2 # Author: Marc Bevand <bevand_m (at) epita.fr>
3 # Copyright 2005-2016 The OpenSSL Project Authors. All Rights Reserved.
5 # Licensed under the OpenSSL license (the "License"). You may not use
6 # this file except in compliance with the License. You can obtain a copy
7 # in the file LICENSE in the source distribution or at
8 # https://www.openssl.org/source/license.html
10 # MD5 optimized for AMD64.
17 # dst = x + ((dst + F(x,y,z) + X[k] + T_i) <<< s)
19 # %r11d = z' (copy of z for the next step)
20 # Each round1_step() takes about 5.3 clocks (9 instructions, 1.7 IPC)
23 my ($pos, $dst, $x, $y, $z, $k_next, $T_i, $s) = @_;
24 $code .= " mov 0*4(%rsi), %r10d /* (NEXT STEP) X[0] */\n" if ($pos == -1);
25 $code .= " mov %edx, %r11d /* (NEXT STEP) z' = %edx */\n" if ($pos == -1);
27 xor $y, %r11d /* y ^ ... */
28 lea $T_i($dst,%r10d),$dst /* Const + dst + ... */
29 and $x, %r11d /* x & ... */
30 mov $k_next*4(%rsi),%r10d /* (NEXT STEP) X[$k_next] */
31 xor $z, %r11d /* z ^ ... */
32 add %r11d, $dst /* dst += ... */
33 rol \$$s, $dst /* dst <<< s */
34 mov $y, %r11d /* (NEXT STEP) z' = $y */
35 add $x, $dst /* dst += x */
40 # dst = x + ((dst + G(x,y,z) + X[k] + T_i) <<< s)
42 # %r11d = z' (copy of z for the next step)
43 # %r12d = z' (copy of z for the next step)
44 # Each round2_step() takes about 5.4 clocks (11 instructions, 2.0 IPC)
47 my ($pos, $dst, $x, $y, $z, $k_next, $T_i, $s) = @_;
48 $code .= " mov %edx, %r11d /* (NEXT STEP) z' = %edx */\n" if ($pos == -1);
49 $code .= " mov %edx, %r12d /* (NEXT STEP) z' = %edx */\n" if ($pos == -1);
52 and $x, %r12d /* x & z */
53 lea $T_i($dst,%r10d),$dst /* Const + dst + ... */
54 and $y, %r11d /* y & (not z) */
55 mov $k_next*4(%rsi),%r10d /* (NEXT STEP) X[$k_next] */
56 or %r11d, %r12d /* (y & (not z)) | (x & z) */
57 mov $y, %r11d /* (NEXT STEP) z' = $y */
58 add %r12d, $dst /* dst += ... */
59 mov $y, %r12d /* (NEXT STEP) z' = $y */
60 rol \$$s, $dst /* dst <<< s */
61 add $x, $dst /* dst += x */
66 # dst = x + ((dst + H(x,y,z) + X[k] + T_i) <<< s)
68 # %r11d = y' (copy of y for the next step)
69 # Each round3_step() takes about 4.2 clocks (8 instructions, 1.9 IPC)
73 my ($pos, $dst, $x, $y, $z, $k_next, $T_i, $s) = @_;
74 $code .= " mov %ecx, %r11d /* (NEXT STEP) y' = %ecx */\n" if ($pos == -1);
76 lea $T_i($dst,%r10d),$dst /* Const + dst + ... */
77 xor $z, %r11d /* z ^ ... */
78 mov $k_next*4(%rsi),%r10d /* (NEXT STEP) X[$k_next] */
79 xor $x, %r11d /* x ^ ... */
80 add %r11d, $dst /* dst += ... */
82 $code .= <<EOF if ($round3_alter);
83 rol \$$s, $dst /* dst <<< s */
84 mov $x, %r11d /* (NEXT STEP) y' = $x */
86 $code .= <<EOF if (!$round3_alter);
87 mov $x, %r11d /* (NEXT STEP) y' = $x */
88 rol \$$s, $dst /* dst <<< s */
91 add $x, $dst /* dst += x */
98 # dst = x + ((dst + I(x,y,z) + X[k] + T_i) <<< s)
100 # %r11d = not z' (copy of not z for the next step)
101 # Each round4_step() takes about 5.2 clocks (9 instructions, 1.7 IPC)
104 my ($pos, $dst, $x, $y, $z, $k_next, $T_i, $s) = @_;
105 $code .= " mov \$0xffffffff, %r11d\n" if ($pos == -1);
106 $code .= " xor %edx, %r11d /* (NEXT STEP) not z' = not %edx*/\n"
109 lea $T_i($dst,%r10d),$dst /* Const + dst + ... */
110 or $x, %r11d /* x | ... */
111 mov $k_next*4(%rsi),%r10d /* (NEXT STEP) X[$k_next] */
112 xor $y, %r11d /* y ^ ... */
113 add %r11d, $dst /* dst += ... */
114 mov \$0xffffffff, %r11d
115 rol \$$s, $dst /* dst <<< s */
116 xor $y, %r11d /* (NEXT STEP) not z' = not $y */
117 add $x, $dst /* dst += x */
121 no warnings qw(uninitialized);
124 if ($flavour =~ /\./) { $output = $flavour; undef $flavour; }
126 my $win64=0; $win64=1 if ($flavour =~ /[nm]asm|mingw64/ || $output =~ /\.asm$/);
128 $0 =~ m/(.*[\/\\])[^\/\\]+$/; my $dir=$1; my $xlate;
129 ( $xlate="${dir}x86_64-xlate.pl" and -f $xlate ) or
130 ( $xlate="${dir}../../perlasm/x86_64-xlate.pl" and -f $xlate) or
131 die "can't locate x86_64-xlate.pl";
133 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\"";
140 .globl md5_block_asm_data_order
141 .type md5_block_asm_data_order,\@function,3
142 md5_block_asm_data_order:
156 # rdi = arg #1 (ctx, MD5_CTX pointer)
157 # rsi = arg #2 (ptr, data pointer)
158 # rdx = arg #3 (nbr, number of 16-word blocks to process)
159 mov %rdi, %rbp # rbp = ctx
160 shl \$6, %rdx # rdx = nbr in bytes
161 lea (%rsi,%rdx), %rdi # rdi = end
162 mov 0*4(%rbp), %eax # eax = ctx->A
163 mov 1*4(%rbp), %ebx # ebx = ctx->B
164 mov 2*4(%rbp), %ecx # ecx = ctx->C
165 mov 3*4(%rbp), %edx # edx = ctx->D
173 cmp %rdi, %rsi # cmp end with ptr
174 je .Lend # jmp if ptr == end
176 # BEGIN of loop over 16-word blocks
177 .Lloop: # save old values of A, B, C, D
183 round1_step(-1,'%eax','%ebx','%ecx','%edx', '1','0xd76aa478', '7');
184 round1_step( 0,'%edx','%eax','%ebx','%ecx', '2','0xe8c7b756','12');
185 round1_step( 0,'%ecx','%edx','%eax','%ebx', '3','0x242070db','17');
186 round1_step( 0,'%ebx','%ecx','%edx','%eax', '4','0xc1bdceee','22');
187 round1_step( 0,'%eax','%ebx','%ecx','%edx', '5','0xf57c0faf', '7');
188 round1_step( 0,'%edx','%eax','%ebx','%ecx', '6','0x4787c62a','12');
189 round1_step( 0,'%ecx','%edx','%eax','%ebx', '7','0xa8304613','17');
190 round1_step( 0,'%ebx','%ecx','%edx','%eax', '8','0xfd469501','22');
191 round1_step( 0,'%eax','%ebx','%ecx','%edx', '9','0x698098d8', '7');
192 round1_step( 0,'%edx','%eax','%ebx','%ecx','10','0x8b44f7af','12');
193 round1_step( 0,'%ecx','%edx','%eax','%ebx','11','0xffff5bb1','17');
194 round1_step( 0,'%ebx','%ecx','%edx','%eax','12','0x895cd7be','22');
195 round1_step( 0,'%eax','%ebx','%ecx','%edx','13','0x6b901122', '7');
196 round1_step( 0,'%edx','%eax','%ebx','%ecx','14','0xfd987193','12');
197 round1_step( 0,'%ecx','%edx','%eax','%ebx','15','0xa679438e','17');
198 round1_step( 1,'%ebx','%ecx','%edx','%eax', '1','0x49b40821','22');
200 round2_step(-1,'%eax','%ebx','%ecx','%edx', '6','0xf61e2562', '5');
201 round2_step( 0,'%edx','%eax','%ebx','%ecx','11','0xc040b340', '9');
202 round2_step( 0,'%ecx','%edx','%eax','%ebx', '0','0x265e5a51','14');
203 round2_step( 0,'%ebx','%ecx','%edx','%eax', '5','0xe9b6c7aa','20');
204 round2_step( 0,'%eax','%ebx','%ecx','%edx','10','0xd62f105d', '5');
205 round2_step( 0,'%edx','%eax','%ebx','%ecx','15', '0x2441453', '9');
206 round2_step( 0,'%ecx','%edx','%eax','%ebx', '4','0xd8a1e681','14');
207 round2_step( 0,'%ebx','%ecx','%edx','%eax', '9','0xe7d3fbc8','20');
208 round2_step( 0,'%eax','%ebx','%ecx','%edx','14','0x21e1cde6', '5');
209 round2_step( 0,'%edx','%eax','%ebx','%ecx', '3','0xc33707d6', '9');
210 round2_step( 0,'%ecx','%edx','%eax','%ebx', '8','0xf4d50d87','14');
211 round2_step( 0,'%ebx','%ecx','%edx','%eax','13','0x455a14ed','20');
212 round2_step( 0,'%eax','%ebx','%ecx','%edx', '2','0xa9e3e905', '5');
213 round2_step( 0,'%edx','%eax','%ebx','%ecx', '7','0xfcefa3f8', '9');
214 round2_step( 0,'%ecx','%edx','%eax','%ebx','12','0x676f02d9','14');
215 round2_step( 1,'%ebx','%ecx','%edx','%eax', '5','0x8d2a4c8a','20');
217 round3_step(-1,'%eax','%ebx','%ecx','%edx', '8','0xfffa3942', '4');
218 round3_step( 0,'%edx','%eax','%ebx','%ecx','11','0x8771f681','11');
219 round3_step( 0,'%ecx','%edx','%eax','%ebx','14','0x6d9d6122','16');
220 round3_step( 0,'%ebx','%ecx','%edx','%eax', '1','0xfde5380c','23');
221 round3_step( 0,'%eax','%ebx','%ecx','%edx', '4','0xa4beea44', '4');
222 round3_step( 0,'%edx','%eax','%ebx','%ecx', '7','0x4bdecfa9','11');
223 round3_step( 0,'%ecx','%edx','%eax','%ebx','10','0xf6bb4b60','16');
224 round3_step( 0,'%ebx','%ecx','%edx','%eax','13','0xbebfbc70','23');
225 round3_step( 0,'%eax','%ebx','%ecx','%edx', '0','0x289b7ec6', '4');
226 round3_step( 0,'%edx','%eax','%ebx','%ecx', '3','0xeaa127fa','11');
227 round3_step( 0,'%ecx','%edx','%eax','%ebx', '6','0xd4ef3085','16');
228 round3_step( 0,'%ebx','%ecx','%edx','%eax', '9', '0x4881d05','23');
229 round3_step( 0,'%eax','%ebx','%ecx','%edx','12','0xd9d4d039', '4');
230 round3_step( 0,'%edx','%eax','%ebx','%ecx','15','0xe6db99e5','11');
231 round3_step( 0,'%ecx','%edx','%eax','%ebx', '2','0x1fa27cf8','16');
232 round3_step( 1,'%ebx','%ecx','%edx','%eax', '0','0xc4ac5665','23');
234 round4_step(-1,'%eax','%ebx','%ecx','%edx', '7','0xf4292244', '6');
235 round4_step( 0,'%edx','%eax','%ebx','%ecx','14','0x432aff97','10');
236 round4_step( 0,'%ecx','%edx','%eax','%ebx', '5','0xab9423a7','15');
237 round4_step( 0,'%ebx','%ecx','%edx','%eax','12','0xfc93a039','21');
238 round4_step( 0,'%eax','%ebx','%ecx','%edx', '3','0x655b59c3', '6');
239 round4_step( 0,'%edx','%eax','%ebx','%ecx','10','0x8f0ccc92','10');
240 round4_step( 0,'%ecx','%edx','%eax','%ebx', '1','0xffeff47d','15');
241 round4_step( 0,'%ebx','%ecx','%edx','%eax', '8','0x85845dd1','21');
242 round4_step( 0,'%eax','%ebx','%ecx','%edx','15','0x6fa87e4f', '6');
243 round4_step( 0,'%edx','%eax','%ebx','%ecx', '6','0xfe2ce6e0','10');
244 round4_step( 0,'%ecx','%edx','%eax','%ebx','13','0xa3014314','15');
245 round4_step( 0,'%ebx','%ecx','%edx','%eax', '4','0x4e0811a1','21');
246 round4_step( 0,'%eax','%ebx','%ecx','%edx','11','0xf7537e82', '6');
247 round4_step( 0,'%edx','%eax','%ebx','%ecx', '2','0xbd3af235','10');
248 round4_step( 0,'%ecx','%edx','%eax','%ebx', '9','0x2ad7d2bb','15');
249 round4_step( 1,'%ebx','%ecx','%edx','%eax', '0','0xeb86d391','21');
251 # add old values of A, B, C, D
258 add \$64, %rsi # ptr += 64
259 cmp %rdi, %rsi # cmp end with ptr
260 jb .Lloop # jmp if ptr < end
261 # END of loop over 16-word blocks
264 mov %eax, 0*4(%rbp) # ctx->A = A
265 mov %ebx, 1*4(%rbp) # ctx->B = B
266 mov %ecx, 2*4(%rbp) # ctx->C = C
267 mov %edx, 3*4(%rbp) # ctx->D = D
280 .cfi_adjust_cfa_offset -40
284 .size md5_block_asm_data_order,.-md5_block_asm_data_order
287 # EXCEPTION_DISPOSITION handler (EXCEPTION_RECORD *rec,ULONG64 frame,
288 # CONTEXT *context,DISPATCHER_CONTEXT *disp)
296 .extern __imp_RtlVirtualUnwind
297 .type se_handler,\@abi-omnipotent
311 mov 120($context),%rax # pull context->Rax
312 mov 248($context),%rbx # pull context->Rip
314 lea .Lprologue(%rip),%r10
315 cmp %r10,%rbx # context->Rip<.Lprologue
318 mov 152($context),%rax # pull context->Rsp
320 lea .Lepilogue(%rip),%r10
321 cmp %r10,%rbx # context->Rip>=.Lepilogue
331 mov %rbx,144($context) # restore context->Rbx
332 mov %rbp,160($context) # restore context->Rbp
333 mov %r12,216($context) # restore context->R12
334 mov %r14,232($context) # restore context->R14
335 mov %r15,240($context) # restore context->R15
340 mov %rax,152($context) # restore context->Rsp
341 mov %rsi,168($context) # restore context->Rsi
342 mov %rdi,176($context) # restore context->Rdi
344 mov 40($disp),%rdi # disp->ContextRecord
345 mov $context,%rsi # context
346 mov \$154,%ecx # sizeof(CONTEXT)
347 .long 0xa548f3fc # cld; rep movsq
350 xor %rcx,%rcx # arg1, UNW_FLAG_NHANDLER
351 mov 8(%rsi),%rdx # arg2, disp->ImageBase
352 mov 0(%rsi),%r8 # arg3, disp->ControlPc
353 mov 16(%rsi),%r9 # arg4, disp->FunctionEntry
354 mov 40(%rsi),%r10 # disp->ContextRecord
355 lea 56(%rsi),%r11 # &disp->HandlerData
356 lea 24(%rsi),%r12 # &disp->EstablisherFrame
357 mov %r10,32(%rsp) # arg5
358 mov %r11,40(%rsp) # arg6
359 mov %r12,48(%rsp) # arg7
360 mov %rcx,56(%rsp) # arg8, (NULL)
361 call *__imp_RtlVirtualUnwind(%rip)
363 mov \$1,%eax # ExceptionContinueSearch
375 .size se_handler,.-se_handler
379 .rva .LSEH_begin_md5_block_asm_data_order
380 .rva .LSEH_end_md5_block_asm_data_order
381 .rva .LSEH_info_md5_block_asm_data_order
385 .LSEH_info_md5_block_asm_data_order: