
  179. round1(15, RL0, RR0, load_next_key);
  180. round1(16+0, RL0, RR0, load_next_key);
  181. round1(16+1, RR0, RL0, load_next_key);
  182. round1(16+2, RL0, RR0, load_next_key);
  183. round1(16+3, RR0, RL0, load_next_key);
  184. round1(16+4, RL0, RR0, load_next_key);
  185. round1(16+5, RR0, RL0, load_next_key);
  186. round1(16+6, RL0, RR0, load_next_key);
  187. round1(16+7, RR0, RL0, load_next_key);
  188. round1(16+8, RL0, RR0, load_next_key);
  189. round1(16+9, RR0, RL0, load_next_key);
  190. round1(16+10, RL0, RR0, load_next_key);
  191. round1(16+11, RR0, RL0, load_next_key);
  192. round1(16+12, RL0, RR0, load_next_key);
  193. round1(16+13, RR0, RL0, load_next_key);
  194. round1(16+14, RL0, RR0, load_next_key);
  195. round1(16+15, RR0, RL0, load_next_key);
  196. round1(32+0, RR0, RL0, load_next_key);
  197. round1(32+1, RL0, RR0, load_next_key);
  198. round1(32+2, RR0, RL0, load_next_key);
  199. round1(32+3, RL0, RR0, load_next_key);
  200. round1(32+4, RR0, RL0, load_next_key);
  201. round1(32+5, RL0, RR0, load_next_key);
  202. round1(32+6, RR0, RL0, load_next_key);
  203. round1(32+7, RL0, RR0, load_next_key);
  204. round1(32+8, RR0, RL0, load_next_key);
  205. round1(32+9, RL0, RR0, load_next_key);
  206. round1(32+10, RR0, RL0, load_next_key);
  207. round1(32+11, RL0, RR0, load_next_key);
  208. round1(32+12, RR0, RL0, load_next_key);
  209. round1(32+13, RL0, RR0, load_next_key);
  210. round1(32+14, RR0, RL0, load_next_key);
  211. round1(32+15, RL0, RR0, dummy2);
  212. final_permutation(RR0, RL0);
  213. write_block(%rsi, RR0, RL0);
  214. popq %r15;
  215. popq %r14;
  216. popq %r13;
  217. popq %r12;
  218. popq %rbx;
  219. popq %rbp;
  220. ret;
  221. ENDPROC(des3_ede_x86_64_crypt_blk)
  222. /***********************************************************************
  223. * 3-way 3DES
  224. ***********************************************************************/
  225. #define expand_to_64bits(val, mask) \
  226. movl val##d, RT0d; \
  227. rorl $4, RT0d; \
  228. shlq $32, RT0; \
  229. orq RT0, val; \
  230. andq mask, val;
  231. #define compress_to_64bits(val) \
  232. movq val, RT0; \
  233. shrq $32, RT0; \
  234. roll $4, RT0d; \
  235. orl RT0d, val##d;
  236. #define initial_permutation3(left, right) \
  237. do_permutation(left##0d, right##0d, 4, 0x0f0f0f0f); \
  238. do_permutation(left##0d, right##0d, 16, 0x0000ffff); \
  239. do_permutation(left##1d, right##1d, 4, 0x0f0f0f0f); \
  240. do_permutation(left##1d, right##1d, 16, 0x0000ffff); \
  241. do_permutation(left##2d, right##2d, 4, 0x0f0f0f0f); \
  242. do_permutation(left##2d, right##2d, 16, 0x0000ffff); \
  243. \
  244. do_permutation(right##0d, left##0d, 2, 0x33333333); \
  245. do_permutation(right##0d, left##0d, 8, 0x00ff00ff); \
  246. do_permutation(right##1d, left##1d, 2, 0x33333333); \
  247. do_permutation(right##1d, left##1d, 8, 0x00ff00ff); \
  248. do_permutation(right##2d, left##2d, 2, 0x33333333); \
  249. do_permutation(right##2d, left##2d, 8, 0x00ff00ff); \
  250. \
  251. movabs $0x3f3f3f3f3f3f3f3f, RT3; \
  252. \
  253. movl left##0d, RW0d; \
  254. roll $1, right##0d; \
  255. xorl right##0d, RW0d; \
  256. andl $0xaaaaaaaa, RW0d; \
  257. xorl RW0d, left##0d; \
  258. xorl RW0d, right##0d; \
  259. roll $1, left##0d; \
  260. expand_to_64bits(right##0, RT3); \
  261. expand_to_64bits(left##0, RT3); \
  262. movl left##1d, RW1d; \
  263. roll $1, right##1d; \
  264. xorl right##1d, RW1d; \
  265. andl $0xaaaaaaaa, RW1d; \
  266. xorl RW1d, left##1d; \
  267. xorl RW1d, right##1d; \
  268. roll $1, left##1d; \
  269. expand_to_64bits(right##1, RT3); \
  270. expand_to_64bits(left##1, RT3); \
  271. movl left##2d, RW2d; \
  272. roll $1, right##2d; \
  273. xorl right##2d, RW2d; \
  274. andl $0xaaaaaaaa, RW2d; \
  275. xorl RW2d, left##2d; \
  276. xorl RW2d, right##2d; \
  277. roll $1, left##2d; \
  278. expand_to_64bits(right##2, RT3); \
  279. expand_to_64bits(left##2, RT3);
  280. #define final_permutation3(left, right) \
  281. compress_to_64bits(right##0); \
  282. compress_to_64bits(left##0); \
  283. movl right##0d, RW0d; \
  284. rorl $1, left##0d; \
  285. xorl left##0d, RW0d; \
  286. andl $0xaaaaaaaa, RW0d; \
  287. xorl RW0d, right##0d; \
  288. xorl RW0d, left##0d; \
  289. rorl $1, right##0d; \
  290. compress_to_64bits(right##1); \
  291. compress_to_64bits(left##1); \
  292. movl right##1d, RW1d; \
  293. rorl $1, left##1d; \
  294. xorl left##1d, RW1d; \
  295. andl $0xaaaaaaaa, RW1d; \
  296. xorl RW1d, right##1d; \
  297. xorl RW1d, left##1d; \
  298. rorl $1, right##1d; \
  299. compress_to_64bits(right##2); \
  300. compress_to_64bits(left##2); \
  301. movl right##2d, RW2d; \
  302. rorl $1, left##2d; \
  303. xorl left##2d, RW2d; \
  304. andl $0xaaaaaaaa, RW2d; \
  305. xorl RW2d, right##2d; \
  306. xorl RW2d, left##2d; \
  307. rorl $1, right##2d; \
  308. \
  309. do_permutation(right##0d, left##0d, 8, 0x00ff00ff); \
  310. do_permutation(right##0d, left##0d, 2, 0x33333333); \
  311. do_permutation(right##1d, left##1d, 8, 0x00ff00ff); \
  312. do_permutation(right##1d, left##1d, 2, 0x33333333); \
  313. do_permutation(right##2d, left##2d, 8, 0x00ff00ff); \
  314. do_permutation(right##2d, left##2d, 2, 0x33333333); \
  315. \
  316. do_permutation(left##0d, right##0d, 16, 0x0000ffff); \
  317. do_permutation(left##0d, right##0d, 4, 0x0f0f0f0f); \
  318. do_permutation(left##1d, right##1d, 16, 0x0000ffff); \
  319. do_permutation(left##1d, right##1d, 4, 0x0f0f0f0f); \
  320. do_permutation(left##2d, right##2d, 16, 0x0000ffff); \
  321. do_permutation(left##2d, right##2d, 4, 0x0f0f0f0f);
  322. #define round3(n, from, to, load_next_key, do_movq) \
  323. xorq from##0, RW0; \
  324. movzbl RW0bl, RT3d; \
  325. movzbl RW0bh, RT1d; \
  326. shrq $16, RW0; \
  327. xorq s8(, RT3, 8), to##0; \
  328. xorq s6(, RT1, 8), to##0; \
  329. movzbl RW0bl, RT3d; \
  330. movzbl RW0bh, RT1d; \
  331. shrq $16, RW0; \
  332. xorq s4(, RT3, 8), to##0; \
  333. xorq s2(, RT1, 8), to##0; \
  334. movzbl RW0bl, RT3d; \
  335. movzbl RW0bh, RT1d; \
  336. shrl $16, RW0d; \
  337. xorq s7(, RT3, 8), to##0; \
  338. xorq s5(, RT1, 8), to##0; \
  339. movzbl RW0bl, RT3d; \
  340. movzbl RW0bh, RT1d; \
  341. load_next_key(n, RW0); \
  342. xorq s3(, RT3, 8), to##0; \
  343. xorq s1(, RT1, 8), to##0; \
  344. xorq from##1, RW1; \
  345. movzbl RW1bl, RT3d; \
  346. movzbl RW1bh, RT1d; \
  347. shrq $16, RW1; \
  348. xorq s8(, RT3, 8), to##1; \
  349. xorq s6(, RT1, 8), to##1; \
  350. movzbl RW1bl, RT3d; \
  351. movzbl RW1bh, RT1d; \
  352. shrq $16, RW1; \
  353. xorq s4(, RT3, 8), to##1; \
  354. xorq s2(, RT1, 8), to##1; \
  355. movzbl RW1bl, RT3d; \
  356. movzbl RW1bh, RT1d; \
  357. shrl $16, RW1d; \
  358. xorq s7(, RT3, 8), to##1; \
  359. xorq s5(, RT1, 8), to##1; \
  360. movzbl RW1bl, RT3d; \
  361. movzbl RW1bh, RT1d; \
  362. do_movq(RW0, RW1); \
  363. xorq s3(, RT3, 8), to##1; \
  364. xorq s1(, RT1, 8), to##1; \
  365. xorq from##2, RW2; \
  366. movzbl RW2bl, RT3d; \
  367. movzbl RW2bh, RT1d; \
  368. shrq $16, RW2; \
  369. xorq s8(, RT3, 8), to##2; \
  370. xorq s6(, RT1, 8), to##2; \
  371. movzbl RW2bl, RT3d; \
  372. movzbl RW2bh, RT1d; \
  373. shrq $16, RW2; \
  374. xorq s4(, RT3, 8), to##2; \
  375. xorq s2(, RT1, 8), to##2; \
  376. movzbl RW2bl, RT3d; \
  377. movzbl RW2bh, RT1d; \
  378. shrl $16, RW2d; \
  379. xorq s7(, RT3, 8), to##2; \
  380. xorq s5(, RT1, 8), to##2; \
  381. movzbl RW2bl, RT3d; \
  382. movzbl RW2bh, RT1d; \
  383. do_movq(RW0, RW2); \
  384. xorq s3(, RT3, 8), to##2; \
  385. xorq s1(, RT1, 8), to##2;
  386. #define __movq(src, dst) \
  387. movq src, dst;
  388. ENTRY(des3_ede_x86_64_crypt_blk_3way)
  389. /* input:
  390. * %rdi: ctx, round keys
  391. * %rsi: dst (3 blocks)
  392. * %rdx: src (3 blocks)
  393. */
  394. pushq %rbp;
  395. pushq %rbx;
  396. pushq %r12;
  397. pushq %r13;
  398. pushq %r14;
  399. pushq %r15;
  400. /* load input */
  401. movl 0 * 4(%rdx), RL0d;
  402. movl 1 * 4(%rdx), RR0d;
  403. movl 2 * 4(%rdx), RL1d;
  404. movl 3 * 4(%rdx), RR1d;
  405. movl 4 * 4(%rdx), RL2d;
  406. movl 5 * 4(%rdx), RR2d;
  407. bswapl RL0d;
  408. bswapl RR0d;
  409. bswapl RL1d;
  410. bswapl RR1d;
  411. bswapl RL2d;
  412. bswapl RR2d;
  413. initial_permutation3(RL, RR);
  414. movq 0(CTX), RW0;
  415. movq RW0, RW1;
  416. movq RW0, RW2;
  417. round3(0, RR, RL, load_next_key, __movq);
  418. round3(1, RL, RR, load_next_key, __movq);
  419. round3(2, RR, RL, load_next_key, __movq);
  420. round3(3, RL, RR, load_next_key, __movq);
  421. round3(4, RR, RL, load_next_key, __movq);
  422. round3(5, RL, RR, load_next_key, __movq);
  423. round3(6, RR, RL, load_next_key, __movq);
  424. round3(7, RL, RR, load_next_key, __movq);
  425. round3(8, RR, RL, load_next_key, __movq);
  426. round3(9, RL, RR, load_next_key, __movq);
  427. round3(10, RR, RL, load_next_key, __movq);
  428. round3(11, RL, RR, load_next_key, __movq);
  429. round3(12, RR, RL, load_next_key, __movq);
  430. round3(13, RL, RR, load_next_key, __movq);
  431. round3(14, RR, RL, load_next_key, __movq);
  432. round3(15, RL, RR, load_next_key, __movq);
  433. round3(16+0, RL, RR, load_next_key, __movq);
  434. round3(16+1, RR, RL, load_next_key, __movq);
  435. round3(16+2, RL, RR, load_next_key, __movq);
  436. round3(16+3, RR, RL, load_next_key, __movq);
  437. round3(16+4, RL, RR, load_next_key, __movq);
  438. round3(16+5, RR, RL, load_next_key, __movq);
  439. round3(16+6, RL, RR, load_next_key, __movq);
  440. round3(16+7, RR, RL, load_next_key, __movq);
  441. round3(16+8, RL, RR, load_next_key, __movq);
  442. round3(16+9, RR, RL, load_next_key, __movq);
  443. round3(16+10, RL, RR, load_next_key, __movq);
  444. round3(16+11, RR, RL, load_next_key, __movq);
  445. round3(16+12, RL, RR, load_next_key, __movq);
  446. round3(16+13, RR, RL, load_next_key, __movq);
  447. round3(16+14, RL, RR, load_next_key, __movq);
  448. round3(16+15, RR, RL, load_next_key, __movq);
  449. round3(32+0, RR, RL, load_next_key, __movq);
  450. round3(32+1, RL, RR, load_next_key, __movq);
  451. round3(32+2, RR, RL, load_next_key, __movq);
  452. round3(32+3, RL, RR, load_next_key, __movq);
  453. round3(32+4, RR, RL, load_next_key, __movq);
  454. round3(32+5, RL, RR, load_next_key, __movq);
  455. round3(32+6, RR, RL, load_next_key, __movq);
  456. round3(32+7, RL, RR, load_next_key, __movq);
  457. round3(32+8, RR, RL, load_next_key, __movq);
  458. round3(32+9, RL, RR, load_next_key, __movq);
  459. round3(32+10, RR, RL, load_next_key, __movq);
  460. round3(32+11, RL, RR, load_next_key, __movq);
  461. round3(32+12, RR, RL, load_next_key, __movq);
  462. round3(32+13, RL, RR, load_next_key, __movq);
  463. round3(32+14, RR, RL, load_next_key, __movq);
  464. round3(32+15, RL, RR, dummy2, dummy2);
  465. final_permutation3(RR, RL);
  466. bswapl RR0d;
  467. bswapl RL0d;
  468. bswapl RR1d;
  469. bswapl RL1d;
  470. bswapl RR2d;
  471. bswapl RL2d;
  472. movl RR0d, 0 * 4(%rsi);
  473. movl RL0d, 1 * 4(%rsi);
  474. movl RR1d, 2 * 4(%rsi);
  475. movl RL1d, 3 * 4(%rsi);
  476. movl RR2d, 4 * 4(%rsi);
  477. movl RL2d, 5 * 4(%rsi);
  478. popq %r15;
  479. popq %r14;
  480. popq %r13;
  481. popq %r12;
  482. popq %rbx;
  483. popq %rbp;
  484. ret;
  485. ENDPROC(des3_ede_x86_64_crypt_blk_3way)
  486. .data
  487. .align 16
  488. .L_s1:
  489. .quad 0x0010100001010400, 0x0000000000000000
  490. .quad 0x0000100000010000, 0x0010100001010404
  491. .quad 0x0010100001010004, 0x0000100000010404
  492. .quad 0x0000000000000004, 0x0000100000010000
  493. .quad 0x0000000000000400, 0x0010100001010400
  494. .quad 0x0010100001010404, 0x0000000000000400
  495. .quad 0x0010000001000404, 0x0010100001010004
  496. .quad 0x0010000001000000, 0x0000000000000004
  497. .quad 0x0000000000000404, 0x0010000001000400
  498. .quad 0x0010000001000400, 0x0000100000010400
  499. .quad 0x0000100000010400, 0x0010100001010000
  500. .quad 0x0010100001010000, 0x0010000001000404
  501. .quad 0x0000100000010004, 0x0010000001000004
  502. .quad 0x0010000001000004, 0x0000100000010004
  503. .quad 0x0000000000000000, 0x0000000000000404
  504. .quad 0x0000100000010404, 0x0010000001000000
  505. .quad 0x0000100000010000, 0x0010100001010404
  506. .quad 0x0000000000000004, 0x0010100001010000
  507. .quad 0x0010100001010400, 0x0010000001000000
  508. .quad 0x0010000001000000, 0x0000000000000400
  509. .quad 0x0010100001010004, 0x0000100000010000
  510. .quad 0x0000100000010400, 0x0010000001000004
  511. .quad 0x0000000000000400, 0x0000000000000004
  512. .quad 0x0010000001000404, 0x0000100000010404
  513. .quad 0x0010100001010404, 0x0000100000010004
  514. .quad 0x0010100001010000, 0x0010000001000404
  515. .quad 0x0010000001000004, 0x0000000000000404
  516. .quad 0x0000100000010404, 0x0010100001010400
  517. .quad 0x0000000000000404, 0x0010000001000400
  518. .quad 0x0010000001000400, 0x0000000000000000
  519. .quad 0x0000100000010004, 0x0000100000010400
  520. .quad 0x0000000000000000, 0x0010100001010004
  521. .L_s2:
  522. .quad 0x0801080200100020, 0x0800080000000000
  523. .quad 0x0000080000000000, 0x0001080200100020
  524. .quad 0x0001000000100000, 0x0000000200000020
  525. .quad 0x0801000200100020, 0x0800080200000020
  526. .quad 0x0800000200000020, 0x0801080200100020
  527. .quad 0x0801080000100000, 0x0800000000000000
  528. .quad 0x0800080000000000, 0x0001000000100000
  529. .quad 0x0000000200000020, 0x0801000200100020
  530. .quad 0x0001080000100000, 0x0001000200100020
  531. .quad 0x0800080200000020, 0x0000000000000000
  532. .quad 0x0800000000000000, 0x0000080000000000
  533. .quad 0x0001080200100020, 0x0801000000100000
  534. .quad 0x0001000200100020, 0x0800000200000020
  535. .quad 0x0000000000000000, 0x0001080000100000
  536. .quad 0x0000080200000020, 0x0801080000100000
  537. .quad 0x0801000000100000, 0x0000080200000020
  538. .quad 0x0000000000000000, 0x0001080200100020
  539. .quad 0x0801000200100020, 0x0001000000100000
  540. .quad 0x0800080200000020, 0x0801000000100000
  541. .quad 0x0801080000100000, 0x0000080000000000
  542. .quad 0x0801000000100000, 0x0800080000000000
  543. .quad 0x0000000200000020, 0x0801080200100020
  544. .quad 0x0001080200100020, 0x0000000200000020
  545. .quad 0x0000080000000000, 0x0800000000000000
  546. .quad 0x0000080200000020, 0x0801080000100000
  547. .quad 0x0001000000100000, 0x0800000200000020
  548. .quad 0x0001000200100020, 0x0800080200000020
  549. .quad 0x0800000200000020, 0x0001000200100020
  550. .quad 0x0001080000100000, 0x0000000000000000
  551. .quad 0x0800080000000000, 0x0000080200000020
  552. .quad 0x0800000000000000, 0x0801000200100020
  553. .quad 0x0801080200100020, 0x0001080000100000
  554. .L_s3:
  555. .quad 0x0000002000000208, 0x0000202008020200
  556. .quad 0x0000000000000000, 0x0000200008020008
  557. .quad 0x0000002008000200, 0x0000000000000000
  558. .quad 0x0000202000020208, 0x0000002008000200
  559. .quad 0x0000200000020008, 0x0000000008000008
  560. .quad 0x0000000008000008, 0x0000200000020000
  561. .quad 0x0000202008020208, 0x0000200000020008
  562. .quad 0x0000200008020000, 0x0000002000000208
  563. .quad 0x0000000008000000, 0x0000000000000008
  564. .quad 0x0000202008020200, 0x0000002000000200
  565. .quad 0x0000202000020200, 0x0000200008020000
  566. .quad 0x0000200008020008, 0x0000202000020208
  567. .quad 0x0000002008000208, 0x0000202000020200
  568. .quad 0x0000200000020000, 0x0000002008000208
  569. .quad 0x0000000000000008, 0x0000202008020208
  570. .quad 0x0000002000000200, 0x0000000008000000
  571. .quad 0x0000202008020200, 0x0000000008000000
  572. .quad 0x0000200000020008, 0x0000002000000208
  573. .quad 0x0000200000020000, 0x0000202008020200
  574. .quad 0x0000002008000200, 0x0000000000000000
  575. .quad 0x0000002000000200, 0x0000200000020008
  576. .quad 0x0000202008020208, 0x0000002008000200
  577. .quad 0x0000000008000008, 0x0000002000000200
  578. .quad 0x0000000000000000, 0x0000200008020008
  579. .quad 0x0000002008000208, 0x0000200000020000
  580. .quad 0x0000000008000000, 0x0000202008020208
  581. .quad 0x0000000000000008, 0x0000202000020208
  582. .quad 0x0000202000020200, 0x0000000008000008
  583. .quad 0x0000200008020000, 0x0000002008000208
  584. .quad 0x0000002000000208, 0x0000200008020000
  585. .quad 0x0000202000020208, 0x0000000000000008
  586. .quad 0x0000200008020008, 0x0000202000020200
  587. .L_s4:
  588. .quad 0x1008020000002001, 0x1000020800002001
  589. .quad 0x1000020800002001, 0x0000000800000000
  590. .quad 0x0008020800002000, 0x1008000800000001
  591. .quad 0x1008000000000001, 0x1000020000002001
  592. .quad 0x0000000000000000, 0x0008020000002000
  593. .quad 0x0008020000002000, 0x1008020800002001
  594. .quad 0x1000000800000001, 0x0000000000000000
  595. .quad 0x0008000800000000, 0x1008000000000001
  596. .quad 0x1000000000000001, 0x0000020000002000
  597. .quad 0x0008000000000000, 0x1008020000002001
  598. .quad 0x0000000800000000, 0x0008000000000000
  599. .quad 0x1000020000002001, 0x0000020800002000
  600. .quad 0x1008000800000001, 0x1000000000000001
  601. .quad 0x0000020800002000, 0x0008000800000000
  602. .quad 0x0000020000002000, 0x0008020800002000
  603. .quad 0x1008020800002001, 0x1000000800000001
  604. .quad 0x0008000800000000, 0x1008000000000001
  605. .quad 0x0008020000002000, 0x1008020800002001
  606. .quad 0x1000000800000001, 0x0000000000000000
  607. .quad 0x0000000000000000, 0x0008020000002000
  608. .quad 0x0000020800002000, 0x0008000800000000
  609. .quad 0x1008000800000001, 0x1000000000000001
  610. .quad 0x1008020000002001, 0x1000020800002001
  611. .quad 0x1000020800002001, 0x0000000800000000
  612. .quad 0x1008020800002001, 0x1000000800000001
  613. .quad 0x1000000000000001, 0x0000020000002000
  614. .quad 0x1008000000000001, 0x1000020000002001
  615. .quad 0x0008020800002000, 0x1008000800000001
  616. .quad 0x1000020000002001, 0x0000020800002000
  617. .quad 0x0008000000000000, 0x1008020000002001
  618. .quad 0x0000000800000000, 0x0008000000000000
  619. .quad 0x0000020000002000, 0x0008020800002000
  620. .L_s5:
  621. .quad 0x0000001000000100, 0x0020001002080100
  622. .quad 0x0020000002080000, 0x0420001002000100
  623. .quad 0x0000000000080000, 0x0000001000000100
  624. .quad 0x0400000000000000, 0x0020000002080000
  625. .quad 0x0400001000080100, 0x0000000000080000
  626. .quad 0x0020001002000100, 0x0400001000080100
  627. .quad 0x0420001002000100, 0x0420000002080000
  628. .quad 0x0000001000080100, 0x0400000000000000
  629. .quad 0x0020000002000000, 0x0400000000080000
  630. .quad 0x0400000000080000, 0x0000000000000000
  631. .quad 0x0400001000000100, 0x0420001002080100
  632. .quad 0x0420001002080100, 0x0020001002000100
  633. .quad 0x0420000002080000, 0x0400001000000100
  634. .quad 0x0000000000000000, 0x0420000002000000
  635. .quad 0x0020001002080100, 0x0020000002000000
  636. .quad 0x0420000002000000, 0x0000001000080100
  637. .quad 0x0000000000080000, 0x0420001002000100
  638. .quad 0x0000001000000100, 0x0020000002000000
  639. .quad 0x0400000000000000, 0x0020000002080000
  640. .quad 0x0420001002000100, 0x0400001000080100
  641. .quad 0x0020001002000100, 0x0400000000000000
  642. .quad 0x0420000002080000, 0x0020001002080100
  643. .quad 0x0400001000080100, 0x0000001000000100
  644. .quad 0x0020000002000000, 0x0420000002080000
  645. .quad 0x0420001002080100, 0x0000001000080100
  646. .quad 0x0420000002000000, 0x0420001002080100
  647. .quad 0x0020000002080000, 0x0000000000000000
  648. .quad 0x0400000000080000, 0x0420000002000000
  649. .quad 0x0000001000080100, 0x0020001002000100
  650. .quad 0x0400001000000100, 0x0000000000080000
  651. .quad 0x0000000000000000, 0x0400000000080000
  652. .quad 0x0020001002080100, 0x0400001000000100
  653. .L_s6:
  654. .quad 0x0200000120000010, 0x0204000020000000
  655. .quad 0x0000040000000000, 0x0204040120000010
  656. .quad 0x0204000020000000, 0x0000000100000010
  657. .quad 0x0204040120000010, 0x0004000000000000
  658. .quad 0x0200040020000000, 0x0004040100000010
  659. .quad 0x0004000000000000, 0x0200000120000010
  660. .quad 0x0004000100000010, 0x0200040020000000
  661. .quad 0x0200000020000000, 0x0000040100000010
  662. .quad 0x0000000000000000, 0x0004000100000010
  663. .quad 0x0200040120000010, 0x0000040000000000
  664. .quad 0x0004040000000000, 0x0200040120000010
  665. .quad 0x0000000100000010, 0x0204000120000010
  666. .quad 0x0204000120000010, 0x0000000000000000
  667. .quad 0x0004040100000010, 0x0204040020000000
  668. .quad 0x0000040100000010, 0x0004040000000000
  669. .quad 0x0204040020000000, 0x0200000020000000
  670. .quad 0x0200040020000000, 0x0000000100000010
  671. .quad 0x0204000120000010, 0x0004040000000000
  672. .quad 0x0204040120000010, 0x0004000000000000
  673. .quad 0x0000040100000010, 0x0200000120000010
  674. .quad 0x0004000000000000, 0x0200040020000000
  675. .quad 0x0200000020000000, 0x0000040100000010
  676. .quad 0x0200000120000010, 0x0204040120000010
  677. .quad 0x0004040000000000, 0x0204000020000000
  678. .quad 0x0004040100000010, 0x0204040020000000
  679. .quad 0x0000000000000000, 0x0204000120000010
  680. .quad 0x0000000100000010, 0x0000040000000000
  681. .quad 0x0204000020000000, 0x0004040100000010
  682. .quad 0x0000040000000000, 0x0004000100000010
  683. .quad 0x0200040120000010, 0x0000000000000000
  684. .quad 0x0204040020000000, 0x0200000020000000
  685. .quad 0x0004000100000010, 0x0200040120000010
  686. .L_s7:
  687. .quad 0x0002000000200000, 0x2002000004200002
  688. .quad 0x2000000004000802, 0x0000000000000000
  689. .quad 0x0000000000000800, 0x2000000004000802
  690. .quad 0x2002000000200802, 0x0002000004200800
  691. .quad 0x2002000004200802, 0x0002000000200000
  692. .quad 0x0000000000000000, 0x2000000004000002
  693. .quad 0x2000000000000002, 0x0000000004000000
  694. .quad 0x2002000004200002, 0x2000000000000802
  695. .quad 0x0000000004000800, 0x2002000000200802
  696. .quad 0x2002000000200002, 0x0000000004000800
  697. .quad 0x2000000004000002, 0x0002000004200000
  698. .quad 0x0002000004200800, 0x2002000000200002
  699. .quad 0x0002000004200000, 0x0000000000000800
  700. .quad 0x2000000000000802, 0x2002000004200802
  701. .quad 0x0002000000200800, 0x2000000000000002
  702. .quad 0x0000000004000000, 0x0002000000200800
  703. .quad 0x0000000004000000, 0x0002000000200800
  704. .quad 0x0002000000200000, 0x2000000004000802
  705. .quad 0x2000000004000802, 0x2002000004200002
  706. .quad 0x2002000004200002, 0x2000000000000002
  707. .quad 0x2002000000200002, 0x0000000004000000
  708. .quad 0x0000000004000800, 0x0002000000200000
  709. .quad 0x0002000004200800, 0x2000000000000802
  710. .quad 0x2002000000200802, 0x0002000004200800
  711. .quad 0x2000000000000802, 0x2000000004000002
  712. .quad 0x2002000004200802, 0x0002000004200000
  713. .quad 0x0002000000200800, 0x0000000000000000
  714. .quad 0x2000000000000002, 0x2002000004200802
  715. .quad 0x0000000000000000, 0x2002000000200802
  716. .quad 0x0002000004200000, 0x0000000000000800
  717. .quad 0x2000000004000002, 0x0000000004000800
  718. .quad 0x0000000000000800, 0x2002000000200002
  719. .L_s8:
  720. .quad 0x0100010410001000, 0x0000010000001000
  721. .quad 0x0000000000040000, 0x0100010410041000
  722. .quad 0x0100000010000000, 0x0100010410001000
  723. .quad 0x0000000400000000, 0x0100000010000000
  724. .quad 0x0000000400040000, 0x0100000010040000
  725. .quad 0x0100010410041000, 0x0000010000041000
  726. .quad 0x0100010010041000, 0x0000010400041000
  727. .quad 0x0000010000001000, 0x0000000400000000
  728. .quad 0x0100000010040000, 0x0100000410000000
  729. .quad 0x0100010010001000, 0x0000010400001000
  730. .quad 0x0000010000041000, 0x0000000400040000
  731. .quad 0x0100000410040000, 0x0100010010041000
  732. .quad 0x0000010400001000, 0x0000000000000000
  733. .quad 0x0000000000000000, 0x0100000410040000
  734. .quad 0x0100000410000000, 0x0100010010001000
  735. .quad 0x0000010400041000, 0x0000000000040000
  736. .quad 0x0000010400041000, 0x0000000000040000
  737. .quad 0x0100010010041000, 0x0000010000001000
  738. .quad 0x0000000400000000, 0x0100000410040000
  739. .quad 0x0000010000001000, 0x0000010400041000
  740. .quad 0x0100010010001000, 0x0000000400000000
  741. .quad 0x0100000410000000, 0x0100000010040000
  742. .quad 0x0100000410040000, 0x0100000010000000
  743. .quad 0x0000000000040000, 0x0100010410001000
  744. .quad 0x0000000000000000, 0x0100010410041000
  745. .quad 0x0000000400040000, 0x0100000410000000
  746. .quad 0x0100000010040000, 0x0100010010001000
  747. .quad 0x0100010410001000, 0x0000000000000000
  748. .quad 0x0100010410041000, 0x0000010000041000
  749. .quad 0x0000010000041000, 0x0000010400001000
  750. .quad 0x0000010400001000, 0x0000000400040000
  751. .quad 0x0100000010000000, 0x0100010010041000